diff --git a/.speakeasy/gen.lock b/.speakeasy/gen.lock index a5e31518e..8b4a48686 100644 --- a/.speakeasy/gen.lock +++ b/.speakeasy/gen.lock @@ -1,30 +1,30 @@ lockVersion: 2.0.0 id: cfa345be-20bc-4980-a260-c3fa74040ac2 management: - docChecksum: b3325da8e73f9deb9074eb6431109f0f - docVersion: 4.19.2-89cac507 - speakeasyVersion: 1.795.1 - generationVersion: 2.932.9 - releaseVersion: 0.11.0 - configChecksum: 9d0bbbefeb8b2ff7ce481e9d4f8af878 + docChecksum: db00d3520ea5f879d66a45d86f521b7d + docVersion: 4.20.0-cee79842 + speakeasyVersion: 1.797.0 + generationVersion: 2.937.18 + releaseVersion: 0.12.0 + configChecksum: 6d3cde65e6cae17721b86f91b41e5a26 repoURL: https://github.com/criblio/cribl_control_plane_sdk_python.git installationURL: https://github.com/criblio/cribl_control_plane_sdk_python.git published: true persistentEdits: - generation_id: 5315bafb-d82b-4451-93c9-ec51f381f7bf - pristine_commit_hash: c5874b91fc1ba671b4e6132248c8ece3dec1d2af - pristine_tree_hash: 662dc88913229621bea8aac27cbeb398d600e06b + generation_id: 0f476aea-4457-408c-9478-ef61c946534d + pristine_commit_hash: 0b9ab4aa15589d9c7e118fd0da87bf8e6eb326df + pristine_tree_hash: 2735004adc4b1ab932ef16a851cd41a892f2d3d1 features: python: additionalDependencies: 1.1.0 additionalProperties: 1.0.2 - constsAndDefaults: 1.0.7 - core: 6.1.0 + constsAndDefaults: 1.0.8 + core: 6.1.2 defaultEnabledRetries: 0.2.0 deprecations: 3.0.2 devContainers: 3.0.0 enumUnions: 0.1.1 - enums: 3.2.0 + enums: 3.2.1 envVarSecurityUsage: 0.3.3 flatRequests: 1.0.1 flattening: 3.1.1 @@ -41,9 +41,9 @@ features: openEnums: 1.0.4 pagination: 3.0.10 responseFormat: 1.1.0 - retries: 3.1.0 + retries: 3.1.2 sdkHooks: 1.3.0 - unions: 3.1.9 + unions: 3.1.10 uploadStreams: 1.0.3 trackedFiles: .devcontainer/README.md: @@ -68,8 +68,8 @@ trackedFiles: pristine_git_object: 8d79f0abb72526f1fb34a4c03e5bba612c6ba2ae USAGE.md: id: 3aed33ce6e6f - last_write_checksum: sha1:33d5d05cfee6756bfd2c5351c71c3964ef5935ee - pristine_git_object: 8cc9e84bce956a80454da0d208b68412b79c0f57 + last_write_checksum: sha1:24b1cccd337284ecbbd84c298b2f498f9c80a6ca + pristine_git_object: 52608e093781a19d45a0fe7985f0a2905cb70db5 docs/errors/error.md: id: 098e4ba23534 last_write_checksum: sha1:fd765abf173770d0cf1e893d0f3e60453ed994ac @@ -100,8 +100,8 @@ trackedFiles: pristine_git_object: 402a99102661f69d1fb9f9c49cd15cc19f745881 docs/models/activities.md: id: e05bc5aa4e49 - last_write_checksum: sha1:c92bf8033c4bb383a4383ae10fe17c5bf33263d4 - pristine_git_object: 447f2e088e16fa2c3ab68bd5202f2ec656e9f0c0 + last_write_checksum: sha1:b7d85e25057f807e87f874718628c6bb2fb4f945 + pristine_git_object: da42aa34269228cd4450b8e0fe1d99822a5b26c7 docs/models/activitiesmanagestate.md: id: 5cd8731acc5e last_write_checksum: sha1:71adf2774c894b5be500b77869d77b6360d159db @@ -150,6 +150,10 @@ trackedFiles: id: c8eccb963947 last_write_checksum: sha1:64d03f8fbd679222ec49a0d79f33e21910d7d148 pristine_git_object: 829598957fc6f813e54f940a078c40f5a691a634 + docs/models/api.md: + id: 565d9cb7648e + last_write_checksum: sha1:7ef832cb5b3a1bb35ba4f8fcee8f0f819aaaa74e + pristine_git_object: bac8676e48f31b9987cca9461df7b52207ac0368 docs/models/apischeme.md: id: b7a630bb9ea7 last_write_checksum: sha1:723c30fa28897666374dcba664df82a0c9d732b7 @@ -160,12 +164,12 @@ trackedFiles: pristine_git_object: 220ca1ace55598247ba5d35560f200d5c3c7621c docs/models/apps.md: id: 9bfa417abe7c - last_write_checksum: sha1:e77c767c07d63b01fde4c28b611a3545edafd986 - pristine_git_object: a8ba273f523ef8b869384b349ace6ab6a678ae4d + last_write_checksum: sha1:49db0201a12cda70c25f986b6c4500df31753077 + pristine_git_object: 1a9a7bd908782258ed19dba197d5f9cd482e25e1 docs/models/appstypesystemsettingsconf.md: id: b5a7e7f6ecdc - last_write_checksum: sha1:31f5dfabd5ac8e20424f842f0d49cdedc6859254 - pristine_git_object: dc064a3de5c4353c3135773a98f53516064aef72 + last_write_checksum: sha1:7c7a20f96287c80c14e842d7b4db2c83bf2b07ad + pristine_git_object: ebac1c2429d773417ea94a80fb3d40ce93f47e2f docs/models/audit.md: id: 122233ecf5ac last_write_checksum: sha1:206247fc13b4329b1f146bd3bea2185e8262f777 @@ -194,18 +198,22 @@ trackedFiles: id: f5156baa7f43 last_write_checksum: sha1:ddcffea89d263c9b787516da9ee9e8d5547cabd3 pristine_git_object: d0022d3b059949a089136b2e12ab0f9f860f7841 + docs/models/authenticationmethodoptionsauthtokensextitems.md: + id: 21a0b381131b + last_write_checksum: sha1:68cf5a7464ae6a7016c700835d81ac3ed7f2788b + pristine_git_object: 59844a40ebe3d960be434b568843aa45a2b2522e docs/models/authenticationmethodoptionsauthtokensitems.md: id: a8ecebcc9082 - last_write_checksum: sha1:040b302d2f4f959f13e95689985e0462ca1fa99e - pristine_git_object: 3937ebc9c7f317fdfc558fda24382445577f279a - docs/models/authenticationmethodoptionsauthtokensitemssecret.md: - id: 92a2efb3dd77 - last_write_checksum: sha1:a7d0d366de49f223920f0cb83592848a9b388fe9 - pristine_git_object: d14e23c53d835aaa792dc3c4547c7b3a926281ce + last_write_checksum: sha1:b26f5f0973a295902510bc564cf08d1f9305cbbf + pristine_git_object: e1199d1fdd6f44ea8aad30d6fa8f2973f80cbdbc docs/models/authenticationmethodoptionsautosecret.md: id: d5f34b9af4f3 last_write_checksum: sha1:7dbb0912fec21847e9df1a17cd2d6e7e7fd71254 pristine_git_object: 3891fa13fc08990a8e700807076ab233aeaa513b + docs/models/authenticationmethodoptionsclientassertionclientassertionrpc.md: + id: 657044cd971c + last_write_checksum: sha1:73e7e952ee2ceccaad1ed3619a91e2336a54a408 + pristine_git_object: 9cfe37684365947dfeb7b21937a69e2f181c2867 docs/models/authenticationmethodoptionsmanualsecret.md: id: 73bc075d6789 last_write_checksum: sha1:9cd3066bb5b4e1be0ce9bba2fc3e23b4f2700a2c @@ -256,12 +264,12 @@ trackedFiles: pristine_git_object: 7298bc956fa02b9a48fbcd2626da469fae25a3ce docs/models/authmethodsext.md: id: 0716cfef3f4d - last_write_checksum: sha1:5837901a6f61f33cfc9cf50eca0b7d9cdfad27cf - pristine_git_object: f6213f7dc5c181044d7a1a39b56cf4b2a5e3eeef + last_write_checksum: sha1:d768f1f24fc81b88271e3237a182567861a438c4 + pristine_git_object: 5dcac0d35e893ebce05854b7c8af2599a04cb59b docs/models/authmethodsextauthenticationtype.md: id: 9e2a7b316c41 - last_write_checksum: sha1:92dc594c5aa86a977918b8b1bcd9b98b89d4bf38 - pristine_git_object: aa488bbe4a096f3e581cddc04803c759ffcb518e + last_write_checksum: sha1:c532a89b18dcfbc5d7a842cc1a6dfabe2486050c + pristine_git_object: 9788fac76551f7f90290b25f8104741935138fa4 docs/models/author.md: id: b4139065dbed last_write_checksum: sha1:e4de78bdc015c401167026ea5c5e757d6d1698d5 @@ -276,12 +284,12 @@ trackedFiles: pristine_git_object: 1e3f97cf768c14e21bc278a86ec2664c4ba16a87 docs/models/authtoken.md: id: 4bd9c62da20d - last_write_checksum: sha1:cd3eadc16f502d652c26e4bb14d59dfae82ed0bd - pristine_git_object: a3930945b098e404ae9cc1d6f712c44027b0a048 + last_write_checksum: sha1:6b10542a0eb0e03072f541342a1cc9aed1174722 + pristine_git_object: 326f575f0ac7560682bf887f0bcb82d9a622a0c3 docs/models/authtokenconfinputcloudflarehec.md: id: 5ed4c87c554c - last_write_checksum: sha1:97e047f97661943d4157d95760f849a821b57839 - pristine_git_object: 1bbf2890308aa120ca020c94554f104a82fa4223 + last_write_checksum: sha1:d79a355e9c533938fd088d94f6b13d7a26e15f97 + pristine_git_object: 8fe5f548a4edbda24979528fab5d5650ee20f39c docs/models/authtokenconfinputcribltcp.md: id: a38009cd8825 last_write_checksum: sha1:201793611f5374b0a3dc33eba16e62fdfc07223e @@ -290,14 +298,6 @@ trackedFiles: id: fd1c6fce012b last_write_checksum: sha1:63071392948e09dbda9067d696634717fc5fe6f5 pristine_git_object: ee048e30a1c3b36088c544fcd5871ca8ee8d03c6 - docs/models/authtokensext.md: - id: aed9821d08bf - last_write_checksum: sha1:6952beab0d975d66ce8c1b6a70d174c08bd174fb - pristine_git_object: 598b808f1f94a85061fb5dacfb88d43060998b60 - docs/models/authtokensextconfinputhttp.md: - id: dc1290943939 - last_write_checksum: sha1:34d3e090e0a0dfdbdf5826a26ee3bbda160e78dd - pristine_git_object: 0d5bc4e0a17123e08005e5fd1e38bb5a83cf8b05 docs/models/authtype.md: id: e7d1386db3fa last_write_checksum: sha1:a496a591248f466144891a9f1b9810fa717ce57d @@ -368,12 +368,16 @@ trackedFiles: pristine_git_object: 4e927c790eefa8fc697a615b46cee8641e22a988 docs/models/azureblobstorage.md: id: f0c373bfc47e - last_write_checksum: sha1:14ad1f9543a9762a8fede7ef5cb653ddf3e6113a - pristine_git_object: 6016a91e4128ff84ce06c51b6570b6f9e9e470d4 + last_write_checksum: sha1:ee1a46dc8b6ca7e1d0d245f25214471a0610e53c + pristine_git_object: 872c475c63c64f1209b4123488d82e38db05d9d8 docs/models/azuretypeheartbeatmetadata.md: id: a2f372dcd8ec last_write_checksum: sha1:c81c992076c9d06251cb9282e7726337dc33be77 pristine_git_object: c879de1a5e3ef2e4f22ae758364054a4a1c53cc1 + docs/models/backendid.md: + id: 276cf36036a0 + last_write_checksum: sha1:10ded02f286e42f23ac19749de7fc97646b0f7ec + pristine_git_object: 31d3c382a7ea33eade03586e47aa3d396254de1d docs/models/backpressurebehavioroptions.md: id: 06a39b1547b3 last_write_checksum: sha1:53afa98d9a892b95092c3e6e78fe6726f9baa1c5 @@ -404,8 +408,12 @@ trackedFiles: pristine_git_object: 609f6caa8bbaaa945eaea48e4aad8e60213b4d41 docs/models/branchinfo.md: id: c4f285e2fed9 - last_write_checksum: sha1:b5744654aa12367e582f6a7f8c889215380794e5 - pristine_git_object: 4457d94babb6f35d1442d2698204792bd79de143 + last_write_checksum: sha1:1ceec535c8d755f39972adee972e256219321a7e + pristine_git_object: 6596077f40ca6bc5bae52da28b557e8f7fbc53f1 + docs/models/bucketwidth.md: + id: 209e4dad10c0 + last_write_checksum: sha1:a4a863023bf2c522884aa422f29060b5c4a40001 + pristine_git_object: 8c26e7e8fbc80ce8ac377e7496783991cba5d2da docs/models/cacheconnection.md: id: 43b19510231e last_write_checksum: sha1:e814ad73d4624af750cd2ce3da0540826ee8e314 @@ -430,22 +438,26 @@ trackedFiles: id: a4a2fef4831f last_write_checksum: sha1:8b951b392a26d9fb52ed457a8502d541e52add45 pristine_git_object: 2b49ff9df1507a371df25bcac4bca680cc45d107 + docs/models/certoptions.md: + id: 0f7cfc419603 + last_write_checksum: sha1:139650b0e95b620a06476cd37de1db7a3fcd847c + pristine_git_object: 448b2864653a5020e244995ec2f93439007b10e2 docs/models/certoptionstype.md: id: 24f0ee3d844d last_write_checksum: sha1:cdb126788e46f980fed9b77694f783b550f4554d pristine_git_object: 0696e3aca9b59fd6357921b58c353c5ff22cb44f docs/models/chatmessages.md: id: 0b63fc7a8496 - last_write_checksum: sha1:cf0d2202a40ae74cafc18c6687f0c5ef889a36a3 - pristine_git_object: b039ff5a3257b29d15456afd076bee570d7f8bca + last_write_checksum: sha1:4cf5038ab6ba89622e28d5b6683f3fcb4aeaf30b + pristine_git_object: 620f07a865361810bcc9aa0416db8869aea370ce docs/models/chatmessagesmanagestate.md: id: 06f6c1340cc2 last_write_checksum: sha1:d1cbb36363f52122cebb778796390cb4d69bbc84 pristine_git_object: a21921fe6daef9127d6aa2a1917ac5b5d7ecb259 docs/models/chats.md: id: 6c80cca961f4 - last_write_checksum: sha1:61d3b7fe1c46b596fc867dfbeeb45b975b8a9071 - pristine_git_object: 0cb02a9b2ed8019b71058a71513323e313cbd5ed + last_write_checksum: sha1:3c36a0925ba08c3e7b73bf98f345821b148f26f8 + pristine_git_object: 2e7cea191fc05cc956622a4ee8bee8ba35f4af79 docs/models/chatsmanagestate.md: id: e4bf00e6038c last_write_checksum: sha1:9a400555a7e80af16df59ae11d8a703301cd5276 @@ -618,26 +630,18 @@ trackedFiles: id: b8def926cb9f last_write_checksum: sha1:c69d2d9a317251d7546e827dbbed51b9dfab2f39 pristine_git_object: f7addc5f600367ad1a5a9b3234df604dc2a9e3c8 - docs/models/conditionspecificconfigurations1.md: - id: 66fc492972f1 - last_write_checksum: sha1:52d6bd84dda004fd05853b80b16cdc9d6ec87388 - pristine_git_object: 18e318068e0cb430b6a19b86ac501a0a8fe5d6a4 - docs/models/conditionspecificconfigurations2.md: - id: 5cedc5ab4f35 - last_write_checksum: sha1:24587b8de26420cc4796e71960bc8248f0b1c357 - pristine_git_object: 24bafb5abec205cd07eb6eea8f6b0b7671a86804 - docs/models/conditionspecificconfigurations3.md: - id: 57986ea40586 - last_write_checksum: sha1:70f3a7e9491f5208b4bf0ebecb5d25aa05b47187 - pristine_git_object: de115e77ce999319a944b11c083fd1f8120797e7 + docs/models/confidence.md: + id: df320e626ea7 + last_write_checksum: sha1:101a7c440ea198b9d335faae698117a3a8352808 + pristine_git_object: 53a0381b59e9fd73557eb333b7a89b23c114f787 docs/models/config.md: id: bef254bf823c last_write_checksum: sha1:cf303b81129eebc91f7bf410c515a8e82a0bf965 pristine_git_object: 5e1d8f82ed219f441c95ca68cf3c62a7568d171d docs/models/configgroup.md: id: 7f7c83526f8c - last_write_checksum: sha1:a8bc8c588d7eb936123d5834379d4b3657426d68 - pristine_git_object: a6b6cd971e46c575ca252c8a416c2d2fa701d606 + last_write_checksum: sha1:48b133878622ff1431a6ddc282409b0e71ca26eb + pristine_git_object: 7b7c6002e972bf47caf8ecafb7df415f059f95fd docs/models/configgroupcloud.md: id: 6bba10d8b38c last_write_checksum: sha1:a88a3e4def09e1eb5d6c70053f2e5c929c6a54e5 @@ -648,8 +652,8 @@ trackedFiles: pristine_git_object: 29f4e359cd8b3d8f15afd0622e9b3f581aa5e22a docs/models/configgrouplookupslookup.md: id: fd555ac7e17a - last_write_checksum: sha1:08fcd79611bbd8b4d0e1a9527af782c342ddc821 - pristine_git_object: 4d05524ed4a067b46c8c3b368573eed48c1e808e + last_write_checksum: sha1:cee3f5c37a6622f6210866969cb8761a3e47e5ce + pristine_git_object: 32160b85ac2d0dc182f6177d48161bd71c5edeb3 docs/models/confinput.md: id: d60ee29375da last_write_checksum: sha1:821eb493732c56abb6af6b4ef5568907cb37c623 @@ -672,172 +676,176 @@ trackedFiles: pristine_git_object: f0f7a03721979f7bc41c1f29b5e19e3d28ab7fec docs/models/contentconfiginput.md: id: 3428f87abd95 - last_write_checksum: sha1:7395490bc5f5580cbe3461ee88832153f61cd37a - pristine_git_object: 975cca67bc611ec286a19ee4aeeed131f3b5c04e + last_write_checksum: sha1:4dbea526306069c361c2c721ccf81ed2b7175b92 + pristine_git_object: 2cd8dc3fc018efb38635398a0823ff3b7f9d5467 + docs/models/contenttype.md: + id: 78e9266f4216 + last_write_checksum: sha1:1247a6195a3c916274907e613f141aea41081e43 + pristine_git_object: d872906697092c8cce037214c47813f3496c8e52 docs/models/countcomparator.md: id: d434f0946c99 last_write_checksum: sha1:e5309e055b638f85067e7d1b7b11e14a27f6783b pristine_git_object: 912295987d4d2123f490e9666b6e2da35faed6f4 docs/models/countedboolean.md: id: 5f211313799e - last_write_checksum: sha1:17cbf679466e9e0516793cdf0da0701e918cef77 - pristine_git_object: e656fa4f32f28d25ac01eccbe19a99ba348a46c1 + last_write_checksum: sha1:cbb5abf89ca7367c6845222fd27f821f3dc7eb49 + pristine_git_object: ba88005943c7623647f9243ed2fcb934fcefb45a docs/models/countedbranchinfo.md: id: cab30d33d1a8 - last_write_checksum: sha1:0978674b8c8e045c8a75dcd35282233d9053c542 - pristine_git_object: 1cfa61d15c4b4bc60568a3a27392391badc66df3 + last_write_checksum: sha1:82068f4bd12246f389399e61dc84d1b19a3c09c8 + pristine_git_object: 9ef8153c2df3f4b150e177e7ecdb63f5eeb49c08 docs/models/countedconfiggroup.md: id: ccc5071913a0 - last_write_checksum: sha1:3029e1db2e669214f0d699c60f74e9bb84c9abf3 - pristine_git_object: 5fa74b700e0e9be38fe36196369928651d09f300 + last_write_checksum: sha1:bc342a76f8a526fe7dbbf72f091e94343a3e9fbe + pristine_git_object: 4ff44f1b9c20e5bb358357d2259a841c572a5f98 docs/models/countedcribllakedataset.md: id: 6bd413f9b941 - last_write_checksum: sha1:1e49d2546dd4d476b746f085eaa8543d9de8e0b2 - pristine_git_object: 6dd0451aa3dba38441954558f57e90cabf9c3a63 + last_write_checksum: sha1:789187ae7c1abb5d77f3fe6b5dd39e51ec523ddb + pristine_git_object: e86e3ec25417c386ec18f4f32d3feaf3e43bbed3 docs/models/countedfunctionresponse.md: id: 43b6b2e50b35 - last_write_checksum: sha1:27d364be828957fd958ae393da540167403127b6 - pristine_git_object: 6b75dd53b1853fd5ad3ed35ba18d4ee1dc4f78d5 + last_write_checksum: sha1:6833538347c3290c2b706beba25b8a8fc539df5a + pristine_git_object: 523bd5cd1871e89d519b6baf191f0c4f80510498 docs/models/countedgitcommitsummary.md: id: 1f68fdbc15aa - last_write_checksum: sha1:78995954a6d3e32c6f861f081de911a249ce6d52 - pristine_git_object: 4f124601e301afdc96bfaa63d279da99c509a220 + last_write_checksum: sha1:92f4d600e148c0b89864a6298334c04f91915d4b + pristine_git_object: 77f2d969b8536bb457f1450a46ffd9c8a02dc33e docs/models/countedgitcountresult.md: id: 277799168ff0 - last_write_checksum: sha1:a3d15b349f447530b464e4ef9514524aa3bc03f5 - pristine_git_object: 4a1400de5bce3c188fce9588685794831ec374e5 + last_write_checksum: sha1:e9969749f7bccabf667bb13d6dbe1f2b25f602ba + pristine_git_object: 2b0608f094aadf715fae0d52ce51f4836adbaca2 docs/models/countedgitdiffresult.md: id: ec6eb1d76f92 - last_write_checksum: sha1:837fb2713f6c0b573724a97ca33d69744de77aac - pristine_git_object: ed38a77ca077c1765674dd6e0128eab7b32c689c + last_write_checksum: sha1:f22f455fa618f89757905bb881bed82a57ce7b16 + pristine_git_object: 8fbd57014604fff158ada274f6e79895c5bd4c19 docs/models/countedgitfilesresponse.md: id: 19970ab201fb - last_write_checksum: sha1:2eab32eb94abb0b4a92c727325bdb6d679e793a0 - pristine_git_object: 2e5f017b0adb6b102f8549db95c38868fd0ff614 + last_write_checksum: sha1:f6a9f0fc3e56041d73efc71191f3b2d8051eefb7 + pristine_git_object: e0a87ed5788c883e0d62200361b88f283804490c docs/models/countedgitinfo.md: id: a94cd27da873 - last_write_checksum: sha1:3c9075f2a1c1d2a5a243510a4eec473d204c886f - pristine_git_object: 3e8505d48f51e39697e4ff25f9eae9380c8dec9d + last_write_checksum: sha1:c00803e15151b4c5780a3cd1c10d25a3a820f644 + pristine_git_object: b9e1e1646bdf0069f8458f5e6962bd21fa4eb977 docs/models/countedgitrevertresult.md: id: e68dc76a9769 - last_write_checksum: sha1:939abb2a9809ae84e1e4c1e0ca56e2d586aec62e - pristine_git_object: b472d8d604bedda49532865e5fede98e7d0ef8e1 + last_write_checksum: sha1:7c511bc445ae7c96cbb97ee3f87b6c2d3712b137 + pristine_git_object: 2ccc9143b33f06f366be251b7b99b621d2201918 docs/models/countedgitshowresult.md: id: ae859dbbd66d - last_write_checksum: sha1:3645daef7c7867acc9b5e15e169cbaa1d4b8a621 - pristine_git_object: 72734c07ef5cadf09e569510dc14a0e5be44e736 + last_write_checksum: sha1:dbf6e922e12d04dafb023df28a8b80b3ea890ea4 + pristine_git_object: 7f2e49bc7b0ccf376fbf8c77f445bb290e77e10c docs/models/countedgitstatusresult.md: id: 9b2c819f7cdc - last_write_checksum: sha1:3b471f2fb65b901912b12cff5ae5348eb3a3aff9 - pristine_git_object: 638487a9b69be90a215723ce811ef2d1a7bafab0 + last_write_checksum: sha1:be1b8dd3484b7dade66b156e3353a7ce475a2001 + pristine_git_object: f2eea79bca6f129fe2d9ce46095a1f961d41dcf9 docs/models/countedinputresponse.md: id: b6b2fc1dbb36 - last_write_checksum: sha1:2193f9b0081756545ed08c2dabc6743d921e1d8c - pristine_git_object: 66b789d4fef0750cda0428834381ee0b6a2e6b28 + last_write_checksum: sha1:59dcb12ee3aa8e459bed6495455c6c2416a85693 + pristine_git_object: 73ca537cb2dab7ec63c2a9e5e01064f3a6867cd9 docs/models/countedinputsplunkhec.md: id: 49782baf5571 - last_write_checksum: sha1:57a46e30d49f8e975748640ecc313f817eeb9bd5 - pristine_git_object: 4919217b111a3a7dc24382768890162e196f68f0 + last_write_checksum: sha1:b5ed192437e512fcbcada2cd34457092670327db + pristine_git_object: 8d29282aa8f69edc14e71011d71aa1f7ec1fac29 docs/models/countedinputstatus.md: id: e21fc88b1b4d - last_write_checksum: sha1:324b4c0f841ff1fe70d9c8d9d3ccbc540145ad1f - pristine_git_object: e3436ba4ac50a9da5cbdf744ce6bf5733b6deeca + last_write_checksum: sha1:35656235becd6e7d23b44a677c883de390bd5b6e + pristine_git_object: 668b43e3d15cc18d262dd15e13f99ad71d53b7c5 docs/models/countedjobinfo.md: id: 0515baa0b6d8 - last_write_checksum: sha1:188331889a5823a76637d93835929db5b0b4881c - pristine_git_object: a0d848b9d5e670c24b87ffa31a6c45dd4dd95c50 + last_write_checksum: sha1:1ab8c579a7f03cd72d8caca141b3c5efbce2751a + pristine_git_object: 5264a9837e8bf30b0a46819fead6c1f39d8ee487 docs/models/countedmasterworkerentry.md: id: bc5b9856a5e4 - last_write_checksum: sha1:953fd66a5e5a96731186585b7583d3194a5e21ac - pristine_git_object: 546a321857ceb9b8a576a75b3052eada7b314acf + last_write_checksum: sha1:1539aba4f650eeb266ed25e395114b3cc1d92429 + pristine_git_object: 69d98a1c938e90990e272537b5b25ba565c56482 docs/models/countednumber.md: id: a265c4629b1f - last_write_checksum: sha1:d0347ff29898a4d9c949639792b00e99fca0e813 - pristine_git_object: 9b5fc1ba5a7a363e11852e8457093eaaf946d33b + last_write_checksum: sha1:c413fe6ff96c3d7deca47a8e73fe116571484e96 + pristine_git_object: eb1a64fe1e17ec05d6ceabda3d0d4be310b6be6e docs/models/countedoutputresponse.md: id: 4361bddb2b4d - last_write_checksum: sha1:ef1eee864888089f9e485a953b2fdb516e990c71 - pristine_git_object: ada5828ff44eedb1118db4f51551f4e09a22e7af + last_write_checksum: sha1:bc3883ff77b62c92e0e8c4e62fb5a9c0e7965e51 + pristine_git_object: 618d12d270689786279d847e7d9f6f36b493554c docs/models/countedoutputsamplesresponse.md: id: ec9f2f9ddf91 - last_write_checksum: sha1:1b953d13aca0c958d5e4f367c5fc6ea0374389d4 - pristine_git_object: 318732b8319d7eb98e00f13ee18cefe47fa7e068 + last_write_checksum: sha1:2f5dd4780fccaf3b3264e68fcec8ad8fdd9eccca + pristine_git_object: fb55729fd3221da3826f452ff31a3ff4a16fc621 docs/models/countedoutputstatus.md: id: 724ee60d86bd - last_write_checksum: sha1:100db1c1123ab96b538dd6b0a5ee049aa5d6e98e - pristine_git_object: 07fbfeb93b6a6b52dc9691dd1b58a18afc41c5dd + last_write_checksum: sha1:b5465f4b766a15642483a55b8abecf9b41d0edb5 + pristine_git_object: cd3c0d45f33adeb6c4fd49ea4d19ad09e2c33d26 docs/models/countedoutputtestresponse.md: id: c7b6172a959d - last_write_checksum: sha1:75218a689630efc3ca093b41eaeb9abb33cd2331 - pristine_git_object: f53240b430e4084a8c695989edfcdc7451bae4ef + last_write_checksum: sha1:973a171e6f4111407c85559241a18fabad9d57e5 + pristine_git_object: 1ef7d02ce2948d04b3581fba3419531a720ac6b9 docs/models/countedpackinfo.md: id: f473002a74bb - last_write_checksum: sha1:44d9faf52e05e249ad79a92ef81607cb98095cee - pristine_git_object: ca7e6ee33fa6aa57fd2726e9e2ad35132cc95d08 + last_write_checksum: sha1:69c3ba43534642fbf43d3b93472eff0761f8a7b6 + pristine_git_object: 857a83170ffb6c9a879e8450c3d5e965c3201ee6 docs/models/countedpackinstallinfo.md: id: 1af61ab7b360 - last_write_checksum: sha1:73db8ea089d0c766eb576d1aaa9d5d9e0b8cf96c - pristine_git_object: f1fbfb00021df1d23d8f627e1253834bfa66b820 + last_write_checksum: sha1:c4683ec3d19659b0b9606ecb86d49b45fcef32a6 + pristine_git_object: 6bfc105cef858ffa57fd67df62656993265aab67 docs/models/countedpackuninstallinfo.md: id: e30a267eb9af - last_write_checksum: sha1:446e0d68d52e7bdd26229649ebd4d6abc363946c - pristine_git_object: bfbcd1b2e102a01a0897c2901788f53ba4c13c8a + last_write_checksum: sha1:e980320a2b0d75700c50852d063f5bc1117f6bf6 + pristine_git_object: b0e246a85b566210ffafa428083e4c90ff065c5c docs/models/countedpipeline.md: id: 381bbf78066a - last_write_checksum: sha1:3b4c1b32cd7bfc94970b1139a90bbd11f975100f - pristine_git_object: aa53a79973c184b480f5a4f27764620f7e34eb3c + last_write_checksum: sha1:00571ed56e0a487bda6e6cd7f87fb20aa2699b4f + pristine_git_object: a605e682b5001a7402de40b72c48c9e776c7e408 docs/models/countedrestartresponse.md: id: 565297be8b11 - last_write_checksum: sha1:14fbdc2f7008b1e2742341c7f497563dec5d8851 - pristine_git_object: 1cb142643813c14a948299ec336427e63aad0fc7 + last_write_checksum: sha1:1b7ac82f1fda6b58a051e07fd7457fb1d4d40ae8 + pristine_git_object: d4c26549100f3ac97d336c106d7d104dfdff413c docs/models/countedroutes.md: id: 5bd8f7e84bbf - last_write_checksum: sha1:0a3dcdf2d726bc81cbb440ec7bee448e1bbf7606 - pristine_git_object: 32c0dc772d5ef2d6a68adb705b1d8c624de72f4b + last_write_checksum: sha1:a86ae6cd3829349533b1911aa830c8ea1975462d + pristine_git_object: 94866a9d3efefaca2e20fed66acbfb8f11ed8bc8 docs/models/countedsavedjobresponse.md: id: 4019d7ab3a8b - last_write_checksum: sha1:8dda64f6357c90df59328caed49175a28d927a26 - pristine_git_object: 5b5f0747903033d3826155148b36548970d7a436 + last_write_checksum: sha1:5047220c2928cd31e17146b2c894035591727e97 + pristine_git_object: 481d5c4f803f383a494d69ef1b401f9c5b3dba27 docs/models/countedstring.md: id: 838a204ff6ff - last_write_checksum: sha1:cd2921802db0103b43947290aa6b8f5b379ce7c4 - pristine_git_object: 8ba0f58fc127338eb6c2222adcd34779ce1efe4e + last_write_checksum: sha1:1cb90ff6b92b452feb7efbc5c4b50a08259a2f2c + pristine_git_object: 26c9bbcf19c244512f7a031a509ca38a56520c5f docs/models/countedsystemrestartresponse.md: id: 81d8aa8e0b67 - last_write_checksum: sha1:bf177cbfd0d7c1d58c7f7d6a6c15d0140d4dd3a9 - pristine_git_object: 92565fec041aa8f24249d085234a359930483d69 + last_write_checksum: sha1:079c6204a383e961aa85190c86f83069bb91ac43 + pristine_git_object: 56aa1cd266f387e06d34efafc15e06ec12a14d03 docs/models/countedsystemsettingsconf.md: id: dc229c0f9ad5 - last_write_checksum: sha1:2baeaf95a8f41f8eb40e823a5c5cfc0ad373d851 - pristine_git_object: 5f6c21ebff611aaccd16ed1f034295ce6f937383 + last_write_checksum: sha1:cddf75f22cf30c231e84ac2ae2f7224f546f5c99 + pristine_git_object: f41701027fc88a544e7a37d9376642a73256f7e1 docs/models/countedsystemsettingsconfresponse.md: id: 234086daa1db - last_write_checksum: sha1:d9443cb7b0aeb49c357e2b1bdd5d51780d639d32 - pristine_git_object: 4c8e241ce95cf7e8e6fb948e25e5fd724339f1cd + last_write_checksum: sha1:9813c299d2d8d8f44b77717c7308d6ba448b2a67 + pristine_git_object: 662bce501924589bf38a4db35699e74c2dc45c5e docs/models/countedteamaccesscontrollist.md: id: 5f38314cd2be - last_write_checksum: sha1:fb5d26fe1b6bb16fc8db85c7f85e5244303d89c8 - pristine_git_object: 03310fadb92f540fe1f92252ba4d104d87d35e17 + last_write_checksum: sha1:f9cd9766cada357dad2d3f3ca06790ce721c763d + pristine_git_object: 45919fa2540e05fb88dd3f3b01fa635b43b0a417 docs/models/counteduseraccesscontrollist.md: id: d91eba8e54ef - last_write_checksum: sha1:060c5c779530112a20f87e011039b019250f582b - pristine_git_object: c1fe729cd113702fd556a58b0b9996d0d7b48513 + last_write_checksum: sha1:662c7404d41b40dbf12f93c73bebe26c793c4fcb + pristine_git_object: c512f3167384c40b75059497f56b2f5457edf5b2 docs/models/createauthloginresponse.md: id: c36f5e51e2e1 last_write_checksum: sha1:e2c378e925085035251685c8e7a67427de588e1e pristine_git_object: 9bf8121706a69ce774c19979135f70fbee8ad7a9 docs/models/createcribllakedatasetbylakeidrequest.md: id: 046303af8694 - last_write_checksum: sha1:627b11726b36f39c60620a33994681382a3c570f - pristine_git_object: 7ba219bc7be8379f95762c34aea1d8e2c8d758de + last_write_checksum: sha1:cb9f6d6ab2af9cc84a41e48d9209fa7466121b84 + pristine_git_object: 513318877174a9ac3c840c36501e7efcd6570d51 docs/models/createinputaccounttype.md: id: b15ceb630b4b last_write_checksum: sha1:10703727b3883aac2cf05a089457cf6252daa431 pristine_git_object: a7dab675bfc0d5a50b70ca1717b3bab6f37ce798 docs/models/createinputactivities.md: id: b0b39e07d6d7 - last_write_checksum: sha1:e312ad574de3b0f4f4b7f966884252acd706eed8 - pristine_git_object: 590cbd3de3b9949ef02a85bbf6f5b22133ab832e + last_write_checksum: sha1:7bafd1036d6e908ae50f0a7a9558ee109a807fab + pristine_git_object: ae293908534b91232bf40fac32bf3df27da8687a docs/models/createinputactivitiesmanagestate.md: id: 0e0134a07799 last_write_checksum: sha1:40ad734e36a8ec0abd5fb5ad7e9fee58ae000d6e @@ -864,36 +872,40 @@ trackedFiles: pristine_git_object: a2542408e7ca3a0f45c74581c6cb511ade214695 docs/models/createinputauthmethodsext.md: id: f6a570dc8fb8 - last_write_checksum: sha1:439bad78d13aa5a440acfb1d3479e0633943e6b9 - pristine_git_object: 9607a30557cae040be18492a6c0f80ad28203c8b + last_write_checksum: sha1:9f027c2d102a596924d3b018c46f9cbaa1f110b0 + pristine_git_object: 543e246fc28e3c6c033339fb35a20b77e36744bd docs/models/createinputauthmethodsextauthenticationtype.md: id: 73152e6ae2c3 - last_write_checksum: sha1:7cff69644e323b4d9d1680e0fbf7c844b106bd78 - pristine_git_object: 23b7152829724ffa891e1c1bfd2b9bbe70f0d82c - docs/models/createinputauthtokensext.md: - id: 0d389cb46d97 - last_write_checksum: sha1:a34bd5d88038de110f3aa7977e7264540db5afa9 - pristine_git_object: 9bea84176799a5a9d2b340007b5e367a25e873a9 + last_write_checksum: sha1:2d7624b09b09b9688a37fd4d75dd9a97ce578f5a + pristine_git_object: fc6db747e8bc619c30a05f24f0ce9ca2eea9e64a docs/models/createinputazureblobstorage.md: id: 89b444189d6d - last_write_checksum: sha1:218440b69167e7ef99499ddc7942709fa1cac677 - pristine_git_object: ac57cf91943fac8bace1c4020f1b65149f68acc1 + last_write_checksum: sha1:aadf5429cddf8c58f5b8f8956c12f896a817a783 + pristine_git_object: e2ef826c92bfb3bdaec2f14cbdc7ebc330f3f0d6 + docs/models/createinputbucketwidth.md: + id: 17e6c11d8433 + last_write_checksum: sha1:1ad58a87585f7da7e84b051ffb611c4ac1759e8a + pristine_git_object: 0b3a5f88683f22f4d33a2435a02fddf05c49eb24 docs/models/createinputcertificate.md: id: e5545ec89a30 last_write_checksum: sha1:ce8dfb227d187d6798dee452d3443c738115d8c6 pristine_git_object: 622fb9631dbc54cfead2c9dbd0b70329800c398b + docs/models/createinputcertoptions.md: + id: 9ab100e02971 + last_write_checksum: sha1:f49071320f5fe9eb155cf293875aa770bf71ffc3 + pristine_git_object: 955a00f3943b6a5b5be8d38d8d775de82ada2001 docs/models/createinputchatmessages.md: id: 699d3cb6cea4 - last_write_checksum: sha1:f0ae984527541c4d3b594b26a1d4d1f0862f4bb5 - pristine_git_object: c9bc5dc6d030ef099d48164323ebb0bea59f6169 + last_write_checksum: sha1:dea06a9e1a64f4837cf47d37b274547bdcd4e9e1 + pristine_git_object: 01f7de8fb37bd687d11104173883f1694fba9bbf docs/models/createinputchatmessagesmanagestate.md: id: a6bcb06cd710 last_write_checksum: sha1:d04cbdd22a003ca278a037f4f0d1cc2683587613 pristine_git_object: 3a70755c8af51b6d583a44ce4041f416afc7277a docs/models/createinputchats.md: id: 0383d13a600e - last_write_checksum: sha1:8fc5aee55bfe72b3ba3238baaaf8ca75b87e5d33 - pristine_git_object: 2f092ecef0eae28f5fb1e4ea978c017aa2246802 + last_write_checksum: sha1:36c26834408ef9215f6ececa6db7c402d174866c + pristine_git_object: 17bc0367fc37a7c31d6cd78728d12afdda662630 docs/models/createinputchatsmanagestate.md: id: fead25287434 last_write_checksum: sha1:1267f276e1386237a7dbc05f3711acc5bac33614 @@ -918,6 +930,10 @@ trackedFiles: id: 5203e70e1f05 last_write_checksum: sha1:ecb6328a9299db41372246e25b1166c8a70c86b8 pristine_git_object: cf1438d63efd73364871e8e82f528dd348b71670 + docs/models/createinputcontenttype.md: + id: a2cb8cf54afb + last_write_checksum: sha1:c25be918c63edc5338c545669e7080bf92142813 + pristine_git_object: a61170d7e3120a3313c0fd6f32bde5d4dec81f76 docs/models/createinputdisksandfilesystems.md: id: c9acdd08f7e2 last_write_checksum: sha1:e32bf2e8316db9a13fb8afd6df2c36a4a6d418a1 @@ -926,10 +942,6 @@ trackedFiles: id: b428cb853edd last_write_checksum: sha1:324415db0388f9e80c38f2f41dc79d5736332261 pristine_git_object: f47a5f6535126e3f59a8614e78b8227ac762c1be - docs/models/createinputelasticsearchmetadata.md: - id: f373a34f8250 - last_write_checksum: sha1:c54e7209138fccfe08fb8c0a2ee411537d8a97d0 - pristine_git_object: 0f1915694a1cd0e1f05a93ede9c30f1dfcfd3c26 docs/models/createinputendpointheader.md: id: 0ade5570df95 last_write_checksum: sha1:77061e6cae17013476cd617edb98029d0a1b88d7 @@ -942,6 +954,10 @@ trackedFiles: id: f2d3ece8f414 last_write_checksum: sha1:7b7ccd83d43a182156e8c5d64445c535820df89e pristine_git_object: 1584751ba51f04db9fc412c15e0776f1cab07897 + docs/models/createinputfeedtype.md: + id: 0e4e6fc8c311 + last_write_checksum: sha1:df7a6c597e5f7b880cb6de8e0f5ffe1206a8caba + pristine_git_object: 46e9221c885ab78fd545025fc0f92d60dde54f90 docs/models/createinputfirewall.md: id: 5ec009b41782 last_write_checksum: sha1:3ea569a5549407ae9842e341b6d1669b21be924a @@ -954,6 +970,10 @@ trackedFiles: id: 1bcb01b5ea9c last_write_checksum: sha1:045f5c3995e0df0bb97afc91adc6429572dec8f5 pristine_git_object: 47cd3308005856f50f720d06a40de5e18de3464a + docs/models/createinputgroupby.md: + id: 8529edff8c90 + last_write_checksum: sha1:7cbe43f61dab9fdd71c81c0d494b17cc7929f8a5 + pristine_git_object: e2357c86207af5ba3262201e9115e007ff650be8 docs/models/createinputgroups.md: id: da539a37736c last_write_checksum: sha1:5b96204645303f74dcc614bedad61559e6b5a301 @@ -972,8 +992,16 @@ trackedFiles: pristine_git_object: 406e8cfd5cdda4ee430409321219d12b24b60b6b docs/models/createinputinput.md: id: 4d29b2306dd4 - last_write_checksum: sha1:4eb0fe7fae57ace40a3293cf892464ef1209449d - pristine_git_object: 23cf508cf30dabaa00bcfb7aa6be099000a2d69c + last_write_checksum: sha1:ca71698db6147ff0a6e87163c5e111ba1edc2ffb + pristine_git_object: 9af14cf84c84ee9ea3aa10e7d9ff756b6babb2d4 + docs/models/createinputinputakamaihec.md: + id: ac60fbfe0041 + last_write_checksum: sha1:a52adf49d1cbd97bd62aee42e5cf0c786075123f + pristine_git_object: 5d967ae023628e2ab0d6496752f5b84ea4a33f41 + docs/models/createinputinputakamaihectype.md: + id: 1117bac8c945 + last_write_checksum: sha1:629b89e6e77d1ed857eed2355f6072c099578279 + pristine_git_object: f3965b4827093652c5ce9329464e9f5c9e44e663 docs/models/createinputinputanthropiccompliance.md: id: 1195fca8486d last_write_checksum: sha1:1298acb7606f6fd470b76ba238b8ae9473381d48 @@ -982,6 +1010,18 @@ trackedFiles: id: 64ae7f17f8ec last_write_checksum: sha1:b8d287899fc630e00425d1500b4e6cf50931e60e pristine_git_object: f5c9ee2aefb3708e2f31b39f0ca5a9700c6df5da + docs/models/createinputinputanthropicenterpriseanalytics.md: + id: 652ee62852ef + last_write_checksum: sha1:9e7c8652518c296bd4d795160410edf72f6e1e83 + pristine_git_object: 0b956ef1ea91c0c4de194ed6dc4583b1170e5cda + docs/models/createinputinputanthropicenterpriseanalyticscontentconfig.md: + id: 59e1f7382858 + last_write_checksum: sha1:89d9c459799dc7617905eca34484c0c85bb67933 + pristine_git_object: 0c8967b0bb4209025b0f624a7e34405785e590e2 + docs/models/createinputinputanthropicenterpriseanalyticstype.md: + id: 5231e198247a + last_write_checksum: sha1:2e3ef1da310a0068f425256ae8b31a47743548d7 + pristine_git_object: 98fea80015a5df39910371dcf6c385e9a7ba3797 docs/models/createinputinputappleunifiedlogs.md: id: b38e9fa29997 last_write_checksum: sha1:b7a70815dc71ae1f584e97341b5f6338d65ec382 @@ -996,8 +1036,8 @@ trackedFiles: pristine_git_object: 093264f91bc4ec435a10ecb2f2157a5c7eb77036 docs/models/createinputinputappscope.md: id: afb18990ae93 - last_write_checksum: sha1:5aedd993753cdb95f3b727f96b2ddf4d3191f636 - pristine_git_object: fb534f87e4639a5bed29c5cdaab5e34020d9261b + last_write_checksum: sha1:1c4ca3d4607748e34affc893526a7981107d4ea1 + pristine_git_object: 4a876e13e3145f31315c477833c8e29c15565d78 docs/models/createinputinputappscopefilter.md: id: 5e91c5d661b6 last_write_checksum: sha1:21810be925ca0b747b80f4ea4b559a9b3c67e380 @@ -1010,10 +1050,26 @@ trackedFiles: id: 3bd67402d78b last_write_checksum: sha1:529987a6e2826288406ce673af2560dfe4008eae pristine_git_object: 86445a4cece1a03a68abd790bb87511410d8fe0f + docs/models/createinputinputaquasecurityhec.md: + id: 4fb3fcad606c + last_write_checksum: sha1:8c59028935bbd3a0eb6602eeff28cacc6eba6477 + pristine_git_object: 438dd63e4a7ff07a8e5a6b0abe9d1822ad902943 + docs/models/createinputinputaquasecurityhectype.md: + id: 468653c82ff6 + last_write_checksum: sha1:0780d1c2cb90a1281a17c46635edcc0d1d5967bc + pristine_git_object: 88ee0b24b9d7f79ae1c87609d12f8f55f4a58e9a docs/models/createinputinputazureblob.md: id: ef82229ad226 - last_write_checksum: sha1:fc233d67f02845961b420fb56bfcf8e1b2bf6181 - pristine_git_object: 890b024d9b080e6c29adbff1db6ea141671d87b7 + last_write_checksum: sha1:b03227f1d179977a32097b23d374a98f719856cd + pristine_git_object: 90087aa95e6788d57060d9666a4b4a24de4359d6 + docs/models/createinputinputazurevnetflowlog.md: + id: e24376060535 + last_write_checksum: sha1:45ab9f0787a05d5831ee10d0a3391943b22c3781 + pristine_git_object: 53da380ce1da13488dca6e49a57dd244d82873e9 + docs/models/createinputinputazurevnetflowlogtype.md: + id: e67ac7690f3a + last_write_checksum: sha1:a62a0cef478a8de06b4361cf0932cd838e6effd8 + pristine_git_object: c90643fd0990c4be28c533d0c75528a238cbaf67 docs/models/createinputinputbedrocks3.md: id: ec31667b0e9f last_write_checksum: sha1:2cccfa527d04b7e1b1e1020aa5a268f78297394d @@ -1022,6 +1078,14 @@ trackedFiles: id: 0751986ad993 last_write_checksum: sha1:287d4d0b1323435225922869efe5c760ba7b4f36 pristine_git_object: 1e7cfa90c796e7448f835a4360f6c2fba4f8f87c + docs/models/createinputinputbeyondtrusthec.md: + id: a441234949af + last_write_checksum: sha1:d8de774bbe6dea4060cbf33b707b01b7fb6dcadc + pristine_git_object: 8851f2cbb43a2c08bcf47d55673ab0ab3da5bbef + docs/models/createinputinputbeyondtrusthectype.md: + id: f3d7b9a07615 + last_write_checksum: sha1:f1f36517a3b54150ca8b4b2294fd00bb973d8cf6 + pristine_git_object: 4d819e27b86f8969bed648a9c726ffc32d1fc00b docs/models/createinputinputcloudflarehec.md: id: 01e243a7b106 last_write_checksum: sha1:22ad6d28a4d3afa0b7e5100b30e2c427b47490a8 @@ -1040,8 +1104,8 @@ trackedFiles: pristine_git_object: 50713b6ef622a94668250edb37cffe2747f369ed docs/models/createinputinputconfluentcloud.md: id: 39da2b8099e8 - last_write_checksum: sha1:35678aef02352bffdb930de4218609e7139c0265 - pristine_git_object: 555194e4072688b5ce7fbbc1aced9d5d404fea86 + last_write_checksum: sha1:a04d3cc7ed11792fc05cbff5c1c3bc6df00a7ebf + pristine_git_object: 3f50d322d6b625c9e63e26e239db039be172a52f docs/models/createinputinputcribl.md: id: d2255710816d last_write_checksum: sha1:906383861de9736a158d7e9862d5a3630a713458 @@ -1056,8 +1120,20 @@ trackedFiles: pristine_git_object: 82cb9b7db46ff752889491e17aece9c7c9757c22 docs/models/createinputinputcribllakehttp.md: id: cfcc443089a6 - last_write_checksum: sha1:a3c581ed824f3aff8748b37166a538d0873ac3a5 - pristine_git_object: feeee5769f6171456862e06bc2983f20b46d1540 + last_write_checksum: sha1:6b04b386b53d54d174ab4c96f8d2e3d71a11e223 + pristine_git_object: 8e0f1eb310720cd9e8b1df6b2faa7046cb642f14 + docs/models/createinputinputcribllakehttpauthtokensext.md: + id: 29f9690e937c + last_write_checksum: sha1:206fc8d85c72c091f195b08b302b46797619ad1f + pristine_git_object: 6030783fed0e67de53ec2ff9156c3c82b73a761c + docs/models/createinputinputcribllakehttpinputhttpauthtokensextitemstype.md: + id: 637200e83727 + last_write_checksum: sha1:2cc1c913ae44e196f8831f6bf6f913fd5e4427ee + pristine_git_object: 0c1eb7ce4358f34c9f28b3115f6fd8bfd1faf224 + docs/models/createinputinputcribllakehttpinputhttpauthtypesecretconstraint.md: + id: cc2128d37e87 + last_write_checksum: sha1:14d5f013d8f3bd9c9f1fb014c8ad2370084de018 + pristine_git_object: 57bf5bdca277be619ce929e72e094243515e7945 docs/models/createinputinputcribllakehttptype.md: id: 8efbf9c4929d last_write_checksum: sha1:4ff8c71043beb1d38dbc200888ce15302f6c644e @@ -1144,16 +1220,12 @@ trackedFiles: pristine_git_object: 350b3e999a230d24fbcbfce2a24e022e57f8cd17 docs/models/createinputinputeventhub.md: id: 519e2cf82f1b - last_write_checksum: sha1:54ecb6d12d780ecd8a700b6455a39d03f1090e33 - pristine_git_object: 2e573bff26c8ae576860e16038ca4d241b313d77 + last_write_checksum: sha1:df1455db4163f642e670a62cc77be5ca66b1d025 + pristine_git_object: 4760067ad3fc1418047c65085d85e4c20baef26d docs/models/createinputinputeventhubamqp.md: id: 1d85feb8c208 - last_write_checksum: sha1:ae0e9f8f0f36f0af2e4cb75193cd49caaf1cd610 - pristine_git_object: 47cddb15e58fd5a6dfc1cc799fda3738cbc26b95 - docs/models/createinputinputeventhubamqpauthenticationmethod.md: - id: b576151b5aca - last_write_checksum: sha1:1c178e0eb58813c1d9765b33c2bdf5d9ab994efa - pristine_git_object: d23a7de725f8f97e52571985b9e10a7a9fcca372 + last_write_checksum: sha1:4f5a5e59e459d025595c0efbb65bdcf89be2d932 + pristine_git_object: 5aee9ca91e4932ae3b6c1a6e6d2bb5949c2e72ac docs/models/createinputinputeventhubamqptype.md: id: 595d51d0dd3b last_write_checksum: sha1:1f35823a26aa8ef7b233351bb37d8763a363694a @@ -1164,16 +1236,32 @@ trackedFiles: pristine_git_object: 662d0dffe041e54130a7cb458827f91453446c62 docs/models/createinputinputexec.md: id: ac1fcdf1f5bd - last_write_checksum: sha1:53212346d8b65ba5dae0ecd9c90b11c434e14f5e - pristine_git_object: 01a03d19987afea779a4ae9a087f18424a343713 + last_write_checksum: sha1:7271274a2005aec552a483cda2c5ca5c8497ad4a + pristine_git_object: 89cfe74cb32c860a03dc9afa1c7bd1e46facc34c docs/models/createinputinputexectype.md: id: 085784ab0a61 last_write_checksum: sha1:8a3b9aefa731b65675b33ab7320a54d59c513378 pristine_git_object: 450e1665f328ce588567750becab8bfd5750a6d7 + docs/models/createinputinputextrahoprevealx360.md: + id: c60e17f4d528 + last_write_checksum: sha1:9e92ebb216f935ee842724f3e46f18ee93d659b3 + pristine_git_object: 0966f333fbcc399f8af3e718d22b6f1fc00a100b + docs/models/createinputinputextrahoprevealx360type.md: + id: fea7225f3796 + last_write_checksum: sha1:46868e77fb38b0fd5438fa634cfe029d049733e1 + pristine_git_object: 8d2915ec9638d0f74590184b1901e9b94fd43c3e + docs/models/createinputinputf5bigip.md: + id: 0078a9997c20 + last_write_checksum: sha1:e7798bf223c9632799ccfe45cf9eb07222895f20 + pristine_git_object: 79bd4bfc5e52cda15a0cb458bac60b313979875e + docs/models/createinputinputf5bigiptype.md: + id: 3d7c77185ee9 + last_write_checksum: sha1:ecb7b20a99b15805807fe33dccad276b568771c5 + pristine_git_object: 68da4ec9a4f0fbbd1c4ee1c4519003518212cee6 docs/models/createinputinputfile.md: id: 271e00f549e5 - last_write_checksum: sha1:c3593f0cc2d2f3aacc6ae712491fda89cbfa3666 - pristine_git_object: a57a4e5302830fce7ca7e6852a885244e3072e8c + last_write_checksum: sha1:21959be5fa812ba92008f88daa64ca161497e534 + pristine_git_object: ae6545aea878dc466e7ec4b27cb2cfaf063779c8 docs/models/createinputinputfilemode.md: id: 4fa25cdbe7b0 last_write_checksum: sha1:4adbf997a7a1d600f205a8c1023c7e0127edd2a7 @@ -1190,10 +1278,18 @@ trackedFiles: id: def500d0fade last_write_checksum: sha1:89947fda340ff2f9bed192a906c9a10bde1328b9 pristine_git_object: b79e74d11666e85effee358b20a6048cfc280630 + docs/models/createinputinputgigamonhec.md: + id: b29296f712cc + last_write_checksum: sha1:308965fe1ba1d60104f996da59794a9325c68cd1 + pristine_git_object: e6e30645f52dba6ece8872ce8a922fe3a563e419 + docs/models/createinputinputgigamonhectype.md: + id: 686b5a2f7972 + last_write_checksum: sha1:c6f7502350e83208f087cbeb5a52190acb05ff81 + pristine_git_object: 8a5a7bf4e7fb890bdb6e0922ae2f339efa12fc92 docs/models/createinputinputgooglepubsub.md: id: 275d9108a951 - last_write_checksum: sha1:0ad16cdfe47f86b96e4c742c711cd9f46cf8b18c - pristine_git_object: 04ff733285d1de87cd7c3c43f79272b9ef7b20a8 + last_write_checksum: sha1:cfaed23839276b19188fd7a652b2c0a476421326 + pristine_git_object: 245db017baf09a48428a22e01577d735dd82fcd6 docs/models/createinputinputgrafanagrafana1.md: id: de27560b0e71 last_write_checksum: sha1:65df4b0c3dfeed86b8dd72ee4ddf5763b4ebd690 @@ -1214,14 +1310,62 @@ trackedFiles: id: 6230c3291677 last_write_checksum: sha1:2ff192f0705730ae138a024c9879b8612402fa70 pristine_git_object: cbbb9c829dfc9d5f1957df4d56919a279b3b2479 + docs/models/createinputinputhashicorphcpvaultdedicated.md: + id: 9f83093649d8 + last_write_checksum: sha1:2fb38525ba3afd87e3ca16941e61f150f945928c + pristine_git_object: 0718053df259cd865b6e0fa3a314fdb4e2e89b19 + docs/models/createinputinputhashicorphcpvaultdedicatedtype.md: + id: 96ede166a487 + last_write_checksum: sha1:5b0bdcd5a0731d7649d77d191d00649a411fc429 + pristine_git_object: 3b22586998e7a8e4d9ee98f8fa74ba047401ca74 docs/models/createinputinputhttp.md: id: 3779621ed420 - last_write_checksum: sha1:f7493b3504631830261642d7963aa803f6a97117 - pristine_git_object: f6749990ad181faa6bdba016ad9ee35123433102 + last_write_checksum: sha1:25b643bb0572d1a2a3016a26645e00b796fa2ea8 + pristine_git_object: 8cbf128f6be0dcc1b601de578946ba17c8d0eecd + docs/models/createinputinputhttpauthtokensext.md: + id: 1c8afce2aa27 + last_write_checksum: sha1:ea8629f8fc5ebc5124b3366edf6f678423a1f935 + pristine_git_object: 0885db9e6c01d634c3a4238b251ff28ee239a0be + docs/models/createinputinputhttpauthtokensextitemstypeelasticsearchmetadata.md: + id: 15463a00f36c + last_write_checksum: sha1:69be0b5d4d36624e5d30d27d8ab5806cd3a0d87e + pristine_git_object: f79022fb090e1606754ba5469777940e120e73ce + docs/models/createinputinputhttpauthtokensextitemstypesplunkhecmetadata.md: + id: f4088df63574 + last_write_checksum: sha1:13b13675a23733510e0df00d0de2bbab9acd5416 + pristine_git_object: c82dbffbdb8017cee38a955a2ed2f67f5ed22cbb + docs/models/createinputinputhttpauthtypesecretconstraintelasticsearchmetadata.md: + id: 7bdcd950c6bb + last_write_checksum: sha1:a00afa1042a6815149ad4597e005a3d336a2d078 + pristine_git_object: a88d7a78cc8c98a1eff4c7bfb47a0d353dc2ae77 + docs/models/createinputinputhttpauthtypesecretconstraintsplunkhecmetadata.md: + id: 4c5e22be6842 + last_write_checksum: sha1:8263dd95bd890a22cc8db39766811f0a8b28bebd + pristine_git_object: 1045fed83ac03d2a388b87e53787f3c73fdea0b3 + docs/models/createinputinputhttpinputhttpauthtokensextitemstype.md: + id: 8f8fd26a96fc + last_write_checksum: sha1:2d71eb655133155c71b9958dc2f95f7d92138a7c + pristine_git_object: 90bc13b677fb970afe218f521dfa6a01aa5c80ea + docs/models/createinputinputhttpinputhttpauthtypesecretconstraint.md: + id: e9b2708cbfa9 + last_write_checksum: sha1:d4177a795d64bdb77a2fa1def265b5d0d17775c1 + pristine_git_object: ca9e36711d2266759c49c90688e1eee1bd241d35 docs/models/createinputinputhttpraw.md: id: f16d55346af0 - last_write_checksum: sha1:ac492143b7e7ae33bf817609040f9877a32d8924 - pristine_git_object: 0d65ed48ea3d9f0fdd5a8e625641eaf541580de6 + last_write_checksum: sha1:d23512e73d7a24ebc2b3606725c40b74326f2df8 + pristine_git_object: a43ffc158dd315838d7588afff705ca95394c7c8 + docs/models/createinputinputhttprawauthtokensext.md: + id: "840878136768" + last_write_checksum: sha1:808e7e87c2b7bdf851dd0a531cf881eebcc21dcc + pristine_git_object: b9ea6fe406584b6faf00d1362e45724453eab371 + docs/models/createinputinputhttprawauthtokensextunion.md: + id: 88dbfaadbdb1 + last_write_checksum: sha1:a856c268ff259a23d6dced24ab073d026f245fd6 + pristine_git_object: 3fbfb18178439ea0667e17e4d2d54265eaeafcb3 + docs/models/createinputinputhttprawinputhttpauthtypesecretconstraint.md: + id: 1d69b69068bd + last_write_checksum: sha1:a2808e44a3a3b0edc04d97b37f029c24963fc265 + pristine_git_object: 06e4694ec729140a9de58fdf7ac7d7e769b7a3e2 docs/models/createinputinputhttprawtype.md: id: 6a7cdda90acd last_write_checksum: sha1:0adfef962eb93d141c563108011f06420a96aeab @@ -1232,8 +1376,8 @@ trackedFiles: pristine_git_object: 93ceb8d03035e308a2484ad5b9fe53cf278967d3 docs/models/createinputinputjournalfiles.md: id: 6f5fd60da521 - last_write_checksum: sha1:2388064f2eb7c8a934d30c6fd7278db32f697e43 - pristine_git_object: 83bf9e62678ad614f1798fe7db68efcf5ea82e8d + last_write_checksum: sha1:ce3169aa84c0037333f095188cb285fc15885b6d + pristine_git_object: 11ef6f0cafd94da1a808ae0760285743ee2b9a78 docs/models/createinputinputjournalfilesrule.md: id: e4029c583895 last_write_checksum: sha1:a5a64ef36579d49718c73b50a97f64f8f20bd170 @@ -1244,12 +1388,12 @@ trackedFiles: pristine_git_object: 4927942e102555e8b5567f3fbc9d77e801367f0e docs/models/createinputinputkafka.md: id: bb7280cb324b - last_write_checksum: sha1:435505f4afb1fc01c095b718d2eb6954e4fe61c0 - pristine_git_object: ee09ab470c733afac4e053e2df7b5684a609fb00 + last_write_checksum: sha1:f325d753fd2c9c17efb45379d21ae3cf5f8337e1 + pristine_git_object: d04b8efcb51bf33718e8fbbcbf6aaeba2e0d5f10 docs/models/createinputinputkinesis.md: id: cb4f18b0fd0b - last_write_checksum: sha1:3aae3f724437c81ca1d458a73d6226a210b7e95e - pristine_git_object: 28db67cf10a46e354e38f23685bf09b9a0d76165 + last_write_checksum: sha1:15020b123938466036fd129ec8d3cc7cd4dafff9 + pristine_git_object: 6aecd305491eb9e6ab47541b72eb5f16f103824b docs/models/createinputinputkubeevents.md: id: 47eb0b866fc0 last_write_checksum: sha1:eaccaf58297573887c188b1cf02380087ce72be9 @@ -1298,30 +1442,62 @@ trackedFiles: id: 153581ad9a10 last_write_checksum: sha1:a510c366cee1472e5131d0bc2e1e9b01f2e4780c pristine_git_object: 97eeac16f195ac86fb147c591f6e4679c1c1d161 + docs/models/createinputinputmicrosoftcopilot.md: + id: 19c797930765 + last_write_checksum: sha1:32211c1932e22ed4b857574fdd419d6e13a757c9 + pristine_git_object: d818d36497f222fb1443d7c4ef325c0a9a7446a1 + docs/models/createinputinputmicrosoftcopilotauthenticationmethod.md: + id: 6b2b9f3ebe3b + last_write_checksum: sha1:0849bb85f4c5c1de9e006c35fa43549e64719e21 + pristine_git_object: 7e3db54c9112e8b5e8f6804e9e94dcf88af71d34 + docs/models/createinputinputmicrosoftcopilotmanagestate.md: + id: 00fcbffc0a73 + last_write_checksum: sha1:a2190be3bf28bef60180dd65006c8afb10c7f57b + pristine_git_object: b5d68f8b87b19f866106fdcfa4e940148d92b56b + docs/models/createinputinputmicrosoftcopilotsubscriptionplan.md: + id: 49d3939ceb9b + last_write_checksum: sha1:11f77a4c686d3abcf87d30318b3702282fecf61a + pristine_git_object: e9db556615b77cce538f9ac522cd740c178bc2c9 + docs/models/createinputinputmicrosoftcopilottype.md: + id: ba1d31ad749b + last_write_checksum: sha1:609377baf6926464d45a6b4d51707869eed12db0 + pristine_git_object: 07edda4deb448fd44887a5db41216cb20630595c docs/models/createinputinputmicrosoftgraph.md: id: 4bd82657dc90 - last_write_checksum: sha1:e03fb5c2d5c2e025377847d62d7227d07665abaf - pristine_git_object: 330f56c76896861a5eae085060277a2f693209d1 + last_write_checksum: sha1:974d9ec864e2d439350c1b910dd800c891d71afc + pristine_git_object: 5cc4ea551dee29eed7c4d4ae8664aeddb5805dd4 docs/models/createinputinputmicrosoftgraphauthenticationmethod.md: id: 7db581100e4a last_write_checksum: sha1:c24f665fe7255031a19fc019639c04264869fb71 pristine_git_object: 7851e3fffe4d5c3addac4fe2ddee8adb9d294b84 + docs/models/createinputinputmicrosoftgraphsubscriptionplan.md: + id: 7e8748c8374a + last_write_checksum: sha1:59b3f2519a73cbf90dd5bfaee41cc551c3516625 + pristine_git_object: 17310d0752f23bb03bef3e2cea0912697d0ae517 docs/models/createinputinputmicrosoftgraphtype.md: id: ba3a9b8cdd3b last_write_checksum: sha1:821fe66bf6fef704b84255a5f75242a1a6178ff2 pristine_git_object: 32235fa43bcf2fd147b110d5f0f52fdede15368e + docs/models/createinputinputmimecasthec.md: + id: 888cd56bedbb + last_write_checksum: sha1:85bdd675bf92904cccba84d92bb009deac1fe40c + pristine_git_object: 115d4cb409bc9e425ea07dbfed3e939dd4bac00d + docs/models/createinputinputmimecasthectype.md: + id: 6fe136c9d436 + last_write_checksum: sha1:70845d884f0d56396620c27ad39313b35c2a3b21 + pristine_git_object: 39a6834bf137073a1d64a484bdd8115e7b63c9d9 docs/models/createinputinputmodeldriventelemetry.md: id: 51f28f0fab6b - last_write_checksum: sha1:168bc1bf4e08852fbef647dc9bea743912012797 - pristine_git_object: 826a5f041c2d02db588eeb513f3da9500b821de2 + last_write_checksum: sha1:6778814a5988598796816c746df163fbb278e909 + pristine_git_object: 5ad88391a3620688adb2ae54858c9c5848af0f23 docs/models/createinputinputmodeldriventelemetrytype.md: id: 14a4490ea656 last_write_checksum: sha1:d940df2c63c9322a36efa76043216282e3a4d72f pristine_git_object: 9eee1369ae26e99e119c565fcdffe35402cc19af docs/models/createinputinputmsk.md: id: 15adcb66d053 - last_write_checksum: sha1:d838321ae4c93e3090828596605fda8e7e50f66d - pristine_git_object: 71037b364a843dcc003783573305e4911a7a8567 + last_write_checksum: sha1:cdc267347c217316ad034c826cfa24495d091dc9 + pristine_git_object: 4c49e342577f73e3ca60e488147c0a119545528e docs/models/createinputinputnetflow.md: id: 1ca2f9008285 last_write_checksum: sha1:00ef993f5b3a07f412e88853e94003f4edf58061 @@ -1392,8 +1568,8 @@ trackedFiles: pristine_git_object: 7c378617510c9df0aa96a15d9c1a02669fec95dd docs/models/createinputinputopenaicontentconfig.md: id: 09dfc5007a76 - last_write_checksum: sha1:c546d6ef3bdb764375c27147c6335d649db3ee88 - pristine_git_object: 7d668071c8cf07096869bfeb08d0677627d3e328 + last_write_checksum: sha1:719b5df688740b1fb0cf9130bae05c22be8c69c2 + pristine_git_object: 5395c97bb901da644e729775112998b71fe461bd docs/models/createinputinputopenailoglevel.md: id: f03aa2f8c4d4 last_write_checksum: sha1:e0c381a8f67fd460af101e121fbf2f5a2b5d1b22 @@ -1408,8 +1584,8 @@ trackedFiles: pristine_git_object: 2027997ee4bd2144aebdb79c959d93caf18c50d0 docs/models/createinputinputopentelemetry.md: id: 7a0edfa30cc3 - last_write_checksum: sha1:7113602efe20c5ce2588a12876b635a6f84c46b7 - pristine_git_object: a666ab6e5913f90a6a3de16e7ddb5da8f0164aa8 + last_write_checksum: sha1:7472dc406d237df7abc1785c94d8d7120253783b + pristine_git_object: 6709994bb520a13e03e9ccd810b6e1f53885822a docs/models/createinputinputopentelemetryauthenticationtype.md: id: d351d92d0dd7 last_write_checksum: sha1:0f90a08768f56519d7d6b789585c7c2c02c9fc45 @@ -1418,6 +1594,14 @@ trackedFiles: id: bd094d4a41be last_write_checksum: sha1:7d4a7b0061ad747b301a1b810b22589bc35c36fe pristine_git_object: 0f8c770dd455260633be0dac12dfa1755ad76677 + docs/models/createinputinputpingidentitypingone.md: + id: 126fad118a87 + last_write_checksum: sha1:4a72f54d44055c2c5bd2678fcd9adc674c9093a2 + pristine_git_object: a32c295da7b520ae69a0ca3d04dfedbf874d7425 + docs/models/createinputinputpingidentitypingonetype.md: + id: 7e68db968128 + last_write_checksum: sha1:b5ed8a20a5d01dfd965ba409b14914a1888ef23f + pristine_git_object: 77e73d8755c5b15fdaf85577a487fba5002d68ee docs/models/createinputinputprometheus.md: id: 646e34e21d66 last_write_checksum: sha1:ee07e07a33aab68d1aca9e1bee6ee91739917bc6 @@ -1434,18 +1618,26 @@ trackedFiles: id: 8c88c51c3ac8 last_write_checksum: sha1:094ef466cc7a810b102a66d94854fd07739ee38e pristine_git_object: b54ca871b735246d3c269f2fce0a0430edf47486 + docs/models/createinputinputproofpointpod.md: + id: ec86fd27583b + last_write_checksum: sha1:4d6a85e623943f2830b529a9eed7dd00763b9690 + pristine_git_object: 08ca43e2d61e400c080b62d7e28ff3410b936a9a + docs/models/createinputinputproofpointpodtype.md: + id: b6e5735b0354 + last_write_checksum: sha1:86cdd8fcf92df5d52ba57af2c2dbe7d4b81e5a3c + pristine_git_object: 4b5e75d1d979696dc8fc6a626a00110d5a0d0cec docs/models/createinputinputrawudp.md: id: 59725c2a1d3c - last_write_checksum: sha1:5ba3a0e58ce98f015ba6695d4554297ee437291e - pristine_git_object: ee1d411a3c9f72519d1bb96665f80270501cf427 + last_write_checksum: sha1:f3e46f39e601ea0dad855a57a9791c00f495e8f3 + pristine_git_object: 97245d3285d80f331aaa02f430e479b46ac5792e docs/models/createinputinputrawudptype.md: id: fffb32a56feb last_write_checksum: sha1:a896e3d20234dead1621527a6b624fc275c62692 pristine_git_object: 62e1a32aecfd7465a568bd50a20dd51192761dbe docs/models/createinputinputs3.md: id: 29538a4d9531 - last_write_checksum: sha1:f00dcd98aa2dd8a426aadafa454a8a9cf36edfc3 - pristine_git_object: 1922be2b63adcacc89091784ffeb34b91f52ff90 + last_write_checksum: sha1:c579e560c0a54a2fdbf636a22269091b10840b71 + pristine_git_object: 446e81cf827aa108df789578f63479f9908738f9 docs/models/createinputinputs3inventory.md: id: 035e16b2ba0d last_write_checksum: sha1:6540724a91bdefb8a8508ae9834ace888f137dbe @@ -1454,6 +1646,14 @@ trackedFiles: id: 6bee335372db last_write_checksum: sha1:a32d6298b88143d9d472e8f1b8d7dec659c89ba7 pristine_git_object: fe2480d71bc4a03896ca5031dfd056f93b8b8fe1 + docs/models/createinputinputsailpointhec.md: + id: f223fdcf267b + last_write_checksum: sha1:81c0df3d6626bd94945bcbe5f6fb483ae85a596d + pristine_git_object: fd5742dee57c0c1f8760d830006e6bc7890a85ef + docs/models/createinputinputsailpointhectype.md: + id: 3b521d06f938 + last_write_checksum: sha1:081dbbdd6b74a7e3394462ce60ab4ac3d6418d77 + pristine_git_object: 4700fad77ff8cf73ab59206bfe999bbecb5aa59a docs/models/createinputinputsecuritylake.md: id: adfd47f46e98 last_write_checksum: sha1:b93456b1d450d4acff074fa3ab42b0123a22ad4c @@ -1480,20 +1680,20 @@ trackedFiles: pristine_git_object: 06c28b4c1b57f4c72f3e0b9ca0f7dd67837b2fca docs/models/createinputinputsplunk.md: id: 9e82761d7180 - last_write_checksum: sha1:fbbed4110c645fb16151da710b1832bfa2d50503 - pristine_git_object: bd3c2c91831be9226392b04264b1d6492f6efcd3 + last_write_checksum: sha1:0f0ffe887df863f9494c5ffd9c1f5a5481478494 + pristine_git_object: d4dc4081906d042e49451405dda9868fa9d885ad docs/models/createinputinputsplunkauthtoken.md: id: 9b6ec14b5ef2 - last_write_checksum: sha1:af8f6f189f7f8c0a33afe96735ffffcc0e12390b - pristine_git_object: 8fa8a7505371834b69806173a2f0e515a7f812d5 + last_write_checksum: sha1:06359d724692c9a237c44c906d0142db42f161fd + pristine_git_object: 11c3def7bb3175197df9b7d63b7370b949429c20 docs/models/createinputinputsplunkhec.md: id: 68a8c70d44e4 - last_write_checksum: sha1:257e19c20189f313e215c476671272c8c81e650d - pristine_git_object: ca29f7187001cb02c3e76fa61faed99a97a0866c + last_write_checksum: sha1:782288214a66682df071454dbd8a91fd61f28703 + pristine_git_object: b4fff5f47f2c429d9a16b6bbc0cf613b5c1a90f0 docs/models/createinputinputsplunkhecauthtoken.md: id: 16cc8e54c2c3 - last_write_checksum: sha1:8ae9f5246dc15a5a5447cfb06dffa8f2d5ecd893 - pristine_git_object: 3a8ec9010c0863e96de7133523b95d9a17b5ba5a + last_write_checksum: sha1:16d0f8b7925f9afd8929992fe8dc2b8be8f22322 + pristine_git_object: f384937c6664be858078aa6e16410cc6e2e1bacf docs/models/createinputinputsplunkhectype.md: id: 7a71da6c15bd last_write_checksum: sha1:96f150287c501b2bd5874c076c2cc359e8005a24 @@ -1516,8 +1716,8 @@ trackedFiles: pristine_git_object: 3f25813a381b6c4f54e6d0906123b525111f1c82 docs/models/createinputinputsqs.md: id: 4588e475bcac - last_write_checksum: sha1:8769774ff5988ba8d123f69cabe5f8265f891f0f - pristine_git_object: 321f0aa7fb52ebd083b53257facc3c699dfa4319 + last_write_checksum: sha1:8f4582d1a0c493ef1cf91ce07df5d753bfc6eb95 + pristine_git_object: 496a3c303c7d454e80b6fcdc6fff69a8004be247 docs/models/createinputinputsysdighec.md: id: b93bb78b500b last_write_checksum: sha1:2f7cb2955edff19951357e3f85f00795c3cb943b @@ -1528,12 +1728,12 @@ trackedFiles: pristine_git_object: 25c495701fb10f6a74cb56046e66405d95807f46 docs/models/createinputinputsyslogsyslog1.md: id: 2598e5bd5369 - last_write_checksum: sha1:929b8477738e1fecc08dfc92bd2ca05d60c20584 - pristine_git_object: ae3a6514ee91150e22629529a01dd5d9951dfa86 + last_write_checksum: sha1:bc9b22c54fd601e70d1494133a8a96479c54b084 + pristine_git_object: 814a6d313e7ceed1697c1ac25bd9c3cc1ce8c254 docs/models/createinputinputsyslogsyslog2.md: id: 036fa6894ba5 - last_write_checksum: sha1:799a5ecb607e251120c86197309d03240f64302e - pristine_git_object: 5e4e093d888590edb05984db8a8179551cd853b0 + last_write_checksum: sha1:dd1055bb447894d743af40bec71448d2a42112ff + pristine_git_object: afa39d2925b8e5d39044af3ed4c39009f745437a docs/models/createinputinputsyslogunion.md: id: 9f0feabace86 last_write_checksum: sha1:7ad6c5db379c3e13d96ebecf0137c5f65ce41056 @@ -1616,16 +1816,32 @@ trackedFiles: pristine_git_object: 1b12bb2956db77d6a63594832aaf36d02a87304e docs/models/createinputinputtcp.md: id: ee9df6e10a37 - last_write_checksum: sha1:37496398721191436b6e657547282b1d00bb2c94 - pristine_git_object: c5f4a2c6ca120835efb675aa73985bb3ff378acb + last_write_checksum: sha1:bde1d7918a782646410a15f0d66573783da3e9e0 + pristine_git_object: 04b57c54385fd8aac6d3fa9899275b2ce4828195 docs/models/createinputinputtcpjson.md: id: b1b2c5d217a9 - last_write_checksum: sha1:a2ae9f36bd05fcb355d0102662474afa5c6758ee - pristine_git_object: 66d6626c1e8d6faad7625b461267694be76fecd8 + last_write_checksum: sha1:f77181cb692f50f061f68a3107066dd9f4a30f83 + pristine_git_object: 8b5708ebb70a76462d780b060e484d08c4490f46 docs/models/createinputinputtcptype.md: id: "997068583e84" last_write_checksum: sha1:eb4ac12f243863653f1ce54e00dfefdb78f64a27 pristine_git_object: 4f7ed98cf1472720b0819261980cf7717f7755f8 + docs/models/createinputinputtrellixhec.md: + id: a1416d14288a + last_write_checksum: sha1:83743c19ba7c45a8003cca54d3b163727943449e + pristine_git_object: 021ca464e1fa8384142c7ef138d43d363540e616 + docs/models/createinputinputtrellixhectype.md: + id: 71138d65a9fa + last_write_checksum: sha1:51040cf6c71fdfd6033d9dd46cd96675edf40411 + pristine_git_object: 5135d9d458e5f35af3cafdd395474d6248fd9cbd + docs/models/createinputinputtrendmicrovisionone.md: + id: 9ddae7219b02 + last_write_checksum: sha1:a74c66b0a5e14d0fec9f58559e8279127380c97d + pristine_git_object: 563b6107ad480fc6fc22e4d02f6f5f27fe4a3813 + docs/models/createinputinputtrendmicrovisiononetype.md: + id: d3791db4baf7 + last_write_checksum: sha1:6cf58d2ba260d70b4cb787b9abc344f0cda54540 + pristine_git_object: 6e566129471ec7aaf7a7f1ed3452fe229799631e docs/models/createinputinputupwindhec.md: id: b6563d547ce0 last_write_checksum: sha1:10717a5bcdc89c150254aae83a8c564da1c88645 @@ -1634,14 +1850,22 @@ trackedFiles: id: 51c893115ff9 last_write_checksum: sha1:70f35c27d1c76c6faf79b366b7a79c57c694bb20 pristine_git_object: 7c8d90f8dd1a1f4879e045f59340f2c797b24447 + docs/models/createinputinputvectraaihec.md: + id: 51958b159b4f + last_write_checksum: sha1:3f73e917e7202aa1abdcda54838f80012d2582a7 + pristine_git_object: 16eea5d7c77d29d52b1b3d308f02bce95b7c3742 + docs/models/createinputinputvectraaihectype.md: + id: fecfb916a309 + last_write_checksum: sha1:3d69e503c239adee746d7ead8d8d1d9996b58a6f + pristine_git_object: 0a17ce51af043b82d9b429dd540c8957befd4372 docs/models/createinputinputwef.md: id: 892051f2da13 last_write_checksum: sha1:423f0fe6e5c57993438b884cc403ac1c76b0ff68 pristine_git_object: 35cc31f01cd10a9b5fde05b793fc0e67fea096d2 docs/models/createinputinputwefauthenticationmethod.md: id: c71bf65a5975 - last_write_checksum: sha1:7bb23b604b7c85829e8ddd4226c3b1e0c6074566 - pristine_git_object: 28cd8d4d91647eaf2c9485f9ec7cb6ed7a9ce725 + last_write_checksum: sha1:2717b1de4cfa32892f62a62a03e6fbd049d7a57b + pristine_git_object: 375e4ec7be69bb2c5c564d82827d4322fa1359e5 docs/models/createinputinputweftype.md: id: 16b056bc38d8 last_write_checksum: sha1:1fc3b396c1f1c94e4bccdb77c201a84473373886 @@ -1708,8 +1932,8 @@ trackedFiles: pristine_git_object: 0f2bce9c859205f90047bcc2521d760f0f547a84 docs/models/createinputinputwineventlogs.md: id: a2e8e887fa70 - last_write_checksum: sha1:bebad83ba7973619efd97edd5532f0d9f5f1882a - pristine_git_object: 61e6a59098be5cc3cf8562f10e6a48f576f1fbb2 + last_write_checksum: sha1:4685f898900c917c3df6287402519920ea6977b7 + pristine_git_object: a7c2b25b868d67d2022b9c2163cb587a9f186b03 docs/models/createinputinputwineventlogsreadmode.md: id: 5ef3075b666a last_write_checksum: sha1:a6febe8c1f45ac939568bb734d12352950132a82 @@ -1736,8 +1960,20 @@ trackedFiles: pristine_git_object: ceb15826d3d721241fafed6d17c542a365ef62f0 docs/models/createinputinputwizwebhook.md: id: 021e73e8970d - last_write_checksum: sha1:7ed6e5dea98cf18181e5b15968413805d4e700da - pristine_git_object: e0daf129950a6116cad444a9f87cfd554dbc3b83 + last_write_checksum: sha1:307a9a1976ba27855dffcd7986b16908f26ba089 + pristine_git_object: 961fbf9fd33c61b5866a3ffe97ada2d47b6a5426 + docs/models/createinputinputwizwebhookauthtokensext1.md: + id: 70afb68109e2 + last_write_checksum: sha1:998a7af8bc3f95d7eb7b95361091905e0126331d + pristine_git_object: 2dd717bb90bcdab54249e3c0a0bab890543e9719 + docs/models/createinputinputwizwebhookauthtokensext2.md: + id: eb89a2cd33ca + last_write_checksum: sha1:f6afd7b9d72dc1cc91e2a76e3dc9243405adf6c2 + pristine_git_object: f6d7235a5839fca625237a4a74b3d6bd81f36327 + docs/models/createinputinputwizwebhookauthtokensextunion.md: + id: 7fe165355aa0 + last_write_checksum: sha1:d73743cb6bbf37a54e1522c0ab8c0eb8e5b842f1 + pristine_git_object: 35c8ce68c7635879e5c06a9f7abd3dbd60729af7 docs/models/createinputinputwizwebhooktype.md: id: a7788a45d0c5 last_write_checksum: sha1:dfcac3d999cca4f0713bcf8ca18f2ce622deac60 @@ -1748,8 +1984,8 @@ trackedFiles: pristine_git_object: 50f77d54f46afe4114c7c2624b3c48f0f6c2326c docs/models/createinputinputzscalerhecauthtoken.md: id: "901268486250" - last_write_checksum: sha1:6e89486401458e72a91a67319aecef2df3600e5e - pristine_git_object: a9d6774ae561cec1e5a399d979bb3e2357582463 + last_write_checksum: sha1:0845ae3fda08b4dcf3534dac08a7c9dc26751376 + pristine_git_object: d2af4092f7fbfbbc88d608fcab99f29278aca7e0 docs/models/createinputinputzscalerhectype.md: id: a0d32295bed4 last_write_checksum: sha1:b98a52f5a35140304f3cc13b94e9ce75063ad4ee @@ -1816,16 +2052,16 @@ trackedFiles: pristine_git_object: 7ac06e449d3ac215bc5e7a76ca2c33bbbce84d4b docs/models/createinputprojectdetails.md: id: 1c64289fccbe - last_write_checksum: sha1:472e440b3e8700e05d73dfe96a0d4e5a12ef277a - pristine_git_object: bc93bbf9a1f9dd792d54dacd3d1bd7f8f6a1a82f + last_write_checksum: sha1:52ad2a7c88e71ac102c45ff8f18c7fcd376a0339 + pristine_git_object: 55d53a60952b1cb42df6fb5fb1f137b726c939d3 docs/models/createinputprojectdetailsmanagestate.md: id: ee715b952ed2 last_write_checksum: sha1:781f2a6294b719c8bf760179402cb2d8538fda0a pristine_git_object: e5597d4ae2176559217f52e62f2c4e928af95bac docs/models/createinputprojects.md: id: 86135e4fc24c - last_write_checksum: sha1:9cac9e38e3146106fa66ce62b62b9cebe387c631 - pristine_git_object: 7b4f1c3e2a21709dc704b26c0628981e2dfbb3ec + last_write_checksum: sha1:99fc00f4c0fb293225f23182deb7039636b4e386 + pristine_git_object: 176c0f6ee97537bd86bc9ddfcf8016765f9aca76 docs/models/createinputprojectsmanagestate.md: id: 53d64ff9ed4e last_write_checksum: sha1:b843fc3a255dc5de8ae243d6a8821988e346e8dd @@ -1858,6 +2094,10 @@ trackedFiles: id: 23d72569987e last_write_checksum: sha1:a100866fa471f85e65e922252e7ceb50c122b0ae pristine_git_object: 59aedc3a3cd2911a5471b782563eb12994c00c9e + docs/models/createinputretryrules.md: + id: f2b150c3d11e + last_write_checksum: sha1:0fc1f3acfffeb3601fba5dc85811ad92b0e31bf0 + pristine_git_object: dc194daa67054c1e3c546e221c25a4374275c3b4 docs/models/createinputroutes.md: id: 224fe393413f last_write_checksum: sha1:00613a56bfddd79e8c7a7a4517259da7b23a35bf @@ -1894,26 +2134,18 @@ trackedFiles: id: f8dbf8bcc06d last_write_checksum: sha1:deb1848065af6283e6bc10f6a417f1fb6aee8299 pristine_git_object: 1ee63b81f7efb04fcb4b7d4532dcf583c50865e2 - docs/models/createinputsplunkhecmetadata.md: - id: 0f1dabf1d164 - last_write_checksum: sha1:e1761932ce764a16961b9c7d1a5abdb5e6ade9eb - pristine_git_object: 941289e5cc7cb22756c49b1fd4726c469f09eece docs/models/createinputsubscription.md: id: a1afeb045832 last_write_checksum: sha1:cef208864db3a6ab7c86d9782fbe129302798ea5 pristine_git_object: dea2e540a1ac5d64344a68068d41722aece1137b - docs/models/createinputsubscriptionplan.md: - id: dab8a9fedbee - last_write_checksum: sha1:c4dfbf2899834e47d752f8f459fb72d156f38f33 - pristine_git_object: af8529cf70bc261e516c11fa9f21ed9e2b7ae46e docs/models/createinputsystembypackaccounttype.md: id: 471f065afbd3 last_write_checksum: sha1:d1bd2a70be1e2e22fbc6e0622e81be6e1af3ba9a pristine_git_object: e7f47e02d62971798bbf242460d157b95cacc0a8 docs/models/createinputsystembypackactivities.md: id: 4faddd51081f - last_write_checksum: sha1:c2becc3dd00ea0be8f9e32b7881519d9da5e33fa - pristine_git_object: cb25a66e67d8ba833385b240c11b0e8f12a44246 + last_write_checksum: sha1:5c95305a6ca6c77a749e07e2dfdf1de4299c77b2 + pristine_git_object: 503999545d4312efc26d76e40172460dd8e9058b docs/models/createinputsystembypackactivitiesmanagestate.md: id: 061a36dac330 last_write_checksum: sha1:ccbcf920572403ecb21e8d927211c1b267e7e848 @@ -1940,36 +2172,40 @@ trackedFiles: pristine_git_object: bf557a539b8ce503cbb707253ba2726a61ea4d01 docs/models/createinputsystembypackauthmethodsext.md: id: fb6e2a755b46 - last_write_checksum: sha1:0303a3463b1e05754fc4448cf647efe4d0233702 - pristine_git_object: f0f1cbbe840891c253ce857c7c46dd78f9e8a996 + last_write_checksum: sha1:3afab3d77ae18be475f907384b030a17c3ecfb81 + pristine_git_object: 76bd616eb240ac35821d9b26465eb8fcad45f8b8 docs/models/createinputsystembypackauthmethodsextauthenticationtype.md: id: 613d6476e1fc - last_write_checksum: sha1:34aec0411ad07c0a3f058018fe830d8f380ecd62 - pristine_git_object: c238a0f89a71729e4ef1a6c23160f7963c2aa5a7 - docs/models/createinputsystembypackauthtokensext.md: - id: d97bbd111275 - last_write_checksum: sha1:2108d2f2f9b71ed49749690fc6665390dd68537c - pristine_git_object: 6bcee79ba1cb4a64ff9b369096527b23a6ac52fd + last_write_checksum: sha1:f083181795c88e7d030f321902665f192c612931 + pristine_git_object: 3970f01c24bebd849625d9f5f5d890762793c9a7 docs/models/createinputsystembypackazureblobstorage.md: id: ad62de702664 - last_write_checksum: sha1:b81460ef22b04e07332d0bf8ef4ba5fd1f483daa - pristine_git_object: 91e13f6686646c3ca80869df4fb1b33690b85cf5 + last_write_checksum: sha1:2b385eed2e301ed14b6e92fe956f9c00b06348dc + pristine_git_object: 72ee934f67072dbbd27e9ecce569c7d225aab333 + docs/models/createinputsystembypackbucketwidth.md: + id: de94a6129d63 + last_write_checksum: sha1:1a8a1851c6396ef65353a1190b5c18f8910fbeed + pristine_git_object: 5515b8df15c3a23b6d2e4266c86e8135debd7bbf docs/models/createinputsystembypackcertificate.md: id: ee50fc08c7b2 last_write_checksum: sha1:a270fc337982207415b67075b110b98ce73d42b8 pristine_git_object: d71f3f6f5538638217a93ea141d11a0acb336021 + docs/models/createinputsystembypackcertoptions.md: + id: 5d5aa2120d45 + last_write_checksum: sha1:06ef78d161776cd343b33cc5a95189976d13672e + pristine_git_object: 6d3cdc4699c077f8b61b1f3c9b9f53a69f3e7d36 docs/models/createinputsystembypackchatmessages.md: id: 5d35e2a42f0f - last_write_checksum: sha1:146c5d4fb91d875712846ad2a78bfeaa1859a5c6 - pristine_git_object: 86669a4f4fcf2ae1712c87c57f332feb5fdfd148 + last_write_checksum: sha1:39933d9e459a35c3d42bfe366005d0570e41b878 + pristine_git_object: ae1479e523542e1e8e393aa03eb2e12561ffa1c0 docs/models/createinputsystembypackchatmessagesmanagestate.md: id: 878cdf2b8a8f last_write_checksum: sha1:15399f3f5e00946247c97b09a3bbcdc988d36092 pristine_git_object: 9378f00da65ac685a83af0197377c7eb115bad8d docs/models/createinputsystembypackchats.md: id: 269b9ec741a8 - last_write_checksum: sha1:d7ee333f9272ebf76d4f588019d499610f291851 - pristine_git_object: 53c4a7ee3c9573d2099bde0f4a2b5f77be5d5131 + last_write_checksum: sha1:7d0384ca119ba2d0a81002445597e114c7e8e424 + pristine_git_object: 1130e0a8b347c8e6ada6a4b75a34ebcef5d8dc98 docs/models/createinputsystembypackchatsmanagestate.md: id: c643fd8e095f last_write_checksum: sha1:4676274c9f2e0b528352d6b9526fda2362323749 @@ -1994,6 +2230,10 @@ trackedFiles: id: 68edaf6db3cb last_write_checksum: sha1:379e24692838573c1cc3900f93023aa808d8d386 pristine_git_object: dc3572421989be598876283deb7f7cb9940849de + docs/models/createinputsystembypackcontenttype.md: + id: b92e565260f7 + last_write_checksum: sha1:73a5b236a0e244ca6cc83d3710b35df3d8759bd6 + pristine_git_object: 5d0b64d4a84b913617d6e9d894ddfb0b4af4a7aa docs/models/createinputsystembypackdisksandfilesystems.md: id: 8c72a12a5e29 last_write_checksum: sha1:3bb99e96bf95b9dec8f7df386320889306f1d890 @@ -2002,10 +2242,6 @@ trackedFiles: id: 80df6c8d78df last_write_checksum: sha1:0655f6ad31f501a825218102879a6f48250749af pristine_git_object: 12c0880167f26c7f5df5412b4d3b0882aa5ab72f - docs/models/createinputsystembypackelasticsearchmetadata.md: - id: 13e272317c74 - last_write_checksum: sha1:55ff430821860ba512742ddacd90d961e991b962 - pristine_git_object: b7362d9af21de32107b7030cf6959cefb9374c3c docs/models/createinputsystembypackendpointheader.md: id: 944a865e6caa last_write_checksum: sha1:e8b930435e655e4720897a2852dc0bf9e43ce083 @@ -2018,6 +2254,10 @@ trackedFiles: id: 49906393f808 last_write_checksum: sha1:bc7bc9d640e22a094bf14b3e2b4202a7d6c5201a pristine_git_object: c1f78f86b6b7a445631fcd2dfc04c90f0924ee30 + docs/models/createinputsystembypackfeedtype.md: + id: 1550d8197a4f + last_write_checksum: sha1:31425ecf3c3874df15ef2a77ca667da5705d7699 + pristine_git_object: f1e6f50180ea540e4c7fbe52fe06d6c98596b9a2 docs/models/createinputsystembypackfirewall.md: id: 613d99853464 last_write_checksum: sha1:0bc0c3ff2c425b539898b3fa2ca25b038226964c @@ -2030,6 +2270,10 @@ trackedFiles: id: 1abbbf4461e2 last_write_checksum: sha1:80bc0fe33d9cb626b7ed0e33e2f5144ea98d8d03 pristine_git_object: e29e07432f46e1ffc3e9e3a4af93801fbe958d38 + docs/models/createinputsystembypackgroupby.md: + id: b91c2a4d0298 + last_write_checksum: sha1:0ec01ec99cc6473bd462370ea0a0c122c00e9bfd + pristine_git_object: 76ab26746e6a7e23189baf4298c1dba0c3cb3abc docs/models/createinputsystembypackgroups.md: id: 7a26970416ae last_write_checksum: sha1:e6e35c1ead2e50f76646bea510fe0be938cbcea1 @@ -2044,8 +2288,16 @@ trackedFiles: pristine_git_object: e69ba09b7b946f7da70021fdc63c9aa5380b25fc docs/models/createinputsystembypackinput.md: id: fb9e6b8d1ea9 - last_write_checksum: sha1:2986e2d0582cf12e92bcf6af13927052a08517af - pristine_git_object: e3af634d846cf505dcd71e1618dbc25df8717892 + last_write_checksum: sha1:02251767698142f90ddee03d94ba56de8563f837 + pristine_git_object: ce8858d47f409adc55885dcabde7c82a5104dc18 + docs/models/createinputsystembypackinputakamaihec.md: + id: e195f78cd294 + last_write_checksum: sha1:4a6097d6c0a33562b2bdf2703be7aa4e214d509c + pristine_git_object: 8c51690a233c04bbcc96963bf7410caec3818cb1 + docs/models/createinputsystembypackinputakamaihectype.md: + id: cce7a317fca2 + last_write_checksum: sha1:1b10a6e6f7d330aba460961f48edf33ebbb32cda + pristine_git_object: d413f23f540a9544c257afeb9337e2907aa70027 docs/models/createinputsystembypackinputanthropiccompliance.md: id: 74097bdd0247 last_write_checksum: sha1:557b56a33acb4783289eab8d4768723b22f19da3 @@ -2054,6 +2306,18 @@ trackedFiles: id: a4e19d8e98bb last_write_checksum: sha1:409651947ca71e834fadc1053d820fd211df320c pristine_git_object: 316fb9723c93bd06fc78c5ad2a165aa06fd53307 + docs/models/createinputsystembypackinputanthropicenterpriseanalytics.md: + id: b75a8ea2e459 + last_write_checksum: sha1:18f217b574d8ee6e571cd16fad25f78d7dd8c2f5 + pristine_git_object: 717ff483a63df30ebb00e9966a11ada79cb9132b + docs/models/createinputsystembypackinputanthropicenterpriseanalyticscontentconfig.md: + id: 1b3ff5f56f94 + last_write_checksum: sha1:82d5fbc4300d5fd6dd02f4e5f52a209076dfe718 + pristine_git_object: 2f4222915880cf1794c976d8d253b1f2c15cc34c + docs/models/createinputsystembypackinputanthropicenterpriseanalyticstype.md: + id: cb1420afb22a + last_write_checksum: sha1:03ab23181e472f1637c37ae32dc76deb61ac33ff + pristine_git_object: 76b0df6444ca1cd34b2927689f422452470bf102 docs/models/createinputsystembypackinputappleunifiedlogs.md: id: 815af1a95329 last_write_checksum: sha1:d1b209e4208e61592dfd83b57f8e95871d8d3e35 @@ -2068,8 +2332,8 @@ trackedFiles: pristine_git_object: 8bbc86ad0952c0e5888b9d7e9e71c34aad129880 docs/models/createinputsystembypackinputappscope.md: id: 7f2753eed7c8 - last_write_checksum: sha1:20a18993b80b2a849933c06b969b44b31ac625f5 - pristine_git_object: dd08a9a20b74c93ba8465256e2bc923d4a4ebb61 + last_write_checksum: sha1:cb80c4dce3f5f5b5a7631ad2d7551bd07acf77be + pristine_git_object: 97263f29c5c2763701bac34a5edd13a2b6264c22 docs/models/createinputsystembypackinputappscopefilter.md: id: a4205451afbb last_write_checksum: sha1:d3b0cb9cf3b1811a8bc42aff8cebf310a6ce6a4e @@ -2082,10 +2346,26 @@ trackedFiles: id: abc2a0e1b284 last_write_checksum: sha1:8a20189d08b7ee992aae66de42d890b7edc4bd44 pristine_git_object: 7ae58f41567d6fe1279373268b202fdd07c71e45 + docs/models/createinputsystembypackinputaquasecurityhec.md: + id: 9a8e5f35f454 + last_write_checksum: sha1:e630510c937e270cca33e3a0466804413cb2bfff + pristine_git_object: b7dd0d93f96d7b2722a0703f3eb94e0c70003ab7 + docs/models/createinputsystembypackinputaquasecurityhectype.md: + id: 4e23f8409628 + last_write_checksum: sha1:2a8253c50ed7853b2a90a55349dcec128ef8d8e7 + pristine_git_object: 7dd5aa31ef679fe6ed942c1741c7b432442c8af3 docs/models/createinputsystembypackinputazureblob.md: id: 4d75b7ae19ac - last_write_checksum: sha1:fa5ff43cd408adbb08a5dbb3a46bb1c973074cea - pristine_git_object: ff64e18d9ed651d6a8b78e7faaaa4f447cd32cfd + last_write_checksum: sha1:3289a3666f88f98819cdc7cb42a8c2e530900697 + pristine_git_object: 6d6c7bd20190693061a7973f44cd32867dd92d0a + docs/models/createinputsystembypackinputazurevnetflowlog.md: + id: 00faf22758d7 + last_write_checksum: sha1:86de064fafcfff40e822300d7f08089a94737478 + pristine_git_object: 935750ba9d2c5c734171df6d4f79137288c8c000 + docs/models/createinputsystembypackinputazurevnetflowlogtype.md: + id: 069823f8ff5e + last_write_checksum: sha1:3099d9254bb782823ba20094e39c68329774c555 + pristine_git_object: edc95f38bf431cdd58030e68646101e92aa78dde docs/models/createinputsystembypackinputbedrocks3.md: id: 875cb25ead3a last_write_checksum: sha1:76adedcf8e92cd9868b8d49e6e41b00b4e0f9843 @@ -2094,6 +2374,14 @@ trackedFiles: id: 6408cefc004b last_write_checksum: sha1:468fbde5d139f5cc7a86a4d3e2309f47b45640d2 pristine_git_object: cc3d26a32ffd7eea8aa6cb5ba1a24481a8bde4e1 + docs/models/createinputsystembypackinputbeyondtrusthec.md: + id: a42556941c41 + last_write_checksum: sha1:54646ec63b098e093505f63a8228a47a88604ec6 + pristine_git_object: 202ea3cbede0be83aa57014a793d8bb8d47b6edb + docs/models/createinputsystembypackinputbeyondtrusthectype.md: + id: 55ccc764accc + last_write_checksum: sha1:7a442f3f7aa775e8265c4a5cbe329591853807ea + pristine_git_object: 5790b48e68daf524125b850418849491a2be91a0 docs/models/createinputsystembypackinputcloudflarehec.md: id: 0ff7d0ce041c last_write_checksum: sha1:faf1d2a9db6f06d791cb81ba298856d80a158bc4 @@ -2112,8 +2400,8 @@ trackedFiles: pristine_git_object: 3974e3d79465ada2cb78ba01e3bdfdc58eba758d docs/models/createinputsystembypackinputconfluentcloud.md: id: c930e9d0440e - last_write_checksum: sha1:d34b985126b154b8ebcfb95cf39b978bad2c1d1d - pristine_git_object: 48613c959ff31706d5c89eb105c07b29111d2c8f + last_write_checksum: sha1:4bf5333298240ac98452f58eeb50ebefc667df85 + pristine_git_object: 7da4cc6e832aa735a9a4dd97ce255f82c546df53 docs/models/createinputsystembypackinputcribl.md: id: 6a5e219a7b9b last_write_checksum: sha1:fb5e154d88a195deee491a920bb99cc3d0ed6df5 @@ -2128,8 +2416,20 @@ trackedFiles: pristine_git_object: 90a919d6859f75ce27692e9312363392a51f9429 docs/models/createinputsystembypackinputcribllakehttp.md: id: dcfb32f376e1 - last_write_checksum: sha1:978185e336d8344296e0c77d33d4697dd83ecd62 - pristine_git_object: 5c378004806620f620e23ce0192c9bd1a1ad8078 + last_write_checksum: sha1:8e9fafadaa10d29aa91f813a8c60de85c21a135a + pristine_git_object: e937443d1272bc0167cda07073d66a8887ce9d4f + docs/models/createinputsystembypackinputcribllakehttpauthtokensext.md: + id: fa30b5f9b140 + last_write_checksum: sha1:0f9f80f6301dcfd280a7c64fc5cddfda6ed5e42f + pristine_git_object: 0223e7e4e5a1af7f1228d23af1dda3d1fbbe4043 + docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtokensextitemstype.md: + id: bd594475a0a3 + last_write_checksum: sha1:ae272f74d59fcf157ac4ebcc5e4d45ca8fa4a309 + pristine_git_object: d03693e82a7dee8a20c4148d413653887fe158a1 + docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtypesecretconstraint.md: + id: 571e4786dcfc + last_write_checksum: sha1:e708f04b9d78b2083ddae977b5bc2e12d9a39cee + pristine_git_object: 0c7cfbacd36391a0ab5f3020ec0bf9be3130020b docs/models/createinputsystembypackinputcribllakehttptype.md: id: 857a673455fa last_write_checksum: sha1:b5c0d648336d5b5c8c78602952e4a9cd9ed56030 @@ -2216,16 +2516,12 @@ trackedFiles: pristine_git_object: 934a2291f4fc8f8314122cb41c710dae44231283 docs/models/createinputsystembypackinputeventhub.md: id: 887d52c0e941 - last_write_checksum: sha1:1d78cc957732fbe2a34a7ebd870426638258d939 - pristine_git_object: 3d6990f5b047bd0e5dd0628263a21b519ab88989 + last_write_checksum: sha1:1aac97ebd28db905ceb1c1297725042f7d6fb454 + pristine_git_object: f362d85f6c77428172b85d7b20f54514c78c7f30 docs/models/createinputsystembypackinputeventhubamqp.md: id: e66e221b7074 - last_write_checksum: sha1:48b484de2b81bcbd9f48ed3389f88fa1fd9053b2 - pristine_git_object: 97054f0437428e65605e307920c7ce52989f55ab - docs/models/createinputsystembypackinputeventhubamqpauthenticationmethod.md: - id: 575f5d4629e5 - last_write_checksum: sha1:48c69ecf9bd6c72071bc24057159b67ada1444be - pristine_git_object: 7ab1c8381292d11d0fbc614cf4313e19ac49e05b + last_write_checksum: sha1:e12cdce4e3a5a486752d03fe875adc2ea0ec9f5c + pristine_git_object: 964507d2b90b82ca6b90235eb64e3b8675ea6d75 docs/models/createinputsystembypackinputeventhubamqptype.md: id: 102f98c801f3 last_write_checksum: sha1:a2453797fc004590229bd8123c3087ad886de4e1 @@ -2236,16 +2532,32 @@ trackedFiles: pristine_git_object: cdb35dbf1820ca87635c70beee32f5e8c645dbfc docs/models/createinputsystembypackinputexec.md: id: 6c3ad780d2ae - last_write_checksum: sha1:0ff429435ca86c2bc91bfb0ffa382b09bced19a8 - pristine_git_object: 9330959df673855b172004991a51cda829d65596 + last_write_checksum: sha1:0e6a7c1616a77d4e1d5f44622d142eb088385292 + pristine_git_object: ebfa48fa8b2053911f2858e2d47805d8afca51b6 docs/models/createinputsystembypackinputexectype.md: id: c2e1863d7e3b last_write_checksum: sha1:7c850d04fbd53d2f5dfef718eafd3709803066f8 pristine_git_object: 653f5ee77447d3c1a0b1a88dff946b318d467b9f + docs/models/createinputsystembypackinputextrahoprevealx360.md: + id: 53fdd9c33dfa + last_write_checksum: sha1:33798bfa87683be7aa94a49cb81b9f7ff34bb1ac + pristine_git_object: f3e9d5b64073b8ff4b2d79e69805790cf351b64b + docs/models/createinputsystembypackinputextrahoprevealx360type.md: + id: 4f6c856ad1f5 + last_write_checksum: sha1:b5aa78d303f572183206386cd3f7e8a4a28374dd + pristine_git_object: 49e8d5a2f33dbe898476619e37a90439f0494238 + docs/models/createinputsystembypackinputf5bigip.md: + id: 5e9e0f683732 + last_write_checksum: sha1:cfb71703bd7d48bb20454068d7b42fac7a500bd7 + pristine_git_object: 917cbbbda35eed1be36724e4a5e3701ffd717703 + docs/models/createinputsystembypackinputf5bigiptype.md: + id: 7b8d34cdea92 + last_write_checksum: sha1:6e96700c3469a90b15827e7f4470cb853a4099b7 + pristine_git_object: 954b3df7619cca2486ccfff8f0e5d288e9510ab9 docs/models/createinputsystembypackinputfile.md: id: d17110253083 - last_write_checksum: sha1:7fef7a47e64a10c3271977616f480c8f585e96df - pristine_git_object: 4419ea18edb0efca0d41ca1d9d5e211a5f9a2645 + last_write_checksum: sha1:0699d66af38eb911a945cb03618ec930bfac7073 + pristine_git_object: f8c0d3dac84ec217ea829c725e3c55a66a914cfe docs/models/createinputsystembypackinputfilemode.md: id: d431a823dea7 last_write_checksum: sha1:b3b44965c55c37f2963b49777f9081a2799b8a1e @@ -2262,10 +2574,18 @@ trackedFiles: id: 8fcf74630fc4 last_write_checksum: sha1:36e48790cc4904d2ae2a2c089af203381dcbfa97 pristine_git_object: 9c9058147d66e9fb4cf5358cb1ba103068132c97 + docs/models/createinputsystembypackinputgigamonhec.md: + id: af1f914fba9b + last_write_checksum: sha1:bc2e5d0be213085b2e804b8e51bd5cd60a4682a7 + pristine_git_object: 896416a2f3d5363cdb8511d65fce1440f9279d81 + docs/models/createinputsystembypackinputgigamonhectype.md: + id: 5af9ec837e95 + last_write_checksum: sha1:f553451427b972fed099f3abb8ca73355f13faa4 + pristine_git_object: 8888f5bbe056051fb552535583bf2ff293cc2067 docs/models/createinputsystembypackinputgooglepubsub.md: id: ca5d408cca21 - last_write_checksum: sha1:20cea55f5aa2c2d446827c27e5e00a7abbe2548a - pristine_git_object: 6dc59e824c8e75b26f81c0d5e0f9818f2cd9fce6 + last_write_checksum: sha1:5e4487dee8aa9ccb0809ec53c3153fd283529a6d + pristine_git_object: 8bdf5405e265e0491a74af44f8da7ed4045fd1c8 docs/models/createinputsystembypackinputgrafanagrafana1.md: id: 813c5e510f20 last_write_checksum: sha1:d94685a892c11ca70a7d1f381c58be89e5e6f06e @@ -2286,14 +2606,62 @@ trackedFiles: id: d9bc79c9fc08 last_write_checksum: sha1:1a214ac4e85ba1060cdde6213e8929f9ee37189b pristine_git_object: 9f49aa6b2516887507720d85fe864f01ace591a9 + docs/models/createinputsystembypackinputhashicorphcpvaultdedicated.md: + id: ed6bd6407355 + last_write_checksum: sha1:0bc90860975b7f155d6ef0d055d3eb91a1902b5d + pristine_git_object: 9513406782ae96feff6af144832a32ec85210234 + docs/models/createinputsystembypackinputhashicorphcpvaultdedicatedtype.md: + id: f6450d804698 + last_write_checksum: sha1:62409da02da18290fc626a8584ec070d5cbed319 + pristine_git_object: 30e74f400166bb33d07e4f7a6cf5b8b48657b5e4 docs/models/createinputsystembypackinputhttp.md: id: 2d40e34a084e - last_write_checksum: sha1:1584092f806a104bda62ba234bec2d76f2ddf170 - pristine_git_object: 5d91cb64741cfe1ca79cac033924a111c120f16d + last_write_checksum: sha1:57b8ca390957efcbb4e04c3be4d1b0fccf6b0aa2 + pristine_git_object: d9a3034a91be129cc652c5a42e4b989e021582a9 + docs/models/createinputsystembypackinputhttpauthtokensext.md: + id: f99fbf2c27bd + last_write_checksum: sha1:5256963517cef9ba023af774f0988dd2aa0a8e47 + pristine_git_object: 7bd85af2919f847e2d06fc756e368a328e2520a6 + docs/models/createinputsystembypackinputhttpauthtokensextitemstypeelasticsearchmetadata.md: + id: 5040928e412c + last_write_checksum: sha1:a1bf54fcbed04317a783a69b8a3e364dd6884789 + pristine_git_object: b1934659a05bc88ffdee669b1023d623f4442a8f + docs/models/createinputsystembypackinputhttpauthtokensextitemstypesplunkhecmetadata.md: + id: 9c4d2eae321b + last_write_checksum: sha1:260f3f287efc852c47935f24c84ad6f1810b2939 + pristine_git_object: bc5d24d59df2e1ef1377f29b7ba56fa4da739879 + docs/models/createinputsystembypackinputhttpauthtypesecretconstraintelasticsearchmetadata.md: + id: fd4510f66349 + last_write_checksum: sha1:e819dac5757217141c513d9713bc9399cc8903d1 + pristine_git_object: 76ae6c2d2a3dade755022fe752566ef8db85f650 + docs/models/createinputsystembypackinputhttpauthtypesecretconstraintsplunkhecmetadata.md: + id: 024e40e5cafc + last_write_checksum: sha1:7c5371f5cc3a203e391403c951ad03a051ff34b1 + pristine_git_object: ba8faa606be6a59d304d3f1006b8c09d3bbd895d + docs/models/createinputsystembypackinputhttpinputhttpauthtokensextitemstype.md: + id: 1ef405e9ebe0 + last_write_checksum: sha1:841c55d7b47f5adbd26bb5b8914ae61def2782f3 + pristine_git_object: 262592e8de11db27c6e5eabf7dc02abb11299bfa + docs/models/createinputsystembypackinputhttpinputhttpauthtypesecretconstraint.md: + id: 1a0c7fd95abf + last_write_checksum: sha1:6668038c0e8d961691c342ae23814045dd8ef722 + pristine_git_object: 970a207b2e1a888796c1dcf1dfe5c36560910cb6 docs/models/createinputsystembypackinputhttpraw.md: id: 6eef62749e27 - last_write_checksum: sha1:60d9469d9a305cdfe08f5c2f04aad51f0d94a616 - pristine_git_object: c385f00d8ef78a7e9c282033df9ee1ae0f765889 + last_write_checksum: sha1:90ce818695b95ac8abf3e7a14520516125c9e9df + pristine_git_object: 7cbc2a5ade7e05aa5d661fe82f613b68c9523388 + docs/models/createinputsystembypackinputhttprawauthtokensext.md: + id: a8462963fc61 + last_write_checksum: sha1:ce6140d6e31519383298ff47b9f72a156af6ab56 + pristine_git_object: 237c616d82ba8a90e608052cd6dee0ae246763fd + docs/models/createinputsystembypackinputhttprawauthtokensextunion.md: + id: 514ffa7c7a32 + last_write_checksum: sha1:d246c3412b22f2060d512dafcbb60aefe1a02e88 + pristine_git_object: c2af6636608ffa5a22ee498b8e6b54f793ae3216 + docs/models/createinputsystembypackinputhttprawinputhttpauthtypesecretconstraint.md: + id: f1e6961913f8 + last_write_checksum: sha1:8c399361ab6629ee75aceab16855a98d38eb8f8d + pristine_git_object: e9217f7bba988a6f963cf05ee61166c2b14d4391 docs/models/createinputsystembypackinputhttprawtype.md: id: 7fc201ad1a1e last_write_checksum: sha1:89da87e9a71a799b7d4aef456dc987021780b199 @@ -2304,8 +2672,8 @@ trackedFiles: pristine_git_object: 6ccdce9112f53e87aa343dc9b5d87b93871f2a31 docs/models/createinputsystembypackinputjournalfiles.md: id: f4fbfd2a7b09 - last_write_checksum: sha1:02e804833eafaecdc40ef953d1b478a1dadf37f5 - pristine_git_object: 66c4ebd7addd0a5973a8037b1a374ee2113e3a39 + last_write_checksum: sha1:fbe90c6f473eaaa8e9fcc8627dd5212bfb22bc28 + pristine_git_object: c88dfde002ce0b7e2f847cbcb74a582e59ac7f65 docs/models/createinputsystembypackinputjournalfilesrule.md: id: b7adac10942b last_write_checksum: sha1:afa472c2cfcd3643b2065009262f5dfa389002b7 @@ -2316,12 +2684,12 @@ trackedFiles: pristine_git_object: bb72d71cc9d102bd8cd352d515c43a2f896cfbe6 docs/models/createinputsystembypackinputkafka.md: id: 372bffde20c1 - last_write_checksum: sha1:8922e1fe91f5e519cbb83e29fe5d07c65760e1d1 - pristine_git_object: 7d627f43274f69f634ea064af700ff83a4e3e7b9 + last_write_checksum: sha1:717ca075ffb6e978067f21dc47ca2f997d3b4293 + pristine_git_object: 3f58991f0d55f733bdd05afc743bffbeeb451d5f docs/models/createinputsystembypackinputkinesis.md: id: 3daa324bd3e5 - last_write_checksum: sha1:815b57e361a500a6346669b1c0d4b6f42d414d7d - pristine_git_object: c6d6ed5cf5d53303b83774b2e07deb68bb5d0b38 + last_write_checksum: sha1:57db7643e1dd7926ba4c9c70cba394a4df21c24c + pristine_git_object: d9d7d7e0d92b898373afe16c037b9d12a40b484c docs/models/createinputsystembypackinputkubeevents.md: id: c33f890cfc47 last_write_checksum: sha1:cdddcc0463703ee4c33df328afe989cb8b03122c @@ -2370,30 +2738,62 @@ trackedFiles: id: 2db2aafee7f5 last_write_checksum: sha1:cdebafc6f6548624b8c764a6638fdbc4042ae4bd pristine_git_object: 37e9ae2ceada5d0d79539bcca2dddce81690610b + docs/models/createinputsystembypackinputmicrosoftcopilot.md: + id: 68a71ee60d7a + last_write_checksum: sha1:f38c5d54381f8700c8609a890ebf72367a4c2566 + pristine_git_object: 7c2a9986436f5889133d495cb18936ed7c4ee977 + docs/models/createinputsystembypackinputmicrosoftcopilotauthenticationmethod.md: + id: 570a64fc0064 + last_write_checksum: sha1:848877c246ad464ee6a99bb4b7ba14a069c58951 + pristine_git_object: 5f7439e15ef8ba67badfd9aafa0780bf3a1b5cc7 + docs/models/createinputsystembypackinputmicrosoftcopilotmanagestate.md: + id: 85c7990457a8 + last_write_checksum: sha1:edd1306810d9d762095ca6d0c0490cc42f6635ab + pristine_git_object: 9b64499a3793dd44c35924f025677d5f145bca32 + docs/models/createinputsystembypackinputmicrosoftcopilotsubscriptionplan.md: + id: 5f5b42c49625 + last_write_checksum: sha1:6cbcc3fd5fbfb541db8c11fc70ca16ba518ea992 + pristine_git_object: b7aa4674e7251509c06172b99d64164424ecd7ce + docs/models/createinputsystembypackinputmicrosoftcopilottype.md: + id: 7c154b3c5994 + last_write_checksum: sha1:12bc8cd8b3cc95d92dd884c5fad7abed4acb8bd9 + pristine_git_object: 6e85ad2a4143e5eb83ee94c7fa750b8edd8dfdcf docs/models/createinputsystembypackinputmicrosoftgraph.md: id: cee0c4fa9690 - last_write_checksum: sha1:8ec6f24db9983123a576571d5320b85531bbe02a - pristine_git_object: 4888fbe36b695a0ecc42468438456ebcbb9585c3 + last_write_checksum: sha1:8e41b7e2e526b6e90b8bb701f2e13915a6d3df64 + pristine_git_object: ebf829bf01c7dd55f6cc67a8a5bbf349f1499890 docs/models/createinputsystembypackinputmicrosoftgraphauthenticationmethod.md: id: 1a20b18d9ec1 last_write_checksum: sha1:ea4124db388d66017579706925661b2ed1b129fc pristine_git_object: 927cbdd3ce2cfd71943507098d73423a256409b1 + docs/models/createinputsystembypackinputmicrosoftgraphsubscriptionplan.md: + id: 1be452683a41 + last_write_checksum: sha1:ddb89a09ef285a6f5193d309bfe58f87c2160f1a + pristine_git_object: aec74beb29f914b1270544b9fc18980e64edb801 docs/models/createinputsystembypackinputmicrosoftgraphtype.md: id: aa8263e25e25 last_write_checksum: sha1:63a5987edca80baa8f828a5353f55f86629ebc0e pristine_git_object: 244fb5ae1f436fdc307dd4f645a6935bb2678ae4 + docs/models/createinputsystembypackinputmimecasthec.md: + id: f181f8014037 + last_write_checksum: sha1:7e8f35e0fc423181c23a74275c710593524b15bd + pristine_git_object: 36192d024d8751799f3ab40a7ee7e9a66289df78 + docs/models/createinputsystembypackinputmimecasthectype.md: + id: e9f1bebfd482 + last_write_checksum: sha1:042681ff1e63e0496fe19ddbb5da5e17b0195774 + pristine_git_object: 46ef83b08f17d0755dc5384c60d8937d21a70364 docs/models/createinputsystembypackinputmodeldriventelemetry.md: id: b5d493a18772 - last_write_checksum: sha1:adc647deb5c197fa4f7bdc7e132ee2d4a849cf50 - pristine_git_object: 9ca1e3edd2e8597d4e56ba730f6e868d57f75e57 + last_write_checksum: sha1:ce30968026eadb5ad4029439dd69ba2a01ee0cce + pristine_git_object: 02e9a765bb4f97d6e1c6454fda48ff2acdebefaf docs/models/createinputsystembypackinputmodeldriventelemetrytype.md: id: c8f2b58ad947 last_write_checksum: sha1:e1845edf66ede0eddc23b4b4503a0fc196d28c04 pristine_git_object: 306640464b60870adfdcc135955701573732367e docs/models/createinputsystembypackinputmsk.md: id: 545b078614cf - last_write_checksum: sha1:1f3f3ee7a03c12354b958f16627a76cf177e82ad - pristine_git_object: beed3986d944a2088eab02d8e39f73d2551208cb + last_write_checksum: sha1:f0f62c9c3578cf8a8e51d44d6179924c5911e104 + pristine_git_object: 5ed6fedf7861f88487cff78552f10430aef3e2cb docs/models/createinputsystembypackinputnetflow.md: id: 4d77d67d0cc4 last_write_checksum: sha1:4433ae1ef134adf64b95e7f41cc388c75785df46 @@ -2464,8 +2864,8 @@ trackedFiles: pristine_git_object: cba072413c4859d9bfc8e431c3d5ad5c1f1e875e docs/models/createinputsystembypackinputopenaicontentconfig.md: id: c16a483d37cf - last_write_checksum: sha1:15eb5df9a07e37635b5c5984c3c7c4a0f096e96e - pristine_git_object: 63bf7f334a5cff4169216a8d474e7b8ec7bc5a0f + last_write_checksum: sha1:713b72ca54acf97c225f34b8990e8a6cb08ac0ba + pristine_git_object: bba5798f322c246c005403e918712a035f439c2b docs/models/createinputsystembypackinputopenailoglevel.md: id: ce2e8bd3dcd1 last_write_checksum: sha1:2fe2ffd01a8aa7f3673d6ad19d2038dba96d767f @@ -2480,8 +2880,8 @@ trackedFiles: pristine_git_object: 4b11049b6fdd960405b3b2c96cab50468247663b docs/models/createinputsystembypackinputopentelemetry.md: id: 0ec7be5ba927 - last_write_checksum: sha1:83520604427cf409acb9b4d8884496e4df1a8778 - pristine_git_object: a017be155519cd56d89141e9ba4d45537fb01865 + last_write_checksum: sha1:4946453ab2e7c409688c7dbabe09682a96898626 + pristine_git_object: 42377dff26edddf87b43b9f853da3b5fb17ecd69 docs/models/createinputsystembypackinputopentelemetryauthenticationtype.md: id: 2e009bc26412 last_write_checksum: sha1:8027653a80f54e0a585f8b15a858918c10754afc @@ -2490,6 +2890,14 @@ trackedFiles: id: 718eadb1f5fa last_write_checksum: sha1:9e550881f8a8ed08e865901ac70374b6a2c65773 pristine_git_object: b8409480e1775ca56448995d4295ba62669bde53 + docs/models/createinputsystembypackinputpingidentitypingone.md: + id: ab59c605d192 + last_write_checksum: sha1:d016131efe404d5914f8b1becdac67091e4b5b1b + pristine_git_object: b8c0b99d12a1c72008706ac2f5492a817c081b9e + docs/models/createinputsystembypackinputpingidentitypingonetype.md: + id: 47b6e9cf956f + last_write_checksum: sha1:6bd512b9aeae79ba9fb6e0456788ec2642ca888f + pristine_git_object: cad4f87ac37c6ee72790cd3dd1286bd6c00f87bf docs/models/createinputsystembypackinputprometheus.md: id: 7be6aa5c7aaa last_write_checksum: sha1:a11ae37a23f3f86bd496892663457e446efe6035 @@ -2506,18 +2914,26 @@ trackedFiles: id: c76953db9a1c last_write_checksum: sha1:723181374976925f10502cbdb737e43c530ef191 pristine_git_object: 3f848a5b238845866b01b1e755765c8504f398f7 + docs/models/createinputsystembypackinputproofpointpod.md: + id: 95e6d8e407ed + last_write_checksum: sha1:100a7ef332632517526d9b0d5b96e3f198606f4b + pristine_git_object: 0d9568643de0433a68a3f6e4f9d5974a19076994 + docs/models/createinputsystembypackinputproofpointpodtype.md: + id: 9cf8dd6b1c46 + last_write_checksum: sha1:f6464e49e985f726fb1ccce9a5d5a85fcbe30b45 + pristine_git_object: 5199cbd5d2b03ea87fb49f7b965b0b9876f79e78 docs/models/createinputsystembypackinputrawudp.md: id: e683a0fd30a2 - last_write_checksum: sha1:70ce0b11da1f6f65642858d11e459e99bf2022c5 - pristine_git_object: 0f71b1ea1bab69335f680af8e83c001248747912 + last_write_checksum: sha1:3c11415e1c89aab645abf854ffe6136141e7c525 + pristine_git_object: 0e55430ebcc6de895f353810bdbcfa4e5efc51fb docs/models/createinputsystembypackinputrawudptype.md: id: 8f2afd02507e last_write_checksum: sha1:099f5776e01a98ea30890cc2a52d7917a203a90f pristine_git_object: 7bb7376daf964add761e4f7c7b78df5921235d81 docs/models/createinputsystembypackinputs3.md: id: 25d0f4cda552 - last_write_checksum: sha1:ed2695ccdfd69d964ae7aec8c211b4f0471744e4 - pristine_git_object: 36ca51dc692610dfba5fe104c3a8e5da93f64f6e + last_write_checksum: sha1:00cf7462863646454e05db1fd1c6241ebbbc0cc2 + pristine_git_object: 42a34ef48169770f5f2b55de140370843944685a docs/models/createinputsystembypackinputs3inventory.md: id: 839665e25184 last_write_checksum: sha1:34704398c11432ae642046161fd239b25e21d157 @@ -2526,6 +2942,14 @@ trackedFiles: id: e8db4e89c082 last_write_checksum: sha1:d88e34d799c7105af70d697b00edd42317b9aeba pristine_git_object: ba8d85f0f1e14dcce141f6df0bc168baf810207c + docs/models/createinputsystembypackinputsailpointhec.md: + id: 82a004ac6af5 + last_write_checksum: sha1:ad1ab5aa666fbcc04a5d2c72c3b040fea2bb7d0e + pristine_git_object: dfbeea90e9276138764b25ace1ab02455194cccc + docs/models/createinputsystembypackinputsailpointhectype.md: + id: 211f572d035d + last_write_checksum: sha1:2316b71ae6472e23c4ba985d7772e3ec859d2aab + pristine_git_object: 0ab06dfa4bc26248baa2d36c44ecce75d5296afe docs/models/createinputsystembypackinputsecuritylake.md: id: ac9dff92a056 last_write_checksum: sha1:04dc153f0603aad53dd4f4084e2350d830f85309 @@ -2552,20 +2976,20 @@ trackedFiles: pristine_git_object: 1c45cf9d5c5b5c8e9769cd9ac5e3e2445909564f docs/models/createinputsystembypackinputsplunk.md: id: 61d7af30953b - last_write_checksum: sha1:42c7fab5495c7521a78d34bd6b8cfba42a607e19 - pristine_git_object: d9ed583f38658c4b0774bd07f28761bb1b3c26fa + last_write_checksum: sha1:7f9715cfd5a6117718b4a99b76f0ee2f809f0dae + pristine_git_object: a60dbb199a4b9f4583a82889b5d34afbb52b4b3a docs/models/createinputsystembypackinputsplunkauthtoken.md: id: 808ac681b38e - last_write_checksum: sha1:fb8ab33698bfd8639d91dfb32544fea5ec6cc05a - pristine_git_object: 6f969730cf084d1a5dd05bfd29dbd03a3fadca4b + last_write_checksum: sha1:adcd64bfae009acc8d859d45e292cb133d7aaafe + pristine_git_object: 4680f8a0b5df055bd682d7573c406f4e7c760b02 docs/models/createinputsystembypackinputsplunkhec.md: id: 1efee85529e1 - last_write_checksum: sha1:fce4b06fdce12b2f45ff2874e17bf4652b961db2 - pristine_git_object: 20c4d0d8bf9d15a29d8eaa534db08d5659a0ef09 + last_write_checksum: sha1:5d8e0945e96bc28207efc94fe6cdc19d0ef35cf9 + pristine_git_object: 6241340813f0aee2bf2ea33466ba1e45624321dc docs/models/createinputsystembypackinputsplunkhecauthtoken.md: id: 0a4244e47f6e - last_write_checksum: sha1:909ae231bc40c4845ef3ec464e7a8be59a824f75 - pristine_git_object: 50d381e3649b28f4f6c8246518b00b65122dea93 + last_write_checksum: sha1:fc321b90a2e696fa0748cfec083606c6c3618828 + pristine_git_object: 3c9e072d3a76730a5199143e43101a38d163eefb docs/models/createinputsystembypackinputsplunkhectype.md: id: 3a073078f5b8 last_write_checksum: sha1:aea9ed44bb50ff43e10e10d0ff5300dc5c63cff2 @@ -2588,8 +3012,8 @@ trackedFiles: pristine_git_object: fc339cf564b0ab342073a032e8364d3e04deab87 docs/models/createinputsystembypackinputsqs.md: id: 3adbda590e19 - last_write_checksum: sha1:4500a0d4a8387cd642c9839b43cdbb8de41b5949 - pristine_git_object: 03ae6233c947635f5f151a1b40c8f4b894bcbb04 + last_write_checksum: sha1:b993f939cd922ae81c9873049c26845e457eb94d + pristine_git_object: faff6980ff7aeb848f18fea7f321fcd7c53fe95e docs/models/createinputsystembypackinputsysdighec.md: id: 1b113d7b2485 last_write_checksum: sha1:567e697344743d8c7f3056bc57f7d007cc366ce9 @@ -2600,12 +3024,12 @@ trackedFiles: pristine_git_object: c28e4c83ec2ec82adfb8df8b11a5fcb9f8fa328c docs/models/createinputsystembypackinputsyslogsyslog1.md: id: 844a96f8412b - last_write_checksum: sha1:81eece422a41fdbbdc9586e6f4c48c126714771f - pristine_git_object: 1af2ee714f65ffb799ae231eb534191793db9a41 + last_write_checksum: sha1:a5bda8f714ac1962feafa41a4e047a8ccd5ea9d3 + pristine_git_object: f90c52ed6774e470be642e76c23cff258ab8fdc5 docs/models/createinputsystembypackinputsyslogsyslog2.md: id: 50d59b2fceb9 - last_write_checksum: sha1:cadb73496abb6649bdda0c9df639d05a02e085f7 - pristine_git_object: fcc38baa9d555ddffceca0cff046be0b985eb403 + last_write_checksum: sha1:66d828c125c1f2c4ff5dc1192d788a7e2725ad1b + pristine_git_object: 3800a21650332b1940ebbac3dc90f2ae60c33ab2 docs/models/createinputsystembypackinputsyslogunion.md: id: 6691387c36f0 last_write_checksum: sha1:57575efd59926ef12e76008f07117c3087882bf6 @@ -2688,16 +3112,32 @@ trackedFiles: pristine_git_object: 9a292127f018c4d3d7f6ca14c0deeea79c7971ee docs/models/createinputsystembypackinputtcp.md: id: 01b7a6966f26 - last_write_checksum: sha1:38cb12e9f965d1ff0ee8c29df2dd1de76490d1f2 - pristine_git_object: 29bf6b841477d901de4776337f6923ad1d50a9da + last_write_checksum: sha1:e4f55be23f866dec0848ef6e1335c670f6a2990d + pristine_git_object: 86a95334b9436f472116524e190f71ed9c8025a5 docs/models/createinputsystembypackinputtcpjson.md: id: d027d9b38537 - last_write_checksum: sha1:a38191be6bd4b3b1544f21979b4e780dcd8ead4d - pristine_git_object: 393421c80286d8874e0a83d91e112d8d3d41582d + last_write_checksum: sha1:576ca7c65a32756a82cbd97240eec638948037ef + pristine_git_object: 91da182abdb477bbac3a3d94f4c3b16f2e66de11 docs/models/createinputsystembypackinputtcptype.md: id: e0f1764a93c0 last_write_checksum: sha1:6cb3eca8e965f91bfb85f292d49900792c7a2abb pristine_git_object: 8e2d47d01bad644c46c2907912d458e89fed6db4 + docs/models/createinputsystembypackinputtrellixhec.md: + id: 6ab610ac0b53 + last_write_checksum: sha1:c33a3ea062c60747866cc6fa827cd42a50cb31fc + pristine_git_object: 53074e5a2729e5648facdb42fc350630356dc07f + docs/models/createinputsystembypackinputtrellixhectype.md: + id: fffea4474387 + last_write_checksum: sha1:26d3ccdbf214fc3d25b7d94702273a6a5e796a9e + pristine_git_object: 011c54e6404964dd98c78fa01b96292f99e196da + docs/models/createinputsystembypackinputtrendmicrovisionone.md: + id: 6b8248e22e31 + last_write_checksum: sha1:1f9afa5d160af8426af95c0109acf514c5333dbc + pristine_git_object: 099e47abe31aa17645a3db299a925162034a4139 + docs/models/createinputsystembypackinputtrendmicrovisiononetype.md: + id: 2b1e3c0e09a5 + last_write_checksum: sha1:b233af3d2143cb1909a905c46edd54c224bf95f8 + pristine_git_object: 897b3c07b9c342b2c9d9a83f522284f8e0796994 docs/models/createinputsystembypackinputupwindhec.md: id: 60d34783c38c last_write_checksum: sha1:ffb75bb607a4c80039d228b21bd7e24a32818352 @@ -2706,14 +3146,22 @@ trackedFiles: id: 62f7ad2b1bcc last_write_checksum: sha1:02127c53f80d7cd6d3e658562a0aa6f0a88b33f1 pristine_git_object: 7a94a77d8e500c17a4ecbe09b6d9b8efc851db6a + docs/models/createinputsystembypackinputvectraaihec.md: + id: e44c7905dce5 + last_write_checksum: sha1:78619e39df298d6c9f81e5ed851da97dfa661499 + pristine_git_object: cd8c915a1e503ae0a926c27cdd8991f70126fea3 + docs/models/createinputsystembypackinputvectraaihectype.md: + id: ac677c8684d0 + last_write_checksum: sha1:a35f645c1c25d2b1d8c6858a6c2af8abdf07e00f + pristine_git_object: c29aaf89465db483ea5bb8d2b4f348d0e758a97c docs/models/createinputsystembypackinputwef.md: id: ca39966df855 last_write_checksum: sha1:3a27d171ad6ad01bda1f6e74f180cb6a52d7377a pristine_git_object: c5f51adb7a5ae98006256fa32a7c6a5e7badc2ad docs/models/createinputsystembypackinputwefauthenticationmethod.md: id: c06c5faaeec8 - last_write_checksum: sha1:04a23e522c9ae0efe727bbc31eb93d73bdf83de0 - pristine_git_object: 8caf0efca644d7b64b0f304fe7d36d646d2bcdae + last_write_checksum: sha1:ed9adf10f1aaaabcaf74ede8a407e3f91abe5e00 + pristine_git_object: db96ddec7b1ad5d12dbb3f6dc426db83a1ed4244 docs/models/createinputsystembypackinputweftype.md: id: c0af12213aeb last_write_checksum: sha1:e8b0ac309d8d7cf3348b1924e56f5f87a0847f9a @@ -2780,8 +3228,8 @@ trackedFiles: pristine_git_object: 3d67ceceeb3b66477397884c15ac4a3f6af3a25c docs/models/createinputsystembypackinputwineventlogs.md: id: 27586396d5f5 - last_write_checksum: sha1:67ad59f44fb6b79e9667b862c70e52544a5574ac - pristine_git_object: fdd495082f385dda8a51592c750d2a2d52f1c5cf + last_write_checksum: sha1:2eaa9c45d84cc6cc6017a441edcdd9a74c92d7e1 + pristine_git_object: aa57a49dfe65b46978e2a8f01d83e96f1a489670 docs/models/createinputsystembypackinputwineventlogsreadmode.md: id: 7b771727537b last_write_checksum: sha1:857b4f9aa5ad0769219b4b009f29cfc7d1c22b12 @@ -2808,8 +3256,20 @@ trackedFiles: pristine_git_object: 6a11a79ecd9a14fd4659b6fbe247dfca049b29e8 docs/models/createinputsystembypackinputwizwebhook.md: id: 96f136902560 - last_write_checksum: sha1:0010ed611ac877f18238961922734cecabbd0716 - pristine_git_object: 052e979263d61446bcc27e5b87aa620139ea5fdc + last_write_checksum: sha1:1d54931d71be099a09b36b5fc0acc2985593d9ef + pristine_git_object: 7b1970b8971ff54848e126d331465aebb87b9fcc + docs/models/createinputsystembypackinputwizwebhookauthtokensext1.md: + id: baa7ad532e65 + last_write_checksum: sha1:917de923ae4af9ad33a5c3e36a83bf6c827fa70f + pristine_git_object: bfed2fa474b04ed5b7f8d4447b2b79c20c24a07a + docs/models/createinputsystembypackinputwizwebhookauthtokensext2.md: + id: ea49a59e9ae7 + last_write_checksum: sha1:7a4fb6f3c9f1738a4b769ce60249608091e53478 + pristine_git_object: ac231ee87b9ff89e1c91cb7d1b355bdf8203dd31 + docs/models/createinputsystembypackinputwizwebhookauthtokensextunion.md: + id: 92ecddce99a0 + last_write_checksum: sha1:f0438ecb31555beeccec80f0da518b8ebcd070f0 + pristine_git_object: 845f0a15ecaa53b925ab41f35ce5d60541f27b6f docs/models/createinputsystembypackinputwizwebhooktype.md: id: 8c0c0445797a last_write_checksum: sha1:5f723e51028adacd9cd553ceb1de5734675ad80d @@ -2820,8 +3280,8 @@ trackedFiles: pristine_git_object: 7b36a68da5feecc800da9e4b99a56f64ae9c4d13 docs/models/createinputsystembypackinputzscalerhecauthtoken.md: id: 035009e3056d - last_write_checksum: sha1:c1089cf4b45d6b515d843c132d4bedaf509677e8 - pristine_git_object: e5a4bb2e1d5438b416018a977dbda9a71c875c1e + last_write_checksum: sha1:18ff1297380f23d881aa3a8ec0f861f51e0f8cb1 + pristine_git_object: 105be80c5047b9405489efb911402a8fe3b82542 docs/models/createinputsystembypackinputzscalerhectype.md: id: 8dc1197d613a last_write_checksum: sha1:75d73ca7beb3db44fcbed41912fca4d267f53901 @@ -2888,16 +3348,16 @@ trackedFiles: pristine_git_object: 10a35acdb9aa68f09e46b4cc8338cd3d705e16ec docs/models/createinputsystembypackprojectdetails.md: id: f58d029fa33a - last_write_checksum: sha1:9769963a9bee58de27143f00f7eac003f54ce942 - pristine_git_object: bb582c7e71a54bf2df6191ed0969131069ba00c5 + last_write_checksum: sha1:2d5c15fb6c2012f49b8188ffd814763c1cd06495 + pristine_git_object: a4c20647795d4c27c01b21efbbdc47847523b85a docs/models/createinputsystembypackprojectdetailsmanagestate.md: id: 45c90e0c8cda last_write_checksum: sha1:50a44f779351a0211ddf4637182b22ce45eff92e pristine_git_object: 188b77a6ff795dbea9c1205aa8232a7b152d16eb docs/models/createinputsystembypackprojects.md: id: 8222f1fe31f9 - last_write_checksum: sha1:8617167a34853a3deb26c41e1f8bc11164f13d93 - pristine_git_object: aa8532297755982d9cb3fce7cdfafd48b406db58 + last_write_checksum: sha1:af19d729bedf728b90cc766081529f8cc5ef167a + pristine_git_object: abef17ab0c9fe5dae4b94e2383e92f9a9fc7eb0d docs/models/createinputsystembypackprojectsmanagestate.md: id: 3e74ef6abbb8 last_write_checksum: sha1:f0d44d32e0f57c5796290afa00c3269bfa67dcdc @@ -2934,6 +3394,10 @@ trackedFiles: id: 93bb9de5808c last_write_checksum: sha1:506283b41fce660f0478b2c02dff4b8b03ea694a pristine_git_object: 4306d7b6197883269e1fdefa4b287915933633a2 + docs/models/createinputsystembypackretryrules.md: + id: 1184b39ad8bc + last_write_checksum: sha1:1ecfd05a70c0879067e731e881361a89364998be + pristine_git_object: 3af19e5e5cc94e514a3baa03b98e1113ef02ccd0 docs/models/createinputsystembypackroutes.md: id: e572355de282 last_write_checksum: sha1:d969ade814451f3c57a7e909c1b50970c2b97ba7 @@ -2970,26 +3434,18 @@ trackedFiles: id: 13529299ea77 last_write_checksum: sha1:f19c98471e73cc9f6264de6d202ddf65e7ad52a0 pristine_git_object: 0e2f9c438b5ff6b794ea2c2ddc2f09f87d9532b9 - docs/models/createinputsystembypacksplunkhecmetadata.md: - id: 35383c48616d - last_write_checksum: sha1:70f89c14b39f54e1965a82a65bf5fd318de2029a - pristine_git_object: 6fc298e449a17a20a75d0e5a1415548030f55ef1 docs/models/createinputsystembypacksubscription.md: id: e9f351e77610 last_write_checksum: sha1:2f6290028d2f30a9317f4df9e5595f53670a3844 pristine_git_object: a5ccc60fb6a571dd9d0a25a50763f9fad0bde7ed - docs/models/createinputsystembypacksubscriptionplan.md: - id: ecf8428d057e - last_write_checksum: sha1:9c7e50297c252c496dacb15fb004df9e25279e6b - pristine_git_object: 28fbb13f1dd32bc985dc9945ee7b3c88c2cc5f78 docs/models/createinputsystembypacktarget.md: id: e87490d80a45 last_write_checksum: sha1:b8646c372053b6a57242ed207bec408eb99d0e2e pristine_git_object: 3344cb35f5d49ad68a6d3ed46cad61966b308608 docs/models/createinputsystembypacktlssettingsserverside.md: id: 9c6c2bb12fec - last_write_checksum: sha1:7a3bb337493717433493344e204ea85c39d5f333 - pristine_git_object: 8ced2b7097a250a7218f284268c34d6336cbf384 + last_write_checksum: sha1:7e2a86cee0830f8ac6392a6954751f3fe019b3a9 + pristine_git_object: aa7239c5f4466dfc4c4cd11917826a9e5c42c89f docs/models/createinputsystembypackunixsocketpermissions.md: id: eddba643405a last_write_checksum: sha1:b977960720eab99b4df02b3e9476b76c41524a20 @@ -2998,10 +3454,18 @@ trackedFiles: id: 0c86c4c83ba7 last_write_checksum: sha1:abb1eb8ed54670f50f5322a1718f52fa747a5bae pristine_git_object: 0d92df09e321cd0df80e99e532d1d058246e8f0a + docs/models/createinputsystembypackv3authenticationkeytype.md: + id: 5a8adb9f1d8d + last_write_checksum: sha1:02aa8647660eed9649e147e2123b018b530e5402 + pristine_git_object: 898ffb155202d480a8f19397ea35df75a354b241 + docs/models/createinputsystembypackv3privacykeytype.md: + id: e374b92c116d + last_write_checksum: sha1:71d2ae393840a923d4528a9aa4d193b11d21b2e0 + pristine_git_object: 39ca2c246b3a45391babad7e7ecad6ad471d4128 docs/models/createinputsystembypackv3user.md: id: d6a6591f0a44 - last_write_checksum: sha1:d2bb9f204e3610f57fa5c981a8d962b368aa48e6 - pristine_git_object: 7cec6616630131f5bff9685fbb39d2ca690780c3 + last_write_checksum: sha1:1cc7beae833e49ef04e59846b3af38ab8bd43bac + pristine_git_object: 729baec271808b23768ecf5cc2eaa7ccb0c0603e docs/models/createinputsystemhectokenbypackandidrequest.md: id: c40cfea6b63e last_write_checksum: sha1:af29416419726b5ae5ce10354a32fff3c085d513 @@ -3012,8 +3476,8 @@ trackedFiles: pristine_git_object: 5805c66fb79f9ca49c5d62909168f567ae3ddd81 docs/models/createinputtlssettingsserverside.md: id: 35a92c64f850 - last_write_checksum: sha1:9b0504e93df389497d234fd27fe1fcd5299e25e2 - pristine_git_object: c7d39de56d4b33ef5f0c79710c51a7ae94e812d1 + last_write_checksum: sha1:81a7aad57a7d2600c5c3edd52ef334d59048e007 + pristine_git_object: 63a3a6bfb8b70ff3be47a2b38f94ba37a7f09066 docs/models/createinputunixsocketpermissions.md: id: bdb7ff531f90 last_write_checksum: sha1:b9601216718d593b5ddb96158253bef003e789a3 @@ -3022,10 +3486,18 @@ trackedFiles: id: ca2f405cb3a5 last_write_checksum: sha1:8b6421ee121e23c065008d6edf80c969f15c7de5 pristine_git_object: 5c978c230a472b25966527950bbf3ba061e5f87d + docs/models/createinputv3authenticationkeytype.md: + id: 3d8525638ca0 + last_write_checksum: sha1:19753fb57b5125e7bd3df3a1ef0f994300d20b28 + pristine_git_object: 830ccb0236441828930c694e099aac90dc1aa7a6 + docs/models/createinputv3privacykeytype.md: + id: 13dac54dd245 + last_write_checksum: sha1:e958e9cf4ce1959dbf5b6ecf2e05a4097baa146d + pristine_git_object: 51225f8b2384627a39bbc75217f42de58681c8c8 docs/models/createinputv3user.md: id: f38d3286fc4e - last_write_checksum: sha1:747c6f1c1b5d9c05aeea1e83b4de5b2e77c1a63d - pristine_git_object: 883184dc22192c014bc0252d073f20b93f8da8fc + last_write_checksum: sha1:4e95a2679d4280ce9d71febdea063fe02e9aa962 + pristine_git_object: 950343aab6ac99e198a523a3cf75ae8e9625dd46 docs/models/createoutputadditionalproperty.md: id: 76dec46e09b9 last_write_checksum: sha1:82d32a9ba682a2b52056f8751f80f57d4d5c5dea @@ -3044,8 +3516,8 @@ trackedFiles: pristine_git_object: 52f07d776fca09091e96b826efd16f3407661921 docs/models/createoutputauthtoken.md: id: 63e9d0181409 - last_write_checksum: sha1:dec6a2b3b30f99b497e09e9156e8e6dcf2bbd9a5 - pristine_git_object: 8481290691943e7e612548f7020dadfcfe9759e0 + last_write_checksum: sha1:6b918c4f93c8889f4f13ef07b1b9b5e5bf520dec + pristine_git_object: c6ecb3d52472b5c65ffeb9461fa9f4f5b42a123e docs/models/createoutputauthtype.md: id: 874b9fa30c12 last_write_checksum: sha1:46704e93208e8957fe8636bc799d342373b92300 @@ -3090,6 +3562,10 @@ trackedFiles: id: a7e13d51cc84 last_write_checksum: sha1:6d77e191face7f0d81274022aa62febac91a7e59 pristine_git_object: 6a48e3423b2531721abe4b7657c9585f76169910 + docs/models/createoutputeventformat.md: + id: 9daacc13bbc9 + last_write_checksum: sha1:7ba7c21ed32dcfaa750e8e59701e9e67e336453d + pristine_git_object: 3a61391ca20e7573df87d2e22b180697df97befe docs/models/createoutputextenttag.md: id: bbfb66f4e334 last_write_checksum: sha1:8a653868a4186f385f17a667ce6a82063b2fe3cc @@ -3108,8 +3584,8 @@ trackedFiles: pristine_git_object: b3a24e9ced7fb7ecd5d03c04670bf889f013386a docs/models/createoutputindexerdiscoveryconfigs.md: id: a13953e2b40f - last_write_checksum: sha1:d258765c02222d5345400da5880de37a024d53c5 - pristine_git_object: 9cec65440e3d4f0da698c8e7fc0997ff4352b3eb + last_write_checksum: sha1:2710024f2e923882f376f065844d39f4267454b8 + pristine_git_object: 1de3443f0529673c574c32963746ef375873a9ce docs/models/createoutputingestifnotexist.md: id: 7256579073ca last_write_checksum: sha1:748c5414e1f971755cd95eb7a17a708f231ad74b @@ -3134,10 +3610,14 @@ trackedFiles: id: 739e32dc75dd last_write_checksum: sha1:9d3a6f7e87d6b8cf4ac0ebe0b5ee9487c51d1171 pristine_git_object: 834165a51ce6f895a277cfa2835df7425fc1a689 + docs/models/createoutputoauthsecretsource.md: + id: fe71e63bfe59 + last_write_checksum: sha1:981186daf66ab05782ee877a88f7694947fd77f0 + pristine_git_object: 6a272602d3e7cf2d4ae2b063cbebdb98a38bd6cf docs/models/createoutputoutput.md: id: 6773b7d11de4 - last_write_checksum: sha1:f9eb8c303064e3fe525e252779092f33c16398f8 - pristine_git_object: d3e7e2310d4eb48918944e1d861b57b2c2d74ea9 + last_write_checksum: sha1:a8b0c55c5e7afa8a553b712b853ade23fcc6a8a1 + pristine_git_object: 286a4625c0408c0ebbbd2ceaa44577c5c2bb7cc6 docs/models/createoutputoutputalibabaclouds3.md: id: ae7402d1afd7 last_write_checksum: sha1:9ad92cb7c43b22f2cf2bb23b2c40ffdd48675051 @@ -3296,8 +3776,8 @@ trackedFiles: pristine_git_object: 00b1892fa4d7743599d3bb9e11c7e5697fbb282f docs/models/createoutputoutputcribllake.md: id: 952f5e762078 - last_write_checksum: sha1:b4f0e73fde9977ef0c147e08555868ff8bfe4286 - pristine_git_object: 88d29fff85e2c3dfa0c9c8b661170c3a3aa96009 + last_write_checksum: sha1:14686d8ec89450dc61507cdca855ee6c25871dd6 + pristine_git_object: 864d5620b6153ee192291248a0b95159cc6023c7 docs/models/createoutputoutputcribllakeformat.md: id: af40a579c467 last_write_checksum: sha1:689af7d70703747f98c7c9e37dae6c2c52ca37e0 @@ -3308,8 +3788,8 @@ trackedFiles: pristine_git_object: 38f014589919a6e562c2e168d91139d834df6f73 docs/models/createoutputoutputcriblsearchengine.md: id: 2ee1493169c1 - last_write_checksum: sha1:8d16bf56dcc1b97a9424c961517ecf46e5dd1caa - pristine_git_object: 3bab41866e2fd214ea621db20659f3b3b02fba98 + last_write_checksum: sha1:45e2ca0278f0b6ba56d18099471d5438196356bb + pristine_git_object: 368ce7a8e8626ab5dff284d5e56b822e6101ecaf docs/models/createoutputoutputcriblsearchenginepqcontrols.md: id: 3ed06577ac77 last_write_checksum: sha1:df85141a0a4ab2d89328f2086f3d2faeba85b028 @@ -3328,8 +3808,8 @@ trackedFiles: pristine_git_object: 1d73794418c6690321306138b6efc7a4620a33dd docs/models/createoutputoutputcrowdstrikenextgensiem.md: id: 0bb332dba9cc - last_write_checksum: sha1:c77ad1088b8b6629420a9ce6209c4cc6112f328b - pristine_git_object: b6faa9cf8e90fce488d97668812fbfaec8a8e03b + last_write_checksum: sha1:30773638b231fbcd40c6cd1f1c827a506058844e + pristine_git_object: b9973f382efba79d51cee1fed9bcc5acef517755 docs/models/createoutputoutputcrowdstrikenextgensiempqcontrols.md: id: acbc5a16306e last_write_checksum: sha1:d314648a37d9c8f2b8946ac3696135943e7d9941 @@ -3358,6 +3838,18 @@ trackedFiles: id: c7204b4f618a last_write_checksum: sha1:14f3ab6ca4abcdfe77b9f2bbeb287811a9f8177d pristine_git_object: 7c227603375681d52a33b12d3bbddcb8dc7fddd4 + docs/models/createoutputoutputdatabrickszerobus.md: + id: 271c6b560592 + last_write_checksum: sha1:b92ea7cc243fed43c4f8b0ba89f7488774174cc4 + pristine_git_object: 723820d1325048748c8aff5eef054c15d9d53080 + docs/models/createoutputoutputdatabrickszerobuspqcontrols.md: + id: 8d2a943f628e + last_write_checksum: sha1:cdade51a45fcfaee9f93dd62ea965b8dff8c2498 + pristine_git_object: 2ef317d7844885d392a0d2fd65cc33b375dcbf5c + docs/models/createoutputoutputdatabrickszerobustype.md: + id: ba53dea6de3a + last_write_checksum: sha1:120a583d7c906be1641d0ceb0bdab88a56b3ee0b + pristine_git_object: ed5191b4b51997a99f10654f0dd58f9e71f725d3 docs/models/createoutputoutputdatadog.md: id: 3498b718c150 last_write_checksum: sha1:47a2826e395131d52db0329cffdba98175924e7a @@ -3500,8 +3992,12 @@ trackedFiles: pristine_git_object: 1e6872f317c024bb44e0b5db34b5174ced041865 docs/models/createoutputoutputexabeam.md: id: d7d7afd338c5 - last_write_checksum: sha1:5635879b70599c3676a99bd8ab9dfe6794f02ba3 - pristine_git_object: df744653d0aa1e27091d74fd83cdb9374241609a + last_write_checksum: sha1:b4e35d4c1dc7c7df8ed2633dac0f4836b272609f + pristine_git_object: 9791001f9501c504f5dcdfded60e27ed17426149 + docs/models/createoutputoutputexabeamauthenticationmethod.md: + id: 1fb94f87164a + last_write_checksum: sha1:9c0502fd48044695beffd664449be837121faeba + pristine_git_object: 82554368baaf7cc984b61ebd36585b22f98e1008 docs/models/createoutputoutputexabeamtype.md: id: dd6d580f246a last_write_checksum: sha1:7d6bd46d2f4ae109f5f70a4e0e2aa1f6b17214b5 @@ -3660,8 +4156,8 @@ trackedFiles: pristine_git_object: 2b866c9c6198a239f078fe70544ef87f94697d65 docs/models/createoutputoutputhumiohec.md: id: 6deeab0ed98e - last_write_checksum: sha1:87e07abae9081c15bf28d0d316a83ac01e071810 - pristine_git_object: 892f7b931c3d28f571f6ae859b7222134093ed39 + last_write_checksum: sha1:c9c0de0e861ba75bef5e7f916f64711bdb1ceacc + pristine_git_object: 5ffeb75310e443fc2d025d7788a96c6c149b7820 docs/models/createoutputoutputhumiohecpqcontrols.md: id: c0dda8931ee0 last_write_checksum: sha1:2602104fbae7343cf50e7034d1e99e535dc1330c @@ -3852,8 +4348,8 @@ trackedFiles: pristine_git_object: 627f38a2de4c01c0e906777e1137cfe16adc6d8b docs/models/createoutputoutputrouter.md: id: 663cdac47d3d - last_write_checksum: sha1:c312f9ba0b769362adbd21493d895fc3a862c24e - pristine_git_object: 53c75e95596b74c9401411b0b172654ac35a4080 + last_write_checksum: sha1:e312b3ce0c4b9863215588aa4a55c9b0c22537bd + pristine_git_object: 6d0a9e56afaa2f65b7b2e3b782ec1f1628984193 docs/models/createoutputoutputroutertype.md: id: 7e8c4c8ae065 last_write_checksum: sha1:87373a0162f4dfc6bab54de0e6d60012eb948ce7 @@ -3876,16 +4372,16 @@ trackedFiles: pristine_git_object: 7f66f150b09c8976ddedb9c506519c5eb709253f docs/models/createoutputoutputsentinel.md: id: 68f02716f418 - last_write_checksum: sha1:ec620a50fba23427712b03b95090f0b9d762b459 - pristine_git_object: 77653d7daba2662ee1d3073e128327ba34cee2dd + last_write_checksum: sha1:2448eee7e60cc4e774a3a93ee2e756d50306a0e9 + pristine_git_object: c83c55c2460a83ad5b51ffbe2c7961621893c7b4 docs/models/createoutputoutputsentinelformat.md: id: c358ed461d14 last_write_checksum: sha1:42e1baa7048ac28dd5d04363244aa219240e5a4c pristine_git_object: 34573dc0edf9fef65492b22e011b033b8625ff67 docs/models/createoutputoutputsentineloneaisiem.md: id: 039e2296c8c9 - last_write_checksum: sha1:2997e4fe5557fba1b1d9867260f69d8232aff568 - pristine_git_object: 54f94eb17af8c8fcad1e7f30a63ef0da3b8c6a71 + last_write_checksum: sha1:3c2fb10e451d1c5b32a84c68db0f9ca9feef7c56 + pristine_git_object: ef759146f438182f3dd09ad5eea7745600e7257e docs/models/createoutputoutputsentineloneaisiempqcontrols.md: id: 5d31a0a2c21f last_write_checksum: sha1:6129b1f3af989be83dc80ba148b558aaad41a027 @@ -3916,8 +4412,8 @@ trackedFiles: pristine_git_object: 5ae0f53d272d9039a17ccc78f6b962f3447843e8 docs/models/createoutputoutputsignalfx.md: id: 132b8d3ecec5 - last_write_checksum: sha1:66dacef8cd8b41f60733a0f2c3b2814d27a6965e - pristine_git_object: 950a756817e991b011824d50b5bf5bb8d47c0edc + last_write_checksum: sha1:536d9b39b52fe7cb13246f2b19eba233769409a1 + pristine_git_object: 116a0ef51e60af213ec9ec6a9af3d7c40245d80a docs/models/createoutputoutputsignalfxpqcontrols.md: id: 8aeede225430 last_write_checksum: sha1:df8b165558154a2015bf13f758c41e5e89c52f0a @@ -3960,12 +4456,12 @@ trackedFiles: pristine_git_object: b76edab972666464ed5fe476c1bfec9c4dd487ff docs/models/createoutputoutputsplunk.md: id: 3de87ca18112 - last_write_checksum: sha1:95d2b8de47ffa450b71af5c94bf32fe2754341bb - pristine_git_object: a8fd72964ad1d2c8de5ea8694f7836d57d88cd1e + last_write_checksum: sha1:7304cbf762904c861f7156a9a942a4b47f2c4a9f + pristine_git_object: 0efba5d478aa3b883240361579af69e77cf7aeec docs/models/createoutputoutputsplunkhec.md: id: cb72d3ef844c - last_write_checksum: sha1:393ef676a02ba60ccebce4e578b43a49b54b2814 - pristine_git_object: d1a19118a39b7e258636de8d7e43f0a150b4e6c4 + last_write_checksum: sha1:56acc365f4161c9def3c8b6d15176a0323094893 + pristine_git_object: a16e8f0db5d099b9bdcae4a873045bf1514e2364 docs/models/createoutputoutputsplunkhecpqcontrols.md: id: c2216163a436 last_write_checksum: sha1:0711667d886ae31df95654f1bb98a75ef380e986 @@ -3980,8 +4476,8 @@ trackedFiles: pristine_git_object: c3639da4efdbe1f61dbf71016c35518c528a2d32 docs/models/createoutputoutputsplunklb.md: id: ad9415a4429f - last_write_checksum: sha1:8da48992286977d3526decc96e819c47ec82ecc0 - pristine_git_object: 82b95f0fe0fe5e9370ce26c53d332f703e71bc4a + last_write_checksum: sha1:c4b55bc862d6f0cef176e4e3a44b94a53b1eab9a + pristine_git_object: 65dc5489989f9a68ff27d880757733fde65f5713 docs/models/createoutputoutputsplunklbpqcontrols.md: id: 0e1a0ccd681a last_write_checksum: sha1:5daada99eb6155835e6b3ee2198b987bbea4b347 @@ -4068,16 +4564,32 @@ trackedFiles: pristine_git_object: 83041980ce886264c9fc850e14ee91604746bb99 docs/models/createoutputoutputtcpjson.md: id: e3e517595c52 - last_write_checksum: sha1:b5be89aa27a72d02cc82b4e6639a2ae5d087a328 - pristine_git_object: 91fa7c9b2df59e0ff932b1ae76380409c96839b8 + last_write_checksum: sha1:25761e471b4f90d47fb4e5f8516f886d9397955d + pristine_git_object: 57c0b932dd43bcb0edfd51af6417cbf02a69e77f docs/models/createoutputoutputtcpjsonpqcontrols.md: id: db93a11b1a34 last_write_checksum: sha1:e5a38e3177eb5f0770d632c3b42ab59541a5d24b pristine_git_object: 9521b031aed22a28d1e4b750fc2c9c9cad91b58e + docs/models/createoutputoutputtraversalotlp.md: + id: 78173a462b80 + last_write_checksum: sha1:c97af1de82dcd9b96d38c18e900dab98b6c0dcf7 + pristine_git_object: c261d9ca7f0a5119bb24d26d58f024d3b66ee709 + docs/models/createoutputoutputtraversalotlpauthenticationtype.md: + id: 0be07a5c8c04 + last_write_checksum: sha1:e7442ffbabc757357c8dc8a10f51999260d0cb59 + pristine_git_object: d658068c07dea14ed583dc4611b7d277c4cc87f2 + docs/models/createoutputoutputtraversalotlppqcontrols.md: + id: ac5abcee87fa + last_write_checksum: sha1:b08d48a284382b9b256639d2dee33c8e2f5f27f8 + pristine_git_object: eae73f132567f737c7f374bc7481340c1c747123 + docs/models/createoutputoutputtraversalotlptype.md: + id: 003f4d730a4f + last_write_checksum: sha1:ae41a4ee92fe926712101120dcf0fe79881e9757 + pristine_git_object: d1c3447f538678001a96b900ad573c639d977dda docs/models/createoutputoutputwavefront.md: id: 75582d1313e6 - last_write_checksum: sha1:fecc6b2cfc407ce8d2e56c27d48776ca13a2616e - pristine_git_object: 85599a08dd1c0e45e0f340949c28f11af3ec85cd + last_write_checksum: sha1:d37ea465169034874696418ee6752f8b3709e7a4 + pristine_git_object: e42178b43e499087716706ac89d216f453691e33 docs/models/createoutputoutputwavefrontpqcontrols.md: id: f94ac2cde336 last_write_checksum: sha1:549ca55dd7671d58b90a7b79d763c68bb582e62a @@ -4140,8 +4652,8 @@ trackedFiles: pristine_git_object: 9edcf6bb29a690ff88550daac06b4672621f599d docs/models/createoutputoutputwizhec.md: id: ba48fd6bb3e7 - last_write_checksum: sha1:34cdb059c1bf8be7bfd3fb36eebae1198ba8e7f8 - pristine_git_object: e49129e60664d7d252bf3f399d15418e7f1c8580 + last_write_checksum: sha1:e73a3933e09e0064a14eb5aca0c5dba97a014a61 + pristine_git_object: b5791557db8f706ad9fd676d354a3bcbfc2e4c08 docs/models/createoutputoutputwizhecpqcontrols.md: id: d36ca39192d5 last_write_checksum: sha1:4b9e6bc2427efa1ab401ac1dc6d8f19a907d4cad @@ -4202,6 +4714,10 @@ trackedFiles: id: 38fc5c5a5dfa last_write_checksum: sha1:1a66324314a5885729e82fb08c70bb5db9e9accf pristine_git_object: bc1462ca896b9b26af005a223b9531f3407b3e92 + docs/models/createoutputsendas.md: + id: 290d6db3c06a + last_write_checksum: sha1:2b81e4378338a86296a3c19586e5599fd80806ef + pristine_git_object: 7d4ea511e956009e9f5e6ce0f1b3a3531c1916ae docs/models/createoutputsendeventsas.md: id: 443c6a6ed7b3 last_write_checksum: sha1:b955e29749c82c52668bddb0aaa31b793348f660 @@ -4232,8 +4748,8 @@ trackedFiles: pristine_git_object: 08b1172d91f71bec57a583172e756b4fbdff62cd docs/models/createoutputsystembypackauthtoken.md: id: 1ae626512d8c - last_write_checksum: sha1:f3f972ac5eebca7f91af741ba43a31e00b66118e - pristine_git_object: f4e870f2e8ca90276ef559693fa62246f4c3d087 + last_write_checksum: sha1:9b5ff42419f78066b2810fc7a99b53098e0a8538 + pristine_git_object: 022551157b57fc06a315f1ce47cda3a02a3f2632 docs/models/createoutputsystembypackauthtype.md: id: b90a48024c43 last_write_checksum: sha1:572d2d00673b8d451205de80975ba6fb37bd0cd6 @@ -4278,6 +4794,10 @@ trackedFiles: id: d6130c7992ce last_write_checksum: sha1:a28314c57a93ede9a5030a222797d32cd68f6b9f pristine_git_object: 18a123e7af605b85c5248510262ec30e9c24f223 + docs/models/createoutputsystembypackeventformat.md: + id: cbe3c262b128 + last_write_checksum: sha1:c3703c0c533ca6da5fd0aaff12bdfba274615497 + pristine_git_object: 3f1398bd12cf95ffe4affb5cb1c1f5d2dc507187 docs/models/createoutputsystembypackextenttag.md: id: 09ce749e1f80 last_write_checksum: sha1:5d06c2bc1711334a94d4d2fd96cd44b83e0a399d @@ -4296,8 +4816,8 @@ trackedFiles: pristine_git_object: 3d9f81bc2ffdfe9dcbc1df52df3a659e8694c095 docs/models/createoutputsystembypackindexerdiscoveryconfigs.md: id: 209f12767a66 - last_write_checksum: sha1:4571de2e2560698540e6201e1d892f2671454f02 - pristine_git_object: 3eaa88da87553e360b8f17df30a9f20f7409b25c + last_write_checksum: sha1:ecab2197e27a8e3292a0d4c02fba6f8c0318fa26 + pristine_git_object: bfee9c08eb118d22e50651c93e756ac2aaaf6b67 docs/models/createoutputsystembypackingestifnotexist.md: id: 4c19cf33f273 last_write_checksum: sha1:5ac8059bb20784fbbc8c3f4145e9926c44f76fc7 @@ -4322,10 +4842,14 @@ trackedFiles: id: d8f5e424a14f last_write_checksum: sha1:55022f1d80f9d622411079f179d763a63a65c5c4 pristine_git_object: 0281a0b49e656528bc8be186d49f009308d6ad0e + docs/models/createoutputsystembypackoauthsecretsource.md: + id: 8f93ccc4314e + last_write_checksum: sha1:f80feef41b70c61bbdda15681824a83552c26dbc + pristine_git_object: 30ed2cc971fd8cdb77380d4fd32973c3ea8f4185 docs/models/createoutputsystembypackoutput.md: id: 585819f2a2da - last_write_checksum: sha1:beb723e443af1a88aa805fb73b0102d17dfbd1f5 - pristine_git_object: 8801a98d2c7045f3d6642be200a021c746ba7954 + last_write_checksum: sha1:87bb1bde867ec36d2843a2fe21910d96d54e3426 + pristine_git_object: 72a1eab9beb41f86952eeefdd5da0e41a4368cb2 docs/models/createoutputsystembypackoutputalibabaclouds3.md: id: 953164777e6c last_write_checksum: sha1:1b2e2cc7f882364c97971510b879499b184dfaa4 @@ -4484,8 +5008,8 @@ trackedFiles: pristine_git_object: a7f72cddb6f3dbd7d3b784a4b87131d010ec3f09 docs/models/createoutputsystembypackoutputcribllake.md: id: b00e95f1573a - last_write_checksum: sha1:b93da0e1213f4689e5729e58e3833138a2790bf5 - pristine_git_object: 65c53741d3958e045ff5e139253ca7850756f812 + last_write_checksum: sha1:ef86af81e908e019dacc216756d3bd40f85d5aaa + pristine_git_object: 95e41aab00c5828c7cdb4f733ebf83f8b8ba6046 docs/models/createoutputsystembypackoutputcribllakeformat.md: id: 53568aca8e5f last_write_checksum: sha1:2f41f1ad5609e0afc596f59d2cc9a8ade61d81ff @@ -4496,8 +5020,8 @@ trackedFiles: pristine_git_object: d90126989204506d267e55df3bd51ccee2748e8b docs/models/createoutputsystembypackoutputcriblsearchengine.md: id: f17303fd42d6 - last_write_checksum: sha1:3be9f72a4219c98aa2d5029963c3c6cfcfde76cb - pristine_git_object: 52f15c23275eddea48c07be42ae1769a658d0f79 + last_write_checksum: sha1:2e41e543447f29d52ffdaf97a80aff1fbbf994b4 + pristine_git_object: 5328b7edfe344be3cffd3e34b646dbf07b6b71ca docs/models/createoutputsystembypackoutputcriblsearchenginepqcontrols.md: id: d1ccfb65cbc3 last_write_checksum: sha1:8df83aa91dbe9b8a0ee1bf6c7913cad2c272d43d @@ -4516,8 +5040,8 @@ trackedFiles: pristine_git_object: 33af1e3a4a85186090918afa3745c940c23ba144 docs/models/createoutputsystembypackoutputcrowdstrikenextgensiem.md: id: 1016ac142312 - last_write_checksum: sha1:73ebffbd21097f6683fee5617d7ee8aa105f756a - pristine_git_object: a5b9b301ea1eccdbbb2a56bd77fe80a25d88e10d + last_write_checksum: sha1:76d3d4c0223ac75fca94a6dc8a3e4f91c4e0e389 + pristine_git_object: 76a78e0bd5e9c7910a7fd79b2de697f6bfdc5bc1 docs/models/createoutputsystembypackoutputcrowdstrikenextgensiempqcontrols.md: id: bbe2401dfea8 last_write_checksum: sha1:2cceb28e142657e647a3f0069620df76a3409a4c @@ -4546,6 +5070,18 @@ trackedFiles: id: 848673bc58df last_write_checksum: sha1:8cdd3bbae44e39f6b7ce6172fd044c3f2c378c2d pristine_git_object: 207767cb0bda31600ef089f4b686655a23d6f886 + docs/models/createoutputsystembypackoutputdatabrickszerobus.md: + id: "7091666749e8" + last_write_checksum: sha1:968331237c1146e16bcc36bef2a7869784328598 + pristine_git_object: fe4c9cae0ca1cc27bbcdc872a8eecfabccc13713 + docs/models/createoutputsystembypackoutputdatabrickszerobuspqcontrols.md: + id: 618b1d68ed74 + last_write_checksum: sha1:8d0dd355e648aff1e8971489e28d8230e5c5ed01 + pristine_git_object: 55fc345fb80648a21ade6960a180c9f167bddcab + docs/models/createoutputsystembypackoutputdatabrickszerobustype.md: + id: 8f24fed55fb0 + last_write_checksum: sha1:7b1ce4e6fca8ecdc42ffdc53e664610c8c1481f3 + pristine_git_object: 297d80c33df04d50e66ac3d536c6b9cc6e8457a8 docs/models/createoutputsystembypackoutputdatadog.md: id: 7a68fa2562c7 last_write_checksum: sha1:8f1775e432756f820c66b3d69519cc66fe68551b @@ -4688,8 +5224,12 @@ trackedFiles: pristine_git_object: d9aaffdf04ac2d569205fafb242475e209ebbf95 docs/models/createoutputsystembypackoutputexabeam.md: id: 616f76116ce9 - last_write_checksum: sha1:5dd7f88d9a4c68b4ed58848ee5986cc801fab0fd - pristine_git_object: 81ddd42304c8a310b293ec2fd53e2c64a4bd2abe + last_write_checksum: sha1:1ed1d3c735a0ebe07f5d7c17c602c28316311146 + pristine_git_object: a81e85755dda5ecd25e19b12c3f283f7a26fce1c + docs/models/createoutputsystembypackoutputexabeamauthenticationmethod.md: + id: 3e50cd17af89 + last_write_checksum: sha1:ae6754bf6bf33f19a55e2f0d034af0b57783041b + pristine_git_object: 61afe626580b698aef6e5a3cae8728e902f0cbdf docs/models/createoutputsystembypackoutputexabeamtype.md: id: 8bc1248daa33 last_write_checksum: sha1:02d2eb852ef1c73d129f73bd8d532583a728fdd9 @@ -4848,8 +5388,8 @@ trackedFiles: pristine_git_object: e116ea4e4cdaf843114e354c67220f78a0943aa8 docs/models/createoutputsystembypackoutputhumiohec.md: id: f6c19204a8c7 - last_write_checksum: sha1:80775c6f17ceb5ecac8acc5f55b43a4d3df8dd34 - pristine_git_object: 6677da4a469280cfdca0bfbf3874c483b94ab42b + last_write_checksum: sha1:78f55eaab514a21fd18fb40937363dfadb151b36 + pristine_git_object: c2481709dd13fc482cf47b52b6b6a3fe0eba62c4 docs/models/createoutputsystembypackoutputhumiohecpqcontrols.md: id: 07bf8166eaa6 last_write_checksum: sha1:987b35c64477df47e68d9652777627c0785aad3e @@ -5040,8 +5580,8 @@ trackedFiles: pristine_git_object: b0d1741bf308a581477b12be497f21eb8177874c docs/models/createoutputsystembypackoutputrouter.md: id: 25c54e6fbe76 - last_write_checksum: sha1:5dfca8b52eb1882323ad5aeb1ffce4d43db0a3ce - pristine_git_object: 7aca575755a27972bc28f4c87bf1331be47b6986 + last_write_checksum: sha1:10b068d498291fbd371a5380ff7c1f4ea92f1038 + pristine_git_object: 4d81a5085050c5932fbac7b020d33e6175152316 docs/models/createoutputsystembypackoutputroutertype.md: id: df724c4d75dc last_write_checksum: sha1:59378d98a5a28c714e630eafb90331bee2bfdb73 @@ -5064,16 +5604,16 @@ trackedFiles: pristine_git_object: 0b11b61ad964b0a568740dbb1b050a7b3a0e71c3 docs/models/createoutputsystembypackoutputsentinel.md: id: a08f85f2e3c4 - last_write_checksum: sha1:0ad0074502594ccf9c9f30524f38305d4dd8a6fa - pristine_git_object: 0a975d38f9857dab0da302a0ab3bd85e464357b8 + last_write_checksum: sha1:f559e67c4a08d37b56924877b0bd590e014b0179 + pristine_git_object: 197f229f7c57e5c0bd10a9c53d41f4d7651f789e docs/models/createoutputsystembypackoutputsentinelformat.md: id: 2c46ce01cb68 last_write_checksum: sha1:1c6f34cccffd9e8dd3ccc7b46154619b5c558282 pristine_git_object: 8a0319c9c066c95c4fe3b96528804bab1408fa30 docs/models/createoutputsystembypackoutputsentineloneaisiem.md: id: 4c9596e87797 - last_write_checksum: sha1:e52ae933d8a650253559c1349d2712111aec71ac - pristine_git_object: 19651154c0b52d1d1fe7e03b6deef5e27e8e2603 + last_write_checksum: sha1:d5f20f8e15df70948759299c104dc5c7d67e5f48 + pristine_git_object: 77dae75a70446027a03cbcf14da41141c0756761 docs/models/createoutputsystembypackoutputsentineloneaisiempqcontrols.md: id: 50e003f25ef2 last_write_checksum: sha1:69c721fb5444103868f2c9475e84edaf4e1e5307 @@ -5104,8 +5644,8 @@ trackedFiles: pristine_git_object: 258862617458969b1c17a61fb2be79f6c0e51940 docs/models/createoutputsystembypackoutputsignalfx.md: id: 3b7b626521e5 - last_write_checksum: sha1:ec492caafabd4a2461920c6fcc6923d6a84d61c1 - pristine_git_object: 1db7f0d2576ad4930a301fcae0704caea8d340e4 + last_write_checksum: sha1:d18746cab14dfb0888ce13ee043d2e24b020625a + pristine_git_object: ec1a0ba5c98fae473939a6cc7cfe11ffcb360d6f docs/models/createoutputsystembypackoutputsignalfxpqcontrols.md: id: 8903f8c0cc56 last_write_checksum: sha1:7276b09700f505f5e6b64dabb1384e0d0f2b1097 @@ -5148,12 +5688,12 @@ trackedFiles: pristine_git_object: 19e858c66f97ba72c11f63db7fd04058d868eba5 docs/models/createoutputsystembypackoutputsplunk.md: id: d54b83e64b60 - last_write_checksum: sha1:826c3b21d6cbec8934581a99856088b897b78e86 - pristine_git_object: b1c505c271cf5906fe452ed19e706a852d7cedf0 + last_write_checksum: sha1:1242c4808351e1c37de919629644c936854f156a + pristine_git_object: 0e15e947209db7715fa975395b01578be4097298 docs/models/createoutputsystembypackoutputsplunkhec.md: id: a0cb2a7b8f84 - last_write_checksum: sha1:d52dde92175576eb88f939d75698d2071fdc5917 - pristine_git_object: 55dd27f34c5dbae0685374e401a6d6053f28b72f + last_write_checksum: sha1:5cdc6b6501c702b83342cc3b0ea22db5756d7b68 + pristine_git_object: ecb461d363b1a8bd8bf970e5225d624ed14dba86 docs/models/createoutputsystembypackoutputsplunkhecpqcontrols.md: id: 21087019ff6a last_write_checksum: sha1:a2fb2689b67e74a3bd49192f298c2f1f31228f97 @@ -5168,8 +5708,8 @@ trackedFiles: pristine_git_object: eedb843cfa622e9bc63e0f6b65eba21d9cdc554c docs/models/createoutputsystembypackoutputsplunklb.md: id: 77173ec266d5 - last_write_checksum: sha1:6f71548f0c3f70710b51386e7847ccc357b929f6 - pristine_git_object: 5394d610c12a7d3ebd5b893c1c8753e6680fcc32 + last_write_checksum: sha1:031540a2ad403bb4500cb0f556b4b20c81ff5bdd + pristine_git_object: 3011559fe7cfcf1f005b3ffaa4ca86d97c8bdb5c docs/models/createoutputsystembypackoutputsplunklbpqcontrols.md: id: a7e24bd604f2 last_write_checksum: sha1:65e44fedcf9953bff706b5d23739d742c2f1ae5b @@ -5256,16 +5796,32 @@ trackedFiles: pristine_git_object: 072af687895d66871a3ce5217c61a8d09b2ebe0e docs/models/createoutputsystembypackoutputtcpjson.md: id: e9ca32c2f1ca - last_write_checksum: sha1:23a864fcdedcf74d7c77a3c64786df9ad3867f10 - pristine_git_object: 4d8cdb1d76742ad74edebf801305dd4eca8884d1 + last_write_checksum: sha1:51ca76c5505a878d9a40b6042fea30add5306315 + pristine_git_object: 7209019a992184b164e6989013e12ac4c6aac058 docs/models/createoutputsystembypackoutputtcpjsonpqcontrols.md: id: cd95f0aa3c5f last_write_checksum: sha1:88a51a9f8f1b60934f904af9c9092fd2c1c346bb pristine_git_object: f29ebe047d9ebf0d85d764329a768b1b1d818f46 + docs/models/createoutputsystembypackoutputtraversalotlp.md: + id: b128d51f54d2 + last_write_checksum: sha1:3e0a30b881a46a321497fe81316e58101239c3dd + pristine_git_object: 5b5f86a0f498de63bef6b0b7cb25d7fe15ba874d + docs/models/createoutputsystembypackoutputtraversalotlpauthenticationtype.md: + id: b1900643a997 + last_write_checksum: sha1:9a4a2c620b55824dce78b9d4ded2b22b5012b6c3 + pristine_git_object: 08ce1b98176553fdbc383e1faee9cf451f2b5564 + docs/models/createoutputsystembypackoutputtraversalotlppqcontrols.md: + id: b5c667746908 + last_write_checksum: sha1:d2fc45f05be9516a99d16b22061fb1081f33c642 + pristine_git_object: aea22065b64b0b68c84c170f9da11d4ab48c6123 + docs/models/createoutputsystembypackoutputtraversalotlptype.md: + id: 465a2a39f31b + last_write_checksum: sha1:7570bd3cddf2e26518430eaccdf099602b8a848b + pristine_git_object: e2abc0f7c297d8b76bb0a31f2c5b2cdd081bdaba docs/models/createoutputsystembypackoutputwavefront.md: id: f9540f7165de - last_write_checksum: sha1:cab4357fe399a070b4543c540a4d49f3a7df895c - pristine_git_object: 409bccd3bd1e113280dbc9563c52ec8fcf168dbd + last_write_checksum: sha1:07cf7ede86e8e3f448926e2eefb9ee64eaa268f0 + pristine_git_object: 6b5f8378b1c9ce7fb60af757f5c63e4bf8ee6abc docs/models/createoutputsystembypackoutputwavefrontpqcontrols.md: id: 9b5ba35e9ab5 last_write_checksum: sha1:32081f0c9d94e239dd0b7ee593f5f469bbc67d2d @@ -5328,8 +5884,8 @@ trackedFiles: pristine_git_object: 2b2c2db57465f2915bbe772df148ae7f601f3aff docs/models/createoutputsystembypackoutputwizhec.md: id: ba84fe43fb9c - last_write_checksum: sha1:9d9e74765735bbff6f1337938abab015fab8391c - pristine_git_object: 5472a0753856ef089c3d7454f183b33e8a304839 + last_write_checksum: sha1:523fe6e4c0c94c6682eb3995cfc0472c8a518e30 + pristine_git_object: c4bfa1b48e39e78dba0b5f5159b240a749bc6998 docs/models/createoutputsystembypackoutputwizhecpqcontrols.md: id: ad14b5b18b20 last_write_checksum: sha1:fffc2a0e0fa986efe627b87aaf472f4942abef15 @@ -5394,6 +5950,10 @@ trackedFiles: id: 65f7652d3951 last_write_checksum: sha1:86c90276b68a058ec5bdf5daab770b6dc42d2157 pristine_git_object: 362d82f62ea8c81950654288fd0af52b372606bc + docs/models/createoutputsystembypacksendas.md: + id: f37a38a83654 + last_write_checksum: sha1:630d89138f53717a2e0403ec7b283a46a109a99d + pristine_git_object: bbadce24564f7e160bd22b8678a673d88666e0b3 docs/models/createoutputsystembypacksendeventsas.md: id: 3d0d98f86921 last_write_checksum: sha1:af3af2d60ba918dbb72bbb555fc843faf9b3d415 @@ -5422,6 +5982,10 @@ trackedFiles: id: 8c4f7001f28d last_write_checksum: sha1:076adb198b6dce3d571457f13f87742b4bd00aa8 pristine_git_object: 2c1a0bdc8ba2c30805763e475bb49db2f12c6787 + docs/models/createoutputsystembypackwizdefendsourcetype.md: + id: eb1a7b16f869 + last_write_checksum: sha1:1b2ab92d6ecb08513829eae9cc0ddecc08109d4c + pristine_git_object: 86cda015879c5b7190fb6ac192851bb8bb3fcdaa docs/models/createoutputsystembypackwriteaction.md: id: acc33191b528 last_write_checksum: sha1:bb032ea6120c3062c5436ab96a0b653328597472 @@ -5450,6 +6014,10 @@ trackedFiles: id: 47c6f60afaed last_write_checksum: sha1:5231118985f9b03d95fc56fd49e5b3ed60944d61 pristine_git_object: b5ff4cb74adfe835fa29aab098a498bec49bd1dc + docs/models/createoutputwizdefendsourcetype.md: + id: dda71ad93abb + last_write_checksum: sha1:296af08bda1eeda9c107f6324f890487bf0aa701 + pristine_git_object: 15a1318b0f0c35fa505b59d98a09d4bf9b215e42 docs/models/createoutputwriteaction.md: id: 2848d801de7d last_write_checksum: sha1:3fc93e9e3f6fecf177f13a9eb5122915fdb152d3 @@ -5480,12 +6048,12 @@ trackedFiles: pristine_git_object: 8e26b1deb830fd24d451eb6311f9f9d77c085fe2 docs/models/cribllakedataset.md: id: 217bd4fe0ce9 - last_write_checksum: sha1:9f08e4c364e528c624c283bf38462f8a0080dfb8 - pristine_git_object: 14c480c4627b0d141ee604dc508d33b5d9cb54a5 + last_write_checksum: sha1:88a05d55dc57ab67bc6156dd6d28e103af388a38 + pristine_git_object: f6aba3da3216eb7c2a4fda9b32767e573409bd37 docs/models/cribllakedatasetupdate.md: id: 7da2b930e08d - last_write_checksum: sha1:b6b2c5070bcb75129e66b6b37bab8eaa96333a87 - pristine_git_object: 2d2611c065a4291de0ca9378f25e455becd9d5ae + last_write_checksum: sha1:972a3b2adecda177c43f14b75ed565b1ec14d075 + pristine_git_object: a44f5faf1d6b9e8b49319b5dd5f2470bf43864e0 docs/models/currentbranchresult.md: id: c6cfe9ac027f last_write_checksum: sha1:c16dc1bc51ffb6b951c5e53cd52ac8d65751ba64 @@ -5520,16 +6088,16 @@ trackedFiles: pristine_git_object: 6df267bd899d22417e893d31f43fac8f3d223ae2 docs/models/databaseconnectionconfig.md: id: 5cd25395d120 - last_write_checksum: sha1:36d79aa2b6fb9caceced6f29bb1e638e37714521 - pristine_git_object: c8a842d105bb18ae6b1097ee6a06f2ab888c37e5 + last_write_checksum: sha1:51ae972bc6d5b61516ff4895ac3fc98b62ea640f + pristine_git_object: 9848ee5c421ccb100095798342ffa0ac5fd06d34 docs/models/databaseconnectionresponseenvelope.md: id: 69e318a7319b last_write_checksum: sha1:e24328170112665edc81bdea4c507c0d1b911979 pristine_git_object: b05fc277db67bfb74ab880ef75c733f8f2c3f18b docs/models/databaseconnectiontype.md: id: 7545a6ba8134 - last_write_checksum: sha1:c4001b7b849514015d00ab18697210400ba38392 - pristine_git_object: a1ca65e387607834e2b1bb8b62593b9ba56b2b1e + last_write_checksum: sha1:c0ded93efb83b52d689a6867896aefe5fcfbf72a + pristine_git_object: 23b2d8f2f40fb6797ec7d559b6be5c72299e426b docs/models/datacompressionformatoptionspersistence.md: id: 2bbcbd9d303a last_write_checksum: sha1:e63fe42b3db4612c8408ead313f417411cc429a4 @@ -5626,6 +6194,10 @@ trackedFiles: id: 5801f6afe752 last_write_checksum: sha1:303d200b69378a3652ffdea72da963da47847746 pristine_git_object: 5984de3d29134fce173f7dcf4fc176c5958167ea + docs/models/deploymode.md: + id: f55028f560c3 + last_write_checksum: sha1:db86e36dd4b3ccae22ef57665f6606c6daeef02c + pristine_git_object: 810c60179c60e2036ee2a7f9c281595168d3cc93 docs/models/deployrequest.md: id: 81d125500c73 last_write_checksum: sha1:8a7424d2d76eba34f0b471ebe8e73a91a25eb9ff @@ -5644,8 +6216,8 @@ trackedFiles: pristine_git_object: e33073f4b3d6d9598c6f776dea19496d252a566a docs/models/destinationtype.md: id: 27183f23a494 - last_write_checksum: sha1:c0aa8ae805e7e9affbb707357590e29b9ec4e125 - pristine_git_object: 05ab68b2211d1aa3725a73ad4954b95118b99ca9 + last_write_checksum: sha1:e2706388e6254cc0d114b0ea239edfeea506542c + pristine_git_object: 926821d2f1d2fcb37884fcd73e544cd20955623f docs/models/difffiles.md: id: 9247d1e22176 last_write_checksum: sha1:fe1c0859d52f7ec00783c48f0c1c26cfe2f8bd3e @@ -5700,8 +6272,8 @@ trackedFiles: pristine_git_object: cbcf3882bf625aa6420192fbd9583b15b299c15d docs/models/distmode.md: id: f9f83ece2d7a - last_write_checksum: sha1:e8f60953fc0ee4b0c68335e35fd3453c73d30d21 - pristine_git_object: 7ba73345a2c24587e66da4a1b07e171d2444d232 + last_write_checksum: sha1:1c1a077963cedd60b2e7de11e6137a135c2b0e3b + pristine_git_object: 21f7d7e906b5514f6b091b5041e37bef16e3cb8b docs/models/distributedsummary.md: id: c3a1cc70d543 last_write_checksum: sha1:e1795b5f41640c2b630041010ebc42d46379de69 @@ -5722,26 +6294,14 @@ trackedFiles: id: 99ccb249b44a last_write_checksum: sha1:4c5642a5732eda2f3ff0a09f4a092ab46b9e1013 pristine_git_object: 37073c51505c5fc97e852d5dc39ed4a5aeeef37d - docs/models/elasticsearchmetadata.md: - id: 87abe602402b - last_write_checksum: sha1:f65fb9bcc8da109e6542e0c87e84086ce9282295 - pristine_git_object: f3b0780663f5809869f3ff52569cd765a9b0f8d6 docs/models/elasticversion.md: id: c82582ebf98f last_write_checksum: sha1:2c0920456ad8b5fa48a22e0ceae4302ac1bc99ea pristine_git_object: ac45043f7b278a3dc6b9aca14c7dc4603a25f69f - docs/models/emailrecipient1.md: - id: 3452fa6197d3 - last_write_checksum: sha1:f1e2daf20506dc3095f0391455f8e31b56cd82f0 - pristine_git_object: b7ee0aee901d97ebf29f1d5bcf12d28fda2ba45f - docs/models/emailrecipient2.md: - id: bcdfb9bccf1b - last_write_checksum: sha1:d70fdd6f1535570c05a35f68359bf55ac6cfbc9a - pristine_git_object: a4ebd4cf521d113d12dbba81559a0d0ec60fb549 - docs/models/emailrecipient3.md: - id: 2f03393df6a7 - last_write_checksum: sha1:2ae9b324f9335b558df3cd5b91c29e7bda77dcb4 - pristine_git_object: c46d447aa7533550eeaa3a09b219c13f9f27f256 + docs/models/emailrecipient.md: + id: e7eb992f0e20 + last_write_checksum: sha1:ea2085520a5dee4b468669d7b8c70839396ca6a4 + pristine_git_object: 0e9a138574d8a608deaa9d7b124e023e145ba8fa docs/models/emptyobject.md: id: b489fae50ac8 last_write_checksum: sha1:7e8c215681a7444d0917526428bd2df67caa708b @@ -5838,22 +6398,14 @@ trackedFiles: id: 5ea921f4eda6 last_write_checksum: sha1:343eeaa93ac75b4e683cd126d7640ad3fd3f7a8e pristine_git_object: d0d6823efea42b93485625478c13a502ac2150f7 - docs/models/eventformat.md: - id: 33ef0c8d4003 - last_write_checksum: sha1:41796bc576edf275a722df910d6268ef7e2586d2 - pristine_git_object: 26ea48c5133204589ede4ca94cdf80f5c4999972 docs/models/eventstatsconfiguration.md: id: 44a0510cb683 last_write_checksum: sha1:0a822f553c7b0d8e1a72c88a9a58423103b493cb pristine_git_object: d89fc37bc883737da59a9ed28717bd225b5ba1ce - docs/models/executorspecificsettingstyperunnablejobexecutorexecutor.md: - id: ab4d94d0f8c3 - last_write_checksum: sha1:21e4cd5ff86ebf00e26110afabd7c2adda1380c0 - pristine_git_object: d21b2459816d092caeb1ddca024c3e13a34e6d01 docs/models/executortyperunnablejobexecutor.md: id: af1722cc599e - last_write_checksum: sha1:d21049f5636e2b8f39fc0ea6fb64f9332dfbfffe - pristine_git_object: 5dd398ce104edaedce58f9b69732b3ce60949641 + last_write_checksum: sha1:eb5dde7ff7a630cb9d6d51573555281062574489 + pristine_git_object: a81309f66e4f040663a35862ec0e09b11e4d01c6 docs/models/extension.md: id: 6461b3463672 last_write_checksum: sha1:c167fae0ac9d2bb1a35a0ecba4e544270177f3a4 @@ -5886,6 +6438,10 @@ trackedFiles: id: bdcfc346b959 last_write_checksum: sha1:c052eda68de0a5eb806d324467fd71cd99dfb331 pristine_git_object: 86d610cc0ea586621e54d6ec675e953dd26f9e62 + docs/models/feedtype.md: + id: 3b6de0be7618 + last_write_checksum: sha1:16a688666751d80416ef548c0add32dd2c4dcbf9 + pristine_git_object: dd3de093771f89dbe8c1d3b43a508d3caf09d14c docs/models/fieldcondition.md: id: 2dd01e492fed last_write_checksum: sha1:bfa17bb7b0eff4681b1078202c8cfda9118a90cc @@ -5894,6 +6450,10 @@ trackedFiles: id: 5ab4dd2cab3d last_write_checksum: sha1:91ab8ffa4a622620f2191f7e4d7c841be7766177 pristine_git_object: cb68b9e18f63b8b029412b6740c0915cc76f9119 + docs/models/fieldoverride.md: + id: 4e3131c2b627 + last_write_checksum: sha1:37d845f8715c32e2c2570ff13664435f169c7b77 + pristine_git_object: 23da5fc1d905cc55795c448699e3c8828b8d0785 docs/models/file.md: id: 4ad31355bd1c last_write_checksum: sha1:e74f12ff9a2f23b3628e8ede963a3419f4aded78 @@ -6010,6 +6570,14 @@ trackedFiles: id: 3b99184a9542 last_write_checksum: sha1:05f437bc7906025d4bb3ff2c7d3912963836773f pristine_git_object: 73296edf0b57eee599d5f439cbb72aa097fe392c + docs/models/functionconfschemadetectionrules.md: + id: a583ae3aa937 + last_write_checksum: sha1:6b604e2e7cb32aacbac2049e906c7dea579addf8 + pristine_git_object: f57bcb6b4a32066c84767a38e8df41127381e161 + docs/models/functionconfschemadetectionrulesseverity.md: + id: 48f29c028410 + last_write_checksum: sha1:e955f5029295d3fadcaaf57c5558642c991a9112 + pristine_git_object: 8241fef924d45641593fbe98fa953c76bf6ca1fa docs/models/functionconfschemadnslookup.md: id: d99c1f0919a1 last_write_checksum: sha1:7e668941ea9b9d9e6d7a24b2ccde34cf996e9f1a @@ -6042,6 +6610,10 @@ trackedFiles: id: 5975eeb74bcd last_write_checksum: sha1:2a3f579a6076f020621d8944a31ce4072859b355 pristine_git_object: 9b82de5ba94e6cd3f7ff64b4f2d0214c5f75020a + docs/models/functionconfschemalakehouseenginemetricsnormalizer.md: + id: 5582f3ab235c + last_write_checksum: sha1:cdd09901e6c3729fe40eda30d3357d5a5391b90e + pristine_git_object: 16c7c0a8fb7d824d32b122a9eba47232cbf1c42b docs/models/functionconfschemalimit.md: id: 640671ffd4b1 last_write_checksum: sha1:7523bb56f24c905b2bd830b9bc6790d57f2ab884 @@ -6066,10 +6638,18 @@ trackedFiles: id: 9f664e99d2c1 last_write_checksum: sha1:a21532eb84a5c7ead4861f32888235366f9b2c92 pristine_git_object: f2cd6f9fec4d29ea910d673bab820e30d4ef1a71 + docs/models/functionconfschemametricstimerangegate.md: + id: 169a8e077f97 + last_write_checksum: sha1:2d927c84a52edd80f7f9a56477ef0a9e26c398f1 + pristine_git_object: ae20543ad1597c38d92ed781783575e23a8efce5 docs/models/functionconfschemanotificationpolicies.md: id: 4a426f38afbb last_write_checksum: sha1:45e9a274cd21a6a99e1b4e234e27c2d2797fc826 pristine_git_object: fcdf962e902d46496c6db7d2ea7e877e89242300 + docs/models/functionconfschemanotificationpoliciestemplatetargetpair.md: + id: 9b64c47a1fce + last_write_checksum: sha1:8e55f78cd4399fc9b5d4fb377cea31127037f59a + pristine_git_object: 0f460ab1ef3ce89e6b8ba2ee76b6686d6dc7438d docs/models/functionconfschemanumerify.md: id: f764717f8e4e last_write_checksum: sha1:834178d84f0fe2388ef9c66e0ca9daf87ee32190 @@ -6142,6 +6722,14 @@ trackedFiles: id: 20fb1226d295 last_write_checksum: sha1:ea0cf24e5ffa9cf179725e18cfcd827855a97388 pristine_git_object: 391ca7f6e92ef005fe6da5e4539f900cf333d51b + docs/models/functiondetectionrules.md: + id: 2cfb34b88b09 + last_write_checksum: sha1:b09b1e4a327cd63c30a6322c591d97988ecd0ad5 + pristine_git_object: 9bd14cccb68a7ab8c0597722bef82e7e5cccea2c + docs/models/functiondetectionrulesid.md: + id: f8962e1fd4ea + last_write_checksum: sha1:9b3eb5215f193432d5a8363e81804a761267058e + pristine_git_object: cc709260d77242d853700f7b03b19d7432c5eea8 docs/models/functiondistinct.md: id: 86e91f547c49 last_write_checksum: sha1:ca1cf852e7ddac29475e21eb3afae5f732917947 @@ -6286,6 +6874,14 @@ trackedFiles: id: 7de161a4ddf5 last_write_checksum: sha1:4cd93f68a61f729ce4ec6b8c3da71e4e7d3d6917 pristine_git_object: f72f1a610e5f7cc7d1227093686fc6dbcf9d63f8 + docs/models/functionlakehouseenginemetricsnormalizer.md: + id: 8b9400e06489 + last_write_checksum: sha1:650364f7792c757fb0e24045fb17c5d27cf38715 + pristine_git_object: 521d91f61b0bf9d66afab8f11c348bb072bcb89a + docs/models/functionlakehouseenginemetricsnormalizerid.md: + id: 2d707317ccd2 + last_write_checksum: sha1:6601f31805bc5f68f50b45c41f10a1d90dc7a4fc + pristine_git_object: 9af13fb4806650b3c432010e36a528d6e1140e01 docs/models/functionlimit.md: id: 45f03ef2f8be last_write_checksum: sha1:57867b83ca3c530b06676031f28acf79963c51e2 @@ -6358,6 +6954,14 @@ trackedFiles: id: 1c591df29ac7 last_write_checksum: sha1:65683d5e98bd15c031c4e5299d67cd693eaaede1 pristine_git_object: e602caf1d7b5d8d4e72eba07d51ca776f17e7732 + docs/models/functionmetricstimerangegate.md: + id: bde4e483f2fd + last_write_checksum: sha1:ee0a73476c332ed3c855d735745e16c4a8eef41d + pristine_git_object: 79773e2ecb4577b52018534364e6be2a73c712e8 + docs/models/functionmetricstimerangegateid.md: + id: 8643284c5438 + last_write_checksum: sha1:445b820fb6163025f615a623ed9673920c686618 + pristine_git_object: 295a176dd31d02703c667c3f69b8b222b40879b8 docs/models/functionmvexpand.md: id: 14c4ef7ddb61 last_write_checksum: sha1:05834bd86a0bbf9fd791b51a8cbcd4e4b16e0326 @@ -6488,8 +7092,8 @@ trackedFiles: pristine_git_object: 8eb8d792ed2ac5d8316ebc5e104ccd0574e9988c docs/models/functionresponse.md: id: d96ffd7d2c6e - last_write_checksum: sha1:c60ca227d68c337d22cdd1c96f8aa6ad56575d26 - pristine_git_object: 1f2efe9bd11096f23334aea9b41ee15be46140d5 + last_write_checksum: sha1:34bb4bd64fa436e7d364526240d44ff801395ee9 + pristine_git_object: 025ea953d5b163b2fe10ebed49dbef1722e653b6 docs/models/functionrollupmetrics.md: id: 29db8a39cff1 last_write_checksum: sha1:7aa89609826845522d2a94419cd3fbd2bed854d1 @@ -6644,8 +7248,8 @@ trackedFiles: pristine_git_object: 4047a6363811e8b54e611052b3afaf9847205eeb docs/models/getcribllakedatasetbylakeidrequest.md: id: ee28c307ffd4 - last_write_checksum: sha1:504caa2828983d44f94e2838e498ca4242cc6448 - pristine_git_object: b6d7c97ecf3eb7537a2b86ae4bac2d371dfe52fd + last_write_checksum: sha1:97ca65b33a5fa0dd083c28cdae7ff05a6374007a + pristine_git_object: b51b610fd949ebc49a84ab28112a436b3e5f712a docs/models/getcribllakedatasetbylakeidresponse.md: id: 4d12e2c6ac35 last_write_checksum: sha1:03c06c8cdd9d01d2539cc88d1f047ea80d6df3a3 @@ -6682,6 +7286,14 @@ trackedFiles: id: 2c54c57ed0bc last_write_checksum: sha1:0dd9dee9624d5906e30a4fd517b95d55121981e4 pristine_git_object: 7f5c007f524f5c20782a2b2f12854462529332a6 + docs/models/getinputrequest.md: + id: 8d1eb4cda43f + last_write_checksum: sha1:5a7ec37d0250d1895b06509fc839eefea0090ddf + pristine_git_object: 376601f5f2382d262b7046a7f4af1e5b024652d9 + docs/models/getinputresponse.md: + id: 2c9c4962d15e + last_write_checksum: sha1:25eac151ea658295dce5edd9a2067d9b32b1baca + pristine_git_object: 669c1f11e9bb6a9924877f3b0acce9c6c43b98dd docs/models/getinputstatusbyidrequest.md: id: f71f7da3c333 last_write_checksum: sha1:a0299fa89be51748b9cef9631d12c2c796631680 @@ -6730,6 +7342,14 @@ trackedFiles: id: 8c55af971d6f last_write_checksum: sha1:dfe02633c5390c9848486edfa5fec489aa796f1f pristine_git_object: a6931c86f406eef7f0872571bc79c169adb234f6 + docs/models/getoutputrequest.md: + id: d47994676d63 + last_write_checksum: sha1:6000306d604c09d6426d571f6d9cc3b48270d42e + pristine_git_object: c545e825da5fd7733757b6852d08e2d2d85fc3e8 + docs/models/getoutputresponse.md: + id: 71cfde471c62 + last_write_checksum: sha1:079748f97c8bab8056517989de5fb3ab69139e02 + pristine_git_object: a78141279c4664bebeeb00976e0f2c87a58a224a docs/models/getoutputsamplesbyidrequest.md: id: 5a9f32642244 last_write_checksum: sha1:32a0487634763189e65ab69bb64371890cd0ce9a @@ -6800,28 +7420,28 @@ trackedFiles: pristine_git_object: ce2511b9d7c8e6c72d913439a072bdaa86b55eb3 docs/models/getpipelinesbypackrequest.md: id: eda3300d658b - last_write_checksum: sha1:91abb11553223b83684897f88d4dc8fe9609f9f8 - pristine_git_object: d30c9891c276e8b697290e33be528313b46d2634 + last_write_checksum: sha1:32e27e8b893f1f9e223af0df07a27bb0bf1cb7a8 + pristine_git_object: f72c979003272883d6839632885c22595d312b99 docs/models/getpipelinesbypackresponse.md: id: 6c803c029119 last_write_checksum: sha1:2c0c90feac3bf98fa5e2c1bf42cdf475cbf1fefe pristine_git_object: a9103080f644ff27ce590f5b15cd8587e630fa8b docs/models/getpipelinesrequest.md: id: d8a50190688a - last_write_checksum: sha1:d99c1ddffdfd3470a53804d18c9b1c5b59bd7332 - pristine_git_object: d847060c8e47da2d671e2fe182c47cea41fd9447 + last_write_checksum: sha1:75bfcdfe32000c564f11fba4e0d60fce2e13721f + pristine_git_object: 7bb0bd524d3f1657fcc5965322f32abddd3a3920 docs/models/getpipelinesresponse.md: id: a42c0cea906a last_write_checksum: sha1:cda929e7de1069f4ed059079e3bc6dfd9954cac1 pristine_git_object: 66e74a9dc6e2e90c4cf4ef6c305d6cd636700a71 docs/models/getproductsgroupsaclbyproductandidrequest.md: id: 24290cd3608e - last_write_checksum: sha1:cc30c53468225a088b9f012b9097928ec64439f4 - pristine_git_object: 1df4a07165f714a7b2142527114be5a58e0613c0 + last_write_checksum: sha1:10b61fbdf8cc0cd38508b749e048b5035e88c6b2 + pristine_git_object: 0a84b50a09cddf2815f9c10b9f945532192b6dc4 docs/models/getproductsgroupsaclteamsbyproductandidrequest.md: id: 8b8a49c18e89 - last_write_checksum: sha1:09eaaf7df998c82d8ac43e9ca2746d12e0ed537e - pristine_git_object: 1c223befbd164b229870a2736af291ff1e9d17a7 + last_write_checksum: sha1:53274d658eac6309b2567041b5686a67ab2b65b1 + pristine_git_object: 53c51ee53ac513268ee33aa9edabfa60421ed0c8 docs/models/getproductsgroupsbyproductandidrequest.md: id: 6d47f11ee146 last_write_checksum: sha1:0d30a4b7b60ecc7111541774eeab7d8e55e37084 @@ -6872,8 +7492,20 @@ trackedFiles: pristine_git_object: ed505901b18de82f55592824a160df2a22bb7698 docs/models/getroutesbypackrequest.md: id: 49ea79588387 - last_write_checksum: sha1:7e9eb945d6e7287a2336e4649cf0017ca0a768cf - pristine_git_object: f44826a99eddbb744c304243e51ff99015dc78ab + last_write_checksum: sha1:2d20c19fe88ef81ab4afa49b8b5e60670b1e8ec9 + pristine_git_object: 11235ae477c52e06a763d0df61564de41a655b04 + docs/models/getroutesbypackresponse.md: + id: 253f5e8716e5 + last_write_checksum: sha1:7eb2edbb3f771498a201ef22b43d31f74a0fc8cc + pristine_git_object: 1f8e59c3eb58af76b513824aafc3977ec142123b + docs/models/getroutesrequest.md: + id: 58cb564ac071 + last_write_checksum: sha1:ea4e7e3b8d3845ee8540ed9f4650bcba4168c859 + pristine_git_object: dabfc839dbeebcb04d90551c07eac7acec4587e9 + docs/models/getroutesresponse.md: + id: 6f13eaff2590 + last_write_checksum: sha1:3ed039c78cfc76eaa2f0fa608f8fe0168668bf90 + pristine_git_object: c6a88e23f6ed49cc092fbd2b542b1be574529b14 docs/models/getsavedjobbyidrequest.md: id: 00d0638ed320 last_write_checksum: sha1:a85e29033fd5f785c5167366ef9189ba05b42360 @@ -7030,14 +7662,18 @@ trackedFiles: id: c3d5681ac7bd last_write_checksum: sha1:b7ddb54d380ffb1a79175ecbea8e03f754a4ba9f pristine_git_object: 27e6ee42011de1f8c3bd1ba27c968d18b41021cf + docs/models/groupby.md: + id: ae3d0966f843 + last_write_checksum: sha1:fa07cfedd588361bb719d12562aa4ccd438c4554 + pristine_git_object: b00a54f2902c3332c90df2a26d7c35096aef3f36 docs/models/groupcreaterequest.md: id: eabe8de251b6 - last_write_checksum: sha1:853f1adee22a2c1b6542d4beaac8d53948b4e84e - pristine_git_object: 9e788fd5d55a31c2d8c09b828e4e23a2b3648a5f + last_write_checksum: sha1:e3336ecd044de11a048b60fc6bc81c3075609cd2 + pristine_git_object: 5eac57349b29e2c77f193fc6e758dba50c17230b docs/models/hbcriblinfo.md: id: 4d3afe069b86 - last_write_checksum: sha1:03485f3e2d4c271f29d137b3bc766c729d8376c3 - pristine_git_object: b09d907061f7993bf49c697c3b241223e2261756 + last_write_checksum: sha1:79d42bd9aa2e2c18da351b0e279f8576bc81132a + pristine_git_object: 1e6b9f3e4aec5c39308badf13925e11dd463823d docs/models/hbleaderinfo.md: id: 7df1b8f9318d last_write_checksum: sha1:44f74ef2a0b745f54a45d425fcd72a6f494c81d2 @@ -7986,10 +8622,14 @@ trackedFiles: id: 05711446c2b1 last_write_checksum: sha1:fdae2fe08de633860ba5bf5face9917bfecc163a pristine_git_object: 8ad27c2168a65bdcba82ab7e033f3cb8c43a1572 + docs/models/impact.md: + id: 0f3826fd003e + last_write_checksum: sha1:2bd20e725cd0ef83a8573b5c127473fe4b1da108 + pristine_git_object: 0f4f2962b62e174d5729bee165b7040cc412e257 docs/models/indexerdiscoveryconfigs.md: id: e7777358f755 - last_write_checksum: sha1:7c837da8343add0838c45a3a2c9c09f31cee48b9 - pristine_git_object: 1d71752278ea5b66580d09350e92e3007c1529cb + last_write_checksum: sha1:229827ea30d4ac6269b61f5a01ecf501d4b96631 + pristine_git_object: 62fd78269c78f80b63d8eeacb0eafc459989a36e docs/models/infield.md: id: b78c9498bbbd last_write_checksum: sha1:1cd7cb25aff3ffced2af81cf5416491141f05b3e @@ -8002,10 +8642,22 @@ trackedFiles: id: 3052ccfa826b last_write_checksum: sha1:0d2ab94d603488ec80cca5228b4f8b9589da5109 pristine_git_object: b555fcc2568380666b48e146dc1efb4c707ffcb7 + docs/models/inlinerule.md: + id: 60d011c9d772 + last_write_checksum: sha1:4715bb2f982141c2393870751d6c3c308ee16b0b + pristine_git_object: 26122d0c943ac63dd345dffd5191e09ab282b006 docs/models/input.md: id: 5cbc446a3956 - last_write_checksum: sha1:845ac519d2636bc4c2d76268f8257b119c87dae3 - pristine_git_object: 244725e8217f6cf8bc930cce65fcfb886852adf0 + last_write_checksum: sha1:3f7697eb7cd3a4c21dcc8e37d692067fc1c876ed + pristine_git_object: 5092c9be4be4c331adaef772509647f6e4eb709b + docs/models/inputakamaihecinput.md: + id: 7507adc86994 + last_write_checksum: sha1:f051a75bfe2f5c1e8031eb6e8d038dbfbabcd7d4 + pristine_git_object: f9a21549e62c9343bad74f3ea8cb489aa3b30a3c + docs/models/inputakamaihectype.md: + id: b659068d752b + last_write_checksum: sha1:9c3eefd43160556a76b8708425486487dd799675 + pristine_git_object: bed3e4faa1d53fff0ddc1d62d277eb84fbe4b700 docs/models/inputanthropiccompliancegroups.md: id: 3cc6fd0521e2 last_write_checksum: sha1:b765bf29f52a2ed50103e284e0db6d85c0fc75f9 @@ -8018,6 +8670,18 @@ trackedFiles: id: 28d3f20493e1 last_write_checksum: sha1:afa27ee7b35c4d75cfd9fb9625ac0089698b191d pristine_git_object: 60527c7d17cbf5f0b2337f834cfdd483bae4e9cd + docs/models/inputanthropicenterpriseanalyticscontentconfig.md: + id: 61dfc1d0e2c5 + last_write_checksum: sha1:52d180387fb32e87c357a3b46d6bef35564a4f43 + pristine_git_object: f3a1877365d4dca99200beaf1c92510b027a64b1 + docs/models/inputanthropicenterpriseanalyticsinput.md: + id: f1e7374f5ee6 + last_write_checksum: sha1:a96d8b23ce127f3ac0005fdf6eb9517ea95ffec6 + pristine_git_object: e2f6f80a3f78edecd937fc9618728c51b91ec716 + docs/models/inputanthropicenterpriseanalyticstype.md: + id: e174333d2445 + last_write_checksum: sha1:e22530b45d44c97f2c958dc0a27ea10a94240f35 + pristine_git_object: 77a3dedc81a7060d90f9773bcf8e2cffb0b72e95 docs/models/inputappleunifiedlogsinput.md: id: 1d6c3782f327 last_write_checksum: sha1:c719cee99d40b4deb81a103e65101bd8f5bd69c6 @@ -8036,8 +8700,8 @@ trackedFiles: pristine_git_object: cb505f84f88c3e7df6e5e7aff66cbc57f6ab1af9 docs/models/inputappscopeinput.md: id: 2f979e216bc2 - last_write_checksum: sha1:558ba18e9216cdf58a4db87c1b16e5daf0c06b2f - pristine_git_object: 26ce6d03f2767e479a8a94d1ec05b46ecb5a640b + last_write_checksum: sha1:0503bd12d1ac75398e8ac71b41b5fb36c26c798b + pristine_git_object: 003dbe086914c0b1901226afcd9adcda4ba664ee docs/models/inputappscopepersistence.md: id: 410f50eb49e7 last_write_checksum: sha1:7d3cb452d53b5bfbebd9204daa42ba5231316986 @@ -8046,10 +8710,26 @@ trackedFiles: id: 6ef4fc593b38 last_write_checksum: sha1:84084eac4194ee7c172a2c98b93ffa7c42cb5204 pristine_git_object: f285628b91f3c87750cbbc6cda99b8ddf41fb53b + docs/models/inputaquasecurityhecinput.md: + id: 55b78460df14 + last_write_checksum: sha1:4a019a297ab13283d0765ccb13f6e97394d3c488 + pristine_git_object: e93d42487f83d31222ee9bf46cb5dab1f23178e9 + docs/models/inputaquasecurityhectype.md: + id: 90e1434252e4 + last_write_checksum: sha1:8e810b1edf1f328b6e7f418c620204e2af26ba6a + pristine_git_object: 08666d334abb66c0ba677020bd52941158754b7d docs/models/inputazureblobinput.md: id: 6ff67dac07e8 - last_write_checksum: sha1:fcc55ee965fdbee2def57e06df5cf996d4fb719a - pristine_git_object: fb28ff1abeb088e03f01af212353640f219bb8ec + last_write_checksum: sha1:930478a0c1a66b25c9bb83754a83adb0e7017943 + pristine_git_object: 2284ed6d6275f8fac359cae7dc5fe83b46b8a3a3 + docs/models/inputazurevnetflowloginput.md: + id: 67a6402a33ff + last_write_checksum: sha1:7e294bf390425d140f10b9fd7f52c5765f64c208 + pristine_git_object: 2cf0cde6177e36650f337820de7dfec996023171 + docs/models/inputazurevnetflowlogtype.md: + id: e928b5448bf0 + last_write_checksum: sha1:0f7807242a5ae66b6a594063b4bfe1239847ecb3 + pristine_git_object: c63c14692916707f6e5273e070fd9953acf9aa5d docs/models/inputbedrocks3input.md: id: 03c8f0596c41 last_write_checksum: sha1:f02f73186dcede70074f1f13cda39e9f53454ea7 @@ -8058,6 +8738,14 @@ trackedFiles: id: 6bb254181bee last_write_checksum: sha1:0f5001d676ca78fca1de68c0f79c32ac50df62bd pristine_git_object: 63954471fd560a2f4f9f85173b90562063a98fb9 + docs/models/inputbeyondtrusthecinput.md: + id: 5f6d06869eea + last_write_checksum: sha1:1fe933efc96f47508efb2ae404ffd3b9b4a5f124 + pristine_git_object: a79d288964b9cb5ffeab931d4ed02bb3cee01dd0 + docs/models/inputbeyondtrusthectype.md: + id: 93d400576665 + last_write_checksum: sha1:d9e1fc002f914c03de2e06f1fed3e854f46be4f5 + pristine_git_object: 9bf8f268211aa1e4327d32d09bba595b3cfb04a3 docs/models/inputcloudflarehecinput.md: id: 6e3c0dbd5424 last_write_checksum: sha1:c18cd23c290aa36248aada774f6268ab684b0486 @@ -8070,18 +8758,14 @@ trackedFiles: id: 8cca9760ada7 last_write_checksum: sha1:b57764a80a6cae3255195cc96f2fa3636eeda5ff pristine_git_object: 1b5cd558376d12d60a09afd2e4fc5f9d471e8cfb - docs/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md: - id: 71a262a75df9 - last_write_checksum: sha1:c13141990e2e84b1f55e5405f4bad6a721cb5737 - pristine_git_object: 656b79d2ecc63b0cf410607ba3eae1ded326cc97 docs/models/inputcollectiontype.md: id: e1c489aa557d last_write_checksum: sha1:90be1dc3ce08793a812b568575e943a34572ed48 pristine_git_object: 3d36aa400a336ebfa2d0e758ff4713acc90c04c3 docs/models/inputconfluentcloudinput.md: id: 2a69bbb1b1db - last_write_checksum: sha1:e9ec27cb70d13fc64bf8f56ad093ae70711bf166 - pristine_git_object: f6072364950313ca75f4c5621f6ab2e09270a425 + last_write_checksum: sha1:ce8d3bb741f7e2af519efccdaf5e4fa94f362618 + pristine_git_object: aa2c64dd3564654a3cfab5423dde4ad47fdeae09 docs/models/inputcriblhttpinput.md: id: fda26cf63246 last_write_checksum: sha1:fbdb6ea4bab1be763ba28de4d7fd63f0947967e8 @@ -8094,10 +8778,22 @@ trackedFiles: id: 24e9fcc0e205 last_write_checksum: sha1:ef14a05eaf86f4256d8f92e2a0194023812b0d05 pristine_git_object: 32449ebd5e9b251649bbb80afa91cd9a85d6c6b1 + docs/models/inputcribllakehttpauthtokensext.md: + id: cc455c331f77 + last_write_checksum: sha1:f64af9bd129b4128931ddfb49d766510c12ba9a4 + pristine_git_object: 99d8f688d821e5887a333dc0a63e9a8e5194d9ef docs/models/inputcribllakehttpinput.md: id: 8f9468fd15c2 - last_write_checksum: sha1:fb3432e19dd8670b0cacc6311095ba65fcf14b7b - pristine_git_object: 930b2690b9a1882977cc32caeef2891fc377c414 + last_write_checksum: sha1:d0d4eb515b15ee7462a1807ae871aebee04aba1f + pristine_git_object: d305621c74b2846250df54f93aac4a6d63ca4510 + docs/models/inputcribllakehttpinputhttpauthtokensextitemstype.md: + id: 6f254bfaa8a8 + last_write_checksum: sha1:b1dea7cc68c40c2f314fa502875047be4ddfe5ab + pristine_git_object: 8d3ccbeff82a249aef456eae659cc7df8de8e9f5 + docs/models/inputcribllakehttpinputhttpauthtypesecretconstraint.md: + id: 14479c5f50e6 + last_write_checksum: sha1:b59fa39d497327bc313435211cabca403d9b55fe + pristine_git_object: 48cf8569f9ca7527dcf12f52228ae92083c232f5 docs/models/inputcribllakehttptype.md: id: ce31cdc6eaf1 last_write_checksum: sha1:76c7b86887af9ccdfe1e87f6cb79cc1db7c64dff @@ -8186,42 +8882,54 @@ trackedFiles: id: 20c0e9008d59 last_write_checksum: sha1:709d15f27036dd5615226643097fe93e017ea66d pristine_git_object: 3be20b06d5326b26d85f472626d184c89a156ff9 - docs/models/inputeventhubamqpauthenticationmethod.md: - id: 1c499af182d2 - last_write_checksum: sha1:fdef0ef9f8b8477e5fc26c946a302936d27f4d3d - pristine_git_object: 808f57ece9abb4d7717b3957cb90f5dfefb93fb2 docs/models/inputeventhubamqpcertificate.md: id: ec71f003adaa last_write_checksum: sha1:883771fe3caca3bd09f682942e57e52fe1b66d9e pristine_git_object: e9bc74b882cef74d37f765b7ccac7427441f5626 docs/models/inputeventhubamqpinput.md: id: 05f9b477cc80 - last_write_checksum: sha1:2dbbd655c7a15a9be1946323792b0bd55e4a448d - pristine_git_object: 3567f719835691eb80a53057d1f1e78ed0feed6e + last_write_checksum: sha1:42ea447066cb9deeb23ad646e50e73bcd4201e0d + pristine_git_object: aeb75f7c94b134fa1ed4e3840a34a2c58737a87f docs/models/inputeventhubamqptype.md: id: cf107be610a2 last_write_checksum: sha1:5d6e594318c8057c34b1bec7770d18b22d3e3c49 pristine_git_object: 0b66b66b9a71885fe2a0a8432086e3e754f1a9e8 docs/models/inputeventhubinput.md: id: 3be64a1725d7 - last_write_checksum: sha1:66f23d0e94bc552d66c29784f97d59cbcfc1988a - pristine_git_object: 54e74d6571137f5f50ca342a4eb9d2c79873205b + last_write_checksum: sha1:dc0b6e6caf47ba34ac8006e80b7604bbee45295e + pristine_git_object: 5cb9fcba14df7e997961db1f0ac091f84b0144ea docs/models/inputeventhubtype.md: id: 76529426ef7d last_write_checksum: sha1:ef918923338bb572a2cdf56b7ffedc3068dd8ddc pristine_git_object: 6db3861f63012fba5873807422277a590c2cc8b1 docs/models/inputexecinput.md: id: cacdc6ae000d - last_write_checksum: sha1:bdd52c1edfb3bab057d11741a66234930348a764 - pristine_git_object: 35d11cb437bc59d8a0f1905242123777eb676b85 + last_write_checksum: sha1:29ebf5489d7a6e6bfc419c3814dede0e51f4d458 + pristine_git_object: db0d4e81c028e7cbf7416f74bd2a3723fda8e22f docs/models/inputexectype.md: id: eb13657e96be last_write_checksum: sha1:0fe71a27b9f95b5d5909c8dca3bc389150799735 pristine_git_object: 5f12db965a1c4b4984c9ebc6129649e83751f7bc + docs/models/inputextrahoprevealx360input.md: + id: 8265ff8e4d7b + last_write_checksum: sha1:ed4a92fab43d7ac869a51ca0bd2d618f660a0d78 + pristine_git_object: 8675f09c9fa69e94e9a7d0ff178f5ece10a83fc6 + docs/models/inputextrahoprevealx360type.md: + id: b7abe75b675a + last_write_checksum: sha1:55e4e32065f8ac3fdf4b3bde1ddba676bde393eb + pristine_git_object: efbc51d732f0d32a57906962bd0fc497ecd3c182 + docs/models/inputf5bigipinput.md: + id: b074b2ebc236 + last_write_checksum: sha1:5be457a09cebf1c57da56e28a635ab85a8b0d44c + pristine_git_object: f0693669f52b9d60d3b26470fec2216296cadf49 + docs/models/inputf5bigiptype.md: + id: ad0ea03e7d32 + last_write_checksum: sha1:e90d7ddb4de91949d7f6a4f4e5046543dd2eedbe + pristine_git_object: fbbe19d84d9a2c73a503ea1baa1fc7e5a8c11c1a docs/models/inputfileinput.md: id: 1fe11e6927d4 - last_write_checksum: sha1:5181502a7a80e04ae99df6383df45f6794f0b6ab - pristine_git_object: baa5a3c34941cc1adf006f79e03bd8261f62c378 + last_write_checksum: sha1:737ff1035d4c3e880eb4f3960a22e9902dcde374 + pristine_git_object: 41cb2ff2353c8a19cfff2cbd9e3687213347790a docs/models/inputfilemode.md: id: d57aa21dc987 last_write_checksum: sha1:4b67e129eefa7ae229a5c2f6ee805ad9dbc76329 @@ -8238,10 +8946,18 @@ trackedFiles: id: a46e38fd714e last_write_checksum: sha1:68b40f80924f8e80055e3a0cdbdf1a6d9df92520 pristine_git_object: 1a7ea2ca8c60bfdacface10c067171d600741b29 + docs/models/inputgigamonhecinput.md: + id: 96ab004130a2 + last_write_checksum: sha1:b05aee370e24bb933018657f9845bace8225a507 + pristine_git_object: fae02253f89728a99337940b22c6b4697113ef4d + docs/models/inputgigamonhectype.md: + id: 7148db7623f1 + last_write_checksum: sha1:5ab54029e75237ffb96b5c8a37a5d8d9be1bb3b2 + pristine_git_object: 97e0c6b8d16fd2176301e9477d001e43edb1acf7 docs/models/inputgooglepubsubinput.md: id: de694b149bfe - last_write_checksum: sha1:266b86bd401ee1f0403611cca59bf39f64c63085 - pristine_git_object: 8e4843d00f781181976febd5a46dda48b3e7f06b + last_write_checksum: sha1:1b5bc0013282964beb74e2546025cc63d4456415 + pristine_git_object: aec08f0443f661fc845769b2e680681708c042fd docs/models/inputgrafanagrafanainput1.md: id: 5f74d15e39fa last_write_checksum: sha1:b4629eee288d783b14eedb05f94c4fb43f110264 @@ -8262,14 +8978,62 @@ trackedFiles: id: 69f4c940fc97 last_write_checksum: sha1:9811983ec68833344df49809773b118a7ba5f95e pristine_git_object: d361852cb9888722f37e95b89115091d542db823 + docs/models/inputhashicorphcpvaultdedicatedinput.md: + id: 1a30b52e4c17 + last_write_checksum: sha1:d87e334dfa5c5fcf6d179e0e2690805d71ef182b + pristine_git_object: 9c9e34416db5ec2fd3b0d54f05440db5014cf258 + docs/models/inputhashicorphcpvaultdedicatedtype.md: + id: 692f2be44a40 + last_write_checksum: sha1:8e6ab2258ec56a1a39c72c74ad3fd5b97b239675 + pristine_git_object: d8b2e2a21faa8de57e8b31274350c8aa9392f827 + docs/models/inputhttpauthtokensext.md: + id: c13efdf3f3ce + last_write_checksum: sha1:3743f478be85fc250e8019afc42502feee3e7e28 + pristine_git_object: 07a79cc5e178b7b8473f54d8f8e4498cc97987a6 + docs/models/inputhttpauthtokensextitemstypeelasticsearchmetadata.md: + id: 683acf8386b7 + last_write_checksum: sha1:f17ca62448591d75b956b3a46931c1db819741e4 + pristine_git_object: 3ca4fbc08ac34177cd85ab52cefc5d60525cd917 + docs/models/inputhttpauthtokensextitemstypesplunkhecmetadata.md: + id: d049b0ec8b63 + last_write_checksum: sha1:69d559386eb46a74a19ad93b67c396ad726a0aa3 + pristine_git_object: 7a18726700b47a5bdcaa48cd1c46b2d90c5973e5 + docs/models/inputhttpauthtypesecretconstraintelasticsearchmetadata.md: + id: 7ae058b5f6f1 + last_write_checksum: sha1:fef3933a44b199f68aac3677ee1f12defc16508c + pristine_git_object: 0bf1b0e9a195ac00044f740c55c42e489e29bbeb + docs/models/inputhttpauthtypesecretconstraintsplunkhecmetadata.md: + id: 645960a0f956 + last_write_checksum: sha1:9c7bec2a1c1ad9ccf2c5ed55b13aa6d25b5c0221 + pristine_git_object: c2f2133bd82af475d566c7f56e0d3a065c9beb54 docs/models/inputhttpinput.md: id: 454ef286b5bc - last_write_checksum: sha1:3055f0f37652fbc4a4579eb1a3cea6f3f52da311 - pristine_git_object: 49fe4b2d90110ffa580954e504d67190a5d0452b + last_write_checksum: sha1:dab7cb0138ae95f44bf48254d8b7b3e889259763 + pristine_git_object: 8bac7e1e892c7be1c583b3c9af642f01b8c50280 + docs/models/inputhttpinputhttpauthtokensextitemstype.md: + id: 378d51304ef8 + last_write_checksum: sha1:d9f828e3e9f9da19b6711c7ce8432ce0dfa5e21a + pristine_git_object: 7142cb92d9086a0a1d7b888b2f7987ccf7c611f4 + docs/models/inputhttpinputhttpauthtypesecretconstraint.md: + id: b3414a359342 + last_write_checksum: sha1:3659e02708f630b1788b8c9c654e3f6e35824bbb + pristine_git_object: f394a1f67d9a1088ec510715d5e2608b0874bd0f + docs/models/inputhttprawauthtokensext.md: + id: cf6474dd7979 + last_write_checksum: sha1:ab87a83260482f6ffd93f847ecc201ba1445acbe + pristine_git_object: 1f78a8431819210dec0d8911a84e603f2f587716 + docs/models/inputhttprawauthtokensextunion.md: + id: c6ca2ded660a + last_write_checksum: sha1:d33b45df1503bfe1731f54c9081371a2478796ec + pristine_git_object: 1d757cb48a71a5c40c1fe125368761608a13f9c0 docs/models/inputhttprawinput.md: id: fc6719a95b7c - last_write_checksum: sha1:b9b60c217fbb428be6d53cf2727481a55526f3ce - pristine_git_object: af50ec856c3f46ea267beb9f6061f3a50415280d + last_write_checksum: sha1:347853a6d5c0d7e7fbcc2da01c25d581b24d7e48 + pristine_git_object: af23e44442d831ad9520d2c43ba3b643a38b6e48 + docs/models/inputhttprawinputhttpauthtypesecretconstraint.md: + id: 42e297e43c06 + last_write_checksum: sha1:6f896bd3107fe4153b4c858f56a7a391ecebe647 + pristine_git_object: bc119bd3bb907be52ddc62653213a3122bd19181 docs/models/inputhttprawtype.md: id: 2e3dd2aba35c last_write_checksum: sha1:d4d523aaaf52aba86ee070e9424839789436f887 @@ -8280,8 +9044,8 @@ trackedFiles: pristine_git_object: 5ab7bec3062f9d51b68a7c9c6517e025823f0cdf docs/models/inputjournalfilesinput.md: id: 922e7794863c - last_write_checksum: sha1:786d49aca957703c994d9408d4183c17cd444221 - pristine_git_object: b25ee7337a236d6c99f8c48b8ac2f4a133ff857b + last_write_checksum: sha1:ff3b5135dcbde6e7a908604690023d86aa9c66de + pristine_git_object: 60c9a94d12f0c2d4d7fd885a409f73a415c1fec2 docs/models/inputjournalfilesrule.md: id: 75f064d697eb last_write_checksum: sha1:d01ecb9eacb475daf103ad233a6dc4a4bb03aa22 @@ -8292,12 +9056,12 @@ trackedFiles: pristine_git_object: 27dc9a851a396a1eff651b7a8db03d2611eb20ab docs/models/inputkafkainput.md: id: 4a5a2acfffba - last_write_checksum: sha1:8597a656fad7beffa6abd2c51f7f2b15d4200b9b - pristine_git_object: 3b4c840876a5672fe10fcd5508a427a6b7dcc564 + last_write_checksum: sha1:27984a86612cfdbbc33c3412b6de3698e4ca6760 + pristine_git_object: ade9929e24d7468f5b6cfc599696b840ab9b04e6 docs/models/inputkinesisinput.md: id: 124fe273b477 - last_write_checksum: sha1:9d335bb5c519cfcce52b35e54399e6cd355b3d7c - pristine_git_object: e27488fb9aa5f38dbec98c78e16f80f1fe886c82 + last_write_checksum: sha1:36d8c1bce9793988896e031b676de65bcfed6aaf + pristine_git_object: 1df7b151b401b3122f0adcd7ee1f9b5a12ed4324 docs/models/inputkubeeventsinput.md: id: 2bfb59d442bf last_write_checksum: sha1:63a7acda53d7893f667128e52ec65e2499d19829 @@ -8346,30 +9110,66 @@ trackedFiles: id: f5c06f1eaa3e last_write_checksum: sha1:4f732249fc1bf8017adfec0a6404903cf1bde173 pristine_git_object: 88aed1bf0f41cf6e1579a40b50dc08b3645d14b3 + docs/models/inputmicrosoftcopilotauthenticationmethod.md: + id: 3da85781bdb5 + last_write_checksum: sha1:bd1c2d3f3d413e755a518d72a9152dab8c7cbf29 + pristine_git_object: e064d1ae4ca5dc77e6a734e5f64704d2e29756de + docs/models/inputmicrosoftcopilotinput.md: + id: 7911d0a64a4d + last_write_checksum: sha1:749aeb9b8cc75439d419ebc73560da444cdeb5e7 + pristine_git_object: 7a6f0da5c98205be74e85dcc904e4d23dad3d721 + docs/models/inputmicrosoftcopilotmanagestate.md: + id: 246ac87a64f4 + last_write_checksum: sha1:ca12923f3d9f2023057aa83160cae8dcb6f2ab0d + pristine_git_object: e13e2718d3e9e9321ae9dacf7b4c44bfd19f4129 + docs/models/inputmicrosoftcopilotretryrules.md: + id: cb3ee1f695db + last_write_checksum: sha1:b8e623f46e998ef6f7dce111e97e4f40c4d8542e + pristine_git_object: ee926df8d7d22c62b2aba29274c8c0d80bea77db + docs/models/inputmicrosoftcopilotsubscriptionplan.md: + id: 29b2a2ece087 + last_write_checksum: sha1:6559803a84d0edfb2b6858faba0eb8a22fbe1dc5 + pristine_git_object: 659e57e77518c3a2d05c80451f60484ce7929028 + docs/models/inputmicrosoftcopilottype.md: + id: cd3d096e3a2e + last_write_checksum: sha1:dbf07e6e28b1dd19cd6acca06444e261427c56fe + pristine_git_object: dae6a67a2a690dd0cac47c0adb2f5a5bf981eed7 docs/models/inputmicrosoftgraphauthenticationmethod.md: id: 6b76176d9eca last_write_checksum: sha1:8c659631a68856839d2c8ce3a774e8a532c91b37 pristine_git_object: 572e35b7dfa36a304de506eccf5b11d3c6b3921f docs/models/inputmicrosoftgraphinput.md: id: 5bc2172360f5 - last_write_checksum: sha1:dced3e05c71671dc0e429ddd797fc9a19bcd7319 - pristine_git_object: 16671c9919a2a666cb5d3a5411a7abe63763ccb4 + last_write_checksum: sha1:8567fb89f9803dc2a2d445e59cce056960b758e1 + pristine_git_object: 35478ed23705d13b3843dbca806327aba639d73d + docs/models/inputmicrosoftgraphsubscriptionplan.md: + id: 96f4525585dc + last_write_checksum: sha1:cd35a4c0e17d74fb0e163a0f6a13277e6df57b42 + pristine_git_object: 05436665d44f49913cb005552083e026f6331ee3 docs/models/inputmicrosoftgraphtype.md: id: 1361d09ed74e last_write_checksum: sha1:e29932fe7317b43b06bd004ce0b4a5d880d62662 pristine_git_object: b493513429828ab917e0ec6b53d8f0896927f167 + docs/models/inputmimecasthecinput.md: + id: f6675b128bf4 + last_write_checksum: sha1:2a367c19fb4643d4ea9608ebaab245b5d4899a36 + pristine_git_object: b11a10fd0e5b2fe7a6d69cd8fb0908b2804887bf + docs/models/inputmimecasthectype.md: + id: 051b22b42b76 + last_write_checksum: sha1:2b833c312e1757a9a8a75211f87e8fbfb005a783 + pristine_git_object: fff9a0286e828283ea8b05cf83793c6040bb67fc docs/models/inputmodeldriventelemetryinput.md: id: a07a4520f563 - last_write_checksum: sha1:0777024d62d41854a0137400c44d95ccc152300a - pristine_git_object: 4fb77d1b02ce467356f75f714258a2cc17baa7fe + last_write_checksum: sha1:58b72c7cc8f127ce3c490e636d612575915cdf76 + pristine_git_object: e01eb415cf4f411def94f77627952faf9a08fb09 docs/models/inputmodeldriventelemetrytype.md: id: 2b222bb926ac last_write_checksum: sha1:5b466a73e856b8b0b710a5eae65a303fb10d31a1 pristine_git_object: e04f57fe15d59be58cb56b6fab0eb00fbc9c8276 docs/models/inputmskinput.md: id: b3731009559c - last_write_checksum: sha1:32cba9154cfbb071de7e31d244f24eeda9505474 - pristine_git_object: 65fab63a3bbaf7347df5ab64637ff496dc30df62 + last_write_checksum: sha1:e3ba504b5a98ef6e79d2f1b5b18a7568ee88b6ed + pristine_git_object: 5cc592ce8989078ede9aa3a722f590cb7cfe2bfc docs/models/inputnetflowinput.md: id: 600d014d4367 last_write_checksum: sha1:9646651fc05e9fa82740eaa047a0cbda13b091fa @@ -8456,8 +9256,8 @@ trackedFiles: pristine_git_object: 0622f7c838a9c6290eacb1b826543f1963e7fb82 docs/models/inputopentelemetryinput.md: id: 560be1f89cb2 - last_write_checksum: sha1:c4be9cea38e77bcdb93aa3b33d930bd4a21c7ebb - pristine_git_object: d179f5b1215ba174a6d32a4a602afb04fb6f0525 + last_write_checksum: sha1:04c13a77b11b14bc6385f757efa50afdddad17b7 + pristine_git_object: 6204b5258b3f9482f85303fb36a31fff310d6be1 docs/models/inputopentelemetryotlpversion.md: id: 552338309ce7 last_write_checksum: sha1:550096d0ae1480f3d0b662538fa05e4cf142a81f @@ -8470,6 +9270,14 @@ trackedFiles: id: 33adad65556e last_write_checksum: sha1:2bfa7c85e929e62ac741fdc0401215f90a09b237 pristine_git_object: 54f478db25e7a3284d0fc36268a80356aef148c3 + docs/models/inputpingidentitypingoneinput.md: + id: efac8a540637 + last_write_checksum: sha1:93a71359d10095c1a8c228deeba286a6dbe93e6d + pristine_git_object: dae4cf101443caf2e8dc3f8c0f61bf8ad6fcce67 + docs/models/inputpingidentitypingonetype.md: + id: bc114e3d964f + last_write_checksum: sha1:70db63d3141e7c29b21b4bb24d973d22bc7083c9 + pristine_git_object: 210eecba6c3d53f0ade396b02fa43b46639f4a45 docs/models/inputprometheusdiscoverytype.md: id: bf99132228e2 last_write_checksum: sha1:92189771a95de601387aeb4f285f41a2e58a2da5 @@ -8486,26 +9294,38 @@ trackedFiles: id: f1d8f5b388b9 last_write_checksum: sha1:0d1a4e2bb901eb564f5fc824183afcaf49afe0b2 pristine_git_object: fe1895910137908431f8384c6b14a9d09d2dc410 + docs/models/inputproofpointpodinput.md: + id: bc44e03105d9 + last_write_checksum: sha1:9adb039a610b7adba04c8909f9e0e96f2d6fc673 + pristine_git_object: 8486518cbb2a5778b4654a6d4830dcab87258f8e + docs/models/inputproofpointpodtype.md: + id: 894178b93909 + last_write_checksum: sha1:b8218ff1db3e5052c8ab92f63ee557e7dda68de3 + pristine_git_object: 579d2d6411157cc47991d91a2a29d45a24de54d1 + docs/models/inputprovenancetypeoptional.md: + id: 5526ba38ef9d + last_write_checksum: sha1:bbaa135fbeca1c765b1f0a31ae6fdf80d0634b75 + pristine_git_object: 83280f2ad3b4566fec7eedcc2e9b07780d4578f7 docs/models/inputrawudpinput.md: id: 881eec3dc394 - last_write_checksum: sha1:762953bd22eff24ba54035fc024b1e750db98c80 - pristine_git_object: 6f96c8fa3e5c04c8ee80cb874fa0017d3a49a721 + last_write_checksum: sha1:d7e4ae3dfa1b894e51ec15ecfba42b882a1dfb5a + pristine_git_object: a7d6d4bfd024da2d1ac49b5f8e6211071531ecef docs/models/inputrawudptype.md: id: 10e225997d0b last_write_checksum: sha1:78dd416d383b670a06786e5d6b862ffa541daa1a pristine_git_object: f8ed0753ffbff249f0ff34ee657c3bb26e8ee690 docs/models/inputresponse.md: id: 5f7c578ba0f0 - last_write_checksum: sha1:f4d2ae7f4d23f50af5d641abbd5fd796144bd175 - pristine_git_object: c5b610adaef1b490856bbabad1792cdac7a8b7f9 + last_write_checksum: sha1:a55d82bd11207335ee609d64f02afa86447b7021 + pristine_git_object: b2bd1a5db88e1329043e62f4fe728ac984068d2d docs/models/inputresponseaccounttype.md: id: 243108baa7ef last_write_checksum: sha1:8186aa7828436acbf9becbbfe421853bd1a8d3a2 pristine_git_object: d7853e302d613599daa93a54309cefcfe1c63a32 docs/models/inputresponseactivities.md: id: 64b10f186b95 - last_write_checksum: sha1:e766bdaea62ee53a8983a3a8fa12d0c35e8ede38 - pristine_git_object: fe9cfe52fa8190bdaff52e5b10088ae81fe2981a + last_write_checksum: sha1:186a7f089a1d9183b8da5e76c79605ba611062a8 + pristine_git_object: d0f3e7fada47082a6d0c7e15620299f196114126 docs/models/inputresponseactivitiesmanagestate.md: id: 03ff38483e46 last_write_checksum: sha1:3508ccf0e7d5f585b9753de77c771f6fb7828bcd @@ -8532,36 +9352,40 @@ trackedFiles: pristine_git_object: 3771f63c55b5dc5da238de9e87e730da0d63cf8e docs/models/inputresponseauthmethodsext.md: id: cba08f8bdf87 - last_write_checksum: sha1:869f16bd17b662285e725f2a8821a2c65b831de6 - pristine_git_object: 9fb9eb8c2f30d355fd2d99503917d3f98a448bb2 + last_write_checksum: sha1:96b8dc5317be913d3f447d0481a11d70281cfcdb + pristine_git_object: 47d0168b92811225fa086348cccab3725f8269b2 docs/models/inputresponseauthmethodsextauthenticationtype.md: id: 664cafe64e32 - last_write_checksum: sha1:f898c16834c95eb912e9fa90a42019d1f1d2c6a7 - pristine_git_object: a1b522d3398c8e9402a6c538ac7e0817e9246714 - docs/models/inputresponseauthtokensext.md: - id: 13d4f32818ad - last_write_checksum: sha1:510d083c971a2d7ae16096881d874e2ec17406b5 - pristine_git_object: a93ac9fcf5da56a2bbc11a0d81b9af862cb6b19d + last_write_checksum: sha1:9e0ccd73073a08534d2d5b493e99a6cc78609556 + pristine_git_object: 93c69fdeb7d1e011a6c9e7df2df799b695bb182f docs/models/inputresponseazureblobstorage.md: id: ee51939bfdab - last_write_checksum: sha1:230e337ab7ce0a6395568e0f1c0ded98778b2939 - pristine_git_object: 8bce7006951b8ce6b9f70ebcc0e7cf6db1b1326c + last_write_checksum: sha1:7c5bad8bb64deda852ef3567a5260a60f981574b + pristine_git_object: e3d539f64bb9910acbc1207faa218113c1ac75c8 + docs/models/inputresponsebucketwidth.md: + id: 1e0c877424be + last_write_checksum: sha1:342a806f8b42b92e9c12d6da65e5af3f3b227048 + pristine_git_object: 59510c567151bced35c925e9a668abb8d3c4e322 docs/models/inputresponsecertificate.md: id: a44fa4fbdffa last_write_checksum: sha1:2d9a061e0009deab68e6d4e87da2d6e23d52de6a pristine_git_object: 37d6d87188e8ae1a2eb5f4cb0845ee237825eadc + docs/models/inputresponsecertoptions.md: + id: 8ea62835dd61 + last_write_checksum: sha1:564fdf3928245d34b611f172e51da4a11892d8c1 + pristine_git_object: ea6a3306b33c084b5a51427c811b6b8dc063b25d docs/models/inputresponsechatmessages.md: id: 85fe0500d828 - last_write_checksum: sha1:a9ad65757da05cf26cf5166b07ea4acce6c1a2e6 - pristine_git_object: b11a3316f0a3ba35292c565d868d26785143bc7c + last_write_checksum: sha1:6e0c0e36d13bc4982567ccd333b539b89bcc3183 + pristine_git_object: 1b5cca5fb00fba56e69d7d407cc3a1e65a7e3ff5 docs/models/inputresponsechatmessagesmanagestate.md: id: 3c6090b18887 last_write_checksum: sha1:214496e7b72b6da0efc1ef4ff2ef617e9335df6a pristine_git_object: c5c68f0e28e5a021a65fa87638e7e0bf7126393b docs/models/inputresponsechats.md: id: 554d4cb7f92e - last_write_checksum: sha1:9e525ad260251629464856ee8b06b2c96a03c5bf - pristine_git_object: 67b3eb55d86d236b0eefecd4f60ab7afbaf6a50b + last_write_checksum: sha1:229684f16a684e4826d26aa0c4381b94fbb7b697 + pristine_git_object: d86b987488782f32bbc29d3c71b12591ae67d84d docs/models/inputresponsechatsmanagestate.md: id: 4ab1f8da7047 last_write_checksum: sha1:af1bc13a6130e1c6dad71916be0d2214365d2e59 @@ -8586,6 +9410,10 @@ trackedFiles: id: 3a0cab6f8024 last_write_checksum: sha1:0ce83f33b76c0524278de552f838bbebfdb07b7c pristine_git_object: 7a2b3841001538b8d957601e4b75ac3973f5eddb + docs/models/inputresponsecontenttype.md: + id: 55a111cc084b + last_write_checksum: sha1:89cb27ed1b3f2587d528276780354032ae78126a + pristine_git_object: 5ab384fc330db31df5b136d14de7f24013dc972e docs/models/inputresponsedisksandfilesystems.md: id: 157f47fb506e last_write_checksum: sha1:f4c4867e926578dd398a1f7b52c256c83f61a5ab @@ -8594,10 +9422,6 @@ trackedFiles: id: 70112faadff1 last_write_checksum: sha1:1990cb1c3c7044acdcf4b34ea7ce6d1976e7192b pristine_git_object: fced57786b57f5ebf94b5875a29dfdabfb73a306 - docs/models/inputresponseelasticsearchmetadata.md: - id: c75d69044785 - last_write_checksum: sha1:41f976abb365915d34f5d83d8a310f143a8f37c0 - pristine_git_object: fd57153cb4299c3eb82b810b5764dd88c59a1c81 docs/models/inputresponseendpointheader.md: id: 9687bbba16b2 last_write_checksum: sha1:8226ee0702175362c3f4c97e4d0bd427ca7431c7 @@ -8610,6 +9434,10 @@ trackedFiles: id: 0d6df7807f7a last_write_checksum: sha1:8f98c56172e94b2954bba15b59f6ce89e856b458 pristine_git_object: 78ee9f1a7aa30261049648afb2f96070ba98354a + docs/models/inputresponsefeedtype.md: + id: bb5128c35e41 + last_write_checksum: sha1:eaafc067b557515d15599870d8391343511112f4 + pristine_git_object: f370d5f5dc4f6f4364149102ac7b47061024dbf1 docs/models/inputresponsefirewall.md: id: d38828464fdf last_write_checksum: sha1:9580669facf664543aca96b5cf26e2b2b6877e6e @@ -8622,6 +9450,10 @@ trackedFiles: id: 8aec13d63119 last_write_checksum: sha1:0ead5572714f658c06c80b4f8a88e868a739506e pristine_git_object: 71c850d7483336e00d9624e433c7de013e299522 + docs/models/inputresponsegroupby.md: + id: a9981fca76a8 + last_write_checksum: sha1:59a9d29cecb9c006ecb91305f687516674636419 + pristine_git_object: 12d5b0f1a56cccd73e801b769f15dd0ecfb3260f docs/models/inputresponsegroups.md: id: cb26a8d872dc last_write_checksum: sha1:9f265d97ee8e60ebca8d87f1f53a3b48a21dbd80 @@ -8634,18 +9466,38 @@ trackedFiles: id: 0b7bfa4c1e21 last_write_checksum: sha1:8bdb5572572c1fff7ceb8a68e33c4eb6b16c8595 pristine_git_object: 24419aae8868494d3aa8651cef8c662f470c304c + docs/models/inputresponseinputakamaihec.md: + id: 4207d01d921d + last_write_checksum: sha1:3284139027b8437961fb1d3e51814c14ca9d8b2e + pristine_git_object: 8225d3aa38f209f83f176165187bcadf88e68e5d + docs/models/inputresponseinputakamaihectype.md: + id: 058d12d5df49 + last_write_checksum: sha1:3dd4f5cd0a662a2850463a9bd3547703ddaaa036 + pristine_git_object: 15c3572044cf60458c08cfcd5d724edb6c1c53c2 docs/models/inputresponseinputanthropiccompliance.md: id: 5b4a209a7a4a - last_write_checksum: sha1:2328a0265c9e09f67424efaa0577b3c8a2dce4d5 - pristine_git_object: 9b9e31c269f8ea34e8ef130c3dea1d80723c7e3b + last_write_checksum: sha1:4f52fd78b9c48fb5dabd21e47ecc58f17d601c45 + pristine_git_object: f319bf84755c8aec4bca28875ccf2f0aad0127ed docs/models/inputresponseinputanthropiccompliancetype.md: id: 49142a81cbd2 last_write_checksum: sha1:1a170d076260b881e3330a987398185658034446 pristine_git_object: f9e6710f641524bdbb8ed921c7072c6bddfca902 + docs/models/inputresponseinputanthropicenterpriseanalytics.md: + id: 49d78454af4e + last_write_checksum: sha1:5eb8b0a80cacb1cccb34f1a17f38799f87294069 + pristine_git_object: 699f70810c24cec0b5639b3dee7b3506392fbfb2 + docs/models/inputresponseinputanthropicenterpriseanalyticscontentconfig.md: + id: 9954e81007dc + last_write_checksum: sha1:3f3a2a448ea4bf4a5d9990eed516cf2346355520 + pristine_git_object: 66cae38c8f1895bb4868c444689c0d39008f32cf + docs/models/inputresponseinputanthropicenterpriseanalyticstype.md: + id: d2d60789497d + last_write_checksum: sha1:fbfa9879cde8b3291e9f8aebf60503c30db6d3b9 + pristine_git_object: 78dc2dbc343008fae282844f515e038b062d9318 docs/models/inputresponseinputappleunifiedlogs.md: id: 690bee993e0e - last_write_checksum: sha1:bab16234fc9f1ad5b85967d4d09a82c574cbbbd9 - pristine_git_object: ad2936d3b9da930e50ca31e925827c2e23b2d513 + last_write_checksum: sha1:064dd5aa7326273d0c63108729dc8ae3931f12f4 + pristine_git_object: 1501bbe8e4dba06ddb5be4eb51d531a45814b3d1 docs/models/inputresponseinputappleunifiedlogsreadmode.md: id: 7a8676c15cfc last_write_checksum: sha1:4c3e5f92ec89d78f54e5dc0d62a2442124d65501 @@ -8656,8 +9508,8 @@ trackedFiles: pristine_git_object: 97c1c105f4986736bbc381ffa66fc65ce581d3a3 docs/models/inputresponseinputappscope.md: id: 93ac1b08a7ac - last_write_checksum: sha1:5250e88dab5458c41a1df933ea30cb8e60aae00d - pristine_git_object: 7c3d87eb01b1e621e19af2c94ff304039851e87c + last_write_checksum: sha1:cd1c958e9da0d696ea217c5e88131915b28f0ac9 + pristine_git_object: 36623073707ec71c9db5cdf6e948ad32c46267f7 docs/models/inputresponseinputappscopefilter.md: id: a2decb488476 last_write_checksum: sha1:cacbfa9eb2dc9b3022cc39793d9482bbf21f6fc5 @@ -8670,86 +9522,122 @@ trackedFiles: id: c2b5bba15bbf last_write_checksum: sha1:8207a43e56110e0ad0f974b626e58ba235090fb3 pristine_git_object: dc53ef3e0b2164c53e6004c31523c86a504dffaa + docs/models/inputresponseinputaquasecurityhec.md: + id: c1549d8e3e15 + last_write_checksum: sha1:367b8abeaed483f1e1548f0aaa299e684d5408e4 + pristine_git_object: 88e7d139fcaba5a64eebf46d7bc32888253d1564 + docs/models/inputresponseinputaquasecurityhectype.md: + id: 6a3a0db87272 + last_write_checksum: sha1:3c8f7a1f9f248b2a568f4fcda944e8bee7b29de8 + pristine_git_object: 828c56bdf6bc7d791528f0dce4824d80dfc7adf0 docs/models/inputresponseinputazureblob.md: id: 4b0af8d73765 - last_write_checksum: sha1:8bbf3a3bbfaf5e3d0b7ed223f281ad3cbea262bc - pristine_git_object: c0d7dc5ec62a480e9af3cf715028f7429f69485d + last_write_checksum: sha1:1636e9f84fa36120e9ab347527995a900176915b + pristine_git_object: 8306d58bd84be5acb1292fe3decbcedd2f89ffb6 + docs/models/inputresponseinputazurevnetflowlog.md: + id: 489238f1c21b + last_write_checksum: sha1:64ad1e3afa5206e54929b6b437715f1f67495906 + pristine_git_object: 90ce2469ac678537ace22950743b1f6e6c9d275d + docs/models/inputresponseinputazurevnetflowlogtype.md: + id: e922a97f18b6 + last_write_checksum: sha1:572e8bd588e5f3b7d7dca17cc641014d82e3005b + pristine_git_object: 9f598f67e5d2e9f7e914ba83ab4f9f8c27a25248 docs/models/inputresponseinputbedrocks3.md: id: 4bfdd9701dc8 - last_write_checksum: sha1:f090fc6a93c20ad23917e4521c384d542210c82f - pristine_git_object: 2239939c64fb7a43f1468158cfa7274460648829 + last_write_checksum: sha1:e4dd8c8fce8ebc007d849653447b97440dc7856c + pristine_git_object: 974e16788fcf48a571d22f5326fb21a9087d43ec docs/models/inputresponseinputbedrocks3type.md: id: 7e6d68c2de43 last_write_checksum: sha1:0c02d214b08c145d2f3d540876e9ef62020b383f pristine_git_object: f0d5d6e4ea8ad91a7febf42f7dd854d7dac726b5 + docs/models/inputresponseinputbeyondtrusthec.md: + id: 3e6727cd48dc + last_write_checksum: sha1:eb463fb853d47c1c7e2a146644efdc59dfa490af + pristine_git_object: 206be6d024445816ddf5f301ff7ecf1f4b13e679 + docs/models/inputresponseinputbeyondtrusthectype.md: + id: 6b29ce93c4e4 + last_write_checksum: sha1:d0e7195a8144558f7a8051a0b5148f0400febd5f + pristine_git_object: 1d7c2f4f6ad8c44bd8fed6ebf3ebe38d8624f01b docs/models/inputresponseinputcloudflarehec.md: id: f96e1955bd24 - last_write_checksum: sha1:73429f64eb908e5dac474645d707253f9b73dee2 - pristine_git_object: 7b6b40e87c5611c8e8a197c378a76053638ac83f + last_write_checksum: sha1:dcab2c8faf90c2dd020d3cd726a4e1fd7505eb4b + pristine_git_object: 0dbee60cb0abef65d13a2c5c8246f8d033374d90 docs/models/inputresponseinputcloudflarehectype.md: id: e526c228e87a last_write_checksum: sha1:da53332a71bb3e54ed1502ecac80d142831eb324 pristine_git_object: 28fc4b6f6b2ce1a7ee1208617f4fcb24ffd710cc docs/models/inputresponseinputcollection.md: id: e4abbf6e006f - last_write_checksum: sha1:208a5aadb7db99d2c262a1b5ef535213a1921d80 - pristine_git_object: d738180314874a254711d37582818ff7c3f91385 + last_write_checksum: sha1:990b9a126f501d9e22e771419af5867f20cea26d + pristine_git_object: 27bbca6fc5407e2f552660baea870516fdb5ec37 docs/models/inputresponseinputcollectiontype.md: id: 5d4ee5b5f2ff last_write_checksum: sha1:dd2a52af6d151f80233aaf3ee1c3c8ba19964571 pristine_git_object: 3b0bc1c4c4324fe752679098cb490c63916c9412 docs/models/inputresponseinputconfluentcloud.md: id: 2c823147d296 - last_write_checksum: sha1:3ab2029fa57d7691e2f0f25f661d2017fa05fe94 - pristine_git_object: 90f993fbbd1f6e611182f61562cf732d27e53771 + last_write_checksum: sha1:3eecdc1b80849693d36076eec737ba6eee2dc869 + pristine_git_object: da8cb7e0c3655a261a4d8842505fc550feb4aa82 docs/models/inputresponseinputcribl.md: id: 12ac139fe1e4 - last_write_checksum: sha1:73c36ed2bfa135e102dd34f6e5abc041800f00cf - pristine_git_object: 1f9916fd4a8304e443e52c597f6dbb8624cbab89 + last_write_checksum: sha1:913ac181e821f589fd721ee6d74c9375f4d098c6 + pristine_git_object: cff696031aa53471743050432f9167173497a3c7 docs/models/inputresponseinputcriblhttp.md: id: ea15b1a97b87 - last_write_checksum: sha1:56f273bb962bbb05143508462a10174bb7fc2580 - pristine_git_object: 70a9f5b91f6b1d860a05bd73deb3f61be9657671 + last_write_checksum: sha1:40f2d802acee2d2a641ee797f81139b113b8c766 + pristine_git_object: ca3f25dd7c1f867eb8c63698a0362948f5200c0f docs/models/inputresponseinputcriblhttptype.md: id: 3937d0ea2156 last_write_checksum: sha1:7ba1d8492c8b21b5899cda16bf999ef865ea6b13 pristine_git_object: 89406541eeb8e56ceaab5496e3779e0766879fea docs/models/inputresponseinputcribllakehttp.md: id: 70d83fc5feeb - last_write_checksum: sha1:ccfebff4cfb37c96b476b2614627819b0ce4e682 - pristine_git_object: 0f4dd73cc1e85bab5ea134911fc837583013e823 + last_write_checksum: sha1:5f46082c7d463e551299633f00f88007fbda3c16 + pristine_git_object: 98eacfdbc5670b7f50a3510351a10d094af0473b + docs/models/inputresponseinputcribllakehttpauthtokensext.md: + id: b1960741053b + last_write_checksum: sha1:13847724c9649699a0ac9a6b358f26e6200f423f + pristine_git_object: 7addbd85b103ff1ace3a1c8cf5edf80311966bef + docs/models/inputresponseinputcribllakehttpinputhttpauthtokensextitemstype.md: + id: 1cf624ce7484 + last_write_checksum: sha1:6fbe54513549a3fa6e9fd05684e84d64a2583a01 + pristine_git_object: ed64c246a2076680eb93d624512b5e31d92e98d1 + docs/models/inputresponseinputcribllakehttpinputhttpauthtypesecretconstraint.md: + id: 78e85a2364c0 + last_write_checksum: sha1:cc4f3fd0d52f3ea02a6c2179ab3a011e6c4f36f8 + pristine_git_object: 67567de2cd1ea0e1ffb6a64fff109c6d9cac3479 docs/models/inputresponseinputcribllakehttptype.md: id: 5d302323ab53 last_write_checksum: sha1:7259bf06ee83f271159c47ad34e529549a4cd29d pristine_git_object: 0756da6f61e9396c3b293880e2b02ae265250211 docs/models/inputresponseinputcriblmetrics.md: id: 3425edb3472e - last_write_checksum: sha1:db029e7f01f19e7f3a20263832fecee75eaff947 - pristine_git_object: 3c0cf863e6b8e8233dac523a3b4c180555d06c55 + last_write_checksum: sha1:ccfad1f0a9f313b3f668c7ebcebe2c4de2287824 + pristine_git_object: 370827b8601a690fd67a07cdec3eb7825aa85c5e docs/models/inputresponseinputcriblmetricstype.md: id: 6a196c7c591c last_write_checksum: sha1:c056fb4095bbd1d61a4c6b740facee4d4ec81e6a pristine_git_object: 429fde657e1ed6fae4a33325f65a502835955ae9 docs/models/inputresponseinputcribltcp.md: id: 4291c90a0dcb - last_write_checksum: sha1:5ca433b53cd775ffd6805ab3eaa653844da14efa - pristine_git_object: c5fb5842c76ee1bcdf120cf4c1e17a04d22c70fd + last_write_checksum: sha1:6eec296f1f80968ac0d0eaee3b2a0c2e435eab93 + pristine_git_object: 0e032444a8e8f8f294b92c5a19c33c36f28a134b docs/models/inputresponseinputcribltype.md: id: 15977a56050c last_write_checksum: sha1:6ff94c48dbfb67864f7257cafdf5b01bfe51b03a pristine_git_object: b9cee6facafaf6e1c2f0d38f58d183a10af175e5 docs/models/inputresponseinputcrowdstrike.md: id: 0f0cab0228b5 - last_write_checksum: sha1:9cd126a7892640bdb1cbb3a8f910a5dbeca8a64c - pristine_git_object: 44d7e5d7c2d1c3c7c1b2579b3bfee505fd515438 + last_write_checksum: sha1:c8529635398723332a2518b4caae0baafa9c2fdd + pristine_git_object: c389ba68b8dd797e6e1aa425638895f59bdafc18 docs/models/inputresponseinputcrowdstriketype.md: id: 57ff9f788d6f last_write_checksum: sha1:de28851547bf0d97eefed0d747106b3a248eeb23 pristine_git_object: 78b4f24a0a3b4a9743dbafea848f43786ebdb728 docs/models/inputresponseinputdatadogagent.md: id: fa30723ba7dd - last_write_checksum: sha1:e183e9e1473e715d6fd07b3dceb22d02f91e2181 - pristine_git_object: c1f0d8529d96f9d27914036a41b644a4162b020f + last_write_checksum: sha1:34faa972452e90f5f205f65b0461c98630fd6f5f + pristine_git_object: abf7c79328a9ad495fa337b90f9eba74f031a068 docs/models/inputresponseinputdatadogagentproxymode.md: id: cd4dbf5bc56c last_write_checksum: sha1:c4672e8d7f7918eaa82d68d73f6741bb91a7c57f @@ -8760,16 +9648,16 @@ trackedFiles: pristine_git_object: 4854b2bb24bc874a836822945be8f69b7f67d7c5 docs/models/inputresponseinputdatagen.md: id: 8a31a1c700b5 - last_write_checksum: sha1:e844ef4a079b3785756575d3693dd14d974057c7 - pristine_git_object: ab8a772eda791e50a02a15f2d3c3eef017182813 + last_write_checksum: sha1:e24a277e9e6ff8d7f1a612df73d87a7ed67583ec + pristine_git_object: cb26adbe80a5bbd5ae690bba7e1cfbd211b3ba86 docs/models/inputresponseinputdatagentype.md: id: 5c18d1a54513 last_write_checksum: sha1:fc341c97c38706330ed33e49e79206729a11238d pristine_git_object: 9480c60264e2c00173d1016f63854c2890a56cc3 docs/models/inputresponseinputedgeprometheus.md: id: 5a1994e497f9 - last_write_checksum: sha1:2afd54516db8067728b634584010b31ff347f6f3 - pristine_git_object: 9848d7a7995bfe6dd8204ba112bc670b1aca55ef + last_write_checksum: sha1:e05e05f5eceab023102b50c842c266131163dfb3 + pristine_git_object: ff9caebf16791ebeeb25efd84e03dbc8ac403a0f docs/models/inputresponseinputedgeprometheusauthenticationmethod.md: id: 85ea7e0ee8c7 last_write_checksum: sha1:4eb6357b0cad0966854b4cdef162d8b9dc2de54f @@ -8784,8 +9672,8 @@ trackedFiles: pristine_git_object: 51b65e1632d64ad72d7a624074a40d0ef63f4720 docs/models/inputresponseinputelastic.md: id: 0b1b3eecca51 - last_write_checksum: sha1:578f830f94f0d20e0c4df34b0b3d38985740743f - pristine_git_object: 86cbafb9c5ec9f89aa3dcdaa47ad615c49405af4 + last_write_checksum: sha1:d2774c1b1b9d7262c15634db544539ba4a1b81da + pristine_git_object: 9b8412c106f674f89d0cac26e2124dc1b436c4a9 docs/models/inputresponseinputelasticauthenticationmethod.md: id: b48258db817c last_write_checksum: sha1:57b0a14c40da38575fd929e04df7aafafa356fa5 @@ -8804,16 +9692,12 @@ trackedFiles: pristine_git_object: c1abc1c252ea8ebf26f51a660e6eb59de8bfe4ac docs/models/inputresponseinputeventhub.md: id: d3c7cc25bf8a - last_write_checksum: sha1:781c62f90821170535f3314a9f7f41dc5e467ac9 - pristine_git_object: 4cc44cb11c7878d24684b07cf5399eefb8afa3f5 + last_write_checksum: sha1:ea9af003c374eaf38a74a96a4b5a06bd93397e01 + pristine_git_object: af7dbec0e5ddfe1336c34f94a8bfc15b086278a5 docs/models/inputresponseinputeventhubamqp.md: id: 01db0073929b - last_write_checksum: sha1:0d7a2b97522b0cc3172af591eb9350f6e1bd1097 - pristine_git_object: 15fe6418a7c585aa9b69be52e32332a305d2d29f - docs/models/inputresponseinputeventhubamqpauthenticationmethod.md: - id: 9fa6f2758905 - last_write_checksum: sha1:c29b42d96c4e07d717638285c8348386c4a93bb3 - pristine_git_object: 555a815c5f6b9b3ead5413d6c9a8e6fcf9c7893e + last_write_checksum: sha1:fb1b59e14eefa220d8a89aea2d0475f4705a0d5e + pristine_git_object: 3828775c311027c9f1189f924fb79dbb3685dcaa docs/models/inputresponseinputeventhubamqptype.md: id: 131e847832e9 last_write_checksum: sha1:3c2960fc60618e642f0d5b0b806270e82f26a91a @@ -8824,16 +9708,32 @@ trackedFiles: pristine_git_object: 23d56fc434bad615baa6225b4018be2e54a262cd docs/models/inputresponseinputexec.md: id: 5539f422fa3c - last_write_checksum: sha1:3744bbefb9ed83e246ad3194eafcf047c43daf53 - pristine_git_object: e64ddc2a634833fea491c912e938e0ad1ade343b + last_write_checksum: sha1:353ced1ad69e5d9eaae40d5bb4acce3cb4892d1c + pristine_git_object: 78577fc6f847dbdc0a8fff88d87b477a8ec453d0 docs/models/inputresponseinputexectype.md: id: b5ce24b5a309 last_write_checksum: sha1:c27e7af18f8803e92134dc8c0128ebf7e2090c96 pristine_git_object: 1c129a80e03b25926cacb68395df2c481fc4733f + docs/models/inputresponseinputextrahoprevealx360.md: + id: f857cbe76d16 + last_write_checksum: sha1:8e9e49ac6d003d7c50739742ca4270694ba8a32f + pristine_git_object: 9457ff133abe188287f6d5af980583cc8d2e279d + docs/models/inputresponseinputextrahoprevealx360type.md: + id: d086b1136c94 + last_write_checksum: sha1:2424e7da6c817a8d9e22106bfbcd0b2bb9373cd0 + pristine_git_object: 360c87de5965369e8ea5eba344b65c51c759bbb4 + docs/models/inputresponseinputf5bigip.md: + id: b3a43383dedd + last_write_checksum: sha1:c5c6122bd1820a53b174b056d5f1a0df82f986d3 + pristine_git_object: 168830667b4e5569df143e238d3030c6d87dae5d + docs/models/inputresponseinputf5bigiptype.md: + id: 0c264da678df + last_write_checksum: sha1:6dd1f659de64b49b7e99cc5bd7c90581a2ca765f + pristine_git_object: 729b9bb2462f38cc262ee2d3d9b142e9af761aaa docs/models/inputresponseinputfile.md: id: 41ea16bd1ce0 - last_write_checksum: sha1:e66db8a0b7ff7de5c92d1c577248438e0fed8f65 - pristine_git_object: 8d4a4a76aaad8a1423d11dcb6bfba4f18d47ffa8 + last_write_checksum: sha1:557449649802851485fb77fb8990a0aa15b2350d + pristine_git_object: e32a7f5204bcfa05a65e7bbdec47ebb55fd52dfb docs/models/inputresponseinputfilemode.md: id: f863e30c3fde last_write_checksum: sha1:132fd9c48423351dabd63bc30875c7216a4519e3 @@ -8844,24 +9744,32 @@ trackedFiles: pristine_git_object: 7856910692c7ccfedd32f721d3044e5b42bf3ebd docs/models/inputresponseinputfirehose.md: id: d84b2819c9eb - last_write_checksum: sha1:ca41ebf3839f65aa0cd3caec3cc850c85662fffe - pristine_git_object: 06d491e3bc9f70fa0877a4a6ae741013a0b0d8b2 + last_write_checksum: sha1:1df0db3925a02b577a0aa96696af8b5aabdf0a34 + pristine_git_object: 836840f20ca414b6fe6ab5bf1051d504e3df3ec3 docs/models/inputresponseinputfirehosetype.md: id: 7aac796c0d5d last_write_checksum: sha1:af2fa638cf1554ff82897a2fca8534dfff4b5b76 pristine_git_object: ef84c97d080fecd3bbaad3a8859552870ee26fc8 + docs/models/inputresponseinputgigamonhec.md: + id: 69310a2e661b + last_write_checksum: sha1:0520a2616053ae79bfdd937a7316e09c1c285c6d + pristine_git_object: 11142dc644b08da6a0b275df442b38a007920f42 + docs/models/inputresponseinputgigamonhectype.md: + id: 3c9597ba047e + last_write_checksum: sha1:6d91ce0aab8f10661d97c65e2b81cd9dfdec309f + pristine_git_object: 5a02515b2b55711f887bb7f24c8f1ce968695040 docs/models/inputresponseinputgooglepubsub.md: id: 9ae9fc3a9e0a - last_write_checksum: sha1:fb9c7de562b13639da9edced60b49bba28778daf - pristine_git_object: 7346b2a8941f5964ad8d301b6380f67a5193e4f8 + last_write_checksum: sha1:81984d965efdef2543250dd63878cc22b2f57594 + pristine_git_object: ed235f4570a7b69fefea8d674f73000fa4d8b3e6 docs/models/inputresponseinputgrafanagrafana1.md: id: 2e2b99e7216b - last_write_checksum: sha1:66d887bba98398ea365aede0da5450d37540dbe2 - pristine_git_object: ff814c266f772093394205e0575e4143e6c5d2cf + last_write_checksum: sha1:4e8f2728bef0660b582c9d95224e1c727650adab + pristine_git_object: 5f3659345108dc01d3ebda798087f117aeb6bf78 docs/models/inputresponseinputgrafanagrafana2.md: id: 654b82d14a98 - last_write_checksum: sha1:5ae9b8ff7a7c4754f54a152dc98cf3ee45996b69 - pristine_git_object: fc2c1b06c29484d0032dabbd6e85a5142d361a09 + last_write_checksum: sha1:6535eb95a7068a631d5445781e24dff453b3f02c + pristine_git_object: a381a7fa541ae2042153fb84496e1c7ad49907bf docs/models/inputresponseinputgrafanatype1.md: id: cf2630457598 last_write_checksum: sha1:eb50ab323c974b68e7794021f60fcd89534b3188 @@ -8874,14 +9782,62 @@ trackedFiles: id: d6be2a13c3e3 last_write_checksum: sha1:0bdb4c4664aa0e5caee0349d2dc4fd6a7b677c08 pristine_git_object: e0eadcd4e129a07be231b40e63251943823b8ba5 + docs/models/inputresponseinputhashicorphcpvaultdedicated.md: + id: 3fb4f473c4d1 + last_write_checksum: sha1:d2cf0e005b19ab95a1159dff3468e2d68073557f + pristine_git_object: 1b4228c7c572f98a6ca24a0082656a4a2a8fbb5f + docs/models/inputresponseinputhashicorphcpvaultdedicatedtype.md: + id: d171d38cef2f + last_write_checksum: sha1:edd1987b3b058b9406e8848675e0e6442a19a952 + pristine_git_object: 54997a0a36006295c862cb90a4d90f1354823262 docs/models/inputresponseinputhttp.md: id: 32896a022b5a - last_write_checksum: sha1:3270fe1c52c442f02a3812b33f5fbdedc67b0616 - pristine_git_object: 90937d83fde957785659f8a90daa23ce78238d04 + last_write_checksum: sha1:8e771ebecaf8557cbd0dd99b4671525374b29979 + pristine_git_object: 6831644f4b04e8a1bf4106f33a3e24f29139a585 + docs/models/inputresponseinputhttpauthtokensext.md: + id: bda51138506b + last_write_checksum: sha1:fb46758763ac9419c0aceed8435ad1c2ae71261f + pristine_git_object: 6bc1cf96d7516907a8bd0efca1280ae7ccfc4190 + docs/models/inputresponseinputhttpauthtokensextitemstypeelasticsearchmetadata.md: + id: 1703d4b0916c + last_write_checksum: sha1:8e1ea687e095fab72fb11beb667d86556409d94f + pristine_git_object: cb266f5bf4b8223118cbeb5bfe8c47edac2efa07 + docs/models/inputresponseinputhttpauthtokensextitemstypesplunkhecmetadata.md: + id: 73235084d487 + last_write_checksum: sha1:8c96a74429fa763345743153ea8bc68c33f1d343 + pristine_git_object: 5a69d15d412e812d6bf709e3f7c8eb3652741c14 + docs/models/inputresponseinputhttpauthtypesecretconstraintelasticsearchmetadata.md: + id: d6b2b4490a39 + last_write_checksum: sha1:0a76018dab12de6bd821c4f8658f3ac391131c54 + pristine_git_object: 50927d45e484d2c414bdee5a79fd2b328dae871d + docs/models/inputresponseinputhttpauthtypesecretconstraintsplunkhecmetadata.md: + id: fc39edb3931d + last_write_checksum: sha1:d0df0eb8c10729017e15882a5a2af17aa1688719 + pristine_git_object: 37059f94329b2b0ebbfdd6f1a53f8671f9a4dcbf + docs/models/inputresponseinputhttpinputhttpauthtokensextitemstype.md: + id: 481963138a28 + last_write_checksum: sha1:e962b2198072a345708e3dcbaf41c70b6084dca1 + pristine_git_object: 14d2ac2f4955c211c7e1bfa83f4d4f88cb9158d0 + docs/models/inputresponseinputhttpinputhttpauthtypesecretconstraint.md: + id: bfa0d1ba907f + last_write_checksum: sha1:9235e5ebe317ce7d2561f022e1e31f7c702af695 + pristine_git_object: 6b0c73ee0e08080d9c54ce6261e65a758d52d85f docs/models/inputresponseinputhttpraw.md: id: 32031f994955 - last_write_checksum: sha1:548381a4132cfd0c5dc983ad7ee24f1337d0dbb4 - pristine_git_object: 85c0bf9f94f4008568a66749de694c5890e4d42f + last_write_checksum: sha1:aefdfa625313492814bbb6e10eab1b1aff3cb1ec + pristine_git_object: 0840fe8134b282e8e5cefa89c313fbddfbf3fc94 + docs/models/inputresponseinputhttprawauthtokensext.md: + id: f238bf68d171 + last_write_checksum: sha1:013bc4af852a473a23c4b430502c35146c081bfb + pristine_git_object: ed6aa3c65bd583d0404b7ee966aa200b7ffb3c70 + docs/models/inputresponseinputhttprawauthtokensextunion.md: + id: 93cc903ae5b9 + last_write_checksum: sha1:6ba2c253269daaec0278f4414e84e8b73c96514b + pristine_git_object: bda89f2f09e0f2ed609ce1d39ecc823568270e02 + docs/models/inputresponseinputhttprawinputhttpauthtypesecretconstraint.md: + id: 80d112945893 + last_write_checksum: sha1:e745b34a1274f9cc1ccbe6cec48af25c8f1d98ce + pristine_git_object: e99dabb68baa9b2e891571ce41559872c4821768 docs/models/inputresponseinputhttprawtype.md: id: 51fe7d7ecdae last_write_checksum: sha1:0c95f5579b626711e78bcc4520030a57f8d7e207 @@ -8892,8 +9848,8 @@ trackedFiles: pristine_git_object: 4c2bbaf2906a38d1248c67e938f65c87072a2969 docs/models/inputresponseinputjournalfiles.md: id: bb6fee8f5d3d - last_write_checksum: sha1:26cc660f89f281a569f84b17c79ba2b4cd08aefc - pristine_git_object: ee1034dc95f4b042ead78319bcfefc23f9d51717 + last_write_checksum: sha1:b458b2a191221b122db883503e9e5caf8a8a5bbe + pristine_git_object: fce793605f0bea31f9044a0f4e2b8544dac353c9 docs/models/inputresponseinputjournalfilesrule.md: id: 8a2f6e89540c last_write_checksum: sha1:bf6da25766418c3eae9b27815361390949ca06ce @@ -8904,24 +9860,24 @@ trackedFiles: pristine_git_object: a56f49923091900d3c9a6c723643a2a09179e0a3 docs/models/inputresponseinputkafka.md: id: 9efbb11bd1a3 - last_write_checksum: sha1:d5d6bbcd4f55eb2ec77776aaa6edf0aaafa3e941 - pristine_git_object: d41418fd3794f156ef8d11ef2de4511440597e28 + last_write_checksum: sha1:632b7ee0887cc8fa0d4fb3e62b62d1af44b218f8 + pristine_git_object: 73269bcd53ce6c8a3c687381051bb3aee86f889e docs/models/inputresponseinputkinesis.md: id: e6f3819a50e5 - last_write_checksum: sha1:c398b6be9b901a2348871d162a22ae201eea42ca - pristine_git_object: f77c6b1177d3bc60609332bcae904db1aecc2be5 + last_write_checksum: sha1:d2ab34a3bde045ba964eb99e59733c9fa4a3faac + pristine_git_object: 82bf04713973c6b43f42302352bed9d2b7d9e036 docs/models/inputresponseinputkubeevents.md: id: b4769513d502 - last_write_checksum: sha1:1701f0fef2fc89d021635c0b9af8b1ac95eeb54a - pristine_git_object: bf522b12681a589952382ccb82e6a744992d3cb5 + last_write_checksum: sha1:2eb1c4a8922395dfa3f680ae53a676c0b018eea4 + pristine_git_object: a088280a69c7616b54a4d93d81bfca70b6005dba docs/models/inputresponseinputkubeeventstype.md: id: 3b790afa26c1 last_write_checksum: sha1:e4285bcc46691aaedea9b63e99685ecb8a78d918 pristine_git_object: 9aad877874f8eaa2695d3a6fd9611838031bed6d docs/models/inputresponseinputkubelogs.md: id: 67c40d04a05e - last_write_checksum: sha1:e3eec63bc4cbb75bb353a861076b01845241b4e8 - pristine_git_object: 2fc18b20ffdee5cdef55a95f4580e65b8a7858df + last_write_checksum: sha1:a814ed92c01cda26e4f29a0d32cc02f32e9c07d1 + pristine_git_object: c50caf9eddb5f59135f48fede11d59d4fe2ca317 docs/models/inputresponseinputkubelogsrule.md: id: ff7e007a5ea7 last_write_checksum: sha1:fbd76f85e414ed3e24131402331770beb352d65f @@ -8932,8 +9888,8 @@ trackedFiles: pristine_git_object: e3520b0dcebc722318a91b36c48b3c400b9bf27f docs/models/inputresponseinputkubemetrics.md: id: 95b8fb6d2ea4 - last_write_checksum: sha1:b9cca5cd0e34d07bccfc5bca30603e1dd48b101e - pristine_git_object: 300a06c08fc3378536936cc3fb3f3629627ff541 + last_write_checksum: sha1:da7019229a240677c642ffe06f05fc00a5570ae5 + pristine_git_object: ce5ce6b2c68dc41525f948ac789377c792279c75 docs/models/inputresponseinputkubemetricspersistence.md: id: e3c1259e189a last_write_checksum: sha1:f324f55e3d2c5881e61692c6cca49a28125e91a5 @@ -8944,52 +9900,84 @@ trackedFiles: pristine_git_object: b10f37fb2f9a5dd3f738e4aa3bd7ddf52b79d4cd docs/models/inputresponseinputloki.md: id: 1c1184c4d280 - last_write_checksum: sha1:c63728567942bcd2b63ab8ed9f657bce29a86c2f - pristine_git_object: c942381bf8f7be7d1170bb0e7949983e5557cecc + last_write_checksum: sha1:174b5ba5cf5f45c3887a1f9905f9b39bc274b99f + pristine_git_object: 72b3533195128670c313099589657da085af8e5b docs/models/inputresponseinputlokitype.md: id: f352e13f40fb last_write_checksum: sha1:770f7e7655c05bf38296e1786b3ff32c4621de96 pristine_git_object: 311fc4e989565efd0e65a2e90c0da9ffadeb5023 docs/models/inputresponseinputmetrics.md: id: 715cd601b436 - last_write_checksum: sha1:a09d81579faaf0ca1d176b53f20f53753a0ce169 - pristine_git_object: 395bc3f55c5daf3f46c13586473b2c2c9e5fbe64 + last_write_checksum: sha1:a0c30ce14a0177d543a000e478f71f1b93d22669 + pristine_git_object: 6b49c7ef68f9cdec6797cf6296b2f2346ace476b docs/models/inputresponseinputmetricstype.md: id: e842ddd0c49b last_write_checksum: sha1:4a7c2c64e35f7d041b8227ea24ffbb87acd5fb9d pristine_git_object: 76740ff8f98312447e824da7e6d0edc9b7f5575c + docs/models/inputresponseinputmicrosoftcopilot.md: + id: ebea1fc12488 + last_write_checksum: sha1:5568495bba873123abcacfc3d324f54a5948a93c + pristine_git_object: 626fa0bc660af53368279aecaf0d814b98f56d4e + docs/models/inputresponseinputmicrosoftcopilotauthenticationmethod.md: + id: 44ffd5195970 + last_write_checksum: sha1:835ef79f9e05ee865e8fcffbce30e357cce6efbd + pristine_git_object: 5034c4175ca09404586b20fb0369cd0ce8d7b3d5 + docs/models/inputresponseinputmicrosoftcopilotmanagestate.md: + id: 5861be0ee6a9 + last_write_checksum: sha1:eca6f3164dc3fd536879fc93023557a185393732 + pristine_git_object: ee9cdb0f2978097e996fc2fd1dd82b8333b51efd + docs/models/inputresponseinputmicrosoftcopilotsubscriptionplan.md: + id: 2d226834d9b4 + last_write_checksum: sha1:88131b13d120d3ccaddf295e720b61d2644761b1 + pristine_git_object: 0528aec46a87a9c326989cea247a40f5fb92e3e4 + docs/models/inputresponseinputmicrosoftcopilottype.md: + id: 67899590013b + last_write_checksum: sha1:344ff4548b9f9cc931e304112d628920bd0fe4d7 + pristine_git_object: edf4352d4670470b7960a72879fcc8379cd5a5ca docs/models/inputresponseinputmicrosoftgraph.md: id: 2e3e68f3c3ba - last_write_checksum: sha1:c4bcd84b50a133f9d7a73df27f8b314efdcd5b00 - pristine_git_object: b9a9fd9d179de1f62e011e7ff46fb42edc27f511 + last_write_checksum: sha1:043ed20068d1f0026528fcea3a1c1932cbb457fe + pristine_git_object: 8231e72e141463dd2f3347e1311bbe8d99366c3c docs/models/inputresponseinputmicrosoftgraphauthenticationmethod.md: id: 4b57e08632bb last_write_checksum: sha1:a40c31120aa67e2888c681848253edf56afaeda1 pristine_git_object: 6a6da7204ad05657cfc187e36160956be2d76074 + docs/models/inputresponseinputmicrosoftgraphsubscriptionplan.md: + id: b7406e7c00c7 + last_write_checksum: sha1:9c298c4748dd070153c58d355785048b3cd90754 + pristine_git_object: 0fc06091d70c2dff1b8650646153ec1650fc8434 docs/models/inputresponseinputmicrosoftgraphtype.md: id: 4d8dbb9ddea3 last_write_checksum: sha1:245b3a8360e9795b5582ca7eda707f7806c6e089 pristine_git_object: b2cbac665d4ba72654d2f634528491598be59e5a + docs/models/inputresponseinputmimecasthec.md: + id: 767a39df38de + last_write_checksum: sha1:85e5090da25447edb11efb1f9c7d383949dea94b + pristine_git_object: b7e61b2346f990e67aa49a6898ad439fa1810c54 + docs/models/inputresponseinputmimecasthectype.md: + id: e1f5883f7ebf + last_write_checksum: sha1:99d4637c7c6a310bec461b1cffacca4ac7a28647 + pristine_git_object: 3c34db09039f02048f862d069f2f05833d47d572 docs/models/inputresponseinputmodeldriventelemetry.md: id: 297dab7ca90e - last_write_checksum: sha1:0ffa598828ab6b175d211c7e5fd784b022d2ff71 - pristine_git_object: d82a42141ab3a35d85905f420b6564b3a65eb8d8 + last_write_checksum: sha1:fdbe8a045e3a4af3ffab83378dc4ae8c4c7161e6 + pristine_git_object: 576baefae9307e823f04760d760bca6a39b09797 docs/models/inputresponseinputmodeldriventelemetrytype.md: id: 2d090476c15d last_write_checksum: sha1:f1a22cc9f8714ab5342e6a691e85278abfd211b9 pristine_git_object: a8a11e28e278f974b26a2cd16565f20ecab5afc3 docs/models/inputresponseinputmsk.md: id: dbbf2620f7fc - last_write_checksum: sha1:f425cd854263c856aef0f6e310d9c5e534e5c7e5 - pristine_git_object: 96a78ec2edf7202cfac330ada9d94acc4c379064 + last_write_checksum: sha1:fb4db4c9827d0280ba9b7de243fbb8310c4f97ce + pristine_git_object: 729ccb868d337a8c48d321a4b692afe80b69b7dc docs/models/inputresponseinputnetflow.md: id: 72fce0f72b6a - last_write_checksum: sha1:91a366d2f7f7366bf2e96cf76bb8edaf6332a2d8 - pristine_git_object: c72161e97741f56e50164287ec6d38e59f05acac + last_write_checksum: sha1:152ea77cb77a4dac07ca60530131f3f0233f5523 + pristine_git_object: 5951532cf141dc28c4de0aeb20e457713f7ea04b docs/models/inputresponseinputoffice365mgmt.md: id: ae6863a95463 - last_write_checksum: sha1:b02f96c3dc97682b247606a2c66edede7d128c98 - pristine_git_object: e27b998ed142af26f1bd81ac306599b3e38cdb92 + last_write_checksum: sha1:c288f4adfd5b5a7bea32deedf8cadb79963b2bdd + pristine_git_object: 2cbfdb1b9ed49d6529d9a30bf3864a117bac191b docs/models/inputresponseinputoffice365mgmtcontentconfig.md: id: 776d4a5c05da last_write_checksum: sha1:3e88020d4d74a532b65b9bdbae98c72839bafc63 @@ -9000,8 +9988,8 @@ trackedFiles: pristine_git_object: 129fc9c472032cfcbade7dccfb4fcc25de0e5a9c docs/models/inputresponseinputoffice365msgtrace.md: id: 1bb749900061 - last_write_checksum: sha1:194df7a150f994ce52bf2d06f20e3f08b382b0ba - pristine_git_object: 655219070aaf6ec0d37ac7e3d243e58644a07fbd + last_write_checksum: sha1:2575d1c29465f9d4f5b5182465fc7ee0b8daf903 + pristine_git_object: e83b9bc34259d313c512a09da4ae4157241ccd81 docs/models/inputresponseinputoffice365msgtraceauthenticationmethod.md: id: 17ca20d336b2 last_write_checksum: sha1:de85219daba2d62e18287fa10d9000ea218fb5b8 @@ -9012,8 +10000,8 @@ trackedFiles: pristine_git_object: 57e0d04e4241eb7829af686f1d6a4fb75f39ad32 docs/models/inputresponseinputoffice365service.md: id: 31584a7bca59 - last_write_checksum: sha1:0b19f4325b03c2cda4f2776f16661edec755ab75 - pristine_git_object: 16508743ec7033278e49a3bd8c73381ed80e0a86 + last_write_checksum: sha1:027aefbb40e40627d1c2c4cf3a7420654dddc246 + pristine_git_object: 3c27c9506ddf530091a446f8491a1814f440f19d docs/models/inputresponseinputoffice365servicecontentconfig.md: id: 781a9860358e last_write_checksum: sha1:cd9f46995681c25c763352ed3306605789588fe3 @@ -9024,8 +10012,8 @@ trackedFiles: pristine_git_object: cd4edabd909424fd5cc377718943249948ad1163 docs/models/inputresponseinputokta.md: id: 247ab9e351b1 - last_write_checksum: sha1:510fb7e870200c2504427d699fe5a3ed1218aee4 - pristine_git_object: d8fbbc048ef4023b4efd937801dbd6d9c059a49d + last_write_checksum: sha1:87f1e0236732c948dd7e4c1293ea3e74c317a7c1 + pristine_git_object: 8da0e27d7f2769f18c636d769f2df23d2128d82a docs/models/inputresponseinputoktamanagestate.md: id: 72b9022c12f0 last_write_checksum: sha1:061b9f934773810aa1964a2780135c2f2ad5f36d @@ -9036,12 +10024,12 @@ trackedFiles: pristine_git_object: fe63a626b1144e617c9350698c133fa7d81ce76a docs/models/inputresponseinputopenai.md: id: dc27ff96e4fb - last_write_checksum: sha1:3c47e81b03c47d89a9d6f6689f1b4756c07c685d - pristine_git_object: e7b5940595935712023a3aef8cde0b4e055c1b56 + last_write_checksum: sha1:78cfeea90712aafcce97c06c461847026934bf11 + pristine_git_object: 2c889f6b8467300757cacf8c902b6681a7fb4ce9 docs/models/inputresponseinputopenaicompliancelogs.md: id: a3a7998c4b02 - last_write_checksum: sha1:7821e30c64c0466036767d426dc2f869469e1e16 - pristine_git_object: 0adeab33746de8e42822c4993cd7bc08766ebb5b + last_write_checksum: sha1:82b41ae50e1c23f3fd58949d45a4e6bf7a8bbd90 + pristine_git_object: 60e6e5306f639d03925218cb0c0176de7f21af7a docs/models/inputresponseinputopenaicompliancelogsmanagestate.md: id: 1dbb8f4d8ae4 last_write_checksum: sha1:c8699f61fa80e7675dde40754f477bebcc2e24b8 @@ -9052,8 +10040,8 @@ trackedFiles: pristine_git_object: 217fcc898706da2d168a66b1abcc2f78c3242f86 docs/models/inputresponseinputopenaicontentconfig.md: id: 143f1d48e897 - last_write_checksum: sha1:8e3c7ab781cd50522af6ba6f740375e7c9350142 - pristine_git_object: dec00373bd8f3029d32eda04a631b07922f3aa8e + last_write_checksum: sha1:6e56cde03033d934715f1312d7e3dbf46c0eb3d8 + pristine_git_object: dc4c9381cfcc02b2596bd6d6e0898164ffa16b56 docs/models/inputresponseinputopenailoglevel.md: id: bc6c55739193 last_write_checksum: sha1:28bf0be49db69c194311b4d29eeb1c108d343500 @@ -9068,8 +10056,8 @@ trackedFiles: pristine_git_object: bef6edd036e945fc972af28217bada2a3d9ede3f docs/models/inputresponseinputopentelemetry.md: id: b8712177bc5a - last_write_checksum: sha1:a49024b9df33c13488cdfec68d200691033f03dc - pristine_git_object: 9313c86c76443f11b99499f55158ca11c4b56a10 + last_write_checksum: sha1:8708d8e986d8cae579c2632a4743d673df0d2cd8 + pristine_git_object: a17bf7bd19d4390c3cb918ff36e5e00b839d7566 docs/models/inputresponseinputopentelemetryauthenticationtype.md: id: 61d698b994b6 last_write_checksum: sha1:3aa6113b04406399f4cb19362d740c81e7a753c1 @@ -9078,50 +10066,74 @@ trackedFiles: id: e5bb39524b61 last_write_checksum: sha1:62b3215a0f576aeb57a771c3be050478fd21295a pristine_git_object: 0f0e732034c3659dbe3ff206525525d41f192f7d + docs/models/inputresponseinputpingidentitypingone.md: + id: de5af9a2c6f0 + last_write_checksum: sha1:347e38194ec8b0ad20ad40930b98c5012bbac370 + pristine_git_object: bddc194639526e7d7c91e73247470d3fe2d77899 + docs/models/inputresponseinputpingidentitypingonetype.md: + id: 2ef59e46ac63 + last_write_checksum: sha1:abec1a08d7c5019f9f77aa59c918eb4d43a84428 + pristine_git_object: 3a6131f9624b1e5d349c14d1f4e2471de6a9b483 docs/models/inputresponseinputprometheus.md: id: 43b251fad9b5 - last_write_checksum: sha1:aa1766086b7393a4c4e532af2991c5322af8d023 - pristine_git_object: 36c46e3db167a232e337c3aa5966571116a23b6d + last_write_checksum: sha1:ef863592a74ffda2a22295d00fbf85cb2e77ef11 + pristine_git_object: 037f715fac9dba313bae533ec390ef4c15e04798 docs/models/inputresponseinputprometheusdiscoverytype.md: id: afa972ce0bfd last_write_checksum: sha1:c034334927d565b185938057fc36b9fb258ab69d pristine_git_object: dbcf540e8db55cef30c212c6e72a7f1dbe85da39 docs/models/inputresponseinputprometheusrw.md: id: bf7bdf36b510 - last_write_checksum: sha1:2d90fb958f395b0e47b432fd312ae7fe529705a4 - pristine_git_object: 2a6303522344811971f1d183bf1f530e3ed377d4 + last_write_checksum: sha1:6236a07ceb1bce26b4170a058120317a3f501937 + pristine_git_object: b79aada2389beb821f68d71a763f2c1a1d5c5222 docs/models/inputresponseinputprometheusrwtype.md: id: 979d58eaccea last_write_checksum: sha1:102d77ef137be11fb6384cabfe07f154c801d6bf pristine_git_object: 10663d03f43823d61353e14520a17b0773c4d906 + docs/models/inputresponseinputproofpointpod.md: + id: 88946d70bbbf + last_write_checksum: sha1:0afd6baaf5fa198a25614e5a8939d018256f9955 + pristine_git_object: e3764cda708f771aff074501c44506ecf23aa357 + docs/models/inputresponseinputproofpointpodtype.md: + id: c7e8b3196a43 + last_write_checksum: sha1:55d842a9115465ab139b239a82a1feba0fcfd972 + pristine_git_object: 4d4a39aeb20ec72d104c7b281c8969c083c14679 docs/models/inputresponseinputrawudp.md: id: 2cd092b2b9ad - last_write_checksum: sha1:e31b29f6784e67fdde53ac56f3f29bedac3e40a7 - pristine_git_object: c4de5dee17a9c824ddd4962edb1cb111a61c909c + last_write_checksum: sha1:e0d5ddfa1ef5783289bdbc59fe5efe958a6ee2aa + pristine_git_object: 737c87819b6a5c717afbc54aad556b256bf5f045 docs/models/inputresponseinputrawudptype.md: id: b20ebfcc4b59 last_write_checksum: sha1:e4e85170d2a11663f37597cadbac1918412a5c62 pristine_git_object: d70e78550f536fc799e57ec8d9255fa0e57357c0 docs/models/inputresponseinputs3.md: id: b85de4592447 - last_write_checksum: sha1:b151896230e058e937a5754098b3ca944cedcc57 - pristine_git_object: fd4cfab432d09110495f26ce7b1549ea331128e7 + last_write_checksum: sha1:7710684cd9f1771768053cf984d44b56c2ee8897 + pristine_git_object: 0de8e92e8042b297a9e55953b56807bfb5db83b9 docs/models/inputresponseinputs3inventory.md: id: a4f059f4b232 - last_write_checksum: sha1:27cb7a17eec79bb20e567ad816f2308c77e36590 - pristine_git_object: c7310aaa8131141517a2fec1b34807861d87ac22 + last_write_checksum: sha1:380a7c917f5fef062f3101eb9d05ee763459070c + pristine_git_object: 4cc09d5fdd627c220b6ebef39149cd0d54b8006e docs/models/inputresponseinputs3inventorytype.md: id: 91556b64b216 last_write_checksum: sha1:95e01d26ea28069018301359608aad64f2e8eba9 pristine_git_object: 2a31c4a32c3afa80209770e982908c9384032800 + docs/models/inputresponseinputsailpointhec.md: + id: 8f3ccba93760 + last_write_checksum: sha1:9d77e7170f49cfd5cec00b77366705b422708945 + pristine_git_object: 2a6945d94f19056524d8063e967b6afea196ace1 + docs/models/inputresponseinputsailpointhectype.md: + id: 91b414201cd7 + last_write_checksum: sha1:c6108f1cbfe3f059b8abd42adf1852f830a65ea3 + pristine_git_object: 1abf476198a01ef323544f29dcb79a154953dcbd docs/models/inputresponseinputsecuritylake.md: id: 26402e9ba01a - last_write_checksum: sha1:a8bce1c3a39d9a7f27af8ddcc19139401056cbe5 - pristine_git_object: c545fa922dbc41381cd165da8625b22526f4d42d + last_write_checksum: sha1:af40f9d356a4ac98fa6903c4a82ac2e6d7e7b592 + pristine_git_object: 9953446f283720e6ced5c79d16281922da079711 docs/models/inputresponseinputservicenowtable.md: id: 68bb88ee164c - last_write_checksum: sha1:726805f530b68b65b8ff9638a23fbad9299a237c - pristine_git_object: 6c6374d6212fc88f14e0f2d7b83290d190581616 + last_write_checksum: sha1:16d75774163135d2ee1f65cc16edbf869ac944d6 + pristine_git_object: 52d56b3a1a24bc9a8a02eb530178745eca1978ef docs/models/inputresponseinputservicenowtableauthenticationtype.md: id: 407f79a974e0 last_write_checksum: sha1:5846ad430067ab3f75b2b43d46b439c0578ca522 @@ -9136,32 +10148,32 @@ trackedFiles: pristine_git_object: 09c31a1088f99b038aaf0336d74b5af122db6dc2 docs/models/inputresponseinputsnmp.md: id: 80be6692199e - last_write_checksum: sha1:47d2767916d2656764c90d71faa1b322809f6bec - pristine_git_object: ae4ea125be252034e87d3ce65479ba536492eb3c + last_write_checksum: sha1:ea72dddc5f585c66da6894c66f8c4ea93a0ab3c4 + pristine_git_object: da72a93518400308cd6291a78b5506bbb96f56a3 docs/models/inputresponseinputsplunk.md: id: a0fdab04c301 - last_write_checksum: sha1:4c8a14cc1402bae07ea2a39bab9068e7ff746bda - pristine_git_object: 9449a75c0f7af03f7fdc24a28064b965b6516e93 + last_write_checksum: sha1:77084e1d1d774e7b525147513dd7613a4b70b9cc + pristine_git_object: 602978ffb5e219992b88125f5f5aa9c8edfabce2 docs/models/inputresponseinputsplunkauthtoken.md: id: f37eb9b7a925 - last_write_checksum: sha1:f00793b9b80be138ed9d17e8e01e31a3c3090476 - pristine_git_object: ac37aed02380f0a0f54d4b6cbfe5989c387a6f99 + last_write_checksum: sha1:23d019454898409522d6f651335c8f5e6af6e7c4 + pristine_git_object: e4c0043da4c050c3f31135c58f06a221d89daf40 docs/models/inputresponseinputsplunkhec.md: id: 0acbcb91a3ee - last_write_checksum: sha1:0d9c8079383bf0498aa93c715eaf0900a631df22 - pristine_git_object: ae5f2be6f40cba6ff2b9b0952260a903f955b3a7 + last_write_checksum: sha1:f6fda3097c0b39625399010dede66fe4f08189ae + pristine_git_object: 8a1e1d307ef8c12c1807da98278f4992686787c9 docs/models/inputresponseinputsplunkhecauthtoken.md: id: d2cff08efd0e - last_write_checksum: sha1:b324e659171b233448f88b28290e4c0386b780e2 - pristine_git_object: 53767d5cc35b731e0b2b8580b67d5f5418707af9 + last_write_checksum: sha1:e7952a2e6948a38425f8c3eaf3dda225656bc1e3 + pristine_git_object: 2f8d8944f29e7d08ed1c59e5e4184d751feddb34 docs/models/inputresponseinputsplunkhectype.md: id: 4a3e902f96ff last_write_checksum: sha1:ec5bf03380020beede24ba59a024336dade42c1d pristine_git_object: 4828498ced3047267fa6b8214bd1b7e253a95331 docs/models/inputresponseinputsplunksearch.md: id: f2444d56ae10 - last_write_checksum: sha1:920b96dfdd7cd7cc68c13c75cb21eace454b4cb6 - pristine_git_object: 2e786d7a39fef8f47abc1cd8de910e530ff210f2 + last_write_checksum: sha1:f77352e4a4c404b06cd3cafee1100062b6655f46 + pristine_git_object: cb9e523515b06fcb4ae7094bbe9e8f9032f22005 docs/models/inputresponseinputsplunksearchauthenticationtype.md: id: 97f50dd6c585 last_write_checksum: sha1:4f83e65ff639faf8813e8e4014853de516da78f0 @@ -9176,32 +10188,32 @@ trackedFiles: pristine_git_object: 58a27b6145bf72454e2041ad8ffa9be02c04bde9 docs/models/inputresponseinputsqs.md: id: 0f2dc0253f4f - last_write_checksum: sha1:ae612ae2290eaecf7c68801f66f79f70069aa8a6 - pristine_git_object: bb2ee0625529676ba5bcc97c0ad763d8260f33d0 + last_write_checksum: sha1:6871b28ddc4f554d7316c5410fe27edd7941cb99 + pristine_git_object: 7a008ffc254fe1172f814fb946367d8a16ac505a docs/models/inputresponseinputsysdighec.md: id: 2677b4c290c5 - last_write_checksum: sha1:f9f3414e25df9f7a47e06d6d53617cc9885071be - pristine_git_object: 2a5fa13132b12d8e295a13ecb7dc45c1061b4c6d + last_write_checksum: sha1:a4831ada1082a8797c2247786cafb7b9277d2014 + pristine_git_object: e06b54d5e8da76bda656e6bd9d61d368de9ca70e docs/models/inputresponseinputsysdighectype.md: id: d111ce329a38 last_write_checksum: sha1:2c10049d9710a076e9e09ed7875d6b034425bce8 pristine_git_object: d4ebf8e0d58a296aee51b572f91d38613e5d568a docs/models/inputresponseinputsyslogsyslog1.md: id: 7622100ea2e4 - last_write_checksum: sha1:39339e9ba9f544c3ac09c26171e1766b6e2775c4 - pristine_git_object: 3e2a9c1268c360be69df904f26078c2a9e43b82d + last_write_checksum: sha1:a0a41dc05372e23f7bddd8cd3b6646297b24a2cf + pristine_git_object: ca855aafcf60701f08116924dd7f6a1ff66fb62a docs/models/inputresponseinputsyslogsyslog2.md: id: 0dc7e321cc17 - last_write_checksum: sha1:4d73768afc0fea953a19587b53844ddf90fe6c1d - pristine_git_object: 1b974a7b48b66e973f1d6bf001b1b3ebbb11af04 + last_write_checksum: sha1:4a162d851d83a6e67b939905aa7fb89d7295ae5a + pristine_git_object: 1d17406a3cb74128caedcba5dd6ea327a390fd2d docs/models/inputresponseinputsyslogunion.md: id: "863622975e42" last_write_checksum: sha1:08f172644bfea8c9f01c07b1a158e2e6b3291a2e pristine_git_object: 2d2a321776f4e6af10b18b417fe29c0b8dfce792 docs/models/inputresponseinputsystemmetrics.md: id: 82bbb136ef01 - last_write_checksum: sha1:a1a4b6006115f455f9768ad5e5bd0154c1fd1f3a - pristine_git_object: 2f7e7a65fe429d299a546d8c10c28d09937f1b3a + last_write_checksum: sha1:339075269f36bd02c6485b98f17c43b4d2534b42 + pristine_git_object: 103dcc6f6e37e1775984fc9fa8067488cbf9da9b docs/models/inputresponseinputsystemmetricscpu.md: id: 5988f5f95804 last_write_checksum: sha1:c32037d23e4b2da06d687cb9f29e6d78583e0d7b @@ -9264,8 +10276,8 @@ trackedFiles: pristine_git_object: e677037e5408a15d91339c6d3ff4962a7c66be3d docs/models/inputresponseinputsystemstate.md: id: 15acf4165392 - last_write_checksum: sha1:f24ae6ee6786c30a82a082c2005cc8df8e86227f - pristine_git_object: cdb0dfdeedb2748ca93274bd53d897371121603f + last_write_checksum: sha1:aeacf833e1a7bdfeed3ba39eecbf37a2f30e6ad8 + pristine_git_object: 8cce157b0c9e8333266c240175b27d4365969d5a docs/models/inputresponseinputsystemstatepersistence.md: id: 1519aee4d4d5 last_write_checksum: sha1:3f9bf424b605d0e1ece4cc4140c24b910007f908 @@ -9276,40 +10288,64 @@ trackedFiles: pristine_git_object: db2c59f97b3d275be650292dc4fc594dbc22bd60 docs/models/inputresponseinputtcp.md: id: ad1be6317600 - last_write_checksum: sha1:1e3ac0bc59f43bb6657626938072023fdb0f3abb - pristine_git_object: e99aa450678ce715bcdf511ac030b97bacc34752 + last_write_checksum: sha1:c8bc0dc704b3a285eb78c05db03b4c891d929d92 + pristine_git_object: e0c997c8e26fe5771443d04b0135ab55fdaf91b1 docs/models/inputresponseinputtcpjson.md: id: ad932982073e - last_write_checksum: sha1:28a5e39682d152674d63293c17d567360610849d - pristine_git_object: 2995610f1d7653f4afb47e7e32f68b92fc083ed7 + last_write_checksum: sha1:e64c79e64829d68383fd28bc144a6998535436b6 + pristine_git_object: f7b5842599efb7cab415366acba1f8fce580e3a0 docs/models/inputresponseinputtcptype.md: id: 4bf6dc372050 last_write_checksum: sha1:c598e5185492c8bc6d7d05ff342835dbc35d8785 pristine_git_object: dc1271ba7514e47550898fa0796fdabc7916994f + docs/models/inputresponseinputtrellixhec.md: + id: 63d51c5d92a8 + last_write_checksum: sha1:065ac647429603fad03786e7068a9855640e4034 + pristine_git_object: ae32fdb11900c09f593fe67665e33d8a5bc67e6e + docs/models/inputresponseinputtrellixhectype.md: + id: 63b52b414ebe + last_write_checksum: sha1:d835d16ade06242cf6b2e77f37c96707e749f677 + pristine_git_object: 54dfe99ef731429b5d3657fe6f37b0c3e292580c + docs/models/inputresponseinputtrendmicrovisionone.md: + id: f0a546c7781d + last_write_checksum: sha1:a56623e5f733415a85553381ac55f7fb5ed7bdb1 + pristine_git_object: 605335bb8aa3f6f2ba37fb1a46518e788caef0a6 + docs/models/inputresponseinputtrendmicrovisiononetype.md: + id: 54f80e36eba6 + last_write_checksum: sha1:b22546516f00e2ef2e548d1f705b80174d817ec8 + pristine_git_object: 752e98186779c6bb1b141180b15355dd692ec232 docs/models/inputresponseinputupwindhec.md: id: d6a4f89c38e0 - last_write_checksum: sha1:efa8d9545a1d71b2aba483e7cbddd445eb25df1e - pristine_git_object: a3fc3932baea01abad39be90ab84d706294ee692 + last_write_checksum: sha1:31d2b52888a534e29940cc05ba3aea7ee7720c9c + pristine_git_object: 6303459d16355dc50658b6c5047fadfcdb51a63e docs/models/inputresponseinputupwindhectype.md: id: c738a3eb1911 last_write_checksum: sha1:4a4882f9107107ccaac1d5d75b0dd58c27c112b7 pristine_git_object: d3efb24cf080d05983fc55430b034f7fece118cb + docs/models/inputresponseinputvectraaihec.md: + id: aaaac38cfde3 + last_write_checksum: sha1:60ae1d0c9d5fb8ff30dfab95d23804c87326fb4d + pristine_git_object: f20b6c8da4b4883c26d9e60dabdcf5d5df7862a3 + docs/models/inputresponseinputvectraaihectype.md: + id: 1252aed5f432 + last_write_checksum: sha1:b75621a5a7a0d6213a251ebda408bc32b7c9478d + pristine_git_object: dda1e5e2623d92b586f6f04441bdd80137486ec1 docs/models/inputresponseinputwef.md: id: a975c793c310 - last_write_checksum: sha1:9dfbfc9ab47c0c85403cd32dfa632b6dcdebda1a - pristine_git_object: 216a4340201f7d984527479515950a68cb8f5e07 + last_write_checksum: sha1:0b91b6d3d3a5a2523c6b7e6266a85ca8f9323634 + pristine_git_object: 9d0b400dfae1420761e65050c8d4eda57ea70116 docs/models/inputresponseinputwefauthenticationmethod.md: id: 3292ab5f0e96 - last_write_checksum: sha1:a3d6a948ee2c5f4c652049afe2eb0b42bcdf307b - pristine_git_object: 137c5e57361571e17c62d1b29dbed548c7065b4d + last_write_checksum: sha1:98bf610cf95bd538deb9aa2976ee60325eaa7bb6 + pristine_git_object: 944fb237c7934ae34b801d8eba4480228a2399c6 docs/models/inputresponseinputweftype.md: id: 97a4aeb672bd last_write_checksum: sha1:75134fbef92cf64549fb04329c60a1ea51f957cd pristine_git_object: f6b84618a3d5ec26e1fb1fa7c796b04940156e83 docs/models/inputresponseinputwindowsmetrics.md: id: 746cda32240a - last_write_checksum: sha1:d2f80e013616907b6f19da3354528a8c4baa9f11 - pristine_git_object: f095af6cf202fc2d1b426f810e738ca6fc3936d0 + last_write_checksum: sha1:edbd0b743e2f77a2c6acfceced75651662b60e61 + pristine_git_object: 1549ce9efcc964a2ab348f76d78a9ca40c195dd3 docs/models/inputresponseinputwindowsmetricscpu.md: id: 272a41a35291 last_write_checksum: sha1:24ae1035e44889c631b0281373a2c9e3aa8489c2 @@ -9368,8 +10404,8 @@ trackedFiles: pristine_git_object: 99fc8c2591ea273471d7a524ee0636d1e00a4028 docs/models/inputresponseinputwineventlogs.md: id: 87b74b9dd640 - last_write_checksum: sha1:ced20bb5e85a1d07f4994c3ddc739f8b8b1aceb9 - pristine_git_object: 3d59974dfc0b4129fd18a2d1788c3c40cfe92c6e + last_write_checksum: sha1:0b21bae862ecb7bc4dc0af883634ed60d132ef56 + pristine_git_object: 26c149965de7064d92e867e2686c028ffff0a306 docs/models/inputresponseinputwineventlogsreadmode.md: id: b2a56f5908ff last_write_checksum: sha1:276ed88b0aa85f435cd751add0f7197ed6c56e96 @@ -9380,8 +10416,8 @@ trackedFiles: pristine_git_object: c291e883eb410746564030d8c665e52b731d40f9 docs/models/inputresponseinputwiz.md: id: 98283c848b73 - last_write_checksum: sha1:56800cfdfd8fee1812fd24c386c81bc5194a7512 - pristine_git_object: 9d8c2c3c437a4c8fbeef50c100ab54e1cf36bb0a + last_write_checksum: sha1:0a86ec698b2481443e06adb9604f8b3fd4f774a4 + pristine_git_object: 97929b915395e1f2ee1b4ddababd1a08696ccd3f docs/models/inputresponseinputwizcontentconfig.md: id: 4bd9b3949ebb last_write_checksum: sha1:72bc9dc125f58f6ab11d5f061270512fc3acfcb9 @@ -9396,20 +10432,32 @@ trackedFiles: pristine_git_object: 4d323f4ec434880ca8a419160233ed4b4e78dc97 docs/models/inputresponseinputwizwebhook.md: id: cca05de9005d - last_write_checksum: sha1:23852916ac9f68a7818fad525630f40c8e029dc6 - pristine_git_object: 6e9b01472b7942c33cbd5b5e9d13dafb6a44f02a + last_write_checksum: sha1:16b7165e8d550f82c747d0151441705fe622ef8d + pristine_git_object: cf9623bdda6e1e629bee7bf4247c6676eadb9c58 + docs/models/inputresponseinputwizwebhookauthtokensext1.md: + id: d4c9d1f35d21 + last_write_checksum: sha1:4e024d0b19e37d1168fee1677cd2cd873067d45e + pristine_git_object: d0ccc1dd622df1c400bfc5f6c7796c5154fabc6b + docs/models/inputresponseinputwizwebhookauthtokensext2.md: + id: 3e2e88887b01 + last_write_checksum: sha1:495899d8365fefeaafecf17a982b2ee2101cac63 + pristine_git_object: c904bde47541dde5f74eff32ed031fbfdf68b2b0 + docs/models/inputresponseinputwizwebhookauthtokensextunion.md: + id: 4735cdec6895 + last_write_checksum: sha1:f4812f62c4846e359d9c43e6d5a5df92ef0ba6f0 + pristine_git_object: 32ae88ae82642ff5a4750621e97fef4e76691af7 docs/models/inputresponseinputwizwebhooktype.md: id: c66dab86bcdd last_write_checksum: sha1:85310863d39b12a0aeeb8579459b7a26dd0e8974 pristine_git_object: 351825ffe68cedd189806e00577119b622e0135b docs/models/inputresponseinputzscalerhec.md: id: 2d9f6138d565 - last_write_checksum: sha1:c16c6c111602ddcf09f8d645a7b3fbc13da07cda - pristine_git_object: 50deab2d1e4bb2f78e15ab985e6ef1befa319cfd + last_write_checksum: sha1:8227748abae75d3dff07b2315f17b14b15b2fa07 + pristine_git_object: 24b923544ac53df4f1c0f04e9a9ee73b48bfd1d4 docs/models/inputresponseinputzscalerhecauthtoken.md: id: ac5599d8ff36 - last_write_checksum: sha1:b3beb91aa2b259b8886a42301340f9cd4569e78c - pristine_git_object: ca9698697228edcfaaf8e9e19ce243540db89f33 + last_write_checksum: sha1:cab8f707b14823f45b6cf3333442778f0a9c77b0 + pristine_git_object: 63b405231e1d2f599262dac2b5b3b208afc886ba docs/models/inputresponseinputzscalerhectype.md: id: 6e2b6960c37e last_write_checksum: sha1:e80148b0d22f8b661eb571b8c3ef4c9327ec57e4 @@ -9476,16 +10524,16 @@ trackedFiles: pristine_git_object: 8cb57c7de5d15bdaba8094849e1655081b3ed37b docs/models/inputresponseprojectdetails.md: id: 99fc1d5f9e85 - last_write_checksum: sha1:a009ee5fd0bd493dd01dc78c8b267fccda492ec7 - pristine_git_object: d7d1fa8a9dd06fc3e96c46a98866df76bebed4a9 + last_write_checksum: sha1:2a6d63f7f3c4a072b28b25c826bb3592fcaa2f0e + pristine_git_object: db3c964224088a7c32517b20031879fd553e66ab docs/models/inputresponseprojectdetailsmanagestate.md: id: 54a67a9da6a6 last_write_checksum: sha1:6b60e4089a4dbe8bcf126e0c4879e9c05f090034 pristine_git_object: 22207ec2589b800d2f60a2f9eaf83e960220e7c1 docs/models/inputresponseprojects.md: id: 5e08328fad59 - last_write_checksum: sha1:aa9c6900f556c6b8d11ab4bb2f2472df2ccbddc3 - pristine_git_object: 86e248d7bd60791e259cab11768cc86ae2904fe8 + last_write_checksum: sha1:2650cf586d6ccd5767296435ae826232d517e64f + pristine_git_object: 25e26383a3579f3b468869c4a0b04403fb78412f docs/models/inputresponseprojectsmanagestate.md: id: d7542ce49819 last_write_checksum: sha1:0b995580f524171b76aabc9b710caa5c7d754583 @@ -9518,6 +10566,10 @@ trackedFiles: id: fee741666a58 last_write_checksum: sha1:bcaa2f5dfdcd4b782a9ea0b7cb462d0fbcb93778 pristine_git_object: 801f55d18a130389e0aa6d24e67c3a3ddcb68d36 + docs/models/inputresponseretryrules.md: + id: 70f806ba8b95 + last_write_checksum: sha1:8b1dbcd170669c65e741d7d57b560e677af2b813 + pristine_git_object: f88179896c034ce77fbd94cbbf47a69b462748ac docs/models/inputresponseroutes.md: id: c42362d91b10 last_write_checksum: sha1:562ec97214fa869e40241a05fb3edd99a81f9b75 @@ -9554,26 +10606,18 @@ trackedFiles: id: d93e5ef07446 last_write_checksum: sha1:b6288736eafeda18068fe9496f41f3dafb5e2262 pristine_git_object: 49dac488daaa3583e2b74a9cacbf1c418a45d318 - docs/models/inputresponsesplunkhecmetadata.md: - id: ebbbf1ee13ab - last_write_checksum: sha1:da0cc8122c4d9eb4c12401e2785304f11ea601c6 - pristine_git_object: 626a53bd3f7010710dc5d792eda275282a458e78 docs/models/inputresponsesubscription.md: id: 543d57e58844 last_write_checksum: sha1:65361594657fc20126e667305531a5603b4cc4ba pristine_git_object: fdfc4a3a252866ae47def2fa768700488411613c - docs/models/inputresponsesubscriptionplan.md: - id: cde92c7b2b27 - last_write_checksum: sha1:71d09002be3623a9280ce3a4357e72dfa23f937e - pristine_git_object: e641516ee486e8408a8dc6c2f8b03b0037581459 docs/models/inputresponsetarget.md: id: 20073a4bf2ea last_write_checksum: sha1:62b3931f62d734a0a50c3ae8aca43b46f00e76ef pristine_git_object: 70e6ad6b812e7165a18f2d524a7c4884fdaecbf1 docs/models/inputresponsetlssettingsserverside.md: id: 11633401d38c - last_write_checksum: sha1:0faa4b1bed6cebee049b6d98ef9fce328a00c81e - pristine_git_object: 6c89a98edb906a4eb01152be82e8ad70506a845b + last_write_checksum: sha1:fffd272cb4649ac8b048e5e96592b2d46c6e5f7d + pristine_git_object: 6eb6257a9d0fe48020777141b19bc7827c233925 docs/models/inputresponseunixsocketpermissions.md: id: fb38c1c50163 last_write_checksum: sha1:12b075e6e9c26258041065d6577784bab5085bb8 @@ -9582,14 +10626,22 @@ trackedFiles: id: aacd0f26c598 last_write_checksum: sha1:ae216984a792274b12b04ae50e69771e3abc85fb pristine_git_object: 478d6472445c80a6c1d2e26b9d1cf93ffcd8bde1 + docs/models/inputresponsev3authenticationkeytype.md: + id: dc23351b945c + last_write_checksum: sha1:5f3b5f39bb2bcb4bdff4a498d4acee78e44e8b01 + pristine_git_object: ae6c69d27be947340be0a4614dea47826dc4ad94 + docs/models/inputresponsev3privacykeytype.md: + id: c76cd85d9297 + last_write_checksum: sha1:8faa5d0dbe277de9fb822ffa800737fe5fa11f46 + pristine_git_object: 4b8971a9e51e8694f2443f4eb2d07f1ce26a960a docs/models/inputresponsev3user.md: id: 040d021fd105 - last_write_checksum: sha1:d6e5f5421b564f856ac6e6acd74d0977c4d0cb02 - pristine_git_object: e26bae7eeba2fd4509600260eeb3f0c184ad44d2 + last_write_checksum: sha1:41c691d05663f306e72b1dabf0a95d9b3a70e4d6 + pristine_git_object: d04e959f8ce3926c32439ba1297da50546e32018 docs/models/inputs3input.md: id: 99897af623c5 - last_write_checksum: sha1:abf5a6270b1e89df1e9717d60fd8c8f94d03db6a - pristine_git_object: 183c61364ed47409adc70cdafc23220221a0db97 + last_write_checksum: sha1:3884466016398cfcc959d57bea445ef6bf04f232 + pristine_git_object: 347ccdefaec6c5a69918da5f9f8bc199b3ab55e9 docs/models/inputs3inventoryinput.md: id: 8210fbb7cbac last_write_checksum: sha1:c81de83625e0d6dc2bce3bc116891c3a18bc6bb0 @@ -9598,6 +10650,14 @@ trackedFiles: id: e2f1705fde98 last_write_checksum: sha1:1a804a6b34e16d5f900087ff844b9daebbb632a4 pristine_git_object: 8c9c1879f20e1045e34474ae73c42dd4aa89f8a9 + docs/models/inputsailpointhecinput.md: + id: c596d01e7ce6 + last_write_checksum: sha1:527602ae8ab16f2adb96a1dbe029413416d2eab7 + pristine_git_object: 2fb6e4ac6580db99a423c411d19931f5ee8793dd + docs/models/inputsailpointhectype.md: + id: c0f94caa053a + last_write_checksum: sha1:9329ac396144157e5c471c98b6783c3aecee1183 + pristine_git_object: d1410c51ad99a791ab84c1de9ba43e0ffe37268e docs/models/inputsecuritylakeinput.md: id: e987c57b2913 last_write_checksum: sha1:06b879277d60423345d90ee924fb249e8a0ad85d @@ -9628,36 +10688,36 @@ trackedFiles: pristine_git_object: 6d9676c2beb440c656c5638e1f26b9ee9f018af9 docs/models/inputsnmpv3user.md: id: 55ae7b681a1c - last_write_checksum: sha1:b7c2c9ed6570a5c26e1727d7adb48ffe35997401 - pristine_git_object: 6fcee1f558fabc8047cc7850e6c5f5d675ae0c07 + last_write_checksum: sha1:c4f09a69c4eaf7ea14c596577d1d4b3f98205227 + pristine_git_object: aca5575c94c53f13b656d741726ebf11f09e1a5b docs/models/inputsplunkauthtoken.md: id: 747e04ea508b - last_write_checksum: sha1:d30a331f60978eefe5129f18f202b1299b62f8a0 - pristine_git_object: 0ada1a3b82d0464aafb3539297369c162c417145 + last_write_checksum: sha1:f79d864d0d4ea7b96b77dbec64ccc4fb3baddc28 + pristine_git_object: cdc8c357779bdfe9b1ba325e0bab670846cda861 docs/models/inputsplunkcompression.md: id: 14bb9272124c last_write_checksum: sha1:ea17fc8c41de0748ced30aaabec3ddb8cc12e90a pristine_git_object: b3025acefc243e35506eb4e644bb5d1110d9d036 docs/models/inputsplunkhec.md: id: 6f0f9ba65c23 - last_write_checksum: sha1:f14723a83f07852158b29ec757a91c13b3ac1af9 - pristine_git_object: fb72a9411f26af71c92e6e945c126afbd793f7c0 + last_write_checksum: sha1:a551c02f3783cabbf2019910bc6f815b811d849b + pristine_git_object: 3962a88054e5394a1310e6544c1f3f35f297f4e2 docs/models/inputsplunkhecauthtoken.md: id: 1c8d0156fac8 - last_write_checksum: sha1:a4511a70572d62054002784a4c8186621f84b8f2 - pristine_git_object: 7da53e6ec8a52d95bada69a294acb1924015e3ef + last_write_checksum: sha1:ab597c92dec10553d0802f379f0847e29495077d + pristine_git_object: 869610434af2e9daa19997f68dd7422116acec9b docs/models/inputsplunkhecinput.md: id: 6404de9c4ff9 - last_write_checksum: sha1:e8683cf7dfe69f8d12773317a0b14c3b6bf1bdca - pristine_git_object: f3f0d23a2009782e4cd46e6e004ca14d663c52d4 + last_write_checksum: sha1:f68b0c22da92a27d10db674132c6a41a02619540 + pristine_git_object: 6666075f59bca0f6de4b1fcc625589d6aab42d69 docs/models/inputsplunkhectype.md: id: 9721fb059b30 last_write_checksum: sha1:2e4235df36b7160fdb0e134410d6f9cb18b09236 pristine_git_object: 658f2ea7a165048e3874c27ef1fcb9e3d391b2d3 docs/models/inputsplunkinput.md: id: 691797551dca - last_write_checksum: sha1:469ac502407346c360410dd0d5dd5554dc85f8ed - pristine_git_object: 1225f6bf73c45a5f8dbeaaf3ef8fc6fe09721a4c + last_write_checksum: sha1:34ae587965b4186227ea183cf1008d451d94e97e + pristine_git_object: ab41c802a21a23c96485a9dd3de2ef5c36e77db6 docs/models/inputsplunksearchauthenticationtype.md: id: 13b9e53ff6d5 last_write_checksum: sha1:1127f4d0875550f2fe2bb8c26ef2200b9782bc4e @@ -9676,8 +10736,8 @@ trackedFiles: pristine_git_object: d378154ede068790a496ad7a698620512097077d docs/models/inputsqsinput.md: id: 3b20c4ecb524 - last_write_checksum: sha1:8fb86d874873597f4bffe65035955f7e75f9e779 - pristine_git_object: 74556802cc0487349eaa98181ca92f18a24193da + last_write_checksum: sha1:05fba8b2f9e90eb437a26197a6640def77e3b4ce + pristine_git_object: 121b88bc266b8c83f02747998591e248eba18249 docs/models/inputsqsqueuetype.md: id: 1e849312572c last_write_checksum: sha1:af6d11dd5026d55346203c70344dcb19b4579e22 @@ -9700,12 +10760,12 @@ trackedFiles: pristine_git_object: ece4988b207cda04219ad687bad31193cbef89c5 docs/models/inputsyslogsysloginput1.md: id: f09aa6afe151 - last_write_checksum: sha1:8ab958410896ce3ae173ad382012ee77052c44a7 - pristine_git_object: fb03a7e551476e159bfcc7a8a4839055dd80d703 + last_write_checksum: sha1:7e0edb53ea304709ab5f4f2555ba7252208035c2 + pristine_git_object: 2bf20e09d13dae85719bb00888d761903a20a3c9 docs/models/inputsyslogsysloginput2.md: id: eccfd53f0167 - last_write_checksum: sha1:490c541d9885f22430a6491e4aa50641c253e1e1 - pristine_git_object: dd2a043323a15b7d78852a4149b0792a0a466f8a + last_write_checksum: sha1:24778b2be5d58e8ff9676c6f0c649caba413bcf1 + pristine_git_object: 60422accb1021cabf63ae09e68d6020dcd18ac66 docs/models/inputsystemmetricscpu.md: id: 6fc6bbcf2af0 last_write_checksum: sha1:aceebbd16250146c866114f427cd0f87f8ca8612 @@ -9788,16 +10848,32 @@ trackedFiles: pristine_git_object: c07e64636045eb9ba05f5b412b6ccf1c225157e2 docs/models/inputtcpinput.md: id: c221c8d03669 - last_write_checksum: sha1:07618c22e72fa3a2643672ff09769be5ade9cf06 - pristine_git_object: 6abf4e4d40659a7ebb8b8a9825e9d3760b1473a4 + last_write_checksum: sha1:e34362941e9dbb458e8b53f644da8b70551ea3f9 + pristine_git_object: 889832759262abc69a6b54afc2d7bd9ff9660110 docs/models/inputtcpjsoninput.md: id: 01d76d7ae89a - last_write_checksum: sha1:d449be0d1084fd05778f7ac8df3e179d65d6089c - pristine_git_object: 84257a0ecaf68dee0f4917645ccb3ab61397c71b + last_write_checksum: sha1:7eb7cd27f71dd3941b9c5290effd713c96a057d2 + pristine_git_object: 6817fd20046ba12ca580fe7dc4ceb556f709fd80 docs/models/inputtcptype.md: id: 85691e0ab889 last_write_checksum: sha1:09b34b3ccb0db51b2a588632c72f67ebb68e1230 pristine_git_object: 1d5a05a49d0cdf073842e07e289276cd17c8209d + docs/models/inputtrellixhecinput.md: + id: ac1fbb3d15ea + last_write_checksum: sha1:b742bae87d7be95df0dabe7f83aae34481e298b4 + pristine_git_object: 8c3bfd1be41de57f92a08e98be5d644b99262bb8 + docs/models/inputtrellixhectype.md: + id: 6a3951f0c225 + last_write_checksum: sha1:e7d9cff6be61e3df5b63fccc3b10ab0ba76cc8ab + pristine_git_object: 2a65d835c06f91e425406defe5677ed3023c1f4e + docs/models/inputtrendmicrovisiononeinput.md: + id: 58c960f78fed + last_write_checksum: sha1:495bcceb9b4fab3f6a589ed1804ddc9aedc1c247 + pristine_git_object: cf8aa14ea99d26c0295d437a55591899eb18d424 + docs/models/inputtrendmicrovisiononetype.md: + id: b0a717e8bd7e + last_write_checksum: sha1:1bb53bf08de0162667fff87fc1299c46e7830f17 + pristine_git_object: 101b0a7d5fc0f04ab3491b6e4be5032986fb8b76 docs/models/inputtyperunnablejobcollection.md: id: 8bd68187e83f last_write_checksum: sha1:11dd3e904f853f92db05dbf29a51fe98ee5374f5 @@ -9810,10 +10886,18 @@ trackedFiles: id: 1b1606ac9bfb last_write_checksum: sha1:3457eaf817f7ca701d55477d77c39ec416a1bf7a pristine_git_object: 579440eb63b632c43c208931861e0218d3cdd371 + docs/models/inputvectraaihecinput.md: + id: 74e7c2a44734 + last_write_checksum: sha1:60d97affb13fef5068a07eba0e43ebdedb121702 + pristine_git_object: 2f67cf6d38d687c34ce707493b9ffb9ab2f81b1d + docs/models/inputvectraaihectype.md: + id: 1e1ad0bf69a4 + last_write_checksum: sha1:f9921b65401a68c3d8dc6f67e28ef6e563ae8830 + pristine_git_object: e25a8892f66b7297fca0db875df38f273c8d6192 docs/models/inputwefauthenticationmethod.md: id: 6126399f563f - last_write_checksum: sha1:4e21cc4b3f0b511a0867f35705c29f62070bb30c - pristine_git_object: 00a6f4aa0299e704abca32c7835e3aaf70a47cb1 + last_write_checksum: sha1:b72e5be40025ff0f810452394520baa5b8620a96 + pristine_git_object: 45d115fd4974b7e40578d6d5e714e7d755d1f455 docs/models/inputwefformat.md: id: "646667000321" last_write_checksum: sha1:350652ba47c81bccea38674379e3e873a89264ab @@ -9886,10 +10970,14 @@ trackedFiles: id: 7dd20acf3839 last_write_checksum: sha1:ca03791726d3b17b80e21cd74fcbbff0c4e83091 pristine_git_object: eaac22d441c748eae10d9106ba176f3d5924d3ed + docs/models/inputwineventlogseventformat.md: + id: 7563502dd915 + last_write_checksum: sha1:b57385213d479112b8414aa312845c0cc6f596d0 + pristine_git_object: c62f7423d8bb4a9e4ce07918a76fc1e7146cacf6 docs/models/inputwineventlogsinput.md: id: 58257175913f - last_write_checksum: sha1:74b5d8c4c9dcd6eeba728e80628c5f1b1761cbf8 - pristine_git_object: 49630cc1e4ce1b883f9eed639014d4ad9ec785d1 + last_write_checksum: sha1:0528fe03f7b1021f94d3d20793ffca3f26e05dbf + pristine_git_object: 27c56d276c9e2139c67e727849d1457cf665da88 docs/models/inputwineventlogsreadmode.md: id: 1fa3fd445122 last_write_checksum: sha1:cc542fadfb01b302728db52ca0ca67b81491221e @@ -9914,18 +11002,30 @@ trackedFiles: id: 4eddebf40214 last_write_checksum: sha1:cc195b59f14263d7d64832ccc56ccbe38adca833 pristine_git_object: e54c5e89df1c6bf100eb680eb95171326bc423bc + docs/models/inputwizwebhookauthtokensext1.md: + id: e537e3e3d411 + last_write_checksum: sha1:4b5176351f68fd77e7edce8ccffcae66186deaf2 + pristine_git_object: db5ff6560e002e6caa8da6c6f328c3c25ed57b7d + docs/models/inputwizwebhookauthtokensext2.md: + id: 6dc59a5c12c3 + last_write_checksum: sha1:7dae7fc7550688e9dd8ae8c03b1b80466be49591 + pristine_git_object: dc996771d8920a88e9e3ebcd8beb2b42aa04fca9 + docs/models/inputwizwebhookauthtokensextunion.md: + id: 9521f614e7ea + last_write_checksum: sha1:7e98554513e5c71ddd01c110348fae96c33bbdda + pristine_git_object: d5086e5740f2bfad2b7bc80590a692cd9b5c16e0 docs/models/inputwizwebhookinput.md: id: 6c81d6a8f68b - last_write_checksum: sha1:cb7ef25383a24cbc858260a61e31b2d4f453bed4 - pristine_git_object: 37a172211ffb9a2264c14a1474123d318cb8902c + last_write_checksum: sha1:eb6b0b7c4bed61950c2d44f5e3982545d5a76a07 + pristine_git_object: 38d4e70d0dfd0fa174ee568e528f7d9d981b0f9a docs/models/inputwizwebhooktype.md: id: 4a55d744a3c3 last_write_checksum: sha1:6476923e686559a4dd9e94f1045fd5e973391e5b pristine_git_object: 740b223e920ef0f02ab36ce4d18cd4518951d2e4 docs/models/inputzscalerhecauthtoken.md: id: 520153cb1e37 - last_write_checksum: sha1:0cd7b7fc2ba0e1a8677b14186d2ce70065b6abe4 - pristine_git_object: 682590f89ffec95e60b7fe88756fddb529326fd8 + last_write_checksum: sha1:aa274fe83ff38ebe2a1384a68ab243d0d60f0df7 + pristine_git_object: b2b0b8f1241ecbca95427f77988acc366d755d18 docs/models/inputzscalerhecinput.md: id: 351471cbc4b2 last_write_checksum: sha1:95619afc14d8de85a3787de2b26033939cb1d5ac @@ -9972,24 +11072,24 @@ trackedFiles: pristine_git_object: 287b27555cb64caec26bec3d753e5a02c7e42557 docs/models/labelfields1.md: id: e47504215de0 - last_write_checksum: sha1:1e2407b660e4a9fecf616812d22237a6f261c8af - pristine_git_object: dbc3f2356f05a55def247fbe6a4dddb0b9b648a8 + last_write_checksum: sha1:88bdeeffbedfc75c4fb203dcefdca80db5814409 + pristine_git_object: 28e044a13ad23f721385adaf9376fdd3f0b3b3b2 docs/models/labelfields2.md: id: c8412f854641 - last_write_checksum: sha1:9db1337ea8bf3448f75e5fd66f4d610374fb4d57 - pristine_git_object: 98ff83e72c5d30264f6a8fd8ae077819dcf9b412 + last_write_checksum: sha1:24501f8bd4992855528d31ddea1a5063eafa7aec + pristine_git_object: 60f0ffab68ce29c759a2d667b0dfda5c9ef6eaa1 docs/models/labelfieldsunion.md: id: b345cf7768d8 - last_write_checksum: sha1:a4190261e9b72c08396e914f49dc3dcc25b48161 - pristine_git_object: 3274d44d28dfd207b211ec57f90d09843b8e2fee + last_write_checksum: sha1:46c37e635060627bed43306abb996d29234505ef + pristine_git_object: 3aba4d86b46cefc015d8a98e680777483a4cc755 docs/models/lakedatasetmetrics.md: id: b5762460f89d last_write_checksum: sha1:8044a894257fa5e1bcd8a8f50d89d80d3bf49442 pristine_git_object: b1e5506337fdf0690e9e3c0541659f2540149ea1 docs/models/lakedatasetsearchconfig.md: id: 1ae748500cc0 - last_write_checksum: sha1:9f0278975c74703286a86ee49a1aceb5b5b9d149 - pristine_git_object: fe82823800d0df50c03a12612d9744aa19e50eb1 + last_write_checksum: sha1:ae8a31c89e2983aa1d48abe1d6ab9f686fb0d130 + pristine_git_object: 05d5ff9e45fe24bdec5d72c17191f1f5e878d723 docs/models/lakeexportconfiguration.md: id: 8bd1bb7bc273 last_write_checksum: sha1:d4b50a07dc8b6631d051e4bbb5b00d2ad09b9aff @@ -10002,30 +11102,18 @@ trackedFiles: id: 49564a9009e4 last_write_checksum: sha1:bb1baeb5be8f5b263d3af63d3d491fe17da1e3a2 pristine_git_object: 256dafebe1a3c197781ea6263dce8981739b4490 - docs/models/listinputrequest.md: - id: e25678728bd6 - last_write_checksum: sha1:5490bbc2b9ee8302c7a1139c88862dae9e503c4d - pristine_git_object: 1030016653ee3f308873c3c9624f993005a68a5b - docs/models/listinputresponse.md: - id: 519307222c08 - last_write_checksum: sha1:0b7ad42ab6c3067f01d892581c6998e7f94c60ec - pristine_git_object: 3c68420c1f7473833d652b06f92c9e7429650ce8 - docs/models/listoutputrequest.md: - id: 6bb51dcf1ffa - last_write_checksum: sha1:4fcf434fa20524cb3244cc72eb89e6f2085f5eb2 - pristine_git_object: 30dec3793bd72c0e5659485040cc09d95d8d925b - docs/models/listoutputresponse.md: - id: 1f91709ca0e0 - last_write_checksum: sha1:97b07579ecd471c30d0a9b5041132cdc6b317e23 - pristine_git_object: a360cb4aec0e79e7e07100a0dba964a7a5e3ae93 + docs/models/localoverrides.md: + id: ecdfc7d7e3cf + last_write_checksum: sha1:1edd73e4c8e97eb697c8a8c4bf865ffc15508394 + pristine_git_object: 7099ecc6a443946f5e4bc294ddd4474094089b85 docs/models/loggedinusers.md: id: 791efcee4e4b last_write_checksum: sha1:2cb3b96e6f33ca7a1561114996b42b7183f436a5 pristine_git_object: ace090d65cfffee858fe7316a222aa7562e39c27 docs/models/logininfo.md: id: a0c99bed1729 - last_write_checksum: sha1:1283a3a4a2903566383dfbd65454737914b46ffa - pristine_git_object: e1a4875e6ed78babd9e5fedddbbd57a6af3ace1b + last_write_checksum: sha1:71188533ebc7cf46b57fd1c32e10a4144427baf9 + pristine_git_object: 3d59b7b02ec0f4fc208777b347ce96fb8923f37a docs/models/loglabelconfoutputgooglecloudlogging.md: id: ed53753c5511 last_write_checksum: sha1:6718c0f795b40942fdd17bf6299a113db17304ff @@ -10130,6 +11218,10 @@ trackedFiles: id: df75b079a96e last_write_checksum: sha1:3fb71f0ac891019eac95ab94195fb5b20f046c60 pristine_git_object: 58fa3a0a07b1cc8efd9e78825f9a13321a185c6d + docs/models/metadataitem.md: + id: 88dc59b2d6b3 + last_write_checksum: sha1:cb978d51cb46f9bef868b5f96fd435704f071a3f + pristine_git_object: 460c8c178ec319d858b643a88418a36b8e960982 docs/models/metadatum.md: id: 004e07e6d66d last_write_checksum: sha1:23090c90b6aa33e35a53a503a23074b49a2e64b5 @@ -10140,8 +11232,8 @@ trackedFiles: pristine_git_object: be0f9cc26bdf8232b1c48a770687aea7f0aed577 docs/models/metricsexportconfiguration.md: id: d13f30e8fa74 - last_write_checksum: sha1:bbaf6e4f1b86b17094c3a0e1d6fb59c70d7a4dc0 - pristine_git_object: 5863ae29c127b0508007eabf96292a5c2d15c244 + last_write_checksum: sha1:dd9d500cf60ed2b41fa4a8b0e5286bb5c54e5816 + pristine_git_object: a0d131a754280f696cc7cc88743fd6153a4a48cb docs/models/metricsprotocol.md: id: c729a1cac160 last_write_checksum: sha1:1afafec319962751b678320cc331f01fa27b504b @@ -10180,8 +11272,8 @@ trackedFiles: pristine_git_object: 4f4fdee10d7aef8ea6ecb107f107fa447775e21f docs/models/namefieldtype.md: id: 2282ab64c57d - last_write_checksum: sha1:c6bce56a58330561943cde64bb36f39cb98336fa - pristine_git_object: fc00ddf4ab9fc1525663210384fd62791bb3b14c + last_write_checksum: sha1:735fb1e8f2c44e766e7981a6d790f7d32688edfe + pristine_git_object: 6b70c4f5cdc0980f06538e7cd115b9761cd7364e docs/models/nestedfieldserializationoptions.md: id: 043e473ea7fa last_write_checksum: sha1:eb1fd45b139ed1890e2f968a250974e3786e9257 @@ -10218,46 +11310,30 @@ trackedFiles: id: 4f5e4d0a10fe last_write_checksum: sha1:1a4284676cd40b5fb619a7d51676390c94943b0a pristine_git_object: 3e9f1fc103694fb47b1c4ee7a225900566c3e28a - docs/models/notification1.md: - id: ce7a490383cc - last_write_checksum: sha1:202304000bfe0d10fe0eeb61171c7f8cf783e020 - pristine_git_object: 457b27cc1092ff0bb4f63ccbb42c80485c28ec2c - docs/models/notification2.md: - id: f251942318e2 - last_write_checksum: sha1:44aa29dc3ffac8a1cdaf258e809453a37e8b0d37 - pristine_git_object: 7b776d3b80ebc4657cda642d45a5036911889fab - docs/models/notification3.md: - id: d7f3e6833080 - last_write_checksum: sha1:e54047fe83fe5e7f641569dd403abcfdde64160f - pristine_git_object: aab73776b1cf8628e48c25eca142ad70a0725c4e - docs/models/notificationconfigforsmtptarget1.md: - id: 32cf4e295928 - last_write_checksum: sha1:d10c8381feee869f6085c4fd6f164613a841387f - pristine_git_object: 183f2995ed8974c576281167981cba6df60bcc0f - docs/models/notificationconfigforsmtptarget2.md: - id: f30ae761415c - last_write_checksum: sha1:2483529262f5ebe303cf07b81d71e7439cb8a4b8 - pristine_git_object: 05185f0cc0ed2aedc6dc5faa65f902496eaecc3f - docs/models/notificationconfigforsmtptarget3.md: - id: cb76de40cf50 - last_write_checksum: sha1:f96348e17758dd08ab89c563080e4b73f6f5e7b8 - pristine_git_object: b3c8c325f810baef3c40f564444207b16f2a8988 - docs/models/notificationmode1.md: - id: b2e792f3ecb9 - last_write_checksum: sha1:60c770bf7922498b33e24a920d7abdd2a38e1587 - pristine_git_object: 85f5062a1fa5aba39015148ed30f77fb279ad5c8 - docs/models/notificationmode2.md: - id: fb74c4ec7ff4 - last_write_checksum: sha1:783e81d16e9e8eec979239bb41ba05e97d775545 - pristine_git_object: 43cfa6543a29834ae3b34f69815f6863cb669470 - docs/models/notificationmode3.md: - id: 8c3168102687 - last_write_checksum: sha1:0b27bbb4e8229d19a5fca80c607f66ab5a646723 - pristine_git_object: 6814d6856fbdbd52f84677a4ba0cb4350186add7 - docs/models/notificationunion.md: - id: 1ab1b1c742e9 - last_write_checksum: sha1:61474ee91771144fbeaa90da6b0978796ea740cb - pristine_git_object: 3bc2e549c27ba3667d78619ca50df417f6df348b + docs/models/notification.md: + id: 3d02056241c3 + last_write_checksum: sha1:01e837c776d7ab01ff9dc2e30aba7aec49db0586 + pristine_git_object: 005d0c4169cf8a822492f98b4dd5a66ec93b55cd + docs/models/notificationmode.md: + id: c5f446aec2e6 + last_write_checksum: sha1:e7504a21fb947f20353ecd46fb0966382edde63a + pristine_git_object: f3e5af931d013d4eff1e5905f822e10452b41cb0 + docs/models/notificationsmtptargetconfig.md: + id: c4099e349941 + last_write_checksum: sha1:791a783264a74a3ed540a2376034dc5a012c902a + pristine_git_object: 06c10515805283b7c455bd09217bb6aefa2f4064 + docs/models/notificationtargetconfig.md: + id: d665bbae1ee4 + last_write_checksum: sha1:44c76b6e56c5b1ac9347ed9b556eb097deb8f49a + pristine_git_object: 80c742f188e142a3802f659b16a9942367c389f2 + docs/models/notificationtargetdetails.md: + id: e452b76232d5 + last_write_checksum: sha1:0a54e0b315d10b94552fa2a27e4dfee360f042f6 + pristine_git_object: cfb361563c58700364d7e217ee0a14b60cb06e08 + docs/models/notificationtemplatetargetpair.md: + id: 7a9997269252 + last_write_checksum: sha1:a71b5233649a466460f4382f6bb9b5fd19ecbb4c + pristine_git_object: 07de5304d1e545114df3a03792c185fdd9f8b01d docs/models/notifyconfiguration.md: id: fa93e572471b last_write_checksum: sha1:42f5db4f0ca40eac262eafb04b0e4e44b3be6c8e @@ -10290,6 +11366,10 @@ trackedFiles: id: 58d845103705 last_write_checksum: sha1:e7e10e9d0c10d9b21ce3d6e1ede89856c9e575e0 pristine_git_object: b05effdb77ee4804f4ea22e4b481260a8d329297 + docs/models/oauthsecretsource.md: + id: 121d1c0cd61c + last_write_checksum: sha1:668dcf422b1a6323c7a54054b94b78096dd0aff1 + pristine_git_object: a79a5709861044247dd1b963d2a156d8fec2a554 docs/models/objectacloptions.md: id: 7341215eff3d last_write_checksum: sha1:b5694bd0ef03c04cb41236c624f526665bb273ea @@ -10322,10 +11402,10 @@ trackedFiles: id: 0ed26d96d630 last_write_checksum: sha1:2ffcea68a1fb11b59e6a1d481c793b34cdd8021c pristine_git_object: 0e5d02aebd29a099b1a30cc279827c9470aadf27 - docs/models/origin.md: - id: 99d16e2ed94f - last_write_checksum: sha1:320c8aebb60f046328cf6e8c353e5c16c3dfe5cf - pristine_git_object: d171a7a6e880f37e69d6fca27b6f4c96727cc045 + docs/models/originoptionscriblsourceprovenance.md: + id: a895922bd9e8 + last_write_checksum: sha1:212a79e7ae9c840a35813a086f4486255f611125 + pristine_git_object: fe4e1c2f68572ae889d8ef7350023585bd9643da docs/models/orphanfilerecoverytype.md: id: 27ccdda6b0ad last_write_checksum: sha1:6ffdfcecbd874bc1da654a61e38b501fc7df9239 @@ -10352,8 +11432,8 @@ trackedFiles: pristine_git_object: 5552f711226dce150fcad99b555df8c6f6f4d133 docs/models/output.md: id: 376633b966cd - last_write_checksum: sha1:7cc9978628e5556713d37c407980706590a048ab - pristine_git_object: 845e8f95cb392e17fd1b07a3ae3ad42551b3296a + last_write_checksum: sha1:3f0d3a5c3b390741c0e84001ea6e6d711a23d0a0 + pristine_git_object: 203cbd51b3d610e4b2e1d0550b1e24f112ae0798 docs/models/outputalibabaclouds3.md: id: 8fbe1415f28b last_write_checksum: sha1:1b52ce3025488c711ef614ba163e1c274b093813 @@ -10516,8 +11596,8 @@ trackedFiles: pristine_git_object: 141f78aa1fb06f2684bdca0b37306678a7116d9a docs/models/outputcribllake.md: id: b90e8719d73e - last_write_checksum: sha1:1900af0bb17cfebcbb3dc3ae1a8b5c300dd8f11d - pristine_git_object: 80bf4ef6230376514432e974c768ac741a29888f + last_write_checksum: sha1:e46ca4cc45a02ca0331f6b7490410d58ba94c823 + pristine_git_object: 81477073b2cc7fa3513a16e12b933c93854cba3e docs/models/outputcribllakeformat.md: id: 09c52708e170 last_write_checksum: sha1:d2910b9de11b0de41645ae9688159e8198a8d15a @@ -10528,8 +11608,8 @@ trackedFiles: pristine_git_object: 645a80842ee1dbbc6cbad2deebee41955ea1c4c6 docs/models/outputcriblsearchengine.md: id: 0ed418fdd6c7 - last_write_checksum: sha1:fdfe07d52e0dd6017c60b88a02bb263cea9657ed - pristine_git_object: 850e397d49e35fcad6bf1f6c5abee110ff9baa07 + last_write_checksum: sha1:7d4c28587d839fa6fc30322d456ee3a90b3cbb27 + pristine_git_object: c83a8aea3b757e43dff816932b24c88d6b888e32 docs/models/outputcriblsearchenginepqcontrols.md: id: a7983f68b41a last_write_checksum: sha1:11c346c9f47a6b1af35af14a3ed4919fbaabce87 @@ -10548,8 +11628,8 @@ trackedFiles: pristine_git_object: 94d2e937d66442a23bb3baa0b3a4e4663d421530 docs/models/outputcrowdstrikenextgensiem.md: id: 5a40577338d8 - last_write_checksum: sha1:c6e9fa520037f477d19e910d9b122efc7270e8ec - pristine_git_object: 5054bcad23c6fd96bbb6bb9dc1f09721d690f6d7 + last_write_checksum: sha1:ae73586e90bef589d0b8b23e963cbc6193730fdb + pristine_git_object: 47a17e304cf86c050ccd5b780b65883e902cda88 docs/models/outputcrowdstrikenextgensiempqcontrols.md: id: 03faf876730f last_write_checksum: sha1:b5c10cbaf43024e3ddecee1a1c1b3605a8a74c59 @@ -10578,6 +11658,18 @@ trackedFiles: id: 34b123ed0c4b last_write_checksum: sha1:1ca46117ffa80edb01f40a870dac9764a43ce139 pristine_git_object: 048fcac862cd05857959434371a1591b388f87e9 + docs/models/outputdatabrickszerobus.md: + id: e2f01a480d1a + last_write_checksum: sha1:bc58ab1aa6a69b550e3831dbb122389a8bf80e47 + pristine_git_object: dab4713f0a8502d5a60b0fa1403a84c90f3bf6bf + docs/models/outputdatabrickszerobuspqcontrols.md: + id: db24268216f3 + last_write_checksum: sha1:a523118facdb33b70bd997dca37fa77e0f94acd9 + pristine_git_object: 6f0a4a6e7fc19b0e484d0c62d13a051b62151549 + docs/models/outputdatabrickszerobustype.md: + id: 70954e783b91 + last_write_checksum: sha1:cddfb4ad9285b8a23cd074f3ed7334a75f44df2c + pristine_git_object: d83347f15b878b1e1cbaa5a04c021d3af70e95d0 docs/models/outputdatadog.md: id: c5607e162b7d last_write_checksum: sha1:70b06e32a328b822c15d2307e19113572b229656 @@ -10720,8 +11812,12 @@ trackedFiles: pristine_git_object: 49922d638feb6d27888ddc7af4912e4467401da9 docs/models/outputexabeam.md: id: 3994111083ee - last_write_checksum: sha1:c812f3c62ec92f708cfe731c86e7170d930c290f - pristine_git_object: 6a369d62d6437c10b8a3ae2870bcad5bfacfb8ae + last_write_checksum: sha1:30431bddbbf9d1e3e563ff51fa1905282030c33b + pristine_git_object: 42dc826ca4a62cea8a785aa97266782efc45f2f1 + docs/models/outputexabeamauthenticationmethod.md: + id: ac5795e465b4 + last_write_checksum: sha1:c2356ab4d0484d6a225f1e58df9d8184e0754158 + pristine_git_object: e25130dcea6c3273c35c56b64638eebf5748e5bb docs/models/outputexabeamtype.md: id: 614d02cac237 last_write_checksum: sha1:83e1283fb06ae20d1126856340e462ced40446c1 @@ -10888,8 +11984,8 @@ trackedFiles: pristine_git_object: 14521b9075460ce26a5c35393c049a247630b730 docs/models/outputhumiohec.md: id: ae7fda9850a8 - last_write_checksum: sha1:90bec066ea52ad58a6465380ee31ba8035451d25 - pristine_git_object: e99251b2c2ffcbd8c20debf9bfba803b743c16f8 + last_write_checksum: sha1:05788995759796e4d68828e8ffc6309563012897 + pristine_git_object: 7e4807547b39220c6f941a50b9001c1a2c1e7977 docs/models/outputhumiohecpqcontrols.md: id: 08c95108c1ee last_write_checksum: sha1:2064364e3b6198e2f47e0b0553783417a4bafd1a @@ -11080,8 +12176,8 @@ trackedFiles: pristine_git_object: 5e6c3cabe3a22609f916b956891f66da69ea817e docs/models/outputresponse.md: id: e09d17192e47 - last_write_checksum: sha1:5fe586ecab16ca80a719587841dfbbf9f72ac09d - pristine_git_object: 9116d260a637f821d7df68a61f50c693ebdba603 + last_write_checksum: sha1:9ea39677bd49a8de394990b0718b30a34547adfd + pristine_git_object: 5f2405da313bc91547fc7b5930d452eefd3b6467 docs/models/outputresponseadditionalproperty.md: id: 9fe152894a06 last_write_checksum: sha1:6f92962f2fe7d2ae7dfb0b923b7508a2859848f3 @@ -11100,8 +12196,8 @@ trackedFiles: pristine_git_object: fc2b8eab2d32522cfe7d6a0efd3374d9be14c159 docs/models/outputresponseauthtoken.md: id: 549f9c35e440 - last_write_checksum: sha1:a717a44cbb4e2976ef88348bfbd575a20f8bf753 - pristine_git_object: 9eb8b5c05f1d144683e3cdfbf840b66d58d7b46f + last_write_checksum: sha1:2e5875848e9857157c846a26f90e70b2016e998a + pristine_git_object: 898b25d934b97ab2ab9688b9e35a130ebe4ca95a docs/models/outputresponseauthtype.md: id: 2c4ed1ef2b0f last_write_checksum: sha1:91338cb4a682bd6c7dfde9f7129532963dd46b55 @@ -11146,6 +12242,10 @@ trackedFiles: id: 34c8a18f6d4e last_write_checksum: sha1:3bba7d42dacd9369d1f3b3e7d6e987db69f15792 pristine_git_object: ade886bc38638275b12dfda243ee29d43853e277 + docs/models/outputresponseeventformat.md: + id: dbf9e5c18fa7 + last_write_checksum: sha1:db974942327d3481d6ff55a727e62664d0aed8ff + pristine_git_object: 5605d53a6b0ee4c5959d45ad142b668388f7d874 docs/models/outputresponseextenttag.md: id: e4e180e0affa last_write_checksum: sha1:b542292d108eddf08870988fe8ee7a1daa49927f @@ -11164,8 +12264,8 @@ trackedFiles: pristine_git_object: 74a6cbe75423890767844f3bc0bdc6ef2b631706 docs/models/outputresponseindexerdiscoveryconfigs.md: id: 37804f022454 - last_write_checksum: sha1:a49ef018e37142177165ad041647d08df0c2917a - pristine_git_object: 9f5a1ca0fbfece448baf93d38138d5673ebf2ac0 + last_write_checksum: sha1:74c61da1b80de9db400b18d991bed5d200462675 + pristine_git_object: ba05d3cea54978ced0b6d38b37f1f9a9eda4603c docs/models/outputresponseingestifnotexist.md: id: da67fc121684 last_write_checksum: sha1:d25f99206c5fc7ccf69d922f3b331e34910eedc8 @@ -11190,10 +12290,14 @@ trackedFiles: id: dbdc3d5bbbf5 last_write_checksum: sha1:1b5ec7fef8d0e681938187fb9c506cb558f36004 pristine_git_object: 7e935eb1e7d25258a7c8dfcfba8a4d4f4f494e54 + docs/models/outputresponseoauthsecretsource.md: + id: 1f449f54dd15 + last_write_checksum: sha1:06e47a592800fea37385fa4b22af148f8b876da2 + pristine_git_object: 272ad5de338cf4f410457715444f78e781601c20 docs/models/outputresponseoutputalibabaclouds3.md: id: 8d45296de875 - last_write_checksum: sha1:207c06b4740fab168bf13bb84245df43b1f9e06f - pristine_git_object: 8bfd9011fb89cf89666eef872d1060fbbed5f4fd + last_write_checksum: sha1:5b4080f4789d576383607ed8909aeb8a0cb94c6a + pristine_git_object: ff7b92880d1efabd599b3c0321eea6bbb962ee3d docs/models/outputresponseoutputalibabaclouds3authenticationmethod.md: id: a3e680c809d3 last_write_checksum: sha1:0bedc452bacfa793e5c8836a7690d22bd2ad4229 @@ -11204,16 +12308,16 @@ trackedFiles: pristine_git_object: 51bd7c7c9dbfa0e11c641ba520387da30ab766c8 docs/models/outputresponseoutputalphasocs3.md: id: b6dbf8b7551e - last_write_checksum: sha1:bdb52e670c2d5317442e48d538b8d3831181648b - pristine_git_object: dc65cf502df7e5d009d206b2b912b6355cf41a23 + last_write_checksum: sha1:d65e2cb33fb5f76d89cc10e2f6e7e532935e2dd9 + pristine_git_object: 9ae10a97499b2889d7900b30f35898f52cc6d693 docs/models/outputresponseoutputalphasocs3type.md: id: 2e54e6cf2b57 last_write_checksum: sha1:5335c901191dcfb702af1c6eefd57210abd3577b pristine_git_object: 64487b18620a87b772f7b2dac88b94b51fd1f7a1 docs/models/outputresponseoutputamazonmanagedprometheus.md: id: b1c85adc6a60 - last_write_checksum: sha1:449f6c5a9125321ace39b370f0a990dd07c5fdbf - pristine_git_object: 1144b2e7393c9962f132010248a3702e4c2453c8 + last_write_checksum: sha1:c3830a4b56130d66e722725194c22de63d21b7f3 + pristine_git_object: f48b1412f7c42e8502dba25f4d3f0e57d01db6bb docs/models/outputresponseoutputamazonmanagedprometheuspqcontrols.md: id: 0f5c2c90ef0f last_write_checksum: sha1:1de0b9a1b1e6731760cc773ffc7b662521dd270d @@ -11224,12 +12328,12 @@ trackedFiles: pristine_git_object: 25a7ed150ff76fa6a596bbfbddf500d4882071f2 docs/models/outputresponseoutputazureblob.md: id: cd66eeca0c92 - last_write_checksum: sha1:1ca23924fc502d138f9813ae3102b8ead14107f6 - pristine_git_object: 2f6b8f8d2184cfe7b8dfbe58228d25469e499b37 + last_write_checksum: sha1:5d6c179ef0671a7169c49fb20fa993c34139cc14 + pristine_git_object: 6f33aa04d176aef3995c47b0d753ee2b264ca8f5 docs/models/outputresponseoutputazuredataexplorer.md: id: 6709dc53e281 - last_write_checksum: sha1:43c83b4e6c1ac1affd5ef1e38484319e8ceac732 - pristine_git_object: 0804825de0084ce7071c6fb38ba02c66bb448562 + last_write_checksum: sha1:85ac08cdea791da1047406d5973c765944163fdd + pristine_git_object: 7d1a8ba76a60d359421730cd63af30ef556c241f docs/models/outputresponseoutputazuredataexplorerauthenticationmethod.md: id: e0401dd10a8e last_write_checksum: sha1:5d816ad4196e3a2f86d7114fb9145323085c9c23 @@ -11244,8 +12348,8 @@ trackedFiles: pristine_git_object: 092ccd6bfb1523e97259a4c0c6b418cff284921c docs/models/outputresponseoutputazureeventhub.md: id: b44a571d1a9c - last_write_checksum: sha1:c5c35517a8f54774352ac382243c8015ddf764df - pristine_git_object: 7a37798b4f2ee6812a0aca9c961ad2db7a2d51ec + last_write_checksum: sha1:7130e92fac85f6807cadee16aefef7f7a5283626 + pristine_git_object: 1c6420abadb2f909e14f737e4dca0db7d8d12734 docs/models/outputresponseoutputazureeventhubpqcontrols.md: id: 447914cdfa91 last_write_checksum: sha1:5df11056c754747bee41b4091411f324a851e2b3 @@ -11256,8 +12360,8 @@ trackedFiles: pristine_git_object: 7f43ff51de82ef7f12fbb8127505cc1f991d4cc2 docs/models/outputresponseoutputazurelogs.md: id: 7e530e119f7d - last_write_checksum: sha1:83535e57b0dd8b633c43428eaaf52ee8bb20a5db - pristine_git_object: ab1308f02708ebbbbbc22feef4ba1a37c3ab20a3 + last_write_checksum: sha1:629e4485a41afb1b515294ab58f56bc504e83f7a + pristine_git_object: 4ea2209b1f76f6ae5ef87db9b273aa074acbcb29 docs/models/outputresponseoutputazurelogsauthenticationmethod.md: id: 1d3e6b918c64 last_write_checksum: sha1:3d8512271759af7050e18c832417434bac34835d @@ -11272,8 +12376,8 @@ trackedFiles: pristine_git_object: 46fad94c521d93a6b0ef13814fe22ac274e89e64 docs/models/outputresponseoutputchronicle.md: id: 4d691b29b4eb - last_write_checksum: sha1:d9ce887300a68ec8d25f7c7d596010d861aa01e0 - pristine_git_object: a103b28bdfcdb753f470af5f95c338884c0ed523 + last_write_checksum: sha1:7ae576c1bb4ec7fa1ea1abfe5cba3a8c939ef124 + pristine_git_object: d00bd937dcd0186b2facfc62ec9676aa628df666 docs/models/outputresponseoutputchronicleauthenticationmethod.md: id: 38dfdbf6833f last_write_checksum: sha1:8c6ac3a57055655385d117dc7c9697369f669168 @@ -11288,8 +12392,8 @@ trackedFiles: pristine_git_object: 4b3f59beb36ce2d4d19811b8a437e0d8b9123b01 docs/models/outputresponseoutputclickhouse.md: id: 87a9c5e49123 - last_write_checksum: sha1:c9e84e74842e364bec55d71555bd70c12b472d7e - pristine_git_object: d7fa1ab946227f20f8c80f9701e8b29c7030fd70 + last_write_checksum: sha1:45060a1ffa50f13e054ec46fcfd8ea0a6cf80838 + pristine_git_object: dfae8edcff548c7181401c9ff5c2609dafbf4501 docs/models/outputresponseoutputclickhousepqcontrols.md: id: 87774d6f7e5e last_write_checksum: sha1:a3f34e188d3b477ed862e89082e495649388cded @@ -11300,24 +12404,24 @@ trackedFiles: pristine_git_object: 0e8df6f308b377669702d60ade02f46a8377d07a docs/models/outputresponseoutputcloudflarer2.md: id: f6222b2f3631 - last_write_checksum: sha1:3d3d77e26cccc37afafdc78923fe63e2d008232d - pristine_git_object: 2e33a01c593e0b6b1f93c29ea7a26cf8012560aa + last_write_checksum: sha1:e74598a6c391da02a99b5bc017ee110ea5ec62e9 + pristine_git_object: f5197bbf69b3900f98ceca59a7a89ba03b12cf5f docs/models/outputresponseoutputcloudflarer2type.md: id: 22e1ff4ecccc last_write_checksum: sha1:65d1e0eb673d664d1d31b88e2d7e4e6cfd7e552c pristine_git_object: 0b19f35b51c5fabf0a7212f6033bf1fad6150ae7 docs/models/outputresponseoutputcloudians3.md: id: ba0ba5f4a497 - last_write_checksum: sha1:0034d30dd4984bb1947576ae04897f09de594ddb - pristine_git_object: 42ec0225ecd5b9e0c15be1a69fdde84caafb13aa + last_write_checksum: sha1:6b26626729f1e7b8a1c35ff5677ad573327bcca3 + pristine_git_object: e99797ed7a0799050421a76d3983af4d3b0852ce docs/models/outputresponseoutputcloudians3type.md: id: 7322d7193f60 last_write_checksum: sha1:bc7417be8207f2e38d94a2126199fa299a0a4208 pristine_git_object: fce65cae903655ab34441bc866282f816cf64ed8 docs/models/outputresponseoutputcloudwatch.md: id: 20b3ba45ca98 - last_write_checksum: sha1:95413de601d5a3e50a646c2619012eb2f6f2e776 - pristine_git_object: 7455bfce610974cf9bab38740fc5cae0b4411a4b + last_write_checksum: sha1:d6e00d6a78ebc21049b34d727136c08d3720a4e9 + pristine_git_object: a3b19be836bc003b6b7d3e16e03246519cc58a23 docs/models/outputresponseoutputcloudwatchpqcontrols.md: id: 3761552fc4c3 last_write_checksum: sha1:acf0db7b6dd6223eab18fa869e9ec8b20f53bdc5 @@ -11328,16 +12432,16 @@ trackedFiles: pristine_git_object: 85387026dffacaec99d1977642fbd21b77f07847 docs/models/outputresponseoutputconfluentcloud.md: id: 7514bd6e96b6 - last_write_checksum: sha1:3a66e1b073ef3d1494da72a385ef001d16069c4b - pristine_git_object: 26446881f9d82323ba4ee6f9e9e4bfb4d9c01225 + last_write_checksum: sha1:b789a84a3c8765326dbf4faeea1745b89f810833 + pristine_git_object: 59d4911001d4e924669c176bbe296844a7c41b51 docs/models/outputresponseoutputconfluentcloudpqcontrols.md: id: 2bd8997309b4 last_write_checksum: sha1:6b5e8c9937bf29e1be2f218fcd614834f40196d6 pristine_git_object: 0d92e00705e6f64931768d361a441eb12d17a8a3 docs/models/outputresponseoutputcriblhttp.md: id: a09cfabc4ef2 - last_write_checksum: sha1:16bcf6bf84c61ffb4e37acc94ab0557d3a1e87ed - pristine_git_object: 1796aae122f242ff55317d09a62b80d2dd0e2aa3 + last_write_checksum: sha1:bfb7e9ef62899edf279964428109e749ffff4d41 + pristine_git_object: f95b3d996500699feeedd7b17d4e8e041e27e130 docs/models/outputresponseoutputcriblhttppqcontrols.md: id: 7ca488995438 last_write_checksum: sha1:e6b91cd478fc3b9f305b5b6e505522cb1f4abffc @@ -11348,8 +12452,8 @@ trackedFiles: pristine_git_object: c9b78073c7c0c92d5c9b5568bd0750724736409f docs/models/outputresponseoutputcribllake.md: id: 74c60dc553c4 - last_write_checksum: sha1:2a7867fad8de232ff7fc038924b71730513d2796 - pristine_git_object: 61a5b7d85cc25134330919be1b7f091ffbb5cb97 + last_write_checksum: sha1:cd5cc14e0215fff7493c36c6017a3c6aefcfa39e + pristine_git_object: 29f6947110905fa61f459c84aba13a5c237731b8 docs/models/outputresponseoutputcribllakeformat.md: id: c0b246c9b4ca last_write_checksum: sha1:040e38d79180873826975caddb01945e5080b9e7 @@ -11360,8 +12464,8 @@ trackedFiles: pristine_git_object: 92b9c2f7ab44926bf3dd2cd00d09543a5c0cc722 docs/models/outputresponseoutputcriblsearchengine.md: id: eb2778b30827 - last_write_checksum: sha1:3bfa76ff3b0cffa0b1c72d9402fd430ba71de603 - pristine_git_object: 1b575f43fe0fa187249f1b91d02767c6a3311cec + last_write_checksum: sha1:4ed0261a3122434bad4aa696be1b98cf8fba680e + pristine_git_object: 7905c818ecd8f1755efbdd880cdcdc6735a96e6b docs/models/outputresponseoutputcriblsearchenginepqcontrols.md: id: 881d1a1ea088 last_write_checksum: sha1:c88357245ffa839fda611bcea14e1c001cb2e1c4 @@ -11372,16 +12476,16 @@ trackedFiles: pristine_git_object: a2a09d1a8e16956b4a21a677bce12061cee5b882 docs/models/outputresponseoutputcribltcp.md: id: e78272be4efe - last_write_checksum: sha1:9cc2dbe545e0c8dc7025c8c90f3154a78b51ee78 - pristine_git_object: b7300d13cf9bc8b15445c36ab6929e1fcb53261c + last_write_checksum: sha1:1f00d82de2fa63baef1286ca229fe44f5111d4c4 + pristine_git_object: 9aa0c9e534be19f043c6d91a81dbea1a2c6f7bed docs/models/outputresponseoutputcribltcppqcontrols.md: id: 929355906ca5 last_write_checksum: sha1:81d93df476b5c156c9cefa6d3f51cec41a9e7b17 pristine_git_object: 5480d7ea0edc02af9de7e2e13cf1b98b0df52f4a docs/models/outputresponseoutputcrowdstrikenextgensiem.md: id: ca115b05146f - last_write_checksum: sha1:7e76420b559989cbe8dea73769a8096812d4e2ed - pristine_git_object: 3717ed5752598432a0df7657ca88593e950ab318 + last_write_checksum: sha1:6cbab145b73f07884715394af0559f6f732bec50 + pristine_git_object: a33eab1e936331ad99259ba40024d8d26fb42198 docs/models/outputresponseoutputcrowdstrikenextgensiempqcontrols.md: id: eba71dbb8da8 last_write_checksum: sha1:53f17c42b1cd2a01acb88c97c53f866c5c2551ec @@ -11392,8 +12496,8 @@ trackedFiles: pristine_git_object: fb8a8f2451bbe9dadc841b61c2a06aa380fef71a docs/models/outputresponseoutputcustomermetricsstorage.md: id: 2d6f0e487d83 - last_write_checksum: sha1:6f05e9b3f9f14b117b7533a3ab72893699d7a35f - pristine_git_object: 57fd399731da6a161fbd982c82b2b608311d7e76 + last_write_checksum: sha1:c1a5f6082fedba8f793c41390a7eb5eb3d10c9e6 + pristine_git_object: 52c07593e295d2e8ce6a3bdcda3d9818f00cb6bd docs/models/outputresponseoutputcustomermetricsstoragepqcontrols.md: id: 77d0eff3feac last_write_checksum: sha1:36a2a901f55965cf123498d228cb30fc16c06d95 @@ -11404,16 +12508,28 @@ trackedFiles: pristine_git_object: 940fae5b5254dc79b6d7a89c450f542ddcc50ab0 docs/models/outputresponseoutputdatabricks.md: id: 7916815682f5 - last_write_checksum: sha1:918ac172d4f748001f3b2f326d35753d82547cff - pristine_git_object: cb7e5cf5686fb3be6e1a0d38536928e52abe7776 + last_write_checksum: sha1:e0d2aa50e1c261c2111d5dbb8aa569674beb3a14 + pristine_git_object: 03315914d4efe29c4d30699d5ce315981e51a162 docs/models/outputresponseoutputdatabrickstype.md: id: 6227747605a1 last_write_checksum: sha1:ecfe667ab80284ec9ed2c10c47b16ba060dadf65 pristine_git_object: c7f4bd0c12b37a08d64f1e2243bace7ce9302603 + docs/models/outputresponseoutputdatabrickszerobus.md: + id: 1dffdb4ad2ea + last_write_checksum: sha1:0248dbf50f8ae1c03c5db5c18d3047e3a323ef03 + pristine_git_object: b5b8f75ec361d81523ed7e4c2418d7dfea5f6af6 + docs/models/outputresponseoutputdatabrickszerobuspqcontrols.md: + id: 0d901d6b3f5a + last_write_checksum: sha1:1fe2d36c12555351abea4d9035366750cc93bd44 + pristine_git_object: 623930e09235a7b97181c4a41655e2071cb11c5d + docs/models/outputresponseoutputdatabrickszerobustype.md: + id: 1b20b8853f99 + last_write_checksum: sha1:ed721708e3352ea9b201615177b5241b4817ca07 + pristine_git_object: f1b795707ea3a8a9520975335ce78402e5c7ef6f docs/models/outputresponseoutputdatadog.md: id: eea4ae807211 - last_write_checksum: sha1:d8f545099d14923678aa293276f9a3efb6413ed4 - pristine_git_object: 81a567125c39a1fcb4922937fb6ed97e94277214 + last_write_checksum: sha1:1ee806d581af27c03b8035d1c3cf14e5e5c484bf + pristine_git_object: 71216449c1fb4268d638c05f2866101f8c96bf80 docs/models/outputresponseoutputdatadogpqcontrols.md: id: 476a88445f9e last_write_checksum: sha1:0ac1b2e7d97bf96d95a890d6aba39c5712fa3298 @@ -11428,8 +12544,8 @@ trackedFiles: pristine_git_object: 79650edd147075c33ec56931b5bf3fefbcd5674c docs/models/outputresponseoutputdataset.md: id: 3746ead5fb63 - last_write_checksum: sha1:32489f66bcabc0ab88cd856cac6f56baa357a096 - pristine_git_object: db12ff7072008c98cd6e12c89898b6d5a97558a3 + last_write_checksum: sha1:54398bc4df2732eb3ffe8a28da3552ff81ef2c52 + pristine_git_object: 0623f5f91655637c1a13b239150f73afcbb4e139 docs/models/outputresponseoutputdatasetpqcontrols.md: id: 62f598fabe73 last_write_checksum: sha1:055de28a5845ac0dbb66a5910bcde51c4b1dd0b7 @@ -11444,48 +12560,48 @@ trackedFiles: pristine_git_object: 483bb7d0784efd1de1820d40adad9cf518005f53 docs/models/outputresponseoutputdefault.md: id: d20ced2bc8af - last_write_checksum: sha1:c18d558d52b05b3abdb7fd1b924a159210133411 - pristine_git_object: 89b6833762bfba533def0f5c39b402720ace91bb + last_write_checksum: sha1:0ceabce27d76af613fba2f0e4016ca38958d2bb3 + pristine_git_object: bef06fd06cab8740f2ce2879bdba11c12eda33c0 docs/models/outputresponseoutputdefaulttype.md: id: 494b10b3c397 last_write_checksum: sha1:3c55dd3410d120c0fc4c80b729a6d0229b26fd9f pristine_git_object: 0169a36cfe6b0d3c7e11990a16317069ca6d7b14 docs/models/outputresponseoutputdells3.md: id: 515523ac75e2 - last_write_checksum: sha1:4bc52d2e589ada50b0be7f982dc1a27d5d8b480e - pristine_git_object: 687621b864c6ab0735a1aa272d9d50bb76d84cca + last_write_checksum: sha1:4e19bd2bfc77ff0bb07b54669abdec70dd73b09a + pristine_git_object: 692151b574eef182872cc41fd7581a55b45649d2 docs/models/outputresponseoutputdells3type.md: id: 4cee74dd8715 last_write_checksum: sha1:2c4ef80cb44a5d19a3cefa01557a69250b78239d pristine_git_object: 96a203552209dda78f891fbad8808a2106984249 docs/models/outputresponseoutputdevnull.md: id: 3e29df8c9d60 - last_write_checksum: sha1:1d0d27f9e62442f0c921ffc591e1c5de38006964 - pristine_git_object: 2fdc1cb63ad8047facf0eb30d3efdf0312197b0f + last_write_checksum: sha1:15f52d1b38dbf7262c855a670c94d965aa7707e8 + pristine_git_object: 7ba852e748e49343570381441e32489fcc00b373 docs/models/outputresponseoutputdevnulltype.md: id: 1ca0f16f8d25 last_write_checksum: sha1:938099edfcb10b03f9a87b460d1e58983a73c291 pristine_git_object: f8ad5f7986e16d07fb3cd3fb13327e0850b08714 docs/models/outputresponseoutputdiskspool.md: id: 902a5903bac3 - last_write_checksum: sha1:76ad4ca783298f984ca0f6cd00f576697d6884b0 - pristine_git_object: ce26ec480ae60597570da203b84fe9867eaed557 + last_write_checksum: sha1:1f13b42d81466e40dc3bfef606722166cd00798b + pristine_git_object: b95cd75f99c19a3c2a711b0ce6cefc57a85572f5 docs/models/outputresponseoutputdiskspooltype.md: id: fc1cf70f6f74 last_write_checksum: sha1:2fd5c9a0afecb42ab3595c15aa7050c9917e9558 pristine_git_object: a4196070e691486dfe971c5486940a35993b41ef docs/models/outputresponseoutputdls3.md: id: a1d78ba9edcb - last_write_checksum: sha1:7dda745e56d602021d83d9cff0d6d54a9532bb57 - pristine_git_object: 57d3f05b1565f3833e58df9da2e6a6f2fc67a4a4 + last_write_checksum: sha1:dd0223947af42eb7bd11051aa3c8c2647e87d506 + pristine_git_object: 3440f7a533042a971c2af9b942b297986a07eb64 docs/models/outputresponseoutputdls3type.md: id: 0de6445b22e1 last_write_checksum: sha1:eda010e1fc9496daf9913c9b9ca8f08e453fad85 pristine_git_object: 301fa14e5b577b41825220ed8f849acbf1750f47 docs/models/outputresponseoutputdynatracehttp.md: id: a3cbb42af6af - last_write_checksum: sha1:67913fcbb984e8fb8667e6234aa0f0751a8c486e - pristine_git_object: 973d973941643a3a4260d0f01b499f033a174b29 + last_write_checksum: sha1:f90fefa545e150c73d10ef8e7dc5b476aa349ca0 + pristine_git_object: 99fa0dc1c9c5a99cfe16d6b0f83f049fd0c1f56b docs/models/outputresponseoutputdynatracehttpauthenticationtype.md: id: 678ebfaa1942 last_write_checksum: sha1:578bd0cb78309ca7082448c2361050fcaead1e15 @@ -11508,8 +12624,8 @@ trackedFiles: pristine_git_object: c5a44dbbea9217776bd9618060ced0bf69b0873b docs/models/outputresponseoutputdynatraceotlp.md: id: a3a6c8f6acea - last_write_checksum: sha1:068a7b7b13def88daf0323cf7dc1eb6aa13a266a - pristine_git_object: 941784fa6ff65acdf11a67a6a9d0390e2cd4786b + last_write_checksum: sha1:837318d26a056ea0f02f37f44493df2650267c47 + pristine_git_object: 5cad45b2eb1c2b8e46f59ac203e0565cbcfbf761 docs/models/outputresponseoutputdynatraceotlppqcontrols.md: id: 7c0e43e50fcd last_write_checksum: sha1:1b869966ae4883cdd87dc2b68f330e4528684656 @@ -11524,12 +12640,12 @@ trackedFiles: pristine_git_object: 58de8ed8a5c3488740cb265c9ed0422994cac9c8 docs/models/outputresponseoutputelastic.md: id: 10556fb5c25c - last_write_checksum: sha1:14ee0a9e41fa30f295c8f5dfb14dcf5872962167 - pristine_git_object: fb2890d1b68862740337d7667342d84cc7c355e3 + last_write_checksum: sha1:d72e7404c17460f2ed0246f487778f8cef83878c + pristine_git_object: 1593fff1a61528adcf365332957f80e74b116531 docs/models/outputresponseoutputelasticcloud.md: id: 8774122802a8 - last_write_checksum: sha1:215c6c81810ef8c47797d6aa85a6839f57ed94a9 - pristine_git_object: e87ec894222a1ba6b0132b77c6c69f1abcd3395e + last_write_checksum: sha1:1c1a03cb5b5f5fd931c1075984e8cd560ca321e2 + pristine_git_object: 69d66b8555e359b842a2066ad3c38022cf0924bd docs/models/outputresponseoutputelasticcloudpqcontrols.md: id: 8f680565fdff last_write_checksum: sha1:3868b735316927465201464a1fd7644ea08db384 @@ -11552,24 +12668,28 @@ trackedFiles: pristine_git_object: 92408ca3c61047d4b88c513f5242c1a3c1d98d67 docs/models/outputresponseoutputexabeam.md: id: 340aa5921897 - last_write_checksum: sha1:35dee06538a4dbaa4967e39527e69fa3f24ced73 - pristine_git_object: 3c7c87558b51feccaa9f1dd246d50fd5324c21ee + last_write_checksum: sha1:7ba25b0f5929b1f8c2584839eac15d76a5fc813d + pristine_git_object: 54ac2d665ac0a7ecad0efec6a709f2c79df12fdf + docs/models/outputresponseoutputexabeamauthenticationmethod.md: + id: 359e7bce9260 + last_write_checksum: sha1:fffcc8986b155159a473a985c65b73a620a5aa64 + pristine_git_object: aaaedbc8bc403a2262953f9c41a945f79fe20a16 docs/models/outputresponseoutputexabeamtype.md: id: 640d00de7936 last_write_checksum: sha1:a5ad5cd0e80384dbf00fe9b7e9efeb4d27142304 pristine_git_object: 211efd18cc6038c6dec6c70f65de5be4ef83faa3 docs/models/outputresponseoutputfilesystem.md: id: 15bb1c0aabe2 - last_write_checksum: sha1:ff97b19e441b657410acbc74bd0f8ed7bb10df9c - pristine_git_object: 2564baf0ad1a58ea19e54111c7ec282deaa2d0a3 + last_write_checksum: sha1:fda748c92c13b71be158f54f7ccb84c53ab16abd + pristine_git_object: d334e41c8e9faf07ad459e889b6bd0b2a2fa7a59 docs/models/outputresponseoutputfilesystemtype.md: id: 4243106afbe2 last_write_checksum: sha1:397a4c7e57cbf603931c0caf7cd8d575f1f1e005 pristine_git_object: 4b9f76f011cdf31d55b7ac96822d2dc21bb3b17c docs/models/outputresponseoutputgooglebigquery.md: id: 27191bc677c2 - last_write_checksum: sha1:40612b30cd39560381e0109a5fd4a9e14ea68f42 - pristine_git_object: 04c49f1f8d7fd9a63b6c1422a1dc80a6704ef2fe + last_write_checksum: sha1:38c835d9b8d54cffdc5be7d3f5dc8613fc938672 + pristine_git_object: 2ffd8ae8a3b0a3a690190aa4946b61ecf3e4b362 docs/models/outputresponseoutputgooglebigquerygoogleauthenticationmethod.md: id: 579bfdf1424c last_write_checksum: sha1:15588ef85eaf636d69125299fb26481e2f340142 @@ -11584,8 +12704,8 @@ trackedFiles: pristine_git_object: 7c0c14e80a10bf0c92ba1a4da98dee6da22921d2 docs/models/outputresponseoutputgooglechronicle.md: id: 54c8ae8614b9 - last_write_checksum: sha1:78146f7965a8065f3d0990796cc4fc58cfe95519 - pristine_git_object: 3e77629bc2f8dd1394a45015e759c20d6c128322 + last_write_checksum: sha1:5111e1f9ccd919a75521c3c9e7db8244a82ad495 + pristine_git_object: e6a3fd57a255a68d14917aeb93285e17ffdcfa83 docs/models/outputresponseoutputgooglechronicleauthenticationmethod.md: id: dafa62fcce48 last_write_checksum: sha1:4ed6d5cb2bc78fb289a87809b895dc80c1136eab @@ -11600,8 +12720,8 @@ trackedFiles: pristine_git_object: e9f0316211223d32bea3cd31592fe565b714d30c docs/models/outputresponseoutputgooglecloudlogging.md: id: b2f501ddfb9e - last_write_checksum: sha1:b07a3a9fdf897a1e701b2b3956f4a9019e647cfc - pristine_git_object: d9fe2c33d17d57a9e0edbab37c1bd13c42813c28 + last_write_checksum: sha1:b92078931e6690a3dcb90fb6403bb566b2009b62 + pristine_git_object: a2a5aa220b1bcce2ab37081b209e51b132cdfe66 docs/models/outputresponseoutputgooglecloudloggingpqcontrols.md: id: 210dfac855ff last_write_checksum: sha1:9aaa4d599adb6cf594381898d46322072ad6ba5b @@ -11612,8 +12732,8 @@ trackedFiles: pristine_git_object: 730e1244b73874373902d25bcd814ef6f92bc4b7 docs/models/outputresponseoutputgooglecloudobservability.md: id: cdd379522813 - last_write_checksum: sha1:d629543f052b9f6f58a03bc4bce1a0e1c8d3e33f - pristine_git_object: 16148f1f4926c860db693c06e454c892c3c02617 + last_write_checksum: sha1:2e371efc4a8857ac96f845ab114a9619ea005ec1 + pristine_git_object: 88d0903a711e1572e1fcabe883f2da89fe93bc70 docs/models/outputresponseoutputgooglecloudobservabilityendpoint.md: id: 46f0a1e169ac last_write_checksum: sha1:152b8039d4ef3459dd1ce729edd7109835190eb1 @@ -11640,8 +12760,8 @@ trackedFiles: pristine_git_object: b2828bd19a41dfe8eed856e0849a78e99680a4a0 docs/models/outputresponseoutputgooglecloudstorage.md: id: a817d6e8e2c5 - last_write_checksum: sha1:1dad76c859cfe9a1f24f73eee6f421cb9fbca091 - pristine_git_object: 30037b3610bfef7c8beb0d92f808d40d88cf042d + last_write_checksum: sha1:c1f07ce1891f4a7eb37447e86f67e64bfc747bea + pristine_git_object: f1892cc12e46d1ea4aae0c18bc024b0bbdeea3e5 docs/models/outputresponseoutputgooglecloudstorageauthenticationmethod.md: id: 75c2d82f05b7 last_write_checksum: sha1:512a4b85e1f82ef69e0f8cb319fef1d1505e7bcd @@ -11652,20 +12772,20 @@ trackedFiles: pristine_git_object: e70dada49f4e090981c8bc292b779cbecf3d922d docs/models/outputresponseoutputgooglepubsub.md: id: dfc98eb0f8c9 - last_write_checksum: sha1:757b0436c48955cb050c94e7d34b415af2505716 - pristine_git_object: 37d1b271abd5cc01ecee630e7c37d11a9f05493f + last_write_checksum: sha1:26d6c9dceabfbe889256a59147ee476997ca9e17 + pristine_git_object: 92d247381d58da97466a31a4a6af75c6d26c9e49 docs/models/outputresponseoutputgooglepubsubpqcontrols.md: id: 7b65edcae509 last_write_checksum: sha1:548be73cd29c2e32be3be94461c4ead6942114bb pristine_git_object: fb99f671fb80eb66e4e5518a21a143a8c2b4642d docs/models/outputresponseoutputgrafanacloudgrafanacloud1.md: id: 285282042b84 - last_write_checksum: sha1:7b2513851585441a4f05ad45cfd7308adcbc5493 - pristine_git_object: 907f2fa9f104f88354cd9f6002eb31a6b3e29f40 + last_write_checksum: sha1:d0e68d8e4a613cab27d45c70396a4d357370e44c + pristine_git_object: 4a8ea51b8ee9355a123920cce68ebd89897bcd06 docs/models/outputresponseoutputgrafanacloudgrafanacloud2.md: id: 66dc96809aa5 - last_write_checksum: sha1:d5245c7179f75262406073a9b85749225dff83ab - pristine_git_object: 63cc32cb1c7375d085ca3f021a35b84c7f51ebdd + last_write_checksum: sha1:63c50aaa08efcfa02025682f81f749a1f55787a5 + pristine_git_object: 9cbd3d41c0c440d257ad1361ff9da1342056dd18 docs/models/outputresponseoutputgrafanacloudpqcontrols1.md: id: 168e4fcb1f5c last_write_checksum: sha1:818ec79ce70370f4372321012b51d4efbdd3034c @@ -11688,8 +12808,8 @@ trackedFiles: pristine_git_object: 02ea28ed2bf7cdd58ddfc6f862749f3c0d085163 docs/models/outputresponseoutputgraphite.md: id: 3c07c015faf9 - last_write_checksum: sha1:deb1bf22b6ae86a702255fd118c4c9fef99ea07c - pristine_git_object: e06a2bace7216f3bdab2d4117e4e570b82ac77dd + last_write_checksum: sha1:7739f08240a7cb29e1e45b3466c0d80526ad8682 + pristine_git_object: b8b9eb6bb18bf5a3a880638f1bd8ded034ca2c1d docs/models/outputresponseoutputgraphitepqcontrols.md: id: a49ca6f54bd2 last_write_checksum: sha1:93f511d3d49e091bd1b097a924845da02c4fa054 @@ -11700,8 +12820,8 @@ trackedFiles: pristine_git_object: a57e6b9336a4a2d106e6b9b2ba0f7abec8f3769e docs/models/outputresponseoutputhoneycomb.md: id: eb46b7ddaf6d - last_write_checksum: sha1:a33a3eaa2c6049452a5e7a293bf2c6078837f32b - pristine_git_object: b83fb2f64881ee555ac15b7f50939a9014f3c2bb + last_write_checksum: sha1:48ad225a9c52cf270adf218dc9ab6f2f2b230d33 + pristine_git_object: ed89a9184680eb0a9a1c983e49bfd4d6ab0beb0b docs/models/outputresponseoutputhoneycombpqcontrols.md: id: 77457b909bda last_write_checksum: sha1:4bd746e7d58ebcc421c2335f352d4e6047bd032f @@ -11712,8 +12832,8 @@ trackedFiles: pristine_git_object: ed4123e7e52f9d86ddd7ae96f2e23dd7e814f8ab docs/models/outputresponseoutputhumiohec.md: id: 245ddd98b246 - last_write_checksum: sha1:3708e8d127bac2e96a403240ac2fec5406a30de0 - pristine_git_object: e598893a6f92d404f9f090269196dd72f639c570 + last_write_checksum: sha1:d2477f3afde7ec000e3a2a02dd85b1ef390714bc + pristine_git_object: d4810ebfdd645df77e1cfd7321b77058a0115224 docs/models/outputresponseoutputhumiohecpqcontrols.md: id: 9bf42d32ca33 last_write_checksum: sha1:b205478d3b33f8ea5f1644dec7724656b77ea27d @@ -11724,16 +12844,16 @@ trackedFiles: pristine_git_object: 16370e37536b154924fd47efcfdf7f8210b8dc77 docs/models/outputresponseoutputibmclouds3.md: id: c6143c3f2e1e - last_write_checksum: sha1:51190813d9cb0998a725ca2930a748d68daf60f7 - pristine_git_object: 945e8b663cd4236995134786667b50154ece6b74 + last_write_checksum: sha1:02ae517984fee6a8b8364a20f9f76e2a5ed2d90a + pristine_git_object: 71ecd052c1d983fa0ef26b0331a4ce23e484c8bf docs/models/outputresponseoutputibmclouds3type.md: id: 0ede2b6201e5 last_write_checksum: sha1:3cd8df0fce3a9478f064eb285a3abfd97af8e680 pristine_git_object: 25c7511a2cc299da4acfa0d164b73fc8ef8d944a docs/models/outputresponseoutputinfluxdb.md: id: c211d4992be4 - last_write_checksum: sha1:a4c99e45e863dfd04c95372ab3352c4feb74a8b1 - pristine_git_object: b9ef4b4fc76f9616e431a9a9e35c027657f1e84d + last_write_checksum: sha1:bd0c59f9135d00f544090a60f5faa901386a46fa + pristine_git_object: 4a43d6a0306910db9f0fee4f542b88b9fecde450 docs/models/outputresponseoutputinfluxdbauthenticationtype.md: id: 51bb03b33725 last_write_checksum: sha1:cb0553606f87859b629e9bb8fce7714ec299c7a8 @@ -11748,24 +12868,24 @@ trackedFiles: pristine_git_object: 9395b30b001e459a5752f8135870447d118e3b5d docs/models/outputresponseoutputkafka.md: id: 04a5915ce172 - last_write_checksum: sha1:03a1a46e6beb24ecf966f476029e4584c257d31d - pristine_git_object: b45c7bc042521a07694f835097d61339bc779879 + last_write_checksum: sha1:55858dd758778776d99210c14cba2c66ab08ee37 + pristine_git_object: 18c677c6f2648c4c0d10a7b74e5e52da4a1cdb80 docs/models/outputresponseoutputkafkapqcontrols.md: id: 98c6b3592260 last_write_checksum: sha1:a5c9ba6d3a639598d730c447002f195d119673f5 pristine_git_object: 09b63ff3639c5fbe3d7193b54dd3bded7e4673a9 docs/models/outputresponseoutputkinesis.md: id: b92abdccc740 - last_write_checksum: sha1:8403997c3d196f00eb090c1b38ea8ed5ff372ffe - pristine_git_object: 2cf1eaf6da1a12845a4fec623489dbf5ada63510 + last_write_checksum: sha1:d3b12322ccaf176952783d7ce30e0fd76ee56b01 + pristine_git_object: 75f62d15e29713a16e6e06e79cd4405b834a803d docs/models/outputresponseoutputkinesispqcontrols.md: id: 470b52d1f9aa last_write_checksum: sha1:62fc97e5a2c23ecf3e40735ac0caf0f8205ddcbd pristine_git_object: fe11d296a938b915a14518d6f43a34734c58de2f docs/models/outputresponseoutputlocalsearchstorage.md: id: a3a009cd59b4 - last_write_checksum: sha1:95946d6f9291c73f98be0dc202c5ea2dbd94cc67 - pristine_git_object: a76cd3c78d1a87b486461ac4cc6a7407f8e121a6 + last_write_checksum: sha1:996efa25066c3829f01448e01a72dfff2b3acc3e + pristine_git_object: f221914ce86d3751d1376fe8f72493e03442b263 docs/models/outputresponseoutputlocalsearchstorageformat.md: id: 853de4df0c97 last_write_checksum: sha1:0089ea6aed2c9729c1191bc39ade2aeb8f9a0a3d @@ -11780,8 +12900,8 @@ trackedFiles: pristine_git_object: 0d37fe2f66388c0a7c0f6a514b254726b8cd32c0 docs/models/outputresponseoutputloki.md: id: 55dcf35a3db2 - last_write_checksum: sha1:eafeef03c6eeae369603cbfe8fcf0e0cf8afc21e - pristine_git_object: 42523fa79463bbab3cde97f851c56ec6e32557f5 + last_write_checksum: sha1:51563e30cdefc2be16ac7d04ef32a2a0303132a3 + pristine_git_object: 23303a3cf0f8080f243915bec51a4b2b327a90c8 docs/models/outputresponseoutputlokipqcontrols.md: id: c4f9c9a45519 last_write_checksum: sha1:26f333ee1ffd6783f0e85368cc36ae895fec56a5 @@ -11792,8 +12912,8 @@ trackedFiles: pristine_git_object: af11b234422571494529c81381bd618009936c31 docs/models/outputresponseoutputmicrosoftfabric.md: id: 7abd738e3ff1 - last_write_checksum: sha1:3b85644c12d1f8c5e1ab150924e2fc47d24f514a - pristine_git_object: ab87924404ad874c4f0077ec228f450711f6574d + last_write_checksum: sha1:346049d1841ab73d9b986988cc49f59d1e6ac86a + pristine_git_object: 5a7f91fd20e5abc39258268d96dca1155c8d3e3e docs/models/outputresponseoutputmicrosoftfabricpqcontrols.md: id: 32f87de59398 last_write_checksum: sha1:33ad31bc25c2a19c60a69097d65b724be9990eb8 @@ -11804,36 +12924,36 @@ trackedFiles: pristine_git_object: 459dbc9fd32bbd574d37713d8e26841cb55da652 docs/models/outputresponseoutputminio.md: id: d723402af2c3 - last_write_checksum: sha1:2e13b760b9e91007387dd343794f3099c5c46123 - pristine_git_object: dbf94f720f911db08958041ed31e3e48e9fc2c0b + last_write_checksum: sha1:01ec68a29114bd91a1d72d4b84b8c84ef88b6fed + pristine_git_object: 1a4e87033af1d05639f205aeea11835a442dacc2 docs/models/outputresponseoutputminiotype.md: id: 0e3365ba24dc last_write_checksum: sha1:75a6facc098293029d5d46bd9859023ea3f82493 pristine_git_object: 42ab2eb437e70348b90fe915d2e16484b3542cb9 docs/models/outputresponseoutputmsk.md: id: a290868350a9 - last_write_checksum: sha1:08f412911c36aa54373ba742a2d27be0ec546efa - pristine_git_object: 592250761ea69cbde258ac44c40a347b182a4703 + last_write_checksum: sha1:60d63ddba56bccc90f75320b79a37db6609449cf + pristine_git_object: b018dcfc370b929fb4f1755735756c23723a4114 docs/models/outputresponseoutputmskpqcontrols.md: id: c101b2bee48c last_write_checksum: sha1:c76033aac6a9d54ee98b98f8bbaa1b80cf1e90d5 pristine_git_object: 33df0fecaefc64d456e7f7e514afefcaae07b92c docs/models/outputresponseoutputnetflow.md: id: 9f91b6dceca1 - last_write_checksum: sha1:7b4073f51891c464e129e876245dbed5aeb5e8a1 - pristine_git_object: cf80066847b8c6aff09ba1fb77368393759f964d + last_write_checksum: sha1:63d49b0865b4d77e05a36cbf99938ccd306bc397 + pristine_git_object: 2bfb60ef9572b0897442aecddc98919dbb82b23d docs/models/outputresponseoutputnetflowhost.md: id: 7eb8bcbe625d last_write_checksum: sha1:052e7d72cb553e5329d7929d6fdc24052117cd83 pristine_git_object: 20c0e331cae9ee62bbf659d15afd5abafeb80183 docs/models/outputresponseoutputnewrelic.md: id: 5204f08fcc1f - last_write_checksum: sha1:3d60c94428b340be0f908b56f6e5843d10135d56 - pristine_git_object: 40f53f0a552ce999d0739a18fb9b229c66769356 + last_write_checksum: sha1:e7dcadbc383c3b2d9e2f64009f954e4a8dbd3cbe + pristine_git_object: 060a27cb3e81ee0263d3e34b585c680ac8f8604a docs/models/outputresponseoutputnewrelicevents.md: id: 3a91c240fc84 - last_write_checksum: sha1:bbef2dcd938a88aeb72fd49b2eb848d0a9e7cace - pristine_git_object: e73cfbb63776af79300af9f6688b6ec2c4dea84a + last_write_checksum: sha1:f6c36c9107ab54f534c8de26efc012e5f6e7f285 + pristine_git_object: 8514ec0035293a106bb7f267b1a033fa44e8982f docs/models/outputresponseoutputnewreliceventspqcontrols.md: id: add9d88011b5 last_write_checksum: sha1:a11130135084544fdd8a9555588feb72a7eb4a0e @@ -11852,16 +12972,16 @@ trackedFiles: pristine_git_object: 0263236a70103682922c9a04921c30485fd08354 docs/models/outputresponseoutputnutanixobjects.md: id: 1cb3cd9a93a3 - last_write_checksum: sha1:4d3cd7f532d239270dda96f70750c0ea93d8ce0b - pristine_git_object: b2607c74253f4a5b0e2fbb86e22d04f3c47d9543 + last_write_checksum: sha1:3f43cddae07312c94f6592a3409dcb92373a12c6 + pristine_git_object: ed1aa550756cc142bfd514a9a9652233ffff9d33 docs/models/outputresponseoutputnutanixobjectstype.md: id: 7d0ae1ec5021 last_write_checksum: sha1:0ae8f62766c5e29395c601d8b936825ff136575a pristine_git_object: b07ba79a22a81926a0f8c6676ba1d2d1716a328f docs/models/outputresponseoutputopentelemetry.md: id: f12008ff473d - last_write_checksum: sha1:2c056805c26df6e7fbd6cebc4e5fd8ff8f7ec8d3 - pristine_git_object: 4b887031c009cfefac1bbe30345e4c321b3e1322 + last_write_checksum: sha1:5a96c2c6f0cd7909696786479ef80a96346e971f + pristine_git_object: ed45b735549234b649a4cb5a4c5d1fa23858d796 docs/models/outputresponseoutputopentelemetryauthenticationtype.md: id: 7782a63d6741 last_write_checksum: sha1:62418a9a34c2dafe62dc4cd08c2d7ca04a7cfdde @@ -11880,8 +13000,8 @@ trackedFiles: pristine_git_object: 35e8d55c654c9590d4ce7b01dc1694eef4a796a4 docs/models/outputresponseoutputprometheus.md: id: "483350017891" - last_write_checksum: sha1:8d97669a36addb625eb3c164f4bac1037290f0fc - pristine_git_object: 3229139b8b2ddbc4edd69fd4e6cd0029a150b139 + last_write_checksum: sha1:34e7f1a9fc75a0ab22b3d0934813a70c56627e58 + pristine_git_object: e8b196554dfc7c3fa78110967654d07c9de7787e docs/models/outputresponseoutputprometheusauthenticationtype.md: id: 6f09c7b6d8de last_write_checksum: sha1:928286fbecd28ca2675821b720f794e0b27f44e8 @@ -11892,8 +13012,8 @@ trackedFiles: pristine_git_object: d9c1a424fe30eef5a53a26dcec73f18c4fa2e291 docs/models/outputresponseoutputring.md: id: f9f1ea7afe85 - last_write_checksum: sha1:ecaaecb4872e1977d2d7f97317166b1b167d35e2 - pristine_git_object: e22596d198ef490785eee7c443ef56d1b5283ba4 + last_write_checksum: sha1:5e147b9db9de5a9a9eb3a312549207ae5c4a478f + pristine_git_object: 8ae330d915d3dffb20f096d3be1203a48d76541a docs/models/outputresponseoutputringdataformat.md: id: 86934eedbd37 last_write_checksum: sha1:b31c097ee6467c602b4be27fdb18480cdfa474cb @@ -11904,40 +13024,40 @@ trackedFiles: pristine_git_object: b7c99c11685dd403d5f5d2da60008ec9bb093cf6 docs/models/outputresponseoutputrouter.md: id: c3e617dab2f4 - last_write_checksum: sha1:b1c06c830c0c67dc3ef161614fb3d60d13bcae03 - pristine_git_object: 428d40f41f5f862e2341ee6e836587c0ff94b3da + last_write_checksum: sha1:67c56a7b045bab2d6e722b89d37f1b4d367cbb93 + pristine_git_object: 1245ccae7abd644819a4a9f94f09ca4855fa8964 docs/models/outputresponseoutputroutertype.md: id: 03c88529ea2e last_write_checksum: sha1:d3c3038dc144125038552c72da8ad156cd9740c2 pristine_git_object: 39d973c69ec6cf1f3a8785d9a59fbdac5e67060e docs/models/outputresponseoutputs3.md: id: f665bc3a232a - last_write_checksum: sha1:d0781c868397e17361a57577fb6135da7ad8c7bf - pristine_git_object: f4f47a3fe266249c1a7aa17f71bd360546f47630 + last_write_checksum: sha1:4a3997672730772dbf0fe33d9598526134b6b8a6 + pristine_git_object: 5d25c3e182429f122a70413504741cedd9d57f41 docs/models/outputresponseoutputscalitys3.md: id: d5b943060fcf - last_write_checksum: sha1:3bd3149f53fc59228339427caaebf8dede40c3ec - pristine_git_object: 0c5f1baf846ab79af07ae8b0820cc0c495c2505c + last_write_checksum: sha1:cad4c9cd9c8e71e5d9b87e46fca309e5666bdd35 + pristine_git_object: 58f8a922510113902df03d77ddd0fac28dea18bb docs/models/outputresponseoutputscalitys3type.md: id: 8330a461f790 last_write_checksum: sha1:986b06b0bf3a106269775db6ebd053f3f77104d6 pristine_git_object: d190006ee38d44b81ad66d26dd7cb01e23c51a5b docs/models/outputresponseoutputsecuritylake.md: id: 063328c29a66 - last_write_checksum: sha1:5a5a35ec4aeb14ba03df8f51826629fba49fc4bb - pristine_git_object: 36ecd6b2a6c1bbab7ad75cdea1b6ff34e93958b5 + last_write_checksum: sha1:3fbe9aaec391c597fabdd39a12a0854dcfdd8d38 + pristine_git_object: 589b7be971b11181bb403e43a00f886d89363bde docs/models/outputresponseoutputsentinel.md: id: ca3df8b8a8bf - last_write_checksum: sha1:b2a3d0a4042cdcef51592e6c40b05c2080b18fd2 - pristine_git_object: a14233b822e2cd216e3c9f685e19ab157afb3565 + last_write_checksum: sha1:f96c87d308bbdc825617f07dd99f0a152da1bb94 + pristine_git_object: 10dfcbd1964be3232e05aa8e5469c17c165a1040 docs/models/outputresponseoutputsentinelformat.md: id: 39c9731d0266 last_write_checksum: sha1:14f037808927ec3fb3f6853adf01f78eb0994565 pristine_git_object: 09a7527fe6d407249d63274d02558562338a4a55 docs/models/outputresponseoutputsentineloneaisiem.md: id: 609583aadb29 - last_write_checksum: sha1:2f7001f3d06ed329536f404da8d9e06a4dd0d659 - pristine_git_object: f3934170c7f747aa1d499704353564acdd47a8bf + last_write_checksum: sha1:cfd6f04e91ebce87467adc0b5a47ecf9daa15998 + pristine_git_object: b12085622d2c6f3637ceff35e66cd4caf489317b docs/models/outputresponseoutputsentineloneaisiempqcontrols.md: id: 6b1954b8ca0c last_write_checksum: sha1:93d0f0b873cc7620e6f359eb4c7d0678e223877c @@ -11956,8 +13076,8 @@ trackedFiles: pristine_git_object: d886c5b97716de20585f722fcfe939068eb4c0d5 docs/models/outputresponseoutputservicenow.md: id: 6030b621ea48 - last_write_checksum: sha1:eced006bf9235562fe1885509712e9c0f8dbb589 - pristine_git_object: 869f75d1d164ecc64a4dccefbebe03cbfce9b88f + last_write_checksum: sha1:1b363c042f853402c431b2c88c9b9cb97597e2e7 + pristine_git_object: 29473674fbfea6d94630fc7944ebc2037df6e225 docs/models/outputresponseoutputservicenowpqcontrols.md: id: 3ede632ffe6a last_write_checksum: sha1:0fd75a62ae9f5069932e5755903b3b94a83c7bd7 @@ -11968,8 +13088,8 @@ trackedFiles: pristine_git_object: fe98d38c86737f98c69135f68d1d278ca772c8b6 docs/models/outputresponseoutputsignalfx.md: id: b4e25513f4ef - last_write_checksum: sha1:fddfa580f147c6bd30fbec12149dea027d6db120 - pristine_git_object: 9d4bf34706771cca0187355cdfd158c9f8dcb0b7 + last_write_checksum: sha1:0a2acd1dcc8a6c4c6077cde0d2d54424ec9987d3 + pristine_git_object: f5fb691091c7404a0819dbb18467d1026c6785ca docs/models/outputresponseoutputsignalfxpqcontrols.md: id: e1f15d35e6e5 last_write_checksum: sha1:f60393656f33c9835ec9c6a3912e49779e377068 @@ -11980,16 +13100,16 @@ trackedFiles: pristine_git_object: d751290e145d8bb56ab2a5b0853e61038b0535ca docs/models/outputresponseoutputsnmp.md: id: 600db83620ac - last_write_checksum: sha1:fed76b2e98caaad3abe5fe6220ba8346223c0c61 - pristine_git_object: c46f92ecfeea63260cec162e67ab9b8e1393b84a + last_write_checksum: sha1:21eaa4f748b256a02facd0663da2f7059d6d09b6 + pristine_git_object: 6f5607c67f52f9ead37a6877dd512915d511cb47 docs/models/outputresponseoutputsnmphost.md: id: f753c53906f9 last_write_checksum: sha1:9b78ee80e5873946c87e828303aa91f6c6a7e2a5 pristine_git_object: fb4aff3825adde271c13aceb6bcbfa96c465ff36 docs/models/outputresponseoutputsnowflakestreaming.md: id: f8e6e5f4a486 - last_write_checksum: sha1:dd35e4fa9e4668586e3e65661dd2db799b669490 - pristine_git_object: 370642a54968edb6e885d0932a38a6b300fae8dc + last_write_checksum: sha1:17fdad7f2922951fd8c967289a4442776d04e4b2 + pristine_git_object: 7389869ddd83388c20010e65e131963bded727e6 docs/models/outputresponseoutputsnowflakestreamingpqcontrols.md: id: ef1c717c3782 last_write_checksum: sha1:f9b273cdc2a79e7a1b92196ffc17dcbc7ccd0a90 @@ -12000,8 +13120,8 @@ trackedFiles: pristine_git_object: 0f8aa6bac502b12c5bd252d6ddedf33a7b6441f6 docs/models/outputresponseoutputsns.md: id: 803b362feaf1 - last_write_checksum: sha1:dd1ae8110e416f4025a2d8e6cf75fd4a4aaebad5 - pristine_git_object: 40173121d55ed598790a88201ee6bd0225021a86 + last_write_checksum: sha1:8e71b224c983ca22f34da67d3e3fa3866a263a37 + pristine_git_object: f8db641be6fa117bd191f6ca96d6eb488ec49e40 docs/models/outputresponseoutputsnspqcontrols.md: id: 4fafe476be07 last_write_checksum: sha1:d3baee1690662bf0915e93ae734a0ccf58154999 @@ -12012,12 +13132,12 @@ trackedFiles: pristine_git_object: 3c04a218263e79ddd7154fb0913fff5300cbbbd0 docs/models/outputresponseoutputsplunk.md: id: c50af938c634 - last_write_checksum: sha1:4fdd7f2f5178068164763094a20e22a908e4f89d - pristine_git_object: 85538ed09f5fe281de3cff9b4b37670432fa49e4 + last_write_checksum: sha1:db57b61d9aa3c3457fd618c5090f27801d830bc0 + pristine_git_object: 7a0a0953c6b02bbf2cb0349278019f66a6ae501e docs/models/outputresponseoutputsplunkhec.md: id: 10f0a3cfb3d5 - last_write_checksum: sha1:4aeebb710f79ee1356ddd2a96069280d997b8cef - pristine_git_object: 19ab92d113bd03f78773d94c6c1cccda1bafe4f5 + last_write_checksum: sha1:991ee1e3eea964cae6dad525da5e1e98bc941533 + pristine_git_object: d6a4236714777d59c03a830172836c24f1f10e31 docs/models/outputresponseoutputsplunkhecpqcontrols.md: id: d48e9c2bd37a last_write_checksum: sha1:94e5a3b4ab9800600edf5b3c4dd6acf4f92ede52 @@ -12032,8 +13152,8 @@ trackedFiles: pristine_git_object: 3ef450d6c774b4b54a7d744ac7c2e7e4db70858d docs/models/outputresponseoutputsplunklb.md: id: 06aa6b6b4298 - last_write_checksum: sha1:b73d171c93322b4f9523b549a4cfa6280f282c01 - pristine_git_object: 6adf2fed22118a8db4174cfb6f239baf60805ff9 + last_write_checksum: sha1:ae0515b360c70916d2adbba33cc547f08c69a74d + pristine_git_object: 9972a9b99605a8050a197da80abb60be6a440356 docs/models/outputresponseoutputsplunklbpqcontrols.md: id: ab31dbfa2ee7 last_write_checksum: sha1:0c5e1aaa3e6be15b06e0dbfacc71120948ec1aad @@ -12048,20 +13168,20 @@ trackedFiles: pristine_git_object: 03c0eb838615afd2c1d6e1145d6be9544c9b0d4a docs/models/outputresponseoutputsqs.md: id: edd53bffe0c3 - last_write_checksum: sha1:4a85413e5117e7800d0dd7853bbac26d5251ffe5 - pristine_git_object: 98abfe1ba744cc892fe09026c43a1b357fe74808 + last_write_checksum: sha1:21ae29e5afe6764988efd49c480bd2916be8f756 + pristine_git_object: 6a84cc3d5f5ef29688c20d9e6febb4e2f1ba1857 docs/models/outputresponseoutputsqspqcontrols.md: id: 875cb015c21e last_write_checksum: sha1:65c757cd3aabf0465a4d780e00b2f56daee83769 pristine_git_object: a140f0eeca6eafda59f9e5dcff575418e2cf1955 docs/models/outputresponseoutputstatsd.md: id: c325f4cd7b33 - last_write_checksum: sha1:ca91c890f7301f56021f3e2b1c236e26b6feccc0 - pristine_git_object: ab5903176c70c9de8c747e9ea698cad234d60af0 + last_write_checksum: sha1:b7d859d4e930065e38ed466ea4528c9f3fbede88 + pristine_git_object: 8e5d8b139ea87ccbc6f2170b0218a562e9507a2b docs/models/outputresponseoutputstatsdext.md: id: 64c739aa8fda - last_write_checksum: sha1:944fca90c0df9a268f551d4a417ca73e8fb76f01 - pristine_git_object: 2d2526a2ada28b28e2359beec50e184555184904 + last_write_checksum: sha1:6e6109dd5cdf81c066d2d5203b377761c1f90d4e + pristine_git_object: 70d3c80fa14f00328708482f5fc0b39893ec9ee7 docs/models/outputresponseoutputstatsdextpqcontrols.md: id: cd9b6cb95dd3 last_write_checksum: sha1:86349067cbe657eee7946cb792c807ec63469991 @@ -12080,16 +13200,16 @@ trackedFiles: pristine_git_object: 71260498b51e6960653262e321bf7a107db6c5ba docs/models/outputresponseoutputstorjs3.md: id: 3d326fc90757 - last_write_checksum: sha1:640afa3056e202a8e37a731fd510bf31edd346de - pristine_git_object: 506c1147cac8bd14d577cbe67a74cf2b8d90054a + last_write_checksum: sha1:f975f8acf1eb01e5e9b7271d77b3d64dc8a70d74 + pristine_git_object: 9fcdc2857f9f998b62a965e967cb462101eca7cd docs/models/outputresponseoutputstorjs3type.md: id: c61833bd3a5a last_write_checksum: sha1:f787b52dbf0d775bf31092cca7c788265432793e pristine_git_object: 09793e9552cb953ec33863a8fb9b49e8604af4f7 docs/models/outputresponseoutputsumologic.md: id: 62a391a5bb67 - last_write_checksum: sha1:d5a139ad43dd275f38c18877026e25b468590b06 - pristine_git_object: c5fc7c24a488dd4da762698d411bd17345ce39bc + last_write_checksum: sha1:2731b276e860ceec73d6442e50a45ec13f5856b0 + pristine_git_object: 2dfa4e193511e1dd3dd07e481fa923f353789f70 docs/models/outputresponseoutputsumologicdataformat.md: id: d1327fd7d000 last_write_checksum: sha1:720b523f275d54b7fbe6fea29daa6051090b2c3c @@ -12104,8 +13224,8 @@ trackedFiles: pristine_git_object: 95d97381a4918698ad659cf8e0424f01c6b6d843 docs/models/outputresponseoutputsyslog.md: id: 8d0cef47b1c4 - last_write_checksum: sha1:a7c3f26cedbd1f2b36454350420edda9ff445209 - pristine_git_object: ed6044e81f13e7f7b12a6d237c9f51cf3466e5de + last_write_checksum: sha1:65f99c1433cbb97377531040f6242617cb4844db + pristine_git_object: 433462ffcf5b213899ae39a4a30e616b56d6eb97 docs/models/outputresponseoutputsyslogpqcontrols.md: id: 0f49d89ff24d last_write_checksum: sha1:f6c7c8cc28f8fb7960904a3656172a72b31f514d @@ -12120,16 +13240,32 @@ trackedFiles: pristine_git_object: 42ee90b428ce74a6b5d2a4b9db9f82d69f4cb8f3 docs/models/outputresponseoutputtcpjson.md: id: 08d819fcd6ea - last_write_checksum: sha1:a9bbd6ffa291012d816c5942a9df13028463794c - pristine_git_object: 9731bc1a57e1723af0c219733fc101be3664ac6f + last_write_checksum: sha1:c2a0fa49894d2e4ec28923c944c184dcd0db23c4 + pristine_git_object: 4154e57345c6f7a7b23de4b1d85f560f6fe76489 docs/models/outputresponseoutputtcpjsonpqcontrols.md: id: 7e876a692427 last_write_checksum: sha1:b66fe8163fc810b2ccc17dcc207f3c3b884a76dd pristine_git_object: 00ebe03a82b7af8b045fb09b67b97cb43adf929c + docs/models/outputresponseoutputtraversalotlp.md: + id: c9bf3a2d2d48 + last_write_checksum: sha1:a5f90b72f52e409e8ee46ad473da7b2e3b1007d4 + pristine_git_object: f2e094d2e6c445ce0e8993e91182f5cc31cd3cbe + docs/models/outputresponseoutputtraversalotlpauthenticationtype.md: + id: f25c21fdfd5a + last_write_checksum: sha1:0f24b2b019e56d2057a95ba5309386783170d0a1 + pristine_git_object: a9ff65f7870feebe6f6d793c1258689fa4254499 + docs/models/outputresponseoutputtraversalotlppqcontrols.md: + id: 503b378b8e71 + last_write_checksum: sha1:ea6a575ed826f7a68f5a483955a1a2fe30831e76 + pristine_git_object: ff40f6875d60a663ca302780eca7322467c21ba3 + docs/models/outputresponseoutputtraversalotlptype.md: + id: d4f2d7fe2b27 + last_write_checksum: sha1:521717e0f19bc247137191f3476c4aa49f4703c1 + pristine_git_object: 936083853482333177434425fa6ccc491f797933 docs/models/outputresponseoutputwavefront.md: id: 3d8b0f0c933f - last_write_checksum: sha1:4503249fe5204d4d2d080723678f7aca1b8ab084 - pristine_git_object: d2de4ca2bb6f6b619a65c9c1c9f4fec9d740e62e + last_write_checksum: sha1:765882b86d724c27d2e232f2d36ffd93baebf2d7 + pristine_git_object: 7868f5821ffd34a8f059f36b7f420d15905547ee docs/models/outputresponseoutputwavefrontpqcontrols.md: id: 29d854ea34b2 last_write_checksum: sha1:061bff500bd8d6d8fc2116b191a85aef68c63acd @@ -12184,16 +13320,16 @@ trackedFiles: pristine_git_object: cefe266ac4b13d90c6e839165f40e73c5efcc8af docs/models/outputresponseoutputwebhookwebhook1.md: id: 76682c9f741b - last_write_checksum: sha1:8998ad828b196e44497e23ddbef7fd133f8520fc - pristine_git_object: 64469e339dbabfd368d04cca8134524ccc19c143 + last_write_checksum: sha1:db276a39605db6c0b40f1441f1231f7343cf5aac + pristine_git_object: ae85e6003b0f6224a862a4076190cbf61a7af42d docs/models/outputresponseoutputwebhookwebhook2.md: id: c5e00d98f79f - last_write_checksum: sha1:4adbc9d44d855aab2e033e7cc385ea528dd3620a - pristine_git_object: 90f1270d39fdb160d408783c777c59b4619de5ae + last_write_checksum: sha1:5628b73be424b41b4d0320226aa10fb38c147441 + pristine_git_object: d1924230e81119ba7c70f30923445b25df723a32 docs/models/outputresponseoutputwizhec.md: id: ad646e280edf - last_write_checksum: sha1:7e435e96cb6e4de8c3dd0a801848deea54b8d23b - pristine_git_object: e6753f1fe60fe908ffabb3700c200db265e132e2 + last_write_checksum: sha1:253255b69f32ebdf10f4355a3d4dec99b5e779ec + pristine_git_object: e1cefc8f31970328411b8e7d529ac9295507a270 docs/models/outputresponseoutputwizhecpqcontrols.md: id: dff1904600d6 last_write_checksum: sha1:ac53cfb61f18726d1f5b67e544781497b948e70f @@ -12204,8 +13340,8 @@ trackedFiles: pristine_git_object: 5f6fb54bcfe7313b9630f934ab3d1b8b6bf72b20 docs/models/outputresponseoutputxsiam.md: id: 4c55c9417a75 - last_write_checksum: sha1:89c44291581a5ca75505f305ee723d676de0e71b - pristine_git_object: 58ddf4c695f4281fbd14beebd3b39c0254f2a22c + last_write_checksum: sha1:5e64ab434f71afeb9f75e2c2edb89f5c1b8e4507 + pristine_git_object: c05efc7a1427c78a0d7e118378aeba7ff5f21cd4 docs/models/outputresponseoutputxsiamauthenticationmethod.md: id: c9a183282222 last_write_checksum: sha1:2ce40b26f715b5845acbca381f17dc145ffa02ed @@ -12254,6 +13390,10 @@ trackedFiles: id: 9445f3e6471a last_write_checksum: sha1:6590443c5c5da2a9849e44b4492ec0734fd11ba3 pristine_git_object: 63ac3fc87572eba7aac14c07112cc3fb84caf398 + docs/models/outputresponsesendas.md: + id: f2f127312cc4 + last_write_checksum: sha1:eb2df55ed281b9d79fc6ed42708717d153e8c50f + pristine_git_object: e1e66333db640eecd466e718f7c5a482a9459fa4 docs/models/outputresponsesendeventsas.md: id: 96cff308214b last_write_checksum: sha1:7a29476d68579739dc13242fc77d2cc4d9beed00 @@ -12282,6 +13422,10 @@ trackedFiles: id: 8258fcc4b783 last_write_checksum: sha1:eddc84e762c1d90c25e8f64b35745efb2ebf1ec1 pristine_git_object: a38c77ec58932dbe18a1b262b30ac625e997af02 + docs/models/outputresponsewizdefendsourcetype.md: + id: bd746e40dbde + last_write_checksum: sha1:293710bdf4175ca243f725165a47eb864e730aed + pristine_git_object: 440b99dc28ff8d24a80b095ad8bcf7988acd21aa docs/models/outputresponsewriteaction.md: id: b1777aeef45c last_write_checksum: sha1:41e44eb3d3f506ce7e1ab84c7634bb02b3b87d4a @@ -12300,8 +13444,8 @@ trackedFiles: pristine_git_object: d849bf15c6a6509cee963e402a3a770d8e79a030 docs/models/outputrouter.md: id: 7bfc543c12e7 - last_write_checksum: sha1:fd027ee34b495be6db6d10d100e758c19d65b0e8 - pristine_git_object: d67747c1ac8d592017a19ffb1912dce9e9e1ad59 + last_write_checksum: sha1:dcdfc88ffc0584961e9a75ee9ebe37fed28cf678 + pristine_git_object: a1826fb8013338ba3d7290440459f9f503951e3f docs/models/outputrouterrule.md: id: c284a0e80882 last_write_checksum: sha1:d290d02eebe0ae6e56e985e0818ca48680c1fb71 @@ -12332,16 +13476,16 @@ trackedFiles: pristine_git_object: 7c1d7715fd24666fa2f0493c01378bb47f13d904 docs/models/outputsentinel.md: id: 03b521a73712 - last_write_checksum: sha1:42b5b33356ebd3a8aa94d68c44f90dfa0af24e87 - pristine_git_object: 151a89c726f5c3c82f8ec349b38252165638ae43 + last_write_checksum: sha1:5b7d760497e007d325ffa3064feeded85e333dc2 + pristine_git_object: 251d28bb510be99056c40c138d890650c9101db8 docs/models/outputsentinelformat.md: id: 27648ecebb8b last_write_checksum: sha1:abe05d5c79128d683faca4e9001491ba21213445 pristine_git_object: 505bbf3a174c2b941c44d7dc2a60d23f5f375e5d docs/models/outputsentineloneaisiem.md: id: 8c9d239317ee - last_write_checksum: sha1:7ee50f10896d631ecd789b67abfeaea14fffe567 - pristine_git_object: 521ab46535fabb126d3eaad40e48bbf6111b920b + last_write_checksum: sha1:a3c8e822fdf8f6c42136224b93cc82c196837d0f + pristine_git_object: 9403038f9be3962280e3de6946c63fbfbf7e6808 docs/models/outputsentineloneaisiempqcontrols.md: id: 6c5b5ecc52f8 last_write_checksum: sha1:ae1a61324f682dd907221d479d8598635355ca81 @@ -12372,8 +13516,8 @@ trackedFiles: pristine_git_object: 98ac02448ea51fea21a0c70465842dfa42b5331f docs/models/outputsignalfx.md: id: 2ce4012a829e - last_write_checksum: sha1:43b3f64b38294b83466e16b604e41bb96a8d4cf5 - pristine_git_object: 24973fe409c612ac1dfa07ccbcf3d1d007389bdc + last_write_checksum: sha1:4e7e90a5e03cb6de13776a6598c58a23c316fcb4 + pristine_git_object: b88f09da82e9cb795e3a1ba3719a9e644679a7aa docs/models/outputsignalfxpqcontrols.md: id: 870b52f48d02 last_write_checksum: sha1:b4776fe9641aefd07cad7c16ef92ac9ff910b267 @@ -12416,12 +13560,12 @@ trackedFiles: pristine_git_object: 2cf92ef5bf48f1a8c39c701cbddc3038eefdbb68 docs/models/outputsplunk.md: id: bcf587b5fbfe - last_write_checksum: sha1:d7192068145aa4b6acd79b262453040801f9c3c6 - pristine_git_object: 233f2d32d1c5cdaf8503d6dffacc06f0162a338b + last_write_checksum: sha1:e87f7bd713dd87b452ea9f6e83ae5c7401a13606 + pristine_git_object: 2bd8a907855ff7a7687cc268054caf6d449769c3 docs/models/outputsplunkhec.md: id: 90814512ad31 - last_write_checksum: sha1:451201dbe0753a422f84eea166d272fb62190cf1 - pristine_git_object: a15387406e0d7b5fd1079a9ab57effff440fdc95 + last_write_checksum: sha1:957c7da0af137714d398bd1019ad92bed187f678 + pristine_git_object: b2b526e7a443ab6d63bfd4317a185be5466a9320 docs/models/outputsplunkhecpqcontrols.md: id: 2c28284f1a2d last_write_checksum: sha1:1fd7314a2e55e8bbcec06d64fa0f8263f71c29f6 @@ -12436,12 +13580,12 @@ trackedFiles: pristine_git_object: 7f19a3bc55aeb22ed851c5ac65f3a20c35dcb7ce docs/models/outputsplunklb.md: id: 16f55b0ec424 - last_write_checksum: sha1:e22b5df6129a0020009d2ee0b5b455d33be20ea1 - pristine_git_object: caf473574d43efd43c886fd022545478fbb02b0a + last_write_checksum: sha1:bc0fe62b3ff3309db338748baf53b6f83373f23e + pristine_git_object: 5e069f41c4e83334fc7e9f4b35527c3f49899105 docs/models/outputsplunklbauthtoken.md: id: d942f69099f2 - last_write_checksum: sha1:5135d399ff06d3a4253985edc36dd000cfbe789b - pristine_git_object: 60ec480aab267331b2877fa5bacdd47b0226e387 + last_write_checksum: sha1:6dc1889f936b2e2d8a98b1cfa12da2132cc8255a + pristine_git_object: 5279441589ec51c8ad3270615d4e4d3118e84a82 docs/models/outputsplunklbpqcontrols.md: id: e5d8a8146ea3 last_write_checksum: sha1:7eea5396869c0c1636d33ec51832945a86ae5864 @@ -12536,8 +13680,8 @@ trackedFiles: pristine_git_object: 23d00b28fc8d3903abb171caadc5c02434fa9331 docs/models/outputtcpjson.md: id: c065e344e101 - last_write_checksum: sha1:155ec19112328d0382932fd769d7754a8d6ec1ec - pristine_git_object: 25dd6d9545937689ccdfa9e2d3872bd1f88ad501 + last_write_checksum: sha1:6b88f76fde6d0e15f07b708d729173de61f06362 + pristine_git_object: ddb49cad282223707b5e08bd42461c3991da108f docs/models/outputtcpjsonpqcontrols.md: id: e58eeb861f60 last_write_checksum: sha1:acced4d10524d8c0b1e2ffa397df9623c2d0ca58 @@ -12550,10 +13694,26 @@ trackedFiles: id: 3b5ceb7ef6d5 last_write_checksum: sha1:96e924b558858405c88eabcbbb0bec36f746ab87 pristine_git_object: 6d4fe1f6548a8b9122e863daeb06d5dc255a7549 + docs/models/outputtraversalotlp.md: + id: a4a7ec0e5e6f + last_write_checksum: sha1:48a9a4e3360e2ba32dc1957fb4bbab9be1f9a3d3 + pristine_git_object: a7608293f8ba11de45ff969a5f795443621b0a30 + docs/models/outputtraversalotlpauthenticationtype.md: + id: 04d881964a9b + last_write_checksum: sha1:56678f8a1dafbb9e216a46f29e3da984489b142b + pristine_git_object: b633ce4152a88e03a02d6a309482803275b117e7 + docs/models/outputtraversalotlppqcontrols.md: + id: 31ac9c8a56c1 + last_write_checksum: sha1:08e08302f618c836036110c12d059b62b9173093 + pristine_git_object: b83515547740fc417e15406a873b64ca2618b33c + docs/models/outputtraversalotlptype.md: + id: 1c7d1a1577c6 + last_write_checksum: sha1:6602da92364b58d9276eead50716c51df03ed3c9 + pristine_git_object: eacc399a1a759fa3fb853f19e8f7e08898c1689c docs/models/outputwavefront.md: id: 73fa435fcd95 - last_write_checksum: sha1:991c4a66532d53a403d774b64452b30dde8248c3 - pristine_git_object: 7c979f2c9cb73dcf51d30727f64f164abc5fb113 + last_write_checksum: sha1:0bcd4c607070c6a3c1a50e7517acf1a1a0194fc6 + pristine_git_object: 57485f76e6b0eefc56f5f512717acfe4907ae53e docs/models/outputwavefrontpqcontrols.md: id: 8e7d762552e0 last_write_checksum: sha1:11af7fa068f2a495362d256a4c2aa93c666aeb2a @@ -12616,8 +13776,12 @@ trackedFiles: pristine_git_object: 80f02c31b718381a89cc1631769463451a62334b docs/models/outputwizhec.md: id: 199fdc64c53d - last_write_checksum: sha1:ec24be943e3f53b0107e800c57efaca873be5069 - pristine_git_object: 5d500bc310ecabeaf75402c92d3bd5080440f2a7 + last_write_checksum: sha1:27b730a4dcadf170f06a4cdf8b6a0261ce39d44b + pristine_git_object: 0f52d83676555fa558653e3ebe183c9bfc245f6d + docs/models/outputwizheceventformat.md: + id: 46033b0db6fd + last_write_checksum: sha1:d5707307ef16149b998168ace6287561a59b4507 + pristine_git_object: cc66eba3f85cd6d6673fe44c9de159a63ae599c1 docs/models/outputwizhecpqcontrols.md: id: bfac6a997922 last_write_checksum: sha1:9611a73ec7447bf1900d434b9f6ce9b5521bacf8 @@ -12652,20 +13816,20 @@ trackedFiles: pristine_git_object: e49acc746d1a29d2a25dc704a676c02857d01478 docs/models/packinfo.md: id: 1cc26c7e105b - last_write_checksum: sha1:0c1384fbf1925b39706127770ee18183bdaa1423 - pristine_git_object: 2c59bd26f4b74f9f2f16ced8bce2f68fe98b6000 + last_write_checksum: sha1:30c263a8b4b99cf7dc8d3ca6f2b38d3d2aa8c3af + pristine_git_object: c7269fc644d018ebfe8a14874da30c1136fa8189 docs/models/packinstallinfo.md: id: 78d53c382d88 - last_write_checksum: sha1:a6b854b1bddb7e867dc694d661e7eeb140c08489 - pristine_git_object: 4fa94115e0f315cdb7864436dae216fcfbcc3007 + last_write_checksum: sha1:b5be077385bd54df1e9791099f0df612cb133ec7 + pristine_git_object: f35fa4ad0e9eafc105d3bf60d41d2fe08e768c2f docs/models/packrequestbody1.md: id: 3845abbc326d - last_write_checksum: sha1:27d682be8a2d1d16dfa5bd8e3498a105d96a0c4e - pristine_git_object: f47201dd9dcdbe3a65b77336f4b825b5ff12c6d6 + last_write_checksum: sha1:b02f8db40365b26a83383785e9c5e427621af45a + pristine_git_object: c7c59cabaa99165380cd1c3220d29d06aa1ba8e0 docs/models/packrequestbody2.md: id: 2b11748d6796 - last_write_checksum: sha1:4eb43cf77f16a35997e0cebb84b9102d7a2b2c01 - pristine_git_object: 5c071f5bb6c7b0cee1ae295df297a55079e4081f + last_write_checksum: sha1:089c263bb76c837b64edb642cb949b554179272e + pristine_git_object: 4e1f757fd2528e5127183f364ef1a21dbaf5a384 docs/models/packrequestbodyunion.md: id: 09bcce03aa14 last_write_checksum: sha1:ae1dc04b4f73c669533f0708141379f1900a2cdf @@ -12680,56 +13844,60 @@ trackedFiles: pristine_git_object: b9161213202177ed6f449c7153ba6e44a63f5a64 docs/models/paginatedconfiggroup.md: id: 165ef25c4ff8 - last_write_checksum: sha1:a6db9f258678f6e1780717daab5b86a9f27bf17c - pristine_git_object: b5b460cdcec7649dfa766f361b2f25b9192c0407 + last_write_checksum: sha1:14056b1cb8cae1b0a01e23ca4e30740222415609 + pristine_git_object: a3a5c1ac130dd8cf48cf4de9845a2331d19e13f6 docs/models/paginatedcribllakedataset.md: id: 81e1518edea9 - last_write_checksum: sha1:422ed8c2d904c02cbf6b979e1598e8fc0f90822d - pristine_git_object: 058780781376261f3e05c3ae6ca88ab64409fc62 + last_write_checksum: sha1:f5ce83d88f7efc1577dad5905066cb1443ecb8e1 + pristine_git_object: b47d3080d5510c71b05e38bd07581a67e33c82f0 docs/models/paginateddistributedsummary.md: id: b2877c8d1962 - last_write_checksum: sha1:dfe443cd1f79ca89c4ea60407c2687a39d047c88 - pristine_git_object: 5f115b6b72bcb02d8814600ee14709a1153863c4 + last_write_checksum: sha1:daad9bb1ec78a2b1d225da31cc70b03cff16232c + pristine_git_object: ef4452e946bbd827b0648b12632a3768b3098842 docs/models/paginatedfunctionresponse.md: id: 8f91f4611f86 - last_write_checksum: sha1:37edfcb8978e97940fa3e68d0fddcd4f06e9a986 - pristine_git_object: 14e8cd239029626997d8ee8bfe3ccebabe762f78 + last_write_checksum: sha1:3a2a7744402701d8fa1c4f6351c333fe451de31b + pristine_git_object: a0fc7b1e66f82ad4deea566c2523f0e8d1102608 docs/models/paginatedgitlogresult.md: id: e7e033f009b6 - last_write_checksum: sha1:41194345bf89b155e434c03c294354f9f909edbf - pristine_git_object: 59b96130a89a7e9aa3d2ddcf9c530fa8cab11aa9 + last_write_checksum: sha1:9528f51d3897b1144921b9d6c2d83464b6c7cced + pristine_git_object: d0d65ec3a45947ef70cb35761ea8eaa9cd0c24de docs/models/paginatedinputresponse.md: id: 4132e741cc25 - last_write_checksum: sha1:fc1a31161441fd6f3f42cf40a4bcad1edc314008 - pristine_git_object: 1eb0cea9dd82548df9ff8a509419bd0211dff6b1 + last_write_checksum: sha1:9fa4734ac76992d7e857812d0542649a5b9e4c16 + pristine_git_object: 81d83d34858fdd061f01307a18d60410aa021b50 docs/models/paginatedinputstatus.md: id: c426555c24c9 - last_write_checksum: sha1:b8aea98d22889a4283bf60f8b5df1c25c6e5f123 - pristine_git_object: 1b5bbf0fbadb2161a755ad9d1124eeed8820f6c8 + last_write_checksum: sha1:e3421d1deab3f9c988f0c93740cc6c1e5c8e5a25 + pristine_git_object: bf2a32af44ba0398f4f5f78e07a7ec6958acc0dc docs/models/paginatedmasterworkerentry.md: id: dbfa717ac716 - last_write_checksum: sha1:283e5f105ccd029c43c1c9730c8c9c470892ba32 - pristine_git_object: fafec6609e1f77617d49ca9aef5106ec6390ceca + last_write_checksum: sha1:6797f7242bd1b3ee6d34626381feedfa7e2f3354 + pristine_git_object: 4a1731f29aac8e023748a3346cd46e47b735794f docs/models/paginatedoutputresponse.md: id: d7e5567852e2 - last_write_checksum: sha1:e74455543065bf4e3493f1071d1ac0afe36ce43e - pristine_git_object: 9cafa92a180e6dc1dbf47a22ff389797b36949f6 + last_write_checksum: sha1:d162534c39dac3e9b3a4067452f2cd037cd1d4b1 + pristine_git_object: 7c3fe4e52fdd0647ac8485b1985c9e579e770183 docs/models/paginatedoutputstatus.md: id: 880b98b9f49e - last_write_checksum: sha1:8c01e94164e36e26f403726b7c2d9d95f8c1cb76 - pristine_git_object: 4a475921bda4697be12d51b6fbfed3ade510b76c + last_write_checksum: sha1:22ccecb24387bc9884a84ca6bd42d33415991cbf + pristine_git_object: a20818df8184c9bd173718aeef61311ed37a980b docs/models/paginatedpackinfo.md: id: b31737ccc1a9 - last_write_checksum: sha1:8bdcaa2b6c1514cc83059aef76e9cad2f66126fc - pristine_git_object: b3255cc34d37a5ce38e1675d728d6cba6c2b4d3e + last_write_checksum: sha1:66893e8e61dfbfcfa185d12d0bc9c0b6f823c7a3 + pristine_git_object: 4c230c2ec0481fe36296810b59c5523066c50587 docs/models/paginatedpipeline.md: id: ff9d9c5f9757 - last_write_checksum: sha1:33613a6ba5906d8a25e10ffdebeb128ef0e4ae88 - pristine_git_object: 7d1b786aab46b611984d5bf0f1208f73accdc259 + last_write_checksum: sha1:ab0db245534ecc8cff6e3cc379d2734fcd4299eb + pristine_git_object: 0dd22c4cc8587709d5ae481d0a6c1bb9ce55662a + docs/models/paginatedroutes.md: + id: f3e3ebab70d3 + last_write_checksum: sha1:82d6df33237c8209572c415d61c2f1d1879e3778 + pristine_git_object: 4fa735fff9d79b282c3ef9816e24f12228f80659 docs/models/paginatedsavedjobresponse.md: id: bea24207b665 - last_write_checksum: sha1:c642a2da56fb21fcf30c2f785ac3ea1fd454d0f2 - pristine_git_object: bc0a5658fdb970cbe61acb68ac5a6b9da2750406 + last_write_checksum: sha1:46841a98ee61ea9390ee1e8704c8b403cbebf69f + pristine_git_object: 230864ea3a53efb6ae3c4c33c1222cfb1ed70b0c docs/models/paginationoptionsrestdiscoverydiscovertypehttppagination.md: id: 420712506cea last_write_checksum: sha1:3b6db5091e74e6bbd6351fd460b48fde97c99ad3 @@ -12872,12 +14040,20 @@ trackedFiles: pristine_git_object: 311b17571b6c627bd77a6622d53ee99439fef530 docs/models/pipelinefunctionconf.md: id: 52478e5b129d - last_write_checksum: sha1:11daa90d5f74a1654cc0d65685370b306485f2ca - pristine_git_object: abf2de7f51f7ebc8d80623355692e7bf7f141278 + last_write_checksum: sha1:c360bfc535e6052e3c66f332738f9478084c232b + pristine_git_object: 2a8d6216d006c2c760854d1e9e3bd7ef56c7c513 docs/models/pipelinefunctionconfinput.md: id: 8775804bf22e - last_write_checksum: sha1:0fcd4dd401076fb87ff55005241669c1581c0b3d - pristine_git_object: 5dc30c0632de773604c4d99c818e707ada8b99a8 + last_write_checksum: sha1:3d51557c835a66d86778c5fa891da770f98e7399 + pristine_git_object: ea10059c55f87d3a011a2c7c78265ad622709841 + docs/models/pipelinefunctiondetectionrules.md: + id: 455ed2403de7 + last_write_checksum: sha1:6700546d81e97ecf55f553eee89aedde4749d95a + pristine_git_object: ccc362a1d666fb19692066bdf2e9a6ff7873a67c + docs/models/pipelinefunctiondetectionrulesid.md: + id: 6525f85831bb + last_write_checksum: sha1:39496cb928f168972b37f373c7558e34684ab1f7 + pristine_git_object: c1c9e8027a2bba8507ebe2390a6dba6bdbe97dcb docs/models/pipelinefunctiondistinct.md: id: ee40702875ea last_write_checksum: sha1:c584c9f75562f27668a5db447ff3bd716876033c @@ -13050,6 +14226,14 @@ trackedFiles: id: 274c61da5cb7 last_write_checksum: sha1:1254717a8ba7e0f4e96a7747bc35b3e4bff60614 pristine_git_object: da2bab66580624aeed4a117576fc76efaa948a6b + docs/models/pipelinefunctionlakehouseenginemetricsnormalizer.md: + id: f470b3127d2f + last_write_checksum: sha1:e9cf8567e26ff827eef2888ba5db8a42d19fad32 + pristine_git_object: 31ad3119f3b9fe3a67c8e2cf27f386a992127d84 + docs/models/pipelinefunctionlakehouseenginemetricsnormalizerid.md: + id: 0cc598eccb90 + last_write_checksum: sha1:ea9fbd7b83af3288ec49b60918e484747127bb37 + pristine_git_object: 9141f387e64d303b379ba3fb0dd372834a41e767 docs/models/pipelinefunctionlimit.md: id: 59f7257d62e3 last_write_checksum: sha1:c29e05897a521b85e087dddce74e1a92eb38782a @@ -13140,12 +14324,20 @@ trackedFiles: pristine_git_object: 12edb78669b6d14d017636d13ef6c5e9bbbb5477 docs/models/pipelinefunctionmetricsexportmode1.md: id: 9c0e2e819b50 - last_write_checksum: sha1:f192524cd527986cf25064837b907f3d61ac50e6 - pristine_git_object: 0f90bd7c7ef91f4eb8435939a4b7fbfea6b46894 + last_write_checksum: sha1:4280d1e48ab0ac470be967529022ca8710902eea + pristine_git_object: f05401d51b28548052d05983b79774fe75a69942 docs/models/pipelinefunctionmetricsexportmode2.md: id: d90c305043ff - last_write_checksum: sha1:65663dc61b438c2ed2d7db6b5650167dd9e2af42 - pristine_git_object: de363a407c222089f85efeeb9e04ad1f597fc2cb + last_write_checksum: sha1:7c9581ab1c5877b2a15dc27de64c267b4cd9abde + pristine_git_object: 5c255a5aaac031382c344be350fa0d598fccaadd + docs/models/pipelinefunctionmetricstimerangegate.md: + id: 6851780fd59a + last_write_checksum: sha1:656647adcd394cdfcbf20a9f51cea35dbd2a7892 + pristine_git_object: 8470714e55390f35c00db08e285c2f43c91bd333 + docs/models/pipelinefunctionmetricstimerangegateid.md: + id: 2fef66488889 + last_write_checksum: sha1:48882b3b7bb3569d2ec946f040d2742648bed8e4 + pristine_git_object: ec96cdf2c9217fe1af8fe85811c13b9376fefd54 docs/models/pipelinefunctionmvexpand.md: id: e9056aef38fb last_write_checksum: sha1:90f0fd32e5d28da960eee3d63d2dd52492ded8ee @@ -13488,8 +14680,8 @@ trackedFiles: pristine_git_object: 4fa3716400ae4a09325ef76f0eac3bf4dc3de168 docs/models/pipelinegroups.md: id: 33a01633cc3c - last_write_checksum: sha1:cdfdf948737a47bb45edac829bea64d81afb1583 - pristine_git_object: cfda9e6876099348c7e85dcad4858e734fc8e527 + last_write_checksum: sha1:ada713a7084ada2c2fc92fcf110fa67c4159f8e1 + pristine_git_object: 7c516236a2913b14b4c83cc8f25752508d975a79 docs/models/pipelineinput.md: id: 53330660965e last_write_checksum: sha1:15e11102fe653aa4dbeb710011b26adb354a82c0 @@ -13500,12 +14692,12 @@ trackedFiles: pristine_git_object: 522b3ef86e99f4268a822fa74a09a67ec585729a docs/models/policy.md: id: c32c4f30cd71 - last_write_checksum: sha1:5cec91f3b724e1d7690b87b479477e1c5f9f3b08 - pristine_git_object: 529d2cc00a9618e42a524e61911d8f850de34a23 + last_write_checksum: sha1:cc853dd07ff722578e2910a2d83b568a9d64d36f + pristine_git_object: 5676eeac55aaacd7e2b24c467135e7993207e009 docs/models/pqtype.md: id: 98c692583770 - last_write_checksum: sha1:1a819b5501465efec8f44d66ac8814a9e96ea833 - pristine_git_object: aaffedfeb226d4307489ab2fbf8cf12141e1d23f + last_write_checksum: sha1:00349f34b57ca84728c5fb3b8ae87a6306675562 + pristine_git_object: 22706911832bc001c091d90173b1ac280e240c2c docs/models/pqtypepqcontrols.md: id: 3de607008d47 last_write_checksum: sha1:a2430a538e8d853c1eb21c859ee110d7b768410b @@ -13540,16 +14732,16 @@ trackedFiles: pristine_git_object: ff4ecd53a1dd7d7b4252d2158e6e592df43077ba docs/models/projectdetails.md: id: 6cfac9b36f1e - last_write_checksum: sha1:cccd0be9fe1a29ae5d83e989a85022f54eab3570 - pristine_git_object: e807657f6c602b4bc440a27a48d95a8b0fa05bd3 + last_write_checksum: sha1:9e1ef5e2c701b2ac9cbe53a7a8632485d17400a1 + pristine_git_object: 68eb0d324235c927abbb66314a365072d523412d docs/models/projectdetailsmanagestate.md: id: 9010a0eb01da last_write_checksum: sha1:e9dbd578788b5b778e5260fc6225b7c13501580e pristine_git_object: a6a61b7945af0a70df37d05dec1abbb384f00aeb docs/models/projects.md: id: 9d0e1cde864d - last_write_checksum: sha1:4e479a21261696baa7099fd897edfa897b38f30e - pristine_git_object: 35491821a557428dd6f5a93ba7a58233bc9cbde7 + last_write_checksum: sha1:72505a8f1e2571eaa755b487b0c2cc61ba92a79b + pristine_git_object: 49089e0f8921b929b49fdf91c0818c2603714242 docs/models/projectsmanagestate.md: id: d43b25ae9df3 last_write_checksum: sha1:5aa0dd93c3f44b8167cdc1baeb468927adeefd4d @@ -13600,8 +14792,8 @@ trackedFiles: pristine_git_object: d2634574a2e161e45516cdb53713d7df5ad48075 docs/models/rbacresource.md: id: 6e329941e5da - last_write_checksum: sha1:19842753bfb4098f1d68e96f1f6c6b9d09f4e965 - pristine_git_object: 1e83722e02fb458eb4ab052c347f312f71944464 + last_write_checksum: sha1:8609d2607b15d5b68e452fe817db47b18542f4f3 + pristine_git_object: f496af7a295c2b45b5a92a29d0ce92b9d47b3b3c docs/models/recorddataformat.md: id: 887ccf15dc03 last_write_checksum: sha1:e6a0d799be0a7118eb2177ee784cc7a6cb5bc4d5 @@ -15844,12 +17036,12 @@ trackedFiles: pristine_git_object: 69076d3303146955b1cdd15c95463c8950709c7d docs/models/routeconf.md: id: 6b5e005c057d - last_write_checksum: sha1:31f85310315b32af6066cc2a2961168b2708792b - pristine_git_object: 2aa1a401718fbfb5da03c82830d1c07775115e76 + last_write_checksum: sha1:b92b08ac9182cc15f24457ff9070cd3c402c96f0 + pristine_git_object: c0e4149a64a0fb8efb9cbb2f95b0ab14f0c18cbc docs/models/routeconfinput.md: id: 9dd81075b2ab - last_write_checksum: sha1:def92359a28e775881fd60e9a428a504889ac05f - pristine_git_object: f121da17c1489b3aca8fdea1999a13ada4191ccf + last_write_checksum: sha1:fd924d7c875f13e73b8da68bb5db9043d2574da6 + pristine_git_object: 7cfef238d148122134606980fb0d541e161602df docs/models/routes.md: id: 7b56d6da5562 last_write_checksum: sha1:8d1972c230196757b550cd3a9347948dd9e51102 @@ -15872,8 +17064,8 @@ trackedFiles: pristine_git_object: 0e710f0067a16f19b5b562943e2707d7bd8a7eef docs/models/runnablejobcollection.md: id: 439fead8f8e5 - last_write_checksum: sha1:3ee53a807d8e64571e97fef3c5a8e915d2e239c9 - pristine_git_object: d505ec6d57f224d650f24f6534196377150cbc7d + last_write_checksum: sha1:212d0d805fd3bf1114a2ddbe2c43c5cc935995e7 + pristine_git_object: 410a3719c1388bd6f5484f93e6088416155a4d08 docs/models/runnablejobcollectionearliest.md: id: e7788aac5a0b last_write_checksum: sha1:a36c5dd9946db2a70ebad442a1e8859203a8bae7 @@ -15888,24 +17080,24 @@ trackedFiles: pristine_git_object: 3a679efe481d5fc878ad4c31befcbdf38376ebcd docs/models/runnablejobcollectionrun.md: id: 833f31034926 - last_write_checksum: sha1:91b5b105ec34bbd2e0a1ba90399539aaa5644fd2 - pristine_git_object: 8612feeddd952ad190383d39b0ef647b2a6ab892 + last_write_checksum: sha1:82e9f44be37263ea68e889750f049dbc0c585a79 + pristine_git_object: 58577bac6be9aabc5c659aa099f402bd11d6213c docs/models/runnablejobexecutor.md: id: a7dcc5bf5989 - last_write_checksum: sha1:69e56991a8cec32b9836e54d4bd6b43207d75e55 - pristine_git_object: 3e9c33f29441ba704dbf4233b5489fd2d167d35c + last_write_checksum: sha1:f7c441d2263d07daeba1780819b3c62174102efb + pristine_git_object: 85e8984cce9ff0b6cbfd411ec3c1a0cf44282ed2 docs/models/runnablejobexecutorrun.md: id: a3e22306ae02 - last_write_checksum: sha1:9ff8e40536d2f03dccf52631d8f746603faf66b8 - pristine_git_object: 916db1788f453a1e425a2e0a5fbdbb3fb7365d52 + last_write_checksum: sha1:4ca6dc4dcbae68536608b4751b61d0276372ddb8 + pristine_git_object: c0dec19d7edd7273b9c87c340fa4a217f53b16af docs/models/runnablejobscheduledsearch.md: id: d56c635c9511 last_write_checksum: sha1:5f6a0e979d90609f77cfa214cc08fda97afdee38 pristine_git_object: 6d10a511c292305b72f1b01a2411402323e5a942 docs/models/runsettingstyperunnablejobcollectionschedule.md: id: 7dc261db0928 - last_write_checksum: sha1:a798b63ce0e21bc46f133620d295219396eccb38 - pristine_git_object: 2d062f9bac75698a8b98c22c53c765b0f2d2b9fc + last_write_checksum: sha1:50e20bb115cf79ddd4fc69be75fa62588566b1da + pristine_git_object: 878d05a5f629ac9f425fed2cf7790d59cdd9ac9a docs/models/runsettingstyperunnablejobcollectionscheduleearliest.md: id: 584af824eefe last_write_checksum: sha1:716bef09ed314e99fff73846f8a09ae071d93fa2 @@ -15920,8 +17112,8 @@ trackedFiles: pristine_git_object: 2ff919bb02c3857e2fc6408b6e002cd43f310f75 docs/models/runsettingstypesavedjobresponsecollectionschedule.md: id: fe943c68fba6 - last_write_checksum: sha1:2c9582456f3ef2d264e641cc20bf76201cf2fc41 - pristine_git_object: f79d28f5746cd8551b892650b15992bc59647170 + last_write_checksum: sha1:195619a0629b2b3b2fb268b980b26057f39c7789 + pristine_git_object: c27130e3caa8f8a788e0a082c3b3db29726a2144 docs/models/runsettingstypesavedjobresponsecollectionscheduleearliest.md: id: 51c8156cf5cf last_write_checksum: sha1:9c17ab4e16d39ab6c6cf2b45ba1abbe222346ea0 @@ -16040,16 +17232,16 @@ trackedFiles: pristine_git_object: d992e4b6e34302a2c3083aeb0f910e85bbbcdc40 docs/models/savedjobresponsecollection.md: id: e5b8680009d0 - last_write_checksum: sha1:7840c2529e09492a0b2d748a5b71b5cf770541ca - pristine_git_object: 33e6763d0470d24857f55d28df5a02fe14200610 + last_write_checksum: sha1:338b06f11a2090519e83abc88cf364544dad031d + pristine_git_object: 9d33d076994b5e0db8482bddbf6ca484dac79280 docs/models/savedjobresponseexecutor.md: id: e9e56e334b36 - last_write_checksum: sha1:d354e75afc28ecb3af6ddc677897f05b4334e401 - pristine_git_object: d34ffbcd3a3214e6be5247427dd970a47bd65173 + last_write_checksum: sha1:668aaeb9b0e92da73807c2dde14103b84431064e + pristine_git_object: aef9330e8993d363c25cca39609fddaa90dd8aa2 docs/models/savedjobresponsescheduledsearch.md: id: 4cc4075b3a12 - last_write_checksum: sha1:d706025672d8701846be71c213597fe3208560a3 - pristine_git_object: 59c6fcf87a23bdf88eb97a9e1460a24ca7409634 + last_write_checksum: sha1:f74e44907dad5e23de39d115c9aead4d348b01ac + pristine_git_object: 1a9f1fc2115822f5aa7470bdd5f7c127ba22b716 docs/models/savedjobscheduledsearch.md: id: 8bc3062ea3db last_write_checksum: sha1:f3338399251f8b233a6c3c941f6cc56419befdfd @@ -16086,6 +17278,10 @@ trackedFiles: id: dff807bb4c0e last_write_checksum: sha1:96906867e3e9b267554a7277bbe60636823bc109 pristine_git_object: dea75eb79a0cb1bd4b7bf100e23e794bc6ff72a3 + docs/models/searchexecutionconfig.md: + id: e040d5760392 + last_write_checksum: sha1:999a2c8295ced2a54613441c1891354c0cf1ea14 + pristine_git_object: 1177b173ee7d2b589d2f793b8f8db88211017de4 docs/models/searchfilterconfinputprometheus.md: id: dfd44abd55c4 last_write_checksum: sha1:366b69e914bd242dd70d821bc73bdff459294481 @@ -16102,6 +17298,10 @@ trackedFiles: id: 452e4d4eb67a last_write_checksum: sha1:c2fcee32c5728f39bc337d990b149dfe19ddb580 pristine_git_object: 2e6fece9268a797703c69f09c33365fd756108b7 + docs/models/sendas.md: + id: 1d077392544b + last_write_checksum: sha1:6b4d3f65f0a3c092c836fbd064b5f4ea9acf80a7 + pristine_git_object: 20f9a39929cb32e50fd1242fead18771d8a5b726 docs/models/sendconfiguration.md: id: 7264c5ca693b last_write_checksum: sha1:020770bffa8870e2360ebc9c2a54e461f8fdeaca @@ -16116,8 +17316,8 @@ trackedFiles: pristine_git_object: 3ff10154db5499d54604282d26e57aa1ffa482f6 docs/models/serdetypeauto.md: id: e6f649d6de6f - last_write_checksum: sha1:409ceb34e3f8e34fc76b1d189ea7c0f4b171cf8c - pristine_git_object: 3838e46d856657af5685940d81040015214b7508 + last_write_checksum: sha1:67c37469c7f37d1aa15c2f47f87857bc906e711b + pristine_git_object: 898633c2958353e55a78d4b84c71044ef435ac21 docs/models/serdetypeautooperationmode.md: id: 8ea4762ebdbe last_write_checksum: sha1:41fea68fb3377ea040580d0273e814116231a620 @@ -16128,8 +17328,8 @@ trackedFiles: pristine_git_object: 66aa8d43bcbeafec04e77d21ec7d4b5a77d3e173 docs/models/serdetypecsv.md: id: 9fa26a8df976 - last_write_checksum: sha1:b2864fd086c997221f0d5e45a044250eeab3cef6 - pristine_git_object: 93631304111a736e0ed935af085e3b3f682f5579 + last_write_checksum: sha1:b75c22a9b0170ee522eba9eb2b45f082c0eb6beb + pristine_git_object: 62b999c0bf9e2f37f37ce62f93dd2fc66f44d247 docs/models/serdetypecsvoperationmode.md: id: 30f10bf0fe73 last_write_checksum: sha1:d1f6667ef937995b55987133362d601480cd2f79 @@ -16140,8 +17340,8 @@ trackedFiles: pristine_git_object: 863dee9ebe8c6b038f24adc4a2369fc72663bcbd docs/models/serdetypedelim.md: id: 5632dbe761a0 - last_write_checksum: sha1:7803dc90ef55a3dbbcfd7b3f302aa8530fa93dba - pristine_git_object: 79e576cf25c0b45c8dd43f1818dae07c70b9ca90 + last_write_checksum: sha1:6258055645b7ca5c5771e1d6649a7abf2965b59c + pristine_git_object: 0299294192ef20dbedbf64398cbea40c2ec56432 docs/models/serdetypedelimoperationmode.md: id: 4f09f0a7e23b last_write_checksum: sha1:cccf4e6d76d8c63dbd92108b0d87ad56552e25ac @@ -16152,8 +17352,8 @@ trackedFiles: pristine_git_object: db0399f43ae63adf67e5c2cf0182c0aa7b7cd672 docs/models/serdetypegrok.md: id: 4d4c83a54b18 - last_write_checksum: sha1:e6f68340b36c9c89d35d19767a5cc6053ac5cc62 - pristine_git_object: f4b2cd0416d92ea042b907f862866a4c77098d84 + last_write_checksum: sha1:4a1544f2f40f5696345abe141c07c3c9828b4028 + pristine_git_object: b21d3eaf87e35320757ee7bb534d772aaa103ebd docs/models/serdetypegrokoperationmode.md: id: 2dce5ff484a2 last_write_checksum: sha1:2a0c8d4abd89a115d94913b2c0ebc95f6f6e4367 @@ -16164,8 +17364,8 @@ trackedFiles: pristine_git_object: 00aad2ffdf14f0b95b03cac26d07000f0ba9f324 docs/models/serdetypejson.md: id: 6a1fc7129128 - last_write_checksum: sha1:580b8851340f958f2d78d43ebaa17e166ad8e12b - pristine_git_object: 052196e385ff469208a768a729775b5ec6fbdb32 + last_write_checksum: sha1:830ffa2997f489e3382d920d87b2024487d92176 + pristine_git_object: d2be2918fdc1e258b543c0b84575a7914092f128 docs/models/serdetypejsonoperationmode.md: id: 67ec3a3b2101 last_write_checksum: sha1:094c9e4effb753fea860bc23eb717ea9ca06808a @@ -16176,8 +17376,8 @@ trackedFiles: pristine_git_object: fd07b7a646615fd967a73b26388c143ef71021bf docs/models/serdetypekvp.md: id: 6717c6215a93 - last_write_checksum: sha1:f39bf2e087bced5cdac58d62fb4cbc505d68d462 - pristine_git_object: b1b95315d6d396969df73f4baf3b80c0305f58bd + last_write_checksum: sha1:a5ba283a047f8815584a0668f077966e2f7e4820 + pristine_git_object: 3cd4ee55297983801eb953088f1795e7c92252c4 docs/models/serdetypekvpoperationmode.md: id: 5fc4454b9fb3 last_write_checksum: sha1:0011671fdf932b2605adec4379d6b186990fe9ac @@ -16188,8 +17388,8 @@ trackedFiles: pristine_git_object: be2ed846886ab2b999dcc917d96fa6657df4c27a docs/models/serdetyperegex.md: id: 73320658cab9 - last_write_checksum: sha1:59c41592be4b939dc9b6728f2af0d3e4a3b4271e - pristine_git_object: c7497cbd283a2bb9662dee4d8dcea9296c61c790 + last_write_checksum: sha1:9007920327ee88d22fdf77d48be02bc1000083fd + pristine_git_object: 9e1d1b496efeefb0c56a7504697f2bbfe765a93f docs/models/serdetyperegexoperationmode.md: id: f0e12938138e last_write_checksum: sha1:acf9ec1b697b8dc78b26114afdb9a75eee94777a @@ -16474,22 +17674,18 @@ trackedFiles: id: bdfaf4a65cbc last_write_checksum: sha1:90e25ae9a3aa468126bfc7ffc3030246c01503d6 pristine_git_object: 47058736d1ee77546397a5d7d69a3cedc3b05123 - docs/models/splunkhecmetadata.md: - id: cbf05736d79f - last_write_checksum: sha1:a8c0767ca7f205362cb1fec16a4f99124db8b9f0 - pristine_git_object: 26b5e91f18ded7d1ca8a352da9559493efaff27f docs/models/sqsauthenticationmethodoptions.md: id: 3aa4d56028e0 last_write_checksum: sha1:5a97a234758192bcd7b1efb5bc7ee07d18792436 pristine_git_object: 2107976725f946533889c40cdd848df8dca2537c docs/models/ssl.md: id: 0f02176dd9fa - last_write_checksum: sha1:41438393d364f36f7683c2127bc11ec291079083 - pristine_git_object: 551f200fb26f08c7a5422426ec45464750c46147 + last_write_checksum: sha1:c36e86f72db881ee21453321e994d4a162e0f770 + pristine_git_object: 7309769f81ad97e3bf23c262de8b60a070e0b06e docs/models/ssltypesystemsettingsconfapi.md: id: 8e17f20d2cd5 - last_write_checksum: sha1:c62d6da91a098815ebba17466e74e993d3092fe7 - pristine_git_object: e8df7e642cbea4dd4b06b780b293ece5774384d6 + last_write_checksum: sha1:4083bdf459b495545525e884eb4c5d14ca30993b + pristine_git_object: b0c1809c163c7693acf3c1135533dd6c588f459a docs/models/state.md: id: e560b4e72643 last_write_checksum: sha1:36047915fd0b341ff412b9e08bdee5568582f3b7 @@ -16530,10 +17726,6 @@ trackedFiles: id: 4a200793e0f4 last_write_checksum: sha1:29fa493204e99f97aff0b6c4fc64a7f9c451312d pristine_git_object: ed046cbf6bc40b0424a90fd802eb0ccf1d0d63e9 - docs/models/subscriptionplan.md: - id: 0b2878b1633d - last_write_checksum: sha1:3fb1442e446212de1e41996d13cdcc819e9c4e64 - pristine_git_object: c5c7441841c8e9a9d23df7dbc2d4f262ec48f9ce docs/models/subscriptionplanoptions.md: id: 89932bfa4383 last_write_checksum: sha1:f3196784e38831165302f2d5bc117d56112b7b76 @@ -16560,24 +17752,12 @@ trackedFiles: pristine_git_object: f650276bc3c5c18ae86850d80752350ecf47d738 docs/models/systemsettingsconfresponse.md: id: 82846bb99992 - last_write_checksum: sha1:ca2e42a7b14cfbfebc4267fe4baa20f0fd101613 - pristine_git_object: 6c23ab95bbb4caf8580d4d8342b2643f21b67e92 - docs/models/systemsettingsconfresponseapi.md: - id: 0f76eae8fcac - last_write_checksum: sha1:101036659228fa388be5f58991e0913c42f8348b - pristine_git_object: 52b476d8328c938b0d0193b08f5ad42dcba44ce9 - docs/models/systemsettingsconfresponsesystem.md: - id: 9f2867a66e2c - last_write_checksum: sha1:78bc74f4ccc3620b0a09bdf785d6b41fb9f8f405 - pristine_git_object: 13674d779762e26cf8b087a4dcad2b65302983f5 + last_write_checksum: sha1:6b3ed5461ba9e87bd0c4c4f802fa12a0f412f552 + pristine_git_object: 95640bb1605c5b894d991237ef8abb847ad24e38 docs/models/systemsettingsconfupdate.md: id: 6ba515723e53 - last_write_checksum: sha1:19e69063d9eb64a6a3b26d32ff760a69e112ef4a - pristine_git_object: 9cdb0edbd951448e1414b073bc950f7c3b6258d4 - docs/models/systemsettingsconfupdateapi.md: - id: 9f6a4517b4a6 - last_write_checksum: sha1:0c93291c7631cc1d3075a14952350daeb5dec651 - pristine_git_object: 6e03b1db0f5d7ff051de3d84ad957cf7dd76ec78 + last_write_checksum: sha1:2dab336d263680be6707a2e681365b83a47a1094 + pristine_git_object: e3a5b5609aeb3d16e0c407e6acc92d6b7392dfda docs/models/systemsettingsconfupdatesystem.md: id: 32bc57b55e0e last_write_checksum: sha1:e26ee3795136d67bcd9e493f9734d0d5269a50e3 @@ -16610,30 +17790,6 @@ trackedFiles: id: 5c0836d4405b last_write_checksum: sha1:c72a9d2d54cf5d83788050530d7200eec76c9004 pristine_git_object: 7457253325102cd09cbe0e0161c9170493b1465e - docs/models/targetconfig1.md: - id: 52a0a4ac3722 - last_write_checksum: sha1:741421960d01e87d275938cba3e25aae79c31edc - pristine_git_object: a05f1cd418f8625b4aafd34894e919bdf87909a0 - docs/models/targetconfig2.md: - id: abfb9ba373bb - last_write_checksum: sha1:ef229702a5df5abab6ea577d3ba47089b6b0bc67 - pristine_git_object: 115b9820251ebc0691dbc6b2a9bd204dad3d461b - docs/models/targetconfig3.md: - id: fea09c91be86 - last_write_checksum: sha1:765f82a857edc75de202ee7c48c80b7eb8758900 - pristine_git_object: 19cb0597f8880ee28f336be7b118e3fe57453e5e - docs/models/targetconfigunion1.md: - id: a101a632d08f - last_write_checksum: sha1:253e755b5b7fa9416895b817a7a90fc99c28a9ab - pristine_git_object: fd0cde750ef6ea5a6c49d4b36459a287a3640e1b - docs/models/targetconfigunion2.md: - id: 972215cf06de - last_write_checksum: sha1:5c351e0129a3d63ab02b8e68f5c0e14e1a51ab28 - pristine_git_object: a6561a5279f10e930804ef87f85e7d9a457452ed - docs/models/targetconfigunion3.md: - id: a7270204220a - last_write_checksum: sha1:d875047c74505bb0c1194a845487605a05b8e82a - pristine_git_object: 5e5ebfb1590ff53a0de57d66a0c30efff2d014fd docs/models/targetcontext.md: id: 7e6866f72ecf last_write_checksum: sha1:1b8f22a82b96afa102956d0794fdd3401f9145f9 @@ -16648,8 +17804,8 @@ trackedFiles: pristine_git_object: 019c05744494c771bbf857648ce251453a508685 docs/models/teamaccesscontrollist.md: id: 6013dc3b0764 - last_write_checksum: sha1:65d7faddcf6f57a9cf4bb8fe0bfc155589185091 - pristine_git_object: dbea4e0a1f991e0e73b15bcb7f41f15098c23981 + last_write_checksum: sha1:77025b66ee1d021f8c5818db07ce5b818c7f9bd5 + pristine_git_object: 0a6f09bf8925732affb0ac210ec2850da690d983 docs/models/telemetrytype.md: id: d61d140d1520 last_write_checksum: sha1:109badc8427218b37c386f933fa1e4df53025987 @@ -16658,10 +17814,10 @@ trackedFiles: id: cc114a7c7d5f last_write_checksum: sha1:54a0088e9b11656436a6b5e5345204cdb63b6b98 pristine_git_object: e9804f24cd181f4584b63221cbaf13772e110a1d - docs/models/templatetargetpairconffunctionconfschemanotificationpolicies.md: - id: cc87c0c83b02 - last_write_checksum: sha1:a35852737ee91e2dcfa46f46ab65e04b3b1e122c - pristine_git_object: 1d2e6c26444c45f21a85bc0f78492e8030ec8ca7 + docs/models/templatefamilyoptionscriblsourceprovenance.md: + id: 84a00dec29cf + last_write_checksum: sha1:3fd5be5d0bd207c8c7628ac6241aed1f7f5ce220 + pristine_git_object: 1619060ce2a61de7949d9645a2dfc248c4eb441c docs/models/timeoutretrysettingstype.md: id: b96ba539ae3e last_write_checksum: sha1:16988be881152d3fff8cf14b553cd5f161fc0248 @@ -16690,10 +17846,6 @@ trackedFiles: id: 60c9fd7a9f6c last_write_checksum: sha1:9b7d204ca0d300bcb039b768341af5bea35ea447 pristine_git_object: 11e7b7046cd5dfa5b689fd852d7ba6e305cf8576 - docs/models/timewarningtyperunnablejobcollectionschedulerun.md: - id: 6672065bd294 - last_write_checksum: sha1:945bfaabc9464b7a45f474c9cadbad4754ddf2b3 - pristine_git_object: e365688654ca4bd9590ffca877dc0a57962fcbff docs/models/tlsclientparams.md: id: 8574bc79c3b0 last_write_checksum: sha1:dc775a8ddf8387efb8127481ffad84ee5295f568 @@ -16728,12 +17880,12 @@ trackedFiles: pristine_git_object: f8daa048594b0f59910f34ff68575fb68b0cba3b docs/models/tlssettingsserverside.md: id: f5e07b0efb17 - last_write_checksum: sha1:c7d3ef3fba2d40d9671d1869a3271771ed88c255 - pristine_git_object: c9a9a2bd98655b229799650d353bbffe960d0009 + last_write_checksum: sha1:f84cc55385b82c9b066298a010df6c79b4cc4c36 + pristine_git_object: 12091ac5fc16fa60e00ae0444648c876a5b0b046 docs/models/tlssettingsserversidetype.md: id: 3455c68c8d0c - last_write_checksum: sha1:650ed715b1289b3256f76ca32fdcfc78659bc339 - pristine_git_object: aaaff38d3de8249885ee17f7de59536b12445154 + last_write_checksum: sha1:49d7f2b12e1064e7eef845222fa01bf5b16a0556 + pristine_git_object: 01ec94d2929098ba4514a926893822d783ad5e6a docs/models/tlssettingsunion.md: id: e603fc0e2c63 last_write_checksum: sha1:f57e0994249c1cfc868762bb50257ce8f115b096 @@ -16868,8 +18020,8 @@ trackedFiles: pristine_git_object: 02b76bdd10b584ee0ab947df8de44dd5156f29b9 docs/models/updatepacksrequest.md: id: 156d63ee1536 - last_write_checksum: sha1:a1a3b00f18171470fd9d423c73d4374e46172e06 - pristine_git_object: 525525cf05ec81010afcc04f5326e9d85dd4df7c + last_write_checksum: sha1:ac21b247ebf896a814ab821acba9f70a2edb7bd3 + pristine_git_object: da25813f340508276e2c92ff58ac92302c660a64 docs/models/updatepipelinesbyidrequest.md: id: 397f21319a79 last_write_checksum: sha1:3a17cf87fa71e032be037b849cf30d7ea40f756c @@ -16928,8 +18080,8 @@ trackedFiles: pristine_git_object: 70473ad55f3383c3bccae371df3a2db3a3f4651d docs/models/useraccesscontrollist.md: id: a1c618011401 - last_write_checksum: sha1:c4fcdf9b73127e4ff54b4c14b83bc2ef69b0328d - pristine_git_object: df664151fb51bcb9c849c5f392e499560299d9bd + last_write_checksum: sha1:82d0c8967b749f39fceb0c24c4d3ee146a7f8c7d + pristine_git_object: bf4b28b9ce48143f44bd70aa69d3d90acefc10d7 docs/models/usersandgroups.md: id: a57932ee03ff last_write_checksum: sha1:61f8f303fdff71f4a012eed638407542c0c18bae @@ -16938,6 +18090,14 @@ trackedFiles: id: 4343ac43161c last_write_checksum: sha1:562c0f21e308ad10c27f85f75704c15592c6929d pristine_git_object: 69dd549ec7f5f885101d08dd502e25748183aebf + docs/models/v3authenticationkeytype.md: + id: a99ccb5c311a + last_write_checksum: sha1:036b4452b78c49a5173d325880f6b1c263781eaf + pristine_git_object: 406d8dff8cb69f381f4518c092dc14e88e497bf8 + docs/models/v3privacykeytype.md: + id: 4a5f4eb20190 + last_write_checksum: sha1:9e91da7825ad6b750d5aecff6a337766bf68567a + pristine_git_object: f96be4cd03f86a87fbb1974d7290cc130e079c5e docs/models/v3user.md: id: 4cdd27be1111 last_write_checksum: sha1:791545e9921214bdf54e3e7041c4d558960919b5 @@ -16950,10 +18110,14 @@ trackedFiles: id: 3b0377ecd039 last_write_checksum: sha1:9fb01218ee643f2fdd38d4fc3a3edc6c2b242531 pristine_git_object: 7d590a0b4595cbff6332a849b3f0f3e4ba251c9c + docs/models/wizdefendsourcetype.md: + id: 558b392c94f1 + last_write_checksum: sha1:8cd95e522560884e5e94c40341a40896a419d7f1 + pristine_git_object: 2f537e015195156f6a4596a084b30dbc7bc44781 docs/models/workerpqstatus.md: id: 40730322a116 - last_write_checksum: sha1:9257086c9a2489a2f93d50def521743adf031788 - pristine_git_object: 1aa6bd2cfd45e9bfc9b1d5f2251235eb116edaf3 + last_write_checksum: sha1:380c1e10f3df17158e357d152ac4b74c6fa8e4bf + pristine_git_object: f370fb359b114da814a4af6a62ffef5f8a61fb4c docs/models/workerstypesystemsettingsconf.md: id: e9937575941f last_write_checksum: sha1:cd87268605ca80495a780ab18ea548a9a8d85b06 @@ -16964,8 +18128,8 @@ trackedFiles: pristine_git_object: ea86be0797b0753697ab8c4e967a3100eea8a281 docs/sdks/acl/README.md: id: fb7bfe4fa08b - last_write_checksum: sha1:5a3bfa8197d30b6d7da09f0239adef5b5dcf5ba4 - pristine_git_object: 82c699622cfe745600e00924a29fb32e1ef556df + last_write_checksum: sha1:8fe033dadd17cf42401319134f2a59ce86ab7d69 + pristine_git_object: 99cf03bfb7379d8fb938edee4b89f83ec9581a19 docs/sdks/branches/README.md: id: 26feb5fd088f last_write_checksum: sha1:6e64726ea365fce33f2deb8679130891ebb36127 @@ -16976,8 +18140,8 @@ trackedFiles: pristine_git_object: f4d09cce88ad3e35be0491042d7f99ebe45b11ba docs/sdks/collectorssdk/README.md: id: fb156921e8e5 - last_write_checksum: sha1:6e039918a35c350adfc910afa2947f768c6d9f42 - pristine_git_object: 4788a0f3ba6d970d44539dc2c7dc04fefaceda00 + last_write_checksum: sha1:9f1d04ff488bb456ed96a9e2fc759b07340448fc + pristine_git_object: 85c72086d4b902a525e6ce49fdaa17cac2d3a48f docs/sdks/commits/README.md: id: ae81a8318c17 last_write_checksum: sha1:8afd314be8c02943216173e1b5f61c6c8016f85b @@ -16992,20 +18156,20 @@ trackedFiles: pristine_git_object: 7f4acccf4aa3d0ab3ff0feeadf6c29f375bc8979 docs/sdks/cribl/README.md: id: 18ac8b824441 - last_write_checksum: sha1:e5a22e19eccf970affb45f6fad03bb061ea7a1d2 - pristine_git_object: df9f158a362be234d27741b332e61197040067eb + last_write_checksum: sha1:235b2504ecfdcb1c72d7f5468401b9579b5b7ed0 + pristine_git_object: 737d4091463b8ae710223ada973506cd74c624a5 docs/sdks/databaseconnections/README.md: id: ef33daf326f1 - last_write_checksum: sha1:817195415abb8b2fdf91b022da0cf642383f3907 - pristine_git_object: ab9fe86ddec283d90d3008b98072771968eda19d + last_write_checksum: sha1:ffcadf3619579eb12d98d9ee587348a7c46792bd + pristine_git_object: c5f6b444dbdfba9f56a00e3d5212482776b1d75e docs/sdks/datasets/README.md: id: deb5d90f4faf - last_write_checksum: sha1:5981c373fab6cae55b998da6acdcb0ed1de43268 - pristine_git_object: 34e2414015cb57dd9e51555a5a5b418756d7c022 + last_write_checksum: sha1:024d0dfbbd6c64fe77f7267c1b79a435756a0a16 + pristine_git_object: 4772b0b4ed1376e2ff4716d2d10b28d41d924335 docs/sdks/destinations/README.md: id: e83d288899aa - last_write_checksum: sha1:72acb1985d0cf27db06ace3357e03127161be79d - pristine_git_object: 687481666901167c26a061323de5ac2a54594ed1 + last_write_checksum: sha1:0fe52bf5f8fe869a9bcf8c69aa2247deb182bacb + pristine_git_object: 14f37d1d474ef55086c38686fbed255b8031af76 docs/sdks/destinationspq/README.md: id: 4e89748a1821 last_write_checksum: sha1:a6fe1bedf0718263bfe54ba35a4e136d09fec975 @@ -17020,8 +18184,8 @@ trackedFiles: pristine_git_object: cbfe68c6860db788f4381752cfe0d0c23fe1f258 docs/sdks/groupssdk/README.md: id: e1199079357d - last_write_checksum: sha1:500469faf3bbf0a18651a7c78dd8e0cb0c5ee979 - pristine_git_object: 373d861f09984d65676c33aca5aed2267792638f + last_write_checksum: sha1:e14c85e815a23bdb79a905396fd795e35c1f7e9e + pristine_git_object: 906bc91d82452605505ff01071378f132202d21e docs/sdks/healthsdk/README.md: id: 79a4ac3e35ad last_write_checksum: sha1:21f5d400999da1910d0830d5e13c87c65d837bb9 @@ -17036,12 +18200,12 @@ trackedFiles: pristine_git_object: 2e8b9da44eb6645dd847ddc4f71d2792557c5d31 docs/sdks/packs/README.md: id: aea0b099af37 - last_write_checksum: sha1:1620c6c95d721b167019bc272bd40789087e79bd - pristine_git_object: 6eeda919ab3411986df45bf45e93013de858da59 + last_write_checksum: sha1:0a815981e1347b5343cd3c9d4401ff1625a4c86e + pristine_git_object: a4c063204ce37336999b9b4e3fe5f09140c2eebc docs/sdks/packsdestinations/README.md: id: 895ef2236167 - last_write_checksum: sha1:a5b1b77f42c4da535279c1edb424ec1b0f1ca234 - pristine_git_object: 41b7d9f153c982fd586b645725b7928877deae4e + last_write_checksum: sha1:5c51326cd9f4d2afd568f3ee591e130543038a5d + pristine_git_object: 151bc2c133f63d2f44a89184781c2be8ccfb9b48 docs/sdks/packsdestinationspq/README.md: id: 12a1d2d7f4c4 last_write_checksum: sha1:5c190fc3bd392e15e50e7a74992ace1a9690b683 @@ -17056,20 +18220,20 @@ trackedFiles: pristine_git_object: e3d1caca36e7ea082ececb8cc8d87480f426630d docs/sdks/packspipelines/README.md: id: b0262a36d64a - last_write_checksum: sha1:241c158d297501f7ec2230b3bdadf7414fe87652 - pristine_git_object: c3caa32dc40a03f866b3bff01bc6f64ae533b7f6 + last_write_checksum: sha1:162fa2e1055412e3c8deac53843f5d5b574fd858 + pristine_git_object: d7a896d63944ff53136c5acf8750085027cfe789 docs/sdks/packsroutes/README.md: id: a1fb73e27b09 - last_write_checksum: sha1:efe6c74f272da9300d6757985d98ce6b0044755f - pristine_git_object: d9a63cdf9c9de4a01cfc72ec266eb54fc86939d5 + last_write_checksum: sha1:7841999b6722380a8fb531e842adca1a5999134f + pristine_git_object: b926725f06fb1af278dcc0ca921e2dbe97202fbf docs/sdks/packssamples/README.md: id: d2c04868bca4 last_write_checksum: sha1:84f986f6d63917b91016fe6486c8d6798b65dec3 pristine_git_object: daac91294ca519fc8e67a76a3e21fd217e842394 docs/sdks/packssources/README.md: id: 91cf5c639969 - last_write_checksum: sha1:aca2b6bff5dd6c3c0553fd7a6ebe4faed02e7986 - pristine_git_object: 3148752e7e707f8683e5c28e52084beba54c6993 + last_write_checksum: sha1:eef3f658b0acac559a6bbf629fd98580e12970d9 + pristine_git_object: 0bd3510c58d0ee6b6cb145b99e5456414fe8f971 docs/sdks/packssourcespq/README.md: id: cbbc4cefed4b last_write_checksum: sha1:0a44958854c01a3768a3c4e86fccfa8d3c30255b @@ -17080,12 +18244,12 @@ trackedFiles: pristine_git_object: 1a1ea9e86603338f2a12e121204ec13367f9d8a6 docs/sdks/pipelines/README.md: id: 96306a4a5f5a - last_write_checksum: sha1:ebcf2111edf95c90487298a718e45eb87a0e12bd - pristine_git_object: 13bc24a8be119a62a7bb774aad9fdc3e436a3333 + last_write_checksum: sha1:d83d907577b39be584406b202f58528a357be8ea + pristine_git_object: 64e315b397193ebf41bfec957959cfc5ce396398 docs/sdks/routessdk/README.md: id: 7c151891b0a4 - last_write_checksum: sha1:42ddd3e3dde0e7c5ab4703066b410af67a2cd626 - pristine_git_object: f95f706fbea713655e32cafb243102e799976d0c + last_write_checksum: sha1:b7dc73b20a0f38c0fe70f714e286fe57134cdd70 + pristine_git_object: 624f7684bf68f25d71d0fdb0b28afe0fe75d4e37 docs/sdks/samples/README.md: id: 2b3e67e9f9a5 last_write_checksum: sha1:679c920e0f67f92c7599ea87b5eb29ff5c33c477 @@ -17096,8 +18260,8 @@ trackedFiles: pristine_git_object: 9789d0b8414f93b2d7d06b593352880ba2c7ba7a docs/sdks/sources/README.md: id: c1396b2a57d9 - last_write_checksum: sha1:ac1eecfb73587034081631edf6f593cf3213a70b - pristine_git_object: 8c515cf883d93641ab1b61e1b7bc31ac42bf568c + last_write_checksum: sha1:eb3de35eaf775770018841e765e83f5b206447de + pristine_git_object: ab44aee1d79ce518b37331c43752c2d398cc9a0f docs/sdks/sourcespq/README.md: id: 08e24f4817a2 last_write_checksum: sha1:21462691d0e4886606dda730f955b1f44bb8db92 @@ -17112,12 +18276,12 @@ trackedFiles: pristine_git_object: 5e88e78c6d3202af4851e04d90ee2ef8e7600a9f docs/sdks/teams/README.md: id: aad657749b4d - last_write_checksum: sha1:088779e60ec5ce477690daacaa900a7b105de622 - pristine_git_object: bfa2dd7d11c5c1b67ebd2facce6a8e2723b4d1cf + last_write_checksum: sha1:dfe87f11e27ff58ef3005e122e8b1aea34849cb9 + pristine_git_object: 296c5bbd0704de19c2430d29ca87293309c77666 docs/sdks/tokens/README.md: id: ca61030eb3e5 - last_write_checksum: sha1:761a50d59e4bcf5d8b3d7e4e1094160601b41ae9 - pristine_git_object: c124493d5a0f47e86f499571eaccf211410dc4b7 + last_write_checksum: sha1:054453a32cf5ee70862029c5f09690c73de9b455 + pristine_git_object: abd7a1e0560a53125a797f3b1458ad14226be681 docs/sdks/versionsconfigs/README.md: id: 5019616c9cac last_write_checksum: sha1:66d96bba7205a1105eae4beeb96cf1f4df6bc340 @@ -17140,8 +18304,8 @@ trackedFiles: pristine_git_object: 1b74b5fc91dcf2b9df16949b77bcec9b03c49e2b pyproject.toml: id: 5d07e7d72637 - last_write_checksum: sha1:ad591418167d206973ac4d853dcaaa63a657a849 - pristine_git_object: f19e40bda3c5d6b5938a7ee33bbea02188fd3bc7 + last_write_checksum: sha1:734dcae1d46ba4079b08502b8075beab3d24f93f + pristine_git_object: 22d26b4149ae59da5e683b6cf4edc871ca0e36f3 scripts/prepare_readme.py: id: e0c5957a6035 last_write_checksum: sha1:a2e0d08bb2b147a5bab939d676620d1686f3b024 @@ -17172,12 +18336,12 @@ trackedFiles: pristine_git_object: faaf4fb816e5dcaf59ae8e6927e853aa7218a3df src/cribl_control_plane/_version.py: id: 9c8e5f14504b - last_write_checksum: sha1:122c7ebd57429efafcb23dbaab4ec06ae06ac60e - pristine_git_object: b5ac829540f79a9c722ab06d013496f30d0f652b + last_write_checksum: sha1:7a62e39eda1ffeebd108539328f7fcf47a05a810 + pristine_git_object: f5ee1173f39c8e6f7b78325ff1f0c1f10d3152c4 src/cribl_control_plane/acl.py: id: 0e865a719763 - last_write_checksum: sha1:559cbdc9c628dd800f56dedbf8dbf593abf532d5 - pristine_git_object: 3533e260d0b917763a84fd56dcd88a5db229fd8d + last_write_checksum: sha1:b529774a83ebe5ca985d05abe78ebf0161455fde + pristine_git_object: 75898a73db72f7ebd539c29c1fc943937056a43f src/cribl_control_plane/auth_sdk.py: id: 11512c31e613 last_write_checksum: sha1:2fbca3c93c2549e3f4c30ac39b6bbb79f74bef3a @@ -17188,52 +18352,52 @@ trackedFiles: pristine_git_object: 1b1af8173ed7b6eef43d701ad7749c210ef466a9 src/cribl_control_plane/branches.py: id: be549eef9f0b - last_write_checksum: sha1:f87294ad71d2528fa4c29b484af326f2701a0157 - pristine_git_object: 89f86421d7cad43d7493d7633ae19862cc5dc18b + last_write_checksum: sha1:bbd3ba99eb8d89ba9b48b420543978f17d87a24c + pristine_git_object: 6b46febf2859e87b0335bfddaecc155f0fb9e77e src/cribl_control_plane/captures.py: id: 459fd1010156 - last_write_checksum: sha1:9e618a04feb0566b6f1096179d8b9c57ff79b41b - pristine_git_object: b4f2c0cf8388e758c40769d8c0174c1c6b8d0b10 + last_write_checksum: sha1:a2a10e20174f59f810ba8f0bba76c15b5412421e + pristine_git_object: c1de2c1f9e5694f4bc0bc4121e082953fe4ac933 src/cribl_control_plane/collectors_sdk.py: id: f84df60bc0f1 - last_write_checksum: sha1:a5cd5f8ce9ca7c8660f3ed9f9ff6b0ec8f8d6837 - pristine_git_object: f94f7ac60c009d326f94e6a76e0d74368476ead0 + last_write_checksum: sha1:ae6419aec54f7017d2577c0293fb851ee259ba42 + pristine_git_object: 6958dec2e66e761dcce16dabd28ade1e01b22b0b src/cribl_control_plane/commits.py: id: 77b962b3c68c - last_write_checksum: sha1:b521fc9a4105524b2c7f7c2ad94019d0a259b47e - pristine_git_object: f8da9e1ab24fb060df34bb3ddf57d1ccab9bbb2b + last_write_checksum: sha1:92681e6ae1a146ed4bf2613af290558a691e401e + pristine_git_object: e64dd645e5f668b18233772292b4dfa1fa2d326c src/cribl_control_plane/commits_files.py: id: 8998c80033e9 - last_write_checksum: sha1:26c1b239e34f2aa528687b5fe77333eae890e16c - pristine_git_object: 5918c2423a4a83c0887622b5b93e480894e9cfd2 + last_write_checksum: sha1:945e639ddb624a2c80340d1beef0ed956bb1f7b6 + pristine_git_object: 2d928689966b1920ae90e36b4ca193744273a438 src/cribl_control_plane/configs_versions.py: id: 412313ca833a - last_write_checksum: sha1:39ded171254fb1fd5ea0cd9f8088a1373fdc1bb6 - pristine_git_object: 26a75646861fa42ed35ae54ba819912831cc7c5b + last_write_checksum: sha1:6c68b96931483e3b767678209cec561b2ee86979 + pristine_git_object: a0d7aa465a7b121597e781b49efb52be3f5c1fcf src/cribl_control_plane/cribl.py: id: e77153ef9ff7 - last_write_checksum: sha1:cd3cfaf99647f3545635b07b2e943a1b5115bf69 - pristine_git_object: 3e15c9b43d487e7a7596ccb15f562b8d4875e9b7 + last_write_checksum: sha1:c2a1b30caacb2ac85f804b8ae7181dd33fb25dab + pristine_git_object: 25375f0b32db10a1d471856e8cc8087373a080c3 src/cribl_control_plane/databaseconnections.py: id: 96bb56ae9234 - last_write_checksum: sha1:d243c986a318fb9f80f0aadb4f7cd114bdec07ba - pristine_git_object: 7c7bc76a224a66ce5e2e42a20673c3a608b1623a + last_write_checksum: sha1:0f2c5d075399607c7c31183ce0284159fdcd7790 + pristine_git_object: c0c4332d046ea6b74752367d78b12e3e11032476 src/cribl_control_plane/datasets.py: id: ed509c41c7d5 - last_write_checksum: sha1:56c1a7844063824bf0b53b147aeb4952372e046d - pristine_git_object: 67b71adf6bb5d4ee4963a064a818435c1831f8cd + last_write_checksum: sha1:9069b84accc1b546dbf9da3a94af8667565fd966 + pristine_git_object: 1d8e253f78083bcbf43dade2c82076588421d515 src/cribl_control_plane/destinations.py: id: 36ffc53f2f7d - last_write_checksum: sha1:1b853d75876ac7dd46b04a86443d51b6fa93a841 - pristine_git_object: 2e672a06735eff3ed4c4b37cb7eb20bc5c043577 + last_write_checksum: sha1:7bd55296ce94c8ec4ee26fd2010106ea70404726 + pristine_git_object: d4aca1248edc4a2ee7bd6ae3b21a12d631fabde5 src/cribl_control_plane/destinations_pq.py: id: 30ac4b7a9e97 - last_write_checksum: sha1:d43a18097a23fa98bdfec6437bfc794f37378870 - pristine_git_object: 32f17c31c9a0b101d2b9a49660e1f02972b4d3e1 + last_write_checksum: sha1:52c7132526590c5682828d9a711fc81fb08c679c + pristine_git_object: 2f11244a3ab975221cfcddacae76b4d465dfff61 src/cribl_control_plane/destinations_statuses.py: id: 69c348d86773 - last_write_checksum: sha1:051289cb687f1184707eb9028e2b72579c62eb82 - pristine_git_object: 100fdf5ca7eaf78ad6a1530f0eab91a076459f15 + last_write_checksum: sha1:26883e20bbe07dd29b3dcaa0a608d2e0d7f7293c + pristine_git_object: c671a4577e799cebbb1f781ce10db5dcc39d4ac2 src/cribl_control_plane/errors/__init__.py: id: d372d9a85443 last_write_checksum: sha1:2ab83a2b4a5d3e797708f7e5add8a062417db364 @@ -17268,24 +18432,24 @@ trackedFiles: pristine_git_object: b7368b51e53e8f73b5d9466a671cb37fc693db92 src/cribl_control_plane/functions.py: id: 48f6a1397f02 - last_write_checksum: sha1:b386900527efd9c2cf4eee5d575bd15cd0355d65 - pristine_git_object: 6813d7b1aa7ec356fd636f70e4ced78eb3f2289a + last_write_checksum: sha1:c5101c637c6cd8e8d6941c997c853dd1d5646f36 + pristine_git_object: 04e66b30a102b169f89556db4b698aeaebaa5942 src/cribl_control_plane/groups_configs.py: id: 5e1a710f5459 last_write_checksum: sha1:42bf74770fe3045659b77bb258867b6c735e2c1c pristine_git_object: fe59e5a3f3f5dcc3e4d037dc66712008545534c2 src/cribl_control_plane/groups_sdk.py: id: 7f1c5a4615e6 - last_write_checksum: sha1:a07b553dd2d1ec3b4eb1ebb1159e64a0194a13b8 - pristine_git_object: 481641f7a01721fdc0cad4fa3d1d0ce8de3e2d1a + last_write_checksum: sha1:469158430755d8185c9a4009bdcee7f2c7b25745 + pristine_git_object: 3404a005dbb9c169ffe72e98b96676cc63f853a1 src/cribl_control_plane/health_sdk.py: id: 680b30c149e3 - last_write_checksum: sha1:63d1dce5127b3961c61b908d94900f0dbae8d738 - pristine_git_object: 1e2ca7656df6c465bd905bcac1252d55337a6604 + last_write_checksum: sha1:81c678001d0d76dd676b4689588febcff196f4ff + pristine_git_object: d12af8086a9e19e5cf99cff31268e863abc0353f src/cribl_control_plane/hectokens.py: id: d43fa881e02c - last_write_checksum: sha1:2acfd370bfb5256c1ab97ca9550647532c6a903a - pristine_git_object: 62e82dc61f1dbfee0e19bb07103cd219507123ad + last_write_checksum: sha1:2ad8e41434e86578dae75e4d48d426f5a7e17a08 + pristine_git_object: 0a5b7f485481964d86b36a793ce38ec5f90113a3 src/cribl_control_plane/httpclient.py: id: fc5018fe7f2e last_write_checksum: sha1:5e55338d6ee9f01ab648cad4380201a8a3da7dd7 @@ -17296,8 +18460,8 @@ trackedFiles: pristine_git_object: 63af9cb836903c89e3db0d04bb4f44141014de8b src/cribl_control_plane/models/__init__.py: id: 558fbe1bf6ca - last_write_checksum: sha1:3d377109fc4b5b7ca9f49f7b88b993ac0f3a2c96 - pristine_git_object: 1560a1cea640a906ba702771891f99022414c6f6 + last_write_checksum: sha1:a0e38640fb915c5ed1c6bb6a1bd0582d7e3c7319 + pristine_git_object: a2e0ad99f128feadbef24fcd09076ae6aecab112 src/cribl_control_plane/models/acknowledgmentsoptions.py: id: 2537877f09eb last_write_checksum: sha1:610fd67330eee25b0afc942d175a52130576ed7d @@ -17344,8 +18508,8 @@ trackedFiles: pristine_git_object: ce87351d86b435ffa32be2f2ecb937dd1e89644c src/cribl_control_plane/models/appstypesystemsettingsconf.py: id: 44322e4a0b04 - last_write_checksum: sha1:6f857dca05b720bb118f35ded7c30c14bc9dc4fa - pristine_git_object: c0baa8b6af1fca1205e2a9688c2baf11685d9345 + last_write_checksum: sha1:2ca924e8717786abbdd1245a1399bda00ab818a0 + pristine_git_object: 5757d8e0105287059a5a98d25a920ff736fd506c src/cribl_control_plane/models/authenticationmethodoptions.py: id: 11e87ecebe77 last_write_checksum: sha1:62925f44fcb201c199f761013c9879feb5f68cb1 @@ -17362,18 +18526,22 @@ trackedFiles: id: 1f308975c816 last_write_checksum: sha1:746537dcd80c8843cf7dd0067f8ecf5dc397c175 pristine_git_object: 0f3d399c3793c0861704eee42c768472ef834a58 + src/cribl_control_plane/models/authenticationmethodoptionsauthtokensextitems.py: + id: 8bfc4bcfba8e + last_write_checksum: sha1:2c769f335ae6cc039e5b26d5da827ccff911c670 + pristine_git_object: 629388c82a5cc6aae57387cfd14f0b26120ddcb1 src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitems.py: id: a0584d1bfe40 - last_write_checksum: sha1:0e327e55b462ea4d85ad32286673a779fbca35d2 - pristine_git_object: 8b047531eae5b55e1fb0f633b0ff1b691cd58f30 - src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitemssecret.py: - id: cbe1499ac698 - last_write_checksum: sha1:a7fb92ee6bbbe0ad1e2721d9edcf6b6892a3cd7b - pristine_git_object: 9567338ca297830a18cf42118ecef0ae1e0749d6 + last_write_checksum: sha1:1f8e79cbefa621a95cf8d25f3454f87f93096b69 + pristine_git_object: b90c7efaa248defc0b5ea1e13f54b1f73a0a4715 src/cribl_control_plane/models/authenticationmethodoptionsautosecret.py: id: 59cc2f99104e last_write_checksum: sha1:c02ac43199f5ca34aeb7b3b53a51e38c144c4b32 pristine_git_object: 9358d3c8952530a710b7b300d5c2e6df8c5585c5 + src/cribl_control_plane/models/authenticationmethodoptionsclientassertionclientassertionrpc.py: + id: 9c5a2aa6cd99 + last_write_checksum: sha1:483b8785d74c9c7f259976386e46afb071eb0b48 + pristine_git_object: 2a696ff68adfcdb7626d0f84c10a4a852cc833ce src/cribl_control_plane/models/authenticationmethodoptionsmanualsecret.py: id: 09b6f25ef801 last_write_checksum: sha1:db1499e210558c7b5f7dc2e93fdfc9683a71d06d @@ -17432,12 +18600,12 @@ trackedFiles: pristine_git_object: 38d789d871a295645fc50736fbd21e84ef6abf43 src/cribl_control_plane/models/authtoken.py: id: 11414ef8024e - last_write_checksum: sha1:63f80693931cdbc44cfceeb22e6e81a7bb992153 - pristine_git_object: 354cb79a74b1e211eca23abc243b053a41cd1787 + last_write_checksum: sha1:06caa3edcc7b60f7f35b97185461dddc13ad5480 + pristine_git_object: d401308eaff182182d6450c8008a9eacdbe7b7b7 src/cribl_control_plane/models/authtokenconfinputcloudflarehec.py: id: 1f7eb8296892 - last_write_checksum: sha1:ae828fd19795f35e49c4a5f2cbbb627cbd52aa3d - pristine_git_object: f1fdcd9575ba253d86d667b232d1b06603b638ae + last_write_checksum: sha1:35363696eb9994e7af210189119a54e6bbbe4414 + pristine_git_object: cd782604f00e3a4d2a10fcb15b17680c2fbf278e src/cribl_control_plane/models/authtokenconfinputcribltcp.py: id: c25e4fc467e8 last_write_checksum: sha1:b80517feda74a52eb7b2cea628b5c83076f2477c @@ -17446,10 +18614,6 @@ trackedFiles: id: 16000e0e92e8 last_write_checksum: sha1:33e72c591fa6e6631d2cf064e9dc7bc215408c6d pristine_git_object: 409623802e531bad1882506184a07ba228a9c440 - src/cribl_control_plane/models/authtokensextconfinputhttp.py: - id: 072f2be140fe - last_write_checksum: sha1:bd4074e5aa1c28fee32ea70ba3c5f505672ce14b - pristine_git_object: 97e65b884903671168c92ed612074280ba30bb57 src/cribl_control_plane/models/authtype.py: id: 293d568a3880 last_write_checksum: sha1:a1a55b074c04e99240477fc78b538e30b1227d42 @@ -17484,8 +18648,8 @@ trackedFiles: pristine_git_object: 87e614b920aba2ef81b9029aa163ae8a08cfc78f src/cribl_control_plane/models/branchinfo.py: id: a11fd1a87f87 - last_write_checksum: sha1:4a0e043a20afb341291e9ace677854373f0ed3b5 - pristine_git_object: 3195c05fc9500ad91e3274890dd58862a1cc7b82 + last_write_checksum: sha1:339bb34b398e84f6ec43e1688e59614cb1582f07 + pristine_git_object: c1e5552a3bddb023d46d88db5d4efc34c2d52100 src/cribl_control_plane/models/cacheconnection.py: id: 653c3c5fd5e5 last_write_checksum: sha1:f5f7310dd4c2335d18fe20845ed7835dddf4b226 @@ -17620,16 +18784,16 @@ trackedFiles: pristine_git_object: 9d143a7c25ae8cccb3b9a299d29222cc53fb3cfb src/cribl_control_plane/models/configgroup.py: id: 5b60884e2a58 - last_write_checksum: sha1:7887d4780d51800e3cd10b52d7cf266ac69a138f - pristine_git_object: 96e48df8d08e1ba7f4f5446601973aa3d5a0ef0c + last_write_checksum: sha1:bcd9f5030ff098af9c202bf3567cad820891b571 + pristine_git_object: d95efe1b6a6a937237189d7ba614ed6a4d5d4fa6 src/cribl_control_plane/models/configgroupcloud.py: id: 3f53a654cacb last_write_checksum: sha1:daf8ec45c9e7a1f776fabc6756aa1effd6dc0baa pristine_git_object: 2cd81b1f22c003bfa5bf3b7d8256d18b729709a4 src/cribl_control_plane/models/configgrouplookups.py: id: ac6594ec5518 - last_write_checksum: sha1:f25727c21e2029502cc5bd12cfd179af6a5d14ea - pristine_git_object: 1a0cc4a77190e29fdccfa4d75d9a5c060f8e26fc + last_write_checksum: sha1:b78e2d526bd973c3d0b26775ff6fc770173ea3c3 + pristine_git_object: febe404312c456818efb5043c9dc819b61ddd348 src/cribl_control_plane/models/connectionconfinputcollection.py: id: fa06226ea010 last_write_checksum: sha1:802291e0cd71426f8bb28d4d029312cb1cab9a15 @@ -17640,204 +18804,212 @@ trackedFiles: pristine_git_object: 80252685b7732324f9c02d5ebc942d7c4ec8b97f src/cribl_control_plane/models/countedboolean.py: id: 7cbc445850e8 - last_write_checksum: sha1:3cf25b2fe8608867f399942dbb7f0db6ed96b5a3 - pristine_git_object: b953ed6c6471f6ab647379dbec955dacf467c161 + last_write_checksum: sha1:e4f1f64cea2a1a58a9b81c084f9e73faea775048 + pristine_git_object: 6863f076ccfbdd587d2751036495ebe4c22421e9 src/cribl_control_plane/models/countedbranchinfo.py: id: ebe1c1f31c50 - last_write_checksum: sha1:fe437af51d5c989cb861f54e5774dfba47d77c38 - pristine_git_object: 453fbf93c5c49a1900eab8cc049aed345691debd + last_write_checksum: sha1:32441ab33bbfd74279033439b38615d32d02d146 + pristine_git_object: b9e791dd34ce6df71b4da1495b6465d05b49e054 src/cribl_control_plane/models/countedconfiggroup.py: id: a02ddb0f1b74 - last_write_checksum: sha1:78b46cd07f06d4df661c2e793aa15eb77f886d98 - pristine_git_object: 53b7db7905d0024e4fc091874d1f2bc035ac4b72 + last_write_checksum: sha1:edc27967f7045ec16a0ac70dcad0b8fcd1401374 + pristine_git_object: c72405fc06ae7598b2b72dc2643f764ebee7b28f src/cribl_control_plane/models/countedcribllakedataset.py: id: 50d88c37bc12 - last_write_checksum: sha1:f58d726f90e292b54d84db2080b979fd3ded2261 - pristine_git_object: f190f42b963a4c0bad2cb824c656794409b3f0b9 + last_write_checksum: sha1:9ab2a09e6e38e2c4ac739edc2b9bdb6b1702876e + pristine_git_object: 7942356339ac4a7626068b86bd41446c3d5fd7c6 src/cribl_control_plane/models/countedfunctionresponse.py: id: 7a23fc8b2c52 - last_write_checksum: sha1:94c9e2d4b5751a729ff285a3cde0ce546223c58f - pristine_git_object: e042e45f4bb93aa64bbc56a619d349f9b224fbb9 + last_write_checksum: sha1:45fb74ea158f75ef979e66be49829663b83ee283 + pristine_git_object: 2a4452fad8920934c91bfb5ea38f02514f7c9291 src/cribl_control_plane/models/countedgitcommitsummary.py: id: 4b41af9a0e3e - last_write_checksum: sha1:ac3aa9e9a25fb6def6914344f8618904dd8044a6 - pristine_git_object: cafae527acee877aad6f0dda7b66697dbea7ea2c + last_write_checksum: sha1:10d613e27f7d295e2ca67d1128bcf4f45307997d + pristine_git_object: 46b4c09ecb9cd9205cc375ab243d7b546f424efd src/cribl_control_plane/models/countedgitcountresult.py: id: 5d7056ed467c - last_write_checksum: sha1:e28d4d6ba385d5b0f616e72eb38ab76542852694 - pristine_git_object: e24324590fbe393cf174943c9d0a70611c20a1d4 + last_write_checksum: sha1:bae95cbb857580cb56c809218fb405c0aeb51629 + pristine_git_object: 7a4f0e329223cb343f4c5eb79bba1129de7d316e src/cribl_control_plane/models/countedgitdiffresult.py: id: 931bbb03ce56 - last_write_checksum: sha1:a3cbfe399294f03755f5358328c723ce87fc7983 - pristine_git_object: a42f523f7b415ad497a251fe463cc312d2b0643d + last_write_checksum: sha1:61f8af705b94964139ec34c200cb789057d77423 + pristine_git_object: 42a780c20a73921678d3da7d59d2a6cef0e52319 src/cribl_control_plane/models/countedgitfilesresponse.py: id: 7645d17b436c - last_write_checksum: sha1:a1f7c85957803ea0d29d038a588ef6bb5d7c8a31 - pristine_git_object: 267888cec39b6cbe49c2aef2f8462233d6804b2f + last_write_checksum: sha1:62e43c6eaafb4b87e0b002a649bb27a37abe9798 + pristine_git_object: f12160a7104f2030be1f2838bc80ece6b8069d51 src/cribl_control_plane/models/countedgitinfo.py: id: ba429b2a6f60 - last_write_checksum: sha1:f20e5d7034526fbe7b5d8f1d26bfe19548f4e63c - pristine_git_object: e7d1a4c2e7437c227ae895775ca45967bf641248 + last_write_checksum: sha1:efe76812a0c3db5c9ce7e6df33a34f389f219f16 + pristine_git_object: ab09dfb702042313c7144fd736a873c3b7c02fdc src/cribl_control_plane/models/countedgitrevertresult.py: id: 7087b1f38284 - last_write_checksum: sha1:0e2042f005b329c7fdff4f4217da3ab24f98f271 - pristine_git_object: 9cbcd4e4856cc42bc123b6370ba3eec2b28d1cad + last_write_checksum: sha1:276245f043c3cb02946e7573b0e8e365053db3f7 + pristine_git_object: ec0a824f35a80ba2b8155b50f4b521ddc9a59b20 src/cribl_control_plane/models/countedgitshowresult.py: id: d380a585410a - last_write_checksum: sha1:8df4588aaff4e2518677ddd4c7cd87726ea1037f - pristine_git_object: abed6a9304f433b62a568cbf194576c5540baf53 + last_write_checksum: sha1:159b9551a40f2d8eb3286069f3a831cb8cdd4703 + pristine_git_object: 4d6c7f8991cc73e12e6cbfa1084f35711fcd736e src/cribl_control_plane/models/countedgitstatusresult.py: id: b4c9564ae736 - last_write_checksum: sha1:a325e4076301244c1646a9ebe1d3e73544a19d60 - pristine_git_object: 3247b0b44e8ad2198106ead45601086a945f17ce + last_write_checksum: sha1:f2a6a480c72b0e35357dbd7c8dc5c6bb8765f154 + pristine_git_object: 020c6ad4d13e69ebf0a0c8db3d1eece85faef8b3 src/cribl_control_plane/models/countedinputresponse.py: id: 3d905a63038a - last_write_checksum: sha1:17a16941f45de241badd0d68839c911f90dd49b7 - pristine_git_object: 590680ac8ede53c6cb5f191d25522e4aaef8b7c4 + last_write_checksum: sha1:d485986f0122651aaed20f03473a7853517b9cb0 + pristine_git_object: 207f076d631feb202bc8aa3b363ca84556841096 src/cribl_control_plane/models/countedinputsplunkhec.py: id: 3c1bd759857c - last_write_checksum: sha1:4b6548f842a4526e4c3b8c029aa6ab1adb8ce709 - pristine_git_object: 7de4bdb1825859852733765dad3bc60dcb1052d2 + last_write_checksum: sha1:336b4bca87ee05ed2d2faa4005d48efd2117f227 + pristine_git_object: 3807ca892f4415d9e75f90b7db0102a589bf5460 src/cribl_control_plane/models/countedinputstatus.py: id: 90f0a4489b9d - last_write_checksum: sha1:20457d533fa180415142869951b423175072e12b - pristine_git_object: 10adbd50fd0c711f14264aea1876f96b308dc558 + last_write_checksum: sha1:26c03d389afd5d78b662d7e4b4f400ca7f006809 + pristine_git_object: f3bd0a3e163c0e0bf4b3db4f67cffabfcfeac06f src/cribl_control_plane/models/countedjobinfo.py: id: e0f64f751352 - last_write_checksum: sha1:7b68514dd41140535f9731148a0fbcce08e3d066 - pristine_git_object: 4e5963540abe61abd2e25a0eaf92520555f6a30e + last_write_checksum: sha1:4ce5221a32e0b5a5e43f7c89bce1a0cc0aff950e + pristine_git_object: 1ed7f6a69b98a2484de5853039b593995fcd34e1 src/cribl_control_plane/models/countedmasterworkerentry.py: id: 5d75edaca7f8 - last_write_checksum: sha1:d8a56b9f7a674a818dfebae03d3fbc1fc3acb77e - pristine_git_object: 67745d57d5e95f55beaa2a2951a96397f9c16e41 + last_write_checksum: sha1:a8ab9b816f6c05584f4c4bb756de423d9263c60b + pristine_git_object: 70056e829bf8bc2a18e18a6b3eb8da1b17776d85 src/cribl_control_plane/models/countednumber.py: id: 814e9e08a4b4 - last_write_checksum: sha1:3abe0fde24436edc25fc9da37db5f5b2fe0a0efe - pristine_git_object: 1f02fc1ec0c23e33710341c4b0b24e410ebf8f23 + last_write_checksum: sha1:4693223352b0838fcd9a51bc2ed4c07084ff6815 + pristine_git_object: bb7c9e3720a146fc46aed68c943cb5b2b1447aa7 src/cribl_control_plane/models/countedoutputresponse.py: id: 6398c5bb78c1 - last_write_checksum: sha1:4fa89cbe22fb93a9119da2b0fb298bd42b6cb9a3 - pristine_git_object: c93368e4378e2671cfdecb13a615720d2c38086e + last_write_checksum: sha1:adbab6dd6c8829057cdf670d5965990d244ff044 + pristine_git_object: 56cae71b5ce2498dc4a77ea1d6e6f87c1dd1c583 src/cribl_control_plane/models/countedoutputsamplesresponse.py: id: 8fcde02eedd8 - last_write_checksum: sha1:e463c7f0e3a54eade0a233abe148648eb8fce280 - pristine_git_object: 2d2b69cedf5fbb97a2133e8bbf786f146c1f8182 + last_write_checksum: sha1:69bf11dc41915250a77000ba13d59dfe682b2e38 + pristine_git_object: 7bb206047093b69ebc2f8af651b4ecee97406941 src/cribl_control_plane/models/countedoutputstatus.py: id: 9e49d0e78d0e - last_write_checksum: sha1:1459fda3c6a7b2d4192624aba8763af6843e5b8b - pristine_git_object: 680532f358caa9c14faa43f0434539cd39210d8a + last_write_checksum: sha1:29c541c90c4a20f1cef3453abf952fcda10b5909 + pristine_git_object: d90ef0bfd057536dee2b7fe288fa44374ef8c475 src/cribl_control_plane/models/countedoutputtestresponse.py: id: 68eccf5489d4 - last_write_checksum: sha1:e7fbec112b5d87a693ddd2334719fa332e533be4 - pristine_git_object: e63d095fe6da82a90d22d7b4514676014feed280 + last_write_checksum: sha1:17b357ba5fd0b7be471fe4d2036ffeb3d6e43efb + pristine_git_object: 6f11bc24124eaddabd44e054603906a2ced7248f src/cribl_control_plane/models/countedpackinfo.py: id: 1fb436a54b55 - last_write_checksum: sha1:af3385b6c3600275c70a96a349ebf922351835a3 - pristine_git_object: c11a6cfae3ef1ab84e29b87d5835fd068b5ba200 + last_write_checksum: sha1:4a219d08beb7054fac5cd898cf781ff049ce93df + pristine_git_object: 6a452c40496c13b74dc8aea97d03d313c517411c src/cribl_control_plane/models/countedpackinstallinfo.py: id: 98dd40e065fc - last_write_checksum: sha1:67616acee32ea9cd0045df348e318d791ed5db94 - pristine_git_object: 9154d4520ad9b6969a51ae75ef54399010afdeaf + last_write_checksum: sha1:63d790384a59cff04017905ca93d24c356ac0a05 + pristine_git_object: adb1437b848cce3d71431f4e9552be447956caef src/cribl_control_plane/models/countedpackuninstallinfo.py: id: fdaffe9317b7 - last_write_checksum: sha1:efad45aa1002b082e8b779e3a30ec2225fe95248 - pristine_git_object: ce7660931b98770951d136f413f8ff6f66d496ef + last_write_checksum: sha1:8de9ee0f6bf0ebba02faf4fd0f71bddd101b2655 + pristine_git_object: e44e3469a63a4586441bbbbac16b629fc9681806 src/cribl_control_plane/models/countedpipeline.py: id: 6086a4e21e39 - last_write_checksum: sha1:ba1c69e3725d58cb747fc6c44bb0bf1933403c50 - pristine_git_object: 9c8f32823abbe4668f7e2e404424d942e6c4fae1 + last_write_checksum: sha1:8e48dc97092b9300a8ab7dc6415253c480068c93 + pristine_git_object: 72c2818866fb8426327af034ab9adb090eab66be src/cribl_control_plane/models/countedrestartresponse.py: id: be2f954effb8 - last_write_checksum: sha1:0d866434dfc352215440933be11eda96ed1e35bc - pristine_git_object: 044c5281b232501f19a33f09af3d54381a5e2ebe + last_write_checksum: sha1:3ab5f76814379a39780e37687f08fb17ca0c8b5e + pristine_git_object: 87d927d2e440adf74b0178f79e2aa52de8e05208 src/cribl_control_plane/models/countedroutes.py: id: b2b8034f2b94 - last_write_checksum: sha1:ada04cf7154207c2cc991c16f46571ef542c7c4c - pristine_git_object: c5145245daa10165e2582ef2fe5c81e1b82eaa35 + last_write_checksum: sha1:fc1b0c6eb29313b989b1295cbbe6ac0759578903 + pristine_git_object: 99327414ac183788ddbfe4210d6bdf6e61c5812f src/cribl_control_plane/models/countedsavedjobresponse.py: id: 4369c7a2cd37 - last_write_checksum: sha1:cb40e07605a826917e446ace110a79b5d56e0f22 - pristine_git_object: 2a05c6ebe685a0e9e9b51a547d8589ef364d3815 + last_write_checksum: sha1:c8b23ba13b51838d6a90e7f938cbc7daf64543b7 + pristine_git_object: f094ebda1a0210c6e45cf6aa7e87bdffa873ed47 src/cribl_control_plane/models/countedstring.py: id: a23c0c56d457 - last_write_checksum: sha1:30ffb778a5a1c3dd691adbec9453071f06a6969c - pristine_git_object: a7c6d80a5aa4d31f2785337e1e1dfa08979c0edb + last_write_checksum: sha1:affe295cc6401c98b74307db1aef0c061bc34fbb + pristine_git_object: 3c80f462c564222b6c9e71d7ed10d24f3512c4ce src/cribl_control_plane/models/countedsystemrestartresponse.py: id: 060d943612a6 - last_write_checksum: sha1:d14b92fba7879d15b015c8b0971d5267b12ba43b - pristine_git_object: fd5b653241ea3797adf767f849ea662d20e51f7f + last_write_checksum: sha1:302fa559e325b7fcee40f867a24414a330992984 + pristine_git_object: ebfe4aa41f13b0461f51f9eca1fde9a0d22fcaa0 src/cribl_control_plane/models/countedsystemsettingsconf.py: id: c8bc69dacdcc - last_write_checksum: sha1:3b41e7ed0229d529ae5938d1dbe8d3502fd9a0d9 - pristine_git_object: 5cb269f10ffcf7e43bcb0ebe62b9047c5e95ed33 + last_write_checksum: sha1:5f39ae1c4f617eeca3907bac9a17a40561838e6f + pristine_git_object: 20c2985d0cfc605fd74957f0b7d741fa0e6e8be4 src/cribl_control_plane/models/countedsystemsettingsconfresponse.py: id: 7d2f91ef8d8e - last_write_checksum: sha1:b28fc2a248293b76ae2fb4a27cffcb61905b9949 - pristine_git_object: 720730782dcd6f99a9de98eace283c01b4c915ad + last_write_checksum: sha1:4554d6b97ee80a66b926eb949419e595265a688a + pristine_git_object: 01d04638fc058705aad593240ae10c21de74803d src/cribl_control_plane/models/countedteamaccesscontrollist.py: id: a299c0bb7712 - last_write_checksum: sha1:64f68143c45a7095085f54b2fb308fa88d2bb864 - pristine_git_object: 0d7cdba5dc121fecf642f018e4b962313528f332 + last_write_checksum: sha1:f18bbef247cb0cda1f04d5ca035512597f7426d9 + pristine_git_object: eba04e36b7aa7416875040c0492f0fcaa30333ea src/cribl_control_plane/models/counteduseraccesscontrollist.py: id: 42c92ec95b5f - last_write_checksum: sha1:96c7e4098f9c77d4b3c3f79861eda9b461422972 - pristine_git_object: 9dc02dd253f3954b7393c0367f7c07e11d6d2d5e + last_write_checksum: sha1:04ea9fd0e9ca51904f72771bc908d6e142838812 + pristine_git_object: 6686ded3c8a2664ab9e25c37d48cf6c468bec9ff src/cribl_control_plane/models/createauthloginop.py: id: 00d898e86c94 last_write_checksum: sha1:251765e987a79d904b0bdf90182d325daac5a09d pristine_git_object: 06bb97fc58198a64073ad62e746cd213bfffb216 src/cribl_control_plane/models/createcribllakedatasetbylakeidop.py: id: 2a8423f8f77c - last_write_checksum: sha1:044626fb0ea8bdb7ddeefe9d607042fac3dc2040 - pristine_git_object: 7dfe7cee25e0723decf70192966daa935a210420 + last_write_checksum: sha1:55c4af8c02161758a116b0f5bb2fd53324fd5b90 + pristine_git_object: 4adaaad174602f4f44f19eb58b4a293fae826860 src/cribl_control_plane/models/createinput_input.py: id: 2bb4ba47ddff - last_write_checksum: sha1:1b78abd96afa20ef6fac3ee15e757f2fb538973f - pristine_git_object: cc28599a305733a6080d3be51bbd3071da61fbe9 - src/cribl_control_plane/models/createinput_inputkubemetrics.py: - id: 04bb2d66bfb8 - last_write_checksum: sha1:a35eecff51dd4a18c8d41643c006065e73499a01 - pristine_git_object: 960af388a6956cd2427d1b3de184682256625865 + last_write_checksum: sha1:8dad71c3785d53986e6bae8209f3213954c2a242 + pristine_git_object: cb25ab96b1a883e1ced4c530fdcc1b648172d161 + src/cribl_control_plane/models/createinput_inputelastic_type.py: + id: c884dbcac347 + last_write_checksum: sha1:0929bc4ed3ef5272dd89ba696e521d7c9ed747d6 + pristine_git_object: fa0bf0612d0711585533b145396e50cd6505b765 + src/cribl_control_plane/models/createinput_v3user.py: + id: b1343f337677 + last_write_checksum: sha1:8f4f957f603979b02286ae44d193deb3affbfb69 + pristine_git_object: 628dcfb0635eb25b9dcb4973d75e9d6afd08a16c src/cribl_control_plane/models/createinputhectokenbyidop.py: id: d2a2fc31d146 last_write_checksum: sha1:3f7d4b12adf786a50235db93776c854ad3947fe9 pristine_git_object: eef650237597a777cbd36dd230a0832afbb67960 - src/cribl_control_plane/models/createinputsystembypack_inputkubemetrics.py: - id: 8d37d18b026a - last_write_checksum: sha1:3319d1e28c9a873b46eb2831fe45736171f0e08d - pristine_git_object: d957ffef4e4643683d7471325afd96ccdba14a32 + src/cribl_control_plane/models/createinputsystembypack_inputelastic_type.py: + id: 77ca17d2f23f + last_write_checksum: sha1:48b3e7001bcae14ec2b2b908187695e88fdd5514 + pristine_git_object: 94ea726e077e595b8995f43c1fbfc7d6c0e7c394 src/cribl_control_plane/models/createinputsystembypack_request.py: id: 9a05ed789849 - last_write_checksum: sha1:dc9341fa433a1d85636eb2d3d04df57687c7c448 - pristine_git_object: 9fd49ba8afd0b141c5542dbfa700535d2a5c81e7 + last_write_checksum: sha1:b229cdf9ace2a6d8c7bc640bb2364131f84ac496 + pristine_git_object: 60cf7031cdcb7639dbd2192b5cee6f2b177783b6 + src/cribl_control_plane/models/createinputsystembypack_v3user.py: + id: 79aaabf3b812 + last_write_checksum: sha1:90127920e83e0e1d1a722da4845545c63219161e + pristine_git_object: 54c3581d77e58938c74199986fa1fc9ea2f0d3b1 src/cribl_control_plane/models/createinputsystemhectokenbypackandidop.py: id: 20d15344dcb5 last_write_checksum: sha1:b6cdc4ad942b4188b7fcbbbbfb85ed2a7692ed08 pristine_git_object: 517c38e4cd8df3e03f3464625bc2e1c750f6c7ed src/cribl_control_plane/models/createoutput_output.py: id: 7199da4b4a7e - last_write_checksum: sha1:55775aff50b187bc39724faccab105f07e0f51b1 - pristine_git_object: 534623077328fabe739915d56b984c9d0c5b0cad - src/cribl_control_plane/models/createoutput_outputdefault_type.py: - id: 07c549e2f384 - last_write_checksum: sha1:1c94a5552f12bb1b02eb19415499332c6228d8e0 - pristine_git_object: 2fa1c7d41434fc8e234110e51d8f38d7a657c008 - src/cribl_control_plane/models/createoutput_outputstatsdext_type.py: - id: ceb15efa10bc - last_write_checksum: sha1:26474e5753b724d66f84c43f3f0dc57830ac0989 - pristine_git_object: 111f48c415464b319a1c6f41abea2793a942b7c2 - src/cribl_control_plane/models/createoutputsystembypack_outputdefault_type.py: - id: 78a93cf45b67 - last_write_checksum: sha1:c0a42da92fabb8491d9595e8fb45379bf8d4bb41 - pristine_git_object: 46419fa108f4e09404ca36b59dde16b828293f59 - src/cribl_control_plane/models/createoutputsystembypack_outputstatsdext_type.py: - id: c721f2a20fd4 - last_write_checksum: sha1:ed536530cc667c50a7cd94dd9450b1b1a8bd23d6 - pristine_git_object: eaaabce4e41b591552061eb0b53a493e3aa48c15 + last_write_checksum: sha1:5b73b3f6d212c1ad1b0cc03079ce7fda5e879c62 + pristine_git_object: e5c22a9b25dafad165990e12b049d2f94e808672 + src/cribl_control_plane/models/createoutput_outputsns_pqcontrols.py: + id: 09e96d6ffc43 + last_write_checksum: sha1:4320639712301650ef0436559babf3daccddb2a0 + pristine_git_object: 6bb1369260818fd12bb4e7da143639177d170a20 + src/cribl_control_plane/models/createoutput_outputwebhook_format_2.py: + id: "692590027130" + last_write_checksum: sha1:f812956fa15aac0619cb85ade62e59539331612e + pristine_git_object: 3134b354aa556c0314b977240141e0f29ae774b7 + src/cribl_control_plane/models/createoutputsystembypack_outputsns_pqcontrols.py: + id: fdb8ac5c2084 + last_write_checksum: sha1:49984d764d2acc83b373845187c4390e7193acd3 + pristine_git_object: 2f8a2326cbd9486b3c71fa2226ce91157c5dc915 + src/cribl_control_plane/models/createoutputsystembypack_outputwebhook_format_2.py: + id: a6d07ec411ea + last_write_checksum: sha1:d5acd08048f200471222e03fe3501573a9fac89e + pristine_git_object: 92032a8ac546461490f645f0eb5bac2877320aad src/cribl_control_plane/models/createoutputsystembypack_request.py: id: b47a50bc9cb8 - last_write_checksum: sha1:660d099253638448437eaff3d689edaf3e5b02b9 - pristine_git_object: daacdc41e18ecee54b91e92cf37c608c5eb3f835 + last_write_checksum: sha1:d94d42a527e2b3d46286ab005e9cbd310f611efa + pristine_git_object: 4a3a93c3e9c0251a441380d89e9cac9ead777c1c src/cribl_control_plane/models/createoutputsystemtestbypackandidop.py: id: d061fc4b3fff last_write_checksum: sha1:5f591b9f2193252a9d83e9fe29734906f95b6c5b @@ -17868,12 +19040,12 @@ trackedFiles: pristine_git_object: 34785c89c05d3dd548db05ce55c229b07b0dbfde src/cribl_control_plane/models/cribllakedataset.py: id: f65290fae1ee - last_write_checksum: sha1:16b128393bd9da84055955504dc03d1212e35b90 - pristine_git_object: beb2ce4dc43b651475e886ab477978e3ff6f7484 + last_write_checksum: sha1:55025ad0577abdd4e6db31a20ed1c301b9cc1b06 + pristine_git_object: 4c8ec8d7c398a8a791e02106c82f77b2beaf832c src/cribl_control_plane/models/cribllakedatasetupdate.py: id: 030ec8ded8ae - last_write_checksum: sha1:ad19316300d30fb0d00c6dec828e77050c80cc27 - pristine_git_object: 8e59cee86b0092f2b5914ff11b7673f0723e3bdf + last_write_checksum: sha1:6621a2be24748a1e8d0d0fee71df6c050a6ad297 + pristine_git_object: c52fa93bf882a72f68b0d3639a7a9f8e10446597 src/cribl_control_plane/models/currentbranchresult.py: id: b03cd82b5d52 last_write_checksum: sha1:61df2a3a2721171db6994baddf4268e3995837e8 @@ -17892,16 +19064,16 @@ trackedFiles: pristine_git_object: d5932ce374d1d5f307bace1f9a2d8ae1a3c752c2 src/cribl_control_plane/models/databaseconnectionconfig.py: id: 648e0cece0e2 - last_write_checksum: sha1:f2487a267d15a85df9c2d1f1afa16e41da8a4493 - pristine_git_object: aa9bf46995ad4627fe496f265c09ffd7732b6949 + last_write_checksum: sha1:9c8c7d915c6a75f7b4a8410b95d6d7cfdf8785c8 + pristine_git_object: 3d1ded2d9ea5989fcda284317f84c46b6f011269 src/cribl_control_plane/models/databaseconnectionresponseenvelope.py: id: cefeb2502d6c last_write_checksum: sha1:38b92e061ef85c5c663a4d3125140bfca521da4f pristine_git_object: 236428841befbfcd8aac9cab9cd87306b7aaf064 src/cribl_control_plane/models/databaseconnectiontype.py: id: b01c5eca12e8 - last_write_checksum: sha1:479f7056aa95bf7475aacb42636405df63887a3a - pristine_git_object: f0d98aebf78d8a9ba9ee5529cfff21b29e0a208a + last_write_checksum: sha1:a5abcef53f5b77f333f9872ead69fc1b1e93181a + pristine_git_object: 6da36ca9972b4bc9026b47d6fb2bbe83bd5c090f src/cribl_control_plane/models/datacompressionformatoptionspersistence.py: id: 318958348d3f last_write_checksum: sha1:fb8ef7b74a3b953782cd66099aef60f1cb19571a @@ -17996,8 +19168,8 @@ trackedFiles: pristine_git_object: 85580e06b41b2873db670966df086d770eaae242 src/cribl_control_plane/models/destinationtype.py: id: 3bac940576a3 - last_write_checksum: sha1:430d1ec0479227621bca8c987171748e08388a2c - pristine_git_object: e2cf28eb7216c1dc84ae7b74d21a7c9070717bf1 + last_write_checksum: sha1:973500ce4d73162ef24f831b46e321d17d9441e2 + pristine_git_object: f9544a7a1df0f54d9ce5db671d3b2ae788cd853f src/cribl_control_plane/models/difffiles.py: id: 76d032a8c166 last_write_checksum: sha1:a263491a3384e2304a558da25fa31ae156dc0736 @@ -18034,6 +19206,10 @@ trackedFiles: id: 2c0ec687856c last_write_checksum: sha1:5327d97c56ba02f61bb54e0e9a3829dc745ff756 pristine_git_object: cc5e1f73bb71faaea3a4e6c7ad53b3241a977900 + src/cribl_control_plane/models/emailrecipient.py: + id: 8f5e62f9eba3 + last_write_checksum: sha1:d427429ba3e0c53dc40aed5a5a8dc0c2c5c12a96 + pristine_git_object: 5e5677dc7785111829ee826f93b003b4a46811d2 src/cribl_control_plane/models/emptyobject.py: id: b277ddbe66aa last_write_checksum: sha1:5d0fca09d33177c84f25ed56c74bc9eb8a2a64b7 @@ -18046,14 +19222,10 @@ trackedFiles: id: 15764f435d58 last_write_checksum: sha1:ac0760be6fb7441e8da4c7ccd85715c4d4142ca5 pristine_git_object: 70e7025a75b613f3dfebcdd5f2a9c25fa0cd3752 - src/cribl_control_plane/models/executorspecificsettingstyperunnablejobexecutorexecutor.py: - id: 48aab4e5ad20 - last_write_checksum: sha1:1a617ee42be387094e91c51a8bb7f78d4c5d7d05 - pristine_git_object: 1d9a682554ff4ba976b4ef2d2a84bdf03fcad790 src/cribl_control_plane/models/executortyperunnablejobexecutor.py: id: be8d61a4de85 - last_write_checksum: sha1:3c99b21eb3e65c660e41739792d464ecec16f602 - pristine_git_object: 5b02297724c13545f1065f9d7a4cb9ac75a7101c + last_write_checksum: sha1:2d0bca12ddb06ba71951512f0587cc071c93bda9 + pristine_git_object: 900c77313bd484e6af8c98b87d49feb96911be47 src/cribl_control_plane/models/extrahttpheaderconfinputelastic.py: id: 4675c3c8a805 last_write_checksum: sha1:7515eb41f41140b99c7ad9561a3bdd9c0e3ba848 @@ -18130,6 +19302,10 @@ trackedFiles: id: a73244084872 last_write_checksum: sha1:febab8e5eac785ae37116e7dd3e34d253d605efd pristine_git_object: 24d3f4e827be97885f90c4fe62607de95748e54d + src/cribl_control_plane/models/functionconfschemadetectionrules.py: + id: f614a949c017 + last_write_checksum: sha1:e42a0e55965f9e960c822704d489b0ab90a42ec1 + pristine_git_object: 22130009919ad48f6164d9288bfd716956f46ac6 src/cribl_control_plane/models/functionconfschemadnslookup.py: id: d1ca2f8ffaf8 last_write_checksum: sha1:15f7ea6f085aaa9ad0cce53f3173788f44c7a6f7 @@ -18158,6 +19334,10 @@ trackedFiles: id: a653423b2939 last_write_checksum: sha1:60c230b4002fa5ba405a6d563071f27447544a66 pristine_git_object: 6b5dba4844567a744362ae461d74518e05e2636d + src/cribl_control_plane/models/functionconfschemalakehouseenginemetricsnormalizer.py: + id: 25bb588039c7 + last_write_checksum: sha1:07e46aedf2ba9ac3c3d488868bef2b922cc90a00 + pristine_git_object: dffa5fe7a23f875eeda222c5cfa0b850528b3c37 src/cribl_control_plane/models/functionconfschemalimit.py: id: 8cb859311c8c last_write_checksum: sha1:16facbca950a31160a2a4e39997cc1448e0f531b @@ -18182,10 +19362,14 @@ trackedFiles: id: 17a6592cf491 last_write_checksum: sha1:bd7c78f6b950554e7e12e9cd70257d27a442f02e pristine_git_object: 10367406b3a5d332bceb3091c1a311ae64cba18c + src/cribl_control_plane/models/functionconfschemametricstimerangegate.py: + id: 8d9498b6c65e + last_write_checksum: sha1:ad4c9fc129b7ecbf57822e016dc1852287433b6f + pristine_git_object: b5e54b68a0f1695689a534b62786c7f344d11c95 src/cribl_control_plane/models/functionconfschemanotificationpolicies.py: id: 79384005643e - last_write_checksum: sha1:edbf7730ef41a4cf81555e65e4628c4d97fb2f5f - pristine_git_object: 8246b13a6c8ba0c7994395a0d8abe9368dd8ffee + last_write_checksum: sha1:0368e192b531787ed117353616acb38f814ee8e4 + pristine_git_object: 46bcfcd57b741e10d8228cfbd1dd3758f63ad667 src/cribl_control_plane/models/functionconfschemanumerify.py: id: f01c1f1be4f6 last_write_checksum: sha1:cdda4ac2aced16180590b62fec3cfa75f285a920 @@ -18234,6 +19418,10 @@ trackedFiles: id: 2be781a5b0a9 last_write_checksum: sha1:ea59b02316d54dbba81340c20402927763e4d3e6 pristine_git_object: cd195a40e7544381f9216902717198ef511b01d0 + src/cribl_control_plane/models/functiondetectionrules.py: + id: 71b1dfe1ccd7 + last_write_checksum: sha1:d5ca781add727e8deaab444fbe3b9778ab60e75a + pristine_git_object: dcb99f9fb68b97a09c1e49d3ceb33f7bd3af9546 src/cribl_control_plane/models/functiondistinct.py: id: 79b27ac69b5e last_write_checksum: sha1:31f32960df13d169f7899dd7b54304bbae01761e @@ -18306,6 +19494,10 @@ trackedFiles: id: 71ebf6961423 last_write_checksum: sha1:57e57d9bd8685f01ccfd88c44cfd62850853ec54 pristine_git_object: 8e38913f740df1089625bf8b9ca3e04da7c819e5 + src/cribl_control_plane/models/functionlakehouseenginemetricsnormalizer.py: + id: b354a3204d11 + last_write_checksum: sha1:51797dfc9b8934335de6e404e46b08565b4808a0 + pristine_git_object: 4d3c73225747708c48a5ff979e694dc31f927ddf src/cribl_control_plane/models/functionlimit.py: id: 4e4ce65b44b3 last_write_checksum: sha1:d1a3c540d14263030329201666729d783aee077a @@ -18342,6 +19534,10 @@ trackedFiles: id: c7543a1cfbfe last_write_checksum: sha1:da8a4b07099ff4046d9ad699c7a9c1ec8e3a67e1 pristine_git_object: ed359b234a589d6f8bf09bf5a09df0e4b10709fd + src/cribl_control_plane/models/functionmetricstimerangegate.py: + id: ed714575c3bc + last_write_checksum: sha1:418feaec7dd29bf7d551cd8aa3e9c745318810c7 + pristine_git_object: fc44e272cd2b87871567f92ac1eb1ca2e868f50b src/cribl_control_plane/models/functionmvexpand.py: id: 72db04037a20 last_write_checksum: sha1:0f60835271100a1b43a1acad827504d61dec152d @@ -18408,8 +19604,8 @@ trackedFiles: pristine_git_object: c0247717d995bc3ba5db305c25f81a8a3eff34d3 src/cribl_control_plane/models/functionresponse.py: id: dc3a23fe3539 - last_write_checksum: sha1:39900d02d5d069e7dfb8387c52f290503b50ebca - pristine_git_object: 17ddfd425b5e2c40fde1a2d5467b1500840624b4 + last_write_checksum: sha1:dea4e69e839025b92e7aa8c36e527e4cb13efd89 + pristine_git_object: 47b0ee1c6281056592478d6d489233c73f95e573 src/cribl_control_plane/models/functionrollupmetrics.py: id: b049bbc2bbc7 last_write_checksum: sha1:af0e6215cda1001f0e1300eae613d0890ffffe37 @@ -18488,8 +19684,8 @@ trackedFiles: pristine_git_object: 9c14b9986a21138c74f9e49760577e8eb97fe23f src/cribl_control_plane/models/getcribllakedatasetbylakeidop.py: id: 2bf0d8c8f207 - last_write_checksum: sha1:e2e842e2f27e25750f72583f1f501692cd6babdd - pristine_git_object: 744978da194515a9dcbb43f59302497293f65d31 + last_write_checksum: sha1:3dc1326c46acd53007707506bb12b5d9ce7de2fb + pristine_git_object: a0198cdb8398d93e6fa1af403a27edb18e77411a src/cribl_control_plane/models/getdatabaseconnectionconfigbyidop.py: id: c28fe8c2f294 last_write_checksum: sha1:54a5079215e8cf1bd2d3e62f98e43a54bcf72348 @@ -18510,6 +19706,10 @@ trackedFiles: id: f044b9ef810a last_write_checksum: sha1:a8642beffb6a825ad24068ef535eb89c64004932 pristine_git_object: 50f65127eab2000f15e8a5225eff645494903cc7 + src/cribl_control_plane/models/getinputop.py: + id: afaad4df8793 + last_write_checksum: sha1:a88a76f24ea53ce6739fde4026eb445c49f07632 + pristine_git_object: 0904ec94d32f04120a998deff381bed8f86d7701 src/cribl_control_plane/models/getinputpqbyidop.py: id: 4d553e18c4bb last_write_checksum: sha1:83b15fc8517cebec38453402bd4921368605a00a @@ -18546,6 +19746,10 @@ trackedFiles: id: 1022f08c1916 last_write_checksum: sha1:e37dbbaac47d53bd0aaf3f7b945c2e797f14d0e5 pristine_git_object: 912c1d9f0035e532ba00ff29e978db7ccd1805af + src/cribl_control_plane/models/getoutputop.py: + id: bb5ef8ebc537 + last_write_checksum: sha1:41e88ee53ae0bbb6c665018e18ca3360cdb35996 + pristine_git_object: 9521901493e3bd1432bf1da669d44a7c3895b175 src/cribl_control_plane/models/getoutputpqbyidop.py: id: 600a0acb69f8 last_write_checksum: sha1:7c556aad927cd4db9ee8db6228e6f2bf7b583cb0 @@ -18604,20 +19808,20 @@ trackedFiles: pristine_git_object: 812273b9400da5b1b601a7d945dc574a7c9a3aed src/cribl_control_plane/models/getpipelinesbypackop.py: id: 8c01a558f5b4 - last_write_checksum: sha1:58b6b8203887a92723f261c5d2e05b38dfe663bb - pristine_git_object: 5fc14e7e582e67d8ecf4b4f2114bbf15339df163 + last_write_checksum: sha1:7c394e1bb93c581d1907335f393646a212d6f87a + pristine_git_object: 669ace8cca19049c115e35801e83eb40d5efae0d src/cribl_control_plane/models/getpipelinesop.py: id: 461c53138fb3 - last_write_checksum: sha1:0061207bbe156c65fff2606b0a310712221eb172 - pristine_git_object: 43a8548571e8d31892ea56b6c38609544bbbde8b + last_write_checksum: sha1:f1891ae16775c797667ad774043306d45061bb64 + pristine_git_object: e12676009dd55e4dab1b7d290fd1792fe2cc8d05 src/cribl_control_plane/models/getproductsgroupsaclbyproductandidop.py: id: 1c82341ab98a - last_write_checksum: sha1:b572aaa37641f06422f11b3efe7a79ca509ddd26 - pristine_git_object: 0cb9593bb9cc62ae4fd3fa15e3f8be15ab26beac + last_write_checksum: sha1:62e3e6d089d61d623b63ec294c4f7b98062f8eff + pristine_git_object: 9b09558601dcf13ea40e34c2df42e09ea189b96f src/cribl_control_plane/models/getproductsgroupsaclteamsbyproductandidop.py: id: b22924742403 - last_write_checksum: sha1:866a84c3cc0282de21f2afb3d5cf8d36fc499732 - pristine_git_object: faa79d553499a82ad35b49fe11ae9070e8d05238 + last_write_checksum: sha1:e0d41d3c341291046f4535ead8bf0145c603f44a + pristine_git_object: 17f5f19ffd4957209bf6e30cdbedff1041342bc2 src/cribl_control_plane/models/getproductsgroupsbyproductandidop.py: id: 44d3ffba81f2 last_write_checksum: sha1:e1dc03a3e90c503a714ae5a5939764db47c8e3e4 @@ -18656,8 +19860,12 @@ trackedFiles: pristine_git_object: 90038345c040e08dc60b0529321fd3f61a78ffd0 src/cribl_control_plane/models/getroutesbypackop.py: id: 3a554f626cf1 - last_write_checksum: sha1:9b08fe1ded394081b2d09b29fc636dd40c6f62e1 - pristine_git_object: 066f0e60e2ccaa659d4a99f99882c4251196ce1e + last_write_checksum: sha1:f4ce4cbda92c634be5ffdaa9a9ba96ee26eed145 + pristine_git_object: 566176d8a35fcf41499b8ec65a9332cc94c300ed + src/cribl_control_plane/models/getroutesop.py: + id: c36947d816b0 + last_write_checksum: sha1:8b92ed6c42661fd718ae37baaafb67dc5a564170 + pristine_git_object: fb75399dcd5591174dcbccade9778fbca44d439e src/cribl_control_plane/models/getsavedjobbyidop.py: id: 4d607db0695e last_write_checksum: sha1:b7235c4b328f6c294a5cc777ad9b4fb7b08390e3 @@ -18756,12 +19964,12 @@ trackedFiles: pristine_git_object: 9b9dc9652ee25d79f0eacf2149e3f68ed876ec72 src/cribl_control_plane/models/groupcreaterequest.py: id: 2993a38accbd - last_write_checksum: sha1:61a6c4687cdf72905b8f63202b4c28310a20f0b5 - pristine_git_object: 6c1245a2af3b2dda2a1ea0365cf52af95310ae87 + last_write_checksum: sha1:fac7a025a1041c63118cb31780c22f34eb8cadeb + pristine_git_object: 2bf3245f746cbe134cbcd0123cb513a6f1312c12 src/cribl_control_plane/models/hbcriblinfo.py: id: d1662d5e9727 - last_write_checksum: sha1:29ea44b7d1f4708c48f9e07b33daf8e499a60bba - pristine_git_object: c6dde4bb9f187d0e2a87e0decccd8ae879c83344 + last_write_checksum: sha1:5e3833b5fc8ab4966abd6f49afcab265c78b0ec6 + pristine_git_object: 6b3963b57962e34f14353859ab751b761f187797 src/cribl_control_plane/models/hbleaderinfo.py: id: 76db1d8ca963 last_write_checksum: sha1:d7cf3649b324bacfe324b0918b0227282b0c6e25 @@ -18808,44 +20016,60 @@ trackedFiles: pristine_git_object: 38caaeb14bbe63cd1b829c6be803a2be37797dfe src/cribl_control_plane/models/input.py: id: 6830a15033b0 - last_write_checksum: sha1:a8ad71f8a2a77aab81362bf5eb810bb46d59afd6 - pristine_git_object: 1407aff423fef41e98d308f9095343cfd2238a06 + last_write_checksum: sha1:c28da92d77440e4b648b886efc950046c611dc55 + pristine_git_object: dc487fcc098778c9bcce7f8678686e9b6dd7825d + src/cribl_control_plane/models/inputakamaihec_input.py: + id: 3440a4e746da + last_write_checksum: sha1:fe87ae20a8c846d6fe7e6742eb894e6b73b796bf + pristine_git_object: afae9a12475a618a2b7e16411d18471501a9828a src/cribl_control_plane/models/inputanthropiccompliance_input.py: id: 22cda9eccc16 - last_write_checksum: sha1:0d64e013c0564f25d44107651b5ba4485d23b88d - pristine_git_object: e8e2b7c1870cd86ec6b0fa5578372cf23779694c + last_write_checksum: sha1:b60991be4e0077a0c8e19ac23b0026dadd4b1d24 + pristine_git_object: d5338902e6e6b4c3cbaf0d061c3b642c096b6c3a + src/cribl_control_plane/models/inputanthropicenterpriseanalytics_input.py: + id: c4fc363bc0d6 + last_write_checksum: sha1:5a42ff72f472d55a9121a5cb3ba37bb368795461 + pristine_git_object: 7d18a1e89a7b325ccc2e9c52d8eb92345643c5d0 src/cribl_control_plane/models/inputappleunifiedlogs_input.py: id: 16b3b9edb704 last_write_checksum: sha1:6b12e2523c6065b586ee643383fe0732e8d14323 pristine_git_object: 95229683b257d4071e52511d15ef92dcf5418371 src/cribl_control_plane/models/inputappscope_input.py: id: cd5957422daf - last_write_checksum: sha1:1e5f4bfc24c0fb955932ef3ee72b65ab298f34e6 - pristine_git_object: 1b1e065205fb7838b0dffa9b173f076c92fcd34a + last_write_checksum: sha1:4f2ad7386187193192ac3724489367db4dc6755a + pristine_git_object: 6bee9c3e2f34b7c9570e7d567a7f5b4ca37b3a3a + src/cribl_control_plane/models/inputaquasecurityhec_input.py: + id: 561022aa0bc9 + last_write_checksum: sha1:88d66c68980704600dffcb83bcb9a4740ffcb0bf + pristine_git_object: a6ff14494e6bfcb6078c3b2b9ebac30849b3e53b src/cribl_control_plane/models/inputazureblob_input.py: id: b5d314666164 - last_write_checksum: sha1:aeaafcf345a423f64b3e2cc5af16c559b1bcc534 - pristine_git_object: 06c5dfedc0f8c9ff4880feba29e4d8afc269cb05 + last_write_checksum: sha1:c9185379c75bfe98681d4c415ad9a7b3002f34b8 + pristine_git_object: 53f463a717eb273106c8a23cbffde2eaee346201 + src/cribl_control_plane/models/inputazurevnetflowlog_input.py: + id: 0cd5cc0a0ea8 + last_write_checksum: sha1:a756271690fed69193c7fecf3685868a25d539e8 + pristine_git_object: b824a2a364be99af7fab56c0fd253ef80ccccf53 src/cribl_control_plane/models/inputbedrocks3_input.py: id: 1e66d300b39d last_write_checksum: sha1:a86bacd0929e13e433a4dc7b8a9a02846d186062 pristine_git_object: 9c1dff44858053cfc1101111b2875d8a4d95f522 + src/cribl_control_plane/models/inputbeyondtrusthec_input.py: + id: e05baad32177 + last_write_checksum: sha1:82cfcd7e78b38b83702a18c8f4217f947f22ea35 + pristine_git_object: d7b784a2f5858ba8e1b45b1da58507e68e39adb8 src/cribl_control_plane/models/inputcloudflarehec_input.py: id: e4377eaf2ef5 - last_write_checksum: sha1:0daf3a2f98becf0a830df3679b11a365eaf6900c - pristine_git_object: 33f0a9aeb0868f50a7cafcd192286eda7fb3ddd7 + last_write_checksum: sha1:6d9b034b6f07d23b337437faefd8de6889f7dc20 + pristine_git_object: 62449c81d42b268e7d26dc5575cb4ddccfc17eb0 src/cribl_control_plane/models/inputcollection_input.py: id: 5751d6cbe10c last_write_checksum: sha1:25d2c7f124a5f6eed9c2d2b2f10a12709f59741d pristine_git_object: d7235540088b38ca7162e22f645e2cedb079402e - src/cribl_control_plane/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.py: - id: 045aede866a6 - last_write_checksum: sha1:1d743bc48bb278e20f5033f3671fc1f984b71ead - pristine_git_object: 19dee6ddff9e0bc07cd1549ebc7125228fb028e1 src/cribl_control_plane/models/inputconfluentcloud_input.py: id: 60ef0c42e033 - last_write_checksum: sha1:393a937e99aa5bf68a47d04ea8418677312c0394 - pristine_git_object: 19d7af3e6fa8ca359a5ce4460ef620319434d3f5 + last_write_checksum: sha1:336abb5784dfd22421c735d242c48758c34c8aff + pristine_git_object: 328d7c933a280321ad4baf5c5e7b99d0b432d4f6 src/cribl_control_plane/models/inputcribl_input.py: id: 9357b3e36726 last_write_checksum: sha1:6bb99d0d5cb6dc3c9c41a773fdf98f02e94ff664 @@ -18856,8 +20080,8 @@ trackedFiles: pristine_git_object: 99013043bf6d18dbe56b03a9ce419c7c63164fa5 src/cribl_control_plane/models/inputcribllakehttp_input.py: id: 0b9adb9c2ffb - last_write_checksum: sha1:adec739d014c03a34c639a6b57bbb484155e0b8e - pristine_git_object: 80262095e3edd1fce14a5af3b028677717e663f7 + last_write_checksum: sha1:1ac59a0b9fd545caeb70c85927158498055ece26 + pristine_git_object: 4e7a5d83d4117fde207b6c1c81d92b53cb4a4541 src/cribl_control_plane/models/inputcriblmetrics_input.py: id: b9b29c6bac9e last_write_checksum: sha1:fb926e2d7691b553cc11a7ba493d6ad4e04f8ae5 @@ -18888,52 +20112,68 @@ trackedFiles: pristine_git_object: 9c08047c8fa44c5c9b2b9e6e1aa1b8bb16954253 src/cribl_control_plane/models/inputeventhub_input.py: id: 2a7a44074d87 - last_write_checksum: sha1:9c7c3b24ed5919c20063cc2549b3f4db0fcf462d - pristine_git_object: c42e79329954ffdd69cca0c3be5f2f06a70b393c + last_write_checksum: sha1:ab2d568df76a3306a1a9000778d8c146cb886c25 + pristine_git_object: 6f83975be4906c3a730cf078053b1fbadf8fd06b src/cribl_control_plane/models/inputeventhubamqp_input.py: id: c9d97d144e1d - last_write_checksum: sha1:740c6ac9bc6ae5fae17c5d6cd15660fa9255ace1 - pristine_git_object: 08b927600492a21be966b641a66cffd4d2587803 + last_write_checksum: sha1:07d5cbbee6447792d31cb5ccc563e6311a6dbac7 + pristine_git_object: f58d48ae54c867212619a5606526d73a8910d6e1 src/cribl_control_plane/models/inputexec_input.py: id: 83de10786a42 - last_write_checksum: sha1:b07667acd27ed0fa4c4fddc0d36479ee40cf1756 - pristine_git_object: 93b4dec55b2a23e86bd80447c61ff1d8475adeeb + last_write_checksum: sha1:b9557f2b4fe61d17cad0534cc978b7e1c665e7ac + pristine_git_object: 8a5f4cf16add3c09f0112b7a5e7b60c9189c72f4 + src/cribl_control_plane/models/inputextrahoprevealx360_input.py: + id: 7eae90cc86ba + last_write_checksum: sha1:5c32b34d6f3a10da7523f34d904cc9872d7c15b5 + pristine_git_object: ac50a7e3044748c1ae97c01b4420f7c4f709acd1 + src/cribl_control_plane/models/inputf5bigip_input.py: + id: 02a5506c72da + last_write_checksum: sha1:bc551589617872e3d44a58a158cbec08ffcf3f3e + pristine_git_object: 6f252efbb0d34ce9079a9d22474206612c103f19 src/cribl_control_plane/models/inputfile_input.py: id: 2f2ece3f4da7 - last_write_checksum: sha1:fce220c8aad3975ef3e83aa9d1445b3721530194 - pristine_git_object: 78f4266613ab14e4557ed40dcb728b2eaa94a91f + last_write_checksum: sha1:572be16622d7628267bd99027681a6300d9a3e07 + pristine_git_object: 73ab35c65ccc0b095fee4a5376e753350f552871 src/cribl_control_plane/models/inputfirehose_input.py: id: 7982aee54e23 last_write_checksum: sha1:df8fc7181b4a33fbdbbc993bfb89ffc92b6ed433 pristine_git_object: f53309a73f1dc38b1e92990d5f93331eb2a5e3d9 + src/cribl_control_plane/models/inputgigamonhec_input.py: + id: d6e2704286e3 + last_write_checksum: sha1:0f522084da56b2b2cd3b65ac18e4eb2e7a59dde8 + pristine_git_object: 7004a6d1ffc59ed1754b9c194179d951640d8566 src/cribl_control_plane/models/inputgooglepubsub_input.py: id: 66ec03ee28a7 - last_write_checksum: sha1:5dec13a04cc52a3ba96553c6a11c08f32395f85a - pristine_git_object: 3726d90da3b14c9b0fd17d39a6c4b790cb9111d4 + last_write_checksum: sha1:7772e8740d1cc45c68ff6ad387cea77c6cf7b10b + pristine_git_object: 3dc9abefff44336d5cb1e27280bf24e21f709624 src/cribl_control_plane/models/inputgrafana_input_union.py: id: 281b44790f77 last_write_checksum: sha1:a97c16f414623f0b2cd51b799b76cb1e186dfd52 pristine_git_object: 168b9e57635147ae751e7e301038a01116becacd + src/cribl_control_plane/models/inputhashicorphcpvaultdedicated_input.py: + id: fa280f6f2e8e + last_write_checksum: sha1:283859ab59372d6fe449ea7e2e17fa967c37c436 + pristine_git_object: a973d5f44c19f3cfad5e46eb6e8524fc8dbab3bb src/cribl_control_plane/models/inputhttp_input.py: id: 659ac8226e04 - last_write_checksum: sha1:3d842e0134bac555ea2d0d6f3cf47e79c76a0989 - pristine_git_object: ef9bfbaa85cf9ec584f7d6d5102d704bf092a54e + last_write_checksum: sha1:8b35cb66c78abed15939b574738b31c45ea6b52b + pristine_git_object: 6c7e2d62e8c0f8293a2b7837aadca25ea0af2076 src/cribl_control_plane/models/inputhttpraw_input.py: id: 1b38ee0e9424 - last_write_checksum: sha1:5f1bbd20ac49c0e6ca2799cbb359aff32e4537fc - pristine_git_object: 70fe4ead4318168550055bc4ef74041505b3f0ea + last_write_checksum: sha1:068ef516ff717835348bfcd7113823357dd92510 + pristine_git_object: 889a414f94372a48d155f0e42e6ab723d5581923 src/cribl_control_plane/models/inputjournalfiles_input.py: id: 7653532158ec - last_write_checksum: sha1:96e1457b61213c6b5414e744304d66811e209bfa - pristine_git_object: ef59721c02c44bbd9a0ccbff907c7fab743fd4fa + last_write_checksum: sha1:e96c32a6a1b6e2fbbc9ac3f67c8e825f1811366a + pristine_git_object: f10a3acb815b5e32e15ca747313080cf4cb3451f src/cribl_control_plane/models/inputkafka_input.py: id: f845de6defe7 - last_write_checksum: sha1:e795fa9b2026750a9daec5addaf540a4a05ba2b8 - pristine_git_object: 3af32a9afcdfa85d6b860256e9bd94c407cbbefa + last_write_checksum: sha1:012fe6a468e731ebc554dab36036ef6e06f2bcc3 + pristine_git_object: 1fb0621f16a60e4d154da1b084ebb2b9d15f7e03 src/cribl_control_plane/models/inputkinesis_input.py: id: 0d81fe4d8717 - last_write_checksum: sha1:6805d9cd1269d2b2cac1c069b0af5ec3ce92bfa2 - pristine_git_object: 60b96a5352f7bcb541c8225002e514f7604e4fc8 + last_write_checksum: sha1:84c03260b185e660ba1e8726924e368d7e9ae133 + pristine_git_object: a49f28e34de8419c9a76c5da3f2d06ce2aa12184 src/cribl_control_plane/models/inputkubeevents_input.py: id: 5405b600cc45 last_write_checksum: sha1:5210bbf4172a357d8e69bbda9896370b95921284 @@ -18954,18 +20194,26 @@ trackedFiles: id: 5ffe6870f9eb last_write_checksum: sha1:564d8687d5348e8e09addc0ea5413aaca6890f31 pristine_git_object: 5470205c80c26bb4e7069c557ef2f7a7a4f5956d + src/cribl_control_plane/models/inputmicrosoftcopilot_input.py: + id: c59810ae65e6 + last_write_checksum: sha1:4558f0411988a99c01006e63e421880810421787 + pristine_git_object: bce4ad86d619a523294520cba33b6526b263843b src/cribl_control_plane/models/inputmicrosoftgraph_input.py: id: fcc7fffc7383 - last_write_checksum: sha1:eb00dca52a7891fbf4a0b73485ec94a8952bc7d3 - pristine_git_object: f3fb1e6a268f1b64be899944a60e1e064f9e3648 + last_write_checksum: sha1:89608f66f5cff03a220f7e912de5eb51df11c57f + pristine_git_object: a012b3fb4e355ea3c7f8a2d64fcbee53e176fc64 + src/cribl_control_plane/models/inputmimecasthec_input.py: + id: 0945d6361541 + last_write_checksum: sha1:637292e00f6e2114453aa1ed1c8e685f29f42d94 + pristine_git_object: 6a24b335fa849a2f34c199614af93892b20aafc6 src/cribl_control_plane/models/inputmodeldriventelemetry_input.py: id: 13d70bdeba62 - last_write_checksum: sha1:ca878365b4651be82e3c7d064d530ea878f07b1e - pristine_git_object: 79d007ac0105a03de17aa899f1fe80daeef2835a + last_write_checksum: sha1:2aa888218bcd59c7ae920ecbe26b938dbbb6b334 + pristine_git_object: 9aa0a49e36d5bd23b9cdaca5940414791b65f831 src/cribl_control_plane/models/inputmsk_input.py: id: 13f3a5c8a003 - last_write_checksum: sha1:bb9124a258ed8590145187977a18d98311807f22 - pristine_git_object: 5bc83222763e4d832438469ad6754429c1ba5576 + last_write_checksum: sha1:8d60ebaef578cf2ff5c68439eebc0c1055a7aee7 + pristine_git_object: c0bd37e8f83364c7eab4c8ec13e989dab3618ca5 src/cribl_control_plane/models/inputnetflow_input.py: id: 5e4cb9ff9920 last_write_checksum: sha1:45ce4faf4b76e27f7d20224bf497606844dc7a96 @@ -18988,16 +20236,20 @@ trackedFiles: pristine_git_object: 9feafdab4ef453871844cdea0af8dbef72db0b7a src/cribl_control_plane/models/inputopenai_input.py: id: 37fc53912818 - last_write_checksum: sha1:e2c7665dc6bd4029ddb76f5a83952762895d569d - pristine_git_object: 25092c294b745591effde010f889bdc061171300 + last_write_checksum: sha1:a33ecf6f34840137269253832bba9b066024899a + pristine_git_object: fe62b25853aae1c249327a89da66fac7860f57fd src/cribl_control_plane/models/inputopenaicompliancelogs_input.py: id: 523c96ec8fb0 last_write_checksum: sha1:e24f23cd5d38a4ac0e4c94fc338fe81adef35077 pristine_git_object: c40839d67df7eb9e7e56c24d0e2cf5e4155f03f7 src/cribl_control_plane/models/inputopentelemetry_input.py: id: ac9a785f02cc - last_write_checksum: sha1:93f938afb9e7b6cba6d0b0dc253ae5dec6cac876 - pristine_git_object: 9771e01c4d2bb260ceaf15272e32529409c430a7 + last_write_checksum: sha1:dcee9c8b034eff4aed65391c176b19f5637739f4 + pristine_git_object: f7a358c8294b674cc2629aac07c79befc3361cf1 + src/cribl_control_plane/models/inputpingidentitypingone_input.py: + id: 43b94f6625ef + last_write_checksum: sha1:7efd0d554abd874f2822cba5df18181e54a439e1 + pristine_git_object: e8a99906af8aad40b3b239c9d62d7b200c495f8b src/cribl_control_plane/models/inputprometheus_input.py: id: 6b2c7b2165a7 last_write_checksum: sha1:237ff50ffe960bd5b5ee9c8991a5c356a98ce6d0 @@ -19006,26 +20258,42 @@ trackedFiles: id: d908fea575c0 last_write_checksum: sha1:1024218cfeac5ac48b516c58735e8602c1223979 pristine_git_object: 14a26c76622eea5396da0c7f46b9deb18cf8756c + src/cribl_control_plane/models/inputproofpointpod_input.py: + id: c66d10090b41 + last_write_checksum: sha1:1e22182d57a0c07719c6667156f11066f2db15af + pristine_git_object: d72a9b186ad26c4dcce039c21f8a1ed7c08ad8b9 + src/cribl_control_plane/models/inputprovenancetypeoptional.py: + id: 9890ddd47f51 + last_write_checksum: sha1:122e092eb081a0404cd60d80e99f5b85d986c37a + pristine_git_object: bc465193cbe695f7b1c566d7fc559ecbb68a17ab src/cribl_control_plane/models/inputrawudp_input.py: id: 841e631fe324 - last_write_checksum: sha1:87656cb3e1d98ac9d45d69c0a4bb82888f6db5e3 - pristine_git_object: fb1bfd8701fec09fbdd60055f50cf9636547aed5 + last_write_checksum: sha1:eee36ee56925a67e15a67bfc150cb77774f58903 + pristine_git_object: 78e125837cc90cf426d005f32e7390be5b7d6b4d src/cribl_control_plane/models/inputresponse.py: id: 767730d04919 - last_write_checksum: sha1:a7174400f42fa00fee78d8809a6f1b41561be327 - pristine_git_object: 8845c60e6436b720494dca972910dcbae9664780 - src/cribl_control_plane/models/inputresponse_inputkubemetrics.py: - id: ba5206b00556 - last_write_checksum: sha1:8a1132ab23d2c782389b6fbe522055186f427afd - pristine_git_object: fbfbc44c96b98c800b96ee9f0c5b45bb14230bb8 + last_write_checksum: sha1:5bda5df48f02c23ffa9dfdbf5586c3b5cfae020c + pristine_git_object: 405c1e8868dbf015c04ee567dce10dca1c2d5de9 + src/cribl_control_plane/models/inputresponse_inputelastic_type.py: + id: c2499a59010b + last_write_checksum: sha1:86f77d49da2eaa2e9dae22f78e6f52d1be5bc01c + pristine_git_object: ce57248599a26e6087359224ebb399e4dd2a46a4 + src/cribl_control_plane/models/inputresponse_v3user.py: + id: c60af74a286e + last_write_checksum: sha1:c1c4a12f7cc3f2d5954d109cecc1bed707b93658 + pristine_git_object: c36f3bb815aa701d5261917c94a1879a4efe29d3 src/cribl_control_plane/models/inputs3_input.py: id: f30537f12b20 - last_write_checksum: sha1:309997e393a2983ffac10528671893da07d116ea - pristine_git_object: 3f207106f0fa6a434bf2e969b945ab8227d2c407 + last_write_checksum: sha1:e28e6d95b237ded365fbc7b7f991ffc4503899ec + pristine_git_object: afae7d843e5d04888ce1c01d16043570a8327e54 src/cribl_control_plane/models/inputs3inventory_input.py: id: d0e47c198788 last_write_checksum: sha1:ab5dcec612f48d000e7bc3744ef9b38797326599 pristine_git_object: 5fd569410403c70d71d12c405ec1737110489bba + src/cribl_control_plane/models/inputsailpointhec_input.py: + id: 027d6f2c3813 + last_write_checksum: sha1:c25a1e6435adbb3be6afbf60b08d336a688e2e29 + pristine_git_object: 9d350873c135c6708674521152115ca19e340e9a src/cribl_control_plane/models/inputsecuritylake_input.py: id: 722391f6e3ef last_write_checksum: sha1:321e7ad7f0cfd9cedaebbf1ccdc987f7df75fa60 @@ -19036,24 +20304,24 @@ trackedFiles: pristine_git_object: 9c9b815d9d86227b757ee32e43b2d4401551caf1 src/cribl_control_plane/models/inputsnmp_input.py: id: e636e09f3b4b - last_write_checksum: sha1:16f7bb130557e287bde1ba012fc582655aa49971 - pristine_git_object: 02be6bb5018ed4ea34c99cb58108c4891fccfb71 + last_write_checksum: sha1:0eea62a2a45d9fd27bd63ec5ceb245dd761c3e45 + pristine_git_object: 918b203222e0cd51240841e6811fb5e4a616108a src/cribl_control_plane/models/inputsplunk_input.py: id: 337f36087cad - last_write_checksum: sha1:843fe582e3d90ccf5eedd613081af9dd420ba996 - pristine_git_object: 65742a08aff54702d7ee0fce2652801b9ac62da5 + last_write_checksum: sha1:2cc8ea3045c687f68a63b50e54ddc6fca12703a4 + pristine_git_object: 319f1305d4ef8ce223938603753ef4b5399aa4ef src/cribl_control_plane/models/inputsplunkhec_input.py: id: abbfbb795039 - last_write_checksum: sha1:29617808d05f02750e0faa76e98179ed095bce61 - pristine_git_object: 88be41a9068ea6a0b6539f9969b12fa8d9916436 + last_write_checksum: sha1:b1c0e0f462fe9148f63a6d90e0af9c25aedba138 + pristine_git_object: 2c33593f2dc61f30712237bf46b054c62bd7b29a src/cribl_control_plane/models/inputsplunksearch_input.py: id: b5791b40b3eb last_write_checksum: sha1:71e3bda8ac3c3672f98fbe1d63dc781bd4484c32 pristine_git_object: a97a5e506eb68626c374da090b882cfb0034aa1b src/cribl_control_plane/models/inputsqs_input.py: id: f509d691b890 - last_write_checksum: sha1:848415fdcd1753e2c5e3fa244fc27b7094581298 - pristine_git_object: a45c18eb0d441b746210bfb6c29a21639de61b30 + last_write_checksum: sha1:04465e0feffcd4a162b95c56aaab6d8b77958a99 + pristine_git_object: 03c7be4e6a4db4cb2c97d41970e358f69b6a539b src/cribl_control_plane/models/inputstatus.py: id: f798d3417f8c last_write_checksum: sha1:6b02c9c9c80885a09f9475cc95c74188907e21d8 @@ -19064,8 +20332,8 @@ trackedFiles: pristine_git_object: ab058df76b162a731558fc66dbd0e614edfce98b src/cribl_control_plane/models/inputsyslog_input_union.py: id: 84122df38308 - last_write_checksum: sha1:973872344cb5d9555ddb9995551f03e4e810d865 - pristine_git_object: 8dcb1478711e99f485b1f488477ac7d0f4d6998d + last_write_checksum: sha1:447e2468a4e66f67410656c6227bd65aaf6d990d + pristine_git_object: a96546159247572693ab18b35d08fa0aed188701 src/cribl_control_plane/models/inputsystemmetrics_input.py: id: b338e7d5c2b5 last_write_checksum: sha1:a20d1f469546d1e074111346d95298d6d3108776 @@ -19076,12 +20344,20 @@ trackedFiles: pristine_git_object: 47e4288705c94e3201455a21f1b183d263fef09a src/cribl_control_plane/models/inputtcp_input.py: id: cb428eab3452 - last_write_checksum: sha1:6c159d17d8910a5cb19e9926767b117f8b8b135d - pristine_git_object: 7f82a971dc61755e9f245bbb2c8a4c47b70e6851 + last_write_checksum: sha1:5fcd0809463b328155ab362eef9f7a77457834c8 + pristine_git_object: 6286a01d5fd8327f941da4c3de539c83d3e4d558 src/cribl_control_plane/models/inputtcpjson_input.py: id: f18a7bae408b - last_write_checksum: sha1:a3831a0657f11269afe4189c96a8db965c231ae6 - pristine_git_object: 6a1eb42f27ca5d1060d5ef1340cd535fecc9b3e8 + last_write_checksum: sha1:b60a8414e0811961426bd4aae779d1afd8835a49 + pristine_git_object: 682748ac381f4de083f28dd6b299d896df616f4f + src/cribl_control_plane/models/inputtrellixhec_input.py: + id: 57304b6c08fe + last_write_checksum: sha1:2864ca92ac871789be9afe1dce1c8be4eabab841 + pristine_git_object: 44adeb952b88128ca1315eba67b4b1e41a0eca06 + src/cribl_control_plane/models/inputtrendmicrovisionone_input.py: + id: 051f86f4f83f + last_write_checksum: sha1:b10a0cea17f9da66a1dc23a49a19b21321365348 + pristine_git_object: a5018e3783d84d32a32b5d5f40084960c4016f56 src/cribl_control_plane/models/inputtyperunnablejobcollection.py: id: 0c068b08ae2f last_write_checksum: sha1:3fb8053a43d7e8a47f5b741e64a87fc19980cd8b @@ -19090,30 +20366,34 @@ trackedFiles: id: 2a9ae60cee61 last_write_checksum: sha1:6a3082255e72b682d47893263f93deaad168a209 pristine_git_object: 108df2cd777908b21b705ec9b3768ab477d45853 + src/cribl_control_plane/models/inputvectraaihec_input.py: + id: aa0af8d9cec2 + last_write_checksum: sha1:fa0826ce2e0d8c58391ae99dfaad6be2ed660f3d + pristine_git_object: baa203bfdb3ad5b61e251d96ef04976d912d840e src/cribl_control_plane/models/inputwef_input.py: id: 9ab97557b19a - last_write_checksum: sha1:33af7ae6a944193adee4b244ee59775d26bb8167 - pristine_git_object: 82fa4c91e0b6eeb8b2d01a04846a6fb34e6322a9 + last_write_checksum: sha1:7d2362fa944d03fb2c3b05c4cc4e1eeb1d72d3ab + pristine_git_object: ec1f2cdff38a7e8f217f15958af2b577c7243c1c src/cribl_control_plane/models/inputwindowsmetrics_input.py: id: 650b252da015 last_write_checksum: sha1:ec2cd81cd1080d4dbc6df4a0f531ba429c888a7c pristine_git_object: a301a94a1d67d99cd4c5a0032b52079419871702 src/cribl_control_plane/models/inputwineventlogs_input.py: id: b9b01a216032 - last_write_checksum: sha1:16a329a5e261cdd5a40965a59032dda6db65141f - pristine_git_object: 83ebb1028a7b2de88473632d0d1b99a69fc84287 + last_write_checksum: sha1:9bb01bd7979bccb40876f53e9ddd3d82dd601044 + pristine_git_object: 5c588fcdf6628bd7e0d5ece9c9f5ec51b6bc7ac9 src/cribl_control_plane/models/inputwiz_input.py: id: 6afb94fa60e0 last_write_checksum: sha1:6c10adc4a881ea9ee46416bd5a39870d198e75f5 pristine_git_object: e70ff3534a4f5a5a578d4503ed797f2b0ea51895 src/cribl_control_plane/models/inputwizwebhook_input.py: id: ee13ab6a9378 - last_write_checksum: sha1:fc4a70179ed71f9c964d2c3a624ec0153422f6f2 - pristine_git_object: 4fea5b8c4a863ac2086f796a1c889e10ddc6f2a4 + last_write_checksum: sha1:df56dd0fb2099e4b2f4da031d0e989d3ad5b9514 + pristine_git_object: 36f4c8d5aea44cd7e8140aec60034611506eea2d src/cribl_control_plane/models/inputzscalerhec_input.py: id: 26ad49916acc - last_write_checksum: sha1:aab5393e387af7d8c0c369081de4c277ae80af61 - pristine_git_object: 7d76e89382b1e01da683ce07f2ceb69b7d1eb748 + last_write_checksum: sha1:7533d03459061151cc093b5a4b39cc38d7c5c629 + pristine_git_object: 27594efa3cec6289283f6c6466f20fa476ae0ad7 src/cribl_control_plane/models/jobinfo.py: id: 5b0f0dc0bf44 last_write_checksum: sha1:7db95c95e26df0903254e19cae5abe776bc36e28 @@ -19148,24 +20428,16 @@ trackedFiles: pristine_git_object: f1a85ae1a2f4f5b196330616583627c2a6b812d1 src/cribl_control_plane/models/lakedatasetsearchconfig.py: id: 131b11361cf6 - last_write_checksum: sha1:f85282a3e100c190c70a00a29d135e25a53e81c4 - pristine_git_object: bb3816b66fb9a7fe7ca92a169884ac6e83aef841 + last_write_checksum: sha1:25215b59d2ad0e3ed36af6ca2dba5b2acd7f7fa3 + pristine_git_object: 829f65a0d1206cf2d8c35aab082a0a74b3d7e5e7 src/cribl_control_plane/models/lakehouseconnectiontype.py: id: cf5a974e7e9f last_write_checksum: sha1:3f0dc547ed94674c0a6a7a51311d1ad5dcd96ca3 pristine_git_object: 1adfef5c0924e2bb6028b5cbe5f66f7c5d9b4f11 - src/cribl_control_plane/models/listinputop.py: - id: 47d60ed569d7 - last_write_checksum: sha1:bee4a0e4f33dafc1645aa276f3567a1ab0908f2e - pristine_git_object: 0b275e9ac8720bd4ef74d59995fe0d3de2c0740f - src/cribl_control_plane/models/listoutputop.py: - id: 07539c4589a9 - last_write_checksum: sha1:10a5d589790c0920434385247b12175ae0b1bec1 - pristine_git_object: 14b933f4a1ff57988e719edb53a0d42bfdf9134f src/cribl_control_plane/models/logininfo.py: id: 939fb33c0092 - last_write_checksum: sha1:e1a5c9910fcb7885210fb71dedfad9a1df100ab3 - pristine_git_object: f7f56a81a7cb00dc6adc3b665bb5b6fe1bf1eeb7 + last_write_checksum: sha1:fe68b65d7fc2033af2dcf156608041d3cb4816fd + pristine_git_object: 9738188aa3a8393013d46e1120853d3ddaa0301c src/cribl_control_plane/models/loglabelconfoutputgooglecloudlogging.py: id: 506fd87b9659 last_write_checksum: sha1:bca6abb1a87d0cefeff380eb56e4e5febb99604b @@ -19226,6 +20498,10 @@ trackedFiles: id: 915fae1bdc9e last_write_checksum: sha1:7b9ce2d919904cbbe34b76f29db56ec372bb60f7 pristine_git_object: 2f0425c21b4c3fd7cee16b29cd856d9ace1f44aa + src/cribl_control_plane/models/metadataitem.py: + id: 347167e1e4d6 + last_write_checksum: sha1:0efccaab83e8de0841d6a4cd56775b5234888c4d + pristine_git_object: c8912b6ffe464545a003a8dd23fb734a9f1f6cc5 src/cribl_control_plane/models/methodoptions.py: id: e11001be3a6f last_write_checksum: sha1:8126ca53daed8ee2bf5ae992d326ebae0cd75f29 @@ -19260,8 +20536,8 @@ trackedFiles: pristine_git_object: a2aaefe04b26cba98d0bf7a41c014ae7bc8f706c src/cribl_control_plane/models/namefieldtype.py: id: 29ab1263ec37 - last_write_checksum: sha1:2183f2065cae22cad4416675108cd916560012de - pristine_git_object: 4eb441586843cd242597a454bbe6034618f6aac8 + last_write_checksum: sha1:7f19d240c900f692ab00af3315f8a3935db665a9 + pristine_git_object: ab0257526b0bbe084dd551f60d3a2a4ceec5eab5 src/cribl_control_plane/models/nestedfieldserializationoptions.py: id: 863deac83938 last_write_checksum: sha1:fc9bc2045040253c7746d3361a32caadd78a7cfe @@ -19298,10 +20574,26 @@ trackedFiles: id: 0dd58456d128 last_write_checksum: sha1:0ea1f6465a0c29073f464afef651d8f1d65061d5 pristine_git_object: 2bbb9253ac32122efb8fac8caf542b211aa3952c - src/cribl_control_plane/models/notification_union.py: - id: 6500f6ea5250 - last_write_checksum: sha1:9e605ee84a88addc505d6b240a368ff1c2b15bb2 - pristine_git_object: f7e9629a9a56a6c5c900df3dc3c4c13ac2e04ae7 + src/cribl_control_plane/models/notification.py: + id: 5664ed8dd471 + last_write_checksum: sha1:9e11bed09d152b71c39c0058d74bcf7f3d215570 + pristine_git_object: f5fbfc9b9be960855c220f726d04033fdd397aba + src/cribl_control_plane/models/notificationmode.py: + id: 49c5ec977eca + last_write_checksum: sha1:0c38a8fcf9947753d6b0a4c7f0af36148d7a999b + pristine_git_object: 3f6bd6fd8edb166aee9b4acb53cb984eea0e8531 + src/cribl_control_plane/models/notificationsmtptargetconfig.py: + id: 39a7d01f21fa + last_write_checksum: sha1:23dc136c4d2eff44b7e2b326838d29e33b14e947 + pristine_git_object: 3fc1552cfdd44ae88084e3e6f9b541f67c388b87 + src/cribl_control_plane/models/notificationtargetconfig.py: + id: b117cf39436f + last_write_checksum: sha1:c3d19c8059d759091340b51d12a42cc5af8842ef + pristine_git_object: 2497aeb06b1f4bef1f0324dfa04c5dd3f483f378 + src/cribl_control_plane/models/notificationtargetdetails.py: + id: 7ccc79ce9c3b + last_write_checksum: sha1:44a8397f471e7669b31dbab7f84632dcaea4e7b8 + pristine_git_object: 5ef61c0cf9824fbab3ee28ea80302c49f8dc8c09 src/cribl_control_plane/models/oauthheaderconfinputservicenowtable.py: id: df6f8f52d447 last_write_checksum: sha1:6564d9f9841648678cd1303676a5c63515bcaff0 @@ -19326,6 +20618,10 @@ trackedFiles: id: 9b6c303cda50 last_write_checksum: sha1:596b8be3e773e8e48ad5032ed16df0a69d9fe6ee pristine_git_object: cbd502442f00fdd12e2a1ccdcedb5fb8951b58e2 + src/cribl_control_plane/models/originoptionscriblsourceprovenance.py: + id: df02e85bd93e + last_write_checksum: sha1:e189a54951f64089400f627146f6e84c9cbb1899 + pristine_git_object: fb8ff3af0b195cdbab1478a1b3fed633a101eb8b src/cribl_control_plane/models/orphanfilerecoverytype.py: id: 0f0e38e92701 last_write_checksum: sha1:e1e38dc8db12959452e35f3f98f91f3aba47dda3 @@ -19344,8 +20640,8 @@ trackedFiles: pristine_git_object: 8eb12d7680df70473a890783dc1b07f0f0ff39af src/cribl_control_plane/models/output.py: id: f4d9666b7d9f - last_write_checksum: sha1:60a857ce38bc5592c906ded18b0cadb90adf54bd - pristine_git_object: ade2bb74237fc9eee30a41aca6bec136bd278a0e + last_write_checksum: sha1:476657fd194e57ba41c314183ca429d343846ab2 + pristine_git_object: d15627af80df78bc5f74c684df333dee71cbd0e1 src/cribl_control_plane/models/outputalibabaclouds3.py: id: 731fd1ec1a1e last_write_checksum: sha1:fe098a24cb04ece77b7b20f11a9450a24b3188b3 @@ -19404,20 +20700,20 @@ trackedFiles: pristine_git_object: 857e5f9a5b0547d95275df732db262ec5c202700 src/cribl_control_plane/models/outputcribllake.py: id: 88401324e633 - last_write_checksum: sha1:11e5af5fa8bfd53e015fffc6cb2b63da41d972bb - pristine_git_object: bf01471b417b05bcc06c8957288777e2cae5a380 + last_write_checksum: sha1:fb05f54b22219536b2e2d1f434eab4ffa356994d + pristine_git_object: 87b5346db6481c58f05c98ba34278f04cc10f1f7 src/cribl_control_plane/models/outputcriblsearchengine.py: id: 0f5362f5f409 - last_write_checksum: sha1:544ee3c488ae8e417e27619dd786f40e6951bf09 - pristine_git_object: 8328e3bfef87a85112d58a283bea82c50ea54d35 + last_write_checksum: sha1:4b92fcfe76ba71d58c097da9935e23c25725820d + pristine_git_object: b7f1175d549da9ea9a56aaae6423034d2e4ef6da src/cribl_control_plane/models/outputcribltcp.py: id: 9a2c64817df7 last_write_checksum: sha1:790ab563d61e801572ce888e1caa6efa416447a5 pristine_git_object: 2a6dfe70e43460e149f738a7e642d235135378c3 src/cribl_control_plane/models/outputcrowdstrikenextgensiem.py: id: a2494a240e4a - last_write_checksum: sha1:f2dd4baddb720ea3fecdafb95129cd2588f8dc1e - pristine_git_object: a8171c84a1c04aa7b166aebebaafb22f70c22c82 + last_write_checksum: sha1:d0457d6ed2cdf6bce2f20da3fce0013a37d78cce + pristine_git_object: e8f1bdf89efc9b79da08a0103dacb5d2bc960361 src/cribl_control_plane/models/outputcustomermetricsstorage.py: id: fa844bfbc77c last_write_checksum: sha1:1f30e953fb56c50a63fdeafc191d2c9cf2abadb3 @@ -19426,6 +20722,10 @@ trackedFiles: id: 4a8494d5d320 last_write_checksum: sha1:734b61195eb84a5c517200347ee93a64ced4b93f pristine_git_object: 9f410eca2fde753db19212e79217938a70935580 + src/cribl_control_plane/models/outputdatabrickszerobus.py: + id: 4b4c6f50c7c5 + last_write_checksum: sha1:dcef1c7c95da58dd4df472b366562fc5b59dca40 + pristine_git_object: 66aa547b55002b8695c7ce79195c4123565d7df6 src/cribl_control_plane/models/outputdatadog.py: id: abb9afed6881 last_write_checksum: sha1:39a18e395ac7037eb1c9374e536d082abf7a0928 @@ -19472,8 +20772,8 @@ trackedFiles: pristine_git_object: 02e8dc89cad4de7066db34534ba2967b6ce2396f src/cribl_control_plane/models/outputexabeam.py: id: 9b6db8800eed - last_write_checksum: sha1:89831143228b46f13753cb061d6ede339bead575 - pristine_git_object: 59312c5612b5d60c52b8d4d2b7d84bda0e58fdb8 + last_write_checksum: sha1:6fae42e58a44f3036536b8a3e61cac672efbdf91 + pristine_git_object: 2ec86090386832eca21fa985388f2378922cd810 src/cribl_control_plane/models/outputfilesystem.py: id: 745f091a33eb last_write_checksum: sha1:b97f74589f98f207e61fb1284a49971ae882b681 @@ -19516,8 +20816,8 @@ trackedFiles: pristine_git_object: 40a157b088e19cb09f36c2bce248b2be60b6e195 src/cribl_control_plane/models/outputhumiohec.py: id: 1c01655b0ac2 - last_write_checksum: sha1:f016c3f58692ea8d9b6eacd3727ecbbb2e658ef7 - pristine_git_object: 67f0e565c0a7bf36ca5cad6e8970623e0438db5c + last_write_checksum: sha1:71e1ad2bb14dd980b3ed0baf28cf83b43c168278 + pristine_git_object: a17e00e4030f1c2b87fed45b2184f5652842cc0e src/cribl_control_plane/models/outputibmclouds3.py: id: 6b76400c2c3f last_write_checksum: sha1:3452ead2fe24f5c148872e6375971182c4c7beff @@ -19584,24 +20884,24 @@ trackedFiles: pristine_git_object: a0a44ceb505fef5c83e6043f2b04272237dd2678 src/cribl_control_plane/models/outputresponse.py: id: 57d67aee671b - last_write_checksum: sha1:9d2cc256193999dfeb504b1f8407afe75280a371 - pristine_git_object: 165493996ce8dc3da66e21d285033ccce9460a72 - src/cribl_control_plane/models/outputresponse_outputdefault_type.py: - id: b7543802a869 - last_write_checksum: sha1:bbf44feec2cbfe04f24f9775433b070462ecd9a6 - pristine_git_object: 150800632e0c681a326887f51b93fd783ad84785 - src/cribl_control_plane/models/outputresponse_outputstatsdext_type.py: - id: cc726aa27699 - last_write_checksum: sha1:29ed7bdc2f3491c4f6238776ea3b47ee4199aed0 - pristine_git_object: a704bcd3f4168e748df43210f2952a41891281e1 + last_write_checksum: sha1:1b8aeea6698919848d65be4c5832d5759d137120 + pristine_git_object: f8f2546c3cb6259d00b9dabe9d6baf3733d7a808 + src/cribl_control_plane/models/outputresponse_outputsns_pqcontrols.py: + id: 18780f663853 + last_write_checksum: sha1:ed61454ae9862114238e41a0678805e57422d7d4 + pristine_git_object: 9f029f9473e5962c56c08e128c3a62dbb9f578c4 + src/cribl_control_plane/models/outputresponse_outputwebhook_format_2.py: + id: 11d90679ce79 + last_write_checksum: sha1:2db7a63fab3557e59cf500da9eb18d7fa43e94e5 + pristine_git_object: 7e3358f1c924eaaa54bd992db759d5b010013141 src/cribl_control_plane/models/outputring.py: id: 38852fbbc850 last_write_checksum: sha1:c2e60629c66be14938b39680d8cc5d5bc165d516 pristine_git_object: 62147533ee9d81c195d9a3c17aaf73169b3e748f src/cribl_control_plane/models/outputrouter.py: id: 18dbd05c4d41 - last_write_checksum: sha1:7f93dba1f46a82412b36d7f9befc766c426a4df0 - pristine_git_object: 2a665878fa2eb102bfbd55b5a79e66a91d348abb + last_write_checksum: sha1:db9d759f9fd9f49ed91a6d40ff2100fc9df69fe5 + pristine_git_object: af7bff1ea4587b48caf56cbe9b60b9c871f3174e src/cribl_control_plane/models/outputs3.py: id: 928b5c4d8c0f last_write_checksum: sha1:7f2f5215c81bdc47eb7a2e281002541ea59fd241 @@ -19620,20 +20920,20 @@ trackedFiles: pristine_git_object: 8b2d37e7b3cefa9c035616bdd7f2fdba8011fb0d src/cribl_control_plane/models/outputsentinel.py: id: 77df0de0dedb - last_write_checksum: sha1:604bc966dd709d91535b41a2b90a731ccec663c5 - pristine_git_object: 90e2bee2263a1e91aa953beb33c1259b264c19dd + last_write_checksum: sha1:2725fca4eb0c986c740bd34cb865985daf976cd3 + pristine_git_object: 7a49d618cb1def1f89cfcc7307707fc0c5beb1ca src/cribl_control_plane/models/outputsentineloneaisiem.py: id: b7fa883b72d0 - last_write_checksum: sha1:13669f6969db8955844b7ba7180d597606eccbf8 - pristine_git_object: bbe4ea5674b6023eca961b3b314f2da9da5ec22f + last_write_checksum: sha1:c8c3de86fef47508b95a49f31801b1c143666fb8 + pristine_git_object: 7bfb28b1ace6747f9196c569f9d8745e82025609 src/cribl_control_plane/models/outputservicenow.py: id: aec9a128d45c last_write_checksum: sha1:2abecb055730b757d0807797af316aefc8d0be3a pristine_git_object: 4d4792ea191b102019972bd10100d14fbe02ba57 src/cribl_control_plane/models/outputsignalfx.py: id: dff4acd82968 - last_write_checksum: sha1:8368ead7b87c2249a4e0b083562d291b214307d8 - pristine_git_object: c06790f0bf3aae01ef07092d7d8e84802b0d6e9b + last_write_checksum: sha1:78cab551a9031f6c590b55be066cda23ddb7abb2 + pristine_git_object: 69a82c8d639535aa6255d40e8d5a77808e5c75f3 src/cribl_control_plane/models/outputsnmp.py: id: 9559bffb693c last_write_checksum: sha1:4c82fb03afa2f75601c5892fe75f271564664b3c @@ -19648,16 +20948,16 @@ trackedFiles: pristine_git_object: b0c23dee0f426e5d2bb9176632fe46d76b1f6a5f src/cribl_control_plane/models/outputsplunk.py: id: 1a1157ebdbe2 - last_write_checksum: sha1:658b3f4dd7623dfce68faab042b107f59276f207 - pristine_git_object: 664026fb419ef49327635866bccc2e84ac74292d + last_write_checksum: sha1:96ec4fe3a2bdb348081bc048108ad049dd722a5e + pristine_git_object: 3161ec2f1209764d3e9234a88827dc10ad848abf src/cribl_control_plane/models/outputsplunkhec.py: id: c90f358b1e4f - last_write_checksum: sha1:447039782b63462669a479f0ca12239ad15f927a - pristine_git_object: 5ed9353a45b5a8e92d7cd6032ba12a62a6b97fcd + last_write_checksum: sha1:d5d52c63e8a99d225fd0aa14de1d9d5f7476c3d2 + pristine_git_object: 0a4692d3f51dc281a15d0a6df649967db6b46f6c src/cribl_control_plane/models/outputsplunklb.py: id: 612f573663e5 - last_write_checksum: sha1:c2e20862ca3756114be9b95a314d20403ec9462f - pristine_git_object: fa72dfd163bb5effc46b22a25847cd21612d7f11 + last_write_checksum: sha1:c34b5b6f1b5d454b58c899c57b6eca047492b69e + pristine_git_object: c388db8257bd0a2c8492e1307fc80b997c87b77c src/cribl_control_plane/models/outputsqs.py: id: c2a5a299ea30 last_write_checksum: sha1:9b20c93e5801cf77b7df9be95c2f5932eef940d1 @@ -19688,8 +20988,8 @@ trackedFiles: pristine_git_object: cb7de2bd41efe0501a5a44a89a9207a27a2f8ae2 src/cribl_control_plane/models/outputtcpjson.py: id: d66a4d365e68 - last_write_checksum: sha1:ee4c6a0d18c90f5e848e43da560141bf9541ce9a - pristine_git_object: 60545d0dc0cca80c380dc191532ccb4d6dbac053 + last_write_checksum: sha1:7291cfda3a7698eed426a4612452312a5e15a0a4 + pristine_git_object: 48f187e677588b1219732e795d865651d8629a07 src/cribl_control_plane/models/outputtestrequest.py: id: 81e1b2c93c61 last_write_checksum: sha1:c19fbd6e6adfbef769fc89ee3870b58e5a074b61 @@ -19698,18 +20998,22 @@ trackedFiles: id: ce6a3bfacf56 last_write_checksum: sha1:524fb67644f16b948512e486831ea6ad0a45b47a pristine_git_object: 5c19dd53957aaaf5f69693e7eeebf327a2baa870 + src/cribl_control_plane/models/outputtraversalotlp.py: + id: feed71505b8a + last_write_checksum: sha1:e1eb0bc207a41bd1eb07ed8c31546b9af3466023 + pristine_git_object: 5d01e76e02b7c568de23842d52d4eb524818723b src/cribl_control_plane/models/outputwavefront.py: id: 0898984eb08a - last_write_checksum: sha1:5eaca56ab57e38f7a2c6294ed9f45fcb45ab3e3f - pristine_git_object: be5289f66fec4fc86b80c2780785214fe1c70748 + last_write_checksum: sha1:75f140798cb814b474d506285d96ac262ac8a810 + pristine_git_object: 34189dae9f4fd043dab2ab5fe403918ed6bc3833 src/cribl_control_plane/models/outputwebhook_union.py: id: 478b65a93371 last_write_checksum: sha1:06c5f0ae2f4cf9c5a1bf0187d530a439152fddde pristine_git_object: f41351fd6b521628820c0c717ba8363fcd56c2eb src/cribl_control_plane/models/outputwizhec.py: id: f0a40a7a4458 - last_write_checksum: sha1:c5ca8e9139c97132a348392060ba15ba5b368034 - pristine_git_object: aefd5a7a3b00240f1d84717be2fbcd6a279526a5 + last_write_checksum: sha1:d856ec7312d7b72ab2f112f3a8e58b94e4c7afe5 + pristine_git_object: 38cd46899fa8f93d7601e12aa8383c6ce458d70b src/cribl_control_plane/models/outputxsiam.py: id: 6c1c39431130 last_write_checksum: sha1:8100cc6991c2458cdce6671e44b4b7b451a4ddaa @@ -19720,16 +21024,16 @@ trackedFiles: pristine_git_object: deef56e8853e8292231dc5691c190d81b57e64a1 src/cribl_control_plane/models/packinfo.py: id: 56a9348d2dd1 - last_write_checksum: sha1:dc349aeaa078a1d460209693efaecbd15984487d - pristine_git_object: 8d6d940a4e6751b3fa5fb942094975e390efc654 + last_write_checksum: sha1:b1246455f055a8912e7d629b67687c8248f341d8 + pristine_git_object: ab3fe00ed9fec820d3d1ffe242ef4e3acff2ed78 src/cribl_control_plane/models/packinstallinfo.py: id: 55493bee8e50 - last_write_checksum: sha1:aca14dd47fdfbc1c5d27869145cae85b64e9f522 - pristine_git_object: 04f8b6caf26f3ee1f9144b78fa2c527000a301b8 + last_write_checksum: sha1:3d44c29fef48db0e8aace96bc9ad0458d2d2f9fc + pristine_git_object: c438bc81aff1c34c10e45c637c91d89554195af9 src/cribl_control_plane/models/packrequestbody_union.py: id: e5e804cc4a6c - last_write_checksum: sha1:b3cb3ef460e9f7f9bc901dc43925f1e188fb1673 - pristine_git_object: c6b990037ec62469ec17bd10b94bbdd7b940df63 + last_write_checksum: sha1:25db8820260455182dc30c55e68189422e0dc759 + pristine_git_object: 7241d14764afd828eff63b408d4ca6bf12f2e6cf src/cribl_control_plane/models/packuninstallinfo.py: id: 1cb115a7bc49 last_write_checksum: sha1:a9a37070c4cfe7353ca82886b61f30e2bf88a9e6 @@ -19740,56 +21044,60 @@ trackedFiles: pristine_git_object: 1e6e54e627d0d64a60427478518e342c5e7bab0c src/cribl_control_plane/models/paginatedconfiggroup.py: id: 90b4e76a7815 - last_write_checksum: sha1:26d29373128e87b6db733c31a5e653c14e72502a - pristine_git_object: 381b0aefaa53d8fdb634c3a62b6d5d972dc6a74b + last_write_checksum: sha1:0393b2de31ab0b9346fde1f6387b49d363a545f2 + pristine_git_object: 45902a832f00dd42db05470093a7123598a8888c src/cribl_control_plane/models/paginatedcribllakedataset.py: id: bcf6ea3c932e - last_write_checksum: sha1:0e14d6ccc7a5c93ae9dd0bbd09984fa5d5390727 - pristine_git_object: 4a7448cd1a3716dfc1e7907c84ceba26543575a4 + last_write_checksum: sha1:53622b7df82b278c30d5d4acb67e48df357f499a + pristine_git_object: bdde2db1593e305e24ee607ec6c613ba44298e3e src/cribl_control_plane/models/paginateddistributedsummary.py: id: 623466ff0c26 - last_write_checksum: sha1:126dffff31a7e627432b0006b125b13638c29f86 - pristine_git_object: 4d1e65ae12ef791c30bc4bc4d77371a5faacb7a5 + last_write_checksum: sha1:2b9b3ddb9d851c6dce6fb375fbdf6c25c8aa863a + pristine_git_object: 695fdc79b8def80ac7e07d1d44fa7a3d3035a9ef src/cribl_control_plane/models/paginatedfunctionresponse.py: id: d234ff659214 - last_write_checksum: sha1:74709f47221f5ad5561adb3db7d736979e4eb4e1 - pristine_git_object: bb2369e0bd55e710372fee2d9ec2f5373912c370 + last_write_checksum: sha1:2fd8bfbad1df27b4d5780cafb5a8ff50a18e0a8f + pristine_git_object: 6b110aa84b2f05a0990e5cc1fa04a4ea8408246d src/cribl_control_plane/models/paginatedgitlogresult.py: id: ca67ccfe9b75 - last_write_checksum: sha1:ca83761283b68f32db966f491163279b7c9a2452 - pristine_git_object: 63b5898e61356d7965cf79fc05ba816200799d6c + last_write_checksum: sha1:221ab06308afaf6a799c5334e481d8983cef1e75 + pristine_git_object: b5314bcc7f866f063b5586682976d11d52a0a5ca src/cribl_control_plane/models/paginatedinputresponse.py: id: 987af2ae12cb - last_write_checksum: sha1:6fc3353ca7ac023864883491ad5cf4cbca4eee5e - pristine_git_object: 50ac3a06fa6f502c092dc2d1c70f137fb041755d + last_write_checksum: sha1:48cb982a637dc34f23c55fbebb1a666877f9d28b + pristine_git_object: d223436fb8029285344b9d4eb176eab8f26aef22 src/cribl_control_plane/models/paginatedinputstatus.py: id: b73167285d48 - last_write_checksum: sha1:8d40e6f0aa3d3ea1f976914db2c411fe9bceed92 - pristine_git_object: 17588388531a65fcb4adf1ae13c32f6a25a17915 + last_write_checksum: sha1:fb8b7a3ef4fe28e0f18e03f378534ddd0e3fe9d5 + pristine_git_object: b0dc3ceaa81ee56d0bfb0287686727497374d0b0 src/cribl_control_plane/models/paginatedmasterworkerentry.py: id: 11e7a01e916b - last_write_checksum: sha1:bf3f833ee6ad21cdef828e3e3e76d57bd0d3bbcc - pristine_git_object: 3327fb5aec9cea13f039d859a7e523f56cf33a6f + last_write_checksum: sha1:22f858f747a05f36621868c0ad33221590dafa54 + pristine_git_object: 0aa5287027dad5c6d5b60a8e34693628e8dec437 src/cribl_control_plane/models/paginatedoutputresponse.py: id: 7842997be02a - last_write_checksum: sha1:c295d7db581aff481d7c70858bccf9ab91043f55 - pristine_git_object: 881433f50479a5eed835ec800871817b31c7191b + last_write_checksum: sha1:ef44b3d99b5532b3ebb2c98af44834e9692f9502 + pristine_git_object: 004befdde9b356bf123b084cee8904ab4e19c0b4 src/cribl_control_plane/models/paginatedoutputstatus.py: id: 07b6114b3832 - last_write_checksum: sha1:284ec5348e029d6c1cdd67b110a075d8fd95fc63 - pristine_git_object: 873c9ead364d2ccb873774d13f2063e1392341cb + last_write_checksum: sha1:634dfec3e8505a63eff238698ac067fb4bac70be + pristine_git_object: b5464491c9fdc9aa3ea9bec3c6c9eb201a7456fc src/cribl_control_plane/models/paginatedpackinfo.py: id: cfa3bbb7a2a2 - last_write_checksum: sha1:a08495508a861bb886fc8853171e7e071d06b7f7 - pristine_git_object: 5743883115f5ca2c563dce5b05c1d2c0cafe0e87 + last_write_checksum: sha1:9fe32da50f4963983289493eda594ce02cedb7bf + pristine_git_object: 3d5cf25237dcb58d8195d02ce66395c402686401 src/cribl_control_plane/models/paginatedpipeline.py: id: cbeac884de21 - last_write_checksum: sha1:f945c6ef7a287de231d89d31c525421680ccc082 - pristine_git_object: 0f5d72ea358a206bf939faf67b31aff0a78767f1 + last_write_checksum: sha1:39fd01f9b74ee985cb983c2b30e7206b4219fe25 + pristine_git_object: 33313dac076fcae086a52a3be940870c802fb701 + src/cribl_control_plane/models/paginatedroutes.py: + id: 6d535187b2b6 + last_write_checksum: sha1:906a317e1098c17eb3135112b8e43bd6104add51 + pristine_git_object: 413950bf6c3724b9cba38552613ebe66b7a03074 src/cribl_control_plane/models/paginatedsavedjobresponse.py: id: 0572f13e2cde - last_write_checksum: sha1:cde605216e26c04f8d2ae07b3eed8cd0f8a5d917 - pristine_git_object: c29e0cb8a4626e58a53b2d010b03b281d61eb7b9 + last_write_checksum: sha1:350107c520b662af6c6c49941c321d793e11219d + pristine_git_object: b8ab5435cfa202e27fc69d3ee3f3f12a463d80f7 src/cribl_control_plane/models/paginationoptionsrestdiscoverydiscovertypehttppagination.py: id: 7144e446a176 last_write_checksum: sha1:b7a4c63e7170ef0cbc7045c91d0b847241778b2a @@ -19816,8 +21124,8 @@ trackedFiles: pristine_git_object: 142a92e3f3d0c153e0f5b57af329bbebe0fd0200 src/cribl_control_plane/models/pipeline.py: id: e7fc0082d01c - last_write_checksum: sha1:b5e01fea8f747997040f9d348035966a2270d27c - pristine_git_object: 44146355061bc3a8eca71bcdb32c332ae3b5ca66 + last_write_checksum: sha1:e9dfadaa8ed212b2cca63e1d4ab1fe6245329111 + pristine_git_object: 52bc4743342992e6c15c5f1f7c42d3bcb82b6401 src/cribl_control_plane/models/pipelinefunctionaggregatemetrics.py: id: d01c836897e3 last_write_checksum: sha1:09e2fd375acbb1a1a4e6456aaec0f325dcde634b @@ -19852,12 +21160,16 @@ trackedFiles: pristine_git_object: 096f52f9c15ccc3ba36725ae73a12ef0be5ce48d src/cribl_control_plane/models/pipelinefunctionconf.py: id: ad399d52be46 - last_write_checksum: sha1:122cd67b0ffd7350279f5a1cd83009b65d77a76e - pristine_git_object: 3d7f7cb896d6b5bea76e52cd153770ca80463e80 + last_write_checksum: sha1:8ea4a8c19897c408d53500059aac591b9ccd8247 + pristine_git_object: 507b796d6c41d6c6aa5886ce5ac44c6cbe8129f6 src/cribl_control_plane/models/pipelinefunctionconf_input.py: id: ec8986c64e7a - last_write_checksum: sha1:0c3107a54b713babee091acdfc884369b9d55e7e - pristine_git_object: 24c9d7f0f1c8f6b15cf9afb761960eaf92fd66b8 + last_write_checksum: sha1:15f1f47a0cf0ccc36530efd19a7e13724a446945 + pristine_git_object: 682b6d588cc2833b53d07f9c86d2cd2c65fa1b59 + src/cribl_control_plane/models/pipelinefunctiondetectionrules.py: + id: 75d52a7f810d + last_write_checksum: sha1:38b782d799b6641373a49b472f2365433a206126 + pristine_git_object: 291e7306213d7eb129dffa38b80314f94aa3b97e src/cribl_control_plane/models/pipelinefunctiondistinct.py: id: 9fd8d6382c8c last_write_checksum: sha1:ade7012b9f80c46a31eb25a74a31ff8b89effe7b @@ -19930,6 +21242,10 @@ trackedFiles: id: d79cb7f88104 last_write_checksum: sha1:7abdb22676018a1234b43e48c9c5a4eb322a70a0 pristine_git_object: 5789f58384a170027adc66cdd9b527609a088dfd + src/cribl_control_plane/models/pipelinefunctionlakehouseenginemetricsnormalizer.py: + id: c712d98cd745 + last_write_checksum: sha1:8e3b9bdbea277412874534b4c72dd70777e12a8e + pristine_git_object: 70fc134adf79a621b8c98ebc366dd2ff21ba2668 src/cribl_control_plane/models/pipelinefunctionlimit.py: id: f2ad728f585e last_write_checksum: sha1:eb5a5baa6ebacbb07858ee90aa91b05f240ad388 @@ -19964,8 +21280,12 @@ trackedFiles: pristine_git_object: 532999607cb710c6833c7467318073e0effbe701 src/cribl_control_plane/models/pipelinefunctionmetricsexport.py: id: a079bf4eab6a - last_write_checksum: sha1:d1af0fe3ffe37e07ec2c726fc555956419497e0b - pristine_git_object: e59f532d210fb71f9940a6407b6c2a5b3344d232 + last_write_checksum: sha1:df852c06aebd6f24cf54befde03d1b7767b64e69 + pristine_git_object: f730072c5a5394a8cc82b3171a1ab76af67ba3b8 + src/cribl_control_plane/models/pipelinefunctionmetricstimerangegate.py: + id: 75a5988f56f2 + last_write_checksum: sha1:ffc9f6d60c31855b572c5654fa503e0478428c1a + pristine_git_object: 1f95b67286bd9f01174507672919c7f48d7088c6 src/cribl_control_plane/models/pipelinefunctionmvexpand.py: id: 822e7c9897bd last_write_checksum: sha1:913f3ed7b734a5be02a7502cbde36fd7e63fc409 @@ -20052,8 +21372,8 @@ trackedFiles: pristine_git_object: a469adee9cd1977d83286b8f1d8936ec6ee11b0b src/cribl_control_plane/models/pipelinefunctionserde.py: id: dfec9a4e2e48 - last_write_checksum: sha1:c9e7a486f5195fe1ea703c448b80731ea9f0ea71 - pristine_git_object: 496338ca5a00f849436f6a9a26202ffac3158f94 + last_write_checksum: sha1:9900b0180035ba428789e406cf8eb1a7f3c3ef31 + pristine_git_object: 723b778000c4247899cf8465b38c3336e789976e src/cribl_control_plane/models/pipelinefunctionserialize.py: id: 2a32d73034c2 last_write_checksum: sha1:0119116d111ffcf4401e7ee343a312bf34975d37 @@ -20104,8 +21424,8 @@ trackedFiles: pristine_git_object: b474e8652588ae31e85dd77759cd849ee6186f1f src/cribl_control_plane/models/pqtype.py: id: 20c891c56168 - last_write_checksum: sha1:264f273193108b2a55ecdbdcaefc3cef2b40de7e - pristine_git_object: 6b16b64474cf5b8e7a5cf6e0ccca1cf4494b5dd2 + last_write_checksum: sha1:0f8e781b81bdde648bdd822f006c4a747f57a33d + pristine_git_object: a8cf68154e9a1a0eec3cf3c99643ecefd4088abe src/cribl_control_plane/models/preprocesstype.py: id: 81b715137f24 last_write_checksum: sha1:68be5cda0bc5ea9ec2485b0457b64108b95911e8 @@ -20148,8 +21468,8 @@ trackedFiles: pristine_git_object: 6e13485828b38df1338d6b3daaae0b5331948fcf src/cribl_control_plane/models/rbacresource.py: id: 2b1c2998a8e5 - last_write_checksum: sha1:1fdb1c4f853bea1ed8de2b24a56d28e7f2f283b7 - pristine_git_object: 1f1efe17cfcafcb65ecfc7cb8a79eb87cd8f16d5 + last_write_checksum: sha1:423509f093ff9444f51d4be8b127dfc29c57ea90 + pristine_git_object: 1a6de0b861ecf09e41a35f5c20453ff94e8693e0 src/cribl_control_plane/models/recorddataformatoptions.py: id: 5ee42db3bd04 last_write_checksum: sha1:a3b8b7f2a50069d2210161cf9e70bf0c6a2d1198 @@ -20244,12 +21564,12 @@ trackedFiles: pristine_git_object: 473da647de2fc950bb817372cc3844ab88cf286c src/cribl_control_plane/models/routeconf.py: id: 99f8023759b2 - last_write_checksum: sha1:77cba9ea036c92d31eb746b12d661d35a91c924d - pristine_git_object: eb401ee4b32f63b10d82b7f6c112f64397a35340 + last_write_checksum: sha1:ca32c5942b1f22d35ae81e42e8913b9652fe6d35 + pristine_git_object: 78715859eca9388c9a4a97433155342a50ffc466 src/cribl_control_plane/models/routeconfinput.py: id: ae86c6b69a58 - last_write_checksum: sha1:5e1b2bfb41139e5460139b54a7fc5703b0387666 - pristine_git_object: bade53beb7c6c9bc5c0b3e72effda08fd320dc10 + last_write_checksum: sha1:5c8305b8319dd29b5a93b90c1c2cb982fe563984 + pristine_git_object: e00e1be2a5d18f964baf47bf3c0850e347dfc0e1 src/cribl_control_plane/models/routes.py: id: 3dda91ee470c last_write_checksum: sha1:92e61b17bf73c4869be4ba45b6b138887fb5327b @@ -20268,24 +21588,24 @@ trackedFiles: pristine_git_object: d8fe401a75c1bee9d57fdae67013063bc3933c24 src/cribl_control_plane/models/runnablejobcollection.py: id: e13f247d077d - last_write_checksum: sha1:a7eaeb5c2693eebe27840d90a1b58841a167e2dc - pristine_git_object: ee7bbf24fd277db9d1273aec909e138aea7481e3 + last_write_checksum: sha1:5f395b7b94b663f16f1be373f778b218668df303 + pristine_git_object: 1d5f48ad21496507166f1e0628c6ae2560cdf04f src/cribl_control_plane/models/runnablejobexecutor.py: id: 49e90f6ba83d - last_write_checksum: sha1:786d8a9b1fa1ac3c8b84acd9b13e574e7e6e29fa - pristine_git_object: f1d97ace6c2acb1e95aa3fda4196ccd11a0b38ac + last_write_checksum: sha1:0c65726b286eb14bfde4647dbb579b29b377248e + pristine_git_object: f01e73ad6a3b25f0e513b1b82947b74b57458667 src/cribl_control_plane/models/runnablejobscheduledsearch.py: id: 035785737aee last_write_checksum: sha1:fba43d9b46800376ea6d511708861e8a4b632dac pristine_git_object: 33d136dfcdeae1c0b3f3d8acee955827a7fbd06c src/cribl_control_plane/models/runsettingstyperunnablejobcollectionschedule.py: id: d69e51fa951c - last_write_checksum: sha1:14faa09b6224faae37dc347b8e88d776b344ff71 - pristine_git_object: 118fd230e07b99119e1d0c8b5ddb312c9b557517 + last_write_checksum: sha1:b808a530394c25a90fe63aa2f89379a293af0fa0 + pristine_git_object: db54ce89bcbcf3ae015610e812a61b7ff4fffbdd src/cribl_control_plane/models/runsettingstypesavedjobresponsecollectionschedule.py: id: cb93de9580c1 - last_write_checksum: sha1:27106e45405e632c2ffe3bd92b253579f6fd4a75 - pristine_git_object: db3424d2baad6bb5a4ff33ad023c436756a9eb5e + last_write_checksum: sha1:a204043d92237652a7c5b3839cf51c521909a7da + pristine_git_object: cd8b875980f33fccaa61b9add9d25268b430b808 src/cribl_control_plane/models/s3collectorconf.py: id: d28817a2832b last_write_checksum: sha1:c962eb570543d496d776d545adf31ba448ba4ab3 @@ -20316,8 +21636,8 @@ trackedFiles: pristine_git_object: d53d53769187086d368338f1359c483009760ae0 src/cribl_control_plane/models/savedjobresponse.py: id: 83a9fbbe1f6f - last_write_checksum: sha1:2fea0eec79fecaff464e43638dafaae107b221b4 - pristine_git_object: e767e842e75de4ca9cab4d498c682e45e48061bc + last_write_checksum: sha1:980f517d2db3d27380a8cbd459e14e655b9f9daa + pristine_git_object: 30cab1e9a634f8c153b9e8c6de8fcadb9241d152 src/cribl_control_plane/models/savedjobscheduledsearch.py: id: 7dcfacfd4540 last_write_checksum: sha1:32884afedfb60babdf50ad0446b7fe83e9ade9f8 @@ -20342,6 +21662,10 @@ trackedFiles: id: 955ce8e30723 last_write_checksum: sha1:37293a92253eeed3e3d6106a67657a2ea5d37081 pristine_git_object: 325dfda927cd0639d3eba1c240a9b4ad40f28103 + src/cribl_control_plane/models/searchexecutionconfig.py: + id: c68d335b245b + last_write_checksum: sha1:e96da0fcf8762851ebe5a8a4dfd7c7da5779394d + pristine_git_object: 9f704f8649f4627f2cdcb87e295c9ab470daf23c src/cribl_control_plane/models/searchfilterconfinputprometheus.py: id: 219ddb27dd20 last_write_checksum: sha1:41056834ed7a8b92895a8434b7f82f983f978ceb @@ -20392,8 +21716,8 @@ trackedFiles: pristine_git_object: 99f333647bd9a699af26ed053986af949e245bef src/cribl_control_plane/models/ssltypesystemsettingsconfapi.py: id: 7cb4b7040f29 - last_write_checksum: sha1:443119069bc72c811453af18f7192c77f98b9d97 - pristine_git_object: df804aca440eb41a06ff6a7e7c4ff364b50ebbec + last_write_checksum: sha1:f07ca7403c00ec6e0b954d874a46a5d55c07896f + pristine_git_object: 1bf02595c6f9178666bd94f625da57ed1ebec7d0 src/cribl_control_plane/models/statuserror.py: id: ba0fc3f8601b last_write_checksum: sha1:1b6205e2537d45d75630aa9a24cc150878c96a4a @@ -20436,12 +21760,12 @@ trackedFiles: pristine_git_object: b3911098ad7e8a0726c3ffde57479a4949047cf0 src/cribl_control_plane/models/systemsettingsconfresponse.py: id: ca46fa03872e - last_write_checksum: sha1:f8d45f35c7d161a7a9e1d9dce8cad83a9778ed7c - pristine_git_object: 878f7718104acc7ff878a2464e01de23352e40ac + last_write_checksum: sha1:d84876222e4639b42d49660808eb3c1cb6898619 + pristine_git_object: 6b0d246511961630773b1c51184069294850635e src/cribl_control_plane/models/systemsettingsconfupdate.py: id: fde6f02e446a - last_write_checksum: sha1:ea06bf282163c47d28f795d7a3199ebe3167b439 - pristine_git_object: 223b7339b9fbfbe61d65f9a2e3f4d0a7183b33b7 + last_write_checksum: sha1:94b3e6f2ffeefa81f0c6a4f1aa6233fc16f3dcea + pristine_git_object: 20c51e0465c3eb3613d9d2c57cedcc23979162ed src/cribl_control_plane/models/systemtypesystemsettingsconf.py: id: 2a279644220d last_write_checksum: sha1:8d060059092c56a1f56c52f586a6f3cad1b6058a @@ -20468,12 +21792,12 @@ trackedFiles: pristine_git_object: 5703d15235f17d22fdba5300a95cfddc2a4359ce src/cribl_control_plane/models/teamaccesscontrollist.py: id: 0438d646b569 - last_write_checksum: sha1:8b396a5f5d0557043dd26863a3993dd1448187b8 - pristine_git_object: 38e2579ef9f7c43581a0eeeaab6efb6c1b977321 - src/cribl_control_plane/models/templatetargetpairconffunctionconfschemanotificationpolicies.py: - id: e2326ec741ff - last_write_checksum: sha1:d50b52cf200a8d8f27e0fc440b31847003c6bbfd - pristine_git_object: 66e568e07953a2cd1d878a70a2991089ed066d8b + last_write_checksum: sha1:67f38282a1c526f8916713ed3e9c2a704f6b6547 + pristine_git_object: 8b948b39529d5aa6fc89aa72123edbffcbc35ff6 + src/cribl_control_plane/models/templatefamilyoptionscriblsourceprovenance.py: + id: ae5ba1632216 + last_write_checksum: sha1:9800d72b5e4099bacc93d62742fe494afbf3e55d + pristine_git_object: 1eca6019cefa9760380954a65eaeb0bd156154f7 src/cribl_control_plane/models/timeoutretrysettingstype.py: id: 89ece5190087 last_write_checksum: sha1:1cc6a1f7dc4546e561964fa91030e41793892201 @@ -20486,10 +21810,6 @@ trackedFiles: id: f9618e83bc1f last_write_checksum: sha1:cab669c2452f9ac63c8b4be888d514c607eb1311 pristine_git_object: 628506b9ad9e558e48b7de6269b25baca146c5c5 - src/cribl_control_plane/models/timewarningtyperunnablejobcollectionschedulerun.py: - id: a92611cf5f45 - last_write_checksum: sha1:3f63c8639bededea0d25bd908d10bcc9ead0b6ef - pristine_git_object: 89e2a9542ad3ea5c28de129e12c4ef0218fdcc82 src/cribl_control_plane/models/tlsclientparams.py: id: 80f1cd8343d0 last_write_checksum: sha1:d343cf589184fdc74722feecfd3899a7f8f8b45f @@ -20524,8 +21844,8 @@ trackedFiles: pristine_git_object: e3beaec8728c682afab80ddbecbe2209a653eae7 src/cribl_control_plane/models/tlssettingsserversidetype.py: id: 812bd0e9776f - last_write_checksum: sha1:d6f309487eaee7746c1b75f42e1e2780e52bf403 - pristine_git_object: fb47e79ab0b94d6110b095d659fb4241a004b095 + last_write_checksum: sha1:c2e402c87275aa22432813559171f5fbe7be7e39 + pristine_git_object: 6b7ded935d28f52abb9f53bb8d378e1a8896f0fc src/cribl_control_plane/models/typeoptions.py: id: 57c40538e449 last_write_checksum: sha1:eb47b737ee9ac705cff4b1a19c74e91adbedd8e5 @@ -20640,8 +21960,8 @@ trackedFiles: pristine_git_object: 5ea9d59b842c8aba86da66ea6a2fc0f71981d95e src/cribl_control_plane/models/updatepacksop.py: id: 4249b1bcad31 - last_write_checksum: sha1:70cf2e68176508e4b29b14105d5a2a195fb01158 - pristine_git_object: e4a2ca5293150d2ea74088b0e83fc98ff298baee + last_write_checksum: sha1:4b5a3ef0b704000df67049cc6520edde498650fa + pristine_git_object: 8f13a31099277bac151b9136e235742771ba445b src/cribl_control_plane/models/updatepipelinesbyidop.py: id: 9f10e2cff08f last_write_checksum: sha1:ba8f074e3bc8f142a158fde32c7e20a62a8fc5ec @@ -20700,80 +22020,80 @@ trackedFiles: pristine_git_object: 89956de6d2aa320c6be6890703becda1f0b7600d src/cribl_control_plane/models/useraccesscontrollist.py: id: e3bb2811fb3b - last_write_checksum: sha1:56d7b0bf1e2c52ec44f3702762c15f70d4cf7659 - pristine_git_object: 81d6dd326e9ca4e65cf61fc28f570836c943d727 + last_write_checksum: sha1:93d2cded585b7079d257e219386906ccf16997a2 + pristine_git_object: 0b2d4fb5deb9d5aa0ead7004c343e5fdafef7a6f src/cribl_control_plane/models/workerpqstatus.py: id: "506122301202" - last_write_checksum: sha1:63cadf89c8457c431ed762b50d1e81c707b86baf - pristine_git_object: b0519d95e6a11d30d999b9173eccf9d71eb88b60 + last_write_checksum: sha1:f9cf0023a572d136aaac65b14322de93bc15d574 + pristine_git_object: 5982126f86d38ffb69c7a79e6253e721852ea3da src/cribl_control_plane/models/workerstypesystemsettingsconf.py: id: 3763852e9a22 last_write_checksum: sha1:3cb9b7925468684a8a9bbf32084d1168bb90ebba pristine_git_object: f75525660641692c6a5e3e2a5adab6871ccc096a src/cribl_control_plane/nodes.py: id: 75dce3f48fe0 - last_write_checksum: sha1:f6d7728aad775807ba5e49cb4d1169f2f848bec4 - pristine_git_object: fc374a6ee9f5ddd1f7f4bc170accd18e1927c619 + last_write_checksum: sha1:42f4e90315148c7d4d32c274226e56ee562ec1a8 + pristine_git_object: 891a12026fe1ed64598778b236b307758bb09821 src/cribl_control_plane/packs.py: id: c77b21eb4262 - last_write_checksum: sha1:10643f4233cbdff9dab71e28f00cb381bae3ee52 - pristine_git_object: 56ede74a24a1346ade4db133d7a6993d73f2b16b + last_write_checksum: sha1:febf44c2ba6dd9066a41b11b99ffaec3df9941c3 + pristine_git_object: d26f4bbddf460c9a1bbf7e1546c92b4c6d2f9135 src/cribl_control_plane/packs_destinations.py: id: c450853c5ba6 - last_write_checksum: sha1:5bc6f13a0dd751c60dc6388c2b3bcf966b201b2b - pristine_git_object: a86de1757b9874d76858a07fde9f41ce419c1afe + last_write_checksum: sha1:3bb810aedd00b38a90c9ddf751f66fae04ad16b3 + pristine_git_object: 87d86cfd96c84c71fb004f3cb8d200e4f370b56b src/cribl_control_plane/packs_destinations_pq.py: id: f732f776c1e8 - last_write_checksum: sha1:af68ddada1327da051bb0e79f6665a38503f974a - pristine_git_object: 4b68149e35acb709fa4393574988c612a224b77e + last_write_checksum: sha1:c2be6d9a2036fbcafef798b8bd2a49b362ff9a35 + pristine_git_object: 4d877f46dcc6b2e4e510053d1c3f1d517622a28e src/cribl_control_plane/packs_destinations_statuses.py: id: cd43b6b72fd5 - last_write_checksum: sha1:015a5ec2f36167ff83f2155fc4cea115b9b9184d - pristine_git_object: 4f719c4bd543abee128891338996661651c3f078 + last_write_checksum: sha1:f2c8ec6b928f7ccd399e9b68a362337fea744641 + pristine_git_object: 46fdffd7b39c842843c4242e6d9724d7dc8f4789 src/cribl_control_plane/packs_hectokens.py: id: 9cf63557bac9 - last_write_checksum: sha1:902eecb54b3b0101731687b494e886a68ebc7013 - pristine_git_object: 6318bd0a02095c74ba5885cde548be46147e7080 + last_write_checksum: sha1:20d6472cb3f7ed8fba7734b9ff11ee2f7a8e4fb0 + pristine_git_object: 1537de09704de65b35da92efc89e7405357506d6 src/cribl_control_plane/packs_pipelines.py: id: 674c9511ec91 - last_write_checksum: sha1:ce026172dcc1666e51eac362e819485acdffa3ec - pristine_git_object: 80546fc61ad7906bd2c982d4b6c92a227a0e1f9f + last_write_checksum: sha1:47daa4b363d50c20a256caf4ed68c618ef024a56 + pristine_git_object: ff208594109fc6f2b3b10b3e3635c497d5b99acc src/cribl_control_plane/packs_routes.py: id: 6f322a6e1e21 - last_write_checksum: sha1:89bcefe70b2e69e53f8a3d35ad01ff458e481e97 - pristine_git_object: 8b1570092af9d73a7930cf8643e91993d962159d + last_write_checksum: sha1:8c88d16d7ee9abc323b4365f1d7c7507b42ed002 + pristine_git_object: 367d7dcfe6f0dc4beea367762a440edb33af9e2c src/cribl_control_plane/packs_samples.py: id: 5d0ef82251bf - last_write_checksum: sha1:77bdf26c299ce4f049de6571771ca23208636b21 - pristine_git_object: 12e75aac2f4f0af371409ab5146e672b3a545ea5 + last_write_checksum: sha1:76ba02a5ffcb7ae462db31209ba2107560b19070 + pristine_git_object: c87b5cffad3b018d0a955e5f06559d31283f21f5 src/cribl_control_plane/packs_sources.py: id: 501249caef46 - last_write_checksum: sha1:8a3da5b9ce0b2d887ac749dc96c071837e92786c - pristine_git_object: 1d54562dfa644ea077706c8b3e709e5eecbb4f8d + last_write_checksum: sha1:76dccadcf17c29dad18b37ee0449761ff6b49ad0 + pristine_git_object: fb34b5cd25c1419299ae1dd97a245678c8d09c59 src/cribl_control_plane/packs_sources_pq.py: id: 4bee3b051119 - last_write_checksum: sha1:c51e6ba7dfa568bdd8e77fb117c99097ece1dacd - pristine_git_object: bd12910d49d4f135134e730cd73bc9dbb5b8dc5a + last_write_checksum: sha1:2a13a762578a267e483320c26dae7e5f41fd2f93 + pristine_git_object: 23d0336467d2ab52011bd1fb47256f45fbbf3145 src/cribl_control_plane/packs_sources_statuses.py: id: 8af1e98f4cb6 - last_write_checksum: sha1:b2679155c2532abaf36a8a961e62e5b424060580 - pristine_git_object: 62e329214c55615ec120855c2a434d6d2cc98e2c + last_write_checksum: sha1:10dc8e30abbe2bfac59e7524a7a27d606ca8812b + pristine_git_object: b167120bacc2bbae14e5876c2073bf58d1df6971 src/cribl_control_plane/pipelines.py: id: dc1a703eab78 - last_write_checksum: sha1:c8da5f7bf96e62c7a05fad1f7886704f2b542cfe - pristine_git_object: 08a20b2e9dcaf8a6f8f6ab25c15d3912d1ae0f5a + last_write_checksum: sha1:ba1d7a199c8ae8147bb87292908853bfa98f08dd + pristine_git_object: 0d407a7604b1062650d51ec304233c4f61d6745d src/cribl_control_plane/py.typed: id: d1e7cfa63a0b last_write_checksum: sha1:8efc425ffe830805ffcc0f3055871bdcdc542c60 pristine_git_object: 3e38f1a929f7d6b1d6de74604aa87e3d8f010544 src/cribl_control_plane/routes_sdk.py: id: d47e5614f00e - last_write_checksum: sha1:8bd78bcb3243e013bbec8e7fb1b58d3021246465 - pristine_git_object: 78f9b61bd9e2767554e1ae5a5f3fccd99c72672a + last_write_checksum: sha1:b122f8bb62973ba42337970baaa4b76ac13e4ad6 + pristine_git_object: ce02b214d396b2d8c73836abac5091e1e42515d1 src/cribl_control_plane/samples.py: id: 18147abe7c06 - last_write_checksum: sha1:17acf0b64afd8785c4a07cb5280e322ab6ed44f9 - pristine_git_object: ee781c26a0134f8aa5d978303a9b9ab3aab8f32e + last_write_checksum: sha1:b58fb02fe541a7b7ed21ea763c0600e261aa4433 + pristine_git_object: f7cbc7ac7ed7ae764dad32af02852554493cf155 src/cribl_control_plane/sdk.py: id: ee02d2b5889e last_write_checksum: sha1:82fa9fdd11f6f7429c8e654c965c1da0f9613a99 @@ -20784,36 +22104,36 @@ trackedFiles: pristine_git_object: 2ac8c7744309f06fbb3faefa3cd708346f3dc406 src/cribl_control_plane/settings.py: id: 346a076742dd - last_write_checksum: sha1:3501534324a75e28d24ec91227f418a64053d078 - pristine_git_object: 02a02987c753f6746e5be64251b7917cdb47fee8 + last_write_checksum: sha1:86dc7e38a01a9d0a16a5549d053ed2a25831f2d0 + pristine_git_object: f2c5897cbd5bf333dae56951748650546d4fb7a8 src/cribl_control_plane/sources.py: id: 51c4b88fc5fb - last_write_checksum: sha1:add8a74fa62f856f69cdbb7362c8f138688c0015 - pristine_git_object: f38cbab1c390ca24bfcb221c057b425579ffaa61 + last_write_checksum: sha1:09e660d74687e134c2928f5e6f75e4505b891a11 + pristine_git_object: 83cd2eb2b386e987a637223fda7cf94cb1751a18 src/cribl_control_plane/sources_pq.py: id: f83af0610b37 - last_write_checksum: sha1:4bbc1687efc3d8bfce7b578a0e956cf3f5883675 - pristine_git_object: 09e63bfce6fb66c0ea5d65d28c221c233b7e1409 + last_write_checksum: sha1:7637b0d7060648158982be79b5e699ac20658df7 + pristine_git_object: 6122322defc26c71963507580cd074a2ca00f1f7 src/cribl_control_plane/sources_statuses.py: id: b33d5c30a8f7 - last_write_checksum: sha1:6d98f87be5404fa79023ff43df86b885bfeb7673 - pristine_git_object: bc5acf19dfcf9ee70dafb62ab9b7317c884cfc18 + last_write_checksum: sha1:a28e09453545154e32784d15341da48f04c50f0c + pristine_git_object: 409d37dd783fc9c830af03a8fb91dbc4bcf25a6b src/cribl_control_plane/summaries.py: id: 7a0e86f2b16e - last_write_checksum: sha1:4656e2b5a0860697d50262eb9177e1f30a545ce8 - pristine_git_object: f59180619f24d99e0fc3e3a82eff806e66d136f9 + last_write_checksum: sha1:46f004fdc197120d09264d2d5cb2a3a826a53732 + pristine_git_object: 7fe0682920377496f139a0b6396b5cfff673817f src/cribl_control_plane/system_sdk.py: id: 8bb841f702c6 last_write_checksum: sha1:f89e447ea59d7fd83c4a6c77eed7f2aaf8a5fcc4 pristine_git_object: 7fd49d2282433ef09451afc89e1ed81dd76bd6cd src/cribl_control_plane/teams.py: id: 42e7a113cca7 - last_write_checksum: sha1:d1edfc4528bcef813f9657356972085b747dcbfd - pristine_git_object: 01ae36b6e04ede869fe08319adeeb9e740cdf101 + last_write_checksum: sha1:4851d2bbd9bc209290a0fbee844d47826053ce1d + pristine_git_object: d3cbeab20606a95707545e97a8e6f0bc790d3cef src/cribl_control_plane/tokens.py: id: "286841425817" - last_write_checksum: sha1:000c9319c9f04d116f20b56271ebe968d2afef51 - pristine_git_object: d2c6b4c142e098158d16497d70ecb3306defc12d + last_write_checksum: sha1:78f0165b01bc401f55e433de44eab05422d15571 + pristine_git_object: 1fd0af8dcc5c0598971bf881a96d9f0de08a327b src/cribl_control_plane/types/__init__.py: id: 4b9154594b49 last_write_checksum: sha1:f9ad14217f832e74f594285960125add50324be9 @@ -20828,8 +22148,8 @@ trackedFiles: pristine_git_object: a9a640a1a7048736383f96c67c6290c86bf536ee src/cribl_control_plane/utils/__init__.py: id: c9ee56b59017 - last_write_checksum: sha1:7bab4464f8e01656349d991d21d1e093b012b7bc - pristine_git_object: 6120a33eec9f6fd7801cc7621f9380f08f503a75 + last_write_checksum: sha1:b9cb5851a618ff388d0c56127f6a7c595aa51978 + pristine_git_object: 0b27ffce2ea45a32158dcf6fdbb03305ff41cef9 src/cribl_control_plane/utils/annotations.py: id: 50e3980c7727 last_write_checksum: sha1:a4824ad65f730303e4e1e3ec1febf87b4eb46dbc @@ -20880,20 +22200,20 @@ trackedFiles: pristine_git_object: 591415af8e64baa410627b507d2740afb5387d13 src/cribl_control_plane/utils/retries.py: id: 33a7d7545e57 - last_write_checksum: sha1:481dfc7cd6a07a3987f0f443e91bee72888ae41d - pristine_git_object: c7418a62826fc73990a52e70df0d54093c5e2a57 + last_write_checksum: sha1:251e4dd969bb6c06025afe1bad1b5035e94c2060 + pristine_git_object: 406c1e7c36c7a4fa4fb48bb567d254e2803e1792 src/cribl_control_plane/utils/security.py: id: e07fa3288aac last_write_checksum: sha1:cb4aa1d8a8315558b97f7bb409ff0f48ffd6514b pristine_git_object: 8c49f72f4c3ec30286f1dd2a15506b9d72ffe610 src/cribl_control_plane/utils/serializers.py: id: 1fd5c84e2b79 - last_write_checksum: sha1:7485f1425b0661fd84836186570df90207eec6af - pristine_git_object: 1031ed930bad5ece220cf7416a56c29f40f0588b + last_write_checksum: sha1:2fb543339b424a0818b126e69695df5c91cd4d7b + pristine_git_object: 5e57d36e8883501df8f6293e4c76ac337c4987eb src/cribl_control_plane/utils/unions.py: id: 24d13b85b9c8 - last_write_checksum: sha1:cd6201e6f43c51545a32f5bd4ac9f508e1ba0c29 - pristine_git_object: 2434640235f9607bd894361dcba872ceb5b26533 + last_write_checksum: sha1:cf05df60e2a9578806d903f79ec6f4758f491044 + pristine_git_object: 45248ff684cf7e6323bad6574021f177907b499d src/cribl_control_plane/utils/unmarshal_json_response.py: id: cb2f8bf22326 last_write_checksum: sha1:4febf7bb9e45b52fbdb13726f3bdcfa18cf5360f @@ -20912,12 +22232,12 @@ trackedFiles: pristine_git_object: 030038d11c357c6fa0aecf920c7476f4d5d825b1 src/cribl_control_plane/versions_configs.py: id: de8dfbc9fdbe - last_write_checksum: sha1:487aeeda71733bce16baae6337bab9f0a3dd0a7d - pristine_git_object: af835b469c2b378e6f45802794970714a5f0924c + last_write_checksum: sha1:df5104a3033821d8ea3759a22143667ebe3dbb13 + pristine_git_object: 3987d69ec452df18ef1af294d512f3d3a2086e01 src/cribl_control_plane/versions_statuses.py: id: c6b0a8378410 - last_write_checksum: sha1:152be362d1e004e08784afb25cac4572bf35d286 - pristine_git_object: a04f305ea7393e47412de75e128825df943d0981 + last_write_checksum: sha1:2d3cd67856cf723e4d543097508cec7d81278b6c + pristine_git_object: 1e54b75c90f4b56718aa4149f0caa8a6fc12f9e8 examples: getHealthInfo: speakeasy-default-get-health-info: @@ -21709,6 +23029,176 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + InputCreateExamplesAkamaiHec: + requestBody: + application/json: {"id": "akamai-hec-source", "type": "akamai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesGigamonHec: + requestBody: + application/json: {"id": "gigamon-hec-source", "type": "gigamon_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesBeyondTrustHec: + requestBody: + application/json: {"id": "beyondtrust-hec-source", "type": "beyondtrust_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesAnthropicEnterpriseAnalytics: + requestBody: + application/json: {"id": "anthropic-enterprise-analytics-source", "type": "anthropic_enterprise_analytics", "sendToRoutes": true, "pqEnabled": false, "textSecret": "anthropic-api-key-secret", "contentConfig": [{"contentType": "Usage Report", "disabled": false, "stateTracking": true, "stateUpdateExpression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", "stateMergeExpression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", "groupBy": [], "bucketWidth": "1d", "cronSchedule": "0 */4 * * *", "earliest": "-7d@d", "jobTimeout": "300"}]} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesAquaSecurityHec: + requestBody: + application/json: {"id": "aqua-security-hec-source", "type": "aqua_security_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesAzureVNetFlowLog: + requestBody: + application/json: {"id": "azure-vnet-flow-log-source", "type": "azure_vnet_flow_log", "sendToRoutes": true, "pqEnabled": false, "queueName": "vnet-flow-log-queue"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesExtrahopRevealx360: + requestBody: + application/json: {"id": "extrahop-revealx-360-source", "type": "extrahop_revealx_360", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesF5BigIp: + requestBody: + application/json: {"id": "f5-big-ip-source", "type": "f5_big_ip", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesHashicorpHcpVaultDedicated: + requestBody: + application/json: {"id": "hashicorp-hcp-vault-dedicated-source", "type": "hashicorp_hcp_vault_dedicated", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesMimecastHec: + requestBody: + application/json: {"id": "mimecast-hec-source", "type": "mimecast_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesMicrosoftCopilot: + requestBody: + application/json: {"id": "microsoft-copilot-source", "type": "microsoft_copilot", "sendToRoutes": true, "pqEnabled": false, "tenantId": "00000000-0000-0000-0000-000000000000", "clientId": "00000000-0000-0000-0000-000000000001", "authType": "oauthSecret", "cronSchedule": "*/15 * * * *", "earliest": "-7d", "latest": "now", "textSecret": "microsoft-copilot-secret"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesPingIdentityPingone: + requestBody: + application/json: {"id": "ping-identity-pingone-source", "type": "ping_identity_pingone", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesProofpointPod: + requestBody: + application/json: {"id": "proofpoint-pod-source", "type": "proofpoint_pod", "sendToRoutes": true, "pqEnabled": false, "clusterId": "my-pod-cluster", "feedType": "message", "textSecret": "proofpoint-pod-token-secret"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesSailpointHec: + requestBody: + application/json: {"id": "sailpoint-hec-source", "type": "sailpoint_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesTrendMicroVisionOne: + requestBody: + application/json: {"id": "trend-micro-vision-one-source", "type": "trend_micro_vision_one", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesTrellixHec: + requestBody: + application/json: {"id": "trellix-hec-source", "type": "trellix_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesVectraAiHec: + requestBody: + application/json: {"id": "vectra-ai-hec-source", "type": "vectra_ai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 839156, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} getInputById: speakeasy-default-get-input-by-id: parameters: @@ -23503,6 +24993,227 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + UpdateInputExamplesAkamaiHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "akamai-hec-source", "type": "akamai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesGigamonHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "gigamon-hec-source", "type": "gigamon_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesBeyondTrustHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "beyondtrust-hec-source", "type": "beyondtrust_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesAnthropicEnterpriseAnalytics: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "anthropic-enterprise-analytics-source", "type": "anthropic_enterprise_analytics", "sendToRoutes": true, "pqEnabled": false, "textSecret": "anthropic-api-key-secret", "contentConfig": [{"contentType": "Usage Report", "disabled": false, "stateTracking": true, "stateUpdateExpression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", "stateMergeExpression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", "groupBy": [], "bucketWidth": "1d", "cronSchedule": "0 */4 * * *", "earliest": "-7d@d", "jobTimeout": "300"}]} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesAquaSecurityHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "aqua-security-hec-source", "type": "aqua_security_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesAzureVNetFlowLog: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "azure-vnet-flow-log-source", "type": "azure_vnet_flow_log", "sendToRoutes": true, "pqEnabled": false, "queueName": "vnet-flow-log-queue"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesExtrahopRevealx360: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "extrahop-revealx-360-source", "type": "extrahop_revealx_360", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesF5BigIp: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "f5-big-ip-source", "type": "f5_big_ip", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesHashicorpHcpVaultDedicated: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "hashicorp-hcp-vault-dedicated-source", "type": "hashicorp_hcp_vault_dedicated", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesMimecastHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "mimecast-hec-source", "type": "mimecast_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesMicrosoftCopilot: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "microsoft-copilot-source", "type": "microsoft_copilot", "sendToRoutes": true, "pqEnabled": false, "tenantId": "00000000-0000-0000-0000-000000000000", "clientId": "00000000-0000-0000-0000-000000000001", "authType": "oauthSecret", "cronSchedule": "*/15 * * * *", "earliest": "-7d", "latest": "now", "textSecret": "microsoft-copilot-secret"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesPingIdentityPingone: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "ping-identity-pingone-source", "type": "ping_identity_pingone", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesProofpointPod: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "proofpoint-pod-source", "type": "proofpoint_pod", "sendToRoutes": true, "pqEnabled": false, "clusterId": "my-pod-cluster", "feedType": "message", "textSecret": "proofpoint-pod-token-secret"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesSailpointHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "sailpoint-hec-source", "type": "sailpoint_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesTrendMicroVisionOne: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "trend-micro-vision-one-source", "type": "trend_micro_vision_one", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesTrellixHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "trellix-hec-source", "type": "trellix_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesVectraAiHec: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "vectra-ai-hec-source", "type": "vectra_ai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 535602, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} deleteInputById: speakeasy-default-delete-input-by-id: parameters: @@ -23811,7 +25522,7 @@ examples: application/json: {"status": "error", "message": ""} OutputCreateExamplesSentinel: requestBody: - application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "secret": "client-secret", "client_id": "client-id", "endpointURLConfiguration": "url", "url": "https://your-workspace.ingest.monitor.azure.com"} + application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "client_id": "client-id", "endpointURLConfiguration": "url", "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com"} responses: "200": application/json: {"count": 443349, "items": []} @@ -24221,7 +25932,7 @@ examples: application/json: {"status": "error", "message": ""} OutputCreateExamplesWizHec: requestBody: - application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "placeholder"} + application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_CLOUDTRAIL"} responses: "200": application/json: {"count": 443349, "items": []} @@ -24331,7 +26042,7 @@ examples: application/json: {"status": "error", "message": ""} OutputCreateExamplesExabeam: requestBody: - application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888"} + application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888", "awsAuthenticationMethod": "secret", "awsSecret": "my-secret-id"} responses: "200": application/json: {"count": 443349, "items": []} @@ -24571,6 +26282,36 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + OutputCreateExamplesTraversalOtlp: + requestBody: + application/json: {"id": "traversal-output", "type": "traversal_otlp", "endpoint": "http://traversal-processor:3000", "protocol": "http"} + responses: + "200": + application/json: {"count": 443349, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + OutputCreateExamplesWizHecVpcFlowLogs: + requestBody: + application/json: {"id": "wiz-hec-vpc-flow-logs-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_VPC_FLOW_LOGS", "wiz_vpc_event_format": "csv_row", "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}"} + responses: + "200": + application/json: {"count": 443349, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + OutputCreateExamplesDatabricksZerobus: + requestBody: + application/json: {"id": "databricks-zerobus-output", "type": "databricks_zerobus", "workspaceUrl": "https://dbc-1234abcd-5e6f.cloud.databricks.com", "workspaceId": "your-workspace-id", "zerobusEndpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", "clientId": "your-client-id", "clientTextSecret": "your-client-secret", "tableName": "main.external.events"} + responses: + "200": + application/json: {"count": 443349, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} getOutputById: speakeasy-default-get-output-by-id: parameters: @@ -25707,7 +27448,7 @@ examples: path: id: "" requestBody: - application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "secret": "client-secret", "client_id": "client-id", "endpointURLConfiguration": "url", "url": "https://your-workspace.ingest.monitor.azure.com"} + application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "client_id": "client-id", "endpointURLConfiguration": "url", "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com"} responses: "200": application/json: {"count": 168884, "items": [{"type": "splunk_hec"}]} @@ -26253,7 +27994,7 @@ examples: path: id: "" requestBody: - application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "placeholder"} + application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_CLOUDTRAIL"} responses: "200": application/json: {"count": 168884, "items": [{"type": "splunk_hec"}]} @@ -26396,7 +28137,7 @@ examples: path: id: "" requestBody: - application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888"} + application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888", "awsAuthenticationMethod": "secret", "awsSecret": "my-secret-id"} responses: "200": application/json: {"count": 168884, "items": [{"type": "splunk_hec"}]} @@ -26607,6 +28348,45 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + UpdateOutputExamplesTraversalOtlp: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "traversal-output", "type": "traversal_otlp", "endpoint": "http://traversal-processor:3000", "protocol": "http"} + responses: + "200": + application/json: {"count": 168884, "items": [{"type": "splunk_hec"}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateOutputExamplesWizHecVpcFlowLogs: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "wiz-hec-vpc-flow-logs-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_VPC_FLOW_LOGS", "wiz_vpc_event_format": "csv_row", "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}"} + responses: + "200": + application/json: {"count": 168884, "items": [{"type": "splunk_hec"}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateOutputExamplesDatabricksZerobus: + parameters: + path: + id: "" + requestBody: + application/json: {"id": "databricks-zerobus-output", "type": "databricks_zerobus", "workspaceUrl": "https://dbc-1234abcd-5e6f.cloud.databricks.com", "workspaceId": "your-workspace-id", "zerobusEndpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", "clientId": "your-client-id", "clientTextSecret": "your-client-secret", "tableName": "main.external.events"} + responses: + "200": + application/json: {"count": 168884, "items": [{"type": "splunk_hec"}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} deleteOutputById: speakeasy-default-delete-output-by-id: parameters: @@ -28190,7 +29970,7 @@ examples: path: lakeId: "" requestBody: - application/json: {"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": false, "fieldList": ["", ""], "scanMode": "detailed"}}} + application/json: {"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": true, "fieldList": ["", "", ""], "scanMode": "detailed"}}} responses: "200": application/json: {"count": 617004, "items": [{"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": false, "fieldList": ["", ""], "scanMode": "detailed"}}}]} @@ -28198,6 +29978,8 @@ examples: application/json: {"status": "error", "message": ""} "401": application/json: {"status": "error", "message": ""} + "201": + application/json: {"count": 617004, "items": [{"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": true, "fieldList": ["", "", ""], "scanMode": "detailed"}}}]} LakeDatasetCreateExamplesJsonDataset: parameters: path: @@ -28211,6 +29993,8 @@ examples: application/json: {"status": "error", "message": ""} "401": application/json: {"status": "error", "message": ""} + "201": + application/json: {"count": 617004, "items": [{"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": true, "fieldList": ["", "", ""], "scanMode": "detailed"}}}]} LakeDatasetCreateExamplesParquetDataset: parameters: path: @@ -28224,6 +30008,8 @@ examples: application/json: {"status": "error", "message": ""} "401": application/json: {"status": "error", "message": ""} + "201": + application/json: {"count": 617004, "items": [{"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": true, "fieldList": ["", "", ""], "scanMode": "detailed"}}}]} LakeDatasetCreateExamplesMinimalDataset: parameters: path: @@ -28237,17 +30023,32 @@ examples: application/json: {"status": "error", "message": ""} "401": application/json: {"status": "error", "message": ""} + "201": + application/json: {"count": 617004, "items": [{"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": true, "fieldList": ["", "", ""], "scanMode": "detailed"}}}]} authenticationFailed: parameters: path: lakeId: "" requestBody: - application/json: {"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": false, "fieldList": ["", ""], "scanMode": "detailed"}}} + application/json: {"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": true, "fieldList": ["", "", ""], "scanMode": "detailed"}}} responses: "401": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + LakeDatasetCreateExamplesBulkCreateDatasets: + parameters: + path: + lakeId: "" + requestBody: + application/json: {"acceleratedFields": ["host", "status"], "description": "Web server access logs", "format": "json", "id": "web_access_logs", "retentionPeriodInDays": 90, "storageLocationId": "my-storage-location"} + responses: + "201": + application/json: {"count": 617004, "items": [{"id": "", "searchConfig": {"metadata": {"earliest": "-30d", "enableAcceleration": true, "fieldList": ["", "", ""], "scanMode": "detailed"}}}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} getCriblLakeDatasetByLakeId: speakeasy-default-get-cribl-lake-dataset-by-lake-id: parameters: @@ -28653,6 +30454,14 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + AclGetTeamsResponseGroupExamplesSuccess: + parameters: + path: + product: "stream" + id: "" + responses: + "200": + application/json: {"count": 1, "items": [{"perms": [{"gid": "group1", "policy": "GroupRead", "type": "groups"}], "team": "engineering-team"}]} deleteCriblLakeDatasetByLakeIdAndId: speakeasy-default-delete-cribl-lake-dataset-by-lake-id-and-id: parameters: @@ -29109,7 +30918,7 @@ examples: GetSystemSettingsConfExamplesDefault: responses: "200": - application/json: {"count": 1, "items": [{"api": {"disabled": false, "host": "0.0.0.0", "port": 9000, "ssl": {"certPath": "/opt/cribl/local/cribl/auth/cribl.crt", "disabled": false, "passphrase": "", "privKeyPath": "/opt/cribl/local/cribl/auth/cribl.key"}}, "apps": {"enabled": true}, "backups": {}, "pii": {}, "proxy": {"useEnvVars": false}, "rollback": {}, "shutdown": {"drainTimeout": 10000}, "sni": {}, "system": {"intercom": true, "upgrade": "api"}, "tls": {"defaultCipherList": "DEFAULT", "defaultEcdhCurve": "auto", "maxVersion": "TLSv1.3", "minVersion": "TLSv1.2", "rejectUnauthorized": true}, "upgradeGroupSettings": {}, "upgradeSettings": {}, "workers": {"count": 0, "memory": 0, "minimum": 1}}]} + application/json: {"count": 1, "items": [{"api": {"disabled": false, "host": "0.0.0.0", "port": 9000, "ssl": {"certPath": "/opt/cribl/local/cribl/auth/myApiCert.crt", "certificateName": "myApiCert", "disabled": false, "passphrase": "", "privKeyPath": "/opt/cribl/local/cribl/auth/myApiCert.key"}}, "apps": {"enabled": true}, "backups": {}, "pii": {}, "proxy": {"useEnvVars": false}, "rollback": {}, "shutdown": {"drainTimeout": 10000}, "sni": {}, "system": {"intercom": true, "upgrade": "api"}, "tls": {"defaultCipherList": "DEFAULT", "defaultEcdhCurve": "auto", "maxVersion": "TLSv1.3", "minVersion": "TLSv1.2", "rejectUnauthorized": true}, "upgradeGroupSettings": {}, "upgradeSettings": {}, "workers": {"count": 0, "memory": 0, "minimum": 1}}]} authenticationFailed: responses: "401": @@ -29129,7 +30938,7 @@ examples: application/json: {"status": "error", "message": ""} UpdateSystemSettingsExamplesUpdateApiSettings: requestBody: - application/json: {"api": {"disabled": false, "host": "0.0.0.0", "port": 9000, "ssl": {"certPath": "/opt/cribl/local/cribl/auth/cribl.crt", "disabled": false, "passphrase": "", "privKeyPath": "/opt/cribl/local/cribl/auth/cribl.key"}}, "backups": {"backupPersistence": "24h", "backupsDirectory": "$CRIBL_STATE_DIR/backups"}, "pii": {"enablePiiDetection": false}, "proxy": {"useEnvVars": false}, "rollback": {"rollbackEnabled": true}, "shutdown": {"drainTimeout": 10000}, "sni": {"disableSNIRouting": false}, "system": {"intercom": true, "upgrade": "api"}, "tls": {"defaultCipherList": "DEFAULT", "defaultEcdhCurve": "auto", "maxVersion": "TLSv1.3", "minVersion": "TLSv1.2", "rejectUnauthorized": true}, "upgradeGroupSettings": {"isRolling": true, "quantity": 100, "retryCount": 5, "retryDelay": 1000}, "upgradeSettings": {}, "workers": {"count": 0, "memory": 0, "minimum": 1}} + application/json: {"api": {"disabled": false, "host": "0.0.0.0", "port": 9000, "ssl": {"certPath": "/opt/cribl/local/cribl/auth/myApiCert.crt", "certificateName": "myApiCert", "disabled": false, "passphrase": "", "privKeyPath": "/opt/cribl/local/cribl/auth/myApiCert.key"}}, "backups": {"backupPersistence": "24h", "backupsDirectory": "$CRIBL_STATE_DIR/backups"}, "pii": {"enablePiiDetection": false}, "proxy": {"useEnvVars": false}, "rollback": {"rollbackEnabled": true}, "shutdown": {"drainTimeout": 10000}, "sni": {"disableSNIRouting": false}, "system": {"intercom": true, "upgrade": "api"}, "tls": {"defaultCipherList": "DEFAULT", "defaultEcdhCurve": "auto", "maxVersion": "TLSv1.3", "minVersion": "TLSv1.2", "rejectUnauthorized": true}, "upgradeGroupSettings": {"isRolling": true, "quantity": 100, "retryCount": 5, "retryDelay": 1000}, "upgradeSettings": {}, "workers": {"count": 0, "memory": 0, "minimum": 1}} responses: "200": application/json: {"count": 199199, "items": []} @@ -29142,7 +30951,7 @@ examples: application/json: {"backups": {}, "pii": {}, "rollback": {}, "sni": {}, "tls": {}} responses: "200": - application/json: {"count": 1, "items": [{"api": {"disabled": false, "host": "0.0.0.0", "port": 9000, "ssl": {"certPath": "/opt/cribl/local/cribl/auth/cribl.crt", "disabled": false, "passphrase": "", "privKeyPath": "/opt/cribl/local/cribl/auth/cribl.key"}}, "apps": {"enabled": true}, "backups": {}, "pii": {}, "proxy": {"useEnvVars": false}, "rollback": {}, "shutdown": {"drainTimeout": 10000}, "sni": {}, "system": {"intercom": true, "upgrade": "api"}, "tls": {"defaultCipherList": "DEFAULT", "defaultEcdhCurve": "auto", "maxVersion": "TLSv1.3", "minVersion": "TLSv1.2", "rejectUnauthorized": true}, "upgradeGroupSettings": {}, "upgradeSettings": {}, "workers": {"count": 0, "memory": 0, "minimum": 1}}]} + application/json: {"count": 1, "items": [{"api": {"disabled": false, "host": "0.0.0.0", "port": 9000, "ssl": {"certPath": "/opt/cribl/local/cribl/auth/myApiCert.crt", "certificateName": "myApiCert", "disabled": false, "passphrase": "", "privKeyPath": "/opt/cribl/local/cribl/auth/myApiCert.key"}}, "apps": {"enabled": true}, "backups": {}, "pii": {}, "proxy": {"useEnvVars": false}, "rollback": {}, "shutdown": {"drainTimeout": 10000}, "sni": {}, "system": {"intercom": true, "upgrade": "api"}, "tls": {"defaultCipherList": "DEFAULT", "defaultEcdhCurve": "auto", "maxVersion": "TLSv1.3", "minVersion": "TLSv1.2", "rejectUnauthorized": true}, "upgradeGroupSettings": {}, "upgradeSettings": {}, "workers": {"count": 0, "memory": 0, "minimum": 1}}]} authenticationFailed: requestBody: application/json: {"backups": {}, "pii": {}, "rollback": {}, "sni": {}, "tls": {}} @@ -29213,12 +31022,28 @@ examples: application/json: {"status": "error", "message": ""} authenticationFailed: requestBody: - application/json: {"password": "6j50J9421x29IhO", "username": "Lilly_Weissnat"} + application/json: {"password": "j50J9421x29IhO_", "username": "Turner.Kuhn"} responses: "401": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + LoginExamplesLocalLogin: + requestBody: + application/json: {"password": "yourPassword", "username": "yourUsername"} + responses: + "200": + application/json: {"forcePasswordChange": true, "token": ""} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + LoginResponseExamplesLocalLogin: + requestBody: + application/json: {"password": "j50J9421x29IhO_", "username": "Turner.Kuhn"} + responses: + "200": + application/json: {"forcePasswordChange": false, "token": "1234abcd5678efgh9101ijklEXAMPLETOKEN"} getHealth: speakeasy-default-get-health: responses: @@ -29240,7 +31065,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "pomelo outside offensively ew", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", ""], "resumeOnBoot": true, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": ["", ""], "workerAffinity": true, "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}, "input": {"type": "collection", "breakerRulesets": ["", "", ""], "staleChannelFlushMs": 3845.21, "sendToRoutes": true, "preprocess": {"disabled": true, "command": "", "args": ["", "", ""]}, "throttleRatePerSec": "", "metadata": [{"name": "", "value": ""}], "pipeline": "", "output": ""}} + application/json: {"type": "executor", "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}} responses: "200": application/json: {"count": 105565, "items": []} @@ -29253,7 +31078,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "pomelo outside offensively ew", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", ""], "resumeOnBoot": true, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": ["", ""], "workerAffinity": true, "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}, "input": {"type": "collection", "breakerRulesets": ["", "", ""], "staleChannelFlushMs": 3845.21, "sendToRoutes": true, "preprocess": {"disabled": true, "command": "", "args": ["", "", ""]}, "throttleRatePerSec": "", "metadata": [{"name": "", "value": ""}], "pipeline": "", "output": ""}} + application/json: {"type": "executor", "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}} responses: "200": application/json: {"count": 105565, "items": []} @@ -29266,7 +31091,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "against between cop-out wretched", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": [""], "resumeOnBoot": false, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": ["", "", ""], "executor": {"type": "", "storeTaskResults": true, "conf": {}}} + application/json: {"type": "executor", "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}} responses: "200": application/json: {"count": 105565, "items": []} @@ -29279,7 +31104,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "pomelo outside offensively ew", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", ""], "resumeOnBoot": true, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": ["", ""], "workerAffinity": true, "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}, "input": {"type": "collection", "breakerRulesets": ["", "", ""], "staleChannelFlushMs": 3845.21, "sendToRoutes": true, "preprocess": {"disabled": true, "command": "", "args": ["", "", ""]}, "throttleRatePerSec": "", "metadata": [{"name": "", "value": ""}], "pipeline": "", "output": ""}} + application/json: {"type": "executor", "savedQueryId": ""} responses: "200": application/json: {"count": 105565, "items": []} @@ -29292,7 +31117,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "pomelo outside offensively ew", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", ""], "resumeOnBoot": true, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": ["", ""], "workerAffinity": true, "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}, "input": {"type": "collection", "breakerRulesets": ["", "", ""], "staleChannelFlushMs": 3845.21, "sendToRoutes": true, "preprocess": {"disabled": true, "command": "", "args": ["", "", ""]}, "throttleRatePerSec": "", "metadata": [{"name": "", "value": ""}], "pipeline": "", "output": ""}} + application/json: {"type": "executor", "executor": {"type": ""}} responses: "200": application/json: {"count": 105565, "items": []} @@ -29305,7 +31130,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "however loyally as likely silent", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", "", ""], "resumeOnBoot": false, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": [""], "savedQueryId": ""} + application/json: {"type": "executor", "executor": {"type": ""}} responses: "200": application/json: {"count": 105565, "items": []} @@ -29318,7 +31143,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "pomelo outside offensively ew", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", ""], "resumeOnBoot": true, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": ["", ""], "workerAffinity": true, "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}, "input": {"type": "collection", "breakerRulesets": ["", "", ""], "staleChannelFlushMs": 3845.21, "sendToRoutes": true, "preprocess": {"disabled": true, "command": "", "args": ["", "", ""]}, "throttleRatePerSec": "", "metadata": [{"name": "", "value": ""}], "pipeline": "", "output": ""}} + application/json: {"type": "executor", "executor": {"type": ""}} responses: "200": application/json: {"count": 105565, "items": []} @@ -29331,7 +31156,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "pomelo outside offensively ew", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", ""], "resumeOnBoot": true, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": ["", ""], "workerAffinity": true, "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}, "input": {"type": "collection", "breakerRulesets": ["", "", ""], "staleChannelFlushMs": 3845.21, "sendToRoutes": true, "preprocess": {"disabled": true, "command": "", "args": ["", "", ""]}, "throttleRatePerSec": "", "metadata": [{"name": "", "value": ""}], "pipeline": "", "output": ""}} + application/json: {"type": "executor", "collector": {"type": "database", "conf": {"connectionId": "", "query": "", "queryValidationEnabled": true, "defaultBreakers": "Cribl", "__scheduling": {"stateTracking": {"enabled": false}}}, "destructive": false, "encoding": ""}} responses: "200": application/json: {"count": 105565, "items": []} @@ -29344,7 +31169,7 @@ examples: query: criblPack: "" requestBody: - application/json: {"id": "", "description": "however loyally as likely silent", "type": "executor", "ttl": "", "ignoreGroupJobsLimit": false, "removeFields": ["", "", ""], "resumeOnBoot": false, "environment": "", "schedule": {"enabled": true, "skippable": true, "resumeMissed": false, "cronSchedule": "", "maxConcurrentRuns": 3006.78, "run": {"type": "collection", "rescheduleDroppedTasks": true, "maxTaskReschedule": 1211.14, "logLevel": "debug", "jobTimeout": "", "mode": "", "timeRangeType": "", "earliest": 4847.66, "latest": 3337.75, "timestampTimezone": "", "timeWarning": {}, "expression": "", "minTaskSize": "", "maxTaskSize": ""}}, "streamtags": [""], "savedQueryId": ""} + application/json: {"type": "executor", "savedQueryId": ""} responses: "200": application/json: {"count": 105565, "items": []} @@ -29935,19 +31760,19 @@ examples: application/json: {"status": "error", "message": ""} DatabaseConnectionResponseExamplesMySQLDatabaseConnection: requestBody: - application/json: {"authType": "connectionString", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credsSecrets": "oracle-production-credentials", "databaseType": "postgres", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} + application/json: {"authType": "connectionString", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credentialsSecret": "mssql-production-credentials", "credsSecrets": "oracle-production-credentials", "databaseType": "postgres", "description": "Production MySQL database for customer data", "host": "'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "sslmode": "VERIFY-FULL", "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} responses: "200": application/json: {"count": 1, "items": [{"authType": "connectionString", "connectionString": "*****", "connectionTimeout": 10000, "databaseType": "mysql", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "tags": "production,mysql,customer-data"}]} DatabaseConnectionBadRequestResponseExamplesInvalidDatabaseConnectionRequest: requestBody: - application/json: {"authType": "connectionString", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credsSecrets": "oracle-production-credentials", "databaseType": "postgres", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} + application/json: {"authType": "connectionString", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credentialsSecret": "mssql-production-credentials", "credsSecrets": "oracle-production-credentials", "databaseType": "postgres", "description": "Production MySQL database for customer data", "host": "'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "sslmode": "VERIFY-FULL", "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} responses: "400": application/json: {"message": "must have required property 'id'", "status": "error"} authenticationFailed: requestBody: - application/json: {"authType": "connectionString", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credsSecrets": "oracle-production-credentials", "databaseType": "postgres", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} + application/json: {"authType": "connectionString", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credentialsSecret": "mssql-production-credentials", "credsSecrets": "oracle-production-credentials", "databaseType": "postgres", "description": "Production MySQL database for customer data", "host": "'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "sslmode": "VERIFY-FULL", "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} responses: "401": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} @@ -30418,7 +32243,7 @@ examples: path: id: "" requestBody: - application/json: {"authType": "configObj", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credsSecrets": "oracle-production-credentials", "databaseType": "sqlserver", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} + application/json: {"authType": "configObj", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credentialsSecret": "mssql-production-credentials", "credsSecrets": "oracle-production-credentials", "databaseType": "sqlserver", "description": "Production MySQL database for customer data", "host": "'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "sslmode": "VERIFY-FULL", "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} responses: "200": application/json: {"count": 1, "items": [{"authType": "connectionString", "connectionString": "*****", "connectionTimeout": 10000, "databaseType": "mysql", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "tags": "production,mysql,customer-data"}]} @@ -30427,7 +32252,7 @@ examples: path: id: "" requestBody: - application/json: {"authType": "configObj", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credsSecrets": "oracle-production-credentials", "databaseType": "sqlserver", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} + application/json: {"authType": "configObj", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credentialsSecret": "mssql-production-credentials", "credsSecrets": "oracle-production-credentials", "databaseType": "sqlserver", "description": "Production MySQL database for customer data", "host": "'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "sslmode": "VERIFY-FULL", "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} responses: "400": application/json: {"message": "must have required property 'id'", "status": "error"} @@ -30436,7 +32261,7 @@ examples: path: id: "" requestBody: - application/json: {"authType": "configObj", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credsSecrets": "oracle-production-credentials", "databaseType": "sqlserver", "description": "Production MySQL database for customer data", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} + application/json: {"authType": "configObj", "configObj": "{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", "connectionString": "mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", "connectionTimeout": 10000, "credentialsSecret": "mssql-production-credentials", "credsSecrets": "oracle-production-credentials", "databaseType": "sqlserver", "description": "Production MySQL database for customer data", "host": "'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", "id": "mysql-prod-db", "password": "yourPassword", "requestTimeout": 30000, "sslmode": "VERIFY-FULL", "tags": "production,mysql,customer-data", "textSecret": "mysql-production-connection", "user": "yourUsername"} responses: "401": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} @@ -30614,7 +32439,7 @@ examples: application/json: {"id": "appscope-source", "type": "appscope", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 9109} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30627,7 +32452,7 @@ examples: application/json: {"id": "azure-blob-source", "type": "azure_blob", "sendToRoutes": true, "pqEnabled": false, "queueName": "azure-blob-queue"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30640,7 +32465,7 @@ examples: application/json: {"id": "cloudflare-hec-source", "type": "cloudflare_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30653,7 +32478,7 @@ examples: application/json: {"id": "confluent-cloud-source", "type": "confluent_cloud", "sendToRoutes": true, "pqEnabled": false, "brokers": ["pkc-xxxxx.us-east-1.aws.confluent.cloud:9092"], "topics": ["logs"]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30666,7 +32491,7 @@ examples: application/json: {"id": "collection-source", "type": "collection", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30679,7 +32504,7 @@ examples: application/json: {"id": "cribl-http-source", "type": "cribl_http", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30692,7 +32517,7 @@ examples: application/json: {"id": "cribl-lake-http-source", "type": "cribl_lake_http", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30705,7 +32530,7 @@ examples: application/json: {"id": "cribl-tcp-source", "type": "cribl_tcp", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10090} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30718,7 +32543,7 @@ examples: application/json: {"id": "crowdstrike-source", "type": "crowdstrike", "sendToRoutes": true, "pqEnabled": false, "queueName": "crowdstrike-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30731,7 +32556,7 @@ examples: application/json: {"id": "datadog-agent-source", "type": "datadog_agent", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8126} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30744,7 +32569,7 @@ examples: application/json: {"id": "datagen-source", "type": "datagen", "sendToRoutes": true, "pqEnabled": false, "samples": [{"sample": "sample.json", "eventsPerSec": 10}]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30757,7 +32582,7 @@ examples: application/json: {"id": "edge-prometheus-source", "type": "edge_prometheus", "sendToRoutes": true, "pqEnabled": false, "discoveryType": "static", "interval": 60, "targets": [{"host": "localhost"}]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30770,7 +32595,7 @@ examples: application/json: {"id": "elastic-source", "type": "elastic", "sendToRoutes": true, "pqEnabled": false, "host": "localhost", "port": 9200, "elasticAPI": "/"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30783,7 +32608,7 @@ examples: application/json: {"id": "eventhub-source", "type": "eventhub", "sendToRoutes": true, "pqEnabled": false, "brokers": ["myeventhub.servicebus.windows.net:9093"], "topics": ["logs"]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30796,7 +32621,7 @@ examples: application/json: {"id": "exec-source", "type": "exec", "sendToRoutes": true, "pqEnabled": false, "command": "echo \"Hello World\"", "interval": 60} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30809,7 +32634,7 @@ examples: application/json: {"id": "file-source", "type": "file", "sendToRoutes": true, "pqEnabled": false, "mode": "manual"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30822,7 +32647,7 @@ examples: application/json: {"id": "firehose-source", "type": "firehose", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30835,7 +32660,7 @@ examples: application/json: {"id": "grafana-source", "type": "grafana", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080, "prometheusAPI": "/api/prom/push"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30848,7 +32673,7 @@ examples: application/json: {"id": "google-pubsub-source", "type": "google_pubsub", "sendToRoutes": true, "pqEnabled": false, "topicName": "my-topic", "subscriptionName": "my-subscription"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30861,7 +32686,7 @@ examples: application/json: {"id": "http-source", "type": "http", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30874,7 +32699,7 @@ examples: application/json: {"id": "http-raw-source", "type": "http_raw", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30887,7 +32712,7 @@ examples: application/json: {"id": "journal-files-source", "type": "journal_files", "sendToRoutes": true, "pqEnabled": false, "path": "/var/log/journal", "journals": ["system"]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30900,7 +32725,7 @@ examples: application/json: {"id": "kafka-source", "type": "kafka", "sendToRoutes": true, "pqEnabled": false, "brokers": ["localhost:9092"], "topics": ["logs"]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30913,7 +32738,7 @@ examples: application/json: {"id": "kinesis-source", "type": "kinesis", "sendToRoutes": true, "pqEnabled": false, "streamName": "my-stream", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30926,7 +32751,7 @@ examples: application/json: {"id": "kube-events-source", "type": "kube_events", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30939,7 +32764,7 @@ examples: application/json: {"id": "kube-logs-source", "type": "kube_logs", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30952,7 +32777,7 @@ examples: application/json: {"id": "kube-metrics-source", "type": "kube_metrics", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30965,7 +32790,7 @@ examples: application/json: {"id": "loki-source", "type": "loki", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080, "lokiAPI": "/loki/api/v1/push"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30978,7 +32803,7 @@ examples: application/json: {"id": "metrics-source", "type": "metrics", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "udpPort": 8125} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -30991,7 +32816,7 @@ examples: application/json: {"id": "mdt-source", "type": "model_driven_telemetry", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 57000} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31004,7 +32829,7 @@ examples: application/json: {"id": "msk-source", "type": "msk", "sendToRoutes": true, "pqEnabled": false, "brokers": ["b-1.example.xxxxx.c2.kafka.us-east-1.amazonaws.com:9092"], "topics": ["logs"], "awsAuthenticationMethod": "auto", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31017,7 +32842,7 @@ examples: application/json: {"id": "netflow-source", "type": "netflow", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 2055} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31030,7 +32855,7 @@ examples: application/json: {"id": "office365-mgmt-source", "type": "office365_mgmt", "sendToRoutes": true, "pqEnabled": false, "planType": "enterprise_gcc", "tenantId": "tenant-id", "appId": "app-id"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31043,7 +32868,7 @@ examples: application/json: {"id": "microsoft-graph-source", "type": "microsoft_graph", "sendToRoutes": true, "pqEnabled": false, "url": "https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces", "interval": 15} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31056,7 +32881,7 @@ examples: application/json: {"id": "office365-msg-trace-source", "type": "office365_msg_trace", "sendToRoutes": true, "pqEnabled": false, "url": "https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace", "interval": 15} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31069,7 +32894,7 @@ examples: application/json: {"id": "office365-service-source", "type": "office365_service", "sendToRoutes": true, "pqEnabled": false, "tenantId": "tenant-id", "appId": "app-id"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31082,7 +32907,7 @@ examples: application/json: {"id": "openai-source", "type": "openai", "sendToRoutes": true, "pqEnabled": false, "contentConfig": [{"disabled": false, "requestParams": [{"name": "effective_at[gt]", "value": "`${Math.round(Date.now()/1000 - 3600)}`"}, {"name": "limit", "value": "100"}], "paginationType": "response_body", "paginationAttribute": ["last_id"], "paginationLastPageExpr": "has_more === false", "cronSchedule": "0 * * * *", "earliest": "-1h", "latest": "now"}], "textSecret": "openai-api-key-secret"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31095,7 +32920,7 @@ examples: application/json: {"id": "otel-source", "type": "open_telemetry", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 4317} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31108,7 +32933,7 @@ examples: application/json: {"id": "prometheus-source", "type": "prometheus", "sendToRoutes": true, "pqEnabled": false, "discoveryType": "static", "interval": 60, "logLevel": "info", "targetList": ["http://localhost:9090/metrics"]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31121,7 +32946,7 @@ examples: application/json: {"id": "prometheus-rw-source", "type": "prometheus_rw", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080, "prometheusAPI": "/write"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31134,7 +32959,7 @@ examples: application/json: {"id": "raw-udp-source", "type": "raw_udp", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 514} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31147,7 +32972,7 @@ examples: application/json: {"id": "s3-source", "type": "s3", "sendToRoutes": true, "pqEnabled": false, "queueName": "s3-notifications-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31160,7 +32985,7 @@ examples: application/json: {"id": "s3-inventory-source", "type": "s3_inventory", "sendToRoutes": true, "pqEnabled": false, "queueName": "s3-inventory-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31173,7 +32998,7 @@ examples: application/json: {"id": "security-lake-source", "type": "security_lake", "sendToRoutes": true, "pqEnabled": false, "queueName": "security-lake-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31186,7 +33011,7 @@ examples: application/json: {"id": "snmp-source", "type": "snmp", "sendToRoutes": true, "pqEnabled": false, "host": "192.168.1.1", "port": 161} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31199,7 +33024,7 @@ examples: application/json: {"id": "splunk-source", "type": "splunk", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 9997} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31212,7 +33037,7 @@ examples: application/json: {"id": "splunk-hec-source", "type": "splunk_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "splunkHecAPI": "/services/collector"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31225,7 +33050,7 @@ examples: application/json: {"id": "splunk-search-source", "type": "splunk_search", "sendToRoutes": true, "pqEnabled": false, "searchHead": "https://localhost:8089", "search": "index=main", "cronSchedule": "*/15 * * * *", "endpoint": "/services/search/v2/jobs/export", "outputMode": "json", "authType": "basic"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31238,7 +33063,7 @@ examples: application/json: {"id": "sqs-source", "type": "sqs", "sendToRoutes": true, "pqEnabled": false, "queueName": "my-queue", "queueType": "standard", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31251,7 +33076,7 @@ examples: application/json: {"id": "syslog-source", "type": "syslog", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "udpPort": 514} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31264,7 +33089,7 @@ examples: application/json: {"id": "system-metrics-source", "type": "system_metrics", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31277,7 +33102,7 @@ examples: application/json: {"id": "system-state-source", "type": "system_state", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31290,7 +33115,7 @@ examples: application/json: {"id": "tcp-source", "type": "tcp", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10090} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31303,7 +33128,7 @@ examples: application/json: {"id": "tcpjson-source", "type": "tcpjson", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10090} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31316,7 +33141,7 @@ examples: application/json: {"id": "wef-source", "type": "wef", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 5985, "subscriptions": [{"subscriptionName": "subscription-1", "contentFormat": "RenderedText", "heartbeatInterval": 60, "batchTimeout": 5, "targets": []}]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31329,7 +33154,7 @@ examples: application/json: {"id": "win-event-logs-source", "type": "win_event_logs", "sendToRoutes": true, "pqEnabled": false, "logNames": ["Application", "System"]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31342,7 +33167,7 @@ examples: application/json: {"id": "windows-metrics-source", "type": "windows_metrics", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31355,7 +33180,7 @@ examples: application/json: {"id": "wiz-source", "type": "wiz", "sendToRoutes": true, "pqEnabled": false, "endpoint": "https://api.wiz.io", "authUrl": "https://auth.wiz.io/oauth/token", "clientId": "client-id", "contentConfig": []} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31368,7 +33193,7 @@ examples: application/json: {"id": "wiz-webhook-source", "type": "wiz_webhook", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31381,7 +33206,7 @@ examples: application/json: {"id": "zscaler-hec-source", "type": "zscaler_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31407,7 +33232,7 @@ examples: application/json: {"id": "anthropic-compliance-source", "type": "anthropic_compliance", "sendToRoutes": true, "pqEnabled": false, "textSecret": "anthropic-api-key-secret"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31420,7 +33245,7 @@ examples: application/json: {"id": "apple-unified-logs-source", "type": "apple_unified_logs", "sendToRoutes": true, "pqEnabled": false, "predicate": "subsystem == \"com.apple.security\""} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31433,7 +33258,7 @@ examples: application/json: {"id": "eventhub-amqp-source", "type": "eventhub_amqp", "sendToRoutes": true, "pqEnabled": false, "eventHubName": "my-event-hub", "consumerGroup": "$Default", "checkpointing": {"blobStore": {"containerName": "my-container"}}} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31446,7 +33271,7 @@ examples: application/json: {"id": "okta-source", "type": "okta", "sendToRoutes": true, "pqEnabled": false, "oktaDomain": "your-org", "textSecret": "okta-api-token-secret", "cronSchedule": "*/5 * * * *", "earliest": "-7d@d", "latest": "now"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31459,7 +33284,7 @@ examples: application/json: {"id": "openai-compliance-logs-source", "type": "openai_compliance_logs", "sendToRoutes": true, "pqEnabled": false, "textSecret": "openai-api-key-secret", "accountType": "workspace", "cronSchedule": "*/15 * * * *", "earliest": "-1h", "latest": "now", "workspaceId": "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee", "workspaceEventTypes": ["AUDIT_LOG", "AUTH_LOG"]} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31472,7 +33297,7 @@ examples: application/json: {"id": "servicenow-table-source", "type": "servicenow_table", "sendToRoutes": true, "pqEnabled": false, "instance": "https://example.service-now.com", "tableName": "incident", "fields": ["sys_id", "number", "short_description"], "pageSize": 10000, "cronSchedule": "0 * * * *", "earliest": "-1d", "latest": "now"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -31485,7 +33310,7 @@ examples: application/json: {"id": "bedrock-s3-source", "type": "bedrock_s3", "sendToRoutes": true, "pqEnabled": false, "queueName": "s3-notifications-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -31498,7 +33323,7 @@ examples: application/json: {"id": "sysdig-hec-source", "type": "sysdig_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -31511,7 +33336,7 @@ examples: application/json: {"id": "syslog-pq-source", "type": "syslog", "sendToRoutes": true, "pqEnabled": true, "pq": {"mode": "always", "maxBufferSizeBytes": "1MB", "maxFileSize": "10MB", "maxSize": "5GB", "path": "$CRIBL_HOME/state/queues", "compress": "none", "onBackpressure": "drop"}, "host": "0.0.0.0", "udpPort": 514} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -31524,7 +33349,7 @@ examples: application/json: {"id": "upwind-hec-source", "type": "upwind_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 755786, "items": [{"type": "upwind_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -31576,6 +33401,227 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + InputCreateExamplesAkamaiHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "akamai-hec-source", "type": "akamai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesGigamonHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "gigamon-hec-source", "type": "gigamon_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesBeyondTrustHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "beyondtrust-hec-source", "type": "beyondtrust_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesAnthropicEnterpriseAnalytics: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "anthropic-enterprise-analytics-source", "type": "anthropic_enterprise_analytics", "sendToRoutes": true, "pqEnabled": false, "textSecret": "anthropic-api-key-secret", "contentConfig": [{"contentType": "Usage Report", "disabled": false, "stateTracking": true, "stateUpdateExpression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", "stateMergeExpression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", "groupBy": [], "bucketWidth": "1d", "cronSchedule": "0 */4 * * *", "earliest": "-7d@d", "jobTimeout": "300"}]} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesAquaSecurityHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "aqua-security-hec-source", "type": "aqua_security_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesAzureVNetFlowLog: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "azure-vnet-flow-log-source", "type": "azure_vnet_flow_log", "sendToRoutes": true, "pqEnabled": false, "queueName": "vnet-flow-log-queue"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesExtrahopRevealx360: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "extrahop-revealx-360-source", "type": "extrahop_revealx_360", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesF5BigIp: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "f5-big-ip-source", "type": "f5_big_ip", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesHashicorpHcpVaultDedicated: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "hashicorp-hcp-vault-dedicated-source", "type": "hashicorp_hcp_vault_dedicated", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesMimecastHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "mimecast-hec-source", "type": "mimecast_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesMicrosoftCopilot: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "microsoft-copilot-source", "type": "microsoft_copilot", "sendToRoutes": true, "pqEnabled": false, "tenantId": "00000000-0000-0000-0000-000000000000", "clientId": "00000000-0000-0000-0000-000000000001", "authType": "oauthSecret", "cronSchedule": "*/15 * * * *", "earliest": "-7d", "latest": "now", "textSecret": "microsoft-copilot-secret"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesPingIdentityPingone: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "ping-identity-pingone-source", "type": "ping_identity_pingone", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesProofpointPod: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "proofpoint-pod-source", "type": "proofpoint_pod", "sendToRoutes": true, "pqEnabled": false, "clusterId": "my-pod-cluster", "feedType": "message", "textSecret": "proofpoint-pod-token-secret"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesSailpointHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "sailpoint-hec-source", "type": "sailpoint_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesTrendMicroVisionOne: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "trend-micro-vision-one-source", "type": "trend_micro_vision_one", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesTrellixHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "trellix-hec-source", "type": "trellix_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + InputCreateExamplesVectraAiHec: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "vectra-ai-hec-source", "type": "vectra_ai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 755786, "items": [{"type": "beyondtrust_hec", "host": "moist-swath.info", "port": 8557.01, "captureHeadersWarning": "", "hecAPI": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} getInputSystemByPackAndId: speakeasy-default-get-input-system-by-pack-and-id: parameters: @@ -32471,7 +34517,7 @@ examples: application/json: {"id": "anthropic-compliance-source", "type": "anthropic_compliance", "sendToRoutes": true, "pqEnabled": false, "textSecret": "anthropic-api-key-secret"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32485,7 +34531,7 @@ examples: application/json: {"id": "apple-unified-logs-source", "type": "apple_unified_logs", "sendToRoutes": true, "pqEnabled": false, "predicate": "subsystem == \"com.apple.security\""} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32499,7 +34545,7 @@ examples: application/json: {"id": "appscope-source", "type": "appscope", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 9109} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32513,7 +34559,7 @@ examples: application/json: {"id": "azure-blob-source", "type": "azure_blob", "sendToRoutes": true, "pqEnabled": false, "queueName": "azure-blob-queue"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32527,7 +34573,7 @@ examples: application/json: {"id": "cloudflare-hec-source", "type": "cloudflare_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32541,7 +34587,7 @@ examples: application/json: {"id": "confluent-cloud-source", "type": "confluent_cloud", "sendToRoutes": true, "pqEnabled": false, "brokers": ["pkc-xxxxx.us-east-1.aws.confluent.cloud:9092"], "topics": ["logs"]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32555,7 +34601,7 @@ examples: application/json: {"id": "collection-source", "type": "collection", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32569,7 +34615,7 @@ examples: application/json: {"id": "cribl-source", "type": "cribl", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32583,7 +34629,7 @@ examples: application/json: {"id": "cribl-http-source", "type": "cribl_http", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32597,7 +34643,7 @@ examples: application/json: {"id": "cribl-lake-http-source", "type": "cribl_lake_http", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32611,7 +34657,7 @@ examples: application/json: {"id": "cribl-metrics-source", "type": "criblmetrics", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32625,7 +34671,7 @@ examples: application/json: {"id": "cribl-tcp-source", "type": "cribl_tcp", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10090} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32639,7 +34685,7 @@ examples: application/json: {"id": "crowdstrike-source", "type": "crowdstrike", "sendToRoutes": true, "pqEnabled": false, "queueName": "crowdstrike-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32653,7 +34699,7 @@ examples: application/json: {"id": "datadog-agent-source", "type": "datadog_agent", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8126} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32667,7 +34713,7 @@ examples: application/json: {"id": "datagen-source", "type": "datagen", "sendToRoutes": true, "pqEnabled": false, "samples": [{"sample": "sample.json", "eventsPerSec": 10}]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32681,7 +34727,7 @@ examples: application/json: {"id": "edge-prometheus-source", "type": "edge_prometheus", "sendToRoutes": true, "pqEnabled": false, "discoveryType": "static", "interval": 60, "targets": [{"host": "localhost"}]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32695,7 +34741,7 @@ examples: application/json: {"id": "elastic-source", "type": "elastic", "sendToRoutes": true, "pqEnabled": false, "host": "localhost", "port": 9200, "elasticAPI": "/"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32709,7 +34755,7 @@ examples: application/json: {"id": "eventhub-source", "type": "eventhub", "sendToRoutes": true, "pqEnabled": false, "brokers": ["myeventhub.servicebus.windows.net:9093"], "topics": ["logs"]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32723,7 +34769,7 @@ examples: application/json: {"id": "eventhub-amqp-source", "type": "eventhub_amqp", "sendToRoutes": true, "pqEnabled": false, "eventHubName": "my-event-hub", "consumerGroup": "$Default", "checkpointing": {"blobStore": {"containerName": "my-container"}}} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32737,7 +34783,7 @@ examples: application/json: {"id": "exec-source", "type": "exec", "sendToRoutes": true, "pqEnabled": false, "command": "echo \"Hello World\"", "interval": 60} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32751,7 +34797,7 @@ examples: application/json: {"id": "file-source", "type": "file", "sendToRoutes": true, "pqEnabled": false, "mode": "manual"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32765,7 +34811,7 @@ examples: application/json: {"id": "firehose-source", "type": "firehose", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32779,7 +34825,7 @@ examples: application/json: {"id": "grafana-source", "type": "grafana", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080, "prometheusAPI": "/api/prom/push"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32793,7 +34839,7 @@ examples: application/json: {"id": "google-pubsub-source", "type": "google_pubsub", "sendToRoutes": true, "pqEnabled": false, "topicName": "my-topic", "subscriptionName": "my-subscription"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32807,7 +34853,7 @@ examples: application/json: {"id": "http-source", "type": "http", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32821,7 +34867,7 @@ examples: application/json: {"id": "http-raw-source", "type": "http_raw", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32835,7 +34881,7 @@ examples: application/json: {"id": "journal-files-source", "type": "journal_files", "sendToRoutes": true, "pqEnabled": false, "path": "/var/log/journal", "journals": ["system"]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32849,7 +34895,7 @@ examples: application/json: {"id": "kafka-source", "type": "kafka", "sendToRoutes": true, "pqEnabled": false, "brokers": ["localhost:9092"], "topics": ["logs"]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32863,7 +34909,7 @@ examples: application/json: {"id": "kinesis-source", "type": "kinesis", "sendToRoutes": true, "pqEnabled": false, "streamName": "my-stream", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32877,7 +34923,7 @@ examples: application/json: {"id": "kube-events-source", "type": "kube_events", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32891,7 +34937,7 @@ examples: application/json: {"id": "kube-logs-source", "type": "kube_logs", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32905,7 +34951,7 @@ examples: application/json: {"id": "kube-metrics-source", "type": "kube_metrics", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32919,7 +34965,7 @@ examples: application/json: {"id": "loki-source", "type": "loki", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080, "lokiAPI": "/loki/api/v1/push"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32933,7 +34979,7 @@ examples: application/json: {"id": "metrics-source", "type": "metrics", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "udpPort": 8125} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32947,7 +34993,7 @@ examples: application/json: {"id": "mdt-source", "type": "model_driven_telemetry", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 57000} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32961,7 +35007,7 @@ examples: application/json: {"id": "msk-source", "type": "msk", "sendToRoutes": true, "pqEnabled": false, "brokers": ["b-1.example.xxxxx.c2.kafka.us-east-1.amazonaws.com:9092"], "topics": ["logs"], "awsAuthenticationMethod": "auto", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32975,7 +35021,7 @@ examples: application/json: {"id": "netflow-source", "type": "netflow", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 2055} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -32989,7 +35035,7 @@ examples: application/json: {"id": "office365-mgmt-source", "type": "office365_mgmt", "sendToRoutes": true, "pqEnabled": false, "planType": "enterprise_gcc", "tenantId": "tenant-id", "appId": "app-id"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33003,7 +35049,7 @@ examples: application/json: {"id": "microsoft-graph-source", "type": "microsoft_graph", "sendToRoutes": true, "pqEnabled": false, "url": "https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces", "interval": 15} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33017,7 +35063,7 @@ examples: application/json: {"id": "office365-msg-trace-source", "type": "office365_msg_trace", "sendToRoutes": true, "pqEnabled": false, "url": "https://reports.office365.com/ecp/reportingwebservice/reporting.svc/MessageTrace", "interval": 15} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33031,7 +35077,7 @@ examples: application/json: {"id": "office365-service-source", "type": "office365_service", "sendToRoutes": true, "pqEnabled": false, "tenantId": "tenant-id", "appId": "app-id"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33045,7 +35091,7 @@ examples: application/json: {"id": "okta-source", "type": "okta", "sendToRoutes": true, "pqEnabled": false, "oktaDomain": "your-org", "textSecret": "okta-api-token-secret", "cronSchedule": "*/5 * * * *", "earliest": "-7d@d", "latest": "now"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33059,7 +35105,7 @@ examples: application/json: {"id": "openai-source", "type": "openai", "sendToRoutes": true, "pqEnabled": false, "contentConfig": [{"disabled": false, "requestParams": [{"name": "effective_at[gt]", "value": "`${Math.round(Date.now()/1000 - 3600)}`"}, {"name": "limit", "value": "100"}], "paginationType": "response_body", "paginationAttribute": ["last_id"], "paginationLastPageExpr": "has_more === false", "cronSchedule": "0 * * * *", "earliest": "-1h", "latest": "now"}], "textSecret": "openai-api-key-secret"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33073,7 +35119,7 @@ examples: application/json: {"id": "openai-compliance-logs-source", "type": "openai_compliance_logs", "sendToRoutes": true, "pqEnabled": false, "textSecret": "openai-api-key-secret", "accountType": "workspace", "cronSchedule": "*/15 * * * *", "earliest": "-1h", "latest": "now", "workspaceId": "aaaaaaaa-bbbb-cccc-dddd-eeeeeeeeeeee", "workspaceEventTypes": ["AUDIT_LOG", "AUTH_LOG"]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33087,7 +35133,7 @@ examples: application/json: {"id": "otel-source", "type": "open_telemetry", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 4317} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33101,7 +35147,7 @@ examples: application/json: {"id": "prometheus-source", "type": "prometheus", "sendToRoutes": true, "pqEnabled": false, "discoveryType": "static", "interval": 60, "logLevel": "info", "targetList": ["http://localhost:9090/metrics"]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33115,7 +35161,7 @@ examples: application/json: {"id": "prometheus-rw-source", "type": "prometheus_rw", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080, "prometheusAPI": "/write"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33129,7 +35175,7 @@ examples: application/json: {"id": "raw-udp-source", "type": "raw_udp", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 514} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33143,7 +35189,7 @@ examples: application/json: {"id": "s3-source", "type": "s3", "sendToRoutes": true, "pqEnabled": false, "queueName": "s3-notifications-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33157,7 +35203,7 @@ examples: application/json: {"id": "s3-inventory-source", "type": "s3_inventory", "sendToRoutes": true, "pqEnabled": false, "queueName": "s3-inventory-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33171,7 +35217,7 @@ examples: application/json: {"id": "security-lake-source", "type": "security_lake", "sendToRoutes": true, "pqEnabled": false, "queueName": "security-lake-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33185,7 +35231,7 @@ examples: application/json: {"id": "servicenow-table-source", "type": "servicenow_table", "sendToRoutes": true, "pqEnabled": false, "instance": "https://example.service-now.com", "tableName": "incident", "fields": ["sys_id", "number", "short_description"], "pageSize": 10000, "cronSchedule": "0 * * * *", "earliest": "-1d", "latest": "now"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33199,7 +35245,7 @@ examples: application/json: {"id": "snmp-source", "type": "snmp", "sendToRoutes": true, "pqEnabled": false, "host": "192.168.1.1", "port": 161} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33213,7 +35259,7 @@ examples: application/json: {"id": "splunk-source", "type": "splunk", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 9997} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33227,7 +35273,7 @@ examples: application/json: {"id": "splunk-hec-source", "type": "splunk_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "splunkHecAPI": "/services/collector"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33241,7 +35287,7 @@ examples: application/json: {"id": "splunk-search-source", "type": "splunk_search", "sendToRoutes": true, "pqEnabled": false, "searchHead": "https://localhost:8089", "search": "index=main", "cronSchedule": "*/15 * * * *", "endpoint": "/services/search/v2/jobs/export", "outputMode": "json", "authType": "basic"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33255,7 +35301,7 @@ examples: application/json: {"id": "sqs-source", "type": "sqs", "sendToRoutes": true, "pqEnabled": false, "queueName": "my-queue", "queueType": "standard", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33269,7 +35315,7 @@ examples: application/json: {"id": "syslog-source", "type": "syslog", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "udpPort": 514} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33283,7 +35329,7 @@ examples: application/json: {"id": "system-metrics-source", "type": "system_metrics", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33297,7 +35343,7 @@ examples: application/json: {"id": "system-state-source", "type": "system_state", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33311,7 +35357,7 @@ examples: application/json: {"id": "tcp-source", "type": "tcp", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10090} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33325,7 +35371,7 @@ examples: application/json: {"id": "tcpjson-source", "type": "tcpjson", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10090} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33339,7 +35385,7 @@ examples: application/json: {"id": "wef-source", "type": "wef", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 5985, "subscriptions": [{"subscriptionName": "subscription-1", "contentFormat": "RenderedText", "heartbeatInterval": 60, "batchTimeout": 5, "targets": []}]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33353,7 +35399,7 @@ examples: application/json: {"id": "win-event-logs-source", "type": "win_event_logs", "sendToRoutes": true, "pqEnabled": false, "logNames": ["Application", "System"]} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33367,7 +35413,7 @@ examples: application/json: {"id": "windows-metrics-source", "type": "windows_metrics", "sendToRoutes": true, "pqEnabled": false} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33381,7 +35427,7 @@ examples: application/json: {"id": "wiz-source", "type": "wiz", "sendToRoutes": true, "pqEnabled": false, "endpoint": "https://api.wiz.io", "authUrl": "https://auth.wiz.io/oauth/token", "clientId": "client-id", "contentConfig": []} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33395,7 +35441,7 @@ examples: application/json: {"id": "wiz-webhook-source", "type": "wiz_webhook", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33409,7 +35455,7 @@ examples: application/json: {"id": "zscaler-hec-source", "type": "zscaler_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "500": application/json: {"status": "error", "message": ""} "401": @@ -33423,7 +35469,7 @@ examples: application/json: {"id": "bedrock-s3-source", "type": "bedrock_s3", "sendToRoutes": true, "pqEnabled": false, "queueName": "s3-notifications-queue", "region": "us-east-1"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -33437,7 +35483,7 @@ examples: application/json: {"id": "sysdig-hec-source", "type": "sysdig_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -33451,7 +35497,7 @@ examples: application/json: {"id": "syslog-pq-source", "type": "syslog", "sendToRoutes": true, "pqEnabled": true, "pq": {"mode": "always", "maxBufferSizeBytes": "1MB", "maxFileSize": "10MB", "maxSize": "5GB", "path": "$CRIBL_HOME/state/queues", "compress": "none", "onBackpressure": "drop"}, "host": "0.0.0.0", "udpPort": 514} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -33465,7 +35511,7 @@ examples: application/json: {"id": "upwind-hec-source", "type": "upwind_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} responses: "200": - application/json: {"count": 226580, "items": [{"type": "eventhub", "brokers": ["", ""], "topics": [""]}]} + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} "401": application/json: {"status": "error", "message": ""} "500": @@ -33522,6 +35568,244 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + UpdateInputExamplesAkamaiHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "akamai-hec-source", "type": "akamai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesGigamonHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "gigamon-hec-source", "type": "gigamon_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesBeyondTrustHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "beyondtrust-hec-source", "type": "beyondtrust_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesAnthropicEnterpriseAnalytics: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "anthropic-enterprise-analytics-source", "type": "anthropic_enterprise_analytics", "sendToRoutes": true, "pqEnabled": false, "textSecret": "anthropic-api-key-secret", "contentConfig": [{"contentType": "Usage Report", "disabled": false, "stateTracking": true, "stateUpdateExpression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", "stateMergeExpression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", "groupBy": [], "bucketWidth": "1d", "cronSchedule": "0 */4 * * *", "earliest": "-7d@d", "jobTimeout": "300"}]} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesAquaSecurityHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "aqua-security-hec-source", "type": "aqua_security_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesAzureVNetFlowLog: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "azure-vnet-flow-log-source", "type": "azure_vnet_flow_log", "sendToRoutes": true, "pqEnabled": false, "queueName": "vnet-flow-log-queue"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesExtrahopRevealx360: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "extrahop-revealx-360-source", "type": "extrahop_revealx_360", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesF5BigIp: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "f5-big-ip-source", "type": "f5_big_ip", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesHashicorpHcpVaultDedicated: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "hashicorp-hcp-vault-dedicated-source", "type": "hashicorp_hcp_vault_dedicated", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesMimecastHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "mimecast-hec-source", "type": "mimecast_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesMicrosoftCopilot: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "microsoft-copilot-source", "type": "microsoft_copilot", "sendToRoutes": true, "pqEnabled": false, "tenantId": "00000000-0000-0000-0000-000000000000", "clientId": "00000000-0000-0000-0000-000000000001", "authType": "oauthSecret", "cronSchedule": "*/15 * * * *", "earliest": "-7d", "latest": "now", "textSecret": "microsoft-copilot-secret"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesPingIdentityPingone: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "ping-identity-pingone-source", "type": "ping_identity_pingone", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesProofpointPod: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "proofpoint-pod-source", "type": "proofpoint_pod", "sendToRoutes": true, "pqEnabled": false, "clusterId": "my-pod-cluster", "feedType": "message", "textSecret": "proofpoint-pod-token-secret"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesSailpointHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "sailpoint-hec-source", "type": "sailpoint_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesTrendMicroVisionOne: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "trend-micro-vision-one-source", "type": "trend_micro_vision_one", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesTrellixHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "trellix-hec-source", "type": "trellix_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateInputExamplesVectraAiHec: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "vectra-ai-hec-source", "type": "vectra_ai_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "hecAPI": "/services/collector"} + responses: + "200": + application/json: {"count": 226580, "items": [{"type": "firehose", "host": "multicolored-giant.info", "port": 6746.58, "captureHeadersWarning": ""}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} deleteInputSystemByPackAndId: speakeasy-default-delete-input-system-by-pack-and-id: parameters: @@ -34020,7 +36304,7 @@ examples: path: pack: "" requestBody: - application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "secret": "client-secret", "client_id": "client-id", "endpointURLConfiguration": "url", "url": "https://your-workspace.ingest.monitor.azure.com"} + application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "client_id": "client-id", "endpointURLConfiguration": "url", "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com"} responses: "200": application/json: {"count": 480579, "items": []} @@ -34553,7 +36837,7 @@ examples: path: pack: "" requestBody: - application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "placeholder"} + application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_CLOUDTRAIL"} responses: "200": application/json: {"count": 480579, "items": []} @@ -34696,7 +36980,7 @@ examples: path: pack: "" requestBody: - application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888"} + application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888", "awsAuthenticationMethod": "secret", "awsSecret": "my-secret-id"} responses: "200": application/json: {"count": 480579, "items": []} @@ -35024,6 +37308,45 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + OutputCreateExamplesTraversalOtlp: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "traversal-output", "type": "traversal_otlp", "endpoint": "http://traversal-processor:3000", "protocol": "http"} + responses: + "200": + application/json: {"count": 480579, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + OutputCreateExamplesWizHecVpcFlowLogs: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "wiz-hec-vpc-flow-logs-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_VPC_FLOW_LOGS", "wiz_vpc_event_format": "csv_row", "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}"} + responses: + "200": + application/json: {"count": 480579, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + OutputCreateExamplesDatabricksZerobus: + parameters: + path: + pack: "" + requestBody: + application/json: {"id": "databricks-zerobus-output", "type": "databricks_zerobus", "workspaceUrl": "https://dbc-1234abcd-5e6f.cloud.databricks.com", "workspaceId": "your-workspace-id", "zerobusEndpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", "clientId": "your-client-id", "clientTextSecret": "your-client-secret", "tableName": "main.external.events"} + responses: + "200": + application/json: {"count": 480579, "items": []} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} getOutputSystemByPackAndId: speakeasy-default-get-output-system-by-pack-and-id: parameters: @@ -36262,7 +38585,7 @@ examples: id: "" pack: "" requestBody: - application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "secret": "client-secret", "client_id": "client-id", "endpointURLConfiguration": "url", "url": "https://your-workspace.ingest.monitor.azure.com"} + application/json: {"id": "sentinel-output", "type": "sentinel", "loginUrl": "https://login.microsoftonline.com", "client_id": "client-id", "endpointURLConfiguration": "url", "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com"} responses: "200": application/json: {"count": 221536, "items": [{"type": "humio_hec", "url": "https://potable-reservation.net", "format": "JSON"}]} @@ -36850,7 +39173,7 @@ examples: id: "" pack: "" requestBody: - application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "placeholder"} + application/json: {"id": "wiz-hec-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_CLOUDTRAIL"} responses: "200": application/json: {"count": 221536, "items": [{"type": "humio_hec", "url": "https://potable-reservation.net", "format": "JSON"}]} @@ -37004,7 +39327,7 @@ examples: id: "" pack: "" requestBody: - application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888"} + application/json: {"id": "exabeam-output", "type": "exabeam", "bucket": "my-bucket", "region": "us-east1", "stagePath": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collectorInstanceId": "11112222-3333-4444-5555-666677778888", "awsAuthenticationMethod": "secret", "awsSecret": "my-secret-id"} responses: "200": application/json: {"count": 221536, "items": [{"type": "humio_hec", "url": "https://potable-reservation.net", "format": "JSON"}]} @@ -37232,6 +39555,48 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + UpdateOutputExamplesTraversalOtlp: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "traversal-output", "type": "traversal_otlp", "endpoint": "http://traversal-processor:3000", "protocol": "http"} + responses: + "200": + application/json: {"count": 221536, "items": [{"type": "humio_hec", "url": "https://potable-reservation.net", "format": "JSON"}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateOutputExamplesWizHecVpcFlowLogs: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "wiz-hec-vpc-flow-logs-output", "type": "wiz_hec", "authType": "manual", "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", "wiz_sourcetype": "AWS_VPC_FLOW_LOGS", "wiz_vpc_event_format": "csv_row", "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}"} + responses: + "200": + application/json: {"count": 221536, "items": [{"type": "humio_hec", "url": "https://potable-reservation.net", "format": "JSON"}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} + UpdateOutputExamplesDatabricksZerobus: + parameters: + path: + id: "" + pack: "" + requestBody: + application/json: {"id": "databricks-zerobus-output", "type": "databricks_zerobus", "workspaceUrl": "https://dbc-1234abcd-5e6f.cloud.databricks.com", "workspaceId": "your-workspace-id", "zerobusEndpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", "clientId": "your-client-id", "clientTextSecret": "your-client-secret", "tableName": "main.external.events"} + responses: + "200": + application/json: {"count": 221536, "items": [{"type": "humio_hec", "url": "https://potable-reservation.net", "format": "JSON"}]} + "401": + application/json: {"status": "error", "message": ""} + "500": + application/json: {"status": "error", "message": ""} deleteOutputSystemByPackAndId: speakeasy-default-delete-output-system-by-pack-and-id: parameters: @@ -39444,14 +41809,14 @@ examples: pack: "" responses: "200": - application/json: {"count": 1, "items": [{"id": "default", "routes": [{"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}]} + application/json: {"items": [{"id": "default", "routes": [{"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}], "count": 1} RoutesResponseExamplesMultiRouteTable: parameters: path: pack: "" responses: "200": - application/json: {"count": 1, "items": [{"id": "default", "routes": [{"disabled": false, "filter": "sourcetype=='syslog'", "final": false, "id": "route-security", "name": "Security events", "output": "splunk-hec", "pipeline": "security-pipeline"}, {"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}]} + application/json: {"items": [{"id": "default", "routes": [{"disabled": false, "filter": "sourcetype=='syslog'", "final": false, "id": "route-security", "name": "Security events", "output": "splunk-hec", "pipeline": "security-pipeline"}, {"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}], "count": 1} authenticationFailed: parameters: path: @@ -41161,11 +43526,11 @@ examples: RoutesResponseExamplesDefaultRoutingTable: responses: "200": - application/json: {"count": 1, "items": [{"id": "default", "routes": [{"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}]} + application/json: {"items": [{"id": "default", "routes": [{"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}], "count": 1} RoutesResponseExamplesMultiRouteTable: responses: "200": - application/json: {"count": 1, "items": [{"id": "default", "routes": [{"disabled": false, "filter": "sourcetype=='syslog'", "final": false, "id": "route-security", "name": "Security events", "output": "splunk-hec", "pipeline": "security-pipeline"}, {"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}]} + application/json: {"items": [{"id": "default", "routes": [{"disabled": false, "filter": "sourcetype=='syslog'", "final": false, "id": "route-security", "name": "Security events", "output": "splunk-hec", "pipeline": "security-pipeline"}, {"disabled": false, "filter": "true", "final": true, "id": "default", "name": "default", "output": "default", "pipeline": "main"}]}], "count": 1} authenticationFailed: responses: "401": @@ -41652,6 +44017,14 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + AclGetUsersResponseGroupExamplesSuccess: + parameters: + path: + product: "outpost" + id: "" + responses: + "200": + application/json: {"count": 1, "items": [{"perms": [{"gid": "group1", "policy": "GroupRead", "type": "groups"}], "user": "user1@example.com"}]} getProductsGroupsConfigVersionByProductAndId: GroupConfigVersionResponseExamplesConfigVersion: parameters: @@ -41683,6 +44056,52 @@ examples: application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} "500": application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + getInput: + InputResponseExamplesSyslogSource: + responses: + "200": + application/json: {"items": [{"id": "syslog-source", "type": "syslog", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "udpPort": 514}], "count": 1} + InputResponseExamplesSyslogWithPQSource: + responses: + "200": + application/json: {"items": [{"id": "syslog-pq-source", "type": "syslog", "sendToRoutes": true, "pqEnabled": true, "pq": {"mode": "always", "maxBufferSizeBytes": "1MB", "maxFileSize": "10MB", "maxSize": "5GB", "path": "$CRIBL_HOME/state/queues", "compress": "none", "onBackpressure": "drop"}, "host": "0.0.0.0", "udpPort": 514}], "count": 1} + InputResponseExamplesSplunkHecSource: + responses: + "200": + application/json: {"items": [{"id": "splunk-hec-source", "type": "splunk_hec", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 8088, "captureHeadersWarning": "", "splunkHecAPI": "/services/collector"}], "count": 1} + InputResponseExamplesHttpSource: + responses: + "200": + application/json: {"items": [{"id": "http-source", "type": "http", "sendToRoutes": true, "pqEnabled": false, "host": "0.0.0.0", "port": 10080, "captureHeadersWarning": ""}], "count": 1} + authenticationFailed: + responses: + "401": + application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + "500": + application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + getOutput: + OutputResponseExamplesSplunkHecDestination: + responses: + "200": + application/json: {"items": [{"id": "splunk-hec-output", "type": "splunk_hec"}], "count": 1} + OutputResponseExamplesS3Destination: + responses: + "200": + application/json: {"items": [{"id": "s3-output", "type": "s3", "bucket": "my-bucket", "region": "us-east-1", "stagePath": "/tmp/staging"}], "count": 1} + OutputResponseExamplesSyslogDestination: + responses: + "200": + application/json: {"items": [{"id": "syslog-output", "type": "syslog", "host": "localhost", "port": 514}], "count": 1} + OutputResponseExamplesSnowflakeStreamingDestination: + responses: + "200": + application/json: {"items": [{"id": "snowflake-streaming-output", "type": "snowflake_streaming", "accountIdentifier": "MYORG-MYACCOUNT", "user": "STREAMING_USER", "pem": {"keyName": "my-snowflake-private-key"}, "database": "EVENTS_DB", "schema": "PUBLIC", "table": "RAW_EVENTS"}], "count": 1} + authenticationFailed: + responses: + "401": + application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} + "500": + application/json: {"status": "error", "message": "Authentication failed (missing or invalid credentials or Bearer token)."} examplesVersion: 1.0.2 generatedTests: getHealthInfo: "2025-07-02T19:12:56+02:00" @@ -41751,7 +44170,38 @@ generatedTests: releaseNotes: | ## Python SDK Changes - This version of the SDK is generated for Cribl version 4.19.2. + This version of the SDK is generated for Cribl version 4.20.0. + + ### New sources + + * `akamai_hec` + * `anthropic_enterprise_analytics` + * `aqua_security_hec` + * `azure_vnet_flow_log` + * `beyondtrust_hec` + * `extrahop_revealx_360` + * `f5_big_ip` + * `gigamon_hec` + * `hashicorp_hcp_vault_dedicated` + * `microsoft_copilot` + * `mimecast_hec` + * `ping_identity_pingone` + * `proofpoint_pod` + * `sailpoint_hec` + * `trellix_hec` + * `trend_micro_vision_one` + * `vectra_ai_hec` + + ### New destinations + + * `databricks_zerobus` + * `traversal_otlp` + + ### New functions + + * `detection_rules` + * `lakehouse_engine_metrics_normalizer` + * `metrics_time_range_gate` generatedFiles: - .devcontainer/README.md diff --git a/.speakeasy/gen.yaml b/.speakeasy/gen.yaml index 85b7579eb..8fbfc6e01 100644 --- a/.speakeasy/gen.yaml +++ b/.speakeasy/gen.yaml @@ -33,7 +33,7 @@ generation: generateNewTests: false skipResponseBodyAssertions: false python: - version: 0.11.0 + version: 0.12.0 additionalDependencies: dev: {} main: {} diff --git a/.speakeasy/out.openapi.yaml b/.speakeasy/out.openapi.yaml index 498274ea4..37ffe9fe3 100644 --- a/.speakeasy/out.openapi.yaml +++ b/.speakeasy/out.openapi.yaml @@ -17,7 +17,7 @@ info: - Host (Worker or Edge Node) context: /api/v1/w/{nodeId} - Search context: /api/v1/m/default_search - version: 4.19.2-89cac507 + version: 4.20.0-cee79842 contact: name: Support url: https://portal.support.cribl.io @@ -428,12 +428,7 @@ components: type: string url: title: Redis URL - description: "Redis URL to connect to. Format: - redis[s]://[[user][:password@]][host][:port][/db-number][?db=db-num\ - ber[&password=bar[&option=value]]]. Must be a JavaScript expression - (which can evaluate to a constant value), enclosed in quotes or - backticks. Can be evaluated only at init time. Example referencing a - Global Variable: `myBucket-${C.vars.myVar}`" + description: "Redis URL to connect to. Format: redis[s]://[[user][:password@]][host][:port][/db-number][?db=db-number[&password=bar[&option=value]]]. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" type: string tlsOptions: $ref: "#/components/schemas/TlsOptionsTypeRedisDeploymentTypeStandalone" @@ -496,10 +491,7 @@ components: host: type: string title: Hostname - description: "Hostname of sentinel node. Must be a JavaScript expression (which - can evaluate to a constant value), enclosed in quotes or - backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myBucket-${C.vars.myVar}`." + description: "Hostname of sentinel node. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`." port: type: number title: Port @@ -585,12 +577,6 @@ components: - auto description: Parser or formatter type to use. type: string - tagDatatype: - type: boolean - title: Tag events with datatype and isParsed - description: Keep the detected datatype field and set isParsed to true on each - event. Enable this when events are bound for downstream Cribl Search - processing. SerdeTypeKvp: type: object properties: @@ -821,12 +807,7 @@ components: minimum: 1 fieldNameExpression: title: Field name format expression - description: "JavaScript expression to format field names when _NAME_n and - _VALUE_n capturing groups are used. Original field name is in global - variable 'name'. Example: To append XX to all field names, use - `${name}_XX` (backticks are literal). If empty, names will be - sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can - access other fields values via __e.." + description: "JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can access other fields values via __e.." type: string overwrite: type: boolean @@ -854,8 +835,7 @@ components: pattern: type: string title: Pattern - description: "Grok pattern to extract fields. Syntax supported: - %{PATTERN_NAME:FIELD_NAME}" + description: "Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME}" patternList: type: array title: Additional Grok patterns @@ -878,8 +858,7 @@ components: description: Clean field names by replacing non-[a-zA-Z0-9] characters with _ fields: title: Fields to serialize - description: "Required for CSV, ELFF, and CLF. All other formats support - wildcard field lists. Examples: host, myField, !source *" + description: "Required for CSV, ELFF, and CLF. All other formats support wildcard field lists. Examples: host, myField, !source *" type: array items: type: string @@ -1018,23 +997,16 @@ components: - name allOf: - oneOf: - - $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProto\ - colNone" - - $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProto\ - colNotNone" + - $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNone" + - $ref: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone" discriminator: propertyName: privProtocol mapping: - none: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProto\ - colNone" - des: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtoc\ - olNotNone" - aes: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtoc\ - olNotNone" - aes256b: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivPr\ - otocolNotNone" - aes256r: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivPr\ - otocolNotNone" + none: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNone" + des: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone" + aes: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone" + aes256b: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone" + aes256r: "#/components/schemas/SnmpTrapSerializeV3UserAuthProtocolNotNonePrivProtocolNotNone" FunctionConfSchemaAggregateMetrics: type: object properties: @@ -1091,18 +1063,11 @@ components: agg: title: Aggregation type: string - description: "Aggregate function to perform on events. Example: - sum(bytes).where(action=='REJECT').as(TotalBytes)" + description: "Aggregate function to perform on events. Example: sum(bytes).where(action=='REJECT').as(TotalBytes)" groupbys: type: array title: Group by dimensions - description: "Optional: One or more dimensions to group aggregates by. Supports - wildcard expressions. Wrap dimension names in quotes if using - literal identifiers, such as 'service.name'. Warning: Using wildcard - '*' causes all dimensions in the event to be included, which can - result in high cardinality and increased memory usage. Exclude - dimensions that can result in high cardinality before using - wildcards. Example: !_time, !_numericValue, *" + description: "Optional: One or more dimensions to group aggregates by. Supports wildcard expressions. Wrap dimension names in quotes if using literal identifiers, such as 'service.name'. Warning: Using wildcard '*' causes all dimensions in the event to be included, which can result in high cardinality and increased memory usage. Exclude dimensions that can result in high cardinality before using wildcards. Example: !_time, !_numericValue, *" items: type: string flushEventLimit: @@ -1114,10 +1079,7 @@ components: flushMemLimit: type: string title: Aggregation memory limit - description: "The memory usage limit to impose upon aggregations. Defaults to - 80% of the process memory; value configured above default limit is - ignored. Accepts numerals with units like KB and MB (example: - 128MB)." + description: "The memory usage limit to impose upon aggregations. Defaults to 80% of the process memory; value configured above default limit is ignored. Accepts numerals with units like KB and MB (example: 128MB)." pattern: ^\d+\s*(?:\w{2})?$ cumulative: type: boolean @@ -1266,20 +1228,14 @@ components: aggregations: type: array title: Aggregates - description: "Aggregate function to perform on events. Example: - sum(bytes).where(action=='REJECT').as(TotalBytes)" + description: "Aggregate function to perform on events. Example: sum(bytes).where(action=='REJECT').as(TotalBytes)" minItems: 1 items: type: string groupbys: type: array title: Group by fields - description: "Optional: One or more fields to group aggregates by. Supports - wildcard expressions. Warning: Using wildcard '*' causes all fields - in the event to be included, which can result in high cardinality - and increased memory usage. Exclude fields that can result in high - cardinality before using wildcards. Example: !_time, !_numericValue, - *" + description: "Optional: One or more fields to group aggregates by. Supports wildcard expressions. Warning: Using wildcard '*' causes all fields in the event to be included, which can result in high cardinality and increased memory usage. Exclude fields that can result in high cardinality before using wildcards. Example: !_time, !_numericValue, *" items: type: string flushEventLimit: @@ -1291,10 +1247,7 @@ components: flushMemLimit: type: string title: Aggregation memory limit - description: "The memory usage limit to impose upon aggregations. Defaults to - 80% of the process memory; value configured above default limit is - ignored. Accepts numerals with units like KB and MB (example: - 128MB)." + description: "The memory usage limit to impose upon aggregations. Defaults to 80% of the process memory; value configured above default limit is ignored. Accepts numerals with units like KB and MB (example: 128MB)." pattern: ^\d+\s*(?:\w{2})?$ cumulative: type: boolean @@ -1834,9 +1787,7 @@ components: code: type: string title: Code - description: "Caution: This Function will be evaluated in an unprotected - context. This means that you will be able to execute almost any - JavaScript code." + description: "Caution: This Function will be evaluated in an unprotected context. This means that you will be able to execute almost any JavaScript code." maxNumOfIterations: type: number title: Iteration limit @@ -1999,6 +1950,203 @@ components: - name - uischema - version + FunctionConfSchemaDetectionRules: + type: object + title: Detection Rules + properties: + localOverrides: + title: Local Overrides + description: Instance-level tuning applied after the rule set is merged. Managed + by Cribl Security; not intended for direct editing. + type: object + properties: + disabled: + title: Disabled Rules + description: Rule IDs to silence entirely. + type: array + items: + type: string + fieldOverrides: + title: Field Overrides + description: Patch scalar fields of a rule without copying its full definition. + type: array + items: + type: object + required: + - id + properties: + id: + title: Rule ID + description: Unique identifier for the Detection Rule to override. + type: string + severityId: + title: Severity + description: Severity level to assign to the Detection Rule. + type: integer + enum: + - 1 + - 2 + - 3 + - 4 + - 5 + x-speakeasy-unknown-values: allow + x-speakeasy-enums: + - SeverityIdOne + - SeverityIdTwo + - SeverityIdThree + - SeverityIdFour + - SeverityIdFive + confidenceId: + title: Confidence + description: Confidence level to assign to the Detection Rule. + type: integer + enum: + - 1 + - 2 + - 3 + x-speakeasy-unknown-values: allow + x-speakeasy-enums: + - ConfidenceIdOne + - ConfidenceIdTwo + - ConfidenceIdThree + impactId: + title: Impact + description: Impact level to assign to the Detection Rule. + type: integer + enum: + - 1 + - 2 + - 3 + - 4 + x-speakeasy-unknown-values: allow + x-speakeasy-enums: + - ImpactIdOne + - ImpactIdTwo + - ImpactIdThree + - ImpactIdFour + isAlert: + title: Is Alert + description: If true, the Detection Rule creates an alert. + Otherwise, false. + type: boolean + message: + title: Message Override + description: Replacement alert message for the Detection Rule. + type: string + inlineRules: + title: Inline Rules + description: Full rule definitions authored here rather than delivered with the + corpus. + type: array + items: + type: object + required: + - id + - name + - condition + properties: + id: + type: string + title: Rule ID + description: Unique identifier for the Detection Rule. + name: + type: string + title: Rule Name + description: Display name for the Detection Rule. + condition: + type: string + title: Condition Expression + description: Expression that determines whether the Detection Rule matches an + event. + severityId: + type: integer + title: Severity + description: Severity level for the Detection Rule. + confidenceId: + type: integer + title: Confidence + description: Confidence level for the Detection Rule. + isAlert: + type: boolean + title: Is Alert + description: If true, the Detection Rule creates an alert. + Otherwise, false. + message: + type: string + title: Message + description: Alert message emitted when the Detection Rule matches. + tags: + type: array + title: Tags + description: Tags for filtering and grouping detection rules. + items: + type: string + FunctionDetectionRules: + type: object + properties: + __filename: + type: string + description: Path to the JavaScript file that implements the Function. + asyncTimeout: + type: number + description: Maximum time, in milliseconds, that the Function is allowed to run + asynchronously before timing out. + cribl_version: + type: string + description: Minimum Cribl version required by the Function, if applicable. + disabled: + type: boolean + description: If true, the Function is disabled and will not execute + in a Pipeline. Otherwise, false. + group: + type: string + description: Category group the Function belongs to. + handleSignals: + type: boolean + description: If true, the Function handles stream signals such as + flush and close. Otherwise, + false. + id: + type: string + enum: + - detection_rules + description: Identifier of the Function. Always detection_rules + loadTime: + type: number + description: Time the Function module was loaded, in milliseconds since the Unix + epoch. + modTime: + type: number + description: Time the Function module was last modified, in milliseconds since + the Unix epoch. + name: + type: string + description: Display name of the Function. + sync: + type: boolean + description: If true, the Function executes synchronously. + Otherwise, false. + uischema: + type: object + additionalProperties: true + description: UI Schema that controls how the Function's configuration form is + rendered. + version: + type: string + description: Version string of the Function. + schema: + type: object + additionalProperties: true + description: JSON Schema document that describes the Function configuration. + required: + - __filename + - group + - id + - loadTime + - modTime + - name + - uischema + - version FunctionConfSchemaDistinct: type: object title: distinct configuration @@ -2158,10 +2306,7 @@ components: overwrite the lookup field. dnsServers: title: DNS server overrides - description: "IPs, in RFC 5952 format, of the DNS servers to use for resolution. - Examples: IPv4 1.1.1.1, 4.2.2.2:53, or IPv6 [2001:4860:4860::8888], - [2001:4860:4860::8888]:1053. If not specified, system's DNS will be - used." + description: "IPs, in RFC 5952 format, of the DNS servers to use for resolution. Examples: IPv4 1.1.1.1, 4.2.2.2:53, or IPv6 [2001:4860:4860::8888], [2001:4860:4860::8888]:1053. If not specified, system's DNS will be used." type: array items: type: string @@ -2182,9 +2327,7 @@ components: type: boolean lookupFallback: title: Fall back to DNS.lookup() - description: "If unable to resolve a DNS short name, make a DNS.lookup() call to - resolve it. Caution: This might degrade performance in unrelated - areas of @{product}." + description: "If unable to resolve a DNS short name, make a DNS.lookup() call to resolve it. Caution: This might degrade performance in unrelated areas of @{product}." type: boolean domainOverrides: title: Use search or domain fallbacks @@ -2357,9 +2500,7 @@ components: dropDimensions: type: array title: Dimensions to drop - description: "One or more dimensions to be dropped. Supports wildcard - expressions. Warning: Using wildcard '*' causes all dimensions in - the event to be dropped." + description: "One or more dimensions to be dropped. Supports wildcard expressions. Warning: Using wildcard '*' causes all dimensions in the event to be dropped." minItems: 1 items: type: string @@ -2441,8 +2582,7 @@ components: mode: title: Sample mode type: string - description: "Defines how sample rate will be derived: log(previousPeriodCount) - or sqrt(previousPeriodCount)" + description: "Defines how sample rate will be derived: log(previousPeriodCount) or sqrt(previousPeriodCount)" enum: - log - sqrt @@ -3316,8 +3456,7 @@ components: pattern: type: string title: Pattern - description: "Grok pattern to extract fields. Syntax supported: - %{PATTERN_NAME:FIELD_NAME}" + description: "Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME}" patternList: type: array title: Additional Grok patterns @@ -3793,16 +3932,9 @@ components: - name - uischema - version - FunctionConfSchemaLimit: + FunctionConfSchemaLakehouseEngineMetricsNormalizer: type: object - additionalProperties: false - properties: - limit: - title: Event limit - description: Number of qualifying events to pass through - type: integer - minimum: 0 - FunctionLimit: + FunctionLakehouseEngineMetricsNormalizer: type: object properties: __filename: @@ -3830,8 +3962,9 @@ components: id: type: string enum: - - limit - description: Identifier of the Function. Always limit + - lakehouse_engine_metrics_normalizer + description: Identifier of the Function. Always + lakehouse_engine_metrics_normalizer loadTime: type: number description: Time the Function module was loaded, in milliseconds since the Unix @@ -3868,9 +4001,16 @@ components: - name - uischema - version - FunctionConfSchemaLocalSearchDatatypeParser: + FunctionConfSchemaLimit: type: object - FunctionLocalSearchDatatypeParser: + additionalProperties: false + properties: + limit: + title: Event limit + description: Number of qualifying events to pass through + type: integer + minimum: 0 + FunctionLimit: type: object properties: __filename: @@ -3898,9 +4038,8 @@ components: id: type: string enum: - - local_search_datatype_parser - description: Identifier of the Function. Always - local_search_datatype_parser + - limit + description: Identifier of the Function. Always limit loadTime: type: number description: Time the Function module was loaded, in milliseconds since the Unix @@ -3937,33 +4076,9 @@ components: - name - uischema - version - FunctionConfSchemaLocalSearchRulesetRunner: + FunctionConfSchemaLocalSearchDatatypeParser: type: object - additionalProperties: false - properties: - rulesetType: - type: string - enum: - - dataset - - datatype - title: Ruleset Type - description: "Type of ruleset to apply: dataset or datatype." - x-speakeasy-unknown-values: allow - rulesetId: - type: string - title: Ruleset ID - description: ID of the ruleset to apply. - ruleset: - type: object - title: Full ruleset - description: Full ruleset definition, used with live data capture for draft or - unsaved rulesets. - markAndIncludeDroppedEvents: - type: boolean - title: Mark and include dropped events - description: Only for use with live data capture. Mark events that were dropped - by dataset rules and still include them for capture - FunctionLocalSearchRulesetRunner: + FunctionLocalSearchDatatypeParser: type: object properties: __filename: @@ -3991,9 +4106,9 @@ components: id: type: string enum: - - local_search_ruleset_runner + - local_search_datatype_parser description: Identifier of the Function. Always - local_search_ruleset_runner + local_search_datatype_parser loadTime: type: number description: Time the Function module was loaded, in milliseconds since the Unix @@ -4030,78 +4145,33 @@ components: - name - uischema - version - FunctionConfSchemaLocalSearchSchemaMapper: - type: object - FunctionLocalSearchSchemaMapper: + FunctionConfSchemaLocalSearchRulesetRunner: type: object + additionalProperties: false properties: - __filename: - type: string - description: Path to the JavaScript file that implements the Function. - asyncTimeout: - type: number - description: Maximum time, in milliseconds, that the Function is allowed to run - asynchronously before timing out. - cribl_version: - type: string - description: Minimum Cribl version required by the Function, if applicable. - disabled: - type: boolean - description: If true, the Function is disabled and will not execute - in a Pipeline. Otherwise, false. - group: - type: string - description: Category group the Function belongs to. - handleSignals: - type: boolean - description: If true, the Function handles stream signals such as - flush and close. Otherwise, - false. - id: + rulesetType: type: string enum: - - local_search_schema_mapper - description: Identifier of the Function. Always - local_search_schema_mapper - loadTime: - type: number - description: Time the Function module was loaded, in milliseconds since the Unix - epoch. - modTime: - type: number - description: Time the Function module was last modified, in milliseconds since - the Unix epoch. - name: - type: string - description: Display name of the Function. - sync: - type: boolean - description: If true, the Function executes synchronously. - Otherwise, false. - uischema: - type: object - additionalProperties: true - description: UI Schema that controls how the Function's configuration form is - rendered. - version: + - dataset + - datatype + title: Ruleset Type + description: "Type of ruleset to apply: dataset or datatype." + x-speakeasy-unknown-values: allow + rulesetId: type: string - description: Version string of the Function. - schema: + title: Ruleset ID + description: ID of the ruleset to apply. + ruleset: type: object - additionalProperties: true - description: JSON Schema document that describes the Function configuration. - required: - - __filename - - group - - id - - loadTime - - modTime - - name - - uischema - - version - FunctionConfSchemaLocalSearchTimeRangeNormalizer: - type: object - FunctionLocalSearchTimeRangeNormalizer: + title: Full ruleset + description: Full ruleset definition, used with live data capture for draft or + unsaved rulesets. + markAndIncludeDroppedEvents: + type: boolean + title: Mark and include dropped events + description: Only for use with live data capture. Mark events that were dropped + by dataset rules and still include them for capture + FunctionLocalSearchRulesetRunner: type: object properties: __filename: @@ -4129,9 +4199,9 @@ components: id: type: string enum: - - local_search_time_range_normalizer + - local_search_ruleset_runner description: Identifier of the Function. Always - local_search_time_range_normalizer + local_search_ruleset_runner loadTime: type: number description: Time the Function module was loaded, in milliseconds since the Unix @@ -4168,9 +4238,9 @@ components: - name - uischema - version - FunctionConfSchemaLocalSearchTransformer: + FunctionConfSchemaLocalSearchSchemaMapper: type: object - FunctionLocalSearchTransformer: + FunctionLocalSearchSchemaMapper: type: object properties: __filename: @@ -4198,9 +4268,147 @@ components: id: type: string enum: - - local_search_transformer + - local_search_schema_mapper description: Identifier of the Function. Always - local_search_transformer + local_search_schema_mapper + loadTime: + type: number + description: Time the Function module was loaded, in milliseconds since the Unix + epoch. + modTime: + type: number + description: Time the Function module was last modified, in milliseconds since + the Unix epoch. + name: + type: string + description: Display name of the Function. + sync: + type: boolean + description: If true, the Function executes synchronously. + Otherwise, false. + uischema: + type: object + additionalProperties: true + description: UI Schema that controls how the Function's configuration form is + rendered. + version: + type: string + description: Version string of the Function. + schema: + type: object + additionalProperties: true + description: JSON Schema document that describes the Function configuration. + required: + - __filename + - group + - id + - loadTime + - modTime + - name + - uischema + - version + FunctionConfSchemaLocalSearchTimeRangeNormalizer: + type: object + FunctionLocalSearchTimeRangeNormalizer: + type: object + properties: + __filename: + type: string + description: Path to the JavaScript file that implements the Function. + asyncTimeout: + type: number + description: Maximum time, in milliseconds, that the Function is allowed to run + asynchronously before timing out. + cribl_version: + type: string + description: Minimum Cribl version required by the Function, if applicable. + disabled: + type: boolean + description: If true, the Function is disabled and will not execute + in a Pipeline. Otherwise, false. + group: + type: string + description: Category group the Function belongs to. + handleSignals: + type: boolean + description: If true, the Function handles stream signals such as + flush and close. Otherwise, + false. + id: + type: string + enum: + - local_search_time_range_normalizer + description: Identifier of the Function. Always + local_search_time_range_normalizer + loadTime: + type: number + description: Time the Function module was loaded, in milliseconds since the Unix + epoch. + modTime: + type: number + description: Time the Function module was last modified, in milliseconds since + the Unix epoch. + name: + type: string + description: Display name of the Function. + sync: + type: boolean + description: If true, the Function executes synchronously. + Otherwise, false. + uischema: + type: object + additionalProperties: true + description: UI Schema that controls how the Function's configuration form is + rendered. + version: + type: string + description: Version string of the Function. + schema: + type: object + additionalProperties: true + description: JSON Schema document that describes the Function configuration. + required: + - __filename + - group + - id + - loadTime + - modTime + - name + - uischema + - version + FunctionConfSchemaLocalSearchTransformer: + type: object + FunctionLocalSearchTransformer: + type: object + properties: + __filename: + type: string + description: Path to the JavaScript file that implements the Function. + asyncTimeout: + type: number + description: Maximum time, in milliseconds, that the Function is allowed to run + asynchronously before timing out. + cribl_version: + type: string + description: Minimum Cribl version required by the Function, if applicable. + disabled: + type: boolean + description: If true, the Function is disabled and will not execute + in a Pipeline. Otherwise, false. + group: + type: string + description: Category group the Function belongs to. + handleSignals: + type: boolean + description: If true, the Function handles stream signals such as + flush and close. Otherwise, + false. + id: + type: string + enum: + - local_search_transformer + description: Identifier of the Function. Always + local_search_transformer loadTime: type: number description: Time the Function module was loaded, in milliseconds since the Unix @@ -4243,8 +4451,7 @@ components: file: type: string title: Lookup file path (.csv, .csv.gz) - description: "Path to the lookup file. Reference environment variables via $. - Example: $HOME/file.csv" + description: "Path to the lookup file. Reference environment variables via $. Example: $HOME/file.csv" minLength: 1 dbLookup: type: boolean @@ -4269,8 +4476,7 @@ components: matchType: title: Match type type: string - description: "Further defines how to handle multiple matches: return the first - match, the most specific match, or all matches" + description: "Further defines how to handle multiple matches: return the first match, the most specific match, or all matches" enum: - first - specific @@ -4302,8 +4508,7 @@ components: lookupField: type: string title: Corresponding Field Name in Lookup - description: "Optional: The field name as it appears in the lookup file. - Defaults to event field name" + description: "Optional: The field name as it appears in the lookup file. Defaults to event field name" outFields: type: array title: Output fields @@ -4321,8 +4526,7 @@ components: eventField: type: string title: Lookup Field Name in Event - description: "Optional: Field name to add to event. Defaults to lookup field - name." + description: "Optional: Field name to add to event. Defaults to lookup field name." pattern: ^[a-zA-Z$_][a-zA-Z0-9$_\[\]\.'"]*$ defaultValue: type: string @@ -4335,8 +4539,7 @@ components: ignoreCase: type: boolean title: Ignore case - description: "Whether to ignore case when performing lookups using Match Mode: - Regex." + description: "Whether to ignore case when performing lookups using Match Mode: Regex." FunctionLookup: type: object properties: @@ -4535,23 +4738,31 @@ components: properties: searchJobId: title: Search Job Id - description: Id of the search job this function is running on. + description: Unique identifier for the Search Job that runs this Function. type: string dataset: title: Dataset Id - description: Id of the metrics dataset + description: Unique identifier for the metrics Dataset. type: string nameField: $ref: "#/components/schemas/NameFieldType" + description: Reference to a field by its original text and parsed path segments. timeField: $ref: "#/components/schemas/NameFieldType" + description: Reference to a field by its original text and parsed path segments. valueField: $ref: "#/components/schemas/NameFieldType" + description: Reference to a field by its original text and parsed path segments. typeField: $ref: "#/components/schemas/NameFieldType" + description: Reference to a field by its original text and parsed path segments. labelFields: + description: Field references to attach as labels to each exported metric. + Specify one field or a list of fields. oneOf: - type: object + description: Label configuration that reads key-value pairs from one object + field. required: - mode - field @@ -4559,11 +4770,13 @@ components: mode: enum: - object - description: Discriminator value. + description: Type of label configuration. Always object. x-speakeasy-unknown-values: allow field: $ref: "#/components/schemas/NameFieldType" + description: Reference to a field by its original text and parsed path segments. - type: object + description: Label configuration that reads values from a list of fields. required: - mode - fields @@ -4571,26 +4784,27 @@ components: mode: enum: - list - description: Discriminator value. + description: Type of label configuration. Always list. x-speakeasy-unknown-values: allow fields: type: array + description: Field references to attach as labels to each exported metric. items: $ref: "#/components/schemas/NameFieldType" tee: title: Tee - description: Tee results to search. When set to true results will be shipped - instead of stats + description: If true, pass processed events to downstream + Functions. If false, emit export statistics. type: boolean flushMs: title: Flush period - description: How often stats are flushed in ms + description: Interval, in milliseconds, between export statistics updates. type: number suppressPreviews: type: boolean title: Suppress periodic stats - description: Disables generation of intermediate stats. When true stats will be - emitted only on end + description: If true, emit export statistics only when processing + completes. If false, emit periodic statistics. FunctionMetricsExport: type: object properties: @@ -4657,6 +4871,75 @@ components: - name - uischema - version + FunctionConfSchemaMetricsTimeRangeGate: + type: object + FunctionMetricsTimeRangeGate: + type: object + properties: + __filename: + type: string + description: Path to the JavaScript file that implements the Function. + asyncTimeout: + type: number + description: Maximum time, in milliseconds, that the Function is allowed to run + asynchronously before timing out. + cribl_version: + type: string + description: Minimum Cribl version required by the Function, if applicable. + disabled: + type: boolean + description: If true, the Function is disabled and will not execute + in a Pipeline. Otherwise, false. + group: + type: string + description: Category group the Function belongs to. + handleSignals: + type: boolean + description: If true, the Function handles stream signals such as + flush and close. Otherwise, + false. + id: + type: string + enum: + - metrics_time_range_gate + description: Identifier of the Function. Always + metrics_time_range_gate + loadTime: + type: number + description: Time the Function module was loaded, in milliseconds since the Unix + epoch. + modTime: + type: number + description: Time the Function module was last modified, in milliseconds since + the Unix epoch. + name: + type: string + description: Display name of the Function. + sync: + type: boolean + description: If true, the Function executes synchronously. + Otherwise, false. + uischema: + type: object + additionalProperties: true + description: UI Schema that controls how the Function's configuration form is + rendered. + version: + type: string + description: Version string of the Function. + schema: + type: object + additionalProperties: true + description: JSON Schema document that describes the Function configuration. + required: + - __filename + - group + - id + - loadTime + - modTime + - name + - uischema + - version FunctionConfSchemaMvExpand: type: object additionalProperties: false @@ -4916,9 +5199,9 @@ components: title: Operator description: Comparison operator enum: - - = + - "=" - "!=" - - =~ + - "=~" - "!~" x-speakeasy-enums: - Equal @@ -4939,8 +5222,19 @@ components: description: List of targets to route to and the templates to use minItems: 1 items: - $ref: "#/components/schemas/TemplateTargetPairConfFunctionConfSchemaNotificatio\ - nPolicies" + type: object + required: + - templateId + - targetId + properties: + templateId: + type: string + title: Template ID + description: ID of the notification template to use + targetId: + type: string + title: Target ID + description: ID of the notification target (output) final: type: boolean title: Final @@ -5143,11 +5437,11 @@ components: description: Operation to be applied over the results count enum: - ">" - - < - - === + - "<" + - "===" - "!==" - ">=" - - <= + - "<=" x-speakeasy-enum-descriptions: - greater than - less than @@ -5170,8 +5464,7 @@ components: type: string message: title: Message content - description: "Message content template, available fields: searchId, resultSet, - savedQueryId, notificationId, searchResultsUrl" + description: "Message content template, available fields: searchId, resultSet, savedQueryId, notificationId, searchResultsUrl" type: string authToken: title: Api Auth Token @@ -5264,22 +5557,14 @@ components: maximum: 10 ignoreFields: title: Ignore fields - description: "Fields to NOT numerify. Takes precedence over 'Include expression' - when set. Supports wildcards. A '!' before field name(s) means: - numerify all fields EXCEPT these. For syntax details, see - [Wildcard Lists](https://docs.cribl.io/stream/introduction-referenc\ - e/#wildcard-lists)." + description: "Fields to NOT numerify. Takes precedence over 'Include expression' when set. Supports wildcards. A '!' before field name(s) means: numerify all fields EXCEPT these. For syntax details, see [Wildcard Lists](https://docs.cribl.io/stream/introduction-reference/#wildcard-lists)." type: array items: type: string description: Field to ignore filterExpr: title: Include expression - description: "Optional JavaScript expression to determine whether a field should - be numerified. If left blank, all fields will be numerified. Use the - 'name' and 'value' global variables to access fields' names/values. - Examples: `value != null`, `name=='fieldname'`. You can access other - fields' values via `__e.`." + description: "Optional JavaScript expression to determine whether a field should be numerified. If left blank, all fields will be numerified. Use the 'name' and 'value' global variables to access fields' names/values. Examples: `value != null`, `name=='fieldname'`. You can access other fields' values via `__e.`." type: string format: title: Format @@ -5417,10 +5702,7 @@ components: metadataCardinalityLimit: type: number title: Metadata cardinality limit - description: "Limit the number of unique combinations of metadata key values - that will be processed over the lifetime of the process. After the - limit is reached, events with new metadata key value combinations - will be dropped. " + description: "Limit the number of unique combinations of metadata key values that will be processed over the lifetime of the process. After the limit is reached, events with new metadata key value combinations will be dropped. " FunctionOtlpLogs: type: object properties: @@ -6073,8 +6355,7 @@ components: type: string command: title: Command - description: "Redis command to perform. For a complete list visit: - https://redis.io/commands" + description: "Redis command to perform. For a complete list visit: https://redis.io/commands" type: string keyExpr: title: Key @@ -6127,12 +6408,7 @@ components: Cache. url: title: Redis URL - description: "Redis URL to connect to. Format: - redis[s]://[[user][:password@]][host][:port][/db-number][?db=db-num\ - ber[&password=bar[&option=value]]]. Must be a JavaScript expression - (which can evaluate to a constant value), enclosed in quotes or - backticks. Can be evaluated only at init time. Example referencing a - Global Variable: `myBucket-${C.vars.myVar}`" + description: "Redis URL to connect to. Format: redis[s]://[[user][:password@]][host][:port][/db-number][?db=db-number[&password=bar[&option=value]]]. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" type: string __template_url: type: string @@ -6303,12 +6579,7 @@ components: minimum: 1 fieldNameExpression: title: Field name format expression - description: "JavaScript expression to format field names when _NAME_n and - _VALUE_n capturing groups are used. Original field name is in global - variable 'name'. Example: To append XX to all field names, use - `${name}_XX` (backticks are literal). If empty, names will be - sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can - access other fields values via __e.." + description: "JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can access other fields values via __e.." type: string overwrite: type: boolean @@ -6507,11 +6778,7 @@ components: pattern: ^(?!__).+ renameExpr: title: Rename expression - description: "Optional JavaScript expression whose returned value will be used - to rename fields. Use the 'name' and 'value' global variables to - access field names/values. Example: `name.startsWith('data') ? - name.toUpperCase() : name`. You can access other field values via - __e.." + description: "Optional JavaScript expression whose returned value will be used to rename fields. Use the 'name' and 'value' global variables to access field names/values. Example: `name.startsWith('data') ? name.toUpperCase() : name`. You can access other field values via __e.." type: string wildcardDepth: type: integer @@ -7157,12 +7424,6 @@ components: - Regular Expression - Grok x-speakeasy-unknown-values: allow - tagDatatype: - type: boolean - title: Tag events with datatype and isParsed - description: Keep the detected datatype field and set isParsed to true on each - event. Enable this when events are bound for downstream Cribl Search - processing. keep: title: Fields to keep description: List of fields to keep. Supports wildcards (*). Takes precedence @@ -7224,12 +7485,7 @@ components: minimum: 1 fieldNameExpression: title: Field name format expression - description: "JavaScript expression to format field names when _NAME_n and - _VALUE_n capturing groups are used. Original field name is in global - variable 'name'. Example: To append XX to all field names, use - `${name}_XX` (backticks are literal). If empty, names will be - sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can - access other fields values via __e.." + description: "JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can access other fields values via __e.." type: string overwrite: type: boolean @@ -7239,8 +7495,7 @@ components: pattern: type: string title: Pattern - description: "Grok pattern to extract fields. Syntax supported: - %{PATTERN_NAME:FIELD_NAME}" + description: "Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME}" patternList: type: array title: Additional Grok patterns @@ -7356,9 +7611,7 @@ components: x-speakeasy-unknown-values: allow fields: title: Fields to serialize - description: "Required for CSV, ELFF, CLF, and Delimited values. All other - formats support wildcard field lists. Examples: host, array*, !host - *" + description: "Required for CSV, ELFF, CLF, and Delimited values. All other formats support wildcard field lists. Examples: host, array*, !host *" type: array items: type: string @@ -8252,8 +8505,7 @@ components: srcExpr: type: string title: Source field expression - description: "Field in which to find/calculate the array to unroll. Example: - _raw, _raw.split(/\\n/)" + description: "Field in which to find/calculate the array to unroll. Example: _raw, _raw.split(/\\n/)" dstField: type: string title: Destination field @@ -8423,8 +8675,7 @@ components: inherit: type: string title: Copy elements regex - description: "Regex matching elements to copy into each unrolled event. Example: - ^root\\.(childA|childB|childC)$" + description: "Regex matching elements to copy into each unrolled event. Example: ^root\\.(childA|childB|childC)$" unrollIdxField: type: string title: Unroll index field @@ -8510,6 +8761,7 @@ components: - $ref: "#/components/schemas/FunctionClone" - $ref: "#/components/schemas/FunctionCode" - $ref: "#/components/schemas/FunctionComment" + - $ref: "#/components/schemas/FunctionDetectionRules" - $ref: "#/components/schemas/FunctionDistinct" - $ref: "#/components/schemas/FunctionDnsLookup" - $ref: "#/components/schemas/FunctionDrop" @@ -8528,6 +8780,7 @@ components: - $ref: "#/components/schemas/FunctionJoin" - $ref: "#/components/schemas/FunctionJsonUnroll" - $ref: "#/components/schemas/FunctionLakeExport" + - $ref: "#/components/schemas/FunctionLakehouseEngineMetricsNormalizer" - $ref: "#/components/schemas/FunctionLimit" - $ref: "#/components/schemas/FunctionLocalSearchDatatypeParser" - $ref: "#/components/schemas/FunctionLocalSearchRulesetRunner" @@ -8537,6 +8790,7 @@ components: - $ref: "#/components/schemas/FunctionLookup" - $ref: "#/components/schemas/FunctionMask" - $ref: "#/components/schemas/FunctionMetricsExport" + - $ref: "#/components/schemas/FunctionMetricsTimeRangeGate" - $ref: "#/components/schemas/FunctionMvExpand" - $ref: "#/components/schemas/FunctionMvPull" - $ref: "#/components/schemas/FunctionNotificationPolicies" @@ -8582,6 +8836,7 @@ components: clone: "#/components/schemas/FunctionClone" code: "#/components/schemas/FunctionCode" comment: "#/components/schemas/FunctionComment" + detection_rules: "#/components/schemas/FunctionDetectionRules" distinct: "#/components/schemas/FunctionDistinct" dns_lookup: "#/components/schemas/FunctionDnsLookup" drop: "#/components/schemas/FunctionDrop" @@ -8600,6 +8855,7 @@ components: join: "#/components/schemas/FunctionJoin" json_unroll: "#/components/schemas/FunctionJsonUnroll" lake_export: "#/components/schemas/FunctionLakeExport" + lakehouse_engine_metrics_normalizer: "#/components/schemas/FunctionLakehouseEngineMetricsNormalizer" limit: "#/components/schemas/FunctionLimit" local_search_datatype_parser: "#/components/schemas/FunctionLocalSearchDatatypeParser" local_search_ruleset_runner: "#/components/schemas/FunctionLocalSearchRulesetRunner" @@ -8609,6 +8865,7 @@ components: lookup: "#/components/schemas/FunctionLookup" mask: "#/components/schemas/FunctionMask" metrics_export: "#/components/schemas/FunctionMetricsExport" + metrics_time_range_gate: "#/components/schemas/FunctionMetricsTimeRangeGate" mv_expand: "#/components/schemas/FunctionMvExpand" mv_pull: "#/components/schemas/FunctionMvPull" notification_policies: "#/components/schemas/FunctionNotificationPolicies" @@ -8982,6 +9239,47 @@ components: title: Group ID description: Unique identifier of the group that contains the Pipeline Function. type: string + PipelineFunctionDetectionRules: + type: object + required: + - id + - conf + additionalProperties: false + properties: + filter: + title: Filter + description: JavaScript expression that selects data to pass through the Function. + type: string + id: + title: ID + description: Identifier of the Function. Always detection_rules + type: string + enum: + - detection_rules + examples: + - detection_rules + description: + title: Description + description: Brief description of the Pipeline function. + type: string + disabled: + title: Disabled + description: If true, disable the Pipeline function so that events + are not passed through it. Otherwise, false. + type: boolean + final: + title: Final + description: If true, stop passing events to downstream Pipeline + Functions after the Function executes. Otherwise, + false. + type: boolean + conf: + $ref: "#/components/schemas/FunctionConfSchemaDetectionRules" + description: Configuration specific to the Pipeline Function. + groupId: + title: Group ID + description: Unique identifier of the group that contains the Pipeline Function. + type: string PipelineFunctionDistinct: type: object required: @@ -9756,6 +10054,48 @@ components: title: Group ID description: Unique identifier of the group that contains the Pipeline Function. type: string + PipelineFunctionLakehouseEngineMetricsNormalizer: + type: object + required: + - id + - conf + additionalProperties: false + properties: + filter: + title: Filter + description: JavaScript expression that selects data to pass through the Function. + type: string + id: + title: ID + description: Identifier of the Function. Always + lakehouse_engine_metrics_normalizer + type: string + enum: + - lakehouse_engine_metrics_normalizer + examples: + - lakehouse_engine_metrics_normalizer + description: + title: Description + description: Brief description of the Pipeline function. + type: string + disabled: + title: Disabled + description: If true, disable the Pipeline function so that events + are not passed through it. Otherwise, false. + type: boolean + final: + title: Final + description: If true, stop passing events to downstream Pipeline + Functions after the Function executes. Otherwise, + false. + type: boolean + conf: + $ref: "#/components/schemas/FunctionConfSchemaLakehouseEngineMetricsNormalizer" + description: Configuration specific to the Pipeline Function. + groupId: + title: Group ID + description: Unique identifier of the group that contains the Pipeline Function. + type: string PipelineFunctionLimit: type: object required: @@ -10140,6 +10480,48 @@ components: title: Group ID description: Unique identifier of the group that contains the Pipeline Function. type: string + PipelineFunctionMetricsTimeRangeGate: + type: object + required: + - id + - conf + additionalProperties: false + properties: + filter: + title: Filter + description: JavaScript expression that selects data to pass through the Function. + type: string + id: + title: ID + description: Identifier of the Function. Always + metrics_time_range_gate + type: string + enum: + - metrics_time_range_gate + examples: + - metrics_time_range_gate + description: + title: Description + description: Brief description of the Pipeline function. + type: string + disabled: + title: Disabled + description: If true, disable the Pipeline function so that events + are not passed through it. Otherwise, false. + type: boolean + final: + title: Final + description: If true, stop passing events to downstream Pipeline + Functions after the Function executes. Otherwise, + false. + type: boolean + conf: + $ref: "#/components/schemas/FunctionConfSchemaMetricsTimeRangeGate" + description: Configuration specific to the Pipeline Function. + groupId: + title: Group ID + description: Unique identifier of the group that contains the Pipeline Function. + type: string PipelineFunctionMvExpand: type: object required: @@ -11627,6 +12009,7 @@ components: - $ref: "#/components/schemas/PipelineFunctionClone" - $ref: "#/components/schemas/PipelineFunctionCode" - $ref: "#/components/schemas/PipelineFunctionComment" + - $ref: "#/components/schemas/PipelineFunctionDetectionRules" - $ref: "#/components/schemas/PipelineFunctionDistinct" - $ref: "#/components/schemas/PipelineFunctionDnsLookup" - $ref: "#/components/schemas/PipelineFunctionDrop" @@ -11645,6 +12028,7 @@ components: - $ref: "#/components/schemas/PipelineFunctionJoin" - $ref: "#/components/schemas/PipelineFunctionJsonUnroll" - $ref: "#/components/schemas/PipelineFunctionLakeExport" + - $ref: "#/components/schemas/PipelineFunctionLakehouseEngineMetricsNormalizer" - $ref: "#/components/schemas/PipelineFunctionLimit" - $ref: "#/components/schemas/PipelineFunctionLocalSearchDatatypeParser" - $ref: "#/components/schemas/PipelineFunctionLocalSearchRulesetRunner" @@ -11654,6 +12038,7 @@ components: - $ref: "#/components/schemas/PipelineFunctionLookup" - $ref: "#/components/schemas/PipelineFunctionMask" - $ref: "#/components/schemas/PipelineFunctionMetricsExport" + - $ref: "#/components/schemas/PipelineFunctionMetricsTimeRangeGate" - $ref: "#/components/schemas/PipelineFunctionMvExpand" - $ref: "#/components/schemas/PipelineFunctionMvPull" - $ref: "#/components/schemas/PipelineFunctionNotificationPolicies" @@ -11699,6 +12084,7 @@ components: clone: "#/components/schemas/PipelineFunctionClone" code: "#/components/schemas/PipelineFunctionCode" comment: "#/components/schemas/PipelineFunctionComment" + detection_rules: "#/components/schemas/PipelineFunctionDetectionRules" distinct: "#/components/schemas/PipelineFunctionDistinct" dns_lookup: "#/components/schemas/PipelineFunctionDnsLookup" drop: "#/components/schemas/PipelineFunctionDrop" @@ -11717,6 +12103,7 @@ components: join: "#/components/schemas/PipelineFunctionJoin" json_unroll: "#/components/schemas/PipelineFunctionJsonUnroll" lake_export: "#/components/schemas/PipelineFunctionLakeExport" + lakehouse_engine_metrics_normalizer: "#/components/schemas/PipelineFunctionLakehouseEngineMetricsNormalizer" limit: "#/components/schemas/PipelineFunctionLimit" local_search_datatype_parser: "#/components/schemas/PipelineFunctionLocalSearchDatatypeParser" local_search_ruleset_runner: "#/components/schemas/PipelineFunctionLocalSearchRulesetRunner" @@ -11726,6 +12113,7 @@ components: lookup: "#/components/schemas/PipelineFunctionLookup" mask: "#/components/schemas/PipelineFunctionMask" metrics_export: "#/components/schemas/PipelineFunctionMetricsExport" + metrics_time_range_gate: "#/components/schemas/PipelineFunctionMetricsTimeRangeGate" mv_expand: "#/components/schemas/PipelineFunctionMvExpand" mv_pull: "#/components/schemas/PipelineFunctionMvPull" notification_policies: "#/components/schemas/PipelineFunctionNotificationPolicies" @@ -11965,9 +12353,7 @@ components: expression: type: string title: Extractor Expression - description: "A JavaScript expression that accesses a corresponding -  through the value variable and evaluates the token to - populate event fields. Example: {date: new Date(+value*1000)}" + description: "A JavaScript expression that accesses a corresponding  through the value variable and evaluates the token to populate event fields. Example: {date: new Date(+value*1000)}" description: 'Extractors allow use of template tokens as context for expressions that enrich discovery results. For example, given a template /path/${epoch}, an extractor under key "epoch" with an expression @@ -11980,15 +12366,11 @@ components: includeMetadata: type: boolean title: Include metadata - description: "Include Azure Blob metadata in collected events. In each event, - metadata will be located at: __collectible.metadata." + description: "Include Azure Blob metadata in collected events. In each event, metadata will be located at: __collectible.metadata." includeTags: type: boolean title: Include tags - description: "Include Azure Blob tags in collected events. In each event, tags - will be located at: __collectible.tags. Disable this feature when - using a Shared Access Signature Connection String, to prevent - errors." + description: "Include Azure Blob tags in collected events. In each event, tags will be located at: __collectible.tags. Disable this feature when using a Shared Access Signature Connection String, to prevent errors." maxBatchSize: type: number title: Batch size limit @@ -12176,11 +12558,7 @@ components: queryValidationEnabled: type: boolean title: Validate Query - description: "Enforces a basic query validation that allows only a single - 'select' statement. Disable for more complex queries or when using - semicolons. Caution: Disabling query validation allows DDL and DML - statements to be executed, which could be destructive to your - database." + description: "Enforces a basic query validation that allows only a single 'select' statement. Disable for more complex queries or when using semicolons. Caution: Disabling query validation allows DDL and DML statements to be executed, which could be destructive to your database." defaultBreakers: $ref: "#/components/schemas/HiddenDefaultBreakersOptionsDatabaseCollectorConf" description: Hidden Default Breakers @@ -12337,9 +12715,7 @@ components: type: string title: Bucket name minLength: 1 - description: "Name of the bucket to collect from. This value can be a constant - or a JavaScript expression that can only be evaluated at init time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`." + description: "Name of the bucket to collect from. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`." path: type: string title: Path @@ -12509,15 +12885,12 @@ components: type: object properties: collectMethod: - $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWit\ - hBody" + $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody" description: Discriminator value. collectBody: type: string title: Health check POST Body - description: "Template for POST body to send with the health check request. You - can reference parameters from the Discover response, using template - params of the form: ${variable}." + description: "Template for POST body to send with the health check request. You can reference parameters from the Discover response, using template params of the form: ${variable}." HealthCheckAuthenticationNone: type: object properties: @@ -12555,8 +12928,7 @@ components: type: object properties: authentication: - $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasic\ - Secret" + $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasicSecret" description: Discriminator value. credentialsSecret: type: string @@ -12640,8 +13012,7 @@ components: type: object properties: authentication: - $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLogin\ - Secret" + $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLoginSecret" description: Discriminator value. loginUrl: type: string @@ -12744,9 +13115,7 @@ components: refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, the Collector uses the refresh - token to obtain new access tokens without re-sending credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token @@ -12765,8 +13134,7 @@ components: servers require 'client_id' here. If not set, the Collector sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - th" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth" __template_loginUrl: type: string description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to @@ -12792,8 +13160,7 @@ components: type: object properties: authentication: - $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauth\ - Secret" + $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauthSecret" description: Discriminator value. loginUrl: type: string @@ -12840,9 +13207,7 @@ components: refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, the Collector uses the refresh - token to obtain new access tokens without re-sending credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token @@ -12861,8 +13226,7 @@ components: servers require 'client_id' here. If not set, the Collector sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" __template_loginUrl: type: string description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to @@ -12912,8 +13276,7 @@ components: type: object properties: discoverMethod: - $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWit\ - hBody" + $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody" description: Discriminator value. discoverBody: type: string @@ -12923,8 +13286,7 @@ components: type: object properties: discoverType: - $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverType\ - Http" + $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeHttp" description: Discriminator value. discoverUrl: type: string @@ -12932,8 +13294,7 @@ components: description: Expression to derive URL to use for the Discover operation (can be a constant). discoverMethod: - $ref: "#/components/schemas/DiscoverMethodOptionsHealthCheckDiscoveryDiscoverTy\ - peHttp" + $ref: "#/components/schemas/DiscoverMethodOptionsHealthCheckDiscoveryDiscoverTypeHttp" description: Discover HTTP method. discoverRequestHeaders: title: Discover Headers @@ -12944,8 +13305,7 @@ components: discoverDataField: type: string title: Discover Data Field - description: "Path to field in the response object which contains discover - results (e.g.: level1.name), leave blank if the result is an array." + description: "Path to field in the response object which contains discover results (e.g.: level1.name), leave blank if the result is an array." __template_discoverUrl: type: string description: Binds 'discoverUrl' to a variable for dynamic value resolution. Set @@ -12962,27 +13322,20 @@ components: - discoverMethod allOf: - oneOf: - - $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodG\ - et" - - $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodP\ - ost" - - $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodP\ - ostWithBody" + - $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodGet" + - $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPost" + - $ref: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody" discriminator: propertyName: discoverMethod mapping: - get: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodGe\ - t" - post: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodP\ - ost" - post_with_body: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDisco\ - verMethodPostWithBody" + get: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodGet" + post: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPost" + post_with_body: "#/components/schemas/HealthCheckDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody" HealthCheckDiscoveryDiscoverTypeJson: type: object properties: discoverType: - $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverType\ - Json" + $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeJson" description: Discriminator value. manualDiscoverResult: type: string @@ -12992,18 +13345,14 @@ components: discoverDataField: type: string title: Discover data field - description: "Within the response JSON, name of the field or array element to - pull results from. Leave blank if the result is an array of values. - Sample entry: items, json: { items: [{id: 'first'},{id: 'second'}] - }" + description: "Within the response JSON, name of the field or array element to pull results from. Leave blank if the result is an array of values. Sample entry: items, json: { items: [{id: 'first'},{id: 'second'}] }" required: - manualDiscoverResult HealthCheckDiscoveryDiscoverTypeList: type: object properties: discoverType: - $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverType\ - List" + $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeList" description: Discriminator value. itemList: type: array @@ -13155,8 +13504,7 @@ components: (group-scoped). Variable value overrides 'discoverUrl' at runtime. discoverMethod: - $ref: "#/components/schemas/DiscoverMethodOptionsHealthCheckDiscoveryDiscoverTy\ - peHttp" + $ref: "#/components/schemas/DiscoverMethodOptionsHealthCheckDiscoveryDiscoverTypeHttp" description: Discover HTTP method. discoverRequestHeaders: title: Discover Headers @@ -13167,9 +13515,7 @@ components: discoverDataField: type: string title: Discover Data Field - description: "Path to field in the response object which contains discover - results (e.g.: level1.name), leave blank if the result is an - array." + description: "Path to field in the response object which contains discover results (e.g.: level1.name), leave blank if the result is an array." __template_discoverDataField: type: string description: Binds 'discoverDataField' to a variable for dynamic value @@ -13386,9 +13732,7 @@ components: refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, the Collector uses the refresh - token to obtain new access tokens without re-sending credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token @@ -13412,8 +13756,7 @@ components: servers require 'client_id' here. If not set, the Collector sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - th" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth" textSecret: type: string title: Client secret value (text secret) @@ -13495,16 +13838,12 @@ components: type: object properties: collectMethod: - $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWit\ - hBody" + $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody" description: Discriminator value. collectBody: type: string title: Collect POST body - description: "Template for POST body to send with the Collect request. Reference - global variables, functions, or parameters from the Discover - response using template params: `${C.vars.myVar}`, or - `${Date.now()}`, `${param}`" + description: "Template for POST body to send with the Collect request. Reference global variables, functions, or parameters from the Discover response using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`" required: - collectBody RestCollectMethodOther: @@ -13520,10 +13859,7 @@ components: collectBody: type: string title: Collect body - description: "Template for body to send with the Collect request. Reference - global variables, functions, or parameters from the Discover - response using template parameters: `${C.vars.myVar}`, or - `${Date.now()}`, `${param}`" + description: "Template for body to send with the Collect request. Reference global variables, functions, or parameters from the Discover response using template parameters: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`" collectRequestParams: title: Collect parameters type: array @@ -13559,8 +13895,7 @@ components: type: object properties: authentication: - $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasic\ - Secret" + $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasicSecret" description: Discriminator value. credentialsSecret: type: string @@ -13650,8 +13985,7 @@ components: type: object properties: authentication: - $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLogin\ - Secret" + $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationLoginSecret" description: Discriminator value. loginUrl: type: string @@ -13761,9 +14095,7 @@ components: refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, the Collector uses the refresh - token to obtain new access tokens without re-sending credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token @@ -13782,8 +14114,7 @@ components: servers require 'client_id' here. If not set, the Collector sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - th" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth" __template_loginUrl: type: string description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to @@ -13809,8 +14140,7 @@ components: type: object properties: authentication: - $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauth\ - Secret" + $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationOauthSecret" description: Discriminator value. loginUrl: type: string @@ -13862,9 +14192,7 @@ components: refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, the Collector uses the refresh - token to obtain new access tokens without re-sending credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token @@ -13883,8 +14211,7 @@ components: servers require 'client_id' here. If not set, the Collector sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" __template_refreshUrl: type: string description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set @@ -14001,8 +14328,7 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeResponseBody" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseBody" description: Resource type identifier. attribute: type: @@ -14032,8 +14358,7 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeResponseHeader" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeader" description: Resource type identifier. attribute: type: @@ -14057,8 +14382,7 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeResponseHeaderLink" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeaderLink" description: Resource type identifier. nextRelationAttribute: type: string @@ -14085,15 +14409,12 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeRequestOffset" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestOffset" description: Resource type identifier. offsetField: type: string title: Offset field name - description: "Query string parameter that sets the index from which to begin - returning records. Example: - /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the index from which to begin returning records. Example: /api/v1/query?term=cribl&limit=100&offset=0" offset: type: number title: Starting offset @@ -14102,8 +14423,7 @@ components: limitField: type: string title: Limit field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&limit=100&offset=0" limit: type: number title: Record limit @@ -14135,14 +14455,12 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeRequestPage" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestPage" description: Resource type identifier. pageField: type: string title: Page number field name - description: "Query string parameter that sets the page index to be returned. - Example: /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the page index to be returned. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" page: type: number title: Starting page number @@ -14151,9 +14469,7 @@ components: sizeField: type: string title: Page size field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: - /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" size: type: number title: Record limit @@ -14214,16 +14530,12 @@ components: type: object properties: discoverMethod: - $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWit\ - hBody" + $ref: "#/components/schemas/CollectMethodOptionsHealthCheckCollectMethodPostWithBody" description: Discriminator value. discoverBody: type: string title: Discover POST body - description: "Template for POST body to send with the discover request. To - reference global variables or functions, use template parameters: `{ - myVar: ${C.vars.myVar}, secret: ${C.Secret('mySecret','text').value} - }`" + description: "Template for POST body to send with the discover request. To reference global variables or functions, use template parameters: `{ myVar: ${C.vars.myVar}, secret: ${C.Secret('mySecret','text').value} }`" required: - discoverBody RestDiscoveryDiscoverTypeHttpDiscoverMethodOther: @@ -14252,8 +14564,7 @@ components: type: object properties: discoverType: - $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverType\ - Http" + $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeHttp" description: Discriminator value. discoverUrl: type: string @@ -14276,8 +14587,7 @@ components: discoverDataField: type: string title: Discover data field - description: "Path to field in the response object that contains discovery - results (ex: level1.name). Leave blank if the result is an array." + description: "Path to field in the response object that contains discovery results (ex: level1.name). Leave blank if the result is an array." enableStrictDiscoverParsing: type: boolean title: Strict discover response parsing @@ -14295,14 +14605,7 @@ components: formatResultCode: type: string title: Format discover result - description: "Custom JavaScript code to format the discover result through the - __e variable which is a JSON object or array containing the original - discover results. The object or array passed should be manipulated - to contain the desired discover results, i.e.: __e['myResult'] = - [{lat: -1.1234, long: 2.345, zip: 11111},{lat: -1.235, long 2.346, - zip: 22222}] or ['11111','22222']. Caution: This function is - evaluated in an unprotected context, allowing you to execute almost - any JavaScript code." + description: "Custom JavaScript code to format the discover result through the __e variable which is a JSON object or array containing the original discover results. The object or array passed should be manipulated to contain the desired discover results, i.e.: __e['myResult'] = [{lat: -1.1234, long: 2.345, zip: 11111},{lat: -1.235, long 2.346, zip: 22222}] or ['11111','22222']. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code." __template_discoverUrl: type: string description: Binds 'discoverUrl' to a variable for dynamic value resolution. Set @@ -14315,23 +14618,20 @@ components: - oneOf: - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodGet" - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPost" - - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPostWith\ - Body" + - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody" - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodOther" discriminator: propertyName: discoverMethod mapping: get: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodGet" post: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPost" - post_with_body: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMeth\ - odPostWithBody" + post_with_body: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodPostWithBody" other: "#/components/schemas/RestDiscoveryDiscoverTypeHttpDiscoverMethodOther" RestDiscoveryDiscoverTypeJson: type: object properties: discoverType: - $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverType\ - Json" + $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeJson" description: Discriminator value. manualDiscoverResult: type: string @@ -14341,18 +14641,14 @@ components: discoverDataField: type: string title: Discover data field - description: "Within the response JSON, the name of the field to pull results - from, typically a JSON array. Leave blank if the result itself is an - array of values. Sample entry: items, json: { items: [{id: - 'first'},{id: 'second'}] }" + description: "Within the response JSON, the name of the field to pull results from, typically a JSON array. Leave blank if the result itself is an array of values. Sample entry: items, json: { items: [{id: 'first'},{id: 'second'}] }" required: - manualDiscoverResult RestDiscoveryDiscoverTypeList: type: object properties: discoverType: - $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverType\ - List" + $ref: "#/components/schemas/DiscoverTypeOptionsHealthCheckDiscoveryDiscoverTypeList" description: Discriminator value. itemList: type: array @@ -14383,8 +14679,7 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeResponseBody" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseBody" description: Resource type identifier. attribute: type: @@ -14414,8 +14709,7 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeResponseHeader" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeader" description: Resource type identifier. attribute: type: @@ -14439,8 +14733,7 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeResponseHeaderLink" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeaderLink" description: Resource type identifier. nextRelationAttribute: type: string @@ -14467,15 +14760,12 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeRequestOffset" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestOffset" description: Resource type identifier. offsetField: type: string title: Offset field name - description: "Query string parameter that sets the index from which to begin - returning records. Example: - /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the index from which to begin returning records. Example: /api/v1/query?term=cribl&limit=100&offset=0" offset: type: number title: Starting offset @@ -14484,8 +14774,7 @@ components: limitField: type: string title: Limit field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&limit=100&offset=0" limit: type: number title: Record limit @@ -14517,14 +14806,12 @@ components: type: object properties: type: - $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationT\ - ypeRequestPage" + $ref: "#/components/schemas/TypeOptionsRestDiscoveryDiscoverTypeHttpPaginationTypeRequestPage" description: Resource type identifier. pageField: type: string title: Page number field name - description: "Query string parameter that sets the page index to be returned. - Example: /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the page index to be returned. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" page: type: number title: Starting page number @@ -14533,9 +14820,7 @@ components: sizeField: type: string title: Page size field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: - /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" size: type: number title: Record limit @@ -14645,8 +14930,7 @@ components: multiplier: type: number title: Backoff multiplier - description: "Base for exponential backoff. Example: base 2 means that retries - will occur after 2, then 4, then 8 seconds, and so on." + description: "Base for exponential backoff. Example: base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on." minimum: 1 maximum: 20 maxIntervalMs: @@ -14737,9 +15021,7 @@ components: discoverDataField: type: string title: Discover data field - description: "Path to field in the response object that contains discovery - results (ex: level1.name). Leave blank if the result is an - array." + description: "Path to field in the response object that contains discovery results (ex: level1.name). Leave blank if the result is an array." enableStrictDiscoverParsing: type: boolean title: Strict discover response parsing @@ -14813,8 +15095,7 @@ components: - type properties: type: - $ref: "#/components/schemas/PaginationOptionsRestDiscoveryDiscoverTypeHttpPagin\ - ation" + $ref: "#/components/schemas/PaginationOptionsRestDiscoveryDiscoverTypeHttpPagination" description: Pagination maxPages: type: number @@ -14843,9 +15124,7 @@ components: offsetField: type: string title: Offset field name - description: "Query string parameter that sets the index from which to begin - returning records. Example: - /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the index from which to begin returning records. Example: /api/v1/query?term=cribl&limit=100&offset=0" offset: type: number title: Starting offset @@ -14854,9 +15133,7 @@ components: limitField: type: string title: Limit field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: - /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&limit=100&offset=0" limit: type: number title: Record limit @@ -14875,8 +15152,7 @@ components: pageField: type: string title: Page number field name - description: "Query string parameter that sets the page index to be returned. - Example: /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the page index to be returned. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" page: type: number title: Starting page number @@ -14885,9 +15161,7 @@ components: sizeField: type: string title: Page size field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: - /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" size: type: number title: Record limit @@ -15118,9 +15392,7 @@ components: refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, the Collector uses the refresh - token to obtain new access tokens without re-sending credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, the Collector uses the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token @@ -15144,8 +15416,7 @@ components: servers require 'client_id' here. If not set, the Collector sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - th" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauth" textSecret: type: string title: Client secret value (text secret) @@ -15385,8 +15656,7 @@ components: endpoint: type: string title: Endpoint - description: "Must point to an S3-compatible endpoint. If empty, defaults to an - AWS region-specific endpoint. " + description: "Must point to an S3-compatible endpoint. If empty, defaults to an AWS region-specific endpoint. " enableAssumeRole: type: boolean title: Enable Assume Role @@ -15597,8 +15867,7 @@ components: type: object properties: authentication: - $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasic\ - Secret" + $ref: "#/components/schemas/AuthenticationOptionsHealthCheckAuthenticationBasicSecret" description: Discriminator value. credentialsSecret: type: string @@ -15755,18 +16024,15 @@ components: search: type: string title: Search - description: "Examples: 'index=myAppLogs level=error channel=myApp' OR '| mstats - avg(myStat) as myStat WHERE index=myStatsIndex.'" + description: "Examples: 'index=myAppLogs level=error channel=myApp' OR '| mstats avg(myStat) as myStat WHERE index=myStatsIndex.'" earliest: title: Earliest type: string - description: "The earliest time boundary for the search. Can be an exact or - relative time. Examples: '2022-01-14T12:00:00Z' or '-16m@m'" + description: "The earliest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-16m@m'" latest: title: Latest type: string - description: "The latest time boundary for the search. Can be an exact or - relative time. Examples: '2022-01-14T12:00:00Z' or '-1m@m'" + description: "The latest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-1m@m'" endpoint: type: string title: Search endpoint @@ -16008,6 +16274,7 @@ components: type: string enum: - groups + - insights-apps - datasets - dataset-providers - projects @@ -16016,6 +16283,7 @@ components: - notebooks - notebook-templates - apps + - secret-folders title: RbacResource x-speakeasy-unknown-values: allow ResourcePolicy: @@ -16048,8 +16316,11 @@ components: type: array items: $ref: "#/components/schemas/ResourcePolicy" + description: List of resource policies that define the access permissions for + this member. user: type: string + description: Username of the member whose access control entries are listed. required: - perms - user @@ -16061,8 +16332,11 @@ components: type: array items: $ref: "#/components/schemas/ResourcePolicy" + description: List of resource policies that define the access permissions for + this team. team: type: string + description: Name of the team whose access control entries are listed. required: - perms - team @@ -16083,6 +16357,7 @@ components: - oracle - postgres - sqlserver + - teradata title: DatabaseConnectionType x-speakeasy-unknown-values: allow SecureVersion: @@ -16167,12 +16442,21 @@ components: - 10000 minimum: 1000 maximum: 60000 + credentialsSecret: + type: string + description: Name of the stored credentials secret containing username and + password for SQL Server configObj authentication. + examples: + - mssql-production-credentials credsSecrets: type: string description: Name of the stored credentials secret containing username and password. Used with Oracle connections. examples: - oracle-production-credentials + database: + type: string + description: Database to connect to instead of the server default. databaseType: $ref: "#/components/schemas/DatabaseConnectionType" description: Type of database engine for the connection. @@ -16183,12 +16467,22 @@ components: description: Brief description of the Database Connection. examples: - Production MySQL database for customer data + host: + type: string + description: Hostname of the server to connect to. + examples: + - |- + 'myId-dt5egqq7iq1hj6kh.env.trial.example.com' + Hostname, currently intended for Teradata id: type: string description: Unique identifier for the Database Connection. examples: - mysql-prod-db pattern: ^[a-zA-Z0-9_\\-]+$ + logOnMechanism: + type: string + description: Log On Mechanism for databases that support multiple, like Teradata. password: type: string description: Database password for authentication. Used with Oracle connections. @@ -16201,6 +16495,12 @@ components: examples: - 30000 minimum: 1000 + sslmode: + type: string + description: HTTPS/TLS connection mode for Teradata. Controls certificate + verification behavior. + examples: + - VERIFY-FULL tags: type: string description: Comma-separated list of tags for categorizing and filtering @@ -16273,10 +16573,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/FunctionResponse" PaginatedFunctionResponse: @@ -16287,12 +16587,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/FunctionResponse" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -16352,8 +16653,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -16388,9 +16688,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ metadata: type: array @@ -16461,8 +16759,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -16488,8 +16785,7 @@ components: topics: type: array title: Topic - description: "Topic to subscribe to. Warning: To optimize performance, Cribl - suggests subscribing each Kafka Source to a single topic only." + description: "Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only." minItems: 1 items: type: string @@ -16651,6 +16947,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -16729,8 +17031,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -16756,8 +17057,7 @@ components: topics: type: array title: Topic - description: "Topic to subscribe to. Warning: To optimize performance, Cribl - suggests subscribing each Kafka Source to a single topic only." + description: "Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only." minItems: 1 items: type: string @@ -16963,6 +17263,12 @@ components: socket minimum: 0 maximum: 100 + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -17081,8 +17387,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -17107,8 +17412,7 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: type: string tls: @@ -17117,10 +17421,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -17216,10 +17517,35 @@ components: authTokensExt: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: - $ref: "#/components/schemas/AuthTokensExtConfInputHttp" + type: object + oneOf: + - $ref: "#/components/schemas/InputHttpAuthTokensExtItemsType" + - $ref: "#/components/schemas/InputHttpAuthTypeSecretConstraint" + properties: + authType: + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" + description: Select Manual to enter an auth token directly, or select Secret to + use a text secret to authenticate + tokenSecret: + type: string + title: Token secret (text secret) + description: Select or create a stored text secret + token: + type: string + title: Token + description: "Shared secret to be provided by any client (Authorization: )" + description: + type: string + title: Description + description: Description + metadata: + type: array + title: Fields + description: Fields to add to events referencing this token + items: + $ref: "#/components/schemas/MetadataConfInputCollection" description: type: string title: Description @@ -17311,8 +17637,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -17398,6 +17723,12 @@ components: out, as is, to the Pipelines minimum: 10 maximum: 43200000 + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). authTokens: type: array title: Auth tokens @@ -17405,9 +17736,15 @@ components: unauthorized access is permitted. items: type: object - required: - - token properties: + authType: + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" + description: Select Manual to enter an auth token directly, or select Secret to + use a text secret to authenticate + tokenSecret: + type: string + title: Token secret (text secret) + description: Select or create a stored text secret token: type: string title: Token @@ -17545,8 +17882,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -17567,19 +17903,15 @@ components: search: type: string title: Search - description: "Enter Splunk search here. Examples: 'index=myAppLogs level=error - channel=myApp' OR '| mstats avg(myStat) as myStat WHERE - index=myStatsIndex.'" + description: "Enter Splunk search here. Examples: 'index=myAppLogs level=error channel=myApp' OR '| mstats avg(myStat) as myStat WHERE index=myStatsIndex.'" earliest: title: Earliest type: string - description: "The earliest time boundary for the search. Can be an exact or - relative time. Examples: '2022-01-14T12:00:00Z' or '-16m@m'" + description: "The earliest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-16m@m'" latest: title: Latest type: string - description: "The latest time boundary for the search. Can be an exact or - relative time. Examples: '2022-01-14T12:00:00Z' or '-1m@m'" + description: "The latest time boundary for the search. Can be an exact or relative time. Examples: '2022-01-14T12:00:00Z' or '-1m@m'" cronSchedule: type: string title: Cron schedule @@ -17849,8 +18181,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -17875,15 +18206,14 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: type: object required: - token properties: authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate tokenSecret: @@ -17893,8 +18223,7 @@ components: token: type: string title: Token - description: "Shared secret to be provided by any client (Authorization: - )" + description: "Shared secret to be provided by any client (Authorization: )" enabled: type: boolean title: Enable token @@ -17925,10 +18254,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -18031,6 +18357,12 @@ components: out, as is, to the Pipelines minimum: 10 maximum: 43200000 + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). useFwdTimezone: type: boolean title: Use Universal Forwarder time zone (S2S only) @@ -18146,8 +18478,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -18163,11 +18494,7 @@ components: queueName: type: string title: Queue - description: "The storage account queue name blob notifications will be read - from. Value must be a JavaScript expression (which can evaluate to a - constant value), enclosed in quotes or backticks. Can be evaluated - only at initialization time. Example referencing a Global Variable: - `myQueue-${C.vars.myVar}`" + description: "The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`" fileFilter: type: string title: Filename filter @@ -18190,9 +18517,7 @@ components: maxMessages: type: number title: Message limit - description: "The maximum number of messages to return in a poll request. Azure - storage queues never returns more messages than this value (however, - fewer messages might be returned). Valid values: 1 to 32." + description: "The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32." minimum: 1 maximum: 32 servicePeriodSecs: @@ -18207,6 +18532,12 @@ components: title: Skip file on error description: Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors. + encoding: + type: string + title: Encoding + description: Character encoding to use when parsing ingested data. When not set, + @{product} will default to UTF-8 but may incorrectly interpret + multi-byte characters. metadata: type: array title: Fields @@ -18245,6 +18576,12 @@ components: authType: $ref: "#/components/schemas/AuthenticationMethodOptions" description: Authentication method + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -18328,6 +18665,207 @@ components: to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime. title: InputAzureBlob + InputAzureVnetFlowLog: + type: object + required: + - type + - queueName + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + enum: + - azure_vnet_flow_log + description: Connector type identifier. + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + queueName: + type: string + title: Queue + description: "The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`" + fileFilter: + type: string + title: Filename filter + description: "Regex matching file names to download and process. Defaults to: .*" + visibilityTimeout: + type: number + title: Visibility timeout (secs) + description: The duration (in seconds) that the received messages are hidden + from subsequent retrieve requests after being retrieved by a + ReceiveMessage request. + minimum: 0 + maximum: 604800 + numReceivers: + type: number + title: Number of receivers + description: How many receiver processes to run. The higher the number, the + better the throughput - at the expense of CPU overhead. + minimum: 1 + maximum: 100 + maxMessages: + type: number + title: Message limit + description: "The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32." + minimum: 1 + maximum: 32 + maxDequeueCount: + type: number + title: Max dequeue count + description: Number of times a non-matching message can be dequeued before it is + permanently deleted. At the default of 1, non-matching messages are + deleted immediately (same as standard Azure Blob source behavior). + Set higher to leave messages in the queue for other consumers. + minimum: 1 + maximum: 100 + servicePeriodSecs: + type: number + title: Service period (secs) + description: The duration (in seconds) which pollers should be validated and + restarted if exited + minimum: 1 + maximum: 10 + metadata: + type: array + title: Fields + description: Fields to add to events from this input + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + breakerRulesets: + type: array + title: Event Breaker rulesets + description: A list of event-breaking rulesets that will be applied, in order, + to the input data stream + items: + type: string + staleChannelFlushMs: + type: number + title: Event Breaker buffer timeout (ms) + description: How long (in milliseconds) the Event Breaker will wait for new data + to be sent to a specific channel before flushing the data stream + out, as is, to the Pipelines + minimum: 10 + maximum: 43200000 + authType: + $ref: "#/components/schemas/AuthenticationMethodOptionsClientAssertionClientAssertionrpc" + description: Authentication method + description: + type: string + title: Description + description: Optional description for this configuration. + textSecret: + type: string + title: Connection string (text secret) + description: Select or create a stored text secret + storageAccountName: + type: string + title: Storage account name + description: The name of your Azure storage account + tenantId: + type: string + title: Tenant ID + description: The service principal's tenant ID + clientId: + type: string + title: Client ID + description: The service principal's client ID + azureCloud: + type: string + title: Azure Cloud + description: The Azure cloud to use. Defaults to Azure Public Cloud. + endpointSuffix: + type: string + title: Endpoint suffix + description: Endpoint suffix for the service URL. Takes precedence over the + Azure Cloud setting. Defaults to core.windows.net. + clientTextSecret: + type: string + title: Client secret (text secret) + description: Select or create a stored text secret + certificate: + $ref: "#/components/schemas/CertificateType" + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_queueName: + type: string + description: Binds 'queueName' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'queueName' at runtime. + __template_storageAccountName: + type: string + description: Binds 'storageAccountName' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'storageAccountName' at runtime. + __template_tenantId: + type: string + description: Binds 'tenantId' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'tenantId' at runtime. + __template_clientId: + type: string + description: Binds 'clientId' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'clientId' at runtime. + __template_azureCloud: + type: string + description: Binds 'azureCloud' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'azureCloud' at runtime. + title: InputAzureVnetFlowLog InputElastic: type: object required: @@ -18377,8 +18915,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -18406,10 +18943,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -18689,8 +19223,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -18718,8 +19251,7 @@ components: topics: type: array title: Topic - description: "Topic to subscribe to. Warning: To optimize performance, Cribl - suggests subscribing each Kafka Source to a single topic only." + description: "Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only." minItems: 1 items: type: string @@ -18878,6 +19410,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -18956,8 +19494,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -18985,10 +19522,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -19058,18 +19592,12 @@ components: prometheusAPI: type: string title: Remote Write API endpoint - description: "Absolute path on which to listen for Grafana Agent's Remote Write - requests. Defaults to /api/prom/push, which will expand as: - 'http://:/api/prom/push'. Either this - field or 'Logs API endpoint' must be configured." + description: "Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured." pattern: ^/ lokiAPI: type: string title: Logs API endpoint - description: "Absolute path on which to listen for Loki logs requests. Defaults - to /loki/api/v1/push, which will (in this example) expand as: - 'http://:/loki/api/v1/push'. Either - this field or 'Remote Write API endpoint' must be configured." + description: "Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured." pattern: ^/ prometheusAuth: type: object @@ -19218,8 +19746,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -19247,10 +19774,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -19316,9 +19840,7 @@ components: lokiAPI: type: string title: Logs API endpoint - description: "Absolute path on which to listen for Loki logs requests. Defaults - to /loki/api/v1/push, which will (in this example) expand as: - 'http://:/loki/api/v1/push'." + description: "Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'." pattern: ^/ authType: $ref: "#/components/schemas/AuthenticationTypeOptionsLokiAuth" @@ -19428,8 +19950,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -19457,10 +19978,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -19526,9 +20044,7 @@ components: prometheusAPI: type: string title: Remote Write API endpoint - description: "Absolute path on which to listen for Prometheus requests. Defaults - to /write, which will expand as: - http://:/write." + description: "Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write." pattern: ^/ authType: $ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuth" @@ -19640,8 +20156,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -19665,9 +20180,7 @@ components: fieldPerMetric: type: boolean title: Use field per metric - description: "When enabled, each metric name is used as the event field key - (example: go_threads: 9) instead of the default _metric/_value - format." + description: "When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format." discoveryType: title: Discovery type type: string @@ -19752,11 +20265,7 @@ components: type: array title: Targets minItems: 1 - description: "List of Prometheus targets to pull metrics from. Values can be in - URL or host[:port] format. For example: - http://localhost:9090/metrics, localhost:9090, or localhost. In - cases where just host[:port] is specified, the endpoint will resolve - to 'http://host[:port]/metrics'." + description: "List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'." items: type: string title: Targets @@ -19862,8 +20371,7 @@ components: title: HTTP headers description: Extra headers to send with the discovery request items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" httpDiscoveryRejectUnauthorized: type: boolean title: Reject unauthorized certificates @@ -20011,8 +20519,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -20036,9 +20543,7 @@ components: fieldPerMetric: type: boolean title: Use field per metric - description: "When enabled, each metric name is used as the event field key - (example: go_threads: 9) instead of the default _metric/_value - format." + description: "When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format." discoveryType: title: Discovery type type: string @@ -20218,11 +20723,7 @@ components: serviceMonitorNamespace: type: string title: ServiceMonitor Namespace - description: "Namespace to search for ServiceMonitor resources. Leave empty to - search in all namespaces. Note: Kubernetes Service Monitor discovery - requires Cribl Edge version 4.18 or greater. Nodes running an older - version with this option configured will report an error due to - configuration schema validation failure." + description: "Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure." scrapeProtocolExpr: type: string title: Protocol @@ -20267,8 +20768,7 @@ components: title: HTTP headers description: Extra headers to send with the discovery request items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" httpDiscoveryRejectUnauthorized: type: boolean title: Reject unauthorized certificates @@ -20392,8 +20892,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -20494,11 +20993,7 @@ components: type: boolean title: Enabled description: Enabled - description: "Enable Microsoft 365 Management Activity API content types and - polling intervals. Polling intervals are used to set up search date - range and cron schedule, e.g.: */${interval} * * * *. Because of - this, intervals entered must be evenly divisible by 60 to give a - predictable schedule." + description: "Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule." ingestionLag: type: number title: Ingestion lag (minutes) @@ -20609,8 +21104,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -20705,11 +21199,7 @@ components: type: boolean title: Enabled description: Enabled - description: "Enable Microsoft 365 Service Communication API content types and - polling intervals. Polling intervals are used to set up search date - range and cron schedule, e.g.: */${interval} * * * *. Because of - this, intervals entered for current and historical status must be - evenly divisible by 60 to give a predictable schedule." + description: "Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule." retryRules: $ref: "#/components/schemas/RetryRulesTypeCodesEnableHeader" authType: @@ -20806,8 +21296,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -20834,15 +21323,11 @@ components: startDate: title: Date range start type: string - description: "Backward offset for the search range's head. (E.g.: -3h@h) Message - Trace data is delayed; this parameter (with Date range end) - compensates for delay and gaps." + description: "Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps." endDate: title: Date range end type: string - description: "Backward offset for the search range's tail. (E.g.: -2h@h) Message - Trace data is delayed; this parameter (with Date range start) - compensates for delay and gaps." + description: "Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps." timeout: type: number title: Request timeout (seconds) @@ -20874,9 +21359,7 @@ components: jobTimeout: title: Job timeout type: string - description: "Maximum time the job is allowed to run. Time unit defaults to - seconds if not specified (examples: 30, 45s, 15m). Enter 0 for - unlimited time." + description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: \d+[sm]?$ maxMissedKeepAlives: type: number @@ -21043,8 +21526,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -21072,15 +21554,11 @@ components: startDate: title: Date range start type: string - description: "Backward offset for the search range's head. (E.g.: -3h@h) - Microsoft Graph data is delayed; this parameter (with Date range - end) compensates for delay and gaps." + description: "Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps." endDate: title: Date range end type: string - description: "Backward offset for the search range's tail. (E.g.: -2h@h) - Microsoft Graph data is delayed; this parameter (with Date range - start) compensates for delay and gaps." + description: "Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps." timeout: type: number title: Request timeout (seconds) @@ -21116,9 +21594,7 @@ components: jobTimeout: title: Job timeout type: string - description: "Maximum time the job is allowed to run. Time unit defaults to - seconds if not specified (examples: 30, 45s, 15m). Enter 0 for - unlimited time." + description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: \d+[sm]?$ maxMissedKeepAlives: type: number @@ -21302,8 +21778,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -21319,10 +21794,7 @@ components: brokers: type: array title: Brokers - description: "List of Event Hubs Kafka brokers to connect to (example: - yourdomain.servicebus.windows.net:9093). The hostname can be found - in the host portion of the primary or secondary connection string in - Shared Access Policies." + description: "List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies." minItems: 1 items: type: string @@ -21330,9 +21802,7 @@ components: topics: type: array title: Event Hub name - description: "The name of the Event Hub (Kafka topic) to subscribe to. Warning: - To optimize performance, Cribl suggests subscribing each Event Hubs - Source to only a single topic." + description: "The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic." minItems: 1 items: type: string @@ -21491,6 +21961,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -21569,8 +22045,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -21705,16 +22180,8 @@ components: maxLength: 63 pattern: ^[a-z0-9](-?[a-z0-9])*$ authType: - title: Authentication method - type: string - enum: - - secret - - clientSecret - - clientCert - - clientAssertion - - clientAssertion_rpc + $ref: "#/components/schemas/AuthenticationMethodOptionsClientAssertionClientAssertionrpc" description: Authentication method - x-speakeasy-unknown-values: allow textSecret: type: string title: Connection string (text secret) @@ -21833,6 +22300,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -21894,8 +22367,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -21952,6 +22424,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -22024,8 +22502,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -22050,8 +22527,7 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: type: string tls: @@ -22060,10 +22536,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -22208,8 +22681,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -22230,10 +22702,7 @@ components: subscriptionName: type: string title: Subscription ID - description: "ID of the subscription to use when receiving events. When Monitor - subscription is enabled, the fully qualified subscription name must - be entered. Example: - projects/myProject/subscriptions/mySubscription" + description: "ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription" monitorSubscription: type: boolean title: Monitor subscription for new messages @@ -22296,6 +22765,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -22376,8 +22851,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -22461,8 +22935,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -22613,8 +23086,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -22650,10 +23122,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -22795,8 +23264,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -22821,8 +23289,7 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: type: string tls: @@ -22831,10 +23298,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -22932,9 +23396,18 @@ components: title: Auth tokens items: type: object - required: - - token + oneOf: + - $ref: "#/components/schemas/InputHttpAuthTokensExtItemsType" + - $ref: "#/components/schemas/InputHttpAuthTypeSecretConstraint" properties: + authType: + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" + description: Select Manual to enter an auth token directly, or select Secret to + use a text secret to authenticate + tokenSecret: + type: string + title: Token secret (text secret) + description: Select or create a stored text secret token: type: string title: Token @@ -23063,8 +23536,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -23140,7 +23612,7 @@ components: title: Enable load balancing description: Load balance traffic across all Worker Processes authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate description: @@ -23221,8 +23693,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -23350,8 +23821,7 @@ components: devices: type: array title: Interface filter - description: "Network interfaces to include/exclude. Examples: eth0, !lo. All - interfaces are included if this list is empty." + description: "Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty." items: type: string perInterface: @@ -23386,27 +23856,19 @@ components: devices: type: array title: Device filter - description: "Block devices to include/exclude. Examples: sda*, !loop*. - Wildcards and ! (not) operators are supported. All - devices are included if this list is empty." + description: "Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty." items: type: string mountpoints: type: array title: Mountpoint filter - description: "Filesystem mountpoints to include/exclude. Examples: /, /home, - !/proc*, !/tmp. Wildcards and ! (not) operators are - supported. All mountpoints are included if this list is - empty." + description: "Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty." items: type: string fstypes: type: array title: Filesystem type filter - description: "Filesystem types to include/exclude. Examples: ext4, !*tmpfs, - !squashfs. Wildcards and ! (not) operators are - supported. All types are included if this list is - empty." + description: "Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty." items: type: string perDevice: @@ -23492,14 +23954,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). - When limit is reached, older data will be deleted." + description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted." pattern: ^\d+\s*(?:\w{2})?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data (examples: 2h, 4d). When - limit is reached, older data will be deleted." + description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/DataCompressionFormatOptionsPersistence" @@ -23571,8 +24031,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -23714,14 +24173,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). - When limit is reached, older data will be deleted." + description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted." pattern: ^\d+\s*(?:\w{2})?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data (examples: 2h, 4d). When - limit is reached, older data will be deleted." + description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/DataCompressionFormatOptionsPersistence" @@ -23805,8 +24262,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -23866,14 +24322,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). - When limit is reached, older data will be deleted." + description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted." pattern: ^\d+\s*(?:\w{2})?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data (examples: 2h, 4d). When - limit is reached, older data will be deleted." + description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/DataCompressionFormatOptionsPersistence" @@ -23944,8 +24398,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -24091,8 +24544,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -24178,8 +24630,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -24343,9 +24794,7 @@ components: volumes: type: array title: Volume filter - description: "Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards - and ! (not) operators are supported. All volumes are - included if this list is empty." + description: "Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty." items: type: string process: @@ -24373,14 +24822,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). - When limit is reached, older data will be deleted." + description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted." pattern: ^\d+\s*(?:\w{2})?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data (examples: 2h, 4d). When - limit is reached, older data will be deleted." + description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/DataCompressionFormatOptionsPersistence" @@ -24461,8 +24908,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -24478,13 +24924,7 @@ components: queueName: type: string title: Queue - description: "The name, URL, or ARN of the SQS queue to read notifications from. - When a non-AWS URL is specified, format must be: - '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value - must be a JavaScript expression (which can evaluate to a constant - value), enclosed in quotes or backticks. Can be evaluated only at - init time. Example referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." fileFilter: type: string title: Filename filter @@ -24538,9 +24978,7 @@ components: maxMessages: type: number title: Message limit - description: "The maximum number of messages SQS should return in a poll - request. Amazon SQS never returns more messages than this value - (however, fewer messages might be returned). Valid values: 1 to 10." + description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10." minimum: 1 maximum: 10 visibilityTimeout: @@ -24810,8 +25248,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -24839,10 +25276,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -25046,8 +25480,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -25150,8 +25583,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -25176,8 +25608,7 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: type: string tls: @@ -25186,10 +25617,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -25267,6 +25695,12 @@ components: out, as is, to the Pipelines minimum: 10 maximum: 43200000 + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). metadata: type: array title: Fields @@ -25292,16 +25726,40 @@ components: authTokensExt: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: - $ref: "#/components/schemas/AuthTokensExtConfInputHttp" + type: object + oneOf: + - required: + - token + - $ref: "#/components/schemas/InputHttpAuthTypeSecretConstraint" + properties: + authType: + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" + description: Select Manual to enter an auth token directly, or select Secret to + use a text secret to authenticate + tokenSecret: + type: string + title: Token secret (text secret) + description: Select or create a stored text secret + token: + type: string + title: Token + description: "Shared secret to be provided by any client (Authorization: )" + description: + type: string + title: Description + description: Description + metadata: + type: array + title: Fields + description: Fields to add to events referencing this token + items: + $ref: "#/components/schemas/MetadataConfInputCollection" accessControlAllowOrigin: title: CORS allowed origins type: array - description: "HTTP origins allowed to send CORS requests (example: - https://pivot.claude.ai). Supports wildcards. Leave empty to disable - CORS. Note: IP allowlist/denylist rules are applied before CORS." + description: "HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS." minItems: 0 items: type: string @@ -25434,8 +25892,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -25580,6 +26037,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -25695,8 +26158,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -25716,13 +26178,7 @@ components: fullFidelity: type: boolean title: Full fidelity - description: "Include granular metrics. Disabling this will drop the following - metrics events: - `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, - `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, - `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, - `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_event\ - s)`." + description: "Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`." metadata: type: array title: Fields @@ -25793,8 +26249,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -25850,11 +26305,7 @@ components: udpSocketRxBufSize: type: number title: UDP socket buffer size (bytes) - description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. - This value tells the operating system how many bytes can be buffered - in the kernel before events are dropped. Leave blank to use the OS - default. Caution: Increasing this value will affect OS memory - utilization." + description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization." minimum: 256 maximum: 4294967295 description: @@ -25932,8 +26383,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -25949,13 +26399,7 @@ components: queueName: type: string title: Queue - description: "The name, URL, or ARN of the SQS queue to read notifications from. - When a non-AWS URL is specified, format must be: - '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value - must be a JavaScript expression (which can evaluate to a constant - value), enclosed in quotes or backticks. Can be evaluated only at - init time. Example referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." fileFilter: type: string title: Filename filter @@ -26009,9 +26453,7 @@ components: maxMessages: type: number title: Message limit - description: "The maximum number of messages SQS should return in a poll - request. Amazon SQS never returns more messages than this value - (however, fewer messages might be returned). Valid values: 1 to 10." + description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10." minimum: 1 maximum: 10 visibilityTimeout: @@ -26127,6 +26569,12 @@ components: title: Tag after processing description: Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions. + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -26297,8 +26745,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -26314,13 +26761,7 @@ components: queueName: type: string title: Queue - description: "The name, URL, or ARN of the SQS queue to read notifications from. - When a non-AWS URL is specified, format must be: - '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value - must be a JavaScript expression (which can evaluate to a constant - value), enclosed in quotes or backticks. Can be evaluated only at - init time. Example referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." fileFilter: type: string title: Filename filter @@ -26374,9 +26815,7 @@ components: maxMessages: type: number title: Message limit - description: "The maximum number of messages SQS should return in a poll - request. Amazon SQS never returns more messages than this value - (however, fewer messages might be returned). Valid values: 1 to 10." + description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10." minimum: 1 maximum: 10 visibilityTimeout: @@ -26671,8 +27110,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -26749,10 +27187,26 @@ components: title: Authentication protocol description: Authentication protocol x-speakeasy-unknown-values: allow + authKeyType: + enum: + - manual + - secret + type: string + x-speakeasy-enum-descriptions: + - Manual + - Secret + title: V3 authentication key type + description: Select Manual to enter the key directly, or Secret to use a stored + text secret + x-speakeasy-unknown-values: allow authKey: type: string title: V3 authentication key description: V3 authentication key + authKeySecret: + type: string + title: V3 authentication key (text secret) + description: Select or create a stored text secret privProtocol: enum: - none @@ -26770,10 +27224,26 @@ components: title: Privacy protocol description: Privacy protocol x-speakeasy-unknown-values: allow + privKeyType: + enum: + - manual + - secret + type: string + x-speakeasy-enum-descriptions: + - Manual + - Secret + title: V3 privacy key type + description: Select Manual to enter the key directly, or Secret to use a stored + text secret + x-speakeasy-unknown-values: allow privKey: type: string title: V3 privacy key description: V3 privacy key + privKeySecret: + type: string + title: V3 privacy key (text secret) + description: Select or create a stored text secret maxBufferSize: type: number title: Buffer size limit (events) @@ -26792,11 +27262,7 @@ components: udpSocketRxBufSize: type: number title: UDP socket buffer size (bytes) - description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. - This value tells the operating system how many bytes can be buffered - in the kernel before events are dropped. Leave blank to use the OS - default. Caution: Increasing this value will affect OS memory - utilization." + description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization." minimum: 256 maximum: 4294967295 varbindsWithTypes: @@ -26882,8 +27348,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -26911,10 +27376,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -27013,8 +27475,9 @@ components: authMethodsExt: type: array title: Auth methods - description: Shared secrets to authenticate clients. Supports Bearer tokens and - Basic auth. If empty, unauthenticated access is permitted. + description: Shared secrets to authenticate clients. Supports Bearer tokens, + Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, + unauthenticated access is permitted. minItems: 0 items: type: object @@ -27029,11 +27492,13 @@ components: - tokenSecret - basic - basicSecret + - oauth x-speakeasy-enum-descriptions: - Token - Token (secret) - Basic - Basic (credentials secret) + - OAuth description: Authentication type x-speakeasy-unknown-values: allow token: @@ -27078,6 +27543,30 @@ components: title: Credentials secret description: Select or create a secret that references your credentials minLength: 1 + issuer: + type: string + minLength: 1 + pattern: .*\S.* + title: Issuer + description: Expected token issuer (iss claim) + jwksUri: + type: string + minLength: 1 + pattern: .*\S.* + title: JWKS URI + description: URL of the JWKS endpoint used to fetch signing keys + audience: + type: string + minLength: 1 + pattern: .*\S.* + title: Audience + description: Expected token audience (aud claim) + scopes: + type: array + items: + type: string + title: Required scopes + description: Scopes the token must grant (optional) metadata: type: array title: Fields @@ -27088,8 +27577,28 @@ components: type: number title: Active connection limit description: Maximum number of active connections allowed per Worker Process. - Use 0 for unlimited. + Use 0 for unlimited. This does not limit concurrent HTTP/2 streams + on a connection; use Maximum concurrent streams and Maximum message + size for that bound. minimum: 0 + maxMessageSizeKB: + type: number + title: Maximum message size (KB) + description: Maximum size, in KB, of a single received gRPC message (OTLP export + request). Requests exceeding this limit are rejected before + processing. Compressed requests are checked against their + decompressed size. + minimum: 1 + maximum: 65536 + maxConcurrentStreams: + type: number + title: Maximum concurrent streams + description: Maximum number of concurrent HTTP/2 streams allowed on a single + gRPC connection. Combined with Maximum message size, this bounds + per-connection receive and decompress state. Active connection limit + only bounds connections. + minimum: 1 + maximum: 10000 description: type: string title: Description @@ -27197,8 +27706,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -27235,6 +27743,24 @@ components: description: Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. minimum: 0 + maxMessageSizeKB: + type: number + title: Maximum message size (KB) + description: Maximum size, in KB, of a single received gRPC message. Messages + exceeding this limit are rejected before processing. Compressed + messages are checked against their decompressed size. + minimum: 1 + maximum: 65536 + maxConcurrentStreams: + type: number + title: Maximum concurrent streams + description: Maximum number of concurrent HTTP/2 streams allowed on a single + gRPC connection. Combined with Maximum message size, this bounds + per-connection receive and decompress state. Active connection limit + only bounds the number of connections, not the streams multiplexed + on each. + minimum: 1 + maximum: 10000 shutdownTimeoutMs: type: number title: Shutdown timeout @@ -27312,8 +27838,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -27329,13 +27854,7 @@ components: queueName: type: string title: Queue - description: "The name, URL, or ARN of the SQS queue to read events from. When a - non-AWS URL is specified, format must be: '{url}/myQueueName'. - Example: 'https://host:port/myQueueName'. Value must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can only be evaluated at init time. Example - referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." queueType: title: Queue type type: string @@ -27407,9 +27926,7 @@ components: maxMessages: type: number title: Message limit - description: "The maximum number of messages SQS should return in a poll - request. Amazon SQS never returns more messages than this value - (however, fewer messages might be returned). Valid values: 1 to 10." + description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10." minimum: 1 maximum: 10 visibilityTimeout: @@ -27436,6 +27953,12 @@ components: system restarts. minimum: 1 maximum: 20 + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -27558,8 +28081,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -27681,17 +28203,19 @@ components: udpSocketRxBufSize: type: number title: UDP socket buffer size (bytes) - description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. - This value tells the operating system how many bytes can be buffered - in the kernel before events are dropped. Leave blank to use the OS - default. Caution: Increasing this value will affect OS memory - utilization." + description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization." minimum: 256 maximum: 4294967295 enableLoadBalancing: type: boolean title: Enable TCP load balancing description: Load balance traffic across all Worker Processes + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -27783,8 +28307,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -27838,9 +28361,7 @@ components: minAgeDur: type: string title: Minimum age duration - description: "The minimum age of files to monitor. Format examples: 30s, 15m, - 1h. Age is relative to file modification time. Leave empty to apply - no age filters." + description: "The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters." maxAgeDur: type: string title: Maximum age duration @@ -27863,6 +28384,10 @@ components: description: Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files. + enableLoadBalancing: + type: boolean + title: Enable load balancing + description: Load balance traffic across all Worker Processes metadata: type: array title: Fields @@ -27890,6 +28415,12 @@ components: out, as is, to the Pipelines minimum: 10 maximum: 43200000 + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -27897,8 +28428,7 @@ components: path: type: string title: Search path - description: "Directory path to search for files. Environment variables will be - resolved (example: $CRIBL_HOME/log/)." + description: "Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/)." depth: type: number minimum: 0 @@ -27929,6 +28459,20 @@ components: load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories. + enableDiscoveryThrottle: + type: boolean + title: Enable discovery Throttling + description: When enabled, discovery will throttle CPU usage to the configured + target percentage. + discoveryThrottleCpuPercent: + type: number + minimum: 1 + maximum: 99 + title: Discovery throttle CPU target (%) + description: Target CPU utilization percentage during file discovery. Discovery + alternates between work and yield periods within a 200ms cycle. For + example, 25% processes entries for 50ms then yields for 150ms. Lower + values reduce CPU usage at the cost of longer discovery times. includeUnidentifiableBinary: type: boolean title: Enable binary files @@ -27994,8 +28538,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -28081,6 +28624,12 @@ components: out, as is, to the Pipelines minimum: 10 maximum: 43200000 + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). enableHeader: type: boolean title: Enable header @@ -28104,7 +28653,7 @@ components: description: Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate textSecret: @@ -28178,8 +28727,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -28306,14 +28854,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). - When limit is reached, older data will be deleted." + description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted." pattern: ^\d+\s*(?:\w{2})?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data (examples: 2h, 4d). When - limit is reached, older data will be deleted." + description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/DataCompressionFormatOptionsPersistence" @@ -28325,7 +28871,7 @@ components: $CRIBL_HOME/state/appscope description: Persistence authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate description: @@ -28434,8 +28980,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -28464,9 +29009,11 @@ components: enum: - clientCert - kerberos + - negotiate x-speakeasy-enum-descriptions: - Client certificate - Kerberos + - Negotiate (SPNEGO) x-speakeasy-unknown-values: allow tls: type: object @@ -28537,10 +29084,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -28814,8 +29358,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -28908,6 +29451,11 @@ components: title: Render event message strings description: Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) + includeEmptyJsonFields: + type: boolean + title: Include empty JSON fields + description: Preserve fields with empty values (such as '-') in the JSON output + instead of omitting them disableXmlRendering: type: boolean title: Render event message strings @@ -28971,8 +29519,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -29075,8 +29622,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -29123,11 +29669,7 @@ components: udpSocketRxBufSize: type: number title: UDP socket buffer size (bytes) - description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. - This value tells the operating system how many bytes can be buffered - in the kernel before events are dropped. Leave blank to use the OS - default. Caution: Increasing this value will affect OS memory - utilization." + description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization." minimum: 256 maximum: 4294967295 metadata: @@ -29136,6 +29678,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -29208,8 +29756,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -29266,8 +29813,7 @@ components: maxAgeDur: type: string title: Age duration limit - description: "The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, - 1w). Default of no value will apply no max age filters." + description: "The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters." suppressMissingPathErrors: type: boolean title: Suppress errors when search path does not exist @@ -29278,6 +29824,12 @@ components: description: Fields to add to events from this input items: $ref: "#/components/schemas/MetadataConfInputCollection" + autoParse: + type: boolean + title: Auto parse + description: Detect the datatype of each event and extract its top-level fields + before the data reaches any of the processing pipelines + (pre-processing, main processing, post-processing). description: type: string title: Description @@ -29343,8 +29895,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -29360,8 +29911,7 @@ components: endpoint: type: string title: GraphQL endpoint - description: "The Wiz GraphQL API endpoint. Example: - https://api.us1.app.wiz.io/graphql" + description: "The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql" pattern: ^https:\/\/ authUrl: type: string @@ -29425,9 +29975,7 @@ components: contentQuery: type: string title: Content query - description: "Template for POST body to send with the Collect request. Reference - global variables, or functions using template params: - `${C.vars.myVar}`, or `${Date.now()}`, `${param}`." + description: "Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`." cronSchedule: type: string title: Cron schedule @@ -29435,21 +29983,15 @@ components: earliest: type: string title: Earliest time - description: "Earliest time, relative to now. Format supported: - [+|-]@ (ex: -1hr, - -42m, -42m@h)" + description: "Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)" latest: type: string title: Latest time - description: "Latest time, relative to now. Format supported: - [+|-]@ (ex: -1hr, - -42m, -42m@h)" + description: "Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)" jobTimeout: title: Job timeout type: string - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Units default to seconds if not specified. Enter 0 for - unlimited time." + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time." pattern: ^\d+[sm]?$ logLevel: $ref: "#/components/schemas/LogLevelOptionsContentConfigItemsDebugError" @@ -29603,8 +30145,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -29673,12 +30214,17 @@ components: type: string title: State update expression description: JavaScript expression that defines how to update the state from an - event + event. Use the event's data and the current state to compute + the new state. See [Understanding State Expression + Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) + for more information. stateMergeExpression: type: string title: State merge expression description: JavaScript expression that defines which state to keep when merging - task state + a task's newly reported state with previously saved state. + Evaluates `prevState` and `newState` variables, resolving to + the state to keep. manageState: type: object requestParams: @@ -29686,8 +30232,7 @@ components: title: Query parameters description: Query-string parameters to send with this endpoint items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" paginationType: type: string title: Pagination type @@ -29742,8 +30287,7 @@ components: jobTimeout: title: Job timeout type: string - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: ^\d+[sm]?$ logLevel: type: string @@ -29886,8 +30430,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -29912,8 +30455,7 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: type: string tls: @@ -29922,10 +30464,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -30028,10 +30567,45 @@ components: authTokensExt: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: - $ref: "#/components/schemas/AuthTokensExtConfInputHttp" + type: object + oneOf: + - required: + - token + - required: + - authType + - tokenSecret + properties: + authType: + $ref: "#/components/schemas/AuthTypeOptionsAuthTokensExtItems" + description: Discriminator value. + tokenSecret: + type: string + description: Select or create a stored text secret + properties: + authType: + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" + description: Select Manual to enter an auth token directly, or select Secret to + use a text secret to authenticate + tokenSecret: + type: string + title: Token secret (text secret) + description: Select or create a stored text secret + token: + type: string + title: Token + description: "Shared secret to be provided by any client (Authorization: )" + description: + type: string + title: Description + description: Description + metadata: + type: array + title: Fields + description: Fields to add to events referencing this token + items: + $ref: "#/components/schemas/MetadataConfInputCollection" description: type: string title: Description @@ -30113,8 +30687,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -30158,11 +30731,7 @@ components: udpSocketRxBufSize: type: number title: UDP socket buffer size (bytes) - description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. - This value tells the operating system how many bytes can be buffered - in the kernel before events are dropped. Leave blank to use the OS - default. Caution: Increasing this value will affect OS memory - utilization." + description: "Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization." minimum: 256 maximum: 4294967295 templateCacheMinutes: @@ -30261,8 +30830,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -30278,13 +30846,7 @@ components: queueName: type: string title: Queue - description: "The name, URL, or ARN of the SQS queue to read notifications from. - When a non-AWS URL is specified, format must be: - '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value - must be a JavaScript expression (which can evaluate to a constant - value), enclosed in quotes or backticks. Can be evaluated only at - init time. Example referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." fileFilter: type: string title: Filename filter @@ -30338,9 +30900,7 @@ components: maxMessages: type: number title: Message limit - description: "The maximum number of messages SQS should return in a poll - request. Amazon SQS never returns more messages than this value - (however, fewer messages might be returned). Valid values: 1 to 10." + description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10." minimum: 1 maximum: 10 visibilityTimeout: @@ -30623,8 +31183,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -30640,13 +31199,7 @@ components: queueName: type: string title: Queue - description: "The name, URL, or ARN of the SQS queue to read notifications from. - When a non-AWS URL is specified, format must be: - '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value - must be a JavaScript expression (which can evaluate to a constant - value), enclosed in quotes or backticks. Can be evaluated only at - init time. Example referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." fileFilter: type: string title: Filename filter @@ -30700,9 +31253,7 @@ components: maxMessages: type: number title: Message limit - description: "The maximum number of messages SQS should return in a poll - request. Amazon SQS never returns more messages than this value - (however, fewer messages might be returned). Valid values: 1 to 10." + description: "The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10." minimum: 1 maximum: 10 visibilityTimeout: @@ -30989,8 +31540,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -31087,16 +31637,12 @@ components: type: string pattern: .*\S.* title: Earliest time - description: "Earliest time, relative to now. Format supported: - [+|-]@ (ex: -1hr, -42m, - -42m@h)" + description: "Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)" latest: type: string pattern: .*\S.* title: Latest time - description: "Latest time, relative to now. Format supported: - [+|-]@ (ex: -1hr, -42m, - -42m@h)" + description: "Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)" stateTracking: type: boolean title: State tracking @@ -31270,13 +31816,13 @@ components: variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. title: InputServicenowTable - InputZscalerHec: + InputProofpointPod: type: object required: - type - - host - - port - - hecAPI + - clusterId + - feedType + - textSecret properties: id: type: string @@ -31284,9 +31830,9 @@ components: description: Unique ID for this input type: type: string - description: Source type identifier. enum: - - zscaler_hec + - proofpoint_pod + description: Connector type identifier. disabled: type: boolean title: Disabled @@ -31319,8 +31865,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -31333,181 +31878,66 @@ components: $ref: "#/components/schemas/ConnectionConfInputCollection" pq: $ref: "#/components/schemas/PqType" - host: + clusterId: type: string - title: Address - description: Address to bind on. Defaults to 0.0.0.0 (all addresses). - port: - type: number - title: Port - maximum: 65535 - description: Port to listen on - authTokens: - type: array - title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." - items: - type: object - required: - - token - properties: - authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" - description: Select Manual to enter an auth token directly, or select Secret to - use a text secret to authenticate - tokenSecret: - type: string - title: Token secret (text secret) - description: Select or create a stored text secret - token: - type: string - title: Token - description: "Shared secret to be provided by any client (Authorization: - )" - enabled: - type: boolean - title: Enable token - description: Enable token - description: - type: string - title: Description - description: Description - allowedIndexesAtToken: - type: array - title: Allowed indexes - description: Enter the values you want to allow in the HEC event index field at - the token level. Supports wildcards. To skip validation, leave - blank. - minItems: 0 - items: - type: string - minLength: 1 - metadata: - type: array - title: Fields - description: Fields to add to events referencing this token - items: - $ref: "#/components/schemas/MetadataConfInputCollection" + title: Cluster ID + description: Proofpoint on Demand cluster ID. + feedType: + type: string + title: Feed type + description: Proofpoint on Demand feed to ingest. + enum: + - message + - maillog + - audit + x-speakeasy-enum-descriptions: + - Message + - Mail log + - Audit + x-speakeasy-unknown-values: allow + textSecret: + type: string + title: Token (text secret) + description: Select or create a stored text secret tls: - $ref: "#/components/schemas/TlsSettingsServerSideType" - description: TLS settings (server side) - maxActiveReq: - type: number - title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." - minimum: 0 - maxRequestsPerSocket: - type: integer - title: Requests-per-socket limit - description: Maximum number of requests per socket before @{product} instructs - the client to close the connection. Default is 0 (unlimited). - minimum: 0 - enableProxyHeader: - type: boolean - title: Show originating IP - description: Extract the client IP and port from PROXY protocol v1/v2. When - enabled, the X-Forwarded-For header is ignored. Disable to use the - X-Forwarded-For header for client IP extraction. - captureHeaders: + $ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath" + description: TLS settings (client side) + compress: type: boolean - title: Capture request headers - description: Add request headers to events, in the __headers field - captureHeadersWarning: - type: string - readOnly: true - const: "" - activityLogSampleRate: - type: number - title: Activity log sample rate - description: How often request activity is logged at the `info` level. A value - of 1 would log every request, 10 every 10th request, etc. - minimum: 1 - requestTimeout: + title: Compress + description: Compress the feed connection. + handshakeTimeout: type: number - title: Request timeout (seconds) - description: How long to wait for an incoming request to complete before - aborting it. Use 0 to disable. - minimum: 0 - socketTimeout: + title: Handshake timeout (ms) + description: Maximum time to wait for the connection handshake to complete. + minimum: 1000 + maximum: 60000 + keepAliveIntervalSec: type: number - title: Socket timeout (seconds) - description: How long @{product} should wait before assuming that an inactive - socket has timed out. To wait forever, set to 0. + title: Keepalive ping interval (seconds) + description: How often to send a keepalive ping while the feed is idle. Use 0 to + disable keepalive pings. minimum: 0 - keepAliveTimeout: + maximum: 3600 + maxMissedKeepAlives: type: number - title: Keep-alive timeout (seconds) - description: After the last response is sent, @{product} will wait this long for - additional data before closing the socket connection. Minimum 1 - second, maximum 600 seconds (10 minutes). + title: Max missed keepalives + description: Maximum number of consecutive keepalive pings that can go + unanswered before reconnecting. minimum: 1 - maximum: 600 - ipAllowlistRegex: - type: string - title: IP allowlist regex - description: Messages from matched IP addresses will be processed, unless also - matched by the denylist - ipDenylistRegex: + maximum: 100 + maxMessageSize: type: string - title: IP denylist regex - description: Messages from matched IP addresses will be ignored. This takes - precedence over the allowlist. - hecAPI: + title: Maximum message size + description: The maximum size of a single feed message. Enter a numeral with + units of KB, MB, etc. + pattern: ^\d+\s*(?:\w{2})?$ + readBufferSize: type: string - title: HEC endpoint - description: Absolute path on which to listen for the Zscaler HTTP Event - Collector API requests. This input supports the /event endpoint. - pattern: ^/ - metadata: - type: array - title: Fields - description: Fields to add to every event. May be overridden by fields added at - the token or request level. - items: - $ref: "#/components/schemas/MetadataConfInputCollection" - allowedIndexes: - type: array - title: Allowed indexes - description: List values allowed in HEC event index field. Leave blank to skip - validation. Supports wildcards. The values here can expand index - validation at the token level. - minItems: 0 - items: - type: string - minLength: 1 - accessControlAllowOrigin: - title: CORS allowed origins - type: array - description: HTTP origins to which @{product} should send CORS (cross-origin - resource sharing) Access-Control-Allow-* headers. Supports - wildcards. - minItems: 0 - items: - type: string - minLength: 1 - accessControlAllowHeaders: - title: CORS allowed headers - type: array - description: HTTP headers that @{product} will send to allowed origins as - "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" - to allow all headers. - minItems: 0 - items: - type: string - minLength: 1 - emitTokenMetrics: - type: boolean - title: Emit per-token request metrics - description: Emit per-token (.http.perToken) and summary - (.http.summary) request metrics - hecAcks: - type: boolean - title: Zscaler HEC Acks - description: Whether to enable Zscaler HEC acknowledgements + title: Read buffer size + description: The maximum size to hold in memory before applying backpressure. + Enter a numeral with units of KB, MB, etc. + pattern: ^\d+\s*(?:\w{2})?$ description: type: string title: Description @@ -31522,41 +31952,13 @@ components: description: Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. - __template_host: - type: string - description: Binds 'host' to a variable for dynamic value resolution. Set to - variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'host' at runtime. - __template_port: - type: string - description: Binds 'port' to a variable for dynamic value resolution. Set to - variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'port' at runtime. - __template_hecAPI: - type: string - description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to - variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'hecAPI' at runtime. - __template_allowedIndexes: + __template_clusterId: type: string - description: Binds 'allowedIndexes' to a variable for dynamic value resolution. - Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'allowedIndexes' at - runtime. - __template_accessControlAllowOrigin: - type: string - description: Binds 'accessControlAllowOrigin' to a variable for dynamic value - resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' - prefixed ID (group-scoped). Variable value overrides - 'accessControlAllowOrigin' at runtime. - __template_accessControlAllowHeaders: - type: string - description: Binds 'accessControlAllowHeaders' to a variable for dynamic value - resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' - prefixed ID (group-scoped). Variable value overrides - 'accessControlAllowHeaders' at runtime. - title: InputZscalerHec - InputCloudflareHec: + description: Binds 'clusterId' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'clusterId' at runtime. + title: InputProofpointPod + InputZscalerHec: type: object required: - type @@ -31572,7 +31974,7 @@ components: type: string description: Source type identifier. enum: - - cloudflare_hec + - zscaler_hec disabled: type: boolean title: Disabled @@ -31605,8 +32007,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -31631,8 +32032,287 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + type: object + required: + - token + properties: + authType: + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" + description: Select Manual to enter an auth token directly, or select Secret to + use a text secret to authenticate + tokenSecret: + type: string + title: Token secret (text secret) + description: Select or create a stored text secret + token: + type: string + title: Token + description: "Shared secret to be provided by any client (Authorization: )" + enabled: + type: boolean + title: Enable token + description: Enable token + description: + type: string + title: Description + description: Description + allowedIndexesAtToken: + type: array + title: Allowed indexes + description: Enter the values you want to allow in the HEC event index field at + the token level. Supports wildcards. To skip validation, leave + blank. + minItems: 0 + items: + type: string + minLength: 1 + metadata: + type: array + title: Fields + description: Fields to add to events referencing this token + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for the Zscaler HTTP Event + Collector API requests. This input supports the /event endpoint. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + hecAcks: + type: boolean + title: Zscaler HEC Acks + description: Whether to enable Zscaler HEC acknowledgements + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputZscalerHec + InputCloudflareHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - cloudflare_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" tls: @@ -31648,6 +32328,11 @@ components: title: Authenticate client (mutual auth) description: Require clients to present their certificates. Used to perform client authentication using SSL certs. + caPath: + type: string + title: CA certificate path + description: Path on server containing CA certificates to use. PEM format. Can + reference $ENV_VARS. rejectUnauthorized: type: boolean title: Validate client certificates @@ -31678,11 +32363,6 @@ components: description: Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled. - caPath: - type: string - title: CA certificate path - description: Path on server containing CA certificates to use. PEM format. Can - reference $ENV_VARS. minVersion: $ref: "#/components/schemas/MinimumTlsVersionOptionsTls" description: Minimum TLS version @@ -31693,10 +32373,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -31914,8 +32591,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -31940,8 +32616,7 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" tls: @@ -31950,10 +32625,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -32157,8 +32829,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -32183,8 +32854,7 @@ components: authTokens: type: array title: Auth tokens - description: "Shared secrets to be provided by any client (Authorization: - ). If empty, unauthorized access is permitted." + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" tls: @@ -32193,10 +32863,7 @@ components: maxActiveReq: type: number title: Active request limit - description: "Maximum number of active requests allowed per Worker Process. Set - to 0 for unlimited. Caution: Increasing the limit above the default - value, or setting it to unlimited, may degrade performance and - reduce throughput." + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 maxRequestsPerSocket: type: integer @@ -32350,13 +33017,13 @@ components: prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. title: InputUpwindHec - InputOpenaiComplianceLogs: + InputTrellixHec: type: object required: - type - - textSecret - - accountType - - cronSchedule + - host + - port + - hecAPI properties: id: type: string @@ -32364,9 +33031,9 @@ components: description: Unique ID for this input type: type: string + description: Source type identifier. enum: - - openai_compliance_logs - description: Connector type identifier. + - trellix_hec disabled: type: boolean title: Disabled @@ -32399,8 +33066,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -32413,155 +33079,340 @@ components: $ref: "#/components/schemas/ConnectionConfInputCollection" pq: $ref: "#/components/schemas/PqType" - apiKey: - type: string - title: API key - description: API key - textSecret: - type: string - title: API key (text secret) - description: Select or create a stored text secret - accountType: - type: string - title: Account type - enum: - - workspace - - organization - x-speakeasy-enum-descriptions: - - Workspace - - Organization - description: Account type - x-speakeasy-unknown-values: allow - cronSchedule: - type: string - title: Cron schedule - description: Cron schedule - earliest: - type: string - title: Earliest time - description: "Relative to the current time. Format: - [+|-]" - latest: - type: string - title: Latest time - description: "Relative to the current time. Format: - [+|-]" - jobTimeout: - title: Job timeout + host: type: string - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." - pattern: ^\d+[sm]?$ - logLevel: - $ref: "#/components/schemas/LogLevelOptionsContentConfigItemsDebugError" - description: Collector runtime log level - maxPages: + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: type: number - title: Page limit - description: Maximum number of log file listing pages to retrieve per run. Set - to 0 to retrieve all pages. + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." minimum: 0 - stateTracking: + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: type: boolean - title: State tracking - description: Track collection progress between consecutive scheduled executions + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 requestTimeout: type: number title: Request timeout (seconds) - description: HTTP request inactivity timeout. Use 0 to disable. + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. minimum: 0 - maximum: 2400 - keepAliveTime: + socketTimeout: type: number - title: Keep alive time (seconds) - description: How often workers should check in with the scheduler to keep job - subscription alive - minimum: 10 - maxMissedKeepAlives: + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: type: number - title: Worker timeout (periods) - description: The number of Keep Alive Time periods before an inactive worker - will have its job subscription revoked. - minimum: 2 - ttl: + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: type: string - title: Time to live - description: Time to keep the job's artifacts on disk after job completion. This - also affects how long a job is listed in the Job Inspector. - pattern: \d+[smh]$ - ignoreGroupJobsLimit: - type: boolean - title: Ignore Worker Group job limits - description: When enabled, this job's artifacts are not counted toward the - Worker Group's finished job artifacts limit. Artifacts will be - removed only after the Collector's configured time to live. + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for the Trellix HTTP Event + Collector API requests. This input supports the /event endpoint. + pattern: ^/ metadata: type: array title: Fields - description: Fields to add to events from this input + description: Fields to add to every event. May be overridden by fields added at + the token or request level. items: $ref: "#/components/schemas/MetadataConfInputCollection" - breakerRulesets: + allowedIndexes: type: array - title: Event Breaker rulesets - description: A list of event-breaking rulesets that will be applied, in order, - to the input data stream + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 items: type: string - staleChannelFlushMs: - type: number - title: Event Breaker buffer timeout (ms) - description: How long (in milliseconds) the Event Breaker will wait for new data - to be sent to a specific channel before flushing the data stream - out, as is, to the Pipelines - minimum: 10 - maximum: 43200000 - retryRules: - $ref: "#/components/schemas/RetryRulesType" + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics description: type: string title: Description description: Optional description for this configuration. - workspaceId: + __template_environment: type: string - title: Workspace ID - description: The ID of the ChatGPT workspace to collect logs from (UUID format) - workspaceEventTypes: + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputTrellixHec + InputSailpointHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - sailpoint_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: type: array - title: Event types - description: One or more compliance log categories to collect + title: Tags + description: Metadata tags used for categorization and filtering. items: type: string - uniqueItems: true - organizationId: + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: type: string - title: Organization ID - description: "The ID of the OpenAI API Platform Organization (example: - org-XXXXXXXXXXXXXXXXXXXXXXXX)" - organizationEventTypes: + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: type: array - title: Event types - description: One or more compliance log categories to collect + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." items: - type: string - uniqueItems: true - stateUpdateExpression: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: type: string - title: State update expression - description: JavaScript expression that defines how to update the state from an - event. Use the event's data and the current state to compute the new - state. See [Understanding State Expression - Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) - for more information. - stateMergeExpression: + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: type: string - title: State merge expression - description: JavaScript expression that defines which state to keep when merging - a task's newly reported state with previously saved state. Evaluates - `prevState` and `newState` variables, resolving to the state to - keep. - manageState: - type: object + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for SailPoint Virtual Appliance + HTTP Event Collector requests. This source uses the + /services/collector endpoint. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + description: + type: string + title: Description + description: Optional description for this configuration. __template_environment: type: string description: Binds 'environment' to a variable for dynamic value resolution. Set @@ -32572,23 +33423,29 @@ components: description: Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. - __template_workspaceId: + __template_host: type: string - description: Binds 'workspaceId' to a variable for dynamic value resolution. Set - to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'workspaceId' at runtime. - __template_organizationId: + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: type: string - description: Binds 'organizationId' to a variable for dynamic value resolution. - Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'organizationId' at - runtime. - title: InputOpenaiComplianceLogs - InputAnthropicCompliance: + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + title: InputSailpointHec + InputExtrahopRevealx360: type: object required: - type - - textSecret + - host + - port + - hecAPI properties: id: type: string @@ -32596,9 +33453,9 @@ components: description: Unique ID for this input type: type: string + description: Source type identifier. enum: - - anthropic_compliance - description: Connector type identifier. + - extrahop_revealx_360 disabled: type: boolean title: Disabled @@ -32631,8 +33488,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -32645,53 +33501,758 @@ components: $ref: "#/components/schemas/ConnectionConfInputCollection" pq: $ref: "#/components/schemas/PqType" - apiKey: + host: type: string - title: API key - description: API key - textSecret: + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: type: string - title: API key (text secret) - description: Select or create a stored Anthropic API key - activities: - type: object - properties: - enabled: - type: boolean - title: Enabled - description: Enabled - cronSchedule: - type: string - title: Cron schedule - description: Schedule on which to run this collection job - earliest: - type: string - title: Earliest - description: Earliest time for data collection, relative to now - latest: - type: string - title: Latest - description: Latest time for data collection, relative to now - jobTimeout: - type: string - title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." - pattern: ^\d+[sm]?$ - stateTracking: - type: boolean - title: State tracking - description: Track collection progress between consecutive scheduled executions - stateUpdateExpression: - type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for ExtraHop RevealX 360 Splunk + HTTP Event Collector requests. This input supports the /event + endpoint. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputExtrahopRevealx360 + InputAquaSecurityHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - aqua_security_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for Aqua Security HTTP Event + Collector API requests. This input supports event, raw, and + acknowledgement endpoints. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + hecAcks: + type: boolean + title: HEC Acks + description: Whether to enable HEC indexer acknowledgements + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputAquaSecurityHec + InputOpenaiComplianceLogs: + type: object + required: + - type + - textSecret + - accountType + - cronSchedule + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + enum: + - openai_compliance_logs + description: Connector type identifier. + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + apiKey: + type: string + title: API key + description: API key + textSecret: + type: string + title: API key (text secret) + description: Select or create a stored text secret + accountType: + type: string + title: Account type + enum: + - workspace + - organization + x-speakeasy-enum-descriptions: + - Workspace + - Organization + description: Account type + x-speakeasy-unknown-values: allow + cronSchedule: + type: string + title: Cron schedule + description: Cron schedule + earliest: + type: string + title: Earliest time + description: "Relative to the current time. Format: [+|-]" + latest: + type: string + title: Latest time + description: "Relative to the current time. Format: [+|-]" + jobTimeout: + title: Job timeout + type: string + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + logLevel: + $ref: "#/components/schemas/LogLevelOptionsContentConfigItemsDebugError" + description: Collector runtime log level + maxPages: + type: number + title: Page limit + description: Maximum number of log file listing pages to retrieve per run. Set + to 0 to retrieve all pages. + minimum: 0 + stateTracking: + type: boolean + title: State tracking + description: Track collection progress between consecutive scheduled executions + requestTimeout: + type: number + title: Request timeout (seconds) + description: HTTP request inactivity timeout. Use 0 to disable. + minimum: 0 + maximum: 2400 + keepAliveTime: + type: number + title: Keep alive time (seconds) + description: How often workers should check in with the scheduler to keep job + subscription alive + minimum: 10 + maxMissedKeepAlives: + type: number + title: Worker timeout (periods) + description: The number of Keep Alive Time periods before an inactive worker + will have its job subscription revoked. + minimum: 2 + ttl: + type: string + title: Time to live + description: Time to keep the job's artifacts on disk after job completion. This + also affects how long a job is listed in the Job Inspector. + pattern: \d+[smh]$ + ignoreGroupJobsLimit: + type: boolean + title: Ignore Worker Group job limits + description: When enabled, this job's artifacts are not counted toward the + Worker Group's finished job artifacts limit. Artifacts will be + removed only after the Collector's configured time to live. + metadata: + type: array + title: Fields + description: Fields to add to events from this input + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + breakerRulesets: + type: array + title: Event Breaker rulesets + description: A list of event-breaking rulesets that will be applied, in order, + to the input data stream + items: + type: string + staleChannelFlushMs: + type: number + title: Event Breaker buffer timeout (ms) + description: How long (in milliseconds) the Event Breaker will wait for new data + to be sent to a specific channel before flushing the data stream + out, as is, to the Pipelines + minimum: 10 + maximum: 43200000 + retryRules: + $ref: "#/components/schemas/RetryRulesType" + description: + type: string + title: Description + description: Optional description for this configuration. + workspaceId: + type: string + title: Workspace ID + description: The ID of the ChatGPT workspace to collect logs from (UUID format) + workspaceEventTypes: + type: array + title: Event types + description: One or more compliance log categories to collect + items: + type: string + uniqueItems: true + organizationId: + type: string + title: Organization ID + description: "The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)" + organizationEventTypes: + type: array + title: Event types + description: One or more compliance log categories to collect + items: + type: string + uniqueItems: true + stateUpdateExpression: + type: string + title: State update expression + description: JavaScript expression that defines how to update the state from an + event. Use the event's data and the current state to compute the new + state. See [Understanding State Expression + Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) + for more information. + stateMergeExpression: + type: string + title: State merge expression + description: JavaScript expression that defines which state to keep when merging + a task's newly reported state with previously saved state. Evaluates + `prevState` and `newState` variables, resolving to the state to + keep. + manageState: + type: object + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_workspaceId: + type: string + description: Binds 'workspaceId' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'workspaceId' at runtime. + __template_organizationId: + type: string + description: Binds 'organizationId' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'organizationId' at + runtime. + title: InputOpenaiComplianceLogs + InputAnthropicCompliance: + type: object + required: + - type + - textSecret + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + enum: + - anthropic_compliance + description: Connector type identifier. + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + apiKey: + type: string + title: API key + description: API key + textSecret: + type: string + title: API key (text secret) + description: Select or create a stored Anthropic API key + activities: + type: object + properties: + enabled: + type: boolean + title: Enabled + description: Enabled + cronSchedule: + type: string + title: Cron schedule + description: Schedule on which to run this collection job + earliest: + type: string + title: Earliest + description: Earliest time for data collection, relative to now + latest: + type: string + title: Latest + description: Latest time for data collection, relative to now + jobTimeout: + type: string + title: Job timeout + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + stateTracking: + type: boolean + title: State tracking + description: Track collection progress between consecutive scheduled executions + stateUpdateExpression: + type: string title: State update expression description: JavaScript expression that defines how to update the state from an - event + event. Use the event's data and the current state to compute the + new state. See [Understanding State Expression + Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) + for more information. stateMergeExpression: type: string title: State merge expression description: JavaScript expression that defines which state to keep when merging - task state + a task's newly reported state with previously saved state. + Evaluates `prevState` and `newState` variables, resolving to the + state to keep. manageState: type: object title: Activities @@ -32718,8 +34279,7 @@ components: jobTimeout: type: string title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: ^\d+[sm]?$ stateTracking: type: boolean @@ -32729,12 +34289,17 @@ components: type: string title: State update expression description: JavaScript expression that defines how to update the state from an - event + event. Use the event's data and the current state to compute the + new state. See [Understanding State Expression + Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) + for more information. stateMergeExpression: type: string title: State merge expression description: JavaScript expression that defines which state to keep when merging - task state + a task's newly reported state with previously saved state. + Evaluates `prevState` and `newState` variables, resolving to the + state to keep. manageState: type: object title: Chats @@ -32761,8 +34326,7 @@ components: jobTimeout: type: string title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: ^\d+[sm]?$ stateTracking: type: boolean @@ -32772,12 +34336,17 @@ components: type: string title: State update expression description: JavaScript expression that defines how to update the state from an - event + event. Use the event's data and the current state to compute the + new state. See [Understanding State Expression + Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) + for more information. stateMergeExpression: type: string title: State merge expression description: JavaScript expression that defines which state to keep when merging - task state + a task's newly reported state with previously saved state. + Evaluates `prevState` and `newState` variables, resolving to the + state to keep. manageState: type: object title: Projects @@ -32804,8 +34373,7 @@ components: jobTimeout: type: string title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: ^\d+[sm]?$ stateTracking: type: boolean @@ -32815,12 +34383,17 @@ components: type: string title: State update expression description: JavaScript expression that defines how to update the state from an - event + event. Use the event's data and the current state to compute the + new state. See [Understanding State Expression + Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) + for more information. stateMergeExpression: type: string title: State merge expression description: JavaScript expression that defines which state to keep when merging - task state + a task's newly reported state with previously saved state. + Evaluates `prevState` and `newState` variables, resolving to the + state to keep. manageState: type: object title: Chat Messages @@ -32847,8 +34420,7 @@ components: jobTimeout: type: string title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: ^\d+[sm]?$ stateTracking: type: boolean @@ -32858,12 +34430,17 @@ components: type: string title: State update expression description: JavaScript expression that defines how to update the state from an - event + event. Use the event's data and the current state to compute the + new state. See [Understanding State Expression + Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) + for more information. stateMergeExpression: type: string title: State merge expression description: JavaScript expression that defines which state to keep when merging - task state + a task's newly reported state with previously saved state. + Evaluates `prevState` and `newState` variables, resolving to the + state to keep. manageState: type: object title: Project Details @@ -32873,130 +34450,2625 @@ components: properties: enabled: type: boolean - title: Enabled - description: Enabled - cronSchedule: - type: string - title: Cron schedule - description: Schedule on which to run this collection job - jobTimeout: - type: string - title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." - pattern: ^\d+[sm]?$ - title: Groups - description: Groups - organizations: - type: object - properties: - enabled: + title: Enabled + description: Enabled + cronSchedule: + type: string + title: Cron schedule + description: Schedule on which to run this collection job + jobTimeout: + type: string + title: Job timeout + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + title: Groups + description: Groups + organizations: + type: object + properties: + enabled: + type: boolean + title: Enabled + description: Enabled + cronSchedule: + type: string + title: Cron schedule + description: Schedule on which to run this collection job + jobTimeout: + type: string + title: Job timeout + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + title: Organizations + description: Organizations + org_users: + type: object + properties: + enabled: + type: boolean + title: Enabled + description: Enabled + cronSchedule: + type: string + title: Cron schedule + description: Schedule on which to run this collection job + jobTimeout: + type: string + title: Job timeout + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + title: Organization Users + description: Organization Users + org_roles: + type: object + properties: + enabled: + type: boolean + title: Enabled + description: Enabled + cronSchedule: + type: string + title: Cron schedule + description: Schedule on which to run this collection job + jobTimeout: + type: string + title: Job timeout + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + title: Organization Roles + description: Organization Roles + requestTimeout: + type: number + title: Request timeout (seconds) + description: HTTP request inactivity timeout. Use 0 to disable. + minimum: 0 + maximum: 2400 + breakerRulesets: + type: array + title: Event Breaker rulesets + description: A list of event-breaking rulesets that will be applied, in order, + to the input data stream + items: + type: string + staleChannelFlushMs: + type: number + title: Event Breaker buffer timeout (ms) + description: How long (in milliseconds) the Event Breaker will wait for new data + to be sent to a specific channel before flushing the data stream + out, as is, to the Pipelines + minimum: 10 + maximum: 43200000 + keepAliveTime: + type: number + title: Keep alive time (seconds) + description: How often workers should check in with the scheduler to keep job + subscription alive + minimum: 10 + maxMissedKeepAlives: + type: number + title: Worker timeout (periods) + description: The number of Keep Alive Time periods before an inactive worker + will have its job subscription revoked. + minimum: 2 + ttl: + type: string + title: Time to live + description: Time to keep the job's artifacts on disk after job completion. This + also affects how long a job is listed in the Job Inspector. + pattern: \d+[smh]$ + ignoreGroupJobsLimit: + type: boolean + title: Ignore Worker Group job limits + description: When enabled, this job's artifacts are not counted toward the + Worker Group's finished job artifacts limit. Artifacts will be + removed only after the Collector's configured time to live. + metadata: + type: array + title: Fields + description: Fields to add to events from this input + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + retryRules: + $ref: "#/components/schemas/RetryRulesType" + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + title: InputAnthropicCompliance + InputAnthropicEnterpriseAnalytics: + type: object + required: + - type + - contentConfig + - textSecret + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + enum: + - anthropic_enterprise_analytics + description: Connector type identifier. + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + apiKey: + type: string + title: API key + description: API key + textSecret: + type: string + title: API key (text secret) + description: Select or create a stored API key with read:analytics scope + contentConfig: + type: array + title: Content types + description: Analytics endpoints to collect from. Each content type runs on its + own schedule as a separate collection job. + items: + type: object + required: + - contentType + - cronSchedule + properties: + contentType: + type: string + title: Content type + enum: + - Usage Report + - Cost Report + description: Content type + x-speakeasy-unknown-values: allow + disabled: + type: boolean + title: Enabled + description: Enabled + stateTracking: + type: boolean + title: State tracking + description: Track collection progress between runs. When enabled, each run + resumes from where the last one left off, preventing duplicate + data. The API refreshes approximately every 4 hours; runs + between refreshes produce zero events until new finalized data + becomes available. This is expected behavior. + stateUpdateExpression: + type: string + title: State update expression + description: JavaScript expression evaluated per event to compute new state. The + default tracks the data_refreshed_at watermark reported by the + API. + stateMergeExpression: + type: string + title: State merge expression + description: JavaScript expression to merge state across distributed Workers. + The default keeps the most recent watermark. + manageState: + type: boolean + title: Manage state + description: Manage state + groupBy: + type: array + title: Group by + description: Dimensions for breaking down usage. Leave empty to collect a single + summed row per time bucket. + uniqueItems: true + items: + type: string + enum: + - model + - product + - context_window + - inference_geo + - speed + - rbac_group_id + - slack_channel_id + - teams_channel_id + - cost_type + - token_type + x-speakeasy-unknown-values: allow + bucketWidth: + type: string + title: Bucket width + description: Time bucket size for aggregated results. Smaller buckets yield more + events per collection run. + enum: + - 1d + - 1h + - 1m + x-speakeasy-enum-descriptions: + - Daily (1d) + - Hourly (1h) + - Per-minute (1m) + x-speakeasy-unknown-values: allow + cronSchedule: + type: string + title: Cron schedule + description: Cron schedule for collection runs. The API refreshes data + approximately every 4 hours, so polling more frequently will + not yield new results. + earliest: + type: string + title: Earliest + description: "Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d." + jobTimeout: + type: string + title: Job timeout + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + requestTimeout: + type: number + title: Request timeout (seconds) + description: HTTP request inactivity timeout. Use 0 to disable. + minimum: 0 + maximum: 2400 + breakerRulesets: + type: array + title: Event Breaker rulesets + description: A list of event-breaking rulesets that will be applied, in order, + to the input data stream + items: + type: string + staleChannelFlushMs: + type: number + title: Event Breaker buffer timeout (ms) + description: How long (in milliseconds) the Event Breaker will wait for new data + to be sent to a specific channel before flushing the data stream + out, as is, to the Pipelines + minimum: 10 + maximum: 43200000 + keepAliveTime: + type: number + title: Keep alive time (seconds) + description: How often workers should check in with the scheduler to keep job + subscription alive + minimum: 10 + maxMissedKeepAlives: + type: number + title: Worker timeout (periods) + description: The number of Keep Alive Time periods before an inactive worker + will have its job subscription revoked. + minimum: 2 + ttl: + type: string + title: Time to live + description: Time to keep the job's artifacts on disk after job completion. This + also affects how long a job is listed in the Job Inspector. + pattern: \d+[smh]$ + ignoreGroupJobsLimit: + type: boolean + title: Ignore Worker Group job limits + description: When enabled, this job's artifacts are not counted toward the + Worker Group's finished job artifacts limit. Artifacts will be + removed only after the Collector's configured time to live. + metadata: + type: array + title: Fields + description: Fields to add to events from this input + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + retryRules: + $ref: "#/components/schemas/RetryRulesType" + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + title: InputAnthropicEnterpriseAnalytics + InputMicrosoftCopilot: + type: object + required: + - type + - tenantId + - clientId + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + enum: + - microsoft_copilot + description: Connector type identifier. + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + tenantId: + type: string + title: Tenant ID + description: Directory (tenant) ID from Azure Active Directory + pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ + clientId: + type: string + title: Client ID + description: Application (client) ID from the app registration + pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ + resource: + type: string + title: Resource + description: Microsoft Graph resource URI used in the OAuth token request scope + parameter. Derived automatically from the selected plan type. + authType: + title: Authentication method + type: string + enum: + - oauthSecret + - oauthCert + description: Select authentication method. + x-speakeasy-unknown-values: allow + planType: + title: Subscription plan + type: string + enum: + - enterprise_gcc + - gcc + - gcc_high + - dod + description: Microsoft 365 subscription plan for your organization, typically + Microsoft 365 Enterprise. + x-speakeasy-unknown-values: allow + cronSchedule: + type: string + title: Schedule + description: Cron schedule for collection runs + earliest: + type: string + title: Earliest + description: Earliest time for data collection, relative to now. Used as the + initial lower bound on first run. + latest: + type: string + title: Latest + description: Latest time for data collection, relative to now + pageSize: + type: integer + title: Page size + description: Number of interactions to request per page ($top). Maximum 1000. + minimum: 1 + maximum: 1000 + appClassFilter: + type: array + title: App class filter + description: Limit collection to specific Copilot app classes. Leave empty to + collect all. + items: + type: string + uniqueItems: true + filterByLicense: + type: boolean + title: User discovery filtering by product license + description: Add a $filter to the /users call for assigned Copilot SKUs. This + reduces unnecessary API calls by excluding unlicensed users during + discovery rather than skipping them at collection time. + skuIds: + type: array + title: Copilot SKU IDs + description: Microsoft 365 SKU GUIDs that grant access to the Copilot + Interaction Export API. During discovery, users are filtered to + those with at least one of these SKUs in their assignedLicenses. + Pre-populated with known Copilot SKUs; add custom entries for + tenant-specific or new plans. + items: + type: string + pattern: ^[0-9a-fA-F]{8}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{4}-[0-9a-fA-F]{12}$ + uniqueItems: true + manageState: + type: object + timeout: + type: number + title: Request timeout (seconds) + description: HTTP request inactivity timeout, in seconds. Enter 0 to wait + indefinitely. + minimum: 0 + maximum: 2400 + keepAliveTime: + type: number + title: Keep alive time (seconds) + description: How often workers should check in with the scheduler to keep job + subscription alive + minimum: 10 + jobTimeout: + title: Job timeout + type: string + description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time." + pattern: ^\d+[sm]?$ + maxMissedKeepAlives: + type: number + title: Worker timeout (periods) + description: The number of Keep Alive Time periods before an inactive worker + will have its job subscription revoked. + minimum: 2 + ttl: + type: string + title: Time to live + description: Time to keep the job's artifacts on disk after job completion. This + also affects how long a job is listed in the Job Inspector. + pattern: \d+[smh]$ + ignoreGroupJobsLimit: + type: boolean + title: Ignore Worker Group job limits + description: When enabled, this job's artifacts are not counted toward the + Worker Group's finished job artifacts limit. Artifacts will be + removed only after the Collector's configured time to live. + metadata: + type: array + title: Fields + description: Fields to add to events from this input + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + retryRules: + type: object + required: + - type + properties: + type: + $ref: "#/components/schemas/RetryTypeOptionsHealthCheckCollectorConfRetryRules" + description: The algorithm to use when performing HTTP retries + interval: + type: number + title: Initial retry interval (ms) + description: Time interval between failed request and first retry (kickoff). + Maximum allowed value is 20,000 ms (1/3 minute). + minimum: 0 + maximum: 20000 + limit: + type: number + title: Retry limit + description: The maximum number of times to retry a failed HTTP request + minimum: 0 + maximum: 20 + multiplier: + type: number + title: Backoff multiplier + description: Base for exponential backoff, e.g., base 2 means that retries will + occur after 2, then 4, then 8 seconds, and so on + minimum: 1 + maximum: 20 + codes: + type: array + title: Retry HTTP codes + description: List of HTTP codes that trigger a retry. Leave empty to use the + default list of 429, 500, and 503. + minItems: 1 + items: + type: number + minimum: 100 + maximum: 599 + enableHeader: + type: boolean + title: Honor Retry-After header + description: Honor any Retry-After header that specifies a delay (in seconds) or + a timestamp after which to retry the request. The delay is + limited to 20 seconds, even if the Retry-After header specifies + a longer delay. When disabled, all Retry-After headers are + ignored. + retryConnectTimeout: + type: boolean + title: Retry connection timeout + description: Make a single retry attempt when a connection timeout (ETIMEDOUT) + error occurs + retryConnectReset: type: boolean - title: Enabled - description: Enabled - cronSchedule: - type: string - title: Cron schedule - description: Schedule on which to run this collection job - jobTimeout: - type: string - title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." - pattern: ^\d+[sm]?$ - title: Organizations - description: Organizations - org_users: + title: Retry connection reset + description: Retry request when a connection reset (ECONNRESET) error occurs + breakerRulesets: + type: array + title: Event Breaker rulesets + description: A list of event-breaking rulesets that will be applied, in order, + to the input data stream + items: + type: string + staleChannelFlushMs: + type: number + title: Event Breaker buffer timeout (ms) + description: How long (in milliseconds) the Event Breaker will wait for new data + to be sent to a specific channel before flushing the data stream + out, as is, to the Pipelines + minimum: 10 + maximum: 43200000 + description: + type: string + title: Description + description: Optional description for this configuration. + textSecret: + type: string + title: Client secret + description: Select or create a secret that references the client secret from + your app registration + certOptions: type: object + required: + - privKeyPath + - certPath properties: - enabled: - type: boolean - title: Enabled - description: Enabled - cronSchedule: + certificateName: type: string - title: Cron schedule - description: Schedule on which to run this collection job - jobTimeout: + title: Certificate + description: The name of a predefined certificate + privKeyPath: type: string - title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." - pattern: ^\d+[sm]?$ - title: Organization Users - description: Organization Users - org_roles: - type: object - properties: - enabled: - type: boolean - title: Enabled - description: Enabled - cronSchedule: + title: Private key path + description: Path to the private key (PEM format). Can reference $ENV_VARS. + passphrase: type: string - title: Cron schedule - description: Schedule on which to run this collection job - jobTimeout: + title: Passphrase + description: Passphrase to decrypt the private key + certPath: type: string - title: Job timeout - description: "Maximum time the job is allowed to run (examples: 30, 45s, 15m). - Enter 0 for unlimited time." - pattern: ^\d+[sm]?$ - title: Organization Roles - description: Organization Roles + title: Certificate path + description: Path to the certificate (PEM format). Can reference $ENV_VARS. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_tenantId: + type: string + description: Binds 'tenantId' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'tenantId' at runtime. + __template_clientId: + type: string + description: Binds 'clientId' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'clientId' at runtime. + __template_planType: + type: string + description: Binds 'planType' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'planType' at runtime. + title: InputMicrosoftCopilot + InputOkta: + type: object + required: + - type + - textSecret + - oktaDomain + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + enum: + - okta + description: Connector type identifier. + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + oktaDomain: + type: string + title: Okta domain + description: "Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes." + oktaToken: + type: string + title: Okta API token + description: Your Okta API token for authentication + textSecret: + type: string + title: Okta API token (text secret) + description: Select or create a stored text secret + cronSchedule: + type: string + title: Cron schedule + description: Schedule on which to run this collection job + earliest: + type: string + title: Earliest + description: Earliest time for data collection, relative to now + latest: + type: string + title: Latest + description: Latest time for data collection, relative to now + manageState: + type: object + jobTimeout: + type: string + title: Job timeout + description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m). + Units are seconds, if not specified. Enter 0 for unlimited time. + pattern: ^\d+[sm]?$ + requestTimeout: + type: number + title: Request timeout (seconds) + description: HTTP request inactivity timeout. Use 0 to disable. + minimum: 0 + maximum: 2400 + keepAliveTime: + type: number + title: Keep alive time (seconds) + description: How often workers should check in with the scheduler to keep job + subscription alive + minimum: 10 + maxMissedKeepAlives: + type: number + title: Worker timeout (periods) + description: The number of Keep Alive Time periods before an inactive worker + will have its job subscription revoked. + minimum: 2 + ttl: + type: string + title: Time to live + description: Time to keep the job's artifacts on disk after job completion. This + also affects how long a job is listed in the Job Inspector. + pattern: \d+[smh]$ + ignoreGroupJobsLimit: + type: boolean + title: Ignore Worker Group job limits + description: When enabled, this job's artifacts are not counted toward the + Worker Group's finished job artifacts limit. Artifacts will be + removed only after the Collector's configured time to live. + metadata: + type: array + title: Fields + description: Fields to add to events from this input + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + retryRules: + $ref: "#/components/schemas/RetryRulesType" + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_oktaDomain: + type: string + description: Binds 'oktaDomain' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'oktaDomain' at runtime. + title: InputOkta + InputAkamaiHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - akamai_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for Akamai DataStream 2 HTTP Event + Collector API requests. Akamai delivers to the /raw endpoint beneath + this path. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + hecAcks: + type: boolean + title: HEC Acks + description: Whether to enable HEC indexer acknowledgements + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + title: InputAkamaiHec + InputPingIdentityPingone: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - ping_identity_pingone + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for Ping Identity PingOne HTTP + Event Collector API requests. PingOne posts structured JSON webhooks + to the /event endpoint. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputPingIdentityPingone + InputGigamonHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - gigamon_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for Gigamon HTTP Event Collector + API requests. This input supports the /event and /raw endpoints. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputGigamonHec + InputVectraAiHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - vectra_ai_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for Vectra AI HTTP Event Collector + API requests. This input supports the /event and /raw endpoints. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputVectraAiHec + InputF5BigIp: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - f5_big_ip + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for F5 BIG-IP HTTP Event Collector + API requests. This input supports the /event and /raw endpoints. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + hecAcks: + type: boolean + title: HEC Acks + description: Whether to enable HEC indexer acknowledgements + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputF5BigIp + InputBeyondtrustHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - beyondtrust_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for BeyondTrust HTTP Event + Collector API requests. BeyondTrust sends event payloads to the + standard HEC endpoint. + pattern: ^/ + metadata: + type: array + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputBeyondtrustHec + InputHashicorpHcpVaultDedicated: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - hashicorp_hcp_vault_dedicated + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 requestTimeout: type: number title: Request timeout (seconds) - description: HTTP request inactivity timeout. Use 0 to disable. + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. minimum: 0 - maximum: 2400 - breakerRulesets: + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: + type: string + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for HashiCorp HCP Vault Dedicated + HTTP Event Collector API requests + pattern: ^/ + metadata: type: array - title: Event Breaker rulesets - description: A list of event-breaking rulesets that will be applied, in order, - to the input data stream + title: Fields + description: Fields to add to every event. May be overridden by fields added at + the token or request level. + items: + $ref: "#/components/schemas/MetadataConfInputCollection" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 items: type: string - staleChannelFlushMs: + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics + description: + type: string + title: Description + description: Optional description for this configuration. + __template_environment: + type: string + description: Binds 'environment' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'environment' at runtime. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputHashicorpHcpVaultDedicated + InputMimecastHec: + type: object + required: + - type + - host + - port + - hecAPI + properties: + id: + type: string + title: Input ID + description: Unique ID for this input + type: + type: string + description: Source type identifier. + enum: + - mimecast_hec + disabled: + type: boolean + title: Disabled + description: If true, the Source is disabled and will not collect data. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data from this Source before sending it through + the Routes + sendToRoutes: + type: boolean + description: Select whether to send data to Routes, or directly to Destinations. + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + pqEnabled: + type: boolean + title: Enable persistent queue + description: Use a disk queue to minimize data loss when connected services + block. See [Cribl + Docs](https://docs.cribl.io/stream/persistent-queues) for PQ + defaults (Cribl-managed Cloud Workers) and configuration options + (on-prem and hybrid Workers). + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + criblSourceProvenance: + $ref: "#/components/schemas/InputProvenanceTypeOptional" + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be + set on create. + connections: + type: array + title: Use QuickConnect + description: Direct connections to Destinations, and optionally via a Pipeline + or a Pack + items: + $ref: "#/components/schemas/ConnectionConfInputCollection" + pq: + $ref: "#/components/schemas/PqType" + host: + type: string + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: type: number - title: Event Breaker buffer timeout (ms) - description: How long (in milliseconds) the Event Breaker will wait for new data - to be sent to a specific channel before flushing the data stream - out, as is, to the Pipelines - minimum: 10 - maximum: 43200000 - keepAliveTime: + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: type: number - title: Keep alive time (seconds) - description: How often workers should check in with the scheduler to keep job - subscription alive - minimum: 10 - maxMissedKeepAlives: + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: + type: string + readOnly: true + const: "" + activityLogSampleRate: type: number - title: Worker timeout (periods) - description: The number of Keep Alive Time periods before an inactive worker - will have its job subscription revoked. - minimum: 2 - ttl: + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 + requestTimeout: + type: number + title: Request timeout (seconds) + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. + minimum: 0 + socketTimeout: + type: number + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: + type: number + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: type: string - title: Time to live - description: Time to keep the job's artifacts on disk after job completion. This - also affects how long a job is listed in the Job Inspector. - pattern: \d+[smh]$ - ignoreGroupJobsLimit: - type: boolean - title: Ignore Worker Group job limits - description: When enabled, this job's artifacts are not counted toward the - Worker Group's finished job artifacts limit. Artifacts will be - removed only after the Collector's configured time to live. + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for Mimecast HTTP Event Collector + API requests. This input supports the /event and /raw endpoints. + pattern: ^/ metadata: type: array title: Fields - description: Fields to add to events from this input + description: Fields to add to every event. May be overridden by fields added at + the token or request level. items: $ref: "#/components/schemas/MetadataConfInputCollection" - retryRules: - $ref: "#/components/schemas/RetryRulesType" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics description: type: string title: Description @@ -33011,13 +37083,47 @@ components: description: Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. - title: InputAnthropicCompliance - InputOkta: + __template_host: + type: string + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputMimecastHec + InputTrendMicroVisionOne: type: object required: - type - - textSecret - - oktaDomain + - host + - port + - hecAPI properties: id: type: string @@ -33025,9 +37131,9 @@ components: description: Unique ID for this input type: type: string + description: Source type identifier. enum: - - okta - description: Connector type identifier. + - trend_micro_vision_one disabled: type: boolean title: Disabled @@ -33060,8 +37166,7 @@ components: items: type: string criblSourceProvenance: - $ref: "#/components/schemas/InputCollectionOriginDataSourceDiscoveryWithDestina\ - tionArnConstraint" + $ref: "#/components/schemas/InputProvenanceTypeOptional" description: Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -33074,77 +37179,134 @@ components: $ref: "#/components/schemas/ConnectionConfInputCollection" pq: $ref: "#/components/schemas/PqType" - oktaDomain: - type: string - title: Okta domain - description: "Your Okta domain (example: your-org). Do not include .okta.com, - https://, or trailing slashes." - oktaToken: - type: string - title: Okta API token - description: Your Okta API token for authentication - textSecret: - type: string - title: Okta API token (text secret) - description: Select or create a stored text secret - cronSchedule: - type: string - title: Cron schedule - description: Schedule on which to run this collection job - earliest: - type: string - title: Earliest - description: Earliest time for data collection, relative to now - latest: + host: type: string - title: Latest - description: Latest time for data collection, relative to now - manageState: - type: object - jobTimeout: + title: Address + description: Address to bind on. Defaults to 0.0.0.0 (all addresses). + port: + type: number + title: Port + maximum: 65535 + description: Port to listen on + authTokens: + type: array + title: Auth tokens + description: "Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted." + items: + $ref: "#/components/schemas/AuthTokenConfInputCloudflareHec" + tls: + $ref: "#/components/schemas/TlsSettingsServerSideType" + description: TLS settings (server side) + maxActiveReq: + type: number + title: Active request limit + description: "Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput." + minimum: 0 + maxRequestsPerSocket: + type: integer + title: Requests-per-socket limit + description: Maximum number of requests per socket before @{product} instructs + the client to close the connection. Default is 0 (unlimited). + minimum: 0 + enableProxyHeader: + type: boolean + title: Show originating IP + description: Extract the client IP and port from PROXY protocol v1/v2. When + enabled, the X-Forwarded-For header is ignored. Disable to use the + X-Forwarded-For header for client IP extraction. + captureHeaders: + type: boolean + title: Capture request headers + description: Add request headers to events, in the __headers field + captureHeadersWarning: type: string - title: Job timeout - description: Maximum time the job is allowed to run (e.g., 30, 45s or 15m). - Units are seconds, if not specified. Enter 0 for unlimited time. - pattern: ^\d+[sm]?$ + readOnly: true + const: "" + activityLogSampleRate: + type: number + title: Activity log sample rate + description: How often request activity is logged at the `info` level. A value + of 1 would log every request, 10 every 10th request, etc. + minimum: 1 requestTimeout: type: number title: Request timeout (seconds) - description: HTTP request inactivity timeout. Use 0 to disable. + description: How long to wait for an incoming request to complete before + aborting it. Use 0 to disable. minimum: 0 - maximum: 2400 - keepAliveTime: + socketTimeout: type: number - title: Keep alive time (seconds) - description: How often workers should check in with the scheduler to keep job - subscription alive - minimum: 10 - maxMissedKeepAlives: + title: Socket timeout (seconds) + description: How long @{product} should wait before assuming that an inactive + socket has timed out. To wait forever, set to 0. + minimum: 0 + keepAliveTimeout: type: number - title: Worker timeout (periods) - description: The number of Keep Alive Time periods before an inactive worker - will have its job subscription revoked. - minimum: 2 - ttl: + title: Keep-alive timeout (seconds) + description: After the last response is sent, @{product} will wait this long for + additional data before closing the socket connection. Minimum 1 + second, maximum 600 seconds (10 minutes). + minimum: 1 + maximum: 600 + ipAllowlistRegex: type: string - title: Time to live - description: Time to keep the job's artifacts on disk after job completion. This - also affects how long a job is listed in the Job Inspector. - pattern: \d+[smh]$ - ignoreGroupJobsLimit: - type: boolean - title: Ignore Worker Group job limits - description: When enabled, this job's artifacts are not counted toward the - Worker Group's finished job artifacts limit. Artifacts will be - removed only after the Collector's configured time to live. + title: IP allowlist regex + description: Messages from matched IP addresses will be processed, unless also + matched by the denylist + ipDenylistRegex: + type: string + title: IP denylist regex + description: Messages from matched IP addresses will be ignored. This takes + precedence over the allowlist. + hecAPI: + type: string + title: HEC endpoint + description: Absolute path on which to listen for the Trend Micro Vision One + HTTP Event Collector API requests. This input supports the /event + endpoint. + pattern: ^/ metadata: type: array title: Fields - description: Fields to add to events from this input + description: Fields to add to every event. May be overridden by fields added at + the token or request level. items: $ref: "#/components/schemas/MetadataConfInputCollection" - retryRules: - $ref: "#/components/schemas/RetryRulesType" + allowedIndexes: + type: array + title: Allowed indexes + description: List values allowed in HEC event index field. Leave blank to skip + validation. Supports wildcards. The values here can expand index + validation at the token level. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowOrigin: + title: CORS allowed origins + type: array + description: HTTP origins to which @{product} should send CORS (cross-origin + resource sharing) Access-Control-Allow-* headers. Supports + wildcards. + minItems: 0 + items: + type: string + minLength: 1 + accessControlAllowHeaders: + title: CORS allowed headers + type: array + description: HTTP headers that @{product} will send to allowed origins as + "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" + to allow all headers. + minItems: 0 + items: + type: string + minLength: 1 + emitTokenMetrics: + type: boolean + title: Emit per-token request metrics + description: Emit per-token (.http.perToken) and summary + (.http.summary) request metrics description: type: string title: Description @@ -33159,12 +37321,40 @@ components: description: Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. - __template_oktaDomain: + __template_host: type: string - description: Binds 'oktaDomain' to a variable for dynamic value resolution. Set - to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'oktaDomain' at runtime. - title: InputOkta + description: Binds 'host' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'host' at runtime. + __template_port: + type: string + description: Binds 'port' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'port' at runtime. + __template_hecAPI: + type: string + description: Binds 'hecAPI' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'hecAPI' at runtime. + __template_allowedIndexes: + type: string + description: Binds 'allowedIndexes' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'allowedIndexes' at + runtime. + __template_accessControlAllowOrigin: + type: string + description: Binds 'accessControlAllowOrigin' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowOrigin' at runtime. + __template_accessControlAllowHeaders: + type: string + description: Binds 'accessControlAllowHeaders' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'accessControlAllowHeaders' at runtime. + title: InputTrendMicroVisionOne Input: oneOf: - $ref: "#/components/schemas/InputCollection" @@ -33175,6 +37365,7 @@ components: - $ref: "#/components/schemas/InputSplunkSearch" - $ref: "#/components/schemas/InputSplunkHec" - $ref: "#/components/schemas/InputAzureBlob" + - $ref: "#/components/schemas/InputAzureVnetFlowLog" - $ref: "#/components/schemas/InputElastic" - $ref: "#/components/schemas/InputConfluentCloud" - $ref: "#/components/schemas/InputGrafana" @@ -33231,13 +37422,29 @@ components: - $ref: "#/components/schemas/InputSecurityLake" - $ref: "#/components/schemas/InputBedrockS3" - $ref: "#/components/schemas/InputServicenowTable" + - $ref: "#/components/schemas/InputProofpointPod" - $ref: "#/components/schemas/InputZscalerHec" - $ref: "#/components/schemas/InputCloudflareHec" - $ref: "#/components/schemas/InputSysdigHec" - $ref: "#/components/schemas/InputUpwindHec" + - $ref: "#/components/schemas/InputTrellixHec" + - $ref: "#/components/schemas/InputSailpointHec" + - $ref: "#/components/schemas/InputExtrahopRevealx360" + - $ref: "#/components/schemas/InputAquaSecurityHec" - $ref: "#/components/schemas/InputOpenaiComplianceLogs" - $ref: "#/components/schemas/InputAnthropicCompliance" + - $ref: "#/components/schemas/InputAnthropicEnterpriseAnalytics" + - $ref: "#/components/schemas/InputMicrosoftCopilot" - $ref: "#/components/schemas/InputOkta" + - $ref: "#/components/schemas/InputAkamaiHec" + - $ref: "#/components/schemas/InputPingIdentityPingone" + - $ref: "#/components/schemas/InputGigamonHec" + - $ref: "#/components/schemas/InputVectraAiHec" + - $ref: "#/components/schemas/InputF5BigIp" + - $ref: "#/components/schemas/InputBeyondtrustHec" + - $ref: "#/components/schemas/InputHashicorpHcpVaultDedicated" + - $ref: "#/components/schemas/InputMimecastHec" + - $ref: "#/components/schemas/InputTrendMicroVisionOne" discriminator: propertyName: type mapping: @@ -33249,6 +37456,7 @@ components: splunk_search: "#/components/schemas/InputSplunkSearch" splunk_hec: "#/components/schemas/InputSplunkHec" azure_blob: "#/components/schemas/InputAzureBlob" + azure_vnet_flow_log: "#/components/schemas/InputAzureVnetFlowLog" elastic: "#/components/schemas/InputElastic" confluent_cloud: "#/components/schemas/InputConfluentCloud" grafana: "#/components/schemas/InputGrafana" @@ -33305,13 +37513,29 @@ components: security_lake: "#/components/schemas/InputSecurityLake" bedrock_s3: "#/components/schemas/InputBedrockS3" servicenow_table: "#/components/schemas/InputServicenowTable" + proofpoint_pod: "#/components/schemas/InputProofpointPod" zscaler_hec: "#/components/schemas/InputZscalerHec" cloudflare_hec: "#/components/schemas/InputCloudflareHec" sysdig_hec: "#/components/schemas/InputSysdigHec" upwind_hec: "#/components/schemas/InputUpwindHec" + trellix_hec: "#/components/schemas/InputTrellixHec" + sailpoint_hec: "#/components/schemas/InputSailpointHec" + extrahop_revealx_360: "#/components/schemas/InputExtrahopRevealx360" + aqua_security_hec: "#/components/schemas/InputAquaSecurityHec" openai_compliance_logs: "#/components/schemas/InputOpenaiComplianceLogs" anthropic_compliance: "#/components/schemas/InputAnthropicCompliance" + anthropic_enterprise_analytics: "#/components/schemas/InputAnthropicEnterpriseAnalytics" + microsoft_copilot: "#/components/schemas/InputMicrosoftCopilot" okta: "#/components/schemas/InputOkta" + akamai_hec: "#/components/schemas/InputAkamaiHec" + ping_identity_pingone: "#/components/schemas/InputPingIdentityPingone" + gigamon_hec: "#/components/schemas/InputGigamonHec" + vectra_ai_hec: "#/components/schemas/InputVectraAiHec" + f5_big_ip: "#/components/schemas/InputF5BigIp" + beyondtrust_hec: "#/components/schemas/InputBeyondtrustHec" + hashicorp_hcp_vault_dedicated: "#/components/schemas/InputHashicorpHcpVaultDedicated" + mimecast_hec: "#/components/schemas/InputMimecastHec" + trend_micro_vision_one: "#/components/schemas/InputTrendMicroVisionOne" title: Input CountedInputSplunkHec: type: object @@ -33321,10 +37545,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/InputSplunkHec" AddHecTokenRequest: @@ -33364,10 +37588,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: type: string CountedJobInfo: @@ -33378,10 +37602,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/JobInfo" RunnableJobCollection: @@ -33456,6 +37680,7 @@ components: routing, and preprocessing options. run: type: object + description: Run settings that control how and when the Collection job runs. required: - mode properties: @@ -33474,9 +37699,7 @@ components: jobTimeout: title: Job timeout type: string - description: "Maximum time the job is allowed to run. Time unit defaults to - seconds if not specified (examples: 30, 45s, 15m). Enter 0 for - unlimited time." + description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: \d+[sm]?$ mode: type: string @@ -33515,10 +37738,6 @@ components: type: string description: Timezone to use for Earliest and Latest times title: Range timezone - timeWarning: - $ref: "#/components/schemas/TimeWarningTypeRunnableJobCollectionScheduleRun" - description: Warning state used when the collection time range is unset for - time-sensitive Collectors. expression: type: string title: Filter @@ -33655,6 +37874,7 @@ components: description: Executor configuration, including the executor type and its settings. run: type: object + description: Run settings that control how and when the Executor job runs. properties: rescheduleDroppedTasks: type: boolean @@ -33671,9 +37891,7 @@ components: jobTimeout: title: Job timeout type: string - description: "Maximum time the job is allowed to run. Time unit defaults to - seconds if not specified (examples: 30, 45s, 15m). Enter 0 for - unlimited time." + description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: \d+[sm]?$ __template_streamtags: type: string @@ -33884,154 +38102,178 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/InputResponse" - Notification: + MetadataItem: + type: object + properties: + name: + type: string + description: Name of the metadata field. + value: + type: string + description: JavaScript expression to compute the metadata field's value, + enclosed in quotes or backticks. Can evaluate to a constant. + required: + - name + - value + title: MetadataItem + NotificationMode: + type: string + enum: + - direct + - policy + title: NotificationMode + x-speakeasy-unknown-values: allow + EmailRecipient: + type: object + properties: + bcc: + type: string + description: "Bcc: Recipients' email addresses." + cc: + type: string + description: "Cc: Recipients' email addresses." + to: + type: string + description: Recipients' email addresses. + required: + - to + title: EmailRecipient + NotificationSmtpTargetConfig: type: object + properties: + body: + type: string + description: Email body. + emailRecipient: + $ref: "#/components/schemas/EmailRecipient" + description: Email recipient settings for the Notification target. + subject: + type: string + description: Email subject. + required: + - emailRecipient + title: NotificationSmtpTargetConfig + NotificationTargetConfig: + type: object + properties: + conf: + $ref: "#/components/schemas/NotificationSmtpTargetConfig" + description: Simple Mail Transfer Protocol (SMTP) configuration for the + Notification target. + id: + type: string + description: The id of the Notification target. required: - id - - condition + title: NotificationTargetConfig + NotificationTargetDetails: + type: object properties: id: type: string - title: ID - pattern: ^[a-zA-Z0-9_-]+$ - description: Unique identifier for the Notification. - disabled: + description: The id of the Notification target. + type: + type: string + description: The type of the Notification target. + required: + - id + - type + title: NotificationTargetDetails + Notification: + type: object + properties: + __srcGroup: + type: string + description: Fleet or group id this entity was inherited from when served by a + Config Helper for a child fleet. Present when inherited from parent, + including when the child has a local overlay. Omitted when the + entity is local and not inherited. Display-only; never persisted. + __srcOverridden: type: boolean - title: Disabled - description: If true, the Notification is disabled and the specified condition - will not trigger it. + description: If true, the child fleet has a local overlay on an inherited + entity. Omitted when inherited and unmodified, or when local and not + inherited. Display-only; never persisted. condition: type: string - title: Condition - description: The condition that triggers the Notification. - targets: + description: The condition that triggers the Notification. Use GET + /conditions for a list of supported condition + values. + conf: + type: object + additionalProperties: true + description: Configuration for the condition that triggers the + Notification. Supported fields vary depending on the + condition. Use GET /conditions/{id} to + review the configuration for a specific condition. + disabled: + type: boolean + description: If true, the Notification is disabled and the + specified condition will not trigger it. + group: + type: string + description: The id of the Worker Group or Edge Fleet that the + Notification applies to. + id: + type: string + description: Unique identifier. + metadata: type: array - title: Notification targets - description: List of the IDs for the Notification targets to send the - Notification to. items: - type: string + $ref: "#/components/schemas/MetadataItem" + description: Metadata tags for the Notification. + mode: + $ref: "#/components/schemas/NotificationMode" + description: "Delivery mode for Notifications.

direct: Notification is sent directly to Notification targets that are defined in templateTargetPairs.

policy: Notification is routed through Notification Policies, which match alerts by labels and route them to Notification targets without relying on templateTargetPairs." + pack: + type: string + description: The id of the Pack the Notification belongs to. + Automatically populated and returned in responses. targetConfigs: type: array - title: Target configuration + items: + $ref: "#/components/schemas/NotificationTargetConfig" description: Override settings to apply for each referenced Notification target. + targetDetails: + type: array items: - type: object - required: - - id - properties: - id: - type: string - title: Notification target ID - description: The id of the Notification target. - pattern: ^[a-zA-Z0-9_-]+$ - anyOf: - - properties: - conf: - type: object - title: Notification config for SMTP target - properties: - subject: - type: string - title: Subject - description: Email subject - body: - type: string - title: Message - description: Email body - emailRecipient: - type: object - required: - - to - properties: - to: - type: string - title: To - description: Recipients' email addresses - cc: - type: string - title: Cc - description: "Cc: Recipients' email addresses" - bcc: - type: string - title: Bcc - description: "Bcc: Recipients' email addresses" - description: Email recipient settings for the Notification target. - description: Simple Mail Transfer Protocol (SMTP) configuration for the - Notification target. - conf: - type: object - title: Condition-specific configurations - description: Configuration for the condition that triggers the Notification. - Supported fields vary depending on the condition. - properties: {} - metadata: + $ref: "#/components/schemas/NotificationTargetDetails" + description: Additional details about referenced Notification targets. + Optionally populated on request. + targets: type: array - title: Fields - description: Fields to add to events from this input items: - $ref: "#/components/schemas/MetadataConfInputCollection" - group: - type: string - title: Worker Group/Fleet - description: The worker group/fleet this notification belongs to - pack: - type: string - title: Pack - description: The pack this notification belongs to - mode: - type: string - title: Mode - description: "Notification mode: direct or policy-based" - enum: - - direct - - policy - x-speakeasy-unknown-values: allow - examples: - - direct + type: string + description: List of the id values for the Notification targets to + send the Notification to. templateTargetPairs: type: array - title: Template & Target Pairs - description: Pairs of templates and targets for notification routing items: - $ref: "#/components/schemas/TemplateTargetPairConfFunctionConfSchemaNotificatio\ - nPolicies" - oneOf: - - properties: - mode: - const: direct - description: Delivery mode for Notifications. - templateTargetPairs: - type: array - minItems: 1 - description: Template and target pairs for direct Notification delivery. - items: - $ref: "#/components/schemas/TemplateTargetPairConfFunctionConfSchemaNotificatio\ - nPolicies" - required: - - mode - - templateTargetPairs - - properties: - mode: - const: policy - description: Delivery mode for Notifications. - templateTargetPairs: - type: array - maxItems: 0 - description: Template and target pairs for direct Notification delivery. - items: - $ref: "#/components/schemas/TemplateTargetPairConfFunctionConfSchemaNotificatio\ - nPolicies" - required: - - mode - - properties: - mode: {} + type: object + properties: + targetId: + type: string + description: The id of the Notification target to send the + Notification to. + templateId: + type: string + description: The id of the Notification template to use. + required: + - targetId + - templateId + description: If mode is direct, the key-value pairs + that define the Notification templates and targets to use for + sending Notifications. + required: + - condition + - conf + - id + - targets title: Notification StatusError: type: object @@ -34051,13 +38293,22 @@ components: properties: error: $ref: "#/components/schemas/StatusError" + description: Error information for the persistent queue, if applicable. health: - type: number + type: integer + description: Persistent queue health status for the Worker Process, as a numeric + code.

0 == Healthy (green; normal + operation)

1 == Degraded (yellow; potential + issues)

2 == Critical (red; problem or error + that affects operation). metrics: type: object additionalProperties: true + description: Persistent-queue metrics reported for the Worker Process. timestamp: - type: number + type: integer + description: Timestamp (in Unix time) when the persistent queue status was last + reported for the Worker Process, in milliseconds. required: - health - metrics @@ -34075,8 +38326,7 @@ components: description: Notifications attached to the Source. status: $ref: "#/components/schemas/StatusType" - description: "Runtime status: health, metrics, and optional persistent-queue - info. Fields may be absent when data is unavailable." + description: "Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable." description: Source configuration with optional Notifications and runtime status. title: InputResponse SourceType: @@ -34092,12 +38342,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/InputResponse" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -34381,11 +38632,7 @@ components: customSourceExpression: type: string title: Source expression - description: "Expression to evaluate on events to generate output. Example: - `raw=${_raw}`. See [Cribl - Docs](https://docs.cribl.io/stream/destinations-webhook#custom-form\ - at) for other examples. If empty, the full event is sent as - stringified JSON." + description: "Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON." customDropWhenNull: type: boolean title: Drop when null @@ -34415,21 +38662,11 @@ components: formatEventCode: type: string title: Format inbound event - description: "Custom JavaScript code to format incoming event data accessible - through the __e variable. The formatted content is added to - (__e['__eventOut']) if available. Otherwise, the original event is - serialized as JSON. Caution: This function is evaluated in an - unprotected context, allowing you to execute almost any JavaScript - code." + description: "Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code." formatPayloadCode: type: string title: Format outbound payload - description: "Optional JavaScript code to format the payload sent to the - Destination. The payload, containing a batch of formatted events, is - accessible through the __e['payload'] variable. The formatted - payload is returned in the __e['__payloadOut'] variable. Caution: - This function is evaluated in an unprotected context, allowing you - to execute almost any JavaScript code." + description: "Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code." pqStrictOrdering: title: Strict ordering description: Use FIFO (first in, first out) processing. Disable to forward new @@ -34477,8 +38714,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -34541,9 +38777,7 @@ components: authHeaderExpr: type: string title: Authorize expression - description: "JavaScript expression to compute the Authorization header value to - pass in requests. The value `${token}` is used to reference the - token obtained from authentication, e.g.: `Bearer ${token}`." + description: "JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`." tokenTimeoutSecs: type: number title: Refresh interval (secs.) @@ -34572,16 +38806,11 @@ components: refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, @{product} will use the - refresh token to obtain new access tokens without re-sending - credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token - description: "@{product} will update the stored value on each successful - refresh. Enable if the server issues a new refresh token on every - use." + description: "@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use." refreshUrl: type: string title: Refresh URL @@ -34595,8 +38824,7 @@ components: servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" url: type: string title: Webhook URL @@ -34697,7 +38925,6 @@ components: - type - endpointURLConfiguration - loginUrl - - secret - client_id properties: id: @@ -34843,23 +39070,14 @@ components: title: Login URL description: URL for OAuth pattern: ^https?://.* - secret: - type: string - title: OAuth secret - description: Secret parameter value to pass in request body refreshTokenField: type: string title: Refresh token field - description: "Field name in the token response that contains a refresh token - (example: 'refresh_token'). When set, @{product} will use the - refresh token to obtain new access tokens without re-sending - credentials." + description: "Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials." rotateRefreshToken: type: boolean title: Rotate refresh token - description: "@{product} will update the stored value on each successful - refresh. Enable if the server issues a new refresh token on every - use." + description: "@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use." refreshUrl: type: string title: Refresh URL @@ -34873,8 +39091,15 @@ components: servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret. items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" + oauthSecretSource: + type: string + title: OAuth secret source + description: Enter the OAuth secret directly, or select a stored text secret + enum: + - inline + - secret + x-speakeasy-unknown-values: allow client_id: title: Client ID type: string @@ -34916,11 +39141,7 @@ components: customSourceExpression: type: string title: Source expression - description: "Expression to evaluate on events to generate output. Example: - `raw=${_raw}`. See [Cribl - Docs](https://docs.cribl.io/stream/destinations-webhook#custom-form\ - at) for other examples. If empty, the full event is sent as - stringified JSON." + description: "Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON." customDropWhenNull: type: boolean title: Drop when null @@ -34950,21 +39171,11 @@ components: formatEventCode: type: string title: Format inbound event - description: "Custom JavaScript code to format incoming event data accessible - through the __e variable. The formatted content is added to - (__e['__eventOut']) if available. Otherwise, the original event is - serialized as JSON. Caution: This function is evaluated in an - unprotected context, allowing you to execute almost any JavaScript - code." + description: "Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code." formatPayloadCode: type: string title: Format outbound payload - description: "Optional JavaScript code to format the payload sent to the - Destination. The payload, containing a batch of formatted events, is - accessible through the __e['payload'] variable. The formatted - payload is returned in the __e['__payloadOut'] variable. Caution: - This function is evaluated in an unprotected context, allowing you - to execute almost any JavaScript code." + description: "Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code." pqStrictOrdering: title: Strict ordering description: Use FIFO (first in, first out) processing. Disable to forward new @@ -35012,8 +39223,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -35034,6 +39244,14 @@ components: type: object title: "" description: Persistent queue controls. + secret: + type: string + title: OAuth secret + description: Secret parameter value to pass in request body + oauthTextSecret: + type: string + title: OAuth secret (text secret) + description: Select or create a stored text secret for the OAuth secret value url: title: URL type: string @@ -35046,9 +39264,7 @@ components: dceEndpoint: type: string title: Data collection endpoint - description: "Data collection endpoint (DCE) URL. In the format: - `https://-..ingest.monitor.azure\ - .com`" + description: "Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`" pattern: ^https:\/\/([a-zA-Z0-9-_\.]+)\.ingest\.monitor\.azure\.com(\/?)$ streamName: type: string @@ -35076,11 +39292,6 @@ components: description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. - __template_secret: - type: string - description: Binds 'secret' to a variable for dynamic value resolution. Set to - variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'secret' at runtime. __template_refreshUrl: type: string description: Binds 'refreshUrl' to a variable for dynamic value resolution. Set @@ -35096,6 +39307,11 @@ components: description: Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime. + __template_secret: + type: string + description: Binds 'secret' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'secret' at runtime. __template_url: type: string description: Binds 'url' to a variable for dynamic value resolution. Set to @@ -35341,9 +39557,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ octetCountFraming: type: boolean @@ -35490,8 +39704,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -35587,9 +39800,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ connectionTimeout: type: number @@ -35625,7 +39836,7 @@ components: $ref: "#/components/schemas/BackpressureBehaviorOptions" description: How to handle events when all receivers are exerting backpressure authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate description: @@ -35691,8 +39902,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -35822,9 +40032,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ connectionTimeout: type: number @@ -35872,7 +40080,7 @@ components: minimum: 0 maximum: 60000 authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate description: @@ -35911,8 +40119,7 @@ components: type: string pattern: ^https?://[a-zA-Z0-9-._]+:[0-9]+$ title: Cluster manager URI - description: "Full URI of Splunk cluster manager (scheme://host:port). Example: - https://managerAddress:8089" + description: "Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089" refreshIntervalSec: type: number minimum: 60 @@ -35935,7 +40142,7 @@ components: type: object properties: authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate authToken: @@ -35948,7 +40155,7 @@ components: title: Auth token (text secret) description: Select or create a stored text secret authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate authToken: @@ -36019,8 +40226,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -36192,7 +40398,7 @@ components: description: Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event. authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate responseRetrySettings: @@ -36343,8 +40549,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -36500,7 +40705,7 @@ components: items: type: string authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate responseRetrySettings: @@ -36540,7 +40745,18 @@ components: wiz_sourcetype: type: string title: Wiz Defend Source type - description: Wiz Defend Source type + description: The Wiz log source type. Select a predefined type or enter a custom + value. + enum: + - AWS_CLOUDTRAIL + - AWS_EKS_AUDIT_LOGS + - AWS_RESOLVER_QUERY_LOGS + - AZURE_ACTIVITY_LOGS + - GCP_AUDIT_LOGS + - GITHUB_AUDIT_LOGS + - OCI_AUDIT_LOGS + - AWS_VPC_FLOW_LOGS + x-speakeasy-unknown-values: allow onBackpressure: $ref: "#/components/schemas/BackpressureBehaviorOptions" description: How to handle events when all receivers are exerting backpressure @@ -36556,6 +40772,19 @@ components: type: string title: Authentication token (text secret) description: Select or create a stored text secret + wiz_vpc_event_format: + enum: + - json + - csv_row + type: string + title: Event format + description: The format of the VPC Flow Log events + x-speakeasy-unknown-values: allow + wiz_vpc_flow_log_format: + type: string + title: Flow log format + description: The format string for VPC Flow Log fields + minLength: 1 pqStrictOrdering: title: Strict ordering description: Use FIFO (first in, first out) processing. Disable to forward new @@ -36603,8 +40832,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -36706,9 +40934,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ tls: $ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath" @@ -36740,7 +40966,7 @@ components: $ref: "#/components/schemas/BackpressureBehaviorOptions" description: How to handle events when all receivers are exerting backpressure authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate description: @@ -36835,8 +41061,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -36928,7 +41153,7 @@ components: items: type: string authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate domain: @@ -37089,8 +41314,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -37167,7 +41391,7 @@ components: items: type: string authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate realm: @@ -37330,8 +41554,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -37728,10 +41951,7 @@ components: bucket: type: string title: S3 bucket name - description: "Name of the destination S3 bucket. Must be a JavaScript expression - (which can evaluate to a constant value), enclosed in quotes or - backticks. Can be evaluated only at initialization time. Example - referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -37739,10 +41959,7 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -37864,8 +42081,7 @@ components: awsSecretKey: type: string title: Secret key - description: "Secret key. This value can be a constant or a JavaScript - expression. Example: `${C.env.SOME_SECRET}`)" + description: "Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)" objectACL: $ref: "#/components/schemas/ObjectAclOptions" description: Object ACL to assign to uploaded objects @@ -39022,8 +43238,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -39254,12 +43469,7 @@ components: apiUrl: type: string title: DNS name of API endpoint - description: "The DNS name of the Log API endpoint that sends log data to a Log - Analytics workspace in Azure Monitor. Defaults to - .ods.opinsights.azure.com. @{product} will add a prefix and suffix - to construct a URI in this format: - /api/logs?api-version=." + description: "The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=." pattern: ^\.[^\/]+$ responseRetrySettings: type: array @@ -39342,8 +43552,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -39605,8 +43814,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -39864,8 +44072,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -40112,8 +44319,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -40320,8 +44526,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -40673,8 +44878,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -40771,10 +44975,7 @@ components: bucket: type: string title: Bucket name - description: "Name of the destination bucket. This value can be a constant or a - JavaScript expression that can only be evaluated at init time. - Example of referencing a Global Variable: - `myBucket-${C.vars.myVar}`." + description: "Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`." region: type: string title: Region @@ -40804,18 +45005,14 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" verifyPermissions: type: boolean title: Verify if bucket exists description: Disable if you can access files within the bucket but not the bucket itself objectACL: - $ref: "#/components/schemas/ObjectAclOptionsAuthenticatedreadBucketownerfullcon\ - trol" + $ref: "#/components/schemas/ObjectAclOptionsAuthenticatedreadBucketownerfullcontrol" description: Object ACL to assign to uploaded objects storageClass: $ref: "#/components/schemas/StorageClassOptionsArchiveColdline" @@ -41557,8 +45754,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -41867,8 +46063,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -42069,8 +46264,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -42157,10 +46351,7 @@ components: bucket: type: string title: Bucket name - description: "Name of the destination bucket. A constant or a JavaScript - expression that can only be evaluated at init time. Example of - referencing a JavaScript Global Variable: - `myBucket-${C.vars.myVar}`." + description: "Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`." region: type: string title: Region @@ -42175,8 +46366,7 @@ components: title: Endpoint description: Google Cloud Storage service endpoint objectACL: - $ref: "#/components/schemas/ObjectAclOptionsAuthenticatedreadBucketownerfullcon\ - trol" + $ref: "#/components/schemas/ObjectAclOptionsAuthenticatedreadBucketownerfullcontrol" description: Object ACL to assign to uploaded objects storageClass: $ref: "#/components/schemas/StorageClassOptionsArchiveColdline" @@ -42255,6 +46445,17 @@ components: description: > ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + awsAuthenticationMethod: + type: string + title: Authentication method + enum: + - manual + - secret + x-speakeasy-enum-descriptions: + - Manual + - Secret + description: Authentication method + x-speakeasy-unknown-values: allow siteName: type: string title: Site name @@ -42270,6 +46471,40 @@ components: type: string title: Timezone offset description: Timezone offset + hostname: + type: string + title: Hostname + description: JavaScript expression for the host from which the log was ingested + into the SIEM, evaluated per event. Static values must be quoted or + backticked (for example, 'collector-1.example.com'); unquoted text + is evaluated as JavaScript, not as a literal. To reference an event + field use an expression, such as `${host}`. Emitted as the + "hostname" metadata field; omitted when empty or not a usable + scalar. + forwarder: + type: string + title: Forwarder + description: JavaScript expression for the host that forwarded the log, + evaluated per event. Static values must be quoted or backticked (for + example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as + a literal. To reference an event field use an expression, such as + `${__forwarder}`. Emitted as the "forwarder" metadata field; omitted + when empty or not a usable scalar. + origin: + type: string + title: Origin + description: "JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object." + logtags: + type: string + title: Log tags + description: 'JavaScript expression that must resolve to an object of custom + metadata key/value pairs (searchable in Exabeam as + m_c_logtags_). Assemble the object upstream and reference it + here (example: __exabeam_logtags), or build it inline (example: + {department: dept, servertype: stype}). Evaluated per event. + Unquoted text is evaluated as JavaScript, not as a literal. Emitted + as the "logtags" metadata field; omitted when the result is not a + non-empty object.' awsApiKey: type: string title: Access key @@ -42307,6 +46542,11 @@ components: description: The maximum number of times a file will attempt to move to its final destination before being dead-lettered minimum: 1 + awsSecret: + type: string + title: Secret key pair + description: Select or create a stored secret that references your access key + and secret key __template_streamtags: type: string description: Binds 'streamtags' to a variable for dynamic value resolution. Set @@ -42419,8 +46659,7 @@ components: forcing a flush. Shorter intervals tend to result in smaller batches being sent. kafkaSchemaRegistry: - $ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschema\ - RegistryUrlAuth" + $ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryUrlAuth" description: Kafka Schema Registry Authentication connectionTimeout: type: number @@ -42553,8 +46792,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -42684,8 +46922,7 @@ components: forcing a flush. Shorter intervals tend to result in smaller batches being sent. kafkaSchemaRegistry: - $ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschema\ - RegistryUrlAuth" + $ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryUrlAuth" description: Kafka Schema Registry Authentication connectionTimeout: type: number @@ -42815,8 +47052,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -42951,8 +47187,7 @@ components: forcing a flush. Shorter intervals tend to result in smaller batches being sent. kafkaSchemaRegistry: - $ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschema\ - RegistryUrlAuth" + $ref: "#/components/schemas/KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryUrlAuth" description: Kafka Schema Registry Authentication connectionTimeout: type: number @@ -43138,8 +47373,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -43370,7 +47604,7 @@ components: description: Optional Elasticsearch version, used to format events. If not specified, will auto-discover version. enum: - - auto + - "auto" - "6" - "7" x-speakeasy-enum-descriptions: @@ -43415,8 +47649,7 @@ components: url: type: string title: Bulk API URL or Cloud ID - description: "The Cloud ID or URL to an Elastic cluster to send events to. - Example: http://elastic:9200/_bulk" + description: "The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk" useRoundRobinDns: type: boolean title: Round-robin DNS @@ -43442,8 +47675,7 @@ components: url: type: string title: URL - description: "The URL to an Elastic node to send events to. Example: - http://elastic:9200/_bulk" + description: "The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk" weight: type: number title: Load Weight @@ -43515,8 +47747,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -43779,8 +48010,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -43875,9 +48105,7 @@ components: logType: type: string title: Log type - description: "Name of the logtype to send with events, e.g.: observability, - access_log. The event's 'sourcetype' field (if set) will override - this value." + description: "Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value." messageField: type: string title: Log message field @@ -44067,8 +48295,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -44330,8 +48557,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -44655,8 +48881,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -44776,9 +49001,7 @@ components: logStreamName: type: string title: Log stream prefix - description: "Prefix for CloudWatch log stream name. This prefix will be used to - generate a unique log stream name per cribl instance, for example: - myStream_myHost_myOutputId" + description: "Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId" awsAuthenticationMethod: $ref: "#/components/schemas/AuthenticationMethodOptionsS3CollectorConf" description: AWS authentication method. Choose Auto to use IAM roles. @@ -44908,8 +49131,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -45037,10 +49259,7 @@ components: bucket: type: string title: MinIO bucket name - description: "Name of the destination MinIO bucket. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at initialization time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -45048,10 +49267,7 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -45173,8 +49389,7 @@ components: awsSecretKey: type: string title: Secret key - description: "Secret key. This value can be a constant or a JavaScript - expression. Example: `${C.env.SOME_SECRET}`)" + description: "Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)" endpoint: type: string title: MinIO endpoint @@ -45460,9 +49675,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ connectionTimeout: type: number @@ -45524,8 +49737,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -45638,9 +49850,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ connectionTimeout: type: number @@ -45702,8 +49912,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -45816,9 +50025,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ connectionTimeout: type: number @@ -45880,8 +50087,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -45951,6 +50157,13 @@ components: description: Metadata tags used for categorization and filtering. items: type: string + reportBranchMetrics: + type: boolean + title: Report Branch Metrics + description: Report per-rule event counts and percentages as internal metrics + (router.out_events, router.out_events_pct, router.in_events, + router.unmatched_events, router.unmatched_events_pct). Adds metric + series per rule. rules: type: array title: Rules @@ -46030,21 +50243,11 @@ components: topicArn: type: string title: Topic ARN - description: "The ARN of the SNS topic to send events to. When a non-AWS URL is - specified, format must be: '{url}/myQueueName'. E.g., - 'https://host:port/myQueueName'. Must be a JavaScript expression - (which can evaluate to a constant value), enclosed in quotes or - backticks. Can be evaluated only at initialization time. Example - referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`" + description: "The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`" messageGroupId: type: string title: Message Group ID - description: "Messages in the same group are processed in a FIFO manner. Must be - a JavaScript expression (which can evaluate to a constant value), - enclosed in quotes or backticks. Can be evaluated only at init time. - Example referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." maxRetries: type: number title: Maximum number of retries @@ -46161,8 +50364,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -46276,13 +50478,7 @@ components: queueName: type: string title: Queue Name - description: "The name, URL, or ARN of the SQS queue to send events to. When a - non-AWS URL is specified, format must be: '{url}/myQueueName'. - Example: 'https://host:port/myQueueName'. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: - `https://host:port/myQueue-${C.vars.myVar}`." + description: "The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`." queueType: title: Queue Type type: string @@ -46445,8 +50641,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -46845,8 +51040,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -47184,8 +51378,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -47297,14 +51490,10 @@ components: labels: type: array title: Logs labels - description: "List of labels to send with logs. Labels define Loki streams, so - use static labels to avoid proliferating label value combinations - and streams. Can be merged and/or overridden by the event's __labels - field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'" + description: "List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'" minItems: 0 items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" metricRenameExpr: type: string title: Metrics renaming expression @@ -47320,28 +51509,19 @@ components: concurrency: type: number title: Request concurrency - description: "Maximum number of ongoing requests before blocking. Warning: - Setting this value > 1 can cause Loki and Prometheus to complain - about entries being delivered out of order." + description: "Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order." minimum: 1 maximum: 32 maxPayloadSizeKB: type: number title: Body size limit (KB) - description: "Maximum size, in KB, of the request body. Warning: Setting this - too low can increase the number of ongoing requests (depending on - the value of 'Request concurrency'); this can cause Loki and - Prometheus to complain about entries being delivered out of order." + description: "Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order." minimum: 1024 maximum: 10240 maxPayloadEvents: type: number title: Events-per-request limit - description: "Maximum number of events to include in the request body. Default - is 0 (unlimited). Warning: Setting this too low can increase the - number of ongoing requests (depending on the value of 'Request - concurrency'); this can cause Loki and Prometheus to complain about - entries being delivered out of order." + description: "Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order." minimum: 0 rejectUnauthorized: type: boolean @@ -47369,14 +51549,7 @@ components: flushPeriodSec: type: number title: Flush period (sec) - description: "Maximum time between requests. Small values could cause the - payload size to be smaller than the configured Maximum time between - requests. Small values can reduce the payload size below the - configured 'Max record size' and 'Max events per request'. Warning: - Setting this too low can increase the number of ongoing requests - (depending on the value of 'Request concurrency'); this can cause - Loki and Prometheus to complain about entries being delivered out of - order." + description: "Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order." extraHttpHeaders: type: array title: Extra HTTP headers @@ -47478,8 +51651,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -47588,43 +51760,29 @@ components: labels: type: array title: Logs labels - description: "List of labels to send with logs. Labels define Loki streams, so - use static labels to avoid proliferating label value combinations - and streams. Can be merged and/or overridden by the event's __labels - field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'" + description: "List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'" minItems: 0 items: - $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOau\ - thSecret" + $ref: "#/components/schemas/RefreshRequestParamConfHealthCheckAuthenticationOauthSecret" authType: - $ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuthBasicCredent\ - ialsSecret" + $ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret" description: Authentication type concurrency: type: number title: Request concurrency - description: "Maximum number of ongoing requests before blocking. Warning: - Setting this value > 1 can cause Loki to complain about entries - being delivered out of order." + description: "Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order." minimum: 1 maximum: 32 maxPayloadSizeKB: type: number title: Body size limit (KB) - description: "Maximum size, in KB, of the request body. Warning: Setting this - too low can increase the number of ongoing requests (depending on - the value of 'Request concurrency'); this can cause Loki to complain - about entries being delivered out of order." + description: "Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order." minimum: 1024 maximum: 10240 maxPayloadEvents: type: number title: Events-per-request limit - description: "Maximum number of events to include in the request body. Defaults - to 0 (unlimited). Warning: Setting this too low can increase the - number of ongoing requests (depending on the value of 'Request - concurrency'); this can cause Loki to complain about entries being - delivered out of order." + description: "Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order." minimum: 0 rejectUnauthorized: type: boolean @@ -47652,13 +51810,7 @@ components: flushPeriodSec: type: number title: Flush period (sec) - description: "Maximum time between requests. Small values could cause the - payload size to be smaller than the configured Maximum time between - requests. Small values can reduce the payload size below the - configured 'Max record size' and 'Max events per request'. Warning: - Setting this too low can increase the number of ongoing requests - (depending on the value of 'Request concurrency'); this can cause - Loki to complain about entries being delivered out of order." + description: "Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order." extraHttpHeaders: type: array title: Extra HTTP headers @@ -47727,10 +51879,7 @@ components: token: type: string title: Auth token - description: "Bearer token to include in the authorization header. In Grafana - Cloud, this is generally built by concatenating the username and the - API key, separated by a colon. Example: - :" + description: "Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :" textSecret: type: string title: Auth token (text secret) @@ -47794,8 +51943,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -48084,8 +52232,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -48373,8 +52520,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -48549,14 +52695,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). - When limit is reached, older data will be deleted." + description: "Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted." pattern: ^\d+\s*(?:\w{2})?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data (examples: 2h, 4d). When - limit is reached, older data will be deleted." + description: "Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/DataCompressionFormatOptionsPersistence" @@ -48816,9 +52960,7 @@ components: authHeaderExpr: type: string title: Authorize expression - description: "JavaScript expression to compute the Authorization header value to - pass in requests. The value `${token}` is used to reference the - token obtained from authentication, e.g.: `Bearer ${token}`." + description: "JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`." tokenTimeoutSecs: type: number title: Refresh interval (secs.) @@ -48939,8 +53081,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -49248,8 +53389,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -49541,8 +53681,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -49642,9 +53781,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ tls: $ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath" @@ -49677,9 +53814,7 @@ components: excludeFields: type: array title: Exclude fields - description: "Fields to exclude from the event. By default, all internal fields - except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards - supported." + description: "Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported." items: type: string onBackpressure: @@ -49777,8 +53912,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -49876,9 +54010,297 @@ components: excludeFields: type: array title: Exclude fields - description: "Fields to exclude from the event. By default, all internal fields - except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards - supported." + description: "Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported." + items: + type: string + compression: + $ref: "#/components/schemas/CompressionOptionsGzipNone" + description: Codec to use to compress the data before sending + concurrency: + type: number + title: Request concurrency + description: Maximum number of ongoing requests before blocking + minimum: 1 + maximum: 32 + maxPayloadSizeKB: + type: number + title: Body size limit (KB) + description: Maximum size, in KB, of the request body + minimum: 1024 + maximum: 10240 + maxPayloadEvents: + type: number + title: Events-per-request limit + description: Maximum number of events to include in the request body. Default is + 0 (unlimited). + minimum: 0 + rejectUnauthorized: + type: boolean + title: Validate server certs + description: >- + Reject certificates not authorized by a CA in the CA certificate + path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + timeoutSec: + type: number + minimum: 1 + maximum: 9007199254740991 + title: Request timeout + description: Amount of time, in seconds, to wait for a request to complete + before canceling it + maxConnectionReuseSec: + type: number + minimum: 0 + title: Max connection reuse (seconds) + description: How long, in seconds, to reuse a keep-alive connection after its + first use before forcing it closed. Set to 0 to disable the + time-based close and reuse connections for as long as the + destination server permits. + flushPeriodSec: + type: number + title: Flush period (sec) + description: Maximum time between requests. Small values could cause the payload + size to be smaller than the configured Body size limit. + extraHttpHeaders: + type: array + title: Extra HTTP headers + description: Headers to add to all events + items: + $ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic" + failedRequestLoggingMode: + $ref: "#/components/schemas/FailedRequestLoggingModeOptions" + description: Data to log when a request fails. All headers are redacted by + default, unless listed as safe headers below. + safeHeaders: + type: array + title: Safe headers + description: List of headers that are safe to log in plain text + items: + type: string + throttleRatePerSec: + type: string + title: Throttling + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." + pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ + responseRetrySettings: + type: array + title: Settings for failed HTTP requests + description: Automatically retry after unsuccessful response status codes, such + as 429 (Too Many Requests) or 503 (Service Unavailable) + minItems: 0 + items: + $ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook" + timeoutRetrySettings: + $ref: "#/components/schemas/TimeoutRetrySettingsType" + responseHonorRetryAfterHeader: + type: boolean + title: Honor Retry-After header + description: Honor any Retry-After header that specifies a delay (in seconds) no + longer than 180 seconds after the retry request. @{product} limits + the delay to 180 seconds, even if the Retry-After header specifies a + longer delay. When enabled, takes precedence over user-configured + retry options. When disabled, all Retry-After headers are ignored. + authTokens: + type: array + title: Connected environment tokens + description: Shared secrets to be used by connected environments to authorize + connections. These tokens should also be installed in Cribl HTTP + Source in Cribl.Cloud. + items: + $ref: "#/components/schemas/AuthTokenConfOutputCriblHttp" + onBackpressure: + $ref: "#/components/schemas/BackpressureBehaviorOptions" + description: How to handle events when all receivers are exerting backpressure + description: + type: string + title: Description + description: Optional description for this configuration. + url: + type: string + title: Cribl endpoint + description: URL of a Cribl Worker to send events to, such as + http://localhost:10200 + pattern: ^https?://.* + useRoundRobinDns: + type: boolean + title: Round-robin DNS + description: Enable round-robin DNS lookup. When a DNS server returns multiple + addresses, @{product} will cycle through them in the order returned. + For optimal performance, consider enabling this setting for non-load + balanced destinations. + excludeSelf: + type: boolean + title: Exclude current host IPs + description: Exclude all IPs of the current host from the list of any resolved + hostnames + urls: + type: array + title: Cribl Worker endpoints + description: Cribl Worker endpoints + minItems: 1 + items: + $ref: "#/components/schemas/UrlConfOutputCriblHttp" + dnsResolvePeriodSec: + type: number + minimum: 0 + maximum: 86400 + title: DNS resolution period (seconds) + description: The interval in which to re-resolve any hostnames and pick up + destinations from A records + loadBalanceStatsPeriodSec: + type: number + minimum: 10 + title: Load balance stats period (seconds) + description: How far back in time to keep traffic stats for load balancing + purposes + pqStrictOrdering: + title: Strict ordering + description: Use FIFO (first in, first out) processing. Disable to forward new + events to receivers before queue is flushed. + type: boolean + pqRatePerSec: + type: number + title: Drain rate limit (EPS) + description: Throttling rate (in events per second) to impose while writing to + Destinations from PQ. Defaults to 0, which disables throttling. + minimum: 0 + pqMode: + $ref: "#/components/schemas/ModeOptions" + description: In Error mode, PQ writes events to the filesystem if the + Destination is unavailable. In Backpressure mode, PQ writes events + to the filesystem when it detects backpressure from the Destination. + In Always On mode, PQ always writes events to the filesystem. + pqMaxBufferSize: + type: number + title: Buffer size limit (events - deprecated) + description: Maximum number of events to hold in memory before writing the + events to disk. Deprecated and only supported in workers < v4.17.0. + Use pqMaxBufferSizeBytes instead. + minimum: 42 + maximum: 1000 + pqMaxBackpressureSec: + type: number + title: Backpressure duration limit + description: How long (in seconds) to wait for backpressure to resolve before + engaging the queue + minimum: 0 + pqMaxFileSize: + type: string + title: File size limit + description: The maximum size to store in each queue file before closing and + optionally compressing (KB, MB, etc.) + pattern: ^\d+\s*(?:\w{2})?$ + pqMaxSize: + type: string + title: Queue size limit + description: The maximum disk space that the queue can consume (as an average + per Worker Process) before queueing stops. Enter a numeral with + units of KB, MB, etc. + pattern: ^\d+\s*(?:\w{2})?$ + pqPath: + type: string + title: Queue file path + description: "The location for the persistent queue files. To this field's value, the system will append: //." + pqCompress: + $ref: "#/components/schemas/CompressionOptionsPq" + description: Codec to use to compress the persisted data + pqOnBackpressure: + $ref: "#/components/schemas/QueueFullBehaviorOptions" + description: How to handle events when the queue is exerting backpressure (full + capacity or low disk). 'Block' is the same behavior as non-PQ + blocking. 'Drop new data' throws away incoming data, while leaving + the contents of the PQ unchanged. + pqMaxBufferSizeBytes: + type: string + title: Buffer size limit (bytes) + description: The maximum size to hold in memory before writing events to disk. + Enter a numeral with units of KB, MB, etc. The minimum value is 64KB + and the maximum value is 10MB. + pattern: ^\d+\s*(?:\w{2})?$ + pqControls: + type: object + title: "" + description: Persistent queue controls. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_failedRequestLoggingMode: + type: string + description: Binds 'failedRequestLoggingMode' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'failedRequestLoggingMode' at runtime. + __template_onBackpressure: + type: string + description: Binds 'onBackpressure' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'onBackpressure' at + runtime. + __template_url: + type: string + description: Binds 'url' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'url' at runtime. + required: + - type + title: OutputCriblHttp + OutputCriblSearchEngine: + type: object + properties: + id: + type: string + title: Output ID + description: Unique ID for this output + type: + type: string + enum: + - cribl_search_engine + description: Connector type identifier. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data before sending out to this output + systemFields: + type: array + title: System fields + description: Fields to automatically add to events, such as cribl_pipe. Supports + wildcards. + items: + type: string + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + loadBalanced: + type: boolean + title: Load balancing + description: For optimal performance, enable load balancing even if you have one + hostname, as it can expand to multiple IPs. If this setting is + disabled, consider enabling round-robin DNS. + tls: + $ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath" + description: TLS settings (client side) + tokenTTLMinutes: + type: number + title: Auth Token TTL minutes + minimum: 1 + maximum: 60 + description: The number of minutes before the internally generated + authentication token expires. Valid values are between 1 and 60. + excludeFields: + type: array + title: Exclude fields + description: "Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported." items: type: string compression: @@ -49949,9 +54371,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ responseRetrySettings: type: array @@ -49975,308 +54395,32 @@ components: type: array title: Connected environment tokens description: Shared secrets to be used by connected environments to authorize - connections. These tokens should also be installed in Cribl HTTP + connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. items: $ref: "#/components/schemas/AuthTokenConfOutputCriblHttp" onBackpressure: $ref: "#/components/schemas/BackpressureBehaviorOptions" description: How to handle events when all receivers are exerting backpressure - description: - type: string - title: Description - description: Optional description for this configuration. - url: - type: string - title: Cribl endpoint - description: URL of a Cribl Worker to send events to, such as - http://localhost:10200 - pattern: ^https?://.* - useRoundRobinDns: - type: boolean - title: Round-robin DNS - description: Enable round-robin DNS lookup. When a DNS server returns multiple - addresses, @{product} will cycle through them in the order returned. - For optimal performance, consider enabling this setting for non-load - balanced destinations. - excludeSelf: - type: boolean - title: Exclude current host IPs - description: Exclude all IPs of the current host from the list of any resolved - hostnames - urls: - type: array - title: Cribl Worker endpoints - description: Cribl Worker endpoints - minItems: 1 - items: - $ref: "#/components/schemas/UrlConfOutputCriblHttp" - dnsResolvePeriodSec: - type: number - minimum: 0 - maximum: 86400 - title: DNS resolution period (seconds) - description: The interval in which to re-resolve any hostnames and pick up - destinations from A records - loadBalanceStatsPeriodSec: - type: number - minimum: 10 - title: Load balance stats period (seconds) - description: How far back in time to keep traffic stats for load balancing - purposes - pqStrictOrdering: - title: Strict ordering - description: Use FIFO (first in, first out) processing. Disable to forward new - events to receivers before queue is flushed. - type: boolean - pqRatePerSec: - type: number - title: Drain rate limit (EPS) - description: Throttling rate (in events per second) to impose while writing to - Destinations from PQ. Defaults to 0, which disables throttling. - minimum: 0 - pqMode: - $ref: "#/components/schemas/ModeOptions" - description: In Error mode, PQ writes events to the filesystem if the - Destination is unavailable. In Backpressure mode, PQ writes events - to the filesystem when it detects backpressure from the Destination. - In Always On mode, PQ always writes events to the filesystem. - pqMaxBufferSize: - type: number - title: Buffer size limit (events - deprecated) - description: Maximum number of events to hold in memory before writing the - events to disk. Deprecated and only supported in workers < v4.17.0. - Use pqMaxBufferSizeBytes instead. - minimum: 42 - maximum: 1000 - pqMaxBackpressureSec: - type: number - title: Backpressure duration limit - description: How long (in seconds) to wait for backpressure to resolve before - engaging the queue - minimum: 0 - pqMaxFileSize: - type: string - title: File size limit - description: The maximum size to store in each queue file before closing and - optionally compressing (KB, MB, etc.) - pattern: ^\d+\s*(?:\w{2})?$ - pqMaxSize: - type: string - title: Queue size limit - description: The maximum disk space that the queue can consume (as an average - per Worker Process) before queueing stops. Enter a numeral with - units of KB, MB, etc. - pattern: ^\d+\s*(?:\w{2})?$ - pqPath: - type: string - title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." - pqCompress: - $ref: "#/components/schemas/CompressionOptionsPq" - description: Codec to use to compress the persisted data - pqOnBackpressure: - $ref: "#/components/schemas/QueueFullBehaviorOptions" - description: How to handle events when the queue is exerting backpressure (full - capacity or low disk). 'Block' is the same behavior as non-PQ - blocking. 'Drop new data' throws away incoming data, while leaving - the contents of the PQ unchanged. - pqMaxBufferSizeBytes: - type: string - title: Buffer size limit (bytes) - description: The maximum size to hold in memory before writing events to disk. - Enter a numeral with units of KB, MB, etc. The minimum value is 64KB - and the maximum value is 10MB. - pattern: ^\d+\s*(?:\w{2})?$ - pqControls: - type: object - title: "" - description: Persistent queue controls. - __template_streamtags: - type: string - description: Binds 'streamtags' to a variable for dynamic value resolution. Set - to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'streamtags' at runtime. - __template_failedRequestLoggingMode: - type: string - description: Binds 'failedRequestLoggingMode' to a variable for dynamic value - resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' - prefixed ID (group-scoped). Variable value overrides - 'failedRequestLoggingMode' at runtime. - __template_onBackpressure: - type: string - description: Binds 'onBackpressure' to a variable for dynamic value resolution. - Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'onBackpressure' at - runtime. - __template_url: - type: string - description: Binds 'url' to a variable for dynamic value resolution. Set to - variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID - (group-scoped). Variable value overrides 'url' at runtime. - required: - - type - title: OutputCriblHttp - OutputCriblSearchEngine: - type: object - properties: - id: - type: string - title: Output ID - description: Unique ID for this output - type: + sendAs: type: string + title: Send as enum: - - cribl_search_engine - description: Connector type identifier. - pipeline: - type: string - title: Pipeline - description: Pipeline to process data before sending out to this output - systemFields: - type: array - title: System fields - description: Fields to automatically add to events, such as cribl_pipe. Supports - wildcards. - items: - type: string - environment: - type: string - title: Environment - description: Optionally, enable this config only on a specified Git branch. If - empty, will be enabled everywhere. - streamtags: - type: array - title: Tags - description: Metadata tags used for categorization and filtering. - items: - type: string - loadBalanced: - type: boolean - title: Load balancing - description: For optimal performance, enable load balancing even if you have one - hostname, as it can expand to multiple IPs. If this setting is - disabled, consider enabling round-robin DNS. - tls: - $ref: "#/components/schemas/TlsSettingsClientSideTypeCaPathCertPath" - description: TLS settings (client side) - tokenTTLMinutes: - type: number - title: Auth Token TTL minutes - minimum: 1 - maximum: 60 - description: The number of minutes before the internally generated - authentication token expires. Valid values are between 1 and 60. - excludeFields: - type: array - title: Exclude fields - description: "Fields to exclude from the event. By default, all internal fields - except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards - supported." - items: - type: string - compression: - $ref: "#/components/schemas/CompressionOptionsGzipNone" - description: Codec to use to compress the data before sending - concurrency: - type: number - title: Request concurrency - description: Maximum number of ongoing requests before blocking - minimum: 1 - maximum: 32 - maxPayloadSizeKB: - type: number - title: Body size limit (KB) - description: Maximum size, in KB, of the request body - minimum: 1024 - maximum: 10240 - maxPayloadEvents: - type: number - title: Events-per-request limit - description: Maximum number of events to include in the request body. Default is - 0 (unlimited). - minimum: 0 - rejectUnauthorized: - type: boolean - title: Validate server certs - description: >- - Reject certificates not authorized by a CA in the CA certificate - path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - timeoutSec: - type: number - minimum: 1 - maximum: 9007199254740991 - title: Request timeout - description: Amount of time, in seconds, to wait for a request to complete - before canceling it - maxConnectionReuseSec: - type: number - minimum: 0 - title: Max connection reuse (seconds) - description: How long, in seconds, to reuse a keep-alive connection after its - first use before forcing it closed. Set to 0 to disable the - time-based close and reuse connections for as long as the - destination server permits. - flushPeriodSec: - type: number - title: Flush period (sec) - description: Maximum time between requests. Small values could cause the payload - size to be smaller than the configured Body size limit. - extraHttpHeaders: - type: array - title: Extra HTTP headers - description: Headers to add to all events - items: - $ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic" - failedRequestLoggingMode: - $ref: "#/components/schemas/FailedRequestLoggingModeOptions" - description: Data to log when a request fails. All headers are redacted by - default, unless listed as safe headers below. - safeHeaders: - type: array - title: Safe headers - description: List of headers that are safe to log in plain text - items: - type: string - throttleRatePerSec: - type: string - title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." - pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ - responseRetrySettings: - type: array - title: Settings for failed HTTP requests - description: Automatically retry after unsuccessful response status codes, such - as 429 (Too Many Requests) or 503 (Service Unavailable) - minItems: 0 - items: - $ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook" - timeoutRetrySettings: - $ref: "#/components/schemas/TimeoutRetrySettingsType" - responseHonorRetryAfterHeader: - type: boolean - title: Honor Retry-After header - description: Honor any Retry-After header that specifies a delay (in seconds) no - longer than 180 seconds after the retry request. @{product} limits - the delay to 180 seconds, even if the Retry-After header specifies a - longer delay. When enabled, takes precedence over user-configured - retry options. When disabled, all Retry-After headers are ignored. - authTokens: - type: array - title: Connected environment tokens - description: Shared secrets to be used by connected environments to authorize - connections. These tokens should also be installed in Cribl Search - Source in Cribl.Cloud. - items: - $ref: "#/components/schemas/AuthTokenConfOutputCriblHttp" - onBackpressure: - $ref: "#/components/schemas/BackpressureBehaviorOptions" - description: How to handle events when all receivers are exerting backpressure + - logs + - metrics + - both + x-speakeasy-enum-descriptions: + - Logs + - Metrics + - Logs and Metrics + description: Which signals this Destination carries. Logs sends everything to + log search, including metric events. Metrics routes metric events to + the metric store and drops everything else. Logs and Metrics routes + metric events to the metric store and sends the rest to log search. + Metric routing requires the receiving Cribl Search Source to be + enabled for metrics storage; if it is not, metric events are + discarded rather than stored as logs. + x-speakeasy-unknown-values: allow useRoundRobinDns: type: boolean title: Round-robin DNS @@ -50366,8 +54510,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -50454,9 +54597,7 @@ components: url: type: string title: LogScale endpoint - description: "URL to a CrowdStrike Falcon LogScale endpoint to send events to. - Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and - https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw" + description: "URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw" pattern: ^https?://.* concurrency: type: number @@ -50537,7 +54678,7 @@ components: required fields before sending. When set to Raw, only the event's `_raw` value is sent. authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate responseRetrySettings: @@ -50620,8 +54761,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -50789,7 +54929,7 @@ components: required fields before sending. When set to Raw, only the event's `_raw` value is sent. authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate responseRetrySettings: @@ -50872,8 +55012,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -50997,10 +55136,7 @@ components: bucket: type: string title: S3 bucket name - description: "Name of the destination S3 bucket. Must be a JavaScript expression - (which can evaluate to a constant value), enclosed in quotes or - backticks. Can be evaluated only at initialization time. Example - referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -51008,10 +55144,7 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -51126,8 +55259,7 @@ components: awsSecretKey: type: string title: Secret key - description: "Secret key. This value can be a constant or a JavaScript - expression. Example: `${C.env.SOME_SECRET}`)" + description: "Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)" objectACL: $ref: "#/components/schemas/ObjectAclOptions" description: Object ACL to assign to uploaded objects @@ -51446,10 +55578,7 @@ components: bucket: type: string title: S3 bucket name - description: "Name of the destination S3 bucket. Must be a JavaScript expression - (which can evaluate to a constant value), enclosed in quotes or - backticks. Can be evaluated only at initialization time. Example - referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -51919,6 +56048,9 @@ components: type: number minimum: 1 maximum: 10 + freshnessGracePeriodSec: + type: number + minimum: 5 description: type: string title: Description @@ -52097,14 +56229,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space that can be consumed before older buckets are - deleted. Examples: 420MB, 4GB. Default is 1GB." + description: "Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB." pattern: ^\d+(\.\d+)?\s*(?:[kmgKMG](b|B))?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data before older buckets are - deleted. Examples: 2h, 4d. Default is 24h." + description: "Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/CompressionOptionsPersistence" @@ -52401,8 +56531,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -52729,8 +56858,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -53104,8 +57232,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -53410,8 +57537,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -53804,8 +57930,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -54153,8 +58278,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -54193,6 +58317,359 @@ components: (group-scoped). Variable value overrides 'onBackpressure' at runtime. title: OutputDynatraceOtlp + OutputTraversalOtlp: + type: object + required: + - type + - endpoint + properties: + id: + type: string + title: Output ID + description: Unique ID for this output + type: + type: string + enum: + - traversal_otlp + description: Connector type identifier. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data before sending out to this output + systemFields: + type: array + title: System fields + description: Fields to automatically add to events, such as cribl_pipe. Supports + wildcards. + items: + type: string + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + authType: + type: string + title: Authentication type + enum: + - none + - credentialsSecret + - textSecret + - oauthSecret + x-speakeasy-enum-descriptions: + - None + - Basic (credentials secret) + - Token (text secret) + - OAuth (text secret) + description: Authentication type + x-speakeasy-unknown-values: allow + endpoint: + type: string + title: Endpoint + description: The endpoint where OTel log events will be sent. Enter any valid + URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square + brackets). + protocol: + $ref: "#/components/schemas/ProtocolOptions" + description: Select a transport option for OpenTelemetry + preserveNativeAnyValue: + type: boolean + title: Preserve native AnyValue wrappers + description: 'Values already in OTLP AnyValue form (e.g. {string_value: "..."}) + are serialized directly instead of being wrapped as key-value maps' + compress: + $ref: "#/components/schemas/CompressionOptionsDeflateGzip" + description: Type of compression to apply to messages sent to the OpenTelemetry + endpoint + httpCompress: + $ref: "#/components/schemas/CompressionOptionsMessages" + description: Type of compression to apply to messages sent to the OpenTelemetry + endpoint + httpLogsEndpointOverride: + type: string + title: Logs endpoint override + description: If you want to send logs to the default `{endpoint}/v1/logs` + endpoint, leave this field empty; otherwise, specify the desired + endpoint + metadata: + type: array + title: Metadata + description: List of key-value pairs to send with each gRPC request. Value + supports JavaScript expressions that are evaluated just once, when + the destination gets started. To pass credentials as metadata, use + 'C.Secret'. + minItems: 0 + items: + $ref: "#/components/schemas/KeyValueMetadataConfOutputFilesystem" + dynamicHeadersEnabled: + type: boolean + title: Use dynamic metadata + description: Batch event data upon dynamic metadata (whether presented or not) + dynamicHeadersField: + type: string + title: Dynamic metadata field + description: When presented, this field which contains metadata, will be + injected into the Destination metadata and used to batch events. + concurrency: + type: number + title: Request concurrency + description: Maximum number of ongoing requests before blocking + minimum: 1 + maximum: 32 + maxPayloadSizeKB: + type: number + title: Body size limit (KB) + description: Maximum size, in KB, of the request body + minimum: 1024 + maximum: 10240 + timeoutSec: + type: number + minimum: 1 + maximum: 9007199254740991 + title: Request timeout + description: Amount of time, in seconds, to wait for a request to complete + before canceling it + maxConnectionReuseSec: + type: number + minimum: 0 + title: Max connection reuse (seconds) + description: How long, in seconds, to reuse a keep-alive connection after its + first use before forcing it closed. Set to 0 to disable the + time-based close and reuse connections for as long as the + destination server permits. + flushPeriodSec: + type: number + title: Flush period (sec) + description: Maximum time between requests. Small values could cause the payload + size to be smaller than the configured Body size limit. + failedRequestLoggingMode: + $ref: "#/components/schemas/FailedRequestLoggingModeOptions" + description: Data to log when a request fails. All headers are redacted by + default, unless listed as safe headers below. + connectionTimeout: + type: number + title: Connection timeout + description: Amount of time (milliseconds) to wait for the connection to + establish before retrying + keepAliveTime: + type: number + title: Keep alive time (seconds) + description: How often the sender should ping the peer to keep the connection open + minimum: 1 + keepAlive: + type: boolean + title: Keep alive + description: Disable to close the connection immediately after sending the + outgoing request + onBackpressure: + $ref: "#/components/schemas/BackpressureBehaviorOptions" + description: How to handle events when all receivers are exerting backpressure + description: + type: string + title: Description + description: Optional description for this configuration. + credentialsSecret: + type: string + title: Credentials secret + description: Select or create a secret that references your credentials + textSecret: + type: string + title: Token (text secret) + description: Select or create a stored text secret + loginUrl: + type: string + title: Login URL + description: URL for OAuth + pattern: ^https?://.* + secretParamName: + type: string + title: OAuth Secret parameter name + description: Secret parameter name to pass in request body + oauthTextSecret: + type: string + title: OAuth secret (text secret) + description: Select or create a stored text secret for the OAuth secret + parameter value to pass in request body + tokenAttributeName: + type: string + title: Token attribute name + description: Name of the auth token attribute in the OAuth response. Can be + top-level (e.g., 'token'); or nested, using a period (e.g., + 'data.token'). + authHeaderExpr: + type: string + title: Authorize expression + description: "JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`." + tokenTimeoutSecs: + type: number + title: Refresh interval (secs.) + description: How often the OAuth token should be refreshed. + minimum: 1 + maximum: 300000 + oauthParams: + type: array + title: OAuth parameters + description: Additional parameters to send in the OAuth login request. + @{product} will combine the secret with these parameters, and will + send the URL-encoded result in a POST request to the endpoint + specified in the 'Login URL'. We'll automatically add the + content-type header 'application/x-www-form-urlencoded' when sending + this request. + items: + $ref: "#/components/schemas/OauthParamConfInputServicenowTable" + oauthHeaders: + type: array + title: OAuth headers + description: Additional headers to send in the OAuth login request. @{product} + will automatically add the content-type header + 'application/x-www-form-urlencoded' when sending this request. + items: + $ref: "#/components/schemas/OauthHeaderConfInputServicenowTable" + rejectUnauthorized: + type: boolean + title: Validate server certs + description: >- + Reject certificates not authorized by a CA in the CA certificate + path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + useRoundRobinDns: + type: boolean + title: Round-robin DNS + description: Enable round-robin DNS lookup. When a DNS server returns multiple + addresses, @{product} will cycle through them in the order returned. + For optimal performance, consider enabling this setting for non-load + balanced destinations. + extraHttpHeaders: + type: array + title: Extra HTTP headers + description: Headers to add to all events + items: + $ref: "#/components/schemas/ExtraHttpHeaderConfInputElastic" + safeHeaders: + type: array + title: Safe headers + description: List of headers that are safe to log in plain text + items: + type: string + responseRetrySettings: + type: array + title: Settings for failed HTTP requests + description: Automatically retry after unsuccessful response status codes, such + as 429 (Too Many Requests) or 503 (Service Unavailable) + minItems: 0 + items: + $ref: "#/components/schemas/ResponseRetrySettingConfOutputWebhook" + timeoutRetrySettings: + $ref: "#/components/schemas/TimeoutRetrySettingsType" + responseHonorRetryAfterHeader: + type: boolean + title: Honor Retry-After header + description: Honor any Retry-After header that specifies a delay (in seconds) no + longer than 180 seconds after the retry request. @{product} limits + the delay to 180 seconds, even if the Retry-After header specifies a + longer delay. When enabled, takes precedence over user-configured + retry options. When disabled, all Retry-After headers are ignored. + tls: + $ref: "#/components/schemas/TlsSettingsClientSideTypeExtended" + description: TLS settings (client side) + pqStrictOrdering: + title: Strict ordering + description: Use FIFO (first in, first out) processing. Disable to forward new + events to receivers before queue is flushed. + type: boolean + pqRatePerSec: + type: number + title: Drain rate limit (EPS) + description: Throttling rate (in events per second) to impose while writing to + Destinations from PQ. Defaults to 0, which disables throttling. + minimum: 0 + pqMode: + $ref: "#/components/schemas/ModeOptions" + description: In Error mode, PQ writes events to the filesystem if the + Destination is unavailable. In Backpressure mode, PQ writes events + to the filesystem when it detects backpressure from the Destination. + In Always On mode, PQ always writes events to the filesystem. + pqMaxBufferSize: + type: number + title: Buffer size limit (events - deprecated) + description: Maximum number of events to hold in memory before writing the + events to disk. Deprecated and only supported in workers < v4.17.0. + Use pqMaxBufferSizeBytes instead. + minimum: 42 + maximum: 1000 + pqMaxBackpressureSec: + type: number + title: Backpressure duration limit + description: How long (in seconds) to wait for backpressure to resolve before + engaging the queue + minimum: 0 + pqMaxFileSize: + type: string + title: File size limit + description: The maximum size to store in each queue file before closing and + optionally compressing (KB, MB, etc.) + pattern: ^\d+\s*(?:\w{2})?$ + pqMaxSize: + type: string + title: Queue size limit + description: The maximum disk space that the queue can consume (as an average + per Worker Process) before queueing stops. Enter a numeral with + units of KB, MB, etc. + pattern: ^\d+\s*(?:\w{2})?$ + pqPath: + type: string + title: Queue file path + description: "The location for the persistent queue files. To this field's value, the system will append: //." + pqCompress: + $ref: "#/components/schemas/CompressionOptionsPq" + description: Codec to use to compress the persisted data + pqOnBackpressure: + $ref: "#/components/schemas/QueueFullBehaviorOptions" + description: How to handle events when the queue is exerting backpressure (full + capacity or low disk). 'Block' is the same behavior as non-PQ + blocking. 'Drop new data' throws away incoming data, while leaving + the contents of the PQ unchanged. + pqMaxBufferSizeBytes: + type: string + title: Buffer size limit (bytes) + description: The maximum size to hold in memory before writing events to disk. + Enter a numeral with units of KB, MB, etc. The minimum value is 64KB + and the maximum value is 10MB. + pattern: ^\d+\s*(?:\w{2})?$ + pqControls: + type: object + title: "" + description: Persistent queue controls. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_failedRequestLoggingMode: + type: string + description: Binds 'failedRequestLoggingMode' to a variable for dynamic value + resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' + prefixed ID (group-scoped). Variable value overrides + 'failedRequestLoggingMode' at runtime. + __template_onBackpressure: + type: string + description: Binds 'onBackpressure' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'onBackpressure' at + runtime. + __template_loginUrl: + type: string + description: Binds 'loginUrl' to a variable for dynamic value resolution. Set to + variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'loginUrl' at runtime. + title: OutputTraversalOtlp OutputSentinelOneAiSiem: type: object required: @@ -54298,7 +58775,7 @@ components: items: type: string authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensExtItems" description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate responseRetrySettings: @@ -54365,10 +58842,7 @@ components: title: Base AI SIEM endpoint URL type: string pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$ - description: "Base URL of the endpoint used to send events to, such as - https://.sentinelone.net. Must begin with http:// or - https://, can include a port number, and no trailing slashes. - Matches pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$." + description: "Base URL of the endpoint used to send events to, such as https://.sentinelone.net. Must begin with http:// or https://, can include a port number, and no trailing slashes. Matches pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$." hostExpression: type: string title: serverHost expression @@ -54505,8 +58979,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -54755,10 +59228,7 @@ components: endpoint: type: string title: Endpoint - description: "Chronicle API service endpoint. If empty, defaults to the - Region-specific endpoint. Otherwise, it must point to a Chronicle - API-compatible endpoint. (Example: - https://custom-endpoint.googleapis.com)" + description: "Chronicle API service endpoint. If empty, defaults to the Region-specific endpoint. Otherwise, it must point to a Chronicle API-compatible endpoint. (Example: https://custom-endpoint.googleapis.com)" pattern: ^https?://.* description: type: string @@ -54821,8 +59291,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -55268,8 +59737,7 @@ components: accountIdentifier: type: string title: Account identifier - description: "Snowflake account identifier in org-account format (example: - MYORG-MYACCOUNT)" + description: "Snowflake account identifier in org-account format (example: MYORG-MYACCOUNT)" user: type: string title: User @@ -55459,8 +59927,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -55806,8 +60273,7 @@ components: pqPath: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //." + description: "The location for the persistent queue files. To this field's value, the system will append: //." pqCompress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -55910,16 +60376,11 @@ components: bucket: type: string title: R2 bucket name - description: "Name of the destination R2 bucket. This value can be a constant or - a JavaScript expression that can only be evaluated at init time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination R2 bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -56041,13 +60502,11 @@ components: awsSecretKey: type: string title: Secret key - description: "Secret key. This value can be a constant or a JavaScript - expression. Example: `${C.env.SOME_SECRET}`)" + description: "Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)" endpoint: type: string title: R2 endpoint - description: "Cloudflare R2 service URL (example: - https://.r2.cloudflarestorage.com)" + description: "Cloudflare R2 service URL (example: https://.r2.cloudflarestorage.com)" pattern: ^https?://.* storageClass: $ref: "#/components/schemas/StorageClassOptionsReducedredundancyStandard" @@ -56280,11 +60739,7 @@ components: bucket: type: string title: Nutanix Objects bucket name - description: "Name of the destination Nutanix Objects bucket. Must be a - JavaScript expression (which can evaluate to a constant value), - enclosed in quotes or backticks. Can be evaluated only at - initialization time. Example referencing a Global Variable: - `myBucket-${C.vars.myVar}`" + description: "Name of the destination Nutanix Objects bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -56292,10 +60747,7 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -56417,8 +60869,7 @@ components: endpoint: type: string title: Nutanix Objects endpoint - description: "Nutanix Objects S3-compatible endpoint URL (example: - https://objects.nutanix.local)" + description: "Nutanix Objects S3-compatible endpoint URL (example: https://objects.nutanix.local)" pattern: ^https?://.* description: type: string @@ -56639,17 +61090,11 @@ components: bucket: type: string title: Storj bucket name - description: "Name of the destination Storj bucket. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at initialization time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination Storj bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -56771,8 +61216,7 @@ components: endpoint: type: string title: Storj endpoint - description: "Storj S3-compatible gateway endpoint URL (example: - https://gateway.storjshare.io)" + description: "Storj S3-compatible gateway endpoint URL (example: https://gateway.storjshare.io)" pattern: ^https?://.* description: type: string @@ -56987,17 +61431,11 @@ components: bucket: type: string title: AlphaSOC bucket name - description: "Name of the destination AlphaSOC bucket. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at initialization time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination AlphaSOC bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -57119,8 +61557,7 @@ components: endpoint: type: string title: AlphaSOC endpoint - description: "AlphaSOC S3-compatible endpoint URL (example: - https://s3.alphasoc.net)" + description: "AlphaSOC S3-compatible endpoint URL (example: https://s3.alphasoc.net)" pattern: ^https?://.* description: type: string @@ -57331,11 +61768,7 @@ components: bucket: type: string title: Dell PowerScale OneFS bucket name - description: "Name of the destination Dell PowerScale OneFS bucket. Must be a - JavaScript expression (which can evaluate to a constant value), - enclosed in quotes or backticks. Can be evaluated only at - initialization time. Example referencing a Global Variable: - `myBucket-${C.vars.myVar}`" + description: "Name of the destination Dell PowerScale OneFS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -57343,10 +61776,7 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -57471,8 +61901,7 @@ components: endpoint: type: string title: Dell PowerScale OneFS endpoint - description: "Dell PowerScale OneFS S3-compatible endpoint URL (example: - https://powerscale.example.com:9021)" + description: "Dell PowerScale OneFS S3-compatible endpoint URL (example: https://powerscale.example.com:9021)" pattern: ^https?://.* description: type: string @@ -57686,8 +62115,7 @@ components: endpoint: type: string title: Cloudian HyperStore endpoint - description: "Cloudian HyperStore S3-compatible endpoint URL (example: - https://s3.hyperstore.example.com)" + description: "Cloudian HyperStore S3-compatible endpoint URL (example: https://s3.hyperstore.example.com)" pattern: ^https?://.* awsAuthenticationMethod: $ref: "#/components/schemas/AuthenticationMethodOptionsSecret" @@ -57704,10 +62132,7 @@ components: bucket: type: string title: Cloudian bucket name - description: "Name of the destination Cloudian bucket. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at initialization time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination Cloudian bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -57715,10 +62140,7 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -58090,10 +62512,7 @@ components: bucket: type: string title: Scality bucket name - description: "Name of the destination Scality bucket. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at initialization time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination Scality bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" region: type: string title: Region @@ -58101,10 +62520,7 @@ components: destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -58226,8 +62642,7 @@ components: endpoint: type: string title: Scality endpoint - description: "Scality RING S3-compatible endpoint URL (example: - https://s3.scality.example.com)" + description: "Scality RING S3-compatible endpoint URL (example: https://s3.scality.example.com)" pattern: ^https?://.* description: type: string @@ -58456,17 +62871,11 @@ components: bucket: type: string title: Alibaba OSS bucket name - description: "Name of the destination Alibaba OSS bucket. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at initialization time. - Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" + description: "Name of the destination Alibaba OSS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -58591,9 +63000,7 @@ components: endpoint: type: string title: OSS endpoint - description: "Alibaba OSS S3-compatible endpoint URL. Examples: public - `https://s3.oss-{region}.aliyuncs.com`, internal - `https://s3.oss-{region}-internal.aliyuncs.com`" + description: "Alibaba OSS S3-compatible endpoint URL. Examples: public `https://s3.oss-{region}.aliyuncs.com`, internal `https://s3.oss-{region}-internal.aliyuncs.com`" pattern: ^https?://.* enableAssumeRole: type: boolean @@ -58610,9 +63017,7 @@ components: assumeRoleArn: type: string title: AssumeRole ARN - description: "ARN of the RAM role to assume. Format: - acs:ram:::role/. Example: - acs:ram::123456789:role/OSSAccessRole" + description: "ARN of the RAM role to assume. Format: acs:ram:::role/. Example: acs:ram::123456789:role/OSSAccessRole" pattern: "^acs:" minLength: 20 assumeRoleExternalId: @@ -58838,8 +63243,7 @@ components: endpoint: type: string title: IBM COS endpoint - description: "IBM Cloud Object Storage S3-compatible endpoint URL (example: - https://s3.us-south.cloud-object-storage.appdomain.cloud)" + description: "IBM Cloud Object Storage S3-compatible endpoint URL (example: https://s3.us-south.cloud-object-storage.appdomain.cloud)" pattern: ^https?://.* awsAuthenticationMethod: $ref: "#/components/schemas/AuthenticationMethodOptionsSecret" @@ -58856,18 +63260,11 @@ components: bucket: type: string title: IBM Cloud Object Storage bucket name - description: "Name of the destination IBM Cloud Object Storage bucket. Must be a - JavaScript expression (which can evaluate to a constant value), - enclosed in quotes or backticks. Can be evaluated only at - initialization time. Example referencing a Global Variable: - `myBucket-${C.vars.myVar}`" + description: "Name of the destination IBM Cloud Object Storage bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`" destPath: type: string title: Key prefix - description: "Prefix to prepend to files before uploading. Must be a JavaScript - expression (which can evaluate to a constant value), enclosed in - quotes or backticks. Can be evaluated only at init time. Example - referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" + description: "Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`" maxConcurrentFileParts: type: number title: Concurrent file parts upload limit @@ -59146,6 +63543,209 @@ components: Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. title: OutputIbmCloudS3 + OutputDatabricksZerobus: + type: object + required: + - type + - workspaceUrl + - workspaceId + - zerobusEndpoint + - clientId + - clientTextSecret + - tableName + properties: + id: + type: string + title: Output ID + description: Unique ID for this output + type: + type: string + enum: + - databricks_zerobus + description: Connector type identifier. + pipeline: + type: string + title: Pipeline + description: Pipeline to process data before sending out to this output + systemFields: + type: array + title: System fields + description: Fields to automatically add to events, such as cribl_pipe. Supports + wildcards. + items: + type: string + environment: + type: string + title: Environment + description: Optionally, enable this config only on a specified Git branch. If + empty, will be enabled everywhere. + streamtags: + type: array + title: Tags + description: Metadata tags used for categorization and filtering. + items: + type: string + workspaceUrl: + type: string + title: Workspace URL + description: "HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://" + pattern: ^https://.+$ + workspaceId: + type: string + title: Workspace ID + description: Unique identifier for the Databricks Workspace. Scopes the OAuth + token to this Workspace. + zerobusEndpoint: + type: string + title: Zerobus endpoint + description: "Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com)." + pattern: ^[^:/\s]+$ + clientId: + type: string + title: Client ID + description: OAuth client ID of the service principal authorized to write to the + target table + clientTextSecret: + type: string + title: Client secret + description: OAuth client secret of the service principal + tableName: + type: string + title: Table name + description: "Three-part Unity Catalog name of the target table: catalog.schema.table" + pattern: ^[^.]+\.[^.]+\.[^.]+$ + maxBatchSizeKB: + type: integer + title: Batch size limit + description: Maximum size, in KB, of the serialized records in a single ingest + batch + minimum: 1 + maximum: 10176 + maxBatchRecords: + type: integer + title: Batch records limit + description: Maximum number of records to include in a single ingest batch + minimum: 1 + maximum: 2000 + maxBufferedKB: + type: integer + title: Buffer memory limit + description: Maximum size, in KB, of unacknowledged records per Worker Process + before blocking. Must be at least the configured Batch size limit. + Records larger than this limit are dropped. + minimum: 1024 + maxInflightBatches: + type: integer + title: In-flight batch limit + description: Maximum number of unacknowledged batches per Worker Process before + blocking + minimum: 1 + maximum: 1000 + flushPeriodSec: + type: integer + title: Flush period + description: Maximum time, in seconds, to hold a batch before sending it + minimum: 1 + ackTimeoutSec: + type: integer + title: Acknowledgment timeout + description: Amount of time, in seconds, to wait for Databricks to acknowledge + sent batches before reconnecting + minimum: 1 + connectionTimeoutSec: + type: integer + title: Connection timeout + description: Amount of time, in seconds, to wait for a new ingest stream to open + before canceling it + minimum: 1 + maximum: 300 + onBackpressure: + $ref: "#/components/schemas/BackpressureBehaviorOptions" + description: How to handle events when all receivers are exerting backpressure + description: + type: string + title: Description + description: Optional description for this configuration. + pqStrictOrdering: + title: Strict ordering + description: Use FIFO (first in, first out) processing. Disable to forward new + events to receivers before queue is flushed. + type: boolean + pqRatePerSec: + type: number + title: Drain rate limit (EPS) + description: Throttling rate (in events per second) to impose while writing to + Destinations from PQ. Defaults to 0, which disables throttling. + minimum: 0 + pqMode: + $ref: "#/components/schemas/ModeOptions" + description: In Error mode, PQ writes events to the filesystem if the + Destination is unavailable. In Backpressure mode, PQ writes events + to the filesystem when it detects backpressure from the Destination. + In Always On mode, PQ always writes events to the filesystem. + pqMaxBufferSize: + type: number + title: Buffer size limit (events - deprecated) + description: Maximum number of events to hold in memory before writing the + events to disk. Deprecated and only supported in workers < v4.17.0. + Use pqMaxBufferSizeBytes instead. + minimum: 42 + maximum: 1000 + pqMaxBackpressureSec: + type: number + title: Backpressure duration limit + description: How long (in seconds) to wait for backpressure to resolve before + engaging the queue + minimum: 0 + pqMaxFileSize: + type: string + title: File size limit + description: The maximum size to store in each queue file before closing and + optionally compressing (KB, MB, etc.) + pattern: ^\d+\s*(?:\w{2})?$ + pqMaxSize: + type: string + title: Queue size limit + description: The maximum disk space that the queue can consume (as an average + per Worker Process) before queueing stops. Enter a numeral with + units of KB, MB, etc. + pattern: ^\d+\s*(?:\w{2})?$ + pqPath: + type: string + title: Queue file path + description: "The location for the persistent queue files. To this field's value, the system will append: //." + pqCompress: + $ref: "#/components/schemas/CompressionOptionsPq" + description: Codec to use to compress the persisted data + pqOnBackpressure: + $ref: "#/components/schemas/QueueFullBehaviorOptions" + description: How to handle events when the queue is exerting backpressure (full + capacity or low disk). 'Block' is the same behavior as non-PQ + blocking. 'Drop new data' throws away incoming data, while leaving + the contents of the PQ unchanged. + pqMaxBufferSizeBytes: + type: string + title: Buffer size limit (bytes) + description: The maximum size to hold in memory before writing events to disk. + Enter a numeral with units of KB, MB, etc. The minimum value is 64KB + and the maximum value is 10MB. + pattern: ^\d+\s*(?:\w{2})?$ + pqControls: + type: object + title: "" + description: Persistent queue controls. + __template_streamtags: + type: string + description: Binds 'streamtags' to a variable for dynamic value resolution. Set + to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'streamtags' at runtime. + __template_onBackpressure: + type: string + description: Binds 'onBackpressure' to a variable for dynamic value resolution. + Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID + (group-scoped). Variable value overrides 'onBackpressure' at + runtime. + title: OutputDatabricksZerobus Output: oneOf: - $ref: "#/components/schemas/OutputDefault" @@ -59218,6 +63818,7 @@ components: - $ref: "#/components/schemas/OutputNetflow" - $ref: "#/components/schemas/OutputDynatraceHttp" - $ref: "#/components/schemas/OutputDynatraceOtlp" + - $ref: "#/components/schemas/OutputTraversalOtlp" - $ref: "#/components/schemas/OutputSentinelOneAiSiem" - $ref: "#/components/schemas/OutputChronicle" - $ref: "#/components/schemas/OutputDatabricks" @@ -59232,6 +63833,7 @@ components: - $ref: "#/components/schemas/OutputScalityS3" - $ref: "#/components/schemas/OutputAlibabaCloudS3" - $ref: "#/components/schemas/OutputIbmCloudS3" + - $ref: "#/components/schemas/OutputDatabricksZerobus" discriminator: propertyName: type mapping: @@ -59305,6 +63907,7 @@ components: netflow: "#/components/schemas/OutputNetflow" dynatrace_http: "#/components/schemas/OutputDynatraceHttp" dynatrace_otlp: "#/components/schemas/OutputDynatraceOtlp" + traversal_otlp: "#/components/schemas/OutputTraversalOtlp" sentinel_one_ai_siem: "#/components/schemas/OutputSentinelOneAiSiem" chronicle: "#/components/schemas/OutputChronicle" databricks: "#/components/schemas/OutputDatabricks" @@ -59319,6 +63922,7 @@ components: scality_s3: "#/components/schemas/OutputScalityS3" alibaba_cloud_s3: "#/components/schemas/OutputAlibabaCloudS3" ibm_cloud_s3: "#/components/schemas/OutputIbmCloudS3" + databricks_zerobus: "#/components/schemas/OutputDatabricksZerobus" title: Output CountedOutputResponse: type: object @@ -59328,10 +63932,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/OutputResponse" OutputResponse: @@ -59346,8 +63950,7 @@ components: description: Notifications attached to the Destination. status: $ref: "#/components/schemas/StatusType" - description: "Runtime status: health, metrics, and optional persistent-queue - info. Fields may be absent when data is unavailable." + description: "Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable." description: Destination configuration with optional Notifications and runtime status. title: OutputResponse DestinationType: @@ -59437,6 +64040,8 @@ components: - alibaba_cloud_s3 - snowflake_streaming - ibm_cloud_s3 + - databricks_zerobus + - traversal_otlp title: DestinationType x-speakeasy-unknown-values: allow PaginatedOutputResponse: @@ -59447,12 +64052,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/OutputResponse" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -59473,10 +64079,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/OutputSamplesResponse" OutputSamplesResponse: @@ -59500,10 +64106,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/OutputTestResponse" OutputTestResponse: @@ -59552,10 +64158,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/Pipeline" Pipeline: @@ -59620,8 +64226,7 @@ components: disabled: type: boolean title: Disabled - description: If true, disable all items in the group. Otherwise, - false. + description: Disable all items in the group. __template_streamtags: type: string description: Binds 'streamtags' to a variable for dynamic value resolution. Set @@ -59636,12 +64241,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/Pipeline" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -59662,10 +64268,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/Routes" RouteComment: @@ -59705,6 +64311,12 @@ components: RouteConf: type: object properties: + autoParse: + type: boolean + description: If true, detect each matched event's datatype and + extract fields from _raw before the Pipeline processes + the event, so Functions and Filters can reference the extracted + fields. Otherwise, false (the default). clones: type: array items: @@ -59714,8 +64326,7 @@ components: Route. context: type: string - description: "Context for the Route: group (Worker Group or Edge - Fleet) or pack." + description: "Context for the Route: group (Worker Group or Edge Fleet) or pack." description: type: string description: Brief description of the Route. @@ -59763,9 +64374,7 @@ components: description: Pipeline that the Route sends matching events to. targetContext: $ref: "#/components/schemas/TargetContext" - description: "Target context for subsequent event processing after applying the - Route: group (Worker Group or Edge Fleet) or - pack." + description: "Target context for subsequent event processing after applying the Route: group (Worker Group or Edge Fleet) or pack." required: - final - id @@ -59799,6 +64408,33 @@ components: - id - routes title: Routes + PaginatedRoutes: + type: object + required: + - items + - count + properties: + items: + type: array + description: The items returned in this response, after any offset/limit + pagination has been applied. + items: + $ref: "#/components/schemas/Routes" + count: + type: integer + description: Number of items returned in the items array. + offset: + type: integer + description: Pagination offset. Returned when offset/limit query parameters are + provided. + limit: + type: integer + description: Pagination limit. Returned when offset/limit query parameters are + provided. + totalCount: + type: integer + description: Total number of items available. Returned when offset/limit query + parameters are provided. RoutesInput: type: object properties: @@ -59839,10 +64475,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/InputStatus" HealthCountType: @@ -59878,13 +64514,7 @@ components: x-speakeasy-unknown-values: allow healthCounts: $ref: "#/components/schemas/HealthCountType" - description: "Counts of persistent queue health statuses for the Source or - Destination across all Worker Processes. Includes only statuses with - non-zero counts.

Green == Healthy: Normal - operation

Yellow == Degraded: Potential - issues

Red == Critical: Problem or error that - affects operation

Unknown == Unknown: Cannot - determine health status." + description: "Counts of persistent queue health statuses for the Source or Destination across all Worker Processes. Includes only statuses with non-zero counts.

Green == Healthy: Normal operation

Yellow == Degraded: Potential issues

Red == Critical: Problem or error that affects operation

Unknown == Unknown: Cannot determine health status." timestamp: type: integer description: Timestamp (in Unix time) when the persistent queue status was last @@ -59905,13 +64535,7 @@ components: description: Overall health status of the Source or Destination. healthCounts: $ref: "#/components/schemas/HealthCountType" - description: "Counts of health statuses for the Source or Destination across all - Worker Processes. Includes only statuses with non-zero counts.
-
Green == Healthy: Normal operation
-
Yellow == Degraded: Potential issues
-
Red == Critical: Problem or error that affects - operation

Unknown == Unknown: Cannot determine - health status." + description: "Counts of health statuses for the Source or Destination across all Worker Processes. Includes only statuses with non-zero counts.

Green == Healthy: Normal operation

Yellow == Degraded: Potential issues

Red == Critical: Problem or error that affects operation

Unknown == Unknown: Cannot determine health status." metrics: type: object additionalProperties: true @@ -59955,12 +64579,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/InputStatus" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -59981,10 +64606,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/OutputStatus" OutputStatus: @@ -60013,12 +64638,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/OutputStatus" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -60039,10 +64665,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/SavedJobResponse" SavedJobResponseEnrichedFields: @@ -60544,12 +65170,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/SavedJobResponse" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -60623,6 +65250,13 @@ components: items: type: object properties: + deployMode: + type: string + enum: + - auto + - manual + description: Deploy mode configured on the lookup file. + x-speakeasy-unknown-values: allow deployedVersion: type: string description: Version of the lookup file currently deployed on the Worker or @@ -60643,6 +65277,17 @@ components: ConfigGroup: type: object properties: + __srcGroup: + type: string + description: Fleet or group id this entity was inherited from when served by a + Config Helper for a child fleet. Present when inherited from parent, + including when the child has a local overlay. Omitted when the + entity is local and not inherited. Display-only; never persisted. + __srcOverridden: + type: boolean + description: If true, the child fleet has a local overlay on an inherited + entity. Omitted when inherited and unmodified, or when local and not + inherited. Display-only; never persisted. cloud: $ref: "#/components/schemas/ConfigGroupCloud" description: Cloud provider and region details for a Cribl.Cloud Worker Group. @@ -60655,20 +65300,10 @@ components: defaults to false for on-prem groups. configVersion: type: string - description: "Commit hash of the deployed configuration version for the Worker - Group, Outpost Group, or Edge Fleet. Automatically populated and - returned in responses.

**Warning**: Do not change the - value of configVersion in the body of PATCH requests. - The PATCH request body must include the value as it appears in the - GET /products/{product}/groups/{id} response." + description: "Commit hash of the deployed configuration version for the Worker Group, Outpost Group, or Edge Fleet. Automatically populated and returned in responses.

**Warning**: Do not change the value of configVersion in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response." deployingWorkerCount: type: integer - description: "Number of Workers or Nodes that are currently deploying the latest - configuration version.

**Warning**: Do not change the - value of deployingWorkerCount in the body of PATCH - requests. The PATCH request body must include the value as it - appears in the GET /products/{product}/groups/{id} - response." + description: "Number of Workers or Nodes that are currently deploying the latest configuration version.

**Warning**: Do not change the value of deployingWorkerCount in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response." description: type: string description: Brief description of the Worker Group, Outpost Group, or Edge Fleet. @@ -60697,12 +65332,7 @@ components: description: Unique identifier. incompatibleWorkerCount: type: integer - description: "Number of Workers or Nodes running a Cribl version that is - incompatible with the current upgrade target.

**Warning**: - Do not change the value of incompatibleWorkerCount in - the body of PATCH requests. The PATCH request body must include the - value as it appears in the GET - /products/{product}/groups/{id} response." + description: "Number of Workers or Nodes running a Cribl version that is incompatible with the current upgrade target.

**Warning**: Do not change the value of incompatibleWorkerCount in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response." inherits: type: string description: The id of the parent Edge Fleet. If provided, this @@ -60722,11 +65352,7 @@ components: type: array items: $ref: "#/components/schemas/ConfigGroupLookups" - description: "Lookup deployment status per Worker or Node context.

- **Warning**: Do not change the value of - lookupDeployments in the body of PATCH requests. The - PATCH request body must include the value as it appears in the - GET /products/{product}/groups/{id} response." + description: "Lookup deployment status per Worker or Node context.

**Warning**: Do not change the value of lookupDeployments in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response." maxWorkerAge: type: string description: Maximum duration a Worker or Node can remain disconnected before @@ -60767,14 +65393,7 @@ components: Edge Fleets. workerCount: type: integer - description: "Number of Workers or Nodes currently in the Worker Group, Outpost - Group, or Edge Fleet. The value is automatically populated and - **does not scale Cribl.Cloud Worker Groups**. Use - estimatedIngestRate to scale Cribl.Cloud Worker Groups. -

**Warning**: Do not change the value of - workerCount in the body of PATCH requests. The PATCH - request body must include the value as it appears in the GET - /products/{product}/groups/{id} response." + description: "Number of Workers or Nodes currently in the Worker Group, Outpost Group, or Edge Fleet. The value is automatically populated and **does not scale Cribl.Cloud Worker Groups**. Use estimatedIngestRate to scale Cribl.Cloud Worker Groups.

**Warning**: Do not change the value of workerCount in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response." workerRemoteAccess: type: boolean description: If true, the Leader allows remote access (teleporting) @@ -60793,12 +65412,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/ConfigGroup" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -60819,15 +65439,26 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/ConfigGroup" GroupCreateRequest: type: object properties: + __srcGroup: + type: string + description: Fleet or group id this entity was inherited from when served by a + Config Helper for a child fleet. Present when inherited from parent, + including when the child has a local overlay. Omitted when the + entity is local and not inherited. Display-only; never persisted. + __srcOverridden: + type: boolean + description: If true, the child fleet has a local overlay on an inherited + entity. Omitted when inherited and unmodified, or when local and not + inherited. Display-only; never persisted. cloud: $ref: "#/components/schemas/ConfigGroupCloud" description: Cloud provider and region details for a Cribl.Cloud Worker Group. @@ -60966,10 +65597,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/UserAccessControlList" ProductsCore: @@ -60988,10 +65619,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/TeamAccessControlList" ProductsBase: @@ -61009,20 +65640,6 @@ components: examples: - {} title: EmptyObject - CountedCriblLakeDataset: - type: object - required: - - items - - count - properties: - count: - type: integer - description: number of items present in the items array - items: - type: array - description: List of items in this response. - items: - $ref: "#/components/schemas/CriblLakeDataset" LakehouseConnectionType: type: string enum: @@ -61161,6 +65778,22 @@ components: - dataTypeId - filter title: ObjectStorageFilter + SearchExecutionConfig: + type: object + properties: + backendId: + type: string + enum: + - dynamic + - byo + x-speakeasy-unknown-values: allow + poolRoutingKey: + type: string + description: Selects the ordinary BYO executor pool. Required only when + backendId is byo; not used for Lake datasets. + required: + - backendId + title: SearchExecutionConfig SearchVersion: type: string enum: @@ -61189,6 +65822,8 @@ components: $ref: "#/components/schemas/ObjectStorageFilter" description: Glob-to-Datatype mappings for the Lake bucket path. Used only for search execution v2. + searchExecution: + $ref: "#/components/schemas/SearchExecutionConfig" searchVersion: $ref: "#/components/schemas/SearchVersion" description: Search execution version for the Cribl Lake Dataset. Search @@ -61207,6 +65842,11 @@ components: type: string description: Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. + allowRecordErasure: + type: boolean + description: If true, the Dataset is opted in to Lake Record + Erasure. Off by default; only settable when the + feature-lake-record-erasure flag is enabled. bucketName: type: string description: Name of the legacy Cribl Lake bucket that backs the Dataset. @@ -61234,6 +65874,13 @@ components: metrics: $ref: "#/components/schemas/LakeDatasetMetrics" description: Most recent Dataset metrics snapshot. + providerPath: + type: string + description: Storage path within the provider (for example an S3 prefix or Azure + container). Independent of id for catalog-backed + Datasets so name reuse after delete cannot collide with lingering + object-storage data. When omitted, id is the storage + path (legacy YAML Datasets). retentionPeriodInDays: type: integer description: Dataset retention period, in days. @@ -61253,6 +65900,20 @@ components: required: - id title: CriblLakeDataset + CountedCriblLakeDataset: + type: object + required: + - items + - count + properties: + count: + type: integer + description: Number of items returned in the items array. + items: + type: array + description: The list of items returned in this response. + items: + $ref: "#/components/schemas/CriblLakeDataset" PaginatedCriblLakeDataset: type: object required: @@ -61261,12 +65922,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/CriblLakeDataset" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -61288,6 +65950,11 @@ components: type: string description: Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. + allowRecordErasure: + type: boolean + description: If true, the Dataset is opted in to Lake Record + Erasure. Off by default; only settable when the + feature-lake-record-erasure flag is enabled. bucketName: type: string description: Name of the legacy Cribl Lake bucket that backs the Dataset. @@ -61316,6 +65983,13 @@ components: metrics: $ref: "#/components/schemas/LakeDatasetMetrics" description: Most recent Dataset metrics snapshot. + providerPath: + type: string + description: Storage path within the provider (for example an S3 prefix or Azure + container). Independent of id for catalog-backed + Datasets so name reuse after delete cannot collide with lingering + object-storage data. When omitted, id is the storage + path (legacy YAML Datasets). retentionPeriodInDays: type: integer description: Dataset retention period, in days. @@ -61338,8 +66012,12 @@ components: properties: forcePasswordChange: type: boolean + description: If true, the user must change their password before + accessing the API. Otherwise, false. token: type: string + description: Bearer token to include in the Authorization header + for subsequent API requests. required: - forcePasswordChange - token @@ -61349,8 +66027,10 @@ components: properties: password: type: string + description: Password for the account. username: type: string + description: Username of the account to authenticate. required: - password - username @@ -61437,10 +66117,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: type: number CountedMasterWorkerEntry: @@ -61451,10 +66131,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/MasterWorkerEntry" ConnectionProtocol: @@ -61580,6 +66260,10 @@ components: HBCriblInfo: type: object properties: + autoLookupVersions: + $ref: "#/components/schemas/LookupVersions" + description: Automatically deployed Lookup file names and their deployed + versions by context. config: type: object properties: @@ -61621,9 +66305,11 @@ components: distMode: type: string enum: + - dedicated-org-leader - edge - managed-edge - master + - org-leader - outpost - search-supervisor - single @@ -62096,8 +66782,7 @@ components: description: JSON-stringified filter object to evaluate against Nodes for inclusion in the response. examples: - - "%7B%22field%22%3A%22group%22%2C%22op%22%3A%22is%22%2C%22value%22%3A%\ - 22default%22%7D" + - "%7B%22field%22%3A%22group%22%2C%22op%22%3A%22is%22%2C%22value%22%3A%22default%22%7D" title: WorkerFilterJson PaginatedMasterWorkerEntry: type: object @@ -62107,12 +66792,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/MasterWorkerEntry" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -62133,10 +66819,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/RestartResponse" RestartResponse: @@ -62180,12 +66866,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/DistributedSummary" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -62334,8 +67021,7 @@ components: - healthy - shutting down - standby - description: "Health state: healthy, standby, or - shutting down." + description: "Health state: healthy, standby, or shutting down." x-speakeasy-unknown-values: allow required: - overlay @@ -62351,10 +67037,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/PackInstallInfo" TagsTypePackInstallInfo: @@ -62396,6 +67082,17 @@ components: PackInstallInfo: type: object properties: + __srcGroup: + type: string + description: Fleet or group id this entity was inherited from when served by a + Config Helper for a child fleet. Present when inherited from parent, + including when the child has a local overlay. Omitted when the + entity is local and not inherited. Display-only; never persisted. + __srcOverridden: + type: boolean + description: If true, the child fleet has a local overlay on an inherited + entity. Omitted when inherited and unmodified, or when local and not + inherited. Display-only; never persisted. author: type: string description: Name or identifier of the Pack author. @@ -62490,10 +67187,7 @@ components: description: Brief description of the Pack and its purpose. source: type: string - description: Source of the Pack. Provide a staging source ID from PUT - /packs, a direct URL to a .crbl file, or a - git+<repo-url> Git repository URL. If omitted, an - empty Pack is created. + description: "Where to install the Pack from: an uploaded Pack source, a direct URL to a .crbl file, or a Git repository URL. Leave empty to create an empty Pack." tags: type: object description: Categorization tags for the Pack. @@ -62526,13 +67220,11 @@ components: description: List of stream tags for routing and filtering. allowCustomFunctions: type: boolean - description: If true or omitted, allow the Pack to use custom - JavaScript functions. If false, reject Packs that use - custom JavaScript functions. + description: Allow the Pack to use custom JavaScript functions. When disabled, + Packs that use custom JavaScript functions are rejected. force: type: boolean - description: If true, overwrite an existing Pack with the same ID. - Otherwise, false. + description: Overwrite an existing Pack that has the same ID. anyOf: - required: - id @@ -62547,10 +67239,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/PackUninstallInfo" PackUninstallInfo: @@ -62574,15 +67266,26 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/PackInfo" PackInfo: type: object properties: + __srcGroup: + type: string + description: Fleet or group id this entity was inherited from when served by a + Config Helper for a child fleet. Present when inherited from parent, + including when the child has a local overlay. Omitted when the + entity is local and not inherited. Display-only; never persisted. + __srcOverridden: + type: boolean + description: If true, the child fleet has a local overlay on an inherited + entity. Omitted when inherited and unmodified, or when local and not + inherited. Display-only; never persisted. author: type: string description: Name or identifier of the Pack author. @@ -62653,12 +67356,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/PackInfo" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -62715,10 +67419,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitCommitSummary" GitFileRename: @@ -62811,10 +67515,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitCountResult" GitCountResult: @@ -62834,10 +67538,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitDiffResult" GitDiffLines: @@ -62993,10 +67697,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitFilesResponse" GitFile: @@ -63019,8 +67723,7 @@ components: description: Path of the file relative to the configuration root. state: type: string - description: "Git status code for the file: M for modified, - A for added, or D for deleted." + description: "Git status code for the file: M for modified, A for added, or D for deleted." required: - name title: GitFile @@ -63050,10 +67753,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitRevertResult" GitRevertResult: @@ -63130,10 +67833,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitShowResult" GitShowResult: @@ -63157,10 +67860,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/SystemSettingsConf" BackupsSettings: @@ -63313,8 +68016,7 @@ components: TLS-inspecting proxy is in use (insecure). upgradeSource: type: string - description: "Upgrade source: cribl for official Cribl packages or - custom for a custom package URL." + description: "Upgrade source: cribl for official Cribl packages or custom for a custom package URL." title: UpgradeSettings SystemSettingsConf: type: object @@ -63371,163 +68073,89 @@ components: workers: $ref: "#/components/schemas/WorkersTypeSystemSettingsConf" description: Worker Process configuration. - required: - - api - - backups - - pii - - proxy - - rollback - - shutdown - - sni - - system - - tls - - upgradeGroupSettings - - upgradeSettings - - workers - title: SystemSettingsConf - CountedSystemSettingsConfResponse: - type: object - required: - - items - - count - properties: - count: - type: integer - description: number of items present in the items array - items: - type: array - description: List of items in this response. - items: - $ref: "#/components/schemas/SystemSettingsConfResponse" - SystemSettingsConfResponse: - type: object - properties: - api: - type: object - properties: - baseUrl: - type: string - description: Base URL for the API server. Used when the server is behind a - reverse proxy. - disableApiCache: - type: boolean - description: If true, disable the API response cache. Otherwise, - false. - disabled: - type: boolean - description: If true, the API server is disabled. Otherwise, - false. - headers: - type: object - additionalProperties: - type: string - description: Custom HTTP response headers to include in every API response. - host: - type: string - description: Hostname or IP address the API server listens on. - idleSessionTTL: - type: integer - description: Idle session timeout in seconds. Sessions are invalidated after the - specified seconds of inactivity. - listenOnPort: - type: boolean - description: If true, bind to the configured port as the server - listen port. Otherwise, false. - loginRateLimit: - type: string - description: Rate limit for login attempts. Value is a string such as - 100/min. - port: - type: integer - description: Port number the API server listens on. - protocol: - type: string - description: "API protocol: http or https." - scripts: - type: boolean - description: If true, enable JavaScript scripting support in the - API. Otherwise, false. - sensitiveFields: - type: array - items: - type: string - description: List of field names whose values are redacted in API responses and - logs. - ssl: - $ref: "#/components/schemas/SslTypeSystemSettingsConfApi" - description: TLS configuration for the API server. - ssoRateLimit: - type: string - description: Rate limit for SSO authentication attempts. Value is a string such - as 100/min. - workerRemoteAccess: - type: boolean - description: If true, enable remote access (teleporting) to Worker - Processes via the API. Otherwise, false. - required: - - disabled - - host - - port - apps: - $ref: "#/components/schemas/AppsTypeSystemSettingsConf" - description: App configuration. - backups: - $ref: "#/components/schemas/BackupsSettings" - description: Configuration backup settings, including storage location and - retention period. - customLogo: - $ref: "#/components/schemas/CustomLogoTypeSystemSettingsConf" - description: Custom logo configuration for the Cribl UI login page and - navigation bar. - pii: - $ref: "#/components/schemas/PiiSettings" - description: Personally identifiable information (PII) detection configuration. - proxy: - $ref: "#/components/schemas/ProxyTypeSystemSettingsConf" - description: HTTP proxy configuration for outbound connections. - rollback: - $ref: "#/components/schemas/RollbackSettings" - description: Automatic rollback settings applied when an upgrade fails. - shutdown: - $ref: "#/components/schemas/ShutdownTypeSystemSettingsConf" - description: Graceful shutdown configuration. - sni: - $ref: "#/components/schemas/SniSettings" - description: Server Name Indication (SNI) routing configuration. - sockets: - $ref: "#/components/schemas/SocketsTypeSystemSettingsConf" - description: Unix domain socket configuration. - support: - $ref: "#/components/schemas/SupportTypeSystemSettingsConf" - description: Support and diagnostics settings. - system: - type: object - properties: - intercom: - type: boolean - description: If true, enable Intercom integration for in-product - messaging. Otherwise, false. - upgrade: - $ref: "#/components/schemas/UpgradeOptionsSystemSettingsConfSystem" - description: "Upgrade permission policy: api to allow upgrades from - the UI or API or false to disable." - required: - - intercom - - upgrade - tls: - $ref: "#/components/schemas/TlsSettings" - description: Global TLS/SSL settings applied to all outbound connections that do - not specify their own TLS configuration. - upgradeGroupSettings: - $ref: "#/components/schemas/UpgradeGroupSettings" - description: Rolling upgrade group settings that control how many nodes are - upgraded at a time. - upgradeSettings: - $ref: "#/components/schemas/UpgradeSettings" - description: Automatic upgrade scheduling and package source configuration. - workers: - $ref: "#/components/schemas/WorkersTypeSystemSettingsConf" - description: Worker Process configuration. + required: + - api + - backups + - pii + - proxy + - rollback + - shutdown + - sni + - system + - tls + - upgradeGroupSettings + - upgradeSettings + - workers + title: SystemSettingsConf + CountedSystemSettingsConfResponse: + type: object + required: + - items + - count + properties: + count: + type: integer + description: Number of items returned in the items array. + items: + type: array + description: The list of items returned in this response. + items: + $ref: "#/components/schemas/SystemSettingsConfResponse" + SystemSettingsConfResponse: + type: object + properties: + api: + $ref: "#/components/schemas/ApiTypeSystemSettingsConf" + description: API server configuration for the Cribl instance. + apps: + $ref: "#/components/schemas/AppsTypeSystemSettingsConf" + description: App configuration. + backups: + $ref: "#/components/schemas/BackupsSettings" + description: Configuration backup settings, including storage location and + retention period. + customLogo: + $ref: "#/components/schemas/CustomLogoTypeSystemSettingsConf" + description: Custom logo configuration for the Cribl UI login page and + navigation bar. + pii: + $ref: "#/components/schemas/PiiSettings" + description: Personally identifiable information (PII) detection configuration. + proxy: + $ref: "#/components/schemas/ProxyTypeSystemSettingsConf" + description: HTTP proxy configuration for outbound connections. + rollback: + $ref: "#/components/schemas/RollbackSettings" + description: Automatic rollback settings applied when an upgrade fails. + shutdown: + $ref: "#/components/schemas/ShutdownTypeSystemSettingsConf" + description: Graceful shutdown configuration. + sni: + $ref: "#/components/schemas/SniSettings" + description: Server Name Indication (SNI) routing configuration. + sockets: + $ref: "#/components/schemas/SocketsTypeSystemSettingsConf" + description: Unix domain socket configuration. + support: + $ref: "#/components/schemas/SupportTypeSystemSettingsConf" + description: Support and diagnostics settings. + system: + $ref: "#/components/schemas/SystemTypeSystemSettingsConf" + description: System-level operational settings for the Cribl instance. + tls: + $ref: "#/components/schemas/TlsSettings" + description: Global TLS/SSL settings applied to all outbound connections that do + not specify their own TLS configuration. + upgradeGroupSettings: + $ref: "#/components/schemas/UpgradeGroupSettings" + description: Rolling upgrade group settings that control how many nodes are + upgraded at a time. + upgradeSettings: + $ref: "#/components/schemas/UpgradeSettings" + description: Automatic upgrade scheduling and package source configuration. + workers: + $ref: "#/components/schemas/WorkersTypeSystemSettingsConf" + description: Worker Process configuration. required: - api - system @@ -63596,6 +68224,9 @@ components: certPath: type: string description: Filesystem path to the PEM-encoded TLS certificate. + certificateName: + type: string + description: Name of a predefined Certificate stored in Cribl. disabled: type: boolean description: If true, TLS is disabled for the API server. @@ -63619,6 +68250,34 @@ components: apps: type: object properties: + appBackendBrokerOrigin: + type: string + description: Public origin for App Platform backend broker callbacks + (standalone/on-prem only). Must be an absolute HTTP(S) URL. + appBackendMaxCallbacksPerInstallation: + type: integer + description: Maximum number of broker callbacks per minute a single app backend + installation may make. Over-limit callbacks receive HTTP 429. + appBackendMaxCallbacksTotal: + type: integer + description: Maximum number of broker callbacks per minute across all app + backend installations on this Leader. Unlimited when unset. + Over-limit callbacks receive HTTP 429. + appBackendMaxInFlight: + type: integer + description: Maximum number of concurrent App Platform backend invocations + across all apps on this Leader. + appScheduleBodyExpressionMaxLength: + type: integer + description: Maximum number of characters allowed in a schedule bodyExpression. + appScheduledConcurrentJobLimit: + type: integer + description: Maximum number of concurrent scheduled App Platform function jobs + across all apps on this Leader (group-wide). Changes require a + Leader restart. + appSchedulesMax: + type: integer + description: Maximum number of schedule records a single App may declare. enabled: type: boolean description: If true, enable Apps. Otherwise, false. @@ -63705,8 +68364,7 @@ components: messaging. Otherwise, false. upgrade: $ref: "#/components/schemas/UpgradeOptionsSystemSettingsConfSystem" - description: "Upgrade permission policy: api to allow upgrades from - the UI or API or false to disable." + description: "Upgrade permission policy: api to allow upgrades from the UI or API or false to disable." description: System-level operational settings for the Cribl instance. tls: $ref: "#/components/schemas/TlsSettings" @@ -63778,10 +68436,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/SystemRestartResponse" SystemRestartResponse: @@ -63802,15 +68460,26 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/BranchInfo" BranchInfo: type: object properties: + __srcGroup: + type: string + description: Fleet or group id this entity was inherited from when served by a + Config Helper for a child fleet. Present when inherited from parent, + including when the child has a local overlay. Omitted when the + entity is local and not inherited. Display-only; never persisted. + __srcOverridden: + type: boolean + description: If true, the child fleet has a local overlay on an inherited + entity. Omitted when inherited and unmodified, or when local and not + inherited. Display-only; never persisted. id: type: string description: Unique identifier. @@ -63854,10 +68523,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitInfo" GitInfo: @@ -63887,12 +68556,13 @@ components: properties: items: type: array - description: The pre-limited items in the list of results + description: The items returned in this response, after any offset/limit + pagination has been applied. items: $ref: "#/components/schemas/GitLogResult" count: type: integer - description: Number of items present in the items array + description: Number of items returned in the items array. offset: type: integer description: Pagination offset. Returned when offset/limit query parameters are @@ -63938,10 +68608,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: $ref: "#/components/schemas/GitStatusResult" GitStatusResult: @@ -64048,10 +68718,10 @@ components: properties: count: type: integer - description: number of items present in the items array + description: Number of items returned in the items array. items: type: array - description: List of items in this response. + description: The list of items returned in this response. items: type: boolean AdditionalPropertiesTypeEnrichedFieldsSavedState: @@ -64138,10 +68808,7 @@ components: host: type: string title: Hostname - description: "Hostname of cluster node. Must be a JavaScript expression (which - can evaluate to a constant value), enclosed in quotes or backticks. - Can be evaluated only at init time. Example referencing a Global - Variable: `myBucket-${C.vars.myVar}`." + description: "Hostname of cluster node. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`." port: type: number title: Port @@ -64179,36 +68846,25 @@ components: pattern: type: string title: Pattern - description: "Grok pattern to extract fields. Syntax supported: - %{PATTERN_NAME:FIELD_NAME}" + description: "Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME}" NameFieldType: type: object + description: Reference to a field by its original text and parsed path segments. required: - raw - path properties: raw: type: string + description: Field name or expression before parsing. path: type: array + description: Path segments for the field name. For example, ["level1", + "level2"] represents level1.level2. items: oneOf: - type: string - type: number - TemplateTargetPairConfFunctionConfSchemaNotificationPolicies: - type: object - required: - - templateId - - targetId - properties: - templateId: - type: string - title: Template ID - description: ID of the notification template to use - targetId: - type: string - title: Target ID - description: ID of the notification target (output) AuthTypeOptionsAzureBlobAuthTypeManual: enum: - manual @@ -64524,30 +69180,20 @@ components: RestDiscoveryDiscoverTypeHttpPaginationType: oneOf: - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeNone" - - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponse\ - Body" - - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponse\ - Header" - - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponse\ - HeaderLink" - - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeRequestO\ - ffset" - - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeRequestP\ - age" + - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponseBody" + - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeader" + - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeaderLink" + - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeRequestOffset" + - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeRequestPage" discriminator: propertyName: type mapping: none: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeNone" - response_body: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTyp\ - eResponseBody" - response_header: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationT\ - ypeResponseHeader" - response_header_link: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPagina\ - tionTypeResponseHeaderLink" - request_offset: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTy\ - peRequestOffset" - request_page: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationType\ - RequestPage" + response_body: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponseBody" + response_header: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeader" + response_header_link: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeResponseHeaderLink" + request_offset: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeRequestOffset" + request_page: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationTypeRequestPage" AuthenticationMethodOptionsS3CollectorConf: type: string title: Authentication method @@ -64569,34 +69215,14 @@ components: - csv - json x-speakeasy-unknown-values: allow - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint: - type: object - title: Input provenance - description: Read-only metadata that records how the Source was created. - Preserved on update when omitted from the request body. Cannot be set on - create. - additionalProperties: false - properties: - origin: - type: string - enum: - - data_source_discovery - description: Feature that created the Source. - x-speakeasy-unknown-values: allow - destinationArn: - type: string - description: ARN of the S3 bucket or Firehose delivery stream configured as the - Source. - sourceArn: - type: string - description: ARN of the AWS resource that produces the logs. - accountId: - type: string - minLength: 1 - description: Cloud tenant or scope id the Source was configured for (for example - an AWS account id, GCP project or folder id, or Azure subscription - or resource group id). - readOnly: true + TemplateFamilyOptionsCriblSourceProvenance: + type: string + enum: + - cloudformation + - terraform + description: Infrastructure-as-code family that provisioned the AWS resources + (absent means cloudformation). + x-speakeasy-unknown-values: allow ConnectionConfInputCollection: type: object properties: @@ -64687,6 +69313,12 @@ components: title: Value description: JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.) + OriginOptionsCriblSourceProvenance: + type: string + enum: + - data_source_discovery + description: Feature that created the Source. + x-speakeasy-unknown-values: allow OauthParamConfInputKafka: type: object required: @@ -64768,12 +69400,7 @@ components: enum: - msk description: Connector type identifier. - TypeOptionsSplunk: - type: string - enum: - - splunk - description: Connector type identifier. - AuthenticationMethodOptionsAuthTokensItems: + AuthenticationMethodOptionsAuthTokensExtItems: title: Authentication method type: string enum: @@ -64782,6 +69409,32 @@ components: description: Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate x-speakeasy-unknown-values: allow + InputHttpAuthTokensExtItemsType: + required: + - token + properties: + token: + type: string + description: Shared secret provided by clients for authentication + InputHttpAuthTypeSecretConstraint: + required: + - authType + properties: + authType: + enum: + - secret + description: Discriminator value. + x-speakeasy-unknown-values: allow + AuthTypeOptionsAuthTokensExtItems: + enum: + - secret + description: Discriminator value. + x-speakeasy-unknown-values: allow + TypeOptionsSplunk: + type: string + enum: + - splunk + description: Connector type identifier. AuthenticationMethodOptions: title: Authentication method type: string @@ -64809,6 +69462,17 @@ components: enum: - azure_blob description: Connector type identifier. + AuthenticationMethodOptionsClientAssertionClientAssertionrpc: + title: Authentication method + type: string + enum: + - secret + - clientSecret + - clientCert + - clientAssertion + - clientAssertion_rpc + description: Authentication method + x-speakeasy-unknown-values: allow ExtraHttpHeaderConfInputElastic: type: object required: @@ -65275,7 +69939,7 @@ components: type: string title: Value description: OAuth header value - AuthenticationMethodOptionsAuthTokensItemsSecret: + AuthenticationMethodOptionsAuthTokensItems: title: Authentication method type: string enum: @@ -65323,22 +69987,32 @@ components: - debug - silly x-speakeasy-unknown-values: allow - TimeWarningTypeRunnableJobCollectionScheduleRun: - type: object - description: Warning state used when the collection time range is unset for - time-sensitive Collectors. - properties: {} TypeOptionsRunnableJobCollectionInput: type: string enum: - collection description: Resource type identifier. x-speakeasy-unknown-values: allow - ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor: + ExecutorTypeRunnableJobExecutor: type: object - title: Executor-specific settings - description: Executor-type-specific settings object. Shape varies by executor type. - properties: {} + description: Executor configuration, including the executor type and its settings. + required: + - type + properties: + type: + type: string + title: Executor type + description: The type of executor to run + storeTaskResults: + type: boolean + title: Store task results + description: Determines whether or not to write task results to disk + conf: + type: object + title: Executor-specific settings + description: Executor-type-specific settings object. Shape varies by executor + type. + additionalProperties: true AdditionalPropertiesTypeJobInfoStats: oneOf: - type: number @@ -65586,27 +70260,19 @@ components: initialBackoffMs: type: number title: Initial backoff (ms) - description: "Initial delay before first retry attempt. Valid range: 1s-5min - (1000-300000ms). Values outside this range will be clamped to the - nearest valid value." + description: "Initial delay before first retry attempt. Valid range: 1s-5min (1000-300000ms). Values outside this range will be clamped to the nearest valid value." backoffMultiplier: type: number title: Backoff multiplier - description: "Multiplier applied to backoff delay after each retry. Valid range: - 1-10. Values outside this range will be clamped to the nearest valid - value." + description: "Multiplier applied to backoff delay after each retry. Valid range: 1-10. Values outside this range will be clamped to the nearest valid value." maxBackoffMs: type: number title: Max backoff (ms) - description: "Maximum delay between retry attempts. Valid range: 1s-10min - (1000-600000ms). Values outside this range will be clamped to the - nearest valid value." + description: "Maximum delay between retry attempts. Valid range: 1s-10min (1000-600000ms). Values outside this range will be clamped to the nearest valid value." jitterPercent: type: number title: Jitter (%) - description: "Random jitter percentage added to backoff delay to prevent - thundering herd. Valid range: 0-100. Values outside this range will - be clamped to the nearest valid value." + description: "Random jitter percentage added to backoff delay to prevent thundering herd. Valid range: 0-100. Values outside this range will be clamped to the nearest valid value." OrphanFileRecoveryType: type: object title: Orphan file recovery @@ -66149,6 +70815,12 @@ components: RouteConfInput: type: object properties: + autoParse: + type: boolean + description: If true, detect each matched event's datatype and + extract fields from _raw before the Pipeline processes + the event, so Functions and Filters can reference the extracted + fields. Otherwise, false (the default). clones: type: array items: @@ -66158,8 +70830,7 @@ components: Route. context: type: string - description: "Context for the Route: group (Worker Group or Edge - Fleet) or pack." + description: "Context for the Route: group (Worker Group or Edge Fleet) or pack." description: type: string description: Brief description of the Route. @@ -66195,9 +70866,7 @@ components: description: Pipeline that the Route sends matching events to. targetContext: $ref: "#/components/schemas/TargetContext" - description: "Target context for subsequent event processing after applying the - Route: group (Worker Group or Edge Fleet) or - pack." + description: "Target context for subsequent event processing after applying the Route: group (Worker Group or Edge Fleet) or pack." final: type: boolean description: If true (default), the Route processes matched events @@ -66297,6 +70966,9 @@ components: certPath: type: string description: Filesystem path to the PEM-encoded TLS certificate. + certificateName: + type: string + description: Name of a predefined Certificate stored in Cribl. disabled: type: boolean description: If true, TLS is disabled for the API server. @@ -66316,6 +70988,34 @@ components: AppsTypeSystemSettingsConf: type: object properties: + appBackendBrokerOrigin: + type: string + description: Public origin for App Platform backend broker callbacks + (standalone/on-prem only). Must be an absolute HTTP(S) URL. + appBackendMaxCallbacksPerInstallation: + type: integer + description: Maximum number of broker callbacks per minute a single app backend + installation may make. Over-limit callbacks receive HTTP 429. + appBackendMaxCallbacksTotal: + type: integer + description: Maximum number of broker callbacks per minute across all app + backend installations on this Leader. Unlimited when unset. + Over-limit callbacks receive HTTP 429. + appBackendMaxInFlight: + type: integer + description: Maximum number of concurrent App Platform backend invocations + across all apps on this Leader. + appScheduleBodyExpressionMaxLength: + type: integer + description: Maximum number of characters allowed in a schedule bodyExpression. + appScheduledConcurrentJobLimit: + type: integer + description: Maximum number of concurrent scheduled App Platform function jobs + across all apps on this Leader (group-wide). Changes require a + Leader restart. + appSchedulesMax: + type: integer + description: Maximum number of schedule records a single App may declare. enabled: type: boolean description: If true, enable Apps. Otherwise, false. @@ -66384,8 +71084,7 @@ components: enum: - api - false - description: "Upgrade permission policy: api to allow upgrades from - the UI or API or false to disable." + description: "Upgrade permission policy: api to allow upgrades from the UI or API or false to disable." x-speakeasy-unknown-values: allow WorkersTypeSystemSettingsConf: type: object @@ -66449,8 +71148,7 @@ components: description: Configuration for extracting and parsing timestamps from events. properties: type: - $ref: "#/components/schemas/TimestampTypeOptionsEventBreakerExistingOrNewNewTim\ - estamp" + $ref: "#/components/schemas/TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp" description: Method to use for timestamp extraction. Use auto for automatic detection, format to specify a strptime format, or current to use the current system time. @@ -66506,12 +71204,10 @@ components: title: Passphrase description: Passphrase to use to decrypt private key minVersion: - $ref: "#/components/schemas/MinimumTlsVersionOptionsRedisDeploymentTypeStandalo\ - neTlsOptions" + $ref: "#/components/schemas/MinimumTlsVersionOptionsRedisDeploymentTypeStandaloneTlsOptions" description: Minimum TLS version to use when connecting maxVersion: - $ref: "#/components/schemas/MaximumTlsVersionOptionsRedisDeploymentTypeStandalo\ - neTlsOptions" + $ref: "#/components/schemas/MaximumTlsVersionOptionsRedisDeploymentTypeStandaloneTlsOptions" description: Maximum TLS version to use when connecting TlsOptionsTypeRedisDeploymentTypeCluster: type: object @@ -66551,12 +71247,10 @@ components: title: Passphrase description: Passphrase to use to decrypt private key minVersion: - $ref: "#/components/schemas/MinimumTlsVersionOptionsRedisDeploymentTypeStandalo\ - neTlsOptions" + $ref: "#/components/schemas/MinimumTlsVersionOptionsRedisDeploymentTypeStandaloneTlsOptions" description: Minimum TLS version to use when connecting maxVersion: - $ref: "#/components/schemas/MaximumTlsVersionOptionsRedisDeploymentTypeStandalo\ - neTlsOptions" + $ref: "#/components/schemas/MaximumTlsVersionOptionsRedisDeploymentTypeStandaloneTlsOptions" description: Maximum TLS version to use when connecting PaginationTypeRestDiscoveryDiscoverTypeHttp: type: object @@ -66566,8 +71260,7 @@ components: - type properties: type: - $ref: "#/components/schemas/PaginationOptionsRestDiscoveryDiscoverTypeHttpPagin\ - ation" + $ref: "#/components/schemas/PaginationOptionsRestDiscoveryDiscoverTypeHttpPagination" description: Pagination maxPages: type: number @@ -66596,9 +71289,7 @@ components: offsetField: type: string title: Offset field name - description: "Query string parameter that sets the index from which to begin - returning records. Example: - /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the index from which to begin returning records. Example: /api/v1/query?term=cribl&limit=100&offset=0" offset: type: number title: Starting offset @@ -66607,8 +71298,7 @@ components: limitField: type: string title: Limit field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: /api/v1/query?term=cribl&limit=100&offset=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&limit=100&offset=0" limit: type: number title: Record limit @@ -66627,8 +71317,7 @@ components: pageField: type: string title: Page number field name - description: "Query string parameter that sets the page index to be returned. - Example: /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the page index to be returned. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" page: type: number title: Starting page number @@ -66637,9 +71326,7 @@ components: sizeField: type: string title: Page size field name - description: "Query string parameter that sets the number of records retrieved - per request. Example: - /api/v1/query?term=cribl&page_size=100&page_number=0" + description: "Query string parameter that sets the number of records retrieved per request. Example: /api/v1/query?term=cribl&page_size=100&page_number=0" size: type: number title: Record limit @@ -66652,6 +71339,38 @@ components: number of pages for the query allOf: - $ref: "#/components/schemas/RestDiscoveryDiscoverTypeHttpPaginationType" + InputProvenanceTypeOptional: + type: object + title: Input provenance + description: Read-only metadata that records how the Source was created. + Preserved on update when omitted from the request body. Cannot be set on + create. + additionalProperties: false + properties: + origin: + $ref: "#/components/schemas/OriginOptionsCriblSourceProvenance" + description: Feature that created the Source. + destinationArn: + type: string + description: ARN of the S3 bucket or Firehose delivery stream configured as the + Source. + sourceArn: + type: string + description: ARN of the AWS resource that produces the logs. + sourceService: + type: string + description: Resolved DSD source-service offering, when known. + accountId: + type: string + minLength: 1 + description: Cloud tenant or scope id the Source was configured for (for example + an AWS account id, GCP project or folder id, or Azure subscription + or resource group id). + templateFamily: + $ref: "#/components/schemas/TemplateFamilyOptionsCriblSourceProvenance" + description: Infrastructure-as-code family that provisioned the AWS resources + (absent means cloudformation). + readOnly: true PqType: type: object properties: @@ -66682,8 +71401,9 @@ components: type: number title: Commit frequency description: The number of events to send downstream before committing that - Stream has read them - minimum: 1 + Stream has read them. Lower values increase cursor-write IOPS and + can add disk pressure, including on shared storage. + minimum: 42 maxFileSize: type: string title: File size limit @@ -66700,8 +71420,7 @@ components: path: type: string title: Queue file path - description: "The location for the persistent queue files. To this field's - value, the system will append: //inputs/" + description: "The location for the persistent queue files. To this field's value, the system will append: //inputs/" compress: $ref: "#/components/schemas/CompressionOptionsPq" description: Codec to use to compress the persisted data @@ -66957,6 +71676,11 @@ components: title: Authenticate client (mutual auth) description: Require clients to present their certificates. Used to perform client authentication using SSL certs. + caPath: + type: string + title: CA certificate path + description: Path on server containing CA certificates to use. PEM format. Can + reference $ENV_VARS. rejectUnauthorized: type: boolean title: Validate client certificates @@ -66985,11 +71709,6 @@ components: title: Certificate path description: Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. - caPath: - type: string - title: CA certificate path - description: Path on server containing CA certificates to use. PEM format. Can - reference $ENV_VARS. minVersion: $ref: "#/components/schemas/MinimumTlsVersionOptionsTls" description: Minimum TLS version @@ -66997,25 +71716,6 @@ components: $ref: "#/components/schemas/MaximumTlsVersionOptionsTls" description: Maximum TLS version description: TLS settings (server side) - AuthTokensExtConfInputHttp: - type: object - required: - - token - properties: - token: - type: string - title: Token - description: "Shared secret to be provided by any client (Authorization: )" - description: - type: string - title: Description - description: Description - metadata: - type: array - title: Fields - description: Fields to add to events referencing this token - items: - $ref: "#/components/schemas/MetadataConfInputCollection" RetryRulesType: type: object required: @@ -67085,14 +71785,12 @@ components: maxDataSize: type: string title: Data size limit - description: "Maximum disk space that can be consumed before older buckets are - deleted. Examples: 420MB, 4GB. Default is 1GB." + description: "Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB." pattern: ^\d+(\.\d+)?\s*(?:[kmgKMG](b|B))?$ maxDataTime: title: Data age limit type: string - description: "Maximum amount of time to retain data before older buckets are - deleted. Examples: 2h, 4d. Default is 24h." + description: "Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h." pattern: \d+[smhd]$ compress: $ref: "#/components/schemas/CompressionOptionsPersistence" @@ -67277,7 +71975,7 @@ components: type: object properties: authType: - $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItemsSecret" + $ref: "#/components/schemas/AuthenticationMethodOptionsAuthTokensItems" description: Select Secret to use a text secret to authenticate tokenSecret: type: string @@ -67313,6 +72011,7 @@ components: $ref: "#/components/schemas/MetadataConfInputCollection" RunnableJobCollectionScheduleRunType: type: object + description: Run settings that control how and when the Collection job runs. required: - mode properties: @@ -67331,9 +72030,7 @@ components: jobTimeout: title: Job timeout type: string - description: "Maximum time the job is allowed to run. Time unit defaults to - seconds if not specified (examples: 30, 45s, 15m). Enter 0 for - unlimited time." + description: "Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time." pattern: \d+[sm]?$ mode: type: string @@ -67362,10 +72059,6 @@ components: type: string description: IANA timezone name for interpreting timestamp values in the collection time range. - timeWarning: - $ref: "#/components/schemas/TimeWarningTypeRunnableJobCollectionScheduleRun" - description: Warning state used when the collection time range is unset for - time-sensitive Collectors. expression: type: string title: Filter @@ -67423,9 +72116,7 @@ components: throttleRatePerSec: type: string title: Throttling - description: "Rate (in bytes per second) to throttle while writing to an output. - Accepts values with multiple-byte units, such as KB, MB, and GB. - (Example: 42 MB) Default value of 0 specifies no throttling." + description: "Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling." pattern: ^[\d.]+(\s[KMGTPEZYkmgtpezy][Bb])?$ metadata: type: array @@ -67441,25 +72132,6 @@ components: type: string title: Destination description: Destination to send results to - ExecutorTypeRunnableJobExecutor: - type: object - description: Executor configuration, including the executor type and its settings. - required: - - type - properties: - type: - type: string - title: Executor type - description: The type of executor to run - storeTaskResults: - type: boolean - title: Store task results - description: Determines whether or not to write task results to disk - conf: - $ref: "#/components/schemas/ExecutorSpecificSettingsTypeRunnableJobExecutorExec\ - utor" - description: Executor-type-specific settings object. Shape varies by executor - type. StatusType: type: object properties: @@ -67483,8 +72155,7 @@ components: type: boolean description: Set to prefer status from the LB process, not from the worker process. - description: "Runtime status: health, metrics, and optional persistent-queue - info. Fields may be absent when data is unavailable." + description: "Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable." TlsSettingsClientSideTypeCaPathCertPathExtended: type: object title: TLS settings (client side) @@ -67654,16 +72325,12 @@ components: type: object properties: authType: - $ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuthBasicCredent\ - ialsSecret" + $ref: "#/components/schemas/AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret" description: Authentication type token: type: string title: Auth token - description: "Bearer token to include in the authorization header. In Grafana - Cloud, this is generally built by concatenating the username and the - API key, separated by a colon. Example: - :" + description: "Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :" textSecret: type: string title: Auth token (text secret) @@ -67772,8 +72439,7 @@ components: messaging. Otherwise, false. upgrade: $ref: "#/components/schemas/UpgradeOptionsSystemSettingsConfSystem" - description: "Upgrade permission policy: api to allow upgrades from - the UI or API or false to disable." + description: "Upgrade permission policy: api to allow upgrades from the UI or API or false to disable." required: - intercom - upgrade @@ -67791,9 +72457,7 @@ components: schemaRegistryURL: type: string title: Schema Registry URL - description: "URL for accessing the Confluent Schema Registry. Example: - http://localhost:8081. To connect over TLS, use https instead of - http." + description: "URL for accessing the Confluent Schema Registry. Example: http://localhost:8081. To connect over TLS, use https instead of http." connectionTimeout: type: number title: Connection timeout (ms) @@ -67848,9 +72512,7 @@ components: schemaRegistryURL: type: string title: Schema Registry URL - description: "URL for accessing the Confluent Schema Registry. Example: - http://localhost:8081. To connect over TLS, use https instead of - http." + description: "URL for accessing the Confluent Schema Registry. Example: http://localhost:8081. To connect over TLS, use https instead of http." connectionTimeout: type: number title: Connection timeout (ms) @@ -68512,6 +73174,39 @@ components: sendToRoutes: true pqEnabled: false count: 1 + InputCreateExamplesAkamaiHec: + summary: Akamai HEC + value: + id: akamai-hec-source + type: akamai_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Akamai HEC Source. + InputCreateExamplesGigamonHec: + summary: Gigamon + value: + id: gigamon-hec-source + type: gigamon_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Gigamon Source. + InputCreateExamplesBeyondTrustHec: + summary: BeyondTrust + value: + id: beyondtrust-hec-source + type: beyondtrust_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a BeyondTrust Source. InputCreateExamplesAnthropicCompliance: summary: Anthropic Compliance value: @@ -68527,12 +73222,42 @@ components: latest: now jobTimeout: "300" stateTracking: true - stateUpdateExpression: "__timestampExtracted !== false && {latestTime: - (state.latestTime || 0) > _time ? state.latestTime : _time}" + stateUpdateExpression: "__timestampExtracted !== false && {latestTime: (state.latestTime || 0) > _time ? state.latestTime : _time}" stateMergeExpression: "prevState.latestTime > newState.latestTime ? prevState : newState" sendToRoutes: true pqEnabled: false description: Example request body for creating a Anthropic Compliance Source. + InputCreateExamplesAnthropicEnterpriseAnalytics: + summary: Claude Enterprise Analytics + value: + id: anthropic-enterprise-analytics-source + type: anthropic_enterprise_analytics + textSecret: anthropic-api-key-secret + contentConfig: + - contentType: Usage Report + disabled: false + cronSchedule: 0 */4 * * * + earliest: -7d@d + bucketWidth: 1d + groupBy: [] + jobTimeout: "300" + stateTracking: true + stateUpdateExpression: "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state" + stateMergeExpression: "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState" + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Claude Enterprise Analytics Source. + InputCreateExamplesAquaSecurityHec: + summary: Aqua Security + value: + id: aqua-security-hec-source + type: aqua_security_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Aqua Security Source. InputCreateExamplesAppleUnifiedLogs: summary: Apple Unified Logs value: @@ -68561,6 +73286,15 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Azure Blob Source. + InputCreateExamplesAzureVNetFlowLog: + summary: Azure VNet Flow Log + value: + id: azure-vnet-flow-log-source + type: azure_vnet_flow_log + queueName: vnet-flow-log-queue + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Azure VNet Flow Log Source. InputCreateExamplesCloudflareHec: summary: Cloudflare HEC value: @@ -68572,6 +73306,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Cloudflare HEC Source. + InputCreateExamplesExtrahopRevealx360: + summary: ExtraHop RevealX 360 + value: + id: extrahop-revealx-360-source + type: extrahop_revealx_360 + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a ExtraHop RevealX 360 Source. InputCreateExamplesConfluentCloud: summary: Confluent Cloud value: @@ -68679,6 +73424,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Elasticsearch Source. + InputCreateExamplesF5BigIp: + summary: F5 BIG-IP + value: + id: f5-big-ip-source + type: f5_big_ip + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a F5 BIG-IP Source. InputCreateExamplesEventhub: summary: Event Hubs value: @@ -68744,6 +73500,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Grafana Source. + InputCreateExamplesHashicorpHcpVaultDedicated: + summary: HashiCorp HCP Vault Dedicated + value: + id: hashicorp-hcp-vault-dedicated-source + type: hashicorp_hcp_vault_dedicated + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a HashiCorp HCP Vault Dedicated Source. InputCreateExamplesGooglePubsub: summary: Google Pub/Sub value: @@ -68852,6 +73619,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Metrics Source. + InputCreateExamplesMimecastHec: + summary: Mimecast HEC + value: + id: mimecast-hec-source + type: mimecast_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Mimecast HEC Source. InputCreateExamplesModelDrivenTelemetry: summary: Model Driven Telemetry value: @@ -68898,6 +73676,21 @@ components: pqEnabled: false description: Example request body for creating a Microsoft 365 Management Activity Source. + InputCreateExamplesMicrosoftCopilot: + summary: Microsoft Copilot + value: + id: microsoft-copilot-source + type: microsoft_copilot + tenantId: 00000000-0000-0000-0000-000000000000 + clientId: 00000000-0000-0000-0000-000000000001 + authType: oauthSecret + textSecret: microsoft-copilot-secret + cronSchedule: "*/15 * * * *" + earliest: -7d + latest: now + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Microsoft Copilot Source. InputCreateExamplesMicrosoftGraph: summary: Microsoft Graph value: @@ -68994,6 +73787,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a OpenTelemetry Source. + InputCreateExamplesPingIdentityPingone: + summary: Ping Identity PingOne + value: + id: ping-identity-pingone-source + type: ping_identity_pingone + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Ping Identity PingOne Source. InputCreateExamplesPrometheus: summary: Prometheus Scraper value: @@ -69018,6 +73822,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Prometheus Remote Write Source. + InputCreateExamplesProofpointPod: + summary: Proofpoint on Demand + value: + id: proofpoint-pod-source + type: proofpoint_pod + clusterId: my-pod-cluster + feedType: message + textSecret: proofpoint-pod-token-secret + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Proofpoint on Demand Source. InputCreateExamplesRawUdp: summary: Raw UDP value: @@ -69058,6 +73873,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a S3 Inventory Source. + InputCreateExamplesSailpointHec: + summary: SailPoint + value: + id: sailpoint-hec-source + type: sailpoint_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a SailPoint Source. InputCreateExamplesSecurityLake: summary: Security Lake value: @@ -69217,6 +74043,17 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a TCP JSON Source. + InputCreateExamplesTrendMicroVisionOne: + summary: Trend Micro Vision One + value: + id: trend-micro-vision-one-source + type: trend_micro_vision_one + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Trend Micro Vision One Source. InputCreateExamplesUpwindHec: summary: Upwind value: @@ -69228,6 +74065,28 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Upwind Source. + InputCreateExamplesTrellixHec: + summary: Trellix + value: + id: trellix-hec-source + type: trellix_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Trellix Source. + InputCreateExamplesVectraAiHec: + summary: Vectra AI + value: + id: vectra-ai-hec-source + type: vectra_ai_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for creating a Vectra AI Source. InputCreateExamplesWef: summary: Windows Event Forwarder value: @@ -69299,6 +74158,46 @@ components: sendToRoutes: true pqEnabled: false description: Example request body for creating a Zscaler Cloud NSS Source. + UpdateInputExamplesAkamaiHec: + summary: Akamai HEC + value: + id: akamai-hec-source + type: akamai_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Akamai HEC Source.

The + request body must include a complete representation of the Source that + you want to update. This endpoint does not support partial updates. + UpdateInputExamplesGigamonHec: + summary: Gigamon + value: + id: gigamon-hec-source + type: gigamon_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Gigamon Source.

The + request body must include a complete representation of the Source that + you want to update. This endpoint does not support partial updates. + UpdateInputExamplesBeyondTrustHec: + summary: BeyondTrust + value: + id: beyondtrust-hec-source + type: beyondtrust_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a BeyondTrust + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesAnthropicCompliance: summary: Anthropic Compliance value: @@ -69314,8 +74213,7 @@ components: latest: now jobTimeout: "300" stateTracking: true - stateUpdateExpression: "__timestampExtracted !== false && {latestTime: - (state.latestTime || 0) > _time ? state.latestTime : _time}" + stateUpdateExpression: "__timestampExtracted !== false && {latestTime: (state.latestTime || 0) > _time ? state.latestTime : _time}" stateMergeExpression: "prevState.latestTime > newState.latestTime ? prevState : newState" sendToRoutes: true pqEnabled: false @@ -69323,6 +74221,43 @@ components: Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesAnthropicEnterpriseAnalytics: + summary: Claude Enterprise Analytics + value: + id: anthropic-enterprise-analytics-source + type: anthropic_enterprise_analytics + textSecret: anthropic-api-key-secret + contentConfig: + - contentType: Usage Report + disabled: false + cronSchedule: 0 */4 * * * + earliest: -7d@d + bucketWidth: 1d + groupBy: [] + jobTimeout: "300" + stateTracking: true + stateUpdateExpression: "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state" + stateMergeExpression: "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState" + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Claude Enterprise Analytics + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. + UpdateInputExamplesAquaSecurityHec: + summary: Aqua Security + value: + id: aqua-security-hec-source + type: aqua_security_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Aqua Security + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesAppleUnifiedLogs: summary: Apple Unified Logs value: @@ -69358,6 +74293,18 @@ components: description: Example request body for updating a Azure Blob Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesAzureVNetFlowLog: + summary: Azure VNet Flow Log + value: + id: azure-vnet-flow-log-source + type: azure_vnet_flow_log + queueName: vnet-flow-log-queue + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Azure VNet Flow Log + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesCloudflareHec: summary: Cloudflare HEC value: @@ -69372,6 +74319,20 @@ components: Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesExtrahopRevealx360: + summary: ExtraHop RevealX 360 + value: + id: extrahop-revealx-360-source + type: extrahop_revealx_360 + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a ExtraHop RevealX 360 + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesConfluentCloud: summary: Confluent Cloud value: @@ -69527,6 +74488,19 @@ components: Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesF5BigIp: + summary: F5 BIG-IP + value: + id: f5-big-ip-source + type: f5_big_ip + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a F5 BIG-IP Source.

The + request body must include a complete representation of the Source that + you want to update. This endpoint does not support partial updates. UpdateInputExamplesEventhub: summary: Event Hubs value: @@ -69606,6 +74580,20 @@ components: description: Example request body for updating a Grafana Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesHashicorpHcpVaultDedicated: + summary: HashiCorp HCP Vault Dedicated + value: + id: hashicorp-hcp-vault-dedicated-source + type: hashicorp_hcp_vault_dedicated + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a HashiCorp HCP Vault Dedicated + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesGooglePubsub: summary: Google Pub/Sub value: @@ -69741,6 +74729,20 @@ components: description: Example request body for updating a Metrics Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesMimecastHec: + summary: Mimecast HEC + value: + id: mimecast-hec-source + type: mimecast_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Mimecast HEC + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesModelDrivenTelemetry: summary: Model Driven Telemetry value: @@ -69796,6 +74798,24 @@ components: Activity Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesMicrosoftCopilot: + summary: Microsoft Copilot + value: + id: microsoft-copilot-source + type: microsoft_copilot + tenantId: 00000000-0000-0000-0000-000000000000 + clientId: 00000000-0000-0000-0000-000000000001 + authType: oauthSecret + textSecret: microsoft-copilot-secret + cronSchedule: "*/15 * * * *" + earliest: -7d + latest: now + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Microsoft Copilot + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesMicrosoftGraph: summary: Microsoft Graph value: @@ -69911,6 +74931,20 @@ components: Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesPingIdentityPingone: + summary: Ping Identity PingOne + value: + id: ping-identity-pingone-source + type: ping_identity_pingone + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Ping Identity PingOne + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesPrometheus: summary: Prometheus Scraper value: @@ -69941,6 +74975,20 @@ components: Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesProofpointPod: + summary: Proofpoint on Demand + value: + id: proofpoint-pod-source + type: proofpoint_pod + clusterId: my-pod-cluster + feedType: message + textSecret: proofpoint-pod-token-secret + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Proofpoint on Demand + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesRawUdp: summary: Raw UDP value: @@ -69990,6 +75038,19 @@ components: Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesSailpointHec: + summary: SailPoint + value: + id: sailpoint-hec-source + type: sailpoint_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a SailPoint Source.

The + request body must include a complete representation of the Source that + you want to update. This endpoint does not support partial updates. UpdateInputExamplesSecurityLake: summary: Security Lake value: @@ -70184,6 +75245,20 @@ components: description: Example request body for updating a TCP JSON Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesTrendMicroVisionOne: + summary: Trend Micro Vision One + value: + id: trend-micro-vision-one-source + type: trend_micro_vision_one + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Trend Micro Vision One + Source.

The request body must include a complete representation + of the Source that you want to update. This endpoint does not support + partial updates. UpdateInputExamplesUpwindHec: summary: Upwind value: @@ -70197,6 +75272,32 @@ components: description: Example request body for updating a Upwind Source.

The request body must include a complete representation of the Source that you want to update. This endpoint does not support partial updates. + UpdateInputExamplesTrellixHec: + summary: Trellix + value: + id: trellix-hec-source + type: trellix_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Trellix Source.

The + request body must include a complete representation of the Source that + you want to update. This endpoint does not support partial updates. + UpdateInputExamplesVectraAiHec: + summary: Vectra AI + value: + id: vectra-ai-hec-source + type: vectra_ai_hec + host: 0.0.0.0 + port: 8088 + hecAPI: /services/collector + sendToRoutes: true + pqEnabled: false + description: Example request body for updating a Vectra AI Source.

The + request body must include a complete representation of the Source that + you want to update. This endpoint does not support partial updates. UpdateInputExamplesWef: summary: Windows Event Forwarder value: @@ -70843,6 +75944,14 @@ components: otlpVersion: 1.3.1 tokenSecret: your-token-secret description: Example request body for creating a Dynatrace OTLP Destination. + OutputCreateExamplesTraversalOtlp: + summary: Traversal + value: + id: traversal-output + type: traversal_otlp + endpoint: http://traversal-processor:3000 + protocol: http + description: Example request body for creating a Traversal Destination. OutputCreateExamplesGoogleCloudObservability: summary: Google Cloud Observability value: @@ -70887,12 +75996,29 @@ components: id: wiz-hec-output type: wiz_hec data_center: us1 - wiz_sourcetype: placeholder + wiz_sourcetype: AWS_CLOUDTRAIL wiz_connector_id: 00000000-0000-0000-0000-000000000000 wiz_environment: test authType: manual hecToken: your-hec-token description: Example request body for creating a Wiz Defend Destination. + OutputCreateExamplesWizHecVpcFlowLogs: + summary: Wiz Defend (VPC Flow Logs) + value: + id: wiz-hec-vpc-flow-logs-output + type: wiz_hec + data_center: us1 + wiz_sourcetype: AWS_VPC_FLOW_LOGS + wiz_vpc_event_format: csv_row + wiz_vpc_flow_log_format: ${version} ${account-id} ${interface-id} ${srcaddr} + ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} + ${start} ${end} ${action} ${log-status} + wiz_connector_id: 00000000-0000-0000-0000-000000000000 + wiz_environment: test + authType: manual + hecToken: your-hec-token + description: Example request body for creating a Wiz Defend (VPC Flow Logs) + Destination. OutputCreateExamplesHumioHec: summary: Humio HEC value: @@ -71057,6 +76183,8 @@ components: endpoint: https://storage.googleapis.com stagePath: /tmp/staging collectorInstanceId: 11112222-3333-4444-5555-666677778888 + awsAuthenticationMethod: secret + awsSecret: my-secret-id description: Example request body for creating a Exabeam Destination. OutputCreateExamplesDiskSpool: summary: Disk Spool @@ -71121,7 +76249,7 @@ components: token: your-api-key description: Example request body for creating a Dynatrace HTTP Destination. OutputCreateExamplesDatabricks: - summary: Databricks + summary: Databricks Object Storage value: id: databricks-output type: databricks @@ -71132,7 +76260,20 @@ components: catalog: main schema: external eventsVolumeName: events - description: Example request body for creating a Databricks Destination. + description: Example request body for creating a Databricks Object Storage + Destination. + OutputCreateExamplesDatabricksZerobus: + summary: Databricks Zerobus + value: + id: databricks-zerobus-output + type: databricks_zerobus + workspaceUrl: https://dbc-1234abcd-5e6f.cloud.databricks.com + workspaceId: your-workspace-id + zerobusEndpoint: 1234567890.zerobus.us-west-2.cloud.databricks.com + clientId: your-client-id + clientTextSecret: your-client-secret + tableName: main.external.events + description: Example request body for creating a Databricks Zerobus Destination. OutputCreateExamplesSnowflakeStreaming: summary: Snowflake Streaming value: @@ -71865,6 +77006,17 @@ components: Destination.

The request body must include a complete representation of the Destination that you want to update. This endpoint does not support partial updates. + UpdateOutputExamplesTraversalOtlp: + summary: Traversal + value: + id: traversal-output + type: traversal_otlp + endpoint: http://traversal-processor:3000 + protocol: http + description: Example request body for updating a Traversal + Destination.

The request body must include a complete + representation of the Destination that you want to update. This endpoint + does not support partial updates. UpdateOutputExamplesGoogleCloudObservability: summary: Google Cloud Observability value: @@ -71923,7 +77075,7 @@ components: id: wiz-hec-output type: wiz_hec data_center: us1 - wiz_sourcetype: placeholder + wiz_sourcetype: AWS_CLOUDTRAIL wiz_connector_id: 00000000-0000-0000-0000-000000000000 wiz_environment: test authType: manual @@ -71932,6 +77084,25 @@ components: Destination.

The request body must include a complete representation of the Destination that you want to update. This endpoint does not support partial updates. + UpdateOutputExamplesWizHecVpcFlowLogs: + summary: Wiz Defend (VPC Flow Logs) + value: + id: wiz-hec-vpc-flow-logs-output + type: wiz_hec + data_center: us1 + wiz_sourcetype: AWS_VPC_FLOW_LOGS + wiz_vpc_event_format: csv_row + wiz_vpc_flow_log_format: ${version} ${account-id} ${interface-id} ${srcaddr} + ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} + ${start} ${end} ${action} ${log-status} + wiz_connector_id: 00000000-0000-0000-0000-000000000000 + wiz_environment: test + authType: manual + hecToken: your-hec-token + description: Example request body for updating a Wiz Defend (VPC Flow Logs) + Destination.

The request body must include a complete + representation of the Destination that you want to update. This endpoint + does not support partial updates. UpdateOutputExamplesHumioHec: summary: Humio HEC value: @@ -72124,6 +77295,8 @@ components: endpoint: https://storage.googleapis.com stagePath: /tmp/staging collectorInstanceId: 11112222-3333-4444-5555-666677778888 + awsAuthenticationMethod: secret + awsSecret: my-secret-id description: Example request body for updating a Exabeam Destination.

The request body must include a complete representation of the Destination that you want to update. This endpoint @@ -72211,7 +77384,7 @@ components: representation of the Destination that you want to update. This endpoint does not support partial updates. UpdateOutputExamplesDatabricks: - summary: Databricks + summary: Databricks Object Storage value: id: databricks-output type: databricks @@ -72222,7 +77395,22 @@ components: catalog: main schema: external eventsVolumeName: events - description: Example request body for updating a Databricks + description: Example request body for updating a Databricks Object Storage + Destination.

The request body must include a complete + representation of the Destination that you want to update. This endpoint + does not support partial updates. + UpdateOutputExamplesDatabricksZerobus: + summary: Databricks Zerobus + value: + id: databricks-zerobus-output + type: databricks_zerobus + workspaceUrl: https://dbc-1234abcd-5e6f.cloud.databricks.com + workspaceId: your-workspace-id + zerobusEndpoint: 1234567890.zerobus.us-west-2.cloud.databricks.com + clientId: your-client-id + clientTextSecret: your-client-secret + tableName: main.external.events + description: Example request body for updating a Databricks Zerobus Destination.

The request body must include a complete representation of the Destination that you want to update. This endpoint does not support partial updates. @@ -72326,8 +77514,7 @@ components: streamtags: [] groups: {} asyncFuncTimeout: 1000 - description: "Pipeline that aggregates process metrics: CPU, memory, and bytes - over time windows" + description: "Pipeline that aggregates process metrics: CPU, memory, and bytes over time windows" functions: - id: aggregate_metrics filter: (_metric == 'proc.cpu_perc' || @@ -72722,8 +77909,7 @@ components: - id: grok filter: "true" conf: - pattern: "%{TIMESTAMP_ISO8601:event_time} %{LOGLEVEL:log_level} - %{GREEDYDATA:log_message}" + pattern: "%{TIMESTAMP_ISO8601:event_time} %{LOGLEVEL:log_level} %{GREEDYDATA:log_message}" source: _raw patternList: [] PipelineExamplesGuard: @@ -73328,8 +78514,7 @@ components: streamtags: [] groups: {} asyncFuncTimeout: 1000 - description: "Pipeline that aggregates process metrics: CPU, memory, and bytes - over time windows" + description: "Pipeline that aggregates process metrics: CPU, memory, and bytes over time windows" functions: - id: aggregate_metrics filter: (_metric == 'proc.cpu_perc' || @@ -73759,8 +78944,7 @@ components: - id: grok filter: "true" conf: - pattern: "%{TIMESTAMP_ISO8601:event_time} %{LOGLEVEL:log_level} - %{GREEDYDATA:log_message}" + pattern: "%{TIMESTAMP_ISO8601:event_time} %{LOGLEVEL:log_level} %{GREEDYDATA:log_message}" source: _raw patternList: [] UpdatePipelineExamplesGuard: @@ -74399,11 +79583,7 @@ components: output: default RoutesUpdateExamplesBasicRoute: summary: Update Routes with a basic Route configuration - description: "Example request body for updating the default Routes table - (id: default) with a simple Route that filters access.log - events and sends them to the main Pipeline.

The request body - must include a complete representation of the Routing table that you - want to update. This endpoint does not support partial updates." + description: "Example request body for updating the default Routes table (id: default) with a simple Route that filters access.log events and sends them to the main Pipeline.

The request body must include a complete representation of the Routing table that you want to update. This endpoint does not support partial updates." value: id: default routes: @@ -74415,11 +79595,7 @@ components: final: true RoutesUpdateExamplesMultipleRoutes: summary: Update Routes with multiple Routes and a catch-all - description: "Example request body for updating the default Routes table - (id: default) with multiple specific Routes evaluated in - order, followed by a default catch-all Route.

The request body - must include a complete representation of the Routing table that you - want to update. This endpoint does not support partial updates." + description: "Example request body for updating the default Routes table (id: default) with multiple specific Routes evaluated in order, followed by a default catch-all Route.

The request body must include a complete representation of the Routing table that you want to update. This endpoint does not support partial updates." value: id: default routes: @@ -74453,12 +79629,7 @@ components: final: true RoutesUpdateExamplesRouteWithOutputExpression: summary: Update Routes with dynamic Destination expression - description: "Example request body for updating the default Routes table - (id: default) with a Route that uses a JavaScript - expression to dynamically determine the Destination.

The - request body must include a complete representation of the Routing table - that you want to update. This endpoint does not support partial - updates." + description: "Example request body for updating the default Routes table (id: default) with a Route that uses a JavaScript expression to dynamically determine the Destination.

The request body must include a complete representation of the Routing table that you want to update. This endpoint does not support partial updates." value: id: default routes: @@ -74472,13 +79643,7 @@ components: final: true RoutesUpdateExamplesRouteWithDefaults: summary: Update the basic Route configuration - description: "Example request body for updating the default Routes table - (id: default) with a basic Route that omits the - id and final fields. The server generates a - deterministic id and sets final to - true by default.

The request body must include a - complete representation of the Routing table that you want to update. - This endpoint does not support partial updates." + description: "Example request body for updating the default Routes table (id: default) with a basic Route that omits the id and final fields. The server generates a deterministic id and sets final to true by default.

The request body must include a complete representation of the Routing table that you want to update. This endpoint does not support partial updates." value: id: default routes: @@ -74488,8 +79653,7 @@ components: description: Route access logs to main Pipeline RoutesAppendExamplesSingleRoute: summary: Append a single Route to the Routing table - description: "Example request body for appending a single Route to the end of - the default Routing table (id: default)." + description: "Example request body for appending a single Route to the end of the default Routing table (id: default)." value: - id: route-new name: new-route @@ -74499,9 +79663,7 @@ components: final: true RoutesAppendExamplesMultipleRoutes: summary: Append multiple Routes to the Routing table - description: "Example request body for appending multiple Routes to the end of - the default Routing table (id: default) in a single - request." + description: "Example request body for appending multiple Routes to the end of the default Routing table (id: default) in a single request." value: - id: route-audit name: audit @@ -74519,9 +79681,7 @@ components: final: false RoutesAppendExamplesRouteWithOutputExpression: summary: Append a Route with dynamic Destination expression - description: "Example request body for appending a Route to the end of the - default Routing table (id: default) that uses a JavaScript - expression to dynamically determine the Destination at Route startup." + description: "Example request body for appending a Route to the end of the default Routing table (id: default) that uses a JavaScript expression to dynamically determine the Destination at Route startup." value: - id: route-dynamic-append name: dynamic-append @@ -74533,11 +79693,7 @@ components: final: true RoutesAppendExamplesRouteWithDefaults: summary: Append a Route omitting optional id and final fields - description: "Example request body for adding a Route to the end of the default - Routes table (id: default) omitting the id and - final fields. The server generates a deterministic - id and sets final to true by - default." + description: "Example request body for adding a Route to the end of the default Routes table (id: default) omitting the id and final fields. The server generates a deterministic id and sets final to true by default." value: - name: new-route pipeline: main @@ -74759,8 +79915,7 @@ components: containerName: "'data-container'" pattern: "'*.json'" authType: manual - connectionString: "'DefaultEndpointsProtocol=https;AccountName=mystorageaccount\ - ;AccountKey=...'" + connectionString: "'DefaultEndpointsProtocol=https;AccountName=mystorageaccount;AccountKey=...'" pipelines: - data-pipeline destinations: @@ -74790,8 +79945,7 @@ components: bucket: "'my-gcs-bucket'" path: "'data/'" authType: manual - serviceAccountCredentials: "'{ \"type\": \"service_account\", \"project_id\": - \"my-project\", \"private_key_id\": \"key123\" }'" + serviceAccountCredentials: "'{ \"type\": \"service_account\", \"project_id\": \"my-project\", \"private_key_id\": \"key123\" }'" pipelines: - csv-processing destinations: @@ -75105,8 +80259,7 @@ components: containerName: "'data-container'" pattern: "'*.json'" authType: manual - connectionString: "'DefaultEndpointsProtocol=https;AccountName=mystorageaccount\ - ;AccountKey=...'" + connectionString: "'DefaultEndpointsProtocol=https;AccountName=mystorageaccount;AccountKey=...'" pipelines: - data-pipeline destinations: @@ -75138,8 +80291,7 @@ components: bucket: "'my-gcs-bucket'" path: "'data/'" authType: manual - serviceAccountCredentials: "'{ \"type\": \"service_account\", \"project_id\": - \"my-project\", \"private_key_id\": \"key123\" }'" + serviceAccountCredentials: "'{ \"type\": \"service_account\", \"project_id\": \"my-project\", \"private_key_id\": \"key123\" }'" pipelines: - csv-processing destinations: @@ -75273,6 +80425,34 @@ components: - lake-data-processing destinations: - analytics-platform + AclGetUsersResponseGroupExamplesSuccess: + summary: List user ACL for a Group + description: Example response for listing the user access control list (ACL) for + a Group.

The response includes only users with explicit access + assignments on the Group, not access granted through Team membership or + inheritance. + value: + count: 1 + items: + - user: user1@example.com + perms: + - type: groups + gid: group1 + policy: GroupRead + AclGetTeamsResponseGroupExamplesSuccess: + summary: List Team ACL for a Group + description: Example response for listing the Team access control list (ACL) for + a Group.

The response includes only Teams with explicit access + assignments on the Group, not access granted individually to Team + Members or through inheritance. + value: + count: 1 + items: + - team: engineering-team + perms: + - type: groups + gid: group1 + policy: GroupRead CreateGroupExamplesCloudWg: summary: Create a Worker Group in Cribl.Cloud description: Example request body for creating a Worker Group on Cribl.Cloud @@ -75534,6 +80714,22 @@ components: incompatibleWorkerCount: 0 deployingWorkerCount: 0 lookupDeployments: [] + LakeDatasetUpdateExamplesUpdateRetention: + summary: Update the retention period for a Lake Dataset + description: Example request body for updating the retention period for an + existing Lake Dataset. + value: + retentionPeriodInDays: 180 + LakeDatasetUpdateExamplesUpdateDescription: + summary: Update description and accelerated fields for a Lake Dataset + description: Example request body for updating the description and accelerated + fields for an existing Lake Dataset. + value: + description: Web server access logs with accelerated fields. + acceleratedFields: + - host + - status + - source LakeDatasetCreateExamplesJsonDataset: summary: Create a Lake Dataset in JSON format description: Example request body for creating a Lake Dataset in JSON format @@ -75567,22 +80763,30 @@ components: required body parameters. value: id: app_logs - LakeDatasetUpdateExamplesUpdateRetention: - summary: Update the retention period for a Lake Dataset - description: Example request body for updating the retention period for an - existing Lake Dataset. - value: - retentionPeriodInDays: 180 - LakeDatasetUpdateExamplesUpdateDescription: - summary: Update description and accelerated fields for a Lake Dataset - description: Example request body for updating the description and accelerated - fields for an existing Lake Dataset. + LakeDatasetCreateExamplesBulkCreateDatasets: + summary: Bulk create Lake Datasets + description: "Example request body for creating multiple new Lake Datasets in a single request.

Send an array of objects — one per Lake Dataset to create, using the same fields as a single-item create (this example shows one such element). The response is { items, errors }: items contains the created Lake Datasets, and errors contains { id, reason } entries for any Lake Datasets that failed validation." value: - description: Web server access logs with accelerated fields. + id: web_access_logs + description: Web server access logs + storageLocationId: my-storage-location + format: json + retentionPeriodInDays: 90 acceleratedFields: - host - status - - source + LoginResponseExamplesLocalLogin: + summary: Successful login response + description: Example response for a successful login with local credentials. + value: + token: 1234abcd5678efgh9101ijklEXAMPLETOKEN + forcePasswordChange: false + LoginExamplesLocalLogin: + summary: Log in with local credentials + description: Example request body for logging in with a local username and password. + value: + username: yourUsername + password: yourPassword CaptureNdjsonResponseExamplesCapturedEvent: summary: Return one captured event description: Example response for streaming one captured event as an NDJSON line @@ -75784,8 +80988,8 @@ components: overlay: state: inactive PackInstallResponseExamplesInstalledFromURL: - summary: Pack installed from URL response - description: Example response for a Pack successfully installed from a URL. + summary: Return a Pack installed from a URL + description: Example response for returning a Pack successfully installed from a URL. value: items: - id: cribl-palo-alto-networks @@ -75842,16 +81046,16 @@ components: source: git+https://github.com/criblio/cribl_ocsf_postprocessing allowCustomFunctions: false PackDeleteResponseExamplesUninstalled: - summary: Pack uninstalled response - description: Example response after successfully uninstalling a Pack. + summary: Return an uninstalled Pack + description: Example response for returning a successfully uninstalled Pack. value: items: - id: cribl-palo-alto-networks source: https://github.com/criblpacks/cribl-palo-alto-networks/releases/download/1.1.4/cribl-palo-alto-networks-a3e5a19d-1.1.4.crbl count: 1 PackGetResponseExamplesInstalledPack: - summary: Installed Pack response - description: Example response for getting a Pack installed from a Git repository. + summary: Return an installed Pack + description: Example response for returning a Pack installed from a Git repository. value: items: - id: cribl-palo-alto-networks @@ -75865,8 +81069,8 @@ components: - inputs count: 1 PackGetResponseExamplesEmptyPack: - summary: Empty Pack response - description: Example response for getting an empty Pack. + summary: Return an empty Pack + description: Example response for returning an empty Pack. value: items: - id: testPackFoo @@ -75902,8 +81106,8 @@ components: offset: 0 limit: 20 PackUpgradeResponseExamplesUpgraded: - summary: Pack upgraded response - description: Example response for upgrading a Pack to a newer version. + summary: Return an upgraded Pack + description: Example response for returning a Pack upgraded to a newer version. value: items: - id: cribl-palo-alto-networks @@ -75923,9 +81127,9 @@ components: value: source: https://github.com/criblpacks/cribl-palo-alto-networks/releases/download/1.1.4/cribl-palo-alto-networks-a3e5a19d-1.1.4.crbl PackUploadResponseExamplesUploadedPack: - summary: Pack file uploaded response - description: Example response after successfully uploading a Pack file. Use the - returned source value in a subsequent POST + summary: Return a Pack upload result + description: Example response for returning a successful Pack upload result. Use + the returned source value in a subsequent POST /packs request to install the Pack. value: source: cribl-palo-alto-networks-1.1.4.AbCdEfGh.crbl @@ -75940,8 +81144,9 @@ components: disabled: false ssl: disabled: false - privKeyPath: /opt/cribl/local/cribl/auth/cribl.key - certPath: /opt/cribl/local/cribl/auth/cribl.crt + certificateName: myApiCert + privKeyPath: /opt/cribl/local/cribl/auth/myApiCert.key + certPath: /opt/cribl/local/cribl/auth/myApiCert.crt passphrase: "" system: upgrade: api @@ -75981,8 +81186,9 @@ components: disabled: false ssl: disabled: false - privKeyPath: /opt/cribl/local/cribl/auth/cribl.key - certPath: /opt/cribl/local/cribl/auth/cribl.crt + certificateName: myApiCert + privKeyPath: /opt/cribl/local/cribl/auth/myApiCert.key + certPath: /opt/cribl/local/cribl/auth/myApiCert.crt passphrase: "" system: upgrade: api @@ -76021,8 +81227,9 @@ components: disabled: false ssl: disabled: false - privKeyPath: /opt/cribl/local/cribl/auth/cribl.key - certPath: /opt/cribl/local/cribl/auth/cribl.crt + certificateName: myApiCert + privKeyPath: /opt/cribl/local/cribl/auth/myApiCert.key + certPath: /opt/cribl/local/cribl/auth/myApiCert.crt passphrase: "" system: upgrade: api @@ -76282,51 +81489,93 @@ tags: - name: databaseConnections description: Actions related to DatabaseConnections x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single - name: destinations description: Actions related to Destinations x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single - name: distributed description: Actions related to Distributed x-cribl-availability: both + x-cribl-api-context: + - leader - name: functions description: Actions related to functions x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single - name: groups description: Actions related to Groups x-cribl-availability: both + x-cribl-api-context: + - leader - name: health description: Actions related to REST server health x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single - name: lake description: Actions related to Lake x-cribl-availability: cloud + x-cribl-api-context: + - leader - name: packs description: Actions related to Packs x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single - name: pipelines description: Actions related to Pipelines x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single - name: preview description: Actions related to data preview x-cribl-availability: both - name: routes description: Actions related to Routes x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single - name: sources description: Actions related to Sources x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single - name: system description: Actions related to system settings x-cribl-availability: both - name: teams description: Actions related to Teams x-cribl-availability: both + x-cribl-api-context: + - leader - name: versioning description: Actions related to Versioning x-cribl-availability: both - name: workers description: Actions related to Workers x-cribl-availability: both + x-cribl-api-context: + - leader paths: /auth/login: post: @@ -76337,6 +81586,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Log in and fetch an authentication token description: This endpoint is unavailable on Cribl.Cloud. Instead, follow the instructions at https://docs.cribl.io/stream/api-tutorials/#criblcloud @@ -76349,6 +81602,9 @@ paths: application/json: schema: $ref: "#/components/schemas/AuthToken" + examples: + LoginResponseExamplesLocalLogin: + $ref: "#/components/examples/LoginResponseExamplesLocalLogin" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -76387,6 +81643,9 @@ paths: application/json: schema: $ref: "#/components/schemas/LoginInfo" + examples: + LoginExamplesLocalLogin: + $ref: "#/components/examples/LoginExamplesLocalLogin" /functions: get: operationId: getFunctions @@ -76396,6 +81655,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: List all Functions description: Get a list of all Functions. responses: @@ -76471,6 +81734,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Get a Function description: Get the specified Function. responses: @@ -76522,6 +81789,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Get the health status of the server description: Get the current health status of the server (Leader or Worker Node). In Distributed deployments, requests routed to a Worker or Edge @@ -76569,6 +81840,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: List all Database Connections description: Get a list of all Database Connections. responses: @@ -76581,8 +81856,7 @@ paths: $ref: "#/components/schemas/DatabaseConnectionResponseEnvelope" examples: DatabaseConnectionListResponseExamplesDatabaseConnectionList: - $ref: "#/components/examples/DatabaseConnectionListResponseExamplesDatabaseConn\ - ectionList" + $ref: "#/components/examples/DatabaseConnectionListResponseExamplesDatabaseConnectionList" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -76647,6 +81921,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Create a Database Connection description: Create a new Database Connection. responses: @@ -76659,8 +81937,7 @@ paths: $ref: "#/components/schemas/DatabaseConnectionResponseEnvelope" examples: DatabaseConnectionResponseExamplesMySQLDatabaseConnection: - $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseCon\ - nection" + $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseConnection" "400": description: Failed validation or malformed input, such as missing or invalid parameters. @@ -76670,8 +81947,7 @@ paths: $ref: "#/components/schemas/RestApiJsonError" examples: DatabaseConnectionBadRequestResponseExamplesInvalidDatabaseConnectionRequest: - $ref: "#/components/examples/DatabaseConnectionBadRequestResponseExamplesInvali\ - dDatabaseConnectionRequest" + $ref: "#/components/examples/DatabaseConnectionBadRequestResponseExamplesInvalidDatabaseConnectionRequest" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -76702,31 +81978,25 @@ paths: $ref: "#/components/schemas/DatabaseConnectionConfig" examples: DatabaseConnectionExamplesMySQLWithConnectionString: - $ref: "#/components/examples/DatabaseConnectionExamplesMySQLWithConnectionStrin\ - g" + $ref: "#/components/examples/DatabaseConnectionExamplesMySQLWithConnectionString" DatabaseConnectionExamplesMySQLWithSecret: $ref: "#/components/examples/DatabaseConnectionExamplesMySQLWithSecret" DatabaseConnectionExamplesPostgreSQLWithConnectionString: - $ref: "#/components/examples/DatabaseConnectionExamplesPostgreSQLWithConnection\ - String" + $ref: "#/components/examples/DatabaseConnectionExamplesPostgreSQLWithConnectionString" DatabaseConnectionExamplesPostgreSQLWithSecret: $ref: "#/components/examples/DatabaseConnectionExamplesPostgreSQLWithSecret" DatabaseConnectionExamplesSQLServerWithConnectionString: - $ref: "#/components/examples/DatabaseConnectionExamplesSQLServerWithConnectionS\ - tring" + $ref: "#/components/examples/DatabaseConnectionExamplesSQLServerWithConnectionString" DatabaseConnectionExamplesSQLServerWithSecret: $ref: "#/components/examples/DatabaseConnectionExamplesSQLServerWithSecret" DatabaseConnectionExamplesSQLServerWithConfigObject: - $ref: "#/components/examples/DatabaseConnectionExamplesSQLServerWithConfigObjec\ - t" + $ref: "#/components/examples/DatabaseConnectionExamplesSQLServerWithConfigObject" DatabaseConnectionExamplesOracleWithConnectionString: - $ref: "#/components/examples/DatabaseConnectionExamplesOracleWithConnectionStri\ - ng" + $ref: "#/components/examples/DatabaseConnectionExamplesOracleWithConnectionString" DatabaseConnectionExamplesOracleWithSecret: $ref: "#/components/examples/DatabaseConnectionExamplesOracleWithSecret" DatabaseConnectionExamplesOracleWithCredentialsSecrets: - $ref: "#/components/examples/DatabaseConnectionExamplesOracleWithCredentialsSec\ - rets" + $ref: "#/components/examples/DatabaseConnectionExamplesOracleWithCredentialsSecrets" DatabaseConnectionExamplesOracleWithMutualTLS: $ref: "#/components/examples/DatabaseConnectionExamplesOracleWithMutualTLS" /lib/database-connections/{id}: @@ -76738,6 +82008,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Get a Database Connection description: Get the specified Database Connection. responses: @@ -76750,8 +82024,7 @@ paths: $ref: "#/components/schemas/DatabaseConnectionResponseEnvelope" examples: DatabaseConnectionResponseExamplesMySQLDatabaseConnection: - $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseCon\ - nection" + $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseConnection" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -76776,8 +82049,7 @@ paths: $ref: "#/components/schemas/RestApiJsonError" examples: DatabaseConnectionNotFoundResponseExamplesDatabaseConnectionNotFound: - $ref: "#/components/examples/DatabaseConnectionNotFoundResponseExamplesDatabase\ - ConnectionNotFound" + $ref: "#/components/examples/DatabaseConnectionNotFoundResponseExamplesDatabaseConnectionNotFound" "500": description: Unexpected server error. content: @@ -76799,6 +82071,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Update a Database Connection description: Update the specified Database Connection.

Provide a complete representation of the Database Connection that you want to @@ -76818,8 +82094,7 @@ paths: $ref: "#/components/schemas/DatabaseConnectionResponseEnvelope" examples: DatabaseConnectionResponseExamplesMySQLDatabaseConnection: - $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseCon\ - nection" + $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseConnection" "400": description: Failed validation or malformed input, such as missing or invalid parameters. @@ -76829,8 +82104,7 @@ paths: $ref: "#/components/schemas/RestApiJsonError" examples: DatabaseConnectionBadRequestResponseExamplesInvalidDatabaseConnectionRequest: - $ref: "#/components/examples/DatabaseConnectionBadRequestResponseExamplesInvali\ - dDatabaseConnectionRequest" + $ref: "#/components/examples/DatabaseConnectionBadRequestResponseExamplesInvalidDatabaseConnectionRequest" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -76854,8 +82128,7 @@ paths: $ref: "#/components/schemas/RestApiJsonError" examples: DatabaseConnectionNotFoundResponseExamplesDatabaseConnectionNotFound: - $ref: "#/components/examples/DatabaseConnectionNotFoundResponseExamplesDatabase\ - ConnectionNotFound" + $ref: "#/components/examples/DatabaseConnectionNotFoundResponseExamplesDatabaseConnectionNotFound" "500": description: Unexpected server error. content: @@ -76871,35 +82144,25 @@ paths: $ref: "#/components/schemas/DatabaseConnectionConfig" examples: UpdateDatabaseConnectionExamplesUpdateMySQLDatabaseConnectionWithConnectionString: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateMySQLDatabas\ - eConnectionWithConnectionString" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateMySQLDatabaseConnectionWithConnectionString" UpdateDatabaseConnectionExamplesUpdateMySQLDatabaseConnectionWithSecret: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateMySQLDatabas\ - eConnectionWithSecret" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateMySQLDatabaseConnectionWithSecret" UpdateDatabaseConnectionExamplesUpdatePostgreSQLDatabaseConnectionWithConnectionString: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdatePostgreSQLDa\ - tabaseConnectionWithConnectionString" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdatePostgreSQLDatabaseConnectionWithConnectionString" UpdateDatabaseConnectionExamplesUpdatePostgreSQLDatabaseConnectionWithSecret: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdatePostgreSQLDa\ - tabaseConnectionWithSecret" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdatePostgreSQLDatabaseConnectionWithSecret" UpdateDatabaseConnectionExamplesUpdateSQLServerDatabaseConnectionWithConnectionString: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateSQLServerDat\ - abaseConnectionWithConnectionString" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateSQLServerDatabaseConnectionWithConnectionString" UpdateDatabaseConnectionExamplesUpdateSQLServerDatabaseConnectionWithSecret: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateSQLServerDat\ - abaseConnectionWithSecret" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateSQLServerDatabaseConnectionWithSecret" UpdateDatabaseConnectionExamplesUpdateSQLServerDatabaseConnectionWithConfigObject: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateSQLServerDat\ - abaseConnectionWithConfigObject" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateSQLServerDatabaseConnectionWithConfigObject" UpdateDatabaseConnectionExamplesUpdateOracleDatabaseConnectionWithConnectionString: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateOracleDataba\ - seConnectionWithConnectionString" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateOracleDatabaseConnectionWithConnectionString" UpdateDatabaseConnectionExamplesUpdateOracleDatabaseConnectionWithSecret: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateOracleDataba\ - seConnectionWithSecret" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateOracleDatabaseConnectionWithSecret" UpdateDatabaseConnectionExamplesUpdateOracleDatabaseConnectionWithCredentialsSecrets: - $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateOracleDataba\ - seConnectionWithCredentialsSecrets" + $ref: "#/components/examples/UpdateDatabaseConnectionExamplesUpdateOracleDatabaseConnectionWithCredentialsSecrets" parameters: - name: id in: path @@ -76915,6 +82178,10 @@ paths: x-speakeasy-name-override: delete x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Delete a Database Connection description: Delete the specified Database Connection. responses: @@ -76927,8 +82194,7 @@ paths: $ref: "#/components/schemas/DatabaseConnectionResponseEnvelope" examples: DatabaseConnectionResponseExamplesMySQLDatabaseConnection: - $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseCon\ - nection" + $ref: "#/components/examples/DatabaseConnectionResponseExamplesMySQLDatabaseConnection" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -76952,8 +82218,7 @@ paths: $ref: "#/components/schemas/RestApiJsonError" examples: DatabaseConnectionNotFoundResponseExamplesDatabaseConnectionNotFound: - $ref: "#/components/examples/DatabaseConnectionNotFoundResponseExamplesDatabase\ - ConnectionNotFound" + $ref: "#/components/examples/DatabaseConnectionNotFoundResponseExamplesDatabaseConnectionNotFound" "409": description: Request conflicts with current resource state — Database Connection is referenced by another entity. @@ -76979,6 +82244,9 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - node + - single summary: List all Collectors description: Get a list of all Collectors. responses: @@ -77053,6 +82321,9 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - node + - single summary: Create a Collector description: Create a new Collector. responses: @@ -77122,6 +82393,9 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - node + - single summary: Get a Collector description: Get the specified Collector. responses: @@ -77171,6 +82445,9 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - node + - single summary: Update a Collector description: Update the specified Collector.

Provide a complete representation of the Collector that you want to update in the request @@ -77252,6 +82529,9 @@ paths: x-speakeasy-name-override: delete x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - node + - single summary: Delete a Collector description: Delete the specified Collector. responses: @@ -77302,6 +82582,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: List all Pipelines within a Pack description: Get a list of all Pipelines within the specified Pack. responses: @@ -77343,15 +82627,17 @@ paths: required: false schema: type: integer - minimum: 0 - description: Pagination offset + description: Starting point from which to retrieve results for this request. Use + with limit to paginate the response into manageable + batches. - name: limit in: query required: false schema: type: integer - minimum: 0 - description: Maximum number of items to return + description: Maximum number of Pipelines to return in the response for this + request. Use with offset to paginate the response into + manageable batches. - name: pack in: path required: true @@ -77377,6 +82663,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Create a Pipeline within a Pack description: Create a new Pipeline within the specified Pack. responses: @@ -77519,6 +82809,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Get a Pipeline within a Pack description: Get the specified Pipeline within the specified Pack. responses: @@ -77575,6 +82869,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Update a Pipeline within a Pack description: Update the specified Pipeline within the specified Pack.

Provide a complete representation of the Pipeline that @@ -77729,6 +83027,10 @@ paths: x-speakeasy-name-override: delete x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Delete a Pipeline within a Pack description: Delete the specified Pipeline within the specified Pack. responses: @@ -77786,6 +83088,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: List all Routes within a Pack description: Get a list of all Routes within the specified Pack. responses: @@ -77794,7 +83100,7 @@ paths: content: application/json: schema: - $ref: "#/components/schemas/CountedRoutes" + $ref: "#/components/schemas/PaginatedRoutes" examples: RoutesResponseExamplesDefaultRoutingTable: $ref: "#/components/examples/RoutesResponseExamplesDefaultRoutingTable" @@ -77822,12 +83128,37 @@ paths: schema: $ref: "#/components/schemas/Error" parameters: + - name: offset + in: query + required: false + schema: + type: integer + minimum: 0 + description: Pagination offset + - name: limit + in: query + required: false + schema: + type: integer + minimum: 0 + description: Maximum number of items to return - name: pack in: path required: true schema: type: string description: The id of the Pack. + x-speakeasy-pagination: + type: offsetLimit + inputs: + - name: offset + in: parameters + type: offset + - name: limit + in: parameters + type: limit + outputs: + results: $.items /p/{pack}/routes/{id}: get: operationId: getRoutesByPackAndId @@ -77837,6 +83168,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get a Routing table within a Pack description: Get the specified Routing table within the specified Pack. responses: @@ -77897,6 +83232,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Update a Routing table within a Pack description: Update the specified Routing table within the specified Pack.

Provide a complete representation of the Routing table @@ -77985,6 +83324,10 @@ paths: x-speakeasy-name-override: append x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Add a Route to the end of the Routing table within a Pack description: Add a Route to the end of the specified Routing table within the specified Pack. @@ -78059,10 +83402,13 @@ paths: description: The id of the Pack. /p/{pack}/system/inputs: get: - operationId: getInputSystemByPack x-speakeasy-group: packs.sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: list tags: - sources @@ -78105,6 +83451,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: getInputSystemByPack parameters: - name: type in: query @@ -78146,10 +83493,13 @@ paths: outputs: results: $.items post: - operationId: createInputSystemByPack x-speakeasy-group: packs.sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: create tags: - sources @@ -78169,16 +83519,30 @@ paths: required: - id examples: + InputCreateExamplesAkamaiHec: + $ref: "#/components/examples/InputCreateExamplesAkamaiHec" + InputCreateExamplesGigamonHec: + $ref: "#/components/examples/InputCreateExamplesGigamonHec" + InputCreateExamplesBeyondTrustHec: + $ref: "#/components/examples/InputCreateExamplesBeyondTrustHec" InputCreateExamplesAnthropicCompliance: $ref: "#/components/examples/InputCreateExamplesAnthropicCompliance" + InputCreateExamplesAnthropicEnterpriseAnalytics: + $ref: "#/components/examples/InputCreateExamplesAnthropicEnterpriseAnalytics" + InputCreateExamplesAquaSecurityHec: + $ref: "#/components/examples/InputCreateExamplesAquaSecurityHec" InputCreateExamplesAppleUnifiedLogs: $ref: "#/components/examples/InputCreateExamplesAppleUnifiedLogs" InputCreateExamplesAppscope: $ref: "#/components/examples/InputCreateExamplesAppscope" InputCreateExamplesAzureBlob: $ref: "#/components/examples/InputCreateExamplesAzureBlob" + InputCreateExamplesAzureVNetFlowLog: + $ref: "#/components/examples/InputCreateExamplesAzureVNetFlowLog" InputCreateExamplesCloudflareHec: $ref: "#/components/examples/InputCreateExamplesCloudflareHec" + InputCreateExamplesExtrahopRevealx360: + $ref: "#/components/examples/InputCreateExamplesExtrahopRevealx360" InputCreateExamplesConfluentCloud: $ref: "#/components/examples/InputCreateExamplesConfluentCloud" InputCreateExamplesCollection: @@ -78199,6 +83563,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesEdgePrometheus" InputCreateExamplesElastic: $ref: "#/components/examples/InputCreateExamplesElastic" + InputCreateExamplesF5BigIp: + $ref: "#/components/examples/InputCreateExamplesF5BigIp" InputCreateExamplesEventhub: $ref: "#/components/examples/InputCreateExamplesEventhub" InputCreateExamplesEventhubAmqp: @@ -78211,6 +83577,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesFirehose" InputCreateExamplesGrafana: $ref: "#/components/examples/InputCreateExamplesGrafana" + InputCreateExamplesHashicorpHcpVaultDedicated: + $ref: "#/components/examples/InputCreateExamplesHashicorpHcpVaultDedicated" InputCreateExamplesGooglePubsub: $ref: "#/components/examples/InputCreateExamplesGooglePubsub" InputCreateExamplesHttp: @@ -78233,6 +83601,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesLoki" InputCreateExamplesMetrics: $ref: "#/components/examples/InputCreateExamplesMetrics" + InputCreateExamplesMimecastHec: + $ref: "#/components/examples/InputCreateExamplesMimecastHec" InputCreateExamplesModelDrivenTelemetry: $ref: "#/components/examples/InputCreateExamplesModelDrivenTelemetry" InputCreateExamplesMsk: @@ -78241,6 +83611,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesNetflow" InputCreateExamplesOffice365Mgmt: $ref: "#/components/examples/InputCreateExamplesOffice365Mgmt" + InputCreateExamplesMicrosoftCopilot: + $ref: "#/components/examples/InputCreateExamplesMicrosoftCopilot" InputCreateExamplesMicrosoftGraph: $ref: "#/components/examples/InputCreateExamplesMicrosoftGraph" InputCreateExamplesOffice365MsgTrace: @@ -78255,10 +83627,14 @@ paths: $ref: "#/components/examples/InputCreateExamplesOpenAIComplianceLogs" InputCreateExamplesOpenTelemetry: $ref: "#/components/examples/InputCreateExamplesOpenTelemetry" + InputCreateExamplesPingIdentityPingone: + $ref: "#/components/examples/InputCreateExamplesPingIdentityPingone" InputCreateExamplesPrometheus: $ref: "#/components/examples/InputCreateExamplesPrometheus" InputCreateExamplesPrometheusRw: $ref: "#/components/examples/InputCreateExamplesPrometheusRw" + InputCreateExamplesProofpointPod: + $ref: "#/components/examples/InputCreateExamplesProofpointPod" InputCreateExamplesRawUdp: $ref: "#/components/examples/InputCreateExamplesRawUdp" InputCreateExamplesBedrockS3: @@ -78267,6 +83643,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesS3" InputCreateExamplesS3Inventory: $ref: "#/components/examples/InputCreateExamplesS3Inventory" + InputCreateExamplesSailpointHec: + $ref: "#/components/examples/InputCreateExamplesSailpointHec" InputCreateExamplesSecurityLake: $ref: "#/components/examples/InputCreateExamplesSecurityLake" InputCreateExamplesServiceNowTable: @@ -78295,8 +83673,14 @@ paths: $ref: "#/components/examples/InputCreateExamplesTcp" InputCreateExamplesTcpjson: $ref: "#/components/examples/InputCreateExamplesTcpjson" + InputCreateExamplesTrendMicroVisionOne: + $ref: "#/components/examples/InputCreateExamplesTrendMicroVisionOne" InputCreateExamplesUpwindHec: $ref: "#/components/examples/InputCreateExamplesUpwindHec" + InputCreateExamplesTrellixHec: + $ref: "#/components/examples/InputCreateExamplesTrellixHec" + InputCreateExamplesVectraAiHec: + $ref: "#/components/examples/InputCreateExamplesVectraAiHec" InputCreateExamplesWef: $ref: "#/components/examples/InputCreateExamplesWef" InputCreateExamplesWinEventLogs: @@ -78349,6 +83733,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: createInputSystemByPack parameters: - name: pack in: path @@ -78358,10 +83743,13 @@ paths: description: The id of the Pack. /p/{pack}/system/inputs/{id}: get: - operationId: getInputSystemByPackAndId x-speakeasy-group: packs.sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: get tags: - sources @@ -78406,6 +83794,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: getInputSystemByPackAndId parameters: - name: id in: path @@ -78420,10 +83809,13 @@ paths: type: string description: The id of the Pack. patch: - operationId: updateInputSystemByPackAndId x-speakeasy-group: packs.sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: update tags: - sources @@ -78446,16 +83838,30 @@ paths: schema: $ref: "#/components/schemas/Input" examples: + UpdateInputExamplesAkamaiHec: + $ref: "#/components/examples/UpdateInputExamplesAkamaiHec" + UpdateInputExamplesGigamonHec: + $ref: "#/components/examples/UpdateInputExamplesGigamonHec" + UpdateInputExamplesBeyondTrustHec: + $ref: "#/components/examples/UpdateInputExamplesBeyondTrustHec" UpdateInputExamplesAnthropicCompliance: $ref: "#/components/examples/UpdateInputExamplesAnthropicCompliance" + UpdateInputExamplesAnthropicEnterpriseAnalytics: + $ref: "#/components/examples/UpdateInputExamplesAnthropicEnterpriseAnalytics" + UpdateInputExamplesAquaSecurityHec: + $ref: "#/components/examples/UpdateInputExamplesAquaSecurityHec" UpdateInputExamplesAppleUnifiedLogs: $ref: "#/components/examples/UpdateInputExamplesAppleUnifiedLogs" UpdateInputExamplesAppscope: $ref: "#/components/examples/UpdateInputExamplesAppscope" UpdateInputExamplesAzureBlob: $ref: "#/components/examples/UpdateInputExamplesAzureBlob" + UpdateInputExamplesAzureVNetFlowLog: + $ref: "#/components/examples/UpdateInputExamplesAzureVNetFlowLog" UpdateInputExamplesCloudflareHec: $ref: "#/components/examples/UpdateInputExamplesCloudflareHec" + UpdateInputExamplesExtrahopRevealx360: + $ref: "#/components/examples/UpdateInputExamplesExtrahopRevealx360" UpdateInputExamplesConfluentCloud: $ref: "#/components/examples/UpdateInputExamplesConfluentCloud" UpdateInputExamplesCollection: @@ -78480,6 +83886,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesEdgePrometheus" UpdateInputExamplesElastic: $ref: "#/components/examples/UpdateInputExamplesElastic" + UpdateInputExamplesF5BigIp: + $ref: "#/components/examples/UpdateInputExamplesF5BigIp" UpdateInputExamplesEventhub: $ref: "#/components/examples/UpdateInputExamplesEventhub" UpdateInputExamplesEventhubAmqp: @@ -78492,6 +83900,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesFirehose" UpdateInputExamplesGrafana: $ref: "#/components/examples/UpdateInputExamplesGrafana" + UpdateInputExamplesHashicorpHcpVaultDedicated: + $ref: "#/components/examples/UpdateInputExamplesHashicorpHcpVaultDedicated" UpdateInputExamplesGooglePubsub: $ref: "#/components/examples/UpdateInputExamplesGooglePubsub" UpdateInputExamplesHttp: @@ -78514,6 +83924,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesLoki" UpdateInputExamplesMetrics: $ref: "#/components/examples/UpdateInputExamplesMetrics" + UpdateInputExamplesMimecastHec: + $ref: "#/components/examples/UpdateInputExamplesMimecastHec" UpdateInputExamplesModelDrivenTelemetry: $ref: "#/components/examples/UpdateInputExamplesModelDrivenTelemetry" UpdateInputExamplesMsk: @@ -78522,6 +83934,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesNetflow" UpdateInputExamplesOffice365Mgmt: $ref: "#/components/examples/UpdateInputExamplesOffice365Mgmt" + UpdateInputExamplesMicrosoftCopilot: + $ref: "#/components/examples/UpdateInputExamplesMicrosoftCopilot" UpdateInputExamplesMicrosoftGraph: $ref: "#/components/examples/UpdateInputExamplesMicrosoftGraph" UpdateInputExamplesOffice365MsgTrace: @@ -78536,10 +83950,14 @@ paths: $ref: "#/components/examples/UpdateInputExamplesOpenAIComplianceLogs" UpdateInputExamplesOpenTelemetry: $ref: "#/components/examples/UpdateInputExamplesOpenTelemetry" + UpdateInputExamplesPingIdentityPingone: + $ref: "#/components/examples/UpdateInputExamplesPingIdentityPingone" UpdateInputExamplesPrometheus: $ref: "#/components/examples/UpdateInputExamplesPrometheus" UpdateInputExamplesPrometheusRw: $ref: "#/components/examples/UpdateInputExamplesPrometheusRw" + UpdateInputExamplesProofpointPod: + $ref: "#/components/examples/UpdateInputExamplesProofpointPod" UpdateInputExamplesRawUdp: $ref: "#/components/examples/UpdateInputExamplesRawUdp" UpdateInputExamplesBedrockS3: @@ -78548,6 +83966,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesS3" UpdateInputExamplesS3Inventory: $ref: "#/components/examples/UpdateInputExamplesS3Inventory" + UpdateInputExamplesSailpointHec: + $ref: "#/components/examples/UpdateInputExamplesSailpointHec" UpdateInputExamplesSecurityLake: $ref: "#/components/examples/UpdateInputExamplesSecurityLake" UpdateInputExamplesServiceNowTable: @@ -78576,8 +83996,14 @@ paths: $ref: "#/components/examples/UpdateInputExamplesTcp" UpdateInputExamplesTcpjson: $ref: "#/components/examples/UpdateInputExamplesTcpjson" + UpdateInputExamplesTrendMicroVisionOne: + $ref: "#/components/examples/UpdateInputExamplesTrendMicroVisionOne" UpdateInputExamplesUpwindHec: $ref: "#/components/examples/UpdateInputExamplesUpwindHec" + UpdateInputExamplesTrellixHec: + $ref: "#/components/examples/UpdateInputExamplesTrellixHec" + UpdateInputExamplesVectraAiHec: + $ref: "#/components/examples/UpdateInputExamplesVectraAiHec" UpdateInputExamplesWef: $ref: "#/components/examples/UpdateInputExamplesWef" UpdateInputExamplesWinEventLogs: @@ -78627,6 +84053,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: updateInputSystemByPackAndId parameters: - name: id in: path @@ -78641,10 +84068,13 @@ paths: type: string description: The id of the Pack. delete: - operationId: deleteInputSystemByPackAndId x-speakeasy-group: packs.sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: delete tags: - sources @@ -78687,6 +84117,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: deleteInputSystemByPackAndId parameters: - name: id in: path @@ -78709,6 +84140,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Add an HEC token and optional metadata to a Splunk HEC Source within a Pack description: Add an HEC token and optional metadata to the specified Splunk HEC @@ -78781,6 +84216,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Update metadata for an HEC token for a Splunk HEC Source within a Pack description: Update the metadata for the specified HEC token for the specified Splunk HEC Source within the specified Pack. @@ -78859,6 +84298,10 @@ paths: x-speakeasy-name-override: clear x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Clear the persistent queue for a Source within a Pack description: Clear the persistent queue (PQ) for the specified Source within the specified Pack. @@ -78915,6 +84358,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get information about the latest job to clear the persistent queue for a Source within a Pack description: Get information about the latest job to clear the persistent queue @@ -78950,68 +84397,71 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" - parameters: - - name: id - in: path - required: true - schema: - type: string - description: The id of the Source to get PQ job information for. - - name: pack - in: path - required: true - schema: - type: string - description: The id of the Pack. - /p/{pack}/system/outputs: - get: + parameters: + - name: id + in: path + required: true + schema: + type: string + description: The id of the Source to get PQ job information for. + - name: pack + in: path + required: true + schema: + type: string + description: The id of the Pack. + /p/{pack}/system/outputs: + get: + x-speakeasy-group: packs.destinations + x-cribl-internal: false + x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single + x-speakeasy-name-override: list + tags: + - destinations + summary: List all Destinations within a Pack + description: Get a list of all Destinations within the specified Pack. + responses: + "200": + description: List of Destination objects. + content: + application/json: + schema: + $ref: "#/components/schemas/PaginatedOutputResponse" + examples: + OutputResponseExamplesSplunkHecDestination: + $ref: "#/components/examples/OutputResponseExamplesSplunkHecDestination" + OutputResponseExamplesS3Destination: + $ref: "#/components/examples/OutputResponseExamplesS3Destination" + OutputResponseExamplesSyslogDestination: + $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" + OutputResponseExamplesSnowflakeStreamingDestination: + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" + "401": + description: Authentication failed (missing or invalid credentials or Bearer + token). + content: + application/json: + schema: + $ref: "#/components/schemas/Error" + examples: + authenticationFailed: + summary: Reject a request with invalid credentials + description: Example response for rejecting an API request with missing or + invalid credentials. + value: + status: error + message: Authentication failed (missing or invalid credentials or Bearer token). + "500": + description: Unexpected server error. + content: + application/json: + schema: + $ref: "#/components/schemas/Error" operationId: getOutputSystemByPack - x-speakeasy-group: packs.destinations - x-cribl-internal: false - x-cribl-availability: both - x-speakeasy-name-override: list - tags: - - destinations - summary: List all Destinations within a Pack - description: Get a list of all Destinations within the specified Pack. - responses: - "200": - description: List of Destination objects. - content: - application/json: - schema: - $ref: "#/components/schemas/PaginatedOutputResponse" - examples: - OutputResponseExamplesSplunkHecDestination: - $ref: "#/components/examples/OutputResponseExamplesSplunkHecDestination" - OutputResponseExamplesS3Destination: - $ref: "#/components/examples/OutputResponseExamplesS3Destination" - OutputResponseExamplesSyslogDestination: - $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" - OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" - "401": - description: Authentication failed (missing or invalid credentials or Bearer - token). - content: - application/json: - schema: - $ref: "#/components/schemas/Error" - examples: - authenticationFailed: - summary: Reject a request with invalid credentials - description: Example response for rejecting an API request with missing or - invalid credentials. - value: - status: error - message: Authentication failed (missing or invalid credentials or Bearer token). - "500": - description: Unexpected server error. - content: - application/json: - schema: - $ref: "#/components/schemas/Error" parameters: - name: type in: query @@ -79053,10 +84503,13 @@ paths: outputs: results: $.items post: - operationId: createOutputSystemByPack x-speakeasy-group: packs.destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: create tags: - destinations @@ -79186,6 +84639,8 @@ paths: $ref: "#/components/examples/OutputCreateExamplesServiceNow" OutputCreateExamplesDynatraceOtlp: $ref: "#/components/examples/OutputCreateExamplesDynatraceOtlp" + OutputCreateExamplesTraversalOtlp: + $ref: "#/components/examples/OutputCreateExamplesTraversalOtlp" OutputCreateExamplesGoogleCloudObservability: $ref: "#/components/examples/OutputCreateExamplesGoogleCloudObservability" OutputCreateExamplesSentinelOneAiSiem: @@ -79198,6 +84653,8 @@ paths: $ref: "#/components/examples/OutputCreateExamplesRouter" OutputCreateExamplesWizHec: $ref: "#/components/examples/OutputCreateExamplesWizHec" + OutputCreateExamplesWizHecVpcFlowLogs: + $ref: "#/components/examples/OutputCreateExamplesWizHecVpcFlowLogs" OutputCreateExamplesHumioHec: $ref: "#/components/examples/OutputCreateExamplesHumioHec" OutputCreateExamplesCrowdstrikeNextGenSiem: @@ -79236,6 +84693,8 @@ paths: $ref: "#/components/examples/OutputCreateExamplesDynatraceHttp" OutputCreateExamplesDatabricks: $ref: "#/components/examples/OutputCreateExamplesDatabricks" + OutputCreateExamplesDatabricksZerobus: + $ref: "#/components/examples/OutputCreateExamplesDatabricksZerobus" OutputCreateExamplesSnowflakeStreaming: $ref: "#/components/examples/OutputCreateExamplesSnowflakeStreaming" responses: @@ -79253,8 +84712,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -79279,6 +84737,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: createOutputSystemByPack parameters: - name: pack in: path @@ -79288,10 +84747,13 @@ paths: description: The id of the Pack. /p/{pack}/system/outputs/{id}: get: - operationId: getOutputSystemByPackAndId x-speakeasy-group: packs.destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: get tags: - destinations @@ -79312,8 +84774,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -79337,6 +84798,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: getOutputSystemByPackAndId parameters: - name: id in: path @@ -79351,10 +84813,13 @@ paths: type: string description: The id of the Pack. patch: - operationId: updateOutputSystemByPackAndId x-speakeasy-group: packs.destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: update tags: - destinations @@ -79488,6 +84953,8 @@ paths: $ref: "#/components/examples/UpdateOutputExamplesServiceNow" UpdateOutputExamplesDynatraceOtlp: $ref: "#/components/examples/UpdateOutputExamplesDynatraceOtlp" + UpdateOutputExamplesTraversalOtlp: + $ref: "#/components/examples/UpdateOutputExamplesTraversalOtlp" UpdateOutputExamplesGoogleCloudObservability: $ref: "#/components/examples/UpdateOutputExamplesGoogleCloudObservability" UpdateOutputExamplesSentinelOneAiSiem: @@ -79500,6 +84967,8 @@ paths: $ref: "#/components/examples/UpdateOutputExamplesRouter" UpdateOutputExamplesWizHec: $ref: "#/components/examples/UpdateOutputExamplesWizHec" + UpdateOutputExamplesWizHecVpcFlowLogs: + $ref: "#/components/examples/UpdateOutputExamplesWizHecVpcFlowLogs" UpdateOutputExamplesHumioHec: $ref: "#/components/examples/UpdateOutputExamplesHumioHec" UpdateOutputExamplesCrowdstrikeNextGenSiem: @@ -79538,6 +85007,8 @@ paths: $ref: "#/components/examples/UpdateOutputExamplesDynatraceHttp" UpdateOutputExamplesDatabricks: $ref: "#/components/examples/UpdateOutputExamplesDatabricks" + UpdateOutputExamplesDatabricksZerobus: + $ref: "#/components/examples/UpdateOutputExamplesDatabricksZerobus" UpdateOutputExamplesSnowflakeStreaming: $ref: "#/components/examples/UpdateOutputExamplesSnowflakeStreaming" responses: @@ -79555,8 +85026,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -79580,6 +85050,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: updateOutputSystemByPackAndId parameters: - name: id in: path @@ -79594,10 +85065,13 @@ paths: type: string description: The id of the Pack. delete: - operationId: deleteOutputSystemByPackAndId x-speakeasy-group: packs.destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: delete tags: - destinations @@ -79618,8 +85092,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -79646,6 +85119,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: deleteOutputSystemByPackAndId parameters: - name: id in: path @@ -79668,6 +85142,10 @@ paths: x-speakeasy-name-override: clear x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Clear the persistent queue for a Destination within a Pack description: Clear the persistent queue (PQ) for the specified Destination within the specified Pack. @@ -79723,6 +85201,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get information about the latest job to clear the persistent queue for a Destination within a Pack description: Get information about the latest job to clear the persistent queue @@ -79777,6 +85259,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get sample event data for a Destination within a Pack description: Get sample event data for the specified Destination to validate the configuration or test connectivity within the specified Pack. @@ -79836,6 +85322,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Send sample event data to a Destination within a Pack description: Send sample event data to the specified Destination to validate the configuration or test connectivity within the specified Pack. @@ -79908,6 +85398,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: List the status of all Sources within a Pack description: List status information and optional metrics for all configured Sources in the Worker Group or Edge Fleet within the specified Pack. @@ -80004,6 +85498,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get the status of a Source within a Pack description: Get the status and optional metrics for the specified Source within the specified Pack. @@ -80076,6 +85574,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: List the status of all Destinations within a Pack description: List status information and optional metrics for all configured Destinations in the Worker Group or Edge Fleet within the specified @@ -80173,6 +85675,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get the status of a Destination within a Pack description: Get the status and optional metrics for the specified Destination within the specified Pack. @@ -80245,6 +85751,10 @@ paths: x-speakeasy-name-override: install x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Install a Pack description: Install a Pack.

To install an uploaded Pack, provide the source value from the PUT /packs response as @@ -80313,6 +85823,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: List all Packs description: Get a list of all Packs. responses: @@ -80352,10 +85866,7 @@ paths: required: false schema: type: string - description: "Comma-separated list of additional properties to include in the - response. When set, the response includes a count of each specified - property in each Pack. Supported values: inputs, - outputs, collectors." + description: "Comma-separated list of additional properties to include in the response. When set, the response includes a count of each specified property in each Pack. Supported values: inputs, outputs, collectors." - name: offset in: query required: false @@ -80389,6 +85900,10 @@ paths: x-speakeasy-name-override: upload x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Upload a Pack file description: Upload a Pack file. Returns the source ID needed to install the Pack with POST /packs, which you must call @@ -80425,6 +85940,8 @@ paths: schema: $ref: "#/components/schemas/Error" requestBody: + description: Binary contents of the .crbl Pack file to stage for + installation required: true content: application/octet-stream: @@ -80432,7 +85949,8 @@ paths: type: string format: binary contentMediaType: application/octet-stream - description: Pack file upload + description: Binary contents of the .crbl Pack file to stage for + installation parameters: - name: filename in: query @@ -80449,6 +85967,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Get a Pack description: Get the specified Pack. responses: @@ -80478,6 +86000,10 @@ paths: value: status: error message: Authentication failed (missing or invalid credentials or Bearer token). + "409": + description: Request conflicts with current resource state — Pack + id is ambiguous because multiple Packs differ only by + case; specify the exact stored Pack Id "500": description: Unexpected server error. content: @@ -80500,6 +86026,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Upgrade a Pack description: Upgrade the specified Pack.

If the Pack includes any user-modified versions of default Cribl Knowledge resources such as @@ -80534,6 +86064,10 @@ paths: value: status: error message: Authentication failed (missing or invalid credentials or Bearer token). + "409": + description: Request conflicts with current resource state — Pack + id is ambiguous because multiple Packs differ only by + case; specify the exact stored Pack Id "500": description: Unexpected server error. content: @@ -80566,6 +86100,10 @@ paths: x-speakeasy-name-override: delete x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Uninstall a Pack description: Uninstall the specified Pack. responses: @@ -80593,6 +86131,10 @@ paths: value: status: error message: Authentication failed (missing or invalid credentials or Bearer token). + "409": + description: Request conflicts with current resource state — Pack + id is ambiguous because multiple Packs differ only by + case; specify the exact stored Pack Id "500": description: Unexpected server error. content: @@ -80616,6 +86158,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: List all Pipelines description: Get a list of all Pipelines. responses: @@ -80657,15 +86203,17 @@ paths: required: false schema: type: integer - minimum: 0 - description: Pagination offset + description: Starting point from which to retrieve results for this request. Use + with limit to paginate the response into manageable + batches. - name: limit in: query required: false schema: type: integer - minimum: 0 - description: Maximum number of items to return + description: Maximum number of Pipelines to return in the response for this + request. Use with offset to paginate the response into + manageable batches. x-speakeasy-pagination: type: offsetLimit inputs: @@ -80685,6 +86233,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Create a Pipeline description: Create a new Pipeline. responses: @@ -80820,6 +86372,10 @@ paths: x-speakeasy-name-override: delete x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Delete a Pipeline description: Delete the specified Pipeline. responses: @@ -80870,6 +86426,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Get a Pipeline description: Get the specified Pipeline. responses: @@ -80920,6 +86480,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Update a Pipeline description: Update the specified Pipeline.

Provide a complete representation of the Pipeline that you want to update in the request @@ -81068,6 +86632,8 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: List all Worker Groups, Outpost Groups, or Edge Fleets description: Get a list of all Worker Groups, Outpost Groups, or Edge Fleets for the specified Cribl product. @@ -81154,6 +86720,8 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Create a Worker Group, Outpost Group, or Edge Fleet description: Create a new Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product. @@ -81197,8 +86765,7 @@ paths: $ref: "#/components/schemas/RestApiJsonError" examples: GroupCreate429ResponseExamplesConfigHelperUnavailable: - $ref: "#/components/examples/GroupCreate429ResponseExamplesConfigHelperUnavaila\ - ble" + $ref: "#/components/examples/GroupCreate429ResponseExamplesConfigHelperUnavailable" headers: retry-after: description: Number of seconds the client should wait before retrying the @@ -81246,6 +86813,8 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Get a Worker Group, Outpost Group, or Edge Fleet description: Get the specified Worker Group, Outpost Group, or Edge Fleet. responses: @@ -81312,21 +86881,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Update a Worker Group, Outpost Group, or Edge Fleet - description: "Update the specified Worker Group, Outpost Group, or Edge - Fleet.

Provide a complete representation of the Group or Fleet - that you want to update in the request body. This endpoint does not - support partial updates. Cribl removes any omitted fields when updating - the Group or Fleet.

Confirm that the configuration in your - request body is correct before sending the request. If the configuration - is incorrect, the updated Group or Fleet might not function as - expected.

**Warning**: Do not change the values for the - following parameters in the body of PATCH requests. The request body - must include the values as they appear in the GET - /products/{product}/groups/{id} response.
- - configVersion
- deployingWorkerCount
- - incompatibleWorkerCount
- - workerCount
- lookupDeployments." + description: "Update the specified Worker Group, Outpost Group, or Edge Fleet.

Provide a complete representation of the Group or Fleet that you want to update in the request body. This endpoint does not support partial updates. Cribl removes any omitted fields when updating the Group or Fleet.

Confirm that the configuration in your request body is correct before sending the request. If the configuration is incorrect, the updated Group or Fleet might not function as expected.

**Warning**: Do not change the values for the following parameters in the body of PATCH requests. The request body must include the values as they appear in the GET /products/{product}/groups/{id} response.
- configVersion
- deployingWorkerCount
- incompatibleWorkerCount
- workerCount
- lookupDeployments." responses: "200": description: The updated ConfigGroup object in a single-item list. @@ -81397,6 +86955,8 @@ paths: x-speakeasy-name-override: delete x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Delete a Worker Group, Outpost Group, or Edge Fleet description: Delete the specified Worker Group, Outpost Group, or Edge Fleet. responses: @@ -81454,10 +87014,18 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both - summary: Get the Access Control List for a Worker Group, Outpost Group, or Edge - Fleet - description: Get the Access Control List (ACL) for the specified Worker Group, - Outpost Group, or Edge Fleet. + x-cribl-api-context: + - leader + summary: Get the user access control list for a Worker Group, Outpost Group, or + Edge Fleet + description: Get the user access control list (ACL) for the specified Worker + Group, Outpost Group, or Edge Fleet.

This endpoint lists users + with explicit access assignments on the Group or Fleet. The response + does not include access granted through Team membership or inherited + based on a user's Permissions and Roles at the Organization/Global, + Workspace, or product level.

To list the Team ACL for a product + and Group or Fleet, use GET + /products/{product}/groups/{id}/acl/teams. responses: "200": description: The requested UserAccessControlList object in a single-item list. @@ -81465,6 +87033,9 @@ paths: application/json: schema: $ref: "#/components/schemas/CountedUserAccessControlList" + examples: + AclGetUsersResponseGroupExamplesSuccess: + $ref: "#/components/examples/AclGetUsersResponseGroupExamplesSuccess" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -81480,6 +87051,8 @@ paths: value: status: error message: Authentication failed (missing or invalid credentials or Bearer token). + "404": + description: Worker Group, Outpost Group, or Edge Fleet not found. "500": description: Unexpected server error. content: @@ -81492,8 +87065,8 @@ paths: required: true schema: $ref: "#/components/schemas/ProductsCore" - description: Name of the Cribl product to get the Worker Groups or Edge Fleets - for. + description: Name of the Cribl product that contains the Worker Group, Outpost + Group, or Edge Fleet. - name: id in: path required: true @@ -81517,11 +87090,18 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both - summary: Get the Access Control List for teams with permissions on a Worker - Group, Outpost Group, or Edge Fleet for the specified Cribl product - description: Get the Access Control List (ACL) for teams that have permissions - on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl - product. + x-cribl-api-context: + - leader + summary: Get the team access control list for a Worker Group, Outpost Group, or + Edge Fleet + description: Get the Team access control list (ACL) for the specified Worker + Group, Outpost Group, or Edge Fleet.

This endpoint lists Teams + with explicit access assignments on the Group or Fleet. The response + does not include access granted to individual Team Members through + direct user assignments or inherited based on Team Permissions and Roles + at the Organization/Global, Workspace, or product level.

To + list the user ACL for a Group or Fleet, use GET + /products/{product}/groups/{id}/acl. responses: "200": description: The requested TeamAccessControlList object in a single-item list. @@ -81529,6 +87109,9 @@ paths: application/json: schema: $ref: "#/components/schemas/CountedTeamAccessControlList" + examples: + AclGetTeamsResponseGroupExamplesSuccess: + $ref: "#/components/examples/AclGetTeamsResponseGroupExamplesSuccess" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -81564,7 +87147,7 @@ paths: schema: type: string description: The id of the Worker Group, Outpost Group, or Edge - Fleet to get the team ACL for. + Fleet to get the Team ACL for. - name: type in: query required: false @@ -81581,6 +87164,8 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Get the configuration version for a Worker Group, Outpost Group, or Edge Fleet description: Get the configuration version for the specified Worker Group, @@ -81640,6 +87225,8 @@ paths: x-speakeasy-name-override: deploy x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Deploy commits to a Worker Group, Outpost Group, or Edge Fleet description: Deploy commits to the specified Worker Group, Outpost Group, or Edge Fleet. @@ -81708,6 +87295,8 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Get a summary of the deployment for a Cribl product description: Get a summary of the deployment for the specified Cribl product (Stream or Edge).

The summary includes a count of Worker Groups @@ -81723,8 +87312,7 @@ paths: $ref: "#/components/schemas/PaginatedDistributedSummary" examples: ProductSummaryResponseExamplesStreamDeploymentSummary: - $ref: "#/components/examples/ProductSummaryResponseExamplesStreamDeploymentSumm\ - ary" + $ref: "#/components/examples/ProductSummaryResponseExamplesStreamDeploymentSummary" "400": description: Failed validation or malformed input if the product is not "stream" or "edge" @@ -81792,6 +87380,8 @@ paths: x-speakeasy-name-override: count x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Get a count of Worker, Edge, or Outpost Nodes description: Get a count of all Worker, Edge, or Outpost Nodes for the specified Cribl product. @@ -81804,8 +87394,7 @@ paths: $ref: "#/components/schemas/CountedNumber" examples: ProductWorkersCountResponseExamplesCountedWorkerNodes: - $ref: "#/components/examples/ProductWorkersCountResponseExamplesCountedWorkerNo\ - des" + $ref: "#/components/examples/ProductWorkersCountResponseExamplesCountedWorkerNodes" "400": description: Failed validation or malformed input if the product is not "stream", "edge", or "outpost" @@ -81856,6 +87445,8 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Get detailed metadata for Worker, Edge, or Outpost Nodes description: Get detailed metadata for Worker, Edge, or Outpost Nodes for the specified Cribl product. @@ -81967,6 +87558,8 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Get detailed metadata for a Worker, Edge, or Outpost Node description: Get detailed metadata for the specified Worker, Edge, or Outpost Node for the specified Cribl product. @@ -82025,6 +87618,8 @@ paths: x-speakeasy-name-override: restart x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader summary: Restart Worker, Edge, or Outpost Nodes description: Restart all Worker, Edge, or Outpost Nodes for the specified Cribl product. @@ -82037,11 +87632,9 @@ paths: $ref: "#/components/schemas/CountedRestartResponse" examples: RestartProductWorkersResponseExamplesRestartingWorkers: - $ref: "#/components/examples/RestartProductWorkersResponseExamplesRestartingWor\ - kers" + $ref: "#/components/examples/RestartProductWorkersResponseExamplesRestartingWorkers" RestartProductWorkersResponseExamplesRestartingWorkersWithError: - $ref: "#/components/examples/RestartProductWorkersResponseExamplesRestartingWor\ - kersWithError" + $ref: "#/components/examples/RestartProductWorkersResponseExamplesRestartingWorkersWithError" "400": description: Failed validation or malformed input if the product is not "stream", "edge", or "outpost" @@ -82095,6 +87688,8 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: cloud + x-cribl-api-context: + - leader summary: List all Lake Datasets (Cribl.Cloud only) description: Get a list of all Lake Datasets in the specified Lake (Cribl.Cloud only). responses: @@ -82104,6 +87699,9 @@ paths: application/json: schema: $ref: "#/components/schemas/PaginatedCriblLakeDataset" + "400": + description: Failed validation or malformed input — invalid orderBy or orderDir + query parameter. "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -82195,15 +87793,54 @@ paths: required: false schema: type: integer - minimum: 0 - description: Pagination offset + description: Starting point for catalog-backed pagination. Requires + limit. - name: limit in: query required: false schema: type: integer - minimum: 0 - description: Maximum number of items to return + description: Page size for catalog-backed pagination. Requires + offset. + - name: orderBy + in: query + required: false + schema: + type: string + description: "Catalog sort field when paginating: name, createdAt, updatedAt, providerPath, type, or retentionPeriodInDays. Defaults to name." + - name: orderDir + in: query + required: false + schema: + type: string + description: "Sort direction when paginating: asc or desc. Defaults to asc." + - name: name + in: query + required: false + schema: + type: string + description: Exact dataset name match (catalog path, with pagination). + - name: nameContains + in: query + required: false + schema: + type: string + description: Case-insensitive substring match on dataset name (catalog path, + with pagination). + - name: providerPathContains + in: query + required: false + schema: + type: string + description: Case-insensitive substring match on provider path (catalog path, + with pagination). + - name: descriptionContains + in: query + required: false + schema: + type: string + description: Case-insensitive substring match on description (catalog path, with + pagination). x-speakeasy-pagination: type: offsetLimit inputs: @@ -82223,10 +87860,19 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: cloud - summary: Create a Lake Dataset (Cribl.Cloud only) - description: Create a new Lake Dataset in the specified Lake (Cribl.Cloud only). + x-cribl-api-context: + - leader + summary: Create Lake Datasets (Cribl.Cloud only) + description: Creates one or more Lake Datasets in the specified Lake in a single + transaction (Cribl.Cloud only). Send a single Lake Dataset object to + create just one, or an array to bulk-create multiple. When an array is + sent, the response is { items, errors } — + items contains the successfully created Lake Datasets, and + errors contains an entry ({ id, reason }) for + each Lake Dataset that failed validation, so a per-item failure does not + fail the rest of the batch. responses: - "200": + "201": description: The created CriblLakeDataset object in a single-item list. content: application/json: @@ -82267,13 +87913,15 @@ paths: $ref: "#/components/examples/LakeDatasetCreateExamplesParquetDataset" LakeDatasetCreateExamplesMinimalDataset: $ref: "#/components/examples/LakeDatasetCreateExamplesMinimalDataset" + LakeDatasetCreateExamplesBulkCreateDatasets: + $ref: "#/components/examples/LakeDatasetCreateExamplesBulkCreateDatasets" parameters: - name: lakeId in: path required: true schema: type: string - description: The id of the Lake to create the Lake Dataset in. + description: The id of the Lake to create the Lake Datasets in. /products/lake/lakes/{lakeId}/datasets/{id}: get: operationId: getCriblLakeDatasetByLakeIdAndId @@ -82283,6 +87931,8 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: cloud + x-cribl-api-context: + - leader summary: Get a Lake Dataset (Cribl.Cloud only) description: Get the specified Lake Dataset in the specified Lake (Cribl.Cloud only). responses: @@ -82343,6 +87993,8 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: cloud + x-cribl-api-context: + - leader summary: Update a Lake Dataset (Cribl.Cloud only) description: Update the specified Lake Dataset in the specified Lake (Cribl.Cloud only). @@ -82353,6 +88005,10 @@ paths: application/json: schema: $ref: "#/components/schemas/CountedCriblLakeDataset" + "400": + description: Failed validation or malformed input — attempt to change a + read-only field (cacheConnection, deletionStartedAt, storageClass) + or an unsupported format in Highside mode. "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -82368,6 +88024,9 @@ paths: value: status: error message: Authentication failed (missing or invalid credentials or Bearer token). + "409": + description: Request conflicts with current resource state — the Lakehouse for + this Dataset is being migrated and cannot be updated. "500": description: Unexpected server error. content: @@ -82408,6 +88067,8 @@ paths: x-speakeasy-name-override: delete x-cribl-internal: false x-cribl-availability: cloud + x-cribl-api-context: + - leader summary: Delete a Lake Dataset (Cribl.Cloud only) description: Delete the specified Lake Dataset in the specified Lake (Cribl.Cloud only). @@ -82462,6 +88123,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: List all Routes description: Get a list of all Routes. responses: @@ -82470,7 +88135,7 @@ paths: content: application/json: schema: - $ref: "#/components/schemas/CountedRoutes" + $ref: "#/components/schemas/PaginatedRoutes" examples: RoutesResponseExamplesDefaultRoutingTable: $ref: "#/components/examples/RoutesResponseExamplesDefaultRoutingTable" @@ -82497,6 +88162,32 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + parameters: + - name: offset + in: query + required: false + schema: + type: integer + minimum: 0 + description: Pagination offset + - name: limit + in: query + required: false + schema: + type: integer + minimum: 0 + description: Maximum number of items to return + x-speakeasy-pagination: + type: offsetLimit + inputs: + - name: offset + in: parameters + type: offset + - name: limit + in: parameters + type: limit + outputs: + results: $.items /routes/{id}: get: operationId: getRoutesById @@ -82506,6 +88197,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get a Routing table description: Get the specified Routing table. responses: @@ -82560,6 +88255,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Update a Routing table description: Update the specified Routing table.

Provide a complete representation of the Routing table that you want to update in the @@ -82641,6 +88340,10 @@ paths: x-speakeasy-name-override: append x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Add a Route to the end of the Routing table description: Add a Route to the end of the specified Routing table. responses: @@ -82715,6 +88418,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Capture live data description: Initiate a live data capture from Cribl Workers. Returns a stream of captured events in NDJSON format that match the parameters specified @@ -82771,10 +88478,13 @@ paths: $ref: "#/components/examples/CaptureExamplesComplexFilter" /system/inputs: get: - operationId: listInput x-speakeasy-group: sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: list tags: - sources @@ -82817,6 +88527,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: getInput parameters: - name: type in: query @@ -82852,10 +88563,13 @@ paths: outputs: results: $.items post: - operationId: createInput x-speakeasy-group: sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: create tags: - sources @@ -82875,16 +88589,30 @@ paths: required: - id examples: + InputCreateExamplesAkamaiHec: + $ref: "#/components/examples/InputCreateExamplesAkamaiHec" + InputCreateExamplesGigamonHec: + $ref: "#/components/examples/InputCreateExamplesGigamonHec" + InputCreateExamplesBeyondTrustHec: + $ref: "#/components/examples/InputCreateExamplesBeyondTrustHec" InputCreateExamplesAnthropicCompliance: $ref: "#/components/examples/InputCreateExamplesAnthropicCompliance" + InputCreateExamplesAnthropicEnterpriseAnalytics: + $ref: "#/components/examples/InputCreateExamplesAnthropicEnterpriseAnalytics" + InputCreateExamplesAquaSecurityHec: + $ref: "#/components/examples/InputCreateExamplesAquaSecurityHec" InputCreateExamplesAppleUnifiedLogs: $ref: "#/components/examples/InputCreateExamplesAppleUnifiedLogs" InputCreateExamplesAppscope: $ref: "#/components/examples/InputCreateExamplesAppscope" InputCreateExamplesAzureBlob: $ref: "#/components/examples/InputCreateExamplesAzureBlob" + InputCreateExamplesAzureVNetFlowLog: + $ref: "#/components/examples/InputCreateExamplesAzureVNetFlowLog" InputCreateExamplesCloudflareHec: $ref: "#/components/examples/InputCreateExamplesCloudflareHec" + InputCreateExamplesExtrahopRevealx360: + $ref: "#/components/examples/InputCreateExamplesExtrahopRevealx360" InputCreateExamplesConfluentCloud: $ref: "#/components/examples/InputCreateExamplesConfluentCloud" InputCreateExamplesCollection: @@ -82905,6 +88633,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesEdgePrometheus" InputCreateExamplesElastic: $ref: "#/components/examples/InputCreateExamplesElastic" + InputCreateExamplesF5BigIp: + $ref: "#/components/examples/InputCreateExamplesF5BigIp" InputCreateExamplesEventhub: $ref: "#/components/examples/InputCreateExamplesEventhub" InputCreateExamplesEventhubAmqp: @@ -82917,6 +88647,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesFirehose" InputCreateExamplesGrafana: $ref: "#/components/examples/InputCreateExamplesGrafana" + InputCreateExamplesHashicorpHcpVaultDedicated: + $ref: "#/components/examples/InputCreateExamplesHashicorpHcpVaultDedicated" InputCreateExamplesGooglePubsub: $ref: "#/components/examples/InputCreateExamplesGooglePubsub" InputCreateExamplesHttp: @@ -82939,6 +88671,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesLoki" InputCreateExamplesMetrics: $ref: "#/components/examples/InputCreateExamplesMetrics" + InputCreateExamplesMimecastHec: + $ref: "#/components/examples/InputCreateExamplesMimecastHec" InputCreateExamplesModelDrivenTelemetry: $ref: "#/components/examples/InputCreateExamplesModelDrivenTelemetry" InputCreateExamplesMsk: @@ -82947,6 +88681,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesNetflow" InputCreateExamplesOffice365Mgmt: $ref: "#/components/examples/InputCreateExamplesOffice365Mgmt" + InputCreateExamplesMicrosoftCopilot: + $ref: "#/components/examples/InputCreateExamplesMicrosoftCopilot" InputCreateExamplesMicrosoftGraph: $ref: "#/components/examples/InputCreateExamplesMicrosoftGraph" InputCreateExamplesOffice365MsgTrace: @@ -82961,10 +88697,14 @@ paths: $ref: "#/components/examples/InputCreateExamplesOpenAIComplianceLogs" InputCreateExamplesOpenTelemetry: $ref: "#/components/examples/InputCreateExamplesOpenTelemetry" + InputCreateExamplesPingIdentityPingone: + $ref: "#/components/examples/InputCreateExamplesPingIdentityPingone" InputCreateExamplesPrometheus: $ref: "#/components/examples/InputCreateExamplesPrometheus" InputCreateExamplesPrometheusRw: $ref: "#/components/examples/InputCreateExamplesPrometheusRw" + InputCreateExamplesProofpointPod: + $ref: "#/components/examples/InputCreateExamplesProofpointPod" InputCreateExamplesRawUdp: $ref: "#/components/examples/InputCreateExamplesRawUdp" InputCreateExamplesBedrockS3: @@ -82973,6 +88713,8 @@ paths: $ref: "#/components/examples/InputCreateExamplesS3" InputCreateExamplesS3Inventory: $ref: "#/components/examples/InputCreateExamplesS3Inventory" + InputCreateExamplesSailpointHec: + $ref: "#/components/examples/InputCreateExamplesSailpointHec" InputCreateExamplesSecurityLake: $ref: "#/components/examples/InputCreateExamplesSecurityLake" InputCreateExamplesServiceNowTable: @@ -83001,8 +88743,14 @@ paths: $ref: "#/components/examples/InputCreateExamplesTcp" InputCreateExamplesTcpjson: $ref: "#/components/examples/InputCreateExamplesTcpjson" + InputCreateExamplesTrendMicroVisionOne: + $ref: "#/components/examples/InputCreateExamplesTrendMicroVisionOne" InputCreateExamplesUpwindHec: $ref: "#/components/examples/InputCreateExamplesUpwindHec" + InputCreateExamplesTrellixHec: + $ref: "#/components/examples/InputCreateExamplesTrellixHec" + InputCreateExamplesVectraAiHec: + $ref: "#/components/examples/InputCreateExamplesVectraAiHec" InputCreateExamplesWef: $ref: "#/components/examples/InputCreateExamplesWef" InputCreateExamplesWinEventLogs: @@ -83055,12 +88803,16 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: createInput /system/inputs/{id}: get: - operationId: getInputById x-speakeasy-group: sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: get tags: - sources @@ -83105,6 +88857,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: getInputById parameters: - name: id in: path @@ -83113,10 +88866,13 @@ paths: type: string description: The id of the Source to get. patch: - operationId: updateInputById x-speakeasy-group: sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: update tags: - sources @@ -83138,16 +88894,30 @@ paths: schema: $ref: "#/components/schemas/Input" examples: + UpdateInputExamplesAkamaiHec: + $ref: "#/components/examples/UpdateInputExamplesAkamaiHec" + UpdateInputExamplesGigamonHec: + $ref: "#/components/examples/UpdateInputExamplesGigamonHec" + UpdateInputExamplesBeyondTrustHec: + $ref: "#/components/examples/UpdateInputExamplesBeyondTrustHec" UpdateInputExamplesAnthropicCompliance: $ref: "#/components/examples/UpdateInputExamplesAnthropicCompliance" + UpdateInputExamplesAnthropicEnterpriseAnalytics: + $ref: "#/components/examples/UpdateInputExamplesAnthropicEnterpriseAnalytics" + UpdateInputExamplesAquaSecurityHec: + $ref: "#/components/examples/UpdateInputExamplesAquaSecurityHec" UpdateInputExamplesAppleUnifiedLogs: $ref: "#/components/examples/UpdateInputExamplesAppleUnifiedLogs" UpdateInputExamplesAppscope: $ref: "#/components/examples/UpdateInputExamplesAppscope" UpdateInputExamplesAzureBlob: $ref: "#/components/examples/UpdateInputExamplesAzureBlob" + UpdateInputExamplesAzureVNetFlowLog: + $ref: "#/components/examples/UpdateInputExamplesAzureVNetFlowLog" UpdateInputExamplesCloudflareHec: $ref: "#/components/examples/UpdateInputExamplesCloudflareHec" + UpdateInputExamplesExtrahopRevealx360: + $ref: "#/components/examples/UpdateInputExamplesExtrahopRevealx360" UpdateInputExamplesConfluentCloud: $ref: "#/components/examples/UpdateInputExamplesConfluentCloud" UpdateInputExamplesCollection: @@ -83172,6 +88942,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesEdgePrometheus" UpdateInputExamplesElastic: $ref: "#/components/examples/UpdateInputExamplesElastic" + UpdateInputExamplesF5BigIp: + $ref: "#/components/examples/UpdateInputExamplesF5BigIp" UpdateInputExamplesEventhub: $ref: "#/components/examples/UpdateInputExamplesEventhub" UpdateInputExamplesEventhubAmqp: @@ -83184,6 +88956,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesFirehose" UpdateInputExamplesGrafana: $ref: "#/components/examples/UpdateInputExamplesGrafana" + UpdateInputExamplesHashicorpHcpVaultDedicated: + $ref: "#/components/examples/UpdateInputExamplesHashicorpHcpVaultDedicated" UpdateInputExamplesGooglePubsub: $ref: "#/components/examples/UpdateInputExamplesGooglePubsub" UpdateInputExamplesHttp: @@ -83206,6 +88980,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesLoki" UpdateInputExamplesMetrics: $ref: "#/components/examples/UpdateInputExamplesMetrics" + UpdateInputExamplesMimecastHec: + $ref: "#/components/examples/UpdateInputExamplesMimecastHec" UpdateInputExamplesModelDrivenTelemetry: $ref: "#/components/examples/UpdateInputExamplesModelDrivenTelemetry" UpdateInputExamplesMsk: @@ -83214,6 +88990,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesNetflow" UpdateInputExamplesOffice365Mgmt: $ref: "#/components/examples/UpdateInputExamplesOffice365Mgmt" + UpdateInputExamplesMicrosoftCopilot: + $ref: "#/components/examples/UpdateInputExamplesMicrosoftCopilot" UpdateInputExamplesMicrosoftGraph: $ref: "#/components/examples/UpdateInputExamplesMicrosoftGraph" UpdateInputExamplesOffice365MsgTrace: @@ -83228,10 +89006,14 @@ paths: $ref: "#/components/examples/UpdateInputExamplesOpenAIComplianceLogs" UpdateInputExamplesOpenTelemetry: $ref: "#/components/examples/UpdateInputExamplesOpenTelemetry" + UpdateInputExamplesPingIdentityPingone: + $ref: "#/components/examples/UpdateInputExamplesPingIdentityPingone" UpdateInputExamplesPrometheus: $ref: "#/components/examples/UpdateInputExamplesPrometheus" UpdateInputExamplesPrometheusRw: $ref: "#/components/examples/UpdateInputExamplesPrometheusRw" + UpdateInputExamplesProofpointPod: + $ref: "#/components/examples/UpdateInputExamplesProofpointPod" UpdateInputExamplesRawUdp: $ref: "#/components/examples/UpdateInputExamplesRawUdp" UpdateInputExamplesBedrockS3: @@ -83240,6 +89022,8 @@ paths: $ref: "#/components/examples/UpdateInputExamplesS3" UpdateInputExamplesS3Inventory: $ref: "#/components/examples/UpdateInputExamplesS3Inventory" + UpdateInputExamplesSailpointHec: + $ref: "#/components/examples/UpdateInputExamplesSailpointHec" UpdateInputExamplesSecurityLake: $ref: "#/components/examples/UpdateInputExamplesSecurityLake" UpdateInputExamplesServiceNowTable: @@ -83268,8 +89052,14 @@ paths: $ref: "#/components/examples/UpdateInputExamplesTcp" UpdateInputExamplesTcpjson: $ref: "#/components/examples/UpdateInputExamplesTcpjson" + UpdateInputExamplesTrendMicroVisionOne: + $ref: "#/components/examples/UpdateInputExamplesTrendMicroVisionOne" UpdateInputExamplesUpwindHec: $ref: "#/components/examples/UpdateInputExamplesUpwindHec" + UpdateInputExamplesTrellixHec: + $ref: "#/components/examples/UpdateInputExamplesTrellixHec" + UpdateInputExamplesVectraAiHec: + $ref: "#/components/examples/UpdateInputExamplesVectraAiHec" UpdateInputExamplesWef: $ref: "#/components/examples/UpdateInputExamplesWef" UpdateInputExamplesWinEventLogs: @@ -83319,6 +89109,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: updateInputById parameters: - name: id in: path @@ -83327,10 +89118,13 @@ paths: type: string description: The id of the Source to update. delete: - operationId: deleteInputById x-speakeasy-group: sources x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: delete tags: - sources @@ -83373,6 +89167,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: deleteInputById parameters: - name: id in: path @@ -83389,6 +89184,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Add an HEC token and optional metadata to a Splunk HEC Source description: Add an HEC token and optional metadata to the specified Splunk HEC Source. @@ -83454,6 +89253,10 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Update metadata for an HEC token for a Splunk HEC Source description: Update the metadata for the specified HEC token for the specified Splunk HEC Source. @@ -83526,6 +89329,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get information about the latest job to clear the persistent queue for a Source description: Get information about the latest job to clear the persistent queue @@ -83576,6 +89383,10 @@ paths: x-speakeasy-name-override: clear x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Clear the persistent queue for a Source description: Clear the persistent queue (PQ) for the specified Source. responses: @@ -83619,10 +89430,13 @@ paths: description: The id of the Source to clear the PQ for. /system/outputs: get: - operationId: listOutput x-speakeasy-group: destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: list tags: - destinations @@ -83643,8 +89457,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -83666,6 +89479,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: getOutput parameters: - name: type in: query @@ -83701,10 +89515,13 @@ paths: outputs: results: $.items post: - operationId: createOutput x-speakeasy-group: destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: create tags: - destinations @@ -83834,6 +89651,8 @@ paths: $ref: "#/components/examples/OutputCreateExamplesServiceNow" OutputCreateExamplesDynatraceOtlp: $ref: "#/components/examples/OutputCreateExamplesDynatraceOtlp" + OutputCreateExamplesTraversalOtlp: + $ref: "#/components/examples/OutputCreateExamplesTraversalOtlp" OutputCreateExamplesGoogleCloudObservability: $ref: "#/components/examples/OutputCreateExamplesGoogleCloudObservability" OutputCreateExamplesSentinelOneAiSiem: @@ -83846,6 +89665,8 @@ paths: $ref: "#/components/examples/OutputCreateExamplesRouter" OutputCreateExamplesWizHec: $ref: "#/components/examples/OutputCreateExamplesWizHec" + OutputCreateExamplesWizHecVpcFlowLogs: + $ref: "#/components/examples/OutputCreateExamplesWizHecVpcFlowLogs" OutputCreateExamplesHumioHec: $ref: "#/components/examples/OutputCreateExamplesHumioHec" OutputCreateExamplesCrowdstrikeNextGenSiem: @@ -83884,6 +89705,8 @@ paths: $ref: "#/components/examples/OutputCreateExamplesDynatraceHttp" OutputCreateExamplesDatabricks: $ref: "#/components/examples/OutputCreateExamplesDatabricks" + OutputCreateExamplesDatabricksZerobus: + $ref: "#/components/examples/OutputCreateExamplesDatabricksZerobus" OutputCreateExamplesSnowflakeStreaming: $ref: "#/components/examples/OutputCreateExamplesSnowflakeStreaming" responses: @@ -83901,8 +89724,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -83927,12 +89749,16 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: createOutput /system/outputs/{id}: get: - operationId: getOutputById x-speakeasy-group: destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: get tags: - destinations @@ -83953,8 +89779,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -83978,6 +89803,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: getOutputById parameters: - name: id in: path @@ -83986,10 +89812,13 @@ paths: type: string description: The id of the Destination to get. patch: - operationId: updateOutputById x-speakeasy-group: destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: update tags: - destinations @@ -84123,6 +89952,8 @@ paths: $ref: "#/components/examples/UpdateOutputExamplesServiceNow" UpdateOutputExamplesDynatraceOtlp: $ref: "#/components/examples/UpdateOutputExamplesDynatraceOtlp" + UpdateOutputExamplesTraversalOtlp: + $ref: "#/components/examples/UpdateOutputExamplesTraversalOtlp" UpdateOutputExamplesGoogleCloudObservability: $ref: "#/components/examples/UpdateOutputExamplesGoogleCloudObservability" UpdateOutputExamplesSentinelOneAiSiem: @@ -84135,6 +89966,8 @@ paths: $ref: "#/components/examples/UpdateOutputExamplesRouter" UpdateOutputExamplesWizHec: $ref: "#/components/examples/UpdateOutputExamplesWizHec" + UpdateOutputExamplesWizHecVpcFlowLogs: + $ref: "#/components/examples/UpdateOutputExamplesWizHecVpcFlowLogs" UpdateOutputExamplesHumioHec: $ref: "#/components/examples/UpdateOutputExamplesHumioHec" UpdateOutputExamplesCrowdstrikeNextGenSiem: @@ -84173,6 +90006,8 @@ paths: $ref: "#/components/examples/UpdateOutputExamplesDynatraceHttp" UpdateOutputExamplesDatabricks: $ref: "#/components/examples/UpdateOutputExamplesDatabricks" + UpdateOutputExamplesDatabricksZerobus: + $ref: "#/components/examples/UpdateOutputExamplesDatabricksZerobus" UpdateOutputExamplesSnowflakeStreaming: $ref: "#/components/examples/UpdateOutputExamplesSnowflakeStreaming" responses: @@ -84190,8 +90025,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -84215,6 +90049,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: updateOutputById parameters: - name: id in: path @@ -84223,10 +90058,13 @@ paths: type: string description: The id of the Destination to update. delete: - operationId: deleteOutputById x-speakeasy-group: destinations x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single x-speakeasy-name-override: delete tags: - destinations @@ -84247,8 +90085,7 @@ paths: OutputResponseExamplesSyslogDestination: $ref: "#/components/examples/OutputResponseExamplesSyslogDestination" OutputResponseExamplesSnowflakeStreamingDestination: - $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestinatio\ - n" + $ref: "#/components/examples/OutputResponseExamplesSnowflakeStreamingDestination" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -84275,6 +90112,7 @@ paths: application/json: schema: $ref: "#/components/schemas/Error" + operationId: deleteOutputById parameters: - name: id in: path @@ -84291,6 +90129,10 @@ paths: x-speakeasy-name-override: clear x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Clear the persistent queue for a Destination description: Clear the persistent queue (PQ) for the specified Destination. responses: @@ -84339,6 +90181,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get information about the latest job to clear the persistent queue for a Destination description: Get information about the latest job to clear the persistent queue @@ -84387,6 +90233,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get sample event data for a Destination description: Get sample event data for the specified Destination to validate the configuration or test connectivity. @@ -84440,6 +90290,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Send sample event data to a Destination description: Send sample event data to the specified Destination to validate the configuration or test connectivity. @@ -84506,6 +90360,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Get system settings description: Get the current Cribl system settings. responses: @@ -84547,13 +90405,20 @@ paths: x-speakeasy-name-override: update x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Update system settings description: Update the specified Cribl system settings.

Provide only the top-level sections (api, workers, tls, proxy, etc.) you want to change. Omitted sections stay unchanged. Each provided section fully replaces the existing one — send the complete section object, not only the changed - fields. + fields.

api.loginRateLimit and + api.ssoRateLimit are deprecated. A new value is still + applied, but it is stored as rateLimits in the API limits + configuration. Use PATCH /system/api-limits instead. responses: "200": description: The updated system settings. @@ -84563,8 +90428,7 @@ paths: $ref: "#/components/schemas/CountedSystemSettingsConfResponse" examples: UpdateSystemSettingsResponseExamplesUpdateApiSettings: - $ref: "#/components/examples/UpdateSystemSettingsResponseExamplesUpdateApiSetti\ - ngs" + $ref: "#/components/examples/UpdateSystemSettingsResponseExamplesUpdateApiSettings" "400": description: Failed validation or malformed input, such as missing or invalid parameters. @@ -84611,6 +90475,10 @@ paths: x-speakeasy-name-override: restart x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - node + - single summary: Restart the Cribl server description: Restart the Cribl server.

This operation requires system.restart to be set to api in @@ -84663,6 +90531,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: List the status of all Sources description: List status information and optional metrics for all configured Sources in the Worker Group or Edge Fleet. @@ -84753,6 +90625,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get the status of a Source description: Get the status and optional metrics for the specified Source. responses: @@ -84818,6 +90694,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: List the status of all Destinations description: List status information and optional metrics for all configured Destinations in the Worker Group or Edge Fleet. @@ -84908,6 +90788,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - node + - single summary: Get the status of a Destination description: Get the status and optional metrics for the specified Destination. responses: @@ -84973,6 +90857,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: List the commit history description: List the commit history.

Analogous to git log for the Cribl configuration, allowing you to audit and review changes @@ -85051,6 +90939,9 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - single summary: List all branches in the Git repository used for Cribl configuration description: Get a list of all branches in the Git repository used for Cribl configuration. @@ -85094,6 +90985,10 @@ paths: x-speakeasy-name-override: create x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Create a new commit for pending changes to the Cribl configuration description: Create a new commit for pending changes to the Cribl configuration. Any merge conflicts indicated in the response must be resolved using @@ -85110,16 +91005,14 @@ paths: VersionCommitResponseExamplesCommitCreated: $ref: "#/components/examples/VersionCommitResponseExamplesCommitCreated" "400": - description: "When effective: true is provided without a group - context." + description: "When effective: true is provided without a group context." content: application/json: schema: $ref: "#/components/schemas/RestApiJsonError" examples: VersionCommitBadRequestExamplesEffectiveWithoutGroup: - $ref: "#/components/examples/VersionCommitBadRequestExamplesEffectiveWithoutGro\ - up" + $ref: "#/components/examples/VersionCommitBadRequestExamplesEffectiveWithoutGroup" "401": description: Authentication failed (missing or invalid credentials or Bearer token). @@ -85162,6 +91055,10 @@ paths: x-speakeasy-name-override: count x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Get a count of files that changed since a commit description: Get a count of the files that changed since a commit. Default is the latest commit (HEAD). @@ -85212,6 +91109,9 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - single summary: Get the name of the Git branch that the Cribl configuration is checked out to description: Get the name of the Git branch that the Cribl configuration is @@ -85256,6 +91156,10 @@ paths: x-speakeasy-name-override: diff x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Get the diff for a commit description: Get the diff for a commit. Default is the latest commit (HEAD). responses: @@ -85319,6 +91223,10 @@ paths: x-speakeasy-name-override: list x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Get the names and statuses of files that changed since a commit description: Get the names and statuses of files that changed since a commit. Default is the latest commit (HEAD). @@ -85369,6 +91277,9 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - single summary: Get the configuration and status for the Git integration description: Get the configuration and versioning status for the Git integration for the Cribl configuration. @@ -85412,6 +91323,9 @@ paths: x-speakeasy-name-override: push x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - leader + - single summary: Push local commits to the remote repository description: Push all local commits from the local repository to the remote repository.

Requires at least one local commit that has not @@ -85457,6 +91371,10 @@ paths: x-speakeasy-name-override: revert x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Revert a commit in the local repository description: Revert a commit in the local repository by creating a new commit that undoes the changes introduced by the specified commit.

Use @@ -85514,6 +91432,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Get the diff and log message for a commit description: Get the diff and log message for a commit. Default is the latest commit (HEAD). @@ -85578,6 +91500,10 @@ paths: x-speakeasy-name-override: get x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Get the status of the current working tree description: Get the status of the current working tree of the Git repository used for Cribl configuration. The response includes details about @@ -85623,6 +91549,10 @@ paths: x-speakeasy-name-override: undo x-cribl-internal: false x-cribl-availability: both + x-cribl-api-context: + - group + - leader + - single summary: Discard uncommitted (staged) changes description: Discard all uncommitted (staged) configuration changes, resetting the working directory to the last committed state. Use only if you are diff --git a/.speakeasy/workflow.lock b/.speakeasy/workflow.lock index 9248ba068..6b2c58775 100644 --- a/.speakeasy/workflow.lock +++ b/.speakeasy/workflow.lock @@ -1,23 +1,23 @@ -speakeasyVersion: 1.795.1 +speakeasyVersion: 1.797.0 sources: Cribl API Reference: sourceNamespace: cribl-api-reference - sourceRevisionDigest: sha256:87e05b6652f5fd6d48cfeb4ef634ece9227538ca5a48452453b53f9490e94794 - sourceBlobDigest: sha256:12e50f712985c36989a07819a57011431eac4a2a0fbc0dd917eb76683cb38571 + sourceRevisionDigest: sha256:e19b9010fedccc8ddac4d037ac15e5df6bf84a466dad5723e975bcce5a7ca853 + sourceBlobDigest: sha256:b9cf2621370cf86e438de658654d42f858cf85f72bdf3204c2acd6e1a1de2107 tags: - latest - - 4.19.2-89cac507 + - 4.20.0-cee79842 targets: cribl-control-plane: source: Cribl API Reference sourceNamespace: cribl-api-reference - sourceRevisionDigest: sha256:87e05b6652f5fd6d48cfeb4ef634ece9227538ca5a48452453b53f9490e94794 - sourceBlobDigest: sha256:12e50f712985c36989a07819a57011431eac4a2a0fbc0dd917eb76683cb38571 + sourceRevisionDigest: sha256:e19b9010fedccc8ddac4d037ac15e5df6bf84a466dad5723e975bcce5a7ca853 + sourceBlobDigest: sha256:b9cf2621370cf86e438de658654d42f858cf85f72bdf3204c2acd6e1a1de2107 codeSamplesNamespace: cribl-api-reference-python-code-samples - codeSamplesRevisionDigest: sha256:135c306a48fb36c5bd61510430f0b1c515e7ae61045b35694fc17307827b3af9 + codeSamplesRevisionDigest: sha256:5f16de7985fe5b8d762c6a98e846d91ce3c19866159d41bd6e739dc178208524 workflow: workflowVersion: 1.0.0 - speakeasyVersion: 1.795.1 + speakeasyVersion: 1.797.0 sources: Cribl API Reference: inputs: diff --git a/README-PYPI.md b/README-PYPI.md index 30b9bea66..0c77287dc 100644 --- a/README-PYPI.md +++ b/README-PYPI.md @@ -275,11 +275,11 @@ The [On-Prem Authentication Example](https://github.com/criblio/cribl_control_pl #### [Groups.Acl](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/acl/README.md) -* [get](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/acl/README.md#get) - Get the Access Control List for a Worker Group, Outpost Group, or Edge Fleet +* [get](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/acl/README.md#get) - Get the user access control list for a Worker Group, Outpost Group, or Edge Fleet ##### [Groups.Acl.Teams](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/teams/README.md) -* [get](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/teams/README.md#get) - Get the Access Control List for teams with permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product +* [get](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/teams/README.md#get) - Get the team access control list for a Worker Group, Outpost Group, or Edge Fleet #### [Groups.Configs.Versions](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/configsversions/README.md) @@ -292,7 +292,7 @@ The [On-Prem Authentication Example](https://github.com/criblio/cribl_control_pl ### [Lakes.Datasets](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/datasets/README.md) * [list](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/datasets/README.md#list) - List all Lake Datasets (Cribl.Cloud only) -* [create](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/datasets/README.md#create) - Create a Lake Dataset (Cribl.Cloud only) +* [create](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/datasets/README.md#create) - Create Lake Datasets (Cribl.Cloud only) * [get](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/datasets/README.md#get) - Get a Lake Dataset (Cribl.Cloud only) * [update](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/datasets/README.md#update) - Update a Lake Dataset (Cribl.Cloud only) * [delete](https://github.com/criblio/cribl_control_plane_sdk_python/blob/master/docs/sdks/datasets/README.md#delete) - Delete a Lake Dataset (Cribl.Cloud only) diff --git a/README.md b/README.md index fb3baa1dd..e3f3c5611 100644 --- a/README.md +++ b/README.md @@ -275,11 +275,11 @@ The [On-Prem Authentication Example](https://github.com/criblio/cribl_control_pl #### [Groups.Acl](docs/sdks/acl/README.md) -* [get](docs/sdks/acl/README.md#get) - Get the Access Control List for a Worker Group, Outpost Group, or Edge Fleet +* [get](docs/sdks/acl/README.md#get) - Get the user access control list for a Worker Group, Outpost Group, or Edge Fleet ##### [Groups.Acl.Teams](docs/sdks/teams/README.md) -* [get](docs/sdks/teams/README.md#get) - Get the Access Control List for teams with permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product +* [get](docs/sdks/teams/README.md#get) - Get the team access control list for a Worker Group, Outpost Group, or Edge Fleet #### [Groups.Configs.Versions](docs/sdks/configsversions/README.md) @@ -292,7 +292,7 @@ The [On-Prem Authentication Example](https://github.com/criblio/cribl_control_pl ### [Lakes.Datasets](docs/sdks/datasets/README.md) * [list](docs/sdks/datasets/README.md#list) - List all Lake Datasets (Cribl.Cloud only) -* [create](docs/sdks/datasets/README.md#create) - Create a Lake Dataset (Cribl.Cloud only) +* [create](docs/sdks/datasets/README.md#create) - Create Lake Datasets (Cribl.Cloud only) * [get](docs/sdks/datasets/README.md#get) - Get a Lake Dataset (Cribl.Cloud only) * [update](docs/sdks/datasets/README.md#update) - Update a Lake Dataset (Cribl.Cloud only) * [delete](docs/sdks/datasets/README.md#delete) - Delete a Lake Dataset (Cribl.Cloud only) diff --git a/RELEASES.md b/RELEASES.md index d1768b40a..83bd6788b 100644 --- a/RELEASES.md +++ b/RELEASES.md @@ -708,4 +708,14 @@ Based on: ### Generated - [python v0.11.0] . ### Releases -- [PyPI v0.11.0] https://pypi.org/project/cribl-control-plane/0.11.0 - . \ No newline at end of file +- [PyPI v0.11.0] https://pypi.org/project/cribl-control-plane/0.11.0 - . + +## 2026-09-17 06:58:05 +### Changes +Based on: +- OpenAPI Doc +- Speakeasy CLI 1.797.0 (2.937.18) https://github.com/speakeasy-api/speakeasy +### Generated +- [python v0.12.0] . +### Releases +- [PyPI v0.12.0] https://pypi.org/project/cribl-control-plane/0.12.0 - . \ No newline at end of file diff --git a/USAGE.md b/USAGE.md index 8cc9e84bc..52608e093 100644 --- a/USAGE.md +++ b/USAGE.md @@ -8,7 +8,7 @@ with CriblControlPlane( "https://api.example.com", ) as ccp_client: - res = ccp_client.auth.tokens.get(password="6j50J9421x29IhO", username="Lilly_Weissnat") + res = ccp_client.auth.tokens.get(password="yourPassword", username="yourUsername") # Handle response print(res) @@ -29,7 +29,7 @@ async def main(): "https://api.example.com", ) as ccp_client: - res = await ccp_client.auth.tokens.get_async(password="6j50J9421x29IhO", username="Lilly_Weissnat") + res = await ccp_client.auth.tokens.get_async(password="yourPassword", username="yourUsername") # Handle response print(res) diff --git a/docs/models/activities.md b/docs/models/activities.md index 447f2e088..da42aa342 100644 --- a/docs/models/activities.md +++ b/docs/models/activities.md @@ -5,14 +5,14 @@ Activities ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.ActivitiesManageState]](../models/activitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.ActivitiesManageState]](../models/activitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/systemsettingsconfupdateapi.md b/docs/models/api.md similarity index 99% rename from docs/models/systemsettingsconfupdateapi.md rename to docs/models/api.md index 6e03b1db0..bac8676e4 100644 --- a/docs/models/systemsettingsconfupdateapi.md +++ b/docs/models/api.md @@ -1,4 +1,4 @@ -# SystemSettingsConfUpdateAPI +# API API server configuration for the Cribl instance. diff --git a/docs/models/apps.md b/docs/models/apps.md index a8ba273f5..1a9a7bd90 100644 --- a/docs/models/apps.md +++ b/docs/models/apps.md @@ -5,6 +5,13 @@ App configuration. ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | If true, enable Apps. Otherwise, false. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `app_backend_broker_origin` | *Optional[str]* | :heavy_minus_sign: | Public origin for App Platform backend broker callbacks (standalone/on-prem only). Must be an absolute HTTP(S) URL. | +| `app_backend_max_callbacks_per_installation` | *Optional[int]* | :heavy_minus_sign: | Maximum number of broker callbacks per minute a single app backend installation may make. Over-limit callbacks receive HTTP 429. | +| `app_backend_max_callbacks_total` | *Optional[int]* | :heavy_minus_sign: | Maximum number of broker callbacks per minute across all app backend installations on this Leader. Unlimited when unset. Over-limit callbacks receive HTTP 429. | +| `app_backend_max_in_flight` | *Optional[int]* | :heavy_minus_sign: | Maximum number of concurrent App Platform backend invocations across all apps on this Leader. | +| `app_schedule_body_expression_max_length` | *Optional[int]* | :heavy_minus_sign: | Maximum number of characters allowed in a schedule bodyExpression. | +| `app_scheduled_concurrent_job_limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of concurrent scheduled App Platform function jobs across all apps on this Leader (group-wide). Changes require a Leader restart. | +| `app_schedules_max` | *Optional[int]* | :heavy_minus_sign: | Maximum number of schedule records a single App may declare. | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | If true, enable Apps. Otherwise, false. | \ No newline at end of file diff --git a/docs/models/appstypesystemsettingsconf.md b/docs/models/appstypesystemsettingsconf.md index dc064a3de..ebac1c242 100644 --- a/docs/models/appstypesystemsettingsconf.md +++ b/docs/models/appstypesystemsettingsconf.md @@ -5,6 +5,13 @@ App configuration. ## Fields -| Field | Type | Required | Description | -| ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | ----------------------------------------------------------------- | -| `enabled` | *bool* | :heavy_check_mark: | If true, enable Apps. Otherwise, false. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `app_backend_broker_origin` | *Optional[str]* | :heavy_minus_sign: | Public origin for App Platform backend broker callbacks (standalone/on-prem only). Must be an absolute HTTP(S) URL. | +| `app_backend_max_callbacks_per_installation` | *Optional[int]* | :heavy_minus_sign: | Maximum number of broker callbacks per minute a single app backend installation may make. Over-limit callbacks receive HTTP 429. | +| `app_backend_max_callbacks_total` | *Optional[int]* | :heavy_minus_sign: | Maximum number of broker callbacks per minute across all app backend installations on this Leader. Unlimited when unset. Over-limit callbacks receive HTTP 429. | +| `app_backend_max_in_flight` | *Optional[int]* | :heavy_minus_sign: | Maximum number of concurrent App Platform backend invocations across all apps on this Leader. | +| `app_schedule_body_expression_max_length` | *Optional[int]* | :heavy_minus_sign: | Maximum number of characters allowed in a schedule bodyExpression. | +| `app_scheduled_concurrent_job_limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of concurrent scheduled App Platform function jobs across all apps on this Leader (group-wide). Changes require a Leader restart. | +| `app_schedules_max` | *Optional[int]* | :heavy_minus_sign: | Maximum number of schedule records a single App may declare. | +| `enabled` | *bool* | :heavy_check_mark: | If true, enable Apps. Otherwise, false. | \ No newline at end of file diff --git a/docs/models/authenticationmethodoptionsauthtokensextitems.md b/docs/models/authenticationmethodoptionsauthtokensextitems.md new file mode 100644 index 000000000..59844a40e --- /dev/null +++ b/docs/models/authenticationmethodoptionsauthtokensextitems.md @@ -0,0 +1,21 @@ +# AuthenticationMethodOptionsAuthTokensExtItems + +Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate + +## Example Usage + +```python +from cribl_control_plane.models import AuthenticationMethodOptionsAuthTokensExtItems + +value = AuthenticationMethodOptionsAuthTokensExtItems.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/authenticationmethodoptionsauthtokensitems.md b/docs/models/authenticationmethodoptionsauthtokensitems.md index 3937ebc9c..e1199d1fd 100644 --- a/docs/models/authenticationmethodoptionsauthtokensitems.md +++ b/docs/models/authenticationmethodoptionsauthtokensitems.md @@ -1,13 +1,13 @@ # AuthenticationMethodOptionsAuthTokensItems -Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate +Select Secret to use a text secret to authenticate ## Example Usage ```python from cribl_control_plane.models import AuthenticationMethodOptionsAuthTokensItems -value = AuthenticationMethodOptionsAuthTokensItems.MANUAL +value = AuthenticationMethodOptionsAuthTokensItems.SECRET # Open enum: unrecognized values are captured as UnrecognizedStr ``` @@ -17,5 +17,4 @@ value = AuthenticationMethodOptionsAuthTokensItems.MANUAL | Name | Value | | -------- | -------- | -| `MANUAL` | manual | | `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/authenticationmethodoptionsauthtokensitemssecret.md b/docs/models/authenticationmethodoptionsauthtokensitemssecret.md deleted file mode 100644 index d14e23c53..000000000 --- a/docs/models/authenticationmethodoptionsauthtokensitemssecret.md +++ /dev/null @@ -1,20 +0,0 @@ -# AuthenticationMethodOptionsAuthTokensItemsSecret - -Select Secret to use a text secret to authenticate - -## Example Usage - -```python -from cribl_control_plane.models import AuthenticationMethodOptionsAuthTokensItemsSecret - -value = AuthenticationMethodOptionsAuthTokensItemsSecret.SECRET - -# Open enum: unrecognized values are captured as UnrecognizedStr -``` - - -## Values - -| Name | Value | -| -------- | -------- | -| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/inputresponseinputeventhubamqpauthenticationmethod.md b/docs/models/authenticationmethodoptionsclientassertionclientassertionrpc.md similarity index 67% rename from docs/models/inputresponseinputeventhubamqpauthenticationmethod.md rename to docs/models/authenticationmethodoptionsclientassertionclientassertionrpc.md index 555a815c5..9cfe37684 100644 --- a/docs/models/inputresponseinputeventhubamqpauthenticationmethod.md +++ b/docs/models/authenticationmethodoptionsclientassertionclientassertionrpc.md @@ -1,13 +1,13 @@ -# InputResponseInputEventhubAmqpAuthenticationMethod +# AuthenticationMethodOptionsClientAssertionClientAssertionrpc Authentication method ## Example Usage ```python -from cribl_control_plane.models import InputResponseInputEventhubAmqpAuthenticationMethod +from cribl_control_plane.models import AuthenticationMethodOptionsClientAssertionClientAssertionrpc -value = InputResponseInputEventhubAmqpAuthenticationMethod.SECRET +value = AuthenticationMethodOptionsClientAssertionClientAssertionrpc.SECRET # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/authmethodsext.md b/docs/models/authmethodsext.md index f6213f7dc..5dcac0d35 100644 --- a/docs/models/authmethodsext.md +++ b/docs/models/authmethodsext.md @@ -13,4 +13,8 @@ | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | -| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | \ No newline at end of file +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `issuer` | *Optional[str]* | :heavy_minus_sign: | Expected token issuer (iss claim) | +| `jwks_uri` | *Optional[str]* | :heavy_minus_sign: | URL of the JWKS endpoint used to fetch signing keys | +| `audience` | *Optional[str]* | :heavy_minus_sign: | Expected token audience (aud claim) | +| `scopes` | List[*str*] | :heavy_minus_sign: | Scopes the token must grant (optional) | \ No newline at end of file diff --git a/docs/models/authmethodsextauthenticationtype.md b/docs/models/authmethodsextauthenticationtype.md index aa488bbe4..9788fac76 100644 --- a/docs/models/authmethodsextauthenticationtype.md +++ b/docs/models/authmethodsextauthenticationtype.md @@ -20,4 +20,5 @@ value = AuthMethodsExtAuthenticationType.TOKEN | `TOKEN` | token | | `TOKEN_SECRET` | tokenSecret | | `BASIC` | basic | -| `BASIC_SECRET` | basicSecret | \ No newline at end of file +| `BASIC_SECRET` | basicSecret | +| `OAUTH` | oauth | \ No newline at end of file diff --git a/docs/models/authtoken.md b/docs/models/authtoken.md index a3930945b..326f575f0 100644 --- a/docs/models/authtoken.md +++ b/docs/models/authtoken.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ----------------------- | ----------------------- | ----------------------- | ----------------------- | -| `force_password_change` | *bool* | :heavy_check_mark: | N/A | -| `token` | *str* | :heavy_check_mark: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `force_password_change` | *bool* | :heavy_check_mark: | If true, the user must change their password before accessing the API. Otherwise, false. | +| `token` | *str* | :heavy_check_mark: | Bearer token to include in the Authorization header for subsequent API requests. | \ No newline at end of file diff --git a/docs/models/authtokenconfinputcloudflarehec.md b/docs/models/authtokenconfinputcloudflarehec.md index 1bbf28903..8fe5f548a 100644 --- a/docs/models/authtokenconfinputcloudflarehec.md +++ b/docs/models/authtokenconfinputcloudflarehec.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItemsSecret]](../models/authenticationmethodoptionsauthtokensitemssecret.md) | :heavy_minus_sign: | Select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enable token | diff --git a/docs/models/authtokensext.md b/docs/models/authtokensext.md deleted file mode 100644 index 598b808f1..000000000 --- a/docs/models/authtokensext.md +++ /dev/null @@ -1,12 +0,0 @@ -# AuthTokensExt - - -## Fields - -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | -| `token` | *str* | :heavy_check_mark: | Token | -| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | -| `splunk_hec_metadata` | [Optional[models.SplunkHecMetadata]](../models/splunkhecmetadata.md) | :heavy_minus_sign: | N/A | -| `elasticsearch_metadata` | [Optional[models.ElasticsearchMetadata]](../models/elasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/authtokensextconfinputhttp.md b/docs/models/authtokensextconfinputhttp.md deleted file mode 100644 index 0d5bc4e0a..000000000 --- a/docs/models/authtokensextconfinputhttp.md +++ /dev/null @@ -1,10 +0,0 @@ -# AuthTokensExtConfInputHTTP - - -## Fields - -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | -| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | -| `description` | *Optional[str]* | :heavy_minus_sign: | Description | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/azureblobstorage.md b/docs/models/azureblobstorage.md index 6016a91e4..872c475c6 100644 --- a/docs/models/azureblobstorage.md +++ b/docs/models/azureblobstorage.md @@ -8,7 +8,7 @@ Azure Blob Storage | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `container_name` | *str* | :heavy_check_mark: | Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens. | -| `auth_type` | [Optional[models.InputEventhubAmqpAuthenticationMethod]](../models/inputeventhubamqpauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | diff --git a/docs/models/backendid.md b/docs/models/backendid.md new file mode 100644 index 000000000..31d3c382a --- /dev/null +++ b/docs/models/backendid.md @@ -0,0 +1,19 @@ +# BackendID + +## Example Usage + +```python +from cribl_control_plane.models import BackendID + +value = BackendID.DYNAMIC + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `DYNAMIC` | dynamic | +| `BYO` | byo | \ No newline at end of file diff --git a/docs/models/branchinfo.md b/docs/models/branchinfo.md index 4457d94ba..6596077f4 100644 --- a/docs/models/branchinfo.md +++ b/docs/models/branchinfo.md @@ -3,6 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| ------------------ | ------------------ | ------------------ | ------------------ | -| `id` | *str* | :heavy_check_mark: | Unique identifier. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | +| `id` | *str* | :heavy_check_mark: | Unique identifier. | \ No newline at end of file diff --git a/docs/models/bucketwidth.md b/docs/models/bucketwidth.md new file mode 100644 index 000000000..8c26e7e8f --- /dev/null +++ b/docs/models/bucketwidth.md @@ -0,0 +1,22 @@ +# BucketWidth + +Time bucket size for aggregated results. Smaller buckets yield more events per collection run. + +## Example Usage + +```python +from cribl_control_plane.models import BucketWidth + +value = BucketWidth.ONED + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------ | ------ | +| `ONED` | 1d | +| `ONEH` | 1h | +| `ONEM` | 1m | \ No newline at end of file diff --git a/docs/models/certoptions.md b/docs/models/certoptions.md new file mode 100644 index 000000000..448b28646 --- /dev/null +++ b/docs/models/certoptions.md @@ -0,0 +1,11 @@ +# CertOptions + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of a predefined certificate | +| `priv_key_path` | *str* | :heavy_check_mark: | Path to the private key (PEM format). Can reference $ENV_VARS. | +| `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to decrypt the private key | +| `cert_path` | *str* | :heavy_check_mark: | Path to the certificate (PEM format). Can reference $ENV_VARS. | \ No newline at end of file diff --git a/docs/models/chatmessages.md b/docs/models/chatmessages.md index b039ff5a3..620f07a86 100644 --- a/docs/models/chatmessages.md +++ b/docs/models/chatmessages.md @@ -5,14 +5,14 @@ Chat Messages ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.ChatMessagesManageState]](../models/chatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.ChatMessagesManageState]](../models/chatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/chats.md b/docs/models/chats.md index 0cb02a9b2..2e7cea191 100644 --- a/docs/models/chats.md +++ b/docs/models/chats.md @@ -5,14 +5,14 @@ Chats ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.ChatsManageState]](../models/chatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.ChatsManageState]](../models/chatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/conditionspecificconfigurations1.md b/docs/models/conditionspecificconfigurations1.md deleted file mode 100644 index 18e318068..000000000 --- a/docs/models/conditionspecificconfigurations1.md +++ /dev/null @@ -1,9 +0,0 @@ -# ConditionSpecificConfigurations1 - -Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. - - -## Fields - -| Field | Type | Required | Description | -| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/conditionspecificconfigurations2.md b/docs/models/conditionspecificconfigurations2.md deleted file mode 100644 index 24bafb5ab..000000000 --- a/docs/models/conditionspecificconfigurations2.md +++ /dev/null @@ -1,9 +0,0 @@ -# ConditionSpecificConfigurations2 - -Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. - - -## Fields - -| Field | Type | Required | Description | -| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/conditionspecificconfigurations3.md b/docs/models/conditionspecificconfigurations3.md deleted file mode 100644 index de115e77c..000000000 --- a/docs/models/conditionspecificconfigurations3.md +++ /dev/null @@ -1,9 +0,0 @@ -# ConditionSpecificConfigurations3 - -Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. - - -## Fields - -| Field | Type | Required | Description | -| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/confidence.md b/docs/models/confidence.md new file mode 100644 index 000000000..53a0381b5 --- /dev/null +++ b/docs/models/confidence.md @@ -0,0 +1,22 @@ +# Confidence + +Confidence level to assign to the Detection Rule. + +## Example Usage + +```python +from cribl_control_plane.models import Confidence + +value = Confidence.CONFIDENCE_ID_ONE + +# Open enum: unrecognized values are captured as UnrecognizedInt +``` + + +## Values + +| Name | Value | +| --------------------- | --------------------- | +| `CONFIDENCE_ID_ONE` | 1 | +| `CONFIDENCE_ID_TWO` | 2 | +| `CONFIDENCE_ID_THREE` | 3 | \ No newline at end of file diff --git a/docs/models/configgroup.md b/docs/models/configgroup.md index a6b6cd971..7b7c6002e 100644 --- a/docs/models/configgroup.md +++ b/docs/models/configgroup.md @@ -7,6 +7,8 @@ Configuration settings and dynamic status for a Worker Group, Outpost Group, or | Field | Type | Required | Description | Example | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | | | `cloud` | [Optional[models.ConfigGroupCloud]](../models/configgroupcloud.md) | :heavy_minus_sign: | N/A | | | `collectors_ha_enabled` | *Optional[bool]* | :heavy_minus_sign: | Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. | | | `config_version` | *Optional[str]* | :heavy_minus_sign: | Commit hash of the deployed configuration version for the Worker Group, Outpost Group, or Edge Fleet. Automatically populated and returned in responses.

**Warning**: Do not change the value of configVersion in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response. | | diff --git a/docs/models/configgrouplookupslookup.md b/docs/models/configgrouplookupslookup.md index 4d05524ed..32160b85a 100644 --- a/docs/models/configgrouplookupslookup.md +++ b/docs/models/configgrouplookupslookup.md @@ -5,6 +5,7 @@ | Field | Type | Required | Description | | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | -------------------------------------------------------------------- | +| `deploy_mode` | [Optional[models.DeployMode]](../models/deploymode.md) | :heavy_minus_sign: | Deploy mode configured on the lookup file. | | `deployed_version` | *Optional[str]* | :heavy_minus_sign: | Version of the lookup file currently deployed on the Worker or Node. | | `file` | *str* | :heavy_check_mark: | File name of the deployed lookup. | | `version` | *Optional[str]* | :heavy_minus_sign: | Version of the lookup file currently staged for deployment. | \ No newline at end of file diff --git a/docs/models/contentconfiginput.md b/docs/models/contentconfiginput.md index 975cca67b..2cd8dc3fc 100644 --- a/docs/models/contentconfiginput.md +++ b/docs/models/contentconfiginput.md @@ -3,23 +3,23 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.InputOpenaiManageState]](../models/inputopenaimanagestate.md) | :heavy_minus_sign: | N/A | -| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | -| `pagination_type` | [models.PaginationType](../models/paginationtype.md) | :heavy_check_mark: | Pagination type | -| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | -| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | -| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | -| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | -| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | -| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | -| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | -| `latest` | *str* | :heavy_check_mark: | Relative to the current time | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `log_level` | [Optional[models.InputOpenaiLogLevel]](../models/inputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | -| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.InputOpenaiManageState]](../models/inputopenaimanagestate.md) | :heavy_minus_sign: | N/A | +| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | +| `pagination_type` | [models.PaginationType](../models/paginationtype.md) | :heavy_check_mark: | Pagination type | +| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | +| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | +| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | +| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | +| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | +| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | +| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | +| `latest` | *str* | :heavy_check_mark: | Relative to the current time | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `log_level` | [Optional[models.InputOpenaiLogLevel]](../models/inputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | +| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file diff --git a/docs/models/contenttype.md b/docs/models/contenttype.md new file mode 100644 index 000000000..d87290669 --- /dev/null +++ b/docs/models/contenttype.md @@ -0,0 +1,21 @@ +# ContentType + +Content type + +## Example Usage + +```python +from cribl_control_plane.models import ContentType + +value = ContentType.USAGE_REPORT + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `USAGE_REPORT` | Usage Report | +| `COST_REPORT` | Cost Report | \ No newline at end of file diff --git a/docs/models/countedboolean.md b/docs/models/countedboolean.md index e656fa4f3..ba8800594 100644 --- a/docs/models/countedboolean.md +++ b/docs/models/countedboolean.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[*bool*] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[*bool*] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedbranchinfo.md b/docs/models/countedbranchinfo.md index 1cfa61d15..9ef8153c2 100644 --- a/docs/models/countedbranchinfo.md +++ b/docs/models/countedbranchinfo.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------- | -------------------------------------------------- | -------------------------------------------------- | -------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.BranchInfo](../models/branchinfo.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.BranchInfo](../models/branchinfo.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedconfiggroup.md b/docs/models/countedconfiggroup.md index 5fa74b700..4ff44f1b9 100644 --- a/docs/models/countedconfiggroup.md +++ b/docs/models/countedconfiggroup.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.ConfigGroup](../models/configgroup.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.ConfigGroup](../models/configgroup.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedcribllakedataset.md b/docs/models/countedcribllakedataset.md index 6dd0451aa..e86e3ec25 100644 --- a/docs/models/countedcribllakedataset.md +++ b/docs/models/countedcribllakedataset.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.CriblLakeDataset](../models/cribllakedataset.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.CriblLakeDataset](../models/cribllakedataset.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedfunctionresponse.md b/docs/models/countedfunctionresponse.md index 6b75dd53b..523bd5cd1 100644 --- a/docs/models/countedfunctionresponse.md +++ b/docs/models/countedfunctionresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.FunctionResponse](../models/functionresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.FunctionResponse](../models/functionresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitcommitsummary.md b/docs/models/countedgitcommitsummary.md index 4f124601e..77f2d969b 100644 --- a/docs/models/countedgitcommitsummary.md +++ b/docs/models/countedgitcommitsummary.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitCommitSummary](../models/gitcommitsummary.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitCommitSummary](../models/gitcommitsummary.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitcountresult.md b/docs/models/countedgitcountresult.md index 4a1400de5..2b0608f09 100644 --- a/docs/models/countedgitcountresult.md +++ b/docs/models/countedgitcountresult.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitCountResult](../models/gitcountresult.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitCountResult](../models/gitcountresult.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitdiffresult.md b/docs/models/countedgitdiffresult.md index ed38a77ca..8fbd57014 100644 --- a/docs/models/countedgitdiffresult.md +++ b/docs/models/countedgitdiffresult.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitDiffResult](../models/gitdiffresult.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitDiffResult](../models/gitdiffresult.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitfilesresponse.md b/docs/models/countedgitfilesresponse.md index 2e5f017b0..e0a87ed57 100644 --- a/docs/models/countedgitfilesresponse.md +++ b/docs/models/countedgitfilesresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitFilesResponse](../models/gitfilesresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitFilesResponse](../models/gitfilesresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitinfo.md b/docs/models/countedgitinfo.md index 3e8505d48..b9e1e1646 100644 --- a/docs/models/countedgitinfo.md +++ b/docs/models/countedgitinfo.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitInfo](../models/gitinfo.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitInfo](../models/gitinfo.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitrevertresult.md b/docs/models/countedgitrevertresult.md index b472d8d60..2ccc9143b 100644 --- a/docs/models/countedgitrevertresult.md +++ b/docs/models/countedgitrevertresult.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitRevertResult](../models/gitrevertresult.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitRevertResult](../models/gitrevertresult.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitshowresult.md b/docs/models/countedgitshowresult.md index 72734c07e..7f2e49bc7 100644 --- a/docs/models/countedgitshowresult.md +++ b/docs/models/countedgitshowresult.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitShowResult](../models/gitshowresult.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitShowResult](../models/gitshowresult.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedgitstatusresult.md b/docs/models/countedgitstatusresult.md index 638487a9b..f2eea79bc 100644 --- a/docs/models/countedgitstatusresult.md +++ b/docs/models/countedgitstatusresult.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.GitStatusResult](../models/gitstatusresult.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.GitStatusResult](../models/gitstatusresult.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedinputresponse.md b/docs/models/countedinputresponse.md index 66b789d4f..73ca537cb 100644 --- a/docs/models/countedinputresponse.md +++ b/docs/models/countedinputresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.InputResponse](../models/inputresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.InputResponse](../models/inputresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedinputsplunkhec.md b/docs/models/countedinputsplunkhec.md index 4919217b1..8d29282aa 100644 --- a/docs/models/countedinputsplunkhec.md +++ b/docs/models/countedinputsplunkhec.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.InputSplunkHec](../models/inputsplunkhec.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.InputSplunkHec](../models/inputsplunkhec.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedinputstatus.md b/docs/models/countedinputstatus.md index e3436ba4a..668b43e3d 100644 --- a/docs/models/countedinputstatus.md +++ b/docs/models/countedinputstatus.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.InputStatus](../models/inputstatus.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.InputStatus](../models/inputstatus.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedjobinfo.md b/docs/models/countedjobinfo.md index a0d848b9d..5264a9837 100644 --- a/docs/models/countedjobinfo.md +++ b/docs/models/countedjobinfo.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.JobInfo](../models/jobinfo.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.JobInfo](../models/jobinfo.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedmasterworkerentry.md b/docs/models/countedmasterworkerentry.md index 546a32185..69d98a1c9 100644 --- a/docs/models/countedmasterworkerentry.md +++ b/docs/models/countedmasterworkerentry.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.MasterWorkerEntry](../models/masterworkerentry.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.MasterWorkerEntry](../models/masterworkerentry.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countednumber.md b/docs/models/countednumber.md index 9b5fc1ba5..eb1a64fe1 100644 --- a/docs/models/countednumber.md +++ b/docs/models/countednumber.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[*float*] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[*float*] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedoutputresponse.md b/docs/models/countedoutputresponse.md index ada5828ff..618d12d27 100644 --- a/docs/models/countedoutputresponse.md +++ b/docs/models/countedoutputresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.OutputResponse](../models/outputresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.OutputResponse](../models/outputresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedoutputsamplesresponse.md b/docs/models/countedoutputsamplesresponse.md index 318732b83..fb55729fd 100644 --- a/docs/models/countedoutputsamplesresponse.md +++ b/docs/models/countedoutputsamplesresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.OutputSamplesResponse](../models/outputsamplesresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.OutputSamplesResponse](../models/outputsamplesresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedoutputstatus.md b/docs/models/countedoutputstatus.md index 07fbfeb93..cd3c0d45f 100644 --- a/docs/models/countedoutputstatus.md +++ b/docs/models/countedoutputstatus.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.OutputStatus](../models/outputstatus.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.OutputStatus](../models/outputstatus.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedoutputtestresponse.md b/docs/models/countedoutputtestresponse.md index f53240b43..1ef7d02ce 100644 --- a/docs/models/countedoutputtestresponse.md +++ b/docs/models/countedoutputtestresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.OutputTestResponse](../models/outputtestresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.OutputTestResponse](../models/outputtestresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedpackinfo.md b/docs/models/countedpackinfo.md index ca7e6ee33..857a83170 100644 --- a/docs/models/countedpackinfo.md +++ b/docs/models/countedpackinfo.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.PackInfo](../models/packinfo.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.PackInfo](../models/packinfo.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedpackinstallinfo.md b/docs/models/countedpackinstallinfo.md index f1fbfb000..6bfc105ce 100644 --- a/docs/models/countedpackinstallinfo.md +++ b/docs/models/countedpackinstallinfo.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.PackInstallInfo](../models/packinstallinfo.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.PackInstallInfo](../models/packinstallinfo.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedpackuninstallinfo.md b/docs/models/countedpackuninstallinfo.md index bfbcd1b2e..b0e246a85 100644 --- a/docs/models/countedpackuninstallinfo.md +++ b/docs/models/countedpackuninstallinfo.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.PackUninstallInfo](../models/packuninstallinfo.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.PackUninstallInfo](../models/packuninstallinfo.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedpipeline.md b/docs/models/countedpipeline.md index aa53a7997..a605e682b 100644 --- a/docs/models/countedpipeline.md +++ b/docs/models/countedpipeline.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | ---------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.Pipeline](../models/pipeline.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.Pipeline](../models/pipeline.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedrestartresponse.md b/docs/models/countedrestartresponse.md index 1cb142643..d4c265491 100644 --- a/docs/models/countedrestartresponse.md +++ b/docs/models/countedrestartresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | ------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.RestartResponse](../models/restartresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.RestartResponse](../models/restartresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedroutes.md b/docs/models/countedroutes.md index 32c0dc772..94866a9d3 100644 --- a/docs/models/countedroutes.md +++ b/docs/models/countedroutes.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.Routes](../models/routes.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.Routes](../models/routes.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedsavedjobresponse.md b/docs/models/countedsavedjobresponse.md index 5b5f07479..481d5c4f8 100644 --- a/docs/models/countedsavedjobresponse.md +++ b/docs/models/countedsavedjobresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.SavedJobResponse](../models/savedjobresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.SavedJobResponse](../models/savedjobresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedstring.md b/docs/models/countedstring.md index 8ba0f58fc..26c9bbcf1 100644 --- a/docs/models/countedstring.md +++ b/docs/models/countedstring.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | ------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[*str*] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | -------------------------------------------- | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[*str*] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedsystemrestartresponse.md b/docs/models/countedsystemrestartresponse.md index 92565fec0..56aa1cd26 100644 --- a/docs/models/countedsystemrestartresponse.md +++ b/docs/models/countedsystemrestartresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.SystemRestartResponse](../models/systemrestartresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.SystemRestartResponse](../models/systemrestartresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedsystemsettingsconf.md b/docs/models/countedsystemsettingsconf.md index 5f6c21ebf..f41701027 100644 --- a/docs/models/countedsystemsettingsconf.md +++ b/docs/models/countedsystemsettingsconf.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.SystemSettingsConf](../models/systemsettingsconf.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.SystemSettingsConf](../models/systemsettingsconf.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedsystemsettingsconfresponse.md b/docs/models/countedsystemsettingsconfresponse.md index 4c8e241ce..662bce501 100644 --- a/docs/models/countedsystemsettingsconfresponse.md +++ b/docs/models/countedsystemsettingsconfresponse.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------- | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.SystemSettingsConfResponse](../models/systemsettingsconfresponse.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.SystemSettingsConfResponse](../models/systemsettingsconfresponse.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/countedteamaccesscontrollist.md b/docs/models/countedteamaccesscontrollist.md index 03310fadb..45919fa25 100644 --- a/docs/models/countedteamaccesscontrollist.md +++ b/docs/models/countedteamaccesscontrollist.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.TeamAccessControlList](../models/teamaccesscontrollist.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.TeamAccessControlList](../models/teamaccesscontrollist.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/counteduseraccesscontrollist.md b/docs/models/counteduseraccesscontrollist.md index c1fe729cd..c512f3167 100644 --- a/docs/models/counteduseraccesscontrollist.md +++ b/docs/models/counteduseraccesscontrollist.md @@ -5,5 +5,5 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | ------------------------------------------------------------------------ | -| `count` | *int* | :heavy_check_mark: | number of items present in the items array | -| `items` | List[[models.UserAccessControlList](../models/useraccesscontrollist.md)] | :heavy_check_mark: | List of items in this response. | \ No newline at end of file +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `items` | List[[models.UserAccessControlList](../models/useraccesscontrollist.md)] | :heavy_check_mark: | The list of items returned in this response. | \ No newline at end of file diff --git a/docs/models/createcribllakedatasetbylakeidrequest.md b/docs/models/createcribllakedatasetbylakeidrequest.md index 7ba219bc7..513318877 100644 --- a/docs/models/createcribllakedatasetbylakeidrequest.md +++ b/docs/models/createcribllakedatasetbylakeidrequest.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake to create the Lake Dataset in. | -| `cribl_lake_dataset` | [models.CriblLakeDataset](../models/cribllakedataset.md) | :heavy_check_mark: | CriblLakeDataset object. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------- | --------------------------------------------------------------- | --------------------------------------------------------------- | --------------------------------------------------------------- | +| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake to create the Lake Datasets in. | +| `cribl_lake_dataset` | [models.CriblLakeDataset](../models/cribllakedataset.md) | :heavy_check_mark: | CriblLakeDataset object. | \ No newline at end of file diff --git a/docs/models/createinputactivities.md b/docs/models/createinputactivities.md index 590cbd3de..ae2939085 100644 --- a/docs/models/createinputactivities.md +++ b/docs/models/createinputactivities.md @@ -5,14 +5,14 @@ Activities ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputActivitiesManageState]](../models/createinputactivitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputActivitiesManageState]](../models/createinputactivitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputauthmethodsext.md b/docs/models/createinputauthmethodsext.md index 9607a3055..543e246fc 100644 --- a/docs/models/createinputauthmethodsext.md +++ b/docs/models/createinputauthmethodsext.md @@ -13,4 +13,8 @@ | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | -| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | \ No newline at end of file +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `issuer` | *Optional[str]* | :heavy_minus_sign: | Expected token issuer (iss claim) | +| `jwks_uri` | *Optional[str]* | :heavy_minus_sign: | URL of the JWKS endpoint used to fetch signing keys | +| `audience` | *Optional[str]* | :heavy_minus_sign: | Expected token audience (aud claim) | +| `scopes` | List[*str*] | :heavy_minus_sign: | Scopes the token must grant (optional) | \ No newline at end of file diff --git a/docs/models/createinputauthmethodsextauthenticationtype.md b/docs/models/createinputauthmethodsextauthenticationtype.md index 23b715282..fc6db747e 100644 --- a/docs/models/createinputauthmethodsextauthenticationtype.md +++ b/docs/models/createinputauthmethodsextauthenticationtype.md @@ -20,4 +20,5 @@ value = CreateInputAuthMethodsExtAuthenticationType.TOKEN | `TOKEN` | token | | `TOKEN_SECRET` | tokenSecret | | `BASIC` | basic | -| `BASIC_SECRET` | basicSecret | \ No newline at end of file +| `BASIC_SECRET` | basicSecret | +| `OAUTH` | oauth | \ No newline at end of file diff --git a/docs/models/createinputauthtokensext.md b/docs/models/createinputauthtokensext.md deleted file mode 100644 index 9bea84176..000000000 --- a/docs/models/createinputauthtokensext.md +++ /dev/null @@ -1,12 +0,0 @@ -# CreateInputAuthTokensExt - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `token` | *str* | :heavy_check_mark: | Token | -| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | -| `splunk_hec_metadata` | [Optional[models.CreateInputSplunkHecMetadata]](../models/createinputsplunkhecmetadata.md) | :heavy_minus_sign: | N/A | -| `elasticsearch_metadata` | [Optional[models.CreateInputElasticsearchMetadata]](../models/createinputelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputazureblobstorage.md b/docs/models/createinputazureblobstorage.md index ac57cf919..e2ef826c9 100644 --- a/docs/models/createinputazureblobstorage.md +++ b/docs/models/createinputazureblobstorage.md @@ -8,7 +8,7 @@ Azure Blob Storage | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `container_name` | *str* | :heavy_check_mark: | Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens. | -| `auth_type` | [Optional[models.CreateInputInputEventhubAmqpAuthenticationMethod]](../models/createinputinputeventhubamqpauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | diff --git a/docs/models/createinputbucketwidth.md b/docs/models/createinputbucketwidth.md new file mode 100644 index 000000000..0b3a5f886 --- /dev/null +++ b/docs/models/createinputbucketwidth.md @@ -0,0 +1,22 @@ +# CreateInputBucketWidth + +Time bucket size for aggregated results. Smaller buckets yield more events per collection run. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputBucketWidth + +value = CreateInputBucketWidth.ONED + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------ | ------ | +| `ONED` | 1d | +| `ONEH` | 1h | +| `ONEM` | 1m | \ No newline at end of file diff --git a/docs/models/createinputcertoptions.md b/docs/models/createinputcertoptions.md new file mode 100644 index 000000000..955a00f39 --- /dev/null +++ b/docs/models/createinputcertoptions.md @@ -0,0 +1,11 @@ +# CreateInputCertOptions + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of a predefined certificate | +| `priv_key_path` | *str* | :heavy_check_mark: | Path to the private key (PEM format). Can reference $ENV_VARS. | +| `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to decrypt the private key | +| `cert_path` | *str* | :heavy_check_mark: | Path to the certificate (PEM format). Can reference $ENV_VARS. | \ No newline at end of file diff --git a/docs/models/createinputchatmessages.md b/docs/models/createinputchatmessages.md index c9bc5dc6d..01f7de8fb 100644 --- a/docs/models/createinputchatmessages.md +++ b/docs/models/createinputchatmessages.md @@ -5,14 +5,14 @@ Chat Messages ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputChatMessagesManageState]](../models/createinputchatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputChatMessagesManageState]](../models/createinputchatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputchats.md b/docs/models/createinputchats.md index 2f092ecef..17bc0367f 100644 --- a/docs/models/createinputchats.md +++ b/docs/models/createinputchats.md @@ -5,14 +5,14 @@ Chats ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputChatsManageState]](../models/createinputchatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputChatsManageState]](../models/createinputchatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputcontenttype.md b/docs/models/createinputcontenttype.md new file mode 100644 index 000000000..a61170d7e --- /dev/null +++ b/docs/models/createinputcontenttype.md @@ -0,0 +1,21 @@ +# CreateInputContentType + +Content type + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputContentType + +value = CreateInputContentType.USAGE_REPORT + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `USAGE_REPORT` | Usage Report | +| `COST_REPORT` | Cost Report | \ No newline at end of file diff --git a/docs/models/createinputfeedtype.md b/docs/models/createinputfeedtype.md new file mode 100644 index 000000000..46e9221c8 --- /dev/null +++ b/docs/models/createinputfeedtype.md @@ -0,0 +1,22 @@ +# CreateInputFeedType + +Proofpoint on Demand feed to ingest. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputFeedType + +value = CreateInputFeedType.MESSAGE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `MESSAGE` | message | +| `MAILLOG` | maillog | +| `AUDIT` | audit | \ No newline at end of file diff --git a/docs/models/createinputgroupby.md b/docs/models/createinputgroupby.md new file mode 100644 index 000000000..e2357c862 --- /dev/null +++ b/docs/models/createinputgroupby.md @@ -0,0 +1,27 @@ +# CreateInputGroupBy + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputGroupBy + +value = CreateInputGroupBy.MODEL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------ | ------------------ | +| `MODEL` | model | +| `PRODUCT` | product | +| `CONTEXT_WINDOW` | context_window | +| `INFERENCE_GEO` | inference_geo | +| `SPEED` | speed | +| `RBAC_GROUP_ID` | rbac_group_id | +| `SLACK_CHANNEL_ID` | slack_channel_id | +| `TEAMS_CHANNEL_ID` | teams_channel_id | +| `COST_TYPE` | cost_type | +| `TOKEN_TYPE` | token_type | \ No newline at end of file diff --git a/docs/models/createinputinput.md b/docs/models/createinputinput.md index 23cf508cf..9af14cf84 100644 --- a/docs/models/createinputinput.md +++ b/docs/models/createinputinput.md @@ -53,6 +53,12 @@ value: models.CreateInputInputSplunkHec = /* values here */ value: models.CreateInputInputAzureBlob = /* values here */ ``` +### `models.CreateInputInputAzureVnetFlowLog` + +```python +value: models.CreateInputInputAzureVnetFlowLog = /* values here */ +``` + ### `models.CreateInputInputElastic` ```python @@ -389,6 +395,12 @@ value: models.CreateInputInputBedrockS3 = /* values here */ value: models.CreateInputInputServicenowTable = /* values here */ ``` +### `models.CreateInputInputProofpointPod` + +```python +value: models.CreateInputInputProofpointPod = /* values here */ +``` + ### `models.CreateInputInputZscalerHec` ```python @@ -413,6 +425,30 @@ value: models.CreateInputInputSysdigHec = /* values here */ value: models.CreateInputInputUpwindHec = /* values here */ ``` +### `models.CreateInputInputTrellixHec` + +```python +value: models.CreateInputInputTrellixHec = /* values here */ +``` + +### `models.CreateInputInputSailpointHec` + +```python +value: models.CreateInputInputSailpointHec = /* values here */ +``` + +### `models.CreateInputInputExtrahopRevealx360` + +```python +value: models.CreateInputInputExtrahopRevealx360 = /* values here */ +``` + +### `models.CreateInputInputAquaSecurityHec` + +```python +value: models.CreateInputInputAquaSecurityHec = /* values here */ +``` + ### `models.CreateInputInputOpenaiComplianceLogs` ```python @@ -425,9 +461,75 @@ value: models.CreateInputInputOpenaiComplianceLogs = /* values here */ value: models.CreateInputInputAnthropicCompliance = /* values here */ ``` +### `models.CreateInputInputAnthropicEnterpriseAnalytics` + +```python +value: models.CreateInputInputAnthropicEnterpriseAnalytics = /* values here */ +``` + +### `models.CreateInputInputMicrosoftCopilot` + +```python +value: models.CreateInputInputMicrosoftCopilot = /* values here */ +``` + ### `models.CreateInputInputOkta` ```python value: models.CreateInputInputOkta = /* values here */ ``` +### `models.CreateInputInputAkamaiHec` + +```python +value: models.CreateInputInputAkamaiHec = /* values here */ +``` + +### `models.CreateInputInputPingIdentityPingone` + +```python +value: models.CreateInputInputPingIdentityPingone = /* values here */ +``` + +### `models.CreateInputInputGigamonHec` + +```python +value: models.CreateInputInputGigamonHec = /* values here */ +``` + +### `models.CreateInputInputVectraAiHec` + +```python +value: models.CreateInputInputVectraAiHec = /* values here */ +``` + +### `models.CreateInputInputF5BigIP` + +```python +value: models.CreateInputInputF5BigIP = /* values here */ +``` + +### `models.CreateInputInputBeyondtrustHec` + +```python +value: models.CreateInputInputBeyondtrustHec = /* values here */ +``` + +### `models.CreateInputInputHashicorpHcpVaultDedicated` + +```python +value: models.CreateInputInputHashicorpHcpVaultDedicated = /* values here */ +``` + +### `models.CreateInputInputMimecastHec` + +```python +value: models.CreateInputInputMimecastHec = /* values here */ +``` + +### `models.CreateInputInputTrendMicroVisionOne` + +```python +value: models.CreateInputInputTrendMicroVisionOne = /* values here */ +``` + diff --git a/docs/models/createinputinputakamaihec.md b/docs/models/createinputinputakamaihec.md new file mode 100644 index 000000000..5d967ae02 --- /dev/null +++ b/docs/models/createinputinputakamaihec.md @@ -0,0 +1,40 @@ +# CreateInputInputAkamaiHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputAkamaiHecType](../models/createinputinputakamaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputakamaihectype.md b/docs/models/createinputinputakamaihectype.md new file mode 100644 index 000000000..f3965b482 --- /dev/null +++ b/docs/models/createinputinputakamaihectype.md @@ -0,0 +1,18 @@ +# CreateInputInputAkamaiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputAkamaiHecType + +value = CreateInputInputAkamaiHecType.AKAMAI_HEC +``` + + +## Values + +| Name | Value | +| ------------ | ------------ | +| `AKAMAI_HEC` | akamai_hec | \ No newline at end of file diff --git a/docs/models/createinputinputanthropicenterpriseanalytics.md b/docs/models/createinputinputanthropicenterpriseanalytics.md new file mode 100644 index 000000000..0b956ef1e --- /dev/null +++ b/docs/models/createinputinputanthropicenterpriseanalytics.md @@ -0,0 +1,32 @@ +# CreateInputInputAnthropicEnterpriseAnalytics + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputAnthropicEnterpriseAnalyticsType](../models/createinputinputanthropicenterpriseanalyticstype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `api_key` | *Optional[str]* | :heavy_minus_sign: | API key | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored API key with read:analytics scope | +| `content_config` | List[[models.CreateInputInputAnthropicEnterpriseAnalyticsContentConfig](../models/createinputinputanthropicenterpriseanalyticscontentconfig.md)] | :heavy_check_mark: | Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout. Use 0 to disable. | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.RetryRulesType]](../models/retryrulestype.md) | :heavy_minus_sign: | N/A | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputanthropicenterpriseanalyticscontentconfig.md b/docs/models/createinputinputanthropicenterpriseanalyticscontentconfig.md new file mode 100644 index 000000000..0c8967b0b --- /dev/null +++ b/docs/models/createinputinputanthropicenterpriseanalyticscontentconfig.md @@ -0,0 +1,18 @@ +# CreateInputInputAnthropicEnterpriseAnalyticsContentConfig + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `content_type` | [models.CreateInputContentType](../models/createinputcontenttype.md) | :heavy_check_mark: | Content type | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark. | +| `manage_state` | *Optional[bool]* | :heavy_minus_sign: | Manage state | +| `group_by` | List[[models.CreateInputGroupBy](../models/createinputgroupby.md)] | :heavy_minus_sign: | Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket. | +| `bucket_width` | [Optional[models.CreateInputBucketWidth]](../models/createinputbucketwidth.md) | :heavy_minus_sign: | Time bucket size for aggregated results. Smaller buckets yield more events per collection run. | +| `cron_schedule` | *str* | :heavy_check_mark: | Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results. | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d. | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | \ No newline at end of file diff --git a/docs/models/createinputinputanthropicenterpriseanalyticstype.md b/docs/models/createinputinputanthropicenterpriseanalyticstype.md new file mode 100644 index 000000000..98fea8001 --- /dev/null +++ b/docs/models/createinputinputanthropicenterpriseanalyticstype.md @@ -0,0 +1,18 @@ +# CreateInputInputAnthropicEnterpriseAnalyticsType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputAnthropicEnterpriseAnalyticsType + +value = CreateInputInputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS +``` + + +## Values + +| Name | Value | +| -------------------------------- | -------------------------------- | +| `ANTHROPIC_ENTERPRISE_ANALYTICS` | anthropic_enterprise_analytics | \ No newline at end of file diff --git a/docs/models/createinputinputappscope.md b/docs/models/createinputinputappscope.md index fb534f87e..4a876e13e 100644 --- a/docs/models/createinputinputappscope.md +++ b/docs/models/createinputinputappscope.md @@ -27,7 +27,7 @@ | `enable_unix_path` | *Optional[bool]* | :heavy_minus_sign: | Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port. | | `filter_` | [Optional[models.CreateInputInputAppscopeFilter]](../models/createinputinputappscopefilter.md) | :heavy_minus_sign: | N/A | | `persistence` | [Optional[models.CreateInputInputAppscopePersistence]](../models/createinputinputappscopepersistence.md) | :heavy_minus_sign: | Persistence | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | | `port` | *Optional[float]* | :heavy_minus_sign: | Port to listen on | diff --git a/docs/models/createinputinputaquasecurityhec.md b/docs/models/createinputinputaquasecurityhec.md new file mode 100644 index 000000000..438dd63e4 --- /dev/null +++ b/docs/models/createinputinputaquasecurityhec.md @@ -0,0 +1,46 @@ +# CreateInputInputAquaSecurityHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputAquaSecurityHecType](../models/createinputinputaquasecurityhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputaquasecurityhectype.md b/docs/models/createinputinputaquasecurityhectype.md new file mode 100644 index 000000000..88ee0b24b --- /dev/null +++ b/docs/models/createinputinputaquasecurityhectype.md @@ -0,0 +1,18 @@ +# CreateInputInputAquaSecurityHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputAquaSecurityHecType + +value = CreateInputInputAquaSecurityHecType.AQUA_SECURITY_HEC +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `AQUA_SECURITY_HEC` | aqua_security_hec | \ No newline at end of file diff --git a/docs/models/createinputinputazureblob.md b/docs/models/createinputinputazureblob.md index 890b024d9..90087aa95 100644 --- a/docs/models/createinputinputazureblob.md +++ b/docs/models/createinputinputazureblob.md @@ -22,12 +22,14 @@ | `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | | `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | | `skip_on_error` | *Optional[bool]* | :heavy_minus_sign: | Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors. | +| `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `parquet_chunk_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum file size for each Parquet chunk | | `parquet_chunk_download_timeout` | *Optional[float]* | :heavy_minus_sign: | The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified. | | `auth_type` | [Optional[models.AuthenticationMethodOptions]](../models/authenticationmethodoptions.md) | :heavy_minus_sign: | Authentication method | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `connection_string` | *Optional[str]* | :heavy_minus_sign: | Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | diff --git a/docs/models/createinputinputazurevnetflowlog.md b/docs/models/createinputinputazurevnetflowlog.md new file mode 100644 index 000000000..53da380ce --- /dev/null +++ b/docs/models/createinputinputazurevnetflowlog.md @@ -0,0 +1,44 @@ +# CreateInputInputAzureVnetFlowLog + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputAzureVnetFlowLogType](../models/createinputinputazurevnetflowlogtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `queue_name` | *str* | :heavy_check_mark: | The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}` | +| `file_filter` | *Optional[str]* | :heavy_minus_sign: | Regex matching file names to download and process. Defaults to: .* | +| `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request. | +| `num_receivers` | *Optional[float]* | :heavy_minus_sign: | How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead. | +| `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | +| `max_dequeue_count` | *Optional[float]* | :heavy_minus_sign: | Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers. | +| `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | +| `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | +| `client_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's client ID | +| `azure_cloud` | *Optional[str]* | :heavy_minus_sign: | The Azure cloud to use. Defaults to Azure Public Cloud. | +| `endpoint_suffix` | *Optional[str]* | :heavy_minus_sign: | Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net. | +| `client_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `certificate` | [Optional[models.CertificateType]](../models/certificatetype.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_queue_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime. | +| `template_storage_account_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_azure_cloud` | *Optional[str]* | :heavy_minus_sign: | Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputazurevnetflowlogtype.md b/docs/models/createinputinputazurevnetflowlogtype.md new file mode 100644 index 000000000..c90643fd0 --- /dev/null +++ b/docs/models/createinputinputazurevnetflowlogtype.md @@ -0,0 +1,18 @@ +# CreateInputInputAzureVnetFlowLogType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputAzureVnetFlowLogType + +value = CreateInputInputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG +``` + + +## Values + +| Name | Value | +| --------------------- | --------------------- | +| `AZURE_VNET_FLOW_LOG` | azure_vnet_flow_log | \ No newline at end of file diff --git a/docs/models/createinputinputbeyondtrusthec.md b/docs/models/createinputinputbeyondtrusthec.md new file mode 100644 index 000000000..8851f2cbb --- /dev/null +++ b/docs/models/createinputinputbeyondtrusthec.md @@ -0,0 +1,44 @@ +# CreateInputInputBeyondtrustHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputBeyondtrustHecType](../models/createinputinputbeyondtrusthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputbeyondtrusthectype.md b/docs/models/createinputinputbeyondtrusthectype.md new file mode 100644 index 000000000..4d819e27b --- /dev/null +++ b/docs/models/createinputinputbeyondtrusthectype.md @@ -0,0 +1,18 @@ +# CreateInputInputBeyondtrustHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputBeyondtrustHecType + +value = CreateInputInputBeyondtrustHecType.BEYONDTRUST_HEC +``` + + +## Values + +| Name | Value | +| ----------------- | ----------------- | +| `BEYONDTRUST_HEC` | beyondtrust_hec | \ No newline at end of file diff --git a/docs/models/createinputinputconfluentcloud.md b/docs/models/createinputinputconfluentcloud.md index 555194e40..3f50d322d 100644 --- a/docs/models/createinputinputconfluentcloud.md +++ b/docs/models/createinputinputconfluentcloud.md @@ -39,6 +39,7 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputcribllakehttp.md b/docs/models/createinputinputcribllakehttp.md index feeee5769..8e0f1eb31 100644 --- a/docs/models/createinputinputcribllakehttp.md +++ b/docs/models/createinputinputcribllakehttp.md @@ -35,7 +35,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.CreateInputAuthTokensExt](../models/createinputauthtokensext.md)] | :heavy_minus_sign: | Auth tokens | +| `auth_tokens_ext` | List[[models.CreateInputInputCriblLakeHTTPAuthTokensExt](../models/createinputinputcribllakehttpauthtokensext.md)] | :heavy_minus_sign: | Auth tokens | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputcribllakehttpauthtokensext.md b/docs/models/createinputinputcribllakehttpauthtokensext.md new file mode 100644 index 000000000..6030783fe --- /dev/null +++ b/docs/models/createinputinputcribllakehttpauthtokensext.md @@ -0,0 +1,17 @@ +# CreateInputInputCriblLakeHTTPAuthTokensExt + + +## Supported Types + +### `models.CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/createinputinputcribllakehttpinputhttpauthtokensextitemstype.md b/docs/models/createinputinputcribllakehttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..0c1eb7ce4 --- /dev/null +++ b/docs/models/createinputinputcribllakehttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,14 @@ +# CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `token` | *str* | :heavy_check_mark: | Token | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata]](../models/createinputinputhttpauthtokensextitemstypesplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata]](../models/createinputinputhttpauthtokensextitemstypeelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputinputcribllakehttpinputhttpauthtypesecretconstraint.md b/docs/models/createinputinputcribllakehttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..57bf5bdca --- /dev/null +++ b/docs/models/createinputinputcribllakehttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,14 @@ +# CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Token | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata]](../models/createinputinputhttpauthtypesecretconstraintsplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata]](../models/createinputinputhttpauthtypesecretconstraintelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputinputeventhub.md b/docs/models/createinputinputeventhub.md index 2e573bff2..4760067ad 100644 --- a/docs/models/createinputinputeventhub.md +++ b/docs/models/createinputinputeventhub.md @@ -39,6 +39,7 @@ | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `minimize_duplicates` | *Optional[bool]* | :heavy_minus_sign: | Minimize duplicate events by starting only one consumer for each topic partition | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputeventhubamqp.md b/docs/models/createinputinputeventhubamqp.md index 47cddb15e..5aee9ca91 100644 --- a/docs/models/createinputinputeventhubamqp.md +++ b/docs/models/createinputinputeventhubamqp.md @@ -31,6 +31,7 @@ | `connection_max_backoff` | *Optional[int]* | :heavy_minus_sign: | Maximum delay between reconnection attempts, in milliseconds | | `connection_timeout_in_ms` | *Optional[int]* | :heavy_minus_sign: | Maximum time to wait for a connection to complete | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputeventhubamqpauthenticationmethod.md b/docs/models/createinputinputeventhubamqpauthenticationmethod.md deleted file mode 100644 index d23a7de72..000000000 --- a/docs/models/createinputinputeventhubamqpauthenticationmethod.md +++ /dev/null @@ -1,24 +0,0 @@ -# CreateInputInputEventhubAmqpAuthenticationMethod - -Authentication method - -## Example Usage - -```python -from cribl_control_plane.models import CreateInputInputEventhubAmqpAuthenticationMethod - -value = CreateInputInputEventhubAmqpAuthenticationMethod.SECRET - -# Open enum: unrecognized values are captured as UnrecognizedStr -``` - - -## Values - -| Name | Value | -| ---------------------- | ---------------------- | -| `SECRET` | secret | -| `CLIENT_SECRET` | clientSecret | -| `CLIENT_CERT` | clientCert | -| `CLIENT_ASSERTION` | clientAssertion | -| `CLIENT_ASSERTION_RPC` | clientAssertion_rpc | \ No newline at end of file diff --git a/docs/models/createinputinputexec.md b/docs/models/createinputinputexec.md index 01a03d199..89cfe74cb 100644 --- a/docs/models/createinputinputexec.md +++ b/docs/models/createinputinputexec.md @@ -22,6 +22,7 @@ | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `interval` | *Optional[float]* | :heavy_minus_sign: | Interval between command executions in seconds. | | `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule to execute the command on. | diff --git a/docs/models/createinputinputextrahoprevealx360.md b/docs/models/createinputinputextrahoprevealx360.md new file mode 100644 index 000000000..0966f333f --- /dev/null +++ b/docs/models/createinputinputextrahoprevealx360.md @@ -0,0 +1,46 @@ +# CreateInputInputExtrahopRevealx360 + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputExtrahopRevealx360Type](../models/createinputinputextrahoprevealx360type.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputextrahoprevealx360type.md b/docs/models/createinputinputextrahoprevealx360type.md new file mode 100644 index 000000000..8d2915ec9 --- /dev/null +++ b/docs/models/createinputinputextrahoprevealx360type.md @@ -0,0 +1,18 @@ +# CreateInputInputExtrahopRevealx360Type + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputExtrahopRevealx360Type + +value = CreateInputInputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360 +``` + + +## Values + +| Name | Value | +| ---------------------- | ---------------------- | +| `EXTRAHOP_REVEALX_360` | extrahop_revealx_360 | \ No newline at end of file diff --git a/docs/models/createinputinputf5bigip.md b/docs/models/createinputinputf5bigip.md new file mode 100644 index 000000000..79bd4bfc5 --- /dev/null +++ b/docs/models/createinputinputf5bigip.md @@ -0,0 +1,47 @@ +# CreateInputInputF5BigIP + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputF5BigIPType](../models/createinputinputf5bigiptype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputf5bigiptype.md b/docs/models/createinputinputf5bigiptype.md new file mode 100644 index 000000000..68da4ec9a --- /dev/null +++ b/docs/models/createinputinputf5bigiptype.md @@ -0,0 +1,18 @@ +# CreateInputInputF5BigIPType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputF5BigIPType + +value = CreateInputInputF5BigIPType.F5_BIG_IP +``` + + +## Values + +| Name | Value | +| ----------- | ----------- | +| `F5_BIG_IP` | f5_big_ip | \ No newline at end of file diff --git a/docs/models/createinputinputfile.md b/docs/models/createinputinputfile.md index a57a4e530..ae6545aea 100644 --- a/docs/models/createinputinputfile.md +++ b/docs/models/createinputinputfile.md @@ -26,10 +26,12 @@ | `check_file_mod_time` | *Optional[bool]* | :heavy_minus_sign: | Skip files with modification times earlier than the maximum age duration | | `force_text` | *Optional[bool]* | :heavy_minus_sign: | Forces files containing binary data to be streamed as text | | `hash_len` | *Optional[float]* | :heavy_minus_sign: | Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files. | +| `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `disable_stale_channel_flush` | *Optional[bool]* | :heavy_minus_sign: | When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS. | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `path` | *Optional[str]* | :heavy_minus_sign: | Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/). | | `depth` | *Optional[float]* | :heavy_minus_sign: | Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth. | @@ -37,6 +39,8 @@ | `delete_files` | *Optional[bool]* | :heavy_minus_sign: | Delete files after they have been collected | | `salt_hash` | *Optional[bool]* | :heavy_minus_sign: | Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion. | | `optimize_leaf_directories` | *Optional[bool]* | :heavy_minus_sign: | Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories. | +| `enable_discovery_throttle` | *Optional[bool]* | :heavy_minus_sign: | When enabled, discovery will throttle CPU usage to the configured target percentage. | +| `discovery_throttle_cpu_percent` | *Optional[float]* | :heavy_minus_sign: | Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times. | | `include_unidentifiable_binary` | *Optional[bool]* | :heavy_minus_sign: | Stream binary files as Base64-encoded chunks | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputgigamonhec.md b/docs/models/createinputinputgigamonhec.md new file mode 100644 index 000000000..e6e30645f --- /dev/null +++ b/docs/models/createinputinputgigamonhec.md @@ -0,0 +1,46 @@ +# CreateInputInputGigamonHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputGigamonHecType](../models/createinputinputgigamonhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputgigamonhectype.md b/docs/models/createinputinputgigamonhectype.md new file mode 100644 index 000000000..8a5a7bf4e --- /dev/null +++ b/docs/models/createinputinputgigamonhectype.md @@ -0,0 +1,18 @@ +# CreateInputInputGigamonHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputGigamonHecType + +value = CreateInputInputGigamonHecType.GIGAMON_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `GIGAMON_HEC` | gigamon_hec | \ No newline at end of file diff --git a/docs/models/createinputinputgooglepubsub.md b/docs/models/createinputinputgooglepubsub.md index 04ff73328..245db017b 100644 --- a/docs/models/createinputinputgooglepubsub.md +++ b/docs/models/createinputinputgooglepubsub.md @@ -28,6 +28,7 @@ | `concurrency` | *Optional[float]* | :heavy_minus_sign: | How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5. | | `request_timeout` | *Optional[float]* | :heavy_minus_sign: | Pull request timeout, in milliseconds | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `ordered_delivery` | *Optional[bool]* | :heavy_minus_sign: | Receive events in the order they were added to the queue. The process sending events must have ordering enabled. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/createinputinputhashicorphcpvaultdedicated.md b/docs/models/createinputinputhashicorphcpvaultdedicated.md new file mode 100644 index 000000000..0718053df --- /dev/null +++ b/docs/models/createinputinputhashicorphcpvaultdedicated.md @@ -0,0 +1,46 @@ +# CreateInputInputHashicorpHcpVaultDedicated + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputHashicorpHcpVaultDedicatedType](../models/createinputinputhashicorphcpvaultdedicatedtype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputhashicorphcpvaultdedicatedtype.md b/docs/models/createinputinputhashicorphcpvaultdedicatedtype.md new file mode 100644 index 000000000..3b2258699 --- /dev/null +++ b/docs/models/createinputinputhashicorphcpvaultdedicatedtype.md @@ -0,0 +1,18 @@ +# CreateInputInputHashicorpHcpVaultDedicatedType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputHashicorpHcpVaultDedicatedType + +value = CreateInputInputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED +``` + + +## Values + +| Name | Value | +| ------------------------------- | ------------------------------- | +| `HASHICORP_HCP_VAULT_DEDICATED` | hashicorp_hcp_vault_dedicated | \ No newline at end of file diff --git a/docs/models/createinputinputhttp.md b/docs/models/createinputinputhttp.md index f6749990a..8cbf128f6 100644 --- a/docs/models/createinputinputhttp.md +++ b/docs/models/createinputinputhttp.md @@ -35,7 +35,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.CreateInputInputHTTPAuthTokensExt](../models/createinputinputhttpauthtokensext.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputhttpauthtokensext.md b/docs/models/createinputinputhttpauthtokensext.md new file mode 100644 index 000000000..0885db9e6 --- /dev/null +++ b/docs/models/createinputinputhttpauthtokensext.md @@ -0,0 +1,17 @@ +# CreateInputInputHTTPAuthTokensExt + + +## Supported Types + +### `models.CreateInputInputHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.CreateInputInputHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/elasticsearchmetadata.md b/docs/models/createinputinputhttpauthtokensextitemstypeelasticsearchmetadata.md similarity index 84% rename from docs/models/elasticsearchmetadata.md rename to docs/models/createinputinputhttpauthtokensextitemstypeelasticsearchmetadata.md index f3b078066..f79022fb0 100644 --- a/docs/models/elasticsearchmetadata.md +++ b/docs/models/createinputinputhttpauthtokensextitemstypeelasticsearchmetadata.md @@ -1,4 +1,4 @@ -# ElasticsearchMetadata +# CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata ## Fields diff --git a/docs/models/inputresponsesplunkhecmetadata.md b/docs/models/createinputinputhttpauthtokensextitemstypesplunkhecmetadata.md similarity index 95% rename from docs/models/inputresponsesplunkhecmetadata.md rename to docs/models/createinputinputhttpauthtokensextitemstypesplunkhecmetadata.md index 626a53bd3..c82dbffbd 100644 --- a/docs/models/inputresponsesplunkhecmetadata.md +++ b/docs/models/createinputinputhttpauthtokensextitemstypesplunkhecmetadata.md @@ -1,4 +1,4 @@ -# InputResponseSplunkHecMetadata +# CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata ## Fields diff --git a/docs/models/inputresponseelasticsearchmetadata.md b/docs/models/createinputinputhttpauthtypesecretconstraintelasticsearchmetadata.md similarity index 83% rename from docs/models/inputresponseelasticsearchmetadata.md rename to docs/models/createinputinputhttpauthtypesecretconstraintelasticsearchmetadata.md index fd57153cb..a88d7a78c 100644 --- a/docs/models/inputresponseelasticsearchmetadata.md +++ b/docs/models/createinputinputhttpauthtypesecretconstraintelasticsearchmetadata.md @@ -1,4 +1,4 @@ -# InputResponseElasticsearchMetadata +# CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata ## Fields diff --git a/docs/models/createinputsplunkhecmetadata.md b/docs/models/createinputinputhttpauthtypesecretconstraintsplunkhecmetadata.md similarity index 95% rename from docs/models/createinputsplunkhecmetadata.md rename to docs/models/createinputinputhttpauthtypesecretconstraintsplunkhecmetadata.md index 941289e5c..1045fed83 100644 --- a/docs/models/createinputsplunkhecmetadata.md +++ b/docs/models/createinputinputhttpauthtypesecretconstraintsplunkhecmetadata.md @@ -1,4 +1,4 @@ -# CreateInputSplunkHecMetadata +# CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata ## Fields diff --git a/docs/models/createinputinputhttpinputhttpauthtokensextitemstype.md b/docs/models/createinputinputhttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..90bc13b67 --- /dev/null +++ b/docs/models/createinputinputhttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,12 @@ +# CreateInputInputHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputinputhttpinputhttpauthtypesecretconstraint.md b/docs/models/createinputinputhttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..ca9e36711 --- /dev/null +++ b/docs/models/createinputinputhttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputinputhttpraw.md b/docs/models/createinputinputhttpraw.md index 0d65ed48e..a43ffc158 100644 --- a/docs/models/createinputinputhttpraw.md +++ b/docs/models/createinputinputhttpraw.md @@ -32,10 +32,11 @@ | `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.CreateInputInputHTTPRawAuthTokensExtUnion](../models/createinputinputhttprawauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS. | | `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use "*" to allow all headers. | | `access_control_allow_methods` | List[*str*] | :heavy_minus_sign: | HTTP methods echoed in Access-Control-Allow-Methods on preflight. | diff --git a/docs/models/createinputinputhttprawauthtokensext.md b/docs/models/createinputinputhttprawauthtokensext.md new file mode 100644 index 000000000..b9ea6fe40 --- /dev/null +++ b/docs/models/createinputinputhttprawauthtokensext.md @@ -0,0 +1,12 @@ +# CreateInputInputHTTPRawAuthTokensExt + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputinputhttprawauthtokensextunion.md b/docs/models/createinputinputhttprawauthtokensextunion.md new file mode 100644 index 000000000..3fbfb1817 --- /dev/null +++ b/docs/models/createinputinputhttprawauthtokensextunion.md @@ -0,0 +1,17 @@ +# CreateInputInputHTTPRawAuthTokensExtUnion + + +## Supported Types + +### `models.CreateInputInputHTTPRawAuthTokensExt` + +```python +value: models.CreateInputInputHTTPRawAuthTokensExt = /* values here */ +``` + +### `models.CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint` + +```python +value: models.CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/createinputinputhttprawinputhttpauthtypesecretconstraint.md b/docs/models/createinputinputhttprawinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..06e4694ec --- /dev/null +++ b/docs/models/createinputinputhttprawinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputinputjournalfiles.md b/docs/models/createinputinputjournalfiles.md index 83bf9e626..11ef6f0ca 100644 --- a/docs/models/createinputinputjournalfiles.md +++ b/docs/models/createinputinputjournalfiles.md @@ -23,6 +23,7 @@ | `max_age_dur` | *Optional[str]* | :heavy_minus_sign: | The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters. | | `suppress_missing_path_errors` | *Optional[bool]* | :heavy_minus_sign: | Suppress errors when search path does not exist | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputkafka.md b/docs/models/createinputinputkafka.md index ee09ab470..d04b8efcb 100644 --- a/docs/models/createinputinputkafka.md +++ b/docs/models/createinputinputkafka.md @@ -39,6 +39,7 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputkinesis.md b/docs/models/createinputinputkinesis.md index 28db67cf1..6aecd3054 100644 --- a/docs/models/createinputinputkinesis.md +++ b/docs/models/createinputinputkinesis.md @@ -36,6 +36,7 @@ | `verify_kpl_check_sums` | *Optional[bool]* | :heavy_minus_sign: | Verify Kinesis Producer Library (KPL) event checksums | | `avoid_duplicates` | *Optional[bool]* | :heavy_minus_sign: | When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputinputmicrosoftcopilot.md b/docs/models/createinputinputmicrosoftcopilot.md new file mode 100644 index 000000000..d818d3649 --- /dev/null +++ b/docs/models/createinputinputmicrosoftcopilot.md @@ -0,0 +1,48 @@ +# CreateInputInputMicrosoftCopilot + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputMicrosoftCopilotType](../models/createinputinputmicrosoftcopilottype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `tenant_id` | *str* | :heavy_check_mark: | Directory (tenant) ID from Azure Active Directory | +| `client_id` | *str* | :heavy_check_mark: | Application (client) ID from the app registration | +| `resource` | *Optional[str]* | :heavy_minus_sign: | Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type. | +| `auth_type` | [Optional[models.CreateInputInputMicrosoftCopilotAuthenticationMethod]](../models/createinputinputmicrosoftcopilotauthenticationmethod.md) | :heavy_minus_sign: | Select authentication method. | +| `plan_type` | [Optional[models.CreateInputInputMicrosoftCopilotSubscriptionPlan]](../models/createinputinputmicrosoftcopilotsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule for collection runs | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run. | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `page_size` | *Optional[int]* | :heavy_minus_sign: | Number of interactions to request per page ($top). Maximum 1000. | +| `app_class_filter` | List[*str*] | :heavy_minus_sign: | Limit collection to specific Copilot app classes. Leave empty to collect all. | +| `filter_by_license` | *Optional[bool]* | :heavy_minus_sign: | Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time. | +| `sku_ids` | List[*str*] | :heavy_minus_sign: | Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans. | +| `manage_state` | [Optional[models.CreateInputInputMicrosoftCopilotManageState]](../models/createinputinputmicrosoftcopilotmanagestate.md) | :heavy_minus_sign: | N/A | +| `timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely. | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.CreateInputRetryRules]](../models/createinputretryrules.md) | :heavy_minus_sign: | N/A | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references the client secret from your app registration | +| `cert_options` | [Optional[models.CreateInputCertOptions]](../models/createinputcertoptions.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_plan_type` | *Optional[str]* | :heavy_minus_sign: | Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputmicrosoftcopilotauthenticationmethod.md b/docs/models/createinputinputmicrosoftcopilotauthenticationmethod.md new file mode 100644 index 000000000..7e3db54c9 --- /dev/null +++ b/docs/models/createinputinputmicrosoftcopilotauthenticationmethod.md @@ -0,0 +1,21 @@ +# CreateInputInputMicrosoftCopilotAuthenticationMethod + +Select authentication method. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputMicrosoftCopilotAuthenticationMethod + +value = CreateInputInputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `OAUTH_SECRET` | oauthSecret | +| `OAUTH_CERT` | oauthCert | \ No newline at end of file diff --git a/docs/models/createinputinputmicrosoftcopilotmanagestate.md b/docs/models/createinputinputmicrosoftcopilotmanagestate.md new file mode 100644 index 000000000..b5d68f8b8 --- /dev/null +++ b/docs/models/createinputinputmicrosoftcopilotmanagestate.md @@ -0,0 +1,7 @@ +# CreateInputInputMicrosoftCopilotManageState + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/createinputinputmicrosoftcopilotsubscriptionplan.md b/docs/models/createinputinputmicrosoftcopilotsubscriptionplan.md new file mode 100644 index 000000000..e9db55661 --- /dev/null +++ b/docs/models/createinputinputmicrosoftcopilotsubscriptionplan.md @@ -0,0 +1,23 @@ +# CreateInputInputMicrosoftCopilotSubscriptionPlan + +Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputMicrosoftCopilotSubscriptionPlan + +value = CreateInputInputMicrosoftCopilotSubscriptionPlan.ENTERPRISE_GCC + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `ENTERPRISE_GCC` | enterprise_gcc | +| `GCC` | gcc | +| `GCC_HIGH` | gcc_high | +| `DOD` | dod | \ No newline at end of file diff --git a/docs/models/createinputinputmicrosoftcopilottype.md b/docs/models/createinputinputmicrosoftcopilottype.md new file mode 100644 index 000000000..07edda4de --- /dev/null +++ b/docs/models/createinputinputmicrosoftcopilottype.md @@ -0,0 +1,18 @@ +# CreateInputInputMicrosoftCopilotType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputMicrosoftCopilotType + +value = CreateInputInputMicrosoftCopilotType.MICROSOFT_COPILOT +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `MICROSOFT_COPILOT` | microsoft_copilot | \ No newline at end of file diff --git a/docs/models/createinputinputmicrosoftgraph.md b/docs/models/createinputinputmicrosoftgraph.md index 330f56c76..5cc4ea551 100644 --- a/docs/models/createinputinputmicrosoftgraph.md +++ b/docs/models/createinputinputmicrosoftgraph.md @@ -40,7 +40,7 @@ | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | Directory ID (tenant identifier) in Azure Active Directory. | | `client_id` | *Optional[str]* | :heavy_minus_sign: | client_id to pass in the OAuth request parameter. | | `resource` | *Optional[str]* | :heavy_minus_sign: | Resource to pass in the OAuth request parameter. | -| `plan_type` | [Optional[models.CreateInputSubscriptionPlan]](../models/createinputsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | +| `plan_type` | [Optional[models.CreateInputInputMicrosoftGraphSubscriptionPlan]](../models/createinputinputmicrosoftgraphsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your client_secret to pass in the OAuth request parameter. | | `cert_options` | [Optional[models.CertOptionsType]](../models/certoptionstype.md) | :heavy_minus_sign: | N/A | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/inputresponsesubscriptionplan.md b/docs/models/createinputinputmicrosoftgraphsubscriptionplan.md similarity index 70% rename from docs/models/inputresponsesubscriptionplan.md rename to docs/models/createinputinputmicrosoftgraphsubscriptionplan.md index e641516ee..17310d075 100644 --- a/docs/models/inputresponsesubscriptionplan.md +++ b/docs/models/createinputinputmicrosoftgraphsubscriptionplan.md @@ -1,13 +1,13 @@ -# InputResponseSubscriptionPlan +# CreateInputInputMicrosoftGraphSubscriptionPlan Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise ## Example Usage ```python -from cribl_control_plane.models import InputResponseSubscriptionPlan +from cribl_control_plane.models import CreateInputInputMicrosoftGraphSubscriptionPlan -value = InputResponseSubscriptionPlan.ENTERPRISE_GCC +value = CreateInputInputMicrosoftGraphSubscriptionPlan.ENTERPRISE_GCC # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/createinputinputmimecasthec.md b/docs/models/createinputinputmimecasthec.md new file mode 100644 index 000000000..115d4cb40 --- /dev/null +++ b/docs/models/createinputinputmimecasthec.md @@ -0,0 +1,46 @@ +# CreateInputInputMimecastHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputMimecastHecType](../models/createinputinputmimecasthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputmimecasthectype.md b/docs/models/createinputinputmimecasthectype.md new file mode 100644 index 000000000..39a6834bf --- /dev/null +++ b/docs/models/createinputinputmimecasthectype.md @@ -0,0 +1,18 @@ +# CreateInputInputMimecastHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputMimecastHecType + +value = CreateInputInputMimecastHecType.MIMECAST_HEC +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `MIMECAST_HEC` | mimecast_hec | \ No newline at end of file diff --git a/docs/models/createinputinputmodeldriventelemetry.md b/docs/models/createinputinputmodeldriventelemetry.md index 826a5f041..5ad88391a 100644 --- a/docs/models/createinputinputmodeldriventelemetry.md +++ b/docs/models/createinputinputmodeldriventelemetry.md @@ -3,26 +3,28 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *str* | :heavy_check_mark: | Unique ID for this input | -| `type` | [models.CreateInputInputModelDrivenTelemetryType](../models/createinputinputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | -| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | -| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | -| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | -| `port` | *float* | :heavy_check_mark: | Port to listen on | -| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | -| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | -| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputModelDrivenTelemetryType](../models/createinputinputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each. | +| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputmsk.md b/docs/models/createinputinputmsk.md index 71037b364..4c49e3425 100644 --- a/docs/models/createinputinputmsk.md +++ b/docs/models/createinputinputmsk.md @@ -48,6 +48,7 @@ | `max_bytes_per_partition` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB). | | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputinputopenaicontentconfig.md b/docs/models/createinputinputopenaicontentconfig.md index 7d668071c..5395c97bb 100644 --- a/docs/models/createinputinputopenaicontentconfig.md +++ b/docs/models/createinputinputopenaicontentconfig.md @@ -3,23 +3,23 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputInputOpenaiManageState]](../models/createinputinputopenaimanagestate.md) | :heavy_minus_sign: | N/A | -| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | -| `pagination_type` | [models.CreateInputPaginationType](../models/createinputpaginationtype.md) | :heavy_check_mark: | Pagination type | -| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | -| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | -| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | -| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | -| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | -| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | -| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | -| `latest` | *str* | :heavy_check_mark: | Relative to the current time | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `log_level` | [Optional[models.CreateInputInputOpenaiLogLevel]](../models/createinputinputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | -| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputInputOpenaiManageState]](../models/createinputinputopenaimanagestate.md) | :heavy_minus_sign: | N/A | +| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | +| `pagination_type` | [models.CreateInputPaginationType](../models/createinputpaginationtype.md) | :heavy_check_mark: | Pagination type | +| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | +| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | +| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | +| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | +| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | +| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | +| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | +| `latest` | *str* | :heavy_check_mark: | Relative to the current time | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `log_level` | [Optional[models.CreateInputInputOpenaiLogLevel]](../models/createinputinputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | +| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file diff --git a/docs/models/createinputinputopentelemetry.md b/docs/models/createinputinputopentelemetry.md index a666ab6e5..6709994bb 100644 --- a/docs/models/createinputinputopentelemetry.md +++ b/docs/models/createinputinputopentelemetry.md @@ -31,9 +31,11 @@ | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point | | `otlp_version` | [Optional[models.CreateInputOTLPVersion]](../models/createinputotlpversion.md) | :heavy_minus_sign: | The version of OTLP Protobuf definitions to use when interpreting received data | | `auth_type` | [Optional[models.CreateInputInputOpenTelemetryAuthenticationType]](../models/createinputinputopentelemetryauthenticationtype.md) | :heavy_minus_sign: | OpenTelemetry authentication type | -| `auth_methods_ext` | List[[models.CreateInputAuthMethodsExt](../models/createinputauthmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted. | +| `auth_methods_ext` | List[[models.CreateInputAuthMethodsExt](../models/createinputauthmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | diff --git a/docs/models/createinputinputpingidentitypingone.md b/docs/models/createinputinputpingidentitypingone.md new file mode 100644 index 000000000..a32c295da --- /dev/null +++ b/docs/models/createinputinputpingidentitypingone.md @@ -0,0 +1,46 @@ +# CreateInputInputPingIdentityPingone + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputPingIdentityPingoneType](../models/createinputinputpingidentitypingonetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputpingidentitypingonetype.md b/docs/models/createinputinputpingidentitypingonetype.md new file mode 100644 index 000000000..77e73d875 --- /dev/null +++ b/docs/models/createinputinputpingidentitypingonetype.md @@ -0,0 +1,18 @@ +# CreateInputInputPingIdentityPingoneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputPingIdentityPingoneType + +value = CreateInputInputPingIdentityPingoneType.PING_IDENTITY_PINGONE +``` + + +## Values + +| Name | Value | +| ----------------------- | ----------------------- | +| `PING_IDENTITY_PINGONE` | ping_identity_pingone | \ No newline at end of file diff --git a/docs/models/createinputinputproofpointpod.md b/docs/models/createinputinputproofpointpod.md new file mode 100644 index 000000000..08ca43e2d --- /dev/null +++ b/docs/models/createinputinputproofpointpod.md @@ -0,0 +1,31 @@ +# CreateInputInputProofpointPod + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputProofpointPodType](../models/createinputinputproofpointpodtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `cluster_id` | *str* | :heavy_check_mark: | Proofpoint on Demand cluster ID. | +| `feed_type` | [models.CreateInputFeedType](../models/createinputfeedtype.md) | :heavy_check_mark: | Proofpoint on Demand feed to ingest. | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `compress` | *Optional[bool]* | :heavy_minus_sign: | Compress the feed connection. | +| `handshake_timeout` | *Optional[float]* | :heavy_minus_sign: | Maximum time to wait for the connection handshake to complete. | +| `keep_alive_interval_sec` | *Optional[float]* | :heavy_minus_sign: | How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | Maximum number of consecutive keepalive pings that can go unanswered before reconnecting. | +| `max_message_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc. | +| `read_buffer_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_cluster_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputproofpointpodtype.md b/docs/models/createinputinputproofpointpodtype.md new file mode 100644 index 000000000..4b5e75d1d --- /dev/null +++ b/docs/models/createinputinputproofpointpodtype.md @@ -0,0 +1,18 @@ +# CreateInputInputProofpointPodType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputProofpointPodType + +value = CreateInputInputProofpointPodType.PROOFPOINT_POD +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `PROOFPOINT_POD` | proofpoint_pod | \ No newline at end of file diff --git a/docs/models/createinputinputrawudp.md b/docs/models/createinputinputrawudp.md index ee1d411a3..97245d328 100644 --- a/docs/models/createinputinputrawudp.md +++ b/docs/models/createinputinputrawudp.md @@ -23,6 +23,7 @@ | `ingest_raw_bytes` | *Optional[bool]* | :heavy_minus_sign: | If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram. | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputs3.md b/docs/models/createinputinputs3.md index 1922be2b6..446e81cf8 100644 --- a/docs/models/createinputinputs3.md +++ b/docs/models/createinputinputs3.md @@ -47,6 +47,7 @@ | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | | `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `tag_after_processing` | *Optional[bool]* | :heavy_minus_sign: | Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputinputsailpointhec.md b/docs/models/createinputinputsailpointhec.md new file mode 100644 index 000000000..fd5742dee --- /dev/null +++ b/docs/models/createinputinputsailpointhec.md @@ -0,0 +1,39 @@ +# CreateInputInputSailpointHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputSailpointHecType](../models/createinputinputsailpointhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputsailpointhectype.md b/docs/models/createinputinputsailpointhectype.md new file mode 100644 index 000000000..4700fad77 --- /dev/null +++ b/docs/models/createinputinputsailpointhectype.md @@ -0,0 +1,18 @@ +# CreateInputInputSailpointHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputSailpointHecType + +value = CreateInputInputSailpointHecType.SAILPOINT_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `SAILPOINT_HEC` | sailpoint_hec | \ No newline at end of file diff --git a/docs/models/createinputinputsplunk.md b/docs/models/createinputinputsplunk.md index bd3c2c918..d4dc40819 100644 --- a/docs/models/createinputinputsplunk.md +++ b/docs/models/createinputinputsplunk.md @@ -27,6 +27,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `auth_tokens` | List[[models.CreateInputInputSplunkAuthToken](../models/createinputinputsplunkauthtoken.md)] | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | | `max_s2_sversion` | [Optional[models.CreateInputMaxS2SVersion]](../models/createinputmaxs2sversion.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | diff --git a/docs/models/createinputinputsplunkauthtoken.md b/docs/models/createinputinputsplunkauthtoken.md index 8fa8a7505..11c3def7b 100644 --- a/docs/models/createinputinputsplunkauthtoken.md +++ b/docs/models/createinputinputsplunkauthtoken.md @@ -3,7 +3,9 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `token` | *str* | :heavy_check_mark: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file diff --git a/docs/models/createinputinputsplunkhec.md b/docs/models/createinputinputsplunkhec.md index ca29f7187..b4fff5f47 100644 --- a/docs/models/createinputinputsplunkhec.md +++ b/docs/models/createinputinputsplunkhec.md @@ -35,6 +35,7 @@ | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `use_fwd_timezone` | *Optional[bool]* | :heavy_minus_sign: | Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event | | `drop_control_fields` | *Optional[bool]* | :heavy_minus_sign: | Drop Splunk control fields such as `crcSalt` and `_savedPort`. If disabled, control fields are stored in the internal field `__ctrlFields`. | | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Extract and process Splunk-generated metrics as Cribl metrics | diff --git a/docs/models/createinputinputsplunkhecauthtoken.md b/docs/models/createinputinputsplunkhecauthtoken.md index 3a8ec9010..f384937c6 100644 --- a/docs/models/createinputinputsplunkhecauthtoken.md +++ b/docs/models/createinputinputsplunkhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the token is active and can be used for authentication. | diff --git a/docs/models/createinputinputsqs.md b/docs/models/createinputinputsqs.md index 321f0aa7f..496a3c303 100644 --- a/docs/models/createinputinputsqs.md +++ b/docs/models/createinputinputsqs.md @@ -33,6 +33,7 @@ | `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputinputsyslogsyslog1.md b/docs/models/createinputinputsyslogsyslog1.md index ae3a6514e..814a6d313 100644 --- a/docs/models/createinputinputsyslogsyslog1.md +++ b/docs/models/createinputinputsyslogsyslog1.md @@ -36,6 +36,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/createinputinputsyslogsyslog2.md b/docs/models/createinputinputsyslogsyslog2.md index 5e4e093d8..afa39d292 100644 --- a/docs/models/createinputinputsyslogsyslog2.md +++ b/docs/models/createinputinputsyslogsyslog2.md @@ -36,6 +36,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/createinputinputtcp.md b/docs/models/createinputinputtcp.md index c5f4a2c6c..04b57c543 100644 --- a/docs/models/createinputinputtcp.md +++ b/docs/models/createinputinputtcp.md @@ -27,11 +27,12 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { "authToken" : "myToken", "fields": { "field1": "value1", "field2": "value2" } } | | `preprocess` | [Optional[models.PreprocessType]](../models/preprocesstype.md) | :heavy_minus_sign: | Optional preprocessing step that pipes collected data through an external command before ingestion. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputtcpjson.md b/docs/models/createinputinputtcpjson.md index 66d6626c1..8b5708ebb 100644 --- a/docs/models/createinputinputtcpjson.md +++ b/docs/models/createinputinputtcpjson.md @@ -26,7 +26,7 @@ | `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Enable if the connection is proxied by a device that supports proxy protocol v1 or v2 | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | diff --git a/docs/models/createinputinputtrellixhec.md b/docs/models/createinputinputtrellixhec.md new file mode 100644 index 000000000..021ca464e --- /dev/null +++ b/docs/models/createinputinputtrellixhec.md @@ -0,0 +1,46 @@ +# CreateInputInputTrellixHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputTrellixHecType](../models/createinputinputtrellixhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputtrellixhectype.md b/docs/models/createinputinputtrellixhectype.md new file mode 100644 index 000000000..5135d9d45 --- /dev/null +++ b/docs/models/createinputinputtrellixhectype.md @@ -0,0 +1,18 @@ +# CreateInputInputTrellixHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputTrellixHecType + +value = CreateInputInputTrellixHecType.TRELLIX_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `TRELLIX_HEC` | trellix_hec | \ No newline at end of file diff --git a/docs/models/createinputinputtrendmicrovisionone.md b/docs/models/createinputinputtrendmicrovisionone.md new file mode 100644 index 000000000..563b6107a --- /dev/null +++ b/docs/models/createinputinputtrendmicrovisionone.md @@ -0,0 +1,46 @@ +# CreateInputInputTrendMicroVisionOne + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputTrendMicroVisionOneType](../models/createinputinputtrendmicrovisiononetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputtrendmicrovisiononetype.md b/docs/models/createinputinputtrendmicrovisiononetype.md new file mode 100644 index 000000000..6e5661294 --- /dev/null +++ b/docs/models/createinputinputtrendmicrovisiononetype.md @@ -0,0 +1,18 @@ +# CreateInputInputTrendMicroVisionOneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputTrendMicroVisionOneType + +value = CreateInputInputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE +``` + + +## Values + +| Name | Value | +| ------------------------ | ------------------------ | +| `TREND_MICRO_VISION_ONE` | trend_micro_vision_one | \ No newline at end of file diff --git a/docs/models/createinputinputvectraaihec.md b/docs/models/createinputinputvectraaihec.md new file mode 100644 index 000000000..16eea5d7c --- /dev/null +++ b/docs/models/createinputinputvectraaihec.md @@ -0,0 +1,46 @@ +# CreateInputInputVectraAiHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputInputVectraAiHecType](../models/createinputinputvectraaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputvectraaihectype.md b/docs/models/createinputinputvectraaihectype.md new file mode 100644 index 000000000..0a17ce51a --- /dev/null +++ b/docs/models/createinputinputvectraaihectype.md @@ -0,0 +1,18 @@ +# CreateInputInputVectraAiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputInputVectraAiHecType + +value = CreateInputInputVectraAiHecType.VECTRA_AI_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `VECTRA_AI_HEC` | vectra_ai_hec | \ No newline at end of file diff --git a/docs/models/createinputinputwefauthenticationmethod.md b/docs/models/createinputinputwefauthenticationmethod.md index 28cd8d4d9..375e4ec7b 100644 --- a/docs/models/createinputinputwefauthenticationmethod.md +++ b/docs/models/createinputinputwefauthenticationmethod.md @@ -18,4 +18,5 @@ value = CreateInputInputWefAuthenticationMethod.CLIENT_CERT | Name | Value | | ------------- | ------------- | | `CLIENT_CERT` | clientCert | -| `KERBEROS` | kerberos | \ No newline at end of file +| `KERBEROS` | kerberos | +| `NEGOTIATE` | negotiate | \ No newline at end of file diff --git a/docs/models/createinputinputwineventlogs.md b/docs/models/createinputinputwineventlogs.md index 61e6a5909..a7c2b25b8 100644 --- a/docs/models/createinputinputwineventlogs.md +++ b/docs/models/createinputinputwineventlogs.md @@ -26,6 +26,7 @@ | `max_event_bytes` | *Optional[int]* | :heavy_minus_sign: | The maximum number of bytes in an event before it is flushed to the pipelines | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `disable_json_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | +| `include_empty_json_fields` | *Optional[bool]* | :heavy_minus_sign: | Preserve fields with empty values (such as '-') in the JSON output instead of omitting them | | `disable_xml_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputinputwizwebhook.md b/docs/models/createinputinputwizwebhook.md index e0daf1299..961fbf9fd 100644 --- a/docs/models/createinputinputwizwebhook.md +++ b/docs/models/createinputinputwizwebhook.md @@ -35,7 +35,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.CreateInputInputWizWebhookAuthTokensExtUnion](../models/createinputinputwizwebhookauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputinputwizwebhookauthtokensext1.md b/docs/models/createinputinputwizwebhookauthtokensext1.md new file mode 100644 index 000000000..2dd717bb9 --- /dev/null +++ b/docs/models/createinputinputwizwebhookauthtokensext1.md @@ -0,0 +1,12 @@ +# CreateInputInputWizWebhookAuthTokensExt1 + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputinputwizwebhookauthtokensext2.md b/docs/models/createinputinputwizwebhookauthtokensext2.md new file mode 100644 index 000000000..f6d7235a5 --- /dev/null +++ b/docs/models/createinputinputwizwebhookauthtokensext2.md @@ -0,0 +1,12 @@ +# CreateInputInputWizWebhookAuthTokensExt2 + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputinputwizwebhookauthtokensextunion.md b/docs/models/createinputinputwizwebhookauthtokensextunion.md new file mode 100644 index 000000000..35c8ce68c --- /dev/null +++ b/docs/models/createinputinputwizwebhookauthtokensextunion.md @@ -0,0 +1,17 @@ +# CreateInputInputWizWebhookAuthTokensExtUnion + + +## Supported Types + +### `models.CreateInputInputWizWebhookAuthTokensExt1` + +```python +value: models.CreateInputInputWizWebhookAuthTokensExt1 = /* values here */ +``` + +### `models.CreateInputInputWizWebhookAuthTokensExt2` + +```python +value: models.CreateInputInputWizWebhookAuthTokensExt2 = /* values here */ +``` + diff --git a/docs/models/createinputinputzscalerhecauthtoken.md b/docs/models/createinputinputzscalerhecauthtoken.md index a9d6774ae..d2af4092f 100644 --- a/docs/models/createinputinputzscalerhecauthtoken.md +++ b/docs/models/createinputinputzscalerhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enable token | diff --git a/docs/models/createinputprojectdetails.md b/docs/models/createinputprojectdetails.md index bc93bbf9a..55d53a609 100644 --- a/docs/models/createinputprojectdetails.md +++ b/docs/models/createinputprojectdetails.md @@ -5,14 +5,14 @@ Project Details ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputProjectDetailsManageState]](../models/createinputprojectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputProjectDetailsManageState]](../models/createinputprojectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputprojects.md b/docs/models/createinputprojects.md index 7b4f1c3e2..176c0f6ee 100644 --- a/docs/models/createinputprojects.md +++ b/docs/models/createinputprojects.md @@ -5,14 +5,14 @@ Projects ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputProjectsManageState]](../models/createinputprojectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputProjectsManageState]](../models/createinputprojectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputretryrules.md b/docs/models/createinputretryrules.md new file mode 100644 index 000000000..dc194daa6 --- /dev/null +++ b/docs/models/createinputretryrules.md @@ -0,0 +1,15 @@ +# CreateInputRetryRules + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `type` | [models.RetryTypeOptionsHealthCheckCollectorConfRetryRules](../models/retrytypeoptionshealthcheckcollectorconfretryrules.md) | :heavy_check_mark: | The algorithm to use when performing HTTP retries | +| `interval` | *Optional[float]* | :heavy_minus_sign: | Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute). | +| `limit` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times to retry a failed HTTP request | +| `multiplier` | *Optional[float]* | :heavy_minus_sign: | Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on | +| `codes` | List[*float*] | :heavy_minus_sign: | List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503. | +| `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored. | +| `retry_connect_timeout` | *Optional[bool]* | :heavy_minus_sign: | Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs | +| `retry_connect_reset` | *Optional[bool]* | :heavy_minus_sign: | Retry request when a connection reset (ECONNRESET) error occurs | \ No newline at end of file diff --git a/docs/models/createinputsystembypackactivities.md b/docs/models/createinputsystembypackactivities.md index cb25a66e6..503999545 100644 --- a/docs/models/createinputsystembypackactivities.md +++ b/docs/models/createinputsystembypackactivities.md @@ -5,14 +5,14 @@ Activities ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputSystemByPackActivitiesManageState]](../models/createinputsystembypackactivitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputSystemByPackActivitiesManageState]](../models/createinputsystembypackactivitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackauthmethodsext.md b/docs/models/createinputsystembypackauthmethodsext.md index f0f1cbbe8..76bd616eb 100644 --- a/docs/models/createinputsystembypackauthmethodsext.md +++ b/docs/models/createinputsystembypackauthmethodsext.md @@ -13,4 +13,8 @@ | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | -| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | \ No newline at end of file +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `issuer` | *Optional[str]* | :heavy_minus_sign: | Expected token issuer (iss claim) | +| `jwks_uri` | *Optional[str]* | :heavy_minus_sign: | URL of the JWKS endpoint used to fetch signing keys | +| `audience` | *Optional[str]* | :heavy_minus_sign: | Expected token audience (aud claim) | +| `scopes` | List[*str*] | :heavy_minus_sign: | Scopes the token must grant (optional) | \ No newline at end of file diff --git a/docs/models/createinputsystembypackauthmethodsextauthenticationtype.md b/docs/models/createinputsystembypackauthmethodsextauthenticationtype.md index c238a0f89..3970f01c2 100644 --- a/docs/models/createinputsystembypackauthmethodsextauthenticationtype.md +++ b/docs/models/createinputsystembypackauthmethodsextauthenticationtype.md @@ -20,4 +20,5 @@ value = CreateInputSystemByPackAuthMethodsExtAuthenticationType.TOKEN | `TOKEN` | token | | `TOKEN_SECRET` | tokenSecret | | `BASIC` | basic | -| `BASIC_SECRET` | basicSecret | \ No newline at end of file +| `BASIC_SECRET` | basicSecret | +| `OAUTH` | oauth | \ No newline at end of file diff --git a/docs/models/createinputsystembypackauthtokensext.md b/docs/models/createinputsystembypackauthtokensext.md deleted file mode 100644 index 6bcee79ba..000000000 --- a/docs/models/createinputsystembypackauthtokensext.md +++ /dev/null @@ -1,12 +0,0 @@ -# CreateInputSystemByPackAuthTokensExt - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------- | -| `token` | *str* | :heavy_check_mark: | Token | -| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | -| `splunk_hec_metadata` | [Optional[models.CreateInputSystemByPackSplunkHecMetadata]](../models/createinputsystembypacksplunkhecmetadata.md) | :heavy_minus_sign: | N/A | -| `elasticsearch_metadata` | [Optional[models.CreateInputSystemByPackElasticsearchMetadata]](../models/createinputsystembypackelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackazureblobstorage.md b/docs/models/createinputsystembypackazureblobstorage.md index 91e13f668..72ee934f6 100644 --- a/docs/models/createinputsystembypackazureblobstorage.md +++ b/docs/models/createinputsystembypackazureblobstorage.md @@ -8,7 +8,7 @@ Azure Blob Storage | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `container_name` | *str* | :heavy_check_mark: | Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens. | -| `auth_type` | [Optional[models.CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod]](../models/createinputsystembypackinputeventhubamqpauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | diff --git a/docs/models/createinputsystembypackbucketwidth.md b/docs/models/createinputsystembypackbucketwidth.md new file mode 100644 index 000000000..5515b8df1 --- /dev/null +++ b/docs/models/createinputsystembypackbucketwidth.md @@ -0,0 +1,22 @@ +# CreateInputSystemByPackBucketWidth + +Time bucket size for aggregated results. Smaller buckets yield more events per collection run. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackBucketWidth + +value = CreateInputSystemByPackBucketWidth.ONED + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------ | ------ | +| `ONED` | 1d | +| `ONEH` | 1h | +| `ONEM` | 1m | \ No newline at end of file diff --git a/docs/models/createinputsystembypackcertoptions.md b/docs/models/createinputsystembypackcertoptions.md new file mode 100644 index 000000000..6d3cdc469 --- /dev/null +++ b/docs/models/createinputsystembypackcertoptions.md @@ -0,0 +1,11 @@ +# CreateInputSystemByPackCertOptions + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of a predefined certificate | +| `priv_key_path` | *str* | :heavy_check_mark: | Path to the private key (PEM format). Can reference $ENV_VARS. | +| `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to decrypt the private key | +| `cert_path` | *str* | :heavy_check_mark: | Path to the certificate (PEM format). Can reference $ENV_VARS. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackchatmessages.md b/docs/models/createinputsystembypackchatmessages.md index 86669a4f4..ae1479e52 100644 --- a/docs/models/createinputsystembypackchatmessages.md +++ b/docs/models/createinputsystembypackchatmessages.md @@ -5,14 +5,14 @@ Chat Messages ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputSystemByPackChatMessagesManageState]](../models/createinputsystembypackchatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputSystemByPackChatMessagesManageState]](../models/createinputsystembypackchatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackchats.md b/docs/models/createinputsystembypackchats.md index 53c4a7ee3..1130e0a8b 100644 --- a/docs/models/createinputsystembypackchats.md +++ b/docs/models/createinputsystembypackchats.md @@ -5,14 +5,14 @@ Chats ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputSystemByPackChatsManageState]](../models/createinputsystembypackchatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputSystemByPackChatsManageState]](../models/createinputsystembypackchatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackcontenttype.md b/docs/models/createinputsystembypackcontenttype.md new file mode 100644 index 000000000..5d0b64d4a --- /dev/null +++ b/docs/models/createinputsystembypackcontenttype.md @@ -0,0 +1,21 @@ +# CreateInputSystemByPackContentType + +Content type + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackContentType + +value = CreateInputSystemByPackContentType.USAGE_REPORT + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `USAGE_REPORT` | Usage Report | +| `COST_REPORT` | Cost Report | \ No newline at end of file diff --git a/docs/models/createinputsystembypackfeedtype.md b/docs/models/createinputsystembypackfeedtype.md new file mode 100644 index 000000000..f1e6f5018 --- /dev/null +++ b/docs/models/createinputsystembypackfeedtype.md @@ -0,0 +1,22 @@ +# CreateInputSystemByPackFeedType + +Proofpoint on Demand feed to ingest. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackFeedType + +value = CreateInputSystemByPackFeedType.MESSAGE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `MESSAGE` | message | +| `MAILLOG` | maillog | +| `AUDIT` | audit | \ No newline at end of file diff --git a/docs/models/createinputsystembypackgroupby.md b/docs/models/createinputsystembypackgroupby.md new file mode 100644 index 000000000..76ab26746 --- /dev/null +++ b/docs/models/createinputsystembypackgroupby.md @@ -0,0 +1,27 @@ +# CreateInputSystemByPackGroupBy + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackGroupBy + +value = CreateInputSystemByPackGroupBy.MODEL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------ | ------------------ | +| `MODEL` | model | +| `PRODUCT` | product | +| `CONTEXT_WINDOW` | context_window | +| `INFERENCE_GEO` | inference_geo | +| `SPEED` | speed | +| `RBAC_GROUP_ID` | rbac_group_id | +| `SLACK_CHANNEL_ID` | slack_channel_id | +| `TEAMS_CHANNEL_ID` | teams_channel_id | +| `COST_TYPE` | cost_type | +| `TOKEN_TYPE` | token_type | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinput.md b/docs/models/createinputsystembypackinput.md index e3af634d8..ce8858d47 100644 --- a/docs/models/createinputsystembypackinput.md +++ b/docs/models/createinputsystembypackinput.md @@ -53,6 +53,12 @@ value: models.CreateInputSystemByPackInputSplunkHec = /* values here */ value: models.CreateInputSystemByPackInputAzureBlob = /* values here */ ``` +### `models.CreateInputSystemByPackInputAzureVnetFlowLog` + +```python +value: models.CreateInputSystemByPackInputAzureVnetFlowLog = /* values here */ +``` + ### `models.CreateInputSystemByPackInputElastic` ```python @@ -389,6 +395,12 @@ value: models.CreateInputSystemByPackInputBedrockS3 = /* values here */ value: models.CreateInputSystemByPackInputServicenowTable = /* values here */ ``` +### `models.CreateInputSystemByPackInputProofpointPod` + +```python +value: models.CreateInputSystemByPackInputProofpointPod = /* values here */ +``` + ### `models.CreateInputSystemByPackInputZscalerHec` ```python @@ -413,6 +425,30 @@ value: models.CreateInputSystemByPackInputSysdigHec = /* values here */ value: models.CreateInputSystemByPackInputUpwindHec = /* values here */ ``` +### `models.CreateInputSystemByPackInputTrellixHec` + +```python +value: models.CreateInputSystemByPackInputTrellixHec = /* values here */ +``` + +### `models.CreateInputSystemByPackInputSailpointHec` + +```python +value: models.CreateInputSystemByPackInputSailpointHec = /* values here */ +``` + +### `models.CreateInputSystemByPackInputExtrahopRevealx360` + +```python +value: models.CreateInputSystemByPackInputExtrahopRevealx360 = /* values here */ +``` + +### `models.CreateInputSystemByPackInputAquaSecurityHec` + +```python +value: models.CreateInputSystemByPackInputAquaSecurityHec = /* values here */ +``` + ### `models.CreateInputSystemByPackInputOpenaiComplianceLogs` ```python @@ -425,9 +461,75 @@ value: models.CreateInputSystemByPackInputOpenaiComplianceLogs = /* values here value: models.CreateInputSystemByPackInputAnthropicCompliance = /* values here */ ``` +### `models.CreateInputSystemByPackInputAnthropicEnterpriseAnalytics` + +```python +value: models.CreateInputSystemByPackInputAnthropicEnterpriseAnalytics = /* values here */ +``` + +### `models.CreateInputSystemByPackInputMicrosoftCopilot` + +```python +value: models.CreateInputSystemByPackInputMicrosoftCopilot = /* values here */ +``` + ### `models.CreateInputSystemByPackInputOkta` ```python value: models.CreateInputSystemByPackInputOkta = /* values here */ ``` +### `models.CreateInputSystemByPackInputAkamaiHec` + +```python +value: models.CreateInputSystemByPackInputAkamaiHec = /* values here */ +``` + +### `models.CreateInputSystemByPackInputPingIdentityPingone` + +```python +value: models.CreateInputSystemByPackInputPingIdentityPingone = /* values here */ +``` + +### `models.CreateInputSystemByPackInputGigamonHec` + +```python +value: models.CreateInputSystemByPackInputGigamonHec = /* values here */ +``` + +### `models.CreateInputSystemByPackInputVectraAiHec` + +```python +value: models.CreateInputSystemByPackInputVectraAiHec = /* values here */ +``` + +### `models.CreateInputSystemByPackInputF5BigIP` + +```python +value: models.CreateInputSystemByPackInputF5BigIP = /* values here */ +``` + +### `models.CreateInputSystemByPackInputBeyondtrustHec` + +```python +value: models.CreateInputSystemByPackInputBeyondtrustHec = /* values here */ +``` + +### `models.CreateInputSystemByPackInputHashicorpHcpVaultDedicated` + +```python +value: models.CreateInputSystemByPackInputHashicorpHcpVaultDedicated = /* values here */ +``` + +### `models.CreateInputSystemByPackInputMimecastHec` + +```python +value: models.CreateInputSystemByPackInputMimecastHec = /* values here */ +``` + +### `models.CreateInputSystemByPackInputTrendMicroVisionOne` + +```python +value: models.CreateInputSystemByPackInputTrendMicroVisionOne = /* values here */ +``` + diff --git a/docs/models/createinputsystembypackinputakamaihec.md b/docs/models/createinputsystembypackinputakamaihec.md new file mode 100644 index 000000000..8c51690a2 --- /dev/null +++ b/docs/models/createinputsystembypackinputakamaihec.md @@ -0,0 +1,40 @@ +# CreateInputSystemByPackInputAkamaiHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputAkamaiHecType](../models/createinputsystembypackinputakamaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputakamaihectype.md b/docs/models/createinputsystembypackinputakamaihectype.md new file mode 100644 index 000000000..d413f23f5 --- /dev/null +++ b/docs/models/createinputsystembypackinputakamaihectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputAkamaiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputAkamaiHecType + +value = CreateInputSystemByPackInputAkamaiHecType.AKAMAI_HEC +``` + + +## Values + +| Name | Value | +| ------------ | ------------ | +| `AKAMAI_HEC` | akamai_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputanthropicenterpriseanalytics.md b/docs/models/createinputsystembypackinputanthropicenterpriseanalytics.md new file mode 100644 index 000000000..717ff483a --- /dev/null +++ b/docs/models/createinputsystembypackinputanthropicenterpriseanalytics.md @@ -0,0 +1,32 @@ +# CreateInputSystemByPackInputAnthropicEnterpriseAnalytics + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType](../models/createinputsystembypackinputanthropicenterpriseanalyticstype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `api_key` | *Optional[str]* | :heavy_minus_sign: | API key | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored API key with read:analytics scope | +| `content_config` | List[[models.CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig](../models/createinputsystembypackinputanthropicenterpriseanalyticscontentconfig.md)] | :heavy_check_mark: | Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout. Use 0 to disable. | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.RetryRulesType]](../models/retryrulestype.md) | :heavy_minus_sign: | N/A | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputanthropicenterpriseanalyticscontentconfig.md b/docs/models/createinputsystembypackinputanthropicenterpriseanalyticscontentconfig.md new file mode 100644 index 000000000..2f4222915 --- /dev/null +++ b/docs/models/createinputsystembypackinputanthropicenterpriseanalyticscontentconfig.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `content_type` | [models.CreateInputSystemByPackContentType](../models/createinputsystembypackcontenttype.md) | :heavy_check_mark: | Content type | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark. | +| `manage_state` | *Optional[bool]* | :heavy_minus_sign: | Manage state | +| `group_by` | List[[models.CreateInputSystemByPackGroupBy](../models/createinputsystembypackgroupby.md)] | :heavy_minus_sign: | Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket. | +| `bucket_width` | [Optional[models.CreateInputSystemByPackBucketWidth]](../models/createinputsystembypackbucketwidth.md) | :heavy_minus_sign: | Time bucket size for aggregated results. Smaller buckets yield more events per collection run. | +| `cron_schedule` | *str* | :heavy_check_mark: | Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results. | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d. | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputanthropicenterpriseanalyticstype.md b/docs/models/createinputsystembypackinputanthropicenterpriseanalyticstype.md new file mode 100644 index 000000000..76b0df644 --- /dev/null +++ b/docs/models/createinputsystembypackinputanthropicenterpriseanalyticstype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType + +value = CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS +``` + + +## Values + +| Name | Value | +| -------------------------------- | -------------------------------- | +| `ANTHROPIC_ENTERPRISE_ANALYTICS` | anthropic_enterprise_analytics | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputappscope.md b/docs/models/createinputsystembypackinputappscope.md index dd08a9a20..97263f29c 100644 --- a/docs/models/createinputsystembypackinputappscope.md +++ b/docs/models/createinputsystembypackinputappscope.md @@ -27,7 +27,7 @@ | `enable_unix_path` | *Optional[bool]* | :heavy_minus_sign: | Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port. | | `filter_` | [Optional[models.CreateInputSystemByPackInputAppscopeFilter]](../models/createinputsystembypackinputappscopefilter.md) | :heavy_minus_sign: | N/A | | `persistence` | [Optional[models.CreateInputSystemByPackInputAppscopePersistence]](../models/createinputsystembypackinputappscopepersistence.md) | :heavy_minus_sign: | Persistence | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | | `port` | *Optional[float]* | :heavy_minus_sign: | Port to listen on | diff --git a/docs/models/createinputsystembypackinputaquasecurityhec.md b/docs/models/createinputsystembypackinputaquasecurityhec.md new file mode 100644 index 000000000..b7dd0d93f --- /dev/null +++ b/docs/models/createinputsystembypackinputaquasecurityhec.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputAquaSecurityHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputAquaSecurityHecType](../models/createinputsystembypackinputaquasecurityhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputaquasecurityhectype.md b/docs/models/createinputsystembypackinputaquasecurityhectype.md new file mode 100644 index 000000000..7dd5aa31e --- /dev/null +++ b/docs/models/createinputsystembypackinputaquasecurityhectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputAquaSecurityHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputAquaSecurityHecType + +value = CreateInputSystemByPackInputAquaSecurityHecType.AQUA_SECURITY_HEC +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `AQUA_SECURITY_HEC` | aqua_security_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputazureblob.md b/docs/models/createinputsystembypackinputazureblob.md index ff64e18d9..6d6c7bd20 100644 --- a/docs/models/createinputsystembypackinputazureblob.md +++ b/docs/models/createinputsystembypackinputazureblob.md @@ -22,12 +22,14 @@ | `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | | `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | | `skip_on_error` | *Optional[bool]* | :heavy_minus_sign: | Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors. | +| `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `parquet_chunk_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum file size for each Parquet chunk | | `parquet_chunk_download_timeout` | *Optional[float]* | :heavy_minus_sign: | The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified. | | `auth_type` | [Optional[models.AuthenticationMethodOptions]](../models/authenticationmethodoptions.md) | :heavy_minus_sign: | Authentication method | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `connection_string` | *Optional[str]* | :heavy_minus_sign: | Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | diff --git a/docs/models/createinputsystembypackinputazurevnetflowlog.md b/docs/models/createinputsystembypackinputazurevnetflowlog.md new file mode 100644 index 000000000..935750ba9 --- /dev/null +++ b/docs/models/createinputsystembypackinputazurevnetflowlog.md @@ -0,0 +1,44 @@ +# CreateInputSystemByPackInputAzureVnetFlowLog + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputAzureVnetFlowLogType](../models/createinputsystembypackinputazurevnetflowlogtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `queue_name` | *str* | :heavy_check_mark: | The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}` | +| `file_filter` | *Optional[str]* | :heavy_minus_sign: | Regex matching file names to download and process. Defaults to: .* | +| `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request. | +| `num_receivers` | *Optional[float]* | :heavy_minus_sign: | How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead. | +| `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | +| `max_dequeue_count` | *Optional[float]* | :heavy_minus_sign: | Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers. | +| `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | +| `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | +| `client_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's client ID | +| `azure_cloud` | *Optional[str]* | :heavy_minus_sign: | The Azure cloud to use. Defaults to Azure Public Cloud. | +| `endpoint_suffix` | *Optional[str]* | :heavy_minus_sign: | Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net. | +| `client_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `certificate` | [Optional[models.CertificateType]](../models/certificatetype.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_queue_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime. | +| `template_storage_account_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_azure_cloud` | *Optional[str]* | :heavy_minus_sign: | Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputazurevnetflowlogtype.md b/docs/models/createinputsystembypackinputazurevnetflowlogtype.md new file mode 100644 index 000000000..edc95f38b --- /dev/null +++ b/docs/models/createinputsystembypackinputazurevnetflowlogtype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputAzureVnetFlowLogType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputAzureVnetFlowLogType + +value = CreateInputSystemByPackInputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG +``` + + +## Values + +| Name | Value | +| --------------------- | --------------------- | +| `AZURE_VNET_FLOW_LOG` | azure_vnet_flow_log | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputbeyondtrusthec.md b/docs/models/createinputsystembypackinputbeyondtrusthec.md new file mode 100644 index 000000000..202ea3cbe --- /dev/null +++ b/docs/models/createinputsystembypackinputbeyondtrusthec.md @@ -0,0 +1,44 @@ +# CreateInputSystemByPackInputBeyondtrustHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputBeyondtrustHecType](../models/createinputsystembypackinputbeyondtrusthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputbeyondtrusthectype.md b/docs/models/createinputsystembypackinputbeyondtrusthectype.md new file mode 100644 index 000000000..5790b48e6 --- /dev/null +++ b/docs/models/createinputsystembypackinputbeyondtrusthectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputBeyondtrustHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputBeyondtrustHecType + +value = CreateInputSystemByPackInputBeyondtrustHecType.BEYONDTRUST_HEC +``` + + +## Values + +| Name | Value | +| ----------------- | ----------------- | +| `BEYONDTRUST_HEC` | beyondtrust_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputconfluentcloud.md b/docs/models/createinputsystembypackinputconfluentcloud.md index 48613c959..7da4cc6e8 100644 --- a/docs/models/createinputsystembypackinputconfluentcloud.md +++ b/docs/models/createinputsystembypackinputconfluentcloud.md @@ -39,6 +39,7 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputcribllakehttp.md b/docs/models/createinputsystembypackinputcribllakehttp.md index 5c3780048..e937443d1 100644 --- a/docs/models/createinputsystembypackinputcribllakehttp.md +++ b/docs/models/createinputsystembypackinputcribllakehttp.md @@ -35,7 +35,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.CreateInputSystemByPackAuthTokensExt](../models/createinputsystembypackauthtokensext.md)] | :heavy_minus_sign: | Auth tokens | +| `auth_tokens_ext` | List[[models.CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt](../models/createinputsystembypackinputcribllakehttpauthtokensext.md)] | :heavy_minus_sign: | Auth tokens | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputcribllakehttpauthtokensext.md b/docs/models/createinputsystembypackinputcribllakehttpauthtokensext.md new file mode 100644 index 000000000..0223e7e4e --- /dev/null +++ b/docs/models/createinputsystembypackinputcribllakehttpauthtokensext.md @@ -0,0 +1,17 @@ +# CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt + + +## Supported Types + +### `models.CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtokensextitemstype.md b/docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..d03693e82 --- /dev/null +++ b/docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,14 @@ +# CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `token` | *str* | :heavy_check_mark: | Token | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata]](../models/createinputsystembypackinputhttpauthtokensextitemstypesplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata]](../models/createinputsystembypackinputhttpauthtokensextitemstypeelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtypesecretconstraint.md b/docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..0c7cfbacd --- /dev/null +++ b/docs/models/createinputsystembypackinputcribllakehttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,14 @@ +# CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Token | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata]](../models/createinputsystembypackinputhttpauthtypesecretconstraintsplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata]](../models/createinputsystembypackinputhttpauthtypesecretconstraintelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputeventhub.md b/docs/models/createinputsystembypackinputeventhub.md index 3d6990f5b..f362d85f6 100644 --- a/docs/models/createinputsystembypackinputeventhub.md +++ b/docs/models/createinputsystembypackinputeventhub.md @@ -39,6 +39,7 @@ | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `minimize_duplicates` | *Optional[bool]* | :heavy_minus_sign: | Minimize duplicate events by starting only one consumer for each topic partition | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputeventhubamqp.md b/docs/models/createinputsystembypackinputeventhubamqp.md index 97054f043..964507d2b 100644 --- a/docs/models/createinputsystembypackinputeventhubamqp.md +++ b/docs/models/createinputsystembypackinputeventhubamqp.md @@ -31,6 +31,7 @@ | `connection_max_backoff` | *Optional[int]* | :heavy_minus_sign: | Maximum delay between reconnection attempts, in milliseconds | | `connection_timeout_in_ms` | *Optional[int]* | :heavy_minus_sign: | Maximum time to wait for a connection to complete | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputeventhubamqpauthenticationmethod.md b/docs/models/createinputsystembypackinputeventhubamqpauthenticationmethod.md deleted file mode 100644 index 7ab1c8381..000000000 --- a/docs/models/createinputsystembypackinputeventhubamqpauthenticationmethod.md +++ /dev/null @@ -1,24 +0,0 @@ -# CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod - -Authentication method - -## Example Usage - -```python -from cribl_control_plane.models import CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod - -value = CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod.SECRET - -# Open enum: unrecognized values are captured as UnrecognizedStr -``` - - -## Values - -| Name | Value | -| ---------------------- | ---------------------- | -| `SECRET` | secret | -| `CLIENT_SECRET` | clientSecret | -| `CLIENT_CERT` | clientCert | -| `CLIENT_ASSERTION` | clientAssertion | -| `CLIENT_ASSERTION_RPC` | clientAssertion_rpc | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputexec.md b/docs/models/createinputsystembypackinputexec.md index 9330959df..ebfa48fa8 100644 --- a/docs/models/createinputsystembypackinputexec.md +++ b/docs/models/createinputsystembypackinputexec.md @@ -22,6 +22,7 @@ | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `interval` | *Optional[float]* | :heavy_minus_sign: | Interval between command executions in seconds. | | `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule to execute the command on. | diff --git a/docs/models/createinputsystembypackinputextrahoprevealx360.md b/docs/models/createinputsystembypackinputextrahoprevealx360.md new file mode 100644 index 000000000..f3e9d5b64 --- /dev/null +++ b/docs/models/createinputsystembypackinputextrahoprevealx360.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputExtrahopRevealx360 + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputExtrahopRevealx360Type](../models/createinputsystembypackinputextrahoprevealx360type.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputextrahoprevealx360type.md b/docs/models/createinputsystembypackinputextrahoprevealx360type.md new file mode 100644 index 000000000..49e8d5a2f --- /dev/null +++ b/docs/models/createinputsystembypackinputextrahoprevealx360type.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputExtrahopRevealx360Type + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputExtrahopRevealx360Type + +value = CreateInputSystemByPackInputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360 +``` + + +## Values + +| Name | Value | +| ---------------------- | ---------------------- | +| `EXTRAHOP_REVEALX_360` | extrahop_revealx_360 | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputf5bigip.md b/docs/models/createinputsystembypackinputf5bigip.md new file mode 100644 index 000000000..917cbbbda --- /dev/null +++ b/docs/models/createinputsystembypackinputf5bigip.md @@ -0,0 +1,47 @@ +# CreateInputSystemByPackInputF5BigIP + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputF5BigIPType](../models/createinputsystembypackinputf5bigiptype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputf5bigiptype.md b/docs/models/createinputsystembypackinputf5bigiptype.md new file mode 100644 index 000000000..954b3df76 --- /dev/null +++ b/docs/models/createinputsystembypackinputf5bigiptype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputF5BigIPType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputF5BigIPType + +value = CreateInputSystemByPackInputF5BigIPType.F5_BIG_IP +``` + + +## Values + +| Name | Value | +| ----------- | ----------- | +| `F5_BIG_IP` | f5_big_ip | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputfile.md b/docs/models/createinputsystembypackinputfile.md index 4419ea18e..f8c0d3dac 100644 --- a/docs/models/createinputsystembypackinputfile.md +++ b/docs/models/createinputsystembypackinputfile.md @@ -26,10 +26,12 @@ | `check_file_mod_time` | *Optional[bool]* | :heavy_minus_sign: | Skip files with modification times earlier than the maximum age duration | | `force_text` | *Optional[bool]* | :heavy_minus_sign: | Forces files containing binary data to be streamed as text | | `hash_len` | *Optional[float]* | :heavy_minus_sign: | Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files. | +| `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `disable_stale_channel_flush` | *Optional[bool]* | :heavy_minus_sign: | When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS. | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `path` | *Optional[str]* | :heavy_minus_sign: | Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/). | | `depth` | *Optional[float]* | :heavy_minus_sign: | Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth. | @@ -37,6 +39,8 @@ | `delete_files` | *Optional[bool]* | :heavy_minus_sign: | Delete files after they have been collected | | `salt_hash` | *Optional[bool]* | :heavy_minus_sign: | Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion. | | `optimize_leaf_directories` | *Optional[bool]* | :heavy_minus_sign: | Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories. | +| `enable_discovery_throttle` | *Optional[bool]* | :heavy_minus_sign: | When enabled, discovery will throttle CPU usage to the configured target percentage. | +| `discovery_throttle_cpu_percent` | *Optional[float]* | :heavy_minus_sign: | Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times. | | `include_unidentifiable_binary` | *Optional[bool]* | :heavy_minus_sign: | Stream binary files as Base64-encoded chunks | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputgigamonhec.md b/docs/models/createinputsystembypackinputgigamonhec.md new file mode 100644 index 000000000..896416a2f --- /dev/null +++ b/docs/models/createinputsystembypackinputgigamonhec.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputGigamonHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputGigamonHecType](../models/createinputsystembypackinputgigamonhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputgigamonhectype.md b/docs/models/createinputsystembypackinputgigamonhectype.md new file mode 100644 index 000000000..8888f5bbe --- /dev/null +++ b/docs/models/createinputsystembypackinputgigamonhectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputGigamonHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputGigamonHecType + +value = CreateInputSystemByPackInputGigamonHecType.GIGAMON_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `GIGAMON_HEC` | gigamon_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputgooglepubsub.md b/docs/models/createinputsystembypackinputgooglepubsub.md index 6dc59e824..8bdf5405e 100644 --- a/docs/models/createinputsystembypackinputgooglepubsub.md +++ b/docs/models/createinputsystembypackinputgooglepubsub.md @@ -28,6 +28,7 @@ | `concurrency` | *Optional[float]* | :heavy_minus_sign: | How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5. | | `request_timeout` | *Optional[float]* | :heavy_minus_sign: | Pull request timeout, in milliseconds | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `ordered_delivery` | *Optional[bool]* | :heavy_minus_sign: | Receive events in the order they were added to the queue. The process sending events must have ordering enabled. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/createinputsystembypackinputhashicorphcpvaultdedicated.md b/docs/models/createinputsystembypackinputhashicorphcpvaultdedicated.md new file mode 100644 index 000000000..951340678 --- /dev/null +++ b/docs/models/createinputsystembypackinputhashicorphcpvaultdedicated.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputHashicorpHcpVaultDedicated + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType](../models/createinputsystembypackinputhashicorphcpvaultdedicatedtype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhashicorphcpvaultdedicatedtype.md b/docs/models/createinputsystembypackinputhashicorphcpvaultdedicatedtype.md new file mode 100644 index 000000000..30e74f400 --- /dev/null +++ b/docs/models/createinputsystembypackinputhashicorphcpvaultdedicatedtype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType + +value = CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED +``` + + +## Values + +| Name | Value | +| ------------------------------- | ------------------------------- | +| `HASHICORP_HCP_VAULT_DEDICATED` | hashicorp_hcp_vault_dedicated | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttp.md b/docs/models/createinputsystembypackinputhttp.md index 5d91cb647..d9a3034a9 100644 --- a/docs/models/createinputsystembypackinputhttp.md +++ b/docs/models/createinputsystembypackinputhttp.md @@ -35,7 +35,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.CreateInputSystemByPackInputHTTPAuthTokensExt](../models/createinputsystembypackinputhttpauthtokensext.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputhttpauthtokensext.md b/docs/models/createinputsystembypackinputhttpauthtokensext.md new file mode 100644 index 000000000..7bd85af29 --- /dev/null +++ b/docs/models/createinputsystembypackinputhttpauthtokensext.md @@ -0,0 +1,17 @@ +# CreateInputSystemByPackInputHTTPAuthTokensExt + + +## Supported Types + +### `models.CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/createinputsystembypackinputhttpauthtokensextitemstypeelasticsearchmetadata.md b/docs/models/createinputsystembypackinputhttpauthtokensextitemstypeelasticsearchmetadata.md new file mode 100644 index 000000000..b1934659a --- /dev/null +++ b/docs/models/createinputsystembypackinputhttpauthtokensextitemstypeelasticsearchmetadata.md @@ -0,0 +1,9 @@ +# CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Elasticsearch | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttpauthtokensextitemstypesplunkhecmetadata.md b/docs/models/createinputsystembypackinputhttpauthtokensextitemstypesplunkhecmetadata.md new file mode 100644 index 000000000..bc5d24d59 --- /dev/null +++ b/docs/models/createinputsystembypackinputhttpauthtokensextitemstypesplunkhecmetadata.md @@ -0,0 +1,10 @@ +# CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | When enabled, the token value is available on events as __hecToken | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `allowed_indexes_at_token` | List[*str*] | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttpauthtypesecretconstraintelasticsearchmetadata.md b/docs/models/createinputsystembypackinputhttpauthtypesecretconstraintelasticsearchmetadata.md new file mode 100644 index 000000000..76ae6c2d2 --- /dev/null +++ b/docs/models/createinputsystembypackinputhttpauthtypesecretconstraintelasticsearchmetadata.md @@ -0,0 +1,9 @@ +# CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Elasticsearch | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttpauthtypesecretconstraintsplunkhecmetadata.md b/docs/models/createinputsystembypackinputhttpauthtypesecretconstraintsplunkhecmetadata.md new file mode 100644 index 000000000..ba8faa606 --- /dev/null +++ b/docs/models/createinputsystembypackinputhttpauthtypesecretconstraintsplunkhecmetadata.md @@ -0,0 +1,10 @@ +# CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | When enabled, the token value is available on events as __hecToken | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `allowed_indexes_at_token` | List[*str*] | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttpinputhttpauthtokensextitemstype.md b/docs/models/createinputsystembypackinputhttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..262592e8d --- /dev/null +++ b/docs/models/createinputsystembypackinputhttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,12 @@ +# CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttpinputhttpauthtypesecretconstraint.md b/docs/models/createinputsystembypackinputhttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..970a207b2 --- /dev/null +++ b/docs/models/createinputsystembypackinputhttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttpraw.md b/docs/models/createinputsystembypackinputhttpraw.md index c385f00d8..7cbc2a5ad 100644 --- a/docs/models/createinputsystembypackinputhttpraw.md +++ b/docs/models/createinputsystembypackinputhttpraw.md @@ -32,10 +32,11 @@ | `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion](../models/createinputsystembypackinputhttprawauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS. | | `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use "*" to allow all headers. | | `access_control_allow_methods` | List[*str*] | :heavy_minus_sign: | HTTP methods echoed in Access-Control-Allow-Methods on preflight. | diff --git a/docs/models/createinputsystembypackinputhttprawauthtokensext.md b/docs/models/createinputsystembypackinputhttprawauthtokensext.md new file mode 100644 index 000000000..237c616d8 --- /dev/null +++ b/docs/models/createinputsystembypackinputhttprawauthtokensext.md @@ -0,0 +1,12 @@ +# CreateInputSystemByPackInputHTTPRawAuthTokensExt + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputhttprawauthtokensextunion.md b/docs/models/createinputsystembypackinputhttprawauthtokensextunion.md new file mode 100644 index 000000000..c2af66366 --- /dev/null +++ b/docs/models/createinputsystembypackinputhttprawauthtokensextunion.md @@ -0,0 +1,17 @@ +# CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion + + +## Supported Types + +### `models.CreateInputSystemByPackInputHTTPRawAuthTokensExt` + +```python +value: models.CreateInputSystemByPackInputHTTPRawAuthTokensExt = /* values here */ +``` + +### `models.CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint` + +```python +value: models.CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/createinputsystembypackinputhttprawinputhttpauthtypesecretconstraint.md b/docs/models/createinputsystembypackinputhttprawinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..e9217f7bb --- /dev/null +++ b/docs/models/createinputsystembypackinputhttprawinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputjournalfiles.md b/docs/models/createinputsystembypackinputjournalfiles.md index 66c4ebd7a..c88dfde00 100644 --- a/docs/models/createinputsystembypackinputjournalfiles.md +++ b/docs/models/createinputsystembypackinputjournalfiles.md @@ -23,6 +23,7 @@ | `max_age_dur` | *Optional[str]* | :heavy_minus_sign: | The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters. | | `suppress_missing_path_errors` | *Optional[bool]* | :heavy_minus_sign: | Suppress errors when search path does not exist | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputkafka.md b/docs/models/createinputsystembypackinputkafka.md index 7d627f432..3f58991f0 100644 --- a/docs/models/createinputsystembypackinputkafka.md +++ b/docs/models/createinputsystembypackinputkafka.md @@ -39,6 +39,7 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputkinesis.md b/docs/models/createinputsystembypackinputkinesis.md index c6d6ed5cf..d9d7d7e0d 100644 --- a/docs/models/createinputsystembypackinputkinesis.md +++ b/docs/models/createinputsystembypackinputkinesis.md @@ -36,6 +36,7 @@ | `verify_kpl_check_sums` | *Optional[bool]* | :heavy_minus_sign: | Verify Kinesis Producer Library (KPL) event checksums | | `avoid_duplicates` | *Optional[bool]* | :heavy_minus_sign: | When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputsystembypackinputmicrosoftcopilot.md b/docs/models/createinputsystembypackinputmicrosoftcopilot.md new file mode 100644 index 000000000..7c2a99864 --- /dev/null +++ b/docs/models/createinputsystembypackinputmicrosoftcopilot.md @@ -0,0 +1,48 @@ +# CreateInputSystemByPackInputMicrosoftCopilot + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputMicrosoftCopilotType](../models/createinputsystembypackinputmicrosoftcopilottype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `tenant_id` | *str* | :heavy_check_mark: | Directory (tenant) ID from Azure Active Directory | +| `client_id` | *str* | :heavy_check_mark: | Application (client) ID from the app registration | +| `resource` | *Optional[str]* | :heavy_minus_sign: | Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type. | +| `auth_type` | [Optional[models.CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod]](../models/createinputsystembypackinputmicrosoftcopilotauthenticationmethod.md) | :heavy_minus_sign: | Select authentication method. | +| `plan_type` | [Optional[models.CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan]](../models/createinputsystembypackinputmicrosoftcopilotsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule for collection runs | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run. | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `page_size` | *Optional[int]* | :heavy_minus_sign: | Number of interactions to request per page ($top). Maximum 1000. | +| `app_class_filter` | List[*str*] | :heavy_minus_sign: | Limit collection to specific Copilot app classes. Leave empty to collect all. | +| `filter_by_license` | *Optional[bool]* | :heavy_minus_sign: | Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time. | +| `sku_ids` | List[*str*] | :heavy_minus_sign: | Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans. | +| `manage_state` | [Optional[models.CreateInputSystemByPackInputMicrosoftCopilotManageState]](../models/createinputsystembypackinputmicrosoftcopilotmanagestate.md) | :heavy_minus_sign: | N/A | +| `timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely. | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.CreateInputSystemByPackRetryRules]](../models/createinputsystembypackretryrules.md) | :heavy_minus_sign: | N/A | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references the client secret from your app registration | +| `cert_options` | [Optional[models.CreateInputSystemByPackCertOptions]](../models/createinputsystembypackcertoptions.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_plan_type` | *Optional[str]* | :heavy_minus_sign: | Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmicrosoftcopilotauthenticationmethod.md b/docs/models/createinputsystembypackinputmicrosoftcopilotauthenticationmethod.md new file mode 100644 index 000000000..5f7439e15 --- /dev/null +++ b/docs/models/createinputsystembypackinputmicrosoftcopilotauthenticationmethod.md @@ -0,0 +1,21 @@ +# CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod + +Select authentication method. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod + +value = CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `OAUTH_SECRET` | oauthSecret | +| `OAUTH_CERT` | oauthCert | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmicrosoftcopilotmanagestate.md b/docs/models/createinputsystembypackinputmicrosoftcopilotmanagestate.md new file mode 100644 index 000000000..9b64499a3 --- /dev/null +++ b/docs/models/createinputsystembypackinputmicrosoftcopilotmanagestate.md @@ -0,0 +1,7 @@ +# CreateInputSystemByPackInputMicrosoftCopilotManageState + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmicrosoftcopilotsubscriptionplan.md b/docs/models/createinputsystembypackinputmicrosoftcopilotsubscriptionplan.md new file mode 100644 index 000000000..b7aa4674e --- /dev/null +++ b/docs/models/createinputsystembypackinputmicrosoftcopilotsubscriptionplan.md @@ -0,0 +1,23 @@ +# CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan + +Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan + +value = CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan.ENTERPRISE_GCC + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `ENTERPRISE_GCC` | enterprise_gcc | +| `GCC` | gcc | +| `GCC_HIGH` | gcc_high | +| `DOD` | dod | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmicrosoftcopilottype.md b/docs/models/createinputsystembypackinputmicrosoftcopilottype.md new file mode 100644 index 000000000..6e85ad2a4 --- /dev/null +++ b/docs/models/createinputsystembypackinputmicrosoftcopilottype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputMicrosoftCopilotType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputMicrosoftCopilotType + +value = CreateInputSystemByPackInputMicrosoftCopilotType.MICROSOFT_COPILOT +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `MICROSOFT_COPILOT` | microsoft_copilot | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmicrosoftgraph.md b/docs/models/createinputsystembypackinputmicrosoftgraph.md index 4888fbe36..ebf829bf0 100644 --- a/docs/models/createinputsystembypackinputmicrosoftgraph.md +++ b/docs/models/createinputsystembypackinputmicrosoftgraph.md @@ -40,7 +40,7 @@ | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | Directory ID (tenant identifier) in Azure Active Directory. | | `client_id` | *Optional[str]* | :heavy_minus_sign: | client_id to pass in the OAuth request parameter. | | `resource` | *Optional[str]* | :heavy_minus_sign: | Resource to pass in the OAuth request parameter. | -| `plan_type` | [Optional[models.CreateInputSystemByPackSubscriptionPlan]](../models/createinputsystembypacksubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | +| `plan_type` | [Optional[models.CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan]](../models/createinputsystembypackinputmicrosoftgraphsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your client_secret to pass in the OAuth request parameter. | | `cert_options` | [Optional[models.CertOptionsType]](../models/certoptionstype.md) | :heavy_minus_sign: | N/A | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/createinputsubscriptionplan.md b/docs/models/createinputsystembypackinputmicrosoftgraphsubscriptionplan.md similarity index 66% rename from docs/models/createinputsubscriptionplan.md rename to docs/models/createinputsystembypackinputmicrosoftgraphsubscriptionplan.md index af8529cf7..aec74beb2 100644 --- a/docs/models/createinputsubscriptionplan.md +++ b/docs/models/createinputsystembypackinputmicrosoftgraphsubscriptionplan.md @@ -1,13 +1,13 @@ -# CreateInputSubscriptionPlan +# CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise ## Example Usage ```python -from cribl_control_plane.models import CreateInputSubscriptionPlan +from cribl_control_plane.models import CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan -value = CreateInputSubscriptionPlan.ENTERPRISE_GCC +value = CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan.ENTERPRISE_GCC # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/createinputsystembypackinputmimecasthec.md b/docs/models/createinputsystembypackinputmimecasthec.md new file mode 100644 index 000000000..36192d024 --- /dev/null +++ b/docs/models/createinputsystembypackinputmimecasthec.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputMimecastHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputMimecastHecType](../models/createinputsystembypackinputmimecasthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmimecasthectype.md b/docs/models/createinputsystembypackinputmimecasthectype.md new file mode 100644 index 000000000..46ef83b08 --- /dev/null +++ b/docs/models/createinputsystembypackinputmimecasthectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputMimecastHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputMimecastHecType + +value = CreateInputSystemByPackInputMimecastHecType.MIMECAST_HEC +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `MIMECAST_HEC` | mimecast_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmodeldriventelemetry.md b/docs/models/createinputsystembypackinputmodeldriventelemetry.md index 9ca1e3edd..02e9a765b 100644 --- a/docs/models/createinputsystembypackinputmodeldriventelemetry.md +++ b/docs/models/createinputsystembypackinputmodeldriventelemetry.md @@ -3,26 +3,28 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *str* | :heavy_check_mark: | Unique ID for this input | -| `type` | [models.CreateInputSystemByPackInputModelDrivenTelemetryType](../models/createinputsystembypackinputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | -| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | -| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | -| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | -| `port` | *float* | :heavy_check_mark: | Port to listen on | -| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | -| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | -| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputModelDrivenTelemetryType](../models/createinputsystembypackinputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each. | +| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputmsk.md b/docs/models/createinputsystembypackinputmsk.md index beed3986d..5ed6fedf7 100644 --- a/docs/models/createinputsystembypackinputmsk.md +++ b/docs/models/createinputsystembypackinputmsk.md @@ -48,6 +48,7 @@ | `max_bytes_per_partition` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB). | | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputsystembypackinputopenaicontentconfig.md b/docs/models/createinputsystembypackinputopenaicontentconfig.md index 63bf7f334..bba5798f3 100644 --- a/docs/models/createinputsystembypackinputopenaicontentconfig.md +++ b/docs/models/createinputsystembypackinputopenaicontentconfig.md @@ -3,23 +3,23 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputSystemByPackInputOpenaiManageState]](../models/createinputsystembypackinputopenaimanagestate.md) | :heavy_minus_sign: | N/A | -| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | -| `pagination_type` | [models.CreateInputSystemByPackPaginationType](../models/createinputsystembypackpaginationtype.md) | :heavy_check_mark: | Pagination type | -| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | -| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | -| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | -| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | -| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | -| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | -| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | -| `latest` | *str* | :heavy_check_mark: | Relative to the current time | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `log_level` | [Optional[models.CreateInputSystemByPackInputOpenaiLogLevel]](../models/createinputsystembypackinputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | -| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputSystemByPackInputOpenaiManageState]](../models/createinputsystembypackinputopenaimanagestate.md) | :heavy_minus_sign: | N/A | +| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | +| `pagination_type` | [models.CreateInputSystemByPackPaginationType](../models/createinputsystembypackpaginationtype.md) | :heavy_check_mark: | Pagination type | +| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | +| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | +| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | +| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | +| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | +| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | +| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | +| `latest` | *str* | :heavy_check_mark: | Relative to the current time | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `log_level` | [Optional[models.CreateInputSystemByPackInputOpenaiLogLevel]](../models/createinputsystembypackinputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | +| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputopentelemetry.md b/docs/models/createinputsystembypackinputopentelemetry.md index a017be155..42377dff2 100644 --- a/docs/models/createinputsystembypackinputopentelemetry.md +++ b/docs/models/createinputsystembypackinputopentelemetry.md @@ -31,9 +31,11 @@ | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point | | `otlp_version` | [Optional[models.CreateInputSystemByPackOTLPVersion]](../models/createinputsystembypackotlpversion.md) | :heavy_minus_sign: | The version of OTLP Protobuf definitions to use when interpreting received data | | `auth_type` | [Optional[models.CreateInputSystemByPackInputOpenTelemetryAuthenticationType]](../models/createinputsystembypackinputopentelemetryauthenticationtype.md) | :heavy_minus_sign: | OpenTelemetry authentication type | -| `auth_methods_ext` | List[[models.CreateInputSystemByPackAuthMethodsExt](../models/createinputsystembypackauthmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted. | +| `auth_methods_ext` | List[[models.CreateInputSystemByPackAuthMethodsExt](../models/createinputsystembypackauthmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | diff --git a/docs/models/createinputsystembypackinputpingidentitypingone.md b/docs/models/createinputsystembypackinputpingidentitypingone.md new file mode 100644 index 000000000..b8c0b99d1 --- /dev/null +++ b/docs/models/createinputsystembypackinputpingidentitypingone.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputPingIdentityPingone + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputPingIdentityPingoneType](../models/createinputsystembypackinputpingidentitypingonetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputpingidentitypingonetype.md b/docs/models/createinputsystembypackinputpingidentitypingonetype.md new file mode 100644 index 000000000..cad4f87ac --- /dev/null +++ b/docs/models/createinputsystembypackinputpingidentitypingonetype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputPingIdentityPingoneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputPingIdentityPingoneType + +value = CreateInputSystemByPackInputPingIdentityPingoneType.PING_IDENTITY_PINGONE +``` + + +## Values + +| Name | Value | +| ----------------------- | ----------------------- | +| `PING_IDENTITY_PINGONE` | ping_identity_pingone | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputproofpointpod.md b/docs/models/createinputsystembypackinputproofpointpod.md new file mode 100644 index 000000000..0d9568643 --- /dev/null +++ b/docs/models/createinputsystembypackinputproofpointpod.md @@ -0,0 +1,31 @@ +# CreateInputSystemByPackInputProofpointPod + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputProofpointPodType](../models/createinputsystembypackinputproofpointpodtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `cluster_id` | *str* | :heavy_check_mark: | Proofpoint on Demand cluster ID. | +| `feed_type` | [models.CreateInputSystemByPackFeedType](../models/createinputsystembypackfeedtype.md) | :heavy_check_mark: | Proofpoint on Demand feed to ingest. | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `compress` | *Optional[bool]* | :heavy_minus_sign: | Compress the feed connection. | +| `handshake_timeout` | *Optional[float]* | :heavy_minus_sign: | Maximum time to wait for the connection handshake to complete. | +| `keep_alive_interval_sec` | *Optional[float]* | :heavy_minus_sign: | How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | Maximum number of consecutive keepalive pings that can go unanswered before reconnecting. | +| `max_message_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc. | +| `read_buffer_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_cluster_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputproofpointpodtype.md b/docs/models/createinputsystembypackinputproofpointpodtype.md new file mode 100644 index 000000000..5199cbd5d --- /dev/null +++ b/docs/models/createinputsystembypackinputproofpointpodtype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputProofpointPodType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputProofpointPodType + +value = CreateInputSystemByPackInputProofpointPodType.PROOFPOINT_POD +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `PROOFPOINT_POD` | proofpoint_pod | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputrawudp.md b/docs/models/createinputsystembypackinputrawudp.md index 0f71b1ea1..0e55430eb 100644 --- a/docs/models/createinputsystembypackinputrawudp.md +++ b/docs/models/createinputsystembypackinputrawudp.md @@ -23,6 +23,7 @@ | `ingest_raw_bytes` | *Optional[bool]* | :heavy_minus_sign: | If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram. | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputs3.md b/docs/models/createinputsystembypackinputs3.md index 36ca51dc6..42a34ef48 100644 --- a/docs/models/createinputsystembypackinputs3.md +++ b/docs/models/createinputsystembypackinputs3.md @@ -47,6 +47,7 @@ | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | | `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `tag_after_processing` | *Optional[bool]* | :heavy_minus_sign: | Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputsystembypackinputsailpointhec.md b/docs/models/createinputsystembypackinputsailpointhec.md new file mode 100644 index 000000000..dfbeea90e --- /dev/null +++ b/docs/models/createinputsystembypackinputsailpointhec.md @@ -0,0 +1,39 @@ +# CreateInputSystemByPackInputSailpointHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputSailpointHecType](../models/createinputsystembypackinputsailpointhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputsailpointhectype.md b/docs/models/createinputsystembypackinputsailpointhectype.md new file mode 100644 index 000000000..0ab06dfa4 --- /dev/null +++ b/docs/models/createinputsystembypackinputsailpointhectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputSailpointHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputSailpointHecType + +value = CreateInputSystemByPackInputSailpointHecType.SAILPOINT_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `SAILPOINT_HEC` | sailpoint_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputsplunk.md b/docs/models/createinputsystembypackinputsplunk.md index d9ed583f3..a60dbb199 100644 --- a/docs/models/createinputsystembypackinputsplunk.md +++ b/docs/models/createinputsystembypackinputsplunk.md @@ -27,6 +27,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `auth_tokens` | List[[models.CreateInputSystemByPackInputSplunkAuthToken](../models/createinputsystembypackinputsplunkauthtoken.md)] | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | | `max_s2_sversion` | [Optional[models.CreateInputSystemByPackMaxS2SVersion]](../models/createinputsystembypackmaxs2sversion.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | diff --git a/docs/models/createinputsystembypackinputsplunkauthtoken.md b/docs/models/createinputsystembypackinputsplunkauthtoken.md index 6f969730c..4680f8a0b 100644 --- a/docs/models/createinputsystembypackinputsplunkauthtoken.md +++ b/docs/models/createinputsystembypackinputsplunkauthtoken.md @@ -3,7 +3,9 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `token` | *str* | :heavy_check_mark: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputsplunkhec.md b/docs/models/createinputsystembypackinputsplunkhec.md index 20c4d0d8b..624134081 100644 --- a/docs/models/createinputsystembypackinputsplunkhec.md +++ b/docs/models/createinputsystembypackinputsplunkhec.md @@ -35,6 +35,7 @@ | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `use_fwd_timezone` | *Optional[bool]* | :heavy_minus_sign: | Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event | | `drop_control_fields` | *Optional[bool]* | :heavy_minus_sign: | Drop Splunk control fields such as `crcSalt` and `_savedPort`. If disabled, control fields are stored in the internal field `__ctrlFields`. | | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Extract and process Splunk-generated metrics as Cribl metrics | diff --git a/docs/models/createinputsystembypackinputsplunkhecauthtoken.md b/docs/models/createinputsystembypackinputsplunkhecauthtoken.md index 50d381e36..3c9e072d3 100644 --- a/docs/models/createinputsystembypackinputsplunkhecauthtoken.md +++ b/docs/models/createinputsystembypackinputsplunkhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the token is active and can be used for authentication. | diff --git a/docs/models/createinputsystembypackinputsqs.md b/docs/models/createinputsystembypackinputsqs.md index 03ae6233c..faff6980f 100644 --- a/docs/models/createinputsystembypackinputsqs.md +++ b/docs/models/createinputsystembypackinputsqs.md @@ -33,6 +33,7 @@ | `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/createinputsystembypackinputsyslogsyslog1.md b/docs/models/createinputsystembypackinputsyslogsyslog1.md index 1af2ee714..f90c52ed6 100644 --- a/docs/models/createinputsystembypackinputsyslogsyslog1.md +++ b/docs/models/createinputsystembypackinputsyslogsyslog1.md @@ -36,6 +36,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/createinputsystembypackinputsyslogsyslog2.md b/docs/models/createinputsystembypackinputsyslogsyslog2.md index fcc38baa9..3800a2165 100644 --- a/docs/models/createinputsystembypackinputsyslogsyslog2.md +++ b/docs/models/createinputsystembypackinputsyslogsyslog2.md @@ -36,6 +36,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/createinputsystembypackinputtcp.md b/docs/models/createinputsystembypackinputtcp.md index 29bf6b841..86a95334b 100644 --- a/docs/models/createinputsystembypackinputtcp.md +++ b/docs/models/createinputsystembypackinputtcp.md @@ -27,11 +27,12 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { "authToken" : "myToken", "fields": { "field1": "value1", "field2": "value2" } } | | `preprocess` | [Optional[models.PreprocessType]](../models/preprocesstype.md) | :heavy_minus_sign: | Optional preprocessing step that pipes collected data through an external command before ingestion. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputtcpjson.md b/docs/models/createinputsystembypackinputtcpjson.md index 393421c80..91da182ab 100644 --- a/docs/models/createinputsystembypackinputtcpjson.md +++ b/docs/models/createinputsystembypackinputtcpjson.md @@ -26,7 +26,7 @@ | `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Enable if the connection is proxied by a device that supports proxy protocol v1 or v2 | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | diff --git a/docs/models/createinputsystembypackinputtrellixhec.md b/docs/models/createinputsystembypackinputtrellixhec.md new file mode 100644 index 000000000..53074e5a2 --- /dev/null +++ b/docs/models/createinputsystembypackinputtrellixhec.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputTrellixHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputTrellixHecType](../models/createinputsystembypackinputtrellixhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputtrellixhectype.md b/docs/models/createinputsystembypackinputtrellixhectype.md new file mode 100644 index 000000000..011c54e64 --- /dev/null +++ b/docs/models/createinputsystembypackinputtrellixhectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputTrellixHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputTrellixHecType + +value = CreateInputSystemByPackInputTrellixHecType.TRELLIX_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `TRELLIX_HEC` | trellix_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputtrendmicrovisionone.md b/docs/models/createinputsystembypackinputtrendmicrovisionone.md new file mode 100644 index 000000000..099e47abe --- /dev/null +++ b/docs/models/createinputsystembypackinputtrendmicrovisionone.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputTrendMicroVisionOne + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputTrendMicroVisionOneType](../models/createinputsystembypackinputtrendmicrovisiononetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputtrendmicrovisiononetype.md b/docs/models/createinputsystembypackinputtrendmicrovisiononetype.md new file mode 100644 index 000000000..897b3c07b --- /dev/null +++ b/docs/models/createinputsystembypackinputtrendmicrovisiononetype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputTrendMicroVisionOneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputTrendMicroVisionOneType + +value = CreateInputSystemByPackInputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE +``` + + +## Values + +| Name | Value | +| ------------------------ | ------------------------ | +| `TREND_MICRO_VISION_ONE` | trend_micro_vision_one | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputvectraaihec.md b/docs/models/createinputsystembypackinputvectraaihec.md new file mode 100644 index 000000000..cd8c915a1 --- /dev/null +++ b/docs/models/createinputsystembypackinputvectraaihec.md @@ -0,0 +1,46 @@ +# CreateInputSystemByPackInputVectraAiHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this input | +| `type` | [models.CreateInputSystemByPackInputVectraAiHecType](../models/createinputsystembypackinputvectraaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputvectraaihectype.md b/docs/models/createinputsystembypackinputvectraaihectype.md new file mode 100644 index 000000000..c29aaf894 --- /dev/null +++ b/docs/models/createinputsystembypackinputvectraaihectype.md @@ -0,0 +1,18 @@ +# CreateInputSystemByPackInputVectraAiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackInputVectraAiHecType + +value = CreateInputSystemByPackInputVectraAiHecType.VECTRA_AI_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `VECTRA_AI_HEC` | vectra_ai_hec | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputwefauthenticationmethod.md b/docs/models/createinputsystembypackinputwefauthenticationmethod.md index 8caf0efca..db96ddec7 100644 --- a/docs/models/createinputsystembypackinputwefauthenticationmethod.md +++ b/docs/models/createinputsystembypackinputwefauthenticationmethod.md @@ -18,4 +18,5 @@ value = CreateInputSystemByPackInputWefAuthenticationMethod.CLIENT_CERT | Name | Value | | ------------- | ------------- | | `CLIENT_CERT` | clientCert | -| `KERBEROS` | kerberos | \ No newline at end of file +| `KERBEROS` | kerberos | +| `NEGOTIATE` | negotiate | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputwineventlogs.md b/docs/models/createinputsystembypackinputwineventlogs.md index fdd495082..aa57a49df 100644 --- a/docs/models/createinputsystembypackinputwineventlogs.md +++ b/docs/models/createinputsystembypackinputwineventlogs.md @@ -26,6 +26,7 @@ | `max_event_bytes` | *Optional[int]* | :heavy_minus_sign: | The maximum number of bytes in an event before it is flushed to the pipelines | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `disable_json_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | +| `include_empty_json_fields` | *Optional[bool]* | :heavy_minus_sign: | Preserve fields with empty values (such as '-') in the JSON output instead of omitting them | | `disable_xml_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputwizwebhook.md b/docs/models/createinputsystembypackinputwizwebhook.md index 052e97926..7b1970b89 100644 --- a/docs/models/createinputsystembypackinputwizwebhook.md +++ b/docs/models/createinputsystembypackinputwizwebhook.md @@ -35,7 +35,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion](../models/createinputsystembypackinputwizwebhookauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/createinputsystembypackinputwizwebhookauthtokensext1.md b/docs/models/createinputsystembypackinputwizwebhookauthtokensext1.md new file mode 100644 index 000000000..bfed2fa47 --- /dev/null +++ b/docs/models/createinputsystembypackinputwizwebhookauthtokensext1.md @@ -0,0 +1,12 @@ +# CreateInputSystemByPackInputWizWebhookAuthTokensExt1 + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputwizwebhookauthtokensext2.md b/docs/models/createinputsystembypackinputwizwebhookauthtokensext2.md new file mode 100644 index 000000000..ac231ee87 --- /dev/null +++ b/docs/models/createinputsystembypackinputwizwebhookauthtokensext2.md @@ -0,0 +1,12 @@ +# CreateInputSystemByPackInputWizWebhookAuthTokensExt2 + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/createinputsystembypackinputwizwebhookauthtokensextunion.md b/docs/models/createinputsystembypackinputwizwebhookauthtokensextunion.md new file mode 100644 index 000000000..845f0a15e --- /dev/null +++ b/docs/models/createinputsystembypackinputwizwebhookauthtokensextunion.md @@ -0,0 +1,17 @@ +# CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion + + +## Supported Types + +### `models.CreateInputSystemByPackInputWizWebhookAuthTokensExt1` + +```python +value: models.CreateInputSystemByPackInputWizWebhookAuthTokensExt1 = /* values here */ +``` + +### `models.CreateInputSystemByPackInputWizWebhookAuthTokensExt2` + +```python +value: models.CreateInputSystemByPackInputWizWebhookAuthTokensExt2 = /* values here */ +``` + diff --git a/docs/models/createinputsystembypackinputzscalerhecauthtoken.md b/docs/models/createinputsystembypackinputzscalerhecauthtoken.md index e5a4bb2e1..105be80c5 100644 --- a/docs/models/createinputsystembypackinputzscalerhecauthtoken.md +++ b/docs/models/createinputsystembypackinputzscalerhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enable token | diff --git a/docs/models/createinputsystembypackprojectdetails.md b/docs/models/createinputsystembypackprojectdetails.md index bb582c7e7..a4c206477 100644 --- a/docs/models/createinputsystembypackprojectdetails.md +++ b/docs/models/createinputsystembypackprojectdetails.md @@ -5,14 +5,14 @@ Project Details ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputSystemByPackProjectDetailsManageState]](../models/createinputsystembypackprojectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputSystemByPackProjectDetailsManageState]](../models/createinputsystembypackprojectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackprojects.md b/docs/models/createinputsystembypackprojects.md index aa8532297..abef17ab0 100644 --- a/docs/models/createinputsystembypackprojects.md +++ b/docs/models/createinputsystembypackprojects.md @@ -5,14 +5,14 @@ Projects ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.CreateInputSystemByPackProjectsManageState]](../models/createinputsystembypackprojectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.CreateInputSystemByPackProjectsManageState]](../models/createinputsystembypackprojectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/createinputsystembypackretryrules.md b/docs/models/createinputsystembypackretryrules.md new file mode 100644 index 000000000..3af19e5e5 --- /dev/null +++ b/docs/models/createinputsystembypackretryrules.md @@ -0,0 +1,15 @@ +# CreateInputSystemByPackRetryRules + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `type` | [models.RetryTypeOptionsHealthCheckCollectorConfRetryRules](../models/retrytypeoptionshealthcheckcollectorconfretryrules.md) | :heavy_check_mark: | The algorithm to use when performing HTTP retries | +| `interval` | *Optional[float]* | :heavy_minus_sign: | Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute). | +| `limit` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times to retry a failed HTTP request | +| `multiplier` | *Optional[float]* | :heavy_minus_sign: | Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on | +| `codes` | List[*float*] | :heavy_minus_sign: | List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503. | +| `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored. | +| `retry_connect_timeout` | *Optional[bool]* | :heavy_minus_sign: | Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs | +| `retry_connect_reset` | *Optional[bool]* | :heavy_minus_sign: | Retry request when a connection reset (ECONNRESET) error occurs | \ No newline at end of file diff --git a/docs/models/createinputsystembypacktlssettingsserverside.md b/docs/models/createinputsystembypacktlssettingsserverside.md index 8ced2b709..aa7239c5f 100644 --- a/docs/models/createinputsystembypacktlssettingsserverside.md +++ b/docs/models/createinputsystembypacktlssettingsserverside.md @@ -9,12 +9,12 @@ TLS settings (server side) | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | | `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enable or disable TLS. Defaults to enabled for Cloudflare sources. | | `request_cert` | *Optional[bool]* | :heavy_minus_sign: | Require clients to present their certificates. Used to perform client authentication using SSL certs. | +| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's) | | `common_name_regex` | *Optional[str]* | :heavy_minus_sign: | Regex matching allowable common names in peer certificates' subject attribute | | `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of the predefined certificate | | `priv_key_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled. | | `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to use to decrypt private key | | `cert_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled. | -| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `min_version` | [Optional[models.MinimumTLSVersionOptionsTLS]](../models/minimumtlsversionoptionstls.md) | :heavy_minus_sign: | Minimum TLS version | | `max_version` | [Optional[models.MaximumTLSVersionOptionsTLS]](../models/maximumtlsversionoptionstls.md) | :heavy_minus_sign: | Maximum TLS version | \ No newline at end of file diff --git a/docs/models/createinputsystembypackv3authenticationkeytype.md b/docs/models/createinputsystembypackv3authenticationkeytype.md new file mode 100644 index 000000000..898ffb155 --- /dev/null +++ b/docs/models/createinputsystembypackv3authenticationkeytype.md @@ -0,0 +1,21 @@ +# CreateInputSystemByPackV3AuthenticationKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackV3AuthenticationKeyType + +value = CreateInputSystemByPackV3AuthenticationKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createinputsystembypackv3privacykeytype.md b/docs/models/createinputsystembypackv3privacykeytype.md new file mode 100644 index 000000000..39ca2c246 --- /dev/null +++ b/docs/models/createinputsystembypackv3privacykeytype.md @@ -0,0 +1,21 @@ +# CreateInputSystemByPackV3PrivacyKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputSystemByPackV3PrivacyKeyType + +value = CreateInputSystemByPackV3PrivacyKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createinputsystembypackv3user.md b/docs/models/createinputsystembypackv3user.md index 7cec66166..729baec27 100644 --- a/docs/models/createinputsystembypackv3user.md +++ b/docs/models/createinputsystembypackv3user.md @@ -3,10 +3,14 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | -| `name` | *str* | :heavy_check_mark: | V3 name | -| `auth_protocol` | [Optional[models.CreateInputSystemByPackAuthenticationProtocol]](../models/createinputsystembypackauthenticationprotocol.md) | :heavy_minus_sign: | Authentication protocol | -| `auth_key` | *Optional[str]* | :heavy_minus_sign: | V3 authentication key | -| `priv_protocol` | [Optional[models.CreateInputSystemByPackPrivacyProtocol]](../models/createinputsystembypackprivacyprotocol.md) | :heavy_minus_sign: | Privacy protocol | -| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------ | +| `name` | *str* | :heavy_check_mark: | V3 name | +| `auth_protocol` | [Optional[models.CreateInputSystemByPackAuthenticationProtocol]](../models/createinputsystembypackauthenticationprotocol.md) | :heavy_minus_sign: | Authentication protocol | +| `auth_key_type` | [Optional[models.CreateInputSystemByPackV3AuthenticationKeyType]](../models/createinputsystembypackv3authenticationkeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | +| `auth_key` | *Optional[str]* | :heavy_minus_sign: | V3 authentication key | +| `auth_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `priv_protocol` | [Optional[models.CreateInputSystemByPackPrivacyProtocol]](../models/createinputsystembypackprivacyprotocol.md) | :heavy_minus_sign: | Privacy protocol | +| `priv_key_type` | [Optional[models.CreateInputSystemByPackV3PrivacyKeyType]](../models/createinputsystembypackv3privacykeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | +| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | +| `priv_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/createinputtlssettingsserverside.md b/docs/models/createinputtlssettingsserverside.md index c7d39de56..63a3a6bfb 100644 --- a/docs/models/createinputtlssettingsserverside.md +++ b/docs/models/createinputtlssettingsserverside.md @@ -9,12 +9,12 @@ TLS settings (server side) | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | | `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enable or disable TLS. Defaults to enabled for Cloudflare sources. | | `request_cert` | *Optional[bool]* | :heavy_minus_sign: | Require clients to present their certificates. Used to perform client authentication using SSL certs. | +| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's) | | `common_name_regex` | *Optional[str]* | :heavy_minus_sign: | Regex matching allowable common names in peer certificates' subject attribute | | `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of the predefined certificate | | `priv_key_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled. | | `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to use to decrypt private key | | `cert_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled. | -| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `min_version` | [Optional[models.MinimumTLSVersionOptionsTLS]](../models/minimumtlsversionoptionstls.md) | :heavy_minus_sign: | Minimum TLS version | | `max_version` | [Optional[models.MaximumTLSVersionOptionsTLS]](../models/maximumtlsversionoptionstls.md) | :heavy_minus_sign: | Maximum TLS version | \ No newline at end of file diff --git a/docs/models/createinputv3authenticationkeytype.md b/docs/models/createinputv3authenticationkeytype.md new file mode 100644 index 000000000..830ccb023 --- /dev/null +++ b/docs/models/createinputv3authenticationkeytype.md @@ -0,0 +1,21 @@ +# CreateInputV3AuthenticationKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputV3AuthenticationKeyType + +value = CreateInputV3AuthenticationKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createinputv3privacykeytype.md b/docs/models/createinputv3privacykeytype.md new file mode 100644 index 000000000..51225f8b2 --- /dev/null +++ b/docs/models/createinputv3privacykeytype.md @@ -0,0 +1,21 @@ +# CreateInputV3PrivacyKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import CreateInputV3PrivacyKeyType + +value = CreateInputV3PrivacyKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createinputv3user.md b/docs/models/createinputv3user.md index 883184dc2..950343aab 100644 --- a/docs/models/createinputv3user.md +++ b/docs/models/createinputv3user.md @@ -3,10 +3,14 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | -| `name` | *str* | :heavy_check_mark: | V3 name | -| `auth_protocol` | [Optional[models.CreateInputAuthenticationProtocol]](../models/createinputauthenticationprotocol.md) | :heavy_minus_sign: | Authentication protocol | -| `auth_key` | *Optional[str]* | :heavy_minus_sign: | V3 authentication key | -| `priv_protocol` | [Optional[models.CreateInputPrivacyProtocol]](../models/createinputprivacyprotocol.md) | :heavy_minus_sign: | Privacy protocol | -| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | +| `name` | *str* | :heavy_check_mark: | V3 name | +| `auth_protocol` | [Optional[models.CreateInputAuthenticationProtocol]](../models/createinputauthenticationprotocol.md) | :heavy_minus_sign: | Authentication protocol | +| `auth_key_type` | [Optional[models.CreateInputV3AuthenticationKeyType]](../models/createinputv3authenticationkeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | +| `auth_key` | *Optional[str]* | :heavy_minus_sign: | V3 authentication key | +| `auth_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `priv_protocol` | [Optional[models.CreateInputPrivacyProtocol]](../models/createinputprivacyprotocol.md) | :heavy_minus_sign: | Privacy protocol | +| `priv_key_type` | [Optional[models.CreateInputV3PrivacyKeyType]](../models/createinputv3privacykeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | +| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | +| `priv_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/createoutputauthtoken.md b/docs/models/createoutputauthtoken.md index 848129069..c6ecb3d52 100644 --- a/docs/models/createoutputauthtoken.md +++ b/docs/models/createoutputauthtoken.md @@ -3,8 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | -| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/createoutputeventformat.md b/docs/models/createoutputeventformat.md new file mode 100644 index 000000000..3a61391ca --- /dev/null +++ b/docs/models/createoutputeventformat.md @@ -0,0 +1,21 @@ +# CreateOutputEventFormat + +The format of the VPC Flow Log events + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputEventFormat + +value = CreateOutputEventFormat.JSON + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `JSON` | json | +| `CSV_ROW` | csv_row | \ No newline at end of file diff --git a/docs/models/createoutputindexerdiscoveryconfigs.md b/docs/models/createoutputindexerdiscoveryconfigs.md index 9cec65440..1de3443f0 100644 --- a/docs/models/createoutputindexerdiscoveryconfigs.md +++ b/docs/models/createoutputindexerdiscoveryconfigs.md @@ -12,6 +12,6 @@ List of configurations to set up indexer discovery in Splunk Indexer clustering | `refresh_interval_sec` | *float* | :heavy_check_mark: | Time interval, in seconds, between two consecutive indexer list fetches from cluster manager | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates. | | `auth_tokens` | List[[models.CreateOutputAuthToken](../models/createoutputauthtoken.md)] | :heavy_minus_sign: | Tokens required to authenticate to cluster manager for indexer discovery | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/createoutputoauthsecretsource.md b/docs/models/createoutputoauthsecretsource.md new file mode 100644 index 000000000..6a272602d --- /dev/null +++ b/docs/models/createoutputoauthsecretsource.md @@ -0,0 +1,21 @@ +# CreateOutputOAuthSecretSource + +Enter the OAuth secret directly, or select a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputOAuthSecretSource + +value = CreateOutputOAuthSecretSource.INLINE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `INLINE` | inline | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createoutputoutput.md b/docs/models/createoutputoutput.md index d3e7e2310..286a4625c 100644 --- a/docs/models/createoutputoutput.md +++ b/docs/models/createoutputoutput.md @@ -425,6 +425,12 @@ value: models.CreateOutputOutputDynatraceHTTP = /* values here */ value: models.CreateOutputOutputDynatraceOtlp = /* values here */ ``` +### `models.CreateOutputOutputTraversalOtlp` + +```python +value: models.CreateOutputOutputTraversalOtlp = /* values here */ +``` + ### `models.CreateOutputOutputSentinelOneAiSiem` ```python @@ -509,3 +515,9 @@ value: models.CreateOutputOutputAlibabaCloudS3 = /* values here */ value: models.CreateOutputOutputIbmCloudS3 = /* values here */ ``` +### `models.CreateOutputOutputDatabricksZerobus` + +```python +value: models.CreateOutputOutputDatabricksZerobus = /* values here */ +``` + diff --git a/docs/models/createoutputoutputcribllake.md b/docs/models/createoutputoutputcribllake.md index 88d29fff8..864d5620b 100644 --- a/docs/models/createoutputoutputcribllake.md +++ b/docs/models/createoutputoutputcribllake.md @@ -34,6 +34,7 @@ | `dynamic_dataset` | *Optional[bool]* | :heavy_minus_sign: | N/A | | `max_closing_files_to_backpressure` | *Optional[float]* | :heavy_minus_sign: | N/A | | `max_concurrent_file_parts` | *Optional[float]* | :heavy_minus_sign: | N/A | +| `freshness_grace_period_sec` | *Optional[float]* | :heavy_minus_sign: | N/A | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `compress` | [Optional[models.CompressionOptionsHTTP]](../models/compressionoptionshttp.md) | :heavy_minus_sign: | Data compression format to apply to HTTP content before it is delivered | | `compression_level` | [Optional[models.CompressionLevelOptions]](../models/compressionleveloptions.md) | :heavy_minus_sign: | Compression level to apply before moving files to final destination | diff --git a/docs/models/createoutputoutputcriblsearchengine.md b/docs/models/createoutputoutputcriblsearchengine.md index 3bab41866..368ce7a8e 100644 --- a/docs/models/createoutputoutputcriblsearchengine.md +++ b/docs/models/createoutputoutputcriblsearchengine.md @@ -3,55 +3,56 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `id` | *str* | :heavy_check_mark: | Unique ID for this output | -| `type` | [models.CreateOutputOutputCriblSearchEngineType](../models/createoutputoutputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | -| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | -| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | -| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | -| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | -| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | -| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | -| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | -| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | -| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | -| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | -| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | -| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | -| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | -| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | -| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | -| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | -| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | -| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | -| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | -| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | -| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | -| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | -| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | -| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | -| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | -| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | -| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | -| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | -| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | -| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | -| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | -| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | -| `pq_controls` | [Optional[models.CreateOutputOutputCriblSearchEnginePqControls]](../models/createoutputoutputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputOutputCriblSearchEngineType](../models/createoutputoutputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | +| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | +| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `send_as` | [Optional[models.CreateOutputSendAs]](../models/createoutputsendas.md) | :heavy_minus_sign: | Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | +| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | +| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | +| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | +| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.CreateOutputOutputCriblSearchEnginePqControls]](../models/createoutputoutputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputoutputcrowdstrikenextgensiem.md b/docs/models/createoutputoutputcrowdstrikenextgensiem.md index b6faa9cf8..b9973f382 100644 --- a/docs/models/createoutputoutputcrowdstrikenextgensiem.md +++ b/docs/models/createoutputoutputcrowdstrikenextgensiem.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputoutputdatabrickszerobus.md b/docs/models/createoutputoutputdatabrickszerobus.md new file mode 100644 index 000000000..723820d13 --- /dev/null +++ b/docs/models/createoutputoutputdatabrickszerobus.md @@ -0,0 +1,42 @@ +# CreateOutputOutputDatabricksZerobus + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputOutputDatabricksZerobusType](../models/createoutputoutputdatabrickszerobustype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `workspace_url` | *str* | :heavy_check_mark: | HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https:// | +| `workspace_id` | *str* | :heavy_check_mark: | Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace. | +| `zerobus_endpoint` | *str* | :heavy_check_mark: | Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com). | +| `client_id` | *str* | :heavy_check_mark: | OAuth client ID of the service principal authorized to write to the target table | +| `client_text_secret` | *str* | :heavy_check_mark: | OAuth client secret of the service principal | +| `table_name` | *str* | :heavy_check_mark: | Three-part Unity Catalog name of the target table: catalog.schema.table | +| `max_batch_size_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of the serialized records in a single ingest batch | +| `max_batch_records` | *Optional[int]* | :heavy_minus_sign: | Maximum number of records to include in a single ingest batch | +| `max_buffered_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped. | +| `max_inflight_batches` | *Optional[int]* | :heavy_minus_sign: | Maximum number of unacknowledged batches per Worker Process before blocking | +| `flush_period_sec` | *Optional[int]* | :heavy_minus_sign: | Maximum time, in seconds, to hold a batch before sending it | +| `ack_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting | +| `connection_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a new ingest stream to open before canceling it | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.CreateOutputOutputDatabricksZerobusPqControls]](../models/createoutputoutputdatabrickszerobuspqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file diff --git a/docs/models/executorspecificsettingstyperunnablejobexecutorexecutor.md b/docs/models/createoutputoutputdatabrickszerobuspqcontrols.md similarity index 50% rename from docs/models/executorspecificsettingstyperunnablejobexecutorexecutor.md rename to docs/models/createoutputoutputdatabrickszerobuspqcontrols.md index d21b24598..2ef317d78 100644 --- a/docs/models/executorspecificsettingstyperunnablejobexecutorexecutor.md +++ b/docs/models/createoutputoutputdatabrickszerobuspqcontrols.md @@ -1,6 +1,6 @@ -# ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor +# CreateOutputOutputDatabricksZerobusPqControls -Executor-type-specific settings object. Shape varies by executor type. +Persistent queue controls. ## Fields diff --git a/docs/models/createoutputoutputdatabrickszerobustype.md b/docs/models/createoutputoutputdatabrickszerobustype.md new file mode 100644 index 000000000..ed5191b4b --- /dev/null +++ b/docs/models/createoutputoutputdatabrickszerobustype.md @@ -0,0 +1,18 @@ +# CreateOutputOutputDatabricksZerobusType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputOutputDatabricksZerobusType + +value = CreateOutputOutputDatabricksZerobusType.DATABRICKS_ZEROBUS +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `DATABRICKS_ZEROBUS` | databricks_zerobus | \ No newline at end of file diff --git a/docs/models/createoutputoutputexabeam.md b/docs/models/createoutputoutputexabeam.md index df744653d..9791001f9 100644 --- a/docs/models/createoutputoutputexabeam.md +++ b/docs/models/createoutputoutputexabeam.md @@ -3,48 +3,54 @@ ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *str* | :heavy_check_mark: | Unique ID for this output | -| `type` | [models.CreateOutputOutputExabeamType](../models/createoutputoutputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | -| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | -| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | -| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | -| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | -| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | -| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | -| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | -| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | -| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | -| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | -| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | -| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | -| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | -| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | -| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | -| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | -| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| -| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | -| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | -| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | -| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | -| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | -| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | -| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | -| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | -| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | -| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | -| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputOutputExabeamType](../models/createoutputoutputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | +| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | +| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | +| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | +| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | +| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | +| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | +| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | +| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | +| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | +| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | +| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | +| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | +| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | +| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | +| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | +| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | +| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| +| `aws_authentication_method` | [Optional[models.CreateOutputOutputExabeamAuthenticationMethod]](../models/createoutputoutputexabeamauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | +| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | +| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | +| `hostname` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the "hostname" metadata field; omitted when empty or not a usable scalar. | +| `forwarder` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the "forwarder" metadata field; omitted when empty or not a usable scalar. | +| `origin` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "origin" metadata field; omitted when the result is not a non-empty object. | +| `logtags` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "logtags" metadata field; omitted when the result is not a non-empty object. | +| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | +| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | +| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | +| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | +| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | +| `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | +| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | +| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | +| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputoutputexabeamauthenticationmethod.md b/docs/models/createoutputoutputexabeamauthenticationmethod.md new file mode 100644 index 000000000..82554368b --- /dev/null +++ b/docs/models/createoutputoutputexabeamauthenticationmethod.md @@ -0,0 +1,21 @@ +# CreateOutputOutputExabeamAuthenticationMethod + +Authentication method + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputOutputExabeamAuthenticationMethod + +value = CreateOutputOutputExabeamAuthenticationMethod.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createoutputoutputhumiohec.md b/docs/models/createoutputoutputhumiohec.md index 892f7b931..5ffeb7531 100644 --- a/docs/models/createoutputoutputhumiohec.md +++ b/docs/models/createoutputoutputhumiohec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputoutputrouter.md b/docs/models/createoutputoutputrouter.md index 53c75e955..6d0a9e56a 100644 --- a/docs/models/createoutputoutputrouter.md +++ b/docs/models/createoutputoutputrouter.md @@ -3,14 +3,15 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *str* | :heavy_check_mark: | Unique ID for this output | -| `type` | [models.CreateOutputOutputRouterType](../models/createoutputoutputroutertype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `rules` | List[[models.CreateOutputRule](../models/createoutputrule.md)] | :heavy_check_mark: | Event routing rules | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputOutputRouterType](../models/createoutputoutputroutertype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `report_branch_metrics` | *Optional[bool]* | :heavy_minus_sign: | Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule. | +| `rules` | List[[models.CreateOutputRule](../models/createoutputrule.md)] | :heavy_check_mark: | Event routing rules | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputoutputsentinel.md b/docs/models/createoutputoutputsentinel.md index 77653d7da..c83c55c24 100644 --- a/docs/models/createoutputoutputsentinel.md +++ b/docs/models/createoutputoutputsentinel.md @@ -30,11 +30,11 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `auth_type` | [Optional[models.CreateOutputAuthType]](../models/createoutputauthtype.md) | :heavy_minus_sign: | Discriminator value. | | `login_url` | *str* | :heavy_check_mark: | URL for OAuth | -| `secret` | *str* | :heavy_check_mark: | Secret parameter value to pass in request body | | `refresh_token_field` | *Optional[str]* | :heavy_minus_sign: | Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials. | | `rotate_refresh_token` | *Optional[bool]* | :heavy_minus_sign: | @{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use. | | `refresh_url` | *Optional[str]* | :heavy_minus_sign: | Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL. | | `refresh_request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_minus_sign: | Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret. | +| `oauth_secret_source` | [Optional[models.CreateOutputOAuthSecretSource]](../models/createoutputoauthsecretsource.md) | :heavy_minus_sign: | Enter the OAuth secret directly, or select a stored text secret | | `client_id` | *str* | :heavy_check_mark: | JavaScript expression to compute the Client ID for the Azure application. Can be a constant. | | `scope` | *Optional[str]* | :heavy_minus_sign: | Scope to pass in the OAuth request | | `endpoint_url_configuration` | [models.CreateOutputEndpointConfiguration](../models/createoutputendpointconfiguration.md) | :heavy_check_mark: | Enter the data collection endpoint URL or the individual ID | @@ -61,6 +61,8 @@ | `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | | `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | | `pq_controls` | [Optional[models.CreateOutputOutputSentinelPqControls]](../models/createoutputoutputsentinelpqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `secret` | *Optional[str]* | :heavy_minus_sign: | Secret parameter value to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret value | | `url` | *Optional[str]* | :heavy_minus_sign: | URL to send events to. Can be overwritten by an event's __url field. | | `dcr_id` | *Optional[str]* | :heavy_minus_sign: | Immutable ID for the Data Collection Rule (DCR) | | `dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com` | @@ -69,10 +71,10 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | -| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_refresh_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime. | | `template_scope` | *Optional[str]* | :heavy_minus_sign: | Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime. | +| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | | `template_dcr_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime. | | `template_dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime. | diff --git a/docs/models/createoutputoutputsentineloneaisiem.md b/docs/models/createoutputoutputsentineloneaisiem.md index 54f94eb17..ef759146f 100644 --- a/docs/models/createoutputoutputsentineloneaisiem.md +++ b/docs/models/createoutputoutputsentineloneaisiem.md @@ -22,7 +22,7 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputoutputsignalfx.md b/docs/models/createoutputoutputsignalfx.md index 950a75681..116a0ef51 100644 --- a/docs/models/createoutputoutputsignalfx.md +++ b/docs/models/createoutputoutputsignalfx.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `realm` | *str* | :heavy_check_mark: | SignalFx realm name, e.g. "us0". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions). | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | diff --git a/docs/models/createoutputoutputsplunk.md b/docs/models/createoutputoutputsplunk.md index a8fd72964..0efba5d47 100644 --- a/docs/models/createoutputoutputsplunk.md +++ b/docs/models/createoutputoutputsplunk.md @@ -23,7 +23,7 @@ | `log_failed_requests` | *Optional[bool]* | :heavy_minus_sign: | Use to troubleshoot issues with sending data | | `max_s2_sversion` | [Optional[models.MaxS2SVersionOptions]](../models/maxs2sversionoptions.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | diff --git a/docs/models/createoutputoutputsplunkhec.md b/docs/models/createoutputoutputsplunkhec.md index d1a19118a..a16e8f0db 100644 --- a/docs/models/createoutputoutputsplunkhec.md +++ b/docs/models/createoutputoutputsplunkhec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `enable_multi_metrics` | *Optional[bool]* | :heavy_minus_sign: | Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputoutputsplunklb.md b/docs/models/createoutputoutputsplunklb.md index 82b95f0fe..65dc54899 100644 --- a/docs/models/createoutputoutputsplunklb.md +++ b/docs/models/createoutputoutputsplunklb.md @@ -26,7 +26,7 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `indexer_discovery` | *Optional[bool]* | :heavy_minus_sign: | Automatically discover indexers in indexer clustering environment. | | `sender_unhealthy_time_allowance` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | diff --git a/docs/models/createoutputoutputtcpjson.md b/docs/models/createoutputoutputtcpjson.md index 91fa7c9b2..57c0b932d 100644 --- a/docs/models/createoutputoutputtcpjson.md +++ b/docs/models/createoutputoutputtcpjson.md @@ -21,7 +21,7 @@ | `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires, valid values between 1 and 60 | | `send_header` | *Optional[bool]* | :heavy_minus_sign: | Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | The hostname of the receiver | | `port` | *Optional[float]* | :heavy_minus_sign: | The port to connect to on the provided host | diff --git a/docs/models/createoutputoutputtraversalotlp.md b/docs/models/createoutputoutputtraversalotlp.md new file mode 100644 index 000000000..c261d9ca7 --- /dev/null +++ b/docs/models/createoutputoutputtraversalotlp.md @@ -0,0 +1,68 @@ +# CreateOutputOutputTraversalOtlp + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputOutputTraversalOtlpType](../models/createoutputoutputtraversalotlptype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `auth_type` | [Optional[models.CreateOutputOutputTraversalOtlpAuthenticationType]](../models/createoutputoutputtraversalotlpauthenticationtype.md) | :heavy_minus_sign: | Authentication type | +| `endpoint` | *str* | :heavy_check_mark: | The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). | +| `protocol` | [Optional[models.ProtocolOptions]](../models/protocoloptions.md) | :heavy_minus_sign: | Select a transport option for OpenTelemetry | +| `preserve_native_any_value` | *Optional[bool]* | :heavy_minus_sign: | Values already in OTLP AnyValue form (e.g. {string_value: "..."}) are serialized directly instead of being wrapped as key-value maps | +| `compress` | [Optional[models.CompressionOptionsDeflateGzip]](../models/compressionoptionsdeflategzip.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_compress` | [Optional[models.CompressionOptionsMessages]](../models/compressionoptionsmessages.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_logs_endpoint_override` | *Optional[str]* | :heavy_minus_sign: | If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint | +| `metadata` | List[[models.KeyValueMetadataConfOutputFilesystem](../models/keyvaluemetadataconfoutputfilesystem.md)] | :heavy_minus_sign: | List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'. | +| `dynamic_headers_enabled` | *Optional[bool]* | :heavy_minus_sign: | Batch event data upon dynamic metadata (whether presented or not) | +| `dynamic_headers_field` | *Optional[str]* | :heavy_minus_sign: | When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events. | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `connection_timeout` | *Optional[float]* | :heavy_minus_sign: | Amount of time (milliseconds) to wait for the connection to establish before retrying | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often the sender should ping the peer to keep the connection open | +| `keep_alive` | *Optional[bool]* | :heavy_minus_sign: | Disable to close the connection immediately after sending the outgoing request | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `login_url` | *Optional[str]* | :heavy_minus_sign: | URL for OAuth | +| `secret_param_name` | *Optional[str]* | :heavy_minus_sign: | Secret parameter name to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret parameter value to pass in request body | +| `token_attribute_name` | *Optional[str]* | :heavy_minus_sign: | Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token'). | +| `auth_header_expr` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`. | +| `token_timeout_secs` | *Optional[float]* | :heavy_minus_sign: | How often the OAuth token should be refreshed. | +| `oauth_params` | List[[models.OauthParamConfInputServicenowTable](../models/oauthparamconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `oauth_headers` | List[[models.OauthHeaderConfInputServicenowTable](../models/oauthheaderconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeExtended]](../models/tlssettingsclientsidetypeextended.md) | :heavy_minus_sign: | TLS settings (client side) | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.CreateOutputOutputTraversalOtlpPqControls]](../models/createoutputoutputtraversalotlppqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputoutputtraversalotlpauthenticationtype.md b/docs/models/createoutputoutputtraversalotlpauthenticationtype.md new file mode 100644 index 000000000..d658068c0 --- /dev/null +++ b/docs/models/createoutputoutputtraversalotlpauthenticationtype.md @@ -0,0 +1,23 @@ +# CreateOutputOutputTraversalOtlpAuthenticationType + +Authentication type + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputOutputTraversalOtlpAuthenticationType + +value = CreateOutputOutputTraversalOtlpAuthenticationType.NONE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `NONE` | none | +| `CREDENTIALS_SECRET` | credentialsSecret | +| `TEXT_SECRET` | textSecret | +| `OAUTH_SECRET` | oauthSecret | \ No newline at end of file diff --git a/docs/models/createoutputoutputtraversalotlppqcontrols.md b/docs/models/createoutputoutputtraversalotlppqcontrols.md new file mode 100644 index 000000000..eae73f132 --- /dev/null +++ b/docs/models/createoutputoutputtraversalotlppqcontrols.md @@ -0,0 +1,9 @@ +# CreateOutputOutputTraversalOtlpPqControls + +Persistent queue controls. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/createoutputoutputtraversalotlptype.md b/docs/models/createoutputoutputtraversalotlptype.md new file mode 100644 index 000000000..d1c3447f5 --- /dev/null +++ b/docs/models/createoutputoutputtraversalotlptype.md @@ -0,0 +1,18 @@ +# CreateOutputOutputTraversalOtlpType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputOutputTraversalOtlpType + +value = CreateOutputOutputTraversalOtlpType.TRAVERSAL_OTLP +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `TRAVERSAL_OTLP` | traversal_otlp | \ No newline at end of file diff --git a/docs/models/createoutputoutputwavefront.md b/docs/models/createoutputoutputwavefront.md index 85599a08d..e42178b43 100644 --- a/docs/models/createoutputoutputwavefront.md +++ b/docs/models/createoutputoutputwavefront.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `domain` | *str* | :heavy_check_mark: | WaveFront domain name, e.g. "longboard" | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | diff --git a/docs/models/createoutputoutputwizhec.md b/docs/models/createoutputoutputwizhec.md index e49129e60..b5791557d 100644 --- a/docs/models/createoutputoutputwizhec.md +++ b/docs/models/createoutputoutputwizhec.md @@ -23,18 +23,20 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | | `wiz_connector_id` | *str* | :heavy_check_mark: | The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration. | | `wiz_environment` | *str* | :heavy_check_mark: | Your Wiz deployment environment | | `data_center` | *str* | :heavy_check_mark: | Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console. | -| `wiz_sourcetype` | *str* | :heavy_check_mark: | Wiz Defend Source type | +| `wiz_sourcetype` | [models.CreateOutputWizDefendSourceType](../models/createoutputwizdefendsourcetype.md) | :heavy_check_mark: | The Wiz log source type. Select a predefined type or enter a custom value. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `token` | *Optional[str]* | :heavy_minus_sign: | Wiz Defend Auth token | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `wiz_vpc_event_format` | [Optional[models.CreateOutputEventFormat]](../models/createoutputeventformat.md) | :heavy_minus_sign: | The format of the VPC Flow Log events | +| `wiz_vpc_flow_log_format` | *Optional[str]* | :heavy_minus_sign: | The format string for VPC Flow Log fields | | `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | | `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | | `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | diff --git a/docs/models/createoutputsendas.md b/docs/models/createoutputsendas.md new file mode 100644 index 000000000..7d4ea511e --- /dev/null +++ b/docs/models/createoutputsendas.md @@ -0,0 +1,22 @@ +# CreateOutputSendAs + +Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSendAs + +value = CreateOutputSendAs.LOGS + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `LOGS` | logs | +| `METRICS` | metrics | +| `BOTH` | both | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackauthtoken.md b/docs/models/createoutputsystembypackauthtoken.md index f4e870f2e..022551157 100644 --- a/docs/models/createoutputsystembypackauthtoken.md +++ b/docs/models/createoutputsystembypackauthtoken.md @@ -3,8 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | -| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackeventformat.md b/docs/models/createoutputsystembypackeventformat.md new file mode 100644 index 000000000..3f1398bd1 --- /dev/null +++ b/docs/models/createoutputsystembypackeventformat.md @@ -0,0 +1,21 @@ +# CreateOutputSystemByPackEventFormat + +The format of the VPC Flow Log events + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackEventFormat + +value = CreateOutputSystemByPackEventFormat.JSON + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `JSON` | json | +| `CSV_ROW` | csv_row | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackindexerdiscoveryconfigs.md b/docs/models/createoutputsystembypackindexerdiscoveryconfigs.md index 3eaa88da8..bfee9c08e 100644 --- a/docs/models/createoutputsystembypackindexerdiscoveryconfigs.md +++ b/docs/models/createoutputsystembypackindexerdiscoveryconfigs.md @@ -12,6 +12,6 @@ List of configurations to set up indexer discovery in Splunk Indexer clustering | `refresh_interval_sec` | *float* | :heavy_check_mark: | Time interval, in seconds, between two consecutive indexer list fetches from cluster manager | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates. | | `auth_tokens` | List[[models.CreateOutputSystemByPackAuthToken](../models/createoutputsystembypackauthtoken.md)] | :heavy_minus_sign: | Tokens required to authenticate to cluster manager for indexer discovery | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoauthsecretsource.md b/docs/models/createoutputsystembypackoauthsecretsource.md new file mode 100644 index 000000000..30ed2cc97 --- /dev/null +++ b/docs/models/createoutputsystembypackoauthsecretsource.md @@ -0,0 +1,21 @@ +# CreateOutputSystemByPackOAuthSecretSource + +Enter the OAuth secret directly, or select a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackOAuthSecretSource + +value = CreateOutputSystemByPackOAuthSecretSource.INLINE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `INLINE` | inline | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutput.md b/docs/models/createoutputsystembypackoutput.md index 8801a98d2..72a1eab9b 100644 --- a/docs/models/createoutputsystembypackoutput.md +++ b/docs/models/createoutputsystembypackoutput.md @@ -425,6 +425,12 @@ value: models.CreateOutputSystemByPackOutputDynatraceHTTP = /* values here */ value: models.CreateOutputSystemByPackOutputDynatraceOtlp = /* values here */ ``` +### `models.CreateOutputSystemByPackOutputTraversalOtlp` + +```python +value: models.CreateOutputSystemByPackOutputTraversalOtlp = /* values here */ +``` + ### `models.CreateOutputSystemByPackOutputSentinelOneAiSiem` ```python @@ -509,3 +515,9 @@ value: models.CreateOutputSystemByPackOutputAlibabaCloudS3 = /* values here */ value: models.CreateOutputSystemByPackOutputIbmCloudS3 = /* values here */ ``` +### `models.CreateOutputSystemByPackOutputDatabricksZerobus` + +```python +value: models.CreateOutputSystemByPackOutputDatabricksZerobus = /* values here */ +``` + diff --git a/docs/models/createoutputsystembypackoutputcribllake.md b/docs/models/createoutputsystembypackoutputcribllake.md index 65c53741d..95e41aab0 100644 --- a/docs/models/createoutputsystembypackoutputcribllake.md +++ b/docs/models/createoutputsystembypackoutputcribllake.md @@ -34,6 +34,7 @@ | `dynamic_dataset` | *Optional[bool]* | :heavy_minus_sign: | N/A | | `max_closing_files_to_backpressure` | *Optional[float]* | :heavy_minus_sign: | N/A | | `max_concurrent_file_parts` | *Optional[float]* | :heavy_minus_sign: | N/A | +| `freshness_grace_period_sec` | *Optional[float]* | :heavy_minus_sign: | N/A | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `compress` | [Optional[models.CompressionOptionsHTTP]](../models/compressionoptionshttp.md) | :heavy_minus_sign: | Data compression format to apply to HTTP content before it is delivered | | `compression_level` | [Optional[models.CompressionLevelOptions]](../models/compressionleveloptions.md) | :heavy_minus_sign: | Compression level to apply before moving files to final destination | diff --git a/docs/models/createoutputsystembypackoutputcriblsearchengine.md b/docs/models/createoutputsystembypackoutputcriblsearchengine.md index 52f15c232..5328b7edf 100644 --- a/docs/models/createoutputsystembypackoutputcriblsearchengine.md +++ b/docs/models/createoutputsystembypackoutputcriblsearchengine.md @@ -3,55 +3,56 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `id` | *str* | :heavy_check_mark: | Unique ID for this output | -| `type` | [models.CreateOutputSystemByPackOutputCriblSearchEngineType](../models/createoutputsystembypackoutputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | -| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | -| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | -| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | -| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | -| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | -| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | -| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | -| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | -| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | -| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | -| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | -| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | -| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | -| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | -| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | -| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | -| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | -| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | -| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | -| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | -| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | -| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | -| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | -| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | -| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | -| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | -| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | -| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | -| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | -| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | -| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | -| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | -| `pq_controls` | [Optional[models.CreateOutputSystemByPackOutputCriblSearchEnginePqControls]](../models/createoutputsystembypackoutputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputSystemByPackOutputCriblSearchEngineType](../models/createoutputsystembypackoutputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | +| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | +| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `send_as` | [Optional[models.CreateOutputSystemByPackSendAs]](../models/createoutputsystembypacksendas.md) | :heavy_minus_sign: | Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | +| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | +| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | +| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | +| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.CreateOutputSystemByPackOutputCriblSearchEnginePqControls]](../models/createoutputsystembypackoutputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputcrowdstrikenextgensiem.md b/docs/models/createoutputsystembypackoutputcrowdstrikenextgensiem.md index a5b9b301e..76a78e0bd 100644 --- a/docs/models/createoutputsystembypackoutputcrowdstrikenextgensiem.md +++ b/docs/models/createoutputsystembypackoutputcrowdstrikenextgensiem.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputsystembypackoutputdatabrickszerobus.md b/docs/models/createoutputsystembypackoutputdatabrickszerobus.md new file mode 100644 index 000000000..fe4c9cae0 --- /dev/null +++ b/docs/models/createoutputsystembypackoutputdatabrickszerobus.md @@ -0,0 +1,42 @@ +# CreateOutputSystemByPackOutputDatabricksZerobus + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputSystemByPackOutputDatabricksZerobusType](../models/createoutputsystembypackoutputdatabrickszerobustype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `workspace_url` | *str* | :heavy_check_mark: | HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https:// | +| `workspace_id` | *str* | :heavy_check_mark: | Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace. | +| `zerobus_endpoint` | *str* | :heavy_check_mark: | Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com). | +| `client_id` | *str* | :heavy_check_mark: | OAuth client ID of the service principal authorized to write to the target table | +| `client_text_secret` | *str* | :heavy_check_mark: | OAuth client secret of the service principal | +| `table_name` | *str* | :heavy_check_mark: | Three-part Unity Catalog name of the target table: catalog.schema.table | +| `max_batch_size_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of the serialized records in a single ingest batch | +| `max_batch_records` | *Optional[int]* | :heavy_minus_sign: | Maximum number of records to include in a single ingest batch | +| `max_buffered_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped. | +| `max_inflight_batches` | *Optional[int]* | :heavy_minus_sign: | Maximum number of unacknowledged batches per Worker Process before blocking | +| `flush_period_sec` | *Optional[int]* | :heavy_minus_sign: | Maximum time, in seconds, to hold a batch before sending it | +| `ack_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting | +| `connection_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a new ingest stream to open before canceling it | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.CreateOutputSystemByPackOutputDatabricksZerobusPqControls]](../models/createoutputsystembypackoutputdatabrickszerobuspqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputdatabrickszerobuspqcontrols.md b/docs/models/createoutputsystembypackoutputdatabrickszerobuspqcontrols.md new file mode 100644 index 000000000..55fc345fb --- /dev/null +++ b/docs/models/createoutputsystembypackoutputdatabrickszerobuspqcontrols.md @@ -0,0 +1,9 @@ +# CreateOutputSystemByPackOutputDatabricksZerobusPqControls + +Persistent queue controls. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputdatabrickszerobustype.md b/docs/models/createoutputsystembypackoutputdatabrickszerobustype.md new file mode 100644 index 000000000..297d80c33 --- /dev/null +++ b/docs/models/createoutputsystembypackoutputdatabrickszerobustype.md @@ -0,0 +1,18 @@ +# CreateOutputSystemByPackOutputDatabricksZerobusType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackOutputDatabricksZerobusType + +value = CreateOutputSystemByPackOutputDatabricksZerobusType.DATABRICKS_ZEROBUS +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `DATABRICKS_ZEROBUS` | databricks_zerobus | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputexabeam.md b/docs/models/createoutputsystembypackoutputexabeam.md index 81ddd4230..a81e85755 100644 --- a/docs/models/createoutputsystembypackoutputexabeam.md +++ b/docs/models/createoutputsystembypackoutputexabeam.md @@ -3,48 +3,54 @@ ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *str* | :heavy_check_mark: | Unique ID for this output | -| `type` | [models.CreateOutputSystemByPackOutputExabeamType](../models/createoutputsystembypackoutputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | -| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | -| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | -| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | -| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | -| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | -| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | -| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | -| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | -| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | -| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | -| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | -| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | -| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | -| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | -| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | -| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | -| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| -| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | -| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | -| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | -| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | -| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | -| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | -| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | -| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | -| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | -| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | -| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputSystemByPackOutputExabeamType](../models/createoutputsystembypackoutputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | +| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | +| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | +| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | +| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | +| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | +| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | +| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | +| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | +| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | +| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | +| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | +| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | +| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | +| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | +| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | +| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | +| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| +| `aws_authentication_method` | [Optional[models.CreateOutputSystemByPackOutputExabeamAuthenticationMethod]](../models/createoutputsystembypackoutputexabeamauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | +| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | +| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | +| `hostname` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the "hostname" metadata field; omitted when empty or not a usable scalar. | +| `forwarder` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the "forwarder" metadata field; omitted when empty or not a usable scalar. | +| `origin` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "origin" metadata field; omitted when the result is not a non-empty object. | +| `logtags` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "logtags" metadata field; omitted when the result is not a non-empty object. | +| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | +| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | +| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | +| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | +| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | +| `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | +| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | +| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | +| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputexabeamauthenticationmethod.md b/docs/models/createoutputsystembypackoutputexabeamauthenticationmethod.md new file mode 100644 index 000000000..61afe6265 --- /dev/null +++ b/docs/models/createoutputsystembypackoutputexabeamauthenticationmethod.md @@ -0,0 +1,21 @@ +# CreateOutputSystemByPackOutputExabeamAuthenticationMethod + +Authentication method + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackOutputExabeamAuthenticationMethod + +value = CreateOutputSystemByPackOutputExabeamAuthenticationMethod.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputhumiohec.md b/docs/models/createoutputsystembypackoutputhumiohec.md index 6677da4a4..c2481709d 100644 --- a/docs/models/createoutputsystembypackoutputhumiohec.md +++ b/docs/models/createoutputsystembypackoutputhumiohec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputsystembypackoutputrouter.md b/docs/models/createoutputsystembypackoutputrouter.md index 7aca57575..4d81a5085 100644 --- a/docs/models/createoutputsystembypackoutputrouter.md +++ b/docs/models/createoutputsystembypackoutputrouter.md @@ -3,14 +3,15 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *str* | :heavy_check_mark: | Unique ID for this output | -| `type` | [models.CreateOutputSystemByPackOutputRouterType](../models/createoutputsystembypackoutputroutertype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `rules` | List[[models.CreateOutputSystemByPackRule](../models/createoutputsystembypackrule.md)] | :heavy_check_mark: | Event routing rules | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputSystemByPackOutputRouterType](../models/createoutputsystembypackoutputroutertype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `report_branch_metrics` | *Optional[bool]* | :heavy_minus_sign: | Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule. | +| `rules` | List[[models.CreateOutputSystemByPackRule](../models/createoutputsystembypackrule.md)] | :heavy_check_mark: | Event routing rules | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputsentinel.md b/docs/models/createoutputsystembypackoutputsentinel.md index 0a975d38f..197f229f7 100644 --- a/docs/models/createoutputsystembypackoutputsentinel.md +++ b/docs/models/createoutputsystembypackoutputsentinel.md @@ -30,11 +30,11 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `auth_type` | [Optional[models.CreateOutputSystemByPackAuthType]](../models/createoutputsystembypackauthtype.md) | :heavy_minus_sign: | Discriminator value. | | `login_url` | *str* | :heavy_check_mark: | URL for OAuth | -| `secret` | *str* | :heavy_check_mark: | Secret parameter value to pass in request body | | `refresh_token_field` | *Optional[str]* | :heavy_minus_sign: | Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials. | | `rotate_refresh_token` | *Optional[bool]* | :heavy_minus_sign: | @{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use. | | `refresh_url` | *Optional[str]* | :heavy_minus_sign: | Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL. | | `refresh_request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_minus_sign: | Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret. | +| `oauth_secret_source` | [Optional[models.CreateOutputSystemByPackOAuthSecretSource]](../models/createoutputsystembypackoauthsecretsource.md) | :heavy_minus_sign: | Enter the OAuth secret directly, or select a stored text secret | | `client_id` | *str* | :heavy_check_mark: | JavaScript expression to compute the Client ID for the Azure application. Can be a constant. | | `scope` | *Optional[str]* | :heavy_minus_sign: | Scope to pass in the OAuth request | | `endpoint_url_configuration` | [models.CreateOutputSystemByPackEndpointConfiguration](../models/createoutputsystembypackendpointconfiguration.md) | :heavy_check_mark: | Enter the data collection endpoint URL or the individual ID | @@ -61,6 +61,8 @@ | `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | | `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | | `pq_controls` | [Optional[models.CreateOutputSystemByPackOutputSentinelPqControls]](../models/createoutputsystembypackoutputsentinelpqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `secret` | *Optional[str]* | :heavy_minus_sign: | Secret parameter value to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret value | | `url` | *Optional[str]* | :heavy_minus_sign: | URL to send events to. Can be overwritten by an event's __url field. | | `dcr_id` | *Optional[str]* | :heavy_minus_sign: | Immutable ID for the Data Collection Rule (DCR) | | `dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com` | @@ -69,10 +71,10 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | -| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_refresh_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime. | | `template_scope` | *Optional[str]* | :heavy_minus_sign: | Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime. | +| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | | `template_dcr_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime. | | `template_dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime. | diff --git a/docs/models/createoutputsystembypackoutputsentineloneaisiem.md b/docs/models/createoutputsystembypackoutputsentineloneaisiem.md index 19651154c..77dae75a7 100644 --- a/docs/models/createoutputsystembypackoutputsentineloneaisiem.md +++ b/docs/models/createoutputsystembypackoutputsentineloneaisiem.md @@ -22,7 +22,7 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputsystembypackoutputsignalfx.md b/docs/models/createoutputsystembypackoutputsignalfx.md index 1db7f0d25..ec1a0ba5c 100644 --- a/docs/models/createoutputsystembypackoutputsignalfx.md +++ b/docs/models/createoutputsystembypackoutputsignalfx.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `realm` | *str* | :heavy_check_mark: | SignalFx realm name, e.g. "us0". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions). | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | diff --git a/docs/models/createoutputsystembypackoutputsplunk.md b/docs/models/createoutputsystembypackoutputsplunk.md index b1c505c27..0e15e9472 100644 --- a/docs/models/createoutputsystembypackoutputsplunk.md +++ b/docs/models/createoutputsystembypackoutputsplunk.md @@ -23,7 +23,7 @@ | `log_failed_requests` | *Optional[bool]* | :heavy_minus_sign: | Use to troubleshoot issues with sending data | | `max_s2_sversion` | [Optional[models.MaxS2SVersionOptions]](../models/maxs2sversionoptions.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | diff --git a/docs/models/createoutputsystembypackoutputsplunkhec.md b/docs/models/createoutputsystembypackoutputsplunkhec.md index 55dd27f34..ecb461d36 100644 --- a/docs/models/createoutputsystembypackoutputsplunkhec.md +++ b/docs/models/createoutputsystembypackoutputsplunkhec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `enable_multi_metrics` | *Optional[bool]* | :heavy_minus_sign: | Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/createoutputsystembypackoutputsplunklb.md b/docs/models/createoutputsystembypackoutputsplunklb.md index 5394d610c..3011559fe 100644 --- a/docs/models/createoutputsystembypackoutputsplunklb.md +++ b/docs/models/createoutputsystembypackoutputsplunklb.md @@ -26,7 +26,7 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `indexer_discovery` | *Optional[bool]* | :heavy_minus_sign: | Automatically discover indexers in indexer clustering environment. | | `sender_unhealthy_time_allowance` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | diff --git a/docs/models/createoutputsystembypackoutputtcpjson.md b/docs/models/createoutputsystembypackoutputtcpjson.md index 4d8cdb1d7..7209019a9 100644 --- a/docs/models/createoutputsystembypackoutputtcpjson.md +++ b/docs/models/createoutputsystembypackoutputtcpjson.md @@ -21,7 +21,7 @@ | `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires, valid values between 1 and 60 | | `send_header` | *Optional[bool]* | :heavy_minus_sign: | Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | The hostname of the receiver | | `port` | *Optional[float]* | :heavy_minus_sign: | The port to connect to on the provided host | diff --git a/docs/models/createoutputsystembypackoutputtraversalotlp.md b/docs/models/createoutputsystembypackoutputtraversalotlp.md new file mode 100644 index 000000000..5b5f86a0f --- /dev/null +++ b/docs/models/createoutputsystembypackoutputtraversalotlp.md @@ -0,0 +1,68 @@ +# CreateOutputSystemByPackOutputTraversalOtlp + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *str* | :heavy_check_mark: | Unique ID for this output | +| `type` | [models.CreateOutputSystemByPackOutputTraversalOtlpType](../models/createoutputsystembypackoutputtraversalotlptype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `auth_type` | [Optional[models.CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType]](../models/createoutputsystembypackoutputtraversalotlpauthenticationtype.md) | :heavy_minus_sign: | Authentication type | +| `endpoint` | *str* | :heavy_check_mark: | The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). | +| `protocol` | [Optional[models.ProtocolOptions]](../models/protocoloptions.md) | :heavy_minus_sign: | Select a transport option for OpenTelemetry | +| `preserve_native_any_value` | *Optional[bool]* | :heavy_minus_sign: | Values already in OTLP AnyValue form (e.g. {string_value: "..."}) are serialized directly instead of being wrapped as key-value maps | +| `compress` | [Optional[models.CompressionOptionsDeflateGzip]](../models/compressionoptionsdeflategzip.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_compress` | [Optional[models.CompressionOptionsMessages]](../models/compressionoptionsmessages.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_logs_endpoint_override` | *Optional[str]* | :heavy_minus_sign: | If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint | +| `metadata` | List[[models.KeyValueMetadataConfOutputFilesystem](../models/keyvaluemetadataconfoutputfilesystem.md)] | :heavy_minus_sign: | List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'. | +| `dynamic_headers_enabled` | *Optional[bool]* | :heavy_minus_sign: | Batch event data upon dynamic metadata (whether presented or not) | +| `dynamic_headers_field` | *Optional[str]* | :heavy_minus_sign: | When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events. | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `connection_timeout` | *Optional[float]* | :heavy_minus_sign: | Amount of time (milliseconds) to wait for the connection to establish before retrying | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often the sender should ping the peer to keep the connection open | +| `keep_alive` | *Optional[bool]* | :heavy_minus_sign: | Disable to close the connection immediately after sending the outgoing request | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `login_url` | *Optional[str]* | :heavy_minus_sign: | URL for OAuth | +| `secret_param_name` | *Optional[str]* | :heavy_minus_sign: | Secret parameter name to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret parameter value to pass in request body | +| `token_attribute_name` | *Optional[str]* | :heavy_minus_sign: | Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token'). | +| `auth_header_expr` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`. | +| `token_timeout_secs` | *Optional[float]* | :heavy_minus_sign: | How often the OAuth token should be refreshed. | +| `oauth_params` | List[[models.OauthParamConfInputServicenowTable](../models/oauthparamconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `oauth_headers` | List[[models.OauthHeaderConfInputServicenowTable](../models/oauthheaderconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeExtended]](../models/tlssettingsclientsidetypeextended.md) | :heavy_minus_sign: | TLS settings (client side) | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.CreateOutputSystemByPackOutputTraversalOtlpPqControls]](../models/createoutputsystembypackoutputtraversalotlppqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputtraversalotlpauthenticationtype.md b/docs/models/createoutputsystembypackoutputtraversalotlpauthenticationtype.md new file mode 100644 index 000000000..08ce1b981 --- /dev/null +++ b/docs/models/createoutputsystembypackoutputtraversalotlpauthenticationtype.md @@ -0,0 +1,23 @@ +# CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType + +Authentication type + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType + +value = CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType.NONE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `NONE` | none | +| `CREDENTIALS_SECRET` | credentialsSecret | +| `TEXT_SECRET` | textSecret | +| `OAUTH_SECRET` | oauthSecret | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputtraversalotlppqcontrols.md b/docs/models/createoutputsystembypackoutputtraversalotlppqcontrols.md new file mode 100644 index 000000000..aea22065b --- /dev/null +++ b/docs/models/createoutputsystembypackoutputtraversalotlppqcontrols.md @@ -0,0 +1,9 @@ +# CreateOutputSystemByPackOutputTraversalOtlpPqControls + +Persistent queue controls. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputtraversalotlptype.md b/docs/models/createoutputsystembypackoutputtraversalotlptype.md new file mode 100644 index 000000000..e2abc0f7c --- /dev/null +++ b/docs/models/createoutputsystembypackoutputtraversalotlptype.md @@ -0,0 +1,18 @@ +# CreateOutputSystemByPackOutputTraversalOtlpType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackOutputTraversalOtlpType + +value = CreateOutputSystemByPackOutputTraversalOtlpType.TRAVERSAL_OTLP +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `TRAVERSAL_OTLP` | traversal_otlp | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackoutputwavefront.md b/docs/models/createoutputsystembypackoutputwavefront.md index 409bccd3b..6b5f8378b 100644 --- a/docs/models/createoutputsystembypackoutputwavefront.md +++ b/docs/models/createoutputsystembypackoutputwavefront.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `domain` | *str* | :heavy_check_mark: | WaveFront domain name, e.g. "longboard" | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | diff --git a/docs/models/createoutputsystembypackoutputwizhec.md b/docs/models/createoutputsystembypackoutputwizhec.md index 5472a0753..c4bfa1b48 100644 --- a/docs/models/createoutputsystembypackoutputwizhec.md +++ b/docs/models/createoutputsystembypackoutputwizhec.md @@ -23,18 +23,20 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | | `wiz_connector_id` | *str* | :heavy_check_mark: | The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration. | | `wiz_environment` | *str* | :heavy_check_mark: | Your Wiz deployment environment | | `data_center` | *str* | :heavy_check_mark: | Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console. | -| `wiz_sourcetype` | *str* | :heavy_check_mark: | Wiz Defend Source type | +| `wiz_sourcetype` | [models.CreateOutputSystemByPackWizDefendSourceType](../models/createoutputsystembypackwizdefendsourcetype.md) | :heavy_check_mark: | The Wiz log source type. Select a predefined type or enter a custom value. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `token` | *Optional[str]* | :heavy_minus_sign: | Wiz Defend Auth token | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `wiz_vpc_event_format` | [Optional[models.CreateOutputSystemByPackEventFormat]](../models/createoutputsystembypackeventformat.md) | :heavy_minus_sign: | The format of the VPC Flow Log events | +| `wiz_vpc_flow_log_format` | *Optional[str]* | :heavy_minus_sign: | The format string for VPC Flow Log fields | | `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | | `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | | `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | diff --git a/docs/models/createoutputsystembypacksendas.md b/docs/models/createoutputsystembypacksendas.md new file mode 100644 index 000000000..bbadce245 --- /dev/null +++ b/docs/models/createoutputsystembypacksendas.md @@ -0,0 +1,22 @@ +# CreateOutputSystemByPackSendAs + +Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackSendAs + +value = CreateOutputSystemByPackSendAs.LOGS + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `LOGS` | logs | +| `METRICS` | metrics | +| `BOTH` | both | \ No newline at end of file diff --git a/docs/models/createoutputsystembypackwizdefendsourcetype.md b/docs/models/createoutputsystembypackwizdefendsourcetype.md new file mode 100644 index 000000000..86cda0158 --- /dev/null +++ b/docs/models/createoutputsystembypackwizdefendsourcetype.md @@ -0,0 +1,27 @@ +# CreateOutputSystemByPackWizDefendSourceType + +The Wiz log source type. Select a predefined type or enter a custom value. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputSystemByPackWizDefendSourceType + +value = CreateOutputSystemByPackWizDefendSourceType.AWS_CLOUDTRAIL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------------- | ------------------------- | +| `AWS_CLOUDTRAIL` | AWS_CLOUDTRAIL | +| `AWS_EKS_AUDIT_LOGS` | AWS_EKS_AUDIT_LOGS | +| `AWS_RESOLVER_QUERY_LOGS` | AWS_RESOLVER_QUERY_LOGS | +| `AZURE_ACTIVITY_LOGS` | AZURE_ACTIVITY_LOGS | +| `GCP_AUDIT_LOGS` | GCP_AUDIT_LOGS | +| `GITHUB_AUDIT_LOGS` | GITHUB_AUDIT_LOGS | +| `OCI_AUDIT_LOGS` | OCI_AUDIT_LOGS | +| `AWS_VPC_FLOW_LOGS` | AWS_VPC_FLOW_LOGS | \ No newline at end of file diff --git a/docs/models/createoutputwizdefendsourcetype.md b/docs/models/createoutputwizdefendsourcetype.md new file mode 100644 index 000000000..15a1318b0 --- /dev/null +++ b/docs/models/createoutputwizdefendsourcetype.md @@ -0,0 +1,27 @@ +# CreateOutputWizDefendSourceType + +The Wiz log source type. Select a predefined type or enter a custom value. + +## Example Usage + +```python +from cribl_control_plane.models import CreateOutputWizDefendSourceType + +value = CreateOutputWizDefendSourceType.AWS_CLOUDTRAIL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------------- | ------------------------- | +| `AWS_CLOUDTRAIL` | AWS_CLOUDTRAIL | +| `AWS_EKS_AUDIT_LOGS` | AWS_EKS_AUDIT_LOGS | +| `AWS_RESOLVER_QUERY_LOGS` | AWS_RESOLVER_QUERY_LOGS | +| `AZURE_ACTIVITY_LOGS` | AZURE_ACTIVITY_LOGS | +| `GCP_AUDIT_LOGS` | GCP_AUDIT_LOGS | +| `GITHUB_AUDIT_LOGS` | GITHUB_AUDIT_LOGS | +| `OCI_AUDIT_LOGS` | OCI_AUDIT_LOGS | +| `AWS_VPC_FLOW_LOGS` | AWS_VPC_FLOW_LOGS | \ No newline at end of file diff --git a/docs/models/cribllakedataset.md b/docs/models/cribllakedataset.md index 14c480c46..f6aba3da3 100644 --- a/docs/models/cribllakedataset.md +++ b/docs/models/cribllakedataset.md @@ -3,19 +3,21 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | -| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | -| `cache_connection` | [Optional[models.CacheConnection]](../models/cacheconnection.md) | :heavy_minus_sign: | N/A | -| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | -| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | -| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | -| `id` | *str* | :heavy_check_mark: | Unique identifier for the Dataset. | -| `metrics` | [Optional[models.LakeDatasetMetrics]](../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | -| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | -| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | -| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | -| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | -| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | +| `allow_record_erasure` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. | +| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | +| `cache_connection` | [Optional[models.CacheConnection]](../models/cacheconnection.md) | :heavy_minus_sign: | N/A | +| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | +| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | +| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | +| `id` | *str* | :heavy_check_mark: | Unique identifier for the Dataset. | +| `metrics` | [Optional[models.LakeDatasetMetrics]](../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | +| `provider_path` | *Optional[str]* | :heavy_minus_sign: | Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). | +| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | +| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | +| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | +| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | +| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | \ No newline at end of file diff --git a/docs/models/cribllakedatasetupdate.md b/docs/models/cribllakedatasetupdate.md index 2d2611c06..a44f5faf1 100644 --- a/docs/models/cribllakedatasetupdate.md +++ b/docs/models/cribllakedatasetupdate.md @@ -3,19 +3,21 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | -| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | -| `cache_connection` | [Optional[models.CacheConnection]](../models/cacheconnection.md) | :heavy_minus_sign: | N/A | -| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | -| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | -| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Dataset. Optional; the path parameter id is authoritative. | -| `metrics` | [Optional[models.LakeDatasetMetrics]](../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | -| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | -| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | -| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | -| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | -| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | +| `allow_record_erasure` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. | +| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | +| `cache_connection` | [Optional[models.CacheConnection]](../models/cacheconnection.md) | :heavy_minus_sign: | N/A | +| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | +| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | +| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Dataset. Optional; the path parameter id is authoritative. | +| `metrics` | [Optional[models.LakeDatasetMetrics]](../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | +| `provider_path` | *Optional[str]* | :heavy_minus_sign: | Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). | +| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | +| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | +| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | +| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | +| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | \ No newline at end of file diff --git a/docs/models/databaseconnectionconfig.md b/docs/models/databaseconnectionconfig.md index c8a842d10..9848ee5c4 100644 --- a/docs/models/databaseconnectionconfig.md +++ b/docs/models/databaseconnectionconfig.md @@ -9,12 +9,17 @@ | `config_obj` | *Optional[str]* | :heavy_minus_sign: | JSON configuration object for advanced SQL Server connection settings. | {
"server": "sqlserver.example.com",
"database": "Reporting",
"user": "yourUsername",
"password": "yourPassword",
"options": {
"connectTimeout": 20000
}
} | | `connection_string` | *Optional[str]* | :heavy_minus_sign: | Database connection string with embedded credentials or server information. | mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true | | `connection_timeout` | *Optional[int]* | :heavy_minus_sign: | Maximum time (in milliseconds) to wait when establishing the database connection. | 10000 | +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Name of the stored credentials secret containing username and password for SQL Server configObj authentication. | mssql-production-credentials | | `creds_secrets` | *Optional[str]* | :heavy_minus_sign: | Name of the stored credentials secret containing username and password. Used with Oracle connections. | oracle-production-credentials | +| `database` | *Optional[str]* | :heavy_minus_sign: | Database to connect to instead of the server default. | | | `database_type` | [models.DatabaseConnectionType](../models/databaseconnectiontype.md) | :heavy_check_mark: | N/A | | | `description` | *str* | :heavy_check_mark: | Brief description of the Database Connection. | Production MySQL database for customer data | +| `host` | *Optional[str]* | :heavy_minus_sign: | Hostname of the server to connect to. | 'myId-dt5egqq7iq1hj6kh.env.trial.example.com'
Hostname, currently intended for Teradata | | `id` | *str* | :heavy_check_mark: | Unique identifier for the Database Connection. | mysql-prod-db | +| `log_on_mechanism` | *Optional[str]* | :heavy_minus_sign: | Log On Mechanism for databases that support multiple, like Teradata. | | | `password` | *Optional[str]* | :heavy_minus_sign: | Database password for authentication. Used with Oracle connections. | yourPassword | | `request_timeout` | *Optional[int]* | :heavy_minus_sign: | Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only. | 30000 | +| `sslmode` | *Optional[str]* | :heavy_minus_sign: | HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior. | VERIFY-FULL | | `tags` | *Optional[str]* | :heavy_minus_sign: | Comma-separated list of tags for categorizing and filtering Database Connections. | production,mysql,customer-data | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Name of the stored text secret containing the connection string. | mysql-production-connection | | `tls` | [Optional[models.TLSClientParams]](../models/tlsclientparams.md) | :heavy_minus_sign: | TLS client connection settings. | | diff --git a/docs/models/databaseconnectiontype.md b/docs/models/databaseconnectiontype.md index a1ca65e38..23b2d8f2f 100644 --- a/docs/models/databaseconnectiontype.md +++ b/docs/models/databaseconnectiontype.md @@ -18,4 +18,5 @@ value = DatabaseConnectionType.MYSQL | `MYSQL` | mysql | | `ORACLE` | oracle | | `POSTGRES` | postgres | -| `SQLSERVER` | sqlserver | \ No newline at end of file +| `SQLSERVER` | sqlserver | +| `TERADATA` | teradata | \ No newline at end of file diff --git a/docs/models/deploymode.md b/docs/models/deploymode.md new file mode 100644 index 000000000..810c60179 --- /dev/null +++ b/docs/models/deploymode.md @@ -0,0 +1,21 @@ +# DeployMode + +Deploy mode configured on the lookup file. + +## Example Usage + +```python +from cribl_control_plane.models import DeployMode + +value = DeployMode.AUTO + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `AUTO` | auto | +| `MANUAL` | manual | \ No newline at end of file diff --git a/docs/models/destinationtype.md b/docs/models/destinationtype.md index 05ab68b22..926821d2f 100644 --- a/docs/models/destinationtype.md +++ b/docs/models/destinationtype.md @@ -98,4 +98,6 @@ value = DestinationType.DEFAULT | `SCALITY_S3` | scality_s3 | | `ALIBABA_CLOUD_S3` | alibaba_cloud_s3 | | `SNOWFLAKE_STREAMING` | snowflake_streaming | -| `IBM_CLOUD_S3` | ibm_cloud_s3 | \ No newline at end of file +| `IBM_CLOUD_S3` | ibm_cloud_s3 | +| `DATABRICKS_ZEROBUS` | databricks_zerobus | +| `TRAVERSAL_OTLP` | traversal_otlp | \ No newline at end of file diff --git a/docs/models/distmode.md b/docs/models/distmode.md index 7ba73345a..21f7d7e90 100644 --- a/docs/models/distmode.md +++ b/docs/models/distmode.md @@ -7,7 +7,7 @@ Distributed deployment mode for the instance. ```python from cribl_control_plane.models import DistMode -value = DistMode.EDGE +value = DistMode.DEDICATED_ORG_LEADER # Open enum: unrecognized values are captured as UnrecognizedStr ``` @@ -15,12 +15,14 @@ value = DistMode.EDGE ## Values -| Name | Value | -| ------------------- | ------------------- | -| `EDGE` | edge | -| `MANAGED_EDGE` | managed-edge | -| `MASTER` | master | -| `OUTPOST` | outpost | -| `SEARCH_SUPERVISOR` | search-supervisor | -| `SINGLE` | single | -| `WORKER` | worker | \ No newline at end of file +| Name | Value | +| ---------------------- | ---------------------- | +| `DEDICATED_ORG_LEADER` | dedicated-org-leader | +| `EDGE` | edge | +| `MANAGED_EDGE` | managed-edge | +| `MASTER` | master | +| `ORG_LEADER` | org-leader | +| `OUTPOST` | outpost | +| `SEARCH_SUPERVISOR` | search-supervisor | +| `SINGLE` | single | +| `WORKER` | worker | \ No newline at end of file diff --git a/docs/models/emailrecipient.md b/docs/models/emailrecipient.md new file mode 100644 index 000000000..0e9a13857 --- /dev/null +++ b/docs/models/emailrecipient.md @@ -0,0 +1,10 @@ +# EmailRecipient + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------- | --------------------------------- | --------------------------------- | --------------------------------- | +| `bcc` | *Optional[str]* | :heavy_minus_sign: | Bcc: Recipients' email addresses. | +| `cc` | *Optional[str]* | :heavy_minus_sign: | Cc: Recipients' email addresses. | +| `to` | *str* | :heavy_check_mark: | Recipients' email addresses. | \ No newline at end of file diff --git a/docs/models/emailrecipient1.md b/docs/models/emailrecipient1.md deleted file mode 100644 index b7ee0aee9..000000000 --- a/docs/models/emailrecipient1.md +++ /dev/null @@ -1,12 +0,0 @@ -# EmailRecipient1 - -Email recipient settings for the Notification target. - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------- | -------------------------------- | -------------------------------- | -------------------------------- | -| `to` | *str* | :heavy_check_mark: | Recipients' email addresses | -| `cc` | *Optional[str]* | :heavy_minus_sign: | Cc: Recipients' email addresses | -| `bcc` | *Optional[str]* | :heavy_minus_sign: | Bcc: Recipients' email addresses | \ No newline at end of file diff --git a/docs/models/emailrecipient2.md b/docs/models/emailrecipient2.md deleted file mode 100644 index a4ebd4cf5..000000000 --- a/docs/models/emailrecipient2.md +++ /dev/null @@ -1,12 +0,0 @@ -# EmailRecipient2 - -Email recipient settings for the Notification target. - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------- | -------------------------------- | -------------------------------- | -------------------------------- | -| `to` | *str* | :heavy_check_mark: | Recipients' email addresses | -| `cc` | *Optional[str]* | :heavy_minus_sign: | Cc: Recipients' email addresses | -| `bcc` | *Optional[str]* | :heavy_minus_sign: | Bcc: Recipients' email addresses | \ No newline at end of file diff --git a/docs/models/emailrecipient3.md b/docs/models/emailrecipient3.md deleted file mode 100644 index c46d447aa..000000000 --- a/docs/models/emailrecipient3.md +++ /dev/null @@ -1,12 +0,0 @@ -# EmailRecipient3 - -Email recipient settings for the Notification target. - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------- | -------------------------------- | -------------------------------- | -------------------------------- | -| `to` | *str* | :heavy_check_mark: | Recipients' email addresses | -| `cc` | *Optional[str]* | :heavy_minus_sign: | Cc: Recipients' email addresses | -| `bcc` | *Optional[str]* | :heavy_minus_sign: | Bcc: Recipients' email addresses | \ No newline at end of file diff --git a/docs/models/executortyperunnablejobexecutor.md b/docs/models/executortyperunnablejobexecutor.md index 5dd398ce1..a81309f66 100644 --- a/docs/models/executortyperunnablejobexecutor.md +++ b/docs/models/executortyperunnablejobexecutor.md @@ -5,8 +5,8 @@ Executor configuration, including the executor type and its settings. ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------ | -| `type` | *str* | :heavy_check_mark: | The type of executor to run | -| `store_task_results` | *Optional[bool]* | :heavy_minus_sign: | Determines whether or not to write task results to disk | -| `conf` | [Optional[models.ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor]](../models/executorspecificsettingstyperunnablejobexecutorexecutor.md) | :heavy_minus_sign: | Executor-type-specific settings object. Shape varies by executor type. | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | ---------------------------------------------------------------------- | +| `type` | *str* | :heavy_check_mark: | The type of executor to run | +| `store_task_results` | *Optional[bool]* | :heavy_minus_sign: | Determines whether or not to write task results to disk | +| `conf` | Dict[str, *Any*] | :heavy_minus_sign: | Executor-type-specific settings object. Shape varies by executor type. | \ No newline at end of file diff --git a/docs/models/feedtype.md b/docs/models/feedtype.md new file mode 100644 index 000000000..dd3de0937 --- /dev/null +++ b/docs/models/feedtype.md @@ -0,0 +1,22 @@ +# FeedType + +Proofpoint on Demand feed to ingest. + +## Example Usage + +```python +from cribl_control_plane.models import FeedType + +value = FeedType.MESSAGE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `MESSAGE` | message | +| `MAILLOG` | maillog | +| `AUDIT` | audit | \ No newline at end of file diff --git a/docs/models/fieldoverride.md b/docs/models/fieldoverride.md new file mode 100644 index 000000000..23da5fc1d --- /dev/null +++ b/docs/models/fieldoverride.md @@ -0,0 +1,13 @@ +# FieldOverride + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `id` | *str* | :heavy_check_mark: | Unique identifier for the Detection Rule to override. | +| `severity_id` | [Optional[models.FunctionConfSchemaDetectionRulesSeverity]](../models/functionconfschemadetectionrulesseverity.md) | :heavy_minus_sign: | Severity level to assign to the Detection Rule. | +| `confidence_id` | [Optional[models.Confidence]](../models/confidence.md) | :heavy_minus_sign: | Confidence level to assign to the Detection Rule. | +| `impact_id` | [Optional[models.Impact]](../models/impact.md) | :heavy_minus_sign: | Impact level to assign to the Detection Rule. | +| `is_alert` | *Optional[bool]* | :heavy_minus_sign: | If true, the Detection Rule creates an alert. Otherwise, false. | +| `message` | *Optional[str]* | :heavy_minus_sign: | Replacement alert message for the Detection Rule. | \ No newline at end of file diff --git a/docs/models/functionconfschemadetectionrules.md b/docs/models/functionconfschemadetectionrules.md new file mode 100644 index 000000000..f57bcb6b4 --- /dev/null +++ b/docs/models/functionconfschemadetectionrules.md @@ -0,0 +1,8 @@ +# FunctionConfSchemaDetectionRules + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | +| `local_overrides` | [Optional[models.LocalOverrides]](../models/localoverrides.md) | :heavy_minus_sign: | Instance-level tuning applied after the rule set is merged. Managed by Cribl Security; not intended for direct editing. | \ No newline at end of file diff --git a/docs/models/functionconfschemadetectionrulesseverity.md b/docs/models/functionconfschemadetectionrulesseverity.md new file mode 100644 index 000000000..8241fef92 --- /dev/null +++ b/docs/models/functionconfschemadetectionrulesseverity.md @@ -0,0 +1,24 @@ +# FunctionConfSchemaDetectionRulesSeverity + +Severity level to assign to the Detection Rule. + +## Example Usage + +```python +from cribl_control_plane.models import FunctionConfSchemaDetectionRulesSeverity + +value = FunctionConfSchemaDetectionRulesSeverity.SEVERITY_ID_ONE + +# Open enum: unrecognized values are captured as UnrecognizedInt +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `SEVERITY_ID_ONE` | 1 | +| `SEVERITY_ID_TWO` | 2 | +| `SEVERITY_ID_THREE` | 3 | +| `SEVERITY_ID_FOUR` | 4 | +| `SEVERITY_ID_FIVE` | 5 | \ No newline at end of file diff --git a/docs/models/functionconfschemalakehouseenginemetricsnormalizer.md b/docs/models/functionconfschemalakehouseenginemetricsnormalizer.md new file mode 100644 index 000000000..16c7c0a8f --- /dev/null +++ b/docs/models/functionconfschemalakehouseenginemetricsnormalizer.md @@ -0,0 +1,7 @@ +# FunctionConfSchemaLakehouseEngineMetricsNormalizer + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/functionconfschemametricstimerangegate.md b/docs/models/functionconfschemametricstimerangegate.md new file mode 100644 index 000000000..ae20543ad --- /dev/null +++ b/docs/models/functionconfschemametricstimerangegate.md @@ -0,0 +1,7 @@ +# FunctionConfSchemaMetricsTimeRangeGate + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/templatetargetpairconffunctionconfschemanotificationpolicies.md b/docs/models/functionconfschemanotificationpoliciestemplatetargetpair.md similarity index 91% rename from docs/models/templatetargetpairconffunctionconfschemanotificationpolicies.md rename to docs/models/functionconfschemanotificationpoliciestemplatetargetpair.md index 1d2e6c264..0f460ab1e 100644 --- a/docs/models/templatetargetpairconffunctionconfschemanotificationpolicies.md +++ b/docs/models/functionconfschemanotificationpoliciestemplatetargetpair.md @@ -1,4 +1,4 @@ -# TemplateTargetPairConfFunctionConfSchemaNotificationPolicies +# FunctionConfSchemaNotificationPoliciesTemplateTargetPair ## Fields diff --git a/docs/models/functiondetectionrules.md b/docs/models/functiondetectionrules.md new file mode 100644 index 000000000..9bd14cccb --- /dev/null +++ b/docs/models/functiondetectionrules.md @@ -0,0 +1,21 @@ +# FunctionDetectionRules + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | +| `filename` | *str* | :heavy_check_mark: | Path to the JavaScript file that implements the Function. | +| `async_timeout` | *Optional[float]* | :heavy_minus_sign: | Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out. | +| `cribl_version` | *Optional[str]* | :heavy_minus_sign: | Minimum Cribl version required by the Function, if applicable. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false. | +| `group` | *str* | :heavy_check_mark: | Category group the Function belongs to. | +| `handle_signals` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function handles stream signals such as flush and close. Otherwise, false. | +| `id` | [models.FunctionDetectionRulesID](../models/functiondetectionrulesid.md) | :heavy_check_mark: | Identifier of the Function. Always detection_rules | +| `load_time` | *float* | :heavy_check_mark: | Time the Function module was loaded, in milliseconds since the Unix epoch. | +| `mod_time` | *float* | :heavy_check_mark: | Time the Function module was last modified, in milliseconds since the Unix epoch. | +| `name` | *str* | :heavy_check_mark: | Display name of the Function. | +| `sync` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function executes synchronously. Otherwise, false. | +| `uischema` | Dict[str, *Any*] | :heavy_check_mark: | UI Schema that controls how the Function's configuration form is rendered. | +| `version` | *str* | :heavy_check_mark: | Version string of the Function. | +| `schema_` | Dict[str, *Any*] | :heavy_minus_sign: | JSON Schema document that describes the Function configuration. | \ No newline at end of file diff --git a/docs/models/functiondetectionrulesid.md b/docs/models/functiondetectionrulesid.md new file mode 100644 index 000000000..cc709260d --- /dev/null +++ b/docs/models/functiondetectionrulesid.md @@ -0,0 +1,18 @@ +# FunctionDetectionRulesID + +Identifier of the Function. Always detection_rules + +## Example Usage + +```python +from cribl_control_plane.models import FunctionDetectionRulesID + +value = FunctionDetectionRulesID.DETECTION_RULES +``` + + +## Values + +| Name | Value | +| ----------------- | ----------------- | +| `DETECTION_RULES` | detection_rules | \ No newline at end of file diff --git a/docs/models/functionlakehouseenginemetricsnormalizer.md b/docs/models/functionlakehouseenginemetricsnormalizer.md new file mode 100644 index 000000000..521d91f61 --- /dev/null +++ b/docs/models/functionlakehouseenginemetricsnormalizer.md @@ -0,0 +1,21 @@ +# FunctionLakehouseEngineMetricsNormalizer + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | +| `filename` | *str* | :heavy_check_mark: | Path to the JavaScript file that implements the Function. | +| `async_timeout` | *Optional[float]* | :heavy_minus_sign: | Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out. | +| `cribl_version` | *Optional[str]* | :heavy_minus_sign: | Minimum Cribl version required by the Function, if applicable. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false. | +| `group` | *str* | :heavy_check_mark: | Category group the Function belongs to. | +| `handle_signals` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function handles stream signals such as flush and close. Otherwise, false. | +| `id` | [models.FunctionLakehouseEngineMetricsNormalizerID](../models/functionlakehouseenginemetricsnormalizerid.md) | :heavy_check_mark: | Identifier of the Function. Always lakehouse_engine_metrics_normalizer | +| `load_time` | *float* | :heavy_check_mark: | Time the Function module was loaded, in milliseconds since the Unix epoch. | +| `mod_time` | *float* | :heavy_check_mark: | Time the Function module was last modified, in milliseconds since the Unix epoch. | +| `name` | *str* | :heavy_check_mark: | Display name of the Function. | +| `sync` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function executes synchronously. Otherwise, false. | +| `uischema` | Dict[str, *Any*] | :heavy_check_mark: | UI Schema that controls how the Function's configuration form is rendered. | +| `version` | *str* | :heavy_check_mark: | Version string of the Function. | +| `schema_` | Dict[str, *Any*] | :heavy_minus_sign: | JSON Schema document that describes the Function configuration. | \ No newline at end of file diff --git a/docs/models/functionlakehouseenginemetricsnormalizerid.md b/docs/models/functionlakehouseenginemetricsnormalizerid.md new file mode 100644 index 000000000..9af13fb48 --- /dev/null +++ b/docs/models/functionlakehouseenginemetricsnormalizerid.md @@ -0,0 +1,18 @@ +# FunctionLakehouseEngineMetricsNormalizerID + +Identifier of the Function. Always lakehouse_engine_metrics_normalizer + +## Example Usage + +```python +from cribl_control_plane.models import FunctionLakehouseEngineMetricsNormalizerID + +value = FunctionLakehouseEngineMetricsNormalizerID.LAKEHOUSE_ENGINE_METRICS_NORMALIZER +``` + + +## Values + +| Name | Value | +| ------------------------------------- | ------------------------------------- | +| `LAKEHOUSE_ENGINE_METRICS_NORMALIZER` | lakehouse_engine_metrics_normalizer | \ No newline at end of file diff --git a/docs/models/functionmetricstimerangegate.md b/docs/models/functionmetricstimerangegate.md new file mode 100644 index 000000000..79773e2ec --- /dev/null +++ b/docs/models/functionmetricstimerangegate.md @@ -0,0 +1,21 @@ +# FunctionMetricsTimeRangeGate + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------- | +| `filename` | *str* | :heavy_check_mark: | Path to the JavaScript file that implements the Function. | +| `async_timeout` | *Optional[float]* | :heavy_minus_sign: | Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out. | +| `cribl_version` | *Optional[str]* | :heavy_minus_sign: | Minimum Cribl version required by the Function, if applicable. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false. | +| `group` | *str* | :heavy_check_mark: | Category group the Function belongs to. | +| `handle_signals` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function handles stream signals such as flush and close. Otherwise, false. | +| `id` | [models.FunctionMetricsTimeRangeGateID](../models/functionmetricstimerangegateid.md) | :heavy_check_mark: | Identifier of the Function. Always metrics_time_range_gate | +| `load_time` | *float* | :heavy_check_mark: | Time the Function module was loaded, in milliseconds since the Unix epoch. | +| `mod_time` | *float* | :heavy_check_mark: | Time the Function module was last modified, in milliseconds since the Unix epoch. | +| `name` | *str* | :heavy_check_mark: | Display name of the Function. | +| `sync` | *Optional[bool]* | :heavy_minus_sign: | If true, the Function executes synchronously. Otherwise, false. | +| `uischema` | Dict[str, *Any*] | :heavy_check_mark: | UI Schema that controls how the Function's configuration form is rendered. | +| `version` | *str* | :heavy_check_mark: | Version string of the Function. | +| `schema_` | Dict[str, *Any*] | :heavy_minus_sign: | JSON Schema document that describes the Function configuration. | \ No newline at end of file diff --git a/docs/models/functionmetricstimerangegateid.md b/docs/models/functionmetricstimerangegateid.md new file mode 100644 index 000000000..295a176dd --- /dev/null +++ b/docs/models/functionmetricstimerangegateid.md @@ -0,0 +1,18 @@ +# FunctionMetricsTimeRangeGateID + +Identifier of the Function. Always metrics_time_range_gate + +## Example Usage + +```python +from cribl_control_plane.models import FunctionMetricsTimeRangeGateID + +value = FunctionMetricsTimeRangeGateID.METRICS_TIME_RANGE_GATE +``` + + +## Values + +| Name | Value | +| ------------------------- | ------------------------- | +| `METRICS_TIME_RANGE_GATE` | metrics_time_range_gate | \ No newline at end of file diff --git a/docs/models/functionresponse.md b/docs/models/functionresponse.md index 1f2efe9bd..025ea953d 100644 --- a/docs/models/functionresponse.md +++ b/docs/models/functionresponse.md @@ -51,6 +51,12 @@ value: models.FunctionCode = /* values here */ value: models.FunctionComment = /* values here */ ``` +### `models.FunctionDetectionRules` + +```python +value: models.FunctionDetectionRules = /* values here */ +``` + ### `models.FunctionDistinct` ```python @@ -159,6 +165,12 @@ value: models.FunctionJSONUnroll = /* values here */ value: models.FunctionLakeExport = /* values here */ ``` +### `models.FunctionLakehouseEngineMetricsNormalizer` + +```python +value: models.FunctionLakehouseEngineMetricsNormalizer = /* values here */ +``` + ### `models.FunctionLimit` ```python @@ -213,6 +225,12 @@ value: models.FunctionMask = /* values here */ value: models.FunctionMetricsExport = /* values here */ ``` +### `models.FunctionMetricsTimeRangeGate` + +```python +value: models.FunctionMetricsTimeRangeGate = /* values here */ +``` + ### `models.FunctionMvExpand` ```python diff --git a/docs/models/getcribllakedatasetbylakeidrequest.md b/docs/models/getcribllakedatasetbylakeidrequest.md index b6d7c97ec..b51b610fd 100644 --- a/docs/models/getcribllakedatasetbylakeidrequest.md +++ b/docs/models/getcribllakedatasetbylakeidrequest.md @@ -3,16 +3,22 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake that contains the Lake Datasets to list. | -| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Filter datasets by storage location ID. Use default for default storage location. | -| `format_` | [Optional[models.DatasetFormatFilter]](../models/datasetformatfilter.md) | :heavy_minus_sign: | Filter datasets by format. Set to ddss to return only DDSS datasets. | -| `exclude_ddss` | *Optional[bool]* | :heavy_minus_sign: | Exclude DDSS format datasets from the response. | -| `exclude_netskope` | *Optional[bool]* | :heavy_minus_sign: | Exclude Netskope format datasets from the response. | -| `exclude_deleted` | *Optional[bool]* | :heavy_minus_sign: | Exclude deleted datasets from the response. | -| `exclude_internal` | *Optional[bool]* | :heavy_minus_sign: | Exclude internal datasets (those with IDs starting with cribl_) from the response. | -| `exclude_byos` | *Optional[bool]* | :heavy_minus_sign: | Exclude BYOS (Bring Your Own Storage) datasets from the response. | -| `include_metrics` | *Optional[bool]* | :heavy_minus_sign: | Set to true to include storage metrics for each Lake Dataset. Otherwise, false (default). Requires a Cribl Lake metrics license. | -| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | -| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | \ No newline at end of file +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake that contains the Lake Datasets to list. | +| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Filter datasets by storage location ID. Use default for default storage location. | +| `format_` | [Optional[models.DatasetFormatFilter]](../models/datasetformatfilter.md) | :heavy_minus_sign: | Filter datasets by format. Set to ddss to return only DDSS datasets. | +| `exclude_ddss` | *Optional[bool]* | :heavy_minus_sign: | Exclude DDSS format datasets from the response. | +| `exclude_netskope` | *Optional[bool]* | :heavy_minus_sign: | Exclude Netskope format datasets from the response. | +| `exclude_deleted` | *Optional[bool]* | :heavy_minus_sign: | Exclude deleted datasets from the response. | +| `exclude_internal` | *Optional[bool]* | :heavy_minus_sign: | Exclude internal datasets (those with IDs starting with cribl_) from the response. | +| `exclude_byos` | *Optional[bool]* | :heavy_minus_sign: | Exclude BYOS (Bring Your Own Storage) datasets from the response. | +| `include_metrics` | *Optional[bool]* | :heavy_minus_sign: | Set to true to include storage metrics for each Lake Dataset. Otherwise, false (default). Requires a Cribl Lake metrics license. | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Starting point for catalog-backed pagination. Requires limit. | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Page size for catalog-backed pagination. Requires offset. | +| `order_by` | *Optional[str]* | :heavy_minus_sign: | Catalog sort field when paginating: name, createdAt, updatedAt, providerPath, type, or retentionPeriodInDays. Defaults to name. | +| `order_dir` | *Optional[str]* | :heavy_minus_sign: | Sort direction when paginating: asc or desc. Defaults to asc. | +| `name` | *Optional[str]* | :heavy_minus_sign: | Exact dataset name match (catalog path, with pagination). | +| `name_contains` | *Optional[str]* | :heavy_minus_sign: | Case-insensitive substring match on dataset name (catalog path, with pagination). | +| `provider_path_contains` | *Optional[str]* | :heavy_minus_sign: | Case-insensitive substring match on provider path (catalog path, with pagination). | +| `description_contains` | *Optional[str]* | :heavy_minus_sign: | Case-insensitive substring match on description (catalog path, with pagination). | \ No newline at end of file diff --git a/docs/models/listinputrequest.md b/docs/models/getinputrequest.md similarity index 99% rename from docs/models/listinputrequest.md rename to docs/models/getinputrequest.md index 103001665..376601f5f 100644 --- a/docs/models/listinputrequest.md +++ b/docs/models/getinputrequest.md @@ -1,4 +1,4 @@ -# ListInputRequest +# GetInputRequest ## Fields diff --git a/docs/models/listinputresponse.md b/docs/models/getinputresponse.md similarity index 97% rename from docs/models/listinputresponse.md rename to docs/models/getinputresponse.md index 3c68420c1..669c1f11e 100644 --- a/docs/models/listinputresponse.md +++ b/docs/models/getinputresponse.md @@ -1,4 +1,4 @@ -# ListInputResponse +# GetInputResponse ## Fields diff --git a/docs/models/listoutputrequest.md b/docs/models/getoutputrequest.md similarity index 99% rename from docs/models/listoutputrequest.md rename to docs/models/getoutputrequest.md index 30dec3793..c545e825d 100644 --- a/docs/models/listoutputrequest.md +++ b/docs/models/getoutputrequest.md @@ -1,4 +1,4 @@ -# ListOutputRequest +# GetOutputRequest ## Fields diff --git a/docs/models/listoutputresponse.md b/docs/models/getoutputresponse.md similarity index 97% rename from docs/models/listoutputresponse.md rename to docs/models/getoutputresponse.md index a360cb4ae..a78141279 100644 --- a/docs/models/listoutputresponse.md +++ b/docs/models/getoutputresponse.md @@ -1,4 +1,4 @@ -# ListOutputResponse +# GetOutputResponse ## Fields diff --git a/docs/models/getpipelinesbypackrequest.md b/docs/models/getpipelinesbypackrequest.md index d30c9891c..f72c97900 100644 --- a/docs/models/getpipelinesbypackrequest.md +++ b/docs/models/getpipelinesbypackrequest.md @@ -3,8 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| --------------------------------- | --------------------------------- | --------------------------------- | --------------------------------- | -| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | -| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | -| `pack` | *str* | :heavy_check_mark: | The id of the Pack. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. | +| `pack` | *str* | :heavy_check_mark: | The id of the Pack. | \ No newline at end of file diff --git a/docs/models/getpipelinesrequest.md b/docs/models/getpipelinesrequest.md index d847060c8..7bb0bd524 100644 --- a/docs/models/getpipelinesrequest.md +++ b/docs/models/getpipelinesrequest.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| --------------------------------- | --------------------------------- | --------------------------------- | --------------------------------- | -| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | -| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. | \ No newline at end of file diff --git a/docs/models/getproductsgroupsaclbyproductandidrequest.md b/docs/models/getproductsgroupsaclbyproductandidrequest.md index 1df4a0716..0a84b50a0 100644 --- a/docs/models/getproductsgroupsaclbyproductandidrequest.md +++ b/docs/models/getproductsgroupsaclbyproductandidrequest.md @@ -5,6 +5,6 @@ | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | -| `product` | [models.ProductsCore](../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product to get the Worker Groups or Edge Fleets for. | +| `product` | [models.ProductsCore](../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. | | `id` | *str* | :heavy_check_mark: | The id of the Worker Group, Outpost Group, or Edge Fleet to get the ACL for. | | `type` | [Optional[models.RbacResource]](../models/rbacresource.md) | :heavy_minus_sign: | Filter for limiting the response to ACL entries for the specified RBAC resource type. | \ No newline at end of file diff --git a/docs/models/getproductsgroupsaclteamsbyproductandidrequest.md b/docs/models/getproductsgroupsaclteamsbyproductandidrequest.md index 1c223befb..53c51ee53 100644 --- a/docs/models/getproductsgroupsaclteamsbyproductandidrequest.md +++ b/docs/models/getproductsgroupsaclteamsbyproductandidrequest.md @@ -6,5 +6,5 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | | `product` | [models.ProductsCore](../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. | -| `id` | *str* | :heavy_check_mark: | The id of the Worker Group, Outpost Group, or Edge Fleet to get the team ACL for. | +| `id` | *str* | :heavy_check_mark: | The id of the Worker Group, Outpost Group, or Edge Fleet to get the Team ACL for. | | `type` | [Optional[models.RbacResource]](../models/rbacresource.md) | :heavy_minus_sign: | Filter for limiting the response to ACL entries for the specified RBAC resource type. | \ No newline at end of file diff --git a/docs/models/getroutesbypackrequest.md b/docs/models/getroutesbypackrequest.md index f44826a99..11235ae47 100644 --- a/docs/models/getroutesbypackrequest.md +++ b/docs/models/getroutesbypackrequest.md @@ -3,6 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------- | -------------------------------- | -------------------------------- | -------------------------------- | -| `pack` | *str* | :heavy_check_mark: | The id of the Pack. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------- | --------------------------------- | --------------------------------- | --------------------------------- | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | +| `pack` | *str* | :heavy_check_mark: | The id of the Pack. | \ No newline at end of file diff --git a/docs/models/getroutesbypackresponse.md b/docs/models/getroutesbypackresponse.md new file mode 100644 index 000000000..1f8e59c3e --- /dev/null +++ b/docs/models/getroutesbypackresponse.md @@ -0,0 +1,8 @@ +# GetRoutesByPackResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `result` | [models.PaginatedRoutes](../models/paginatedroutes.md) | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/models/getroutesrequest.md b/docs/models/getroutesrequest.md new file mode 100644 index 000000000..dabfc839d --- /dev/null +++ b/docs/models/getroutesrequest.md @@ -0,0 +1,9 @@ +# GetRoutesRequest + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------- | --------------------------------- | --------------------------------- | --------------------------------- | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | \ No newline at end of file diff --git a/docs/models/getroutesresponse.md b/docs/models/getroutesresponse.md new file mode 100644 index 000000000..c6a88e23f --- /dev/null +++ b/docs/models/getroutesresponse.md @@ -0,0 +1,8 @@ +# GetRoutesResponse + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | ------------------------------------------------------ | +| `result` | [models.PaginatedRoutes](../models/paginatedroutes.md) | :heavy_check_mark: | N/A | \ No newline at end of file diff --git a/docs/models/groupby.md b/docs/models/groupby.md new file mode 100644 index 000000000..b00a54f29 --- /dev/null +++ b/docs/models/groupby.md @@ -0,0 +1,27 @@ +# GroupBy + +## Example Usage + +```python +from cribl_control_plane.models import GroupBy + +value = GroupBy.MODEL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------ | ------------------ | +| `MODEL` | model | +| `PRODUCT` | product | +| `CONTEXT_WINDOW` | context_window | +| `INFERENCE_GEO` | inference_geo | +| `SPEED` | speed | +| `RBAC_GROUP_ID` | rbac_group_id | +| `SLACK_CHANNEL_ID` | slack_channel_id | +| `TEAMS_CHANNEL_ID` | teams_channel_id | +| `COST_TYPE` | cost_type | +| `TOKEN_TYPE` | token_type | \ No newline at end of file diff --git a/docs/models/groupcreaterequest.md b/docs/models/groupcreaterequest.md index 9e788fd5d..5eac57349 100644 --- a/docs/models/groupcreaterequest.md +++ b/docs/models/groupcreaterequest.md @@ -7,6 +7,8 @@ Request body for creating a new Worker Group, Outpost Group, or Edge Fleet. Do n | Field | Type | Required | Description | Example | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | | | `cloud` | [Optional[models.ConfigGroupCloud]](../models/configgroupcloud.md) | :heavy_minus_sign: | N/A | | | `collectors_ha_enabled` | *Optional[bool]* | :heavy_minus_sign: | Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. | | | `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Worker Group, Outpost Group, or Edge Fleet. | | diff --git a/docs/models/hbcriblinfo.md b/docs/models/hbcriblinfo.md index b09d90706..1e6b9f3e4 100644 --- a/docs/models/hbcriblinfo.md +++ b/docs/models/hbcriblinfo.md @@ -5,6 +5,7 @@ | Field | Type | Required | Description | Example | | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------- | +| `auto_lookup_versions` | Dict[str, Dict[str, *str*]] | :heavy_minus_sign: | Objects that map Lookup files to deployment versions. | | | `config` | [models.Config](../models/config.md) | :heavy_check_mark: | Configuration bundle and policy revision metadata for the node. | | | `deployment_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the deployment assigned for the node. | | | `disable_sni_routing` | *Optional[bool]* | :heavy_minus_sign: | If true, SNI-based routing to the Leader is disabled for the connection. | | diff --git a/docs/models/impact.md b/docs/models/impact.md new file mode 100644 index 000000000..0f4f2962b --- /dev/null +++ b/docs/models/impact.md @@ -0,0 +1,23 @@ +# Impact + +Impact level to assign to the Detection Rule. + +## Example Usage + +```python +from cribl_control_plane.models import Impact + +value = Impact.IMPACT_ID_ONE + +# Open enum: unrecognized values are captured as UnrecognizedInt +``` + + +## Values + +| Name | Value | +| ----------------- | ----------------- | +| `IMPACT_ID_ONE` | 1 | +| `IMPACT_ID_TWO` | 2 | +| `IMPACT_ID_THREE` | 3 | +| `IMPACT_ID_FOUR` | 4 | \ No newline at end of file diff --git a/docs/models/indexerdiscoveryconfigs.md b/docs/models/indexerdiscoveryconfigs.md index 1d7175227..62fd78269 100644 --- a/docs/models/indexerdiscoveryconfigs.md +++ b/docs/models/indexerdiscoveryconfigs.md @@ -12,6 +12,6 @@ List of configurations to set up indexer discovery in Splunk Indexer clustering | `refresh_interval_sec` | *float* | :heavy_check_mark: | Time interval, in seconds, between two consecutive indexer list fetches from cluster manager | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates. | | `auth_tokens` | List[[models.OutputSplunkLbAuthToken](../models/outputsplunklbauthtoken.md)] | :heavy_minus_sign: | Tokens required to authenticate to cluster manager for indexer discovery | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/inlinerule.md b/docs/models/inlinerule.md new file mode 100644 index 000000000..26122d0c9 --- /dev/null +++ b/docs/models/inlinerule.md @@ -0,0 +1,15 @@ +# InlineRule + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique identifier for the Detection Rule. | +| `name` | *str* | :heavy_check_mark: | Display name for the Detection Rule. | +| `condition` | *str* | :heavy_check_mark: | Expression that determines whether the Detection Rule matches an event. | +| `severity_id` | *Optional[int]* | :heavy_minus_sign: | Severity level for the Detection Rule. | +| `confidence_id` | *Optional[int]* | :heavy_minus_sign: | Confidence level for the Detection Rule. | +| `is_alert` | *Optional[bool]* | :heavy_minus_sign: | If true, the Detection Rule creates an alert. Otherwise, false. | +| `message` | *Optional[str]* | :heavy_minus_sign: | Alert message emitted when the Detection Rule matches. | +| `tags` | List[*str*] | :heavy_minus_sign: | Tags for filtering and grouping detection rules. | \ No newline at end of file diff --git a/docs/models/input.md b/docs/models/input.md index 244725e82..5092c9be4 100644 --- a/docs/models/input.md +++ b/docs/models/input.md @@ -51,6 +51,12 @@ value: models.InputSplunkHecInput = /* values here */ value: models.InputAzureBlobInput = /* values here */ ``` +### `models.InputAzureVnetFlowLogInput` + +```python +value: models.InputAzureVnetFlowLogInput = /* values here */ +``` + ### `models.InputElasticInput` ```python @@ -387,6 +393,12 @@ value: models.InputBedrockS3Input = /* values here */ value: models.InputServicenowTableInput = /* values here */ ``` +### `models.InputProofpointPodInput` + +```python +value: models.InputProofpointPodInput = /* values here */ +``` + ### `models.InputZscalerHecInput` ```python @@ -411,6 +423,30 @@ value: models.InputSysdigHecInput = /* values here */ value: models.InputUpwindHecInput = /* values here */ ``` +### `models.InputTrellixHecInput` + +```python +value: models.InputTrellixHecInput = /* values here */ +``` + +### `models.InputSailpointHecInput` + +```python +value: models.InputSailpointHecInput = /* values here */ +``` + +### `models.InputExtrahopRevealx360Input` + +```python +value: models.InputExtrahopRevealx360Input = /* values here */ +``` + +### `models.InputAquaSecurityHecInput` + +```python +value: models.InputAquaSecurityHecInput = /* values here */ +``` + ### `models.InputOpenaiComplianceLogsInput` ```python @@ -423,9 +459,75 @@ value: models.InputOpenaiComplianceLogsInput = /* values here */ value: models.InputAnthropicComplianceInput = /* values here */ ``` +### `models.InputAnthropicEnterpriseAnalyticsInput` + +```python +value: models.InputAnthropicEnterpriseAnalyticsInput = /* values here */ +``` + +### `models.InputMicrosoftCopilotInput` + +```python +value: models.InputMicrosoftCopilotInput = /* values here */ +``` + ### `models.InputOktaInput` ```python value: models.InputOktaInput = /* values here */ ``` +### `models.InputAkamaiHecInput` + +```python +value: models.InputAkamaiHecInput = /* values here */ +``` + +### `models.InputPingIdentityPingoneInput` + +```python +value: models.InputPingIdentityPingoneInput = /* values here */ +``` + +### `models.InputGigamonHecInput` + +```python +value: models.InputGigamonHecInput = /* values here */ +``` + +### `models.InputVectraAiHecInput` + +```python +value: models.InputVectraAiHecInput = /* values here */ +``` + +### `models.InputF5BigIPInput` + +```python +value: models.InputF5BigIPInput = /* values here */ +``` + +### `models.InputBeyondtrustHecInput` + +```python +value: models.InputBeyondtrustHecInput = /* values here */ +``` + +### `models.InputHashicorpHcpVaultDedicatedInput` + +```python +value: models.InputHashicorpHcpVaultDedicatedInput = /* values here */ +``` + +### `models.InputMimecastHecInput` + +```python +value: models.InputMimecastHecInput = /* values here */ +``` + +### `models.InputTrendMicroVisionOneInput` + +```python +value: models.InputTrendMicroVisionOneInput = /* values here */ +``` + diff --git a/docs/models/inputakamaihecinput.md b/docs/models/inputakamaihecinput.md new file mode 100644 index 000000000..f9a21549e --- /dev/null +++ b/docs/models/inputakamaihecinput.md @@ -0,0 +1,40 @@ +# InputAkamaiHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputAkamaiHecType](../models/inputakamaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | \ No newline at end of file diff --git a/docs/models/inputakamaihectype.md b/docs/models/inputakamaihectype.md new file mode 100644 index 000000000..bed3e4faa --- /dev/null +++ b/docs/models/inputakamaihectype.md @@ -0,0 +1,18 @@ +# InputAkamaiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputAkamaiHecType + +value = InputAkamaiHecType.AKAMAI_HEC +``` + + +## Values + +| Name | Value | +| ------------ | ------------ | +| `AKAMAI_HEC` | akamai_hec | \ No newline at end of file diff --git a/docs/models/inputanthropicenterpriseanalyticscontentconfig.md b/docs/models/inputanthropicenterpriseanalyticscontentconfig.md new file mode 100644 index 000000000..f3a187736 --- /dev/null +++ b/docs/models/inputanthropicenterpriseanalyticscontentconfig.md @@ -0,0 +1,18 @@ +# InputAnthropicEnterpriseAnalyticsContentConfig + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `content_type` | [models.ContentType](../models/contenttype.md) | :heavy_check_mark: | Content type | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark. | +| `manage_state` | *Optional[bool]* | :heavy_minus_sign: | Manage state | +| `group_by` | List[[models.GroupBy](../models/groupby.md)] | :heavy_minus_sign: | Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket. | +| `bucket_width` | [Optional[models.BucketWidth]](../models/bucketwidth.md) | :heavy_minus_sign: | Time bucket size for aggregated results. Smaller buckets yield more events per collection run. | +| `cron_schedule` | *str* | :heavy_check_mark: | Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results. | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d. | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | \ No newline at end of file diff --git a/docs/models/inputanthropicenterpriseanalyticsinput.md b/docs/models/inputanthropicenterpriseanalyticsinput.md new file mode 100644 index 000000000..e2f6f80a3 --- /dev/null +++ b/docs/models/inputanthropicenterpriseanalyticsinput.md @@ -0,0 +1,32 @@ +# InputAnthropicEnterpriseAnalyticsInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputAnthropicEnterpriseAnalyticsType](../models/inputanthropicenterpriseanalyticstype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `api_key` | *Optional[str]* | :heavy_minus_sign: | API key | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored API key with read:analytics scope | +| `content_config` | List[[models.InputAnthropicEnterpriseAnalyticsContentConfig](../models/inputanthropicenterpriseanalyticscontentconfig.md)] | :heavy_check_mark: | Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout. Use 0 to disable. | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.RetryRulesType]](../models/retryrulestype.md) | :heavy_minus_sign: | N/A | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/inputanthropicenterpriseanalyticstype.md b/docs/models/inputanthropicenterpriseanalyticstype.md new file mode 100644 index 000000000..77a3dedc8 --- /dev/null +++ b/docs/models/inputanthropicenterpriseanalyticstype.md @@ -0,0 +1,18 @@ +# InputAnthropicEnterpriseAnalyticsType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputAnthropicEnterpriseAnalyticsType + +value = InputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS +``` + + +## Values + +| Name | Value | +| -------------------------------- | -------------------------------- | +| `ANTHROPIC_ENTERPRISE_ANALYTICS` | anthropic_enterprise_analytics | \ No newline at end of file diff --git a/docs/models/inputappscopeinput.md b/docs/models/inputappscopeinput.md index 26ce6d03f..003dbe086 100644 --- a/docs/models/inputappscopeinput.md +++ b/docs/models/inputappscopeinput.md @@ -27,7 +27,7 @@ | `enable_unix_path` | *Optional[bool]* | :heavy_minus_sign: | Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port. | | `filter_` | [Optional[models.InputAppscopeFilter]](../models/inputappscopefilter.md) | :heavy_minus_sign: | N/A | | `persistence` | [Optional[models.InputAppscopePersistence]](../models/inputappscopepersistence.md) | :heavy_minus_sign: | Persistence | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | | `port` | *Optional[float]* | :heavy_minus_sign: | Port to listen on | diff --git a/docs/models/inputaquasecurityhecinput.md b/docs/models/inputaquasecurityhecinput.md new file mode 100644 index 000000000..e93d42487 --- /dev/null +++ b/docs/models/inputaquasecurityhecinput.md @@ -0,0 +1,46 @@ +# InputAquaSecurityHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputAquaSecurityHecType](../models/inputaquasecurityhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputaquasecurityhectype.md b/docs/models/inputaquasecurityhectype.md new file mode 100644 index 000000000..08666d334 --- /dev/null +++ b/docs/models/inputaquasecurityhectype.md @@ -0,0 +1,18 @@ +# InputAquaSecurityHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputAquaSecurityHecType + +value = InputAquaSecurityHecType.AQUA_SECURITY_HEC +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `AQUA_SECURITY_HEC` | aqua_security_hec | \ No newline at end of file diff --git a/docs/models/inputazureblobinput.md b/docs/models/inputazureblobinput.md index fb28ff1ab..2284ed6d6 100644 --- a/docs/models/inputazureblobinput.md +++ b/docs/models/inputazureblobinput.md @@ -22,12 +22,14 @@ | `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | | `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | | `skip_on_error` | *Optional[bool]* | :heavy_minus_sign: | Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors. | +| `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `parquet_chunk_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum file size for each Parquet chunk | | `parquet_chunk_download_timeout` | *Optional[float]* | :heavy_minus_sign: | The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified. | | `auth_type` | [Optional[models.AuthenticationMethodOptions]](../models/authenticationmethodoptions.md) | :heavy_minus_sign: | Authentication method | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `connection_string` | *Optional[str]* | :heavy_minus_sign: | Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | diff --git a/docs/models/inputazurevnetflowloginput.md b/docs/models/inputazurevnetflowloginput.md new file mode 100644 index 000000000..2cf0cde61 --- /dev/null +++ b/docs/models/inputazurevnetflowloginput.md @@ -0,0 +1,44 @@ +# InputAzureVnetFlowLogInput + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputAzureVnetFlowLogType](../models/inputazurevnetflowlogtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `queue_name` | *str* | :heavy_check_mark: | The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}` | +| `file_filter` | *Optional[str]* | :heavy_minus_sign: | Regex matching file names to download and process. Defaults to: .* | +| `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request. | +| `num_receivers` | *Optional[float]* | :heavy_minus_sign: | How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead. | +| `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | +| `max_dequeue_count` | *Optional[float]* | :heavy_minus_sign: | Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers. | +| `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | +| `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | +| `client_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's client ID | +| `azure_cloud` | *Optional[str]* | :heavy_minus_sign: | The Azure cloud to use. Defaults to Azure Public Cloud. | +| `endpoint_suffix` | *Optional[str]* | :heavy_minus_sign: | Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net. | +| `client_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `certificate` | [Optional[models.CertificateType]](../models/certificatetype.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_queue_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime. | +| `template_storage_account_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_azure_cloud` | *Optional[str]* | :heavy_minus_sign: | Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime. | \ No newline at end of file diff --git a/docs/models/inputazurevnetflowlogtype.md b/docs/models/inputazurevnetflowlogtype.md new file mode 100644 index 000000000..c63c14692 --- /dev/null +++ b/docs/models/inputazurevnetflowlogtype.md @@ -0,0 +1,18 @@ +# InputAzureVnetFlowLogType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputAzureVnetFlowLogType + +value = InputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG +``` + + +## Values + +| Name | Value | +| --------------------- | --------------------- | +| `AZURE_VNET_FLOW_LOG` | azure_vnet_flow_log | \ No newline at end of file diff --git a/docs/models/inputbeyondtrusthecinput.md b/docs/models/inputbeyondtrusthecinput.md new file mode 100644 index 000000000..a79d28896 --- /dev/null +++ b/docs/models/inputbeyondtrusthecinput.md @@ -0,0 +1,44 @@ +# InputBeyondtrustHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputBeyondtrustHecType](../models/inputbeyondtrusthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputbeyondtrusthectype.md b/docs/models/inputbeyondtrusthectype.md new file mode 100644 index 000000000..9bf8f2682 --- /dev/null +++ b/docs/models/inputbeyondtrusthectype.md @@ -0,0 +1,18 @@ +# InputBeyondtrustHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputBeyondtrustHecType + +value = InputBeyondtrustHecType.BEYONDTRUST_HEC +``` + + +## Values + +| Name | Value | +| ----------------- | ----------------- | +| `BEYONDTRUST_HEC` | beyondtrust_hec | \ No newline at end of file diff --git a/docs/models/inputconfluentcloudinput.md b/docs/models/inputconfluentcloudinput.md index f60723649..aa2c64dd3 100644 --- a/docs/models/inputconfluentcloudinput.md +++ b/docs/models/inputconfluentcloudinput.md @@ -39,6 +39,7 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputcribllakehttpauthtokensext.md b/docs/models/inputcribllakehttpauthtokensext.md new file mode 100644 index 000000000..99d8f688d --- /dev/null +++ b/docs/models/inputcribllakehttpauthtokensext.md @@ -0,0 +1,17 @@ +# InputCriblLakeHTTPAuthTokensExt + + +## Supported Types + +### `models.InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/inputcribllakehttpinput.md b/docs/models/inputcribllakehttpinput.md index 930b2690b..d305621c7 100644 --- a/docs/models/inputcribllakehttpinput.md +++ b/docs/models/inputcribllakehttpinput.md @@ -35,7 +35,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.AuthTokensExt](../models/authtokensext.md)] | :heavy_minus_sign: | Auth tokens | +| `auth_tokens_ext` | List[[models.InputCriblLakeHTTPAuthTokensExt](../models/inputcribllakehttpauthtokensext.md)] | :heavy_minus_sign: | Auth tokens | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputcribllakehttpinputhttpauthtokensextitemstype.md b/docs/models/inputcribllakehttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..8d3ccbeff --- /dev/null +++ b/docs/models/inputcribllakehttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,14 @@ +# InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------ | +| `token` | *str* | :heavy_check_mark: | Token | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata]](../models/inputhttpauthtokensextitemstypesplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata]](../models/inputhttpauthtokensextitemstypeelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputcribllakehttpinputhttpauthtypesecretconstraint.md b/docs/models/inputcribllakehttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..48cf8569f --- /dev/null +++ b/docs/models/inputcribllakehttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,14 @@ +# InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Token | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.InputHTTPAuthTypeSecretConstraintSplunkHecMetadata]](../models/inputhttpauthtypesecretconstraintsplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.InputHTTPAuthTypeSecretConstraintElasticsearchMetadata]](../models/inputhttpauthtypesecretconstraintelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputeventhubamqpauthenticationmethod.md b/docs/models/inputeventhubamqpauthenticationmethod.md deleted file mode 100644 index 808f57ece..000000000 --- a/docs/models/inputeventhubamqpauthenticationmethod.md +++ /dev/null @@ -1,24 +0,0 @@ -# InputEventhubAmqpAuthenticationMethod - -Authentication method - -## Example Usage - -```python -from cribl_control_plane.models import InputEventhubAmqpAuthenticationMethod - -value = InputEventhubAmqpAuthenticationMethod.SECRET - -# Open enum: unrecognized values are captured as UnrecognizedStr -``` - - -## Values - -| Name | Value | -| ---------------------- | ---------------------- | -| `SECRET` | secret | -| `CLIENT_SECRET` | clientSecret | -| `CLIENT_CERT` | clientCert | -| `CLIENT_ASSERTION` | clientAssertion | -| `CLIENT_ASSERTION_RPC` | clientAssertion_rpc | \ No newline at end of file diff --git a/docs/models/inputeventhubamqpinput.md b/docs/models/inputeventhubamqpinput.md index 3567f7198..aeb75f7c9 100644 --- a/docs/models/inputeventhubamqpinput.md +++ b/docs/models/inputeventhubamqpinput.md @@ -31,6 +31,7 @@ | `connection_max_backoff` | *Optional[int]* | :heavy_minus_sign: | Maximum delay between reconnection attempts, in milliseconds | | `connection_timeout_in_ms` | *Optional[int]* | :heavy_minus_sign: | Maximum time to wait for a connection to complete | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/inputeventhubinput.md b/docs/models/inputeventhubinput.md index 54e74d657..5cb9fcba1 100644 --- a/docs/models/inputeventhubinput.md +++ b/docs/models/inputeventhubinput.md @@ -39,6 +39,7 @@ | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `minimize_duplicates` | *Optional[bool]* | :heavy_minus_sign: | Minimize duplicate events by starting only one consumer for each topic partition | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputexecinput.md b/docs/models/inputexecinput.md index 35d11cb43..db0d4e81c 100644 --- a/docs/models/inputexecinput.md +++ b/docs/models/inputexecinput.md @@ -22,6 +22,7 @@ | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `interval` | *Optional[float]* | :heavy_minus_sign: | Interval between command executions in seconds. | | `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule to execute the command on. | diff --git a/docs/models/inputextrahoprevealx360input.md b/docs/models/inputextrahoprevealx360input.md new file mode 100644 index 000000000..8675f09c9 --- /dev/null +++ b/docs/models/inputextrahoprevealx360input.md @@ -0,0 +1,46 @@ +# InputExtrahopRevealx360Input + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputExtrahopRevealx360Type](../models/inputextrahoprevealx360type.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputextrahoprevealx360type.md b/docs/models/inputextrahoprevealx360type.md new file mode 100644 index 000000000..efbc51d73 --- /dev/null +++ b/docs/models/inputextrahoprevealx360type.md @@ -0,0 +1,18 @@ +# InputExtrahopRevealx360Type + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputExtrahopRevealx360Type + +value = InputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360 +``` + + +## Values + +| Name | Value | +| ---------------------- | ---------------------- | +| `EXTRAHOP_REVEALX_360` | extrahop_revealx_360 | \ No newline at end of file diff --git a/docs/models/inputf5bigipinput.md b/docs/models/inputf5bigipinput.md new file mode 100644 index 000000000..f0693669f --- /dev/null +++ b/docs/models/inputf5bigipinput.md @@ -0,0 +1,47 @@ +# InputF5BigIPInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputF5BigIPType](../models/inputf5bigiptype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputf5bigiptype.md b/docs/models/inputf5bigiptype.md new file mode 100644 index 000000000..fbbe19d84 --- /dev/null +++ b/docs/models/inputf5bigiptype.md @@ -0,0 +1,18 @@ +# InputF5BigIPType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputF5BigIPType + +value = InputF5BigIPType.F5_BIG_IP +``` + + +## Values + +| Name | Value | +| ----------- | ----------- | +| `F5_BIG_IP` | f5_big_ip | \ No newline at end of file diff --git a/docs/models/inputfileinput.md b/docs/models/inputfileinput.md index baa5a3c34..41cb2ff23 100644 --- a/docs/models/inputfileinput.md +++ b/docs/models/inputfileinput.md @@ -26,10 +26,12 @@ | `check_file_mod_time` | *Optional[bool]* | :heavy_minus_sign: | Skip files with modification times earlier than the maximum age duration | | `force_text` | *Optional[bool]* | :heavy_minus_sign: | Forces files containing binary data to be streamed as text | | `hash_len` | *Optional[float]* | :heavy_minus_sign: | Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files. | +| `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `disable_stale_channel_flush` | *Optional[bool]* | :heavy_minus_sign: | When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS. | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `path` | *Optional[str]* | :heavy_minus_sign: | Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/). | | `depth` | *Optional[float]* | :heavy_minus_sign: | Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth. | @@ -37,6 +39,8 @@ | `delete_files` | *Optional[bool]* | :heavy_minus_sign: | Delete files after they have been collected | | `salt_hash` | *Optional[bool]* | :heavy_minus_sign: | Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion. | | `optimize_leaf_directories` | *Optional[bool]* | :heavy_minus_sign: | Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories. | +| `enable_discovery_throttle` | *Optional[bool]* | :heavy_minus_sign: | When enabled, discovery will throttle CPU usage to the configured target percentage. | +| `discovery_throttle_cpu_percent` | *Optional[float]* | :heavy_minus_sign: | Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times. | | `include_unidentifiable_binary` | *Optional[bool]* | :heavy_minus_sign: | Stream binary files as Base64-encoded chunks | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/inputgigamonhecinput.md b/docs/models/inputgigamonhecinput.md new file mode 100644 index 000000000..fae02253f --- /dev/null +++ b/docs/models/inputgigamonhecinput.md @@ -0,0 +1,46 @@ +# InputGigamonHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputGigamonHecType](../models/inputgigamonhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputgigamonhectype.md b/docs/models/inputgigamonhectype.md new file mode 100644 index 000000000..97e0c6b8d --- /dev/null +++ b/docs/models/inputgigamonhectype.md @@ -0,0 +1,18 @@ +# InputGigamonHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputGigamonHecType + +value = InputGigamonHecType.GIGAMON_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `GIGAMON_HEC` | gigamon_hec | \ No newline at end of file diff --git a/docs/models/inputgooglepubsubinput.md b/docs/models/inputgooglepubsubinput.md index 8e4843d00..aec08f044 100644 --- a/docs/models/inputgooglepubsubinput.md +++ b/docs/models/inputgooglepubsubinput.md @@ -28,6 +28,7 @@ | `concurrency` | *Optional[float]* | :heavy_minus_sign: | How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5. | | `request_timeout` | *Optional[float]* | :heavy_minus_sign: | Pull request timeout, in milliseconds | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `ordered_delivery` | *Optional[bool]* | :heavy_minus_sign: | Receive events in the order they were added to the queue. The process sending events must have ordering enabled. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/inputhashicorphcpvaultdedicatedinput.md b/docs/models/inputhashicorphcpvaultdedicatedinput.md new file mode 100644 index 000000000..9c9e34416 --- /dev/null +++ b/docs/models/inputhashicorphcpvaultdedicatedinput.md @@ -0,0 +1,46 @@ +# InputHashicorpHcpVaultDedicatedInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputHashicorpHcpVaultDedicatedType](../models/inputhashicorphcpvaultdedicatedtype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputhashicorphcpvaultdedicatedtype.md b/docs/models/inputhashicorphcpvaultdedicatedtype.md new file mode 100644 index 000000000..d8b2e2a21 --- /dev/null +++ b/docs/models/inputhashicorphcpvaultdedicatedtype.md @@ -0,0 +1,18 @@ +# InputHashicorpHcpVaultDedicatedType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputHashicorpHcpVaultDedicatedType + +value = InputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED +``` + + +## Values + +| Name | Value | +| ------------------------------- | ------------------------------- | +| `HASHICORP_HCP_VAULT_DEDICATED` | hashicorp_hcp_vault_dedicated | \ No newline at end of file diff --git a/docs/models/inputhttpauthtokensext.md b/docs/models/inputhttpauthtokensext.md new file mode 100644 index 000000000..07a79cc5e --- /dev/null +++ b/docs/models/inputhttpauthtokensext.md @@ -0,0 +1,17 @@ +# InputHTTPAuthTokensExt + + +## Supported Types + +### `models.InputHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.InputHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.InputHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.InputHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/createinputelasticsearchmetadata.md b/docs/models/inputhttpauthtokensextitemstypeelasticsearchmetadata.md similarity index 86% rename from docs/models/createinputelasticsearchmetadata.md rename to docs/models/inputhttpauthtokensextitemstypeelasticsearchmetadata.md index 0f1915694..3ca4fbc08 100644 --- a/docs/models/createinputelasticsearchmetadata.md +++ b/docs/models/inputhttpauthtokensextitemstypeelasticsearchmetadata.md @@ -1,4 +1,4 @@ -# CreateInputElasticsearchMetadata +# InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata ## Fields diff --git a/docs/models/splunkhecmetadata.md b/docs/models/inputhttpauthtokensextitemstypesplunkhecmetadata.md similarity index 96% rename from docs/models/splunkhecmetadata.md rename to docs/models/inputhttpauthtokensextitemstypesplunkhecmetadata.md index 26b5e91f1..7a1872670 100644 --- a/docs/models/splunkhecmetadata.md +++ b/docs/models/inputhttpauthtokensextitemstypesplunkhecmetadata.md @@ -1,4 +1,4 @@ -# SplunkHecMetadata +# InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata ## Fields diff --git a/docs/models/createinputsystembypackelasticsearchmetadata.md b/docs/models/inputhttpauthtypesecretconstraintelasticsearchmetadata.md similarity index 86% rename from docs/models/createinputsystembypackelasticsearchmetadata.md rename to docs/models/inputhttpauthtypesecretconstraintelasticsearchmetadata.md index b7362d9af..0bf1b0e9a 100644 --- a/docs/models/createinputsystembypackelasticsearchmetadata.md +++ b/docs/models/inputhttpauthtypesecretconstraintelasticsearchmetadata.md @@ -1,4 +1,4 @@ -# CreateInputSystemByPackElasticsearchMetadata +# InputHTTPAuthTypeSecretConstraintElasticsearchMetadata ## Fields diff --git a/docs/models/createinputsystembypacksplunkhecmetadata.md b/docs/models/inputhttpauthtypesecretconstraintsplunkhecmetadata.md similarity index 96% rename from docs/models/createinputsystembypacksplunkhecmetadata.md rename to docs/models/inputhttpauthtypesecretconstraintsplunkhecmetadata.md index 6fc298e44..c2f2133bd 100644 --- a/docs/models/createinputsystembypacksplunkhecmetadata.md +++ b/docs/models/inputhttpauthtypesecretconstraintsplunkhecmetadata.md @@ -1,4 +1,4 @@ -# CreateInputSystemByPackSplunkHecMetadata +# InputHTTPAuthTypeSecretConstraintSplunkHecMetadata ## Fields diff --git a/docs/models/inputhttpinput.md b/docs/models/inputhttpinput.md index 49fe4b2d9..8bac7e1e8 100644 --- a/docs/models/inputhttpinput.md +++ b/docs/models/inputhttpinput.md @@ -35,7 +35,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.InputHTTPAuthTokensExt](../models/inputhttpauthtokensext.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputhttpinputhttpauthtokensextitemstype.md b/docs/models/inputhttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..7142cb92d --- /dev/null +++ b/docs/models/inputhttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,12 @@ +# InputHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputhttpinputhttpauthtypesecretconstraint.md b/docs/models/inputhttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..f394a1f67 --- /dev/null +++ b/docs/models/inputhttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# InputHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputhttprawauthtokensext.md b/docs/models/inputhttprawauthtokensext.md new file mode 100644 index 000000000..1f78a8431 --- /dev/null +++ b/docs/models/inputhttprawauthtokensext.md @@ -0,0 +1,12 @@ +# InputHTTPRawAuthTokensExt + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputhttprawauthtokensextunion.md b/docs/models/inputhttprawauthtokensextunion.md new file mode 100644 index 000000000..1d757cb48 --- /dev/null +++ b/docs/models/inputhttprawauthtokensextunion.md @@ -0,0 +1,17 @@ +# InputHTTPRawAuthTokensExtUnion + + +## Supported Types + +### `models.InputHTTPRawAuthTokensExt` + +```python +value: models.InputHTTPRawAuthTokensExt = /* values here */ +``` + +### `models.InputHTTPRawInputHTTPAuthTypeSecretConstraint` + +```python +value: models.InputHTTPRawInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/inputhttprawinput.md b/docs/models/inputhttprawinput.md index af50ec856..af23e4444 100644 --- a/docs/models/inputhttprawinput.md +++ b/docs/models/inputhttprawinput.md @@ -32,10 +32,11 @@ | `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.InputHTTPRawAuthTokensExtUnion](../models/inputhttprawauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS. | | `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use "*" to allow all headers. | | `access_control_allow_methods` | List[*str*] | :heavy_minus_sign: | HTTP methods echoed in Access-Control-Allow-Methods on preflight. | diff --git a/docs/models/inputhttprawinputhttpauthtypesecretconstraint.md b/docs/models/inputhttprawinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..bc119bd3b --- /dev/null +++ b/docs/models/inputhttprawinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# InputHTTPRawInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputjournalfilesinput.md b/docs/models/inputjournalfilesinput.md index b25ee7337..60c9a94d1 100644 --- a/docs/models/inputjournalfilesinput.md +++ b/docs/models/inputjournalfilesinput.md @@ -23,6 +23,7 @@ | `max_age_dur` | *Optional[str]* | :heavy_minus_sign: | The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters. | | `suppress_missing_path_errors` | *Optional[bool]* | :heavy_minus_sign: | Suppress errors when search path does not exist | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/inputkafkainput.md b/docs/models/inputkafkainput.md index 3b4c84087..ade9929e2 100644 --- a/docs/models/inputkafkainput.md +++ b/docs/models/inputkafkainput.md @@ -39,6 +39,7 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputkinesisinput.md b/docs/models/inputkinesisinput.md index e27488fb9..1df7b151b 100644 --- a/docs/models/inputkinesisinput.md +++ b/docs/models/inputkinesisinput.md @@ -36,6 +36,7 @@ | `verify_kpl_check_sums` | *Optional[bool]* | :heavy_minus_sign: | Verify Kinesis Producer Library (KPL) event checksums | | `avoid_duplicates` | *Optional[bool]* | :heavy_minus_sign: | When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/inputmicrosoftcopilotauthenticationmethod.md b/docs/models/inputmicrosoftcopilotauthenticationmethod.md new file mode 100644 index 000000000..e064d1ae4 --- /dev/null +++ b/docs/models/inputmicrosoftcopilotauthenticationmethod.md @@ -0,0 +1,21 @@ +# InputMicrosoftCopilotAuthenticationMethod + +Select authentication method. + +## Example Usage + +```python +from cribl_control_plane.models import InputMicrosoftCopilotAuthenticationMethod + +value = InputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `OAUTH_SECRET` | oauthSecret | +| `OAUTH_CERT` | oauthCert | \ No newline at end of file diff --git a/docs/models/inputmicrosoftcopilotinput.md b/docs/models/inputmicrosoftcopilotinput.md new file mode 100644 index 000000000..7a6f0da5c --- /dev/null +++ b/docs/models/inputmicrosoftcopilotinput.md @@ -0,0 +1,48 @@ +# InputMicrosoftCopilotInput + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputMicrosoftCopilotType](../models/inputmicrosoftcopilottype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `tenant_id` | *str* | :heavy_check_mark: | Directory (tenant) ID from Azure Active Directory | +| `client_id` | *str* | :heavy_check_mark: | Application (client) ID from the app registration | +| `resource` | *Optional[str]* | :heavy_minus_sign: | Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type. | +| `auth_type` | [Optional[models.InputMicrosoftCopilotAuthenticationMethod]](../models/inputmicrosoftcopilotauthenticationmethod.md) | :heavy_minus_sign: | Select authentication method. | +| `plan_type` | [Optional[models.InputMicrosoftCopilotSubscriptionPlan]](../models/inputmicrosoftcopilotsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule for collection runs | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run. | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `page_size` | *Optional[int]* | :heavy_minus_sign: | Number of interactions to request per page ($top). Maximum 1000. | +| `app_class_filter` | List[*str*] | :heavy_minus_sign: | Limit collection to specific Copilot app classes. Leave empty to collect all. | +| `filter_by_license` | *Optional[bool]* | :heavy_minus_sign: | Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time. | +| `sku_ids` | List[*str*] | :heavy_minus_sign: | Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans. | +| `manage_state` | [Optional[models.InputMicrosoftCopilotManageState]](../models/inputmicrosoftcopilotmanagestate.md) | :heavy_minus_sign: | N/A | +| `timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely. | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.InputMicrosoftCopilotRetryRules]](../models/inputmicrosoftcopilotretryrules.md) | :heavy_minus_sign: | N/A | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references the client secret from your app registration | +| `cert_options` | [Optional[models.CertOptions]](../models/certoptions.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_plan_type` | *Optional[str]* | :heavy_minus_sign: | Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime. | \ No newline at end of file diff --git a/docs/models/inputmicrosoftcopilotmanagestate.md b/docs/models/inputmicrosoftcopilotmanagestate.md new file mode 100644 index 000000000..e13e2718d --- /dev/null +++ b/docs/models/inputmicrosoftcopilotmanagestate.md @@ -0,0 +1,7 @@ +# InputMicrosoftCopilotManageState + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/inputmicrosoftcopilotretryrules.md b/docs/models/inputmicrosoftcopilotretryrules.md new file mode 100644 index 000000000..ee926df8d --- /dev/null +++ b/docs/models/inputmicrosoftcopilotretryrules.md @@ -0,0 +1,15 @@ +# InputMicrosoftCopilotRetryRules + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `type` | [models.RetryTypeOptionsHealthCheckCollectorConfRetryRules](../models/retrytypeoptionshealthcheckcollectorconfretryrules.md) | :heavy_check_mark: | The algorithm to use when performing HTTP retries | +| `interval` | *Optional[float]* | :heavy_minus_sign: | Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute). | +| `limit` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times to retry a failed HTTP request | +| `multiplier` | *Optional[float]* | :heavy_minus_sign: | Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on | +| `codes` | List[*float*] | :heavy_minus_sign: | List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503. | +| `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored. | +| `retry_connect_timeout` | *Optional[bool]* | :heavy_minus_sign: | Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs | +| `retry_connect_reset` | *Optional[bool]* | :heavy_minus_sign: | Retry request when a connection reset (ECONNRESET) error occurs | \ No newline at end of file diff --git a/docs/models/inputmicrosoftcopilotsubscriptionplan.md b/docs/models/inputmicrosoftcopilotsubscriptionplan.md new file mode 100644 index 000000000..659e57e77 --- /dev/null +++ b/docs/models/inputmicrosoftcopilotsubscriptionplan.md @@ -0,0 +1,23 @@ +# InputMicrosoftCopilotSubscriptionPlan + +Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. + +## Example Usage + +```python +from cribl_control_plane.models import InputMicrosoftCopilotSubscriptionPlan + +value = InputMicrosoftCopilotSubscriptionPlan.ENTERPRISE_GCC + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `ENTERPRISE_GCC` | enterprise_gcc | +| `GCC` | gcc | +| `GCC_HIGH` | gcc_high | +| `DOD` | dod | \ No newline at end of file diff --git a/docs/models/inputmicrosoftcopilottype.md b/docs/models/inputmicrosoftcopilottype.md new file mode 100644 index 000000000..dae6a67a2 --- /dev/null +++ b/docs/models/inputmicrosoftcopilottype.md @@ -0,0 +1,18 @@ +# InputMicrosoftCopilotType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputMicrosoftCopilotType + +value = InputMicrosoftCopilotType.MICROSOFT_COPILOT +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `MICROSOFT_COPILOT` | microsoft_copilot | \ No newline at end of file diff --git a/docs/models/inputmicrosoftgraphinput.md b/docs/models/inputmicrosoftgraphinput.md index 16671c991..35478ed23 100644 --- a/docs/models/inputmicrosoftgraphinput.md +++ b/docs/models/inputmicrosoftgraphinput.md @@ -40,7 +40,7 @@ | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | Directory ID (tenant identifier) in Azure Active Directory. | | `client_id` | *Optional[str]* | :heavy_minus_sign: | client_id to pass in the OAuth request parameter. | | `resource` | *Optional[str]* | :heavy_minus_sign: | Resource to pass in the OAuth request parameter. | -| `plan_type` | [Optional[models.SubscriptionPlan]](../models/subscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | +| `plan_type` | [Optional[models.InputMicrosoftGraphSubscriptionPlan]](../models/inputmicrosoftgraphsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your client_secret to pass in the OAuth request parameter. | | `cert_options` | [Optional[models.CertOptionsType]](../models/certoptionstype.md) | :heavy_minus_sign: | N/A | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/subscriptionplan.md b/docs/models/inputmicrosoftgraphsubscriptionplan.md similarity index 73% rename from docs/models/subscriptionplan.md rename to docs/models/inputmicrosoftgraphsubscriptionplan.md index c5c744184..05436665d 100644 --- a/docs/models/subscriptionplan.md +++ b/docs/models/inputmicrosoftgraphsubscriptionplan.md @@ -1,13 +1,13 @@ -# SubscriptionPlan +# InputMicrosoftGraphSubscriptionPlan Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise ## Example Usage ```python -from cribl_control_plane.models import SubscriptionPlan +from cribl_control_plane.models import InputMicrosoftGraphSubscriptionPlan -value = SubscriptionPlan.ENTERPRISE_GCC +value = InputMicrosoftGraphSubscriptionPlan.ENTERPRISE_GCC # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/inputmimecasthecinput.md b/docs/models/inputmimecasthecinput.md new file mode 100644 index 000000000..b11a10fd0 --- /dev/null +++ b/docs/models/inputmimecasthecinput.md @@ -0,0 +1,46 @@ +# InputMimecastHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputMimecastHecType](../models/inputmimecasthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputmimecasthectype.md b/docs/models/inputmimecasthectype.md new file mode 100644 index 000000000..fff9a0286 --- /dev/null +++ b/docs/models/inputmimecasthectype.md @@ -0,0 +1,18 @@ +# InputMimecastHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputMimecastHecType + +value = InputMimecastHecType.MIMECAST_HEC +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `MIMECAST_HEC` | mimecast_hec | \ No newline at end of file diff --git a/docs/models/inputmodeldriventelemetryinput.md b/docs/models/inputmodeldriventelemetryinput.md index 4fb77d1b0..e01eb415c 100644 --- a/docs/models/inputmodeldriventelemetryinput.md +++ b/docs/models/inputmodeldriventelemetryinput.md @@ -3,26 +3,28 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | -| `type` | [models.InputModelDrivenTelemetryType](../models/inputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | -| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | -| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | -| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | -| `port` | *float* | :heavy_check_mark: | Port to listen on | -| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | -| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | -| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputModelDrivenTelemetryType](../models/inputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each. | +| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | \ No newline at end of file diff --git a/docs/models/inputmskinput.md b/docs/models/inputmskinput.md index 65fab63a3..5cc592ce8 100644 --- a/docs/models/inputmskinput.md +++ b/docs/models/inputmskinput.md @@ -48,6 +48,7 @@ | `max_bytes_per_partition` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB). | | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/inputopentelemetryinput.md b/docs/models/inputopentelemetryinput.md index d179f5b12..6204b5258 100644 --- a/docs/models/inputopentelemetryinput.md +++ b/docs/models/inputopentelemetryinput.md @@ -31,9 +31,11 @@ | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point | | `otlp_version` | [Optional[models.InputOpenTelemetryOTLPVersion]](../models/inputopentelemetryotlpversion.md) | :heavy_minus_sign: | The version of OTLP Protobuf definitions to use when interpreting received data | | `auth_type` | [Optional[models.InputOpenTelemetryAuthenticationType]](../models/inputopentelemetryauthenticationtype.md) | :heavy_minus_sign: | OpenTelemetry authentication type | -| `auth_methods_ext` | List[[models.AuthMethodsExt](../models/authmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted. | +| `auth_methods_ext` | List[[models.AuthMethodsExt](../models/authmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | diff --git a/docs/models/inputpingidentitypingoneinput.md b/docs/models/inputpingidentitypingoneinput.md new file mode 100644 index 000000000..dae4cf101 --- /dev/null +++ b/docs/models/inputpingidentitypingoneinput.md @@ -0,0 +1,46 @@ +# InputPingIdentityPingoneInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputPingIdentityPingoneType](../models/inputpingidentitypingonetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputpingidentitypingonetype.md b/docs/models/inputpingidentitypingonetype.md new file mode 100644 index 000000000..210eecba6 --- /dev/null +++ b/docs/models/inputpingidentitypingonetype.md @@ -0,0 +1,18 @@ +# InputPingIdentityPingoneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputPingIdentityPingoneType + +value = InputPingIdentityPingoneType.PING_IDENTITY_PINGONE +``` + + +## Values + +| Name | Value | +| ----------------------- | ----------------------- | +| `PING_IDENTITY_PINGONE` | ping_identity_pingone | \ No newline at end of file diff --git a/docs/models/inputproofpointpodinput.md b/docs/models/inputproofpointpodinput.md new file mode 100644 index 000000000..8486518cb --- /dev/null +++ b/docs/models/inputproofpointpodinput.md @@ -0,0 +1,31 @@ +# InputProofpointPodInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputProofpointPodType](../models/inputproofpointpodtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `cluster_id` | *str* | :heavy_check_mark: | Proofpoint on Demand cluster ID. | +| `feed_type` | [models.FeedType](../models/feedtype.md) | :heavy_check_mark: | Proofpoint on Demand feed to ingest. | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `compress` | *Optional[bool]* | :heavy_minus_sign: | Compress the feed connection. | +| `handshake_timeout` | *Optional[float]* | :heavy_minus_sign: | Maximum time to wait for the connection handshake to complete. | +| `keep_alive_interval_sec` | *Optional[float]* | :heavy_minus_sign: | How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | Maximum number of consecutive keepalive pings that can go unanswered before reconnecting. | +| `max_message_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc. | +| `read_buffer_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_cluster_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime. | \ No newline at end of file diff --git a/docs/models/inputproofpointpodtype.md b/docs/models/inputproofpointpodtype.md new file mode 100644 index 000000000..579d2d641 --- /dev/null +++ b/docs/models/inputproofpointpodtype.md @@ -0,0 +1,18 @@ +# InputProofpointPodType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputProofpointPodType + +value = InputProofpointPodType.PROOFPOINT_POD +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `PROOFPOINT_POD` | proofpoint_pod | \ No newline at end of file diff --git a/docs/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md b/docs/models/inputprovenancetypeoptional.md similarity index 72% rename from docs/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md rename to docs/models/inputprovenancetypeoptional.md index 656b79d2e..83280f2ad 100644 --- a/docs/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md +++ b/docs/models/inputprovenancetypeoptional.md @@ -1,4 +1,4 @@ -# InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint +# InputProvenanceTypeOptional Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. @@ -7,7 +7,9 @@ Read-only metadata that records how the Source was created. Preserved on update | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `origin` | [Optional[models.Origin]](../models/origin.md) | :heavy_minus_sign: | Feature that created the Source. | +| `origin` | [Optional[models.OriginOptionsCriblSourceProvenance]](../models/originoptionscriblsourceprovenance.md) | :heavy_minus_sign: | Feature that created the Source. | | `destination_arn` | *Optional[str]* | :heavy_minus_sign: | ARN of the S3 bucket or Firehose delivery stream configured as the Source. | | `source_arn` | *Optional[str]* | :heavy_minus_sign: | ARN of the AWS resource that produces the logs. | -| `account_id` | *Optional[str]* | :heavy_minus_sign: | Cloud tenant or scope id the Source was configured for (for example an AWS account id, GCP project or folder id, or Azure subscription or resource group id). | \ No newline at end of file +| `source_service` | *Optional[str]* | :heavy_minus_sign: | Resolved DSD source-service offering, when known. | +| `account_id` | *Optional[str]* | :heavy_minus_sign: | Cloud tenant or scope id the Source was configured for (for example an AWS account id, GCP project or folder id, or Azure subscription or resource group id). | +| `template_family` | [Optional[models.TemplateFamilyOptionsCriblSourceProvenance]](../models/templatefamilyoptionscriblsourceprovenance.md) | :heavy_minus_sign: | Infrastructure-as-code family that provisioned the AWS resources (absent means cloudformation). | \ No newline at end of file diff --git a/docs/models/inputrawudpinput.md b/docs/models/inputrawudpinput.md index 6f96c8fa3..a7d6d4bfd 100644 --- a/docs/models/inputrawudpinput.md +++ b/docs/models/inputrawudpinput.md @@ -23,6 +23,7 @@ | `ingest_raw_bytes` | *Optional[bool]* | :heavy_minus_sign: | If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram. | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputresponse.md b/docs/models/inputresponse.md index c5b610ada..b2bd1a5db 100644 --- a/docs/models/inputresponse.md +++ b/docs/models/inputresponse.md @@ -53,6 +53,12 @@ value: models.InputResponseInputSplunkHec = /* values here */ value: models.InputResponseInputAzureBlob = /* values here */ ``` +### `models.InputResponseInputAzureVnetFlowLog` + +```python +value: models.InputResponseInputAzureVnetFlowLog = /* values here */ +``` + ### `models.InputResponseInputElastic` ```python @@ -389,6 +395,12 @@ value: models.InputResponseInputBedrockS3 = /* values here */ value: models.InputResponseInputServicenowTable = /* values here */ ``` +### `models.InputResponseInputProofpointPod` + +```python +value: models.InputResponseInputProofpointPod = /* values here */ +``` + ### `models.InputResponseInputZscalerHec` ```python @@ -413,6 +425,30 @@ value: models.InputResponseInputSysdigHec = /* values here */ value: models.InputResponseInputUpwindHec = /* values here */ ``` +### `models.InputResponseInputTrellixHec` + +```python +value: models.InputResponseInputTrellixHec = /* values here */ +``` + +### `models.InputResponseInputSailpointHec` + +```python +value: models.InputResponseInputSailpointHec = /* values here */ +``` + +### `models.InputResponseInputExtrahopRevealx360` + +```python +value: models.InputResponseInputExtrahopRevealx360 = /* values here */ +``` + +### `models.InputResponseInputAquaSecurityHec` + +```python +value: models.InputResponseInputAquaSecurityHec = /* values here */ +``` + ### `models.InputResponseInputOpenaiComplianceLogs` ```python @@ -425,9 +461,75 @@ value: models.InputResponseInputOpenaiComplianceLogs = /* values here */ value: models.InputResponseInputAnthropicCompliance = /* values here */ ``` +### `models.InputResponseInputAnthropicEnterpriseAnalytics` + +```python +value: models.InputResponseInputAnthropicEnterpriseAnalytics = /* values here */ +``` + +### `models.InputResponseInputMicrosoftCopilot` + +```python +value: models.InputResponseInputMicrosoftCopilot = /* values here */ +``` + ### `models.InputResponseInputOkta` ```python value: models.InputResponseInputOkta = /* values here */ ``` +### `models.InputResponseInputAkamaiHec` + +```python +value: models.InputResponseInputAkamaiHec = /* values here */ +``` + +### `models.InputResponseInputPingIdentityPingone` + +```python +value: models.InputResponseInputPingIdentityPingone = /* values here */ +``` + +### `models.InputResponseInputGigamonHec` + +```python +value: models.InputResponseInputGigamonHec = /* values here */ +``` + +### `models.InputResponseInputVectraAiHec` + +```python +value: models.InputResponseInputVectraAiHec = /* values here */ +``` + +### `models.InputResponseInputF5BigIP` + +```python +value: models.InputResponseInputF5BigIP = /* values here */ +``` + +### `models.InputResponseInputBeyondtrustHec` + +```python +value: models.InputResponseInputBeyondtrustHec = /* values here */ +``` + +### `models.InputResponseInputHashicorpHcpVaultDedicated` + +```python +value: models.InputResponseInputHashicorpHcpVaultDedicated = /* values here */ +``` + +### `models.InputResponseInputMimecastHec` + +```python +value: models.InputResponseInputMimecastHec = /* values here */ +``` + +### `models.InputResponseInputTrendMicroVisionOne` + +```python +value: models.InputResponseInputTrendMicroVisionOne = /* values here */ +``` + diff --git a/docs/models/inputresponseactivities.md b/docs/models/inputresponseactivities.md index fe9cfe52f..d0f3e7fad 100644 --- a/docs/models/inputresponseactivities.md +++ b/docs/models/inputresponseactivities.md @@ -5,14 +5,14 @@ Activities ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.InputResponseActivitiesManageState]](../models/inputresponseactivitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.InputResponseActivitiesManageState]](../models/inputresponseactivitiesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseauthmethodsext.md b/docs/models/inputresponseauthmethodsext.md index 9fb9eb8c2..47d0168b9 100644 --- a/docs/models/inputresponseauthmethodsext.md +++ b/docs/models/inputresponseauthmethodsext.md @@ -13,4 +13,8 @@ | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | -| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | \ No newline at end of file +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `issuer` | *Optional[str]* | :heavy_minus_sign: | Expected token issuer (iss claim) | +| `jwks_uri` | *Optional[str]* | :heavy_minus_sign: | URL of the JWKS endpoint used to fetch signing keys | +| `audience` | *Optional[str]* | :heavy_minus_sign: | Expected token audience (aud claim) | +| `scopes` | List[*str*] | :heavy_minus_sign: | Scopes the token must grant (optional) | \ No newline at end of file diff --git a/docs/models/inputresponseauthmethodsextauthenticationtype.md b/docs/models/inputresponseauthmethodsextauthenticationtype.md index a1b522d33..93c69fdeb 100644 --- a/docs/models/inputresponseauthmethodsextauthenticationtype.md +++ b/docs/models/inputresponseauthmethodsextauthenticationtype.md @@ -20,4 +20,5 @@ value = InputResponseAuthMethodsExtAuthenticationType.TOKEN | `TOKEN` | token | | `TOKEN_SECRET` | tokenSecret | | `BASIC` | basic | -| `BASIC_SECRET` | basicSecret | \ No newline at end of file +| `BASIC_SECRET` | basicSecret | +| `OAUTH` | oauth | \ No newline at end of file diff --git a/docs/models/inputresponseauthtokensext.md b/docs/models/inputresponseauthtokensext.md deleted file mode 100644 index a93ac9fcf..000000000 --- a/docs/models/inputresponseauthtokensext.md +++ /dev/null @@ -1,12 +0,0 @@ -# InputResponseAuthTokensExt - - -## Fields - -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------ | -| `token` | *str* | :heavy_check_mark: | Token | -| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | -| `splunk_hec_metadata` | [Optional[models.InputResponseSplunkHecMetadata]](../models/inputresponsesplunkhecmetadata.md) | :heavy_minus_sign: | N/A | -| `elasticsearch_metadata` | [Optional[models.InputResponseElasticsearchMetadata]](../models/inputresponseelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseazureblobstorage.md b/docs/models/inputresponseazureblobstorage.md index 8bce70069..e3d539f64 100644 --- a/docs/models/inputresponseazureblobstorage.md +++ b/docs/models/inputresponseazureblobstorage.md @@ -8,7 +8,7 @@ Azure Blob Storage | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `container_name` | *str* | :heavy_check_mark: | Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens. | -| `auth_type` | [Optional[models.InputResponseInputEventhubAmqpAuthenticationMethod]](../models/inputresponseinputeventhubamqpauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | diff --git a/docs/models/inputresponsebucketwidth.md b/docs/models/inputresponsebucketwidth.md new file mode 100644 index 000000000..59510c567 --- /dev/null +++ b/docs/models/inputresponsebucketwidth.md @@ -0,0 +1,22 @@ +# InputResponseBucketWidth + +Time bucket size for aggregated results. Smaller buckets yield more events per collection run. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseBucketWidth + +value = InputResponseBucketWidth.ONED + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------ | ------ | +| `ONED` | 1d | +| `ONEH` | 1h | +| `ONEM` | 1m | \ No newline at end of file diff --git a/docs/models/inputresponsecertoptions.md b/docs/models/inputresponsecertoptions.md new file mode 100644 index 000000000..ea6a3306b --- /dev/null +++ b/docs/models/inputresponsecertoptions.md @@ -0,0 +1,11 @@ +# InputResponseCertOptions + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | -------------------------------------------------------------- | +| `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of a predefined certificate | +| `priv_key_path` | *str* | :heavy_check_mark: | Path to the private key (PEM format). Can reference $ENV_VARS. | +| `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to decrypt the private key | +| `cert_path` | *str* | :heavy_check_mark: | Path to the certificate (PEM format). Can reference $ENV_VARS. | \ No newline at end of file diff --git a/docs/models/inputresponsechatmessages.md b/docs/models/inputresponsechatmessages.md index b11a3316f..1b5cca5fb 100644 --- a/docs/models/inputresponsechatmessages.md +++ b/docs/models/inputresponsechatmessages.md @@ -5,14 +5,14 @@ Chat Messages ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.InputResponseChatMessagesManageState]](../models/inputresponsechatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.InputResponseChatMessagesManageState]](../models/inputresponsechatmessagesmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponsechats.md b/docs/models/inputresponsechats.md index 67b3eb55d..d86b98748 100644 --- a/docs/models/inputresponsechats.md +++ b/docs/models/inputresponsechats.md @@ -5,14 +5,14 @@ Chats ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.InputResponseChatsManageState]](../models/inputresponsechatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.InputResponseChatsManageState]](../models/inputresponsechatsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponsecontenttype.md b/docs/models/inputresponsecontenttype.md new file mode 100644 index 000000000..5ab384fc3 --- /dev/null +++ b/docs/models/inputresponsecontenttype.md @@ -0,0 +1,21 @@ +# InputResponseContentType + +Content type + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseContentType + +value = InputResponseContentType.USAGE_REPORT + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `USAGE_REPORT` | Usage Report | +| `COST_REPORT` | Cost Report | \ No newline at end of file diff --git a/docs/models/inputresponsefeedtype.md b/docs/models/inputresponsefeedtype.md new file mode 100644 index 000000000..f370d5f5d --- /dev/null +++ b/docs/models/inputresponsefeedtype.md @@ -0,0 +1,22 @@ +# InputResponseFeedType + +Proofpoint on Demand feed to ingest. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseFeedType + +value = InputResponseFeedType.MESSAGE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `MESSAGE` | message | +| `MAILLOG` | maillog | +| `AUDIT` | audit | \ No newline at end of file diff --git a/docs/models/inputresponsegroupby.md b/docs/models/inputresponsegroupby.md new file mode 100644 index 000000000..12d5b0f1a --- /dev/null +++ b/docs/models/inputresponsegroupby.md @@ -0,0 +1,27 @@ +# InputResponseGroupBy + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseGroupBy + +value = InputResponseGroupBy.MODEL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------ | ------------------ | +| `MODEL` | model | +| `PRODUCT` | product | +| `CONTEXT_WINDOW` | context_window | +| `INFERENCE_GEO` | inference_geo | +| `SPEED` | speed | +| `RBAC_GROUP_ID` | rbac_group_id | +| `SLACK_CHANNEL_ID` | slack_channel_id | +| `TEAMS_CHANNEL_ID` | teams_channel_id | +| `COST_TYPE` | cost_type | +| `TOKEN_TYPE` | token_type | \ No newline at end of file diff --git a/docs/models/inputresponseinputakamaihec.md b/docs/models/inputresponseinputakamaihec.md new file mode 100644 index 000000000..8225d3aa3 --- /dev/null +++ b/docs/models/inputresponseinputakamaihec.md @@ -0,0 +1,44 @@ +# InputResponseInputAkamaiHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputAkamaiHecType](../models/inputresponseinputakamaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputakamaihectype.md b/docs/models/inputresponseinputakamaihectype.md new file mode 100644 index 000000000..15c357204 --- /dev/null +++ b/docs/models/inputresponseinputakamaihectype.md @@ -0,0 +1,18 @@ +# InputResponseInputAkamaiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputAkamaiHecType + +value = InputResponseInputAkamaiHecType.AKAMAI_HEC +``` + + +## Values + +| Name | Value | +| ------------ | ------------ | +| `AKAMAI_HEC` | akamai_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputanthropiccompliance.md b/docs/models/inputresponseinputanthropiccompliance.md index 9b9e31c26..f319bf847 100644 --- a/docs/models/inputresponseinputanthropiccompliance.md +++ b/docs/models/inputresponseinputanthropiccompliance.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `api_key` | *Optional[str]* | :heavy_minus_sign: | API key | @@ -39,5 +39,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputanthropicenterpriseanalytics.md b/docs/models/inputresponseinputanthropicenterpriseanalytics.md new file mode 100644 index 000000000..699f70810 --- /dev/null +++ b/docs/models/inputresponseinputanthropicenterpriseanalytics.md @@ -0,0 +1,35 @@ +# InputResponseInputAnthropicEnterpriseAnalytics + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputAnthropicEnterpriseAnalyticsType](../models/inputresponseinputanthropicenterpriseanalyticstype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `api_key` | *Optional[str]* | :heavy_minus_sign: | API key | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored API key with read:analytics scope | +| `content_config` | List[[models.InputResponseInputAnthropicEnterpriseAnalyticsContentConfig](../models/inputresponseinputanthropicenterpriseanalyticscontentconfig.md)] | :heavy_check_mark: | Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout. Use 0 to disable. | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.RetryRulesType]](../models/retryrulestype.md) | :heavy_minus_sign: | N/A | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputanthropicenterpriseanalyticscontentconfig.md b/docs/models/inputresponseinputanthropicenterpriseanalyticscontentconfig.md new file mode 100644 index 000000000..66cae38c8 --- /dev/null +++ b/docs/models/inputresponseinputanthropicenterpriseanalyticscontentconfig.md @@ -0,0 +1,18 @@ +# InputResponseInputAnthropicEnterpriseAnalyticsContentConfig + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `content_type` | [models.InputResponseContentType](../models/inputresponsecontenttype.md) | :heavy_check_mark: | Content type | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark. | +| `manage_state` | *Optional[bool]* | :heavy_minus_sign: | Manage state | +| `group_by` | List[[models.InputResponseGroupBy](../models/inputresponsegroupby.md)] | :heavy_minus_sign: | Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket. | +| `bucket_width` | [Optional[models.InputResponseBucketWidth]](../models/inputresponsebucketwidth.md) | :heavy_minus_sign: | Time bucket size for aggregated results. Smaller buckets yield more events per collection run. | +| `cron_schedule` | *str* | :heavy_check_mark: | Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results. | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d. | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | \ No newline at end of file diff --git a/docs/models/inputresponseinputanthropicenterpriseanalyticstype.md b/docs/models/inputresponseinputanthropicenterpriseanalyticstype.md new file mode 100644 index 000000000..78dc2dbc3 --- /dev/null +++ b/docs/models/inputresponseinputanthropicenterpriseanalyticstype.md @@ -0,0 +1,18 @@ +# InputResponseInputAnthropicEnterpriseAnalyticsType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputAnthropicEnterpriseAnalyticsType + +value = InputResponseInputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS +``` + + +## Values + +| Name | Value | +| -------------------------------- | -------------------------------- | +| `ANTHROPIC_ENTERPRISE_ANALYTICS` | anthropic_enterprise_analytics | \ No newline at end of file diff --git a/docs/models/inputresponseinputappleunifiedlogs.md b/docs/models/inputresponseinputappleunifiedlogs.md index ad2936d3b..1501bbe8e 100644 --- a/docs/models/inputresponseinputappleunifiedlogs.md +++ b/docs/models/inputresponseinputappleunifiedlogs.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `predicate` | *str* | :heavy_check_mark: | String to filter log entries, in NSPredicate format (e.g., subsystem == "com.apple.security" or process == "kernel"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information. | @@ -22,5 +22,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputappscope.md b/docs/models/inputresponseinputappscope.md index 7c3d87eb0..366230737 100644 --- a/docs/models/inputresponseinputappscope.md +++ b/docs/models/inputresponseinputappscope.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `ip_whitelist_regex` | *Optional[str]* | :heavy_minus_sign: | Regex matching IP addresses that are allowed to establish a connection | @@ -28,7 +28,7 @@ | `enable_unix_path` | *Optional[bool]* | :heavy_minus_sign: | Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port. | | `filter_` | [Optional[models.InputResponseInputAppscopeFilter]](../models/inputresponseinputappscopefilter.md) | :heavy_minus_sign: | N/A | | `persistence` | [Optional[models.InputResponseInputAppscopePersistence]](../models/inputresponseinputappscopepersistence.md) | :heavy_minus_sign: | Persistence | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | | `port` | *Optional[float]* | :heavy_minus_sign: | Port to listen on | @@ -41,5 +41,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputaquasecurityhec.md b/docs/models/inputresponseinputaquasecurityhec.md new file mode 100644 index 000000000..88e7d139f --- /dev/null +++ b/docs/models/inputresponseinputaquasecurityhec.md @@ -0,0 +1,50 @@ +# InputResponseInputAquaSecurityHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputAquaSecurityHecType](../models/inputresponseinputaquasecurityhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputaquasecurityhectype.md b/docs/models/inputresponseinputaquasecurityhectype.md new file mode 100644 index 000000000..828c56bdf --- /dev/null +++ b/docs/models/inputresponseinputaquasecurityhectype.md @@ -0,0 +1,18 @@ +# InputResponseInputAquaSecurityHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputAquaSecurityHecType + +value = InputResponseInputAquaSecurityHecType.AQUA_SECURITY_HEC +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `AQUA_SECURITY_HEC` | aqua_security_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputazureblob.md b/docs/models/inputresponseinputazureblob.md index c0d7dc5ec..8306d58bd 100644 --- a/docs/models/inputresponseinputazureblob.md +++ b/docs/models/inputresponseinputazureblob.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `queue_name` | *str* | :heavy_check_mark: | The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}` | @@ -23,12 +23,14 @@ | `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | | `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | | `skip_on_error` | *Optional[bool]* | :heavy_minus_sign: | Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors. | +| `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `parquet_chunk_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum file size for each Parquet chunk | | `parquet_chunk_download_timeout` | *Optional[float]* | :heavy_minus_sign: | The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified. | | `auth_type` | [Optional[models.AuthenticationMethodOptions]](../models/authenticationmethodoptions.md) | :heavy_minus_sign: | Authentication method | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `connection_string` | *Optional[str]* | :heavy_minus_sign: | Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | @@ -47,5 +49,5 @@ | `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | | `template_azure_cloud` | *Optional[str]* | :heavy_minus_sign: | Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputazurevnetflowlog.md b/docs/models/inputresponseinputazurevnetflowlog.md new file mode 100644 index 000000000..90ce2469a --- /dev/null +++ b/docs/models/inputresponseinputazurevnetflowlog.md @@ -0,0 +1,47 @@ +# InputResponseInputAzureVnetFlowLog + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputAzureVnetFlowLogType](../models/inputresponseinputazurevnetflowlogtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `queue_name` | *str* | :heavy_check_mark: | The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}` | +| `file_filter` | *Optional[str]* | :heavy_minus_sign: | Regex matching file names to download and process. Defaults to: .* | +| `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request. | +| `num_receivers` | *Optional[float]* | :heavy_minus_sign: | How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead. | +| `max_messages` | *Optional[float]* | :heavy_minus_sign: | The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32. | +| `max_dequeue_count` | *Optional[float]* | :heavy_minus_sign: | Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers. | +| `service_period_secs` | *Optional[float]* | :heavy_minus_sign: | The duration (in seconds) which pollers should be validated and restarted if exited | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc]](../models/authenticationmethodoptionsclientassertionclientassertionrpc.md) | :heavy_minus_sign: | Authentication method | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `storage_account_name` | *Optional[str]* | :heavy_minus_sign: | The name of your Azure storage account | +| `tenant_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's tenant ID | +| `client_id` | *Optional[str]* | :heavy_minus_sign: | The service principal's client ID | +| `azure_cloud` | *Optional[str]* | :heavy_minus_sign: | The Azure cloud to use. Defaults to Azure Public Cloud. | +| `endpoint_suffix` | *Optional[str]* | :heavy_minus_sign: | Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net. | +| `client_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `certificate` | [Optional[models.CertificateType]](../models/certificatetype.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_queue_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime. | +| `template_storage_account_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_azure_cloud` | *Optional[str]* | :heavy_minus_sign: | Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputazurevnetflowlogtype.md b/docs/models/inputresponseinputazurevnetflowlogtype.md new file mode 100644 index 000000000..9f598f67e --- /dev/null +++ b/docs/models/inputresponseinputazurevnetflowlogtype.md @@ -0,0 +1,18 @@ +# InputResponseInputAzureVnetFlowLogType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputAzureVnetFlowLogType + +value = InputResponseInputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG +``` + + +## Values + +| Name | Value | +| --------------------- | --------------------- | +| `AZURE_VNET_FLOW_LOG` | azure_vnet_flow_log | \ No newline at end of file diff --git a/docs/models/inputresponseinputbedrocks3.md b/docs/models/inputresponseinputbedrocks3.md index 2239939c6..974e16788 100644 --- a/docs/models/inputresponseinputbedrocks3.md +++ b/docs/models/inputresponseinputbedrocks3.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `queue_name` | *str* | :heavy_check_mark: | The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`. | @@ -72,5 +72,5 @@ | `template_sqs_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime. | | `template_sqs_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime. | | `template_sqs_aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputbeyondtrusthec.md b/docs/models/inputresponseinputbeyondtrusthec.md new file mode 100644 index 000000000..206be6d02 --- /dev/null +++ b/docs/models/inputresponseinputbeyondtrusthec.md @@ -0,0 +1,48 @@ +# InputResponseInputBeyondtrustHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputBeyondtrustHecType](../models/inputresponseinputbeyondtrusthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputbeyondtrusthectype.md b/docs/models/inputresponseinputbeyondtrusthectype.md new file mode 100644 index 000000000..1d7c2f4f6 --- /dev/null +++ b/docs/models/inputresponseinputbeyondtrusthectype.md @@ -0,0 +1,18 @@ +# InputResponseInputBeyondtrustHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputBeyondtrustHecType + +value = InputResponseInputBeyondtrustHecType.BEYONDTRUST_HEC +``` + + +## Values + +| Name | Value | +| ----------------- | ----------------- | +| `BEYONDTRUST_HEC` | beyondtrust_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputcloudflarehec.md b/docs/models/inputresponseinputcloudflarehec.md index 7b6b40e87..0dbee60cb 100644 --- a/docs/models/inputresponseinputcloudflarehec.md +++ b/docs/models/inputresponseinputcloudflarehec.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -48,5 +48,5 @@ | `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | | `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | | `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputcollection.md b/docs/models/inputresponseinputcollection.md index d73818031..27bbca6fc 100644 --- a/docs/models/inputresponseinputcollection.md +++ b/docs/models/inputresponseinputcollection.md @@ -15,7 +15,7 @@ Input settings for a collection job, including event breaking, routing, and prep | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | @@ -26,5 +26,5 @@ Input settings for a collection job, including event breaking, routing, and prep | `output` | *Optional[str]* | :heavy_minus_sign: | Destination to send results to | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputconfluentcloud.md b/docs/models/inputresponseinputconfluentcloud.md index 90f993fbb..da8cb7e0c 100644 --- a/docs/models/inputresponseinputconfluentcloud.md +++ b/docs/models/inputresponseinputconfluentcloud.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `brokers` | List[*str*] | :heavy_check_mark: | List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092 | @@ -40,11 +40,12 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_brokers` | *Optional[str]* | :heavy_minus_sign: | Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime. | | `template_topics` | *Optional[str]* | :heavy_minus_sign: | Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime. | | `template_group_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputcribl.md b/docs/models/inputresponseinputcribl.md index 1f9916fd4..cff696031 100644 --- a/docs/models/inputresponseinputcribl.md +++ b/docs/models/inputresponseinputcribl.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `filter_` | *Optional[str]* | :heavy_minus_sign: | N/A | @@ -21,5 +21,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputcriblhttp.md b/docs/models/inputresponseinputcriblhttp.md index 70a9f5b91..ca3f25dd7 100644 --- a/docs/models/inputresponseinputcriblhttp.md +++ b/docs/models/inputresponseinputcriblhttp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -38,5 +38,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputcribllakehttp.md b/docs/models/inputresponseinputcribllakehttp.md index 0f4dd73cc..98eacfdbc 100644 --- a/docs/models/inputresponseinputcribllakehttp.md +++ b/docs/models/inputresponseinputcribllakehttp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -37,7 +37,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.InputResponseAuthTokensExt](../models/inputresponseauthtokensext.md)] | :heavy_minus_sign: | Auth tokens | +| `auth_tokens_ext` | List[[models.InputResponseInputCriblLakeHTTPAuthTokensExt](../models/inputresponseinputcribllakehttpauthtokensext.md)] | :heavy_minus_sign: | Auth tokens | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | @@ -47,5 +47,5 @@ | `template_cribl_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime. | | `template_elastic_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime. | | `template_splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputcribllakehttpauthtokensext.md b/docs/models/inputresponseinputcribllakehttpauthtokensext.md new file mode 100644 index 000000000..7addbd85b --- /dev/null +++ b/docs/models/inputresponseinputcribllakehttpauthtokensext.md @@ -0,0 +1,17 @@ +# InputResponseInputCriblLakeHTTPAuthTokensExt + + +## Supported Types + +### `models.InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/inputresponseinputcribllakehttpinputhttpauthtokensextitemstype.md b/docs/models/inputresponseinputcribllakehttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..ed64c246a --- /dev/null +++ b/docs/models/inputresponseinputcribllakehttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,14 @@ +# InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `token` | *str* | :heavy_check_mark: | Token | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata]](../models/inputresponseinputhttpauthtokensextitemstypesplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata]](../models/inputresponseinputhttpauthtokensextitemstypeelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseinputcribllakehttpinputhttpauthtypesecretconstraint.md b/docs/models/inputresponseinputcribllakehttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..67567de2c --- /dev/null +++ b/docs/models/inputresponseinputcribllakehttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,14 @@ +# InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Token | +| `description` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | +| `splunk_hec_metadata` | [Optional[models.InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata]](../models/inputresponseinputhttpauthtypesecretconstraintsplunkhecmetadata.md) | :heavy_minus_sign: | N/A | +| `elasticsearch_metadata` | [Optional[models.InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata]](../models/inputresponseinputhttpauthtypesecretconstraintelasticsearchmetadata.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseinputcriblmetrics.md b/docs/models/inputresponseinputcriblmetrics.md index 3c0cf863e..370827b86 100644 --- a/docs/models/inputresponseinputcriblmetrics.md +++ b/docs/models/inputresponseinputcriblmetrics.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `prefix` | *Optional[str]* | :heavy_minus_sign: | A prefix that is applied to the metrics provided by Cribl Stream | @@ -22,5 +22,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputcribltcp.md b/docs/models/inputresponseinputcribltcp.md index c5fb5842c..0e032444a 100644 --- a/docs/models/inputresponseinputcribltcp.md +++ b/docs/models/inputresponseinputcribltcp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -32,5 +32,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputcrowdstrike.md b/docs/models/inputresponseinputcrowdstrike.md index 44d7e5d7c..c389ba68b 100644 --- a/docs/models/inputresponseinputcrowdstrike.md +++ b/docs/models/inputresponseinputcrowdstrike.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `queue_name` | *str* | :heavy_check_mark: | The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`. | @@ -70,5 +70,5 @@ | `template_sqs_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime. | | `template_sqs_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime. | | `template_sqs_aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputdatadogagent.md b/docs/models/inputresponseinputdatadogagent.md index c1f0d8529..abf7c7932 100644 --- a/docs/models/inputresponseinputdatadogagent.md +++ b/docs/models/inputresponseinputdatadogagent.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -41,5 +41,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputdatagen.md b/docs/models/inputresponseinputdatagen.md index ab8a772ed..cb26adbe8 100644 --- a/docs/models/inputresponseinputdatagen.md +++ b/docs/models/inputresponseinputdatagen.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `samples` | List[[models.InputResponseSample](../models/inputresponsesample.md)] | :heavy_check_mark: | Datagens | @@ -21,5 +21,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputedgeprometheus.md b/docs/models/inputresponseinputedgeprometheus.md index 9848d7a79..ff9caebf1 100644 --- a/docs/models/inputresponseinputedgeprometheus.md +++ b/docs/models/inputresponseinputedgeprometheus.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `dimension_list` | List[*str*] | :heavy_minus_sign: | Other dimensions to include in events | @@ -67,5 +67,5 @@ | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime. | | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputelastic.md b/docs/models/inputresponseinputelastic.md index 86cbafb9c..9b8412c10 100644 --- a/docs/models/inputresponseinputelastic.md +++ b/docs/models/inputresponseinputelastic.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -49,5 +49,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_elastic_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime. | | `template_auth_tokens` | *Optional[str]* | :heavy_minus_sign: | Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputeventhub.md b/docs/models/inputresponseinputeventhub.md index 4cc44cb11..af7dbec0e 100644 --- a/docs/models/inputresponseinputeventhub.md +++ b/docs/models/inputresponseinputeventhub.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `brokers` | List[*str*] | :heavy_check_mark: | List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies. | @@ -40,11 +40,12 @@ | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `minimize_duplicates` | *Optional[bool]* | :heavy_minus_sign: | Minimize duplicate events by starting only one consumer for each topic partition | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_brokers` | *Optional[str]* | :heavy_minus_sign: | Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime. | | `template_topics` | *Optional[str]* | :heavy_minus_sign: | Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime. | | `template_group_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputeventhubamqp.md b/docs/models/inputresponseinputeventhubamqp.md index 15fe6418a..3828775c3 100644 --- a/docs/models/inputresponseinputeventhubamqp.md +++ b/docs/models/inputresponseinputeventhubamqp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `event_hub_name` | *Optional[str]* | :heavy_minus_sign: | The name of the Event Hub to consume from | @@ -32,8 +32,9 @@ | `connection_max_backoff` | *Optional[int]* | :heavy_minus_sign: | Maximum delay between reconnection attempts, in milliseconds | | `connection_timeout_in_ms` | *Optional[int]* | :heavy_minus_sign: | Maximum time to wait for a connection to complete | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputexec.md b/docs/models/inputresponseinputexec.md index e64ddc2a6..78577fc6f 100644 --- a/docs/models/inputresponseinputexec.md +++ b/docs/models/inputresponseinputexec.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `command` | *str* | :heavy_check_mark: | Command to execute; supports Bourne shell (or CMD on Windows) syntax | @@ -23,10 +23,11 @@ | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `interval` | *Optional[float]* | :heavy_minus_sign: | Interval between command executions in seconds. | | `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule to execute the command on. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputextrahoprevealx360.md b/docs/models/inputresponseinputextrahoprevealx360.md new file mode 100644 index 000000000..9457ff133 --- /dev/null +++ b/docs/models/inputresponseinputextrahoprevealx360.md @@ -0,0 +1,50 @@ +# InputResponseInputExtrahopRevealx360 + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputExtrahopRevealx360Type](../models/inputresponseinputextrahoprevealx360type.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputextrahoprevealx360type.md b/docs/models/inputresponseinputextrahoprevealx360type.md new file mode 100644 index 000000000..360c87de5 --- /dev/null +++ b/docs/models/inputresponseinputextrahoprevealx360type.md @@ -0,0 +1,18 @@ +# InputResponseInputExtrahopRevealx360Type + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputExtrahopRevealx360Type + +value = InputResponseInputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360 +``` + + +## Values + +| Name | Value | +| ---------------------- | ---------------------- | +| `EXTRAHOP_REVEALX_360` | extrahop_revealx_360 | \ No newline at end of file diff --git a/docs/models/inputresponseinputf5bigip.md b/docs/models/inputresponseinputf5bigip.md new file mode 100644 index 000000000..168830667 --- /dev/null +++ b/docs/models/inputresponseinputf5bigip.md @@ -0,0 +1,51 @@ +# InputResponseInputF5BigIP + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputF5BigIPType](../models/inputresponseinputf5bigiptype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Whether to enable HEC indexer acknowledgements | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputf5bigiptype.md b/docs/models/inputresponseinputf5bigiptype.md new file mode 100644 index 000000000..729b9bb24 --- /dev/null +++ b/docs/models/inputresponseinputf5bigiptype.md @@ -0,0 +1,18 @@ +# InputResponseInputF5BigIPType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputF5BigIPType + +value = InputResponseInputF5BigIPType.F5_BIG_IP +``` + + +## Values + +| Name | Value | +| ----------- | ----------- | +| `F5_BIG_IP` | f5_big_ip | \ No newline at end of file diff --git a/docs/models/inputresponseinputfile.md b/docs/models/inputresponseinputfile.md index 8d4a4a76a..e32a7f520 100644 --- a/docs/models/inputresponseinputfile.md +++ b/docs/models/inputresponseinputfile.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `mode` | [Optional[models.InputResponseInputFileMode]](../models/inputresponseinputfilemode.md) | :heavy_minus_sign: | Choose how to discover files to monitor | @@ -27,10 +27,12 @@ | `check_file_mod_time` | *Optional[bool]* | :heavy_minus_sign: | Skip files with modification times earlier than the maximum age duration | | `force_text` | *Optional[bool]* | :heavy_minus_sign: | Forces files containing binary data to be streamed as text | | `hash_len` | *Optional[float]* | :heavy_minus_sign: | Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files. | +| `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `disable_stale_channel_flush` | *Optional[bool]* | :heavy_minus_sign: | When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS. | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `path` | *Optional[str]* | :heavy_minus_sign: | Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/). | | `depth` | *Optional[float]* | :heavy_minus_sign: | Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth. | @@ -38,8 +40,10 @@ | `delete_files` | *Optional[bool]* | :heavy_minus_sign: | Delete files after they have been collected | | `salt_hash` | *Optional[bool]* | :heavy_minus_sign: | Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion. | | `optimize_leaf_directories` | *Optional[bool]* | :heavy_minus_sign: | Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories. | +| `enable_discovery_throttle` | *Optional[bool]* | :heavy_minus_sign: | When enabled, discovery will throttle CPU usage to the configured target percentage. | +| `discovery_throttle_cpu_percent` | *Optional[float]* | :heavy_minus_sign: | Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times. | | `include_unidentifiable_binary` | *Optional[bool]* | :heavy_minus_sign: | Stream binary files as Base64-encoded chunks | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputfirehose.md b/docs/models/inputresponseinputfirehose.md index 06d491e3b..836840f20 100644 --- a/docs/models/inputresponseinputfirehose.md +++ b/docs/models/inputresponseinputfirehose.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -39,5 +39,5 @@ | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_auth_tokens` | *Optional[str]* | :heavy_minus_sign: | Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputgigamonhec.md b/docs/models/inputresponseinputgigamonhec.md new file mode 100644 index 000000000..11142dc64 --- /dev/null +++ b/docs/models/inputresponseinputgigamonhec.md @@ -0,0 +1,50 @@ +# InputResponseInputGigamonHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputGigamonHecType](../models/inputresponseinputgigamonhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputgigamonhectype.md b/docs/models/inputresponseinputgigamonhectype.md new file mode 100644 index 000000000..5a02515b2 --- /dev/null +++ b/docs/models/inputresponseinputgigamonhectype.md @@ -0,0 +1,18 @@ +# InputResponseInputGigamonHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputGigamonHecType + +value = InputResponseInputGigamonHecType.GIGAMON_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `GIGAMON_HEC` | gigamon_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputgooglepubsub.md b/docs/models/inputresponseinputgooglepubsub.md index 7346b2a89..ed235f457 100644 --- a/docs/models/inputresponseinputgooglepubsub.md +++ b/docs/models/inputresponseinputgooglepubsub.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `topic_name` | *str* | :heavy_check_mark: | ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered. | @@ -29,6 +29,7 @@ | `concurrency` | *Optional[float]* | :heavy_minus_sign: | How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5. | | `request_timeout` | *Optional[float]* | :heavy_minus_sign: | Pull request timeout, in milliseconds | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `ordered_delivery` | *Optional[bool]* | :heavy_minus_sign: | Receive events in the order they were added to the queue. The process sending events must have ordering enabled. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | @@ -36,5 +37,5 @@ | `template_topic_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime. | | `template_subscription_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime. | | `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputgrafanagrafana1.md b/docs/models/inputresponseinputgrafanagrafana1.md index ff814c266..5f3659345 100644 --- a/docs/models/inputresponseinputgrafanagrafana1.md +++ b/docs/models/inputresponseinputgrafanagrafana1.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -43,5 +43,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_prometheus_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime. | | `template_loki_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputgrafanagrafana2.md b/docs/models/inputresponseinputgrafanagrafana2.md index fc2c1b06c..a381a7fa5 100644 --- a/docs/models/inputresponseinputgrafanagrafana2.md +++ b/docs/models/inputresponseinputgrafanagrafana2.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -43,5 +43,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_prometheus_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime. | | `template_loki_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputhashicorphcpvaultdedicated.md b/docs/models/inputresponseinputhashicorphcpvaultdedicated.md new file mode 100644 index 000000000..1b4228c7c --- /dev/null +++ b/docs/models/inputresponseinputhashicorphcpvaultdedicated.md @@ -0,0 +1,50 @@ +# InputResponseInputHashicorpHcpVaultDedicated + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputHashicorpHcpVaultDedicatedType](../models/inputresponseinputhashicorphcpvaultdedicatedtype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputhashicorphcpvaultdedicatedtype.md b/docs/models/inputresponseinputhashicorphcpvaultdedicatedtype.md new file mode 100644 index 000000000..54997a0a3 --- /dev/null +++ b/docs/models/inputresponseinputhashicorphcpvaultdedicatedtype.md @@ -0,0 +1,18 @@ +# InputResponseInputHashicorpHcpVaultDedicatedType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputHashicorpHcpVaultDedicatedType + +value = InputResponseInputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED +``` + + +## Values + +| Name | Value | +| ------------------------------- | ------------------------------- | +| `HASHICORP_HCP_VAULT_DEDICATED` | hashicorp_hcp_vault_dedicated | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttp.md b/docs/models/inputresponseinputhttp.md index 90937d83f..6831644f4 100644 --- a/docs/models/inputresponseinputhttp.md +++ b/docs/models/inputresponseinputhttp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -37,7 +37,7 @@ | `splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable. | | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.InputResponseInputHTTPAuthTokensExt](../models/inputresponseinputhttpauthtokensext.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | @@ -47,5 +47,5 @@ | `template_cribl_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime. | | `template_elastic_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime. | | `template_splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttpauthtokensext.md b/docs/models/inputresponseinputhttpauthtokensext.md new file mode 100644 index 000000000..6bc1cf96d --- /dev/null +++ b/docs/models/inputresponseinputhttpauthtokensext.md @@ -0,0 +1,17 @@ +# InputResponseInputHTTPAuthTokensExt + + +## Supported Types + +### `models.InputResponseInputHTTPInputHTTPAuthTokensExtItemsType` + +```python +value: models.InputResponseInputHTTPInputHTTPAuthTokensExtItemsType = /* values here */ +``` + +### `models.InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint` + +```python +value: models.InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/inputresponseinputhttpauthtokensextitemstypeelasticsearchmetadata.md b/docs/models/inputresponseinputhttpauthtokensextitemstypeelasticsearchmetadata.md new file mode 100644 index 000000000..cb266f5bf --- /dev/null +++ b/docs/models/inputresponseinputhttpauthtokensextitemstypeelasticsearchmetadata.md @@ -0,0 +1,9 @@ +# InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Elasticsearch | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttpauthtokensextitemstypesplunkhecmetadata.md b/docs/models/inputresponseinputhttpauthtokensextitemstypesplunkhecmetadata.md new file mode 100644 index 000000000..5a69d15d4 --- /dev/null +++ b/docs/models/inputresponseinputhttpauthtokensextitemstypesplunkhecmetadata.md @@ -0,0 +1,10 @@ +# InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | When enabled, the token value is available on events as __hecToken | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `allowed_indexes_at_token` | List[*str*] | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttpauthtypesecretconstraintelasticsearchmetadata.md b/docs/models/inputresponseinputhttpauthtypesecretconstraintelasticsearchmetadata.md new file mode 100644 index 000000000..50927d45e --- /dev/null +++ b/docs/models/inputresponseinputhttpauthtypesecretconstraintelasticsearchmetadata.md @@ -0,0 +1,9 @@ +# InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------ | ------------------ | ------------------ | ------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Elasticsearch | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttpauthtypesecretconstraintsplunkhecmetadata.md b/docs/models/inputresponseinputhttpauthtypesecretconstraintsplunkhecmetadata.md new file mode 100644 index 000000000..37059f943 --- /dev/null +++ b/docs/models/inputresponseinputhttpauthtypesecretconstraintsplunkhecmetadata.md @@ -0,0 +1,10 @@ +# InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | ------------------------------------------------------------------ | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | When enabled, the token value is available on events as __hecToken | +| `default_dataset` | *Optional[str]* | :heavy_minus_sign: | N/A | +| `allowed_indexes_at_token` | List[*str*] | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttpinputhttpauthtokensextitemstype.md b/docs/models/inputresponseinputhttpinputhttpauthtokensextitemstype.md new file mode 100644 index 000000000..14d2ac2f4 --- /dev/null +++ b/docs/models/inputresponseinputhttpinputhttpauthtokensextitemstype.md @@ -0,0 +1,12 @@ +# InputResponseInputHTTPInputHTTPAuthTokensExtItemsType + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttpinputhttpauthtypesecretconstraint.md b/docs/models/inputresponseinputhttpinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..6b0c73ee0 --- /dev/null +++ b/docs/models/inputresponseinputhttpinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttpraw.md b/docs/models/inputresponseinputhttpraw.md index 85c0bf9f9..0840fe813 100644 --- a/docs/models/inputresponseinputhttpraw.md +++ b/docs/models/inputresponseinputhttpraw.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -34,10 +34,11 @@ | `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.InputResponseInputHTTPRawAuthTokensExtUnion](../models/inputresponseinputhttprawauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS. | | `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use "*" to allow all headers. | | `access_control_allow_methods` | List[*str*] | :heavy_minus_sign: | HTTP methods echoed in Access-Control-Allow-Methods on preflight. | @@ -53,5 +54,5 @@ | `template_allowed_paths` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime. | | `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | | `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttprawauthtokensext.md b/docs/models/inputresponseinputhttprawauthtokensext.md new file mode 100644 index 000000000..ed6aa3c65 --- /dev/null +++ b/docs/models/inputresponseinputhttprawauthtokensext.md @@ -0,0 +1,12 @@ +# InputResponseInputHTTPRawAuthTokensExt + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputresponseinputhttprawauthtokensextunion.md b/docs/models/inputresponseinputhttprawauthtokensextunion.md new file mode 100644 index 000000000..bda89f2f0 --- /dev/null +++ b/docs/models/inputresponseinputhttprawauthtokensextunion.md @@ -0,0 +1,17 @@ +# InputResponseInputHTTPRawAuthTokensExtUnion + + +## Supported Types + +### `models.InputResponseInputHTTPRawAuthTokensExt` + +```python +value: models.InputResponseInputHTTPRawAuthTokensExt = /* values here */ +``` + +### `models.InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint` + +```python +value: models.InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint = /* values here */ +``` + diff --git a/docs/models/inputresponseinputhttprawinputhttpauthtypesecretconstraint.md b/docs/models/inputresponseinputhttprawinputhttpauthtypesecretconstraint.md new file mode 100644 index 000000000..e99dabb68 --- /dev/null +++ b/docs/models/inputresponseinputhttprawinputhttpauthtypesecretconstraint.md @@ -0,0 +1,12 @@ +# InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputresponseinputjournalfiles.md b/docs/models/inputresponseinputjournalfiles.md index ee1034dc9..fce793605 100644 --- a/docs/models/inputresponseinputjournalfiles.md +++ b/docs/models/inputresponseinputjournalfiles.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `path` | *str* | :heavy_check_mark: | Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID. | @@ -24,8 +24,9 @@ | `max_age_dur` | *Optional[str]* | :heavy_minus_sign: | The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters. | | `suppress_missing_path_errors` | *Optional[bool]* | :heavy_minus_sign: | Suppress errors when search path does not exist | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputkafka.md b/docs/models/inputresponseinputkafka.md index d41418fd3..73269bcd5 100644 --- a/docs/models/inputresponseinputkafka.md +++ b/docs/models/inputresponseinputkafka.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `brokers` | List[*str*] | :heavy_check_mark: | Enter each Kafka bootstrap server you want to use. Specify the hostname and port (such as mykafkabroker:9092) or just the hostname (in which case @{product} will assign port 9092). | @@ -40,11 +40,12 @@ | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_brokers` | *Optional[str]* | :heavy_minus_sign: | Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime. | | `template_topics` | *Optional[str]* | :heavy_minus_sign: | Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime. | | `template_group_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputkinesis.md b/docs/models/inputresponseinputkinesis.md index f77c6b117..82bf04713 100644 --- a/docs/models/inputresponseinputkinesis.md +++ b/docs/models/inputresponseinputkinesis.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `stream_name` | *str* | :heavy_check_mark: | Kinesis Data Stream to read data from | @@ -37,6 +37,7 @@ | `verify_kpl_check_sums` | *Optional[bool]* | :heavy_minus_sign: | Verify Kinesis Producer Library (KPL) event checksums | | `avoid_duplicates` | *Optional[bool]* | :heavy_minus_sign: | When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | @@ -51,5 +52,5 @@ | `template_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime. | | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputkubeevents.md b/docs/models/inputresponseinputkubeevents.md index bf522b126..a088280a6 100644 --- a/docs/models/inputresponseinputkubeevents.md +++ b/docs/models/inputresponseinputkubeevents.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `rules` | List[[models.RuleConfInputKubeMetrics](../models/ruleconfinputkubemetrics.md)] | :heavy_minus_sign: | Filtering on event fields | @@ -21,5 +21,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputkubelogs.md b/docs/models/inputresponseinputkubelogs.md index 2fc18b20f..c50caf9ed 100644 --- a/docs/models/inputresponseinputkubelogs.md +++ b/docs/models/inputresponseinputkubelogs.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `interval` | *Optional[float]* | :heavy_minus_sign: | Time, in seconds, between checks for new containers. Default is 15 secs. | @@ -29,5 +29,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputkubemetrics.md b/docs/models/inputresponseinputkubemetrics.md index 300a06c08..ce5ce6b2c 100644 --- a/docs/models/inputresponseinputkubemetrics.md +++ b/docs/models/inputresponseinputkubemetrics.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `interval` | *Optional[float]* | :heavy_minus_sign: | Time, in seconds, between consecutive metrics collections. Default is 15 secs. | @@ -25,5 +25,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputloki.md b/docs/models/inputresponseinputloki.md index c942381bf..72b353319 100644 --- a/docs/models/inputresponseinputloki.md +++ b/docs/models/inputresponseinputloki.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -45,5 +45,5 @@ | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_loki_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputmetrics.md b/docs/models/inputresponseinputmetrics.md index 395bc3f55..6b49c7ef6 100644 --- a/docs/models/inputresponseinputmetrics.md +++ b/docs/models/inputresponseinputmetrics.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address. | @@ -31,5 +31,5 @@ | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_udp_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime. | | `template_tcp_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputmicrosoftcopilot.md b/docs/models/inputresponseinputmicrosoftcopilot.md new file mode 100644 index 000000000..626fa0bc6 --- /dev/null +++ b/docs/models/inputresponseinputmicrosoftcopilot.md @@ -0,0 +1,51 @@ +# InputResponseInputMicrosoftCopilot + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputMicrosoftCopilotType](../models/inputresponseinputmicrosoftcopilottype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `tenant_id` | *str* | :heavy_check_mark: | Directory (tenant) ID from Azure Active Directory | +| `client_id` | *str* | :heavy_check_mark: | Application (client) ID from the app registration | +| `resource` | *Optional[str]* | :heavy_minus_sign: | Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type. | +| `auth_type` | [Optional[models.InputResponseInputMicrosoftCopilotAuthenticationMethod]](../models/inputresponseinputmicrosoftcopilotauthenticationmethod.md) | :heavy_minus_sign: | Select authentication method. | +| `plan_type` | [Optional[models.InputResponseInputMicrosoftCopilotSubscriptionPlan]](../models/inputresponseinputmicrosoftcopilotsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Cron schedule for collection runs | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now. Used as the initial lower bound on first run. | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `page_size` | *Optional[int]* | :heavy_minus_sign: | Number of interactions to request per page ($top). Maximum 1000. | +| `app_class_filter` | List[*str*] | :heavy_minus_sign: | Limit collection to specific Copilot app classes. Leave empty to collect all. | +| `filter_by_license` | *Optional[bool]* | :heavy_minus_sign: | Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time. | +| `sku_ids` | List[*str*] | :heavy_minus_sign: | Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans. | +| `manage_state` | [Optional[models.InputResponseInputMicrosoftCopilotManageState]](../models/inputresponseinputmicrosoftcopilotmanagestate.md) | :heavy_minus_sign: | N/A | +| `timeout` | *Optional[float]* | :heavy_minus_sign: | HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely. | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often workers should check in with the scheduler to keep job subscription alive | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked. | +| `ttl` | *Optional[str]* | :heavy_minus_sign: | Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector. | +| `ignore_group_jobs_limit` | *Optional[bool]* | :heavy_minus_sign: | When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `retry_rules` | [Optional[models.InputResponseRetryRules]](../models/inputresponseretryrules.md) | :heavy_minus_sign: | N/A | +| `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | +| `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references the client secret from your app registration | +| `cert_options` | [Optional[models.InputResponseCertOptions]](../models/inputresponsecertoptions.md) | :heavy_minus_sign: | N/A | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | +| `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | +| `template_plan_type` | *Optional[str]* | :heavy_minus_sign: | Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputmicrosoftcopilotauthenticationmethod.md b/docs/models/inputresponseinputmicrosoftcopilotauthenticationmethod.md new file mode 100644 index 000000000..5034c4175 --- /dev/null +++ b/docs/models/inputresponseinputmicrosoftcopilotauthenticationmethod.md @@ -0,0 +1,21 @@ +# InputResponseInputMicrosoftCopilotAuthenticationMethod + +Select authentication method. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputMicrosoftCopilotAuthenticationMethod + +value = InputResponseInputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `OAUTH_SECRET` | oauthSecret | +| `OAUTH_CERT` | oauthCert | \ No newline at end of file diff --git a/docs/models/inputresponseinputmicrosoftcopilotmanagestate.md b/docs/models/inputresponseinputmicrosoftcopilotmanagestate.md new file mode 100644 index 000000000..ee9cdb0f2 --- /dev/null +++ b/docs/models/inputresponseinputmicrosoftcopilotmanagestate.md @@ -0,0 +1,7 @@ +# InputResponseInputMicrosoftCopilotManageState + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/inputresponseinputmicrosoftcopilotsubscriptionplan.md b/docs/models/inputresponseinputmicrosoftcopilotsubscriptionplan.md new file mode 100644 index 000000000..0528aec46 --- /dev/null +++ b/docs/models/inputresponseinputmicrosoftcopilotsubscriptionplan.md @@ -0,0 +1,23 @@ +# InputResponseInputMicrosoftCopilotSubscriptionPlan + +Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputMicrosoftCopilotSubscriptionPlan + +value = InputResponseInputMicrosoftCopilotSubscriptionPlan.ENTERPRISE_GCC + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `ENTERPRISE_GCC` | enterprise_gcc | +| `GCC` | gcc | +| `GCC_HIGH` | gcc_high | +| `DOD` | dod | \ No newline at end of file diff --git a/docs/models/inputresponseinputmicrosoftcopilottype.md b/docs/models/inputresponseinputmicrosoftcopilottype.md new file mode 100644 index 000000000..edf4352d4 --- /dev/null +++ b/docs/models/inputresponseinputmicrosoftcopilottype.md @@ -0,0 +1,18 @@ +# InputResponseInputMicrosoftCopilotType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputMicrosoftCopilotType + +value = InputResponseInputMicrosoftCopilotType.MICROSOFT_COPILOT +``` + + +## Values + +| Name | Value | +| ------------------- | ------------------- | +| `MICROSOFT_COPILOT` | microsoft_copilot | \ No newline at end of file diff --git a/docs/models/inputresponseinputmicrosoftgraph.md b/docs/models/inputresponseinputmicrosoftgraph.md index b9a9fd9d1..8231e72e1 100644 --- a/docs/models/inputresponseinputmicrosoftgraph.md +++ b/docs/models/inputresponseinputmicrosoftgraph.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `url` | *str* | :heavy_check_mark: | Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces) | @@ -41,7 +41,7 @@ | `tenant_id` | *Optional[str]* | :heavy_minus_sign: | Directory ID (tenant identifier) in Azure Active Directory. | | `client_id` | *Optional[str]* | :heavy_minus_sign: | client_id to pass in the OAuth request parameter. | | `resource` | *Optional[str]* | :heavy_minus_sign: | Resource to pass in the OAuth request parameter. | -| `plan_type` | [Optional[models.InputResponseSubscriptionPlan]](../models/inputresponsesubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | +| `plan_type` | [Optional[models.InputResponseInputMicrosoftGraphSubscriptionPlan]](../models/inputresponseinputmicrosoftgraphsubscriptionplan.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your client_secret to pass in the OAuth request parameter. | | `cert_options` | [Optional[models.CertOptionsType]](../models/certoptionstype.md) | :heavy_minus_sign: | N/A | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | @@ -51,5 +51,5 @@ | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | | `template_resource` | *Optional[str]* | :heavy_minus_sign: | Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime. | | `template_plan_type` | *Optional[str]* | :heavy_minus_sign: | Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/createinputsystembypacksubscriptionplan.md b/docs/models/inputresponseinputmicrosoftgraphsubscriptionplan.md similarity index 69% rename from docs/models/createinputsystembypacksubscriptionplan.md rename to docs/models/inputresponseinputmicrosoftgraphsubscriptionplan.md index 28fbb13f1..0fc06091d 100644 --- a/docs/models/createinputsystembypacksubscriptionplan.md +++ b/docs/models/inputresponseinputmicrosoftgraphsubscriptionplan.md @@ -1,13 +1,13 @@ -# CreateInputSystemByPackSubscriptionPlan +# InputResponseInputMicrosoftGraphSubscriptionPlan Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise ## Example Usage ```python -from cribl_control_plane.models import CreateInputSystemByPackSubscriptionPlan +from cribl_control_plane.models import InputResponseInputMicrosoftGraphSubscriptionPlan -value = CreateInputSystemByPackSubscriptionPlan.ENTERPRISE_GCC +value = InputResponseInputMicrosoftGraphSubscriptionPlan.ENTERPRISE_GCC # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/inputresponseinputmimecasthec.md b/docs/models/inputresponseinputmimecasthec.md new file mode 100644 index 000000000..b7e61b234 --- /dev/null +++ b/docs/models/inputresponseinputmimecasthec.md @@ -0,0 +1,50 @@ +# InputResponseInputMimecastHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputMimecastHecType](../models/inputresponseinputmimecasthectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputmimecasthectype.md b/docs/models/inputresponseinputmimecasthectype.md new file mode 100644 index 000000000..3c34db090 --- /dev/null +++ b/docs/models/inputresponseinputmimecasthectype.md @@ -0,0 +1,18 @@ +# InputResponseInputMimecastHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputMimecastHecType + +value = InputResponseInputMimecastHecType.MIMECAST_HEC +``` + + +## Values + +| Name | Value | +| -------------- | -------------- | +| `MIMECAST_HEC` | mimecast_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputmodeldriventelemetry.md b/docs/models/inputresponseinputmodeldriventelemetry.md index d82a42141..576baefae 100644 --- a/docs/models/inputresponseinputmodeldriventelemetry.md +++ b/docs/models/inputresponseinputmodeldriventelemetry.md @@ -3,29 +3,31 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | -| `type` | [models.InputResponseInputModelDrivenTelemetryType](../models/inputresponseinputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | -| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | -| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | -| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | -| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | -| `port` | *float* | :heavy_check_mark: | Port to listen on | -| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | -| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | -| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | -| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputModelDrivenTelemetryType](../models/inputresponseinputmodeldriventelemetrytype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each. | +| `shutdown_timeout_ms` | *Optional[float]* | :heavy_minus_sign: | Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputmsk.md b/docs/models/inputresponseinputmsk.md index 96a78ec2e..729ccb868 100644 --- a/docs/models/inputresponseinputmsk.md +++ b/docs/models/inputresponseinputmsk.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `brokers` | List[*str*] | :heavy_check_mark: | Enter each Kafka bootstrap server you want to use. Specify the hostname and port (such as mykafkabroker:9092) or just the hostname (in which case @{product} will assign port 9092). | @@ -49,6 +49,7 @@ | `max_bytes_per_partition` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB). | | `max_bytes` | *Optional[float]* | :heavy_minus_sign: | Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB). | | `max_socket_errors` | *Optional[float]* | :heavy_minus_sign: | Maximum number of network errors before the consumer re-creates a socket | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | @@ -63,5 +64,5 @@ | `template_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime. | | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputnetflow.md b/docs/models/inputresponseinputnetflow.md index c72161e97..5951532cf 100644 --- a/docs/models/inputresponseinputnetflow.md +++ b/docs/models/inputresponseinputnetflow.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address. | @@ -32,5 +32,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputoffice365mgmt.md b/docs/models/inputresponseinputoffice365mgmt.md index e27b998ed..2cbfdb1b9 100644 --- a/docs/models/inputresponseinputoffice365mgmt.md +++ b/docs/models/inputresponseinputoffice365mgmt.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `plan_type` | [models.SubscriptionPlanOptions](../models/subscriptionplanoptions.md) | :heavy_check_mark: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | @@ -41,5 +41,5 @@ | `template_app_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime. | | `template_publisher_identifier` | *Optional[str]* | :heavy_minus_sign: | Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime. | | `template_client_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputoffice365msgtrace.md b/docs/models/inputresponseinputoffice365msgtrace.md index 655219070..e83b9bc34 100644 --- a/docs/models/inputresponseinputoffice365msgtrace.md +++ b/docs/models/inputresponseinputoffice365msgtrace.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `url` | *str* | :heavy_check_mark: | URL to use when retrieving report data. | @@ -51,5 +51,5 @@ | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | | `template_resource` | *Optional[str]* | :heavy_minus_sign: | Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime. | | `template_plan_type` | *Optional[str]* | :heavy_minus_sign: | Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputoffice365service.md b/docs/models/inputresponseinputoffice365service.md index 16508743e..3c27c9506 100644 --- a/docs/models/inputresponseinputoffice365service.md +++ b/docs/models/inputresponseinputoffice365service.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `plan_type` | [Optional[models.SubscriptionPlanOptions]](../models/subscriptionplanoptions.md) | :heavy_minus_sign: | Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise | @@ -38,5 +38,5 @@ | `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | | `template_app_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime. | | `template_client_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputokta.md b/docs/models/inputresponseinputokta.md index d8fbbc048..8da0e27d7 100644 --- a/docs/models/inputresponseinputokta.md +++ b/docs/models/inputresponseinputokta.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `okta_domain` | *str* | :heavy_check_mark: | Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes. | @@ -35,5 +35,5 @@ | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_okta_domain` | *Optional[str]* | :heavy_minus_sign: | Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputopenai.md b/docs/models/inputresponseinputopenai.md index e7b594059..2c889f6b8 100644 --- a/docs/models/inputresponseinputopenai.md +++ b/docs/models/inputresponseinputopenai.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `openai_organization` | *Optional[str]* | :heavy_minus_sign: | Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx` | @@ -33,5 +33,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_openai_organization` | *Optional[str]* | :heavy_minus_sign: | Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime. | | `template_openai_project` | *Optional[str]* | :heavy_minus_sign: | Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputopenaicompliancelogs.md b/docs/models/inputresponseinputopenaicompliancelogs.md index 0adeab337..60e6e5306 100644 --- a/docs/models/inputresponseinputopenaicompliancelogs.md +++ b/docs/models/inputresponseinputopenaicompliancelogs.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `api_key` | *Optional[str]* | :heavy_minus_sign: | API key | @@ -47,5 +47,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_workspace_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime. | | `template_organization_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputopenaicontentconfig.md b/docs/models/inputresponseinputopenaicontentconfig.md index dec00373b..dc4c9381c 100644 --- a/docs/models/inputresponseinputopenaicontentconfig.md +++ b/docs/models/inputresponseinputopenaicontentconfig.md @@ -3,27 +3,27 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | -| `content_type` | *str* | :heavy_check_mark: | Content type | -| `content_description` | *Optional[str]* | :heavy_minus_sign: | Description | -| `collect_path` | *str* | :heavy_check_mark: | OpenAI Organization API path | -| `docs_url` | *Optional[str]* | :heavy_minus_sign: | Docs URL | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.InputResponseInputOpenaiManageState]](../models/inputresponseinputopenaimanagestate.md) | :heavy_minus_sign: | N/A | -| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | -| `pagination_type` | [models.InputResponsePaginationType](../models/inputresponsepaginationtype.md) | :heavy_check_mark: | Pagination type | -| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | -| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | -| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | -| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | -| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | -| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | -| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | -| `latest` | *str* | :heavy_check_mark: | Relative to the current time | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `log_level` | [Optional[models.InputResponseInputOpenaiLogLevel]](../models/inputresponseinputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | -| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `content_type` | *str* | :heavy_check_mark: | Content type | +| `content_description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `collect_path` | *str* | :heavy_check_mark: | OpenAI Organization API path | +| `docs_url` | *Optional[str]* | :heavy_minus_sign: | Docs URL | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions. | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.InputResponseInputOpenaiManageState]](../models/inputresponseinputopenaimanagestate.md) | :heavy_minus_sign: | N/A | +| `request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_check_mark: | Query-string parameters to send with this endpoint | +| `pagination_type` | [models.InputResponsePaginationType](../models/inputresponsepaginationtype.md) | :heavy_check_mark: | Pagination type | +| `pagination_attribute` | List[*str*] | :heavy_minus_sign: | Pagination attributes | +| `pagination_last_page_expr` | *Optional[str]* | :heavy_minus_sign: | Last page expression | +| `max_pages` | *Optional[float]* | :heavy_minus_sign: | Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required. | +| `pagination_next_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Used only for RFC 5988 link-header pagination | +| `pagination_cur_relation_attribute` | *Optional[str]* | :heavy_minus_sign: | Optional relation that represents the current page | +| `cron_schedule` | *str* | :heavy_check_mark: | A cron schedule on which to run this job | +| `earliest` | *str* | :heavy_check_mark: | Relative to the current time | +| `latest` | *str* | :heavy_check_mark: | Relative to the current time | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `log_level` | [Optional[models.InputResponseInputOpenaiLogLevel]](../models/inputresponseinputopenailoglevel.md) | :heavy_minus_sign: | Collector runtime log level. | +| `endpoint_metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields automatically added to events from this Content Type | \ No newline at end of file diff --git a/docs/models/inputresponseinputopentelemetry.md b/docs/models/inputresponseinputopentelemetry.md index 9313c86c7..a17bf7bd1 100644 --- a/docs/models/inputresponseinputopentelemetry.md +++ b/docs/models/inputresponseinputopentelemetry.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -33,9 +33,11 @@ | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point | | `otlp_version` | [Optional[models.InputResponseOTLPVersion]](../models/inputresponseotlpversion.md) | :heavy_minus_sign: | The version of OTLP Protobuf definitions to use when interpreting received data | | `auth_type` | [Optional[models.InputResponseInputOpenTelemetryAuthenticationType]](../models/inputresponseinputopentelemetryauthenticationtype.md) | :heavy_minus_sign: | OpenTelemetry authentication type | -| `auth_methods_ext` | List[[models.InputResponseAuthMethodsExt](../models/inputresponseauthmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted. | +| `auth_methods_ext` | List[[models.InputResponseAuthMethodsExt](../models/inputresponseauthmethodsext.md)] | :heavy_minus_sign: | Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | -| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. | +| `max_active_cxn` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound. | +| `max_message_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size. | +| `max_concurrent_streams` | *Optional[float]* | :heavy_minus_sign: | Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `username` | *Optional[str]* | :heavy_minus_sign: | Username | | `password` | *Optional[str]* | :heavy_minus_sign: | Password | @@ -49,5 +51,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_protocol` | *Optional[str]* | :heavy_minus_sign: | Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime. | | `template_otlp_version` | *Optional[str]* | :heavy_minus_sign: | Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputpingidentitypingone.md b/docs/models/inputresponseinputpingidentitypingone.md new file mode 100644 index 000000000..bddc19463 --- /dev/null +++ b/docs/models/inputresponseinputpingidentitypingone.md @@ -0,0 +1,50 @@ +# InputResponseInputPingIdentityPingone + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputPingIdentityPingoneType](../models/inputresponseinputpingidentitypingonetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputpingidentitypingonetype.md b/docs/models/inputresponseinputpingidentitypingonetype.md new file mode 100644 index 000000000..3a6131f96 --- /dev/null +++ b/docs/models/inputresponseinputpingidentitypingonetype.md @@ -0,0 +1,18 @@ +# InputResponseInputPingIdentityPingoneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputPingIdentityPingoneType + +value = InputResponseInputPingIdentityPingoneType.PING_IDENTITY_PINGONE +``` + + +## Values + +| Name | Value | +| ----------------------- | ----------------------- | +| `PING_IDENTITY_PINGONE` | ping_identity_pingone | \ No newline at end of file diff --git a/docs/models/inputresponseinputprometheus.md b/docs/models/inputresponseinputprometheus.md index 36c46e3db..037f715fa 100644 --- a/docs/models/inputresponseinputprometheus.md +++ b/docs/models/inputresponseinputprometheus.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `dimension_list` | List[*str*] | :heavy_minus_sign: | Other dimensions to include in events | @@ -72,5 +72,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_username` | *Optional[str]* | :heavy_minus_sign: | Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime. | | `template_password` | *Optional[str]* | :heavy_minus_sign: | Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputprometheusrw.md b/docs/models/inputresponseinputprometheusrw.md index 2a6303522..b79aada23 100644 --- a/docs/models/inputresponseinputprometheusrw.md +++ b/docs/models/inputresponseinputprometheusrw.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -46,5 +46,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_prometheus_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime. | | `template_username` | *Optional[str]* | :heavy_minus_sign: | Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputproofpointpod.md b/docs/models/inputresponseinputproofpointpod.md new file mode 100644 index 000000000..e3764cda7 --- /dev/null +++ b/docs/models/inputresponseinputproofpointpod.md @@ -0,0 +1,34 @@ +# InputResponseInputProofpointPod + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputProofpointPodType](../models/inputresponseinputproofpointpodtype.md) | :heavy_check_mark: | Connector type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `cluster_id` | *str* | :heavy_check_mark: | Proofpoint on Demand cluster ID. | +| `feed_type` | [models.InputResponseFeedType](../models/inputresponsefeedtype.md) | :heavy_check_mark: | Proofpoint on Demand feed to ingest. | +| `text_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `compress` | *Optional[bool]* | :heavy_minus_sign: | Compress the feed connection. | +| `handshake_timeout` | *Optional[float]* | :heavy_minus_sign: | Maximum time to wait for the connection handshake to complete. | +| `keep_alive_interval_sec` | *Optional[float]* | :heavy_minus_sign: | How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings. | +| `max_missed_keep_alives` | *Optional[float]* | :heavy_minus_sign: | Maximum number of consecutive keepalive pings that can go unanswered before reconnecting. | +| `max_message_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc. | +| `read_buffer_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_cluster_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputproofpointpodtype.md b/docs/models/inputresponseinputproofpointpodtype.md new file mode 100644 index 000000000..4d4a39aeb --- /dev/null +++ b/docs/models/inputresponseinputproofpointpodtype.md @@ -0,0 +1,18 @@ +# InputResponseInputProofpointPodType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputProofpointPodType + +value = InputResponseInputProofpointPodType.PROOFPOINT_POD +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `PROOFPOINT_POD` | proofpoint_pod | \ No newline at end of file diff --git a/docs/models/inputresponseinputrawudp.md b/docs/models/inputresponseinputrawudp.md index c4de5dee1..737c87819 100644 --- a/docs/models/inputresponseinputrawudp.md +++ b/docs/models/inputresponseinputrawudp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address. | @@ -24,10 +24,11 @@ | `ingest_raw_bytes` | *Optional[bool]* | :heavy_minus_sign: | If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram. | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputs3.md b/docs/models/inputresponseinputs3.md index fd4cfab43..0de8e92e8 100644 --- a/docs/models/inputresponseinputs3.md +++ b/docs/models/inputresponseinputs3.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `queue_name` | *str* | :heavy_check_mark: | The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`. | @@ -48,6 +48,7 @@ | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | | `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `tag_after_processing` | *Optional[bool]* | :heavy_minus_sign: | Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | @@ -72,5 +73,5 @@ | `template_sqs_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime. | | `template_sqs_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime. | | `template_sqs_aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputs3inventory.md b/docs/models/inputresponseinputs3inventory.md index c7310aaa8..4cc09d5fd 100644 --- a/docs/models/inputresponseinputs3inventory.md +++ b/docs/models/inputresponseinputs3inventory.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `queue_name` | *str* | :heavy_check_mark: | The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`. | @@ -74,5 +74,5 @@ | `template_sqs_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime. | | `template_sqs_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime. | | `template_sqs_aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsailpointhec.md b/docs/models/inputresponseinputsailpointhec.md new file mode 100644 index 000000000..2a6945d94 --- /dev/null +++ b/docs/models/inputresponseinputsailpointhec.md @@ -0,0 +1,43 @@ +# InputResponseInputSailpointHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputSailpointHecType](../models/inputresponseinputsailpointhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsailpointhectype.md b/docs/models/inputresponseinputsailpointhectype.md new file mode 100644 index 000000000..1abf47619 --- /dev/null +++ b/docs/models/inputresponseinputsailpointhectype.md @@ -0,0 +1,18 @@ +# InputResponseInputSailpointHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputSailpointHecType + +value = InputResponseInputSailpointHecType.SAILPOINT_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `SAILPOINT_HEC` | sailpoint_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputsecuritylake.md b/docs/models/inputresponseinputsecuritylake.md index c545fa922..9953446f2 100644 --- a/docs/models/inputresponseinputsecuritylake.md +++ b/docs/models/inputresponseinputsecuritylake.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `queue_name` | *str* | :heavy_check_mark: | The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`. | @@ -72,5 +72,5 @@ | `template_sqs_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime. | | `template_sqs_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime. | | `template_sqs_aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputservicenowtable.md b/docs/models/inputresponseinputservicenowtable.md index 6c6374d62..52d56b3a1 100644 --- a/docs/models/inputresponseinputservicenowtable.md +++ b/docs/models/inputresponseinputservicenowtable.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `instance` | *str* | :heavy_check_mark: | ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL. | @@ -60,5 +60,5 @@ | `template_query` | *Optional[str]* | :heavy_minus_sign: | Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime. | | `template_username` | *Optional[str]* | :heavy_minus_sign: | Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsnmp.md b/docs/models/inputresponseinputsnmp.md index ae4ea125b..da72a9351 100644 --- a/docs/models/inputresponseinputsnmp.md +++ b/docs/models/inputresponseinputsnmp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address. | @@ -30,5 +30,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsplunk.md b/docs/models/inputresponseinputsplunk.md index 9449a75c0..602978ffb 100644 --- a/docs/models/inputresponseinputsplunk.md +++ b/docs/models/inputresponseinputsplunk.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -28,6 +28,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `auth_tokens` | List[[models.InputResponseInputSplunkAuthToken](../models/inputresponseinputsplunkauthtoken.md)] | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | | `max_s2_sversion` | [Optional[models.InputResponseMaxS2SVersion]](../models/inputresponsemaxs2sversion.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | @@ -41,5 +42,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_max_s2_sversion` | *Optional[str]* | :heavy_minus_sign: | Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsplunkauthtoken.md b/docs/models/inputresponseinputsplunkauthtoken.md index ac37aed02..e4c0043da 100644 --- a/docs/models/inputresponseinputsplunkauthtoken.md +++ b/docs/models/inputresponseinputsplunkauthtoken.md @@ -3,7 +3,9 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `token` | *str* | :heavy_check_mark: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file diff --git a/docs/models/inputresponseinputsplunkhec.md b/docs/models/inputresponseinputsplunkhec.md index ae5f2be6f..8a1e1d307 100644 --- a/docs/models/inputresponseinputsplunkhec.md +++ b/docs/models/inputresponseinputsplunkhec.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -37,6 +37,7 @@ | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `use_fwd_timezone` | *Optional[bool]* | :heavy_minus_sign: | Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event | | `drop_control_fields` | *Optional[bool]* | :heavy_minus_sign: | Drop Splunk control fields such as `crcSalt` and `_savedPort`. If disabled, control fields are stored in the internal field `__ctrlFields`. | | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Extract and process Splunk-generated metrics as Cribl metrics | @@ -49,5 +50,5 @@ | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_splunk_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsplunkhecauthtoken.md b/docs/models/inputresponseinputsplunkhecauthtoken.md index 53767d5cc..2f8d8944f 100644 --- a/docs/models/inputresponseinputsplunkhecauthtoken.md +++ b/docs/models/inputresponseinputsplunkhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the token is active and can be used for authentication. | diff --git a/docs/models/inputresponseinputsplunksearch.md b/docs/models/inputresponseinputsplunksearch.md index 2e786d7a3..cb9e52351 100644 --- a/docs/models/inputresponseinputsplunksearch.md +++ b/docs/models/inputresponseinputsplunksearch.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `search_head` | *str* | :heavy_check_mark: | Search head base URL. Can be an expression. Default is https://localhost:8089. | @@ -54,5 +54,5 @@ | `template_latest` | *Optional[str]* | :heavy_minus_sign: | Binds 'latest' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'latest' at runtime. | | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_log_level` | *Optional[str]* | :heavy_minus_sign: | Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsqs.md b/docs/models/inputresponseinputsqs.md index bb2ee0625..7a008ffc2 100644 --- a/docs/models/inputresponseinputsqs.md +++ b/docs/models/inputresponseinputsqs.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `queue_name` | *str* | :heavy_check_mark: | The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`. | @@ -34,6 +34,7 @@ | `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | @@ -49,5 +50,5 @@ | `template_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime. | | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsysdighec.md b/docs/models/inputresponseinputsysdighec.md index 2a5fa1313..e06b54d5e 100644 --- a/docs/models/inputresponseinputsysdighec.md +++ b/docs/models/inputresponseinputsysdighec.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -46,5 +46,5 @@ | `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | | `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | | `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsyslogsyslog1.md b/docs/models/inputresponseinputsyslogsyslog1.md index 3e2a9c126..ca855aafc 100644 --- a/docs/models/inputresponseinputsyslogsyslog1.md +++ b/docs/models/inputresponseinputsyslogsyslog1.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address. | @@ -37,6 +37,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | @@ -45,5 +46,5 @@ | `template_udp_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime. | | `template_tcp_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime. | | `template_timestamp_timezone` | *Optional[str]* | :heavy_minus_sign: | Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsyslogsyslog2.md b/docs/models/inputresponseinputsyslogsyslog2.md index 1b974a7b4..1d17406a3 100644 --- a/docs/models/inputresponseinputsyslogsyslog2.md +++ b/docs/models/inputresponseinputsyslogsyslog2.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address. | @@ -37,6 +37,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | @@ -45,5 +46,5 @@ | `template_udp_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime. | | `template_tcp_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime. | | `template_timestamp_timezone` | *Optional[str]* | :heavy_minus_sign: | Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsystemmetrics.md b/docs/models/inputresponseinputsystemmetrics.md index 2f7e7a65f..103dcc6f6 100644 --- a/docs/models/inputresponseinputsystemmetrics.md +++ b/docs/models/inputresponseinputsystemmetrics.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `interval` | *Optional[float]* | :heavy_minus_sign: | Time, in seconds, between consecutive metric collections. Default is 10 seconds. | @@ -26,5 +26,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputsystemstate.md b/docs/models/inputresponseinputsystemstate.md index cdb0dfdee..8cce157b0 100644 --- a/docs/models/inputresponseinputsystemstate.md +++ b/docs/models/inputresponseinputsystemstate.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `interval` | *Optional[float]* | :heavy_minus_sign: | Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes). | @@ -25,5 +25,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputtcp.md b/docs/models/inputresponseinputtcp.md index e99aa4506..e0c997c8e 100644 --- a/docs/models/inputresponseinputtcp.md +++ b/docs/models/inputresponseinputtcp.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -28,15 +28,16 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { "authToken" : "myToken", "fields": { "field1": "value1", "field2": "value2" } } | | `preprocess` | [Optional[models.PreprocessType]](../models/preprocesstype.md) | :heavy_minus_sign: | Optional preprocessing step that pipes collected data through an external command before ingestion. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputtcpjson.md b/docs/models/inputresponseinputtcpjson.md index 2995610f1..f7b584259 100644 --- a/docs/models/inputresponseinputtcpjson.md +++ b/docs/models/inputresponseinputtcpjson.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -27,7 +27,7 @@ | `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Enable if the connection is proxied by a device that supports proxy protocol v1 or v2 | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | @@ -35,5 +35,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputtrellixhec.md b/docs/models/inputresponseinputtrellixhec.md new file mode 100644 index 000000000..ae32fdb11 --- /dev/null +++ b/docs/models/inputresponseinputtrellixhec.md @@ -0,0 +1,50 @@ +# InputResponseInputTrellixHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputTrellixHecType](../models/inputresponseinputtrellixhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputtrellixhectype.md b/docs/models/inputresponseinputtrellixhectype.md new file mode 100644 index 000000000..54dfe99ef --- /dev/null +++ b/docs/models/inputresponseinputtrellixhectype.md @@ -0,0 +1,18 @@ +# InputResponseInputTrellixHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputTrellixHecType + +value = InputResponseInputTrellixHecType.TRELLIX_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `TRELLIX_HEC` | trellix_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputtrendmicrovisionone.md b/docs/models/inputresponseinputtrendmicrovisionone.md new file mode 100644 index 000000000..605335bb8 --- /dev/null +++ b/docs/models/inputresponseinputtrendmicrovisionone.md @@ -0,0 +1,50 @@ +# InputResponseInputTrendMicroVisionOne + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputTrendMicroVisionOneType](../models/inputresponseinputtrendmicrovisiononetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputtrendmicrovisiononetype.md b/docs/models/inputresponseinputtrendmicrovisiononetype.md new file mode 100644 index 000000000..752e98186 --- /dev/null +++ b/docs/models/inputresponseinputtrendmicrovisiononetype.md @@ -0,0 +1,18 @@ +# InputResponseInputTrendMicroVisionOneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputTrendMicroVisionOneType + +value = InputResponseInputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE +``` + + +## Values + +| Name | Value | +| ------------------------ | ------------------------ | +| `TREND_MICRO_VISION_ONE` | trend_micro_vision_one | \ No newline at end of file diff --git a/docs/models/inputresponseinputupwindhec.md b/docs/models/inputresponseinputupwindhec.md index a3fc3932b..6303459d1 100644 --- a/docs/models/inputresponseinputupwindhec.md +++ b/docs/models/inputresponseinputupwindhec.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -46,5 +46,5 @@ | `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | | `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | | `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputvectraaihec.md b/docs/models/inputresponseinputvectraaihec.md new file mode 100644 index 000000000..f20b6c8da --- /dev/null +++ b/docs/models/inputresponseinputvectraaihec.md @@ -0,0 +1,50 @@ +# InputResponseInputVectraAiHec + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputResponseInputVectraAiHecType](../models/inputresponseinputvectraaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `capture_headers_warning` | *Optional[Literal[""]]* | :heavy_minus_sign: | N/A | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputvectraaihectype.md b/docs/models/inputresponseinputvectraaihectype.md new file mode 100644 index 000000000..dda1e5e26 --- /dev/null +++ b/docs/models/inputresponseinputvectraaihectype.md @@ -0,0 +1,18 @@ +# InputResponseInputVectraAiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseInputVectraAiHecType + +value = InputResponseInputVectraAiHecType.VECTRA_AI_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `VECTRA_AI_HEC` | vectra_ai_hec | \ No newline at end of file diff --git a/docs/models/inputresponseinputwef.md b/docs/models/inputresponseinputwef.md index 216a43402..9d0b400df 100644 --- a/docs/models/inputresponseinputwef.md +++ b/docs/models/inputresponseinputwef.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -44,5 +44,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_keytab` | *Optional[str]* | :heavy_minus_sign: | Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime. | | `template_principal` | *Optional[str]* | :heavy_minus_sign: | Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputwefauthenticationmethod.md b/docs/models/inputresponseinputwefauthenticationmethod.md index 137c5e573..944fb237c 100644 --- a/docs/models/inputresponseinputwefauthenticationmethod.md +++ b/docs/models/inputresponseinputwefauthenticationmethod.md @@ -18,4 +18,5 @@ value = InputResponseInputWefAuthenticationMethod.CLIENT_CERT | Name | Value | | ------------- | ------------- | | `CLIENT_CERT` | clientCert | -| `KERBEROS` | kerberos | \ No newline at end of file +| `KERBEROS` | kerberos | +| `NEGOTIATE` | negotiate | \ No newline at end of file diff --git a/docs/models/inputresponseinputwindowsmetrics.md b/docs/models/inputresponseinputwindowsmetrics.md index f095af6cf..1549ce9ef 100644 --- a/docs/models/inputresponseinputwindowsmetrics.md +++ b/docs/models/inputresponseinputwindowsmetrics.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `interval` | *Optional[float]* | :heavy_minus_sign: | Time, in seconds, between consecutive metric collections. Default is 10 seconds. | @@ -26,5 +26,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputwineventlogs.md b/docs/models/inputresponseinputwineventlogs.md index 3d59974df..26c149965 100644 --- a/docs/models/inputresponseinputwineventlogs.md +++ b/docs/models/inputresponseinputwineventlogs.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `log_names` | List[*str*] | :heavy_check_mark: | Enter the event logs to collect. Run "Get-WinEvent -ListLog *" in PowerShell to see the available logs. | @@ -27,8 +27,9 @@ | `max_event_bytes` | *Optional[int]* | :heavy_minus_sign: | The maximum number of bytes in an event before it is flushed to the pipelines | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `disable_json_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | +| `include_empty_json_fields` | *Optional[bool]* | :heavy_minus_sign: | Preserve fields with empty values (such as '-') in the JSON output instead of omitting them | | `disable_xml_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputwiz.md b/docs/models/inputresponseinputwiz.md index 9d8c2c3c4..97929b915 100644 --- a/docs/models/inputresponseinputwiz.md +++ b/docs/models/inputresponseinputwiz.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `endpoint` | *str* | :heavy_check_mark: | The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql | @@ -39,5 +39,5 @@ | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_auth_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputwizwebhook.md b/docs/models/inputresponseinputwizwebhook.md index 6e9b01472..cf9623bdd 100644 --- a/docs/models/inputresponseinputwizwebhook.md +++ b/docs/models/inputresponseinputwizwebhook.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -37,7 +37,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.InputResponseInputWizWebhookAuthTokensExtUnion](../models/inputresponseinputwizwebhookauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | @@ -45,5 +45,5 @@ | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_auth_tokens` | *Optional[str]* | :heavy_minus_sign: | Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime. | | `template_allowed_paths` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputwizwebhookauthtokensext1.md b/docs/models/inputresponseinputwizwebhookauthtokensext1.md new file mode 100644 index 000000000..d0ccc1dd6 --- /dev/null +++ b/docs/models/inputresponseinputwizwebhookauthtokensext1.md @@ -0,0 +1,12 @@ +# InputResponseInputWizWebhookAuthTokensExt1 + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputresponseinputwizwebhookauthtokensext2.md b/docs/models/inputresponseinputwizwebhookauthtokensext2.md new file mode 100644 index 000000000..c904bde47 --- /dev/null +++ b/docs/models/inputresponseinputwizwebhookauthtokensext2.md @@ -0,0 +1,12 @@ +# InputResponseInputWizWebhookAuthTokensExt2 + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputresponseinputwizwebhookauthtokensextunion.md b/docs/models/inputresponseinputwizwebhookauthtokensextunion.md new file mode 100644 index 000000000..32ae88ae8 --- /dev/null +++ b/docs/models/inputresponseinputwizwebhookauthtokensextunion.md @@ -0,0 +1,17 @@ +# InputResponseInputWizWebhookAuthTokensExtUnion + + +## Supported Types + +### `models.InputResponseInputWizWebhookAuthTokensExt1` + +```python +value: models.InputResponseInputWizWebhookAuthTokensExt1 = /* values here */ +``` + +### `models.InputResponseInputWizWebhookAuthTokensExt2` + +```python +value: models.InputResponseInputWizWebhookAuthTokensExt2 = /* values here */ +``` + diff --git a/docs/models/inputresponseinputzscalerhec.md b/docs/models/inputresponseinputzscalerhec.md index 50deab2d1..24b923544 100644 --- a/docs/models/inputresponseinputzscalerhec.md +++ b/docs/models/inputresponseinputzscalerhec.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -47,5 +47,5 @@ | `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | | `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | | `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Source. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Source. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/inputresponseinputzscalerhecauthtoken.md b/docs/models/inputresponseinputzscalerhecauthtoken.md index ca9698697..63b405231 100644 --- a/docs/models/inputresponseinputzscalerhecauthtoken.md +++ b/docs/models/inputresponseinputzscalerhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enable token | diff --git a/docs/models/inputresponseprojectdetails.md b/docs/models/inputresponseprojectdetails.md index d7d1fa8a9..db3c96422 100644 --- a/docs/models/inputresponseprojectdetails.md +++ b/docs/models/inputresponseprojectdetails.md @@ -5,14 +5,14 @@ Project Details ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.InputResponseProjectDetailsManageState]](../models/inputresponseprojectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.InputResponseProjectDetailsManageState]](../models/inputresponseprojectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseprojects.md b/docs/models/inputresponseprojects.md index 86e248d7b..25e26383a 100644 --- a/docs/models/inputresponseprojects.md +++ b/docs/models/inputresponseprojects.md @@ -5,14 +5,14 @@ Projects ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.InputResponseProjectsManageState]](../models/inputresponseprojectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.InputResponseProjectsManageState]](../models/inputresponseprojectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/inputresponseretryrules.md b/docs/models/inputresponseretryrules.md new file mode 100644 index 000000000..f88179896 --- /dev/null +++ b/docs/models/inputresponseretryrules.md @@ -0,0 +1,15 @@ +# InputResponseRetryRules + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `type` | [models.RetryTypeOptionsHealthCheckCollectorConfRetryRules](../models/retrytypeoptionshealthcheckcollectorconfretryrules.md) | :heavy_check_mark: | The algorithm to use when performing HTTP retries | +| `interval` | *Optional[float]* | :heavy_minus_sign: | Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute). | +| `limit` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times to retry a failed HTTP request | +| `multiplier` | *Optional[float]* | :heavy_minus_sign: | Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on | +| `codes` | List[*float*] | :heavy_minus_sign: | List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503. | +| `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored. | +| `retry_connect_timeout` | *Optional[bool]* | :heavy_minus_sign: | Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs | +| `retry_connect_reset` | *Optional[bool]* | :heavy_minus_sign: | Retry request when a connection reset (ECONNRESET) error occurs | \ No newline at end of file diff --git a/docs/models/inputresponsetlssettingsserverside.md b/docs/models/inputresponsetlssettingsserverside.md index 6c89a98ed..6eb6257a9 100644 --- a/docs/models/inputresponsetlssettingsserverside.md +++ b/docs/models/inputresponsetlssettingsserverside.md @@ -9,12 +9,12 @@ TLS settings (server side) | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | | `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enable or disable TLS. Defaults to enabled for Cloudflare sources. | | `request_cert` | *Optional[bool]* | :heavy_minus_sign: | Require clients to present their certificates. Used to perform client authentication using SSL certs. | +| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's) | | `common_name_regex` | *Optional[str]* | :heavy_minus_sign: | Regex matching allowable common names in peer certificates' subject attribute | | `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of the predefined certificate | | `priv_key_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled. | | `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to use to decrypt private key | | `cert_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled. | -| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `min_version` | [Optional[models.MinimumTLSVersionOptionsTLS]](../models/minimumtlsversionoptionstls.md) | :heavy_minus_sign: | Minimum TLS version | | `max_version` | [Optional[models.MaximumTLSVersionOptionsTLS]](../models/maximumtlsversionoptionstls.md) | :heavy_minus_sign: | Maximum TLS version | \ No newline at end of file diff --git a/docs/models/inputresponsev3authenticationkeytype.md b/docs/models/inputresponsev3authenticationkeytype.md new file mode 100644 index 000000000..ae6c69d27 --- /dev/null +++ b/docs/models/inputresponsev3authenticationkeytype.md @@ -0,0 +1,21 @@ +# InputResponseV3AuthenticationKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseV3AuthenticationKeyType + +value = InputResponseV3AuthenticationKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/inputresponsev3privacykeytype.md b/docs/models/inputresponsev3privacykeytype.md new file mode 100644 index 000000000..4b8971a9e --- /dev/null +++ b/docs/models/inputresponsev3privacykeytype.md @@ -0,0 +1,21 @@ +# InputResponseV3PrivacyKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import InputResponseV3PrivacyKeyType + +value = InputResponseV3PrivacyKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/inputresponsev3user.md b/docs/models/inputresponsev3user.md index e26bae7ee..d04e959f8 100644 --- a/docs/models/inputresponsev3user.md +++ b/docs/models/inputresponsev3user.md @@ -3,10 +3,14 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -| `name` | *str* | :heavy_check_mark: | V3 name | -| `auth_protocol` | [Optional[models.InputResponseAuthenticationProtocol]](../models/inputresponseauthenticationprotocol.md) | :heavy_minus_sign: | Authentication protocol | -| `auth_key` | *Optional[str]* | :heavy_minus_sign: | V3 authentication key | -| `priv_protocol` | [Optional[models.InputResponsePrivacyProtocol]](../models/inputresponseprivacyprotocol.md) | :heavy_minus_sign: | Privacy protocol | -| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------- | +| `name` | *str* | :heavy_check_mark: | V3 name | +| `auth_protocol` | [Optional[models.InputResponseAuthenticationProtocol]](../models/inputresponseauthenticationprotocol.md) | :heavy_minus_sign: | Authentication protocol | +| `auth_key_type` | [Optional[models.InputResponseV3AuthenticationKeyType]](../models/inputresponsev3authenticationkeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | +| `auth_key` | *Optional[str]* | :heavy_minus_sign: | V3 authentication key | +| `auth_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `priv_protocol` | [Optional[models.InputResponsePrivacyProtocol]](../models/inputresponseprivacyprotocol.md) | :heavy_minus_sign: | Privacy protocol | +| `priv_key_type` | [Optional[models.InputResponseV3PrivacyKeyType]](../models/inputresponsev3privacykeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | +| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | +| `priv_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/inputs3input.md b/docs/models/inputs3input.md index 183c61364..347ccdefa 100644 --- a/docs/models/inputs3input.md +++ b/docs/models/inputs3input.md @@ -47,6 +47,7 @@ | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | | `encoding` | *Optional[str]* | :heavy_minus_sign: | Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters. | | `tag_after_processing` | *Optional[bool]* | :heavy_minus_sign: | Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/inputsailpointhecinput.md b/docs/models/inputsailpointhecinput.md new file mode 100644 index 000000000..2fb6e4ac6 --- /dev/null +++ b/docs/models/inputsailpointhecinput.md @@ -0,0 +1,39 @@ +# InputSailpointHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputSailpointHecType](../models/inputsailpointhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | \ No newline at end of file diff --git a/docs/models/inputsailpointhectype.md b/docs/models/inputsailpointhectype.md new file mode 100644 index 000000000..d1410c51a --- /dev/null +++ b/docs/models/inputsailpointhectype.md @@ -0,0 +1,18 @@ +# InputSailpointHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputSailpointHecType + +value = InputSailpointHecType.SAILPOINT_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `SAILPOINT_HEC` | sailpoint_hec | \ No newline at end of file diff --git a/docs/models/inputsnmpv3user.md b/docs/models/inputsnmpv3user.md index 6fcee1f55..aca5575c9 100644 --- a/docs/models/inputsnmpv3user.md +++ b/docs/models/inputsnmpv3user.md @@ -7,6 +7,10 @@ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | | `name` | *str* | :heavy_check_mark: | V3 name | | `auth_protocol` | [Optional[models.InputSnmpAuthenticationProtocol]](../models/inputsnmpauthenticationprotocol.md) | :heavy_minus_sign: | Authentication protocol | +| `auth_key_type` | [Optional[models.V3AuthenticationKeyType]](../models/v3authenticationkeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | | `auth_key` | *Optional[str]* | :heavy_minus_sign: | V3 authentication key | +| `auth_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `priv_protocol` | [Optional[models.PrivacyProtocol]](../models/privacyprotocol.md) | :heavy_minus_sign: | Privacy protocol | -| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | \ No newline at end of file +| `priv_key_type` | [Optional[models.V3PrivacyKeyType]](../models/v3privacykeytype.md) | :heavy_minus_sign: | Select Manual to enter the key directly, or Secret to use a stored text secret | +| `priv_key` | *Optional[str]* | :heavy_minus_sign: | V3 privacy key | +| `priv_key_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/inputsplunkauthtoken.md b/docs/models/inputsplunkauthtoken.md index 0ada1a3b8..cdc8c3577 100644 --- a/docs/models/inputsplunkauthtoken.md +++ b/docs/models/inputsplunkauthtoken.md @@ -3,7 +3,9 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `token` | *str* | :heavy_check_mark: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | \ No newline at end of file diff --git a/docs/models/inputsplunkhec.md b/docs/models/inputsplunkhec.md index fb72a9411..3962a8805 100644 --- a/docs/models/inputsplunkhec.md +++ b/docs/models/inputsplunkhec.md @@ -13,7 +13,7 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `cribl_source_provenance` | [Optional[models.InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint]](../models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | +| `cribl_source_provenance` | [Optional[models.InputProvenanceTypeOptional]](../models/inputprovenancetypeoptional.md) | :heavy_minus_sign: | Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create. | | `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | | `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | | `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | @@ -37,6 +37,7 @@ | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `use_fwd_timezone` | *Optional[bool]* | :heavy_minus_sign: | Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event | | `drop_control_fields` | *Optional[bool]* | :heavy_minus_sign: | Drop Splunk control fields such as `crcSalt` and `_savedPort`. If disabled, control fields are stored in the internal field `__ctrlFields`. | | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Extract and process Splunk-generated metrics as Cribl metrics | diff --git a/docs/models/inputsplunkhecauthtoken.md b/docs/models/inputsplunkhecauthtoken.md index 7da53e6ec..869610434 100644 --- a/docs/models/inputsplunkhecauthtoken.md +++ b/docs/models/inputsplunkhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the token is active and can be used for authentication. | diff --git a/docs/models/inputsplunkhecinput.md b/docs/models/inputsplunkhecinput.md index f3f0d23a2..6666075f5 100644 --- a/docs/models/inputsplunkhecinput.md +++ b/docs/models/inputsplunkhecinput.md @@ -35,6 +35,7 @@ | `splunk_hec_acks` | *Optional[bool]* | :heavy_minus_sign: | Enable Splunk HEC acknowledgements | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `use_fwd_timezone` | *Optional[bool]* | :heavy_minus_sign: | Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event | | `drop_control_fields` | *Optional[bool]* | :heavy_minus_sign: | Drop Splunk control fields such as `crcSalt` and `_savedPort`. If disabled, control fields are stored in the internal field `__ctrlFields`. | | `extract_metrics` | *Optional[bool]* | :heavy_minus_sign: | Extract and process Splunk-generated metrics as Cribl metrics | diff --git a/docs/models/inputsplunkinput.md b/docs/models/inputsplunkinput.md index 1225f6bf7..ab41c802a 100644 --- a/docs/models/inputsplunkinput.md +++ b/docs/models/inputsplunkinput.md @@ -27,6 +27,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `auth_tokens` | List[[models.InputSplunkAuthToken](../models/inputsplunkauthtoken.md)] | :heavy_minus_sign: | Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted. | | `max_s2_sversion` | [Optional[models.MaxS2SVersion]](../models/maxs2sversion.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | diff --git a/docs/models/inputsqsinput.md b/docs/models/inputsqsinput.md index 74556802c..121b88bc2 100644 --- a/docs/models/inputsqsinput.md +++ b/docs/models/inputsqsinput.md @@ -33,6 +33,7 @@ | `visibility_timeout` | *Optional[float]* | :heavy_minus_sign: | After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours). | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `poll_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts. | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Access key | | `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | diff --git a/docs/models/inputsyslogsysloginput1.md b/docs/models/inputsyslogsysloginput1.md index fb03a7e55..2bf20e09d 100644 --- a/docs/models/inputsyslogsysloginput1.md +++ b/docs/models/inputsyslogsysloginput1.md @@ -36,6 +36,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/inputsyslogsysloginput2.md b/docs/models/inputsyslogsysloginput2.md index dd2a04332..60422accb 100644 --- a/docs/models/inputsyslogsysloginput2.md +++ b/docs/models/inputsyslogsysloginput2.md @@ -36,6 +36,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `udp_socket_rx_buf_size` | *Optional[float]* | :heavy_minus_sign: | Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization. | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `enable_enhanced_proxy_header_parsing` | *Optional[bool]* | :heavy_minus_sign: | When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | diff --git a/docs/models/inputtcpinput.md b/docs/models/inputtcpinput.md index 6abf4e4d4..889832759 100644 --- a/docs/models/inputtcpinput.md +++ b/docs/models/inputtcpinput.md @@ -27,11 +27,12 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `breaker_rulesets` | List[*str*] | :heavy_minus_sign: | A list of event-breaking rulesets that will be applied, in order, to the input data stream | | `stale_channel_flush_ms` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing). | | `enable_header` | *Optional[bool]* | :heavy_minus_sign: | Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { "authToken" : "myToken", "fields": { "field1": "value1", "field2": "value2" } } | | `preprocess` | [Optional[models.PreprocessType]](../models/preprocesstype.md) | :heavy_minus_sign: | Optional preprocessing step that pipes collected data through an external command before ingestion. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputtcpjsoninput.md b/docs/models/inputtcpjsoninput.md index 84257a0ec..6817fd200 100644 --- a/docs/models/inputtcpjsoninput.md +++ b/docs/models/inputtcpjsoninput.md @@ -26,7 +26,7 @@ | `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Enable if the connection is proxied by a device that supports proxy protocol v1 or v2 | | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `enable_load_balancing` | *Optional[bool]* | :heavy_minus_sign: | Load balance traffic across all Worker Processes | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | diff --git a/docs/models/inputtrellixhecinput.md b/docs/models/inputtrellixhecinput.md new file mode 100644 index 000000000..8c3bfd1be --- /dev/null +++ b/docs/models/inputtrellixhecinput.md @@ -0,0 +1,46 @@ +# InputTrellixHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputTrellixHecType](../models/inputtrellixhectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputtrellixhectype.md b/docs/models/inputtrellixhectype.md new file mode 100644 index 000000000..2a65d835c --- /dev/null +++ b/docs/models/inputtrellixhectype.md @@ -0,0 +1,18 @@ +# InputTrellixHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputTrellixHecType + +value = InputTrellixHecType.TRELLIX_HEC +``` + + +## Values + +| Name | Value | +| ------------- | ------------- | +| `TRELLIX_HEC` | trellix_hec | \ No newline at end of file diff --git a/docs/models/inputtrendmicrovisiononeinput.md b/docs/models/inputtrendmicrovisiononeinput.md new file mode 100644 index 000000000..cf8aa14ea --- /dev/null +++ b/docs/models/inputtrendmicrovisiononeinput.md @@ -0,0 +1,46 @@ +# InputTrendMicroVisionOneInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputTrendMicroVisionOneType](../models/inputtrendmicrovisiononetype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputtrendmicrovisiononetype.md b/docs/models/inputtrendmicrovisiononetype.md new file mode 100644 index 000000000..101b0a7d5 --- /dev/null +++ b/docs/models/inputtrendmicrovisiononetype.md @@ -0,0 +1,18 @@ +# InputTrendMicroVisionOneType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputTrendMicroVisionOneType + +value = InputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE +``` + + +## Values + +| Name | Value | +| ------------------------ | ------------------------ | +| `TREND_MICRO_VISION_ONE` | trend_micro_vision_one | \ No newline at end of file diff --git a/docs/models/inputvectraaihecinput.md b/docs/models/inputvectraaihecinput.md new file mode 100644 index 000000000..2f67cf6d3 --- /dev/null +++ b/docs/models/inputvectraaihecinput.md @@ -0,0 +1,46 @@ +# InputVectraAiHecInput + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this input | +| `type` | [models.InputVectraAiHecType](../models/inputvectraaihectype.md) | :heavy_check_mark: | Source type identifier. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Source is disabled and will not collect data. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data from this Source before sending it through the Routes | +| `send_to_routes` | *Optional[bool]* | :heavy_minus_sign: | Select whether to send data to Routes, or directly to Destinations. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `pq_enabled` | *Optional[bool]* | :heavy_minus_sign: | Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers). | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `connections` | List[[models.ConnectionConfInputCollection](../models/connectionconfinputcollection.md)] | :heavy_minus_sign: | Direct connections to Destinations, and optionally via a Pipeline or a Pack | +| `pq` | [Optional[models.PqType]](../models/pqtype.md) | :heavy_minus_sign: | N/A | +| `host` | *str* | :heavy_check_mark: | Address to bind on. Defaults to 0.0.0.0 (all addresses). | +| `port` | *float* | :heavy_check_mark: | Port to listen on | +| `auth_tokens` | List[[models.AuthTokenConfInputCloudflareHec](../models/authtokenconfinputcloudflarehec.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `tls` | [Optional[models.TLSSettingsServerSideType]](../models/tlssettingsserversidetype.md) | :heavy_minus_sign: | TLS settings (server side) | +| `max_active_req` | *Optional[float]* | :heavy_minus_sign: | Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput. | +| `max_requests_per_socket` | *Optional[int]* | :heavy_minus_sign: | Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited). | +| `enable_proxy_header` | *Optional[bool]* | :heavy_minus_sign: | Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction. | +| `capture_headers` | *Optional[bool]* | :heavy_minus_sign: | Add request headers to events, in the __headers field | +| `activity_log_sample_rate` | *Optional[float]* | :heavy_minus_sign: | How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc. | +| `request_timeout` | *Optional[float]* | :heavy_minus_sign: | How long to wait for an incoming request to complete before aborting it. Use 0 to disable. | +| `socket_timeout` | *Optional[float]* | :heavy_minus_sign: | How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0. | +| `keep_alive_timeout` | *Optional[float]* | :heavy_minus_sign: | After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes). | +| `ip_allowlist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be processed, unless also matched by the denylist | +| `ip_denylist_regex` | *Optional[str]* | :heavy_minus_sign: | Messages from matched IP addresses will be ignored. This takes precedence over the allowlist. | +| `hec_api` | *str* | :heavy_check_mark: | Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints. | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to every event. May be overridden by fields added at the token or request level. | +| `allowed_indexes` | List[*str*] | :heavy_minus_sign: | List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level. | +| `access_control_allow_origin` | List[*str*] | :heavy_minus_sign: | HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards. | +| `access_control_allow_headers` | List[*str*] | :heavy_minus_sign: | HTTP headers that @{product} will send to allowed origins as "Access-Control-Allow-Headers" in a CORS preflight response. Use "*" to allow all headers. | +| `emit_token_metrics` | *Optional[bool]* | :heavy_minus_sign: | Emit per-token (.http.perToken) and summary (.http.summary) request metrics | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | +| `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | +| `template_hec_api` | *Optional[str]* | :heavy_minus_sign: | Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime. | +| `template_allowed_indexes` | *Optional[str]* | :heavy_minus_sign: | Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime. | +| `template_access_control_allow_origin` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime. | +| `template_access_control_allow_headers` | *Optional[str]* | :heavy_minus_sign: | Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime. | \ No newline at end of file diff --git a/docs/models/inputvectraaihectype.md b/docs/models/inputvectraaihectype.md new file mode 100644 index 000000000..e25a8892f --- /dev/null +++ b/docs/models/inputvectraaihectype.md @@ -0,0 +1,18 @@ +# InputVectraAiHecType + +Source type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import InputVectraAiHecType + +value = InputVectraAiHecType.VECTRA_AI_HEC +``` + + +## Values + +| Name | Value | +| --------------- | --------------- | +| `VECTRA_AI_HEC` | vectra_ai_hec | \ No newline at end of file diff --git a/docs/models/inputwefauthenticationmethod.md b/docs/models/inputwefauthenticationmethod.md index 00a6f4aa0..45d115fd4 100644 --- a/docs/models/inputwefauthenticationmethod.md +++ b/docs/models/inputwefauthenticationmethod.md @@ -18,4 +18,5 @@ value = InputWefAuthenticationMethod.CLIENT_CERT | Name | Value | | ------------- | ------------- | | `CLIENT_CERT` | clientCert | -| `KERBEROS` | kerberos | \ No newline at end of file +| `KERBEROS` | kerberos | +| `NEGOTIATE` | negotiate | \ No newline at end of file diff --git a/docs/models/eventformat.md b/docs/models/inputwineventlogseventformat.md similarity index 61% rename from docs/models/eventformat.md rename to docs/models/inputwineventlogseventformat.md index 26ea48c51..c62f7423d 100644 --- a/docs/models/eventformat.md +++ b/docs/models/inputwineventlogseventformat.md @@ -1,13 +1,13 @@ -# EventFormat +# InputWinEventLogsEventFormat Format of individual events ## Example Usage ```python -from cribl_control_plane.models import EventFormat +from cribl_control_plane.models import InputWinEventLogsEventFormat -value = EventFormat.JSON +value = InputWinEventLogsEventFormat.JSON # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/inputwineventlogsinput.md b/docs/models/inputwineventlogsinput.md index 49630cc1e..27c56d276 100644 --- a/docs/models/inputwineventlogsinput.md +++ b/docs/models/inputwineventlogsinput.md @@ -18,7 +18,7 @@ | `log_names` | List[*str*] | :heavy_check_mark: | Enter the event logs to collect. Run "Get-WinEvent -ListLog *" in PowerShell to see the available logs. | | `suppress_missing_log_errors` | *Optional[bool]* | :heavy_minus_sign: | When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs. | | `read_mode` | [Optional[models.InputWinEventLogsReadMode]](../models/inputwineventlogsreadmode.md) | :heavy_minus_sign: | Read all stored and future event logs, or only future events | -| `event_format` | [Optional[models.EventFormat]](../models/eventformat.md) | :heavy_minus_sign: | Format of individual events | +| `event_format` | [Optional[models.InputWinEventLogsEventFormat]](../models/inputwineventlogseventformat.md) | :heavy_minus_sign: | Format of individual events | | `disable_native_module` | *Optional[bool]* | :heavy_minus_sign: | Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings) | | `interval` | *Optional[float]* | :heavy_minus_sign: | Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools) | | `batch_size` | *Optional[float]* | :heavy_minus_sign: | The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools) | @@ -26,6 +26,7 @@ | `max_event_bytes` | *Optional[int]* | :heavy_minus_sign: | The maximum number of bytes in an event before it is flushed to the pipelines | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `disable_json_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | +| `include_empty_json_fields` | *Optional[bool]* | :heavy_minus_sign: | Preserve fields with empty values (such as '-') in the JSON output instead of omitting them | | `disable_xml_rendering` | *Optional[bool]* | :heavy_minus_sign: | Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API) | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/inputwizwebhookauthtokensext1.md b/docs/models/inputwizwebhookauthtokensext1.md new file mode 100644 index 000000000..db5ff6560 --- /dev/null +++ b/docs/models/inputwizwebhookauthtokensext1.md @@ -0,0 +1,12 @@ +# InputWizWebhookAuthTokensExt1 + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputwizwebhookauthtokensext2.md b/docs/models/inputwizwebhookauthtokensext2.md new file mode 100644 index 000000000..dc996771d --- /dev/null +++ b/docs/models/inputwizwebhookauthtokensext2.md @@ -0,0 +1,12 @@ +# InputWizWebhookAuthTokensExt2 + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | +| `auth_type` | [models.AuthenticationMethodOptionsAuthTokensExtItems](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_check_mark: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `token_secret` | *str* | :heavy_check_mark: | Select or create a stored text secret | +| `token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (Authorization: ) | +| `description` | *Optional[str]* | :heavy_minus_sign: | Description | +| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events referencing this token | \ No newline at end of file diff --git a/docs/models/inputwizwebhookauthtokensextunion.md b/docs/models/inputwizwebhookauthtokensextunion.md new file mode 100644 index 000000000..d5086e574 --- /dev/null +++ b/docs/models/inputwizwebhookauthtokensextunion.md @@ -0,0 +1,17 @@ +# InputWizWebhookAuthTokensExtUnion + + +## Supported Types + +### `models.InputWizWebhookAuthTokensExt1` + +```python +value: models.InputWizWebhookAuthTokensExt1 = /* values here */ +``` + +### `models.InputWizWebhookAuthTokensExt2` + +```python +value: models.InputWizWebhookAuthTokensExt2 = /* values here */ +``` + diff --git a/docs/models/inputwizwebhookinput.md b/docs/models/inputwizwebhookinput.md index 37a172211..38d4e70d0 100644 --- a/docs/models/inputwizwebhookinput.md +++ b/docs/models/inputwizwebhookinput.md @@ -35,7 +35,7 @@ | `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | `allowed_paths` | List[*str*] | :heavy_minus_sign: | List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all. | | `allowed_methods` | List[*str*] | :heavy_minus_sign: | List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all. | -| `auth_tokens_ext` | List[[models.AuthTokensExtConfInputHTTP](../models/authtokensextconfinputhttp.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | +| `auth_tokens_ext` | List[[models.InputWizWebhookAuthTokensExtUnion](../models/inputwizwebhookauthtokensextunion.md)] | :heavy_minus_sign: | Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_environment` | *Optional[str]* | :heavy_minus_sign: | Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | diff --git a/docs/models/inputzscalerhecauthtoken.md b/docs/models/inputzscalerhecauthtoken.md index 682590f89..b2b0b8f12 100644 --- a/docs/models/inputzscalerhecauthtoken.md +++ b/docs/models/inputzscalerhecauthtoken.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `token_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | | `token` | *str* | :heavy_check_mark: | Shared secret to be provided by any client (Authorization: ) | | `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enable token | diff --git a/docs/models/labelfields1.md b/docs/models/labelfields1.md index dbc3f2356..28e044a13 100644 --- a/docs/models/labelfields1.md +++ b/docs/models/labelfields1.md @@ -1,9 +1,11 @@ # LabelFields1 +Label configuration that reads key-value pairs from one object field. + ## Fields | Field | Type | Required | Description | | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `mode` | [models.PipelineFunctionMetricsExportMode1](../models/pipelinefunctionmetricsexportmode1.md) | :heavy_check_mark: | Discriminator value. | -| `field` | [models.NameFieldType](../models/namefieldtype.md) | :heavy_check_mark: | N/A | \ No newline at end of file +| `mode` | [models.PipelineFunctionMetricsExportMode1](../models/pipelinefunctionmetricsexportmode1.md) | :heavy_check_mark: | Type of label configuration. Always object. | +| `field` | [models.NameFieldType](../models/namefieldtype.md) | :heavy_check_mark: | Reference to a field by its original text and parsed path segments. | \ No newline at end of file diff --git a/docs/models/labelfields2.md b/docs/models/labelfields2.md index 98ff83e72..60f0ffab6 100644 --- a/docs/models/labelfields2.md +++ b/docs/models/labelfields2.md @@ -1,9 +1,11 @@ # LabelFields2 +Label configuration that reads values from a list of fields. + ## Fields | Field | Type | Required | Description | | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `mode` | [models.PipelineFunctionMetricsExportMode2](../models/pipelinefunctionmetricsexportmode2.md) | :heavy_check_mark: | Discriminator value. | -| `fields` | List[[models.NameFieldType](../models/namefieldtype.md)] | :heavy_check_mark: | N/A | \ No newline at end of file +| `mode` | [models.PipelineFunctionMetricsExportMode2](../models/pipelinefunctionmetricsexportmode2.md) | :heavy_check_mark: | Type of label configuration. Always list. | +| `fields` | List[[models.NameFieldType](../models/namefieldtype.md)] | :heavy_check_mark: | Field references to attach as labels to each exported metric. | \ No newline at end of file diff --git a/docs/models/labelfieldsunion.md b/docs/models/labelfieldsunion.md index 3274d44d2..3aba4d86b 100644 --- a/docs/models/labelfieldsunion.md +++ b/docs/models/labelfieldsunion.md @@ -1,5 +1,7 @@ # LabelFieldsUnion +Field references to attach as labels to each exported metric. Specify one field or a list of fields. + ## Supported Types diff --git a/docs/models/lakedatasetsearchconfig.md b/docs/models/lakedatasetsearchconfig.md index fe8282380..05d5ff9e4 100644 --- a/docs/models/lakedatasetsearchconfig.md +++ b/docs/models/lakedatasetsearchconfig.md @@ -9,5 +9,6 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset search configuration. | | `metadata` | [Optional[models.DatasetMetadata]](../models/datasetmetadata.md) | :heavy_minus_sign: | N/A | | `path_filters` | List[[models.ObjectStorageFilter](../models/objectstoragefilter.md)] | :heavy_minus_sign: | Glob-to-Datatype mappings for the Lake bucket path. Used only for search execution v2. | +| `search_execution` | [Optional[models.SearchExecutionConfig]](../models/searchexecutionconfig.md) | :heavy_minus_sign: | N/A | | `search_version` | [Optional[models.SearchVersion]](../models/searchversion.md) | :heavy_minus_sign: | N/A | | `tags` | *Optional[str]* | :heavy_minus_sign: | Comma-separated tags for the Dataset search configuration. | \ No newline at end of file diff --git a/docs/models/localoverrides.md b/docs/models/localoverrides.md new file mode 100644 index 000000000..7099ecc6a --- /dev/null +++ b/docs/models/localoverrides.md @@ -0,0 +1,12 @@ +# LocalOverrides + +Instance-level tuning applied after the rule set is merged. Managed by Cribl Security; not intended for direct editing. + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | -------------------------------------------------------------------------- | +| `disabled` | List[*str*] | :heavy_minus_sign: | Rule IDs to silence entirely. | +| `field_overrides` | List[[models.FieldOverride](../models/fieldoverride.md)] | :heavy_minus_sign: | Patch scalar fields of a rule without copying its full definition. | +| `inline_rules` | List[[models.InlineRule](../models/inlinerule.md)] | :heavy_minus_sign: | Full rule definitions authored here rather than delivered with the corpus. | \ No newline at end of file diff --git a/docs/models/logininfo.md b/docs/models/logininfo.md index e1a4875e6..3d59b7b02 100644 --- a/docs/models/logininfo.md +++ b/docs/models/logininfo.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ------------------ | ------------------ | ------------------ | ------------------ | -| `password` | *str* | :heavy_check_mark: | N/A | -| `username` | *str* | :heavy_check_mark: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------- | ---------------------------------------- | ---------------------------------------- | ---------------------------------------- | +| `password` | *str* | :heavy_check_mark: | Password for the account. | +| `username` | *str* | :heavy_check_mark: | Username of the account to authenticate. | \ No newline at end of file diff --git a/docs/models/metadataitem.md b/docs/models/metadataitem.md new file mode 100644 index 000000000..460c8c178 --- /dev/null +++ b/docs/models/metadataitem.md @@ -0,0 +1,9 @@ +# MetadataItem + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------- | +| `name` | *str* | :heavy_check_mark: | Name of the metadata field. | +| `value` | *str* | :heavy_check_mark: | JavaScript expression to compute the metadata field's value, enclosed in quotes or backticks. Can evaluate to a constant. | \ No newline at end of file diff --git a/docs/models/metricsexportconfiguration.md b/docs/models/metricsexportconfiguration.md index 5863ae29c..a0d131a75 100644 --- a/docs/models/metricsexportconfiguration.md +++ b/docs/models/metricsexportconfiguration.md @@ -5,16 +5,16 @@ Configuration specific to the Pipeline Function. ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------- | -| `search_job_id` | *str* | :heavy_check_mark: | Id of the search job this function is running on. | -| `dataset` | *str* | :heavy_check_mark: | Id of the metrics dataset | -| `name_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | N/A | -| `time_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | N/A | -| `value_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | N/A | -| `type_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | N/A | -| `label_fields` | [Optional[models.LabelFieldsUnion]](../models/labelfieldsunion.md) | :heavy_minus_sign: | N/A | -| `tee` | *Optional[bool]* | :heavy_minus_sign: | Tee results to search. When set to true results will be shipped instead of stats | -| `flush_ms` | *Optional[float]* | :heavy_minus_sign: | How often stats are flushed in ms | -| `suppress_previews` | *Optional[bool]* | :heavy_minus_sign: | Disables generation of intermediate stats. When true stats will be emitted only on end | -| `__pydantic_extra__` | Dict[str, *Any*] | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------- | +| `search_job_id` | *str* | :heavy_check_mark: | Unique identifier for the Search Job that runs this Function. | +| `dataset` | *str* | :heavy_check_mark: | Unique identifier for the metrics Dataset. | +| `name_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | Reference to a field by its original text and parsed path segments. | +| `time_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | Reference to a field by its original text and parsed path segments. | +| `value_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | Reference to a field by its original text and parsed path segments. | +| `type_field` | [Optional[models.NameFieldType]](../models/namefieldtype.md) | :heavy_minus_sign: | Reference to a field by its original text and parsed path segments. | +| `label_fields` | [Optional[models.LabelFieldsUnion]](../models/labelfieldsunion.md) | :heavy_minus_sign: | Field references to attach as labels to each exported metric. Specify one field or a list of fields. | +| `tee` | *Optional[bool]* | :heavy_minus_sign: | If true, pass processed events to downstream Functions. If false, emit export statistics. | +| `flush_ms` | *Optional[float]* | :heavy_minus_sign: | Interval, in milliseconds, between export statistics updates. | +| `suppress_previews` | *Optional[bool]* | :heavy_minus_sign: | If true, emit export statistics only when processing completes. If false, emit periodic statistics. | +| `__pydantic_extra__` | Dict[str, *Any*] | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/namefieldtype.md b/docs/models/namefieldtype.md index fc00ddf4a..6b70c4f5c 100644 --- a/docs/models/namefieldtype.md +++ b/docs/models/namefieldtype.md @@ -1,9 +1,11 @@ # NameFieldType +Reference to a field by its original text and parsed path segments. + ## Fields -| Field | Type | Required | Description | -| -------------------------------------- | -------------------------------------- | -------------------------------------- | -------------------------------------- | -| `raw` | *str* | :heavy_check_mark: | N/A | -| `path` | List[[models.Path](../models/path.md)] | :heavy_check_mark: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------- | +| `raw` | *str* | :heavy_check_mark: | Field name or expression before parsing. | +| `path` | List[[models.Path](../models/path.md)] | :heavy_check_mark: | Path segments for the field name. For example, ["level1", "level2"] represents level1.level2. | \ No newline at end of file diff --git a/docs/models/notification.md b/docs/models/notification.md new file mode 100644 index 000000000..005d0c416 --- /dev/null +++ b/docs/models/notification.md @@ -0,0 +1,21 @@ +# Notification + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | +| `condition` | *str* | :heavy_check_mark: | The condition that triggers the Notification. Use GET /conditions for a list of supported condition values. | +| `conf` | Dict[str, *Any*] | :heavy_check_mark: | Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. Use GET /conditions/{id} to review the configuration for a specific condition. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Notification is disabled and the specified condition will not trigger it. | +| `group` | *Optional[str]* | :heavy_minus_sign: | The id of the Worker Group or Edge Fleet that the Notification applies to. | +| `id` | *str* | :heavy_check_mark: | Unique identifier. | +| `metadata` | List[[models.MetadataItem](../models/metadataitem.md)] | :heavy_minus_sign: | Metadata tags for the Notification. | +| `mode` | [Optional[models.NotificationMode]](../models/notificationmode.md) | :heavy_minus_sign: | N/A | +| `pack` | *Optional[str]* | :heavy_minus_sign: | The id of the Pack the Notification belongs to. Automatically populated and returned in responses. | +| `target_configs` | List[[models.NotificationTargetConfig](../models/notificationtargetconfig.md)] | :heavy_minus_sign: | Override settings to apply for each referenced Notification target. | +| `target_details` | List[[models.NotificationTargetDetails](../models/notificationtargetdetails.md)] | :heavy_minus_sign: | Additional details about referenced Notification targets. Optionally populated on request. | +| `targets` | List[*str*] | :heavy_check_mark: | List of the id values for the Notification targets to send the Notification to. | +| `template_target_pairs` | List[[models.NotificationTemplateTargetPair](../models/notificationtemplatetargetpair.md)] | :heavy_minus_sign: | If mode is direct, the key-value pairs that define the Notification templates and targets to use for sending Notifications. | \ No newline at end of file diff --git a/docs/models/notification1.md b/docs/models/notification1.md deleted file mode 100644 index 457b27cc1..000000000 --- a/docs/models/notification1.md +++ /dev/null @@ -1,18 +0,0 @@ -# Notification1 - - -## Fields - -| Field | Type | Required | Description | Example | -| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `mode` | [models.NotificationMode1](../models/notificationmode1.md) | :heavy_check_mark: | Notification mode: direct or policy-based | direct | -| `template_target_pairs` | List[[models.TemplateTargetPairConfFunctionConfSchemaNotificationPolicies](../models/templatetargetpairconffunctionconfschemanotificationpolicies.md)] | :heavy_check_mark: | Pairs of templates and targets for notification routing | | -| `id` | *str* | :heavy_check_mark: | Unique identifier for the Notification. | | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Notification is disabled and the specified condition will not trigger it. | | -| `condition` | *str* | :heavy_check_mark: | The condition that triggers the Notification. | | -| `targets` | List[*str*] | :heavy_minus_sign: | List of the IDs for the Notification targets to send the Notification to. | | -| `target_configs` | List[[models.TargetConfigUnion1](../models/targetconfigunion1.md)] | :heavy_minus_sign: | Override settings to apply for each referenced Notification target. | | -| `conf` | [Optional[models.ConditionSpecificConfigurations1]](../models/conditionspecificconfigurations1.md) | :heavy_minus_sign: | Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. | | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | -| `group` | *Optional[str]* | :heavy_minus_sign: | The worker group/fleet this notification belongs to | | -| `pack` | *Optional[str]* | :heavy_minus_sign: | The pack this notification belongs to | | \ No newline at end of file diff --git a/docs/models/notification2.md b/docs/models/notification2.md deleted file mode 100644 index 7b776d3b8..000000000 --- a/docs/models/notification2.md +++ /dev/null @@ -1,18 +0,0 @@ -# Notification2 - - -## Fields - -| Field | Type | Required | Description | Example | -| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `mode` | [models.NotificationMode2](../models/notificationmode2.md) | :heavy_check_mark: | Notification mode: direct or policy-based | direct | -| `template_target_pairs` | List[[models.TemplateTargetPairConfFunctionConfSchemaNotificationPolicies](../models/templatetargetpairconffunctionconfschemanotificationpolicies.md)] | :heavy_minus_sign: | Pairs of templates and targets for notification routing | | -| `id` | *str* | :heavy_check_mark: | Unique identifier for the Notification. | | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Notification is disabled and the specified condition will not trigger it. | | -| `condition` | *str* | :heavy_check_mark: | The condition that triggers the Notification. | | -| `targets` | List[*str*] | :heavy_minus_sign: | List of the IDs for the Notification targets to send the Notification to. | | -| `target_configs` | List[[models.TargetConfigUnion2](../models/targetconfigunion2.md)] | :heavy_minus_sign: | Override settings to apply for each referenced Notification target. | | -| `conf` | [Optional[models.ConditionSpecificConfigurations2]](../models/conditionspecificconfigurations2.md) | :heavy_minus_sign: | Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. | | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | -| `group` | *Optional[str]* | :heavy_minus_sign: | The worker group/fleet this notification belongs to | | -| `pack` | *Optional[str]* | :heavy_minus_sign: | The pack this notification belongs to | | \ No newline at end of file diff --git a/docs/models/notification3.md b/docs/models/notification3.md deleted file mode 100644 index aab73776b..000000000 --- a/docs/models/notification3.md +++ /dev/null @@ -1,18 +0,0 @@ -# Notification3 - - -## Fields - -| Field | Type | Required | Description | Example | -| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `mode` | [Optional[models.NotificationMode3]](../models/notificationmode3.md) | :heavy_minus_sign: | Notification mode: direct or policy-based | direct | -| `id` | *str* | :heavy_check_mark: | Unique identifier for the Notification. | | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Notification is disabled and the specified condition will not trigger it. | | -| `condition` | *str* | :heavy_check_mark: | The condition that triggers the Notification. | | -| `targets` | List[*str*] | :heavy_minus_sign: | List of the IDs for the Notification targets to send the Notification to. | | -| `target_configs` | List[[models.TargetConfigUnion3](../models/targetconfigunion3.md)] | :heavy_minus_sign: | Override settings to apply for each referenced Notification target. | | -| `conf` | [Optional[models.ConditionSpecificConfigurations3]](../models/conditionspecificconfigurations3.md) | :heavy_minus_sign: | Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. | | -| `metadata` | List[[models.MetadataConfInputCollection](../models/metadataconfinputcollection.md)] | :heavy_minus_sign: | Fields to add to events from this input | | -| `group` | *Optional[str]* | :heavy_minus_sign: | The worker group/fleet this notification belongs to | | -| `pack` | *Optional[str]* | :heavy_minus_sign: | The pack this notification belongs to | | -| `template_target_pairs` | List[[models.TemplateTargetPairConfFunctionConfSchemaNotificationPolicies](../models/templatetargetpairconffunctionconfschemanotificationpolicies.md)] | :heavy_minus_sign: | Pairs of templates and targets for notification routing | | \ No newline at end of file diff --git a/docs/models/notificationconfigforsmtptarget1.md b/docs/models/notificationconfigforsmtptarget1.md deleted file mode 100644 index 183f2995e..000000000 --- a/docs/models/notificationconfigforsmtptarget1.md +++ /dev/null @@ -1,12 +0,0 @@ -# NotificationConfigForSMTPTarget1 - -Simple Mail Transfer Protocol (SMTP) configuration for the Notification target. - - -## Fields - -| Field | Type | Required | Description | -| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | -| `subject` | *Optional[str]* | :heavy_minus_sign: | Email subject | -| `body` | *Optional[str]* | :heavy_minus_sign: | Email body | -| `email_recipient` | [Optional[models.EmailRecipient1]](../models/emailrecipient1.md) | :heavy_minus_sign: | Email recipient settings for the Notification target. | \ No newline at end of file diff --git a/docs/models/notificationconfigforsmtptarget2.md b/docs/models/notificationconfigforsmtptarget2.md deleted file mode 100644 index 05185f0cc..000000000 --- a/docs/models/notificationconfigforsmtptarget2.md +++ /dev/null @@ -1,12 +0,0 @@ -# NotificationConfigForSMTPTarget2 - -Simple Mail Transfer Protocol (SMTP) configuration for the Notification target. - - -## Fields - -| Field | Type | Required | Description | -| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | -| `subject` | *Optional[str]* | :heavy_minus_sign: | Email subject | -| `body` | *Optional[str]* | :heavy_minus_sign: | Email body | -| `email_recipient` | [Optional[models.EmailRecipient2]](../models/emailrecipient2.md) | :heavy_minus_sign: | Email recipient settings for the Notification target. | \ No newline at end of file diff --git a/docs/models/notificationconfigforsmtptarget3.md b/docs/models/notificationconfigforsmtptarget3.md deleted file mode 100644 index b3c8c325f..000000000 --- a/docs/models/notificationconfigforsmtptarget3.md +++ /dev/null @@ -1,12 +0,0 @@ -# NotificationConfigForSMTPTarget3 - -Simple Mail Transfer Protocol (SMTP) configuration for the Notification target. - - -## Fields - -| Field | Type | Required | Description | -| ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | ---------------------------------------------------------------- | -| `subject` | *Optional[str]* | :heavy_minus_sign: | Email subject | -| `body` | *Optional[str]* | :heavy_minus_sign: | Email body | -| `email_recipient` | [Optional[models.EmailRecipient3]](../models/emailrecipient3.md) | :heavy_minus_sign: | Email recipient settings for the Notification target. | \ No newline at end of file diff --git a/docs/models/notificationmode3.md b/docs/models/notificationmode.md similarity index 57% rename from docs/models/notificationmode3.md rename to docs/models/notificationmode.md index 6814d6856..f3e5af931 100644 --- a/docs/models/notificationmode3.md +++ b/docs/models/notificationmode.md @@ -1,13 +1,11 @@ -# NotificationMode3 - -Notification mode: direct or policy-based +# NotificationMode ## Example Usage ```python -from cribl_control_plane.models import NotificationMode3 +from cribl_control_plane.models import NotificationMode -value = NotificationMode3.DIRECT +value = NotificationMode.DIRECT # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/notificationmode1.md b/docs/models/notificationmode1.md deleted file mode 100644 index 85f5062a1..000000000 --- a/docs/models/notificationmode1.md +++ /dev/null @@ -1,21 +0,0 @@ -# NotificationMode1 - -Notification mode: direct or policy-based - -## Example Usage - -```python -from cribl_control_plane.models import NotificationMode1 - -value = NotificationMode1.DIRECT - -# Open enum: unrecognized values are captured as UnrecognizedStr -``` - - -## Values - -| Name | Value | -| -------- | -------- | -| `DIRECT` | direct | -| `POLICY` | policy | \ No newline at end of file diff --git a/docs/models/notificationmode2.md b/docs/models/notificationmode2.md deleted file mode 100644 index 43cfa6543..000000000 --- a/docs/models/notificationmode2.md +++ /dev/null @@ -1,21 +0,0 @@ -# NotificationMode2 - -Notification mode: direct or policy-based - -## Example Usage - -```python -from cribl_control_plane.models import NotificationMode2 - -value = NotificationMode2.DIRECT - -# Open enum: unrecognized values are captured as UnrecognizedStr -``` - - -## Values - -| Name | Value | -| -------- | -------- | -| `DIRECT` | direct | -| `POLICY` | policy | \ No newline at end of file diff --git a/docs/models/notificationsmtptargetconfig.md b/docs/models/notificationsmtptargetconfig.md new file mode 100644 index 000000000..06c105158 --- /dev/null +++ b/docs/models/notificationsmtptargetconfig.md @@ -0,0 +1,10 @@ +# NotificationSMTPTargetConfig + + +## Fields + +| Field | Type | Required | Description | +| ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | ---------------------------------------------------- | +| `body` | *Optional[str]* | :heavy_minus_sign: | Email body. | +| `email_recipient` | [models.EmailRecipient](../models/emailrecipient.md) | :heavy_check_mark: | N/A | +| `subject` | *Optional[str]* | :heavy_minus_sign: | Email subject. | \ No newline at end of file diff --git a/docs/models/notificationtargetconfig.md b/docs/models/notificationtargetconfig.md new file mode 100644 index 000000000..80c742f18 --- /dev/null +++ b/docs/models/notificationtargetconfig.md @@ -0,0 +1,9 @@ +# NotificationTargetConfig + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `conf` | [Optional[models.NotificationSMTPTargetConfig]](../models/notificationsmtptargetconfig.md) | :heavy_minus_sign: | N/A | +| `id` | *str* | :heavy_check_mark: | The id of the Notification target. | \ No newline at end of file diff --git a/docs/models/notificationtargetdetails.md b/docs/models/notificationtargetdetails.md new file mode 100644 index 000000000..cfb361563 --- /dev/null +++ b/docs/models/notificationtargetdetails.md @@ -0,0 +1,9 @@ +# NotificationTargetDetails + + +## Fields + +| Field | Type | Required | Description | +| ----------------------------------------------- | ----------------------------------------------- | ----------------------------------------------- | ----------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | The id of the Notification target. | +| `type` | *str* | :heavy_check_mark: | The type of the Notification target. | \ No newline at end of file diff --git a/docs/models/notificationtemplatetargetpair.md b/docs/models/notificationtemplatetargetpair.md new file mode 100644 index 000000000..07de5304d --- /dev/null +++ b/docs/models/notificationtemplatetargetpair.md @@ -0,0 +1,9 @@ +# NotificationTemplateTargetPair + + +## Fields + +| Field | Type | Required | Description | +| --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | +| `target_id` | *str* | :heavy_check_mark: | The id of the Notification target to send the Notification to. | +| `template_id` | *str* | :heavy_check_mark: | The id of the Notification template to use. | \ No newline at end of file diff --git a/docs/models/notificationunion.md b/docs/models/notificationunion.md deleted file mode 100644 index 3bc2e549c..000000000 --- a/docs/models/notificationunion.md +++ /dev/null @@ -1,23 +0,0 @@ -# NotificationUnion - - -## Supported Types - -### `models.Notification1` - -```python -value: models.Notification1 = /* values here */ -``` - -### `models.Notification2` - -```python -value: models.Notification2 = /* values here */ -``` - -### `models.Notification3` - -```python -value: models.Notification3 = /* values here */ -``` - diff --git a/docs/models/oauthsecretsource.md b/docs/models/oauthsecretsource.md new file mode 100644 index 000000000..a79a57098 --- /dev/null +++ b/docs/models/oauthsecretsource.md @@ -0,0 +1,21 @@ +# OAuthSecretSource + +Enter the OAuth secret directly, or select a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import OAuthSecretSource + +value = OAuthSecretSource.INLINE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `INLINE` | inline | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/origin.md b/docs/models/originoptionscriblsourceprovenance.md similarity index 63% rename from docs/models/origin.md rename to docs/models/originoptionscriblsourceprovenance.md index d171a7a6e..fe4e1c2f6 100644 --- a/docs/models/origin.md +++ b/docs/models/originoptionscriblsourceprovenance.md @@ -1,13 +1,13 @@ -# Origin +# OriginOptionsCriblSourceProvenance Feature that created the Source. ## Example Usage ```python -from cribl_control_plane.models import Origin +from cribl_control_plane.models import OriginOptionsCriblSourceProvenance -value = Origin.DATA_SOURCE_DISCOVERY +value = OriginOptionsCriblSourceProvenance.DATA_SOURCE_DISCOVERY # Open enum: unrecognized values are captured as UnrecognizedStr ``` diff --git a/docs/models/output.md b/docs/models/output.md index 845e8f95c..203cbd51b 100644 --- a/docs/models/output.md +++ b/docs/models/output.md @@ -423,6 +423,12 @@ value: models.OutputDynatraceHTTP = /* values here */ value: models.OutputDynatraceOtlp = /* values here */ ``` +### `models.OutputTraversalOtlp` + +```python +value: models.OutputTraversalOtlp = /* values here */ +``` + ### `models.OutputSentinelOneAiSiem` ```python @@ -507,3 +513,9 @@ value: models.OutputAlibabaCloudS3 = /* values here */ value: models.OutputIbmCloudS3 = /* values here */ ``` +### `models.OutputDatabricksZerobus` + +```python +value: models.OutputDatabricksZerobus = /* values here */ +``` + diff --git a/docs/models/outputcribllake.md b/docs/models/outputcribllake.md index 80bf4ef62..81477073b 100644 --- a/docs/models/outputcribllake.md +++ b/docs/models/outputcribllake.md @@ -34,6 +34,7 @@ | `dynamic_dataset` | *Optional[bool]* | :heavy_minus_sign: | N/A | | `max_closing_files_to_backpressure` | *Optional[float]* | :heavy_minus_sign: | N/A | | `max_concurrent_file_parts` | *Optional[float]* | :heavy_minus_sign: | N/A | +| `freshness_grace_period_sec` | *Optional[float]* | :heavy_minus_sign: | N/A | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `compress` | [Optional[models.CompressionOptionsHTTP]](../models/compressionoptionshttp.md) | :heavy_minus_sign: | Data compression format to apply to HTTP content before it is delivered | | `compression_level` | [Optional[models.CompressionLevelOptions]](../models/compressionleveloptions.md) | :heavy_minus_sign: | Compression level to apply before moving files to final destination | diff --git a/docs/models/outputcriblsearchengine.md b/docs/models/outputcriblsearchengine.md index 850e397d4..c83a8aea3 100644 --- a/docs/models/outputcriblsearchengine.md +++ b/docs/models/outputcriblsearchengine.md @@ -3,55 +3,56 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | -| `type` | [models.OutputCriblSearchEngineType](../models/outputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | -| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | -| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | -| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | -| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | -| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | -| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | -| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | -| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | -| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | -| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | -| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | -| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | -| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | -| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | -| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | -| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | -| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | -| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | -| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | -| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | -| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | -| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | -| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | -| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | -| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | -| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | -| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | -| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | -| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | -| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | -| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | -| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | -| `pq_controls` | [Optional[models.OutputCriblSearchEnginePqControls]](../models/outputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputCriblSearchEngineType](../models/outputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | +| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | +| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `send_as` | [Optional[models.SendAs]](../models/sendas.md) | :heavy_minus_sign: | Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | +| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | +| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | +| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | +| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.OutputCriblSearchEnginePqControls]](../models/outputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | \ No newline at end of file diff --git a/docs/models/outputcrowdstrikenextgensiem.md b/docs/models/outputcrowdstrikenextgensiem.md index 5054bcad2..47a17e304 100644 --- a/docs/models/outputcrowdstrikenextgensiem.md +++ b/docs/models/outputcrowdstrikenextgensiem.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/outputdatabrickszerobus.md b/docs/models/outputdatabrickszerobus.md new file mode 100644 index 000000000..dab4713f0 --- /dev/null +++ b/docs/models/outputdatabrickszerobus.md @@ -0,0 +1,42 @@ +# OutputDatabricksZerobus + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputDatabricksZerobusType](../models/outputdatabrickszerobustype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `workspace_url` | *str* | :heavy_check_mark: | HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https:// | +| `workspace_id` | *str* | :heavy_check_mark: | Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace. | +| `zerobus_endpoint` | *str* | :heavy_check_mark: | Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com). | +| `client_id` | *str* | :heavy_check_mark: | OAuth client ID of the service principal authorized to write to the target table | +| `client_text_secret` | *str* | :heavy_check_mark: | OAuth client secret of the service principal | +| `table_name` | *str* | :heavy_check_mark: | Three-part Unity Catalog name of the target table: catalog.schema.table | +| `max_batch_size_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of the serialized records in a single ingest batch | +| `max_batch_records` | *Optional[int]* | :heavy_minus_sign: | Maximum number of records to include in a single ingest batch | +| `max_buffered_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped. | +| `max_inflight_batches` | *Optional[int]* | :heavy_minus_sign: | Maximum number of unacknowledged batches per Worker Process before blocking | +| `flush_period_sec` | *Optional[int]* | :heavy_minus_sign: | Maximum time, in seconds, to hold a batch before sending it | +| `ack_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting | +| `connection_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a new ingest stream to open before canceling it | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.OutputDatabricksZerobusPqControls]](../models/outputdatabrickszerobuspqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file diff --git a/docs/models/outputdatabrickszerobuspqcontrols.md b/docs/models/outputdatabrickszerobuspqcontrols.md new file mode 100644 index 000000000..6f0a4a6e7 --- /dev/null +++ b/docs/models/outputdatabrickszerobuspqcontrols.md @@ -0,0 +1,9 @@ +# OutputDatabricksZerobusPqControls + +Persistent queue controls. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/outputdatabrickszerobustype.md b/docs/models/outputdatabrickszerobustype.md new file mode 100644 index 000000000..d83347f15 --- /dev/null +++ b/docs/models/outputdatabrickszerobustype.md @@ -0,0 +1,18 @@ +# OutputDatabricksZerobusType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import OutputDatabricksZerobusType + +value = OutputDatabricksZerobusType.DATABRICKS_ZEROBUS +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `DATABRICKS_ZEROBUS` | databricks_zerobus | \ No newline at end of file diff --git a/docs/models/outputexabeam.md b/docs/models/outputexabeam.md index 6a369d62d..42dc826ca 100644 --- a/docs/models/outputexabeam.md +++ b/docs/models/outputexabeam.md @@ -3,48 +3,54 @@ ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | -| `type` | [models.OutputExabeamType](../models/outputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | -| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | -| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | -| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | -| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | -| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | -| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | -| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | -| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | -| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | -| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | -| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | -| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | -| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | -| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | -| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | -| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | -| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| -| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | -| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | -| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | -| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | -| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | -| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | -| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | -| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | -| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | -| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | -| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputExabeamType](../models/outputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | +| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | +| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | +| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | +| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | +| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | +| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | +| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | +| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | +| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | +| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | +| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | +| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | +| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | +| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | +| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | +| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | +| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| +| `aws_authentication_method` | [Optional[models.OutputExabeamAuthenticationMethod]](../models/outputexabeamauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | +| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | +| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | +| `hostname` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the "hostname" metadata field; omitted when empty or not a usable scalar. | +| `forwarder` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the "forwarder" metadata field; omitted when empty or not a usable scalar. | +| `origin` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "origin" metadata field; omitted when the result is not a non-empty object. | +| `logtags` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "logtags" metadata field; omitted when the result is not a non-empty object. | +| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | +| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | +| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | +| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | +| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | +| `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | +| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | +| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | +| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | \ No newline at end of file diff --git a/docs/models/outputexabeamauthenticationmethod.md b/docs/models/outputexabeamauthenticationmethod.md new file mode 100644 index 000000000..e25130dce --- /dev/null +++ b/docs/models/outputexabeamauthenticationmethod.md @@ -0,0 +1,21 @@ +# OutputExabeamAuthenticationMethod + +Authentication method + +## Example Usage + +```python +from cribl_control_plane.models import OutputExabeamAuthenticationMethod + +value = OutputExabeamAuthenticationMethod.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/outputhumiohec.md b/docs/models/outputhumiohec.md index e99251b2c..7e4807547 100644 --- a/docs/models/outputhumiohec.md +++ b/docs/models/outputhumiohec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/outputresponse.md b/docs/models/outputresponse.md index 9116d260a..5f2405da3 100644 --- a/docs/models/outputresponse.md +++ b/docs/models/outputresponse.md @@ -425,6 +425,12 @@ value: models.OutputResponseOutputDynatraceHTTP = /* values here */ value: models.OutputResponseOutputDynatraceOtlp = /* values here */ ``` +### `models.OutputResponseOutputTraversalOtlp` + +```python +value: models.OutputResponseOutputTraversalOtlp = /* values here */ +``` + ### `models.OutputResponseOutputSentinelOneAiSiem` ```python @@ -509,3 +515,9 @@ value: models.OutputResponseOutputAlibabaCloudS3 = /* values here */ value: models.OutputResponseOutputIbmCloudS3 = /* values here */ ``` +### `models.OutputResponseOutputDatabricksZerobus` + +```python +value: models.OutputResponseOutputDatabricksZerobus = /* values here */ +``` + diff --git a/docs/models/outputresponseauthtoken.md b/docs/models/outputresponseauthtoken.md index 9eb8b5c05..898b25d93 100644 --- a/docs/models/outputresponseauthtoken.md +++ b/docs/models/outputresponseauthtoken.md @@ -3,8 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | -| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/outputresponseeventformat.md b/docs/models/outputresponseeventformat.md new file mode 100644 index 000000000..5605d53a6 --- /dev/null +++ b/docs/models/outputresponseeventformat.md @@ -0,0 +1,21 @@ +# OutputResponseEventFormat + +The format of the VPC Flow Log events + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseEventFormat + +value = OutputResponseEventFormat.JSON + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `JSON` | json | +| `CSV_ROW` | csv_row | \ No newline at end of file diff --git a/docs/models/outputresponseindexerdiscoveryconfigs.md b/docs/models/outputresponseindexerdiscoveryconfigs.md index 9f5a1ca0f..ba05d3cea 100644 --- a/docs/models/outputresponseindexerdiscoveryconfigs.md +++ b/docs/models/outputresponseindexerdiscoveryconfigs.md @@ -12,6 +12,6 @@ List of configurations to set up indexer discovery in Splunk Indexer clustering | `refresh_interval_sec` | *float* | :heavy_check_mark: | Time interval, in seconds, between two consecutive indexer list fetches from cluster manager | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates. | | `auth_tokens` | List[[models.OutputResponseAuthToken](../models/outputresponseauthtoken.md)] | :heavy_minus_sign: | Tokens required to authenticate to cluster manager for indexer discovery | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/outputresponseoauthsecretsource.md b/docs/models/outputresponseoauthsecretsource.md new file mode 100644 index 000000000..272ad5de3 --- /dev/null +++ b/docs/models/outputresponseoauthsecretsource.md @@ -0,0 +1,21 @@ +# OutputResponseOAuthSecretSource + +Enter the OAuth secret directly, or select a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseOAuthSecretSource + +value = OutputResponseOAuthSecretSource.INLINE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `INLINE` | inline | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/outputresponseoutputalibabaclouds3.md b/docs/models/outputresponseoutputalibabaclouds3.md index 8bfd9011f..ff7b92880 100644 --- a/docs/models/outputresponseoutputalibabaclouds3.md +++ b/docs/models/outputresponseoutputalibabaclouds3.md @@ -77,5 +77,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputalphasocs3.md b/docs/models/outputresponseoutputalphasocs3.md index dc65cf502..9ae10a974 100644 --- a/docs/models/outputresponseoutputalphasocs3.md +++ b/docs/models/outputresponseoutputalphasocs3.md @@ -68,5 +68,5 @@ | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputamazonmanagedprometheus.md b/docs/models/outputresponseoutputamazonmanagedprometheus.md index 1144b2e73..f48b1412f 100644 --- a/docs/models/outputresponseoutputamazonmanagedprometheus.md +++ b/docs/models/outputresponseoutputamazonmanagedprometheus.md @@ -60,5 +60,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputazureblob.md b/docs/models/outputresponseoutputazureblob.md index 2f6b8f8d2..6f33aa04d 100644 --- a/docs/models/outputresponseoutputazureblob.md +++ b/docs/models/outputresponseoutputazureblob.md @@ -78,5 +78,5 @@ | `template_tenant_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime. | | `template_azure_cloud` | *Optional[str]* | :heavy_minus_sign: | Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputazuredataexplorer.md b/docs/models/outputresponseoutputazuredataexplorer.md index 0804825de..7d1a8ba76 100644 --- a/docs/models/outputresponseoutputazuredataexplorer.md +++ b/docs/models/outputresponseoutputazuredataexplorer.md @@ -108,5 +108,5 @@ | `template_ingest_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_file_name_suffix` | *Optional[str]* | :heavy_minus_sign: | Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputazureeventhub.md b/docs/models/outputresponseoutputazureeventhub.md index 7a37798b4..1c6420aba 100644 --- a/docs/models/outputresponseoutputazureeventhub.md +++ b/docs/models/outputresponseoutputazureeventhub.md @@ -47,5 +47,5 @@ | `template_topic` | *Optional[str]* | :heavy_minus_sign: | Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime. | | `template_format` | *Optional[str]* | :heavy_minus_sign: | Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputazurelogs.md b/docs/models/outputresponseoutputazurelogs.md index ab1308f02..4ea2209b1 100644 --- a/docs/models/outputresponseoutputazurelogs.md +++ b/docs/models/outputresponseoutputazurelogs.md @@ -52,5 +52,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_workspace_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime. | | `template_workspace_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputchronicle.md b/docs/models/outputresponseoutputchronicle.md index a103b28bd..d00bd937d 100644 --- a/docs/models/outputresponseoutputchronicle.md +++ b/docs/models/outputresponseoutputchronicle.md @@ -64,5 +64,5 @@ | `template_gcp_project_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'gcpProjectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpProjectId' at runtime. | | `template_gcp_instance` | *Optional[str]* | :heavy_minus_sign: | Binds 'gcpInstance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpInstance' at runtime. | | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputclickhouse.md b/docs/models/outputresponseoutputclickhouse.md index d7fa1ab94..dfae8edcf 100644 --- a/docs/models/outputresponseoutputclickhouse.md +++ b/docs/models/outputresponseoutputclickhouse.md @@ -64,5 +64,5 @@ | `template_table_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcloudflarer2.md b/docs/models/outputresponseoutputcloudflarer2.md index 2e33a01c5..f5197bbf6 100644 --- a/docs/models/outputresponseoutputcloudflarer2.md +++ b/docs/models/outputresponseoutputcloudflarer2.md @@ -74,5 +74,5 @@ | `template_server_side_encryption` | *Optional[str]* | :heavy_minus_sign: | Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcloudians3.md b/docs/models/outputresponseoutputcloudians3.md index 42ec0225e..e99797ed7 100644 --- a/docs/models/outputresponseoutputcloudians3.md +++ b/docs/models/outputresponseoutputcloudians3.md @@ -79,5 +79,5 @@ | `template_kms_key_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcloudwatch.md b/docs/models/outputresponseoutputcloudwatch.md index 7455bfce6..a3b19be83 100644 --- a/docs/models/outputresponseoutputcloudwatch.md +++ b/docs/models/outputresponseoutputcloudwatch.md @@ -52,5 +52,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputconfluentcloud.md b/docs/models/outputresponseoutputconfluentcloud.md index 26446881f..59d491100 100644 --- a/docs/models/outputresponseoutputconfluentcloud.md +++ b/docs/models/outputresponseoutputconfluentcloud.md @@ -52,5 +52,5 @@ | `template_format` | *Optional[str]* | :heavy_minus_sign: | Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime. | | `template_compression` | *Optional[str]* | :heavy_minus_sign: | Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcriblhttp.md b/docs/models/outputresponseoutputcriblhttp.md index 1796aae12..f95b3d996 100644 --- a/docs/models/outputresponseoutputcriblhttp.md +++ b/docs/models/outputresponseoutputcriblhttp.md @@ -55,5 +55,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcribllake.md b/docs/models/outputresponseoutputcribllake.md index 61a5b7d85..29f694711 100644 --- a/docs/models/outputresponseoutputcribllake.md +++ b/docs/models/outputresponseoutputcribllake.md @@ -34,6 +34,7 @@ | `dynamic_dataset` | *Optional[bool]* | :heavy_minus_sign: | N/A | | `max_closing_files_to_backpressure` | *Optional[float]* | :heavy_minus_sign: | N/A | | `max_concurrent_file_parts` | *Optional[float]* | :heavy_minus_sign: | N/A | +| `freshness_grace_period_sec` | *Optional[float]* | :heavy_minus_sign: | N/A | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `compress` | [Optional[models.CompressionOptionsHTTP]](../models/compressionoptionshttp.md) | :heavy_minus_sign: | Data compression format to apply to HTTP content before it is delivered | | `compression_level` | [Optional[models.CompressionLevelOptions]](../models/compressionleveloptions.md) | :heavy_minus_sign: | Compression level to apply before moving files to final destination | @@ -59,5 +60,5 @@ | `template_dest_path` | *Optional[str]* | :heavy_minus_sign: | Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcriblsearchengine.md b/docs/models/outputresponseoutputcriblsearchengine.md index 1b575f43f..7905c818e 100644 --- a/docs/models/outputresponseoutputcriblsearchengine.md +++ b/docs/models/outputresponseoutputcriblsearchengine.md @@ -3,57 +3,58 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | -| `type` | [models.OutputResponseOutputCriblSearchEngineType](../models/outputresponseoutputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | -| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | -| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | -| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | -| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | -| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | -| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | -| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | -| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | -| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | -| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | -| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | -| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | -| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | -| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | -| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | -| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | -| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | -| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | -| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | -| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | -| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | -| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | -| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | -| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | -| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | -| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | -| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | -| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | -| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | -| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | -| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | -| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | -| `pq_controls` | [Optional[models.OutputResponseOutputCriblSearchEnginePqControls]](../models/outputresponseoutputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | -| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputResponseOutputCriblSearchEngineType](../models/outputresponseoutputcriblsearchenginetype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `load_balanced` | *Optional[bool]* | :heavy_minus_sign: | For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeCaPathCertPath]](../models/tlssettingsclientsidetypecapathcertpath.md) | :heavy_minus_sign: | TLS settings (client side) | +| `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60. | +| `exclude_fields` | List[*str*] | :heavy_minus_sign: | Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported. | +| `compression` | [Optional[models.CompressionOptionsGzipNone]](../models/compressionoptionsgzipnone.md) | :heavy_minus_sign: | Codec to use to compress the data before sending | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `max_payload_events` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to include in the request body. Default is 0 (unlimited). | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `throttle_rate_per_sec` | *Optional[str]* | :heavy_minus_sign: | Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling. | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `auth_tokens` | List[[models.AuthTokenConfOutputCriblHTTP](../models/authtokenconfoutputcriblhttp.md)] | :heavy_minus_sign: | Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `send_as` | [Optional[models.OutputResponseSendAs]](../models/outputresponsesendas.md) | :heavy_minus_sign: | Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `url` | *Optional[str]* | :heavy_minus_sign: | URL of a Cribl Worker to send events to, such as http://localhost:10200 | +| `exclude_self` | *Optional[bool]* | :heavy_minus_sign: | Exclude all IPs of the current host from the list of any resolved hostnames | +| `urls` | List[[models.URLConfOutputCriblHTTP](../models/urlconfoutputcriblhttp.md)] | :heavy_minus_sign: | Cribl Worker endpoints | +| `dns_resolve_period_sec` | *Optional[float]* | :heavy_minus_sign: | The interval in which to re-resolve any hostnames and pick up destinations from A records | +| `load_balance_stats_period_sec` | *Optional[float]* | :heavy_minus_sign: | How far back in time to keep traffic stats for load balancing purposes | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.OutputResponseOutputCriblSearchEnginePqControls]](../models/outputresponseoutputcriblsearchenginepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcribltcp.md b/docs/models/outputresponseoutputcribltcp.md index b7300d13c..9aa0c9e53 100644 --- a/docs/models/outputresponseoutputcribltcp.md +++ b/docs/models/outputresponseoutputcribltcp.md @@ -46,5 +46,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcrowdstrikenextgensiem.md b/docs/models/outputresponseoutputcrowdstrikenextgensiem.md index 3717ed575..a33eab1e9 100644 --- a/docs/models/outputresponseoutputcrowdstrikenextgensiem.md +++ b/docs/models/outputresponseoutputcrowdstrikenextgensiem.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | @@ -49,5 +49,5 @@ | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputcustomermetricsstorage.md b/docs/models/outputresponseoutputcustomermetricsstorage.md index 57fd39973..52c07593e 100644 --- a/docs/models/outputresponseoutputcustomermetricsstorage.md +++ b/docs/models/outputresponseoutputcustomermetricsstorage.md @@ -64,5 +64,5 @@ | `template_table_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdatabricks.md b/docs/models/outputresponseoutputdatabricks.md index cb7e5cf56..03315914d 100644 --- a/docs/models/outputresponseoutputdatabricks.md +++ b/docs/models/outputresponseoutputdatabricks.md @@ -66,5 +66,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdatabrickszerobus.md b/docs/models/outputresponseoutputdatabrickszerobus.md new file mode 100644 index 000000000..b5b8f75ec --- /dev/null +++ b/docs/models/outputresponseoutputdatabrickszerobus.md @@ -0,0 +1,44 @@ +# OutputResponseOutputDatabricksZerobus + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputResponseOutputDatabricksZerobusType](../models/outputresponseoutputdatabrickszerobustype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `workspace_url` | *str* | :heavy_check_mark: | HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https:// | +| `workspace_id` | *str* | :heavy_check_mark: | Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace. | +| `zerobus_endpoint` | *str* | :heavy_check_mark: | Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com). | +| `client_id` | *str* | :heavy_check_mark: | OAuth client ID of the service principal authorized to write to the target table | +| `client_text_secret` | *str* | :heavy_check_mark: | OAuth client secret of the service principal | +| `table_name` | *str* | :heavy_check_mark: | Three-part Unity Catalog name of the target table: catalog.schema.table | +| `max_batch_size_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of the serialized records in a single ingest batch | +| `max_batch_records` | *Optional[int]* | :heavy_minus_sign: | Maximum number of records to include in a single ingest batch | +| `max_buffered_kb` | *Optional[int]* | :heavy_minus_sign: | Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped. | +| `max_inflight_batches` | *Optional[int]* | :heavy_minus_sign: | Maximum number of unacknowledged batches per Worker Process before blocking | +| `flush_period_sec` | *Optional[int]* | :heavy_minus_sign: | Maximum time, in seconds, to hold a batch before sending it | +| `ack_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting | +| `connection_timeout_sec` | *Optional[int]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a new ingest stream to open before canceling it | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.OutputResponseOutputDatabricksZerobusPqControls]](../models/outputresponseoutputdatabrickszerobuspqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdatabrickszerobuspqcontrols.md b/docs/models/outputresponseoutputdatabrickszerobuspqcontrols.md new file mode 100644 index 000000000..623930e09 --- /dev/null +++ b/docs/models/outputresponseoutputdatabrickszerobuspqcontrols.md @@ -0,0 +1,9 @@ +# OutputResponseOutputDatabricksZerobusPqControls + +Persistent queue controls. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdatabrickszerobustype.md b/docs/models/outputresponseoutputdatabrickszerobustype.md new file mode 100644 index 000000000..f1b795707 --- /dev/null +++ b/docs/models/outputresponseoutputdatabrickszerobustype.md @@ -0,0 +1,18 @@ +# OutputResponseOutputDatabricksZerobusType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseOutputDatabricksZerobusType + +value = OutputResponseOutputDatabricksZerobusType.DATABRICKS_ZEROBUS +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `DATABRICKS_ZEROBUS` | databricks_zerobus | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdatadog.md b/docs/models/outputresponseoutputdatadog.md index 81a567125..71216449c 100644 --- a/docs/models/outputresponseoutputdatadog.md +++ b/docs/models/outputresponseoutputdatadog.md @@ -60,5 +60,5 @@ | `template_tags` | *Optional[str]* | :heavy_minus_sign: | Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdataset.md b/docs/models/outputresponseoutputdataset.md index db12ff707..0623f5f91 100644 --- a/docs/models/outputresponseoutputdataset.md +++ b/docs/models/outputresponseoutputdataset.md @@ -55,5 +55,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_custom_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdefault.md b/docs/models/outputresponseoutputdefault.md index 89b683376..bef06fd06 100644 --- a/docs/models/outputresponseoutputdefault.md +++ b/docs/models/outputresponseoutputdefault.md @@ -13,5 +13,5 @@ | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | | `default_id` | *Nullable[str]* | :heavy_check_mark: | ID of the default output. This will be used whenever a nonexistent/deleted output is referenced. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdells3.md b/docs/models/outputresponseoutputdells3.md index 687621b86..692151b57 100644 --- a/docs/models/outputresponseoutputdells3.md +++ b/docs/models/outputresponseoutputdells3.md @@ -73,5 +73,5 @@ | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdevnull.md b/docs/models/outputresponseoutputdevnull.md index 2fdc1cb63..7ba852e74 100644 --- a/docs/models/outputresponseoutputdevnull.md +++ b/docs/models/outputresponseoutputdevnull.md @@ -12,5 +12,5 @@ | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdiskspool.md b/docs/models/outputresponseoutputdiskspool.md index ce26ec480..b95cd75f9 100644 --- a/docs/models/outputresponseoutputdiskspool.md +++ b/docs/models/outputresponseoutputdiskspool.md @@ -18,5 +18,5 @@ | `partition_expr` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory. | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdls3.md b/docs/models/outputresponseoutputdls3.md index 57d3f05b1..3440f7a53 100644 --- a/docs/models/outputresponseoutputdls3.md +++ b/docs/models/outputresponseoutputdls3.md @@ -89,5 +89,5 @@ | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdynatracehttp.md b/docs/models/outputresponseoutputdynatracehttp.md index 973d97394..99fa0dc1c 100644 --- a/docs/models/outputresponseoutputdynatracehttp.md +++ b/docs/models/outputresponseoutputdynatracehttp.md @@ -56,5 +56,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputdynatraceotlp.md b/docs/models/outputresponseoutputdynatraceotlp.md index 941784fa6..5cad45b2e 100644 --- a/docs/models/outputresponseoutputdynatraceotlp.md +++ b/docs/models/outputresponseoutputdynatraceotlp.md @@ -59,5 +59,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputelastic.md b/docs/models/outputresponseoutputelastic.md index fb2890d1b..1593fff1a 100644 --- a/docs/models/outputresponseoutputelastic.md +++ b/docs/models/outputresponseoutputelastic.md @@ -62,5 +62,5 @@ | `template_elastic_pipeline` | *Optional[str]* | :heavy_minus_sign: | Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputelasticcloud.md b/docs/models/outputresponseoutputelasticcloud.md index e87ec8942..69d66b855 100644 --- a/docs/models/outputresponseoutputelasticcloud.md +++ b/docs/models/outputresponseoutputelasticcloud.md @@ -51,5 +51,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_elastic_pipeline` | *Optional[str]* | :heavy_minus_sign: | Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputexabeam.md b/docs/models/outputresponseoutputexabeam.md index 3c7c87558..54ac2d665 100644 --- a/docs/models/outputresponseoutputexabeam.md +++ b/docs/models/outputresponseoutputexabeam.md @@ -3,50 +3,56 @@ ## Fields -| Field | Type | Required | Description | -| --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | -| `type` | [models.OutputResponseOutputExabeamType](../models/outputresponseoutputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | -| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | -| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | -| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | -| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | -| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | -| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | -| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | -| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | -| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | -| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | -| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | -| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | -| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | -| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | -| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | -| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | -| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | -| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | -| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| -| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | -| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | -| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | -| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | -| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | -| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | -| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | -| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | -| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | -| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | -| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | -| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | -| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputResponseOutputExabeamType](../models/outputresponseoutputexabeamtype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `bucket` | *str* | :heavy_check_mark: | Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`. | +| `region` | *str* | :heavy_check_mark: | Region where the bucket is located | +| `stage_path` | *str* | :heavy_check_mark: | Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage. | +| `endpoint` | *str* | :heavy_check_mark: | Google Cloud Storage service endpoint | +| `object_acl` | [Optional[models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol]](../models/objectacloptionsauthenticatedreadbucketownerfullcontrol.md) | :heavy_minus_sign: | Object ACL to assign to uploaded objects | +| `storage_class` | [Optional[models.StorageClassOptionsArchiveColdline]](../models/storageclassoptionsarchivecoldline.md) | :heavy_minus_sign: | Storage class to select for uploaded objects | +| `reuse_connections` | *Optional[bool]* | :heavy_minus_sign: | Reuse connections between requests, which can improve performance | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates that cannot be verified against a valid CA, such as self-signed certificates | +| `add_id_to_stage_path` | *Optional[bool]* | :heavy_minus_sign: | Add the Output ID value to staging location | +| `remove_empty_dirs` | *Optional[bool]* | :heavy_minus_sign: | Remove empty staging directories after moving files | +| `max_file_open_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location. | +| `max_file_idle_time_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location. | +| `max_open_files` | *Optional[float]* | :heavy_minus_sign: | Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location. | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptionsBlockDrop]](../models/backpressurebehavioroptionsblockdrop.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `deadletter_enabled` | *Optional[bool]* | :heavy_minus_sign: | If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors | +| `on_disk_full_backpressure` | [Optional[models.DiskSpaceProtectionOptions]](../models/diskspaceprotectionoptions.md) | :heavy_minus_sign: | How to handle events when disk space is below the global 'Min free disk space' limit | +| `retry_settings` | [Optional[models.RetrySettingsType]](../models/retrysettingstype.md) | :heavy_minus_sign: | N/A | +| `orphans` | [Optional[models.OrphanFileRecoveryType]](../models/orphanfilerecoverytype.md) | :heavy_minus_sign: | Orphan file recovery | +| `max_file_size_mb` | *Optional[float]* | :heavy_minus_sign: | Maximum uncompressed output file size. Files of this size will be closed and moved to final output location. | +| `encoded_configuration` | *Optional[str]* | :heavy_minus_sign: | Enter an encoded string containing Exabeam configurations | +| `collector_instance_id` | *str* | :heavy_check_mark: | ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888
| +| `aws_authentication_method` | [Optional[models.OutputResponseOutputExabeamAuthenticationMethod]](../models/outputresponseoutputexabeamauthenticationmethod.md) | :heavy_minus_sign: | Authentication method | +| `site_name` | *Optional[str]* | :heavy_minus_sign: | Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants. | +| `site_id` | *Optional[str]* | :heavy_minus_sign: | Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name. | +| `timezone_offset` | *Optional[str]* | :heavy_minus_sign: | Timezone offset | +| `hostname` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the "hostname" metadata field; omitted when empty or not a usable scalar. | +| `forwarder` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the "forwarder" metadata field; omitted when empty or not a usable scalar. | +| `origin` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "origin" metadata field; omitted when the result is not a non-empty object. | +| `logtags` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the "logtags" metadata field; omitted when the result is not a non-empty object. | +| `aws_api_key` | *Optional[str]* | :heavy_minus_sign: | HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`. | +| `aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `empty_dir_cleanup_sec` | *Optional[float]* | :heavy_minus_sign: | How frequently, in seconds, to clean up empty directories | +| `directory_batch_size` | *Optional[float]* | :heavy_minus_sign: | Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory. | +| `deadletter_path` | *Optional[str]* | :heavy_minus_sign: | Storage location for files that fail to reach their final destination after maximum retries are exceeded | +| `max_retry_num` | *Optional[float]* | :heavy_minus_sign: | The maximum number of times a file will attempt to move to its final destination before being dead-lettered | +| `aws_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored secret that references your access key and secret key | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | +| `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | +| `template_object_acl` | *Optional[str]* | :heavy_minus_sign: | Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime. | +| `template_storage_class` | *Optional[str]* | :heavy_minus_sign: | Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputexabeamauthenticationmethod.md b/docs/models/outputresponseoutputexabeamauthenticationmethod.md new file mode 100644 index 000000000..aaaedbc8b --- /dev/null +++ b/docs/models/outputresponseoutputexabeamauthenticationmethod.md @@ -0,0 +1,21 @@ +# OutputResponseOutputExabeamAuthenticationMethod + +Authentication method + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseOutputExabeamAuthenticationMethod + +value = OutputResponseOutputExabeamAuthenticationMethod.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/outputresponseoutputfilesystem.md b/docs/models/outputresponseoutputfilesystem.md index 2564baf0a..d334e41c8 100644 --- a/docs/models/outputresponseoutputfilesystem.md +++ b/docs/models/outputresponseoutputfilesystem.md @@ -57,5 +57,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgooglebigquery.md b/docs/models/outputresponseoutputgooglebigquery.md index 04c49f1f8..2ffd8ae8a 100644 --- a/docs/models/outputresponseoutputgooglebigquery.md +++ b/docs/models/outputresponseoutputgooglebigquery.md @@ -41,5 +41,5 @@ | `template_dataset_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime. | | `template_table_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgooglechronicle.md b/docs/models/outputresponseoutputgooglechronicle.md index 3e77629bc..e6a3fd57a 100644 --- a/docs/models/outputresponseoutputgooglechronicle.md +++ b/docs/models/outputresponseoutputgooglechronicle.md @@ -62,5 +62,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_customer_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgooglecloudlogging.md b/docs/models/outputresponseoutputgooglecloudlogging.md index d9fe2c33d..a2a5aa220 100644 --- a/docs/models/outputresponseoutputgooglecloudlogging.md +++ b/docs/models/outputresponseoutputgooglecloudlogging.md @@ -88,5 +88,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_log_location_expression` | *Optional[str]* | :heavy_minus_sign: | Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime. | | `template_payload_expression` | *Optional[str]* | :heavy_minus_sign: | Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgooglecloudobservability.md b/docs/models/outputresponseoutputgooglecloudobservability.md index 16148f1f4..88d0903a7 100644 --- a/docs/models/outputresponseoutputgooglecloudobservability.md +++ b/docs/models/outputresponseoutputgooglecloudobservability.md @@ -47,5 +47,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgooglecloudstorage.md b/docs/models/outputresponseoutputgooglecloudstorage.md index 30037b361..f1892cc12 100644 --- a/docs/models/outputresponseoutputgooglecloudstorage.md +++ b/docs/models/outputresponseoutputgooglecloudstorage.md @@ -77,5 +77,5 @@ | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | | `template_aws_secret_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgooglepubsub.md b/docs/models/outputresponseoutputgooglepubsub.md index 37d1b271a..92d247381 100644 --- a/docs/models/outputresponseoutputgooglepubsub.md +++ b/docs/models/outputresponseoutputgooglepubsub.md @@ -42,5 +42,5 @@ | `template_topic_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime. | | `template_region` | *Optional[str]* | :heavy_minus_sign: | Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgrafanacloudgrafanacloud1.md b/docs/models/outputresponseoutputgrafanacloudgrafanacloud1.md index 907f2fa9f..4a8ea51b8 100644 --- a/docs/models/outputresponseoutputgrafanacloudgrafanacloud1.md +++ b/docs/models/outputresponseoutputgrafanacloudgrafanacloud1.md @@ -53,5 +53,5 @@ | `template_prometheus_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgrafanacloudgrafanacloud2.md b/docs/models/outputresponseoutputgrafanacloudgrafanacloud2.md index 63cc32cb1..9cbd3d41c 100644 --- a/docs/models/outputresponseoutputgrafanacloudgrafanacloud2.md +++ b/docs/models/outputresponseoutputgrafanacloudgrafanacloud2.md @@ -53,5 +53,5 @@ | `template_prometheus_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputgraphite.md b/docs/models/outputresponseoutputgraphite.md index e06a2bace..b8b9eb6bb 100644 --- a/docs/models/outputresponseoutputgraphite.md +++ b/docs/models/outputresponseoutputgraphite.md @@ -36,5 +36,5 @@ | `pq_controls` | [Optional[models.OutputResponseOutputGraphitePqControls]](../models/outputresponseoutputgraphitepqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputhoneycomb.md b/docs/models/outputresponseoutputhoneycomb.md index b83fb2f64..ed89a9184 100644 --- a/docs/models/outputresponseoutputhoneycomb.md +++ b/docs/models/outputresponseoutputhoneycomb.md @@ -47,5 +47,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputhumiohec.md b/docs/models/outputresponseoutputhumiohec.md index e598893a6..d4810ebfd 100644 --- a/docs/models/outputresponseoutputhumiohec.md +++ b/docs/models/outputresponseoutputhumiohec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `format_` | [models.RequestFormatOptions](../models/requestformatoptions.md) | :heavy_check_mark: | When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | @@ -49,5 +49,5 @@ | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputibmclouds3.md b/docs/models/outputresponseoutputibmclouds3.md index 945e8b663..71ecd052c 100644 --- a/docs/models/outputresponseoutputibmclouds3.md +++ b/docs/models/outputresponseoutputibmclouds3.md @@ -69,5 +69,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputinfluxdb.md b/docs/models/outputresponseoutputinfluxdb.md index b9ef4b4fc..4a43d6a03 100644 --- a/docs/models/outputresponseoutputinfluxdb.md +++ b/docs/models/outputresponseoutputinfluxdb.md @@ -60,5 +60,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_database` | *Optional[str]* | :heavy_minus_sign: | Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime. | | `template_bucket` | *Optional[str]* | :heavy_minus_sign: | Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputkafka.md b/docs/models/outputresponseoutputkafka.md index b45c7bc04..18c677c6f 100644 --- a/docs/models/outputresponseoutputkafka.md +++ b/docs/models/outputresponseoutputkafka.md @@ -51,5 +51,5 @@ | `template_format` | *Optional[str]* | :heavy_minus_sign: | Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime. | | `template_compression` | *Optional[str]* | :heavy_minus_sign: | Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputkinesis.md b/docs/models/outputresponseoutputkinesis.md index 2cf1eaf6d..75f62d15e 100644 --- a/docs/models/outputresponseoutputkinesis.md +++ b/docs/models/outputresponseoutputkinesis.md @@ -54,5 +54,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputlocalsearchstorage.md b/docs/models/outputresponseoutputlocalsearchstorage.md index a76cd3c78..f221914ce 100644 --- a/docs/models/outputresponseoutputlocalsearchstorage.md +++ b/docs/models/outputresponseoutputlocalsearchstorage.md @@ -65,5 +65,5 @@ | `template_table_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputloki.md b/docs/models/outputresponseoutputloki.md index 42523fa79..23303a3cf 100644 --- a/docs/models/outputresponseoutputloki.md +++ b/docs/models/outputresponseoutputloki.md @@ -55,5 +55,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputmicrosoftfabric.md b/docs/models/outputresponseoutputmicrosoftfabric.md index ab8792440..5a7f91fd2 100644 --- a/docs/models/outputresponseoutputmicrosoftfabric.md +++ b/docs/models/outputresponseoutputmicrosoftfabric.md @@ -47,5 +47,5 @@ | `template_format` | *Optional[str]* | :heavy_minus_sign: | Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_bootstrap_server` | *Optional[str]* | :heavy_minus_sign: | Binds 'bootstrap_server' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bootstrap_server' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputminio.md b/docs/models/outputresponseoutputminio.md index dbf94f720..1a4e87033 100644 --- a/docs/models/outputresponseoutputminio.md +++ b/docs/models/outputresponseoutputminio.md @@ -80,5 +80,5 @@ | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputmsk.md b/docs/models/outputresponseoutputmsk.md index 592250761..b018dcfc3 100644 --- a/docs/models/outputresponseoutputmsk.md +++ b/docs/models/outputresponseoutputmsk.md @@ -68,5 +68,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputnetflow.md b/docs/models/outputresponseoutputnetflow.md index cf8006684..2bfb60ef9 100644 --- a/docs/models/outputresponseoutputnetflow.md +++ b/docs/models/outputresponseoutputnetflow.md @@ -17,5 +17,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_record_size` | *Optional[float]* | :heavy_minus_sign: | MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputnewrelic.md b/docs/models/outputresponseoutputnewrelic.md index 40f53f0a5..060a27cb3 100644 --- a/docs/models/outputresponseoutputnewrelic.md +++ b/docs/models/outputresponseoutputnewrelic.md @@ -55,5 +55,5 @@ | `template_message_field` | *Optional[str]* | :heavy_minus_sign: | Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputnewrelicevents.md b/docs/models/outputresponseoutputnewrelicevents.md index e73cfbb63..8514ec003 100644 --- a/docs/models/outputresponseoutputnewrelicevents.md +++ b/docs/models/outputresponseoutputnewrelicevents.md @@ -54,5 +54,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_custom_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputnutanixobjects.md b/docs/models/outputresponseoutputnutanixobjects.md index b2607c742..ed1aa5507 100644 --- a/docs/models/outputresponseoutputnutanixobjects.md +++ b/docs/models/outputresponseoutputnutanixobjects.md @@ -71,5 +71,5 @@ | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputopentelemetry.md b/docs/models/outputresponseoutputopentelemetry.md index 4b887031c..ed45b7355 100644 --- a/docs/models/outputresponseoutputopentelemetry.md +++ b/docs/models/outputresponseoutputopentelemetry.md @@ -72,5 +72,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputprometheus.md b/docs/models/outputresponseoutputprometheus.md index 3229139b8..e8b196554 100644 --- a/docs/models/outputresponseoutputprometheus.md +++ b/docs/models/outputresponseoutputprometheus.md @@ -66,5 +66,5 @@ | `template_aws_service` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime. | | `template_assume_role_arn` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime. | | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputring.md b/docs/models/outputresponseoutputring.md index e22596d19..8ae330d91 100644 --- a/docs/models/outputresponseoutputring.md +++ b/docs/models/outputresponseoutputring.md @@ -21,5 +21,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputrouter.md b/docs/models/outputresponseoutputrouter.md index 428d40f41..1245ccae7 100644 --- a/docs/models/outputresponseoutputrouter.md +++ b/docs/models/outputresponseoutputrouter.md @@ -3,16 +3,17 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | -| `type` | [models.OutputResponseOutputRouterType](../models/outputresponseoutputroutertype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `rules` | List[[models.OutputResponseRule](../models/outputresponserule.md)] | :heavy_check_mark: | Event routing rules | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | -| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputResponseOutputRouterType](../models/outputresponseoutputroutertype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `report_branch_metrics` | *Optional[bool]* | :heavy_minus_sign: | Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule. | +| `rules` | List[[models.OutputResponseRule](../models/outputresponserule.md)] | :heavy_check_mark: | Event routing rules | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputs3.md b/docs/models/outputresponseoutputs3.md index f4f47a3fe..5d25c3e18 100644 --- a/docs/models/outputresponseoutputs3.md +++ b/docs/models/outputresponseoutputs3.md @@ -89,5 +89,5 @@ | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputscalitys3.md b/docs/models/outputresponseoutputscalitys3.md index 0c5f1baf8..58f8a9225 100644 --- a/docs/models/outputresponseoutputscalitys3.md +++ b/docs/models/outputresponseoutputscalitys3.md @@ -71,5 +71,5 @@ | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsecuritylake.md b/docs/models/outputresponseoutputsecuritylake.md index 36ecd6b2a..589b7be97 100644 --- a/docs/models/outputresponseoutputsecuritylake.md +++ b/docs/models/outputresponseoutputsecuritylake.md @@ -82,5 +82,5 @@ | `template_custom_source` | *Optional[str]* | :heavy_minus_sign: | Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsentinel.md b/docs/models/outputresponseoutputsentinel.md index a14233b82..10dfcbd19 100644 --- a/docs/models/outputresponseoutputsentinel.md +++ b/docs/models/outputresponseoutputsentinel.md @@ -30,11 +30,11 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `auth_type` | [Optional[models.OutputResponseAuthType]](../models/outputresponseauthtype.md) | :heavy_minus_sign: | Discriminator value. | | `login_url` | *str* | :heavy_check_mark: | URL for OAuth | -| `secret` | *str* | :heavy_check_mark: | Secret parameter value to pass in request body | | `refresh_token_field` | *Optional[str]* | :heavy_minus_sign: | Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials. | | `rotate_refresh_token` | *Optional[bool]* | :heavy_minus_sign: | @{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use. | | `refresh_url` | *Optional[str]* | :heavy_minus_sign: | Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL. | | `refresh_request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_minus_sign: | Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret. | +| `oauth_secret_source` | [Optional[models.OutputResponseOAuthSecretSource]](../models/outputresponseoauthsecretsource.md) | :heavy_minus_sign: | Enter the OAuth secret directly, or select a stored text secret | | `client_id` | *str* | :heavy_check_mark: | JavaScript expression to compute the Client ID for the Azure application. Can be a constant. | | `scope` | *Optional[str]* | :heavy_minus_sign: | Scope to pass in the OAuth request | | `endpoint_url_configuration` | [models.OutputResponseEndpointConfiguration](../models/outputresponseendpointconfiguration.md) | :heavy_check_mark: | Enter the data collection endpoint URL or the individual ID | @@ -61,6 +61,8 @@ | `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | | `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | | `pq_controls` | [Optional[models.OutputResponseOutputSentinelPqControls]](../models/outputresponseoutputsentinelpqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `secret` | *Optional[str]* | :heavy_minus_sign: | Secret parameter value to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret value | | `url` | *Optional[str]* | :heavy_minus_sign: | URL to send events to. Can be overwritten by an event's __url field. | | `dcr_id` | *Optional[str]* | :heavy_minus_sign: | Immutable ID for the Data Collection Rule (DCR) | | `dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com` | @@ -69,13 +71,13 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | -| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_refresh_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime. | | `template_scope` | *Optional[str]* | :heavy_minus_sign: | Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime. | +| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | | `template_dcr_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime. | | `template_dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime. | | `template_stream_name` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsentineloneaisiem.md b/docs/models/outputresponseoutputsentineloneaisiem.md index f3934170c..b12085622 100644 --- a/docs/models/outputresponseoutputsentineloneaisiem.md +++ b/docs/models/outputresponseoutputsentineloneaisiem.md @@ -22,7 +22,7 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | @@ -62,5 +62,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputservicenow.md b/docs/models/outputresponseoutputservicenow.md index 869f75d1d..29473674f 100644 --- a/docs/models/outputresponseoutputservicenow.md +++ b/docs/models/outputresponseoutputservicenow.md @@ -59,5 +59,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsignalfx.md b/docs/models/outputresponseoutputsignalfx.md index 9d4bf3470..f5fb69109 100644 --- a/docs/models/outputresponseoutputsignalfx.md +++ b/docs/models/outputresponseoutputsignalfx.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `realm` | *str* | :heavy_check_mark: | SignalFx realm name, e.g. "us0". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions). | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | @@ -47,5 +47,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsnmp.md b/docs/models/outputresponseoutputsnmp.md index c46f92ecf..6f5607c67 100644 --- a/docs/models/outputresponseoutputsnmp.md +++ b/docs/models/outputresponseoutputsnmp.md @@ -17,5 +17,5 @@ | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_record_size` | *Optional[float]* | :heavy_minus_sign: | MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsnowflakestreaming.md b/docs/models/outputresponseoutputsnowflakestreaming.md index 370642a54..7389869dd 100644 --- a/docs/models/outputresponseoutputsnowflakestreaming.md +++ b/docs/models/outputresponseoutputsnowflakestreaming.md @@ -59,5 +59,5 @@ | `template_role` | *Optional[str]* | :heavy_minus_sign: | Binds 'role' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'role' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsns.md b/docs/models/outputresponseoutputsns.md index 40173121d..f8db641be 100644 --- a/docs/models/outputresponseoutputsns.md +++ b/docs/models/outputresponseoutputsns.md @@ -50,5 +50,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsplunk.md b/docs/models/outputresponseoutputsplunk.md index 85538ed09..7a0a0953c 100644 --- a/docs/models/outputresponseoutputsplunk.md +++ b/docs/models/outputresponseoutputsplunk.md @@ -23,7 +23,7 @@ | `log_failed_requests` | *Optional[bool]* | :heavy_minus_sign: | Use to troubleshoot issues with sending data | | `max_s2_sversion` | [Optional[models.MaxS2SVersionOptions]](../models/maxs2sversionoptions.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | @@ -48,5 +48,5 @@ | `template_max_s2_sversion` | *Optional[str]* | :heavy_minus_sign: | Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsplunkhec.md b/docs/models/outputresponseoutputsplunkhec.md index 19ab92d11..d6a423671 100644 --- a/docs/models/outputresponseoutputsplunkhec.md +++ b/docs/models/outputresponseoutputsplunkhec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `enable_multi_metrics` | *Optional[bool]* | :heavy_minus_sign: | Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | @@ -57,5 +57,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsplunklb.md b/docs/models/outputresponseoutputsplunklb.md index 6adf2fed2..9972a9b99 100644 --- a/docs/models/outputresponseoutputsplunklb.md +++ b/docs/models/outputresponseoutputsplunklb.md @@ -26,7 +26,7 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `indexer_discovery` | *Optional[bool]* | :heavy_minus_sign: | Automatically discover indexers in indexer clustering environment. | | `sender_unhealthy_time_allowance` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | @@ -52,5 +52,5 @@ | `template_max_s2_sversion` | *Optional[str]* | :heavy_minus_sign: | Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsqs.md b/docs/models/outputresponseoutputsqs.md index 98abfe1ba..6a84cc3d5 100644 --- a/docs/models/outputresponseoutputsqs.md +++ b/docs/models/outputresponseoutputsqs.md @@ -58,5 +58,5 @@ | `template_assume_role_external_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_aws_api_key` | *Optional[str]* | :heavy_minus_sign: | Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputstatsd.md b/docs/models/outputresponseoutputstatsd.md index ab5903176..8e5d8b139 100644 --- a/docs/models/outputresponseoutputstatsd.md +++ b/docs/models/outputresponseoutputstatsd.md @@ -36,5 +36,5 @@ | `pq_controls` | [Optional[models.OutputResponseOutputStatsdPqControls]](../models/outputresponseoutputstatsdpqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputstatsdext.md b/docs/models/outputresponseoutputstatsdext.md index 2d2526a2a..70d3c80fa 100644 --- a/docs/models/outputresponseoutputstatsdext.md +++ b/docs/models/outputresponseoutputstatsdext.md @@ -36,5 +36,5 @@ | `pq_controls` | [Optional[models.OutputResponseOutputStatsdExtPqControls]](../models/outputresponseoutputstatsdextpqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputstorjs3.md b/docs/models/outputresponseoutputstorjs3.md index 506c1147c..9fcdc2857 100644 --- a/docs/models/outputresponseoutputstorjs3.md +++ b/docs/models/outputresponseoutputstorjs3.md @@ -69,5 +69,5 @@ | `template_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime. | | `template_compress` | *Optional[str]* | :heavy_minus_sign: | Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime. | | `template_parquet_schema` | *Optional[str]* | :heavy_minus_sign: | Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsumologic.md b/docs/models/outputresponseoutputsumologic.md index c5fc7c24a..2dfa4e193 100644 --- a/docs/models/outputresponseoutputsumologic.md +++ b/docs/models/outputresponseoutputsumologic.md @@ -49,5 +49,5 @@ | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputsyslog.md b/docs/models/outputresponseoutputsyslog.md index ed6044e81..433462ffc 100644 --- a/docs/models/outputresponseoutputsyslog.md +++ b/docs/models/outputresponseoutputsyslog.md @@ -52,5 +52,5 @@ | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputtcpjson.md b/docs/models/outputresponseoutputtcpjson.md index 9731bc1a5..4154e5734 100644 --- a/docs/models/outputresponseoutputtcpjson.md +++ b/docs/models/outputresponseoutputtcpjson.md @@ -21,7 +21,7 @@ | `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires, valid values between 1 and 60 | | `send_header` | *Optional[bool]* | :heavy_minus_sign: | Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | The hostname of the receiver | | `port` | *Optional[float]* | :heavy_minus_sign: | The port to connect to on the provided host | @@ -48,5 +48,5 @@ | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_host` | *Optional[str]* | :heavy_minus_sign: | Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime. | | `template_port` | *Optional[str]* | :heavy_minus_sign: | Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputtraversalotlp.md b/docs/models/outputresponseoutputtraversalotlp.md new file mode 100644 index 000000000..f2e094d2e --- /dev/null +++ b/docs/models/outputresponseoutputtraversalotlp.md @@ -0,0 +1,70 @@ +# OutputResponseOutputTraversalOtlp + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputResponseOutputTraversalOtlpType](../models/outputresponseoutputtraversalotlptype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `auth_type` | [Optional[models.OutputResponseOutputTraversalOtlpAuthenticationType]](../models/outputresponseoutputtraversalotlpauthenticationtype.md) | :heavy_minus_sign: | Authentication type | +| `endpoint` | *str* | :heavy_check_mark: | The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). | +| `protocol` | [Optional[models.ProtocolOptions]](../models/protocoloptions.md) | :heavy_minus_sign: | Select a transport option for OpenTelemetry | +| `preserve_native_any_value` | *Optional[bool]* | :heavy_minus_sign: | Values already in OTLP AnyValue form (e.g. {string_value: "..."}) are serialized directly instead of being wrapped as key-value maps | +| `compress` | [Optional[models.CompressionOptionsDeflateGzip]](../models/compressionoptionsdeflategzip.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_compress` | [Optional[models.CompressionOptionsMessages]](../models/compressionoptionsmessages.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_logs_endpoint_override` | *Optional[str]* | :heavy_minus_sign: | If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint | +| `metadata` | List[[models.KeyValueMetadataConfOutputFilesystem](../models/keyvaluemetadataconfoutputfilesystem.md)] | :heavy_minus_sign: | List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'. | +| `dynamic_headers_enabled` | *Optional[bool]* | :heavy_minus_sign: | Batch event data upon dynamic metadata (whether presented or not) | +| `dynamic_headers_field` | *Optional[str]* | :heavy_minus_sign: | When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events. | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `connection_timeout` | *Optional[float]* | :heavy_minus_sign: | Amount of time (milliseconds) to wait for the connection to establish before retrying | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often the sender should ping the peer to keep the connection open | +| `keep_alive` | *Optional[bool]* | :heavy_minus_sign: | Disable to close the connection immediately after sending the outgoing request | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `login_url` | *Optional[str]* | :heavy_minus_sign: | URL for OAuth | +| `secret_param_name` | *Optional[str]* | :heavy_minus_sign: | Secret parameter name to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret parameter value to pass in request body | +| `token_attribute_name` | *Optional[str]* | :heavy_minus_sign: | Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token'). | +| `auth_header_expr` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`. | +| `token_timeout_secs` | *Optional[float]* | :heavy_minus_sign: | How often the OAuth token should be refreshed. | +| `oauth_params` | List[[models.OauthParamConfInputServicenowTable](../models/oauthparamconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `oauth_headers` | List[[models.OauthHeaderConfInputServicenowTable](../models/oauthheaderconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeExtended]](../models/tlssettingsclientsidetypeextended.md) | :heavy_minus_sign: | TLS settings (client side) | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.OutputResponseOutputTraversalOtlpPqControls]](../models/outputresponseoutputtraversalotlppqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputtraversalotlpauthenticationtype.md b/docs/models/outputresponseoutputtraversalotlpauthenticationtype.md new file mode 100644 index 000000000..a9ff65f78 --- /dev/null +++ b/docs/models/outputresponseoutputtraversalotlpauthenticationtype.md @@ -0,0 +1,23 @@ +# OutputResponseOutputTraversalOtlpAuthenticationType + +Authentication type + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseOutputTraversalOtlpAuthenticationType + +value = OutputResponseOutputTraversalOtlpAuthenticationType.NONE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `NONE` | none | +| `CREDENTIALS_SECRET` | credentialsSecret | +| `TEXT_SECRET` | textSecret | +| `OAUTH_SECRET` | oauthSecret | \ No newline at end of file diff --git a/docs/models/outputresponseoutputtraversalotlppqcontrols.md b/docs/models/outputresponseoutputtraversalotlppqcontrols.md new file mode 100644 index 000000000..ff40f6875 --- /dev/null +++ b/docs/models/outputresponseoutputtraversalotlppqcontrols.md @@ -0,0 +1,9 @@ +# OutputResponseOutputTraversalOtlpPqControls + +Persistent queue controls. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/outputresponseoutputtraversalotlptype.md b/docs/models/outputresponseoutputtraversalotlptype.md new file mode 100644 index 000000000..936083853 --- /dev/null +++ b/docs/models/outputresponseoutputtraversalotlptype.md @@ -0,0 +1,18 @@ +# OutputResponseOutputTraversalOtlpType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseOutputTraversalOtlpType + +value = OutputResponseOutputTraversalOtlpType.TRAVERSAL_OTLP +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `TRAVERSAL_OTLP` | traversal_otlp | \ No newline at end of file diff --git a/docs/models/outputresponseoutputwavefront.md b/docs/models/outputresponseoutputwavefront.md index d2de4ca2b..7868f5821 100644 --- a/docs/models/outputresponseoutputwavefront.md +++ b/docs/models/outputresponseoutputwavefront.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `domain` | *str* | :heavy_check_mark: | WaveFront domain name, e.g. "longboard" | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | @@ -47,5 +47,5 @@ | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputwebhookwebhook1.md b/docs/models/outputresponseoutputwebhookwebhook1.md index 64469e339..ae85e6003 100644 --- a/docs/models/outputresponseoutputwebhookwebhook1.md +++ b/docs/models/outputresponseoutputwebhookwebhook1.md @@ -84,5 +84,5 @@ | `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_refresh_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputwebhookwebhook2.md b/docs/models/outputresponseoutputwebhookwebhook2.md index 90f1270d3..d1924230e 100644 --- a/docs/models/outputresponseoutputwebhookwebhook2.md +++ b/docs/models/outputresponseoutputwebhookwebhook2.md @@ -84,5 +84,5 @@ | `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_refresh_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputwizhec.md b/docs/models/outputresponseoutputwizhec.md index e6753f1fe..e1cefc8f3 100644 --- a/docs/models/outputresponseoutputwizhec.md +++ b/docs/models/outputresponseoutputwizhec.md @@ -23,18 +23,20 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | | `wiz_connector_id` | *str* | :heavy_check_mark: | The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration. | | `wiz_environment` | *str* | :heavy_check_mark: | Your Wiz deployment environment | | `data_center` | *str* | :heavy_check_mark: | Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console. | -| `wiz_sourcetype` | *str* | :heavy_check_mark: | Wiz Defend Source type | +| `wiz_sourcetype` | [models.OutputResponseWizDefendSourceType](../models/outputresponsewizdefendsourcetype.md) | :heavy_check_mark: | The Wiz log source type. Select a predefined type or enter a custom value. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `token` | *Optional[str]* | :heavy_minus_sign: | Wiz Defend Auth token | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `wiz_vpc_event_format` | [Optional[models.OutputResponseEventFormat]](../models/outputresponseeventformat.md) | :heavy_minus_sign: | The format of the VPC Flow Log events | +| `wiz_vpc_flow_log_format` | *Optional[str]* | :heavy_minus_sign: | The format string for VPC Flow Log fields | | `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | | `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | | `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | @@ -53,5 +55,5 @@ | `template_data_center` | *Optional[str]* | :heavy_minus_sign: | Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime. | | `template_wiz_sourcetype` | *Optional[str]* | :heavy_minus_sign: | Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponseoutputxsiam.md b/docs/models/outputresponseoutputxsiam.md index 58ddf4c69..c05efc7a1 100644 --- a/docs/models/outputresponseoutputxsiam.md +++ b/docs/models/outputresponseoutputxsiam.md @@ -55,5 +55,5 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notifications attached to the Destination. | | `status` | [Optional[models.StatusType]](../models/statustype.md) | :heavy_minus_sign: | Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable. | \ No newline at end of file diff --git a/docs/models/outputresponsesendas.md b/docs/models/outputresponsesendas.md new file mode 100644 index 000000000..e1e66333d --- /dev/null +++ b/docs/models/outputresponsesendas.md @@ -0,0 +1,22 @@ +# OutputResponseSendAs + +Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseSendAs + +value = OutputResponseSendAs.LOGS + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `LOGS` | logs | +| `METRICS` | metrics | +| `BOTH` | both | \ No newline at end of file diff --git a/docs/models/outputresponsewizdefendsourcetype.md b/docs/models/outputresponsewizdefendsourcetype.md new file mode 100644 index 000000000..440b99dc2 --- /dev/null +++ b/docs/models/outputresponsewizdefendsourcetype.md @@ -0,0 +1,27 @@ +# OutputResponseWizDefendSourceType + +The Wiz log source type. Select a predefined type or enter a custom value. + +## Example Usage + +```python +from cribl_control_plane.models import OutputResponseWizDefendSourceType + +value = OutputResponseWizDefendSourceType.AWS_CLOUDTRAIL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------------- | ------------------------- | +| `AWS_CLOUDTRAIL` | AWS_CLOUDTRAIL | +| `AWS_EKS_AUDIT_LOGS` | AWS_EKS_AUDIT_LOGS | +| `AWS_RESOLVER_QUERY_LOGS` | AWS_RESOLVER_QUERY_LOGS | +| `AZURE_ACTIVITY_LOGS` | AZURE_ACTIVITY_LOGS | +| `GCP_AUDIT_LOGS` | GCP_AUDIT_LOGS | +| `GITHUB_AUDIT_LOGS` | GITHUB_AUDIT_LOGS | +| `OCI_AUDIT_LOGS` | OCI_AUDIT_LOGS | +| `AWS_VPC_FLOW_LOGS` | AWS_VPC_FLOW_LOGS | \ No newline at end of file diff --git a/docs/models/outputrouter.md b/docs/models/outputrouter.md index d67747c1a..a1826fb80 100644 --- a/docs/models/outputrouter.md +++ b/docs/models/outputrouter.md @@ -3,14 +3,15 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | -| `type` | [models.OutputRouterType](../models/outputroutertype.md) | :heavy_check_mark: | Connector type identifier. | -| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | -| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | -| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | -| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `rules` | List[[models.OutputRouterRule](../models/outputrouterrule.md)] | :heavy_check_mark: | Event routing rules | -| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | -| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputRouterType](../models/outputroutertype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `report_branch_metrics` | *Optional[bool]* | :heavy_minus_sign: | Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule. | +| `rules` | List[[models.OutputRouterRule](../models/outputrouterrule.md)] | :heavy_check_mark: | Event routing rules | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/outputsentinel.md b/docs/models/outputsentinel.md index 151a89c72..251d28bb5 100644 --- a/docs/models/outputsentinel.md +++ b/docs/models/outputsentinel.md @@ -30,11 +30,11 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `auth_type` | [Optional[models.AuthTypeEnum]](../models/authtypeenum.md) | :heavy_minus_sign: | Discriminator value. | | `login_url` | *str* | :heavy_check_mark: | URL for OAuth | -| `secret` | *str* | :heavy_check_mark: | Secret parameter value to pass in request body | | `refresh_token_field` | *Optional[str]* | :heavy_minus_sign: | Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials. | | `rotate_refresh_token` | *Optional[bool]* | :heavy_minus_sign: | @{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use. | | `refresh_url` | *Optional[str]* | :heavy_minus_sign: | Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL. | | `refresh_request_params` | List[[models.RefreshRequestParamConfHealthCheckAuthenticationOauthSecret](../models/refreshrequestparamconfhealthcheckauthenticationoauthsecret.md)] | :heavy_minus_sign: | Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret. | +| `oauth_secret_source` | [Optional[models.OAuthSecretSource]](../models/oauthsecretsource.md) | :heavy_minus_sign: | Enter the OAuth secret directly, or select a stored text secret | | `client_id` | *str* | :heavy_check_mark: | JavaScript expression to compute the Client ID for the Azure application. Can be a constant. | | `scope` | *Optional[str]* | :heavy_minus_sign: | Scope to pass in the OAuth request | | `endpoint_url_configuration` | [models.EndpointConfiguration](../models/endpointconfiguration.md) | :heavy_check_mark: | Enter the data collection endpoint URL or the individual ID | @@ -61,6 +61,8 @@ | `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | | `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | | `pq_controls` | [Optional[models.OutputSentinelPqControls]](../models/outputsentinelpqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `secret` | *Optional[str]* | :heavy_minus_sign: | Secret parameter value to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret value | | `url` | *Optional[str]* | :heavy_minus_sign: | URL to send events to. Can be overwritten by an event's __url field. | | `dcr_id` | *Optional[str]* | :heavy_minus_sign: | Immutable ID for the Data Collection Rule (DCR) | | `dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com` | @@ -69,10 +71,10 @@ | `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | | `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | | `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | -| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_refresh_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime. | | `template_client_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime. | | `template_scope` | *Optional[str]* | :heavy_minus_sign: | Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime. | +| `template_secret` | *Optional[str]* | :heavy_minus_sign: | Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime. | | `template_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime. | | `template_dcr_id` | *Optional[str]* | :heavy_minus_sign: | Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime. | | `template_dce_endpoint` | *Optional[str]* | :heavy_minus_sign: | Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime. | diff --git a/docs/models/outputsentineloneaisiem.md b/docs/models/outputsentineloneaisiem.md index 521ab4653..9403038f9 100644 --- a/docs/models/outputsentineloneaisiem.md +++ b/docs/models/outputsentineloneaisiem.md @@ -22,7 +22,7 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/outputsignalfx.md b/docs/models/outputsignalfx.md index 24973fe40..b88f09da8 100644 --- a/docs/models/outputsignalfx.md +++ b/docs/models/outputsignalfx.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `realm` | *str* | :heavy_check_mark: | SignalFx realm name, e.g. "us0". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions). | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | diff --git a/docs/models/outputsplunk.md b/docs/models/outputsplunk.md index 233f2d32d..2bd8a9078 100644 --- a/docs/models/outputsplunk.md +++ b/docs/models/outputsplunk.md @@ -23,7 +23,7 @@ | `log_failed_requests` | *Optional[bool]* | :heavy_minus_sign: | Use to troubleshoot issues with sending data | | `max_s2_sversion` | [Optional[models.MaxS2SVersionOptions]](../models/maxs2sversionoptions.md) | :heavy_minus_sign: | The highest S2S protocol version to advertise during handshake | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | diff --git a/docs/models/outputsplunkhec.md b/docs/models/outputsplunkhec.md index a15387406..b2b526e7a 100644 --- a/docs/models/outputsplunkhec.md +++ b/docs/models/outputsplunkhec.md @@ -25,7 +25,7 @@ | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | | `enable_multi_metrics` | *Optional[bool]* | :heavy_minus_sign: | Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | diff --git a/docs/models/outputsplunklb.md b/docs/models/outputsplunklb.md index caf473574..5e069f41c 100644 --- a/docs/models/outputsplunklb.md +++ b/docs/models/outputsplunklb.md @@ -26,7 +26,7 @@ | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `indexer_discovery` | *Optional[bool]* | :heavy_minus_sign: | Automatically discover indexers in indexer clustering environment. | | `sender_unhealthy_time_allowance` | *Optional[float]* | :heavy_minus_sign: | How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `max_failed_health_checks` | *Optional[float]* | :heavy_minus_sign: | Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur. | | `compress` | [Optional[models.CompressionOptions]](../models/compressionoptions.md) | :heavy_minus_sign: | Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data. | diff --git a/docs/models/outputsplunklbauthtoken.md b/docs/models/outputsplunklbauthtoken.md index 60ec480aa..527944158 100644 --- a/docs/models/outputsplunklbauthtoken.md +++ b/docs/models/outputsplunklbauthtoken.md @@ -3,8 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------- | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | -| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | -| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------- | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_token` | *Optional[str]* | :heavy_minus_sign: | Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted. | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | \ No newline at end of file diff --git a/docs/models/outputtcpjson.md b/docs/models/outputtcpjson.md index 25dd6d954..ddb49cad2 100644 --- a/docs/models/outputtcpjson.md +++ b/docs/models/outputtcpjson.md @@ -21,7 +21,7 @@ | `token_ttl_minutes` | *Optional[float]* | :heavy_minus_sign: | The number of minutes before the internally generated authentication token expires, valid values between 1 and 60 | | `send_header` | *Optional[bool]* | :heavy_minus_sign: | Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `host` | *Optional[str]* | :heavy_minus_sign: | The hostname of the receiver | | `port` | *Optional[float]* | :heavy_minus_sign: | The port to connect to on the provided host | diff --git a/docs/models/outputtraversalotlp.md b/docs/models/outputtraversalotlp.md new file mode 100644 index 000000000..a7608293f --- /dev/null +++ b/docs/models/outputtraversalotlp.md @@ -0,0 +1,68 @@ +# OutputTraversalOtlp + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique ID for this output | +| `type` | [models.OutputTraversalOtlpType](../models/outputtraversalotlptype.md) | :heavy_check_mark: | Connector type identifier. | +| `pipeline` | *Optional[str]* | :heavy_minus_sign: | Pipeline to process data before sending out to this output | +| `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | +| `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | +| `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | +| `auth_type` | [Optional[models.OutputTraversalOtlpAuthenticationType]](../models/outputtraversalotlpauthenticationtype.md) | :heavy_minus_sign: | Authentication type | +| `endpoint` | *str* | :heavy_check_mark: | The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). | +| `protocol` | [Optional[models.ProtocolOptions]](../models/protocoloptions.md) | :heavy_minus_sign: | Select a transport option for OpenTelemetry | +| `preserve_native_any_value` | *Optional[bool]* | :heavy_minus_sign: | Values already in OTLP AnyValue form (e.g. {string_value: "..."}) are serialized directly instead of being wrapped as key-value maps | +| `compress` | [Optional[models.CompressionOptionsDeflateGzip]](../models/compressionoptionsdeflategzip.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_compress` | [Optional[models.CompressionOptionsMessages]](../models/compressionoptionsmessages.md) | :heavy_minus_sign: | Type of compression to apply to messages sent to the OpenTelemetry endpoint | +| `http_logs_endpoint_override` | *Optional[str]* | :heavy_minus_sign: | If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint | +| `metadata` | List[[models.KeyValueMetadataConfOutputFilesystem](../models/keyvaluemetadataconfoutputfilesystem.md)] | :heavy_minus_sign: | List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'. | +| `dynamic_headers_enabled` | *Optional[bool]* | :heavy_minus_sign: | Batch event data upon dynamic metadata (whether presented or not) | +| `dynamic_headers_field` | *Optional[str]* | :heavy_minus_sign: | When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events. | +| `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | +| `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | +| `timeout_sec` | *Optional[float]* | :heavy_minus_sign: | Amount of time, in seconds, to wait for a request to complete before canceling it | +| `max_connection_reuse_sec` | *Optional[float]* | :heavy_minus_sign: | How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits. | +| `flush_period_sec` | *Optional[float]* | :heavy_minus_sign: | Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit. | +| `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | +| `connection_timeout` | *Optional[float]* | :heavy_minus_sign: | Amount of time (milliseconds) to wait for the connection to establish before retrying | +| `keep_alive_time` | *Optional[float]* | :heavy_minus_sign: | How often the sender should ping the peer to keep the connection open | +| `keep_alive` | *Optional[bool]* | :heavy_minus_sign: | Disable to close the connection immediately after sending the outgoing request | +| `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | +| `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a secret that references your credentials | +| `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `login_url` | *Optional[str]* | :heavy_minus_sign: | URL for OAuth | +| `secret_param_name` | *Optional[str]* | :heavy_minus_sign: | Secret parameter name to pass in request body | +| `oauth_text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret for the OAuth secret parameter value to pass in request body | +| `token_attribute_name` | *Optional[str]* | :heavy_minus_sign: | Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token'). | +| `auth_header_expr` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`. | +| `token_timeout_secs` | *Optional[float]* | :heavy_minus_sign: | How often the OAuth token should be refreshed. | +| `oauth_params` | List[[models.OauthParamConfInputServicenowTable](../models/oauthparamconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `oauth_headers` | List[[models.OauthHeaderConfInputServicenowTable](../models/oauthheaderconfinputservicenowtable.md)] | :heavy_minus_sign: | Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request. | +| `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's).
Enabled by default. When this setting is also present in TLS Settings (Client Side),
that value will take precedence. | +| `use_round_robin_dns` | *Optional[bool]* | :heavy_minus_sign: | Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations. | +| `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | +| `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | +| `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | +| `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | +| `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | +| `tls` | [Optional[models.TLSSettingsClientSideTypeExtended]](../models/tlssettingsclientsidetypeextended.md) | :heavy_minus_sign: | TLS settings (client side) | +| `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | +| `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | +| `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | +| `pq_max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead. | +| `pq_max_backpressure_sec` | *Optional[float]* | :heavy_minus_sign: | How long (in seconds) to wait for backpressure to resolve before engaging the queue | +| `pq_max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.) | +| `pq_max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | +| `pq_path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //. | +| `pq_compress` | [Optional[models.CompressionOptionsPq]](../models/compressionoptionspq.md) | :heavy_minus_sign: | Codec to use to compress the persisted data | +| `pq_on_backpressure` | [Optional[models.QueueFullBehaviorOptions]](../models/queuefullbehavioroptions.md) | :heavy_minus_sign: | How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged. | +| `pq_max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | +| `pq_controls` | [Optional[models.OutputTraversalOtlpPqControls]](../models/outputtraversalotlppqcontrols.md) | :heavy_minus_sign: | Persistent queue controls. | +| `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | +| `template_failed_request_logging_mode` | *Optional[str]* | :heavy_minus_sign: | Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime. | +| `template_on_backpressure` | *Optional[str]* | :heavy_minus_sign: | Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime. | +| `template_login_url` | *Optional[str]* | :heavy_minus_sign: | Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime. | \ No newline at end of file diff --git a/docs/models/outputtraversalotlpauthenticationtype.md b/docs/models/outputtraversalotlpauthenticationtype.md new file mode 100644 index 000000000..b633ce415 --- /dev/null +++ b/docs/models/outputtraversalotlpauthenticationtype.md @@ -0,0 +1,23 @@ +# OutputTraversalOtlpAuthenticationType + +Authentication type + +## Example Usage + +```python +from cribl_control_plane.models import OutputTraversalOtlpAuthenticationType + +value = OutputTraversalOtlpAuthenticationType.NONE + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------------------- | -------------------- | +| `NONE` | none | +| `CREDENTIALS_SECRET` | credentialsSecret | +| `TEXT_SECRET` | textSecret | +| `OAUTH_SECRET` | oauthSecret | \ No newline at end of file diff --git a/docs/models/outputtraversalotlppqcontrols.md b/docs/models/outputtraversalotlppqcontrols.md new file mode 100644 index 000000000..b83515547 --- /dev/null +++ b/docs/models/outputtraversalotlppqcontrols.md @@ -0,0 +1,9 @@ +# OutputTraversalOtlpPqControls + +Persistent queue controls. + + +## Fields + +| Field | Type | Required | Description | +| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/outputtraversalotlptype.md b/docs/models/outputtraversalotlptype.md new file mode 100644 index 000000000..eacc399a1 --- /dev/null +++ b/docs/models/outputtraversalotlptype.md @@ -0,0 +1,18 @@ +# OutputTraversalOtlpType + +Connector type identifier. + +## Example Usage + +```python +from cribl_control_plane.models import OutputTraversalOtlpType + +value = OutputTraversalOtlpType.TRAVERSAL_OTLP +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `TRAVERSAL_OTLP` | traversal_otlp | \ No newline at end of file diff --git a/docs/models/outputwavefront.md b/docs/models/outputwavefront.md index 7c979f2c9..57485f76e 100644 --- a/docs/models/outputwavefront.md +++ b/docs/models/outputwavefront.md @@ -11,7 +11,7 @@ | `system_fields` | List[*str*] | :heavy_minus_sign: | Fields to automatically add to events, such as cribl_pipe. Supports wildcards. | | `environment` | *Optional[str]* | :heavy_minus_sign: | Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere. | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `domain` | *str* | :heavy_check_mark: | WaveFront domain name, e.g. "longboard" | | `concurrency` | *Optional[float]* | :heavy_minus_sign: | Maximum number of ongoing requests before blocking | | `max_payload_size_kb` | *Optional[float]* | :heavy_minus_sign: | Maximum size, in KB, of the request body | diff --git a/docs/models/outputwizhec.md b/docs/models/outputwizhec.md index 5d500bc31..0f52d8367 100644 --- a/docs/models/outputwizhec.md +++ b/docs/models/outputwizhec.md @@ -23,18 +23,20 @@ | `extra_http_headers` | List[[models.ExtraHTTPHeaderConfInputElastic](../models/extrahttpheaderconfinputelastic.md)] | :heavy_minus_sign: | Headers to add to all events | | `failed_request_logging_mode` | [Optional[models.FailedRequestLoggingModeOptions]](../models/failedrequestloggingmodeoptions.md) | :heavy_minus_sign: | Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below. | | `safe_headers` | List[*str*] | :heavy_minus_sign: | List of headers that are safe to log in plain text | -| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensItems]](../models/authenticationmethodoptionsauthtokensitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | +| `auth_type` | [Optional[models.AuthenticationMethodOptionsAuthTokensExtItems]](../models/authenticationmethodoptionsauthtokensextitems.md) | :heavy_minus_sign: | Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate | | `response_retry_settings` | List[[models.ResponseRetrySettingConfOutputWebhook](../models/responseretrysettingconfoutputwebhook.md)] | :heavy_minus_sign: | Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable) | | `timeout_retry_settings` | [Optional[models.TimeoutRetrySettingsType]](../models/timeoutretrysettingstype.md) | :heavy_minus_sign: | N/A | | `response_honor_retry_after_header` | *Optional[bool]* | :heavy_minus_sign: | Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored. | | `wiz_connector_id` | *str* | :heavy_check_mark: | The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration. | | `wiz_environment` | *str* | :heavy_check_mark: | Your Wiz deployment environment | | `data_center` | *str* | :heavy_check_mark: | Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console. | -| `wiz_sourcetype` | *str* | :heavy_check_mark: | Wiz Defend Source type | +| `wiz_sourcetype` | [models.WizDefendSourceType](../models/wizdefendsourcetype.md) | :heavy_check_mark: | The Wiz log source type. Select a predefined type or enter a custom value. | | `on_backpressure` | [Optional[models.BackpressureBehaviorOptions]](../models/backpressurebehavioroptions.md) | :heavy_minus_sign: | How to handle events when all receivers are exerting backpressure | | `description` | *Optional[str]* | :heavy_minus_sign: | Optional description for this configuration. | | `token` | *Optional[str]* | :heavy_minus_sign: | Wiz Defend Auth token | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Select or create a stored text secret | +| `wiz_vpc_event_format` | [Optional[models.OutputWizHecEventFormat]](../models/outputwizheceventformat.md) | :heavy_minus_sign: | The format of the VPC Flow Log events | +| `wiz_vpc_flow_log_format` | *Optional[str]* | :heavy_minus_sign: | The format string for VPC Flow Log fields | | `pq_strict_ordering` | *Optional[bool]* | :heavy_minus_sign: | Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed. | | `pq_rate_per_sec` | *Optional[float]* | :heavy_minus_sign: | Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling. | | `pq_mode` | [Optional[models.ModeOptions]](../models/modeoptions.md) | :heavy_minus_sign: | In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem. | diff --git a/docs/models/outputwizheceventformat.md b/docs/models/outputwizheceventformat.md new file mode 100644 index 000000000..cc66eba3f --- /dev/null +++ b/docs/models/outputwizheceventformat.md @@ -0,0 +1,21 @@ +# OutputWizHecEventFormat + +The format of the VPC Flow Log events + +## Example Usage + +```python +from cribl_control_plane.models import OutputWizHecEventFormat + +value = OutputWizHecEventFormat.JSON + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `JSON` | json | +| `CSV_ROW` | csv_row | \ No newline at end of file diff --git a/docs/models/packinfo.md b/docs/models/packinfo.md index 2c59bd26f..c7269fc64 100644 --- a/docs/models/packinfo.md +++ b/docs/models/packinfo.md @@ -3,21 +3,23 @@ ## Fields -| Field | Type | Required | Description | Example | -| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | -| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | -| `collectors` | *Optional[float]* | :heavy_minus_sign: | Number of Collectors (saved jobs) configured within the Pack. | | -| `dependencies` | Dict[str, *str*] | :heavy_minus_sign: | Map of Pack dependency identifiers to their version constraints. | | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | -| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | -| `exports` | List[*str*] | :heavy_minus_sign: | List of entity IDs exported by this Pack and available for use outside the Pack context. | | -| `id` | *str* | :heavy_check_mark: | Unique identifier. | | -| `inputs` | *Optional[float]* | :heavy_minus_sign: | Number of Sources configured within the Pack. | | -| `is_disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Pack is disabled. Otherwise, false. | | -| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | -| `outputs` | *Optional[float]* | :heavy_minus_sign: | Number of Destinations configured within the Pack. | | -| `settings` | Dict[str, *Any*] | :heavy_minus_sign: | Pack-specific settings object. Contents vary by Pack. | | -| `source` | *str* | :heavy_check_mark: | Source of the Pack — a file path, URL, or Git URL from which the Pack was installed. | | -| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint that was applied when the Pack was installed. | | -| `tags` | [Optional[models.TagsTypePackInstallInfo]](../models/tagstypepackinstallinfo.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | -| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | \ No newline at end of file +| Field | Type | Required | Description | Example | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | | +| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | +| `collectors` | *Optional[float]* | :heavy_minus_sign: | Number of Collectors (saved jobs) configured within the Pack. | | +| `dependencies` | Dict[str, *str*] | :heavy_minus_sign: | Map of Pack dependency identifiers to their version constraints. | | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | +| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | +| `exports` | List[*str*] | :heavy_minus_sign: | List of entity IDs exported by this Pack and available for use outside the Pack context. | | +| `id` | *str* | :heavy_check_mark: | Unique identifier. | | +| `inputs` | *Optional[float]* | :heavy_minus_sign: | Number of Sources configured within the Pack. | | +| `is_disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Pack is disabled. Otherwise, false. | | +| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | +| `outputs` | *Optional[float]* | :heavy_minus_sign: | Number of Destinations configured within the Pack. | | +| `settings` | Dict[str, *Any*] | :heavy_minus_sign: | Pack-specific settings object. Contents vary by Pack. | | +| `source` | *str* | :heavy_check_mark: | Source of the Pack — a file path, URL, or Git URL from which the Pack was installed. | | +| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint that was applied when the Pack was installed. | | +| `tags` | [Optional[models.TagsTypePackInstallInfo]](../models/tagstypepackinstallinfo.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | +| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | \ No newline at end of file diff --git a/docs/models/packinstallinfo.md b/docs/models/packinstallinfo.md index 4fa94115e..f35fa4ad0 100644 --- a/docs/models/packinstallinfo.md +++ b/docs/models/packinstallinfo.md @@ -3,22 +3,24 @@ ## Fields -| Field | Type | Required | Description | Example | -| ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------- | -| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | -| `collectors` | *Optional[float]* | :heavy_minus_sign: | Number of Collectors (saved jobs) configured within the Pack. | | -| `dependencies` | Dict[str, *str*] | :heavy_minus_sign: | Map of Pack dependency identifiers to their version constraints. | | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | -| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | -| `exports` | List[*str*] | :heavy_minus_sign: | List of entity IDs exported by this Pack and available for use outside the Pack context. | | -| `id` | *str* | :heavy_check_mark: | Unique identifier. | | -| `inputs` | *Optional[float]* | :heavy_minus_sign: | Number of Sources configured within the Pack. | | -| `is_disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Pack is disabled. Otherwise, false. | | -| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | -| `outputs` | *Optional[float]* | :heavy_minus_sign: | Number of Destinations configured within the Pack. | | -| `settings` | Dict[str, *Any*] | :heavy_minus_sign: | Pack-specific settings object. Contents vary by Pack. | | -| `source` | *str* | :heavy_check_mark: | Source of the Pack — a file path, URL, or Git URL from which the Pack was installed. | | -| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint that was applied when the Pack was installed. | | -| `tags` | [Optional[models.TagsTypePackInstallInfo]](../models/tagstypepackinstallinfo.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | -| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | -| `warnings` | List[*str*] | :heavy_minus_sign: | N/A | | \ No newline at end of file +| Field | Type | Required | Description | Example | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | | +| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | +| `collectors` | *Optional[float]* | :heavy_minus_sign: | Number of Collectors (saved jobs) configured within the Pack. | | +| `dependencies` | Dict[str, *str*] | :heavy_minus_sign: | Map of Pack dependency identifiers to their version constraints. | | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | +| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | +| `exports` | List[*str*] | :heavy_minus_sign: | List of entity IDs exported by this Pack and available for use outside the Pack context. | | +| `id` | *str* | :heavy_check_mark: | Unique identifier. | | +| `inputs` | *Optional[float]* | :heavy_minus_sign: | Number of Sources configured within the Pack. | | +| `is_disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, the Pack is disabled. Otherwise, false. | | +| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | +| `outputs` | *Optional[float]* | :heavy_minus_sign: | Number of Destinations configured within the Pack. | | +| `settings` | Dict[str, *Any*] | :heavy_minus_sign: | Pack-specific settings object. Contents vary by Pack. | | +| `source` | *str* | :heavy_check_mark: | Source of the Pack — a file path, URL, or Git URL from which the Pack was installed. | | +| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint that was applied when the Pack was installed. | | +| `tags` | [Optional[models.TagsTypePackInstallInfo]](../models/tagstypepackinstallinfo.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | +| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | +| `warnings` | List[*str*] | :heavy_minus_sign: | N/A | | \ No newline at end of file diff --git a/docs/models/packrequestbody1.md b/docs/models/packrequestbody1.md index f47201dd9..c7c59caba 100644 --- a/docs/models/packrequestbody1.md +++ b/docs/models/packrequestbody1.md @@ -3,16 +3,16 @@ ## Fields -| Field | Type | Required | Description | Example | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *str* | :heavy_check_mark: | Unique identifier for the Pack. | | -| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint to apply when resolving the Pack version to install. | | -| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | -| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | -| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | -| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | -| `source` | *Optional[str]* | :heavy_minus_sign: | Source of the Pack. Provide a staging source ID from PUT /packs, a direct URL to a .crbl file, or a git+<repo-url> Git repository URL. If omitted, an empty Pack is created. | | -| `tags` | [Optional[models.Tags1]](../models/tags1.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | -| `allow_custom_functions` | *Optional[bool]* | :heavy_minus_sign: | If true or omitted, allow the Pack to use custom JavaScript functions. If false, reject Packs that use custom JavaScript functions. | | -| `force` | *Optional[bool]* | :heavy_minus_sign: | If true, overwrite an existing Pack with the same ID. Otherwise, false. | | \ No newline at end of file +| Field | Type | Required | Description | Example | +| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique identifier for the Pack. | | +| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint to apply when resolving the Pack version to install. | | +| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | +| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | +| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | +| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | +| `source` | *Optional[str]* | :heavy_minus_sign: | Where to install the Pack from: an uploaded Pack source, a direct URL to a .crbl file, or a Git repository URL. Leave empty to create an empty Pack. | | +| `tags` | [Optional[models.Tags1]](../models/tags1.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | +| `allow_custom_functions` | *Optional[bool]* | :heavy_minus_sign: | Allow the Pack to use custom JavaScript functions. When disabled, Packs that use custom JavaScript functions are rejected. | | +| `force` | *Optional[bool]* | :heavy_minus_sign: | Overwrite an existing Pack that has the same ID. | | \ No newline at end of file diff --git a/docs/models/packrequestbody2.md b/docs/models/packrequestbody2.md index 5c071f5bb..4e1f757fd 100644 --- a/docs/models/packrequestbody2.md +++ b/docs/models/packrequestbody2.md @@ -3,16 +3,16 @@ ## Fields -| Field | Type | Required | Description | Example | -| ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Pack. | | -| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint to apply when resolving the Pack version to install. | | -| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | -| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | -| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | -| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | -| `source` | *str* | :heavy_check_mark: | Source of the Pack. Provide a staging source ID from PUT /packs, a direct URL to a .crbl file, or a git+<repo-url> Git repository URL. If omitted, an empty Pack is created. | | -| `tags` | [Optional[models.Tags2]](../models/tags2.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | -| `allow_custom_functions` | *Optional[bool]* | :heavy_minus_sign: | If true or omitted, allow the Pack to use custom JavaScript functions. If false, reject Packs that use custom JavaScript functions. | | -| `force` | *Optional[bool]* | :heavy_minus_sign: | If true, overwrite an existing Pack with the same ID. Otherwise, false. | | \ No newline at end of file +| Field | Type | Required | Description | Example | +| ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Pack. | | +| `spec` | *Optional[str]* | :heavy_minus_sign: | Semver range constraint to apply when resolving the Pack version to install. | | +| `version` | *Optional[str]* | :heavy_minus_sign: | Version of the Pack, following semantic versioning. | 1.0.0 | +| `min_log_stream_version` | *Optional[str]* | :heavy_minus_sign: | Minimum version of Cribl Stream required to run this Pack. | | +| `display_name` | *Optional[str]* | :heavy_minus_sign: | Human-readable display name for the Pack. | | +| `author` | *Optional[str]* | :heavy_minus_sign: | Name or identifier of the Pack author. | | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pack and its purpose. | | +| `source` | *str* | :heavy_check_mark: | Where to install the Pack from: an uploaded Pack source, a direct URL to a .crbl file, or a Git repository URL. Leave empty to create an empty Pack. | | +| `tags` | [Optional[models.Tags2]](../models/tags2.md) | :heavy_minus_sign: | Categorization tags for the Pack. | | +| `allow_custom_functions` | *Optional[bool]* | :heavy_minus_sign: | Allow the Pack to use custom JavaScript functions. When disabled, Packs that use custom JavaScript functions are rejected. | | +| `force` | *Optional[bool]* | :heavy_minus_sign: | Overwrite an existing Pack that has the same ID. | | \ No newline at end of file diff --git a/docs/models/paginatedconfiggroup.md b/docs/models/paginatedconfiggroup.md index b5b460cdc..a3a5c1ac1 100644 --- a/docs/models/paginatedconfiggroup.md +++ b/docs/models/paginatedconfiggroup.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.ConfigGroup](../models/configgroup.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.ConfigGroup](../models/configgroup.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedcribllakedataset.md b/docs/models/paginatedcribllakedataset.md index 058780781..b47d3080d 100644 --- a/docs/models/paginatedcribllakedataset.md +++ b/docs/models/paginatedcribllakedataset.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.CriblLakeDataset](../models/cribllakedataset.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.CriblLakeDataset](../models/cribllakedataset.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginateddistributedsummary.md b/docs/models/paginateddistributedsummary.md index 5f115b6b7..ef4452e94 100644 --- a/docs/models/paginateddistributedsummary.md +++ b/docs/models/paginateddistributedsummary.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.DistributedSummary](../models/distributedsummary.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.DistributedSummary](../models/distributedsummary.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedfunctionresponse.md b/docs/models/paginatedfunctionresponse.md index 14e8cd239..a0fc7b1e6 100644 --- a/docs/models/paginatedfunctionresponse.md +++ b/docs/models/paginatedfunctionresponse.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.FunctionResponse](../models/functionresponse.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.FunctionResponse](../models/functionresponse.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedgitlogresult.md b/docs/models/paginatedgitlogresult.md index 59b96130a..d0d65ec3a 100644 --- a/docs/models/paginatedgitlogresult.md +++ b/docs/models/paginatedgitlogresult.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.GitLogResult](../models/gitlogresult.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.GitLogResult](../models/gitlogresult.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedinputresponse.md b/docs/models/paginatedinputresponse.md index 1eb0cea9d..81d83d348 100644 --- a/docs/models/paginatedinputresponse.md +++ b/docs/models/paginatedinputresponse.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.InputResponse](../models/inputresponse.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.InputResponse](../models/inputresponse.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedinputstatus.md b/docs/models/paginatedinputstatus.md index 1b5bbf0fb..bf2a32af4 100644 --- a/docs/models/paginatedinputstatus.md +++ b/docs/models/paginatedinputstatus.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.InputStatus](../models/inputstatus.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.InputStatus](../models/inputstatus.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedmasterworkerentry.md b/docs/models/paginatedmasterworkerentry.md index fafec6609..4a1731f29 100644 --- a/docs/models/paginatedmasterworkerentry.md +++ b/docs/models/paginatedmasterworkerentry.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.MasterWorkerEntry](../models/masterworkerentry.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.MasterWorkerEntry](../models/masterworkerentry.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedoutputresponse.md b/docs/models/paginatedoutputresponse.md index 9cafa92a1..7c3fe4e52 100644 --- a/docs/models/paginatedoutputresponse.md +++ b/docs/models/paginatedoutputresponse.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.OutputResponse](../models/outputresponse.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.OutputResponse](../models/outputresponse.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedoutputstatus.md b/docs/models/paginatedoutputstatus.md index 4a475921b..a20818df8 100644 --- a/docs/models/paginatedoutputstatus.md +++ b/docs/models/paginatedoutputstatus.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.OutputStatus](../models/outputstatus.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.OutputStatus](../models/outputstatus.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedpackinfo.md b/docs/models/paginatedpackinfo.md index b3255cc34..4c230c2ec 100644 --- a/docs/models/paginatedpackinfo.md +++ b/docs/models/paginatedpackinfo.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.PackInfo](../models/packinfo.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.PackInfo](../models/packinfo.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedpipeline.md b/docs/models/paginatedpipeline.md index 7d1b786aa..0dd22c4cc 100644 --- a/docs/models/paginatedpipeline.md +++ b/docs/models/paginatedpipeline.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.Pipeline](../models/pipeline.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.Pipeline](../models/pipeline.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedroutes.md b/docs/models/paginatedroutes.md new file mode 100644 index 000000000..4fa735fff --- /dev/null +++ b/docs/models/paginatedroutes.md @@ -0,0 +1,12 @@ +# PaginatedRoutes + + +## Fields + +| Field | Type | Required | Description | +| ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | +| `items` | List[[models.Routes](../models/routes.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | +| `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/paginatedsavedjobresponse.md b/docs/models/paginatedsavedjobresponse.md index bc0a5658f..230864ea3 100644 --- a/docs/models/paginatedsavedjobresponse.md +++ b/docs/models/paginatedsavedjobresponse.md @@ -5,8 +5,8 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------ | -| `items` | List[[models.SavedJobResponse](../models/savedjobresponse.md)] | :heavy_check_mark: | The pre-limited items in the list of results | -| `count` | *int* | :heavy_check_mark: | Number of items present in the items array | +| `items` | List[[models.SavedJobResponse](../models/savedjobresponse.md)] | :heavy_check_mark: | The items returned in this response, after any offset/limit pagination has been applied. | +| `count` | *int* | :heavy_check_mark: | Number of items returned in the items array. | | `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset. Returned when offset/limit query parameters are provided. | | `limit` | *Optional[int]* | :heavy_minus_sign: | Pagination limit. Returned when offset/limit query parameters are provided. | | `total_count` | *Optional[int]* | :heavy_minus_sign: | Total number of items available. Returned when offset/limit query parameters are provided. | \ No newline at end of file diff --git a/docs/models/pipelinefunctionconf.md b/docs/models/pipelinefunctionconf.md index abf2de7f5..2a8d6216d 100644 --- a/docs/models/pipelinefunctionconf.md +++ b/docs/models/pipelinefunctionconf.md @@ -51,6 +51,12 @@ value: models.PipelineFunctionCode = /* values here */ value: models.PipelineFunctionComment = /* values here */ ``` +### `models.PipelineFunctionDetectionRules` + +```python +value: models.PipelineFunctionDetectionRules = /* values here */ +``` + ### `models.PipelineFunctionDistinct` ```python @@ -159,6 +165,12 @@ value: models.PipelineFunctionJSONUnroll = /* values here */ value: models.PipelineFunctionLakeExport = /* values here */ ``` +### `models.PipelineFunctionLakehouseEngineMetricsNormalizer` + +```python +value: models.PipelineFunctionLakehouseEngineMetricsNormalizer = /* values here */ +``` + ### `models.PipelineFunctionLimit` ```python @@ -213,6 +225,12 @@ value: models.PipelineFunctionMask = /* values here */ value: models.PipelineFunctionMetricsExport = /* values here */ ``` +### `models.PipelineFunctionMetricsTimeRangeGate` + +```python +value: models.PipelineFunctionMetricsTimeRangeGate = /* values here */ +``` + ### `models.PipelineFunctionMvExpand` ```python diff --git a/docs/models/pipelinefunctionconfinput.md b/docs/models/pipelinefunctionconfinput.md index 5dc30c063..ea10059c5 100644 --- a/docs/models/pipelinefunctionconfinput.md +++ b/docs/models/pipelinefunctionconfinput.md @@ -51,6 +51,12 @@ value: models.PipelineFunctionCode = /* values here */ value: models.PipelineFunctionComment = /* values here */ ``` +### `models.PipelineFunctionDetectionRules` + +```python +value: models.PipelineFunctionDetectionRules = /* values here */ +``` + ### `models.PipelineFunctionDistinct` ```python @@ -159,6 +165,12 @@ value: models.PipelineFunctionJSONUnroll = /* values here */ value: models.PipelineFunctionLakeExport = /* values here */ ``` +### `models.PipelineFunctionLakehouseEngineMetricsNormalizer` + +```python +value: models.PipelineFunctionLakehouseEngineMetricsNormalizer = /* values here */ +``` + ### `models.PipelineFunctionLimit` ```python @@ -213,6 +225,12 @@ value: models.PipelineFunctionMask = /* values here */ value: models.PipelineFunctionMetricsExport = /* values here */ ``` +### `models.PipelineFunctionMetricsTimeRangeGate` + +```python +value: models.PipelineFunctionMetricsTimeRangeGate = /* values here */ +``` + ### `models.PipelineFunctionMvExpand` ```python diff --git a/docs/models/pipelinefunctiondetectionrules.md b/docs/models/pipelinefunctiondetectionrules.md new file mode 100644 index 000000000..ccc362a1d --- /dev/null +++ b/docs/models/pipelinefunctiondetectionrules.md @@ -0,0 +1,14 @@ +# PipelineFunctionDetectionRules + + +## Fields + +| Field | Type | Required | Description | Example | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `filter_` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that selects data to pass through the Function. | | +| `id` | [models.PipelineFunctionDetectionRulesID](../models/pipelinefunctiondetectionrulesid.md) | :heavy_check_mark: | Identifier of the Function. Always detection_rules | detection_rules | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pipeline function. | | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, disable the Pipeline function so that events are not passed through it. Otherwise, false. | | +| `final` | *Optional[bool]* | :heavy_minus_sign: | If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false. | | +| `conf` | [models.FunctionConfSchemaDetectionRules](../models/functionconfschemadetectionrules.md) | :heavy_check_mark: | N/A | | +| `group_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier of the group that contains the Pipeline Function. | | \ No newline at end of file diff --git a/docs/models/pipelinefunctiondetectionrulesid.md b/docs/models/pipelinefunctiondetectionrulesid.md new file mode 100644 index 000000000..c1c9e8027 --- /dev/null +++ b/docs/models/pipelinefunctiondetectionrulesid.md @@ -0,0 +1,18 @@ +# PipelineFunctionDetectionRulesID + +Identifier of the Function. Always detection_rules + +## Example Usage + +```python +from cribl_control_plane.models import PipelineFunctionDetectionRulesID + +value = PipelineFunctionDetectionRulesID.DETECTION_RULES +``` + + +## Values + +| Name | Value | +| ----------------- | ----------------- | +| `DETECTION_RULES` | detection_rules | \ No newline at end of file diff --git a/docs/models/pipelinefunctionlakehouseenginemetricsnormalizer.md b/docs/models/pipelinefunctionlakehouseenginemetricsnormalizer.md new file mode 100644 index 000000000..31ad3119f --- /dev/null +++ b/docs/models/pipelinefunctionlakehouseenginemetricsnormalizer.md @@ -0,0 +1,14 @@ +# PipelineFunctionLakehouseEngineMetricsNormalizer + + +## Fields + +| Field | Type | Required | Description | Example | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `filter_` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that selects data to pass through the Function. | | +| `id` | [models.PipelineFunctionLakehouseEngineMetricsNormalizerID](../models/pipelinefunctionlakehouseenginemetricsnormalizerid.md) | :heavy_check_mark: | Identifier of the Function. Always lakehouse_engine_metrics_normalizer | lakehouse_engine_metrics_normalizer | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pipeline function. | | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, disable the Pipeline function so that events are not passed through it. Otherwise, false. | | +| `final` | *Optional[bool]* | :heavy_minus_sign: | If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false. | | +| `conf` | [models.FunctionConfSchemaLakehouseEngineMetricsNormalizer](../models/functionconfschemalakehouseenginemetricsnormalizer.md) | :heavy_check_mark: | N/A | | +| `group_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier of the group that contains the Pipeline Function. | | \ No newline at end of file diff --git a/docs/models/pipelinefunctionlakehouseenginemetricsnormalizerid.md b/docs/models/pipelinefunctionlakehouseenginemetricsnormalizerid.md new file mode 100644 index 000000000..9141f387e --- /dev/null +++ b/docs/models/pipelinefunctionlakehouseenginemetricsnormalizerid.md @@ -0,0 +1,18 @@ +# PipelineFunctionLakehouseEngineMetricsNormalizerID + +Identifier of the Function. Always lakehouse_engine_metrics_normalizer + +## Example Usage + +```python +from cribl_control_plane.models import PipelineFunctionLakehouseEngineMetricsNormalizerID + +value = PipelineFunctionLakehouseEngineMetricsNormalizerID.LAKEHOUSE_ENGINE_METRICS_NORMALIZER +``` + + +## Values + +| Name | Value | +| ------------------------------------- | ------------------------------------- | +| `LAKEHOUSE_ENGINE_METRICS_NORMALIZER` | lakehouse_engine_metrics_normalizer | \ No newline at end of file diff --git a/docs/models/pipelinefunctionmetricsexportmode1.md b/docs/models/pipelinefunctionmetricsexportmode1.md index 0f90bd7c7..f05401d51 100644 --- a/docs/models/pipelinefunctionmetricsexportmode1.md +++ b/docs/models/pipelinefunctionmetricsexportmode1.md @@ -1,6 +1,6 @@ # PipelineFunctionMetricsExportMode1 -Discriminator value. +Type of label configuration. Always object. ## Example Usage diff --git a/docs/models/pipelinefunctionmetricsexportmode2.md b/docs/models/pipelinefunctionmetricsexportmode2.md index de363a407..5c255a5aa 100644 --- a/docs/models/pipelinefunctionmetricsexportmode2.md +++ b/docs/models/pipelinefunctionmetricsexportmode2.md @@ -1,6 +1,6 @@ # PipelineFunctionMetricsExportMode2 -Discriminator value. +Type of label configuration. Always list. ## Example Usage diff --git a/docs/models/pipelinefunctionmetricstimerangegate.md b/docs/models/pipelinefunctionmetricstimerangegate.md new file mode 100644 index 000000000..8470714e5 --- /dev/null +++ b/docs/models/pipelinefunctionmetricstimerangegate.md @@ -0,0 +1,14 @@ +# PipelineFunctionMetricsTimeRangeGate + + +## Fields + +| Field | Type | Required | Description | Example | +| -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------- | +| `filter_` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that selects data to pass through the Function. | | +| `id` | [models.PipelineFunctionMetricsTimeRangeGateID](../models/pipelinefunctionmetricstimerangegateid.md) | :heavy_check_mark: | Identifier of the Function. Always metrics_time_range_gate | metrics_time_range_gate | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Pipeline function. | | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, disable the Pipeline function so that events are not passed through it. Otherwise, false. | | +| `final` | *Optional[bool]* | :heavy_minus_sign: | If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false. | | +| `conf` | [models.FunctionConfSchemaMetricsTimeRangeGate](../models/functionconfschemametricstimerangegate.md) | :heavy_check_mark: | N/A | | +| `group_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier of the group that contains the Pipeline Function. | | \ No newline at end of file diff --git a/docs/models/pipelinefunctionmetricstimerangegateid.md b/docs/models/pipelinefunctionmetricstimerangegateid.md new file mode 100644 index 000000000..ec96cdf2c --- /dev/null +++ b/docs/models/pipelinefunctionmetricstimerangegateid.md @@ -0,0 +1,18 @@ +# PipelineFunctionMetricsTimeRangeGateID + +Identifier of the Function. Always metrics_time_range_gate + +## Example Usage + +```python +from cribl_control_plane.models import PipelineFunctionMetricsTimeRangeGateID + +value = PipelineFunctionMetricsTimeRangeGateID.METRICS_TIME_RANGE_GATE +``` + + +## Values + +| Name | Value | +| ------------------------- | ------------------------- | +| `METRICS_TIME_RANGE_GATE` | metrics_time_range_gate | \ No newline at end of file diff --git a/docs/models/pipelinegroups.md b/docs/models/pipelinegroups.md index cfda9e687..7c516236a 100644 --- a/docs/models/pipelinegroups.md +++ b/docs/models/pipelinegroups.md @@ -3,8 +3,8 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------ | -| `name` | *str* | :heavy_check_mark: | Name of the group. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the group. | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, disable all items in the group. Otherwise, false. | \ No newline at end of file +| Field | Type | Required | Description | +| ------------------------------- | ------------------------------- | ------------------------------- | ------------------------------- | +| `name` | *str* | :heavy_check_mark: | Name of the group. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the group. | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | Disable all items in the group. | \ No newline at end of file diff --git a/docs/models/policy.md b/docs/models/policy.md index 529d2cc00..5676eeac5 100644 --- a/docs/models/policy.md +++ b/docs/models/policy.md @@ -3,13 +3,13 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | -| `id` | *str* | :heavy_check_mark: | Unique identifier for this policy | -| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, this policy will be skipped during evaluation | -| `wait_to_group` | *Optional[int]* | :heavy_minus_sign: | Time to wait (in minutes) to group similar alerts before sending | -| `group_by_labels` | List[*str*] | :heavy_minus_sign: | Event fields to use for grouping | -| `conditions` | List[List[[models.Condition](../models/condition.md)]] | :heavy_minus_sign: | List of conditions. If ANY condition matches (OR), the policy applies. Each condition is a list of tags that must ALL match (AND). | -| `template_target_pairs` | List[[models.TemplateTargetPairConfFunctionConfSchemaNotificationPolicies](../models/templatetargetpairconffunctionconfschemanotificationpolicies.md)] | :heavy_check_mark: | List of targets to route to and the templates to use | -| `final` | *Optional[bool]* | :heavy_minus_sign: | If true, stop evaluating further policies after this one matches | -| `order` | *int* | :heavy_check_mark: | Evaluation order of this policy (lower numbers evaluated first) | \ No newline at end of file +| Field | Type | Required | Description | +| ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------- | +| `id` | *str* | :heavy_check_mark: | Unique identifier for this policy | +| `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, this policy will be skipped during evaluation | +| `wait_to_group` | *Optional[int]* | :heavy_minus_sign: | Time to wait (in minutes) to group similar alerts before sending | +| `group_by_labels` | List[*str*] | :heavy_minus_sign: | Event fields to use for grouping | +| `conditions` | List[List[[models.Condition](../models/condition.md)]] | :heavy_minus_sign: | List of conditions. If ANY condition matches (OR), the policy applies. Each condition is a list of tags that must ALL match (AND). | +| `template_target_pairs` | List[[models.FunctionConfSchemaNotificationPoliciesTemplateTargetPair](../models/functionconfschemanotificationpoliciestemplatetargetpair.md)] | :heavy_check_mark: | List of targets to route to and the templates to use | +| `final` | *Optional[bool]* | :heavy_minus_sign: | If true, stop evaluating further policies after this one matches | +| `order` | *int* | :heavy_check_mark: | Evaluation order of this policy (lower numbers evaluated first) | \ No newline at end of file diff --git a/docs/models/pqtype.md b/docs/models/pqtype.md index aaffedfeb..227069118 100644 --- a/docs/models/pqtype.md +++ b/docs/models/pqtype.md @@ -8,7 +8,7 @@ | `mode` | [Optional[models.ModeOptionsPq]](../models/modeoptionspq.md) | :heavy_minus_sign: | With Smart mode (deprecated), PQ will write events to the filesystem only when it detects backpressure from the processing engine. Smart mode will have no new development starting July 2026, followed by End of Support and feature removal (auto-migrating to Always On) in January 2027. We recommend using Always On mode instead. With Always On mode, PQ will always write events directly to the queue before forwarding them to the processing engine. | | `max_buffer_size_bytes` | *Optional[str]* | :heavy_minus_sign: | The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB. | | `max_buffer_size` | *Optional[float]* | :heavy_minus_sign: | Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use maxBufferSizeBytes instead. | -| `commit_frequency` | *Optional[float]* | :heavy_minus_sign: | The number of events to send downstream before committing that Stream has read them | +| `commit_frequency` | *Optional[float]* | :heavy_minus_sign: | The number of events to send downstream before committing that Stream has read them. Lower values increase cursor-write IOPS and can add disk pressure, including on shared storage. | | `max_file_size` | *Optional[str]* | :heavy_minus_sign: | The maximum size to store in each queue file before closing and optionally compressing. Enter a numeral with units of KB, MB, etc. | | `max_size` | *Optional[str]* | :heavy_minus_sign: | The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc. | | `path` | *Optional[str]* | :heavy_minus_sign: | The location for the persistent queue files. To this field's value, the system will append: //inputs/ | diff --git a/docs/models/projectdetails.md b/docs/models/projectdetails.md index e807657f6..68eb0d324 100644 --- a/docs/models/projectdetails.md +++ b/docs/models/projectdetails.md @@ -5,14 +5,14 @@ Project Details ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.ProjectDetailsManageState]](../models/projectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.ProjectDetailsManageState]](../models/projectdetailsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/projects.md b/docs/models/projects.md index 35491821a..49089e0f8 100644 --- a/docs/models/projects.md +++ b/docs/models/projects.md @@ -5,14 +5,14 @@ Projects ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------- | -| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | -| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | -| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | -| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | -| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | -| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | -| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event | -| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging task state | -| `manage_state` | [Optional[models.ProjectsManageState]](../models/projectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `enabled` | *Optional[bool]* | :heavy_minus_sign: | Enabled | +| `cron_schedule` | *Optional[str]* | :heavy_minus_sign: | Schedule on which to run this collection job | +| `earliest` | *Optional[str]* | :heavy_minus_sign: | Earliest time for data collection, relative to now | +| `latest` | *Optional[str]* | :heavy_minus_sign: | Latest time for data collection, relative to now | +| `job_timeout` | *Optional[str]* | :heavy_minus_sign: | Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time. | +| `state_tracking` | *Optional[bool]* | :heavy_minus_sign: | Track collection progress between consecutive scheduled executions | +| `state_update_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information. | +| `state_merge_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep. | +| `manage_state` | [Optional[models.ProjectsManageState]](../models/projectsmanagestate.md) | :heavy_minus_sign: | N/A | \ No newline at end of file diff --git a/docs/models/rbacresource.md b/docs/models/rbacresource.md index 1e83722e0..f496af7a2 100644 --- a/docs/models/rbacresource.md +++ b/docs/models/rbacresource.md @@ -16,6 +16,7 @@ value = RbacResource.GROUPS | Name | Value | | -------------------- | -------------------- | | `GROUPS` | groups | +| `INSIGHTS_APPS` | insights-apps | | `DATASETS` | datasets | | `DATASET_PROVIDERS` | dataset-providers | | `PROJECTS` | projects | @@ -23,4 +24,5 @@ value = RbacResource.GROUPS | `MACROS` | macros | | `NOTEBOOKS` | notebooks | | `NOTEBOOK_TEMPLATES` | notebook-templates | -| `APPS` | apps | \ No newline at end of file +| `APPS` | apps | +| `SECRET_FOLDERS` | secret-folders | \ No newline at end of file diff --git a/docs/models/routeconf.md b/docs/models/routeconf.md index 2aa1a4017..c0e4149a6 100644 --- a/docs/models/routeconf.md +++ b/docs/models/routeconf.md @@ -5,6 +5,7 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | If true, detect each matched event's datatype and extract fields from _raw before the Pipeline processes the event, so Functions and Filters can reference the extracted fields. Otherwise, false (the default). | | `clones` | List[Dict[str, *str*]] | :heavy_minus_sign: | Array of clone configurations, each with a key-value pair to set or overwrite in cloned events. Original events continue to the next Route. | | `context` | *Optional[str]* | :heavy_minus_sign: | Context for the Route: group (Worker Group or Edge Fleet) or pack. | | `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Route. | diff --git a/docs/models/routeconfinput.md b/docs/models/routeconfinput.md index f121da17c..7cfef238d 100644 --- a/docs/models/routeconfinput.md +++ b/docs/models/routeconfinput.md @@ -5,6 +5,7 @@ | Field | Type | Required | Description | | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `auto_parse` | *Optional[bool]* | :heavy_minus_sign: | If true, detect each matched event's datatype and extract fields from _raw before the Pipeline processes the event, so Functions and Filters can reference the extracted fields. Otherwise, false (the default). | | `clones` | List[Dict[str, *str*]] | :heavy_minus_sign: | Array of clone configurations, each with a key-value pair to set or overwrite in cloned events. Original events continue to the next Route. | | `context` | *Optional[str]* | :heavy_minus_sign: | Context for the Route: group (Worker Group or Edge Fleet) or pack. | | `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Route. | diff --git a/docs/models/runnablejobcollection.md b/docs/models/runnablejobcollection.md index d505ec6d5..410a3719c 100644 --- a/docs/models/runnablejobcollection.md +++ b/docs/models/runnablejobcollection.md @@ -20,5 +20,5 @@ Configuration for a saved collection job, including Collector, input, and option | `worker_affinity` | *Optional[bool]* | :heavy_minus_sign: | If enabled, tasks are created and run by the same Worker Node | | `collector` | [models.Collector](../models/collector.md) | :heavy_check_mark: | Collector configuration | | `input` | [Optional[models.InputTypeRunnableJobCollection]](../models/inputtyperunnablejobcollection.md) | :heavy_minus_sign: | Input settings for a collection job, including event breaking, routing, and preprocessing options. | -| `run` | [models.RunnableJobCollectionRun](../models/runnablejobcollectionrun.md) | :heavy_check_mark: | N/A | +| `run` | [models.RunnableJobCollectionRun](../models/runnablejobcollectionrun.md) | :heavy_check_mark: | Run settings that control how and when the Collection job runs. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/runnablejobcollectionrun.md b/docs/models/runnablejobcollectionrun.md index 8612feedd..58577bac6 100644 --- a/docs/models/runnablejobcollectionrun.md +++ b/docs/models/runnablejobcollectionrun.md @@ -1,5 +1,7 @@ # RunnableJobCollectionRun +Run settings that control how and when the Collection job runs. + ## Fields @@ -14,7 +16,6 @@ | `earliest` | [Optional[models.RunnableJobCollectionEarliest]](../models/runnablejobcollectionearliest.md) | :heavy_minus_sign: | Earliest time to collect data for the selected timezone | | `latest` | [Optional[models.RunnableJobCollectionLatest]](../models/runnablejobcollectionlatest.md) | :heavy_minus_sign: | Latest time to collect data for the selected timezone | | `timestamp_timezone` | *Optional[str]* | :heavy_minus_sign: | Timezone to use for Earliest and Latest times | -| `time_warning` | [Optional[models.TimeWarningTypeRunnableJobCollectionScheduleRun]](../models/timewarningtyperunnablejobcollectionschedulerun.md) | :heavy_minus_sign: | Warning state used when the collection time range is unset for time-sensitive Collectors. | | `expression` | *Optional[str]* | :heavy_minus_sign: | A filter for tokens in the provided collect path and/or the events being collected | | `min_task_size` | *Optional[str]* | :heavy_minus_sign: | Limits the bundle size for small tasks. For example,

if your lower bundle size is 1MB, you can bundle up to five 200KB files into one task. | | `max_task_size` | *Optional[str]* | :heavy_minus_sign: | Limits the bundle size for files above the lower task bundle size. For example, if your upper bundle size is 10MB,

you can bundle up to five 2MB files into one task. Files greater than this size will be assigned to individual tasks. | diff --git a/docs/models/runnablejobexecutor.md b/docs/models/runnablejobexecutor.md index 3e9c33f29..85e8984cc 100644 --- a/docs/models/runnablejobexecutor.md +++ b/docs/models/runnablejobexecutor.md @@ -18,5 +18,5 @@ Configuration for a saved executor job, including executor type and run settings | `schedule` | [Optional[models.ScheduleTypeRunnableJobCollection]](../models/scheduletyperunnablejobcollection.md) | :heavy_minus_sign: | Configuration for a scheduled job | | `streamtags` | List[*str*] | :heavy_minus_sign: | Metadata tags used for categorization and filtering. | | `executor` | [models.ExecutorTypeRunnableJobExecutor](../models/executortyperunnablejobexecutor.md) | :heavy_check_mark: | Executor configuration, including the executor type and its settings. | -| `run` | [models.RunnableJobExecutorRun](../models/runnablejobexecutorrun.md) | :heavy_check_mark: | N/A | +| `run` | [models.RunnableJobExecutorRun](../models/runnablejobexecutorrun.md) | :heavy_check_mark: | Run settings that control how and when the Executor job runs. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | \ No newline at end of file diff --git a/docs/models/runnablejobexecutorrun.md b/docs/models/runnablejobexecutorrun.md index 916db1788..c0dec19d7 100644 --- a/docs/models/runnablejobexecutorrun.md +++ b/docs/models/runnablejobexecutorrun.md @@ -1,5 +1,7 @@ # RunnableJobExecutorRun +Run settings that control how and when the Executor job runs. + ## Fields diff --git a/docs/models/runsettingstyperunnablejobcollectionschedule.md b/docs/models/runsettingstyperunnablejobcollectionschedule.md index 2d062f9ba..878d05a5f 100644 --- a/docs/models/runsettingstyperunnablejobcollectionschedule.md +++ b/docs/models/runsettingstyperunnablejobcollectionschedule.md @@ -17,7 +17,6 @@ Run settings that control how the scheduled job executes, including log level, t | `earliest` | [Optional[models.RunSettingsTypeRunnableJobCollectionScheduleEarliest]](../models/runsettingstyperunnablejobcollectionscheduleearliest.md) | :heavy_minus_sign: | Earliest time to collect data for the selected timezone | | `latest` | [Optional[models.RunSettingsTypeRunnableJobCollectionScheduleLatest]](../models/runsettingstyperunnablejobcollectionschedulelatest.md) | :heavy_minus_sign: | Latest time to collect data for the selected timezone | | `timestamp_timezone` | *Optional[str]* | :heavy_minus_sign: | IANA timezone name for interpreting timestamp values in the collection time range. | -| `time_warning` | [Optional[models.TimeWarningTypeRunnableJobCollectionScheduleRun]](../models/timewarningtyperunnablejobcollectionschedulerun.md) | :heavy_minus_sign: | Warning state used when the collection time range is unset for time-sensitive Collectors. | | `expression` | *Optional[str]* | :heavy_minus_sign: | A filter for tokens in the provided collect path and/or the events being collected | | `min_task_size` | *Optional[str]* | :heavy_minus_sign: | Limits the bundle size for small tasks. For example,

if your lower bundle size is 1MB, you can bundle up to five 200KB files into one task. | | `max_task_size` | *Optional[str]* | :heavy_minus_sign: | Limits the bundle size for files above the lower task bundle size. For example, if your upper bundle size is 10MB,

you can bundle up to five 2MB files into one task. Files greater than this size will be assigned to individual tasks. | \ No newline at end of file diff --git a/docs/models/runsettingstypesavedjobresponsecollectionschedule.md b/docs/models/runsettingstypesavedjobresponsecollectionschedule.md index f79d28f57..c27130e3c 100644 --- a/docs/models/runsettingstypesavedjobresponsecollectionschedule.md +++ b/docs/models/runsettingstypesavedjobresponsecollectionschedule.md @@ -17,7 +17,6 @@ Run settings that control how the scheduled job executes, including log level, t | `earliest` | [Optional[models.RunSettingsTypeSavedJobResponseCollectionScheduleEarliest]](../models/runsettingstypesavedjobresponsecollectionscheduleearliest.md) | :heavy_minus_sign: | Earliest time to collect data for the selected timezone | | `latest` | [Optional[models.RunSettingsTypeSavedJobResponseCollectionScheduleLatest]](../models/runsettingstypesavedjobresponsecollectionschedulelatest.md) | :heavy_minus_sign: | Latest time to collect data for the selected timezone | | `timestamp_timezone` | *Optional[str]* | :heavy_minus_sign: | IANA timezone name for interpreting timestamp values in the collection time range. | -| `time_warning` | [Optional[models.TimeWarningTypeRunnableJobCollectionScheduleRun]](../models/timewarningtyperunnablejobcollectionschedulerun.md) | :heavy_minus_sign: | Warning state used when the collection time range is unset for time-sensitive Collectors. | | `expression` | *Optional[str]* | :heavy_minus_sign: | A filter for tokens in the provided collect path and/or the events being collected | | `min_task_size` | *Optional[str]* | :heavy_minus_sign: | Limits the bundle size for small tasks. For example,

if your lower bundle size is 1MB, you can bundle up to five 200KB files into one task. | | `max_task_size` | *Optional[str]* | :heavy_minus_sign: | Limits the bundle size for files above the lower task bundle size. For example, if your upper bundle size is 10MB,

you can bundle up to five 2MB files into one task. Files greater than this size will be assigned to individual tasks. | \ No newline at end of file diff --git a/docs/models/savedjobresponsecollection.md b/docs/models/savedjobresponsecollection.md index 33e6763d0..9d33d0769 100644 --- a/docs/models/savedjobresponsecollection.md +++ b/docs/models/savedjobresponsecollection.md @@ -22,4 +22,4 @@ Configuration for a saved collection job, including Collector, input, and option | `input` | [Optional[models.InputTypeRunnableJobCollection]](../models/inputtyperunnablejobcollection.md) | :heavy_minus_sign: | Input settings for a collection job, including event breaking, routing, and preprocessing options. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `saved_state` | Dict[str, [models.AdditionalPropertiesTypeEnrichedFieldsSavedState](../models/additionalpropertiestypeenrichedfieldssavedstate.md)] | :heavy_minus_sign: | Runtime collection state. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notification targets. | \ No newline at end of file +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notification targets. | \ No newline at end of file diff --git a/docs/models/savedjobresponseexecutor.md b/docs/models/savedjobresponseexecutor.md index d34ffbcd3..aef9330e8 100644 --- a/docs/models/savedjobresponseexecutor.md +++ b/docs/models/savedjobresponseexecutor.md @@ -20,4 +20,4 @@ Configuration for a saved executor job, including executor type and run settings | `executor` | [models.ExecutorTypeRunnableJobExecutor](../models/executortyperunnablejobexecutor.md) | :heavy_check_mark: | Executor configuration, including the executor type and its settings. | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `saved_state` | Dict[str, [models.AdditionalPropertiesTypeEnrichedFieldsSavedState](../models/additionalpropertiestypeenrichedfieldssavedstate.md)] | :heavy_minus_sign: | Runtime collection state. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notification targets. | \ No newline at end of file +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notification targets. | \ No newline at end of file diff --git a/docs/models/savedjobresponsescheduledsearch.md b/docs/models/savedjobresponsescheduledsearch.md index 59c6fcf87..1a9f1fc21 100644 --- a/docs/models/savedjobresponsescheduledsearch.md +++ b/docs/models/savedjobresponsescheduledsearch.md @@ -20,4 +20,4 @@ Configuration for a saved scheduled search job, including the search query to ru | `saved_query_id` | *str* | :heavy_check_mark: | Identifies which search query to run | | `template_streamtags` | *Optional[str]* | :heavy_minus_sign: | Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime. | | `saved_state` | Dict[str, [models.AdditionalPropertiesTypeEnrichedFieldsSavedState](../models/additionalpropertiestypeenrichedfieldssavedstate.md)] | :heavy_minus_sign: | Runtime collection state. | -| `notifications` | List[[models.NotificationUnion](../models/notificationunion.md)] | :heavy_minus_sign: | Notification targets. | \ No newline at end of file +| `notifications` | List[[models.Notification](../models/notification.md)] | :heavy_minus_sign: | Notification targets. | \ No newline at end of file diff --git a/docs/models/searchexecutionconfig.md b/docs/models/searchexecutionconfig.md new file mode 100644 index 000000000..1177b173e --- /dev/null +++ b/docs/models/searchexecutionconfig.md @@ -0,0 +1,9 @@ +# SearchExecutionConfig + + +## Fields + +| Field | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------- | +| `backend_id` | [models.BackendID](../models/backendid.md) | :heavy_check_mark: | N/A | +| `pool_routing_key` | *Optional[str]* | :heavy_minus_sign: | Selects the ordinary BYO executor pool. Required only when backendId is byo; not used for Lake datasets. | \ No newline at end of file diff --git a/docs/models/sendas.md b/docs/models/sendas.md new file mode 100644 index 000000000..20f9a3992 --- /dev/null +++ b/docs/models/sendas.md @@ -0,0 +1,22 @@ +# SendAs + +Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs. + +## Example Usage + +```python +from cribl_control_plane.models import SendAs + +value = SendAs.LOGS + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| --------- | --------- | +| `LOGS` | logs | +| `METRICS` | metrics | +| `BOTH` | both | \ No newline at end of file diff --git a/docs/models/serdetypeauto.md b/docs/models/serdetypeauto.md index 3838e46d8..898633c29 100644 --- a/docs/models/serdetypeauto.md +++ b/docs/models/serdetypeauto.md @@ -6,7 +6,6 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------ | | `type` | [models.SerdeTypeAutoType](../models/serdetypeautotype.md) | :heavy_check_mark: | Parser or formatter type to use. | -| `tag_datatype` | *Optional[bool]* | :heavy_minus_sign: | Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing. | | `mode` | [models.SerdeTypeAutoOperationMode](../models/serdetypeautooperationmode.md) | :heavy_check_mark: | Extract creates new fields. Reserialize extracts and filters fields, and then reserializes. | | `keep` | List[*str*] | :heavy_minus_sign: | List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'. | | `remove` | List[*str*] | :heavy_minus_sign: | List of fields to remove. Supports wildcards (*). Cannot remove fields that match 'Fields to keep'. | diff --git a/docs/models/serdetypecsv.md b/docs/models/serdetypecsv.md index 936313041..62b999c0b 100644 --- a/docs/models/serdetypecsv.md +++ b/docs/models/serdetypecsv.md @@ -13,7 +13,6 @@ | `remove` | List[*str*] | :heavy_minus_sign: | List of fields to remove. Supports wildcards (*). Cannot remove fields that match 'Fields to keep'. | | `field_filter_expr` | *Optional[str]* | :heavy_minus_sign: | Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it. | | `mode` | [models.SerdeTypeCsvOperationMode](../models/serdetypecsvoperationmode.md) | :heavy_check_mark: | Extract creates new fields. Reserialize extracts and filters fields, and then reserializes. | -| `tag_datatype` | *Optional[bool]* | :heavy_minus_sign: | Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing. | | `allowed_key_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a key name, even though they are normally separator or control characters | | `allowed_value_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a value, even though they are normally separator or control characters | | `regex` | *Optional[str]* | :heavy_minus_sign: | Regex literal with named capturing groups, such as (?bar), or _NAME_ and _VALUE_ capturing groups, such as(?<_NAME_0>[^ =]+)=(?<_VALUE_0>[^,]+) | diff --git a/docs/models/serdetypedelim.md b/docs/models/serdetypedelim.md index 79e576cf2..029929419 100644 --- a/docs/models/serdetypedelim.md +++ b/docs/models/serdetypedelim.md @@ -17,7 +17,6 @@ | `escape_char` | *Optional[str]* | :heavy_minus_sign: | Escape character used to escape delimiter or quote character | | `null_value` | *Optional[str]* | :heavy_minus_sign: | Field value representing the null value. Null fields will be omitted. | | `mode` | [models.SerdeTypeDelimOperationMode](../models/serdetypedelimoperationmode.md) | :heavy_check_mark: | Extract creates new fields. Reserialize extracts and filters fields, and then reserializes. | -| `tag_datatype` | *Optional[bool]* | :heavy_minus_sign: | Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing. | | `allowed_key_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a key name, even though they are normally separator or control characters | | `allowed_value_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a value, even though they are normally separator or control characters | | `regex` | *Optional[str]* | :heavy_minus_sign: | Regex literal with named capturing groups, such as (?bar), or _NAME_ and _VALUE_ capturing groups, such as(?<_NAME_0>[^ =]+)=(?<_VALUE_0>[^,]+) | diff --git a/docs/models/serdetypegrok.md b/docs/models/serdetypegrok.md index f4b2cd041..b21d3eaf8 100644 --- a/docs/models/serdetypegrok.md +++ b/docs/models/serdetypegrok.md @@ -11,7 +11,6 @@ | `pattern` | *str* | :heavy_check_mark: | Grok pattern to extract fields. Syntax supported: %{PATTERN_NAME:FIELD_NAME} | | `pattern_list` | List[[models.PatternListConfSerdeTypeGrok](../models/patternlistconfserdetypegrok.md)] | :heavy_minus_sign: | Additional Grok patterns to apply to the source field. | | `mode` | [models.SerdeTypeGrokOperationMode](../models/serdetypegrokoperationmode.md) | :heavy_check_mark: | Extract creates new fields. Reserialize extracts and filters fields, and then reserializes. | -| `tag_datatype` | *Optional[bool]* | :heavy_minus_sign: | Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing. | | `keep` | List[*str*] | :heavy_minus_sign: | List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'. | | `remove` | List[*str*] | :heavy_minus_sign: | List of fields to remove. Supports wildcards (*). Cannot remove fields that match 'Fields to keep'. | | `field_filter_expr` | *Optional[str]* | :heavy_minus_sign: | Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it. | diff --git a/docs/models/serdetypejson.md b/docs/models/serdetypejson.md index 052196e38..d2be2918f 100644 --- a/docs/models/serdetypejson.md +++ b/docs/models/serdetypejson.md @@ -12,7 +12,6 @@ | `remove` | List[*str*] | :heavy_minus_sign: | List of fields to remove. Supports wildcards (*). Cannot remove fields that match 'Fields to keep'. | | `field_filter_expr` | *Optional[str]* | :heavy_minus_sign: | Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it. | | `mode` | [models.SerdeTypeJSONOperationMode](../models/serdetypejsonoperationmode.md) | :heavy_check_mark: | Extract creates new fields. Reserialize extracts and filters fields, and then reserializes. | -| `tag_datatype` | *Optional[bool]* | :heavy_minus_sign: | Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing. | | `allowed_key_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a key name, even though they are normally separator or control characters | | `allowed_value_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a value, even though they are normally separator or control characters | | `fields` | List[*str*] | :heavy_minus_sign: | The fields to be extracted, listed in order. Will auto-generate if empty. | diff --git a/docs/models/serdetypekvp.md b/docs/models/serdetypekvp.md index b1b95315d..3cd4ee552 100644 --- a/docs/models/serdetypekvp.md +++ b/docs/models/serdetypekvp.md @@ -15,7 +15,6 @@ | `allowed_key_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a key name, even though they are normally separator or control characters | | `allowed_value_chars` | List[*str*] | :heavy_minus_sign: | A list of characters that may be present in a value, even though they are normally separator or control characters | | `mode` | [models.SerdeTypeKvpOperationMode](../models/serdetypekvpoperationmode.md) | :heavy_check_mark: | Extract creates new fields. Reserialize extracts and filters fields, and then reserializes. | -| `tag_datatype` | *Optional[bool]* | :heavy_minus_sign: | Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing. | | `fields` | List[*str*] | :heavy_minus_sign: | The fields to be extracted, listed in order. Will auto-generate if empty. | | `regex` | *Optional[str]* | :heavy_minus_sign: | Regex literal with named capturing groups, such as (?bar), or _NAME_ and _VALUE_ capturing groups, such as(?<_NAME_0>[^ =]+)=(?<_VALUE_0>[^,]+) | | `regex_list` | List[[models.RegexListConfSerdeTypeRegex](../models/regexlistconfserdetyperegex.md)] | :heavy_minus_sign: | Additional regex patterns to apply for field extraction. | diff --git a/docs/models/serdetyperegex.md b/docs/models/serdetyperegex.md index c7497cbd2..9e1d1b496 100644 --- a/docs/models/serdetyperegex.md +++ b/docs/models/serdetyperegex.md @@ -14,7 +14,6 @@ | `field_name_expression` | *Optional[str]* | :heavy_minus_sign: | JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+\|[^a-zA-Z0-9_]+/g. You can access other fields values via __e.. | | `overwrite` | *Optional[bool]* | :heavy_minus_sign: | Overwrite existing event fields with extracted values. If disabled, existing fields will be converted to an array. | | `mode` | [models.SerdeTypeRegexOperationMode](../models/serdetyperegexoperationmode.md) | :heavy_check_mark: | Extract creates new fields. Reserialize extracts and filters fields, and then reserializes. | -| `tag_datatype` | *Optional[bool]* | :heavy_minus_sign: | Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing. | | `keep` | List[*str*] | :heavy_minus_sign: | List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'. | | `remove` | List[*str*] | :heavy_minus_sign: | List of fields to remove. Supports wildcards (*). Cannot remove fields that match 'Fields to keep'. | | `field_filter_expr` | *Optional[str]* | :heavy_minus_sign: | Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it. | diff --git a/docs/models/ssl.md b/docs/models/ssl.md index 551f200fb..7309769f8 100644 --- a/docs/models/ssl.md +++ b/docs/models/ssl.md @@ -9,6 +9,7 @@ TLS configuration for the API server. | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | | `ca_path` | *Optional[str]* | :heavy_minus_sign: | Filesystem path to the PEM-encoded Certificate Authority (CA) certificate for client authentication. | | `cert_path` | *Optional[str]* | :heavy_minus_sign: | Filesystem path to the PEM-encoded TLS certificate. | +| `certificate_name` | *Optional[str]* | :heavy_minus_sign: | Name of a predefined Certificate stored in Cribl. | | `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, TLS is disabled for the API server. Otherwise, false. | | `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to decrypt the TLS private key, if encrypted. | | `priv_key_path` | *Optional[str]* | :heavy_minus_sign: | Filesystem path to the PEM-encoded TLS private key. | \ No newline at end of file diff --git a/docs/models/ssltypesystemsettingsconfapi.md b/docs/models/ssltypesystemsettingsconfapi.md index e8df7e642..b0c1809c1 100644 --- a/docs/models/ssltypesystemsettingsconfapi.md +++ b/docs/models/ssltypesystemsettingsconfapi.md @@ -9,6 +9,7 @@ TLS configuration for the API server. | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------- | | `ca_path` | *Optional[str]* | :heavy_minus_sign: | Filesystem path to the PEM-encoded Certificate Authority (CA) certificate for client authentication. | | `cert_path` | *str* | :heavy_check_mark: | Filesystem path to the PEM-encoded TLS certificate. | +| `certificate_name` | *Optional[str]* | :heavy_minus_sign: | Name of a predefined Certificate stored in Cribl. | | `disabled` | *bool* | :heavy_check_mark: | If true, TLS is disabled for the API server. Otherwise, false. | | `passphrase` | *str* | :heavy_check_mark: | Passphrase to decrypt the TLS private key, if encrypted. | | `priv_key_path` | *str* | :heavy_check_mark: | Filesystem path to the PEM-encoded TLS private key. | \ No newline at end of file diff --git a/docs/models/systemsettingsconfresponse.md b/docs/models/systemsettingsconfresponse.md index 6c23ab95b..95640bb16 100644 --- a/docs/models/systemsettingsconfresponse.md +++ b/docs/models/systemsettingsconfresponse.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `api` | [models.SystemSettingsConfResponseAPI](../models/systemsettingsconfresponseapi.md) | :heavy_check_mark: | N/A | +| `api` | [models.APITypeSystemSettingsConf](../models/apitypesystemsettingsconf.md) | :heavy_check_mark: | API server configuration for the Cribl instance. | | `apps` | [Optional[models.AppsTypeSystemSettingsConf]](../models/appstypesystemsettingsconf.md) | :heavy_minus_sign: | App configuration. | | `backups` | [Optional[models.BackupsSettingsUnion]](../models/backupssettingsunion.md) | :heavy_minus_sign: | N/A | | `custom_logo` | [Optional[models.CustomLogoTypeSystemSettingsConf]](../models/customlogotypesystemsettingsconf.md) | :heavy_minus_sign: | Custom logo configuration for the Cribl UI login page and navigation bar. | @@ -16,7 +16,7 @@ | `sni` | [Optional[models.SniSettingsUnion]](../models/snisettingsunion.md) | :heavy_minus_sign: | N/A | | `sockets` | [Optional[models.SocketsTypeSystemSettingsConf]](../models/socketstypesystemsettingsconf.md) | :heavy_minus_sign: | Unix domain socket configuration. | | `support` | [Optional[models.SupportTypeSystemSettingsConf]](../models/supporttypesystemsettingsconf.md) | :heavy_minus_sign: | Support and diagnostics settings. | -| `system` | [models.SystemSettingsConfResponseSystem](../models/systemsettingsconfresponsesystem.md) | :heavy_check_mark: | N/A | +| `system` | [models.SystemTypeSystemSettingsConf](../models/systemtypesystemsettingsconf.md) | :heavy_check_mark: | System-level operational settings for the Cribl instance. | | `tls` | [Optional[models.TLSSettingsUnion]](../models/tlssettingsunion.md) | :heavy_minus_sign: | N/A | | `upgrade_group_settings` | [Optional[models.UpgradeGroupSettings]](../models/upgradegroupsettings.md) | :heavy_minus_sign: | N/A | | `upgrade_settings` | [Optional[models.UpgradeSettings]](../models/upgradesettings.md) | :heavy_minus_sign: | N/A | diff --git a/docs/models/systemsettingsconfresponseapi.md b/docs/models/systemsettingsconfresponseapi.md deleted file mode 100644 index 52b476d83..000000000 --- a/docs/models/systemsettingsconfresponseapi.md +++ /dev/null @@ -1,22 +0,0 @@ -# SystemSettingsConfResponseAPI - - -## Fields - -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------ | -| `base_url` | *Optional[str]* | :heavy_minus_sign: | Base URL for the API server. Used when the server is behind a reverse proxy. | -| `disable_api_cache` | *Optional[bool]* | :heavy_minus_sign: | If true, disable the API response cache. Otherwise, false. | -| `disabled` | *bool* | :heavy_check_mark: | If true, the API server is disabled. Otherwise, false. | -| `headers` | Dict[str, *str*] | :heavy_minus_sign: | Custom HTTP response headers to include in every API response. | -| `host` | *str* | :heavy_check_mark: | Hostname or IP address the API server listens on. | -| `idle_session_ttl` | *Optional[int]* | :heavy_minus_sign: | Idle session timeout in seconds. Sessions are invalidated after the specified seconds of inactivity. | -| `listen_on_port` | *Optional[bool]* | :heavy_minus_sign: | If true, bind to the configured port as the server listen port. Otherwise, false. | -| `login_rate_limit` | *Optional[str]* | :heavy_minus_sign: | Rate limit for login attempts. Value is a string such as 100/min. | -| `port` | *int* | :heavy_check_mark: | Port number the API server listens on. | -| `protocol` | *Optional[str]* | :heavy_minus_sign: | API protocol: http or https. | -| `scripts` | *Optional[bool]* | :heavy_minus_sign: | If true, enable JavaScript scripting support in the API. Otherwise, false. | -| `sensitive_fields` | List[*str*] | :heavy_minus_sign: | List of field names whose values are redacted in API responses and logs. | -| `ssl` | [Optional[models.SslTypeSystemSettingsConfAPI]](../models/ssltypesystemsettingsconfapi.md) | :heavy_minus_sign: | TLS configuration for the API server. | -| `sso_rate_limit` | *Optional[str]* | :heavy_minus_sign: | Rate limit for SSO authentication attempts. Value is a string such as 100/min. | -| `worker_remote_access` | *Optional[bool]* | :heavy_minus_sign: | If true, enable remote access (teleporting) to Worker Processes via the API. Otherwise, false. | \ No newline at end of file diff --git a/docs/models/systemsettingsconfresponsesystem.md b/docs/models/systemsettingsconfresponsesystem.md deleted file mode 100644 index 13674d779..000000000 --- a/docs/models/systemsettingsconfresponsesystem.md +++ /dev/null @@ -1,9 +0,0 @@ -# SystemSettingsConfResponseSystem - - -## Fields - -| Field | Type | Required | Description | -| ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------ | -| `intercom` | *bool* | :heavy_check_mark: | If true, enable Intercom integration for in-product messaging. Otherwise, false. | -| `upgrade` | [models.UpgradeOptionsSystemSettingsConfSystem](../models/upgradeoptionssystemsettingsconfsystem.md) | :heavy_check_mark: | Upgrade permission policy: api to allow upgrades from the UI or API or false to disable. | \ No newline at end of file diff --git a/docs/models/systemsettingsconfupdate.md b/docs/models/systemsettingsconfupdate.md index 9cdb0edbd..e3a5b5609 100644 --- a/docs/models/systemsettingsconfupdate.md +++ b/docs/models/systemsettingsconfupdate.md @@ -5,7 +5,7 @@ | Field | Type | Required | Description | | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------ | -| `api` | [Optional[models.SystemSettingsConfUpdateAPI]](../models/systemsettingsconfupdateapi.md) | :heavy_minus_sign: | API server configuration for the Cribl instance. | +| `api` | [Optional[models.API]](../models/api.md) | :heavy_minus_sign: | API server configuration for the Cribl instance. | | `apps` | [Optional[models.Apps]](../models/apps.md) | :heavy_minus_sign: | App configuration. | | `backups` | [Optional[models.BackupsSettingsUnion]](../models/backupssettingsunion.md) | :heavy_minus_sign: | N/A | | `custom_logo` | [Optional[models.CustomLogo]](../models/customlogo.md) | :heavy_minus_sign: | Custom logo configuration for the Cribl UI login page and navigation bar. | diff --git a/docs/models/targetconfig1.md b/docs/models/targetconfig1.md deleted file mode 100644 index a05f1cd41..000000000 --- a/docs/models/targetconfig1.md +++ /dev/null @@ -1,9 +0,0 @@ -# TargetConfig1 - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `conf` | [Optional[models.NotificationConfigForSMTPTarget1]](../models/notificationconfigforsmtptarget1.md) | :heavy_minus_sign: | Simple Mail Transfer Protocol (SMTP) configuration for the Notification target. | -| `id` | *str* | :heavy_check_mark: | The id of the Notification target. | \ No newline at end of file diff --git a/docs/models/targetconfig2.md b/docs/models/targetconfig2.md deleted file mode 100644 index 115b98202..000000000 --- a/docs/models/targetconfig2.md +++ /dev/null @@ -1,9 +0,0 @@ -# TargetConfig2 - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `conf` | [Optional[models.NotificationConfigForSMTPTarget2]](../models/notificationconfigforsmtptarget2.md) | :heavy_minus_sign: | Simple Mail Transfer Protocol (SMTP) configuration for the Notification target. | -| `id` | *str* | :heavy_check_mark: | The id of the Notification target. | \ No newline at end of file diff --git a/docs/models/targetconfig3.md b/docs/models/targetconfig3.md deleted file mode 100644 index 19cb0597f..000000000 --- a/docs/models/targetconfig3.md +++ /dev/null @@ -1,9 +0,0 @@ -# TargetConfig3 - - -## Fields - -| Field | Type | Required | Description | -| -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------- | -| `conf` | [Optional[models.NotificationConfigForSMTPTarget3]](../models/notificationconfigforsmtptarget3.md) | :heavy_minus_sign: | Simple Mail Transfer Protocol (SMTP) configuration for the Notification target. | -| `id` | *str* | :heavy_check_mark: | The id of the Notification target. | \ No newline at end of file diff --git a/docs/models/targetconfigunion1.md b/docs/models/targetconfigunion1.md deleted file mode 100644 index fd0cde750..000000000 --- a/docs/models/targetconfigunion1.md +++ /dev/null @@ -1,11 +0,0 @@ -# TargetConfigUnion1 - - -## Supported Types - -### `models.TargetConfig1` - -```python -value: models.TargetConfig1 = /* values here */ -``` - diff --git a/docs/models/targetconfigunion2.md b/docs/models/targetconfigunion2.md deleted file mode 100644 index a6561a527..000000000 --- a/docs/models/targetconfigunion2.md +++ /dev/null @@ -1,11 +0,0 @@ -# TargetConfigUnion2 - - -## Supported Types - -### `models.TargetConfig2` - -```python -value: models.TargetConfig2 = /* values here */ -``` - diff --git a/docs/models/targetconfigunion3.md b/docs/models/targetconfigunion3.md deleted file mode 100644 index 5e5ebfb15..000000000 --- a/docs/models/targetconfigunion3.md +++ /dev/null @@ -1,11 +0,0 @@ -# TargetConfigUnion3 - - -## Supported Types - -### `models.TargetConfig3` - -```python -value: models.TargetConfig3 = /* values here */ -``` - diff --git a/docs/models/teamaccesscontrollist.md b/docs/models/teamaccesscontrollist.md index dbea4e0a1..0a6f09bf8 100644 --- a/docs/models/teamaccesscontrollist.md +++ b/docs/models/teamaccesscontrollist.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | -| `perms` | List[[models.ResourcePolicy](../models/resourcepolicy.md)] | :heavy_check_mark: | N/A | -| `team` | *str* | :heavy_check_mark: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | --------------------------------------------------------------------------- | +| `perms` | List[[models.ResourcePolicy](../models/resourcepolicy.md)] | :heavy_check_mark: | List of resource policies that define the access permissions for this team. | +| `team` | *str* | :heavy_check_mark: | Name of the team whose access control entries are listed. | \ No newline at end of file diff --git a/docs/models/templatefamilyoptionscriblsourceprovenance.md b/docs/models/templatefamilyoptionscriblsourceprovenance.md new file mode 100644 index 000000000..1619060ce --- /dev/null +++ b/docs/models/templatefamilyoptionscriblsourceprovenance.md @@ -0,0 +1,21 @@ +# TemplateFamilyOptionsCriblSourceProvenance + +Infrastructure-as-code family that provisioned the AWS resources (absent means cloudformation). + +## Example Usage + +```python +from cribl_control_plane.models import TemplateFamilyOptionsCriblSourceProvenance + +value = TemplateFamilyOptionsCriblSourceProvenance.CLOUDFORMATION + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ---------------- | ---------------- | +| `CLOUDFORMATION` | cloudformation | +| `TERRAFORM` | terraform | \ No newline at end of file diff --git a/docs/models/timewarningtyperunnablejobcollectionschedulerun.md b/docs/models/timewarningtyperunnablejobcollectionschedulerun.md deleted file mode 100644 index e36568865..000000000 --- a/docs/models/timewarningtyperunnablejobcollectionschedulerun.md +++ /dev/null @@ -1,9 +0,0 @@ -# TimeWarningTypeRunnableJobCollectionScheduleRun - -Warning state used when the collection time range is unset for time-sensitive Collectors. - - -## Fields - -| Field | Type | Required | Description | -| ----------- | ----------- | ----------- | ----------- | \ No newline at end of file diff --git a/docs/models/tlssettingsserverside.md b/docs/models/tlssettingsserverside.md index c9a9a2bd9..12091ac5f 100644 --- a/docs/models/tlssettingsserverside.md +++ b/docs/models/tlssettingsserverside.md @@ -9,12 +9,12 @@ TLS settings (server side) | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | | `disabled` | *Optional[bool]* | :heavy_minus_sign: | Enable or disable TLS. Defaults to enabled for Cloudflare sources. | | `request_cert` | *Optional[bool]* | :heavy_minus_sign: | Require clients to present their certificates. Used to perform client authentication using SSL certs. | +| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's) | | `common_name_regex` | *Optional[str]* | :heavy_minus_sign: | Regex matching allowable common names in peer certificates' subject attribute | | `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of the predefined certificate | | `priv_key_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled. | | `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to use to decrypt private key | | `cert_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled. | -| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `min_version` | [Optional[models.MinimumTLSVersionOptionsTLS]](../models/minimumtlsversionoptionstls.md) | :heavy_minus_sign: | Minimum TLS version | | `max_version` | [Optional[models.MaximumTLSVersionOptionsTLS]](../models/maximumtlsversionoptionstls.md) | :heavy_minus_sign: | Maximum TLS version | \ No newline at end of file diff --git a/docs/models/tlssettingsserversidetype.md b/docs/models/tlssettingsserversidetype.md index aaaff38d3..01ec94d29 100644 --- a/docs/models/tlssettingsserversidetype.md +++ b/docs/models/tlssettingsserversidetype.md @@ -9,12 +9,12 @@ TLS settings (server side) | --------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------------------------- | | `disabled` | *Optional[bool]* | :heavy_minus_sign: | If true, TLS is disabled on this connection. | | `request_cert` | *Optional[bool]* | :heavy_minus_sign: | Require clients to present their certificates. Used to perform client authentication using SSL certs. | +| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `reject_unauthorized` | *Optional[bool]* | :heavy_minus_sign: | Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's) | | `common_name_regex` | *Optional[str]* | :heavy_minus_sign: | Regex matching allowable common names in peer certificates' subject attribute | | `certificate_name` | *Optional[str]* | :heavy_minus_sign: | The name of the predefined certificate | | `priv_key_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. | | `passphrase` | *Optional[str]* | :heavy_minus_sign: | Passphrase to use to decrypt private key | | `cert_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. | -| `ca_path` | *Optional[str]* | :heavy_minus_sign: | Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS. | | `min_version` | [Optional[models.MinimumTLSVersionOptionsTLS]](../models/minimumtlsversionoptionstls.md) | :heavy_minus_sign: | Minimum TLS version | | `max_version` | [Optional[models.MaximumTLSVersionOptionsTLS]](../models/maximumtlsversionoptionstls.md) | :heavy_minus_sign: | Maximum TLS version | \ No newline at end of file diff --git a/docs/models/updatepacksrequest.md b/docs/models/updatepacksrequest.md index 525525cf0..da25813f3 100644 --- a/docs/models/updatepacksrequest.md +++ b/docs/models/updatepacksrequest.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ------------------------------------ | ------------------------------------ | ------------------------------------ | ------------------------------------ | -| `filename` | *str* | :heavy_check_mark: | Filename of the Pack file to upload. | -| `request_body` | *Union[bytes, IO[bytes], io.IOBase]* | :heavy_check_mark: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | +| `filename` | *str* | :heavy_check_mark: | Filename of the Pack file to upload. | +| `request_body` | *Union[bytes, IO[bytes], io.IOBase]* | :heavy_check_mark: | Binary contents of the .crbl Pack file to stage for installation | \ No newline at end of file diff --git a/docs/models/useraccesscontrollist.md b/docs/models/useraccesscontrollist.md index df664151f..bf4b28b9c 100644 --- a/docs/models/useraccesscontrollist.md +++ b/docs/models/useraccesscontrollist.md @@ -3,7 +3,7 @@ ## Fields -| Field | Type | Required | Description | -| ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | ---------------------------------------------------------- | -| `perms` | List[[models.ResourcePolicy](../models/resourcepolicy.md)] | :heavy_check_mark: | N/A | -| `user` | *str* | :heavy_check_mark: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | +| `perms` | List[[models.ResourcePolicy](../models/resourcepolicy.md)] | :heavy_check_mark: | List of resource policies that define the access permissions for this member. | +| `user` | *str* | :heavy_check_mark: | Username of the member whose access control entries are listed. | \ No newline at end of file diff --git a/docs/models/v3authenticationkeytype.md b/docs/models/v3authenticationkeytype.md new file mode 100644 index 000000000..406d8dff8 --- /dev/null +++ b/docs/models/v3authenticationkeytype.md @@ -0,0 +1,21 @@ +# V3AuthenticationKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import V3AuthenticationKeyType + +value = V3AuthenticationKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/v3privacykeytype.md b/docs/models/v3privacykeytype.md new file mode 100644 index 000000000..f96be4cd0 --- /dev/null +++ b/docs/models/v3privacykeytype.md @@ -0,0 +1,21 @@ +# V3PrivacyKeyType + +Select Manual to enter the key directly, or Secret to use a stored text secret + +## Example Usage + +```python +from cribl_control_plane.models import V3PrivacyKeyType + +value = V3PrivacyKeyType.MANUAL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| -------- | -------- | +| `MANUAL` | manual | +| `SECRET` | secret | \ No newline at end of file diff --git a/docs/models/wizdefendsourcetype.md b/docs/models/wizdefendsourcetype.md new file mode 100644 index 000000000..2f537e015 --- /dev/null +++ b/docs/models/wizdefendsourcetype.md @@ -0,0 +1,27 @@ +# WizDefendSourceType + +The Wiz log source type. Select a predefined type or enter a custom value. + +## Example Usage + +```python +from cribl_control_plane.models import WizDefendSourceType + +value = WizDefendSourceType.AWS_CLOUDTRAIL + +# Open enum: unrecognized values are captured as UnrecognizedStr +``` + + +## Values + +| Name | Value | +| ------------------------- | ------------------------- | +| `AWS_CLOUDTRAIL` | AWS_CLOUDTRAIL | +| `AWS_EKS_AUDIT_LOGS` | AWS_EKS_AUDIT_LOGS | +| `AWS_RESOLVER_QUERY_LOGS` | AWS_RESOLVER_QUERY_LOGS | +| `AZURE_ACTIVITY_LOGS` | AZURE_ACTIVITY_LOGS | +| `GCP_AUDIT_LOGS` | GCP_AUDIT_LOGS | +| `GITHUB_AUDIT_LOGS` | GITHUB_AUDIT_LOGS | +| `OCI_AUDIT_LOGS` | OCI_AUDIT_LOGS | +| `AWS_VPC_FLOW_LOGS` | AWS_VPC_FLOW_LOGS | \ No newline at end of file diff --git a/docs/models/workerpqstatus.md b/docs/models/workerpqstatus.md index 1aa6bd2cf..f370fb359 100644 --- a/docs/models/workerpqstatus.md +++ b/docs/models/workerpqstatus.md @@ -3,9 +3,9 @@ ## Fields -| Field | Type | Required | Description | -| -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -------------------------------------------------------- | -| `error` | [Optional[models.StatusError]](../models/statuserror.md) | :heavy_minus_sign: | N/A | -| `health` | *float* | :heavy_check_mark: | N/A | -| `metrics` | Dict[str, *Any*] | :heavy_check_mark: | N/A | -| `timestamp` | *float* | :heavy_check_mark: | N/A | \ No newline at end of file +| Field | Type | Required | Description | +| ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `error` | [Optional[models.StatusError]](../models/statuserror.md) | :heavy_minus_sign: | N/A | +| `health` | *int* | :heavy_check_mark: | Persistent queue health status for the Worker Process, as a numeric code.

0 == Healthy (green; normal operation)

1 == Degraded (yellow; potential issues)

2 == Critical (red; problem or error that affects operation). | +| `metrics` | Dict[str, *Any*] | :heavy_check_mark: | Persistent-queue metrics reported for the Worker Process. | +| `timestamp` | *int* | :heavy_check_mark: | Timestamp (in Unix time) when the persistent queue status was last reported for the Worker Process, in milliseconds. | \ No newline at end of file diff --git a/docs/sdks/acl/README.md b/docs/sdks/acl/README.md index 82c699622..99cf03bfb 100644 --- a/docs/sdks/acl/README.md +++ b/docs/sdks/acl/README.md @@ -4,15 +4,15 @@ ### Available Operations -* [get](#get) - Get the Access Control List for a Worker Group, Outpost Group, or Edge Fleet +* [get](#get) - Get the user access control list for a Worker Group, Outpost Group, or Edge Fleet ## get -Get the Access Control List (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet. +Get the user access control list (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet.

This endpoint lists users with explicit access assignments on the Group or Fleet. The response does not include access granted through Team membership or inherited based on a user's Permissions and Roles at the Organization/Global, Workspace, or product level.

To list the Team ACL for a product and Group or Fleet, use GET /products/{product}/groups/{id}/acl/teams. ### Example Usage - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -36,7 +36,7 @@ with CriblControlPlane( | Parameter | Type | Required | Description | | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------- | -| `product` | [models.ProductsCore](../../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product to get the Worker Groups or Edge Fleets for. | +| `product` | [models.ProductsCore](../../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. | | `id` | *str* | :heavy_check_mark: | The id of the Worker Group, Outpost Group, or Edge Fleet to get the ACL for. | | `type` | [Optional[models.RbacResource]](../../models/rbacresource.md) | :heavy_minus_sign: | Filter for limiting the response to ACL entries for the specified RBAC resource type. | | `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | diff --git a/docs/sdks/collectorssdk/README.md b/docs/sdks/collectorssdk/README.md index 4788a0f3b..85c72086d 100644 --- a/docs/sdks/collectorssdk/README.md +++ b/docs/sdks/collectorssdk/README.md @@ -80,91 +80,10 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.create(request=models.SavedJobCollection( - id="", - description="pomelo outside offensively ew", - type=models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - "", - ], - resume_on_boot=True, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=True, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=3006.78, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=True, - max_task_reschedule=1211.14, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - job_timeout="", - mode="", - time_range_type="", - earliest=4847.66, - latest=3337.75, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=True, - collector=models.CollectorDatabase( - type=models.CollectorDatabaseType.DATABASE, - conf=models.DatabaseCollectorConf( - connection_id="", - query="", - query_validation_enabled=True, - default_breakers=models.HiddenDefaultBreakersOptionsDatabaseCollectorConf.CRIBL, - scheduling=models.DatabaseCollectorConfScheduling( - state_tracking=models.DatabaseCollectorConfStateTracking( - enabled=False, - ), - ), - ), - destructive=False, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - "", - "", - ], - stale_channel_flush_ms=3845.21, - send_to_routes=True, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), - )) + res = ccp_client.collectors.create(request={ + "type": models.JobTypeOptionsRunnableJobCollection.EXECUTOR, + "saved_query_id": "", + }) # Handle response print(res) @@ -186,44 +105,7 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.create(request={ - "id": "", - "description": "however loyally as likely silent", "type": models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - "ttl": "", - "ignore_group_jobs_limit": False, - "remove_fields": [ - "", - "", - "", - ], - "resume_on_boot": False, - "environment": "", - "schedule": { - "enabled": True, - "skippable": True, - "resume_missed": False, - "cron_schedule": "", - "max_concurrent_runs": 3006.78, - "run": { - "type": models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - "reschedule_dropped_tasks": True, - "max_task_reschedule": 1211.14, - "log_level": models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - "job_timeout": "", - "mode": "", - "time_range_type": "", - "earliest": 4847.66, - "latest": 3337.75, - "timestamp_timezone": "", - "time_warning": {}, - "expression": "", - "min_task_size": "", - "max_task_size": "", - }, - }, - "streamtags": [ - "", - ], "saved_query_id": "", }) @@ -247,45 +129,10 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.create(request={ - "id": "", - "description": "however loyally as likely silent", "type": models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - "ttl": "", - "ignore_group_jobs_limit": False, - "remove_fields": [ - "", - "", - "", - ], - "resume_on_boot": False, - "environment": "", - "schedule": { - "enabled": True, - "skippable": True, - "resume_missed": False, - "cron_schedule": "", - "max_concurrent_runs": 3006.78, - "run": { - "type": models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - "reschedule_dropped_tasks": True, - "max_task_reschedule": 1211.14, - "log_level": models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - "job_timeout": "", - "mode": "", - "time_range_type": "", - "earliest": 4847.66, - "latest": 3337.75, - "timestamp_timezone": "", - "time_warning": {}, - "expression": "", - "min_task_size": "", - "max_task_size": "", - }, + "executor": { + "type": "", }, - "streamtags": [ - "", - ], - "saved_query_id": "", }) # Handle response @@ -307,51 +154,25 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.create(request={ - "id": "", - "description": "against between cop-out wretched", - "type": models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - "ttl": "", - "ignore_group_jobs_limit": False, - "remove_fields": [ - "", - ], - "resume_on_boot": False, - "environment": "", - "schedule": { - "enabled": True, - "skippable": True, - "resume_missed": False, - "cron_schedule": "", - "max_concurrent_runs": 3006.78, - "run": { - "type": models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - "reschedule_dropped_tasks": True, - "max_task_reschedule": 1211.14, - "log_level": models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - "job_timeout": "", - "mode": "", - "time_range_type": "", - "earliest": 4847.66, - "latest": 3337.75, - "timestamp_timezone": "", - "time_warning": {}, - "expression": "", - "min_task_size": "", - "max_task_size": "", - }, - }, - "streamtags": [ - "", - "", - "", - ], - "executor": { - "type": "", - "store_task_results": True, - "conf": {}, - }, - }) + res = ccp_client.collectors.create(request=models.SavedJobCollection( + type=models.JobTypeOptionsRunnableJobCollection.EXECUTOR, + collector=models.CollectorDatabase( + type=models.CollectorDatabaseType.DATABASE, + conf=models.DatabaseCollectorConf( + connection_id="", + query="", + query_validation_enabled=True, + default_breakers=models.HiddenDefaultBreakersOptionsDatabaseCollectorConf.CRIBL, + scheduling=models.DatabaseCollectorConfScheduling( + state_tracking=models.DatabaseCollectorConfStateTracking( + enabled=False, + ), + ), + ), + destructive=False, + encoding="", + ), + )) # Handle response print(res) @@ -372,91 +193,12 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.create(request=models.SavedJobCollection( - id="", - description="pomelo outside offensively ew", - type=models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - "", - ], - resume_on_boot=True, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=True, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=3006.78, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=True, - max_task_reschedule=1211.14, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - job_timeout="", - mode="", - time_range_type="", - earliest=4847.66, - latest=3337.75, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=True, - collector=models.CollectorDatabase( - type=models.CollectorDatabaseType.DATABASE, - conf=models.DatabaseCollectorConf( - connection_id="", - query="", - query_validation_enabled=True, - default_breakers=models.HiddenDefaultBreakersOptionsDatabaseCollectorConf.CRIBL, - scheduling=models.DatabaseCollectorConfScheduling( - state_tracking=models.DatabaseCollectorConfStateTracking( - enabled=False, - ), - ), - ), - destructive=False, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - "", - "", - ], - stale_channel_flush_ms=3845.21, - send_to_routes=True, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), - )) + res = ccp_client.collectors.create(request={ + "type": models.JobTypeOptionsRunnableJobCollection.EXECUTOR, + "executor": { + "type": "", + }, + }) # Handle response print(res) @@ -478,45 +220,7 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.create(request=models.SavedJobCollection( - id="", - description="pomelo outside offensively ew", type=models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - "", - ], - resume_on_boot=True, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=True, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=3006.78, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=True, - max_task_reschedule=1211.14, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - job_timeout="", - mode="", - time_range_type="", - earliest=4847.66, - latest=3337.75, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=True, collector=models.CollectorDatabase( type=models.CollectorDatabaseType.DATABASE, conf=models.DatabaseCollectorConf( @@ -533,34 +237,6 @@ with CriblControlPlane( destructive=False, encoding="", ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - "", - "", - ], - stale_channel_flush_ms=3845.21, - send_to_routes=True, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), )) # Handle response @@ -583,45 +259,7 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.create(request=models.SavedJobCollection( - id="", - description="pomelo outside offensively ew", type=models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - "", - ], - resume_on_boot=True, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=True, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=3006.78, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=True, - max_task_reschedule=1211.14, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - job_timeout="", - mode="", - time_range_type="", - earliest=4847.66, - latest=3337.75, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=True, collector=models.CollectorDatabase( type=models.CollectorDatabaseType.DATABASE, conf=models.DatabaseCollectorConf( @@ -638,34 +276,6 @@ with CriblControlPlane( destructive=False, encoding="", ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - "", - "", - ], - stale_channel_flush_ms=3845.21, - send_to_routes=True, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), )) # Handle response @@ -688,45 +298,7 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.create(request=models.SavedJobCollection( - id="", - description="pomelo outside offensively ew", type=models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - "", - ], - resume_on_boot=True, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=True, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=3006.78, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=True, - max_task_reschedule=1211.14, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - job_timeout="", - mode="", - time_range_type="", - earliest=4847.66, - latest=3337.75, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=True, collector=models.CollectorDatabase( type=models.CollectorDatabaseType.DATABASE, conf=models.DatabaseCollectorConf( @@ -743,34 +315,6 @@ with CriblControlPlane( destructive=False, encoding="", ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - "", - "", - ], - stale_channel_flush_ms=3845.21, - send_to_routes=True, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), )) # Handle response @@ -792,91 +336,12 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.create(request=models.SavedJobCollection( - id="", - description="pomelo outside offensively ew", - type=models.JobTypeOptionsRunnableJobCollection.EXECUTOR, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - "", - ], - resume_on_boot=True, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=True, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=3006.78, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=True, - max_task_reschedule=1211.14, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.DEBUG, - job_timeout="", - mode="", - time_range_type="", - earliest=4847.66, - latest=3337.75, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=True, - collector=models.CollectorDatabase( - type=models.CollectorDatabaseType.DATABASE, - conf=models.DatabaseCollectorConf( - connection_id="", - query="", - query_validation_enabled=True, - default_breakers=models.HiddenDefaultBreakersOptionsDatabaseCollectorConf.CRIBL, - scheduling=models.DatabaseCollectorConfScheduling( - state_tracking=models.DatabaseCollectorConfStateTracking( - enabled=False, - ), - ), - ), - destructive=False, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - "", - "", - ], - stale_channel_flush_ms=3845.21, - send_to_routes=True, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), - )) + res = ccp_client.collectors.create(request={ + "type": models.JobTypeOptionsRunnableJobCollection.EXECUTOR, + "executor": { + "type": "", + }, + }) # Handle response print(res) @@ -1037,50 +502,20 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.update(id="", saved_job={ - "id": "", - "description": "sparse obnoxiously editor sticker finally into down", - "type": models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - "ttl": "", - "ignore_group_jobs_limit": False, - "remove_fields": [ - "", - ], - "resume_on_boot": False, - "environment": "", - "schedule": { - "enabled": True, - "skippable": False, - "resume_missed": False, - "cron_schedule": "", - "max_concurrent_runs": 1498.35, - "run": { - "type": models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - "reschedule_dropped_tasks": False, - "max_task_reschedule": 9677.47, - "log_level": models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - "job_timeout": "", - "mode": "", - "time_range_type": "", - "earliest": 8882.78, - "latest": 6778.74, - "timestamp_timezone": "", - "time_warning": {}, - "expression": "", - "min_task_size": "", - "max_task_size": "", - }, - }, - "streamtags": [ - "", - "", - ], - "executor": { - "type": "", - "store_task_results": True, - "conf": {}, - }, - }) + res = ccp_client.collectors.update(id="", saved_job=models.SavedJobCollection( + type=models.JobTypeOptionsRunnableJobCollection.COLLECTION, + collector=models.CollectorSplunk( + type=models.CollectorSplunkType.SPLUNK, + conf=models.SplunkAuthenticationToken( + authentication=models.SplunkAuthenticationTokenAuthentication.TOKEN, + token="", + search_head="", + search="", + endpoint="", + output_mode=models.OutputModeOptionsSplunkCollectorConf.JSON, + ), + ), + )) # Handle response print(res) @@ -1101,103 +536,12 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.update(id="", saved_job=models.SavedJobCollection( - id="", - description="unabashedly notwithstanding ugh digestive", - type=models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - ], - resume_on_boot=False, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=False, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=1498.35, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=False, - max_task_reschedule=9677.47, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - job_timeout="", - mode="", - time_range_type="", - earliest=8882.78, - latest=6778.74, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=False, - collector=models.CollectorS3( - type=models.CollectorS3Type.S3, - conf=models.S3AwsAuthenticationMethodAuto( - aws_authentication_method=models.AuthenticationMethodOptionsS3CollectorConf.AUTO, - output_name="", - bucket="", - parquet_chunk_size_mb=2532.22, - parquet_chunk_download_timeout=6271.26, - region="", - path="/selinux", - partitioning_scheme=models.S3AwsAuthenticationMethodAutoPartitioningScheme.NONE, - extractors=[ - models.S3AwsAuthenticationMethodAutoExtractor( - key="", - expression="", - ), - ], - endpoint="", - enable_assume_role=True, - assume_role_arn="", - assume_role_external_id="", - duration_seconds=2075.63, - max_batch_size=968.91, - reuse_connections=True, - reject_unauthorized=False, - verify_permissions=True, - disable_time_filter=True, - ), - destructive=True, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - ], - stale_channel_flush_ms=6331.52, - send_to_routes=False, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), - )) + res = ccp_client.collectors.update(id="", saved_job={ + "type": models.JobTypeOptionsRunnableJobCollection.COLLECTION, + "executor": { + "type": "", + }, + }) # Handle response print(res) @@ -1219,100 +563,17 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.update(id="", saved_job=models.SavedJobCollection( - id="", - description="unabashedly notwithstanding ugh digestive", - type=models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - ], - resume_on_boot=False, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=False, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=1498.35, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=False, - max_task_reschedule=9677.47, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - job_timeout="", - mode="", - time_range_type="", - earliest=8882.78, - latest=6778.74, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=False, - collector=models.CollectorS3( - type=models.CollectorS3Type.S3, - conf=models.S3AwsAuthenticationMethodAuto( - aws_authentication_method=models.AuthenticationMethodOptionsS3CollectorConf.AUTO, - output_name="", - bucket="", - parquet_chunk_size_mb=2532.22, - parquet_chunk_download_timeout=6271.26, - region="", - path="/selinux", - partitioning_scheme=models.S3AwsAuthenticationMethodAutoPartitioningScheme.NONE, - extractors=[ - models.S3AwsAuthenticationMethodAutoExtractor( - key="", - expression="", - ), - ], + type=models.JobTypeOptionsRunnableJobCollection.COLLECTION, + collector=models.CollectorSplunk( + type=models.CollectorSplunkType.SPLUNK, + conf=models.SplunkAuthenticationToken( + authentication=models.SplunkAuthenticationTokenAuthentication.TOKEN, + token="", + search_head="", + search="", endpoint="", - enable_assume_role=True, - assume_role_arn="", - assume_role_external_id="", - duration_seconds=2075.63, - max_batch_size=968.91, - reuse_connections=True, - reject_unauthorized=False, - verify_permissions=True, - disable_time_filter=True, - ), - destructive=True, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - ], - stale_channel_flush_ms=6331.52, - send_to_routes=False, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], + output_mode=models.OutputModeOptionsSplunkCollectorConf.JSON, ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", ), )) @@ -1336,44 +597,7 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.update(id="", saved_job={ - "id": "", - "description": "gee pomelo coincide animated yesterday fatally adolescent till inside rule", "type": models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - "ttl": "", - "ignore_group_jobs_limit": True, - "remove_fields": [ - "", - "", - "", - ], - "resume_on_boot": True, - "environment": "", - "schedule": { - "enabled": True, - "skippable": False, - "resume_missed": False, - "cron_schedule": "", - "max_concurrent_runs": 1498.35, - "run": { - "type": models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - "reschedule_dropped_tasks": False, - "max_task_reschedule": 9677.47, - "log_level": models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - "job_timeout": "", - "mode": "", - "time_range_type": "", - "earliest": 8882.78, - "latest": 6778.74, - "timestamp_timezone": "", - "time_warning": {}, - "expression": "", - "min_task_size": "", - "max_task_size": "", - }, - }, - "streamtags": [ - "", - ], "saved_query_id": "", }) @@ -1397,47 +621,9 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.update(id="", saved_job={ - "id": "", - "description": "sparse obnoxiously editor sticker finally into down", - "type": models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - "ttl": "", - "ignore_group_jobs_limit": False, - "remove_fields": [ - "", - ], - "resume_on_boot": False, - "environment": "", - "schedule": { - "enabled": True, - "skippable": False, - "resume_missed": False, - "cron_schedule": "", - "max_concurrent_runs": 1498.35, - "run": { - "type": models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - "reschedule_dropped_tasks": False, - "max_task_reschedule": 9677.47, - "log_level": models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - "job_timeout": "", - "mode": "", - "time_range_type": "", - "earliest": 8882.78, - "latest": 6778.74, - "timestamp_timezone": "", - "time_warning": {}, - "expression": "", - "min_task_size": "", - "max_task_size": "", - }, - }, - "streamtags": [ - "", - "", - ], + "type": models.JobTypeOptionsRunnableJobCollection.COLLECTION, "executor": { "type": "", - "store_task_results": True, - "conf": {}, }, }) @@ -1460,103 +646,10 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.update(id="", saved_job=models.SavedJobCollection( - id="", - description="unabashedly notwithstanding ugh digestive", - type=models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - ], - resume_on_boot=False, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=False, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=1498.35, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=False, - max_task_reschedule=9677.47, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - job_timeout="", - mode="", - time_range_type="", - earliest=8882.78, - latest=6778.74, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=False, - collector=models.CollectorS3( - type=models.CollectorS3Type.S3, - conf=models.S3AwsAuthenticationMethodAuto( - aws_authentication_method=models.AuthenticationMethodOptionsS3CollectorConf.AUTO, - output_name="", - bucket="", - parquet_chunk_size_mb=2532.22, - parquet_chunk_download_timeout=6271.26, - region="", - path="/selinux", - partitioning_scheme=models.S3AwsAuthenticationMethodAutoPartitioningScheme.NONE, - extractors=[ - models.S3AwsAuthenticationMethodAutoExtractor( - key="", - expression="", - ), - ], - endpoint="", - enable_assume_role=True, - assume_role_arn="", - assume_role_external_id="", - duration_seconds=2075.63, - max_batch_size=968.91, - reuse_connections=True, - reject_unauthorized=False, - verify_permissions=True, - disable_time_filter=True, - ), - destructive=True, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - ], - stale_channel_flush_ms=6331.52, - send_to_routes=False, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], - ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", - ), - )) + res = ccp_client.collectors.update(id="", saved_job={ + "type": models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, + "saved_query_id": "", + }) # Handle response print(res) @@ -1577,50 +670,20 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.collectors.update(id="", saved_job={ - "id": "", - "description": "sparse obnoxiously editor sticker finally into down", - "type": models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - "ttl": "", - "ignore_group_jobs_limit": False, - "remove_fields": [ - "", - ], - "resume_on_boot": False, - "environment": "", - "schedule": { - "enabled": True, - "skippable": False, - "resume_missed": False, - "cron_schedule": "", - "max_concurrent_runs": 1498.35, - "run": { - "type": models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - "reschedule_dropped_tasks": False, - "max_task_reschedule": 9677.47, - "log_level": models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - "job_timeout": "", - "mode": "", - "time_range_type": "", - "earliest": 8882.78, - "latest": 6778.74, - "timestamp_timezone": "", - "time_warning": {}, - "expression": "", - "min_task_size": "", - "max_task_size": "", - }, - }, - "streamtags": [ - "", - "", - ], - "executor": { - "type": "", - "store_task_results": True, - "conf": {}, - }, - }) + res = ccp_client.collectors.update(id="", saved_job=models.SavedJobCollection( + type=models.JobTypeOptionsRunnableJobCollection.COLLECTION, + collector=models.CollectorSplunk( + type=models.CollectorSplunkType.SPLUNK, + conf=models.SplunkAuthenticationToken( + authentication=models.SplunkAuthenticationTokenAuthentication.TOKEN, + token="", + search_head="", + search="", + endpoint="", + output_mode=models.OutputModeOptionsSplunkCollectorConf.JSON, + ), + ), + )) # Handle response print(res) @@ -1642,100 +705,17 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.update(id="", saved_job=models.SavedJobCollection( - id="", - description="unabashedly notwithstanding ugh digestive", - type=models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - ], - resume_on_boot=False, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=False, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=1498.35, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=False, - max_task_reschedule=9677.47, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - job_timeout="", - mode="", - time_range_type="", - earliest=8882.78, - latest=6778.74, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=False, - collector=models.CollectorS3( - type=models.CollectorS3Type.S3, - conf=models.S3AwsAuthenticationMethodAuto( - aws_authentication_method=models.AuthenticationMethodOptionsS3CollectorConf.AUTO, - output_name="", - bucket="", - parquet_chunk_size_mb=2532.22, - parquet_chunk_download_timeout=6271.26, - region="", - path="/selinux", - partitioning_scheme=models.S3AwsAuthenticationMethodAutoPartitioningScheme.NONE, - extractors=[ - models.S3AwsAuthenticationMethodAutoExtractor( - key="", - expression="", - ), - ], + type=models.JobTypeOptionsRunnableJobCollection.COLLECTION, + collector=models.CollectorSplunk( + type=models.CollectorSplunkType.SPLUNK, + conf=models.SplunkAuthenticationToken( + authentication=models.SplunkAuthenticationTokenAuthentication.TOKEN, + token="", + search_head="", + search="", endpoint="", - enable_assume_role=True, - assume_role_arn="", - assume_role_external_id="", - duration_seconds=2075.63, - max_batch_size=968.91, - reuse_connections=True, - reject_unauthorized=False, - verify_permissions=True, - disable_time_filter=True, - ), - destructive=True, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - ], - stale_channel_flush_ms=6331.52, - send_to_routes=False, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], + output_mode=models.OutputModeOptionsSplunkCollectorConf.JSON, ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", ), )) @@ -1759,100 +739,17 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.collectors.update(id="", saved_job=models.SavedJobCollection( - id="", - description="unabashedly notwithstanding ugh digestive", - type=models.JobTypeOptionsRunnableJobCollection.SCHEDULED_SEARCH, - ttl="", - ignore_group_jobs_limit=False, - remove_fields=[ - "", - ], - resume_on_boot=False, - environment="", - schedule=models.ScheduleTypeSavedJobResponseCollection( - enabled=True, - skippable=False, - resume_missed=False, - cron_schedule="", - max_concurrent_runs=1498.35, - run=models.RunSettingsTypeSavedJobResponseCollectionSchedule( - type=models.RunSettingsTypeSavedJobResponseCollectionScheduleType.COLLECTION, - reschedule_dropped_tasks=False, - max_task_reschedule=9677.47, - log_level=models.LogLevelOptionsRunnableJobCollectionScheduleRun.ERROR, - job_timeout="", - mode="", - time_range_type="", - earliest=8882.78, - latest=6778.74, - timestamp_timezone="", - time_warning=models.TimeWarningTypeRunnableJobCollectionScheduleRun(), - expression="", - min_task_size="", - max_task_size="", - ), - ), - streamtags=[ - "", - "", - ], - worker_affinity=False, - collector=models.CollectorS3( - type=models.CollectorS3Type.S3, - conf=models.S3AwsAuthenticationMethodAuto( - aws_authentication_method=models.AuthenticationMethodOptionsS3CollectorConf.AUTO, - output_name="", - bucket="", - parquet_chunk_size_mb=2532.22, - parquet_chunk_download_timeout=6271.26, - region="", - path="/selinux", - partitioning_scheme=models.S3AwsAuthenticationMethodAutoPartitioningScheme.NONE, - extractors=[ - models.S3AwsAuthenticationMethodAutoExtractor( - key="", - expression="", - ), - ], + type=models.JobTypeOptionsRunnableJobCollection.COLLECTION, + collector=models.CollectorSplunk( + type=models.CollectorSplunkType.SPLUNK, + conf=models.SplunkAuthenticationToken( + authentication=models.SplunkAuthenticationTokenAuthentication.TOKEN, + token="", + search_head="", + search="", endpoint="", - enable_assume_role=True, - assume_role_arn="", - assume_role_external_id="", - duration_seconds=2075.63, - max_batch_size=968.91, - reuse_connections=True, - reject_unauthorized=False, - verify_permissions=True, - disable_time_filter=True, - ), - destructive=True, - encoding="", - ), - input=models.InputTypeRunnableJobCollection( - type=models.TypeOptionsRunnableJobCollectionInput.COLLECTION, - breaker_rulesets=[ - "", - ], - stale_channel_flush_ms=6331.52, - send_to_routes=False, - preprocess=models.PreprocessType( - disabled=True, - command="", - args=[ - "", - "", - "", - ], + output_mode=models.OutputModeOptionsSplunkCollectorConf.JSON, ), - throttle_rate_per_sec="", - metadata=[ - models.MetadataConfInputCollection( - name="", - value="", - ), - ], - pipeline="", - output="", ), )) diff --git a/docs/sdks/cribl/README.md b/docs/sdks/cribl/README.md index df9f158a3..737d40914 100644 --- a/docs/sdks/cribl/README.md +++ b/docs/sdks/cribl/README.md @@ -53,7 +53,7 @@ with CriblControlPlane( ## update -Update the specified Cribl system settings.

Provide only the top-level sections (api, workers, tls, proxy, etc.) you want to change. Omitted sections stay unchanged. Each provided section fully replaces the existing one — send the complete section object, not only the changed fields. +Update the specified Cribl system settings.

Provide only the top-level sections (api, workers, tls, proxy, etc.) you want to change. Omitted sections stay unchanged. Each provided section fully replaces the existing one — send the complete section object, not only the changed fields.

api.loginRateLimit and api.ssoRateLimit are deprecated. A new value is still applied, but it is stored as rateLimits in the API limits configuration. Use PATCH /system/api-limits instead. ### Example Usage: UpdateSystemSettingsExamplesUpdateApiSettings @@ -75,10 +75,11 @@ with CriblControlPlane( "host": "0.0.0.0", "port": 9000, "ssl": { - "cert_path": "/opt/cribl/local/cribl/auth/cribl.crt", + "cert_path": "/opt/cribl/local/cribl/auth/myApiCert.crt", + "certificate_name": "myApiCert", "disabled": False, "passphrase": "", - "priv_key_path": "/opt/cribl/local/cribl/auth/cribl.key", + "priv_key_path": "/opt/cribl/local/cribl/auth/myApiCert.key", }, }, backups={ "backup_persistence": "24h", @@ -164,7 +165,7 @@ with CriblControlPlane( | Parameter | Type | Required | Description | | --------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | --------------------------------------------------------------------------------------------------- | -| `api` | [Optional[models.SystemSettingsConfUpdateAPI]](../../models/systemsettingsconfupdateapi.md) | :heavy_minus_sign: | API server configuration for the Cribl instance. | +| `api` | [Optional[models.API]](../../models/api.md) | :heavy_minus_sign: | API server configuration for the Cribl instance. | | `apps` | [Optional[models.Apps]](../../models/apps.md) | :heavy_minus_sign: | App configuration. | | `backups` | [Optional[models.BackupsSettingsUnion]](../../models/backupssettingsunion.md) | :heavy_minus_sign: | N/A | | `custom_logo` | [Optional[models.CustomLogo]](../../models/customlogo.md) | :heavy_minus_sign: | Custom logo configuration for the Cribl UI login page and navigation bar. | diff --git a/docs/sdks/databaseconnections/README.md b/docs/sdks/databaseconnections/README.md index ab9fe86dd..c5f6b444d 100644 --- a/docs/sdks/databaseconnections/README.md +++ b/docs/sdks/databaseconnections/README.md @@ -80,7 +80,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -101,7 +101,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -122,7 +122,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") # Handle response print(res) @@ -143,7 +143,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="erp,oracle,finance", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,oracle,finance", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -164,7 +164,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-secure-credentials", password="yourPassword", request_timeout=30000, tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-secure-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") # Handle response print(res) @@ -185,7 +185,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle database reached over TCPS with mutual TLS", id="oracle-mtls-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="tcps://oracle.example.com:2484/ORCL", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="Oracle_Pass456!", request_timeout=30000, tags="erp,oracle,mtls,production", text_secret="mysql-production-connection", tls=models.TLSClientParams( + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle database reached over TCPS with mutual TLS", id="oracle-mtls-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="tcps://oracle.example.com:2484/ORCL", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="Oracle_Pass456!", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,oracle,mtls,production", text_secret="mysql-production-connection", tls=models.TLSClientParams( certificate_name="oracle-client-cert", disabled=False, reject_unauthorized=True, @@ -210,7 +210,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="yourUsername") # Handle response print(res) @@ -231,7 +231,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://yourUsername:yourPassword@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://yourUsername:yourPassword@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -252,7 +252,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") # Handle response print(res) @@ -273,7 +273,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=60000, tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=60000, sslmode="VERIFY-FULL", tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -294,7 +294,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=yourUsername;Password=yourPassword;Encrypt=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=yourUsername;Password=yourPassword;Encrypt=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -315,7 +315,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=15000, tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=15000, sslmode="VERIFY-FULL", tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") # Handle response print(res) @@ -336,7 +336,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -357,7 +357,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.create(auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -375,9 +375,14 @@ with CriblControlPlane( | `config_obj` | *Optional[str]* | :heavy_minus_sign: | JSON configuration object for advanced SQL Server connection settings. | {
"server": "sqlserver.example.com",
"database": "Reporting",
"user": "yourUsername",
"password": "yourPassword",
"options": {
"connectTimeout": 20000
}
} | | `connection_string` | *Optional[str]* | :heavy_minus_sign: | Database connection string with embedded credentials or server information. | mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true | | `connection_timeout` | *Optional[int]* | :heavy_minus_sign: | Maximum time (in milliseconds) to wait when establishing the database connection. | 10000 | +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Name of the stored credentials secret containing username and password for SQL Server configObj authentication. | mssql-production-credentials | | `creds_secrets` | *Optional[str]* | :heavy_minus_sign: | Name of the stored credentials secret containing username and password. Used with Oracle connections. | oracle-production-credentials | +| `database` | *Optional[str]* | :heavy_minus_sign: | Database to connect to instead of the server default. | | +| `host` | *Optional[str]* | :heavy_minus_sign: | Hostname of the server to connect to. | 'myId-dt5egqq7iq1hj6kh.env.trial.example.com'
Hostname, currently intended for Teradata | +| `log_on_mechanism` | *Optional[str]* | :heavy_minus_sign: | Log On Mechanism for databases that support multiple, like Teradata. | | | `password` | *Optional[str]* | :heavy_minus_sign: | Database password for authentication. Used with Oracle connections. | yourPassword | | `request_timeout` | *Optional[int]* | :heavy_minus_sign: | Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only. | 30000 | +| `sslmode` | *Optional[str]* | :heavy_minus_sign: | HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior. | VERIFY-FULL | | `tags` | *Optional[str]* | :heavy_minus_sign: | Comma-separated list of tags for categorizing and filtering Database Connections. | production,mysql,customer-data | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Name of the stored text secret containing the connection string. | mysql-production-connection | | `tls` | [Optional[models.TLSClientParams]](../../models/tlsclientparams.md) | :heavy_minus_sign: | TLS client connection settings. | | @@ -462,7 +467,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -483,7 +488,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://admin:password123@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://admin:password123@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -504,7 +509,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") # Handle response print(res) @@ -525,7 +530,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="Oracle_Pass456!", request_timeout=30000, tags="erp,oracle,finance", text_secret="mysql-production-connection", user="erp_user") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="Oracle_Pass456!", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,oracle,finance", text_secret="mysql-production-connection", user="erp_user") # Handle response print(res) @@ -546,7 +551,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-secure-credentials", password="yourPassword", request_timeout=30000, tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-secure-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") # Handle response print(res) @@ -567,7 +572,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, creds_secrets="oracle-production-credentials", password="Warehouse_Pass789!", request_timeout=30000, tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="warehouse_user") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="Warehouse_Pass789!", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="warehouse_user") # Handle response print(res) @@ -588,7 +593,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://warehouse_user:SecurePass456@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://warehouse_user:SecurePass456@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -609,7 +614,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") # Handle response print(res) @@ -630,7 +635,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"report_user\",\"password\":\"Report_Pass123!\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=60000, tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"report_user\",\"password\":\"Report_Pass123!\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=60000, sslmode="VERIFY-FULL", tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -651,7 +656,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=erp_admin;Password=ERP_Pass789!;Encrypt=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=erp_admin;Password=ERP_Pass789!;Encrypt=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -672,7 +677,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=15000, tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=15000, sslmode="VERIFY-FULL", tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") # Handle response print(res) @@ -693,7 +698,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -714,7 +719,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://admin:password123@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://admin:password123@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -735,7 +740,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") # Handle response print(res) @@ -756,7 +761,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="Oracle_Pass456!", request_timeout=30000, tags="erp,oracle,finance", text_secret="mysql-production-connection", user="erp_user") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="Oracle_Pass456!", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,oracle,finance", text_secret="mysql-production-connection", user="erp_user") # Handle response print(res) @@ -777,7 +782,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-secure-credentials", password="yourPassword", request_timeout=30000, tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-secure-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") # Handle response print(res) @@ -798,7 +803,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, creds_secrets="oracle-production-credentials", password="Warehouse_Pass789!", request_timeout=30000, tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="warehouse_user") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="Warehouse_Pass789!", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="warehouse_user") # Handle response print(res) @@ -819,7 +824,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://warehouse_user:SecurePass456@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://warehouse_user:SecurePass456@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -840,7 +845,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") # Handle response print(res) @@ -861,7 +866,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"report_user\",\"password\":\"Report_Pass123!\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=60000, tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"report_user\",\"password\":\"Report_Pass123!\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=60000, sslmode="VERIFY-FULL", tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -882,7 +887,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=erp_admin;Password=ERP_Pass789!;Encrypt=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=erp_admin;Password=ERP_Pass789!;Encrypt=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -903,7 +908,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=15000, tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=15000, sslmode="VERIFY-FULL", tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") # Handle response print(res) @@ -924,7 +929,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.MYSQL, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -945,7 +950,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.MYSQL, description="Analytics MySQL database", id="mysql-analytics-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="analytics,mysql", text_secret="mysql-analytics-connection", user="yourUsername") # Handle response print(res) @@ -966,7 +971,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="erp,oracle,finance", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle ERP database", id="oracle-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="oracle.example.com:1521/ORCL", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,oracle,finance", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -987,7 +992,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-secure-credentials", password="yourPassword", request_timeout=30000, tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRETS, database_type=models.DatabaseConnectionType.ORACLE, description="High-security Oracle database with credential secrets", id="oracle-secure-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-secure-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="secure,oracle,sensitive-data", text_secret="oracle-secure-connection", user="yourUsername") # Handle response print(res) @@ -1008,7 +1013,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.ORACLE, description="Oracle data warehouse", id="oracle-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=20000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,oracle,reporting", text_secret="oracle-warehouse-connection", user="yourUsername") # Handle response print(res) @@ -1029,7 +1034,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://yourUsername:yourPassword@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.POSTGRES, description="Data warehouse PostgreSQL database", id="postgres-warehouse", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="postgresql://yourUsername:yourPassword@postgres.example.com:5432/warehouse?sslmode=require", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="warehouse,postgres,reporting", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -1050,7 +1055,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.POSTGRES, description="Logs PostgreSQL database", id="postgres-logs", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="logs,postgres", text_secret="postgres-logs-connection", user="yourUsername") # Handle response print(res) @@ -1071,7 +1076,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=60000, tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Reporting SQL Server database with custom config", id="sqlserver-reporting", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"encrypt\":true,\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=60000, sslmode="VERIFY-FULL", tags="reporting,sqlserver,analytics", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -1092,7 +1097,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=yourUsername;Password=yourPassword;Encrypt=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONNECTION_STRING, database_type=models.DatabaseConnectionType.SQLSERVER, description="ERP SQL Server database", id="sqlserver-erp", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="Server=sqlserver.example.com;Database=ERP;User Id=yourUsername;Password=yourPassword;Encrypt=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="erp,sqlserver,finance", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -1113,7 +1118,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=15000, tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.SECRET, database_type=models.DatabaseConnectionType.SQLSERVER, description="CRM SQL Server database", id="sqlserver-crm", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=15000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=15000, sslmode="VERIFY-FULL", tags="crm,sqlserver,sales", text_secret="sqlserver-crm-connection", user="yourUsername") # Handle response print(res) @@ -1134,7 +1139,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, creds_secrets="oracle-production-credentials", password="yourPassword", request_timeout=30000, tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") + res = ccp_client.database_connections.update(id_param="", auth_type=models.DatabaseConnectionAuthType.CONFIG_OBJ, database_type=models.DatabaseConnectionType.SQLSERVER, description="Production MySQL database for customer data", id="mysql-prod-db", config_obj="{\"server\":\"sqlserver.example.com\",\"database\":\"Reporting\",\"user\":\"yourUsername\",\"password\":\"yourPassword\",\"options\":{\"trustServerCertificate\":false,\"connectTimeout\":20000}}", connection_string="mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true", connection_timeout=10000, credentials_secret="mssql-production-credentials", creds_secrets="oracle-production-credentials", host="'myId-dt5egqq7iq1hj6kh.env.trial.example.com'\nHostname, currently intended for Teradata", password="yourPassword", request_timeout=30000, sslmode="VERIFY-FULL", tags="production,mysql,customer-data", text_secret="mysql-production-connection", user="yourUsername") # Handle response print(res) @@ -1153,9 +1158,14 @@ with CriblControlPlane( | `config_obj` | *Optional[str]* | :heavy_minus_sign: | JSON configuration object for advanced SQL Server connection settings. | {
"server": "sqlserver.example.com",
"database": "Reporting",
"user": "yourUsername",
"password": "yourPassword",
"options": {
"connectTimeout": 20000
}
} | | `connection_string` | *Optional[str]* | :heavy_minus_sign: | Database connection string with embedded credentials or server information. | mysql://yourUsername:yourPassword@mysql.example.com:3306/production?ssl=true | | `connection_timeout` | *Optional[int]* | :heavy_minus_sign: | Maximum time (in milliseconds) to wait when establishing the database connection. | 10000 | +| `credentials_secret` | *Optional[str]* | :heavy_minus_sign: | Name of the stored credentials secret containing username and password for SQL Server configObj authentication. | mssql-production-credentials | | `creds_secrets` | *Optional[str]* | :heavy_minus_sign: | Name of the stored credentials secret containing username and password. Used with Oracle connections. | oracle-production-credentials | +| `database` | *Optional[str]* | :heavy_minus_sign: | Database to connect to instead of the server default. | | +| `host` | *Optional[str]* | :heavy_minus_sign: | Hostname of the server to connect to. | 'myId-dt5egqq7iq1hj6kh.env.trial.example.com'
Hostname, currently intended for Teradata | +| `log_on_mechanism` | *Optional[str]* | :heavy_minus_sign: | Log On Mechanism for databases that support multiple, like Teradata. | | | `password` | *Optional[str]* | :heavy_minus_sign: | Database password for authentication. Used with Oracle connections. | yourPassword | | `request_timeout` | *Optional[int]* | :heavy_minus_sign: | Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only. | 30000 | +| `sslmode` | *Optional[str]* | :heavy_minus_sign: | HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior. | VERIFY-FULL | | `tags` | *Optional[str]* | :heavy_minus_sign: | Comma-separated list of tags for categorizing and filtering Database Connections. | production,mysql,customer-data | | `text_secret` | *Optional[str]* | :heavy_minus_sign: | Name of the stored text secret containing the connection string. | mysql-production-connection | | `tls` | [Optional[models.TLSClientParams]](../../models/tlsclientparams.md) | :heavy_minus_sign: | TLS client connection settings. | | diff --git a/docs/sdks/datasets/README.md b/docs/sdks/datasets/README.md index 34e241401..4772b0b4e 100644 --- a/docs/sdks/datasets/README.md +++ b/docs/sdks/datasets/README.md @@ -5,7 +5,7 @@ ### Available Operations * [list](#list) - List all Lake Datasets (Cribl.Cloud only) -* [create](#create) - Create a Lake Dataset (Cribl.Cloud only) +* [create](#create) - Create Lake Datasets (Cribl.Cloud only) * [get](#get) - Get a Lake Dataset (Cribl.Cloud only) * [update](#update) - Update a Lake Dataset (Cribl.Cloud only) * [delete](#delete) - Delete a Lake Dataset (Cribl.Cloud only) @@ -40,20 +40,26 @@ with CriblControlPlane( ### Parameters -| Parameter | Type | Required | Description | -| ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------- | -| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake that contains the Lake Datasets to list. | -| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Filter datasets by storage location ID. Use default for default storage location. | -| `format_` | [Optional[models.DatasetFormatFilter]](../../models/datasetformatfilter.md) | :heavy_minus_sign: | Filter datasets by format. Set to ddss to return only DDSS datasets. | -| `exclude_ddss` | *Optional[bool]* | :heavy_minus_sign: | Exclude DDSS format datasets from the response. | -| `exclude_netskope` | *Optional[bool]* | :heavy_minus_sign: | Exclude Netskope format datasets from the response. | -| `exclude_deleted` | *Optional[bool]* | :heavy_minus_sign: | Exclude deleted datasets from the response. | -| `exclude_internal` | *Optional[bool]* | :heavy_minus_sign: | Exclude internal datasets (those with IDs starting with cribl_) from the response. | -| `exclude_byos` | *Optional[bool]* | :heavy_minus_sign: | Exclude BYOS (Bring Your Own Storage) datasets from the response. | -| `include_metrics` | *Optional[bool]* | :heavy_minus_sign: | Set to true to include storage metrics for each Lake Dataset. Otherwise, false (default). Requires a Cribl Lake metrics license. | -| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | -| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | -| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake that contains the Lake Datasets to list. | +| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Filter datasets by storage location ID. Use default for default storage location. | +| `format_` | [Optional[models.DatasetFormatFilter]](../../models/datasetformatfilter.md) | :heavy_minus_sign: | Filter datasets by format. Set to ddss to return only DDSS datasets. | +| `exclude_ddss` | *Optional[bool]* | :heavy_minus_sign: | Exclude DDSS format datasets from the response. | +| `exclude_netskope` | *Optional[bool]* | :heavy_minus_sign: | Exclude Netskope format datasets from the response. | +| `exclude_deleted` | *Optional[bool]* | :heavy_minus_sign: | Exclude deleted datasets from the response. | +| `exclude_internal` | *Optional[bool]* | :heavy_minus_sign: | Exclude internal datasets (those with IDs starting with cribl_) from the response. | +| `exclude_byos` | *Optional[bool]* | :heavy_minus_sign: | Exclude BYOS (Bring Your Own Storage) datasets from the response. | +| `include_metrics` | *Optional[bool]* | :heavy_minus_sign: | Set to true to include storage metrics for each Lake Dataset. Otherwise, false (default). Requires a Cribl Lake metrics license. | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Starting point for catalog-backed pagination. Requires limit. | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Page size for catalog-backed pagination. Requires offset. | +| `order_by` | *Optional[str]* | :heavy_minus_sign: | Catalog sort field when paginating: name, createdAt, updatedAt, providerPath, type, or retentionPeriodInDays. Defaults to name. | +| `order_dir` | *Optional[str]* | :heavy_minus_sign: | Sort direction when paginating: asc or desc. Defaults to asc. | +| `name` | *Optional[str]* | :heavy_minus_sign: | Exact dataset name match (catalog path, with pagination). | +| `name_contains` | *Optional[str]* | :heavy_minus_sign: | Case-insensitive substring match on dataset name (catalog path, with pagination). | +| `provider_path_contains` | *Optional[str]* | :heavy_minus_sign: | Case-insensitive substring match on provider path (catalog path, with pagination). | +| `description_contains` | *Optional[str]* | :heavy_minus_sign: | Case-insensitive substring match on description (catalog path, with pagination). | +| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response @@ -69,8 +75,42 @@ with CriblControlPlane( ## create -Create a new Lake Dataset in the specified Lake (Cribl.Cloud only). +Creates one or more Lake Datasets in the specified Lake in a single transaction (Cribl.Cloud only). Send a single Lake Dataset object to create just one, or an array to bulk-create multiple. When an array is sent, the response is { items, errors } — items contains the successfully created Lake Datasets, and errors contains an entry ({ id, reason }) for each Lake Dataset that failed validation, so a per-item failure does not fail the rest of the batch. + +### Example Usage: LakeDatasetCreateExamplesBulkCreateDatasets + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.lakes.datasets.create(lake_id="", id="web_access_logs", accelerated_fields=[ + "host", + "status", + ], description="Web server access logs", format_=models.FormatOptionsCriblLakeDataset.JSON, retention_period_in_days=90, search_config={ + "metadata": { + "earliest": "-30d", + "enable_acceleration": False, + "field_list": [ + "", + "", + ], + "scan_mode": models.ScanMode.DETAILED, + }, + }, storage_location_id="my-storage-location") + + # Handle response + print(res) + +``` ### Example Usage: LakeDatasetCreateExamplesJsonDataset @@ -180,10 +220,11 @@ with CriblControlPlane( res = ccp_client.lakes.datasets.create(lake_id="", id="", search_config={ "metadata": { "earliest": "-30d", - "enable_acceleration": False, + "enable_acceleration": True, "field_list": [ "", "", + "", ], "scan_mode": models.ScanMode.DETAILED, }, @@ -196,24 +237,26 @@ with CriblControlPlane( ### Parameters -| Parameter | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake to create the Lake Dataset in. | -| `id` | *str* | :heavy_check_mark: | Unique identifier for the Dataset. | -| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | -| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | -| `cache_connection` | [Optional[models.CacheConnection]](../../models/cacheconnection.md) | :heavy_minus_sign: | N/A | -| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | -| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | -| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | -| `metrics` | [Optional[models.LakeDatasetMetrics]](../../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | -| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | -| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | -| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | -| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | -| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | -| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake to create the Lake Datasets in. | +| `id` | *str* | :heavy_check_mark: | Unique identifier for the Dataset. | +| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | +| `allow_record_erasure` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. | +| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | +| `cache_connection` | [Optional[models.CacheConnection]](../../models/cacheconnection.md) | :heavy_minus_sign: | N/A | +| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | +| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | +| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | +| `metrics` | [Optional[models.LakeDatasetMetrics]](../../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | +| `provider_path` | *Optional[str]* | :heavy_minus_sign: | Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). | +| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | +| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | +| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | +| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | +| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | +| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response @@ -378,25 +421,27 @@ with CriblControlPlane( ### Parameters -| Parameter | Type | Required | Description | -| -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------- | -| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake that contains the Lake Dataset to update. | -| `id_param` | *str* | :heavy_check_mark: | The id of the Lake Dataset to update. | -| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | -| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | -| `cache_connection` | [Optional[models.CacheConnection]](../../models/cacheconnection.md) | :heavy_minus_sign: | N/A | -| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | -| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | -| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | -| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | -| `id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Dataset. Optional; the path parameter id is authoritative. | -| `metrics` | [Optional[models.LakeDatasetMetrics]](../../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | -| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | -| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | -| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | -| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | -| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | -| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | +| Parameter | Type | Required | Description | +| -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | -------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | +| `lake_id` | *str* | :heavy_check_mark: | The id of the Lake that contains the Lake Dataset to update. | +| `id_param` | *str* | :heavy_check_mark: | The id of the Lake Dataset to update. | +| `accelerated_fields` | List[*str*] | :heavy_minus_sign: | Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. | +| `allow_record_erasure` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. | +| `bucket_name` | *Optional[str]* | :heavy_minus_sign: | Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. | +| `cache_connection` | [Optional[models.CacheConnection]](../../models/cacheconnection.md) | :heavy_minus_sign: | N/A | +| `deletion_started_at` | *Optional[float]* | :heavy_minus_sign: | Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. | +| `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Dataset. | +| `format_` | [Optional[models.FormatOptionsCriblLakeDataset]](../../models/formatoptionscribllakedataset.md) | :heavy_minus_sign: | Storage format used for data persisted in the Dataset. | +| `http_da_used` | *Optional[bool]* | :heavy_minus_sign: | If true, the Dataset is used by Direct Access HTTP. Otherwise, false. | +| `id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Dataset. Optional; the path parameter id is authoritative. | +| `metrics` | [Optional[models.LakeDatasetMetrics]](../../models/lakedatasetmetrics.md) | :heavy_minus_sign: | N/A | +| `provider_path` | *Optional[str]* | :heavy_minus_sign: | Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). | +| `retention_period_in_days` | *Optional[int]* | :heavy_minus_sign: | Dataset retention period, in days. | +| `search_config` | [Optional[models.LakeDatasetSearchConfig]](../../models/lakedatasetsearchconfig.md) | :heavy_minus_sign: | N/A | +| `storage_class` | [Optional[models.StorageClassOptionsCriblLakeDataset]](../../models/storageclassoptionscribllakedataset.md) | :heavy_minus_sign: | Storage class used for objects written to the Dataset. | +| `storage_location_id` | *Optional[str]* | :heavy_minus_sign: | Unique identifier for the Storage Location that backs the Dataset. Mutually exclusive with bucketName. | +| `view_name` | *Optional[str]* | :heavy_minus_sign: | Name of the ClickHouse view for the Dataset on the Lakehouse. | +| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response diff --git a/docs/sdks/destinations/README.md b/docs/sdks/destinations/README.md index 687481666..14f37d1d4 100644 --- a/docs/sdks/destinations/README.md +++ b/docs/sdks/destinations/README.md @@ -18,7 +18,7 @@ Get a list of all Destinations. ### Example Usage: OutputResponseExamplesS3Destination - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -41,7 +41,7 @@ with CriblControlPlane( ``` ### Example Usage: OutputResponseExamplesSnowflakeStreamingDestination - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -64,7 +64,7 @@ with CriblControlPlane( ``` ### Example Usage: OutputResponseExamplesSplunkHecDestination - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -87,7 +87,7 @@ with CriblControlPlane( ``` ### Example Usage: OutputResponseExamplesSyslogDestination - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -120,7 +120,7 @@ with CriblControlPlane( ### Response -**[models.ListOutputResponse](../../models/listoutputresponse.md)** +**[models.GetOutputResponse](../../models/getoutputresponse.md)** ### Errors @@ -517,76 +517,76 @@ with CriblControlPlane( "tls": { "disabled": True, }, - "token_ttl_minutes": 60, + "token_ttl_minutes": 60.0, "exclude_fields": [ "__kube_*", "__metadata", "__winEvent", ], "compression": models.CompressionOptionsGzipNone.GZIP, - "concurrency": 5, - "max_payload_size_kb": 4096, - "max_payload_events": 0, + "concurrency": 5.0, + "max_payload_size_kb": 4096.0, + "max_payload_events": 0.0, "reject_unauthorized": True, - "timeout_sec": 30, - "flush_period_sec": 1, + "timeout_sec": 30.0, + "flush_period_sec": 1.0, "failed_request_logging_mode": models.FailedRequestLoggingModeOptions.NONE, "safe_headers": [], "throttle_rate_per_sec": "0", "response_retry_settings": [ { - "http_status": 401, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 401.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 403, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 403.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 408, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 408.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 429, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 429.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 500, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 500.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 502, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 502.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 503, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 503.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 504, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 504.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 509, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 509.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, ], "timeout_retry_settings": { @@ -621,7 +621,7 @@ with CriblControlPlane( "id": "cribl-tcp-output", "type": models.TypeOptionsCribltcp.CRIBL_TCP, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -648,7 +648,7 @@ with CriblControlPlane( "type": models.CreateOutputOutputCrowdstrikeNextGenSiemType.CROWDSTRIKE_NEXT_GEN_SIEM, "url": "https://ingest.us.crowdstrike.com/api/ingest/hec/connection-id/v1/services/collector", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -713,6 +713,36 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: OutputCreateExamplesDatabricksZerobus + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.destinations.create(request={ + "id": "databricks-zerobus-output", + "type": models.CreateOutputOutputDatabricksZerobusType.DATABRICKS_ZEROBUS, + "workspace_url": "https://dbc-1234abcd-5e6f.cloud.databricks.com", + "workspace_id": "your-workspace-id", + "zerobus_endpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", + "client_id": "your-client-id", + "client_text_secret": "your-client-secret", + "table_name": "main.external.events", + }) + + # Handle response + print(res) + ``` ### Example Usage: OutputCreateExamplesDatadog @@ -946,6 +976,8 @@ with CriblControlPlane( "stage_path": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collector_instance_id": "11112222-3333-4444-5555-666677778888", + "aws_authentication_method": models.CreateOutputOutputExabeamAuthenticationMethod.SECRET, + "aws_secret": "my-secret-id", }) # Handle response @@ -1182,7 +1214,7 @@ with CriblControlPlane( "type": models.CreateOutputOutputGraphiteType.GRAPHITE, "protocol": models.DestinationProtocolOptions.TCP, "host": "localhost", - "port": 2003, + "port": 2003.0, }) # Handle response @@ -1234,7 +1266,7 @@ with CriblControlPlane( "type": models.CreateOutputOutputHumioHecType.HUMIO_HEC, "url": "https://cloud.us.humio.com/api/v1/ingest/hec", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -1478,7 +1510,7 @@ with CriblControlPlane( "hosts": [ { "host": "localhost", - "port": 2055, + "port": 2055.0, }, ], }) @@ -1746,9 +1778,9 @@ with CriblControlPlane( "id": "sentinel-output", "type": models.CreateOutputOutputSentinelType.SENTINEL, "login_url": "https://login.microsoftonline.com", - "secret": "client-secret", "client_id": "client-id", "endpoint_url_configuration": models.CreateOutputEndpointConfiguration.URL, + "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com", }) @@ -1857,7 +1889,7 @@ with CriblControlPlane( "hosts": [ { "host": "192.168.1.1", - "port": 161, + "port": 161.0, }, ], }) @@ -1944,7 +1976,7 @@ with CriblControlPlane( "id": "splunk-output", "type": models.TypeOptionsSplunk.SPLUNK, "host": "localhost", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -1996,7 +2028,7 @@ with CriblControlPlane( hosts=[ models.HostConfOutputSyslog( host="localhost", - port=9997, + port=9997.0, ), ], )) @@ -2052,7 +2084,7 @@ with CriblControlPlane( "type": models.CreateOutputOutputStatsdType.STATSD, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -2079,7 +2111,7 @@ with CriblControlPlane( "type": models.CreateOutputOutputStatsdExtType.STATSD_EXT, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -2157,7 +2189,7 @@ with CriblControlPlane( "id": "syslog-output", "type": models.TypeOptionsSyslog.SYSLOG, "host": "localhost", - "port": 514, + "port": 514.0, }) # Handle response @@ -2183,7 +2215,33 @@ with CriblControlPlane( "id": "tcpjson-output", "type": models.TypeOptionsTcpjson.TCPJSON, "host": "localhost", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: OutputCreateExamplesTraversalOtlp + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.destinations.create(request={ + "id": "traversal-output", + "type": models.CreateOutputOutputTraversalOtlpType.TRAVERSAL_OTLP, + "endpoint": "http://traversal-processor:3000", + "protocol": models.ProtocolOptions.HTTP, }) # Handle response @@ -2259,11 +2317,42 @@ with CriblControlPlane( res = ccp_client.destinations.create(request={ "id": "wiz-hec-output", "type": models.CreateOutputOutputWizHecType.WIZ_HEC, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", - "wiz_sourcetype": "placeholder", + "wiz_sourcetype": models.CreateOutputWizDefendSourceType.AWS_CLOUDTRAIL, + }) + + # Handle response + print(res) + +``` +### Example Usage: OutputCreateExamplesWizHecVpcFlowLogs + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.destinations.create(request={ + "id": "wiz-hec-vpc-flow-logs-output", + "type": models.CreateOutputOutputWizHecType.WIZ_HEC, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, + "wiz_connector_id": "00000000-0000-0000-0000-000000000000", + "wiz_environment": "test", + "data_center": "us1", + "wiz_sourcetype": models.CreateOutputWizDefendSourceType.AWS_VPC_FLOW_LOGS, + "wiz_vpc_event_format": models.CreateOutputEventFormat.CSV_ROW, + "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}", }) # Handle response @@ -3044,76 +3133,76 @@ with CriblControlPlane( "tls": { "disabled": True, }, - "token_ttl_minutes": 60, + "token_ttl_minutes": 60.0, "exclude_fields": [ "__kube_*", "__metadata", "__winEvent", ], "compression": models.CompressionOptionsGzipNone.GZIP, - "concurrency": 5, - "max_payload_size_kb": 4096, - "max_payload_events": 0, + "concurrency": 5.0, + "max_payload_size_kb": 4096.0, + "max_payload_events": 0.0, "reject_unauthorized": True, - "timeout_sec": 30, - "flush_period_sec": 1, + "timeout_sec": 30.0, + "flush_period_sec": 1.0, "failed_request_logging_mode": models.FailedRequestLoggingModeOptions.NONE, "safe_headers": [], "throttle_rate_per_sec": "0", "response_retry_settings": [ { - "http_status": 401, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 401.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 403, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 403.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 408, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 408.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 429, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 429.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 500, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 500.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 502, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 502.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 503, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 503.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 504, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 504.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 509, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 509.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, ], "timeout_retry_settings": { @@ -3148,7 +3237,7 @@ with CriblControlPlane( "id": "cribl-tcp-output", "type": models.TypeOptionsCribltcp.CRIBL_TCP, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -3175,7 +3264,7 @@ with CriblControlPlane( "type": models.OutputCrowdstrikeNextGenSiemType.CROWDSTRIKE_NEXT_GEN_SIEM, "url": "https://ingest.us.crowdstrike.com/api/ingest/hec/connection-id/v1/services/collector", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -3629,7 +3718,7 @@ with CriblControlPlane( "type": models.OutputGraphiteType.GRAPHITE, "protocol": models.DestinationProtocolOptions.TCP, "host": "localhost", - "port": 2003, + "port": 2003.0, }) # Handle response @@ -3681,7 +3770,7 @@ with CriblControlPlane( "type": models.OutputHumioHecType.HUMIO_HEC, "url": "https://cloud.us.humio.com/api/v1/ingest/hec", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -3925,7 +4014,7 @@ with CriblControlPlane( "hosts": [ { "host": "localhost", - "port": 2055, + "port": 2055.0, }, ], }) @@ -4193,9 +4282,9 @@ with CriblControlPlane( "id": "sentinel-output", "type": models.OutputSentinelType.SENTINEL, "login_url": "https://login.microsoftonline.com", - "secret": "client-secret", "client_id": "client-id", "endpoint_url_configuration": models.EndpointConfiguration.URL, + "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com", }) @@ -4304,7 +4393,7 @@ with CriblControlPlane( "hosts": [ { "host": "192.168.1.1", - "port": 161, + "port": 161.0, }, ], }) @@ -4359,7 +4448,7 @@ with CriblControlPlane( "id": "splunk-output", "type": models.TypeOptionsSplunk.SPLUNK, "host": "localhost", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -4411,7 +4500,7 @@ with CriblControlPlane( hosts=[ models.HostConfOutputSyslog( host="localhost", - port=9997, + port=9997.0, ), ], )) @@ -4467,7 +4556,7 @@ with CriblControlPlane( "type": models.OutputStatsdType.STATSD, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -4494,7 +4583,7 @@ with CriblControlPlane( "type": models.OutputStatsdExtType.STATSD_EXT, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -4572,7 +4661,7 @@ with CriblControlPlane( "id": "syslog-output", "type": models.TypeOptionsSyslog.SYSLOG, "host": "localhost", - "port": 514, + "port": 514.0, }) # Handle response @@ -4598,7 +4687,7 @@ with CriblControlPlane( "id": "tcpjson-output", "type": models.TypeOptionsTcpjson.TCPJSON, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4674,11 +4763,10 @@ with CriblControlPlane( res = ccp_client.destinations.update(id="", output={ "id": "wiz-hec-output", "type": models.OutputWizHecType.WIZ_HEC, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", - "wiz_sourcetype": "placeholder", }) # Handle response @@ -5327,76 +5415,76 @@ with CriblControlPlane( "tls": { "disabled": True, }, - "token_ttl_minutes": 60, + "token_ttl_minutes": 60.0, "exclude_fields": [ "__kube_*", "__metadata", "__winEvent", ], "compression": models.CompressionOptionsGzipNone.GZIP, - "concurrency": 5, - "max_payload_size_kb": 4096, - "max_payload_events": 0, + "concurrency": 5.0, + "max_payload_size_kb": 4096.0, + "max_payload_events": 0.0, "reject_unauthorized": True, - "timeout_sec": 30, - "flush_period_sec": 1, + "timeout_sec": 30.0, + "flush_period_sec": 1.0, "failed_request_logging_mode": models.FailedRequestLoggingModeOptions.NONE, "safe_headers": [], "throttle_rate_per_sec": "0", "response_retry_settings": [ { - "http_status": 401, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 401.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 403, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 403.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 408, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 408.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 429, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 429.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 500, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 500.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 502, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 502.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 503, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 503.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 504, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 504.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 509, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 509.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, ], "timeout_retry_settings": { @@ -5431,7 +5519,7 @@ with CriblControlPlane( "id": "cribl-tcp-output", "type": models.TypeOptionsCribltcp.CRIBL_TCP, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -5458,7 +5546,7 @@ with CriblControlPlane( "type": models.OutputCrowdstrikeNextGenSiemType.CROWDSTRIKE_NEXT_GEN_SIEM, "url": "https://ingest.us.crowdstrike.com/api/ingest/hec/connection-id/v1/services/collector", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -5523,6 +5611,36 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateOutputExamplesDatabricksZerobus + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.destinations.update(id="", output={ + "id": "databricks-zerobus-output", + "type": models.OutputDatabricksZerobusType.DATABRICKS_ZEROBUS, + "workspace_url": "https://dbc-1234abcd-5e6f.cloud.databricks.com", + "workspace_id": "your-workspace-id", + "zerobus_endpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", + "client_id": "your-client-id", + "client_text_secret": "your-client-secret", + "table_name": "main.external.events", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateOutputExamplesDatadog @@ -5781,6 +5899,8 @@ with CriblControlPlane( "stage_path": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collector_instance_id": "11112222-3333-4444-5555-666677778888", + "aws_authentication_method": models.OutputExabeamAuthenticationMethod.SECRET, + "aws_secret": "my-secret-id", }) # Handle response @@ -6017,7 +6137,7 @@ with CriblControlPlane( "type": models.OutputGraphiteType.GRAPHITE, "protocol": models.DestinationProtocolOptions.TCP, "host": "localhost", - "port": 2003, + "port": 2003.0, }) # Handle response @@ -6069,7 +6189,7 @@ with CriblControlPlane( "type": models.OutputHumioHecType.HUMIO_HEC, "url": "https://cloud.us.humio.com/api/v1/ingest/hec", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -6313,7 +6433,7 @@ with CriblControlPlane( "hosts": [ { "host": "localhost", - "port": 2055, + "port": 2055.0, }, ], }) @@ -6581,9 +6701,9 @@ with CriblControlPlane( "id": "sentinel-output", "type": models.OutputSentinelType.SENTINEL, "login_url": "https://login.microsoftonline.com", - "secret": "client-secret", "client_id": "client-id", "endpoint_url_configuration": models.EndpointConfiguration.URL, + "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com", }) @@ -6692,7 +6812,7 @@ with CriblControlPlane( "hosts": [ { "host": "192.168.1.1", - "port": 161, + "port": 161.0, }, ], }) @@ -6779,7 +6899,7 @@ with CriblControlPlane( "id": "splunk-output", "type": models.TypeOptionsSplunk.SPLUNK, "host": "localhost", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -6831,7 +6951,7 @@ with CriblControlPlane( hosts=[ models.HostConfOutputSyslog( host="localhost", - port=9997, + port=9997.0, ), ], )) @@ -6887,7 +7007,7 @@ with CriblControlPlane( "type": models.OutputStatsdType.STATSD, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -6914,7 +7034,7 @@ with CriblControlPlane( "type": models.OutputStatsdExtType.STATSD_EXT, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -6992,7 +7112,7 @@ with CriblControlPlane( "id": "syslog-output", "type": models.TypeOptionsSyslog.SYSLOG, "host": "localhost", - "port": 514, + "port": 514.0, }) # Handle response @@ -7018,7 +7138,33 @@ with CriblControlPlane( "id": "tcpjson-output", "type": models.TypeOptionsTcpjson.TCPJSON, "host": "localhost", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateOutputExamplesTraversalOtlp + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.destinations.update(id="", output={ + "id": "traversal-output", + "type": models.OutputTraversalOtlpType.TRAVERSAL_OTLP, + "endpoint": "http://traversal-processor:3000", + "protocol": models.ProtocolOptions.HTTP, }) # Handle response @@ -7094,11 +7240,42 @@ with CriblControlPlane( res = ccp_client.destinations.update(id="", output={ "id": "wiz-hec-output", "type": models.OutputWizHecType.WIZ_HEC, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, + "wiz_connector_id": "00000000-0000-0000-0000-000000000000", + "wiz_environment": "test", + "data_center": "us1", + "wiz_sourcetype": models.WizDefendSourceType.AWS_CLOUDTRAIL, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateOutputExamplesWizHecVpcFlowLogs + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.destinations.update(id="", output={ + "id": "wiz-hec-vpc-flow-logs-output", + "type": models.OutputWizHecType.WIZ_HEC, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", - "wiz_sourcetype": "placeholder", + "wiz_sourcetype": models.WizDefendSourceType.AWS_VPC_FLOW_LOGS, + "wiz_vpc_event_format": models.OutputWizHecEventFormat.CSV_ROW, + "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}", }) # Handle response diff --git a/docs/sdks/groupssdk/README.md b/docs/sdks/groupssdk/README.md index 373d861f0..906bc91d8 100644 --- a/docs/sdks/groupssdk/README.md +++ b/docs/sdks/groupssdk/README.md @@ -224,6 +224,8 @@ with CriblControlPlane( | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | ----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- | | `product` | [models.ProductsCore](../../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product to add the Worker Group, Outpost Group, or Edge Fleet to. | | | `id` | *str* | :heavy_check_mark: | Unique identifier. | | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | | | `cloud` | [Optional[models.ConfigGroupCloud]](../../models/configgroupcloud.md) | :heavy_minus_sign: | N/A | | | `collectors_ha_enabled` | *Optional[bool]* | :heavy_minus_sign: | Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. | | | `description` | *Optional[str]* | :heavy_minus_sign: | Brief description of the Worker Group, Outpost Group, or Edge Fleet. | | @@ -402,6 +404,8 @@ with CriblControlPlane( | `product` | [models.ProductsCore](../../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. | | | `id_param` | *str* | :heavy_check_mark: | The id of the Worker Group, Outpost Group, or Edge Fleet to update. | | | `id` | *str* | :heavy_check_mark: | Unique identifier. | | +| `src_group` | *Optional[str]* | :heavy_minus_sign: | Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. | | +| `src_overridden` | *Optional[bool]* | :heavy_minus_sign: | If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. | | | `cloud` | [Optional[models.ConfigGroupCloud]](../../models/configgroupcloud.md) | :heavy_minus_sign: | N/A | | | `collectors_ha_enabled` | *Optional[bool]* | :heavy_minus_sign: | Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. | | | `config_version` | *Optional[str]* | :heavy_minus_sign: | Commit hash of the deployed configuration version for the Worker Group, Outpost Group, or Edge Fleet. Automatically populated and returned in responses.

**Warning**: Do not change the value of configVersion in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response. | | diff --git a/docs/sdks/packs/README.md b/docs/sdks/packs/README.md index 6eeda919a..a4c063204 100644 --- a/docs/sdks/packs/README.md +++ b/docs/sdks/packs/README.md @@ -351,11 +351,11 @@ with CriblControlPlane( ### Parameters -| Parameter | Type | Required | Description | -| ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | -| `filename` | *str* | :heavy_check_mark: | Filename of the Pack file to upload. | -| `request_body` | *Union[bytes, IO[bytes], io.IOBase]* | :heavy_check_mark: | N/A | -| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | +| Parameter | Type | Required | Description | +| ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | ----------------------------------------------------------------------------- | +| `filename` | *str* | :heavy_check_mark: | Filename of the Pack file to upload. | +| `request_body` | *Union[bytes, IO[bytes], io.IOBase]* | :heavy_check_mark: | Binary contents of the .crbl Pack file to stage for installation | +| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response diff --git a/docs/sdks/packsdestinations/README.md b/docs/sdks/packsdestinations/README.md index 41b7d9f15..151bc2c13 100644 --- a/docs/sdks/packsdestinations/README.md +++ b/docs/sdks/packsdestinations/README.md @@ -516,76 +516,76 @@ with CriblControlPlane( "tls": { "disabled": True, }, - "token_ttl_minutes": 60, + "token_ttl_minutes": 60.0, "exclude_fields": [ "__kube_*", "__metadata", "__winEvent", ], "compression": models.CompressionOptionsGzipNone.GZIP, - "concurrency": 5, - "max_payload_size_kb": 4096, - "max_payload_events": 0, + "concurrency": 5.0, + "max_payload_size_kb": 4096.0, + "max_payload_events": 0.0, "reject_unauthorized": True, - "timeout_sec": 30, - "flush_period_sec": 1, + "timeout_sec": 30.0, + "flush_period_sec": 1.0, "failed_request_logging_mode": models.FailedRequestLoggingModeOptions.NONE, "safe_headers": [], "throttle_rate_per_sec": "0", "response_retry_settings": [ { - "http_status": 401, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 401.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 403, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 403.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 408, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 408.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 429, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 429.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 500, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 500.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 502, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 502.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 503, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 503.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 504, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 504.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 509, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 509.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, ], "timeout_retry_settings": { @@ -620,7 +620,7 @@ with CriblControlPlane( "id": "cribl-tcp-output", "type": models.TypeOptionsCribltcp.CRIBL_TCP, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -647,7 +647,7 @@ with CriblControlPlane( "type": models.CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType.CROWDSTRIKE_NEXT_GEN_SIEM, "url": "https://ingest.us.crowdstrike.com/api/ingest/hec/connection-id/v1/services/collector", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -712,6 +712,36 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: OutputCreateExamplesDatabricksZerobus + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.destinations.create(pack="", request_body={ + "id": "databricks-zerobus-output", + "type": models.CreateOutputSystemByPackOutputDatabricksZerobusType.DATABRICKS_ZEROBUS, + "workspace_url": "https://dbc-1234abcd-5e6f.cloud.databricks.com", + "workspace_id": "your-workspace-id", + "zerobus_endpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", + "client_id": "your-client-id", + "client_text_secret": "your-client-secret", + "table_name": "main.external.events", + }) + + # Handle response + print(res) + ``` ### Example Usage: OutputCreateExamplesDatadog @@ -945,6 +975,8 @@ with CriblControlPlane( "stage_path": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collector_instance_id": "11112222-3333-4444-5555-666677778888", + "aws_authentication_method": models.CreateOutputSystemByPackOutputExabeamAuthenticationMethod.SECRET, + "aws_secret": "my-secret-id", }) # Handle response @@ -1181,7 +1213,7 @@ with CriblControlPlane( "type": models.CreateOutputSystemByPackOutputGraphiteType.GRAPHITE, "protocol": models.DestinationProtocolOptions.TCP, "host": "localhost", - "port": 2003, + "port": 2003.0, }) # Handle response @@ -1233,7 +1265,7 @@ with CriblControlPlane( "type": models.CreateOutputSystemByPackOutputHumioHecType.HUMIO_HEC, "url": "https://cloud.us.humio.com/api/v1/ingest/hec", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -1477,7 +1509,7 @@ with CriblControlPlane( "hosts": [ { "host": "localhost", - "port": 2055, + "port": 2055.0, }, ], }) @@ -1745,9 +1777,9 @@ with CriblControlPlane( "id": "sentinel-output", "type": models.CreateOutputSystemByPackOutputSentinelType.SENTINEL, "login_url": "https://login.microsoftonline.com", - "secret": "client-secret", "client_id": "client-id", "endpoint_url_configuration": models.CreateOutputSystemByPackEndpointConfiguration.URL, + "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com", }) @@ -1856,7 +1888,7 @@ with CriblControlPlane( "hosts": [ { "host": "192.168.1.1", - "port": 161, + "port": 161.0, }, ], }) @@ -1943,7 +1975,7 @@ with CriblControlPlane( "id": "splunk-output", "type": models.TypeOptionsSplunk.SPLUNK, "host": "localhost", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -1995,7 +2027,7 @@ with CriblControlPlane( hosts=[ models.HostConfOutputSyslog( host="localhost", - port=9997, + port=9997.0, ), ], )) @@ -2051,7 +2083,7 @@ with CriblControlPlane( "type": models.CreateOutputSystemByPackOutputStatsdType.STATSD, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -2078,7 +2110,7 @@ with CriblControlPlane( "type": models.CreateOutputSystemByPackOutputStatsdExtType.STATSD_EXT, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -2156,7 +2188,7 @@ with CriblControlPlane( "id": "syslog-output", "type": models.TypeOptionsSyslog.SYSLOG, "host": "localhost", - "port": 514, + "port": 514.0, }) # Handle response @@ -2182,7 +2214,33 @@ with CriblControlPlane( "id": "tcpjson-output", "type": models.TypeOptionsTcpjson.TCPJSON, "host": "localhost", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: OutputCreateExamplesTraversalOtlp + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.destinations.create(pack="", request_body={ + "id": "traversal-output", + "type": models.CreateOutputSystemByPackOutputTraversalOtlpType.TRAVERSAL_OTLP, + "endpoint": "http://traversal-processor:3000", + "protocol": models.ProtocolOptions.HTTP, }) # Handle response @@ -2258,11 +2316,42 @@ with CriblControlPlane( res = ccp_client.packs.destinations.create(pack="", request_body={ "id": "wiz-hec-output", "type": models.CreateOutputSystemByPackOutputWizHecType.WIZ_HEC, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", - "wiz_sourcetype": "placeholder", + "wiz_sourcetype": models.CreateOutputSystemByPackWizDefendSourceType.AWS_CLOUDTRAIL, + }) + + # Handle response + print(res) + +``` +### Example Usage: OutputCreateExamplesWizHecVpcFlowLogs + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.destinations.create(pack="", request_body={ + "id": "wiz-hec-vpc-flow-logs-output", + "type": models.CreateOutputSystemByPackOutputWizHecType.WIZ_HEC, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, + "wiz_connector_id": "00000000-0000-0000-0000-000000000000", + "wiz_environment": "test", + "data_center": "us1", + "wiz_sourcetype": models.CreateOutputSystemByPackWizDefendSourceType.AWS_VPC_FLOW_LOGS, + "wiz_vpc_event_format": models.CreateOutputSystemByPackEventFormat.CSV_ROW, + "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}", }) # Handle response @@ -3049,76 +3138,76 @@ with CriblControlPlane( "tls": { "disabled": True, }, - "token_ttl_minutes": 60, + "token_ttl_minutes": 60.0, "exclude_fields": [ "__kube_*", "__metadata", "__winEvent", ], "compression": models.CompressionOptionsGzipNone.GZIP, - "concurrency": 5, - "max_payload_size_kb": 4096, - "max_payload_events": 0, + "concurrency": 5.0, + "max_payload_size_kb": 4096.0, + "max_payload_events": 0.0, "reject_unauthorized": True, - "timeout_sec": 30, - "flush_period_sec": 1, + "timeout_sec": 30.0, + "flush_period_sec": 1.0, "failed_request_logging_mode": models.FailedRequestLoggingModeOptions.NONE, "safe_headers": [], "throttle_rate_per_sec": "0", "response_retry_settings": [ { - "http_status": 401, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 401.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 403, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 403.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 408, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 408.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 429, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 429.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 500, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 500.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 502, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 502.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 503, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 503.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 504, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 504.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 509, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 509.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, ], "timeout_retry_settings": { @@ -3153,7 +3242,7 @@ with CriblControlPlane( "id": "cribl-tcp-output", "type": models.TypeOptionsCribltcp.CRIBL_TCP, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -3180,7 +3269,7 @@ with CriblControlPlane( "type": models.OutputCrowdstrikeNextGenSiemType.CROWDSTRIKE_NEXT_GEN_SIEM, "url": "https://ingest.us.crowdstrike.com/api/ingest/hec/connection-id/v1/services/collector", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -3634,7 +3723,7 @@ with CriblControlPlane( "type": models.OutputGraphiteType.GRAPHITE, "protocol": models.DestinationProtocolOptions.TCP, "host": "localhost", - "port": 2003, + "port": 2003.0, }) # Handle response @@ -3686,7 +3775,7 @@ with CriblControlPlane( "type": models.OutputHumioHecType.HUMIO_HEC, "url": "https://cloud.us.humio.com/api/v1/ingest/hec", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -3930,7 +4019,7 @@ with CriblControlPlane( "hosts": [ { "host": "localhost", - "port": 2055, + "port": 2055.0, }, ], }) @@ -4198,9 +4287,9 @@ with CriblControlPlane( "id": "sentinel-output", "type": models.OutputSentinelType.SENTINEL, "login_url": "https://login.microsoftonline.com", - "secret": "client-secret", "client_id": "client-id", "endpoint_url_configuration": models.EndpointConfiguration.URL, + "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com", }) @@ -4309,7 +4398,7 @@ with CriblControlPlane( "hosts": [ { "host": "192.168.1.1", - "port": 161, + "port": 161.0, }, ], }) @@ -4364,7 +4453,7 @@ with CriblControlPlane( "id": "splunk-output", "type": models.TypeOptionsSplunk.SPLUNK, "host": "localhost", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -4416,7 +4505,7 @@ with CriblControlPlane( hosts=[ models.HostConfOutputSyslog( host="localhost", - port=9997, + port=9997.0, ), ], )) @@ -4472,7 +4561,7 @@ with CriblControlPlane( "type": models.OutputStatsdType.STATSD, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -4499,7 +4588,7 @@ with CriblControlPlane( "type": models.OutputStatsdExtType.STATSD_EXT, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -4577,7 +4666,7 @@ with CriblControlPlane( "id": "syslog-output", "type": models.TypeOptionsSyslog.SYSLOG, "host": "localhost", - "port": 514, + "port": 514.0, }) # Handle response @@ -4603,7 +4692,7 @@ with CriblControlPlane( "id": "tcpjson-output", "type": models.TypeOptionsTcpjson.TCPJSON, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4679,11 +4768,10 @@ with CriblControlPlane( res = ccp_client.packs.destinations.update(id="", pack="", output={ "id": "wiz-hec-output", "type": models.OutputWizHecType.WIZ_HEC, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", - "wiz_sourcetype": "placeholder", }) # Handle response @@ -5328,76 +5416,76 @@ with CriblControlPlane( "tls": { "disabled": True, }, - "token_ttl_minutes": 60, + "token_ttl_minutes": 60.0, "exclude_fields": [ "__kube_*", "__metadata", "__winEvent", ], "compression": models.CompressionOptionsGzipNone.GZIP, - "concurrency": 5, - "max_payload_size_kb": 4096, - "max_payload_events": 0, + "concurrency": 5.0, + "max_payload_size_kb": 4096.0, + "max_payload_events": 0.0, "reject_unauthorized": True, - "timeout_sec": 30, - "flush_period_sec": 1, + "timeout_sec": 30.0, + "flush_period_sec": 1.0, "failed_request_logging_mode": models.FailedRequestLoggingModeOptions.NONE, "safe_headers": [], "throttle_rate_per_sec": "0", "response_retry_settings": [ { - "http_status": 401, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 401.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 403, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 20000, + "http_status": 403.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 20000.0, }, { - "http_status": 408, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 408.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 429, - "initial_backoff": 1000, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 429.0, + "initial_backoff": 1000.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 500, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 500.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 502, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 502.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 503, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 503.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 504, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 504.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, { - "http_status": 509, - "initial_backoff": 250, - "backoff_rate": 2, - "max_backoff": 10000, + "http_status": 509.0, + "initial_backoff": 250.0, + "backoff_rate": 2.0, + "max_backoff": 10000.0, }, ], "timeout_retry_settings": { @@ -5432,7 +5520,7 @@ with CriblControlPlane( "id": "cribl-tcp-output", "type": models.TypeOptionsCribltcp.CRIBL_TCP, "host": "localhost", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -5459,7 +5547,7 @@ with CriblControlPlane( "type": models.OutputCrowdstrikeNextGenSiemType.CROWDSTRIKE_NEXT_GEN_SIEM, "url": "https://ingest.us.crowdstrike.com/api/ingest/hec/connection-id/v1/services/collector", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -5524,6 +5612,36 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateOutputExamplesDatabricksZerobus + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.destinations.update(id="", pack="", output={ + "id": "databricks-zerobus-output", + "type": models.OutputDatabricksZerobusType.DATABRICKS_ZEROBUS, + "workspace_url": "https://dbc-1234abcd-5e6f.cloud.databricks.com", + "workspace_id": "your-workspace-id", + "zerobus_endpoint": "1234567890.zerobus.us-west-2.cloud.databricks.com", + "client_id": "your-client-id", + "client_text_secret": "your-client-secret", + "table_name": "main.external.events", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateOutputExamplesDatadog @@ -5782,6 +5900,8 @@ with CriblControlPlane( "stage_path": "/tmp/staging", "endpoint": "https://storage.googleapis.com", "collector_instance_id": "11112222-3333-4444-5555-666677778888", + "aws_authentication_method": models.OutputExabeamAuthenticationMethod.SECRET, + "aws_secret": "my-secret-id", }) # Handle response @@ -6018,7 +6138,7 @@ with CriblControlPlane( "type": models.OutputGraphiteType.GRAPHITE, "protocol": models.DestinationProtocolOptions.TCP, "host": "localhost", - "port": 2003, + "port": 2003.0, }) # Handle response @@ -6070,7 +6190,7 @@ with CriblControlPlane( "type": models.OutputHumioHecType.HUMIO_HEC, "url": "https://cloud.us.humio.com/api/v1/ingest/hec", "format_": models.RequestFormatOptions.JSON, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "token": "your-token", }) @@ -6314,7 +6434,7 @@ with CriblControlPlane( "hosts": [ { "host": "localhost", - "port": 2055, + "port": 2055.0, }, ], }) @@ -6582,9 +6702,9 @@ with CriblControlPlane( "id": "sentinel-output", "type": models.OutputSentinelType.SENTINEL, "login_url": "https://login.microsoftonline.com", - "secret": "client-secret", "client_id": "client-id", "endpoint_url_configuration": models.EndpointConfiguration.URL, + "secret": "client-secret", "url": "https://your-workspace.ingest.monitor.azure.com", }) @@ -6693,7 +6813,7 @@ with CriblControlPlane( "hosts": [ { "host": "192.168.1.1", - "port": 161, + "port": 161.0, }, ], }) @@ -6780,7 +6900,7 @@ with CriblControlPlane( "id": "splunk-output", "type": models.TypeOptionsSplunk.SPLUNK, "host": "localhost", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -6832,7 +6952,7 @@ with CriblControlPlane( hosts=[ models.HostConfOutputSyslog( host="localhost", - port=9997, + port=9997.0, ), ], )) @@ -6888,7 +7008,7 @@ with CriblControlPlane( "type": models.OutputStatsdType.STATSD, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -6915,7 +7035,7 @@ with CriblControlPlane( "type": models.OutputStatsdExtType.STATSD_EXT, "protocol": models.DestinationProtocolOptions.UDP, "host": "localhost", - "port": 8125, + "port": 8125.0, }) # Handle response @@ -6993,7 +7113,7 @@ with CriblControlPlane( "id": "syslog-output", "type": models.TypeOptionsSyslog.SYSLOG, "host": "localhost", - "port": 514, + "port": 514.0, }) # Handle response @@ -7019,7 +7139,33 @@ with CriblControlPlane( "id": "tcpjson-output", "type": models.TypeOptionsTcpjson.TCPJSON, "host": "localhost", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateOutputExamplesTraversalOtlp + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.destinations.update(id="", pack="", output={ + "id": "traversal-output", + "type": models.OutputTraversalOtlpType.TRAVERSAL_OTLP, + "endpoint": "http://traversal-processor:3000", + "protocol": models.ProtocolOptions.HTTP, }) # Handle response @@ -7095,11 +7241,42 @@ with CriblControlPlane( res = ccp_client.packs.destinations.update(id="", pack="", output={ "id": "wiz-hec-output", "type": models.OutputWizHecType.WIZ_HEC, - "auth_type": models.AuthenticationMethodOptionsAuthTokensItems.MANUAL, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, + "wiz_connector_id": "00000000-0000-0000-0000-000000000000", + "wiz_environment": "test", + "data_center": "us1", + "wiz_sourcetype": models.WizDefendSourceType.AWS_CLOUDTRAIL, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateOutputExamplesWizHecVpcFlowLogs + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.destinations.update(id="", pack="", output={ + "id": "wiz-hec-vpc-flow-logs-output", + "type": models.OutputWizHecType.WIZ_HEC, + "auth_type": models.AuthenticationMethodOptionsAuthTokensExtItems.MANUAL, "wiz_connector_id": "00000000-0000-0000-0000-000000000000", "wiz_environment": "test", "data_center": "us1", - "wiz_sourcetype": "placeholder", + "wiz_sourcetype": models.WizDefendSourceType.AWS_VPC_FLOW_LOGS, + "wiz_vpc_event_format": models.OutputWizHecEventFormat.CSV_ROW, + "wiz_vpc_flow_log_format": "${version} ${account-id} ${interface-id} ${srcaddr} ${dstaddr} ${srcport} ${dstport} ${protocol} ${packets} ${bytes} ${start} ${end} ${action} ${log-status}", }) # Handle response diff --git a/docs/sdks/packspipelines/README.md b/docs/sdks/packspipelines/README.md index c3caa32dc..d7a896d63 100644 --- a/docs/sdks/packspipelines/README.md +++ b/docs/sdks/packspipelines/README.md @@ -63,12 +63,12 @@ with CriblControlPlane( ### Parameters -| Parameter | Type | Required | Description | -| ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | -| `pack` | *str* | :heavy_check_mark: | The id of the Pack. | -| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | -| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | -| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `pack` | *str* | :heavy_check_mark: | The id of the Pack. | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. | +| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response @@ -227,8 +227,8 @@ with CriblControlPlane( "dst_field": "_time", "default_timezone": "local", "time_expression": "time.getTime() / 1000", - "offset": 0, - "max_len": 150, + "offset": 0.0, + "max_len": 150.0, "default_time": models.DefaultTime.NOW, "latest_date_allowed": "+1week", "earliest_date_allowed": "-420weeks", @@ -476,8 +476,8 @@ with CriblControlPlane( out_field_name="src_hostname", ), ], - cache_ttl=30, - max_cache_size=5000, + cache_ttl=30.0, + max_cache_size=5000.0, use_resolv_conf=False, lookup_fallback=False, lookup_fail_log_level=models.LogLevelForFailedLookups.ERROR, @@ -600,9 +600,9 @@ with CriblControlPlane( "conf": { "mode": models.SampleMode.SQRT, "key_expr": "`${domain}:${httpCode}`", - "sample_period": 20, - "min_events": 3, - "max_sample_rate": 3, + "sample_period": 20.0, + "min_events": 3.0, + "max_sample_rate": 3.0, }, }, ], @@ -729,11 +729,11 @@ with CriblControlPlane( rule_type=models.EventBreakerTypeOptionsEventBreakerExistingOrNewNew.REGEX, event_breaker_regex="/[\\n\\r]+(?!\\s)/", existing_or_new=models.EventBreakerExistingOrNewNewRuleTypeRegexExistingOrNew.NEW, - max_event_bytes=51200, + max_event_bytes=51200.0, timestamp_anchor_regex="/^/", timestamp=models.EventBreakerExistingOrNewNewTimestampTypeAuto( type=models.TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp.AUTO, - length=150, + length=150.0, ), timestamp_timezone="local", timestamp_earliest="-420weeks", @@ -778,7 +778,7 @@ with CriblControlPlane( "conf": { "fields": [], "prefix": "", - "depth": 5, + "depth": 5.0, "delimiter": "_", }, }, @@ -1040,7 +1040,7 @@ with CriblControlPlane( "file": "ip_locations.csv", "db_lookup": False, "match_mode": models.MatchMode.EXACT, - "reload_period_sec": -1, + "reload_period_sec": -1.0, "in_fields": [ { "event_field": "destination_ip", @@ -1184,11 +1184,11 @@ with CriblControlPlane( "conf": { "drop_non_log_events": False, "batch_otlp_logs": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -1238,11 +1238,11 @@ with CriblControlPlane( "drop_non_metric_events": False, "otlp_version": models.FunctionConfSchemaOTLPMetricsOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_metrics": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -1283,11 +1283,11 @@ with CriblControlPlane( "drop_non_trace_events": False, "otlp_version": models.FunctionConfSchemaOTLPTracesOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_traces": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -1441,7 +1441,7 @@ with CriblControlPlane( ), ], deployment_type=models.RedisAuthTypeNoneDeploymentType.STANDALONE, - max_block_secs=60, + max_block_secs=60.0, url="'redis://localhost:6379/0'", ), ), @@ -1482,7 +1482,7 @@ with CriblControlPlane( "conf": { "regex": "/metric1=(?\\d+)/", "source": "_raw", - "iterations": 100, + "iterations": 100.0, "overwrite": False, }, }, @@ -1769,12 +1769,12 @@ with CriblControlPlane( "id": models.PipelineFunctionSuppressID.SUPPRESS, "conf": { "key_expr": "`${ip}:${port}`", - "allow": 1, - "suppress_period_sec": 30, + "allow": 1.0, + "suppress_period_sec": 30.0, "drop_events_mode": True, - "max_cache_size": 50000, - "cache_idle_timeout_periods": 2, - "num_events_idle_timeout_trigger": 10000, + "max_cache_size": 50000.0, + "cache_idle_timeout_periods": 2.0, + "num_events_idle_timeout_trigger": 10000.0, }, }, ], @@ -2242,8 +2242,8 @@ with CriblControlPlane( "dst_field": "_time", "default_timezone": "local", "time_expression": "time.getTime() / 1000", - "offset": 0, - "max_len": 150, + "offset": 0.0, + "max_len": 150.0, "default_time": models.DefaultTime.NOW, "latest_date_allowed": "+1week", "earliest_date_allowed": "-420weeks", @@ -2491,8 +2491,8 @@ with CriblControlPlane( out_field_name="src_hostname", ), ], - cache_ttl=30, - max_cache_size=5000, + cache_ttl=30.0, + max_cache_size=5000.0, use_resolv_conf=False, lookup_fallback=False, lookup_fail_log_level=models.LogLevelForFailedLookups.ERROR, @@ -2615,9 +2615,9 @@ with CriblControlPlane( "conf": { "mode": models.SampleMode.SQRT, "key_expr": "`${domain}:${httpCode}`", - "sample_period": 20, - "min_events": 3, - "max_sample_rate": 3, + "sample_period": 20.0, + "min_events": 3.0, + "max_sample_rate": 3.0, }, }, ], @@ -2744,11 +2744,11 @@ with CriblControlPlane( rule_type=models.EventBreakerTypeOptionsEventBreakerExistingOrNewNew.REGEX, event_breaker_regex="/[\\n\\r]+(?!\\s)/", existing_or_new=models.EventBreakerExistingOrNewNewRuleTypeRegexExistingOrNew.NEW, - max_event_bytes=51200, + max_event_bytes=51200.0, timestamp_anchor_regex="/^/", timestamp=models.EventBreakerExistingOrNewNewTimestampTypeAuto( type=models.TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp.AUTO, - length=150, + length=150.0, ), timestamp_timezone="local", timestamp_earliest="-420weeks", @@ -2793,7 +2793,7 @@ with CriblControlPlane( "conf": { "fields": [], "prefix": "", - "depth": 5, + "depth": 5.0, "delimiter": "_", }, }, @@ -3055,7 +3055,7 @@ with CriblControlPlane( "file": "ip_locations.csv", "db_lookup": False, "match_mode": models.MatchMode.EXACT, - "reload_period_sec": -1, + "reload_period_sec": -1.0, "in_fields": [ { "event_field": "destination_ip", @@ -3199,11 +3199,11 @@ with CriblControlPlane( "conf": { "drop_non_log_events": False, "batch_otlp_logs": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -3253,11 +3253,11 @@ with CriblControlPlane( "drop_non_metric_events": False, "otlp_version": models.FunctionConfSchemaOTLPMetricsOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_metrics": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -3298,11 +3298,11 @@ with CriblControlPlane( "drop_non_trace_events": False, "otlp_version": models.FunctionConfSchemaOTLPTracesOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_traces": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -3456,7 +3456,7 @@ with CriblControlPlane( ), ], deployment_type=models.RedisAuthTypeNoneDeploymentType.STANDALONE, - max_block_secs=60, + max_block_secs=60.0, url="'redis://localhost:6379/0'", ), ), @@ -3497,7 +3497,7 @@ with CriblControlPlane( "conf": { "regex": "/metric1=(?\\d+)/", "source": "_raw", - "iterations": 100, + "iterations": 100.0, "overwrite": False, }, }, @@ -3784,12 +3784,12 @@ with CriblControlPlane( "id": models.PipelineFunctionSuppressID.SUPPRESS, "conf": { "key_expr": "`${ip}:${port}`", - "allow": 1, - "suppress_period_sec": 30, + "allow": 1.0, + "suppress_period_sec": 30.0, "drop_events_mode": True, - "max_cache_size": 50000, - "cache_idle_timeout_periods": 2, - "num_events_idle_timeout_trigger": 10000, + "max_cache_size": 50000.0, + "cache_idle_timeout_periods": 2.0, + "num_events_idle_timeout_trigger": 10000.0, }, }, ], @@ -4124,8 +4124,8 @@ with CriblControlPlane( "dst_field": "_time", "default_timezone": "local", "time_expression": "time.getTime() / 1000", - "offset": 0, - "max_len": 150, + "offset": 0.0, + "max_len": 150.0, "default_time": models.DefaultTime.NOW, "latest_date_allowed": "+1week", "earliest_date_allowed": "-420weeks", @@ -4373,8 +4373,8 @@ with CriblControlPlane( out_field_name="src_hostname", ), ], - cache_ttl=30, - max_cache_size=5000, + cache_ttl=30.0, + max_cache_size=5000.0, use_resolv_conf=False, lookup_fallback=False, lookup_fail_log_level=models.LogLevelForFailedLookups.ERROR, @@ -4497,9 +4497,9 @@ with CriblControlPlane( "conf": { "mode": models.SampleMode.SQRT, "key_expr": "`${domain}:${httpCode}`", - "sample_period": 20, - "min_events": 3, - "max_sample_rate": 3, + "sample_period": 20.0, + "min_events": 3.0, + "max_sample_rate": 3.0, }, }, ], @@ -4626,11 +4626,11 @@ with CriblControlPlane( rule_type=models.EventBreakerTypeOptionsEventBreakerExistingOrNewNew.REGEX, event_breaker_regex="/[\\n\\r]+(?!\\s)/", existing_or_new=models.EventBreakerExistingOrNewNewRuleTypeRegexExistingOrNew.NEW, - max_event_bytes=51200, + max_event_bytes=51200.0, timestamp_anchor_regex="/^/", timestamp=models.EventBreakerExistingOrNewNewTimestampTypeAuto( type=models.TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp.AUTO, - length=150, + length=150.0, ), timestamp_timezone="local", timestamp_earliest="-420weeks", @@ -4675,7 +4675,7 @@ with CriblControlPlane( "conf": { "fields": [], "prefix": "", - "depth": 5, + "depth": 5.0, "delimiter": "_", }, }, @@ -4937,7 +4937,7 @@ with CriblControlPlane( "file": "ip_locations.csv", "db_lookup": False, "match_mode": models.MatchMode.EXACT, - "reload_period_sec": -1, + "reload_period_sec": -1.0, "in_fields": [ { "event_field": "destination_ip", @@ -5081,11 +5081,11 @@ with CriblControlPlane( "conf": { "drop_non_log_events": False, "batch_otlp_logs": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -5135,11 +5135,11 @@ with CriblControlPlane( "drop_non_metric_events": False, "otlp_version": models.FunctionConfSchemaOTLPMetricsOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_metrics": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -5180,11 +5180,11 @@ with CriblControlPlane( "drop_non_trace_events": False, "otlp_version": models.FunctionConfSchemaOTLPTracesOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_traces": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -5338,7 +5338,7 @@ with CriblControlPlane( ), ], deployment_type=models.RedisAuthTypeNoneDeploymentType.STANDALONE, - max_block_secs=60, + max_block_secs=60.0, url="'redis://localhost:6379/0'", ), ), @@ -5379,7 +5379,7 @@ with CriblControlPlane( "conf": { "regex": "/metric1=(?\\d+)/", "source": "_raw", - "iterations": 100, + "iterations": 100.0, "overwrite": False, }, }, @@ -5666,12 +5666,12 @@ with CriblControlPlane( "id": models.PipelineFunctionSuppressID.SUPPRESS, "conf": { "key_expr": "`${ip}:${port}`", - "allow": 1, - "suppress_period_sec": 30, + "allow": 1.0, + "suppress_period_sec": 30.0, "drop_events_mode": True, - "max_cache_size": 50000, - "cache_idle_timeout_periods": 2, - "num_events_idle_timeout_trigger": 10000, + "max_cache_size": 50000.0, + "cache_idle_timeout_periods": 2.0, + "num_events_idle_timeout_trigger": 10000.0, }, }, ], diff --git a/docs/sdks/packsroutes/README.md b/docs/sdks/packsroutes/README.md index d9a63cdf9..b926725f0 100644 --- a/docs/sdks/packsroutes/README.md +++ b/docs/sdks/packsroutes/README.md @@ -30,8 +30,10 @@ with CriblControlPlane( res = ccp_client.packs.routes.list(pack="") - # Handle response - print(res) + while res is not None: + # Handle items + + res = res.next() ``` ### Example Usage: RoutesResponseExamplesMultiRouteTable @@ -51,8 +53,10 @@ with CriblControlPlane( res = ccp_client.packs.routes.list(pack="") - # Handle response - print(res) + while res is not None: + # Handle items + + res = res.next() ``` @@ -61,11 +65,13 @@ with CriblControlPlane( | Parameter | Type | Required | Description | | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | | `pack` | *str* | :heavy_check_mark: | The id of the Pack. | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | | `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response -**[models.CountedRoutes](../../models/countedroutes.md)** +**[models.GetRoutesByPackResponse](../../models/getroutesbypackresponse.md)** ### Errors diff --git a/docs/sdks/packssources/README.md b/docs/sdks/packssources/README.md index 3148752e7..0bd3510c5 100644 --- a/docs/sdks/packssources/README.md +++ b/docs/sdks/packssources/README.md @@ -133,6 +133,35 @@ with CriblControlPlane( Create a new Source. The system-managed provenance field (JSON criblSourceProvenance) must be omitted from the request body within the specified Pack. +### Example Usage: InputCreateExamplesAkamaiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "akamai-hec-source", + "type": models.CreateInputSystemByPackInputAkamaiHecType.AKAMAI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` ### Example Usage: InputCreateExamplesAnthropicCompliance @@ -159,6 +188,47 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesAnthropicEnterpriseAnalytics + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "anthropic-enterprise-analytics-source", + "type": models.CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS, + "send_to_routes": True, + "pq_enabled": False, + "text_secret": "anthropic-api-key-secret", + "content_config": [ + { + "content_type": models.CreateInputSystemByPackContentType.USAGE_REPORT, + "disabled": False, + "state_tracking": True, + "state_update_expression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", + "state_merge_expression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", + "group_by": [], + "bucket_width": models.CreateInputSystemByPackBucketWidth.ONED, + "cron_schedule": "0 */4 * * *", + "earliest": "-7d@d", + "job_timeout": "300", + }, + ], + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesAppleUnifiedLogs @@ -208,7 +278,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9109, + "port": 9109.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesAquaSecurityHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "aqua-security-hec-source", + "type": models.CreateInputSystemByPackInputAquaSecurityHecType.AQUA_SECURITY_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -241,6 +340,33 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesAzureVNetFlowLog + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "azure-vnet-flow-log-source", + "type": models.CreateInputSystemByPackInputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG, + "send_to_routes": True, + "pq_enabled": False, + "queue_name": "vnet-flow-log-queue", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesBedrockS3 @@ -269,6 +395,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesBeyondTrustHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "beyondtrust-hec-source", + "type": models.CreateInputSystemByPackInputBeyondtrustHecType.BEYONDTRUST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesCloudflareHec @@ -291,7 +446,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -378,7 +533,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -406,7 +561,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -434,7 +589,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -490,7 +645,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8126, + "port": 8126.0, }) # Handle response @@ -520,7 +675,7 @@ with CriblControlPlane( "samples": [ { "sample": "sample.json", - "events_per_sec": 10, + "events_per_sec": 10.0, }, ], }) @@ -550,7 +705,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.CreateInputSystemByPackInputEdgePrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "targets": [ { "host": "localhost", @@ -583,7 +738,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "localhost", - "port": 9200, + "port": 9200.0, "elastic_api": "/", }) @@ -677,7 +832,65 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "command": "echo \"Hello World\"", - "interval": 60, + "interval": 60.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesExtrahopRevealx360 + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "extrahop-revealx-360-source", + "type": models.CreateInputSystemByPackInputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesF5BigIp + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "f5-big-ip-source", + "type": models.CreateInputSystemByPackInputF5BigIPType.F5_BIG_IP, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -732,7 +945,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesGigamonHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "gigamon-hec-source", + "type": models.CreateInputSystemByPackInputGigamonHecType.GIGAMON_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -788,13 +1030,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/api/prom/push", }) # Handle response print(res) +``` +### Example Usage: InputCreateExamplesHashicorpHcpVaultDedicated + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "hashicorp-hcp-vault-dedicated-source", + "type": models.CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesHttp @@ -817,7 +1088,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -845,7 +1116,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -1041,7 +1312,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "loki_api": "/loki/api/v1/push", }) @@ -1070,7 +1341,40 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 8125, + "udp_port": 8125.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesMicrosoftCopilot + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "microsoft-copilot-source", + "type": models.CreateInputSystemByPackInputMicrosoftCopilotType.MICROSOFT_COPILOT, + "send_to_routes": True, + "pq_enabled": False, + "tenant_id": "00000000-0000-0000-0000-000000000000", + "client_id": "00000000-0000-0000-0000-000000000001", + "auth_type": models.CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET, + "cron_schedule": "*/15 * * * *", + "earliest": "-7d", + "latest": "now", + "text_secret": "microsoft-copilot-secret", }) # Handle response @@ -1104,6 +1408,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesMimecastHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "mimecast-hec-source", + "type": models.CreateInputSystemByPackInputMimecastHecType.MIMECAST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesModelDrivenTelemetry @@ -1126,7 +1459,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 57000, + "port": 57000.0, }) # Handle response @@ -1188,7 +1521,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 2055, + "port": 2055.0, }) # Handle response @@ -1418,7 +1751,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 4317, + "port": 4317.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesPingIdentityPingone + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "ping-identity-pingone-source", + "type": models.CreateInputSystemByPackInputPingIdentityPingoneType.PING_IDENTITY_PINGONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -1446,7 +1808,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.CreateInputSystemByPackInputPrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "log_level": models.LogLevelOptions.INFO, "target_list": [ "http://localhost:9090/metrics", @@ -1478,13 +1840,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/write", }) # Handle response print(res) +``` +### Example Usage: InputCreateExamplesProofpointPod + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "proofpoint-pod-source", + "type": models.CreateInputSystemByPackInputProofpointPodType.PROOFPOINT_POD, + "send_to_routes": True, + "pq_enabled": False, + "cluster_id": "my-pod-cluster", + "feed_type": models.CreateInputSystemByPackFeedType.MESSAGE, + "text_secret": "proofpoint-pod-token-secret", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesRawUdp @@ -1507,7 +1898,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 514, + "port": 514.0, }) # Handle response @@ -1562,8 +1953,37 @@ with CriblControlPlane( "type": models.CreateInputSystemByPackInputS3InventoryType.S3_INVENTORY, "send_to_routes": True, "pq_enabled": False, - "queue_name": "s3-inventory-queue", - "region": "us-east-1", + "queue_name": "s3-inventory-queue", + "region": "us-east-1", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesSailpointHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "sailpoint-hec-source", + "type": models.CreateInputSystemByPackInputSailpointHecType.SAILPOINT_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -1656,7 +2076,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "192.168.1.1", - "port": 161, + "port": 161.0, }) # Handle response @@ -1684,7 +2104,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -1712,7 +2132,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "splunk_hec_api": "/services/collector", }) @@ -1802,7 +2222,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -1831,7 +2251,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -1868,7 +2288,7 @@ with CriblControlPlane( "on_backpressure": models.QueueFullBehaviorOptionsPq.DROP, }, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -1948,7 +2368,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -1976,7 +2396,65 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesTrellixHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "trellix-hec-source", + "type": models.CreateInputSystemByPackInputTrellixHecType.TRELLIX_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesTrendMicroVisionOne + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "trend-micro-vision-one-source", + "type": models.CreateInputSystemByPackInputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -2004,7 +2482,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesVectraAiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.create(pack="", request_body={ + "id": "vectra-ai-hec-source", + "type": models.CreateInputSystemByPackInputVectraAiHecType.VECTRA_AI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, "hec_api": "/services/collector", }) @@ -2033,13 +2540,13 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 5985, + "port": 5985.0, "subscriptions": [ { "subscription_name": "subscription-1", "content_format": models.CreateInputSystemByPackFormat.RENDERED_TEXT, - "heartbeat_interval": 60, - "batch_timeout": 5, + "heartbeat_interval": 60.0, + "batch_timeout": 5.0, "targets": [], }, ], @@ -2156,7 +2663,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -2184,7 +2691,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -2533,7 +3040,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9109, + "port": 9109.0, }) # Handle response @@ -2588,7 +3095,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -2675,7 +3182,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -2703,7 +3210,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -2731,7 +3238,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -2787,7 +3294,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8126, + "port": 8126.0, }) # Handle response @@ -2817,7 +3324,7 @@ with CriblControlPlane( "samples": [ { "sample": "sample.json", - "events_per_sec": 10, + "events_per_sec": 10.0, }, ], }) @@ -2847,7 +3354,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputEdgePrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "targets": [ { "host": "localhost", @@ -2880,7 +3387,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "localhost", - "port": 9200, + "port": 9200.0, "elastic_api": "/", }) @@ -2974,7 +3481,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "command": "echo \"Hello World\"", - "interval": 60, + "interval": 60.0, }) # Handle response @@ -3029,7 +3536,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -3085,7 +3592,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/api/prom/push", }) @@ -3114,7 +3621,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -3142,7 +3649,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -3338,7 +3845,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "loki_api": "/loki/api/v1/push", }) @@ -3367,7 +3874,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 8125, + "udp_port": 8125.0, }) # Handle response @@ -3423,7 +3930,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 57000, + "port": 57000.0, }) # Handle response @@ -3485,7 +3992,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 2055, + "port": 2055.0, }) # Handle response @@ -3715,7 +4222,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 4317, + "port": 4317.0, }) # Handle response @@ -3743,7 +4250,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputPrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "log_level": models.LogLevelOptions.INFO, "target_list": [ "http://localhost:9090/metrics", @@ -3775,7 +4282,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/write", }) @@ -3804,7 +4311,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 514, + "port": 514.0, }) # Handle response @@ -3953,7 +4460,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "192.168.1.1", - "port": 161, + "port": 161.0, }) # Handle response @@ -3981,7 +4488,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -4009,7 +4516,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "splunk_hec_api": "/services/collector", }) @@ -4099,7 +4606,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -4179,7 +4686,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4207,7 +4714,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4235,13 +4742,13 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 5985, + "port": 5985.0, "subscriptions": [ { "subscription_name": "subscription-1", "content_format": models.InputWefFormat.RENDERED_TEXT, - "heartbeat_interval": 60, - "batch_timeout": 5, + "heartbeat_interval": 60.0, + "batch_timeout": 5.0, "targets": [], }, ], @@ -4358,7 +4865,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -4386,7 +4893,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -4544,6 +5051,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesAkamaiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "akamai-hec-source", + "type": models.InputAkamaiHecType.AKAMAI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesAnthropicCompliance @@ -4571,6 +5107,47 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesAnthropicEnterpriseAnalytics + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "anthropic-enterprise-analytics-source", + "type": models.InputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS, + "send_to_routes": True, + "pq_enabled": False, + "text_secret": "anthropic-api-key-secret", + "content_config": [ + { + "content_type": models.ContentType.USAGE_REPORT, + "disabled": False, + "state_tracking": True, + "state_update_expression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", + "state_merge_expression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", + "group_by": [], + "bucket_width": models.BucketWidth.ONED, + "cron_schedule": "0 */4 * * *", + "earliest": "-7d@d", + "job_timeout": "300", + }, + ], + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesAppleUnifiedLogs @@ -4620,7 +5197,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9109, + "port": 9109.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesAquaSecurityHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "aqua-security-hec-source", + "type": models.InputAquaSecurityHecType.AQUA_SECURITY_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -4653,6 +5259,33 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesAzureVNetFlowLog + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "azure-vnet-flow-log-source", + "type": models.InputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG, + "send_to_routes": True, + "pq_enabled": False, + "queue_name": "vnet-flow-log-queue", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesBedrockS3 @@ -4681,6 +5314,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesBeyondTrustHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "beyondtrust-hec-source", + "type": models.InputBeyondtrustHecType.BEYONDTRUST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesCloudflareHec @@ -4703,7 +5365,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -4816,7 +5478,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -4844,7 +5506,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -4898,7 +5560,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4954,7 +5616,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8126, + "port": 8126.0, }) # Handle response @@ -4984,7 +5646,7 @@ with CriblControlPlane( "samples": [ { "sample": "sample.json", - "events_per_sec": 10, + "events_per_sec": 10.0, }, ], }) @@ -5014,7 +5676,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputEdgePrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "targets": [ { "host": "localhost", @@ -5047,7 +5709,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "localhost", - "port": 9200, + "port": 9200.0, "elastic_api": "/", }) @@ -5103,26 +5765,83 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.packs.sources.update(id="", pack="", input_={ - "id": "eventhub-amqp-source", - "type": models.InputEventhubAmqpType.EVENTHUB_AMQP, + "id": "eventhub-amqp-source", + "type": models.InputEventhubAmqpType.EVENTHUB_AMQP, + "send_to_routes": True, + "pq_enabled": False, + "event_hub_name": "my-event-hub", + "consumer_group": "$Default", + "checkpointing": { + "blob_store": { + "container_name": "my-container", + }, + }, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesExec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "exec-source", + "type": models.InputExecType.EXEC, + "send_to_routes": True, + "pq_enabled": False, + "command": "echo \"Hello World\"", + "interval": 60.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesExtrahopRevealx360 + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "extrahop-revealx-360-source", + "type": models.InputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360, "send_to_routes": True, "pq_enabled": False, - "event_hub_name": "my-event-hub", - "consumer_group": "$Default", - "checkpointing": { - "blob_store": { - "container_name": "my-container", - }, - }, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response print(res) ``` -### Example Usage: UpdateInputExamplesExec +### Example Usage: UpdateInputExamplesF5BigIp - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -5136,12 +5855,13 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.packs.sources.update(id="", pack="", input_={ - "id": "exec-source", - "type": models.InputExecType.EXEC, + "id": "f5-big-ip-source", + "type": models.InputF5BigIPType.F5_BIG_IP, "send_to_routes": True, "pq_enabled": False, - "command": "echo \"Hello World\"", - "interval": 60, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -5196,7 +5916,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesGigamonHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "gigamon-hec-source", + "type": models.InputGigamonHecType.GIGAMON_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -5252,13 +6001,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/api/prom/push", }) # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesHashicorpHcpVaultDedicated + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "hashicorp-hcp-vault-dedicated-source", + "type": models.InputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesHttp @@ -5281,7 +6059,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -5309,7 +6087,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -5505,7 +6283,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "loki_api": "/loki/api/v1/push", }) @@ -5534,7 +6312,40 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 8125, + "udp_port": 8125.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesMicrosoftCopilot + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "microsoft-copilot-source", + "type": models.InputMicrosoftCopilotType.MICROSOFT_COPILOT, + "send_to_routes": True, + "pq_enabled": False, + "tenant_id": "00000000-0000-0000-0000-000000000000", + "client_id": "00000000-0000-0000-0000-000000000001", + "auth_type": models.InputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET, + "cron_schedule": "*/15 * * * *", + "earliest": "-7d", + "latest": "now", + "text_secret": "microsoft-copilot-secret", }) # Handle response @@ -5568,6 +6379,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesMimecastHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "mimecast-hec-source", + "type": models.InputMimecastHecType.MIMECAST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesModelDrivenTelemetry @@ -5590,7 +6430,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 57000, + "port": 57000.0, }) # Handle response @@ -5652,7 +6492,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 2055, + "port": 2055.0, }) # Handle response @@ -5882,7 +6722,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 4317, + "port": 4317.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesPingIdentityPingone + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "ping-identity-pingone-source", + "type": models.InputPingIdentityPingoneType.PING_IDENTITY_PINGONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -5910,7 +6779,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputPrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "log_level": models.LogLevelOptions.INFO, "target_list": [ "http://localhost:9090/metrics", @@ -5942,13 +6811,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/write", }) # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesProofpointPod + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "proofpoint-pod-source", + "type": models.InputProofpointPodType.PROOFPOINT_POD, + "send_to_routes": True, + "pq_enabled": False, + "cluster_id": "my-pod-cluster", + "feed_type": models.FeedType.MESSAGE, + "text_secret": "proofpoint-pod-token-secret", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesRawUdp @@ -5971,7 +6869,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 514, + "port": 514.0, }) # Handle response @@ -6033,6 +6931,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesSailpointHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "sailpoint-hec-source", + "type": models.InputSailpointHecType.SAILPOINT_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesSecurityLake @@ -6120,7 +7047,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "192.168.1.1", - "port": 161, + "port": 161.0, }) # Handle response @@ -6148,7 +7075,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -6176,7 +7103,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "splunk_hec_api": "/services/collector", }) @@ -6266,7 +7193,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -6295,7 +7222,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -6332,7 +7259,7 @@ with CriblControlPlane( "on_backpressure": models.QueueFullBehaviorOptionsPq.DROP, }, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -6412,7 +7339,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -6440,7 +7367,65 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesTrellixHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "trellix-hec-source", + "type": models.InputTrellixHecType.TRELLIX_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesTrendMicroVisionOne + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "trend-micro-vision-one-source", + "type": models.InputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -6468,7 +7453,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesVectraAiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.packs.sources.update(id="", pack="", input_={ + "id": "vectra-ai-hec-source", + "type": models.InputVectraAiHecType.VECTRA_AI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, "hec_api": "/services/collector", }) @@ -6497,13 +7511,13 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 5985, + "port": 5985.0, "subscriptions": [ { "subscription_name": "subscription-1", "content_format": models.InputWefFormat.RENDERED_TEXT, - "heartbeat_interval": 60, - "batch_timeout": 5, + "heartbeat_interval": 60.0, + "batch_timeout": 5.0, "targets": [], }, ], @@ -6620,7 +7634,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -6648,7 +7662,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) diff --git a/docs/sdks/pipelines/README.md b/docs/sdks/pipelines/README.md index 13bc24a8b..64e315b39 100644 --- a/docs/sdks/pipelines/README.md +++ b/docs/sdks/pipelines/README.md @@ -65,11 +65,11 @@ with CriblControlPlane( ### Parameters -| Parameter | Type | Required | Description | -| ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | -| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | -| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | -| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | +| Parameter | Type | Required | Description | +| ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | ------------------------------------------------------------------------------------------------------------------------------------------------------ | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. | +| `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response @@ -228,8 +228,8 @@ with CriblControlPlane( "dst_field": "_time", "default_timezone": "local", "time_expression": "time.getTime() / 1000", - "offset": 0, - "max_len": 150, + "offset": 0.0, + "max_len": 150.0, "default_time": models.DefaultTime.NOW, "latest_date_allowed": "+1week", "earliest_date_allowed": "-420weeks", @@ -477,8 +477,8 @@ with CriblControlPlane( out_field_name="src_hostname", ), ], - cache_ttl=30, - max_cache_size=5000, + cache_ttl=30.0, + max_cache_size=5000.0, use_resolv_conf=False, lookup_fallback=False, lookup_fail_log_level=models.LogLevelForFailedLookups.ERROR, @@ -601,9 +601,9 @@ with CriblControlPlane( "conf": { "mode": models.SampleMode.SQRT, "key_expr": "`${domain}:${httpCode}`", - "sample_period": 20, - "min_events": 3, - "max_sample_rate": 3, + "sample_period": 20.0, + "min_events": 3.0, + "max_sample_rate": 3.0, }, }, ], @@ -730,11 +730,11 @@ with CriblControlPlane( rule_type=models.EventBreakerTypeOptionsEventBreakerExistingOrNewNew.REGEX, event_breaker_regex="/[\\n\\r]+(?!\\s)/", existing_or_new=models.EventBreakerExistingOrNewNewRuleTypeRegexExistingOrNew.NEW, - max_event_bytes=51200, + max_event_bytes=51200.0, timestamp_anchor_regex="/^/", timestamp=models.EventBreakerExistingOrNewNewTimestampTypeAuto( type=models.TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp.AUTO, - length=150, + length=150.0, ), timestamp_timezone="local", timestamp_earliest="-420weeks", @@ -779,7 +779,7 @@ with CriblControlPlane( "conf": { "fields": [], "prefix": "", - "depth": 5, + "depth": 5.0, "delimiter": "_", }, }, @@ -1041,7 +1041,7 @@ with CriblControlPlane( "file": "ip_locations.csv", "db_lookup": False, "match_mode": models.MatchMode.EXACT, - "reload_period_sec": -1, + "reload_period_sec": -1.0, "in_fields": [ { "event_field": "destination_ip", @@ -1185,11 +1185,11 @@ with CriblControlPlane( "conf": { "drop_non_log_events": False, "batch_otlp_logs": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -1239,11 +1239,11 @@ with CriblControlPlane( "drop_non_metric_events": False, "otlp_version": models.FunctionConfSchemaOTLPMetricsOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_metrics": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -1284,11 +1284,11 @@ with CriblControlPlane( "drop_non_trace_events": False, "otlp_version": models.FunctionConfSchemaOTLPTracesOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_traces": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -1442,7 +1442,7 @@ with CriblControlPlane( ), ], deployment_type=models.RedisAuthTypeNoneDeploymentType.STANDALONE, - max_block_secs=60, + max_block_secs=60.0, url="'redis://localhost:6379/0'", ), ), @@ -1483,7 +1483,7 @@ with CriblControlPlane( "conf": { "regex": "/metric1=(?\\d+)/", "source": "_raw", - "iterations": 100, + "iterations": 100.0, "overwrite": False, }, }, @@ -1770,12 +1770,12 @@ with CriblControlPlane( "id": models.PipelineFunctionSuppressID.SUPPRESS, "conf": { "key_expr": "`${ip}:${port}`", - "allow": 1, - "suppress_period_sec": 30, + "allow": 1.0, + "suppress_period_sec": 30.0, "drop_events_mode": True, - "max_cache_size": 50000, - "cache_idle_timeout_periods": 2, - "num_events_idle_timeout_trigger": 10000, + "max_cache_size": 50000.0, + "cache_idle_timeout_periods": 2.0, + "num_events_idle_timeout_trigger": 10000.0, }, }, ], @@ -2295,8 +2295,8 @@ with CriblControlPlane( "dst_field": "_time", "default_timezone": "local", "time_expression": "time.getTime() / 1000", - "offset": 0, - "max_len": 150, + "offset": 0.0, + "max_len": 150.0, "default_time": models.DefaultTime.NOW, "latest_date_allowed": "+1week", "earliest_date_allowed": "-420weeks", @@ -2544,8 +2544,8 @@ with CriblControlPlane( out_field_name="src_hostname", ), ], - cache_ttl=30, - max_cache_size=5000, + cache_ttl=30.0, + max_cache_size=5000.0, use_resolv_conf=False, lookup_fallback=False, lookup_fail_log_level=models.LogLevelForFailedLookups.ERROR, @@ -2668,9 +2668,9 @@ with CriblControlPlane( "conf": { "mode": models.SampleMode.SQRT, "key_expr": "`${domain}:${httpCode}`", - "sample_period": 20, - "min_events": 3, - "max_sample_rate": 3, + "sample_period": 20.0, + "min_events": 3.0, + "max_sample_rate": 3.0, }, }, ], @@ -2797,11 +2797,11 @@ with CriblControlPlane( rule_type=models.EventBreakerTypeOptionsEventBreakerExistingOrNewNew.REGEX, event_breaker_regex="/[\\n\\r]+(?!\\s)/", existing_or_new=models.EventBreakerExistingOrNewNewRuleTypeRegexExistingOrNew.NEW, - max_event_bytes=51200, + max_event_bytes=51200.0, timestamp_anchor_regex="/^/", timestamp=models.EventBreakerExistingOrNewNewTimestampTypeAuto( type=models.TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp.AUTO, - length=150, + length=150.0, ), timestamp_timezone="local", timestamp_earliest="-420weeks", @@ -2846,7 +2846,7 @@ with CriblControlPlane( "conf": { "fields": [], "prefix": "", - "depth": 5, + "depth": 5.0, "delimiter": "_", }, }, @@ -3108,7 +3108,7 @@ with CriblControlPlane( "file": "ip_locations.csv", "db_lookup": False, "match_mode": models.MatchMode.EXACT, - "reload_period_sec": -1, + "reload_period_sec": -1.0, "in_fields": [ { "event_field": "destination_ip", @@ -3252,11 +3252,11 @@ with CriblControlPlane( "conf": { "drop_non_log_events": False, "batch_otlp_logs": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -3306,11 +3306,11 @@ with CriblControlPlane( "drop_non_metric_events": False, "otlp_version": models.FunctionConfSchemaOTLPMetricsOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_metrics": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -3351,11 +3351,11 @@ with CriblControlPlane( "drop_non_trace_events": False, "otlp_version": models.FunctionConfSchemaOTLPTracesOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_traces": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -3509,7 +3509,7 @@ with CriblControlPlane( ), ], deployment_type=models.RedisAuthTypeNoneDeploymentType.STANDALONE, - max_block_secs=60, + max_block_secs=60.0, url="'redis://localhost:6379/0'", ), ), @@ -3550,7 +3550,7 @@ with CriblControlPlane( "conf": { "regex": "/metric1=(?\\d+)/", "source": "_raw", - "iterations": 100, + "iterations": 100.0, "overwrite": False, }, }, @@ -3837,12 +3837,12 @@ with CriblControlPlane( "id": models.PipelineFunctionSuppressID.SUPPRESS, "conf": { "key_expr": "`${ip}:${port}`", - "allow": 1, - "suppress_period_sec": 30, + "allow": 1.0, + "suppress_period_sec": 30.0, "drop_events_mode": True, - "max_cache_size": 50000, - "cache_idle_timeout_periods": 2, - "num_events_idle_timeout_trigger": 10000, + "max_cache_size": 50000.0, + "cache_idle_timeout_periods": 2.0, + "num_events_idle_timeout_trigger": 10000.0, }, }, ], @@ -4177,8 +4177,8 @@ with CriblControlPlane( "dst_field": "_time", "default_timezone": "local", "time_expression": "time.getTime() / 1000", - "offset": 0, - "max_len": 150, + "offset": 0.0, + "max_len": 150.0, "default_time": models.DefaultTime.NOW, "latest_date_allowed": "+1week", "earliest_date_allowed": "-420weeks", @@ -4426,8 +4426,8 @@ with CriblControlPlane( out_field_name="src_hostname", ), ], - cache_ttl=30, - max_cache_size=5000, + cache_ttl=30.0, + max_cache_size=5000.0, use_resolv_conf=False, lookup_fallback=False, lookup_fail_log_level=models.LogLevelForFailedLookups.ERROR, @@ -4550,9 +4550,9 @@ with CriblControlPlane( "conf": { "mode": models.SampleMode.SQRT, "key_expr": "`${domain}:${httpCode}`", - "sample_period": 20, - "min_events": 3, - "max_sample_rate": 3, + "sample_period": 20.0, + "min_events": 3.0, + "max_sample_rate": 3.0, }, }, ], @@ -4679,11 +4679,11 @@ with CriblControlPlane( rule_type=models.EventBreakerTypeOptionsEventBreakerExistingOrNewNew.REGEX, event_breaker_regex="/[\\n\\r]+(?!\\s)/", existing_or_new=models.EventBreakerExistingOrNewNewRuleTypeRegexExistingOrNew.NEW, - max_event_bytes=51200, + max_event_bytes=51200.0, timestamp_anchor_regex="/^/", timestamp=models.EventBreakerExistingOrNewNewTimestampTypeAuto( type=models.TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp.AUTO, - length=150, + length=150.0, ), timestamp_timezone="local", timestamp_earliest="-420weeks", @@ -4728,7 +4728,7 @@ with CriblControlPlane( "conf": { "fields": [], "prefix": "", - "depth": 5, + "depth": 5.0, "delimiter": "_", }, }, @@ -4990,7 +4990,7 @@ with CriblControlPlane( "file": "ip_locations.csv", "db_lookup": False, "match_mode": models.MatchMode.EXACT, - "reload_period_sec": -1, + "reload_period_sec": -1.0, "in_fields": [ { "event_field": "destination_ip", @@ -5134,11 +5134,11 @@ with CriblControlPlane( "conf": { "drop_non_log_events": False, "batch_otlp_logs": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -5188,11 +5188,11 @@ with CriblControlPlane( "drop_non_metric_events": False, "otlp_version": models.FunctionConfSchemaOTLPMetricsOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_metrics": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -5233,11 +5233,11 @@ with CriblControlPlane( "drop_non_trace_events": False, "otlp_version": models.FunctionConfSchemaOTLPTracesOTLPVersion.ZERO_DOT_10_DOT_0, "batch_otlp_traces": True, - "send_batch_size": 8192, - "timeout": 200, - "send_batch_max_size": 0, + "send_batch_size": 8192.0, + "timeout": 200.0, + "send_batch_max_size": 0.0, "metadata_keys": [], - "metadata_cardinality_limit": 1000, + "metadata_cardinality_limit": 1000.0, }, }, ], @@ -5391,7 +5391,7 @@ with CriblControlPlane( ), ], deployment_type=models.RedisAuthTypeNoneDeploymentType.STANDALONE, - max_block_secs=60, + max_block_secs=60.0, url="'redis://localhost:6379/0'", ), ), @@ -5432,7 +5432,7 @@ with CriblControlPlane( "conf": { "regex": "/metric1=(?\\d+)/", "source": "_raw", - "iterations": 100, + "iterations": 100.0, "overwrite": False, }, }, @@ -5719,12 +5719,12 @@ with CriblControlPlane( "id": models.PipelineFunctionSuppressID.SUPPRESS, "conf": { "key_expr": "`${ip}:${port}`", - "allow": 1, - "suppress_period_sec": 30, + "allow": 1.0, + "suppress_period_sec": 30.0, "drop_events_mode": True, - "max_cache_size": 50000, - "cache_idle_timeout_periods": 2, - "num_events_idle_timeout_trigger": 10000, + "max_cache_size": 50000.0, + "cache_idle_timeout_periods": 2.0, + "num_events_idle_timeout_trigger": 10000.0, }, }, ], diff --git a/docs/sdks/routessdk/README.md b/docs/sdks/routessdk/README.md index f95f706fb..624f7684b 100644 --- a/docs/sdks/routessdk/README.md +++ b/docs/sdks/routessdk/README.md @@ -32,8 +32,10 @@ with CriblControlPlane( res = ccp_client.routes.list() - # Handle response - print(res) + while res is not None: + # Handle items + + res = res.next() ``` ### Example Usage: RoutesResponseExamplesMultiRouteTable @@ -53,8 +55,10 @@ with CriblControlPlane( res = ccp_client.routes.list() - # Handle response - print(res) + while res is not None: + # Handle items + + res = res.next() ``` @@ -62,11 +66,13 @@ with CriblControlPlane( | Parameter | Type | Required | Description | | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | +| `offset` | *Optional[int]* | :heavy_minus_sign: | Pagination offset | +| `limit` | *Optional[int]* | :heavy_minus_sign: | Maximum number of items to return | | `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response -**[models.CountedRoutes](../../models/countedroutes.md)** +**[models.GetRoutesResponse](../../models/getroutesresponse.md)** ### Errors diff --git a/docs/sdks/sources/README.md b/docs/sdks/sources/README.md index 8c515cf88..ab44aee1d 100644 --- a/docs/sdks/sources/README.md +++ b/docs/sdks/sources/README.md @@ -18,7 +18,7 @@ Get a list of all Sources. ### Example Usage: InputResponseExamplesHttpSource - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -41,7 +41,7 @@ with CriblControlPlane( ``` ### Example Usage: InputResponseExamplesSplunkHecSource - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -64,7 +64,7 @@ with CriblControlPlane( ``` ### Example Usage: InputResponseExamplesSyslogSource - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -87,7 +87,7 @@ with CriblControlPlane( ``` ### Example Usage: InputResponseExamplesSyslogWithPQSource - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -120,7 +120,7 @@ with CriblControlPlane( ### Response -**[models.ListInputResponse](../../models/listinputresponse.md)** +**[models.GetInputResponse](../../models/getinputresponse.md)** ### Errors @@ -134,6 +134,35 @@ with CriblControlPlane( Create a new Source. The system-managed provenance field (JSON criblSourceProvenance) must be omitted from the request body. +### Example Usage: InputCreateExamplesAkamaiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "akamai-hec-source", + "type": models.CreateInputInputAkamaiHecType.AKAMAI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` ### Example Usage: InputCreateExamplesAnthropicCompliance @@ -160,6 +189,47 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesAnthropicEnterpriseAnalytics + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "anthropic-enterprise-analytics-source", + "type": models.CreateInputInputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS, + "send_to_routes": True, + "pq_enabled": False, + "text_secret": "anthropic-api-key-secret", + "content_config": [ + { + "content_type": models.CreateInputContentType.USAGE_REPORT, + "disabled": False, + "state_tracking": True, + "state_update_expression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", + "state_merge_expression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", + "group_by": [], + "bucket_width": models.CreateInputBucketWidth.ONED, + "cron_schedule": "0 */4 * * *", + "earliest": "-7d@d", + "job_timeout": "300", + }, + ], + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesAppleUnifiedLogs @@ -209,7 +279,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9109, + "port": 9109.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesAquaSecurityHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "aqua-security-hec-source", + "type": models.CreateInputInputAquaSecurityHecType.AQUA_SECURITY_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -242,6 +341,33 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesAzureVNetFlowLog + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "azure-vnet-flow-log-source", + "type": models.CreateInputInputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG, + "send_to_routes": True, + "pq_enabled": False, + "queue_name": "vnet-flow-log-queue", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesBedrockS3 @@ -270,6 +396,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesBeyondTrustHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "beyondtrust-hec-source", + "type": models.CreateInputInputBeyondtrustHecType.BEYONDTRUST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesCloudflareHec @@ -292,7 +447,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -379,7 +534,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -407,7 +562,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -435,7 +590,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -491,7 +646,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8126, + "port": 8126.0, }) # Handle response @@ -521,7 +676,7 @@ with CriblControlPlane( "samples": [ { "sample": "sample.json", - "events_per_sec": 10, + "events_per_sec": 10.0, }, ], }) @@ -551,7 +706,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.CreateInputInputEdgePrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "targets": [ { "host": "localhost", @@ -584,7 +739,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "localhost", - "port": 9200, + "port": 9200.0, "elastic_api": "/", }) @@ -678,7 +833,65 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "command": "echo \"Hello World\"", - "interval": 60, + "interval": 60.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesExtrahopRevealx360 + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "extrahop-revealx-360-source", + "type": models.CreateInputInputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesF5BigIp + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "f5-big-ip-source", + "type": models.CreateInputInputF5BigIPType.F5_BIG_IP, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -733,7 +946,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesGigamonHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "gigamon-hec-source", + "type": models.CreateInputInputGigamonHecType.GIGAMON_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -789,13 +1031,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/api/prom/push", }) # Handle response print(res) +``` +### Example Usage: InputCreateExamplesHashicorpHcpVaultDedicated + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "hashicorp-hcp-vault-dedicated-source", + "type": models.CreateInputInputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesHttp @@ -818,7 +1089,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -846,7 +1117,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -1042,7 +1313,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "loki_api": "/loki/api/v1/push", }) @@ -1071,7 +1342,40 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 8125, + "udp_port": 8125.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesMicrosoftCopilot + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "microsoft-copilot-source", + "type": models.CreateInputInputMicrosoftCopilotType.MICROSOFT_COPILOT, + "send_to_routes": True, + "pq_enabled": False, + "tenant_id": "00000000-0000-0000-0000-000000000000", + "client_id": "00000000-0000-0000-0000-000000000001", + "auth_type": models.CreateInputInputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET, + "cron_schedule": "*/15 * * * *", + "earliest": "-7d", + "latest": "now", + "text_secret": "microsoft-copilot-secret", }) # Handle response @@ -1105,6 +1409,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: InputCreateExamplesMimecastHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "mimecast-hec-source", + "type": models.CreateInputInputMimecastHecType.MIMECAST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesModelDrivenTelemetry @@ -1127,7 +1460,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 57000, + "port": 57000.0, }) # Handle response @@ -1189,7 +1522,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 2055, + "port": 2055.0, }) # Handle response @@ -1419,7 +1752,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 4317, + "port": 4317.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesPingIdentityPingone + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "ping-identity-pingone-source", + "type": models.CreateInputInputPingIdentityPingoneType.PING_IDENTITY_PINGONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -1447,7 +1809,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.CreateInputInputPrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "log_level": models.LogLevelOptions.INFO, "target_list": [ "http://localhost:9090/metrics", @@ -1479,13 +1841,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/write", }) # Handle response print(res) +``` +### Example Usage: InputCreateExamplesProofpointPod + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "proofpoint-pod-source", + "type": models.CreateInputInputProofpointPodType.PROOFPOINT_POD, + "send_to_routes": True, + "pq_enabled": False, + "cluster_id": "my-pod-cluster", + "feed_type": models.CreateInputFeedType.MESSAGE, + "text_secret": "proofpoint-pod-token-secret", + }) + + # Handle response + print(res) + ``` ### Example Usage: InputCreateExamplesRawUdp @@ -1508,7 +1899,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 514, + "port": 514.0, }) # Handle response @@ -1563,8 +1954,37 @@ with CriblControlPlane( "type": models.CreateInputInputS3InventoryType.S3_INVENTORY, "send_to_routes": True, "pq_enabled": False, - "queue_name": "s3-inventory-queue", - "region": "us-east-1", + "queue_name": "s3-inventory-queue", + "region": "us-east-1", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesSailpointHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "sailpoint-hec-source", + "type": models.CreateInputInputSailpointHecType.SAILPOINT_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -1657,7 +2077,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "192.168.1.1", - "port": 161, + "port": 161.0, }) # Handle response @@ -1685,7 +2105,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -1713,7 +2133,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "splunk_hec_api": "/services/collector", }) @@ -1803,7 +2223,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -1832,7 +2252,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -1869,7 +2289,7 @@ with CriblControlPlane( "on_backpressure": models.QueueFullBehaviorOptionsPq.DROP, }, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -1949,7 +2369,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -1977,7 +2397,65 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesTrellixHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "trellix-hec-source", + "type": models.CreateInputInputTrellixHecType.TRELLIX_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesTrendMicroVisionOne + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "trend-micro-vision-one-source", + "type": models.CreateInputInputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -2005,7 +2483,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: InputCreateExamplesVectraAiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.create(request={ + "id": "vectra-ai-hec-source", + "type": models.CreateInputInputVectraAiHecType.VECTRA_AI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, "hec_api": "/services/collector", }) @@ -2034,13 +2541,13 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 5985, + "port": 5985.0, "subscriptions": [ { "subscription_name": "subscription-1", "content_format": models.CreateInputFormat.RENDERED_TEXT, - "heartbeat_interval": 60, - "batch_timeout": 5, + "heartbeat_interval": 60.0, + "batch_timeout": 5.0, "targets": [], }, ], @@ -2157,7 +2664,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -2185,7 +2692,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -2527,7 +3034,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9109, + "port": 9109.0, }) # Handle response @@ -2582,7 +3089,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -2669,7 +3176,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -2697,7 +3204,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -2725,7 +3232,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -2781,7 +3288,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8126, + "port": 8126.0, }) # Handle response @@ -2811,7 +3318,7 @@ with CriblControlPlane( "samples": [ { "sample": "sample.json", - "events_per_sec": 10, + "events_per_sec": 10.0, }, ], }) @@ -2841,7 +3348,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputEdgePrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "targets": [ { "host": "localhost", @@ -2874,7 +3381,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "localhost", - "port": 9200, + "port": 9200.0, "elastic_api": "/", }) @@ -2968,7 +3475,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "command": "echo \"Hello World\"", - "interval": 60, + "interval": 60.0, }) # Handle response @@ -3023,7 +3530,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -3079,7 +3586,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/api/prom/push", }) @@ -3108,7 +3615,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -3136,7 +3643,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -3332,7 +3839,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "loki_api": "/loki/api/v1/push", }) @@ -3361,7 +3868,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 8125, + "udp_port": 8125.0, }) # Handle response @@ -3417,7 +3924,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 57000, + "port": 57000.0, }) # Handle response @@ -3479,7 +3986,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 2055, + "port": 2055.0, }) # Handle response @@ -3709,7 +4216,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 4317, + "port": 4317.0, }) # Handle response @@ -3737,7 +4244,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputPrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "log_level": models.LogLevelOptions.INFO, "target_list": [ "http://localhost:9090/metrics", @@ -3769,7 +4276,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/write", }) @@ -3798,7 +4305,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 514, + "port": 514.0, }) # Handle response @@ -3947,7 +4454,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "192.168.1.1", - "port": 161, + "port": 161.0, }) # Handle response @@ -3975,7 +4482,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -4003,7 +4510,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "splunk_hec_api": "/services/collector", }) @@ -4093,7 +4600,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -4173,7 +4680,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4201,7 +4708,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4229,13 +4736,13 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 5985, + "port": 5985.0, "subscriptions": [ { "subscription_name": "subscription-1", "content_format": models.InputWefFormat.RENDERED_TEXT, - "heartbeat_interval": 60, - "batch_timeout": 5, + "heartbeat_interval": 60.0, + "batch_timeout": 5.0, "targets": [], }, ], @@ -4352,7 +4859,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -4380,7 +4887,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -4543,6 +5050,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesAkamaiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "akamai-hec-source", + "type": models.InputAkamaiHecType.AKAMAI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesAnthropicCompliance @@ -4570,6 +5106,47 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesAnthropicEnterpriseAnalytics + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "anthropic-enterprise-analytics-source", + "type": models.InputAnthropicEnterpriseAnalyticsType.ANTHROPIC_ENTERPRISE_ANALYTICS, + "send_to_routes": True, + "pq_enabled": False, + "text_secret": "anthropic-api-key-secret", + "content_config": [ + { + "content_type": models.ContentType.USAGE_REPORT, + "disabled": False, + "state_tracking": True, + "state_update_expression": "data_refreshed_at && data_refreshed_at > (state.latestDataRefreshedAt || '') ? {latestDataRefreshedAt: data_refreshed_at} : state", + "state_merge_expression": "(prevState.latestDataRefreshedAt || '') >= (newState.latestDataRefreshedAt || '') ? prevState : newState", + "group_by": [], + "bucket_width": models.BucketWidth.ONED, + "cron_schedule": "0 */4 * * *", + "earliest": "-7d@d", + "job_timeout": "300", + }, + ], + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesAppleUnifiedLogs @@ -4619,7 +5196,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9109, + "port": 9109.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesAquaSecurityHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "aqua-security-hec-source", + "type": models.InputAquaSecurityHecType.AQUA_SECURITY_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -4652,6 +5258,33 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesAzureVNetFlowLog + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "azure-vnet-flow-log-source", + "type": models.InputAzureVnetFlowLogType.AZURE_VNET_FLOW_LOG, + "send_to_routes": True, + "pq_enabled": False, + "queue_name": "vnet-flow-log-queue", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesBedrockS3 @@ -4680,6 +5313,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesBeyondTrustHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "beyondtrust-hec-source", + "type": models.InputBeyondtrustHecType.BEYONDTRUST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesCloudflareHec @@ -4702,7 +5364,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -4815,7 +5477,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -4843,7 +5505,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -4897,7 +5559,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -4953,7 +5615,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8126, + "port": 8126.0, }) # Handle response @@ -4983,7 +5645,7 @@ with CriblControlPlane( "samples": [ { "sample": "sample.json", - "events_per_sec": 10, + "events_per_sec": 10.0, }, ], }) @@ -5013,7 +5675,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputEdgePrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "targets": [ { "host": "localhost", @@ -5046,7 +5708,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "localhost", - "port": 9200, + "port": 9200.0, "elastic_api": "/", }) @@ -5102,26 +5764,83 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.sources.update(id="", input_={ - "id": "eventhub-amqp-source", - "type": models.InputEventhubAmqpType.EVENTHUB_AMQP, + "id": "eventhub-amqp-source", + "type": models.InputEventhubAmqpType.EVENTHUB_AMQP, + "send_to_routes": True, + "pq_enabled": False, + "event_hub_name": "my-event-hub", + "consumer_group": "$Default", + "checkpointing": { + "blob_store": { + "container_name": "my-container", + }, + }, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesExec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "exec-source", + "type": models.InputExecType.EXEC, + "send_to_routes": True, + "pq_enabled": False, + "command": "echo \"Hello World\"", + "interval": 60.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesExtrahopRevealx360 + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "extrahop-revealx-360-source", + "type": models.InputExtrahopRevealx360Type.EXTRAHOP_REVEALX_360, "send_to_routes": True, "pq_enabled": False, - "event_hub_name": "my-event-hub", - "consumer_group": "$Default", - "checkpointing": { - "blob_store": { - "container_name": "my-container", - }, - }, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response print(res) ``` -### Example Usage: UpdateInputExamplesExec +### Example Usage: UpdateInputExamplesF5BigIp - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -5135,12 +5854,13 @@ with CriblControlPlane( ) as ccp_client: res = ccp_client.sources.update(id="", input_={ - "id": "exec-source", - "type": models.InputExecType.EXEC, + "id": "f5-big-ip-source", + "type": models.InputF5BigIPType.F5_BIG_IP, "send_to_routes": True, "pq_enabled": False, - "command": "echo \"Hello World\"", - "interval": 60, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -5195,7 +5915,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesGigamonHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "gigamon-hec-source", + "type": models.InputGigamonHecType.GIGAMON_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -5251,13 +6000,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/api/prom/push", }) # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesHashicorpHcpVaultDedicated + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "hashicorp-hcp-vault-dedicated-source", + "type": models.InputHashicorpHcpVaultDedicatedType.HASHICORP_HCP_VAULT_DEDICATED, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesHttp @@ -5280,7 +6058,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -5308,7 +6086,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -5504,7 +6282,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "loki_api": "/loki/api/v1/push", }) @@ -5533,7 +6311,40 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 8125, + "udp_port": 8125.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesMicrosoftCopilot + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "microsoft-copilot-source", + "type": models.InputMicrosoftCopilotType.MICROSOFT_COPILOT, + "send_to_routes": True, + "pq_enabled": False, + "tenant_id": "00000000-0000-0000-0000-000000000000", + "client_id": "00000000-0000-0000-0000-000000000001", + "auth_type": models.InputMicrosoftCopilotAuthenticationMethod.OAUTH_SECRET, + "cron_schedule": "*/15 * * * *", + "earliest": "-7d", + "latest": "now", + "text_secret": "microsoft-copilot-secret", }) # Handle response @@ -5567,6 +6378,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesMimecastHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "mimecast-hec-source", + "type": models.InputMimecastHecType.MIMECAST_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesModelDrivenTelemetry @@ -5589,7 +6429,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 57000, + "port": 57000.0, }) # Handle response @@ -5651,7 +6491,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 2055, + "port": 2055.0, }) # Handle response @@ -5881,7 +6721,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 4317, + "port": 4317.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesPingIdentityPingone + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "ping-identity-pingone-source", + "type": models.InputPingIdentityPingoneType.PING_IDENTITY_PINGONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -5909,7 +6778,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "discovery_type": models.InputPrometheusDiscoveryType.STATIC, - "interval": 60, + "interval": 60.0, "log_level": models.LogLevelOptions.INFO, "target_list": [ "http://localhost:9090/metrics", @@ -5941,13 +6810,42 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, "prometheus_api": "/write", }) # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesProofpointPod + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "proofpoint-pod-source", + "type": models.InputProofpointPodType.PROOFPOINT_POD, + "send_to_routes": True, + "pq_enabled": False, + "cluster_id": "my-pod-cluster", + "feed_type": models.FeedType.MESSAGE, + "text_secret": "proofpoint-pod-token-secret", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesRawUdp @@ -5970,7 +6868,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 514, + "port": 514.0, }) # Handle response @@ -6032,6 +6930,35 @@ with CriblControlPlane( # Handle response print(res) +``` +### Example Usage: UpdateInputExamplesSailpointHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "sailpoint-hec-source", + "type": models.InputSailpointHecType.SAILPOINT_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + ``` ### Example Usage: UpdateInputExamplesSecurityLake @@ -6119,7 +7046,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "192.168.1.1", - "port": 161, + "port": 161.0, }) # Handle response @@ -6147,7 +7074,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 9997, + "port": 9997.0, }) # Handle response @@ -6175,7 +7102,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "splunk_hec_api": "/services/collector", }) @@ -6265,7 +7192,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) @@ -6294,7 +7221,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -6331,7 +7258,7 @@ with CriblControlPlane( "on_backpressure": models.QueueFullBehaviorOptionsPq.DROP, }, "host": "0.0.0.0", - "udp_port": 514, + "udp_port": 514.0, }) # Handle response @@ -6411,7 +7338,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, }) # Handle response @@ -6439,7 +7366,65 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10090, + "port": 10090.0, + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesTrellixHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "trellix-hec-source", + "type": models.InputTrellixHecType.TRELLIX_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesTrendMicroVisionOne + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "trend-micro-vision-one-source", + "type": models.InputTrendMicroVisionOneType.TREND_MICRO_VISION_ONE, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, + "hec_api": "/services/collector", }) # Handle response @@ -6467,7 +7452,36 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, + "hec_api": "/services/collector", + }) + + # Handle response + print(res) + +``` +### Example Usage: UpdateInputExamplesVectraAiHec + + +```python +from cribl_control_plane import CriblControlPlane, models +import os + + +with CriblControlPlane( + "https://api.example.com", + security=models.Security( + bearer_auth=os.getenv("CRIBLCONTROLPLANE_BEARER_AUTH", ""), + ), +) as ccp_client: + + res = ccp_client.sources.update(id="", input_={ + "id": "vectra-ai-hec-source", + "type": models.InputVectraAiHecType.VECTRA_AI_HEC, + "send_to_routes": True, + "pq_enabled": False, + "host": "0.0.0.0", + "port": 8088.0, "hec_api": "/services/collector", }) @@ -6496,13 +7510,13 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 5985, + "port": 5985.0, "subscriptions": [ { "subscription_name": "subscription-1", "content_format": models.InputWefFormat.RENDERED_TEXT, - "heartbeat_interval": 60, - "batch_timeout": 5, + "heartbeat_interval": 60.0, + "batch_timeout": 5.0, "targets": [], }, ], @@ -6619,7 +7633,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 10080, + "port": 10080.0, }) # Handle response @@ -6647,7 +7661,7 @@ with CriblControlPlane( "send_to_routes": True, "pq_enabled": False, "host": "0.0.0.0", - "port": 8088, + "port": 8088.0, "hec_api": "/services/collector", }) diff --git a/docs/sdks/teams/README.md b/docs/sdks/teams/README.md index bfa2dd7d1..296c5bbd0 100644 --- a/docs/sdks/teams/README.md +++ b/docs/sdks/teams/README.md @@ -4,15 +4,15 @@ ### Available Operations -* [get](#get) - Get the Access Control List for teams with permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product +* [get](#get) - Get the team access control list for a Worker Group, Outpost Group, or Edge Fleet ## get -Get the Access Control List (ACL) for teams that have permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product. +Get the Team access control list (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet.

This endpoint lists Teams with explicit access assignments on the Group or Fleet. The response does not include access granted to individual Team Members through direct user assignments or inherited based on Team Permissions and Roles at the Organization/Global, Workspace, or product level.

To list the user ACL for a Group or Fleet, use GET /products/{product}/groups/{id}/acl. ### Example Usage - + ```python from cribl_control_plane import CriblControlPlane, models import os @@ -25,7 +25,7 @@ with CriblControlPlane( ), ) as ccp_client: - res = ccp_client.groups.acl.teams.get(product=models.ProductsCore.STREAM, id="", type_=models.RbacResource.DATASETS) + res = ccp_client.groups.acl.teams.get(product=models.ProductsCore.STREAM, id="") # Handle response print(res) @@ -37,7 +37,7 @@ with CriblControlPlane( | Parameter | Type | Required | Description | | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------- | | `product` | [models.ProductsCore](../../models/productscore.md) | :heavy_check_mark: | Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. | -| `id` | *str* | :heavy_check_mark: | The id of the Worker Group, Outpost Group, or Edge Fleet to get the team ACL for. | +| `id` | *str* | :heavy_check_mark: | The id of the Worker Group, Outpost Group, or Edge Fleet to get the Team ACL for. | | `type` | [Optional[models.RbacResource]](../../models/rbacresource.md) | :heavy_minus_sign: | Filter for limiting the response to ACL entries for the specified RBAC resource type. | | `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | diff --git a/docs/sdks/tokens/README.md b/docs/sdks/tokens/README.md index c124493d5..abd7a1e05 100644 --- a/docs/sdks/tokens/README.md +++ b/docs/sdks/tokens/README.md @@ -10,7 +10,41 @@ This endpoint is unavailable on Cribl.Cloud. Instead, follow the instructions at https://docs.cribl.io/stream/api-tutorials/#criblcloud to get an Auth token for Cribl.Cloud. -### Example Usage +### Example Usage: LoginExamplesLocalLogin + + +```python +from cribl_control_plane import CriblControlPlane + + +with CriblControlPlane( + "https://api.example.com", +) as ccp_client: + + res = ccp_client.auth.tokens.get(password="yourPassword", username="yourUsername") + + # Handle response + print(res) + +``` +### Example Usage: LoginResponseExamplesLocalLogin + + +```python +from cribl_control_plane import CriblControlPlane + + +with CriblControlPlane( + "https://api.example.com", +) as ccp_client: + + res = ccp_client.auth.tokens.get(password="j50J9421x29IhO_", username="Turner.Kuhn") + + # Handle response + print(res) + +``` +### Example Usage: authenticationFailed ```python @@ -21,7 +55,7 @@ with CriblControlPlane( "https://api.example.com", ) as ccp_client: - res = ccp_client.auth.tokens.get(password="6j50J9421x29IhO", username="Lilly_Weissnat") + res = ccp_client.auth.tokens.get(password="j50J9421x29IhO_", username="Turner.Kuhn") # Handle response print(res) @@ -32,8 +66,8 @@ with CriblControlPlane( | Parameter | Type | Required | Description | | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | ------------------------------------------------------------------- | -| `password` | *str* | :heavy_check_mark: | N/A | -| `username` | *str* | :heavy_check_mark: | N/A | +| `password` | *str* | :heavy_check_mark: | Password for the account. | +| `username` | *str* | :heavy_check_mark: | Username of the account to authenticate. | | `retries` | [Optional[utils.RetryConfig]](../../models/utils/retryconfig.md) | :heavy_minus_sign: | Configuration to override the default retry behavior of the client. | ### Response diff --git a/examples/example_cloud_configure_resources.py b/examples/example_cloud_configure_resources.py index d404d9ed2..179242093 100644 --- a/examples/example_cloud_configure_resources.py +++ b/examples/example_cloud_configure_resources.py @@ -236,10 +236,10 @@ async def main(): # the new Route (based on the Route definition block), saves the updated # Routing table, and prints a confirmation message. routes_list_response = cribl.routes.list(server_url=group_url) - if not routes_list_response.items or len(routes_list_response.items) == 0: + if not routes_list_response or not routes_list_response.result.items: raise Exception("No Routes found") - routes = routes_list_response.items[0] + routes = routes_list_response.result.items[0] if not routes or not routes.id: raise Exception("No Routes found") diff --git a/examples/example_onprem_configure_resources.py b/examples/example_onprem_configure_resources.py index 02cccdcdd..e4f306c31 100644 --- a/examples/example_onprem_configure_resources.py +++ b/examples/example_onprem_configure_resources.py @@ -224,10 +224,10 @@ async def main(): # the new Route (based on the Route definition block), saves the updated # Routing table, and prints a confirmation message. routes_list_response = cribl.routes.list(server_url=group_url) - if not routes_list_response.items or len(routes_list_response.items) == 0: + if not routes_list_response or not routes_list_response.result.items: raise Exception("No Routes found") - routes = routes_list_response.items[0] + routes = routes_list_response.result.items[0] if not routes or not routes.id: raise Exception("No Routes found") diff --git a/pyproject.toml b/pyproject.toml index f19e40bda..22d26b414 100644 --- a/pyproject.toml +++ b/pyproject.toml @@ -1,7 +1,7 @@ [project] name = "cribl-control-plane" -version = "0.11.0" +version = "0.12.0" description = "Python Client SDK Generated by Speakeasy." authors = [{ name = "Speakeasy" },] readme = "README-PYPI.md" diff --git a/src/cribl_control_plane/_version.py b/src/cribl_control_plane/_version.py index b5ac82954..f5ee1173f 100644 --- a/src/cribl_control_plane/_version.py +++ b/src/cribl_control_plane/_version.py @@ -3,11 +3,11 @@ import importlib.metadata __title__: str = "cribl-control-plane" -__version__: str = "0.11.0" -__openapi_doc_version__: str = "4.19.2-89cac507" -__gen_version__: str = "2.932.9" +__version__: str = "0.12.0" +__openapi_doc_version__: str = "4.20.0-cee79842" +__gen_version__: str = "2.937.18" __user_agent__: str = ( - "speakeasy-sdk/python 0.11.0 2.932.9 4.19.2-89cac507 cribl-control-plane" + "speakeasy-sdk/python 0.12.0 2.937.18 4.20.0-cee79842 cribl-control-plane" ) try: diff --git a/src/cribl_control_plane/acl.py b/src/cribl_control_plane/acl.py index 3533e260d..75898a73d 100644 --- a/src/cribl_control_plane/acl.py +++ b/src/cribl_control_plane/acl.py @@ -35,11 +35,11 @@ def get( timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, ) -> models.CountedUserAccessControlList: - r"""Get the Access Control List for a Worker Group, Outpost Group, or Edge Fleet + r"""Get the user access control list for a Worker Group, Outpost Group, or Edge Fleet - Get the Access Control List (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet. + Get the user access control list (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet.

This endpoint lists users with explicit access assignments on the Group or Fleet. The response does not include access granted through Team membership or inherited based on a user's Permissions and Roles at the Organization/Global, Workspace, or product level.

To list the Team ACL for a product and Group or Fleet, use GET /products/{product}/groups/{id}/acl/teams. - :param product: Name of the Cribl product to get the Worker Groups or Edge Fleets for. + :param product: Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. :param id: The id of the Worker Group, Outpost Group, or Edge Fleet to get the ACL for. :param type: Filter for limiting the response to ACL entries for the specified RBAC resource type. :param retries: Override the default retry configuration for this method @@ -102,7 +102,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -120,7 +124,7 @@ def get( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["404", "4XX"], "*"): http_res_text = utils.stream_to_text(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -140,11 +144,11 @@ async def get_async( timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, ) -> models.CountedUserAccessControlList: - r"""Get the Access Control List for a Worker Group, Outpost Group, or Edge Fleet + r"""Get the user access control list for a Worker Group, Outpost Group, or Edge Fleet - Get the Access Control List (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet. + Get the user access control list (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet.

This endpoint lists users with explicit access assignments on the Group or Fleet. The response does not include access granted through Team membership or inherited based on a user's Permissions and Roles at the Organization/Global, Workspace, or product level.

To list the Team ACL for a product and Group or Fleet, use GET /products/{product}/groups/{id}/acl/teams. - :param product: Name of the Cribl product to get the Worker Groups or Edge Fleets for. + :param product: Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. :param id: The id of the Worker Group, Outpost Group, or Edge Fleet to get the ACL for. :param type: Filter for limiting the response to ACL entries for the specified RBAC resource type. :param retries: Override the default retry configuration for this method @@ -207,7 +211,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -225,7 +233,7 @@ async def get_async( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["404", "4XX"], "*"): http_res_text = await utils.stream_to_text_async(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): diff --git a/src/cribl_control_plane/branches.py b/src/cribl_control_plane/branches.py index 89f86421d..6b46febf2 100644 --- a/src/cribl_control_plane/branches.py +++ b/src/cribl_control_plane/branches.py @@ -75,7 +75,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -165,7 +169,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -255,7 +263,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -345,7 +357,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/captures.py b/src/cribl_control_plane/captures.py index b4f2c0cf8..c1de2c1f9 100644 --- a/src/cribl_control_plane/captures.py +++ b/src/cribl_control_plane/captures.py @@ -103,7 +103,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["preview"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -233,7 +237,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["preview"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/collectors_sdk.py b/src/cribl_control_plane/collectors_sdk.py index f94f7ac60..6958dec2e 100644 --- a/src/cribl_control_plane/collectors_sdk.py +++ b/src/cribl_control_plane/collectors_sdk.py @@ -91,7 +91,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -224,7 +228,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -357,7 +365,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -457,7 +469,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -554,7 +570,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -651,7 +671,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -754,7 +778,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -857,7 +885,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -954,7 +986,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1051,7 +1087,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["collectors"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/commits.py b/src/cribl_control_plane/commits.py index f8da9e1ab..e64dd645e 100644 --- a/src/cribl_control_plane/commits.py +++ b/src/cribl_control_plane/commits.py @@ -103,7 +103,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -234,7 +238,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -371,7 +379,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -482,7 +494,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -590,7 +606,11 @@ def diff( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -693,7 +713,11 @@ async def diff_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -783,7 +807,11 @@ def push( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -873,7 +901,11 @@ async def push_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -979,7 +1011,11 @@ def revert( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1085,7 +1121,11 @@ async def revert_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1188,7 +1228,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1291,7 +1335,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1381,7 +1429,11 @@ def undo( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1471,7 +1523,11 @@ async def undo_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/commits_files.py b/src/cribl_control_plane/commits_files.py index 5918c2423..2d9286899 100644 --- a/src/cribl_control_plane/commits_files.py +++ b/src/cribl_control_plane/commits_files.py @@ -82,7 +82,11 @@ def count( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -179,7 +183,11 @@ async def count_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -276,7 +284,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -373,7 +385,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/configs_versions.py b/src/cribl_control_plane/configs_versions.py index 26a756468..a0d7aa465 100644 --- a/src/cribl_control_plane/configs_versions.py +++ b/src/cribl_control_plane/configs_versions.py @@ -85,7 +85,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -185,7 +189,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/cribl.py b/src/cribl_control_plane/cribl.py index 3e15c9b43..25375f0b3 100644 --- a/src/cribl_control_plane/cribl.py +++ b/src/cribl_control_plane/cribl.py @@ -75,7 +75,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["system"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -165,7 +169,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["system"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -193,12 +201,7 @@ async def list_async( def update( self, *, - api: Optional[ - Union[ - models.SystemSettingsConfUpdateAPI, - models.SystemSettingsConfUpdateAPITypedDict, - ] - ] = None, + api: Optional[Union[models.API, models.APITypedDict]] = None, apps: Optional[Union[models.Apps, models.AppsTypedDict]] = None, backups: Optional[ Union[models.BackupsSettingsUnion, models.BackupsSettingsUnionTypedDict] @@ -252,7 +255,7 @@ def update( ) -> models.CountedSystemSettingsConfResponse: r"""Update system settings - Update the specified Cribl system settings.

Provide only the top-level sections (api, workers, tls, proxy, etc.) you want to change. Omitted sections stay unchanged. Each provided section fully replaces the existing one — send the complete section object, not only the changed fields. + Update the specified Cribl system settings.

Provide only the top-level sections (api, workers, tls, proxy, etc.) you want to change. Omitted sections stay unchanged. Each provided section fully replaces the existing one — send the complete section object, not only the changed fields.

api.loginRateLimit and api.ssoRateLimit are deprecated. A new value is still applied, but it is stored as rateLimits in the API limits configuration. Use PATCH /system/api-limits instead. :param api: API server configuration for the Cribl instance. :param apps: App configuration. @@ -286,9 +289,7 @@ def update( base_url = self._get_url(base_url, url_variables) request = models.SystemSettingsConfUpdate( - api=utils.get_pydantic_model( - api, Optional[models.SystemSettingsConfUpdateAPI] - ), + api=utils.get_pydantic_model(api, Optional[models.API]), apps=utils.get_pydantic_model(apps, Optional[models.Apps]), backups=utils.get_pydantic_model( backups, Optional[models.BackupsSettingsUnion] @@ -364,7 +365,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["system"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -394,12 +399,7 @@ def update( async def update_async( self, *, - api: Optional[ - Union[ - models.SystemSettingsConfUpdateAPI, - models.SystemSettingsConfUpdateAPITypedDict, - ] - ] = None, + api: Optional[Union[models.API, models.APITypedDict]] = None, apps: Optional[Union[models.Apps, models.AppsTypedDict]] = None, backups: Optional[ Union[models.BackupsSettingsUnion, models.BackupsSettingsUnionTypedDict] @@ -453,7 +453,7 @@ async def update_async( ) -> models.CountedSystemSettingsConfResponse: r"""Update system settings - Update the specified Cribl system settings.

Provide only the top-level sections (api, workers, tls, proxy, etc.) you want to change. Omitted sections stay unchanged. Each provided section fully replaces the existing one — send the complete section object, not only the changed fields. + Update the specified Cribl system settings.

Provide only the top-level sections (api, workers, tls, proxy, etc.) you want to change. Omitted sections stay unchanged. Each provided section fully replaces the existing one — send the complete section object, not only the changed fields.

api.loginRateLimit and api.ssoRateLimit are deprecated. A new value is still applied, but it is stored as rateLimits in the API limits configuration. Use PATCH /system/api-limits instead. :param api: API server configuration for the Cribl instance. :param apps: App configuration. @@ -487,9 +487,7 @@ async def update_async( base_url = self._get_url(base_url, url_variables) request = models.SystemSettingsConfUpdate( - api=utils.get_pydantic_model( - api, Optional[models.SystemSettingsConfUpdateAPI] - ), + api=utils.get_pydantic_model(api, Optional[models.API]), apps=utils.get_pydantic_model(apps, Optional[models.Apps]), backups=utils.get_pydantic_model( backups, Optional[models.BackupsSettingsUnion] @@ -565,7 +563,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["system"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/databaseconnections.py b/src/cribl_control_plane/databaseconnections.py index 7c7bc76a2..c0c4332d0 100644 --- a/src/cribl_control_plane/databaseconnections.py +++ b/src/cribl_control_plane/databaseconnections.py @@ -91,7 +91,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -224,7 +228,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -294,9 +302,14 @@ def create( config_obj: Optional[str] = None, connection_string: Optional[str] = None, connection_timeout: Optional[int] = None, + credentials_secret: Optional[str] = None, creds_secrets: Optional[str] = None, + database: Optional[str] = None, + host: Optional[str] = None, + log_on_mechanism: Optional[str] = None, password: Optional[str] = None, request_timeout: Optional[int] = None, + sslmode: Optional[str] = None, tags: Optional[str] = None, text_secret: Optional[str] = None, tls: Optional[ @@ -319,9 +332,14 @@ def create( :param config_obj: JSON configuration object for advanced SQL Server connection settings. :param connection_string: Database connection string with embedded credentials or server information. :param connection_timeout: Maximum time (in milliseconds) to wait when establishing the database connection. + :param credentials_secret: Name of the stored credentials secret containing username and password for SQL Server configObj authentication. :param creds_secrets: Name of the stored credentials secret containing username and password. Used with Oracle connections. + :param database: Database to connect to instead of the server default. + :param host: Hostname of the server to connect to. + :param log_on_mechanism: Log On Mechanism for databases that support multiple, like Teradata. :param password: Database password for authentication. Used with Oracle connections. :param request_timeout: Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only. + :param sslmode: HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior. :param tags: Comma-separated list of tags for categorizing and filtering Database Connections. :param text_secret: Name of the stored text secret containing the connection string. :param tls: TLS client connection settings. @@ -346,12 +364,17 @@ def create( config_obj=config_obj, connection_string=connection_string, connection_timeout=connection_timeout, + credentials_secret=credentials_secret, creds_secrets=creds_secrets, + database=database, database_type=database_type, description=description, + host=host, id=id, + log_on_mechanism=log_on_mechanism, password=password, request_timeout=request_timeout, + sslmode=sslmode, tags=tags, text_secret=text_secret, tls=utils.get_pydantic_model(tls, Optional[models.TLSClientParams]), @@ -400,7 +423,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -442,9 +469,14 @@ async def create_async( config_obj: Optional[str] = None, connection_string: Optional[str] = None, connection_timeout: Optional[int] = None, + credentials_secret: Optional[str] = None, creds_secrets: Optional[str] = None, + database: Optional[str] = None, + host: Optional[str] = None, + log_on_mechanism: Optional[str] = None, password: Optional[str] = None, request_timeout: Optional[int] = None, + sslmode: Optional[str] = None, tags: Optional[str] = None, text_secret: Optional[str] = None, tls: Optional[ @@ -467,9 +499,14 @@ async def create_async( :param config_obj: JSON configuration object for advanced SQL Server connection settings. :param connection_string: Database connection string with embedded credentials or server information. :param connection_timeout: Maximum time (in milliseconds) to wait when establishing the database connection. + :param credentials_secret: Name of the stored credentials secret containing username and password for SQL Server configObj authentication. :param creds_secrets: Name of the stored credentials secret containing username and password. Used with Oracle connections. + :param database: Database to connect to instead of the server default. + :param host: Hostname of the server to connect to. + :param log_on_mechanism: Log On Mechanism for databases that support multiple, like Teradata. :param password: Database password for authentication. Used with Oracle connections. :param request_timeout: Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only. + :param sslmode: HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior. :param tags: Comma-separated list of tags for categorizing and filtering Database Connections. :param text_secret: Name of the stored text secret containing the connection string. :param tls: TLS client connection settings. @@ -494,12 +531,17 @@ async def create_async( config_obj=config_obj, connection_string=connection_string, connection_timeout=connection_timeout, + credentials_secret=credentials_secret, creds_secrets=creds_secrets, + database=database, database_type=database_type, description=description, + host=host, id=id, + log_on_mechanism=log_on_mechanism, password=password, request_timeout=request_timeout, + sslmode=sslmode, tags=tags, text_secret=text_secret, tls=utils.get_pydantic_model(tls, Optional[models.TLSClientParams]), @@ -548,7 +590,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -652,7 +698,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -756,7 +806,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -799,9 +853,14 @@ def update( config_obj: Optional[str] = None, connection_string: Optional[str] = None, connection_timeout: Optional[int] = None, + credentials_secret: Optional[str] = None, creds_secrets: Optional[str] = None, + database: Optional[str] = None, + host: Optional[str] = None, + log_on_mechanism: Optional[str] = None, password: Optional[str] = None, request_timeout: Optional[int] = None, + sslmode: Optional[str] = None, tags: Optional[str] = None, text_secret: Optional[str] = None, tls: Optional[ @@ -825,9 +884,14 @@ def update( :param config_obj: JSON configuration object for advanced SQL Server connection settings. :param connection_string: Database connection string with embedded credentials or server information. :param connection_timeout: Maximum time (in milliseconds) to wait when establishing the database connection. + :param credentials_secret: Name of the stored credentials secret containing username and password for SQL Server configObj authentication. :param creds_secrets: Name of the stored credentials secret containing username and password. Used with Oracle connections. + :param database: Database to connect to instead of the server default. + :param host: Hostname of the server to connect to. + :param log_on_mechanism: Log On Mechanism for databases that support multiple, like Teradata. :param password: Database password for authentication. Used with Oracle connections. :param request_timeout: Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only. + :param sslmode: HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior. :param tags: Comma-separated list of tags for categorizing and filtering Database Connections. :param text_secret: Name of the stored text secret containing the connection string. :param tls: TLS client connection settings. @@ -854,12 +918,17 @@ def update( config_obj=config_obj, connection_string=connection_string, connection_timeout=connection_timeout, + credentials_secret=credentials_secret, creds_secrets=creds_secrets, + database=database, database_type=database_type, description=description, + host=host, id=id, + log_on_mechanism=log_on_mechanism, password=password, request_timeout=request_timeout, + sslmode=sslmode, tags=tags, text_secret=text_secret, tls=utils.get_pydantic_model(tls, Optional[models.TLSClientParams]), @@ -913,7 +982,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -956,9 +1029,14 @@ async def update_async( config_obj: Optional[str] = None, connection_string: Optional[str] = None, connection_timeout: Optional[int] = None, + credentials_secret: Optional[str] = None, creds_secrets: Optional[str] = None, + database: Optional[str] = None, + host: Optional[str] = None, + log_on_mechanism: Optional[str] = None, password: Optional[str] = None, request_timeout: Optional[int] = None, + sslmode: Optional[str] = None, tags: Optional[str] = None, text_secret: Optional[str] = None, tls: Optional[ @@ -982,9 +1060,14 @@ async def update_async( :param config_obj: JSON configuration object for advanced SQL Server connection settings. :param connection_string: Database connection string with embedded credentials or server information. :param connection_timeout: Maximum time (in milliseconds) to wait when establishing the database connection. + :param credentials_secret: Name of the stored credentials secret containing username and password for SQL Server configObj authentication. :param creds_secrets: Name of the stored credentials secret containing username and password. Used with Oracle connections. + :param database: Database to connect to instead of the server default. + :param host: Hostname of the server to connect to. + :param log_on_mechanism: Log On Mechanism for databases that support multiple, like Teradata. :param password: Database password for authentication. Used with Oracle connections. :param request_timeout: Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only. + :param sslmode: HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior. :param tags: Comma-separated list of tags for categorizing and filtering Database Connections. :param text_secret: Name of the stored text secret containing the connection string. :param tls: TLS client connection settings. @@ -1011,12 +1094,17 @@ async def update_async( config_obj=config_obj, connection_string=connection_string, connection_timeout=connection_timeout, + credentials_secret=credentials_secret, creds_secrets=creds_secrets, + database=database, database_type=database_type, description=description, + host=host, id=id, + log_on_mechanism=log_on_mechanism, password=password, request_timeout=request_timeout, + sslmode=sslmode, tags=tags, text_secret=text_secret, tls=utils.get_pydantic_model(tls, Optional[models.TLSClientParams]), @@ -1070,7 +1158,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1174,7 +1266,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1278,7 +1374,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["databaseConnections"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/datasets.py b/src/cribl_control_plane/datasets.py index 67b71adf6..1d8e253f7 100644 --- a/src/cribl_control_plane/datasets.py +++ b/src/cribl_control_plane/datasets.py @@ -25,6 +25,12 @@ def list( include_metrics: Optional[bool] = None, offset: Optional[int] = None, limit: Optional[int] = None, + order_by: Optional[str] = None, + order_dir: Optional[str] = None, + name: Optional[str] = None, + name_contains: Optional[str] = None, + provider_path_contains: Optional[str] = None, + description_contains: Optional[str] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, @@ -43,8 +49,14 @@ def list( :param exclude_internal: Exclude internal datasets (those with IDs starting with cribl_) from the response. :param exclude_byos: Exclude BYOS (Bring Your Own Storage) datasets from the response. :param include_metrics: Set to true to include storage metrics for each Lake Dataset. Otherwise, false (default). Requires a Cribl Lake metrics license. - :param offset: Pagination offset - :param limit: Maximum number of items to return + :param offset: Starting point for catalog-backed pagination. Requires limit. + :param limit: Page size for catalog-backed pagination. Requires offset. + :param order_by: Catalog sort field when paginating: name, createdAt, updatedAt, providerPath, type, or retentionPeriodInDays. Defaults to name. + :param order_dir: Sort direction when paginating: asc or desc. Defaults to asc. + :param name: Exact dataset name match (catalog path, with pagination). + :param name_contains: Case-insensitive substring match on dataset name (catalog path, with pagination). + :param provider_path_contains: Case-insensitive substring match on provider path (catalog path, with pagination). + :param description_contains: Case-insensitive substring match on description (catalog path, with pagination). :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -72,6 +84,12 @@ def list( include_metrics=include_metrics, offset=offset, limit=limit, + order_by=order_by, + order_dir=order_dir, + name=name, + name_contains=name_contains, + provider_path_contains=provider_path_contains, + description_contains=description_contains, ) req = self._build_request( @@ -113,7 +131,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -147,6 +169,12 @@ def next_func() -> Optional[models.GetCriblLakeDatasetByLakeIDResponse]: include_metrics=include_metrics, offset=next_offset, limit=limit, + order_by=order_by, + order_dir=order_dir, + name=name, + name_contains=name_contains, + provider_path_contains=provider_path_contains, + description_contains=description_contains, retries=retries, server_url=server_url, timeout_ms=timeout_ms, @@ -167,7 +195,7 @@ def next_func() -> Optional[models.GetCriblLakeDatasetByLakeIDResponse]: if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["400", "4XX"], "*"): http_res_text = utils.stream_to_text(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -190,6 +218,12 @@ async def list_async( include_metrics: Optional[bool] = None, offset: Optional[int] = None, limit: Optional[int] = None, + order_by: Optional[str] = None, + order_dir: Optional[str] = None, + name: Optional[str] = None, + name_contains: Optional[str] = None, + provider_path_contains: Optional[str] = None, + description_contains: Optional[str] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, @@ -208,8 +242,14 @@ async def list_async( :param exclude_internal: Exclude internal datasets (those with IDs starting with cribl_) from the response. :param exclude_byos: Exclude BYOS (Bring Your Own Storage) datasets from the response. :param include_metrics: Set to true to include storage metrics for each Lake Dataset. Otherwise, false (default). Requires a Cribl Lake metrics license. - :param offset: Pagination offset - :param limit: Maximum number of items to return + :param offset: Starting point for catalog-backed pagination. Requires limit. + :param limit: Page size for catalog-backed pagination. Requires offset. + :param order_by: Catalog sort field when paginating: name, createdAt, updatedAt, providerPath, type, or retentionPeriodInDays. Defaults to name. + :param order_dir: Sort direction when paginating: asc or desc. Defaults to asc. + :param name: Exact dataset name match (catalog path, with pagination). + :param name_contains: Case-insensitive substring match on dataset name (catalog path, with pagination). + :param provider_path_contains: Case-insensitive substring match on provider path (catalog path, with pagination). + :param description_contains: Case-insensitive substring match on description (catalog path, with pagination). :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -237,6 +277,12 @@ async def list_async( include_metrics=include_metrics, offset=offset, limit=limit, + order_by=order_by, + order_dir=order_dir, + name=name, + name_contains=name_contains, + provider_path_contains=provider_path_contains, + description_contains=description_contains, ) req = self._build_request_async( @@ -278,7 +324,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -317,6 +367,12 @@ async def empty_result(): include_metrics=include_metrics, offset=next_offset, limit=limit, + order_by=order_by, + order_dir=order_dir, + name=name, + name_contains=name_contains, + provider_path_contains=provider_path_contains, + description_contains=description_contains, retries=retries, server_url=server_url, timeout_ms=timeout_ms, @@ -337,7 +393,7 @@ async def empty_result(): if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["400", "4XX"], "*"): http_res_text = await utils.stream_to_text_async(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -352,6 +408,7 @@ def create( lake_id: str, id: str, accelerated_fields: Optional[Iterable[str]] = None, + allow_record_erasure: Optional[bool] = None, bucket_name: Optional[str] = None, cache_connection: Optional[ Union[models.CacheConnection, models.CacheConnectionTypedDict] @@ -363,6 +420,7 @@ def create( metrics: Optional[ Union[models.LakeDatasetMetrics, models.LakeDatasetMetricsTypedDict] ] = None, + provider_path: Optional[str] = None, retention_period_in_days: Optional[int] = None, search_config: Optional[ Union[ @@ -377,13 +435,14 @@ def create( timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, ) -> models.CountedCriblLakeDataset: - r"""Create a Lake Dataset (Cribl.Cloud only) + r"""Create Lake Datasets (Cribl.Cloud only) - Create a new Lake Dataset in the specified Lake (Cribl.Cloud only). + Creates one or more Lake Datasets in the specified Lake in a single transaction (Cribl.Cloud only). Send a single Lake Dataset object to create just one, or an array to bulk-create multiple. When an array is sent, the response is { items, errors } — items contains the successfully created Lake Datasets, and errors contains an entry ({ id, reason }) for each Lake Dataset that failed validation, so a per-item failure does not fail the rest of the batch. - :param lake_id: The id of the Lake to create the Lake Dataset in. + :param lake_id: The id of the Lake to create the Lake Datasets in. :param id: Unique identifier for the Dataset. :param accelerated_fields: Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. + :param allow_record_erasure: If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. :param bucket_name: Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. :param cache_connection: :param deletion_started_at: Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. @@ -391,6 +450,7 @@ def create( :param format_: Storage format used for data persisted in the Dataset. :param http_da_used: If true, the Dataset is used by Direct Access HTTP. Otherwise, false. :param metrics: + :param provider_path: Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). :param retention_period_in_days: Dataset retention period, in days. :param search_config: :param storage_class: Storage class used for objects written to the Dataset. @@ -417,6 +477,7 @@ def create( accelerated_fields=utils.unmarshal( accelerated_fields, Optional[List[str]] ), + allow_record_erasure=allow_record_erasure, bucket_name=bucket_name, cache_connection=utils.get_pydantic_model( cache_connection, Optional[models.CacheConnection] @@ -429,6 +490,7 @@ def create( metrics=utils.get_pydantic_model( metrics, Optional[models.LakeDatasetMetrics] ), + provider_path=provider_path, retention_period_in_days=retention_period_in_days, search_config=utils.get_pydantic_model( search_config, Optional[models.LakeDatasetSearchConfig] @@ -485,7 +547,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -493,7 +559,7 @@ def create( ) response_data: Any = None - if utils.match_response(http_res, "200", "application/json"): + if utils.match_response(http_res, "201", "application/json"): return unmarshal_json_response(models.CountedCriblLakeDataset, http_res) if utils.match_response(http_res, "401", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) @@ -516,6 +582,7 @@ async def create_async( lake_id: str, id: str, accelerated_fields: Optional[Iterable[str]] = None, + allow_record_erasure: Optional[bool] = None, bucket_name: Optional[str] = None, cache_connection: Optional[ Union[models.CacheConnection, models.CacheConnectionTypedDict] @@ -527,6 +594,7 @@ async def create_async( metrics: Optional[ Union[models.LakeDatasetMetrics, models.LakeDatasetMetricsTypedDict] ] = None, + provider_path: Optional[str] = None, retention_period_in_days: Optional[int] = None, search_config: Optional[ Union[ @@ -541,13 +609,14 @@ async def create_async( timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, ) -> models.CountedCriblLakeDataset: - r"""Create a Lake Dataset (Cribl.Cloud only) + r"""Create Lake Datasets (Cribl.Cloud only) - Create a new Lake Dataset in the specified Lake (Cribl.Cloud only). + Creates one or more Lake Datasets in the specified Lake in a single transaction (Cribl.Cloud only). Send a single Lake Dataset object to create just one, or an array to bulk-create multiple. When an array is sent, the response is { items, errors } — items contains the successfully created Lake Datasets, and errors contains an entry ({ id, reason }) for each Lake Dataset that failed validation, so a per-item failure does not fail the rest of the batch. - :param lake_id: The id of the Lake to create the Lake Dataset in. + :param lake_id: The id of the Lake to create the Lake Datasets in. :param id: Unique identifier for the Dataset. :param accelerated_fields: Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. + :param allow_record_erasure: If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. :param bucket_name: Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. :param cache_connection: :param deletion_started_at: Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. @@ -555,6 +624,7 @@ async def create_async( :param format_: Storage format used for data persisted in the Dataset. :param http_da_used: If true, the Dataset is used by Direct Access HTTP. Otherwise, false. :param metrics: + :param provider_path: Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). :param retention_period_in_days: Dataset retention period, in days. :param search_config: :param storage_class: Storage class used for objects written to the Dataset. @@ -581,6 +651,7 @@ async def create_async( accelerated_fields=utils.unmarshal( accelerated_fields, Optional[List[str]] ), + allow_record_erasure=allow_record_erasure, bucket_name=bucket_name, cache_connection=utils.get_pydantic_model( cache_connection, Optional[models.CacheConnection] @@ -593,6 +664,7 @@ async def create_async( metrics=utils.get_pydantic_model( metrics, Optional[models.LakeDatasetMetrics] ), + provider_path=provider_path, retention_period_in_days=retention_period_in_days, search_config=utils.get_pydantic_model( search_config, Optional[models.LakeDatasetSearchConfig] @@ -649,7 +721,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -657,7 +733,7 @@ async def create_async( ) response_data: Any = None - if utils.match_response(http_res, "200", "application/json"): + if utils.match_response(http_res, "201", "application/json"): return unmarshal_json_response(models.CountedCriblLakeDataset, http_res) if utils.match_response(http_res, "401", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) @@ -752,7 +828,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -855,7 +935,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -886,6 +970,7 @@ def update( lake_id: str, id_param: str, accelerated_fields: Optional[Iterable[str]] = None, + allow_record_erasure: Optional[bool] = None, bucket_name: Optional[str] = None, cache_connection: Optional[ Union[models.CacheConnection, models.CacheConnectionTypedDict] @@ -898,6 +983,7 @@ def update( metrics: Optional[ Union[models.LakeDatasetMetrics, models.LakeDatasetMetricsTypedDict] ] = None, + provider_path: Optional[str] = None, retention_period_in_days: Optional[int] = None, search_config: Optional[ Union[ @@ -919,6 +1005,7 @@ def update( :param lake_id: The id of the Lake that contains the Lake Dataset to update. :param id_param: The id of the Lake Dataset to update. :param accelerated_fields: Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. + :param allow_record_erasure: If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. :param bucket_name: Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. :param cache_connection: :param deletion_started_at: Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. @@ -927,6 +1014,7 @@ def update( :param http_da_used: If true, the Dataset is used by Direct Access HTTP. Otherwise, false. :param id: Unique identifier for the Dataset. Optional; the path parameter id is authoritative. :param metrics: + :param provider_path: Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). :param retention_period_in_days: Dataset retention period, in days. :param search_config: :param storage_class: Storage class used for objects written to the Dataset. @@ -954,6 +1042,7 @@ def update( accelerated_fields=utils.unmarshal( accelerated_fields, Optional[List[str]] ), + allow_record_erasure=allow_record_erasure, bucket_name=bucket_name, cache_connection=utils.get_pydantic_model( cache_connection, Optional[models.CacheConnection] @@ -966,6 +1055,7 @@ def update( metrics=utils.get_pydantic_model( metrics, Optional[models.LakeDatasetMetrics] ), + provider_path=provider_path, retention_period_in_days=retention_period_in_days, search_config=utils.get_pydantic_model( search_config, Optional[models.LakeDatasetSearchConfig] @@ -1022,7 +1112,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1038,7 +1132,7 @@ def update( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["400", "409", "4XX"], "*"): http_res_text = utils.stream_to_text(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -1053,6 +1147,7 @@ async def update_async( lake_id: str, id_param: str, accelerated_fields: Optional[Iterable[str]] = None, + allow_record_erasure: Optional[bool] = None, bucket_name: Optional[str] = None, cache_connection: Optional[ Union[models.CacheConnection, models.CacheConnectionTypedDict] @@ -1065,6 +1160,7 @@ async def update_async( metrics: Optional[ Union[models.LakeDatasetMetrics, models.LakeDatasetMetricsTypedDict] ] = None, + provider_path: Optional[str] = None, retention_period_in_days: Optional[int] = None, search_config: Optional[ Union[ @@ -1086,6 +1182,7 @@ async def update_async( :param lake_id: The id of the Lake that contains the Lake Dataset to update. :param id_param: The id of the Lake Dataset to update. :param accelerated_fields: Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance. + :param allow_record_erasure: If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled. :param bucket_name: Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId. :param cache_connection: :param deletion_started_at: Timestamp (in Unix time) when Dataset deletion was initiated, in milliseconds. @@ -1094,6 +1191,7 @@ async def update_async( :param http_da_used: If true, the Dataset is used by Direct Access HTTP. Otherwise, false. :param id: Unique identifier for the Dataset. Optional; the path parameter id is authoritative. :param metrics: + :param provider_path: Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets). :param retention_period_in_days: Dataset retention period, in days. :param search_config: :param storage_class: Storage class used for objects written to the Dataset. @@ -1121,6 +1219,7 @@ async def update_async( accelerated_fields=utils.unmarshal( accelerated_fields, Optional[List[str]] ), + allow_record_erasure=allow_record_erasure, bucket_name=bucket_name, cache_connection=utils.get_pydantic_model( cache_connection, Optional[models.CacheConnection] @@ -1133,6 +1232,7 @@ async def update_async( metrics=utils.get_pydantic_model( metrics, Optional[models.LakeDatasetMetrics] ), + provider_path=provider_path, retention_period_in_days=retention_period_in_days, search_config=utils.get_pydantic_model( search_config, Optional[models.LakeDatasetSearchConfig] @@ -1189,7 +1289,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1205,7 +1309,7 @@ async def update_async( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["400", "409", "4XX"], "*"): http_res_text = await utils.stream_to_text_async(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -1289,7 +1393,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1389,7 +1497,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["lake"], - extensions={"x-cribl-availability": "cloud", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "cloud", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/destinations.py b/src/cribl_control_plane/destinations.py index 2e672a067..d4aca1248 100644 --- a/src/cribl_control_plane/destinations.py +++ b/src/cribl_control_plane/destinations.py @@ -45,7 +45,7 @@ def list( server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> Optional[models.ListOutputResponse]: + ) -> Optional[models.GetOutputResponse]: r"""List all Destinations Get a list of all Destinations. @@ -68,7 +68,7 @@ def list( else: base_url = self._get_url(base_url, url_variables) - request = models.ListOutputRequest( + request = models.GetOutputRequest( type=type_, offset=offset, limit=limit, @@ -107,20 +107,24 @@ def list( hook_ctx=HookContext( config=self.sdk_configuration, base_url=base_url or "", - operation_id="listOutput", + operation_id="getOutput", oauth2_scopes=[], security_source=get_security_from_env( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) - def next_func() -> Optional[models.ListOutputResponse]: + def next_func() -> Optional[models.GetOutputResponse]: body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) offset = request.offset if isinstance(request.offset, int) else 0 @@ -147,7 +151,7 @@ def next_func() -> Optional[models.ListOutputResponse]: response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return models.ListOutputResponse( + return models.GetOutputResponse( result=unmarshal_json_response( models.PaginatedOutputResponse, http_res ), @@ -178,7 +182,7 @@ async def list_async( server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> Optional[models.ListOutputResponse]: + ) -> Optional[models.GetOutputResponse]: r"""List all Destinations Get a list of all Destinations. @@ -201,7 +205,7 @@ async def list_async( else: base_url = self._get_url(base_url, url_variables) - request = models.ListOutputRequest( + request = models.GetOutputRequest( type=type_, offset=offset, limit=limit, @@ -240,20 +244,24 @@ async def list_async( hook_ctx=HookContext( config=self.sdk_configuration, base_url=base_url or "", - operation_id="listOutput", + operation_id="getOutput", oauth2_scopes=[], security_source=get_security_from_env( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) - def next_func() -> Awaitable[Optional[models.ListOutputResponse]]: + def next_func() -> Awaitable[Optional[models.GetOutputResponse]]: body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) async def empty_result(): @@ -283,7 +291,7 @@ async def empty_result(): response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return models.ListOutputResponse( + return models.GetOutputResponse( result=unmarshal_json_response( models.PaginatedOutputResponse, http_res ), @@ -379,7 +387,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -479,7 +491,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -576,7 +592,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -673,7 +693,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -776,7 +800,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -879,7 +907,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -976,7 +1008,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1073,7 +1109,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/destinations_pq.py b/src/cribl_control_plane/destinations_pq.py index 32f17c31c..2f11244a3 100644 --- a/src/cribl_control_plane/destinations_pq.py +++ b/src/cribl_control_plane/destinations_pq.py @@ -82,7 +82,11 @@ def clear( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -179,7 +183,11 @@ async def clear_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -276,7 +284,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -373,7 +385,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/destinations_statuses.py b/src/cribl_control_plane/destinations_statuses.py index 100fdf5ca..c671a4577 100644 --- a/src/cribl_control_plane/destinations_statuses.py +++ b/src/cribl_control_plane/destinations_statuses.py @@ -92,7 +92,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -227,7 +231,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -362,7 +370,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -465,7 +477,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/functions.py b/src/cribl_control_plane/functions.py index 6813d7b1a..04e66b30a 100644 --- a/src/cribl_control_plane/functions.py +++ b/src/cribl_control_plane/functions.py @@ -91,7 +91,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["functions"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -224,7 +228,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["functions"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -354,7 +362,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["functions"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -451,7 +463,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["functions"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/groups_sdk.py b/src/cribl_control_plane/groups_sdk.py index 481641f7a..3404a005d 100644 --- a/src/cribl_control_plane/groups_sdk.py +++ b/src/cribl_control_plane/groups_sdk.py @@ -111,7 +111,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -246,7 +250,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -310,6 +318,8 @@ def create( *, product: models.ProductsCore, id: str, + src_group: Optional[str] = None, + src_overridden: Optional[bool] = None, cloud: Optional[ Union[models.ConfigGroupCloud, models.ConfigGroupCloudTypedDict] ] = None, @@ -342,6 +352,8 @@ def create( :param product: Name of the Cribl product to add the Worker Group, Outpost Group, or Edge Fleet to. :param id: Unique identifier. + :param src_group: Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. + :param src_overridden: If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. :param cloud: :param collectors_ha_enabled: Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. :param description: Brief description of the Worker Group, Outpost Group, or Edge Fleet. @@ -377,6 +389,8 @@ def create( request = models.CreateProductsGroupsByProductRequest( product=product, group_create_request=models.GroupCreateRequest( + src_group=src_group, + src_overridden=src_overridden, cloud=utils.get_pydantic_model( cloud, Optional[models.ConfigGroupCloud] ), @@ -446,7 +460,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -484,6 +502,8 @@ async def create_async( *, product: models.ProductsCore, id: str, + src_group: Optional[str] = None, + src_overridden: Optional[bool] = None, cloud: Optional[ Union[models.ConfigGroupCloud, models.ConfigGroupCloudTypedDict] ] = None, @@ -516,6 +536,8 @@ async def create_async( :param product: Name of the Cribl product to add the Worker Group, Outpost Group, or Edge Fleet to. :param id: Unique identifier. + :param src_group: Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. + :param src_overridden: If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. :param cloud: :param collectors_ha_enabled: Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. :param description: Brief description of the Worker Group, Outpost Group, or Edge Fleet. @@ -551,6 +573,8 @@ async def create_async( request = models.CreateProductsGroupsByProductRequest( product=product, group_create_request=models.GroupCreateRequest( + src_group=src_group, + src_overridden=src_overridden, cloud=utils.get_pydantic_model( cloud, Optional[models.ConfigGroupCloud] ), @@ -620,7 +644,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -731,7 +759,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -834,7 +866,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -865,6 +901,8 @@ def update( product: models.ProductsCore, id_param: str, id: str, + src_group: Optional[str] = None, + src_overridden: Optional[bool] = None, cloud: Optional[ Union[models.ConfigGroupCloud, models.ConfigGroupCloudTypedDict] ] = None, @@ -908,6 +946,8 @@ def update( :param product: Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. :param id_param: The id of the Worker Group, Outpost Group, or Edge Fleet to update. :param id: Unique identifier. + :param src_group: Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. + :param src_overridden: If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. :param cloud: :param collectors_ha_enabled: Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. :param config_version: Commit hash of the deployed configuration version for the Worker Group, Outpost Group, or Edge Fleet. Automatically populated and returned in responses.

**Warning**: Do not change the value of configVersion in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response. @@ -949,6 +989,8 @@ def update( product=product, id_param=id_param, config_group=models.ConfigGroup( + src_group=src_group, + src_overridden=src_overridden, cloud=utils.get_pydantic_model( cloud, Optional[models.ConfigGroupCloud] ), @@ -1021,7 +1063,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1052,6 +1098,8 @@ async def update_async( product: models.ProductsCore, id_param: str, id: str, + src_group: Optional[str] = None, + src_overridden: Optional[bool] = None, cloud: Optional[ Union[models.ConfigGroupCloud, models.ConfigGroupCloudTypedDict] ] = None, @@ -1095,6 +1143,8 @@ async def update_async( :param product: Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. :param id_param: The id of the Worker Group, Outpost Group, or Edge Fleet to update. :param id: Unique identifier. + :param src_group: Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted. + :param src_overridden: If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted. :param cloud: :param collectors_ha_enabled: Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. :param config_version: Commit hash of the deployed configuration version for the Worker Group, Outpost Group, or Edge Fleet. Automatically populated and returned in responses.

**Warning**: Do not change the value of configVersion in the body of PATCH requests. The PATCH request body must include the value as it appears in the GET /products/{product}/groups/{id} response. @@ -1136,6 +1186,8 @@ async def update_async( product=product, id_param=id_param, config_group=models.ConfigGroup( + src_group=src_group, + src_overridden=src_overridden, cloud=utils.get_pydantic_model( cloud, Optional[models.ConfigGroupCloud] ), @@ -1208,7 +1260,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1308,7 +1364,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1408,7 +1468,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1526,7 +1590,11 @@ def deploy( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1644,7 +1712,11 @@ async def deploy_async( self.sdk_configuration.security, models.Security ), tags=["groups"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/health_sdk.py b/src/cribl_control_plane/health_sdk.py index 1e2ca7656..d12af8086 100644 --- a/src/cribl_control_plane/health_sdk.py +++ b/src/cribl_control_plane/health_sdk.py @@ -77,7 +77,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["health"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -169,7 +173,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["health"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/hectokens.py b/src/cribl_control_plane/hectokens.py index 62e82dc61..0a5b7f485 100644 --- a/src/cribl_control_plane/hectokens.py +++ b/src/cribl_control_plane/hectokens.py @@ -115,7 +115,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -245,7 +249,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -375,7 +383,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -505,7 +517,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/models/__init__.py b/src/cribl_control_plane/models/__init__.py index 1560a1cea..a2e0ad99f 100644 --- a/src/cribl_control_plane/models/__init__.py +++ b/src/cribl_control_plane/models/__init__.py @@ -48,15 +48,18 @@ from .authenticationmethodoptionsauthmanualmanualapikey import ( AuthenticationMethodOptionsAuthManualManualAPIKey, ) + from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, + ) from .authenticationmethodoptionsauthtokensitems import ( AuthenticationMethodOptionsAuthTokensItems, ) - from .authenticationmethodoptionsauthtokensitemssecret import ( - AuthenticationMethodOptionsAuthTokensItemsSecret, - ) from .authenticationmethodoptionsautosecret import ( AuthenticationMethodOptionsAutoSecret, ) + from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, + ) from .authenticationmethodoptionsmanualsecret import ( AuthenticationMethodOptionsManualSecret, ) @@ -105,10 +108,6 @@ AuthTokenConfOutputCriblHTTP, AuthTokenConfOutputCriblHTTPTypedDict, ) - from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, - ) from .authtype import AuthType, AuthTypeTypedDict from .authtypetemplatemanualapikeyauthtype import ( AuthTypeTemplatemanualAPIKeyAuthType, @@ -242,6 +241,7 @@ ConfigGroupLookupsLookup, ConfigGroupLookupsLookupTypedDict, ConfigGroupLookupsTypedDict, + DeployMode, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -366,9 +366,58 @@ ) from .createinput_input import ( CreateInputAPIVersion, + CreateInputCompression, + CreateInputEndpointHeader, + CreateInputEndpointHeaderTypedDict, + CreateInputEndpointParam, + CreateInputEndpointParamTypedDict, + CreateInputInput, + CreateInputInputAzureBlob, + CreateInputInputAzureBlobTypedDict, + CreateInputInputAzureVnetFlowLog, + CreateInputInputAzureVnetFlowLogType, + CreateInputInputAzureVnetFlowLogTypedDict, + CreateInputInputCollection, + CreateInputInputCollectionType, + CreateInputInputCollectionTypedDict, + CreateInputInputElastic, + CreateInputInputElasticAuthenticationMethod, + CreateInputInputElasticAuthenticationType, + CreateInputInputElasticProxyMode, + CreateInputInputElasticProxyModeTypedDict, + CreateInputInputElasticTypedDict, + CreateInputInputHTTP, + CreateInputInputHTTPAuthTokensExt, + CreateInputInputHTTPAuthTokensExtTypedDict, + CreateInputInputHTTPInputHTTPAuthTokensExtItemsType, + CreateInputInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint, + CreateInputInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + CreateInputInputHTTPType, + CreateInputInputHTTPTypedDict, + CreateInputInputKafka, + CreateInputInputKafkaTypedDict, + CreateInputInputMsk, + CreateInputInputMskTypedDict, + CreateInputInputSplunk, + CreateInputInputSplunkAuthToken, + CreateInputInputSplunkAuthTokenTypedDict, + CreateInputInputSplunkHec, + CreateInputInputSplunkHecAuthToken, + CreateInputInputSplunkHecAuthTokenTypedDict, + CreateInputInputSplunkHecType, + CreateInputInputSplunkHecTypedDict, + CreateInputInputSplunkSearch, + CreateInputInputSplunkSearchAuthenticationType, + CreateInputInputSplunkSearchLogLevel, + CreateInputInputSplunkSearchType, + CreateInputInputSplunkSearchTypedDict, + CreateInputInputSplunkTypedDict, + CreateInputInputTypedDict, + CreateInputMaxS2SVersion, + ) + from .createinput_inputelastic_type import ( CreateInputAuth, - CreateInputAuthTokensExt, - CreateInputAuthTokensExtTypedDict, CreateInputAuthTypedDict, CreateInputAuthenticationMechanism, CreateInputAzureBlobStorage, @@ -379,7 +428,6 @@ CreateInputCheckpointingTypedDict, CreateInputCollectors, CreateInputCollectorsTypedDict, - CreateInputCompression, CreateInputContainer, CreateInputContainerMode, CreateInputContainerTypedDict, @@ -387,24 +435,12 @@ CreateInputDNSTypedDict, CreateInputDisksAndFileSystems, CreateInputDisksAndFileSystemsTypedDict, - CreateInputElasticsearchMetadata, - CreateInputElasticsearchMetadataTypedDict, - CreateInputEndpointHeader, - CreateInputEndpointHeaderTypedDict, - CreateInputEndpointParam, - CreateInputEndpointParamTypedDict, CreateInputFirewall, CreateInputFirewallTypedDict, CreateInputHostInfo, CreateInputHostInfoTypedDict, CreateInputHostsFile, CreateInputHostsFileTypedDict, - CreateInputInput, - CreateInputInputAzureBlob, - CreateInputInputAzureBlobTypedDict, - CreateInputInputCollection, - CreateInputInputCollectionType, - CreateInputInputCollectionTypedDict, CreateInputInputConfluentCloud, CreateInputInputConfluentCloudTypedDict, CreateInputInputCribl, @@ -412,27 +448,40 @@ CreateInputInputCriblHTTPType, CreateInputInputCriblHTTPTypedDict, CreateInputInputCriblLakeHTTP, + CreateInputInputCriblLakeHTTPAuthTokensExt, + CreateInputInputCriblLakeHTTPAuthTokensExtTypedDict, + CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, CreateInputInputCriblLakeHTTPType, CreateInputInputCriblLakeHTTPTypedDict, CreateInputInputCriblTCP, CreateInputInputCriblTCPTypedDict, CreateInputInputCriblType, CreateInputInputCriblTypedDict, + CreateInputInputCriblmetrics, + CreateInputInputCriblmetricsType, + CreateInputInputCriblmetricsTypedDict, + CreateInputInputCrowdstrike, + CreateInputInputCrowdstrikeType, + CreateInputInputCrowdstrikeTypedDict, + CreateInputInputDatadogAgent, + CreateInputInputDatadogAgentProxyMode, + CreateInputInputDatadogAgentProxyModeTypedDict, + CreateInputInputDatadogAgentType, + CreateInputInputDatadogAgentTypedDict, + CreateInputInputDatagen, + CreateInputInputDatagenType, + CreateInputInputDatagenTypedDict, CreateInputInputEdgePrometheus, CreateInputInputEdgePrometheusAuthenticationMethod, CreateInputInputEdgePrometheusDiscoveryType, CreateInputInputEdgePrometheusType, CreateInputInputEdgePrometheusTypedDict, - CreateInputInputElastic, - CreateInputInputElasticAuthenticationMethod, - CreateInputInputElasticAuthenticationType, - CreateInputInputElasticProxyMode, - CreateInputInputElasticProxyModeTypedDict, CreateInputInputElasticType, - CreateInputInputElasticTypedDict, CreateInputInputEventhub, CreateInputInputEventhubAmqp, - CreateInputInputEventhubAmqpAuthenticationMethod, CreateInputInputEventhubAmqpType, CreateInputInputEventhubAmqpTypedDict, CreateInputInputEventhubType, @@ -453,20 +502,49 @@ CreateInputInputGrafanaType2, CreateInputInputGrafanaUnion, CreateInputInputGrafanaUnionTypedDict, - CreateInputInputHTTP, - CreateInputInputHTTPType, - CreateInputInputHTTPTypedDict, - CreateInputInputKafka, - CreateInputInputKafkaTypedDict, + CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata, + CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict, + CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata, + CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict, + CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata, + CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict, + CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata, + CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict, + CreateInputInputHTTPRaw, + CreateInputInputHTTPRawAuthTokensExt, + CreateInputInputHTTPRawAuthTokensExtTypedDict, + CreateInputInputHTTPRawAuthTokensExtUnion, + CreateInputInputHTTPRawAuthTokensExtUnionTypedDict, + CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint, + CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, + CreateInputInputHTTPRawType, + CreateInputInputHTTPRawTypedDict, + CreateInputInputKinesis, + CreateInputInputKinesisTypedDict, + CreateInputInputKubeEvents, + CreateInputInputKubeEventsType, + CreateInputInputKubeEventsTypedDict, + CreateInputInputKubeLogs, + CreateInputInputKubeLogsRule, + CreateInputInputKubeLogsRuleTypedDict, + CreateInputInputKubeLogsType, + CreateInputInputKubeLogsTypedDict, + CreateInputInputKubeMetrics, + CreateInputInputKubeMetricsPersistence, + CreateInputInputKubeMetricsPersistenceTypedDict, + CreateInputInputKubeMetricsType, + CreateInputInputKubeMetricsTypedDict, CreateInputInputLoki, CreateInputInputLokiType, CreateInputInputLokiTypedDict, + CreateInputInputMetrics, + CreateInputInputMetricsType, + CreateInputInputMetricsTypedDict, CreateInputInputMicrosoftGraph, CreateInputInputMicrosoftGraphAuthenticationMethod, + CreateInputInputMicrosoftGraphSubscriptionPlan, CreateInputInputMicrosoftGraphType, CreateInputInputMicrosoftGraphTypedDict, - CreateInputInputMsk, - CreateInputInputMskTypedDict, CreateInputInputOffice365Mgmt, CreateInputInputOffice365MgmtContentConfig, CreateInputInputOffice365MgmtContentConfigTypedDict, @@ -487,20 +565,13 @@ CreateInputInputPrometheusRwType, CreateInputInputPrometheusRwTypedDict, CreateInputInputPrometheusTypedDict, - CreateInputInputSplunk, - CreateInputInputSplunkAuthToken, - CreateInputInputSplunkAuthTokenTypedDict, - CreateInputInputSplunkHec, - CreateInputInputSplunkHecAuthToken, - CreateInputInputSplunkHecAuthTokenTypedDict, - CreateInputInputSplunkHecType, - CreateInputInputSplunkHecTypedDict, - CreateInputInputSplunkSearch, - CreateInputInputSplunkSearchAuthenticationType, - CreateInputInputSplunkSearchLogLevel, - CreateInputInputSplunkSearchType, - CreateInputInputSplunkSearchTypedDict, - CreateInputInputSplunkTypedDict, + CreateInputInputS3, + CreateInputInputS3Inventory, + CreateInputInputS3InventoryType, + CreateInputInputS3InventoryTypedDict, + CreateInputInputS3TypedDict, + CreateInputInputSnmp, + CreateInputInputSnmpTypedDict, CreateInputInputSystemMetrics, CreateInputInputSystemMetricsCPU, CreateInputInputSystemMetricsCPUMode, @@ -534,7 +605,30 @@ CreateInputInputSystemStateTypedDict, CreateInputInputTcpjson, CreateInputInputTcpjsonTypedDict, - CreateInputInputTypedDict, + CreateInputInputWindowsMetrics, + CreateInputInputWindowsMetricsCPU, + CreateInputInputWindowsMetricsCPUMode, + CreateInputInputWindowsMetricsCPUTypedDict, + CreateInputInputWindowsMetricsCustom, + CreateInputInputWindowsMetricsCustomTypedDict, + CreateInputInputWindowsMetricsDisk, + CreateInputInputWindowsMetricsDiskMode, + CreateInputInputWindowsMetricsDiskTypedDict, + CreateInputInputWindowsMetricsHost, + CreateInputInputWindowsMetricsHostTypedDict, + CreateInputInputWindowsMetricsMemory, + CreateInputInputWindowsMetricsMemoryMode, + CreateInputInputWindowsMetricsMemoryTypedDict, + CreateInputInputWindowsMetricsNetwork, + CreateInputInputWindowsMetricsNetworkMode, + CreateInputInputWindowsMetricsNetworkTypedDict, + CreateInputInputWindowsMetricsPersistence, + CreateInputInputWindowsMetricsPersistenceTypedDict, + CreateInputInputWindowsMetricsSystem, + CreateInputInputWindowsMetricsSystemMode, + CreateInputInputWindowsMetricsSystemTypedDict, + CreateInputInputWindowsMetricsType, + CreateInputInputWindowsMetricsTypedDict, CreateInputInterfaces, CreateInputInterfacesTypedDict, CreateInputListeningPorts, @@ -545,7 +639,6 @@ CreateInputLokiAuth1TypedDict, CreateInputLokiAuth2, CreateInputLokiAuth2TypedDict, - CreateInputMaxS2SVersion, CreateInputMetricsProtocol, CreateInputPodFilter, CreateInputPodFilterTypedDict, @@ -553,20 +646,26 @@ CreateInputPrometheusAuth1TypedDict, CreateInputPrometheusAuth2, CreateInputPrometheusAuth2TypedDict, + CreateInputRecordDataFormat, CreateInputRoutes, CreateInputRoutesTypedDict, + CreateInputSNMPv3Authentication, + CreateInputSNMPv3AuthenticationTypedDict, + CreateInputSample, + CreateInputSampleTypedDict, + CreateInputSamplingRule, + CreateInputSamplingRuleTypedDict, CreateInputScheduleType, CreateInputServices, CreateInputServicesTypedDict, - CreateInputSplunkHecMetadata, - CreateInputSplunkHecMetadataTypedDict, - CreateInputSubscriptionPlan, + CreateInputShardIteratorStart, + CreateInputShardLoadBalancing, CreateInputTarget, CreateInputTargetTypedDict, CreateInputUsersAndGroups, CreateInputUsersAndGroupsTypedDict, ) - from .createinput_inputkubemetrics import ( + from .createinput_v3user import ( CreateInputAccountType, CreateInputActivities, CreateInputActivitiesManageState, @@ -578,6 +677,9 @@ CreateInputAuthMethodsExtAuthenticationType, CreateInputAuthMethodsExtTypedDict, CreateInputAuthenticationProtocol, + CreateInputBucketWidth, + CreateInputCertOptions, + CreateInputCertOptionsTypedDict, CreateInputChatMessages, CreateInputChatMessagesManageState, CreateInputChatMessagesManageStateTypedDict, @@ -586,14 +688,25 @@ CreateInputChatsManageState, CreateInputChatsManageStateTypedDict, CreateInputChatsTypedDict, + CreateInputContentType, CreateInputEventFormat, + CreateInputFeedType, CreateInputFormat, CreateInputGrantType, + CreateInputGroupBy, CreateInputGroups, CreateInputGroupsTypedDict, + CreateInputInputAkamaiHec, + CreateInputInputAkamaiHecType, + CreateInputInputAkamaiHecTypedDict, CreateInputInputAnthropicCompliance, CreateInputInputAnthropicComplianceType, CreateInputInputAnthropicComplianceTypedDict, + CreateInputInputAnthropicEnterpriseAnalytics, + CreateInputInputAnthropicEnterpriseAnalyticsContentConfig, + CreateInputInputAnthropicEnterpriseAnalyticsContentConfigTypedDict, + CreateInputInputAnthropicEnterpriseAnalyticsType, + CreateInputInputAnthropicEnterpriseAnalyticsTypedDict, CreateInputInputAppleUnifiedLogs, CreateInputInputAppleUnifiedLogsReadMode, CreateInputInputAppleUnifiedLogsType, @@ -605,56 +718,49 @@ CreateInputInputAppscopePersistenceTypedDict, CreateInputInputAppscopeType, CreateInputInputAppscopeTypedDict, + CreateInputInputAquaSecurityHec, + CreateInputInputAquaSecurityHecType, + CreateInputInputAquaSecurityHecTypedDict, CreateInputInputBedrockS3, CreateInputInputBedrockS3Type, CreateInputInputBedrockS3TypedDict, + CreateInputInputBeyondtrustHec, + CreateInputInputBeyondtrustHecType, + CreateInputInputBeyondtrustHecTypedDict, CreateInputInputCloudflareHec, CreateInputInputCloudflareHecType, CreateInputInputCloudflareHecTypedDict, - CreateInputInputCriblmetrics, - CreateInputInputCriblmetricsType, - CreateInputInputCriblmetricsTypedDict, - CreateInputInputCrowdstrike, - CreateInputInputCrowdstrikeType, - CreateInputInputCrowdstrikeTypedDict, - CreateInputInputDatadogAgent, - CreateInputInputDatadogAgentProxyMode, - CreateInputInputDatadogAgentProxyModeTypedDict, - CreateInputInputDatadogAgentType, - CreateInputInputDatadogAgentTypedDict, - CreateInputInputDatagen, - CreateInputInputDatagenType, - CreateInputInputDatagenTypedDict, + CreateInputInputExtrahopRevealx360, + CreateInputInputExtrahopRevealx360Type, + CreateInputInputExtrahopRevealx360TypedDict, + CreateInputInputF5BigIP, + CreateInputInputF5BigIPType, + CreateInputInputF5BigIPTypedDict, CreateInputInputFile, CreateInputInputFileMode, CreateInputInputFileType, CreateInputInputFileTypedDict, - CreateInputInputHTTPRaw, - CreateInputInputHTTPRawType, - CreateInputInputHTTPRawTypedDict, + CreateInputInputGigamonHec, + CreateInputInputGigamonHecType, + CreateInputInputGigamonHecTypedDict, + CreateInputInputHashicorpHcpVaultDedicated, + CreateInputInputHashicorpHcpVaultDedicatedType, + CreateInputInputHashicorpHcpVaultDedicatedTypedDict, CreateInputInputJournalFiles, CreateInputInputJournalFilesRule, CreateInputInputJournalFilesRuleTypedDict, CreateInputInputJournalFilesType, CreateInputInputJournalFilesTypedDict, - CreateInputInputKinesis, - CreateInputInputKinesisTypedDict, - CreateInputInputKubeEvents, - CreateInputInputKubeEventsType, - CreateInputInputKubeEventsTypedDict, - CreateInputInputKubeLogs, - CreateInputInputKubeLogsRule, - CreateInputInputKubeLogsRuleTypedDict, - CreateInputInputKubeLogsType, - CreateInputInputKubeLogsTypedDict, - CreateInputInputKubeMetrics, - CreateInputInputKubeMetricsPersistence, - CreateInputInputKubeMetricsPersistenceTypedDict, - CreateInputInputKubeMetricsType, - CreateInputInputKubeMetricsTypedDict, - CreateInputInputMetrics, - CreateInputInputMetricsType, - CreateInputInputMetricsTypedDict, + CreateInputInputMicrosoftCopilot, + CreateInputInputMicrosoftCopilotAuthenticationMethod, + CreateInputInputMicrosoftCopilotManageState, + CreateInputInputMicrosoftCopilotManageStateTypedDict, + CreateInputInputMicrosoftCopilotSubscriptionPlan, + CreateInputInputMicrosoftCopilotType, + CreateInputInputMicrosoftCopilotTypedDict, + CreateInputInputMimecastHec, + CreateInputInputMimecastHecType, + CreateInputInputMimecastHecTypedDict, CreateInputInputModelDrivenTelemetry, CreateInputInputModelDrivenTelemetryType, CreateInputInputModelDrivenTelemetryTypedDict, @@ -682,14 +788,18 @@ CreateInputInputOpenaiManageStateTypedDict, CreateInputInputOpenaiType, CreateInputInputOpenaiTypedDict, + CreateInputInputPingIdentityPingone, + CreateInputInputPingIdentityPingoneType, + CreateInputInputPingIdentityPingoneTypedDict, + CreateInputInputProofpointPod, + CreateInputInputProofpointPodType, + CreateInputInputProofpointPodTypedDict, CreateInputInputRawUDP, CreateInputInputRawUDPType, CreateInputInputRawUDPTypedDict, - CreateInputInputS3, - CreateInputInputS3Inventory, - CreateInputInputS3InventoryType, - CreateInputInputS3InventoryTypedDict, - CreateInputInputS3TypedDict, + CreateInputInputSailpointHec, + CreateInputInputSailpointHecType, + CreateInputInputSailpointHecTypedDict, CreateInputInputSecurityLake, CreateInputInputSecurityLakeTypedDict, CreateInputInputServicenowTable, @@ -698,8 +808,6 @@ CreateInputInputServicenowTableManageStateTypedDict, CreateInputInputServicenowTableType, CreateInputInputServicenowTableTypedDict, - CreateInputInputSnmp, - CreateInputInputSnmpTypedDict, CreateInputInputSqs, CreateInputInputSqsTypedDict, CreateInputInputSysdigHec, @@ -714,9 +822,18 @@ CreateInputInputTCP, CreateInputInputTCPType, CreateInputInputTCPTypedDict, + CreateInputInputTrellixHec, + CreateInputInputTrellixHecType, + CreateInputInputTrellixHecTypedDict, + CreateInputInputTrendMicroVisionOne, + CreateInputInputTrendMicroVisionOneType, + CreateInputInputTrendMicroVisionOneTypedDict, CreateInputInputUpwindHec, CreateInputInputUpwindHecType, CreateInputInputUpwindHecTypedDict, + CreateInputInputVectraAiHec, + CreateInputInputVectraAiHecType, + CreateInputInputVectraAiHecTypedDict, CreateInputInputWef, CreateInputInputWefAuthenticationMethod, CreateInputInputWefType, @@ -725,30 +842,6 @@ CreateInputInputWinEventLogsReadMode, CreateInputInputWinEventLogsType, CreateInputInputWinEventLogsTypedDict, - CreateInputInputWindowsMetrics, - CreateInputInputWindowsMetricsCPU, - CreateInputInputWindowsMetricsCPUMode, - CreateInputInputWindowsMetricsCPUTypedDict, - CreateInputInputWindowsMetricsCustom, - CreateInputInputWindowsMetricsCustomTypedDict, - CreateInputInputWindowsMetricsDisk, - CreateInputInputWindowsMetricsDiskMode, - CreateInputInputWindowsMetricsDiskTypedDict, - CreateInputInputWindowsMetricsHost, - CreateInputInputWindowsMetricsHostTypedDict, - CreateInputInputWindowsMetricsMemory, - CreateInputInputWindowsMetricsMemoryMode, - CreateInputInputWindowsMetricsMemoryTypedDict, - CreateInputInputWindowsMetricsNetwork, - CreateInputInputWindowsMetricsNetworkMode, - CreateInputInputWindowsMetricsNetworkTypedDict, - CreateInputInputWindowsMetricsPersistence, - CreateInputInputWindowsMetricsPersistenceTypedDict, - CreateInputInputWindowsMetricsSystem, - CreateInputInputWindowsMetricsSystemMode, - CreateInputInputWindowsMetricsSystemTypedDict, - CreateInputInputWindowsMetricsType, - CreateInputInputWindowsMetricsTypedDict, CreateInputInputWiz, CreateInputInputWizContentConfig, CreateInputInputWizContentConfigTypedDict, @@ -757,6 +850,12 @@ CreateInputInputWizType, CreateInputInputWizTypedDict, CreateInputInputWizWebhook, + CreateInputInputWizWebhookAuthTokensExt1, + CreateInputInputWizWebhookAuthTokensExt1TypedDict, + CreateInputInputWizWebhookAuthTokensExt2, + CreateInputInputWizWebhookAuthTokensExt2TypedDict, + CreateInputInputWizWebhookAuthTokensExtUnion, + CreateInputInputWizWebhookAuthTokensExtUnionTypedDict, CreateInputInputWizWebhookType, CreateInputInputWizWebhookTypedDict, CreateInputInputZscalerHec, @@ -788,15 +887,8 @@ CreateInputQueryBuilderMode, CreateInputQueryTypedDict, CreateInputQueueType, - CreateInputRecordDataFormat, - CreateInputSNMPv3Authentication, - CreateInputSNMPv3AuthenticationTypedDict, - CreateInputSample, - CreateInputSampleTypedDict, - CreateInputSamplingRule, - CreateInputSamplingRuleTypedDict, - CreateInputShardIteratorStart, - CreateInputShardLoadBalancing, + CreateInputRetryRules, + CreateInputRetryRulesTypedDict, CreateInputSortDirection, CreateInputSubscription, CreateInputSubscriptionTypedDict, @@ -804,6 +896,8 @@ CreateInputTLSSettingsServerSideTypedDict, CreateInputUNIXSocketPermissions, CreateInputUNIXSocketPermissionsTypedDict, + CreateInputV3AuthenticationKeyType, + CreateInputV3PrivacyKeyType, CreateInputV3User, CreateInputV3UserTypedDict, ) @@ -811,51 +905,50 @@ CreateInputHecTokenByIDRequest, CreateInputHecTokenByIDRequestTypedDict, ) - from .createinputsystembypack_inputkubemetrics import ( - CreateInputSystemByPackAccountType, - CreateInputSystemByPackActivities, - CreateInputSystemByPackActivitiesManageState, - CreateInputSystemByPackActivitiesManageStateTypedDict, - CreateInputSystemByPackActivitiesTypedDict, - CreateInputSystemByPackAllow, - CreateInputSystemByPackAllowTypedDict, - CreateInputSystemByPackAuthMethodsExt, - CreateInputSystemByPackAuthMethodsExtAuthenticationType, - CreateInputSystemByPackAuthMethodsExtTypedDict, - CreateInputSystemByPackAuthenticationProtocol, - CreateInputSystemByPackChatMessages, - CreateInputSystemByPackChatMessagesManageState, - CreateInputSystemByPackChatMessagesManageStateTypedDict, - CreateInputSystemByPackChatMessagesTypedDict, - CreateInputSystemByPackChats, - CreateInputSystemByPackChatsManageState, - CreateInputSystemByPackChatsManageStateTypedDict, - CreateInputSystemByPackChatsTypedDict, - CreateInputSystemByPackEventFormat, - CreateInputSystemByPackFormat, - CreateInputSystemByPackGrantType, - CreateInputSystemByPackGroups, - CreateInputSystemByPackGroupsTypedDict, - CreateInputSystemByPackInputAnthropicCompliance, - CreateInputSystemByPackInputAnthropicComplianceType, - CreateInputSystemByPackInputAnthropicComplianceTypedDict, - CreateInputSystemByPackInputAppleUnifiedLogs, - CreateInputSystemByPackInputAppleUnifiedLogsReadMode, - CreateInputSystemByPackInputAppleUnifiedLogsType, - CreateInputSystemByPackInputAppleUnifiedLogsTypedDict, - CreateInputSystemByPackInputAppscope, - CreateInputSystemByPackInputAppscopeFilter, - CreateInputSystemByPackInputAppscopeFilterTypedDict, - CreateInputSystemByPackInputAppscopePersistence, - CreateInputSystemByPackInputAppscopePersistenceTypedDict, - CreateInputSystemByPackInputAppscopeType, - CreateInputSystemByPackInputAppscopeTypedDict, - CreateInputSystemByPackInputBedrockS3, - CreateInputSystemByPackInputBedrockS3Type, - CreateInputSystemByPackInputBedrockS3TypedDict, - CreateInputSystemByPackInputCloudflareHec, - CreateInputSystemByPackInputCloudflareHecType, - CreateInputSystemByPackInputCloudflareHecTypedDict, + from .createinputsystembypack_inputelastic_type import ( + CreateInputSystemByPackAuth, + CreateInputSystemByPackAuthTypedDict, + CreateInputSystemByPackAuthenticationMechanism, + CreateInputSystemByPackAzureBlobStorage, + CreateInputSystemByPackAzureBlobStorageTypedDict, + CreateInputSystemByPackCertificate, + CreateInputSystemByPackCertificateTypedDict, + CreateInputSystemByPackCheckpointing, + CreateInputSystemByPackCheckpointingTypedDict, + CreateInputSystemByPackCollectors, + CreateInputSystemByPackCollectorsTypedDict, + CreateInputSystemByPackContainer, + CreateInputSystemByPackContainerMode, + CreateInputSystemByPackContainerTypedDict, + CreateInputSystemByPackDNS, + CreateInputSystemByPackDNSTypedDict, + CreateInputSystemByPackDisksAndFileSystems, + CreateInputSystemByPackDisksAndFileSystemsTypedDict, + CreateInputSystemByPackFirewall, + CreateInputSystemByPackFirewallTypedDict, + CreateInputSystemByPackHostInfo, + CreateInputSystemByPackHostInfoTypedDict, + CreateInputSystemByPackHostsFile, + CreateInputSystemByPackHostsFileTypedDict, + CreateInputSystemByPackInputConfluentCloud, + CreateInputSystemByPackInputConfluentCloudTypedDict, + CreateInputSystemByPackInputCribl, + CreateInputSystemByPackInputCriblHTTP, + CreateInputSystemByPackInputCriblHTTPType, + CreateInputSystemByPackInputCriblHTTPTypedDict, + CreateInputSystemByPackInputCriblLakeHTTP, + CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt, + CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExtTypedDict, + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + CreateInputSystemByPackInputCriblLakeHTTPType, + CreateInputSystemByPackInputCriblLakeHTTPTypedDict, + CreateInputSystemByPackInputCriblTCP, + CreateInputSystemByPackInputCriblTCPTypedDict, + CreateInputSystemByPackInputCriblType, + CreateInputSystemByPackInputCriblTypedDict, CreateInputSystemByPackInputCriblmetrics, CreateInputSystemByPackInputCriblmetricsType, CreateInputSystemByPackInputCriblmetricsTypedDict, @@ -870,18 +963,51 @@ CreateInputSystemByPackInputDatagen, CreateInputSystemByPackInputDatagenType, CreateInputSystemByPackInputDatagenTypedDict, - CreateInputSystemByPackInputFile, - CreateInputSystemByPackInputFileMode, - CreateInputSystemByPackInputFileType, - CreateInputSystemByPackInputFileTypedDict, + CreateInputSystemByPackInputEdgePrometheus, + CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod, + CreateInputSystemByPackInputEdgePrometheusDiscoveryType, + CreateInputSystemByPackInputEdgePrometheusType, + CreateInputSystemByPackInputEdgePrometheusTypedDict, + CreateInputSystemByPackInputElasticType, + CreateInputSystemByPackInputEventhub, + CreateInputSystemByPackInputEventhubAmqp, + CreateInputSystemByPackInputEventhubAmqpType, + CreateInputSystemByPackInputEventhubAmqpTypedDict, + CreateInputSystemByPackInputEventhubType, + CreateInputSystemByPackInputEventhubTypedDict, + CreateInputSystemByPackInputExec, + CreateInputSystemByPackInputExecType, + CreateInputSystemByPackInputExecTypedDict, + CreateInputSystemByPackInputFirehose, + CreateInputSystemByPackInputFirehoseType, + CreateInputSystemByPackInputFirehoseTypedDict, + CreateInputSystemByPackInputGooglePubsub, + CreateInputSystemByPackInputGooglePubsubTypedDict, + CreateInputSystemByPackInputGrafanaGrafana1, + CreateInputSystemByPackInputGrafanaGrafana1TypedDict, + CreateInputSystemByPackInputGrafanaGrafana2, + CreateInputSystemByPackInputGrafanaGrafana2TypedDict, + CreateInputSystemByPackInputGrafanaType1, + CreateInputSystemByPackInputGrafanaType2, + CreateInputSystemByPackInputGrafanaUnion, + CreateInputSystemByPackInputGrafanaUnionTypedDict, + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata, + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict, + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata, + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict, + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata, + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict, + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata, + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict, CreateInputSystemByPackInputHTTPRaw, + CreateInputSystemByPackInputHTTPRawAuthTokensExt, + CreateInputSystemByPackInputHTTPRawAuthTokensExtTypedDict, + CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion, + CreateInputSystemByPackInputHTTPRawAuthTokensExtUnionTypedDict, + CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint, + CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, CreateInputSystemByPackInputHTTPRawType, CreateInputSystemByPackInputHTTPRawTypedDict, - CreateInputSystemByPackInputJournalFiles, - CreateInputSystemByPackInputJournalFilesRule, - CreateInputSystemByPackInputJournalFilesRuleTypedDict, - CreateInputSystemByPackInputJournalFilesType, - CreateInputSystemByPackInputJournalFilesTypedDict, CreateInputSystemByPackInputKinesis, CreateInputSystemByPackInputKinesisTypedDict, CreateInputSystemByPackInputKubeEvents, @@ -897,79 +1023,77 @@ CreateInputSystemByPackInputKubeMetricsPersistenceTypedDict, CreateInputSystemByPackInputKubeMetricsType, CreateInputSystemByPackInputKubeMetricsTypedDict, + CreateInputSystemByPackInputLoki, + CreateInputSystemByPackInputLokiType, + CreateInputSystemByPackInputLokiTypedDict, CreateInputSystemByPackInputMetrics, CreateInputSystemByPackInputMetricsType, CreateInputSystemByPackInputMetricsTypedDict, - CreateInputSystemByPackInputModelDrivenTelemetry, - CreateInputSystemByPackInputModelDrivenTelemetryType, - CreateInputSystemByPackInputModelDrivenTelemetryTypedDict, - CreateInputSystemByPackInputNetflow, - CreateInputSystemByPackInputNetflowTypedDict, - CreateInputSystemByPackInputOkta, - CreateInputSystemByPackInputOktaManageState, - CreateInputSystemByPackInputOktaManageStateTypedDict, - CreateInputSystemByPackInputOktaType, - CreateInputSystemByPackInputOktaTypedDict, - CreateInputSystemByPackInputOpenTelemetry, - CreateInputSystemByPackInputOpenTelemetryAuthenticationType, - CreateInputSystemByPackInputOpenTelemetryType, - CreateInputSystemByPackInputOpenTelemetryTypedDict, - CreateInputSystemByPackInputOpenai, - CreateInputSystemByPackInputOpenaiComplianceLogs, - CreateInputSystemByPackInputOpenaiComplianceLogsManageState, - CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict, - CreateInputSystemByPackInputOpenaiComplianceLogsType, - CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict, - CreateInputSystemByPackInputOpenaiContentConfig, - CreateInputSystemByPackInputOpenaiContentConfigTypedDict, - CreateInputSystemByPackInputOpenaiLogLevel, - CreateInputSystemByPackInputOpenaiManageState, - CreateInputSystemByPackInputOpenaiManageStateTypedDict, - CreateInputSystemByPackInputOpenaiType, - CreateInputSystemByPackInputOpenaiTypedDict, - CreateInputSystemByPackInputRawUDP, - CreateInputSystemByPackInputRawUDPType, - CreateInputSystemByPackInputRawUDPTypedDict, + CreateInputSystemByPackInputMicrosoftGraph, + CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod, + CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan, + CreateInputSystemByPackInputMicrosoftGraphType, + CreateInputSystemByPackInputMicrosoftGraphTypedDict, + CreateInputSystemByPackInputOffice365Mgmt, + CreateInputSystemByPackInputOffice365MgmtContentConfig, + CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict, + CreateInputSystemByPackInputOffice365MgmtType, + CreateInputSystemByPackInputOffice365MgmtTypedDict, + CreateInputSystemByPackInputOffice365MsgTrace, + CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod, + CreateInputSystemByPackInputOffice365MsgTraceType, + CreateInputSystemByPackInputOffice365MsgTraceTypedDict, + CreateInputSystemByPackInputOffice365Service, + CreateInputSystemByPackInputOffice365ServiceContentConfig, + CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict, + CreateInputSystemByPackInputOffice365ServiceType, + CreateInputSystemByPackInputOffice365ServiceTypedDict, + CreateInputSystemByPackInputPrometheus, + CreateInputSystemByPackInputPrometheusDiscoveryType, + CreateInputSystemByPackInputPrometheusRw, + CreateInputSystemByPackInputPrometheusRwType, + CreateInputSystemByPackInputPrometheusRwTypedDict, + CreateInputSystemByPackInputPrometheusTypedDict, CreateInputSystemByPackInputS3, CreateInputSystemByPackInputS3Inventory, CreateInputSystemByPackInputS3InventoryType, CreateInputSystemByPackInputS3InventoryTypedDict, CreateInputSystemByPackInputS3TypedDict, - CreateInputSystemByPackInputSecurityLake, - CreateInputSystemByPackInputSecurityLakeTypedDict, - CreateInputSystemByPackInputServicenowTable, - CreateInputSystemByPackInputServicenowTableAuthenticationType, - CreateInputSystemByPackInputServicenowTableManageState, - CreateInputSystemByPackInputServicenowTableManageStateTypedDict, - CreateInputSystemByPackInputServicenowTableType, - CreateInputSystemByPackInputServicenowTableTypedDict, CreateInputSystemByPackInputSnmp, CreateInputSystemByPackInputSnmpTypedDict, - CreateInputSystemByPackInputSqs, - CreateInputSystemByPackInputSqsTypedDict, - CreateInputSystemByPackInputSysdigHec, - CreateInputSystemByPackInputSysdigHecType, - CreateInputSystemByPackInputSysdigHecTypedDict, - CreateInputSystemByPackInputSyslogSyslog1, - CreateInputSystemByPackInputSyslogSyslog1TypedDict, - CreateInputSystemByPackInputSyslogSyslog2, - CreateInputSystemByPackInputSyslogSyslog2TypedDict, - CreateInputSystemByPackInputSyslogUnion, - CreateInputSystemByPackInputSyslogUnionTypedDict, - CreateInputSystemByPackInputTCP, - CreateInputSystemByPackInputTCPType, - CreateInputSystemByPackInputTCPTypedDict, - CreateInputSystemByPackInputUpwindHec, - CreateInputSystemByPackInputUpwindHecType, - CreateInputSystemByPackInputUpwindHecTypedDict, - CreateInputSystemByPackInputWef, - CreateInputSystemByPackInputWefAuthenticationMethod, - CreateInputSystemByPackInputWefType, - CreateInputSystemByPackInputWefTypedDict, - CreateInputSystemByPackInputWinEventLogs, - CreateInputSystemByPackInputWinEventLogsReadMode, - CreateInputSystemByPackInputWinEventLogsType, - CreateInputSystemByPackInputWinEventLogsTypedDict, + CreateInputSystemByPackInputSystemMetrics, + CreateInputSystemByPackInputSystemMetricsCPU, + CreateInputSystemByPackInputSystemMetricsCPUMode, + CreateInputSystemByPackInputSystemMetricsCPUTypedDict, + CreateInputSystemByPackInputSystemMetricsCustom, + CreateInputSystemByPackInputSystemMetricsCustomTypedDict, + CreateInputSystemByPackInputSystemMetricsDisk, + CreateInputSystemByPackInputSystemMetricsDiskMode, + CreateInputSystemByPackInputSystemMetricsDiskTypedDict, + CreateInputSystemByPackInputSystemMetricsFilter, + CreateInputSystemByPackInputSystemMetricsFilterTypedDict, + CreateInputSystemByPackInputSystemMetricsHost, + CreateInputSystemByPackInputSystemMetricsHostTypedDict, + CreateInputSystemByPackInputSystemMetricsMemory, + CreateInputSystemByPackInputSystemMetricsMemoryMode, + CreateInputSystemByPackInputSystemMetricsMemoryTypedDict, + CreateInputSystemByPackInputSystemMetricsNetwork, + CreateInputSystemByPackInputSystemMetricsNetworkMode, + CreateInputSystemByPackInputSystemMetricsNetworkTypedDict, + CreateInputSystemByPackInputSystemMetricsPersistence, + CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict, + CreateInputSystemByPackInputSystemMetricsSystem, + CreateInputSystemByPackInputSystemMetricsSystemMode, + CreateInputSystemByPackInputSystemMetricsSystemTypedDict, + CreateInputSystemByPackInputSystemMetricsType, + CreateInputSystemByPackInputSystemMetricsTypedDict, + CreateInputSystemByPackInputSystemState, + CreateInputSystemByPackInputSystemStatePersistence, + CreateInputSystemByPackInputSystemStatePersistenceTypedDict, + CreateInputSystemByPackInputSystemStateType, + CreateInputSystemByPackInputSystemStateTypedDict, + CreateInputSystemByPackInputTcpjson, + CreateInputSystemByPackInputTcpjsonTypedDict, CreateInputSystemByPackInputWindowsMetrics, CreateInputSystemByPackInputWindowsMetricsCPU, CreateInputSystemByPackInputWindowsMetricsCPUMode, @@ -994,187 +1118,77 @@ CreateInputSystemByPackInputWindowsMetricsSystemTypedDict, CreateInputSystemByPackInputWindowsMetricsType, CreateInputSystemByPackInputWindowsMetricsTypedDict, - CreateInputSystemByPackInputWiz, - CreateInputSystemByPackInputWizContentConfig, - CreateInputSystemByPackInputWizContentConfigTypedDict, - CreateInputSystemByPackInputWizManageState, - CreateInputSystemByPackInputWizManageStateTypedDict, - CreateInputSystemByPackInputWizType, - CreateInputSystemByPackInputWizTypedDict, - CreateInputSystemByPackInputWizWebhook, - CreateInputSystemByPackInputWizWebhookType, - CreateInputSystemByPackInputWizWebhookTypedDict, - CreateInputSystemByPackInputZscalerHec, - CreateInputSystemByPackInputZscalerHecAuthToken, - CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict, - CreateInputSystemByPackInputZscalerHecType, - CreateInputSystemByPackInputZscalerHecTypedDict, - CreateInputSystemByPackMTLSSettings, - CreateInputSystemByPackMTLSSettingsTypedDict, - CreateInputSystemByPackOTLPVersion, - CreateInputSystemByPackOrganizationRoles, - CreateInputSystemByPackOrganizationRolesTypedDict, - CreateInputSystemByPackOrganizationUsers, - CreateInputSystemByPackOrganizationUsersTypedDict, - CreateInputSystemByPackOrganizations, - CreateInputSystemByPackOrganizationsTypedDict, - CreateInputSystemByPackPaginationType, - CreateInputSystemByPackPrivacyProtocol, - CreateInputSystemByPackProjectDetails, - CreateInputSystemByPackProjectDetailsManageState, - CreateInputSystemByPackProjectDetailsManageStateTypedDict, - CreateInputSystemByPackProjectDetailsTypedDict, - CreateInputSystemByPackProjects, - CreateInputSystemByPackProjectsManageState, - CreateInputSystemByPackProjectsManageStateTypedDict, - CreateInputSystemByPackProjectsTypedDict, - CreateInputSystemByPackProtocol, - CreateInputSystemByPackQuery, - CreateInputSystemByPackQueryBuilderMode, - CreateInputSystemByPackQueryTypedDict, - CreateInputSystemByPackQueueType, + CreateInputSystemByPackInterfaces, + CreateInputSystemByPackInterfacesTypedDict, + CreateInputSystemByPackListeningPorts, + CreateInputSystemByPackListeningPortsTypedDict, + CreateInputSystemByPackLoggedInUsers, + CreateInputSystemByPackLoggedInUsersTypedDict, + CreateInputSystemByPackLokiAuth1, + CreateInputSystemByPackLokiAuth1TypedDict, + CreateInputSystemByPackLokiAuth2, + CreateInputSystemByPackLokiAuth2TypedDict, + CreateInputSystemByPackMetricsProtocol, + CreateInputSystemByPackPodFilter, + CreateInputSystemByPackPodFilterTypedDict, + CreateInputSystemByPackPrometheusAuth1, + CreateInputSystemByPackPrometheusAuth1TypedDict, + CreateInputSystemByPackPrometheusAuth2, + CreateInputSystemByPackPrometheusAuth2TypedDict, CreateInputSystemByPackRecordDataFormat, + CreateInputSystemByPackRoutes, + CreateInputSystemByPackRoutesTypedDict, CreateInputSystemByPackSNMPv3Authentication, CreateInputSystemByPackSNMPv3AuthenticationTypedDict, CreateInputSystemByPackSample, CreateInputSystemByPackSampleTypedDict, CreateInputSystemByPackSamplingRule, CreateInputSystemByPackSamplingRuleTypedDict, + CreateInputSystemByPackScheduleType, + CreateInputSystemByPackServices, + CreateInputSystemByPackServicesTypedDict, CreateInputSystemByPackShardIteratorStart, CreateInputSystemByPackShardLoadBalancing, - CreateInputSystemByPackSortDirection, - CreateInputSystemByPackSubscription, - CreateInputSystemByPackSubscriptionTypedDict, - CreateInputSystemByPackTLSSettingsServerSide, - CreateInputSystemByPackTLSSettingsServerSideTypedDict, - CreateInputSystemByPackUNIXSocketPermissions, - CreateInputSystemByPackUNIXSocketPermissionsTypedDict, - CreateInputSystemByPackV3User, - CreateInputSystemByPackV3UserTypedDict, + CreateInputSystemByPackTarget, + CreateInputSystemByPackTargetTypedDict, + CreateInputSystemByPackUsersAndGroups, + CreateInputSystemByPackUsersAndGroupsTypedDict, ) from .createinputsystembypack_request import ( CreateInputSystemByPackAPIVersion, - CreateInputSystemByPackAuth, - CreateInputSystemByPackAuthTokensExt, - CreateInputSystemByPackAuthTokensExtTypedDict, - CreateInputSystemByPackAuthTypedDict, - CreateInputSystemByPackAuthenticationMechanism, - CreateInputSystemByPackAzureBlobStorage, - CreateInputSystemByPackAzureBlobStorageTypedDict, - CreateInputSystemByPackCertificate, - CreateInputSystemByPackCertificateTypedDict, - CreateInputSystemByPackCheckpointing, - CreateInputSystemByPackCheckpointingTypedDict, - CreateInputSystemByPackCollectors, - CreateInputSystemByPackCollectorsTypedDict, CreateInputSystemByPackCompression, - CreateInputSystemByPackContainer, - CreateInputSystemByPackContainerMode, - CreateInputSystemByPackContainerTypedDict, - CreateInputSystemByPackDNS, - CreateInputSystemByPackDNSTypedDict, - CreateInputSystemByPackDisksAndFileSystems, - CreateInputSystemByPackDisksAndFileSystemsTypedDict, - CreateInputSystemByPackElasticsearchMetadata, - CreateInputSystemByPackElasticsearchMetadataTypedDict, CreateInputSystemByPackEndpointHeader, CreateInputSystemByPackEndpointHeaderTypedDict, CreateInputSystemByPackEndpointParam, CreateInputSystemByPackEndpointParamTypedDict, - CreateInputSystemByPackFirewall, - CreateInputSystemByPackFirewallTypedDict, - CreateInputSystemByPackHostInfo, - CreateInputSystemByPackHostInfoTypedDict, - CreateInputSystemByPackHostsFile, - CreateInputSystemByPackHostsFileTypedDict, CreateInputSystemByPackInput, CreateInputSystemByPackInputAzureBlob, CreateInputSystemByPackInputAzureBlobTypedDict, + CreateInputSystemByPackInputAzureVnetFlowLog, + CreateInputSystemByPackInputAzureVnetFlowLogType, + CreateInputSystemByPackInputAzureVnetFlowLogTypedDict, CreateInputSystemByPackInputCollection, CreateInputSystemByPackInputCollectionType, CreateInputSystemByPackInputCollectionTypedDict, - CreateInputSystemByPackInputConfluentCloud, - CreateInputSystemByPackInputConfluentCloudTypedDict, - CreateInputSystemByPackInputCribl, - CreateInputSystemByPackInputCriblHTTP, - CreateInputSystemByPackInputCriblHTTPType, - CreateInputSystemByPackInputCriblHTTPTypedDict, - CreateInputSystemByPackInputCriblLakeHTTP, - CreateInputSystemByPackInputCriblLakeHTTPType, - CreateInputSystemByPackInputCriblLakeHTTPTypedDict, - CreateInputSystemByPackInputCriblTCP, - CreateInputSystemByPackInputCriblTCPTypedDict, - CreateInputSystemByPackInputCriblType, - CreateInputSystemByPackInputCriblTypedDict, - CreateInputSystemByPackInputEdgePrometheus, - CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod, - CreateInputSystemByPackInputEdgePrometheusDiscoveryType, - CreateInputSystemByPackInputEdgePrometheusType, - CreateInputSystemByPackInputEdgePrometheusTypedDict, CreateInputSystemByPackInputElastic, CreateInputSystemByPackInputElasticAuthenticationMethod, CreateInputSystemByPackInputElasticAuthenticationType, CreateInputSystemByPackInputElasticProxyMode, CreateInputSystemByPackInputElasticProxyModeTypedDict, - CreateInputSystemByPackInputElasticType, CreateInputSystemByPackInputElasticTypedDict, - CreateInputSystemByPackInputEventhub, - CreateInputSystemByPackInputEventhubAmqp, - CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod, - CreateInputSystemByPackInputEventhubAmqpType, - CreateInputSystemByPackInputEventhubAmqpTypedDict, - CreateInputSystemByPackInputEventhubType, - CreateInputSystemByPackInputEventhubTypedDict, - CreateInputSystemByPackInputExec, - CreateInputSystemByPackInputExecType, - CreateInputSystemByPackInputExecTypedDict, - CreateInputSystemByPackInputFirehose, - CreateInputSystemByPackInputFirehoseType, - CreateInputSystemByPackInputFirehoseTypedDict, - CreateInputSystemByPackInputGooglePubsub, - CreateInputSystemByPackInputGooglePubsubTypedDict, - CreateInputSystemByPackInputGrafanaGrafana1, - CreateInputSystemByPackInputGrafanaGrafana1TypedDict, - CreateInputSystemByPackInputGrafanaGrafana2, - CreateInputSystemByPackInputGrafanaGrafana2TypedDict, - CreateInputSystemByPackInputGrafanaType1, - CreateInputSystemByPackInputGrafanaType2, - CreateInputSystemByPackInputGrafanaUnion, - CreateInputSystemByPackInputGrafanaUnionTypedDict, CreateInputSystemByPackInputHTTP, + CreateInputSystemByPackInputHTTPAuthTokensExt, + CreateInputSystemByPackInputHTTPAuthTokensExtTypedDict, + CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType, + CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint, + CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, CreateInputSystemByPackInputHTTPType, CreateInputSystemByPackInputHTTPTypedDict, CreateInputSystemByPackInputKafka, CreateInputSystemByPackInputKafkaTypedDict, - CreateInputSystemByPackInputLoki, - CreateInputSystemByPackInputLokiType, - CreateInputSystemByPackInputLokiTypedDict, - CreateInputSystemByPackInputMicrosoftGraph, - CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod, - CreateInputSystemByPackInputMicrosoftGraphType, - CreateInputSystemByPackInputMicrosoftGraphTypedDict, CreateInputSystemByPackInputMsk, CreateInputSystemByPackInputMskTypedDict, - CreateInputSystemByPackInputOffice365Mgmt, - CreateInputSystemByPackInputOffice365MgmtContentConfig, - CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict, - CreateInputSystemByPackInputOffice365MgmtType, - CreateInputSystemByPackInputOffice365MgmtTypedDict, - CreateInputSystemByPackInputOffice365MsgTrace, - CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod, - CreateInputSystemByPackInputOffice365MsgTraceType, - CreateInputSystemByPackInputOffice365MsgTraceTypedDict, - CreateInputSystemByPackInputOffice365Service, - CreateInputSystemByPackInputOffice365ServiceContentConfig, - CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict, - CreateInputSystemByPackInputOffice365ServiceType, - CreateInputSystemByPackInputOffice365ServiceTypedDict, - CreateInputSystemByPackInputPrometheus, - CreateInputSystemByPackInputPrometheusDiscoveryType, - CreateInputSystemByPackInputPrometheusRw, - CreateInputSystemByPackInputPrometheusRwType, - CreateInputSystemByPackInputPrometheusRwTypedDict, - CreateInputSystemByPackInputPrometheusTypedDict, CreateInputSystemByPackInputSplunk, CreateInputSystemByPackInputSplunkAuthToken, CreateInputSystemByPackInputSplunkAuthTokenTypedDict, @@ -1189,294 +1203,265 @@ CreateInputSystemByPackInputSplunkSearchType, CreateInputSystemByPackInputSplunkSearchTypedDict, CreateInputSystemByPackInputSplunkTypedDict, - CreateInputSystemByPackInputSystemMetrics, - CreateInputSystemByPackInputSystemMetricsCPU, - CreateInputSystemByPackInputSystemMetricsCPUMode, - CreateInputSystemByPackInputSystemMetricsCPUTypedDict, - CreateInputSystemByPackInputSystemMetricsCustom, - CreateInputSystemByPackInputSystemMetricsCustomTypedDict, - CreateInputSystemByPackInputSystemMetricsDisk, - CreateInputSystemByPackInputSystemMetricsDiskMode, - CreateInputSystemByPackInputSystemMetricsDiskTypedDict, - CreateInputSystemByPackInputSystemMetricsFilter, - CreateInputSystemByPackInputSystemMetricsFilterTypedDict, - CreateInputSystemByPackInputSystemMetricsHost, - CreateInputSystemByPackInputSystemMetricsHostTypedDict, - CreateInputSystemByPackInputSystemMetricsMemory, - CreateInputSystemByPackInputSystemMetricsMemoryMode, - CreateInputSystemByPackInputSystemMetricsMemoryTypedDict, - CreateInputSystemByPackInputSystemMetricsNetwork, - CreateInputSystemByPackInputSystemMetricsNetworkMode, - CreateInputSystemByPackInputSystemMetricsNetworkTypedDict, - CreateInputSystemByPackInputSystemMetricsPersistence, - CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict, - CreateInputSystemByPackInputSystemMetricsSystem, - CreateInputSystemByPackInputSystemMetricsSystemMode, - CreateInputSystemByPackInputSystemMetricsSystemTypedDict, - CreateInputSystemByPackInputSystemMetricsType, - CreateInputSystemByPackInputSystemMetricsTypedDict, - CreateInputSystemByPackInputSystemState, - CreateInputSystemByPackInputSystemStatePersistence, - CreateInputSystemByPackInputSystemStatePersistenceTypedDict, - CreateInputSystemByPackInputSystemStateType, - CreateInputSystemByPackInputSystemStateTypedDict, - CreateInputSystemByPackInputTcpjson, - CreateInputSystemByPackInputTcpjsonTypedDict, CreateInputSystemByPackInputTypedDict, - CreateInputSystemByPackInterfaces, - CreateInputSystemByPackInterfacesTypedDict, - CreateInputSystemByPackListeningPorts, - CreateInputSystemByPackListeningPortsTypedDict, - CreateInputSystemByPackLoggedInUsers, - CreateInputSystemByPackLoggedInUsersTypedDict, - CreateInputSystemByPackLokiAuth1, - CreateInputSystemByPackLokiAuth1TypedDict, - CreateInputSystemByPackLokiAuth2, - CreateInputSystemByPackLokiAuth2TypedDict, CreateInputSystemByPackMaxS2SVersion, - CreateInputSystemByPackMetricsProtocol, - CreateInputSystemByPackPodFilter, - CreateInputSystemByPackPodFilterTypedDict, - CreateInputSystemByPackPrometheusAuth1, - CreateInputSystemByPackPrometheusAuth1TypedDict, - CreateInputSystemByPackPrometheusAuth2, - CreateInputSystemByPackPrometheusAuth2TypedDict, CreateInputSystemByPackRequest, CreateInputSystemByPackRequestTypedDict, - CreateInputSystemByPackRoutes, - CreateInputSystemByPackRoutesTypedDict, - CreateInputSystemByPackScheduleType, - CreateInputSystemByPackServices, - CreateInputSystemByPackServicesTypedDict, - CreateInputSystemByPackSplunkHecMetadata, - CreateInputSystemByPackSplunkHecMetadataTypedDict, - CreateInputSystemByPackSubscriptionPlan, - CreateInputSystemByPackTarget, - CreateInputSystemByPackTargetTypedDict, - CreateInputSystemByPackUsersAndGroups, - CreateInputSystemByPackUsersAndGroupsTypedDict, - ) - from .createinputsystemhectokenbypackandidop import ( - CreateInputSystemHecTokenByPackAndIDRequest, - CreateInputSystemHecTokenByPackAndIDRequestTypedDict, - ) - from .createoutput_output import ( - CreateOutputOutput, - CreateOutputOutputDefault, - CreateOutputOutputDefaultTypedDict, - CreateOutputOutputTypedDict, ) - from .createoutput_outputdefault_type import ( - CreateOutputAPIVersion, - CreateOutputAdditionalProperty, - CreateOutputAdditionalPropertyTypedDict, - CreateOutputAuthToken, - CreateOutputAuthTokenTypedDict, - CreateOutputAuthType, - CreateOutputBlobAccessTier, - CreateOutputCertificate, - CreateOutputCertificateTypedDict, - CreateOutputCompression, - CreateOutputElasticVersion, - CreateOutputEndpointConfiguration, - CreateOutputExtentTag, - CreateOutputExtentTagTypedDict, - CreateOutputExtraLogType, - CreateOutputExtraLogTypeTypedDict, - CreateOutputFacility, - CreateOutputFieldName, - CreateOutputIndexerDiscoveryConfigs, - CreateOutputIndexerDiscoveryConfigsTypedDict, - CreateOutputIngestIfNotExist, - CreateOutputIngestIfNotExistTypedDict, - CreateOutputIngestionMode, - CreateOutputLogLocationType, - CreateOutputMessageFormat, - CreateOutputMetadatum, - CreateOutputMetadatumTypedDict, - CreateOutputOutputAzureBlob, - CreateOutputOutputAzureBlobTypedDict, - CreateOutputOutputAzureDataExplorer, - CreateOutputOutputAzureDataExplorerAuthenticationMethod, - CreateOutputOutputAzureDataExplorerPqControls, - CreateOutputOutputAzureDataExplorerPqControlsTypedDict, - CreateOutputOutputAzureDataExplorerType, - CreateOutputOutputAzureDataExplorerTypedDict, - CreateOutputOutputAzureEventhub, - CreateOutputOutputAzureEventhubPqControls, - CreateOutputOutputAzureEventhubPqControlsTypedDict, - CreateOutputOutputAzureEventhubType, - CreateOutputOutputAzureEventhubTypedDict, - CreateOutputOutputAzureLogs, - CreateOutputOutputAzureLogsAuthenticationMethod, - CreateOutputOutputAzureLogsPqControls, - CreateOutputOutputAzureLogsPqControlsTypedDict, - CreateOutputOutputAzureLogsType, - CreateOutputOutputAzureLogsTypedDict, - CreateOutputOutputCloudwatch, - CreateOutputOutputCloudwatchPqControls, - CreateOutputOutputCloudwatchPqControlsTypedDict, - CreateOutputOutputCloudwatchType, - CreateOutputOutputCloudwatchTypedDict, - CreateOutputOutputConfluentCloud, - CreateOutputOutputConfluentCloudPqControls, - CreateOutputOutputConfluentCloudPqControlsTypedDict, - CreateOutputOutputConfluentCloudTypedDict, - CreateOutputOutputDefaultType, - CreateOutputOutputDevnull, - CreateOutputOutputDevnullType, - CreateOutputOutputDevnullTypedDict, - CreateOutputOutputElastic, - CreateOutputOutputElasticCloud, - CreateOutputOutputElasticCloudPqControls, - CreateOutputOutputElasticCloudPqControlsTypedDict, - CreateOutputOutputElasticCloudType, - CreateOutputOutputElasticCloudTypedDict, - CreateOutputOutputElasticPqControls, - CreateOutputOutputElasticPqControlsTypedDict, - CreateOutputOutputElasticType, - CreateOutputOutputElasticTypedDict, - CreateOutputOutputElasticURL, - CreateOutputOutputElasticURLTypedDict, - CreateOutputOutputExabeam, - CreateOutputOutputExabeamType, - CreateOutputOutputExabeamTypedDict, - CreateOutputOutputFilesystem, - CreateOutputOutputFilesystemType, - CreateOutputOutputFilesystemTypedDict, - CreateOutputOutputGoogleBigquery, - CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod, - CreateOutputOutputGoogleBigqueryPqControls, - CreateOutputOutputGoogleBigqueryPqControlsTypedDict, - CreateOutputOutputGoogleBigqueryType, - CreateOutputOutputGoogleBigqueryTypedDict, - CreateOutputOutputGoogleChronicle, - CreateOutputOutputGoogleChronicleAuthenticationMethod, - CreateOutputOutputGoogleChroniclePqControls, - CreateOutputOutputGoogleChroniclePqControlsTypedDict, - CreateOutputOutputGoogleChronicleType, - CreateOutputOutputGoogleChronicleTypedDict, - CreateOutputOutputGoogleCloudLogging, - CreateOutputOutputGoogleCloudLoggingPqControls, - CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict, - CreateOutputOutputGoogleCloudLoggingType, - CreateOutputOutputGoogleCloudLoggingTypedDict, - CreateOutputOutputGoogleCloudObservability, - CreateOutputOutputGoogleCloudObservabilityEndpoint, - CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod, - CreateOutputOutputGoogleCloudObservabilityOtlpVersion, - CreateOutputOutputGoogleCloudObservabilityPqControls, - CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict, - CreateOutputOutputGoogleCloudObservabilityProtocol, - CreateOutputOutputGoogleCloudObservabilityType, - CreateOutputOutputGoogleCloudObservabilityTypedDict, - CreateOutputOutputGoogleCloudStorage, - CreateOutputOutputGoogleCloudStorageAuthenticationMethod, - CreateOutputOutputGoogleCloudStorageType, - CreateOutputOutputGoogleCloudStorageTypedDict, - CreateOutputOutputGooglePubsub, - CreateOutputOutputGooglePubsubPqControls, - CreateOutputOutputGooglePubsubPqControlsTypedDict, - CreateOutputOutputGooglePubsubTypedDict, - CreateOutputOutputHoneycomb, - CreateOutputOutputHoneycombPqControls, - CreateOutputOutputHoneycombPqControlsTypedDict, - CreateOutputOutputHoneycombType, - CreateOutputOutputHoneycombTypedDict, - CreateOutputOutputInfluxdb, - CreateOutputOutputInfluxdbAuthenticationType, - CreateOutputOutputInfluxdbPqControls, - CreateOutputOutputInfluxdbPqControlsTypedDict, - CreateOutputOutputInfluxdbType, - CreateOutputOutputInfluxdbTypedDict, - CreateOutputOutputKafka, - CreateOutputOutputKafkaPqControls, - CreateOutputOutputKafkaPqControlsTypedDict, - CreateOutputOutputKafkaTypedDict, - CreateOutputOutputKinesis, - CreateOutputOutputKinesisPqControls, - CreateOutputOutputKinesisPqControlsTypedDict, - CreateOutputOutputKinesisTypedDict, - CreateOutputOutputMinio, - CreateOutputOutputMinioType, - CreateOutputOutputMinioTypedDict, - CreateOutputOutputMsk, - CreateOutputOutputMskPqControls, - CreateOutputOutputMskPqControlsTypedDict, - CreateOutputOutputMskTypedDict, - CreateOutputOutputNewrelic, - CreateOutputOutputNewrelicEvents, - CreateOutputOutputNewrelicEventsPqControls, - CreateOutputOutputNewrelicEventsPqControlsTypedDict, - CreateOutputOutputNewrelicEventsType, - CreateOutputOutputNewrelicEventsTypedDict, - CreateOutputOutputNewrelicPqControls, - CreateOutputOutputNewrelicPqControlsTypedDict, - CreateOutputOutputNewrelicType, - CreateOutputOutputNewrelicTypedDict, - CreateOutputOutputS3, - CreateOutputOutputS3TypedDict, - CreateOutputOutputSentinel, - CreateOutputOutputSentinelFormat, - CreateOutputOutputSentinelPqControls, - CreateOutputOutputSentinelPqControlsTypedDict, - CreateOutputOutputSentinelType, - CreateOutputOutputSentinelTypedDict, - CreateOutputOutputSignalfx, - CreateOutputOutputSignalfxPqControls, - CreateOutputOutputSignalfxPqControlsTypedDict, - CreateOutputOutputSignalfxType, - CreateOutputOutputSignalfxTypedDict, - CreateOutputOutputSplunk, - CreateOutputOutputSplunkHec, - CreateOutputOutputSplunkHecPqControls, - CreateOutputOutputSplunkHecPqControlsTypedDict, - CreateOutputOutputSplunkHecType, - CreateOutputOutputSplunkHecTypedDict, - CreateOutputOutputSplunkHecURL, - CreateOutputOutputSplunkHecURLTypedDict, - CreateOutputOutputSplunkLb, - CreateOutputOutputSplunkLbPqControls, - CreateOutputOutputSplunkLbPqControlsTypedDict, - CreateOutputOutputSplunkLbType, - CreateOutputOutputSplunkLbTypedDict, - CreateOutputOutputSplunkPqControls, - CreateOutputOutputSplunkPqControlsTypedDict, - CreateOutputOutputSplunkTypedDict, - CreateOutputOutputStatsd, - CreateOutputOutputStatsdExt, - CreateOutputOutputStatsdExtPqControls, - CreateOutputOutputStatsdExtPqControlsTypedDict, - CreateOutputOutputStatsdExtTypedDict, - CreateOutputOutputStatsdPqControls, - CreateOutputOutputStatsdPqControlsTypedDict, - CreateOutputOutputStatsdType, - CreateOutputOutputStatsdTypedDict, - CreateOutputOutputSyslog, - CreateOutputOutputSyslogPqControls, - CreateOutputOutputSyslogPqControlsTypedDict, - CreateOutputOutputSyslogProtocol, - CreateOutputOutputSyslogSeverity, - CreateOutputOutputSyslogTypedDict, - CreateOutputOutputTcpjson, - CreateOutputOutputTcpjsonPqControls, - CreateOutputOutputTcpjsonPqControlsTypedDict, - CreateOutputOutputTcpjsonTypedDict, - CreateOutputOutputWavefront, - CreateOutputOutputWavefrontPqControls, - CreateOutputOutputWavefrontPqControlsTypedDict, - CreateOutputOutputWavefrontType, - CreateOutputOutputWavefrontTypedDict, + from .createinputsystembypack_v3user import ( + CreateInputSystemByPackAccountType, + CreateInputSystemByPackActivities, + CreateInputSystemByPackActivitiesManageState, + CreateInputSystemByPackActivitiesManageStateTypedDict, + CreateInputSystemByPackActivitiesTypedDict, + CreateInputSystemByPackAllow, + CreateInputSystemByPackAllowTypedDict, + CreateInputSystemByPackAuthMethodsExt, + CreateInputSystemByPackAuthMethodsExtAuthenticationType, + CreateInputSystemByPackAuthMethodsExtTypedDict, + CreateInputSystemByPackAuthenticationProtocol, + CreateInputSystemByPackBucketWidth, + CreateInputSystemByPackCertOptions, + CreateInputSystemByPackCertOptionsTypedDict, + CreateInputSystemByPackChatMessages, + CreateInputSystemByPackChatMessagesManageState, + CreateInputSystemByPackChatMessagesManageStateTypedDict, + CreateInputSystemByPackChatMessagesTypedDict, + CreateInputSystemByPackChats, + CreateInputSystemByPackChatsManageState, + CreateInputSystemByPackChatsManageStateTypedDict, + CreateInputSystemByPackChatsTypedDict, + CreateInputSystemByPackContentType, + CreateInputSystemByPackEventFormat, + CreateInputSystemByPackFeedType, + CreateInputSystemByPackFormat, + CreateInputSystemByPackGrantType, + CreateInputSystemByPackGroupBy, + CreateInputSystemByPackGroups, + CreateInputSystemByPackGroupsTypedDict, + CreateInputSystemByPackInputAkamaiHec, + CreateInputSystemByPackInputAkamaiHecType, + CreateInputSystemByPackInputAkamaiHecTypedDict, + CreateInputSystemByPackInputAnthropicCompliance, + CreateInputSystemByPackInputAnthropicComplianceType, + CreateInputSystemByPackInputAnthropicComplianceTypedDict, + CreateInputSystemByPackInputAnthropicEnterpriseAnalytics, + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig, + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfigTypedDict, + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType, + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsTypedDict, + CreateInputSystemByPackInputAppleUnifiedLogs, + CreateInputSystemByPackInputAppleUnifiedLogsReadMode, + CreateInputSystemByPackInputAppleUnifiedLogsType, + CreateInputSystemByPackInputAppleUnifiedLogsTypedDict, + CreateInputSystemByPackInputAppscope, + CreateInputSystemByPackInputAppscopeFilter, + CreateInputSystemByPackInputAppscopeFilterTypedDict, + CreateInputSystemByPackInputAppscopePersistence, + CreateInputSystemByPackInputAppscopePersistenceTypedDict, + CreateInputSystemByPackInputAppscopeType, + CreateInputSystemByPackInputAppscopeTypedDict, + CreateInputSystemByPackInputAquaSecurityHec, + CreateInputSystemByPackInputAquaSecurityHecType, + CreateInputSystemByPackInputAquaSecurityHecTypedDict, + CreateInputSystemByPackInputBedrockS3, + CreateInputSystemByPackInputBedrockS3Type, + CreateInputSystemByPackInputBedrockS3TypedDict, + CreateInputSystemByPackInputBeyondtrustHec, + CreateInputSystemByPackInputBeyondtrustHecType, + CreateInputSystemByPackInputBeyondtrustHecTypedDict, + CreateInputSystemByPackInputCloudflareHec, + CreateInputSystemByPackInputCloudflareHecType, + CreateInputSystemByPackInputCloudflareHecTypedDict, + CreateInputSystemByPackInputExtrahopRevealx360, + CreateInputSystemByPackInputExtrahopRevealx360Type, + CreateInputSystemByPackInputExtrahopRevealx360TypedDict, + CreateInputSystemByPackInputF5BigIP, + CreateInputSystemByPackInputF5BigIPType, + CreateInputSystemByPackInputF5BigIPTypedDict, + CreateInputSystemByPackInputFile, + CreateInputSystemByPackInputFileMode, + CreateInputSystemByPackInputFileType, + CreateInputSystemByPackInputFileTypedDict, + CreateInputSystemByPackInputGigamonHec, + CreateInputSystemByPackInputGigamonHecType, + CreateInputSystemByPackInputGigamonHecTypedDict, + CreateInputSystemByPackInputHashicorpHcpVaultDedicated, + CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType, + CreateInputSystemByPackInputHashicorpHcpVaultDedicatedTypedDict, + CreateInputSystemByPackInputJournalFiles, + CreateInputSystemByPackInputJournalFilesRule, + CreateInputSystemByPackInputJournalFilesRuleTypedDict, + CreateInputSystemByPackInputJournalFilesType, + CreateInputSystemByPackInputJournalFilesTypedDict, + CreateInputSystemByPackInputMicrosoftCopilot, + CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod, + CreateInputSystemByPackInputMicrosoftCopilotManageState, + CreateInputSystemByPackInputMicrosoftCopilotManageStateTypedDict, + CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan, + CreateInputSystemByPackInputMicrosoftCopilotType, + CreateInputSystemByPackInputMicrosoftCopilotTypedDict, + CreateInputSystemByPackInputMimecastHec, + CreateInputSystemByPackInputMimecastHecType, + CreateInputSystemByPackInputMimecastHecTypedDict, + CreateInputSystemByPackInputModelDrivenTelemetry, + CreateInputSystemByPackInputModelDrivenTelemetryType, + CreateInputSystemByPackInputModelDrivenTelemetryTypedDict, + CreateInputSystemByPackInputNetflow, + CreateInputSystemByPackInputNetflowTypedDict, + CreateInputSystemByPackInputOkta, + CreateInputSystemByPackInputOktaManageState, + CreateInputSystemByPackInputOktaManageStateTypedDict, + CreateInputSystemByPackInputOktaType, + CreateInputSystemByPackInputOktaTypedDict, + CreateInputSystemByPackInputOpenTelemetry, + CreateInputSystemByPackInputOpenTelemetryAuthenticationType, + CreateInputSystemByPackInputOpenTelemetryType, + CreateInputSystemByPackInputOpenTelemetryTypedDict, + CreateInputSystemByPackInputOpenai, + CreateInputSystemByPackInputOpenaiComplianceLogs, + CreateInputSystemByPackInputOpenaiComplianceLogsManageState, + CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict, + CreateInputSystemByPackInputOpenaiComplianceLogsType, + CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict, + CreateInputSystemByPackInputOpenaiContentConfig, + CreateInputSystemByPackInputOpenaiContentConfigTypedDict, + CreateInputSystemByPackInputOpenaiLogLevel, + CreateInputSystemByPackInputOpenaiManageState, + CreateInputSystemByPackInputOpenaiManageStateTypedDict, + CreateInputSystemByPackInputOpenaiType, + CreateInputSystemByPackInputOpenaiTypedDict, + CreateInputSystemByPackInputPingIdentityPingone, + CreateInputSystemByPackInputPingIdentityPingoneType, + CreateInputSystemByPackInputPingIdentityPingoneTypedDict, + CreateInputSystemByPackInputProofpointPod, + CreateInputSystemByPackInputProofpointPodType, + CreateInputSystemByPackInputProofpointPodTypedDict, + CreateInputSystemByPackInputRawUDP, + CreateInputSystemByPackInputRawUDPType, + CreateInputSystemByPackInputRawUDPTypedDict, + CreateInputSystemByPackInputSailpointHec, + CreateInputSystemByPackInputSailpointHecType, + CreateInputSystemByPackInputSailpointHecTypedDict, + CreateInputSystemByPackInputSecurityLake, + CreateInputSystemByPackInputSecurityLakeTypedDict, + CreateInputSystemByPackInputServicenowTable, + CreateInputSystemByPackInputServicenowTableAuthenticationType, + CreateInputSystemByPackInputServicenowTableManageState, + CreateInputSystemByPackInputServicenowTableManageStateTypedDict, + CreateInputSystemByPackInputServicenowTableType, + CreateInputSystemByPackInputServicenowTableTypedDict, + CreateInputSystemByPackInputSqs, + CreateInputSystemByPackInputSqsTypedDict, + CreateInputSystemByPackInputSysdigHec, + CreateInputSystemByPackInputSysdigHecType, + CreateInputSystemByPackInputSysdigHecTypedDict, + CreateInputSystemByPackInputSyslogSyslog1, + CreateInputSystemByPackInputSyslogSyslog1TypedDict, + CreateInputSystemByPackInputSyslogSyslog2, + CreateInputSystemByPackInputSyslogSyslog2TypedDict, + CreateInputSystemByPackInputSyslogUnion, + CreateInputSystemByPackInputSyslogUnionTypedDict, + CreateInputSystemByPackInputTCP, + CreateInputSystemByPackInputTCPType, + CreateInputSystemByPackInputTCPTypedDict, + CreateInputSystemByPackInputTrellixHec, + CreateInputSystemByPackInputTrellixHecType, + CreateInputSystemByPackInputTrellixHecTypedDict, + CreateInputSystemByPackInputTrendMicroVisionOne, + CreateInputSystemByPackInputTrendMicroVisionOneType, + CreateInputSystemByPackInputTrendMicroVisionOneTypedDict, + CreateInputSystemByPackInputUpwindHec, + CreateInputSystemByPackInputUpwindHecType, + CreateInputSystemByPackInputUpwindHecTypedDict, + CreateInputSystemByPackInputVectraAiHec, + CreateInputSystemByPackInputVectraAiHecType, + CreateInputSystemByPackInputVectraAiHecTypedDict, + CreateInputSystemByPackInputWef, + CreateInputSystemByPackInputWefAuthenticationMethod, + CreateInputSystemByPackInputWefType, + CreateInputSystemByPackInputWefTypedDict, + CreateInputSystemByPackInputWinEventLogs, + CreateInputSystemByPackInputWinEventLogsReadMode, + CreateInputSystemByPackInputWinEventLogsType, + CreateInputSystemByPackInputWinEventLogsTypedDict, + CreateInputSystemByPackInputWiz, + CreateInputSystemByPackInputWizContentConfig, + CreateInputSystemByPackInputWizContentConfigTypedDict, + CreateInputSystemByPackInputWizManageState, + CreateInputSystemByPackInputWizManageStateTypedDict, + CreateInputSystemByPackInputWizType, + CreateInputSystemByPackInputWizTypedDict, + CreateInputSystemByPackInputWizWebhook, + CreateInputSystemByPackInputWizWebhookAuthTokensExt1, + CreateInputSystemByPackInputWizWebhookAuthTokensExt1TypedDict, + CreateInputSystemByPackInputWizWebhookAuthTokensExt2, + CreateInputSystemByPackInputWizWebhookAuthTokensExt2TypedDict, + CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion, + CreateInputSystemByPackInputWizWebhookAuthTokensExtUnionTypedDict, + CreateInputSystemByPackInputWizWebhookType, + CreateInputSystemByPackInputWizWebhookTypedDict, + CreateInputSystemByPackInputZscalerHec, + CreateInputSystemByPackInputZscalerHecAuthToken, + CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict, + CreateInputSystemByPackInputZscalerHecType, + CreateInputSystemByPackInputZscalerHecTypedDict, + CreateInputSystemByPackMTLSSettings, + CreateInputSystemByPackMTLSSettingsTypedDict, + CreateInputSystemByPackOTLPVersion, + CreateInputSystemByPackOrganizationRoles, + CreateInputSystemByPackOrganizationRolesTypedDict, + CreateInputSystemByPackOrganizationUsers, + CreateInputSystemByPackOrganizationUsersTypedDict, + CreateInputSystemByPackOrganizations, + CreateInputSystemByPackOrganizationsTypedDict, + CreateInputSystemByPackPaginationType, + CreateInputSystemByPackPrivacyProtocol, + CreateInputSystemByPackProjectDetails, + CreateInputSystemByPackProjectDetailsManageState, + CreateInputSystemByPackProjectDetailsManageStateTypedDict, + CreateInputSystemByPackProjectDetailsTypedDict, + CreateInputSystemByPackProjects, + CreateInputSystemByPackProjectsManageState, + CreateInputSystemByPackProjectsManageStateTypedDict, + CreateInputSystemByPackProjectsTypedDict, + CreateInputSystemByPackProtocol, + CreateInputSystemByPackQuery, + CreateInputSystemByPackQueryBuilderMode, + CreateInputSystemByPackQueryTypedDict, + CreateInputSystemByPackQueueType, + CreateInputSystemByPackRetryRules, + CreateInputSystemByPackRetryRulesTypedDict, + CreateInputSystemByPackSortDirection, + CreateInputSystemByPackSubscription, + CreateInputSystemByPackSubscriptionTypedDict, + CreateInputSystemByPackTLSSettingsServerSide, + CreateInputSystemByPackTLSSettingsServerSideTypedDict, + CreateInputSystemByPackUNIXSocketPermissions, + CreateInputSystemByPackUNIXSocketPermissionsTypedDict, + CreateInputSystemByPackV3AuthenticationKeyType, + CreateInputSystemByPackV3PrivacyKeyType, + CreateInputSystemByPackV3User, + CreateInputSystemByPackV3UserTypedDict, + ) + from .createinputsystemhectokenbypackandidop import ( + CreateInputSystemHecTokenByPackAndIDRequest, + CreateInputSystemHecTokenByPackAndIDRequestTypedDict, + ) + from .createoutput_output import ( + CreateOutputOutput, + CreateOutputOutputDefault, + CreateOutputOutputDefaultType, + CreateOutputOutputDefaultTypedDict, + CreateOutputOutputTypedDict, CreateOutputOutputWebhookAuthenticationType1, CreateOutputOutputWebhookAuthenticationType2, CreateOutputOutputWebhookFormat1, - CreateOutputOutputWebhookFormat2, CreateOutputOutputWebhookPqControls1, CreateOutputOutputWebhookPqControls1TypedDict, CreateOutputOutputWebhookPqControls2, CreateOutputOutputWebhookPqControls2TypedDict, CreateOutputOutputWebhookType1, - CreateOutputOutputWebhookType2, CreateOutputOutputWebhookURL1, CreateOutputOutputWebhookURL1TypedDict, CreateOutputOutputWebhookURL2, @@ -1487,22 +1472,8 @@ CreateOutputOutputWebhookWebhook1TypedDict, CreateOutputOutputWebhookWebhook2, CreateOutputOutputWebhookWebhook2TypedDict, - CreateOutputOutputWizHec, - CreateOutputOutputWizHecPqControls, - CreateOutputOutputWizHecPqControlsTypedDict, - CreateOutputOutputWizHecType, - CreateOutputOutputWizHecTypedDict, - CreateOutputPayloadFormat, - CreateOutputPrefixOptional, - CreateOutputReportLevel, - CreateOutputReportMethod, - CreateOutputSendEventsAs, - CreateOutputTimestampFormat, - CreateOutputTimestampPrecision, - CreateOutputUDMType, - CreateOutputWriteAction, ) - from .createoutput_outputstatsdext_type import ( + from .createoutput_outputsns_pqcontrols import ( CreateOutputAISIEMEndpointPath, CreateOutputAuthentication, CreateOutputAuthenticationTypedDict, @@ -1574,6 +1545,11 @@ CreateOutputOutputDatabricks, CreateOutputOutputDatabricksType, CreateOutputOutputDatabricksTypedDict, + CreateOutputOutputDatabricksZerobus, + CreateOutputOutputDatabricksZerobusPqControls, + CreateOutputOutputDatabricksZerobusPqControlsTypedDict, + CreateOutputOutputDatabricksZerobusType, + CreateOutputOutputDatabricksZerobusTypedDict, CreateOutputOutputDatadog, CreateOutputOutputDatadogPqControls, CreateOutputOutputDatadogPqControlsTypedDict, @@ -1621,11 +1597,6 @@ CreateOutputOutputGrafanaCloudType2, CreateOutputOutputGrafanaCloudUnion, CreateOutputOutputGrafanaCloudUnionTypedDict, - CreateOutputOutputGraphite, - CreateOutputOutputGraphitePqControls, - CreateOutputOutputGraphitePqControlsTypedDict, - CreateOutputOutputGraphiteType, - CreateOutputOutputGraphiteTypedDict, CreateOutputOutputHumioHec, CreateOutputOutputHumioHecPqControls, CreateOutputOutputHumioHecPqControlsTypedDict, @@ -1673,9 +1644,6 @@ CreateOutputOutputRingDataFormat, CreateOutputOutputRingType, CreateOutputOutputRingTypedDict, - CreateOutputOutputRouter, - CreateOutputOutputRouterType, - CreateOutputOutputRouterTypedDict, CreateOutputOutputScalityS3, CreateOutputOutputScalityS3Type, CreateOutputOutputScalityS3TypedDict, @@ -1700,16 +1668,13 @@ CreateOutputOutputSnowflakeStreamingPqControlsTypedDict, CreateOutputOutputSnowflakeStreamingType, CreateOutputOutputSnowflakeStreamingTypedDict, - CreateOutputOutputSns, CreateOutputOutputSnsPqControls, CreateOutputOutputSnsPqControlsTypedDict, CreateOutputOutputSnsType, - CreateOutputOutputSnsTypedDict, CreateOutputOutputSqs, CreateOutputOutputSqsPqControls, CreateOutputOutputSqsPqControlsTypedDict, CreateOutputOutputSqsTypedDict, - CreateOutputOutputStatsdExtType, CreateOutputOutputStorjS3, CreateOutputOutputStorjS3Type, CreateOutputOutputStorjS3TypedDict, @@ -1719,6 +1684,12 @@ CreateOutputOutputSumoLogicPqControlsTypedDict, CreateOutputOutputSumoLogicType, CreateOutputOutputSumoLogicTypedDict, + CreateOutputOutputTraversalOtlp, + CreateOutputOutputTraversalOtlpAuthenticationType, + CreateOutputOutputTraversalOtlpPqControls, + CreateOutputOutputTraversalOtlpPqControlsTypedDict, + CreateOutputOutputTraversalOtlpType, + CreateOutputOutputTraversalOtlpTypedDict, CreateOutputOutputXsiam, CreateOutputOutputXsiamAuthenticationMethod, CreateOutputOutputXsiamPqControls, @@ -1731,250 +1702,247 @@ CreateOutputPrivateKeyTypedDict, CreateOutputQueueType, CreateOutputRegion, + CreateOutputSendAs, + CreateOutputSendLogsAs, + CreateOutputStatsDestination, + CreateOutputStatsDestinationTypedDict, + CreateOutputTelemetryType, + ) + from .createoutput_outputwebhook_format_2 import ( + CreateOutputAPIVersion, + CreateOutputAdditionalProperty, + CreateOutputAdditionalPropertyTypedDict, + CreateOutputAuthToken, + CreateOutputAuthTokenTypedDict, + CreateOutputAuthType, + CreateOutputBlobAccessTier, + CreateOutputCertificate, + CreateOutputCertificateTypedDict, + CreateOutputCompression, + CreateOutputElasticVersion, + CreateOutputEndpointConfiguration, + CreateOutputEventFormat, + CreateOutputExtentTag, + CreateOutputExtentTagTypedDict, + CreateOutputExtraLogType, + CreateOutputExtraLogTypeTypedDict, + CreateOutputFacility, + CreateOutputFieldName, + CreateOutputIndexerDiscoveryConfigs, + CreateOutputIndexerDiscoveryConfigsTypedDict, + CreateOutputIngestIfNotExist, + CreateOutputIngestIfNotExistTypedDict, + CreateOutputIngestionMode, + CreateOutputLogLocationType, + CreateOutputMessageFormat, + CreateOutputMetadatum, + CreateOutputMetadatumTypedDict, + CreateOutputOAuthSecretSource, + CreateOutputOutputAzureBlob, + CreateOutputOutputAzureBlobTypedDict, + CreateOutputOutputAzureDataExplorer, + CreateOutputOutputAzureDataExplorerAuthenticationMethod, + CreateOutputOutputAzureDataExplorerPqControls, + CreateOutputOutputAzureDataExplorerPqControlsTypedDict, + CreateOutputOutputAzureDataExplorerType, + CreateOutputOutputAzureDataExplorerTypedDict, + CreateOutputOutputAzureEventhub, + CreateOutputOutputAzureEventhubPqControls, + CreateOutputOutputAzureEventhubPqControlsTypedDict, + CreateOutputOutputAzureEventhubType, + CreateOutputOutputAzureEventhubTypedDict, + CreateOutputOutputAzureLogs, + CreateOutputOutputAzureLogsAuthenticationMethod, + CreateOutputOutputAzureLogsPqControls, + CreateOutputOutputAzureLogsPqControlsTypedDict, + CreateOutputOutputAzureLogsType, + CreateOutputOutputAzureLogsTypedDict, + CreateOutputOutputCloudwatch, + CreateOutputOutputCloudwatchPqControls, + CreateOutputOutputCloudwatchPqControlsTypedDict, + CreateOutputOutputCloudwatchType, + CreateOutputOutputCloudwatchTypedDict, + CreateOutputOutputConfluentCloud, + CreateOutputOutputConfluentCloudPqControls, + CreateOutputOutputConfluentCloudPqControlsTypedDict, + CreateOutputOutputConfluentCloudTypedDict, + CreateOutputOutputDevnull, + CreateOutputOutputDevnullType, + CreateOutputOutputDevnullTypedDict, + CreateOutputOutputElastic, + CreateOutputOutputElasticCloud, + CreateOutputOutputElasticCloudPqControls, + CreateOutputOutputElasticCloudPqControlsTypedDict, + CreateOutputOutputElasticCloudType, + CreateOutputOutputElasticCloudTypedDict, + CreateOutputOutputElasticPqControls, + CreateOutputOutputElasticPqControlsTypedDict, + CreateOutputOutputElasticType, + CreateOutputOutputElasticTypedDict, + CreateOutputOutputElasticURL, + CreateOutputOutputElasticURLTypedDict, + CreateOutputOutputExabeam, + CreateOutputOutputExabeamAuthenticationMethod, + CreateOutputOutputExabeamType, + CreateOutputOutputExabeamTypedDict, + CreateOutputOutputFilesystem, + CreateOutputOutputFilesystemType, + CreateOutputOutputFilesystemTypedDict, + CreateOutputOutputGoogleBigquery, + CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod, + CreateOutputOutputGoogleBigqueryPqControls, + CreateOutputOutputGoogleBigqueryPqControlsTypedDict, + CreateOutputOutputGoogleBigqueryType, + CreateOutputOutputGoogleBigqueryTypedDict, + CreateOutputOutputGoogleChronicle, + CreateOutputOutputGoogleChronicleAuthenticationMethod, + CreateOutputOutputGoogleChroniclePqControls, + CreateOutputOutputGoogleChroniclePqControlsTypedDict, + CreateOutputOutputGoogleChronicleType, + CreateOutputOutputGoogleChronicleTypedDict, + CreateOutputOutputGoogleCloudLogging, + CreateOutputOutputGoogleCloudLoggingPqControls, + CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict, + CreateOutputOutputGoogleCloudLoggingType, + CreateOutputOutputGoogleCloudLoggingTypedDict, + CreateOutputOutputGoogleCloudObservability, + CreateOutputOutputGoogleCloudObservabilityEndpoint, + CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod, + CreateOutputOutputGoogleCloudObservabilityOtlpVersion, + CreateOutputOutputGoogleCloudObservabilityPqControls, + CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict, + CreateOutputOutputGoogleCloudObservabilityProtocol, + CreateOutputOutputGoogleCloudObservabilityType, + CreateOutputOutputGoogleCloudObservabilityTypedDict, + CreateOutputOutputGoogleCloudStorage, + CreateOutputOutputGoogleCloudStorageAuthenticationMethod, + CreateOutputOutputGoogleCloudStorageType, + CreateOutputOutputGoogleCloudStorageTypedDict, + CreateOutputOutputGooglePubsub, + CreateOutputOutputGooglePubsubPqControls, + CreateOutputOutputGooglePubsubPqControlsTypedDict, + CreateOutputOutputGooglePubsubTypedDict, + CreateOutputOutputGraphite, + CreateOutputOutputGraphitePqControls, + CreateOutputOutputGraphitePqControlsTypedDict, + CreateOutputOutputGraphiteType, + CreateOutputOutputGraphiteTypedDict, + CreateOutputOutputHoneycomb, + CreateOutputOutputHoneycombPqControls, + CreateOutputOutputHoneycombPqControlsTypedDict, + CreateOutputOutputHoneycombType, + CreateOutputOutputHoneycombTypedDict, + CreateOutputOutputInfluxdb, + CreateOutputOutputInfluxdbAuthenticationType, + CreateOutputOutputInfluxdbPqControls, + CreateOutputOutputInfluxdbPqControlsTypedDict, + CreateOutputOutputInfluxdbType, + CreateOutputOutputInfluxdbTypedDict, + CreateOutputOutputKafka, + CreateOutputOutputKafkaPqControls, + CreateOutputOutputKafkaPqControlsTypedDict, + CreateOutputOutputKafkaTypedDict, + CreateOutputOutputKinesis, + CreateOutputOutputKinesisPqControls, + CreateOutputOutputKinesisPqControlsTypedDict, + CreateOutputOutputKinesisTypedDict, + CreateOutputOutputMinio, + CreateOutputOutputMinioType, + CreateOutputOutputMinioTypedDict, + CreateOutputOutputMsk, + CreateOutputOutputMskPqControls, + CreateOutputOutputMskPqControlsTypedDict, + CreateOutputOutputMskTypedDict, + CreateOutputOutputNewrelic, + CreateOutputOutputNewrelicEvents, + CreateOutputOutputNewrelicEventsPqControls, + CreateOutputOutputNewrelicEventsPqControlsTypedDict, + CreateOutputOutputNewrelicEventsType, + CreateOutputOutputNewrelicEventsTypedDict, + CreateOutputOutputNewrelicPqControls, + CreateOutputOutputNewrelicPqControlsTypedDict, + CreateOutputOutputNewrelicType, + CreateOutputOutputNewrelicTypedDict, + CreateOutputOutputRouter, + CreateOutputOutputRouterType, + CreateOutputOutputRouterTypedDict, + CreateOutputOutputS3, + CreateOutputOutputS3TypedDict, + CreateOutputOutputSentinel, + CreateOutputOutputSentinelFormat, + CreateOutputOutputSentinelPqControls, + CreateOutputOutputSentinelPqControlsTypedDict, + CreateOutputOutputSentinelType, + CreateOutputOutputSentinelTypedDict, + CreateOutputOutputSignalfx, + CreateOutputOutputSignalfxPqControls, + CreateOutputOutputSignalfxPqControlsTypedDict, + CreateOutputOutputSignalfxType, + CreateOutputOutputSignalfxTypedDict, + CreateOutputOutputSns, + CreateOutputOutputSnsTypedDict, + CreateOutputOutputSplunk, + CreateOutputOutputSplunkHec, + CreateOutputOutputSplunkHecPqControls, + CreateOutputOutputSplunkHecPqControlsTypedDict, + CreateOutputOutputSplunkHecType, + CreateOutputOutputSplunkHecTypedDict, + CreateOutputOutputSplunkHecURL, + CreateOutputOutputSplunkHecURLTypedDict, + CreateOutputOutputSplunkLb, + CreateOutputOutputSplunkLbPqControls, + CreateOutputOutputSplunkLbPqControlsTypedDict, + CreateOutputOutputSplunkLbType, + CreateOutputOutputSplunkLbTypedDict, + CreateOutputOutputSplunkPqControls, + CreateOutputOutputSplunkPqControlsTypedDict, + CreateOutputOutputSplunkTypedDict, + CreateOutputOutputStatsd, + CreateOutputOutputStatsdExt, + CreateOutputOutputStatsdExtPqControls, + CreateOutputOutputStatsdExtPqControlsTypedDict, + CreateOutputOutputStatsdExtType, + CreateOutputOutputStatsdExtTypedDict, + CreateOutputOutputStatsdPqControls, + CreateOutputOutputStatsdPqControlsTypedDict, + CreateOutputOutputStatsdType, + CreateOutputOutputStatsdTypedDict, + CreateOutputOutputSyslog, + CreateOutputOutputSyslogPqControls, + CreateOutputOutputSyslogPqControlsTypedDict, + CreateOutputOutputSyslogProtocol, + CreateOutputOutputSyslogSeverity, + CreateOutputOutputSyslogTypedDict, + CreateOutputOutputTcpjson, + CreateOutputOutputTcpjsonPqControls, + CreateOutputOutputTcpjsonPqControlsTypedDict, + CreateOutputOutputTcpjsonTypedDict, + CreateOutputOutputWavefront, + CreateOutputOutputWavefrontPqControls, + CreateOutputOutputWavefrontPqControlsTypedDict, + CreateOutputOutputWavefrontType, + CreateOutputOutputWavefrontTypedDict, + CreateOutputOutputWebhookFormat2, + CreateOutputOutputWebhookType2, + CreateOutputOutputWizHec, + CreateOutputOutputWizHecPqControls, + CreateOutputOutputWizHecPqControlsTypedDict, + CreateOutputOutputWizHecType, + CreateOutputOutputWizHecTypedDict, + CreateOutputPayloadFormat, + CreateOutputPrefixOptional, + CreateOutputReportLevel, + CreateOutputReportMethod, CreateOutputRule, CreateOutputRuleTypedDict, - CreateOutputSendLogsAs, - CreateOutputStatsDestination, - CreateOutputStatsDestinationTypedDict, - CreateOutputTelemetryType, - ) - from .createoutputsystembypack_outputdefault_type import ( - CreateOutputSystemByPackAPIVersion, - CreateOutputSystemByPackAdditionalProperty, - CreateOutputSystemByPackAdditionalPropertyTypedDict, - CreateOutputSystemByPackAuthToken, - CreateOutputSystemByPackAuthTokenTypedDict, - CreateOutputSystemByPackAuthType, - CreateOutputSystemByPackBlobAccessTier, - CreateOutputSystemByPackCertificate, - CreateOutputSystemByPackCertificateTypedDict, - CreateOutputSystemByPackCompression, - CreateOutputSystemByPackElasticVersion, - CreateOutputSystemByPackEndpointConfiguration, - CreateOutputSystemByPackExtentTag, - CreateOutputSystemByPackExtentTagTypedDict, - CreateOutputSystemByPackExtraLogType, - CreateOutputSystemByPackExtraLogTypeTypedDict, - CreateOutputSystemByPackFacility, - CreateOutputSystemByPackFieldName, - CreateOutputSystemByPackIndexerDiscoveryConfigs, - CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict, - CreateOutputSystemByPackIngestIfNotExist, - CreateOutputSystemByPackIngestIfNotExistTypedDict, - CreateOutputSystemByPackIngestionMode, - CreateOutputSystemByPackLogLocationType, - CreateOutputSystemByPackMessageFormat, - CreateOutputSystemByPackMetadatum, - CreateOutputSystemByPackMetadatumTypedDict, - CreateOutputSystemByPackOutputAzureBlob, - CreateOutputSystemByPackOutputAzureBlobTypedDict, - CreateOutputSystemByPackOutputAzureDataExplorer, - CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod, - CreateOutputSystemByPackOutputAzureDataExplorerPqControls, - CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict, - CreateOutputSystemByPackOutputAzureDataExplorerType, - CreateOutputSystemByPackOutputAzureDataExplorerTypedDict, - CreateOutputSystemByPackOutputAzureEventhub, - CreateOutputSystemByPackOutputAzureEventhubPqControls, - CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict, - CreateOutputSystemByPackOutputAzureEventhubType, - CreateOutputSystemByPackOutputAzureEventhubTypedDict, - CreateOutputSystemByPackOutputAzureLogs, - CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod, - CreateOutputSystemByPackOutputAzureLogsPqControls, - CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict, - CreateOutputSystemByPackOutputAzureLogsType, - CreateOutputSystemByPackOutputAzureLogsTypedDict, - CreateOutputSystemByPackOutputCloudwatch, - CreateOutputSystemByPackOutputCloudwatchPqControls, - CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict, - CreateOutputSystemByPackOutputCloudwatchType, - CreateOutputSystemByPackOutputCloudwatchTypedDict, - CreateOutputSystemByPackOutputConfluentCloud, - CreateOutputSystemByPackOutputConfluentCloudPqControls, - CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict, - CreateOutputSystemByPackOutputConfluentCloudTypedDict, - CreateOutputSystemByPackOutputDefaultType, - CreateOutputSystemByPackOutputDevnull, - CreateOutputSystemByPackOutputDevnullType, - CreateOutputSystemByPackOutputDevnullTypedDict, - CreateOutputSystemByPackOutputElastic, - CreateOutputSystemByPackOutputElasticCloud, - CreateOutputSystemByPackOutputElasticCloudPqControls, - CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict, - CreateOutputSystemByPackOutputElasticCloudType, - CreateOutputSystemByPackOutputElasticCloudTypedDict, - CreateOutputSystemByPackOutputElasticPqControls, - CreateOutputSystemByPackOutputElasticPqControlsTypedDict, - CreateOutputSystemByPackOutputElasticType, - CreateOutputSystemByPackOutputElasticTypedDict, - CreateOutputSystemByPackOutputElasticURL, - CreateOutputSystemByPackOutputElasticURLTypedDict, - CreateOutputSystemByPackOutputExabeam, - CreateOutputSystemByPackOutputExabeamType, - CreateOutputSystemByPackOutputExabeamTypedDict, - CreateOutputSystemByPackOutputFilesystem, - CreateOutputSystemByPackOutputFilesystemType, - CreateOutputSystemByPackOutputFilesystemTypedDict, - CreateOutputSystemByPackOutputGoogleBigquery, - CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod, - CreateOutputSystemByPackOutputGoogleBigqueryPqControls, - CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict, - CreateOutputSystemByPackOutputGoogleBigqueryType, - CreateOutputSystemByPackOutputGoogleBigqueryTypedDict, - CreateOutputSystemByPackOutputGoogleChronicle, - CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod, - CreateOutputSystemByPackOutputGoogleChroniclePqControls, - CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict, - CreateOutputSystemByPackOutputGoogleChronicleType, - CreateOutputSystemByPackOutputGoogleChronicleTypedDict, - CreateOutputSystemByPackOutputGoogleCloudLogging, - CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls, - CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict, - CreateOutputSystemByPackOutputGoogleCloudLoggingType, - CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict, - CreateOutputSystemByPackOutputGoogleCloudObservability, - CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint, - CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod, - CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion, - CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls, - CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict, - CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol, - CreateOutputSystemByPackOutputGoogleCloudObservabilityType, - CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict, - CreateOutputSystemByPackOutputGoogleCloudStorage, - CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod, - CreateOutputSystemByPackOutputGoogleCloudStorageType, - CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict, - CreateOutputSystemByPackOutputGooglePubsub, - CreateOutputSystemByPackOutputGooglePubsubPqControls, - CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict, - CreateOutputSystemByPackOutputGooglePubsubTypedDict, - CreateOutputSystemByPackOutputHoneycomb, - CreateOutputSystemByPackOutputHoneycombPqControls, - CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict, - CreateOutputSystemByPackOutputHoneycombType, - CreateOutputSystemByPackOutputHoneycombTypedDict, - CreateOutputSystemByPackOutputInfluxdb, - CreateOutputSystemByPackOutputInfluxdbAuthenticationType, - CreateOutputSystemByPackOutputInfluxdbPqControls, - CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict, - CreateOutputSystemByPackOutputInfluxdbType, - CreateOutputSystemByPackOutputInfluxdbTypedDict, - CreateOutputSystemByPackOutputKafka, - CreateOutputSystemByPackOutputKafkaPqControls, - CreateOutputSystemByPackOutputKafkaPqControlsTypedDict, - CreateOutputSystemByPackOutputKafkaTypedDict, - CreateOutputSystemByPackOutputKinesis, - CreateOutputSystemByPackOutputKinesisPqControls, - CreateOutputSystemByPackOutputKinesisPqControlsTypedDict, - CreateOutputSystemByPackOutputKinesisTypedDict, - CreateOutputSystemByPackOutputMinio, - CreateOutputSystemByPackOutputMinioType, - CreateOutputSystemByPackOutputMinioTypedDict, - CreateOutputSystemByPackOutputMsk, - CreateOutputSystemByPackOutputMskPqControls, - CreateOutputSystemByPackOutputMskPqControlsTypedDict, - CreateOutputSystemByPackOutputMskTypedDict, - CreateOutputSystemByPackOutputNewrelic, - CreateOutputSystemByPackOutputNewrelicEvents, - CreateOutputSystemByPackOutputNewrelicEventsPqControls, - CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict, - CreateOutputSystemByPackOutputNewrelicEventsType, - CreateOutputSystemByPackOutputNewrelicEventsTypedDict, - CreateOutputSystemByPackOutputNewrelicPqControls, - CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict, - CreateOutputSystemByPackOutputNewrelicType, - CreateOutputSystemByPackOutputNewrelicTypedDict, - CreateOutputSystemByPackOutputS3, - CreateOutputSystemByPackOutputS3TypedDict, - CreateOutputSystemByPackOutputSentinel, - CreateOutputSystemByPackOutputSentinelFormat, - CreateOutputSystemByPackOutputSentinelPqControls, - CreateOutputSystemByPackOutputSentinelPqControlsTypedDict, - CreateOutputSystemByPackOutputSentinelType, - CreateOutputSystemByPackOutputSentinelTypedDict, - CreateOutputSystemByPackOutputSignalfx, - CreateOutputSystemByPackOutputSignalfxPqControls, - CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict, - CreateOutputSystemByPackOutputSignalfxType, - CreateOutputSystemByPackOutputSignalfxTypedDict, - CreateOutputSystemByPackOutputSplunk, - CreateOutputSystemByPackOutputSplunkHec, - CreateOutputSystemByPackOutputSplunkHecPqControls, - CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict, - CreateOutputSystemByPackOutputSplunkHecType, - CreateOutputSystemByPackOutputSplunkHecTypedDict, - CreateOutputSystemByPackOutputSplunkHecURL, - CreateOutputSystemByPackOutputSplunkHecURLTypedDict, - CreateOutputSystemByPackOutputSplunkLb, - CreateOutputSystemByPackOutputSplunkLbPqControls, - CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict, - CreateOutputSystemByPackOutputSplunkLbType, - CreateOutputSystemByPackOutputSplunkLbTypedDict, - CreateOutputSystemByPackOutputSplunkPqControls, - CreateOutputSystemByPackOutputSplunkPqControlsTypedDict, - CreateOutputSystemByPackOutputSplunkTypedDict, - CreateOutputSystemByPackOutputStatsd, - CreateOutputSystemByPackOutputStatsdExt, - CreateOutputSystemByPackOutputStatsdExtPqControls, - CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict, - CreateOutputSystemByPackOutputStatsdExtTypedDict, - CreateOutputSystemByPackOutputStatsdPqControls, - CreateOutputSystemByPackOutputStatsdPqControlsTypedDict, - CreateOutputSystemByPackOutputStatsdType, - CreateOutputSystemByPackOutputStatsdTypedDict, - CreateOutputSystemByPackOutputSyslog, - CreateOutputSystemByPackOutputSyslogPqControls, - CreateOutputSystemByPackOutputSyslogPqControlsTypedDict, - CreateOutputSystemByPackOutputSyslogProtocol, - CreateOutputSystemByPackOutputSyslogSeverity, - CreateOutputSystemByPackOutputSyslogTypedDict, - CreateOutputSystemByPackOutputTcpjson, - CreateOutputSystemByPackOutputTcpjsonPqControls, - CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict, - CreateOutputSystemByPackOutputTcpjsonTypedDict, - CreateOutputSystemByPackOutputWavefront, - CreateOutputSystemByPackOutputWavefrontPqControls, - CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict, - CreateOutputSystemByPackOutputWavefrontType, - CreateOutputSystemByPackOutputWavefrontTypedDict, - CreateOutputSystemByPackOutputWebhookAuthenticationType1, - CreateOutputSystemByPackOutputWebhookAuthenticationType2, - CreateOutputSystemByPackOutputWebhookFormat1, - CreateOutputSystemByPackOutputWebhookFormat2, - CreateOutputSystemByPackOutputWebhookPqControls1, - CreateOutputSystemByPackOutputWebhookPqControls1TypedDict, - CreateOutputSystemByPackOutputWebhookPqControls2, - CreateOutputSystemByPackOutputWebhookPqControls2TypedDict, - CreateOutputSystemByPackOutputWebhookType1, - CreateOutputSystemByPackOutputWebhookType2, - CreateOutputSystemByPackOutputWebhookURL1, - CreateOutputSystemByPackOutputWebhookURL1TypedDict, - CreateOutputSystemByPackOutputWebhookURL2, - CreateOutputSystemByPackOutputWebhookURL2TypedDict, - CreateOutputSystemByPackOutputWebhookUnion, - CreateOutputSystemByPackOutputWebhookUnionTypedDict, - CreateOutputSystemByPackOutputWebhookWebhook1, - CreateOutputSystemByPackOutputWebhookWebhook1TypedDict, - CreateOutputSystemByPackOutputWebhookWebhook2, - CreateOutputSystemByPackOutputWebhookWebhook2TypedDict, - CreateOutputSystemByPackOutputWizHec, - CreateOutputSystemByPackOutputWizHecPqControls, - CreateOutputSystemByPackOutputWizHecPqControlsTypedDict, - CreateOutputSystemByPackOutputWizHecType, - CreateOutputSystemByPackOutputWizHecTypedDict, - CreateOutputSystemByPackPayloadFormat, - CreateOutputSystemByPackPrefixOptional, - CreateOutputSystemByPackReportLevel, - CreateOutputSystemByPackReportMethod, - CreateOutputSystemByPackSendEventsAs, - CreateOutputSystemByPackTimestampFormat, - CreateOutputSystemByPackTimestampPrecision, - CreateOutputSystemByPackUDMType, - CreateOutputSystemByPackWriteAction, + CreateOutputSendEventsAs, + CreateOutputTimestampFormat, + CreateOutputTimestampPrecision, + CreateOutputUDMType, + CreateOutputWizDefendSourceType, + CreateOutputWriteAction, ) - from .createoutputsystembypack_outputstatsdext_type import ( + from .createoutputsystembypack_outputsns_pqcontrols import ( CreateOutputSystemByPackAISIEMEndpointPath, CreateOutputSystemByPackAuthentication, CreateOutputSystemByPackAuthenticationTypedDict, @@ -2046,6 +2014,11 @@ CreateOutputSystemByPackOutputDatabricks, CreateOutputSystemByPackOutputDatabricksType, CreateOutputSystemByPackOutputDatabricksTypedDict, + CreateOutputSystemByPackOutputDatabricksZerobus, + CreateOutputSystemByPackOutputDatabricksZerobusPqControls, + CreateOutputSystemByPackOutputDatabricksZerobusPqControlsTypedDict, + CreateOutputSystemByPackOutputDatabricksZerobusType, + CreateOutputSystemByPackOutputDatabricksZerobusTypedDict, CreateOutputSystemByPackOutputDatadog, CreateOutputSystemByPackOutputDatadogPqControls, CreateOutputSystemByPackOutputDatadogPqControlsTypedDict, @@ -2093,11 +2066,6 @@ CreateOutputSystemByPackOutputGrafanaCloudType2, CreateOutputSystemByPackOutputGrafanaCloudUnion, CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict, - CreateOutputSystemByPackOutputGraphite, - CreateOutputSystemByPackOutputGraphitePqControls, - CreateOutputSystemByPackOutputGraphitePqControlsTypedDict, - CreateOutputSystemByPackOutputGraphiteType, - CreateOutputSystemByPackOutputGraphiteTypedDict, CreateOutputSystemByPackOutputHumioHec, CreateOutputSystemByPackOutputHumioHecPqControls, CreateOutputSystemByPackOutputHumioHecPqControlsTypedDict, @@ -2144,10 +2112,7 @@ CreateOutputSystemByPackOutputRing, CreateOutputSystemByPackOutputRingDataFormat, CreateOutputSystemByPackOutputRingType, - CreateOutputSystemByPackOutputRingTypedDict, - CreateOutputSystemByPackOutputRouter, - CreateOutputSystemByPackOutputRouterType, - CreateOutputSystemByPackOutputRouterTypedDict, + CreateOutputSystemByPackOutputRingTypedDict, CreateOutputSystemByPackOutputScalityS3, CreateOutputSystemByPackOutputScalityS3Type, CreateOutputSystemByPackOutputScalityS3TypedDict, @@ -2172,16 +2137,13 @@ CreateOutputSystemByPackOutputSnowflakeStreamingPqControlsTypedDict, CreateOutputSystemByPackOutputSnowflakeStreamingType, CreateOutputSystemByPackOutputSnowflakeStreamingTypedDict, - CreateOutputSystemByPackOutputSns, CreateOutputSystemByPackOutputSnsPqControls, CreateOutputSystemByPackOutputSnsPqControlsTypedDict, CreateOutputSystemByPackOutputSnsType, - CreateOutputSystemByPackOutputSnsTypedDict, CreateOutputSystemByPackOutputSqs, CreateOutputSystemByPackOutputSqsPqControls, CreateOutputSystemByPackOutputSqsPqControlsTypedDict, CreateOutputSystemByPackOutputSqsTypedDict, - CreateOutputSystemByPackOutputStatsdExtType, CreateOutputSystemByPackOutputStorjS3, CreateOutputSystemByPackOutputStorjS3Type, CreateOutputSystemByPackOutputStorjS3TypedDict, @@ -2191,6 +2153,12 @@ CreateOutputSystemByPackOutputSumoLogicPqControlsTypedDict, CreateOutputSystemByPackOutputSumoLogicType, CreateOutputSystemByPackOutputSumoLogicTypedDict, + CreateOutputSystemByPackOutputTraversalOtlp, + CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType, + CreateOutputSystemByPackOutputTraversalOtlpPqControls, + CreateOutputSystemByPackOutputTraversalOtlpPqControlsTypedDict, + CreateOutputSystemByPackOutputTraversalOtlpType, + CreateOutputSystemByPackOutputTraversalOtlpTypedDict, CreateOutputSystemByPackOutputXsiam, CreateOutputSystemByPackOutputXsiamAuthenticationMethod, CreateOutputSystemByPackOutputXsiamPqControls, @@ -2203,18 +2171,270 @@ CreateOutputSystemByPackPrivateKeyTypedDict, CreateOutputSystemByPackQueueType, CreateOutputSystemByPackRegion, - CreateOutputSystemByPackRule, - CreateOutputSystemByPackRuleTypedDict, + CreateOutputSystemByPackSendAs, CreateOutputSystemByPackSendLogsAs, CreateOutputSystemByPackStatsDestination, CreateOutputSystemByPackStatsDestinationTypedDict, CreateOutputSystemByPackTelemetryType, ) + from .createoutputsystembypack_outputwebhook_format_2 import ( + CreateOutputSystemByPackAPIVersion, + CreateOutputSystemByPackAdditionalProperty, + CreateOutputSystemByPackAdditionalPropertyTypedDict, + CreateOutputSystemByPackAuthToken, + CreateOutputSystemByPackAuthTokenTypedDict, + CreateOutputSystemByPackAuthType, + CreateOutputSystemByPackBlobAccessTier, + CreateOutputSystemByPackCertificate, + CreateOutputSystemByPackCertificateTypedDict, + CreateOutputSystemByPackCompression, + CreateOutputSystemByPackElasticVersion, + CreateOutputSystemByPackEndpointConfiguration, + CreateOutputSystemByPackEventFormat, + CreateOutputSystemByPackExtentTag, + CreateOutputSystemByPackExtentTagTypedDict, + CreateOutputSystemByPackExtraLogType, + CreateOutputSystemByPackExtraLogTypeTypedDict, + CreateOutputSystemByPackFacility, + CreateOutputSystemByPackFieldName, + CreateOutputSystemByPackIndexerDiscoveryConfigs, + CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict, + CreateOutputSystemByPackIngestIfNotExist, + CreateOutputSystemByPackIngestIfNotExistTypedDict, + CreateOutputSystemByPackIngestionMode, + CreateOutputSystemByPackLogLocationType, + CreateOutputSystemByPackMessageFormat, + CreateOutputSystemByPackMetadatum, + CreateOutputSystemByPackMetadatumTypedDict, + CreateOutputSystemByPackOAuthSecretSource, + CreateOutputSystemByPackOutputAzureBlob, + CreateOutputSystemByPackOutputAzureBlobTypedDict, + CreateOutputSystemByPackOutputAzureDataExplorer, + CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod, + CreateOutputSystemByPackOutputAzureDataExplorerPqControls, + CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict, + CreateOutputSystemByPackOutputAzureDataExplorerType, + CreateOutputSystemByPackOutputAzureDataExplorerTypedDict, + CreateOutputSystemByPackOutputAzureEventhub, + CreateOutputSystemByPackOutputAzureEventhubPqControls, + CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict, + CreateOutputSystemByPackOutputAzureEventhubType, + CreateOutputSystemByPackOutputAzureEventhubTypedDict, + CreateOutputSystemByPackOutputAzureLogs, + CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod, + CreateOutputSystemByPackOutputAzureLogsPqControls, + CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict, + CreateOutputSystemByPackOutputAzureLogsType, + CreateOutputSystemByPackOutputAzureLogsTypedDict, + CreateOutputSystemByPackOutputCloudwatch, + CreateOutputSystemByPackOutputCloudwatchPqControls, + CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict, + CreateOutputSystemByPackOutputCloudwatchType, + CreateOutputSystemByPackOutputCloudwatchTypedDict, + CreateOutputSystemByPackOutputConfluentCloud, + CreateOutputSystemByPackOutputConfluentCloudPqControls, + CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict, + CreateOutputSystemByPackOutputConfluentCloudTypedDict, + CreateOutputSystemByPackOutputDevnull, + CreateOutputSystemByPackOutputDevnullType, + CreateOutputSystemByPackOutputDevnullTypedDict, + CreateOutputSystemByPackOutputElastic, + CreateOutputSystemByPackOutputElasticCloud, + CreateOutputSystemByPackOutputElasticCloudPqControls, + CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict, + CreateOutputSystemByPackOutputElasticCloudType, + CreateOutputSystemByPackOutputElasticCloudTypedDict, + CreateOutputSystemByPackOutputElasticPqControls, + CreateOutputSystemByPackOutputElasticPqControlsTypedDict, + CreateOutputSystemByPackOutputElasticType, + CreateOutputSystemByPackOutputElasticTypedDict, + CreateOutputSystemByPackOutputElasticURL, + CreateOutputSystemByPackOutputElasticURLTypedDict, + CreateOutputSystemByPackOutputExabeam, + CreateOutputSystemByPackOutputExabeamAuthenticationMethod, + CreateOutputSystemByPackOutputExabeamType, + CreateOutputSystemByPackOutputExabeamTypedDict, + CreateOutputSystemByPackOutputFilesystem, + CreateOutputSystemByPackOutputFilesystemType, + CreateOutputSystemByPackOutputFilesystemTypedDict, + CreateOutputSystemByPackOutputGoogleBigquery, + CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod, + CreateOutputSystemByPackOutputGoogleBigqueryPqControls, + CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict, + CreateOutputSystemByPackOutputGoogleBigqueryType, + CreateOutputSystemByPackOutputGoogleBigqueryTypedDict, + CreateOutputSystemByPackOutputGoogleChronicle, + CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod, + CreateOutputSystemByPackOutputGoogleChroniclePqControls, + CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict, + CreateOutputSystemByPackOutputGoogleChronicleType, + CreateOutputSystemByPackOutputGoogleChronicleTypedDict, + CreateOutputSystemByPackOutputGoogleCloudLogging, + CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls, + CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict, + CreateOutputSystemByPackOutputGoogleCloudLoggingType, + CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict, + CreateOutputSystemByPackOutputGoogleCloudObservability, + CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint, + CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod, + CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion, + CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls, + CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict, + CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol, + CreateOutputSystemByPackOutputGoogleCloudObservabilityType, + CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict, + CreateOutputSystemByPackOutputGoogleCloudStorage, + CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod, + CreateOutputSystemByPackOutputGoogleCloudStorageType, + CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict, + CreateOutputSystemByPackOutputGooglePubsub, + CreateOutputSystemByPackOutputGooglePubsubPqControls, + CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict, + CreateOutputSystemByPackOutputGooglePubsubTypedDict, + CreateOutputSystemByPackOutputGraphite, + CreateOutputSystemByPackOutputGraphitePqControls, + CreateOutputSystemByPackOutputGraphitePqControlsTypedDict, + CreateOutputSystemByPackOutputGraphiteType, + CreateOutputSystemByPackOutputGraphiteTypedDict, + CreateOutputSystemByPackOutputHoneycomb, + CreateOutputSystemByPackOutputHoneycombPqControls, + CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict, + CreateOutputSystemByPackOutputHoneycombType, + CreateOutputSystemByPackOutputHoneycombTypedDict, + CreateOutputSystemByPackOutputInfluxdb, + CreateOutputSystemByPackOutputInfluxdbAuthenticationType, + CreateOutputSystemByPackOutputInfluxdbPqControls, + CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict, + CreateOutputSystemByPackOutputInfluxdbType, + CreateOutputSystemByPackOutputInfluxdbTypedDict, + CreateOutputSystemByPackOutputKafka, + CreateOutputSystemByPackOutputKafkaPqControls, + CreateOutputSystemByPackOutputKafkaPqControlsTypedDict, + CreateOutputSystemByPackOutputKafkaTypedDict, + CreateOutputSystemByPackOutputKinesis, + CreateOutputSystemByPackOutputKinesisPqControls, + CreateOutputSystemByPackOutputKinesisPqControlsTypedDict, + CreateOutputSystemByPackOutputKinesisTypedDict, + CreateOutputSystemByPackOutputMinio, + CreateOutputSystemByPackOutputMinioType, + CreateOutputSystemByPackOutputMinioTypedDict, + CreateOutputSystemByPackOutputMsk, + CreateOutputSystemByPackOutputMskPqControls, + CreateOutputSystemByPackOutputMskPqControlsTypedDict, + CreateOutputSystemByPackOutputMskTypedDict, + CreateOutputSystemByPackOutputNewrelic, + CreateOutputSystemByPackOutputNewrelicEvents, + CreateOutputSystemByPackOutputNewrelicEventsPqControls, + CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict, + CreateOutputSystemByPackOutputNewrelicEventsType, + CreateOutputSystemByPackOutputNewrelicEventsTypedDict, + CreateOutputSystemByPackOutputNewrelicPqControls, + CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict, + CreateOutputSystemByPackOutputNewrelicType, + CreateOutputSystemByPackOutputNewrelicTypedDict, + CreateOutputSystemByPackOutputRouter, + CreateOutputSystemByPackOutputRouterType, + CreateOutputSystemByPackOutputRouterTypedDict, + CreateOutputSystemByPackOutputS3, + CreateOutputSystemByPackOutputS3TypedDict, + CreateOutputSystemByPackOutputSentinel, + CreateOutputSystemByPackOutputSentinelFormat, + CreateOutputSystemByPackOutputSentinelPqControls, + CreateOutputSystemByPackOutputSentinelPqControlsTypedDict, + CreateOutputSystemByPackOutputSentinelType, + CreateOutputSystemByPackOutputSentinelTypedDict, + CreateOutputSystemByPackOutputSignalfx, + CreateOutputSystemByPackOutputSignalfxPqControls, + CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict, + CreateOutputSystemByPackOutputSignalfxType, + CreateOutputSystemByPackOutputSignalfxTypedDict, + CreateOutputSystemByPackOutputSns, + CreateOutputSystemByPackOutputSnsTypedDict, + CreateOutputSystemByPackOutputSplunk, + CreateOutputSystemByPackOutputSplunkHec, + CreateOutputSystemByPackOutputSplunkHecPqControls, + CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict, + CreateOutputSystemByPackOutputSplunkHecType, + CreateOutputSystemByPackOutputSplunkHecTypedDict, + CreateOutputSystemByPackOutputSplunkHecURL, + CreateOutputSystemByPackOutputSplunkHecURLTypedDict, + CreateOutputSystemByPackOutputSplunkLb, + CreateOutputSystemByPackOutputSplunkLbPqControls, + CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict, + CreateOutputSystemByPackOutputSplunkLbType, + CreateOutputSystemByPackOutputSplunkLbTypedDict, + CreateOutputSystemByPackOutputSplunkPqControls, + CreateOutputSystemByPackOutputSplunkPqControlsTypedDict, + CreateOutputSystemByPackOutputSplunkTypedDict, + CreateOutputSystemByPackOutputStatsd, + CreateOutputSystemByPackOutputStatsdExt, + CreateOutputSystemByPackOutputStatsdExtPqControls, + CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict, + CreateOutputSystemByPackOutputStatsdExtType, + CreateOutputSystemByPackOutputStatsdExtTypedDict, + CreateOutputSystemByPackOutputStatsdPqControls, + CreateOutputSystemByPackOutputStatsdPqControlsTypedDict, + CreateOutputSystemByPackOutputStatsdType, + CreateOutputSystemByPackOutputStatsdTypedDict, + CreateOutputSystemByPackOutputSyslog, + CreateOutputSystemByPackOutputSyslogPqControls, + CreateOutputSystemByPackOutputSyslogPqControlsTypedDict, + CreateOutputSystemByPackOutputSyslogProtocol, + CreateOutputSystemByPackOutputSyslogSeverity, + CreateOutputSystemByPackOutputSyslogTypedDict, + CreateOutputSystemByPackOutputTcpjson, + CreateOutputSystemByPackOutputTcpjsonPqControls, + CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict, + CreateOutputSystemByPackOutputTcpjsonTypedDict, + CreateOutputSystemByPackOutputWavefront, + CreateOutputSystemByPackOutputWavefrontPqControls, + CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict, + CreateOutputSystemByPackOutputWavefrontType, + CreateOutputSystemByPackOutputWavefrontTypedDict, + CreateOutputSystemByPackOutputWebhookFormat2, + CreateOutputSystemByPackOutputWebhookType2, + CreateOutputSystemByPackOutputWizHec, + CreateOutputSystemByPackOutputWizHecPqControls, + CreateOutputSystemByPackOutputWizHecPqControlsTypedDict, + CreateOutputSystemByPackOutputWizHecType, + CreateOutputSystemByPackOutputWizHecTypedDict, + CreateOutputSystemByPackPayloadFormat, + CreateOutputSystemByPackPrefixOptional, + CreateOutputSystemByPackReportLevel, + CreateOutputSystemByPackReportMethod, + CreateOutputSystemByPackRule, + CreateOutputSystemByPackRuleTypedDict, + CreateOutputSystemByPackSendEventsAs, + CreateOutputSystemByPackTimestampFormat, + CreateOutputSystemByPackTimestampPrecision, + CreateOutputSystemByPackUDMType, + CreateOutputSystemByPackWizDefendSourceType, + CreateOutputSystemByPackWriteAction, + ) from .createoutputsystembypack_request import ( CreateOutputSystemByPackOutput, CreateOutputSystemByPackOutputDefault, + CreateOutputSystemByPackOutputDefaultType, CreateOutputSystemByPackOutputDefaultTypedDict, CreateOutputSystemByPackOutputTypedDict, + CreateOutputSystemByPackOutputWebhookAuthenticationType1, + CreateOutputSystemByPackOutputWebhookAuthenticationType2, + CreateOutputSystemByPackOutputWebhookFormat1, + CreateOutputSystemByPackOutputWebhookPqControls1, + CreateOutputSystemByPackOutputWebhookPqControls1TypedDict, + CreateOutputSystemByPackOutputWebhookPqControls2, + CreateOutputSystemByPackOutputWebhookPqControls2TypedDict, + CreateOutputSystemByPackOutputWebhookType1, + CreateOutputSystemByPackOutputWebhookURL1, + CreateOutputSystemByPackOutputWebhookURL1TypedDict, + CreateOutputSystemByPackOutputWebhookURL2, + CreateOutputSystemByPackOutputWebhookURL2TypedDict, + CreateOutputSystemByPackOutputWebhookUnion, + CreateOutputSystemByPackOutputWebhookUnionTypedDict, + CreateOutputSystemByPackOutputWebhookWebhook1, + CreateOutputSystemByPackOutputWebhookWebhook1TypedDict, + CreateOutputSystemByPackOutputWebhookWebhook2, + CreateOutputSystemByPackOutputWebhookWebhook2TypedDict, CreateOutputSystemByPackRequest, CreateOutputSystemByPackRequestTypedDict, ) @@ -2396,6 +2616,7 @@ DistributedSummaryWorkers, DistributedSummaryWorkersTypedDict, ) + from .emailrecipient import EmailRecipient, EmailRecipientTypedDict from .emptyobject import EmptyObject, EmptyObjectTypedDict from .estimatedingestrateoptionsconfiggroup import ( EstimatedIngestRateOptionsConfigGroup, @@ -2403,10 +2624,6 @@ from .eventbreakertypeoptionseventbreakerexistingornewnew import ( EventBreakerTypeOptionsEventBreakerExistingOrNewNew, ) - from .executorspecificsettingstyperunnablejobexecutorexecutor import ( - ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor, - ExecutorSpecificSettingsTypeRunnableJobExecutorExecutorTypedDict, - ) from .executortyperunnablejobexecutor import ( ExecutorTypeRunnableJobExecutor, ExecutorTypeRunnableJobExecutorTypedDict, @@ -2483,6 +2700,19 @@ FunctionConfSchemaComment, FunctionConfSchemaCommentTypedDict, ) + from .functionconfschemadetectionrules import ( + Confidence, + FieldOverride, + FieldOverrideTypedDict, + FunctionConfSchemaDetectionRules, + FunctionConfSchemaDetectionRulesSeverity, + FunctionConfSchemaDetectionRulesTypedDict, + Impact, + InlineRule, + InlineRuleTypedDict, + LocalOverrides, + LocalOverridesTypedDict, + ) from .functionconfschemadnslookup import ( DNSLookupField, DNSLookupFieldTypedDict, @@ -2519,6 +2749,10 @@ FunctionConfSchemaGenStats, FunctionConfSchemaGenStatsTypedDict, ) + from .functionconfschemalakehouseenginemetricsnormalizer import ( + FunctionConfSchemaLakehouseEngineMetricsNormalizer, + FunctionConfSchemaLakehouseEngineMetricsNormalizerTypedDict, + ) from .functionconfschemalimit import ( FunctionConfSchemaLimit, FunctionConfSchemaLimitTypedDict, @@ -2546,10 +2780,16 @@ FunctionConfSchemaLocalSearchTransformer, FunctionConfSchemaLocalSearchTransformerTypedDict, ) + from .functionconfschemametricstimerangegate import ( + FunctionConfSchemaMetricsTimeRangeGate, + FunctionConfSchemaMetricsTimeRangeGateTypedDict, + ) from .functionconfschemanotificationpolicies import ( Condition, ConditionTypedDict, FunctionConfSchemaNotificationPolicies, + FunctionConfSchemaNotificationPoliciesTemplateTargetPair, + FunctionConfSchemaNotificationPoliciesTemplateTargetPairTypedDict, FunctionConfSchemaNotificationPoliciesTypedDict, Operator, Policy, @@ -2641,6 +2881,11 @@ FunctionConfSchemaTrimTimestamp, FunctionConfSchemaTrimTimestampTypedDict, ) + from .functiondetectionrules import ( + FunctionDetectionRules, + FunctionDetectionRulesID, + FunctionDetectionRulesTypedDict, + ) from .functiondistinct import ( FunctionDistinct, FunctionDistinctID, @@ -2711,6 +2956,11 @@ FunctionLakeExportID, FunctionLakeExportTypedDict, ) + from .functionlakehouseenginemetricsnormalizer import ( + FunctionLakehouseEngineMetricsNormalizer, + FunctionLakehouseEngineMetricsNormalizerID, + FunctionLakehouseEngineMetricsNormalizerTypedDict, + ) from .functionlimit import FunctionLimit, FunctionLimitID, FunctionLimitTypedDict from .functionlocalsearchdatatypeparser import ( FunctionLocalSearchDatatypeParser, @@ -2748,6 +2998,11 @@ FunctionMetricsExportID, FunctionMetricsExportTypedDict, ) + from .functionmetricstimerangegate import ( + FunctionMetricsTimeRangeGate, + FunctionMetricsTimeRangeGateID, + FunctionMetricsTimeRangeGateTypedDict, + ) from .functionmvexpand import ( FunctionMvExpand, FunctionMvExpandID, @@ -2919,6 +3174,12 @@ GetFunctionsResponseTypedDict, ) from .getinputbyidop import GetInputByIDRequest, GetInputByIDRequestTypedDict + from .getinputop import ( + GetInputRequest, + GetInputRequestTypedDict, + GetInputResponse, + GetInputResponseTypedDict, + ) from .getinputpqbyidop import GetInputPqByIDRequest, GetInputPqByIDRequestTypedDict from .getinputstatusbyidop import ( GetInputStatusByIDRequest, @@ -2955,6 +3216,12 @@ GetInputSystemPqByPackAndIDRequestTypedDict, ) from .getoutputbyidop import GetOutputByIDRequest, GetOutputByIDRequestTypedDict + from .getoutputop import ( + GetOutputRequest, + GetOutputRequestTypedDict, + GetOutputResponse, + GetOutputResponseTypedDict, + ) from .getoutputpqbyidop import ( GetOutputPqByIDRequest, GetOutputPqByIDRequestTypedDict, @@ -3078,6 +3345,14 @@ from .getroutesbypackop import ( GetRoutesByPackRequest, GetRoutesByPackRequestTypedDict, + GetRoutesByPackResponse, + GetRoutesByPackResponseTypedDict, + ) + from .getroutesop import ( + GetRoutesRequest, + GetRoutesRequestTypedDict, + GetRoutesResponse, + GetRoutesResponseTypedDict, ) from .getsavedjobbyidop import ( GetSavedJobByIDRequest, @@ -3598,6 +3873,11 @@ HostOsTypeHeartbeatMetadataTypedDict, ) from .input import Input, InputTypedDict + from .inputakamaihec_input import ( + InputAkamaiHecInput, + InputAkamaiHecInputTypedDict, + InputAkamaiHecType, + ) from .inputanthropiccompliance_input import ( Activities, ActivitiesManageState, @@ -3631,6 +3911,16 @@ ProjectsManageStateTypedDict, ProjectsTypedDict, ) + from .inputanthropicenterpriseanalytics_input import ( + BucketWidth, + ContentType, + GroupBy, + InputAnthropicEnterpriseAnalyticsContentConfig, + InputAnthropicEnterpriseAnalyticsContentConfigTypedDict, + InputAnthropicEnterpriseAnalyticsInput, + InputAnthropicEnterpriseAnalyticsInputTypedDict, + InputAnthropicEnterpriseAnalyticsType, + ) from .inputappleunifiedlogs_input import ( InputAppleUnifiedLogsInput, InputAppleUnifiedLogsInputTypedDict, @@ -3650,12 +3940,27 @@ UNIXSocketPermissions, UNIXSocketPermissionsTypedDict, ) + from .inputaquasecurityhec_input import ( + InputAquaSecurityHecInput, + InputAquaSecurityHecInputTypedDict, + InputAquaSecurityHecType, + ) from .inputazureblob_input import InputAzureBlobInput, InputAzureBlobInputTypedDict + from .inputazurevnetflowlog_input import ( + InputAzureVnetFlowLogInput, + InputAzureVnetFlowLogInputTypedDict, + InputAzureVnetFlowLogType, + ) from .inputbedrocks3_input import ( InputBedrockS3Input, InputBedrockS3InputTypedDict, InputBedrockS3Type, ) + from .inputbeyondtrusthec_input import ( + InputBeyondtrustHecInput, + InputBeyondtrustHecInputTypedDict, + InputBeyondtrustHecType, + ) from .inputcloudflarehec_input import ( InputCloudflareHecInput, InputCloudflareHecInputTypedDict, @@ -3668,11 +3973,6 @@ InputCollectionInputTypedDict, InputCollectionType, ) - from .inputcollectionorigindatasourcediscoverywithdestinationarnconstraint import ( - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint, - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict, - Origin, - ) from .inputconfluentcloud_input import ( InputConfluentCloudInput, InputConfluentCloudInputTypedDict, @@ -3688,15 +3988,23 @@ InputCriblHTTPType, ) from .inputcribllakehttp_input import ( - AuthTokensExt, - AuthTokensExtTypedDict, - ElasticsearchMetadata, - ElasticsearchMetadataTypedDict, + InputCriblLakeHTTPAuthTokensExt, + InputCriblLakeHTTPAuthTokensExtTypedDict, InputCriblLakeHTTPInput, + InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + InputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, InputCriblLakeHTTPInputTypedDict, InputCriblLakeHTTPType, - SplunkHecMetadata, - SplunkHecMetadataTypedDict, + InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata, + InputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict, + InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata, + InputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict, + InputHTTPAuthTypeSecretConstraintElasticsearchMetadata, + InputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict, + InputHTTPAuthTypeSecretConstraintSplunkHecMetadata, + InputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict, ) from .inputcriblmetrics_input import ( InputCriblmetricsInput, @@ -3759,7 +4067,6 @@ AzureBlobStorageTypedDict, Checkpointing, CheckpointingTypedDict, - InputEventhubAmqpAuthenticationMethod, InputEventhubAmqpCertificate, InputEventhubAmqpCertificateTypedDict, InputEventhubAmqpInput, @@ -3772,6 +4079,16 @@ InputExecType, ScheduleType, ) + from .inputextrahoprevealx360_input import ( + InputExtrahopRevealx360Input, + InputExtrahopRevealx360InputTypedDict, + InputExtrahopRevealx360Type, + ) + from .inputf5bigip_input import ( + InputF5BigIPInput, + InputF5BigIPInputTypedDict, + InputF5BigIPType, + ) from .inputfile_input import ( InputFileInput, InputFileInputTypedDict, @@ -3783,6 +4100,11 @@ InputFirehoseInputTypedDict, InputFirehoseType, ) + from .inputgigamonhec_input import ( + InputGigamonHecInput, + InputGigamonHecInputTypedDict, + InputGigamonHecType, + ) from .inputgooglepubsub_input import ( InputGooglePubsubInput, InputGooglePubsubInputTypedDict, @@ -3805,9 +4127,30 @@ PrometheusAuth2, PrometheusAuth2TypedDict, ) - from .inputhttp_input import InputHTTPInput, InputHTTPInputTypedDict, InputHTTPType + from .inputhashicorphcpvaultdedicated_input import ( + InputHashicorpHcpVaultDedicatedInput, + InputHashicorpHcpVaultDedicatedInputTypedDict, + InputHashicorpHcpVaultDedicatedType, + ) + from .inputhttp_input import ( + InputHTTPAuthTokensExt, + InputHTTPAuthTokensExtTypedDict, + InputHTTPInput, + InputHTTPInputHTTPAuthTokensExtItemsType, + InputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputHTTPInputHTTPAuthTypeSecretConstraint, + InputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + InputHTTPInputTypedDict, + InputHTTPType, + ) from .inputhttpraw_input import ( + InputHTTPRawAuthTokensExt, + InputHTTPRawAuthTokensExtTypedDict, + InputHTTPRawAuthTokensExtUnion, + InputHTTPRawAuthTokensExtUnionTypedDict, InputHTTPRawInput, + InputHTTPRawInputHTTPAuthTypeSecretConstraint, + InputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, InputHTTPRawInputTypedDict, InputHTTPRawType, ) @@ -3851,12 +4194,30 @@ InputMetricsInputTypedDict, InputMetricsType, ) + from .inputmicrosoftcopilot_input import ( + CertOptions, + CertOptionsTypedDict, + InputMicrosoftCopilotAuthenticationMethod, + InputMicrosoftCopilotInput, + InputMicrosoftCopilotInputTypedDict, + InputMicrosoftCopilotManageState, + InputMicrosoftCopilotManageStateTypedDict, + InputMicrosoftCopilotRetryRules, + InputMicrosoftCopilotRetryRulesTypedDict, + InputMicrosoftCopilotSubscriptionPlan, + InputMicrosoftCopilotType, + ) from .inputmicrosoftgraph_input import ( InputMicrosoftGraphAuthenticationMethod, InputMicrosoftGraphInput, InputMicrosoftGraphInputTypedDict, + InputMicrosoftGraphSubscriptionPlan, InputMicrosoftGraphType, - SubscriptionPlan, + ) + from .inputmimecasthec_input import ( + InputMimecastHecInput, + InputMimecastHecInputTypedDict, + InputMimecastHecType, ) from .inputmodeldriventelemetry_input import ( InputModelDrivenTelemetryInput, @@ -3922,6 +4283,11 @@ InputOpenTelemetryProtocol, InputOpenTelemetryType, ) + from .inputpingidentitypingone_input import ( + InputPingIdentityPingoneInput, + InputPingIdentityPingoneInputTypedDict, + InputPingIdentityPingoneType, + ) from .inputprometheus_input import ( InputPrometheusDiscoveryType, InputPrometheusInput, @@ -3933,6 +4299,16 @@ InputPrometheusRwInputTypedDict, InputPrometheusRwType, ) + from .inputproofpointpod_input import ( + FeedType, + InputProofpointPodInput, + InputProofpointPodInputTypedDict, + InputProofpointPodType, + ) + from .inputprovenancetypeoptional import ( + InputProvenanceTypeOptional, + InputProvenanceTypeOptionalTypedDict, + ) from .inputrawudp_input import ( InputRawUDPInput, InputRawUDPInputTypedDict, @@ -3941,9 +4317,58 @@ from .inputresponse import ( InputResponse, InputResponseAPIVersion, + InputResponseCompression, + InputResponseEndpointHeader, + InputResponseEndpointHeaderTypedDict, + InputResponseEndpointParam, + InputResponseEndpointParamTypedDict, + InputResponseInputAzureBlob, + InputResponseInputAzureBlobTypedDict, + InputResponseInputAzureVnetFlowLog, + InputResponseInputAzureVnetFlowLogType, + InputResponseInputAzureVnetFlowLogTypedDict, + InputResponseInputCollection, + InputResponseInputCollectionType, + InputResponseInputCollectionTypedDict, + InputResponseInputElastic, + InputResponseInputElasticAuthenticationMethod, + InputResponseInputElasticAuthenticationType, + InputResponseInputElasticProxyMode, + InputResponseInputElasticProxyModeTypedDict, + InputResponseInputElasticTypedDict, + InputResponseInputHTTP, + InputResponseInputHTTPAuthTokensExt, + InputResponseInputHTTPAuthTokensExtTypedDict, + InputResponseInputHTTPInputHTTPAuthTokensExtItemsType, + InputResponseInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint, + InputResponseInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + InputResponseInputHTTPType, + InputResponseInputHTTPTypedDict, + InputResponseInputKafka, + InputResponseInputKafkaTypedDict, + InputResponseInputMsk, + InputResponseInputMskTypedDict, + InputResponseInputSplunk, + InputResponseInputSplunkAuthToken, + InputResponseInputSplunkAuthTokenTypedDict, + InputResponseInputSplunkHec, + InputResponseInputSplunkHecAuthToken, + InputResponseInputSplunkHecAuthTokenTypedDict, + InputResponseInputSplunkHecType, + InputResponseInputSplunkHecTypedDict, + InputResponseInputSplunkSearch, + InputResponseInputSplunkSearchAuthenticationType, + InputResponseInputSplunkSearchLogLevel, + InputResponseInputSplunkSearchType, + InputResponseInputSplunkSearchTypedDict, + InputResponseInputSplunkTypedDict, + InputResponseMaxS2SVersion, + InputResponseTypedDict, + UnknownInputResponse, + ) + from .inputresponse_inputelastic_type import ( InputResponseAuth, - InputResponseAuthTokensExt, - InputResponseAuthTokensExtTypedDict, InputResponseAuthTypedDict, InputResponseAuthenticationMechanism, InputResponseAzureBlobStorage, @@ -3954,7 +4379,6 @@ InputResponseCheckpointingTypedDict, InputResponseCollectors, InputResponseCollectorsTypedDict, - InputResponseCompression, InputResponseContainer, InputResponseContainerMode, InputResponseContainerTypedDict, @@ -3962,23 +4386,12 @@ InputResponseDNSTypedDict, InputResponseDisksAndFileSystems, InputResponseDisksAndFileSystemsTypedDict, - InputResponseElasticsearchMetadata, - InputResponseElasticsearchMetadataTypedDict, - InputResponseEndpointHeader, - InputResponseEndpointHeaderTypedDict, - InputResponseEndpointParam, - InputResponseEndpointParamTypedDict, InputResponseFirewall, InputResponseFirewallTypedDict, InputResponseHostInfo, InputResponseHostInfoTypedDict, InputResponseHostsFile, InputResponseHostsFileTypedDict, - InputResponseInputAzureBlob, - InputResponseInputAzureBlobTypedDict, - InputResponseInputCollection, - InputResponseInputCollectionType, - InputResponseInputCollectionTypedDict, InputResponseInputConfluentCloud, InputResponseInputConfluentCloudTypedDict, InputResponseInputCribl, @@ -3986,27 +4399,40 @@ InputResponseInputCriblHTTPType, InputResponseInputCriblHTTPTypedDict, InputResponseInputCriblLakeHTTP, + InputResponseInputCriblLakeHTTPAuthTokensExt, + InputResponseInputCriblLakeHTTPAuthTokensExtTypedDict, + InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, InputResponseInputCriblLakeHTTPType, InputResponseInputCriblLakeHTTPTypedDict, InputResponseInputCriblTCP, InputResponseInputCriblTCPTypedDict, InputResponseInputCriblType, InputResponseInputCriblTypedDict, + InputResponseInputCriblmetrics, + InputResponseInputCriblmetricsType, + InputResponseInputCriblmetricsTypedDict, + InputResponseInputCrowdstrike, + InputResponseInputCrowdstrikeType, + InputResponseInputCrowdstrikeTypedDict, + InputResponseInputDatadogAgent, + InputResponseInputDatadogAgentProxyMode, + InputResponseInputDatadogAgentProxyModeTypedDict, + InputResponseInputDatadogAgentType, + InputResponseInputDatadogAgentTypedDict, + InputResponseInputDatagen, + InputResponseInputDatagenType, + InputResponseInputDatagenTypedDict, InputResponseInputEdgePrometheus, InputResponseInputEdgePrometheusAuthenticationMethod, InputResponseInputEdgePrometheusDiscoveryType, InputResponseInputEdgePrometheusType, InputResponseInputEdgePrometheusTypedDict, - InputResponseInputElastic, - InputResponseInputElasticAuthenticationMethod, - InputResponseInputElasticAuthenticationType, - InputResponseInputElasticProxyMode, - InputResponseInputElasticProxyModeTypedDict, InputResponseInputElasticType, - InputResponseInputElasticTypedDict, InputResponseInputEventhub, InputResponseInputEventhubAmqp, - InputResponseInputEventhubAmqpAuthenticationMethod, InputResponseInputEventhubAmqpType, InputResponseInputEventhubAmqpTypedDict, InputResponseInputEventhubType, @@ -4027,20 +4453,49 @@ InputResponseInputGrafanaType2, InputResponseInputGrafanaUnion, InputResponseInputGrafanaUnionTypedDict, - InputResponseInputHTTP, - InputResponseInputHTTPType, - InputResponseInputHTTPTypedDict, - InputResponseInputKafka, - InputResponseInputKafkaTypedDict, + InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata, + InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict, + InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata, + InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict, + InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata, + InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict, + InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata, + InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict, + InputResponseInputHTTPRaw, + InputResponseInputHTTPRawAuthTokensExt, + InputResponseInputHTTPRawAuthTokensExtTypedDict, + InputResponseInputHTTPRawAuthTokensExtUnion, + InputResponseInputHTTPRawAuthTokensExtUnionTypedDict, + InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint, + InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, + InputResponseInputHTTPRawType, + InputResponseInputHTTPRawTypedDict, + InputResponseInputKinesis, + InputResponseInputKinesisTypedDict, + InputResponseInputKubeEvents, + InputResponseInputKubeEventsType, + InputResponseInputKubeEventsTypedDict, + InputResponseInputKubeLogs, + InputResponseInputKubeLogsRule, + InputResponseInputKubeLogsRuleTypedDict, + InputResponseInputKubeLogsType, + InputResponseInputKubeLogsTypedDict, + InputResponseInputKubeMetrics, + InputResponseInputKubeMetricsPersistence, + InputResponseInputKubeMetricsPersistenceTypedDict, + InputResponseInputKubeMetricsType, + InputResponseInputKubeMetricsTypedDict, InputResponseInputLoki, InputResponseInputLokiType, InputResponseInputLokiTypedDict, + InputResponseInputMetrics, + InputResponseInputMetricsType, + InputResponseInputMetricsTypedDict, InputResponseInputMicrosoftGraph, InputResponseInputMicrosoftGraphAuthenticationMethod, + InputResponseInputMicrosoftGraphSubscriptionPlan, InputResponseInputMicrosoftGraphType, InputResponseInputMicrosoftGraphTypedDict, - InputResponseInputMsk, - InputResponseInputMskTypedDict, InputResponseInputOffice365Mgmt, InputResponseInputOffice365MgmtContentConfig, InputResponseInputOffice365MgmtContentConfigTypedDict, @@ -4061,20 +4516,13 @@ InputResponseInputPrometheusRwType, InputResponseInputPrometheusRwTypedDict, InputResponseInputPrometheusTypedDict, - InputResponseInputSplunk, - InputResponseInputSplunkAuthToken, - InputResponseInputSplunkAuthTokenTypedDict, - InputResponseInputSplunkHec, - InputResponseInputSplunkHecAuthToken, - InputResponseInputSplunkHecAuthTokenTypedDict, - InputResponseInputSplunkHecType, - InputResponseInputSplunkHecTypedDict, - InputResponseInputSplunkSearch, - InputResponseInputSplunkSearchAuthenticationType, - InputResponseInputSplunkSearchLogLevel, - InputResponseInputSplunkSearchType, - InputResponseInputSplunkSearchTypedDict, - InputResponseInputSplunkTypedDict, + InputResponseInputS3, + InputResponseInputS3Inventory, + InputResponseInputS3InventoryType, + InputResponseInputS3InventoryTypedDict, + InputResponseInputS3TypedDict, + InputResponseInputSnmp, + InputResponseInputSnmpTypedDict, InputResponseInputSystemMetrics, InputResponseInputSystemMetricsCPU, InputResponseInputSystemMetricsCPUMode, @@ -4108,6 +4556,30 @@ InputResponseInputSystemStateTypedDict, InputResponseInputTcpjson, InputResponseInputTcpjsonTypedDict, + InputResponseInputWindowsMetrics, + InputResponseInputWindowsMetricsCPU, + InputResponseInputWindowsMetricsCPUMode, + InputResponseInputWindowsMetricsCPUTypedDict, + InputResponseInputWindowsMetricsCustom, + InputResponseInputWindowsMetricsCustomTypedDict, + InputResponseInputWindowsMetricsDisk, + InputResponseInputWindowsMetricsDiskMode, + InputResponseInputWindowsMetricsDiskTypedDict, + InputResponseInputWindowsMetricsHost, + InputResponseInputWindowsMetricsHostTypedDict, + InputResponseInputWindowsMetricsMemory, + InputResponseInputWindowsMetricsMemoryMode, + InputResponseInputWindowsMetricsMemoryTypedDict, + InputResponseInputWindowsMetricsNetwork, + InputResponseInputWindowsMetricsNetworkMode, + InputResponseInputWindowsMetricsNetworkTypedDict, + InputResponseInputWindowsMetricsPersistence, + InputResponseInputWindowsMetricsPersistenceTypedDict, + InputResponseInputWindowsMetricsSystem, + InputResponseInputWindowsMetricsSystemMode, + InputResponseInputWindowsMetricsSystemTypedDict, + InputResponseInputWindowsMetricsType, + InputResponseInputWindowsMetricsTypedDict, InputResponseInterfaces, InputResponseInterfacesTypedDict, InputResponseListeningPorts, @@ -4118,7 +4590,6 @@ InputResponseLokiAuth1TypedDict, InputResponseLokiAuth2, InputResponseLokiAuth2TypedDict, - InputResponseMaxS2SVersion, InputResponseMetricsProtocol, InputResponsePodFilter, InputResponsePodFilterTypedDict, @@ -4126,22 +4597,26 @@ InputResponsePrometheusAuth1TypedDict, InputResponsePrometheusAuth2, InputResponsePrometheusAuth2TypedDict, + InputResponseRecordDataFormat, InputResponseRoutes, InputResponseRoutesTypedDict, + InputResponseSNMPv3Authentication, + InputResponseSNMPv3AuthenticationTypedDict, + InputResponseSample, + InputResponseSampleTypedDict, + InputResponseSamplingRule, + InputResponseSamplingRuleTypedDict, InputResponseScheduleType, InputResponseServices, InputResponseServicesTypedDict, - InputResponseSplunkHecMetadata, - InputResponseSplunkHecMetadataTypedDict, - InputResponseSubscriptionPlan, + InputResponseShardIteratorStart, + InputResponseShardLoadBalancing, InputResponseTarget, InputResponseTargetTypedDict, - InputResponseTypedDict, InputResponseUsersAndGroups, InputResponseUsersAndGroupsTypedDict, - UnknownInputResponse, ) - from .inputresponse_inputkubemetrics import ( + from .inputresponse_v3user import ( InputResponseAccountType, InputResponseActivities, InputResponseActivitiesManageState, @@ -4153,6 +4628,9 @@ InputResponseAuthMethodsExtAuthenticationType, InputResponseAuthMethodsExtTypedDict, InputResponseAuthenticationProtocol, + InputResponseBucketWidth, + InputResponseCertOptions, + InputResponseCertOptionsTypedDict, InputResponseChatMessages, InputResponseChatMessagesManageState, InputResponseChatMessagesManageStateTypedDict, @@ -4161,14 +4639,25 @@ InputResponseChatsManageState, InputResponseChatsManageStateTypedDict, InputResponseChatsTypedDict, + InputResponseContentType, InputResponseEventFormat, + InputResponseFeedType, InputResponseFormat, InputResponseGrantType, + InputResponseGroupBy, InputResponseGroups, InputResponseGroupsTypedDict, + InputResponseInputAkamaiHec, + InputResponseInputAkamaiHecType, + InputResponseInputAkamaiHecTypedDict, InputResponseInputAnthropicCompliance, InputResponseInputAnthropicComplianceType, InputResponseInputAnthropicComplianceTypedDict, + InputResponseInputAnthropicEnterpriseAnalytics, + InputResponseInputAnthropicEnterpriseAnalyticsContentConfig, + InputResponseInputAnthropicEnterpriseAnalyticsContentConfigTypedDict, + InputResponseInputAnthropicEnterpriseAnalyticsType, + InputResponseInputAnthropicEnterpriseAnalyticsTypedDict, InputResponseInputAppleUnifiedLogs, InputResponseInputAppleUnifiedLogsReadMode, InputResponseInputAppleUnifiedLogsType, @@ -4180,56 +4669,49 @@ InputResponseInputAppscopePersistenceTypedDict, InputResponseInputAppscopeType, InputResponseInputAppscopeTypedDict, + InputResponseInputAquaSecurityHec, + InputResponseInputAquaSecurityHecType, + InputResponseInputAquaSecurityHecTypedDict, InputResponseInputBedrockS3, InputResponseInputBedrockS3Type, InputResponseInputBedrockS3TypedDict, + InputResponseInputBeyondtrustHec, + InputResponseInputBeyondtrustHecType, + InputResponseInputBeyondtrustHecTypedDict, InputResponseInputCloudflareHec, InputResponseInputCloudflareHecType, InputResponseInputCloudflareHecTypedDict, - InputResponseInputCriblmetrics, - InputResponseInputCriblmetricsType, - InputResponseInputCriblmetricsTypedDict, - InputResponseInputCrowdstrike, - InputResponseInputCrowdstrikeType, - InputResponseInputCrowdstrikeTypedDict, - InputResponseInputDatadogAgent, - InputResponseInputDatadogAgentProxyMode, - InputResponseInputDatadogAgentProxyModeTypedDict, - InputResponseInputDatadogAgentType, - InputResponseInputDatadogAgentTypedDict, - InputResponseInputDatagen, - InputResponseInputDatagenType, - InputResponseInputDatagenTypedDict, + InputResponseInputExtrahopRevealx360, + InputResponseInputExtrahopRevealx360Type, + InputResponseInputExtrahopRevealx360TypedDict, + InputResponseInputF5BigIP, + InputResponseInputF5BigIPType, + InputResponseInputF5BigIPTypedDict, InputResponseInputFile, InputResponseInputFileMode, InputResponseInputFileType, InputResponseInputFileTypedDict, - InputResponseInputHTTPRaw, - InputResponseInputHTTPRawType, - InputResponseInputHTTPRawTypedDict, + InputResponseInputGigamonHec, + InputResponseInputGigamonHecType, + InputResponseInputGigamonHecTypedDict, + InputResponseInputHashicorpHcpVaultDedicated, + InputResponseInputHashicorpHcpVaultDedicatedType, + InputResponseInputHashicorpHcpVaultDedicatedTypedDict, InputResponseInputJournalFiles, InputResponseInputJournalFilesRule, InputResponseInputJournalFilesRuleTypedDict, InputResponseInputJournalFilesType, InputResponseInputJournalFilesTypedDict, - InputResponseInputKinesis, - InputResponseInputKinesisTypedDict, - InputResponseInputKubeEvents, - InputResponseInputKubeEventsType, - InputResponseInputKubeEventsTypedDict, - InputResponseInputKubeLogs, - InputResponseInputKubeLogsRule, - InputResponseInputKubeLogsRuleTypedDict, - InputResponseInputKubeLogsType, - InputResponseInputKubeLogsTypedDict, - InputResponseInputKubeMetrics, - InputResponseInputKubeMetricsPersistence, - InputResponseInputKubeMetricsPersistenceTypedDict, - InputResponseInputKubeMetricsType, - InputResponseInputKubeMetricsTypedDict, - InputResponseInputMetrics, - InputResponseInputMetricsType, - InputResponseInputMetricsTypedDict, + InputResponseInputMicrosoftCopilot, + InputResponseInputMicrosoftCopilotAuthenticationMethod, + InputResponseInputMicrosoftCopilotManageState, + InputResponseInputMicrosoftCopilotManageStateTypedDict, + InputResponseInputMicrosoftCopilotSubscriptionPlan, + InputResponseInputMicrosoftCopilotType, + InputResponseInputMicrosoftCopilotTypedDict, + InputResponseInputMimecastHec, + InputResponseInputMimecastHecType, + InputResponseInputMimecastHecTypedDict, InputResponseInputModelDrivenTelemetry, InputResponseInputModelDrivenTelemetryType, InputResponseInputModelDrivenTelemetryTypedDict, @@ -4257,14 +4739,18 @@ InputResponseInputOpenaiManageStateTypedDict, InputResponseInputOpenaiType, InputResponseInputOpenaiTypedDict, + InputResponseInputPingIdentityPingone, + InputResponseInputPingIdentityPingoneType, + InputResponseInputPingIdentityPingoneTypedDict, + InputResponseInputProofpointPod, + InputResponseInputProofpointPodType, + InputResponseInputProofpointPodTypedDict, InputResponseInputRawUDP, InputResponseInputRawUDPType, InputResponseInputRawUDPTypedDict, - InputResponseInputS3, - InputResponseInputS3Inventory, - InputResponseInputS3InventoryType, - InputResponseInputS3InventoryTypedDict, - InputResponseInputS3TypedDict, + InputResponseInputSailpointHec, + InputResponseInputSailpointHecType, + InputResponseInputSailpointHecTypedDict, InputResponseInputSecurityLake, InputResponseInputSecurityLakeTypedDict, InputResponseInputServicenowTable, @@ -4273,8 +4759,6 @@ InputResponseInputServicenowTableManageStateTypedDict, InputResponseInputServicenowTableType, InputResponseInputServicenowTableTypedDict, - InputResponseInputSnmp, - InputResponseInputSnmpTypedDict, InputResponseInputSqs, InputResponseInputSqsTypedDict, InputResponseInputSysdigHec, @@ -4289,41 +4773,26 @@ InputResponseInputTCP, InputResponseInputTCPType, InputResponseInputTCPTypedDict, - InputResponseInputUpwindHec, - InputResponseInputUpwindHecType, - InputResponseInputUpwindHecTypedDict, - InputResponseInputWef, - InputResponseInputWefAuthenticationMethod, - InputResponseInputWefType, - InputResponseInputWefTypedDict, - InputResponseInputWinEventLogs, - InputResponseInputWinEventLogsReadMode, - InputResponseInputWinEventLogsType, - InputResponseInputWinEventLogsTypedDict, - InputResponseInputWindowsMetrics, - InputResponseInputWindowsMetricsCPU, - InputResponseInputWindowsMetricsCPUMode, - InputResponseInputWindowsMetricsCPUTypedDict, - InputResponseInputWindowsMetricsCustom, - InputResponseInputWindowsMetricsCustomTypedDict, - InputResponseInputWindowsMetricsDisk, - InputResponseInputWindowsMetricsDiskMode, - InputResponseInputWindowsMetricsDiskTypedDict, - InputResponseInputWindowsMetricsHost, - InputResponseInputWindowsMetricsHostTypedDict, - InputResponseInputWindowsMetricsMemory, - InputResponseInputWindowsMetricsMemoryMode, - InputResponseInputWindowsMetricsMemoryTypedDict, - InputResponseInputWindowsMetricsNetwork, - InputResponseInputWindowsMetricsNetworkMode, - InputResponseInputWindowsMetricsNetworkTypedDict, - InputResponseInputWindowsMetricsPersistence, - InputResponseInputWindowsMetricsPersistenceTypedDict, - InputResponseInputWindowsMetricsSystem, - InputResponseInputWindowsMetricsSystemMode, - InputResponseInputWindowsMetricsSystemTypedDict, - InputResponseInputWindowsMetricsType, - InputResponseInputWindowsMetricsTypedDict, + InputResponseInputTrellixHec, + InputResponseInputTrellixHecType, + InputResponseInputTrellixHecTypedDict, + InputResponseInputTrendMicroVisionOne, + InputResponseInputTrendMicroVisionOneType, + InputResponseInputTrendMicroVisionOneTypedDict, + InputResponseInputUpwindHec, + InputResponseInputUpwindHecType, + InputResponseInputUpwindHecTypedDict, + InputResponseInputVectraAiHec, + InputResponseInputVectraAiHecType, + InputResponseInputVectraAiHecTypedDict, + InputResponseInputWef, + InputResponseInputWefAuthenticationMethod, + InputResponseInputWefType, + InputResponseInputWefTypedDict, + InputResponseInputWinEventLogs, + InputResponseInputWinEventLogsReadMode, + InputResponseInputWinEventLogsType, + InputResponseInputWinEventLogsTypedDict, InputResponseInputWiz, InputResponseInputWizContentConfig, InputResponseInputWizContentConfigTypedDict, @@ -4332,6 +4801,12 @@ InputResponseInputWizType, InputResponseInputWizTypedDict, InputResponseInputWizWebhook, + InputResponseInputWizWebhookAuthTokensExt1, + InputResponseInputWizWebhookAuthTokensExt1TypedDict, + InputResponseInputWizWebhookAuthTokensExt2, + InputResponseInputWizWebhookAuthTokensExt2TypedDict, + InputResponseInputWizWebhookAuthTokensExtUnion, + InputResponseInputWizWebhookAuthTokensExtUnionTypedDict, InputResponseInputWizWebhookType, InputResponseInputWizWebhookTypedDict, InputResponseInputZscalerHec, @@ -4363,15 +4838,8 @@ InputResponseQueryBuilderMode, InputResponseQueryTypedDict, InputResponseQueueType, - InputResponseRecordDataFormat, - InputResponseSNMPv3Authentication, - InputResponseSNMPv3AuthenticationTypedDict, - InputResponseSample, - InputResponseSampleTypedDict, - InputResponseSamplingRule, - InputResponseSamplingRuleTypedDict, - InputResponseShardIteratorStart, - InputResponseShardLoadBalancing, + InputResponseRetryRules, + InputResponseRetryRulesTypedDict, InputResponseSortDirection, InputResponseSubscription, InputResponseSubscriptionTypedDict, @@ -4379,6 +4847,8 @@ InputResponseTLSSettingsServerSideTypedDict, InputResponseUNIXSocketPermissions, InputResponseUNIXSocketPermissionsTypedDict, + InputResponseV3AuthenticationKeyType, + InputResponseV3PrivacyKeyType, InputResponseV3User, InputResponseV3UserTypedDict, ) @@ -4388,6 +4858,11 @@ InputS3InventoryInputTypedDict, InputS3InventoryType, ) + from .inputsailpointhec_input import ( + InputSailpointHecInput, + InputSailpointHecInputTypedDict, + InputSailpointHecType, + ) from .inputsecuritylake_input import ( InputSecurityLakeInput, InputSecurityLakeInputTypedDict, @@ -4411,6 +4886,8 @@ PrivacyProtocol, SNMPv3Authentication, SNMPv3AuthenticationTypedDict, + V3AuthenticationKeyType, + V3PrivacyKeyType, ) from .inputsplunk_input import ( InputSplunkAuthToken, @@ -4519,6 +4996,16 @@ ) from .inputtcp_input import InputTCPInput, InputTCPInputTypedDict, InputTCPType from .inputtcpjson_input import InputTcpjsonInput, InputTcpjsonInputTypedDict + from .inputtrellixhec_input import ( + InputTrellixHecInput, + InputTrellixHecInputTypedDict, + InputTrellixHecType, + ) + from .inputtrendmicrovisionone_input import ( + InputTrendMicroVisionOneInput, + InputTrendMicroVisionOneInputTypedDict, + InputTrendMicroVisionOneType, + ) from .inputtyperunnablejobcollection import ( InputTypeRunnableJobCollection, InputTypeRunnableJobCollectionTypedDict, @@ -4528,6 +5015,11 @@ InputUpwindHecInputTypedDict, InputUpwindHecType, ) + from .inputvectraaihec_input import ( + InputVectraAiHecInput, + InputVectraAiHecInputTypedDict, + InputVectraAiHecType, + ) from .inputwef_input import ( InputWefAuthenticationMethod, InputWefFormat, @@ -4569,7 +5061,7 @@ InputWindowsMetricsType, ) from .inputwineventlogs_input import ( - EventFormat, + InputWinEventLogsEventFormat, InputWinEventLogsInput, InputWinEventLogsInputTypedDict, InputWinEventLogsReadMode, @@ -4585,6 +5077,12 @@ InputWizType, ) from .inputwizwebhook_input import ( + InputWizWebhookAuthTokensExt1, + InputWizWebhookAuthTokensExt1TypedDict, + InputWizWebhookAuthTokensExt2, + InputWizWebhookAuthTokensExt2TypedDict, + InputWizWebhookAuthTokensExtUnion, + InputWizWebhookAuthTokensExtUnionTypedDict, InputWizWebhookInput, InputWizWebhookInputTypedDict, InputWizWebhookType, @@ -4621,18 +5119,6 @@ LakeDatasetSearchConfigTypedDict, ) from .lakehouseconnectiontype import LakehouseConnectionType - from .listinputop import ( - ListInputRequest, - ListInputRequestTypedDict, - ListInputResponse, - ListInputResponseTypedDict, - ) - from .listoutputop import ( - ListOutputRequest, - ListOutputRequestTypedDict, - ListOutputResponse, - ListOutputResponseTypedDict, - ) from .logininfo import LoginInfo, LoginInfoTypedDict from .loglabelconfoutputgooglecloudlogging import ( LogLabelConfOutputGoogleCloudLogging, @@ -4671,6 +5157,7 @@ MetadataConfInputCollection, MetadataConfInputCollectionTypedDict, ) + from .metadataitem import MetadataItem, MetadataItemTypedDict from .methodoptions import MethodOptions from .microsoftentraidauthenticationendpointoptionssasl import ( MicrosoftEntraIDAuthenticationEndpointOptionsSasl, @@ -4706,48 +5193,24 @@ from .nodeskippedupgradestatus import NodeSkippedUpgradeStatus from .nodeupgradestate import NodeUpgradeState from .nodeupgradestatus import NodeUpgradeStatus, NodeUpgradeStatusTypedDict - from .notification_union import ( - ConditionSpecificConfigurations1, - ConditionSpecificConfigurations1TypedDict, - ConditionSpecificConfigurations2, - ConditionSpecificConfigurations2TypedDict, - ConditionSpecificConfigurations3, - ConditionSpecificConfigurations3TypedDict, - EmailRecipient1, - EmailRecipient1TypedDict, - EmailRecipient2, - EmailRecipient2TypedDict, - EmailRecipient3, - EmailRecipient3TypedDict, - Notification1, - Notification1TypedDict, - Notification2, - Notification2TypedDict, - Notification3, - Notification3TypedDict, - NotificationConfigForSMTPTarget1, - NotificationConfigForSMTPTarget1TypedDict, - NotificationConfigForSMTPTarget2, - NotificationConfigForSMTPTarget2TypedDict, - NotificationConfigForSMTPTarget3, - NotificationConfigForSMTPTarget3TypedDict, - NotificationMode1, - NotificationMode2, - NotificationMode3, - NotificationUnion, - NotificationUnionTypedDict, - TargetConfig1, - TargetConfig1TypedDict, - TargetConfig2, - TargetConfig2TypedDict, - TargetConfig3, - TargetConfig3TypedDict, - TargetConfigUnion1, - TargetConfigUnion1TypedDict, - TargetConfigUnion2, - TargetConfigUnion2TypedDict, - TargetConfigUnion3, - TargetConfigUnion3TypedDict, + from .notification import ( + Notification, + NotificationTemplateTargetPair, + NotificationTemplateTargetPairTypedDict, + NotificationTypedDict, + ) + from .notificationmode import NotificationMode + from .notificationsmtptargetconfig import ( + NotificationSMTPTargetConfig, + NotificationSMTPTargetConfigTypedDict, + ) + from .notificationtargetconfig import ( + NotificationTargetConfig, + NotificationTargetConfigTypedDict, + ) + from .notificationtargetdetails import ( + NotificationTargetDetails, + NotificationTargetDetailsTypedDict, ) from .oauthheaderconfinputservicenowtable import ( OauthHeaderConfInputServicenowTable, @@ -4766,6 +5229,7 @@ ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol, ) from .objectstoragefilter import ObjectStorageFilter, ObjectStorageFilterTypedDict + from .originoptionscriblsourceprovenance import OriginOptionsCriblSourceProvenance from .orphanfilerecoverytype import ( OrphanFileRecoveryType, OrphanFileRecoveryTypeTypedDict, @@ -4894,6 +5358,7 @@ OutputCriblSearchEnginePqControlsTypedDict, OutputCriblSearchEngineType, OutputCriblSearchEngineTypedDict, + SendAs, ) from .outputcribltcp import ( OutputCriblTCP, @@ -4920,6 +5385,13 @@ OutputDatabricksType, OutputDatabricksTypedDict, ) + from .outputdatabrickszerobus import ( + OutputDatabricksZerobus, + OutputDatabricksZerobusPqControls, + OutputDatabricksZerobusPqControlsTypedDict, + OutputDatabricksZerobusType, + OutputDatabricksZerobusTypedDict, + ) from .outputdatadog import ( DatadogSite, OutputDatadog, @@ -4986,7 +5458,12 @@ OutputElasticCloudType, OutputElasticCloudTypedDict, ) - from .outputexabeam import OutputExabeam, OutputExabeamType, OutputExabeamTypedDict + from .outputexabeam import ( + OutputExabeam, + OutputExabeamAuthenticationMethod, + OutputExabeamType, + OutputExabeamTypedDict, + ) from .outputfilesystem import ( OutputFilesystem, OutputFilesystemType, @@ -5193,247 +5670,30 @@ from .outputresponse import ( OutputResponse, OutputResponseOutputDefault, - OutputResponseOutputDefaultTypedDict, - OutputResponseTypedDict, - UnknownOutputResponse, - ) - from .outputresponse_outputdefault_type import ( - OutputResponseAPIVersion, - OutputResponseAdditionalProperty, - OutputResponseAdditionalPropertyTypedDict, - OutputResponseAuthToken, - OutputResponseAuthTokenTypedDict, - OutputResponseAuthType, - OutputResponseBlobAccessTier, - OutputResponseCertificate, - OutputResponseCertificateTypedDict, - OutputResponseCompression, - OutputResponseElasticVersion, - OutputResponseEndpointConfiguration, - OutputResponseExtentTag, - OutputResponseExtentTagTypedDict, - OutputResponseExtraLogType, - OutputResponseExtraLogTypeTypedDict, - OutputResponseFacility, - OutputResponseFieldName, - OutputResponseIndexerDiscoveryConfigs, - OutputResponseIndexerDiscoveryConfigsTypedDict, - OutputResponseIngestIfNotExist, - OutputResponseIngestIfNotExistTypedDict, - OutputResponseIngestionMode, - OutputResponseLogLocationType, - OutputResponseMessageFormat, - OutputResponseMetadatum, - OutputResponseMetadatumTypedDict, - OutputResponseOutputAzureBlob, - OutputResponseOutputAzureBlobTypedDict, - OutputResponseOutputAzureDataExplorer, - OutputResponseOutputAzureDataExplorerAuthenticationMethod, - OutputResponseOutputAzureDataExplorerPqControls, - OutputResponseOutputAzureDataExplorerPqControlsTypedDict, - OutputResponseOutputAzureDataExplorerType, - OutputResponseOutputAzureDataExplorerTypedDict, - OutputResponseOutputAzureEventhub, - OutputResponseOutputAzureEventhubPqControls, - OutputResponseOutputAzureEventhubPqControlsTypedDict, - OutputResponseOutputAzureEventhubType, - OutputResponseOutputAzureEventhubTypedDict, - OutputResponseOutputAzureLogs, - OutputResponseOutputAzureLogsAuthenticationMethod, - OutputResponseOutputAzureLogsPqControls, - OutputResponseOutputAzureLogsPqControlsTypedDict, - OutputResponseOutputAzureLogsType, - OutputResponseOutputAzureLogsTypedDict, - OutputResponseOutputCloudwatch, - OutputResponseOutputCloudwatchPqControls, - OutputResponseOutputCloudwatchPqControlsTypedDict, - OutputResponseOutputCloudwatchType, - OutputResponseOutputCloudwatchTypedDict, - OutputResponseOutputConfluentCloud, - OutputResponseOutputConfluentCloudPqControls, - OutputResponseOutputConfluentCloudPqControlsTypedDict, - OutputResponseOutputConfluentCloudTypedDict, OutputResponseOutputDefaultType, - OutputResponseOutputDevnull, - OutputResponseOutputDevnullType, - OutputResponseOutputDevnullTypedDict, - OutputResponseOutputElastic, - OutputResponseOutputElasticCloud, - OutputResponseOutputElasticCloudPqControls, - OutputResponseOutputElasticCloudPqControlsTypedDict, - OutputResponseOutputElasticCloudType, - OutputResponseOutputElasticCloudTypedDict, - OutputResponseOutputElasticPqControls, - OutputResponseOutputElasticPqControlsTypedDict, - OutputResponseOutputElasticType, - OutputResponseOutputElasticTypedDict, - OutputResponseOutputElasticURL, - OutputResponseOutputElasticURLTypedDict, - OutputResponseOutputExabeam, - OutputResponseOutputExabeamType, - OutputResponseOutputExabeamTypedDict, - OutputResponseOutputFilesystem, - OutputResponseOutputFilesystemType, - OutputResponseOutputFilesystemTypedDict, - OutputResponseOutputGoogleBigquery, - OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod, - OutputResponseOutputGoogleBigqueryPqControls, - OutputResponseOutputGoogleBigqueryPqControlsTypedDict, - OutputResponseOutputGoogleBigqueryType, - OutputResponseOutputGoogleBigqueryTypedDict, - OutputResponseOutputGoogleChronicle, - OutputResponseOutputGoogleChronicleAuthenticationMethod, - OutputResponseOutputGoogleChroniclePqControls, - OutputResponseOutputGoogleChroniclePqControlsTypedDict, - OutputResponseOutputGoogleChronicleType, - OutputResponseOutputGoogleChronicleTypedDict, - OutputResponseOutputGoogleCloudLogging, - OutputResponseOutputGoogleCloudLoggingPqControls, - OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict, - OutputResponseOutputGoogleCloudLoggingType, - OutputResponseOutputGoogleCloudLoggingTypedDict, - OutputResponseOutputGoogleCloudObservability, - OutputResponseOutputGoogleCloudObservabilityEndpoint, - OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod, - OutputResponseOutputGoogleCloudObservabilityOtlpVersion, - OutputResponseOutputGoogleCloudObservabilityPqControls, - OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict, - OutputResponseOutputGoogleCloudObservabilityProtocol, - OutputResponseOutputGoogleCloudObservabilityType, - OutputResponseOutputGoogleCloudObservabilityTypedDict, - OutputResponseOutputGoogleCloudStorage, - OutputResponseOutputGoogleCloudStorageAuthenticationMethod, - OutputResponseOutputGoogleCloudStorageType, - OutputResponseOutputGoogleCloudStorageTypedDict, - OutputResponseOutputGooglePubsub, - OutputResponseOutputGooglePubsubPqControls, - OutputResponseOutputGooglePubsubPqControlsTypedDict, - OutputResponseOutputGooglePubsubTypedDict, - OutputResponseOutputHoneycomb, - OutputResponseOutputHoneycombPqControls, - OutputResponseOutputHoneycombPqControlsTypedDict, - OutputResponseOutputHoneycombType, - OutputResponseOutputHoneycombTypedDict, - OutputResponseOutputInfluxdb, - OutputResponseOutputInfluxdbAuthenticationType, - OutputResponseOutputInfluxdbPqControls, - OutputResponseOutputInfluxdbPqControlsTypedDict, - OutputResponseOutputInfluxdbType, - OutputResponseOutputInfluxdbTypedDict, - OutputResponseOutputKafka, - OutputResponseOutputKafkaPqControls, - OutputResponseOutputKafkaPqControlsTypedDict, - OutputResponseOutputKafkaTypedDict, - OutputResponseOutputKinesis, - OutputResponseOutputKinesisPqControls, - OutputResponseOutputKinesisPqControlsTypedDict, - OutputResponseOutputKinesisTypedDict, - OutputResponseOutputMinio, - OutputResponseOutputMinioType, - OutputResponseOutputMinioTypedDict, - OutputResponseOutputMsk, - OutputResponseOutputMskPqControls, - OutputResponseOutputMskPqControlsTypedDict, - OutputResponseOutputMskTypedDict, - OutputResponseOutputNewrelic, - OutputResponseOutputNewrelicEvents, - OutputResponseOutputNewrelicEventsPqControls, - OutputResponseOutputNewrelicEventsPqControlsTypedDict, - OutputResponseOutputNewrelicEventsType, - OutputResponseOutputNewrelicEventsTypedDict, - OutputResponseOutputNewrelicPqControls, - OutputResponseOutputNewrelicPqControlsTypedDict, - OutputResponseOutputNewrelicType, - OutputResponseOutputNewrelicTypedDict, - OutputResponseOutputS3, - OutputResponseOutputS3TypedDict, - OutputResponseOutputSentinel, - OutputResponseOutputSentinelFormat, - OutputResponseOutputSentinelPqControls, - OutputResponseOutputSentinelPqControlsTypedDict, - OutputResponseOutputSentinelType, - OutputResponseOutputSentinelTypedDict, - OutputResponseOutputSignalfx, - OutputResponseOutputSignalfxPqControls, - OutputResponseOutputSignalfxPqControlsTypedDict, - OutputResponseOutputSignalfxType, - OutputResponseOutputSignalfxTypedDict, - OutputResponseOutputSplunk, - OutputResponseOutputSplunkHec, - OutputResponseOutputSplunkHecPqControls, - OutputResponseOutputSplunkHecPqControlsTypedDict, - OutputResponseOutputSplunkHecType, - OutputResponseOutputSplunkHecTypedDict, - OutputResponseOutputSplunkHecURL, - OutputResponseOutputSplunkHecURLTypedDict, - OutputResponseOutputSplunkLb, - OutputResponseOutputSplunkLbPqControls, - OutputResponseOutputSplunkLbPqControlsTypedDict, - OutputResponseOutputSplunkLbType, - OutputResponseOutputSplunkLbTypedDict, - OutputResponseOutputSplunkPqControls, - OutputResponseOutputSplunkPqControlsTypedDict, - OutputResponseOutputSplunkTypedDict, - OutputResponseOutputStatsd, - OutputResponseOutputStatsdExt, - OutputResponseOutputStatsdExtPqControls, - OutputResponseOutputStatsdExtPqControlsTypedDict, - OutputResponseOutputStatsdExtTypedDict, - OutputResponseOutputStatsdPqControls, - OutputResponseOutputStatsdPqControlsTypedDict, - OutputResponseOutputStatsdType, - OutputResponseOutputStatsdTypedDict, - OutputResponseOutputSyslog, - OutputResponseOutputSyslogPqControls, - OutputResponseOutputSyslogPqControlsTypedDict, - OutputResponseOutputSyslogProtocol, - OutputResponseOutputSyslogSeverity, - OutputResponseOutputSyslogTypedDict, - OutputResponseOutputTcpjson, - OutputResponseOutputTcpjsonPqControls, - OutputResponseOutputTcpjsonPqControlsTypedDict, - OutputResponseOutputTcpjsonTypedDict, - OutputResponseOutputWavefront, - OutputResponseOutputWavefrontPqControls, - OutputResponseOutputWavefrontPqControlsTypedDict, - OutputResponseOutputWavefrontType, - OutputResponseOutputWavefrontTypedDict, + OutputResponseOutputDefaultTypedDict, OutputResponseOutputWebhookAuthenticationType1, OutputResponseOutputWebhookAuthenticationType2, OutputResponseOutputWebhookFormat1, - OutputResponseOutputWebhookFormat2, OutputResponseOutputWebhookPqControls1, OutputResponseOutputWebhookPqControls1TypedDict, OutputResponseOutputWebhookPqControls2, OutputResponseOutputWebhookPqControls2TypedDict, OutputResponseOutputWebhookType1, - OutputResponseOutputWebhookType2, OutputResponseOutputWebhookURL1, OutputResponseOutputWebhookURL1TypedDict, OutputResponseOutputWebhookURL2, OutputResponseOutputWebhookURL2TypedDict, - OutputResponseOutputWebhookUnion, - OutputResponseOutputWebhookUnionTypedDict, - OutputResponseOutputWebhookWebhook1, - OutputResponseOutputWebhookWebhook1TypedDict, - OutputResponseOutputWebhookWebhook2, - OutputResponseOutputWebhookWebhook2TypedDict, - OutputResponseOutputWizHec, - OutputResponseOutputWizHecPqControls, - OutputResponseOutputWizHecPqControlsTypedDict, - OutputResponseOutputWizHecType, - OutputResponseOutputWizHecTypedDict, - OutputResponsePayloadFormat, - OutputResponsePrefixOptional, - OutputResponseReportLevel, - OutputResponseReportMethod, - OutputResponseSendEventsAs, - OutputResponseTimestampFormat, - OutputResponseTimestampPrecision, - OutputResponseUDMType, - OutputResponseWriteAction, + OutputResponseOutputWebhookUnion, + OutputResponseOutputWebhookUnionTypedDict, + OutputResponseOutputWebhookWebhook1, + OutputResponseOutputWebhookWebhook1TypedDict, + OutputResponseOutputWebhookWebhook2, + OutputResponseOutputWebhookWebhook2TypedDict, + OutputResponseTypedDict, + UnknownOutputResponse, ) - from .outputresponse_outputstatsdext_type import ( + from .outputresponse_outputsns_pqcontrols import ( OutputResponseAISIEMEndpointPath, OutputResponseAuthentication, OutputResponseAuthenticationTypedDict, @@ -5505,6 +5765,11 @@ OutputResponseOutputDatabricks, OutputResponseOutputDatabricksType, OutputResponseOutputDatabricksTypedDict, + OutputResponseOutputDatabricksZerobus, + OutputResponseOutputDatabricksZerobusPqControls, + OutputResponseOutputDatabricksZerobusPqControlsTypedDict, + OutputResponseOutputDatabricksZerobusType, + OutputResponseOutputDatabricksZerobusTypedDict, OutputResponseOutputDatadog, OutputResponseOutputDatadogPqControls, OutputResponseOutputDatadogPqControlsTypedDict, @@ -5552,11 +5817,6 @@ OutputResponseOutputGrafanaCloudType2, OutputResponseOutputGrafanaCloudUnion, OutputResponseOutputGrafanaCloudUnionTypedDict, - OutputResponseOutputGraphite, - OutputResponseOutputGraphitePqControls, - OutputResponseOutputGraphitePqControlsTypedDict, - OutputResponseOutputGraphiteType, - OutputResponseOutputGraphiteTypedDict, OutputResponseOutputHumioHec, OutputResponseOutputHumioHecPqControls, OutputResponseOutputHumioHecPqControlsTypedDict, @@ -5604,9 +5864,6 @@ OutputResponseOutputRingDataFormat, OutputResponseOutputRingType, OutputResponseOutputRingTypedDict, - OutputResponseOutputRouter, - OutputResponseOutputRouterType, - OutputResponseOutputRouterTypedDict, OutputResponseOutputScalityS3, OutputResponseOutputScalityS3Type, OutputResponseOutputScalityS3TypedDict, @@ -5631,16 +5888,13 @@ OutputResponseOutputSnowflakeStreamingPqControlsTypedDict, OutputResponseOutputSnowflakeStreamingType, OutputResponseOutputSnowflakeStreamingTypedDict, - OutputResponseOutputSns, OutputResponseOutputSnsPqControls, OutputResponseOutputSnsPqControlsTypedDict, OutputResponseOutputSnsType, - OutputResponseOutputSnsTypedDict, OutputResponseOutputSqs, OutputResponseOutputSqsPqControls, OutputResponseOutputSqsPqControlsTypedDict, OutputResponseOutputSqsTypedDict, - OutputResponseOutputStatsdExtType, OutputResponseOutputStorjS3, OutputResponseOutputStorjS3Type, OutputResponseOutputStorjS3TypedDict, @@ -5650,6 +5904,12 @@ OutputResponseOutputSumoLogicPqControlsTypedDict, OutputResponseOutputSumoLogicType, OutputResponseOutputSumoLogicTypedDict, + OutputResponseOutputTraversalOtlp, + OutputResponseOutputTraversalOtlpAuthenticationType, + OutputResponseOutputTraversalOtlpPqControls, + OutputResponseOutputTraversalOtlpPqControlsTypedDict, + OutputResponseOutputTraversalOtlpType, + OutputResponseOutputTraversalOtlpTypedDict, OutputResponseOutputXsiam, OutputResponseOutputXsiamAuthenticationMethod, OutputResponseOutputXsiamPqControls, @@ -5662,13 +5922,246 @@ OutputResponsePrivateKeyTypedDict, OutputResponseQueueType, OutputResponseRegion, - OutputResponseRule, - OutputResponseRuleTypedDict, + OutputResponseSendAs, OutputResponseSendLogsAs, OutputResponseStatsDestination, OutputResponseStatsDestinationTypedDict, OutputResponseTelemetryType, ) + from .outputresponse_outputwebhook_format_2 import ( + OutputResponseAPIVersion, + OutputResponseAdditionalProperty, + OutputResponseAdditionalPropertyTypedDict, + OutputResponseAuthToken, + OutputResponseAuthTokenTypedDict, + OutputResponseAuthType, + OutputResponseBlobAccessTier, + OutputResponseCertificate, + OutputResponseCertificateTypedDict, + OutputResponseCompression, + OutputResponseElasticVersion, + OutputResponseEndpointConfiguration, + OutputResponseEventFormat, + OutputResponseExtentTag, + OutputResponseExtentTagTypedDict, + OutputResponseExtraLogType, + OutputResponseExtraLogTypeTypedDict, + OutputResponseFacility, + OutputResponseFieldName, + OutputResponseIndexerDiscoveryConfigs, + OutputResponseIndexerDiscoveryConfigsTypedDict, + OutputResponseIngestIfNotExist, + OutputResponseIngestIfNotExistTypedDict, + OutputResponseIngestionMode, + OutputResponseLogLocationType, + OutputResponseMessageFormat, + OutputResponseMetadatum, + OutputResponseMetadatumTypedDict, + OutputResponseOAuthSecretSource, + OutputResponseOutputAzureBlob, + OutputResponseOutputAzureBlobTypedDict, + OutputResponseOutputAzureDataExplorer, + OutputResponseOutputAzureDataExplorerAuthenticationMethod, + OutputResponseOutputAzureDataExplorerPqControls, + OutputResponseOutputAzureDataExplorerPqControlsTypedDict, + OutputResponseOutputAzureDataExplorerType, + OutputResponseOutputAzureDataExplorerTypedDict, + OutputResponseOutputAzureEventhub, + OutputResponseOutputAzureEventhubPqControls, + OutputResponseOutputAzureEventhubPqControlsTypedDict, + OutputResponseOutputAzureEventhubType, + OutputResponseOutputAzureEventhubTypedDict, + OutputResponseOutputAzureLogs, + OutputResponseOutputAzureLogsAuthenticationMethod, + OutputResponseOutputAzureLogsPqControls, + OutputResponseOutputAzureLogsPqControlsTypedDict, + OutputResponseOutputAzureLogsType, + OutputResponseOutputAzureLogsTypedDict, + OutputResponseOutputCloudwatch, + OutputResponseOutputCloudwatchPqControls, + OutputResponseOutputCloudwatchPqControlsTypedDict, + OutputResponseOutputCloudwatchType, + OutputResponseOutputCloudwatchTypedDict, + OutputResponseOutputConfluentCloud, + OutputResponseOutputConfluentCloudPqControls, + OutputResponseOutputConfluentCloudPqControlsTypedDict, + OutputResponseOutputConfluentCloudTypedDict, + OutputResponseOutputDevnull, + OutputResponseOutputDevnullType, + OutputResponseOutputDevnullTypedDict, + OutputResponseOutputElastic, + OutputResponseOutputElasticCloud, + OutputResponseOutputElasticCloudPqControls, + OutputResponseOutputElasticCloudPqControlsTypedDict, + OutputResponseOutputElasticCloudType, + OutputResponseOutputElasticCloudTypedDict, + OutputResponseOutputElasticPqControls, + OutputResponseOutputElasticPqControlsTypedDict, + OutputResponseOutputElasticType, + OutputResponseOutputElasticTypedDict, + OutputResponseOutputElasticURL, + OutputResponseOutputElasticURLTypedDict, + OutputResponseOutputExabeam, + OutputResponseOutputExabeamAuthenticationMethod, + OutputResponseOutputExabeamType, + OutputResponseOutputExabeamTypedDict, + OutputResponseOutputFilesystem, + OutputResponseOutputFilesystemType, + OutputResponseOutputFilesystemTypedDict, + OutputResponseOutputGoogleBigquery, + OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod, + OutputResponseOutputGoogleBigqueryPqControls, + OutputResponseOutputGoogleBigqueryPqControlsTypedDict, + OutputResponseOutputGoogleBigqueryType, + OutputResponseOutputGoogleBigqueryTypedDict, + OutputResponseOutputGoogleChronicle, + OutputResponseOutputGoogleChronicleAuthenticationMethod, + OutputResponseOutputGoogleChroniclePqControls, + OutputResponseOutputGoogleChroniclePqControlsTypedDict, + OutputResponseOutputGoogleChronicleType, + OutputResponseOutputGoogleChronicleTypedDict, + OutputResponseOutputGoogleCloudLogging, + OutputResponseOutputGoogleCloudLoggingPqControls, + OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict, + OutputResponseOutputGoogleCloudLoggingType, + OutputResponseOutputGoogleCloudLoggingTypedDict, + OutputResponseOutputGoogleCloudObservability, + OutputResponseOutputGoogleCloudObservabilityEndpoint, + OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod, + OutputResponseOutputGoogleCloudObservabilityOtlpVersion, + OutputResponseOutputGoogleCloudObservabilityPqControls, + OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict, + OutputResponseOutputGoogleCloudObservabilityProtocol, + OutputResponseOutputGoogleCloudObservabilityType, + OutputResponseOutputGoogleCloudObservabilityTypedDict, + OutputResponseOutputGoogleCloudStorage, + OutputResponseOutputGoogleCloudStorageAuthenticationMethod, + OutputResponseOutputGoogleCloudStorageType, + OutputResponseOutputGoogleCloudStorageTypedDict, + OutputResponseOutputGooglePubsub, + OutputResponseOutputGooglePubsubPqControls, + OutputResponseOutputGooglePubsubPqControlsTypedDict, + OutputResponseOutputGooglePubsubTypedDict, + OutputResponseOutputGraphite, + OutputResponseOutputGraphitePqControls, + OutputResponseOutputGraphitePqControlsTypedDict, + OutputResponseOutputGraphiteType, + OutputResponseOutputGraphiteTypedDict, + OutputResponseOutputHoneycomb, + OutputResponseOutputHoneycombPqControls, + OutputResponseOutputHoneycombPqControlsTypedDict, + OutputResponseOutputHoneycombType, + OutputResponseOutputHoneycombTypedDict, + OutputResponseOutputInfluxdb, + OutputResponseOutputInfluxdbAuthenticationType, + OutputResponseOutputInfluxdbPqControls, + OutputResponseOutputInfluxdbPqControlsTypedDict, + OutputResponseOutputInfluxdbType, + OutputResponseOutputInfluxdbTypedDict, + OutputResponseOutputKafka, + OutputResponseOutputKafkaPqControls, + OutputResponseOutputKafkaPqControlsTypedDict, + OutputResponseOutputKafkaTypedDict, + OutputResponseOutputKinesis, + OutputResponseOutputKinesisPqControls, + OutputResponseOutputKinesisPqControlsTypedDict, + OutputResponseOutputKinesisTypedDict, + OutputResponseOutputMinio, + OutputResponseOutputMinioType, + OutputResponseOutputMinioTypedDict, + OutputResponseOutputMsk, + OutputResponseOutputMskPqControls, + OutputResponseOutputMskPqControlsTypedDict, + OutputResponseOutputMskTypedDict, + OutputResponseOutputNewrelic, + OutputResponseOutputNewrelicEvents, + OutputResponseOutputNewrelicEventsPqControls, + OutputResponseOutputNewrelicEventsPqControlsTypedDict, + OutputResponseOutputNewrelicEventsType, + OutputResponseOutputNewrelicEventsTypedDict, + OutputResponseOutputNewrelicPqControls, + OutputResponseOutputNewrelicPqControlsTypedDict, + OutputResponseOutputNewrelicType, + OutputResponseOutputNewrelicTypedDict, + OutputResponseOutputRouter, + OutputResponseOutputRouterType, + OutputResponseOutputRouterTypedDict, + OutputResponseOutputS3, + OutputResponseOutputS3TypedDict, + OutputResponseOutputSentinel, + OutputResponseOutputSentinelFormat, + OutputResponseOutputSentinelPqControls, + OutputResponseOutputSentinelPqControlsTypedDict, + OutputResponseOutputSentinelType, + OutputResponseOutputSentinelTypedDict, + OutputResponseOutputSignalfx, + OutputResponseOutputSignalfxPqControls, + OutputResponseOutputSignalfxPqControlsTypedDict, + OutputResponseOutputSignalfxType, + OutputResponseOutputSignalfxTypedDict, + OutputResponseOutputSns, + OutputResponseOutputSnsTypedDict, + OutputResponseOutputSplunk, + OutputResponseOutputSplunkHec, + OutputResponseOutputSplunkHecPqControls, + OutputResponseOutputSplunkHecPqControlsTypedDict, + OutputResponseOutputSplunkHecType, + OutputResponseOutputSplunkHecTypedDict, + OutputResponseOutputSplunkHecURL, + OutputResponseOutputSplunkHecURLTypedDict, + OutputResponseOutputSplunkLb, + OutputResponseOutputSplunkLbPqControls, + OutputResponseOutputSplunkLbPqControlsTypedDict, + OutputResponseOutputSplunkLbType, + OutputResponseOutputSplunkLbTypedDict, + OutputResponseOutputSplunkPqControls, + OutputResponseOutputSplunkPqControlsTypedDict, + OutputResponseOutputSplunkTypedDict, + OutputResponseOutputStatsd, + OutputResponseOutputStatsdExt, + OutputResponseOutputStatsdExtPqControls, + OutputResponseOutputStatsdExtPqControlsTypedDict, + OutputResponseOutputStatsdExtType, + OutputResponseOutputStatsdExtTypedDict, + OutputResponseOutputStatsdPqControls, + OutputResponseOutputStatsdPqControlsTypedDict, + OutputResponseOutputStatsdType, + OutputResponseOutputStatsdTypedDict, + OutputResponseOutputSyslog, + OutputResponseOutputSyslogPqControls, + OutputResponseOutputSyslogPqControlsTypedDict, + OutputResponseOutputSyslogProtocol, + OutputResponseOutputSyslogSeverity, + OutputResponseOutputSyslogTypedDict, + OutputResponseOutputTcpjson, + OutputResponseOutputTcpjsonPqControls, + OutputResponseOutputTcpjsonPqControlsTypedDict, + OutputResponseOutputTcpjsonTypedDict, + OutputResponseOutputWavefront, + OutputResponseOutputWavefrontPqControls, + OutputResponseOutputWavefrontPqControlsTypedDict, + OutputResponseOutputWavefrontType, + OutputResponseOutputWavefrontTypedDict, + OutputResponseOutputWebhookFormat2, + OutputResponseOutputWebhookType2, + OutputResponseOutputWizHec, + OutputResponseOutputWizHecPqControls, + OutputResponseOutputWizHecPqControlsTypedDict, + OutputResponseOutputWizHecType, + OutputResponseOutputWizHecTypedDict, + OutputResponsePayloadFormat, + OutputResponsePrefixOptional, + OutputResponseReportLevel, + OutputResponseReportMethod, + OutputResponseRule, + OutputResponseRuleTypedDict, + OutputResponseSendEventsAs, + OutputResponseTimestampFormat, + OutputResponseTimestampPrecision, + OutputResponseUDMType, + OutputResponseWizDefendSourceType, + OutputResponseWriteAction, + ) from .outputring import ( OutputRing, OutputRingDataFormat, @@ -5696,6 +6189,7 @@ from .outputsentinel import ( AuthTypeEnum, EndpointConfiguration, + OAuthSecretSource, OutputSentinel, OutputSentinelFormat, OutputSentinelPqControls, @@ -5824,6 +6318,14 @@ ) from .outputtestrequest import OutputTestRequest, OutputTestRequestTypedDict from .outputtestresponse import OutputTestResponse, OutputTestResponseTypedDict + from .outputtraversalotlp import ( + OutputTraversalOtlp, + OutputTraversalOtlpAuthenticationType, + OutputTraversalOtlpPqControls, + OutputTraversalOtlpPqControlsTypedDict, + OutputTraversalOtlpType, + OutputTraversalOtlpTypedDict, + ) from .outputwavefront import ( OutputWavefront, OutputWavefrontPqControls, @@ -5855,10 +6357,12 @@ ) from .outputwizhec import ( OutputWizHec, + OutputWizHecEventFormat, OutputWizHecPqControls, OutputWizHecPqControlsTypedDict, OutputWizHecType, OutputWizHecTypedDict, + WizDefendSourceType, ) from .outputxsiam import ( OutputXsiam, @@ -5932,6 +6436,7 @@ ) from .paginatedpackinfo import PaginatedPackInfo, PaginatedPackInfoTypedDict from .paginatedpipeline import PaginatedPipeline, PaginatedPipelineTypedDict + from .paginatedroutes import PaginatedRoutes, PaginatedRoutesTypedDict from .paginatedsavedjobresponse import ( PaginatedSavedJobResponse, PaginatedSavedJobResponseTypedDict, @@ -6048,6 +6553,11 @@ PipelineFunctionConfInput, PipelineFunctionConfInputTypedDict, ) + from .pipelinefunctiondetectionrules import ( + PipelineFunctionDetectionRules, + PipelineFunctionDetectionRulesID, + PipelineFunctionDetectionRulesTypedDict, + ) from .pipelinefunctiondistinct import ( DistinctConfiguration, DistinctConfigurationTypedDict, @@ -6191,6 +6701,11 @@ PipelineFunctionLakeExportID, PipelineFunctionLakeExportTypedDict, ) + from .pipelinefunctionlakehouseenginemetricsnormalizer import ( + PipelineFunctionLakehouseEngineMetricsNormalizer, + PipelineFunctionLakehouseEngineMetricsNormalizerID, + PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict, + ) from .pipelinefunctionlimit import ( PipelineFunctionLimit, PipelineFunctionLimitID, @@ -6260,6 +6775,11 @@ PipelineFunctionMetricsExportMode2, PipelineFunctionMetricsExportTypedDict, ) + from .pipelinefunctionmetricstimerangegate import ( + PipelineFunctionMetricsTimeRangeGate, + PipelineFunctionMetricsTimeRangeGateID, + PipelineFunctionMetricsTimeRangeGateTypedDict, + ) from .pipelinefunctionmvexpand import ( BagExpansionMode, PipelineFunctionMvExpand, @@ -7678,6 +8198,11 @@ ScriptCollectorConf, ScriptCollectorConfTypedDict, ) + from .searchexecutionconfig import ( + BackendID, + SearchExecutionConfig, + SearchExecutionConfigTypedDict, + ) from .searchfilterconfinputprometheus import ( SearchFilterConfInputPrometheus, SearchFilterConfInputPrometheusTypedDict, @@ -7819,13 +8344,11 @@ from .systemsettingsconf import SystemSettingsConf, SystemSettingsConfTypedDict from .systemsettingsconfresponse import ( SystemSettingsConfResponse, - SystemSettingsConfResponseAPI, - SystemSettingsConfResponseAPITypedDict, - SystemSettingsConfResponseSystem, - SystemSettingsConfResponseSystemTypedDict, SystemSettingsConfResponseTypedDict, ) from .systemsettingsconfupdate import ( + API, + APITypedDict, Apps, AppsTypedDict, CustomLogo, @@ -7841,8 +8364,6 @@ Support, SupportTypedDict, SystemSettingsConfUpdate, - SystemSettingsConfUpdateAPI, - SystemSettingsConfUpdateAPITypedDict, SystemSettingsConfUpdateSystem, SystemSettingsConfUpdateSystemTypedDict, SystemSettingsConfUpdateTypedDict, @@ -7865,9 +8386,8 @@ TeamAccessControlList, TeamAccessControlListTypedDict, ) - from .templatetargetpairconffunctionconfschemanotificationpolicies import ( - TemplateTargetPairConfFunctionConfSchemaNotificationPolicies, - TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict, + from .templatefamilyoptionscriblsourceprovenance import ( + TemplateFamilyOptionsCriblSourceProvenance, ) from .timeoutretrysettingstype import ( TimeoutRetrySettingsType, @@ -7887,10 +8407,6 @@ from .timestamptypeoptionseventbreakerexistingornewnewtimestamp import ( TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp, ) - from .timewarningtyperunnablejobcollectionschedulerun import ( - TimeWarningTypeRunnableJobCollectionScheduleRun, - TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict, - ) from .tlsclientparams import TLSClientParams, TLSClientParamsTypedDict from .tlsoptionshostsitems import TLSOptionsHostsItems from .tlsoptionstyperedisdeploymenttypestandalone import ( @@ -8042,9 +8558,11 @@ __all__ = [ "AISIEMEndpointPath", + "API", "APIScheme", "APITypeSystemSettingsConf", "APITypeSystemSettingsConfTypedDict", + "APITypedDict", "AccountType", "AcknowledgmentsOptions", "AcknowledgmentsOptionsAllLeader", @@ -8096,10 +8614,6 @@ "AuthTokenConfOutputCriblHTTP", "AuthTokenConfOutputCriblHTTPTypedDict", "AuthTokenTypedDict", - "AuthTokensExt", - "AuthTokensExtConfInputHTTP", - "AuthTokensExtConfInputHTTPTypedDict", - "AuthTokensExtTypedDict", "AuthType", "AuthTypeEnum", "AuthTypeTemplatemanualAPIKeyAuthType", @@ -8111,9 +8625,10 @@ "AuthenticationMethodOptionsAPI", "AuthenticationMethodOptionsAuth", "AuthenticationMethodOptionsAuthManualManualAPIKey", + "AuthenticationMethodOptionsAuthTokensExtItems", "AuthenticationMethodOptionsAuthTokensItems", - "AuthenticationMethodOptionsAuthTokensItemsSecret", "AuthenticationMethodOptionsAutoSecret", + "AuthenticationMethodOptionsClientAssertionClientAssertionrpc", "AuthenticationMethodOptionsManualSecret", "AuthenticationMethodOptionsS3CollectorConf", "AuthenticationMethodOptionsSasl", @@ -8158,6 +8673,7 @@ "AzureBlobStorageTypedDict", "AzureTypeHeartbeatMetadata", "AzureTypeHeartbeatMetadataTypedDict", + "BackendID", "BackpressureBehaviorOptions", "BackpressureBehaviorOptionsBlockDrop", "BackupsSettings", @@ -8170,6 +8686,7 @@ "BlockTypedDict", "BranchInfo", "BranchInfoTypedDict", + "BucketWidth", "CacheConnection", "CacheConnectionTypedDict", "CaptureLevel", @@ -8177,8 +8694,10 @@ "CaptureParamsReqTypedDict", "CaptureSettings", "CaptureSettingsTypedDict", + "CertOptions", "CertOptionsType", "CertOptionsTypeTypedDict", + "CertOptionsTypedDict", "CertificateType", "CertificateTypeAzureBlobAuthTypeClientCert", "CertificateTypeAzureBlobAuthTypeClientCertTypedDict", @@ -8253,15 +8772,10 @@ "CompressionOptionsPersistence", "CompressionOptionsPq", "Condition", - "ConditionSpecificConfigurations1", - "ConditionSpecificConfigurations1TypedDict", - "ConditionSpecificConfigurations2", - "ConditionSpecificConfigurations2TypedDict", - "ConditionSpecificConfigurations3", - "ConditionSpecificConfigurations3TypedDict", "ConditionTypedDict", "ConfInput", "ConfInputTypedDict", + "Confidence", "Config", "ConfigGroup", "ConfigGroupCloud", @@ -8280,6 +8794,7 @@ "ContainerTypedDict", "ContentConfigInput", "ContentConfigInputTypedDict", + "ContentType", "CountComparator", "CountedBoolean", "CountedBooleanTypedDict", @@ -8369,13 +8884,14 @@ "CreateInputAuthMethodsExt", "CreateInputAuthMethodsExtAuthenticationType", "CreateInputAuthMethodsExtTypedDict", - "CreateInputAuthTokensExt", - "CreateInputAuthTokensExtTypedDict", "CreateInputAuthTypedDict", "CreateInputAuthenticationMechanism", "CreateInputAuthenticationProtocol", "CreateInputAzureBlobStorage", "CreateInputAzureBlobStorageTypedDict", + "CreateInputBucketWidth", + "CreateInputCertOptions", + "CreateInputCertOptionsTypedDict", "CreateInputCertificate", "CreateInputCertificateTypedDict", "CreateInputChatMessages", @@ -8394,21 +8910,22 @@ "CreateInputContainer", "CreateInputContainerMode", "CreateInputContainerTypedDict", + "CreateInputContentType", "CreateInputDNS", "CreateInputDNSTypedDict", "CreateInputDisksAndFileSystems", "CreateInputDisksAndFileSystemsTypedDict", - "CreateInputElasticsearchMetadata", - "CreateInputElasticsearchMetadataTypedDict", "CreateInputEndpointHeader", "CreateInputEndpointHeaderTypedDict", "CreateInputEndpointParam", "CreateInputEndpointParamTypedDict", "CreateInputEventFormat", + "CreateInputFeedType", "CreateInputFirewall", "CreateInputFirewallTypedDict", "CreateInputFormat", "CreateInputGrantType", + "CreateInputGroupBy", "CreateInputGroups", "CreateInputGroupsTypedDict", "CreateInputHecTokenByIDRequest", @@ -8418,9 +8935,17 @@ "CreateInputHostsFile", "CreateInputHostsFileTypedDict", "CreateInputInput", + "CreateInputInputAkamaiHec", + "CreateInputInputAkamaiHecType", + "CreateInputInputAkamaiHecTypedDict", "CreateInputInputAnthropicCompliance", "CreateInputInputAnthropicComplianceType", "CreateInputInputAnthropicComplianceTypedDict", + "CreateInputInputAnthropicEnterpriseAnalytics", + "CreateInputInputAnthropicEnterpriseAnalyticsContentConfig", + "CreateInputInputAnthropicEnterpriseAnalyticsContentConfigTypedDict", + "CreateInputInputAnthropicEnterpriseAnalyticsType", + "CreateInputInputAnthropicEnterpriseAnalyticsTypedDict", "CreateInputInputAppleUnifiedLogs", "CreateInputInputAppleUnifiedLogsReadMode", "CreateInputInputAppleUnifiedLogsType", @@ -8432,11 +8957,20 @@ "CreateInputInputAppscopePersistenceTypedDict", "CreateInputInputAppscopeType", "CreateInputInputAppscopeTypedDict", + "CreateInputInputAquaSecurityHec", + "CreateInputInputAquaSecurityHecType", + "CreateInputInputAquaSecurityHecTypedDict", "CreateInputInputAzureBlob", "CreateInputInputAzureBlobTypedDict", + "CreateInputInputAzureVnetFlowLog", + "CreateInputInputAzureVnetFlowLogType", + "CreateInputInputAzureVnetFlowLogTypedDict", "CreateInputInputBedrockS3", "CreateInputInputBedrockS3Type", "CreateInputInputBedrockS3TypedDict", + "CreateInputInputBeyondtrustHec", + "CreateInputInputBeyondtrustHecType", + "CreateInputInputBeyondtrustHecTypedDict", "CreateInputInputCloudflareHec", "CreateInputInputCloudflareHecType", "CreateInputInputCloudflareHecTypedDict", @@ -8450,6 +8984,12 @@ "CreateInputInputCriblHTTPType", "CreateInputInputCriblHTTPTypedDict", "CreateInputInputCriblLakeHTTP", + "CreateInputInputCriblLakeHTTPAuthTokensExt", + "CreateInputInputCriblLakeHTTPAuthTokensExtTypedDict", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "CreateInputInputCriblLakeHTTPType", "CreateInputInputCriblLakeHTTPTypedDict", "CreateInputInputCriblTCP", @@ -8484,7 +9024,6 @@ "CreateInputInputElasticTypedDict", "CreateInputInputEventhub", "CreateInputInputEventhubAmqp", - "CreateInputInputEventhubAmqpAuthenticationMethod", "CreateInputInputEventhubAmqpType", "CreateInputInputEventhubAmqpTypedDict", "CreateInputInputEventhubType", @@ -8492,6 +9031,12 @@ "CreateInputInputExec", "CreateInputInputExecType", "CreateInputInputExecTypedDict", + "CreateInputInputExtrahopRevealx360", + "CreateInputInputExtrahopRevealx360Type", + "CreateInputInputExtrahopRevealx360TypedDict", + "CreateInputInputF5BigIP", + "CreateInputInputF5BigIPType", + "CreateInputInputF5BigIPTypedDict", "CreateInputInputFile", "CreateInputInputFileMode", "CreateInputInputFileType", @@ -8499,6 +9044,9 @@ "CreateInputInputFirehose", "CreateInputInputFirehoseType", "CreateInputInputFirehoseTypedDict", + "CreateInputInputGigamonHec", + "CreateInputInputGigamonHecType", + "CreateInputInputGigamonHecTypedDict", "CreateInputInputGooglePubsub", "CreateInputInputGooglePubsubTypedDict", "CreateInputInputGrafanaGrafana1", @@ -8510,11 +9058,34 @@ "CreateInputInputGrafanaUnion", "CreateInputInputGrafanaUnionTypedDict", "CreateInputInputHTTP", + "CreateInputInputHTTPAuthTokensExt", + "CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata", + "CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict", + "CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata", + "CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict", + "CreateInputInputHTTPAuthTokensExtTypedDict", + "CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata", + "CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict", + "CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata", + "CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict", + "CreateInputInputHTTPInputHTTPAuthTokensExtItemsType", + "CreateInputInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint", + "CreateInputInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "CreateInputInputHTTPRaw", + "CreateInputInputHTTPRawAuthTokensExt", + "CreateInputInputHTTPRawAuthTokensExtTypedDict", + "CreateInputInputHTTPRawAuthTokensExtUnion", + "CreateInputInputHTTPRawAuthTokensExtUnionTypedDict", + "CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint", + "CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict", "CreateInputInputHTTPRawType", "CreateInputInputHTTPRawTypedDict", "CreateInputInputHTTPType", "CreateInputInputHTTPTypedDict", + "CreateInputInputHashicorpHcpVaultDedicated", + "CreateInputInputHashicorpHcpVaultDedicatedType", + "CreateInputInputHashicorpHcpVaultDedicatedTypedDict", "CreateInputInputJournalFiles", "CreateInputInputJournalFilesRule", "CreateInputInputJournalFilesRuleTypedDict", @@ -8543,10 +9114,21 @@ "CreateInputInputMetrics", "CreateInputInputMetricsType", "CreateInputInputMetricsTypedDict", + "CreateInputInputMicrosoftCopilot", + "CreateInputInputMicrosoftCopilotAuthenticationMethod", + "CreateInputInputMicrosoftCopilotManageState", + "CreateInputInputMicrosoftCopilotManageStateTypedDict", + "CreateInputInputMicrosoftCopilotSubscriptionPlan", + "CreateInputInputMicrosoftCopilotType", + "CreateInputInputMicrosoftCopilotTypedDict", "CreateInputInputMicrosoftGraph", "CreateInputInputMicrosoftGraphAuthenticationMethod", + "CreateInputInputMicrosoftGraphSubscriptionPlan", "CreateInputInputMicrosoftGraphType", "CreateInputInputMicrosoftGraphTypedDict", + "CreateInputInputMimecastHec", + "CreateInputInputMimecastHecType", + "CreateInputInputMimecastHecTypedDict", "CreateInputInputModelDrivenTelemetry", "CreateInputInputModelDrivenTelemetryType", "CreateInputInputModelDrivenTelemetryTypedDict", @@ -8590,12 +9172,18 @@ "CreateInputInputOpenaiManageStateTypedDict", "CreateInputInputOpenaiType", "CreateInputInputOpenaiTypedDict", + "CreateInputInputPingIdentityPingone", + "CreateInputInputPingIdentityPingoneType", + "CreateInputInputPingIdentityPingoneTypedDict", "CreateInputInputPrometheus", "CreateInputInputPrometheusDiscoveryType", "CreateInputInputPrometheusRw", "CreateInputInputPrometheusRwType", "CreateInputInputPrometheusRwTypedDict", "CreateInputInputPrometheusTypedDict", + "CreateInputInputProofpointPod", + "CreateInputInputProofpointPodType", + "CreateInputInputProofpointPodTypedDict", "CreateInputInputRawUDP", "CreateInputInputRawUDPType", "CreateInputInputRawUDPTypedDict", @@ -8604,6 +9192,9 @@ "CreateInputInputS3InventoryType", "CreateInputInputS3InventoryTypedDict", "CreateInputInputS3TypedDict", + "CreateInputInputSailpointHec", + "CreateInputInputSailpointHecType", + "CreateInputInputSailpointHecTypedDict", "CreateInputInputSecurityLake", "CreateInputInputSecurityLakeTypedDict", "CreateInputInputServicenowTable", @@ -8675,10 +9266,19 @@ "CreateInputInputTCPTypedDict", "CreateInputInputTcpjson", "CreateInputInputTcpjsonTypedDict", + "CreateInputInputTrellixHec", + "CreateInputInputTrellixHecType", + "CreateInputInputTrellixHecTypedDict", + "CreateInputInputTrendMicroVisionOne", + "CreateInputInputTrendMicroVisionOneType", + "CreateInputInputTrendMicroVisionOneTypedDict", "CreateInputInputTypedDict", "CreateInputInputUpwindHec", "CreateInputInputUpwindHecType", "CreateInputInputUpwindHecTypedDict", + "CreateInputInputVectraAiHec", + "CreateInputInputVectraAiHecType", + "CreateInputInputVectraAiHecTypedDict", "CreateInputInputWef", "CreateInputInputWefAuthenticationMethod", "CreateInputInputWefType", @@ -8719,6 +9319,12 @@ "CreateInputInputWizType", "CreateInputInputWizTypedDict", "CreateInputInputWizWebhook", + "CreateInputInputWizWebhookAuthTokensExt1", + "CreateInputInputWizWebhookAuthTokensExt1TypedDict", + "CreateInputInputWizWebhookAuthTokensExt2", + "CreateInputInputWizWebhookAuthTokensExt2TypedDict", + "CreateInputInputWizWebhookAuthTokensExtUnion", + "CreateInputInputWizWebhookAuthTokensExtUnionTypedDict", "CreateInputInputWizWebhookType", "CreateInputInputWizWebhookTypedDict", "CreateInputInputZscalerHec", @@ -8769,6 +9375,8 @@ "CreateInputQueryTypedDict", "CreateInputQueueType", "CreateInputRecordDataFormat", + "CreateInputRetryRules", + "CreateInputRetryRulesTypedDict", "CreateInputRoutes", "CreateInputRoutesTypedDict", "CreateInputSNMPv3Authentication", @@ -8783,10 +9391,7 @@ "CreateInputShardIteratorStart", "CreateInputShardLoadBalancing", "CreateInputSortDirection", - "CreateInputSplunkHecMetadata", - "CreateInputSplunkHecMetadataTypedDict", "CreateInputSubscription", - "CreateInputSubscriptionPlan", "CreateInputSubscriptionTypedDict", "CreateInputSystemByPackAPIVersion", "CreateInputSystemByPackAccountType", @@ -8800,13 +9405,14 @@ "CreateInputSystemByPackAuthMethodsExt", "CreateInputSystemByPackAuthMethodsExtAuthenticationType", "CreateInputSystemByPackAuthMethodsExtTypedDict", - "CreateInputSystemByPackAuthTokensExt", - "CreateInputSystemByPackAuthTokensExtTypedDict", "CreateInputSystemByPackAuthTypedDict", "CreateInputSystemByPackAuthenticationMechanism", "CreateInputSystemByPackAuthenticationProtocol", "CreateInputSystemByPackAzureBlobStorage", "CreateInputSystemByPackAzureBlobStorageTypedDict", + "CreateInputSystemByPackBucketWidth", + "CreateInputSystemByPackCertOptions", + "CreateInputSystemByPackCertOptionsTypedDict", "CreateInputSystemByPackCertificate", "CreateInputSystemByPackCertificateTypedDict", "CreateInputSystemByPackChatMessages", @@ -8825,21 +9431,22 @@ "CreateInputSystemByPackContainer", "CreateInputSystemByPackContainerMode", "CreateInputSystemByPackContainerTypedDict", + "CreateInputSystemByPackContentType", "CreateInputSystemByPackDNS", "CreateInputSystemByPackDNSTypedDict", "CreateInputSystemByPackDisksAndFileSystems", "CreateInputSystemByPackDisksAndFileSystemsTypedDict", - "CreateInputSystemByPackElasticsearchMetadata", - "CreateInputSystemByPackElasticsearchMetadataTypedDict", "CreateInputSystemByPackEndpointHeader", "CreateInputSystemByPackEndpointHeaderTypedDict", "CreateInputSystemByPackEndpointParam", "CreateInputSystemByPackEndpointParamTypedDict", "CreateInputSystemByPackEventFormat", + "CreateInputSystemByPackFeedType", "CreateInputSystemByPackFirewall", "CreateInputSystemByPackFirewallTypedDict", "CreateInputSystemByPackFormat", "CreateInputSystemByPackGrantType", + "CreateInputSystemByPackGroupBy", "CreateInputSystemByPackGroups", "CreateInputSystemByPackGroupsTypedDict", "CreateInputSystemByPackHostInfo", @@ -8847,9 +9454,17 @@ "CreateInputSystemByPackHostsFile", "CreateInputSystemByPackHostsFileTypedDict", "CreateInputSystemByPackInput", + "CreateInputSystemByPackInputAkamaiHec", + "CreateInputSystemByPackInputAkamaiHecType", + "CreateInputSystemByPackInputAkamaiHecTypedDict", "CreateInputSystemByPackInputAnthropicCompliance", "CreateInputSystemByPackInputAnthropicComplianceType", "CreateInputSystemByPackInputAnthropicComplianceTypedDict", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalytics", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfigTypedDict", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsTypedDict", "CreateInputSystemByPackInputAppleUnifiedLogs", "CreateInputSystemByPackInputAppleUnifiedLogsReadMode", "CreateInputSystemByPackInputAppleUnifiedLogsType", @@ -8861,11 +9476,20 @@ "CreateInputSystemByPackInputAppscopePersistenceTypedDict", "CreateInputSystemByPackInputAppscopeType", "CreateInputSystemByPackInputAppscopeTypedDict", + "CreateInputSystemByPackInputAquaSecurityHec", + "CreateInputSystemByPackInputAquaSecurityHecType", + "CreateInputSystemByPackInputAquaSecurityHecTypedDict", "CreateInputSystemByPackInputAzureBlob", "CreateInputSystemByPackInputAzureBlobTypedDict", + "CreateInputSystemByPackInputAzureVnetFlowLog", + "CreateInputSystemByPackInputAzureVnetFlowLogType", + "CreateInputSystemByPackInputAzureVnetFlowLogTypedDict", "CreateInputSystemByPackInputBedrockS3", "CreateInputSystemByPackInputBedrockS3Type", "CreateInputSystemByPackInputBedrockS3TypedDict", + "CreateInputSystemByPackInputBeyondtrustHec", + "CreateInputSystemByPackInputBeyondtrustHecType", + "CreateInputSystemByPackInputBeyondtrustHecTypedDict", "CreateInputSystemByPackInputCloudflareHec", "CreateInputSystemByPackInputCloudflareHecType", "CreateInputSystemByPackInputCloudflareHecTypedDict", @@ -8879,6 +9503,12 @@ "CreateInputSystemByPackInputCriblHTTPType", "CreateInputSystemByPackInputCriblHTTPTypedDict", "CreateInputSystemByPackInputCriblLakeHTTP", + "CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt", + "CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExtTypedDict", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "CreateInputSystemByPackInputCriblLakeHTTPType", "CreateInputSystemByPackInputCriblLakeHTTPTypedDict", "CreateInputSystemByPackInputCriblTCP", @@ -8913,7 +9543,6 @@ "CreateInputSystemByPackInputElasticTypedDict", "CreateInputSystemByPackInputEventhub", "CreateInputSystemByPackInputEventhubAmqp", - "CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod", "CreateInputSystemByPackInputEventhubAmqpType", "CreateInputSystemByPackInputEventhubAmqpTypedDict", "CreateInputSystemByPackInputEventhubType", @@ -8921,6 +9550,12 @@ "CreateInputSystemByPackInputExec", "CreateInputSystemByPackInputExecType", "CreateInputSystemByPackInputExecTypedDict", + "CreateInputSystemByPackInputExtrahopRevealx360", + "CreateInputSystemByPackInputExtrahopRevealx360Type", + "CreateInputSystemByPackInputExtrahopRevealx360TypedDict", + "CreateInputSystemByPackInputF5BigIP", + "CreateInputSystemByPackInputF5BigIPType", + "CreateInputSystemByPackInputF5BigIPTypedDict", "CreateInputSystemByPackInputFile", "CreateInputSystemByPackInputFileMode", "CreateInputSystemByPackInputFileType", @@ -8928,6 +9563,9 @@ "CreateInputSystemByPackInputFirehose", "CreateInputSystemByPackInputFirehoseType", "CreateInputSystemByPackInputFirehoseTypedDict", + "CreateInputSystemByPackInputGigamonHec", + "CreateInputSystemByPackInputGigamonHecType", + "CreateInputSystemByPackInputGigamonHecTypedDict", "CreateInputSystemByPackInputGooglePubsub", "CreateInputSystemByPackInputGooglePubsubTypedDict", "CreateInputSystemByPackInputGrafanaGrafana1", @@ -8939,11 +9577,34 @@ "CreateInputSystemByPackInputGrafanaUnion", "CreateInputSystemByPackInputGrafanaUnionTypedDict", "CreateInputSystemByPackInputHTTP", + "CreateInputSystemByPackInputHTTPAuthTokensExt", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict", + "CreateInputSystemByPackInputHTTPAuthTokensExtTypedDict", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "CreateInputSystemByPackInputHTTPRaw", + "CreateInputSystemByPackInputHTTPRawAuthTokensExt", + "CreateInputSystemByPackInputHTTPRawAuthTokensExtTypedDict", + "CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion", + "CreateInputSystemByPackInputHTTPRawAuthTokensExtUnionTypedDict", + "CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint", + "CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict", "CreateInputSystemByPackInputHTTPRawType", "CreateInputSystemByPackInputHTTPRawTypedDict", "CreateInputSystemByPackInputHTTPType", "CreateInputSystemByPackInputHTTPTypedDict", + "CreateInputSystemByPackInputHashicorpHcpVaultDedicated", + "CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType", + "CreateInputSystemByPackInputHashicorpHcpVaultDedicatedTypedDict", "CreateInputSystemByPackInputJournalFiles", "CreateInputSystemByPackInputJournalFilesRule", "CreateInputSystemByPackInputJournalFilesRuleTypedDict", @@ -8972,10 +9633,21 @@ "CreateInputSystemByPackInputMetrics", "CreateInputSystemByPackInputMetricsType", "CreateInputSystemByPackInputMetricsTypedDict", + "CreateInputSystemByPackInputMicrosoftCopilot", + "CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod", + "CreateInputSystemByPackInputMicrosoftCopilotManageState", + "CreateInputSystemByPackInputMicrosoftCopilotManageStateTypedDict", + "CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan", + "CreateInputSystemByPackInputMicrosoftCopilotType", + "CreateInputSystemByPackInputMicrosoftCopilotTypedDict", "CreateInputSystemByPackInputMicrosoftGraph", "CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod", + "CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan", "CreateInputSystemByPackInputMicrosoftGraphType", "CreateInputSystemByPackInputMicrosoftGraphTypedDict", + "CreateInputSystemByPackInputMimecastHec", + "CreateInputSystemByPackInputMimecastHecType", + "CreateInputSystemByPackInputMimecastHecTypedDict", "CreateInputSystemByPackInputModelDrivenTelemetry", "CreateInputSystemByPackInputModelDrivenTelemetryType", "CreateInputSystemByPackInputModelDrivenTelemetryTypedDict", @@ -9019,12 +9691,18 @@ "CreateInputSystemByPackInputOpenaiManageStateTypedDict", "CreateInputSystemByPackInputOpenaiType", "CreateInputSystemByPackInputOpenaiTypedDict", + "CreateInputSystemByPackInputPingIdentityPingone", + "CreateInputSystemByPackInputPingIdentityPingoneType", + "CreateInputSystemByPackInputPingIdentityPingoneTypedDict", "CreateInputSystemByPackInputPrometheus", "CreateInputSystemByPackInputPrometheusDiscoveryType", "CreateInputSystemByPackInputPrometheusRw", "CreateInputSystemByPackInputPrometheusRwType", "CreateInputSystemByPackInputPrometheusRwTypedDict", "CreateInputSystemByPackInputPrometheusTypedDict", + "CreateInputSystemByPackInputProofpointPod", + "CreateInputSystemByPackInputProofpointPodType", + "CreateInputSystemByPackInputProofpointPodTypedDict", "CreateInputSystemByPackInputRawUDP", "CreateInputSystemByPackInputRawUDPType", "CreateInputSystemByPackInputRawUDPTypedDict", @@ -9033,6 +9711,9 @@ "CreateInputSystemByPackInputS3InventoryType", "CreateInputSystemByPackInputS3InventoryTypedDict", "CreateInputSystemByPackInputS3TypedDict", + "CreateInputSystemByPackInputSailpointHec", + "CreateInputSystemByPackInputSailpointHecType", + "CreateInputSystemByPackInputSailpointHecTypedDict", "CreateInputSystemByPackInputSecurityLake", "CreateInputSystemByPackInputSecurityLakeTypedDict", "CreateInputSystemByPackInputServicenowTable", @@ -9104,10 +9785,19 @@ "CreateInputSystemByPackInputTCPTypedDict", "CreateInputSystemByPackInputTcpjson", "CreateInputSystemByPackInputTcpjsonTypedDict", + "CreateInputSystemByPackInputTrellixHec", + "CreateInputSystemByPackInputTrellixHecType", + "CreateInputSystemByPackInputTrellixHecTypedDict", + "CreateInputSystemByPackInputTrendMicroVisionOne", + "CreateInputSystemByPackInputTrendMicroVisionOneType", + "CreateInputSystemByPackInputTrendMicroVisionOneTypedDict", "CreateInputSystemByPackInputTypedDict", "CreateInputSystemByPackInputUpwindHec", "CreateInputSystemByPackInputUpwindHecType", "CreateInputSystemByPackInputUpwindHecTypedDict", + "CreateInputSystemByPackInputVectraAiHec", + "CreateInputSystemByPackInputVectraAiHecType", + "CreateInputSystemByPackInputVectraAiHecTypedDict", "CreateInputSystemByPackInputWef", "CreateInputSystemByPackInputWefAuthenticationMethod", "CreateInputSystemByPackInputWefType", @@ -9148,6 +9838,12 @@ "CreateInputSystemByPackInputWizType", "CreateInputSystemByPackInputWizTypedDict", "CreateInputSystemByPackInputWizWebhook", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt1", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt1TypedDict", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt2", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt2TypedDict", + "CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion", + "CreateInputSystemByPackInputWizWebhookAuthTokensExtUnionTypedDict", "CreateInputSystemByPackInputWizWebhookType", "CreateInputSystemByPackInputWizWebhookTypedDict", "CreateInputSystemByPackInputZscalerHec", @@ -9200,6 +9896,8 @@ "CreateInputSystemByPackRecordDataFormat", "CreateInputSystemByPackRequest", "CreateInputSystemByPackRequestTypedDict", + "CreateInputSystemByPackRetryRules", + "CreateInputSystemByPackRetryRulesTypedDict", "CreateInputSystemByPackRoutes", "CreateInputSystemByPackRoutesTypedDict", "CreateInputSystemByPackSNMPv3Authentication", @@ -9214,10 +9912,7 @@ "CreateInputSystemByPackShardIteratorStart", "CreateInputSystemByPackShardLoadBalancing", "CreateInputSystemByPackSortDirection", - "CreateInputSystemByPackSplunkHecMetadata", - "CreateInputSystemByPackSplunkHecMetadataTypedDict", "CreateInputSystemByPackSubscription", - "CreateInputSystemByPackSubscriptionPlan", "CreateInputSystemByPackSubscriptionTypedDict", "CreateInputSystemByPackTLSSettingsServerSide", "CreateInputSystemByPackTLSSettingsServerSideTypedDict", @@ -9227,6 +9922,8 @@ "CreateInputSystemByPackUNIXSocketPermissionsTypedDict", "CreateInputSystemByPackUsersAndGroups", "CreateInputSystemByPackUsersAndGroupsTypedDict", + "CreateInputSystemByPackV3AuthenticationKeyType", + "CreateInputSystemByPackV3PrivacyKeyType", "CreateInputSystemByPackV3User", "CreateInputSystemByPackV3UserTypedDict", "CreateInputSystemHecTokenByPackAndIDRequest", @@ -9239,6 +9936,8 @@ "CreateInputUNIXSocketPermissionsTypedDict", "CreateInputUsersAndGroups", "CreateInputUsersAndGroupsTypedDict", + "CreateInputV3AuthenticationKeyType", + "CreateInputV3PrivacyKeyType", "CreateInputV3User", "CreateInputV3UserTypedDict", "CreateOutputAISIEMEndpointPath", @@ -9263,6 +9962,7 @@ "CreateOutputElasticVersion", "CreateOutputEndpointConfiguration", "CreateOutputEndpointType", + "CreateOutputEventFormat", "CreateOutputExtentTag", "CreateOutputExtentTagTypedDict", "CreateOutputExtraLogType", @@ -9279,6 +9979,7 @@ "CreateOutputMessageFormat", "CreateOutputMetadatum", "CreateOutputMetadatumTypedDict", + "CreateOutputOAuthSecretSource", "CreateOutputOutput", "CreateOutputOutputAlibabaCloudS3", "CreateOutputOutputAlibabaCloudS3AuthenticationMethod", @@ -9368,6 +10069,11 @@ "CreateOutputOutputDatabricks", "CreateOutputOutputDatabricksType", "CreateOutputOutputDatabricksTypedDict", + "CreateOutputOutputDatabricksZerobus", + "CreateOutputOutputDatabricksZerobusPqControls", + "CreateOutputOutputDatabricksZerobusPqControlsTypedDict", + "CreateOutputOutputDatabricksZerobusType", + "CreateOutputOutputDatabricksZerobusTypedDict", "CreateOutputOutputDatadog", "CreateOutputOutputDatadogPqControls", "CreateOutputOutputDatadogPqControlsTypedDict", @@ -9422,6 +10128,7 @@ "CreateOutputOutputElasticURL", "CreateOutputOutputElasticURLTypedDict", "CreateOutputOutputExabeam", + "CreateOutputOutputExabeamAuthenticationMethod", "CreateOutputOutputExabeamType", "CreateOutputOutputExabeamTypedDict", "CreateOutputOutputFilesystem", @@ -9655,6 +10362,12 @@ "CreateOutputOutputTcpjsonPqControls", "CreateOutputOutputTcpjsonPqControlsTypedDict", "CreateOutputOutputTcpjsonTypedDict", + "CreateOutputOutputTraversalOtlp", + "CreateOutputOutputTraversalOtlpAuthenticationType", + "CreateOutputOutputTraversalOtlpPqControls", + "CreateOutputOutputTraversalOtlpPqControlsTypedDict", + "CreateOutputOutputTraversalOtlpType", + "CreateOutputOutputTraversalOtlpTypedDict", "CreateOutputOutputTypedDict", "CreateOutputOutputWavefront", "CreateOutputOutputWavefrontPqControls", @@ -9704,6 +10417,7 @@ "CreateOutputReportMethod", "CreateOutputRule", "CreateOutputRuleTypedDict", + "CreateOutputSendAs", "CreateOutputSendEventsAs", "CreateOutputSendLogsAs", "CreateOutputStatsDestination", @@ -9730,6 +10444,7 @@ "CreateOutputSystemByPackElasticVersion", "CreateOutputSystemByPackEndpointConfiguration", "CreateOutputSystemByPackEndpointType", + "CreateOutputSystemByPackEventFormat", "CreateOutputSystemByPackExtentTag", "CreateOutputSystemByPackExtentTagTypedDict", "CreateOutputSystemByPackExtraLogType", @@ -9746,6 +10461,7 @@ "CreateOutputSystemByPackMessageFormat", "CreateOutputSystemByPackMetadatum", "CreateOutputSystemByPackMetadatumTypedDict", + "CreateOutputSystemByPackOAuthSecretSource", "CreateOutputSystemByPackOutput", "CreateOutputSystemByPackOutputAlibabaCloudS3", "CreateOutputSystemByPackOutputAlibabaCloudS3AuthenticationMethod", @@ -9835,6 +10551,11 @@ "CreateOutputSystemByPackOutputDatabricks", "CreateOutputSystemByPackOutputDatabricksType", "CreateOutputSystemByPackOutputDatabricksTypedDict", + "CreateOutputSystemByPackOutputDatabricksZerobus", + "CreateOutputSystemByPackOutputDatabricksZerobusPqControls", + "CreateOutputSystemByPackOutputDatabricksZerobusPqControlsTypedDict", + "CreateOutputSystemByPackOutputDatabricksZerobusType", + "CreateOutputSystemByPackOutputDatabricksZerobusTypedDict", "CreateOutputSystemByPackOutputDatadog", "CreateOutputSystemByPackOutputDatadogPqControls", "CreateOutputSystemByPackOutputDatadogPqControlsTypedDict", @@ -9889,6 +10610,7 @@ "CreateOutputSystemByPackOutputElasticURL", "CreateOutputSystemByPackOutputElasticURLTypedDict", "CreateOutputSystemByPackOutputExabeam", + "CreateOutputSystemByPackOutputExabeamAuthenticationMethod", "CreateOutputSystemByPackOutputExabeamType", "CreateOutputSystemByPackOutputExabeamTypedDict", "CreateOutputSystemByPackOutputFilesystem", @@ -10122,6 +10844,12 @@ "CreateOutputSystemByPackOutputTcpjsonPqControls", "CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict", "CreateOutputSystemByPackOutputTcpjsonTypedDict", + "CreateOutputSystemByPackOutputTraversalOtlp", + "CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType", + "CreateOutputSystemByPackOutputTraversalOtlpPqControls", + "CreateOutputSystemByPackOutputTraversalOtlpPqControlsTypedDict", + "CreateOutputSystemByPackOutputTraversalOtlpType", + "CreateOutputSystemByPackOutputTraversalOtlpTypedDict", "CreateOutputSystemByPackOutputTypedDict", "CreateOutputSystemByPackOutputWavefront", "CreateOutputSystemByPackOutputWavefrontPqControls", @@ -10173,6 +10901,7 @@ "CreateOutputSystemByPackRequestTypedDict", "CreateOutputSystemByPackRule", "CreateOutputSystemByPackRuleTypedDict", + "CreateOutputSystemByPackSendAs", "CreateOutputSystemByPackSendEventsAs", "CreateOutputSystemByPackSendLogsAs", "CreateOutputSystemByPackStatsDestination", @@ -10181,6 +10910,7 @@ "CreateOutputSystemByPackTimestampFormat", "CreateOutputSystemByPackTimestampPrecision", "CreateOutputSystemByPackUDMType", + "CreateOutputSystemByPackWizDefendSourceType", "CreateOutputSystemByPackWriteAction", "CreateOutputSystemTestByPackAndIDRequest", "CreateOutputSystemTestByPackAndIDRequestTypedDict", @@ -10190,6 +10920,7 @@ "CreateOutputTimestampFormat", "CreateOutputTimestampPrecision", "CreateOutputUDMType", + "CreateOutputWizDefendSourceType", "CreateOutputWriteAction", "CreatePipelinesByPackRequest", "CreatePipelinesByPackRequestTypedDict", @@ -10272,6 +11003,7 @@ "DeleteProductsGroupsByProductAndIDRequestTypedDict", "DeleteSavedJobByIDRequest", "DeleteSavedJobByIDRequestTypedDict", + "DeployMode", "DeployRequest", "DeployRequestLookups", "DeployRequestLookupsLookup", @@ -10308,14 +11040,8 @@ "DistributedSummaryWorkers", "DistributedSummaryWorkersTypedDict", "ElasticVersion", - "ElasticsearchMetadata", - "ElasticsearchMetadataTypedDict", - "EmailRecipient1", - "EmailRecipient1TypedDict", - "EmailRecipient2", - "EmailRecipient2TypedDict", - "EmailRecipient3", - "EmailRecipient3TypedDict", + "EmailRecipient", + "EmailRecipientTypedDict", "EmptyObject", "EmptyObjectTypedDict", "EndpointConfiguration", @@ -10354,11 +11080,8 @@ "EventBreakerExistingOrNewNewTimestampTypeFormatTypedDict", "EventBreakerExistingOrNewNewTypedDict", "EventBreakerTypeOptionsEventBreakerExistingOrNewNew", - "EventFormat", "EventstatsConfiguration", "EventstatsConfigurationTypedDict", - "ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor", - "ExecutorSpecificSettingsTypeRunnableJobExecutorExecutorTypedDict", "ExecutorTypeRunnableJobExecutor", "ExecutorTypeRunnableJobExecutorTypedDict", "Extension", @@ -10375,9 +11098,12 @@ "FeatureFlagOverrideConfSystemSettingsConf", "FeatureFlagOverrideConfSystemSettingsConfTypedDict", "FeatureFlagOverrideTypedDict", + "FeedType", "FieldCondition", "FieldConditionTypedDict", "FieldName", + "FieldOverride", + "FieldOverrideTypedDict", "File", "FileTypedDict", "FilesystemCollectorConf", @@ -10428,6 +11154,9 @@ "FunctionConfSchemaCommentTypedDict", "FunctionConfSchemaDNSLookup", "FunctionConfSchemaDNSLookupTypedDict", + "FunctionConfSchemaDetectionRules", + "FunctionConfSchemaDetectionRulesSeverity", + "FunctionConfSchemaDetectionRulesTypedDict", "FunctionConfSchemaDrop", "FunctionConfSchemaDropTypedDict", "FunctionConfSchemaEval", @@ -10442,6 +11171,8 @@ "FunctionConfSchemaFoldkeysTypedDict", "FunctionConfSchemaGenStats", "FunctionConfSchemaGenStatsTypedDict", + "FunctionConfSchemaLakehouseEngineMetricsNormalizer", + "FunctionConfSchemaLakehouseEngineMetricsNormalizerTypedDict", "FunctionConfSchemaLimit", "FunctionConfSchemaLimitTypedDict", "FunctionConfSchemaLocalSearchDatatypeParser", @@ -10454,7 +11185,11 @@ "FunctionConfSchemaLocalSearchTimeRangeNormalizerTypedDict", "FunctionConfSchemaLocalSearchTransformer", "FunctionConfSchemaLocalSearchTransformerTypedDict", + "FunctionConfSchemaMetricsTimeRangeGate", + "FunctionConfSchemaMetricsTimeRangeGateTypedDict", "FunctionConfSchemaNotificationPolicies", + "FunctionConfSchemaNotificationPoliciesTemplateTargetPair", + "FunctionConfSchemaNotificationPoliciesTemplateTargetPairTypedDict", "FunctionConfSchemaNotificationPoliciesTypedDict", "FunctionConfSchemaNumerify", "FunctionConfSchemaNumerifyTypedDict", @@ -10492,6 +11227,9 @@ "FunctionDNSLookup", "FunctionDNSLookupID", "FunctionDNSLookupTypedDict", + "FunctionDetectionRules", + "FunctionDetectionRulesID", + "FunctionDetectionRulesTypedDict", "FunctionDistinct", "FunctionDistinctID", "FunctionDistinctTypedDict", @@ -10543,6 +11281,9 @@ "FunctionLakeExport", "FunctionLakeExportID", "FunctionLakeExportTypedDict", + "FunctionLakehouseEngineMetricsNormalizer", + "FunctionLakehouseEngineMetricsNormalizerID", + "FunctionLakehouseEngineMetricsNormalizerTypedDict", "FunctionLimit", "FunctionLimitID", "FunctionLimitTypedDict", @@ -10570,6 +11311,9 @@ "FunctionMetricsExport", "FunctionMetricsExportID", "FunctionMetricsExportTypedDict", + "FunctionMetricsTimeRangeGate", + "FunctionMetricsTimeRangeGateID", + "FunctionMetricsTimeRangeGateTypedDict", "FunctionMvExpand", "FunctionMvExpandID", "FunctionMvExpandTypedDict", @@ -10697,6 +11441,10 @@ "GetInputByIDRequestTypedDict", "GetInputPqByIDRequest", "GetInputPqByIDRequestTypedDict", + "GetInputRequest", + "GetInputRequestTypedDict", + "GetInputResponse", + "GetInputResponseTypedDict", "GetInputStatusByIDRequest", "GetInputStatusByIDRequestTypedDict", "GetInputStatusRequest", @@ -10721,6 +11469,10 @@ "GetOutputByIDRequestTypedDict", "GetOutputPqByIDRequest", "GetOutputPqByIDRequestTypedDict", + "GetOutputRequest", + "GetOutputRequestTypedDict", + "GetOutputResponse", + "GetOutputResponseTypedDict", "GetOutputSamplesByIDRequest", "GetOutputSamplesByIDRequestTypedDict", "GetOutputStatusByIDRequest", @@ -10793,6 +11545,12 @@ "GetRoutesByPackAndIDRequestTypedDict", "GetRoutesByPackRequest", "GetRoutesByPackRequestTypedDict", + "GetRoutesByPackResponse", + "GetRoutesByPackResponseTypedDict", + "GetRoutesRequest", + "GetRoutesRequestTypedDict", + "GetRoutesResponse", + "GetRoutesResponseTypedDict", "GetSavedJobByIDRequest", "GetSavedJobByIDRequestTypedDict", "GetSavedJobRequest", @@ -10866,6 +11624,7 @@ "GpuType", "GpuTypeTypedDict", "GrantType", + "GroupBy", "GroupCreateRequest", "GroupCreateRequestTypedDict", "HBCriblInfo", @@ -11260,6 +12019,7 @@ "HostOsTypeHeartbeatMetadataTypedDict", "HostsFile", "HostsFileTypedDict", + "Impact", "InField", "InFieldTypedDict", "IndexerDiscoveryConfigs", @@ -11267,12 +12027,22 @@ "IngestIfNotExist", "IngestIfNotExistTypedDict", "IngestionMode", + "InlineRule", + "InlineRuleTypedDict", "Input", + "InputAkamaiHecInput", + "InputAkamaiHecInputTypedDict", + "InputAkamaiHecType", "InputAnthropicComplianceGroups", "InputAnthropicComplianceGroupsTypedDict", "InputAnthropicComplianceInput", "InputAnthropicComplianceInputTypedDict", "InputAnthropicComplianceType", + "InputAnthropicEnterpriseAnalyticsContentConfig", + "InputAnthropicEnterpriseAnalyticsContentConfigTypedDict", + "InputAnthropicEnterpriseAnalyticsInput", + "InputAnthropicEnterpriseAnalyticsInputTypedDict", + "InputAnthropicEnterpriseAnalyticsType", "InputAppleUnifiedLogsInput", "InputAppleUnifiedLogsInputTypedDict", "InputAppleUnifiedLogsReadMode", @@ -11284,18 +12054,25 @@ "InputAppscopePersistence", "InputAppscopePersistenceTypedDict", "InputAppscopeType", + "InputAquaSecurityHecInput", + "InputAquaSecurityHecInputTypedDict", + "InputAquaSecurityHecType", "InputAzureBlobInput", "InputAzureBlobInputTypedDict", + "InputAzureVnetFlowLogInput", + "InputAzureVnetFlowLogInputTypedDict", + "InputAzureVnetFlowLogType", "InputBedrockS3Input", "InputBedrockS3InputTypedDict", "InputBedrockS3Type", + "InputBeyondtrustHecInput", + "InputBeyondtrustHecInputTypedDict", + "InputBeyondtrustHecType", "InputCloudflareHecInput", "InputCloudflareHecInputTypedDict", "InputCloudflareHecType", "InputCollectionInput", "InputCollectionInputTypedDict", - "InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint", - "InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict", "InputCollectionType", "InputConfluentCloudInput", "InputConfluentCloudInputTypedDict", @@ -11304,7 +12081,13 @@ "InputCriblHTTPType", "InputCriblInput", "InputCriblInputTypedDict", + "InputCriblLakeHTTPAuthTokensExt", + "InputCriblLakeHTTPAuthTokensExtTypedDict", "InputCriblLakeHTTPInput", + "InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType", + "InputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint", + "InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "InputCriblLakeHTTPInputTypedDict", "InputCriblLakeHTTPType", "InputCriblTCPInput", @@ -11337,7 +12120,6 @@ "InputElasticProxyMode", "InputElasticProxyModeTypedDict", "InputElasticType", - "InputEventhubAmqpAuthenticationMethod", "InputEventhubAmqpCertificate", "InputEventhubAmqpCertificateTypedDict", "InputEventhubAmqpInput", @@ -11349,6 +12131,12 @@ "InputExecInput", "InputExecInputTypedDict", "InputExecType", + "InputExtrahopRevealx360Input", + "InputExtrahopRevealx360InputTypedDict", + "InputExtrahopRevealx360Type", + "InputF5BigIPInput", + "InputF5BigIPInputTypedDict", + "InputF5BigIPType", "InputFileInput", "InputFileInputTypedDict", "InputFileMode", @@ -11356,6 +12144,9 @@ "InputFirehoseInput", "InputFirehoseInputTypedDict", "InputFirehoseType", + "InputGigamonHecInput", + "InputGigamonHecInputTypedDict", + "InputGigamonHecType", "InputGooglePubsubInput", "InputGooglePubsubInputTypedDict", "InputGrafanaGrafanaInput1", @@ -11366,12 +12157,35 @@ "InputGrafanaInputUnionTypedDict", "InputGrafanaType1", "InputGrafanaType2", + "InputHTTPAuthTokensExt", + "InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata", + "InputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict", + "InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata", + "InputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict", + "InputHTTPAuthTokensExtTypedDict", + "InputHTTPAuthTypeSecretConstraintElasticsearchMetadata", + "InputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict", + "InputHTTPAuthTypeSecretConstraintSplunkHecMetadata", + "InputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict", "InputHTTPInput", + "InputHTTPInputHTTPAuthTokensExtItemsType", + "InputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "InputHTTPInputHTTPAuthTypeSecretConstraint", + "InputHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "InputHTTPInputTypedDict", + "InputHTTPRawAuthTokensExt", + "InputHTTPRawAuthTokensExtTypedDict", + "InputHTTPRawAuthTokensExtUnion", + "InputHTTPRawAuthTokensExtUnionTypedDict", "InputHTTPRawInput", + "InputHTTPRawInputHTTPAuthTypeSecretConstraint", + "InputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict", "InputHTTPRawInputTypedDict", "InputHTTPRawType", "InputHTTPType", + "InputHashicorpHcpVaultDedicatedInput", + "InputHashicorpHcpVaultDedicatedInputTypedDict", + "InputHashicorpHcpVaultDedicatedType", "InputJournalFilesInput", "InputJournalFilesInputTypedDict", "InputJournalFilesRule", @@ -11400,10 +12214,23 @@ "InputMetricsInput", "InputMetricsInputTypedDict", "InputMetricsType", + "InputMicrosoftCopilotAuthenticationMethod", + "InputMicrosoftCopilotInput", + "InputMicrosoftCopilotInputTypedDict", + "InputMicrosoftCopilotManageState", + "InputMicrosoftCopilotManageStateTypedDict", + "InputMicrosoftCopilotRetryRules", + "InputMicrosoftCopilotRetryRulesTypedDict", + "InputMicrosoftCopilotSubscriptionPlan", + "InputMicrosoftCopilotType", "InputMicrosoftGraphAuthenticationMethod", "InputMicrosoftGraphInput", "InputMicrosoftGraphInputTypedDict", + "InputMicrosoftGraphSubscriptionPlan", "InputMicrosoftGraphType", + "InputMimecastHecInput", + "InputMimecastHecInputTypedDict", + "InputMimecastHecType", "InputModelDrivenTelemetryInput", "InputModelDrivenTelemetryInputTypedDict", "InputModelDrivenTelemetryType", @@ -11447,12 +12274,20 @@ "InputOpenaiManageState", "InputOpenaiManageStateTypedDict", "InputOpenaiType", + "InputPingIdentityPingoneInput", + "InputPingIdentityPingoneInputTypedDict", + "InputPingIdentityPingoneType", "InputPrometheusDiscoveryType", "InputPrometheusInput", "InputPrometheusInputTypedDict", "InputPrometheusRwInput", "InputPrometheusRwInputTypedDict", "InputPrometheusRwType", + "InputProofpointPodInput", + "InputProofpointPodInputTypedDict", + "InputProofpointPodType", + "InputProvenanceTypeOptional", + "InputProvenanceTypeOptionalTypedDict", "InputRawUDPInput", "InputRawUDPInputTypedDict", "InputRawUDPType", @@ -11469,13 +12304,14 @@ "InputResponseAuthMethodsExt", "InputResponseAuthMethodsExtAuthenticationType", "InputResponseAuthMethodsExtTypedDict", - "InputResponseAuthTokensExt", - "InputResponseAuthTokensExtTypedDict", "InputResponseAuthTypedDict", "InputResponseAuthenticationMechanism", "InputResponseAuthenticationProtocol", "InputResponseAzureBlobStorage", "InputResponseAzureBlobStorageTypedDict", + "InputResponseBucketWidth", + "InputResponseCertOptions", + "InputResponseCertOptionsTypedDict", "InputResponseCertificate", "InputResponseCertificateTypedDict", "InputResponseChatMessages", @@ -11494,30 +12330,39 @@ "InputResponseContainer", "InputResponseContainerMode", "InputResponseContainerTypedDict", + "InputResponseContentType", "InputResponseDNS", "InputResponseDNSTypedDict", "InputResponseDisksAndFileSystems", "InputResponseDisksAndFileSystemsTypedDict", - "InputResponseElasticsearchMetadata", - "InputResponseElasticsearchMetadataTypedDict", "InputResponseEndpointHeader", "InputResponseEndpointHeaderTypedDict", "InputResponseEndpointParam", "InputResponseEndpointParamTypedDict", "InputResponseEventFormat", + "InputResponseFeedType", "InputResponseFirewall", "InputResponseFirewallTypedDict", "InputResponseFormat", "InputResponseGrantType", + "InputResponseGroupBy", "InputResponseGroups", "InputResponseGroupsTypedDict", "InputResponseHostInfo", "InputResponseHostInfoTypedDict", "InputResponseHostsFile", "InputResponseHostsFileTypedDict", + "InputResponseInputAkamaiHec", + "InputResponseInputAkamaiHecType", + "InputResponseInputAkamaiHecTypedDict", "InputResponseInputAnthropicCompliance", "InputResponseInputAnthropicComplianceType", "InputResponseInputAnthropicComplianceTypedDict", + "InputResponseInputAnthropicEnterpriseAnalytics", + "InputResponseInputAnthropicEnterpriseAnalyticsContentConfig", + "InputResponseInputAnthropicEnterpriseAnalyticsContentConfigTypedDict", + "InputResponseInputAnthropicEnterpriseAnalyticsType", + "InputResponseInputAnthropicEnterpriseAnalyticsTypedDict", "InputResponseInputAppleUnifiedLogs", "InputResponseInputAppleUnifiedLogsReadMode", "InputResponseInputAppleUnifiedLogsType", @@ -11529,11 +12374,20 @@ "InputResponseInputAppscopePersistenceTypedDict", "InputResponseInputAppscopeType", "InputResponseInputAppscopeTypedDict", + "InputResponseInputAquaSecurityHec", + "InputResponseInputAquaSecurityHecType", + "InputResponseInputAquaSecurityHecTypedDict", "InputResponseInputAzureBlob", "InputResponseInputAzureBlobTypedDict", + "InputResponseInputAzureVnetFlowLog", + "InputResponseInputAzureVnetFlowLogType", + "InputResponseInputAzureVnetFlowLogTypedDict", "InputResponseInputBedrockS3", "InputResponseInputBedrockS3Type", "InputResponseInputBedrockS3TypedDict", + "InputResponseInputBeyondtrustHec", + "InputResponseInputBeyondtrustHecType", + "InputResponseInputBeyondtrustHecTypedDict", "InputResponseInputCloudflareHec", "InputResponseInputCloudflareHecType", "InputResponseInputCloudflareHecTypedDict", @@ -11547,6 +12401,12 @@ "InputResponseInputCriblHTTPType", "InputResponseInputCriblHTTPTypedDict", "InputResponseInputCriblLakeHTTP", + "InputResponseInputCriblLakeHTTPAuthTokensExt", + "InputResponseInputCriblLakeHTTPAuthTokensExtTypedDict", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "InputResponseInputCriblLakeHTTPType", "InputResponseInputCriblLakeHTTPTypedDict", "InputResponseInputCriblTCP", @@ -11581,7 +12441,6 @@ "InputResponseInputElasticTypedDict", "InputResponseInputEventhub", "InputResponseInputEventhubAmqp", - "InputResponseInputEventhubAmqpAuthenticationMethod", "InputResponseInputEventhubAmqpType", "InputResponseInputEventhubAmqpTypedDict", "InputResponseInputEventhubType", @@ -11589,6 +12448,12 @@ "InputResponseInputExec", "InputResponseInputExecType", "InputResponseInputExecTypedDict", + "InputResponseInputExtrahopRevealx360", + "InputResponseInputExtrahopRevealx360Type", + "InputResponseInputExtrahopRevealx360TypedDict", + "InputResponseInputF5BigIP", + "InputResponseInputF5BigIPType", + "InputResponseInputF5BigIPTypedDict", "InputResponseInputFile", "InputResponseInputFileMode", "InputResponseInputFileType", @@ -11596,6 +12461,9 @@ "InputResponseInputFirehose", "InputResponseInputFirehoseType", "InputResponseInputFirehoseTypedDict", + "InputResponseInputGigamonHec", + "InputResponseInputGigamonHecType", + "InputResponseInputGigamonHecTypedDict", "InputResponseInputGooglePubsub", "InputResponseInputGooglePubsubTypedDict", "InputResponseInputGrafanaGrafana1", @@ -11607,11 +12475,34 @@ "InputResponseInputGrafanaUnion", "InputResponseInputGrafanaUnionTypedDict", "InputResponseInputHTTP", + "InputResponseInputHTTPAuthTokensExt", + "InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata", + "InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict", + "InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata", + "InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict", + "InputResponseInputHTTPAuthTokensExtTypedDict", + "InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata", + "InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict", + "InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata", + "InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict", + "InputResponseInputHTTPInputHTTPAuthTokensExtItemsType", + "InputResponseInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict", + "InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint", + "InputResponseInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict", "InputResponseInputHTTPRaw", + "InputResponseInputHTTPRawAuthTokensExt", + "InputResponseInputHTTPRawAuthTokensExtTypedDict", + "InputResponseInputHTTPRawAuthTokensExtUnion", + "InputResponseInputHTTPRawAuthTokensExtUnionTypedDict", + "InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint", + "InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict", "InputResponseInputHTTPRawType", "InputResponseInputHTTPRawTypedDict", "InputResponseInputHTTPType", "InputResponseInputHTTPTypedDict", + "InputResponseInputHashicorpHcpVaultDedicated", + "InputResponseInputHashicorpHcpVaultDedicatedType", + "InputResponseInputHashicorpHcpVaultDedicatedTypedDict", "InputResponseInputJournalFiles", "InputResponseInputJournalFilesRule", "InputResponseInputJournalFilesRuleTypedDict", @@ -11640,10 +12531,21 @@ "InputResponseInputMetrics", "InputResponseInputMetricsType", "InputResponseInputMetricsTypedDict", + "InputResponseInputMicrosoftCopilot", + "InputResponseInputMicrosoftCopilotAuthenticationMethod", + "InputResponseInputMicrosoftCopilotManageState", + "InputResponseInputMicrosoftCopilotManageStateTypedDict", + "InputResponseInputMicrosoftCopilotSubscriptionPlan", + "InputResponseInputMicrosoftCopilotType", + "InputResponseInputMicrosoftCopilotTypedDict", "InputResponseInputMicrosoftGraph", "InputResponseInputMicrosoftGraphAuthenticationMethod", + "InputResponseInputMicrosoftGraphSubscriptionPlan", "InputResponseInputMicrosoftGraphType", "InputResponseInputMicrosoftGraphTypedDict", + "InputResponseInputMimecastHec", + "InputResponseInputMimecastHecType", + "InputResponseInputMimecastHecTypedDict", "InputResponseInputModelDrivenTelemetry", "InputResponseInputModelDrivenTelemetryType", "InputResponseInputModelDrivenTelemetryTypedDict", @@ -11687,12 +12589,18 @@ "InputResponseInputOpenaiManageStateTypedDict", "InputResponseInputOpenaiType", "InputResponseInputOpenaiTypedDict", + "InputResponseInputPingIdentityPingone", + "InputResponseInputPingIdentityPingoneType", + "InputResponseInputPingIdentityPingoneTypedDict", "InputResponseInputPrometheus", "InputResponseInputPrometheusDiscoveryType", "InputResponseInputPrometheusRw", "InputResponseInputPrometheusRwType", "InputResponseInputPrometheusRwTypedDict", "InputResponseInputPrometheusTypedDict", + "InputResponseInputProofpointPod", + "InputResponseInputProofpointPodType", + "InputResponseInputProofpointPodTypedDict", "InputResponseInputRawUDP", "InputResponseInputRawUDPType", "InputResponseInputRawUDPTypedDict", @@ -11701,6 +12609,9 @@ "InputResponseInputS3InventoryType", "InputResponseInputS3InventoryTypedDict", "InputResponseInputS3TypedDict", + "InputResponseInputSailpointHec", + "InputResponseInputSailpointHecType", + "InputResponseInputSailpointHecTypedDict", "InputResponseInputSecurityLake", "InputResponseInputSecurityLakeTypedDict", "InputResponseInputServicenowTable", @@ -11772,9 +12683,18 @@ "InputResponseInputTCPTypedDict", "InputResponseInputTcpjson", "InputResponseInputTcpjsonTypedDict", + "InputResponseInputTrellixHec", + "InputResponseInputTrellixHecType", + "InputResponseInputTrellixHecTypedDict", + "InputResponseInputTrendMicroVisionOne", + "InputResponseInputTrendMicroVisionOneType", + "InputResponseInputTrendMicroVisionOneTypedDict", "InputResponseInputUpwindHec", "InputResponseInputUpwindHecType", "InputResponseInputUpwindHecTypedDict", + "InputResponseInputVectraAiHec", + "InputResponseInputVectraAiHecType", + "InputResponseInputVectraAiHecTypedDict", "InputResponseInputWef", "InputResponseInputWefAuthenticationMethod", "InputResponseInputWefType", @@ -11815,6 +12735,12 @@ "InputResponseInputWizType", "InputResponseInputWizTypedDict", "InputResponseInputWizWebhook", + "InputResponseInputWizWebhookAuthTokensExt1", + "InputResponseInputWizWebhookAuthTokensExt1TypedDict", + "InputResponseInputWizWebhookAuthTokensExt2", + "InputResponseInputWizWebhookAuthTokensExt2TypedDict", + "InputResponseInputWizWebhookAuthTokensExtUnion", + "InputResponseInputWizWebhookAuthTokensExtUnionTypedDict", "InputResponseInputWizWebhookType", "InputResponseInputWizWebhookTypedDict", "InputResponseInputZscalerHec", @@ -11865,6 +12791,8 @@ "InputResponseQueryTypedDict", "InputResponseQueueType", "InputResponseRecordDataFormat", + "InputResponseRetryRules", + "InputResponseRetryRulesTypedDict", "InputResponseRoutes", "InputResponseRoutesTypedDict", "InputResponseSNMPv3Authentication", @@ -11879,10 +12807,7 @@ "InputResponseShardIteratorStart", "InputResponseShardLoadBalancing", "InputResponseSortDirection", - "InputResponseSplunkHecMetadata", - "InputResponseSplunkHecMetadataTypedDict", "InputResponseSubscription", - "InputResponseSubscriptionPlan", "InputResponseSubscriptionTypedDict", "InputResponseTLSSettingsServerSide", "InputResponseTLSSettingsServerSideTypedDict", @@ -11893,6 +12818,8 @@ "InputResponseUNIXSocketPermissionsTypedDict", "InputResponseUsersAndGroups", "InputResponseUsersAndGroupsTypedDict", + "InputResponseV3AuthenticationKeyType", + "InputResponseV3PrivacyKeyType", "InputResponseV3User", "InputResponseV3UserTypedDict", "InputS3Input", @@ -11900,6 +12827,9 @@ "InputS3InventoryInput", "InputS3InventoryInputTypedDict", "InputS3InventoryType", + "InputSailpointHecInput", + "InputSailpointHecInputTypedDict", + "InputSailpointHecType", "InputSecurityLakeInput", "InputSecurityLakeInputTypedDict", "InputServicenowTableAuthenticationType", @@ -11982,17 +12912,27 @@ "InputTCPType", "InputTcpjsonInput", "InputTcpjsonInputTypedDict", + "InputTrellixHecInput", + "InputTrellixHecInputTypedDict", + "InputTrellixHecType", + "InputTrendMicroVisionOneInput", + "InputTrendMicroVisionOneInputTypedDict", + "InputTrendMicroVisionOneType", "InputTypeRunnableJobCollection", "InputTypeRunnableJobCollectionTypedDict", "InputTypedDict", "InputUpwindHecInput", "InputUpwindHecInputTypedDict", "InputUpwindHecType", + "InputVectraAiHecInput", + "InputVectraAiHecInputTypedDict", + "InputVectraAiHecType", "InputWefAuthenticationMethod", "InputWefFormat", "InputWefInput", "InputWefInputTypedDict", "InputWefType", + "InputWinEventLogsEventFormat", "InputWinEventLogsInput", "InputWinEventLogsInputTypedDict", "InputWinEventLogsReadMode", @@ -12028,6 +12968,12 @@ "InputWizManageState", "InputWizManageStateTypedDict", "InputWizType", + "InputWizWebhookAuthTokensExt1", + "InputWizWebhookAuthTokensExt1TypedDict", + "InputWizWebhookAuthTokensExt2", + "InputWizWebhookAuthTokensExt2TypedDict", + "InputWizWebhookAuthTokensExtUnion", + "InputWizWebhookAuthTokensExtUnionTypedDict", "InputWizWebhookInput", "InputWizWebhookInputTypedDict", "InputWizWebhookType", @@ -12066,16 +13012,10 @@ "LakeExportConfiguration", "LakeExportConfigurationTypedDict", "LakehouseConnectionType", - "ListInputRequest", - "ListInputRequestTypedDict", - "ListInputResponse", - "ListInputResponseTypedDict", - "ListOutputRequest", - "ListOutputRequestTypedDict", - "ListOutputResponse", - "ListOutputResponseTypedDict", "ListeningPorts", "ListeningPortsTypedDict", + "LocalOverrides", + "LocalOverridesTypedDict", "LogLabelConfOutputGoogleCloudLogging", "LogLabelConfOutputGoogleCloudLoggingTypedDict", "LogLevelForFailedLookups", @@ -12116,6 +13056,8 @@ "MetadataConfAddHecTokenRequestTypedDict", "MetadataConfInputCollection", "MetadataConfInputCollectionTypedDict", + "MetadataItem", + "MetadataItemTypedDict", "Metadatum", "MetadatumTypedDict", "MethodOptions", @@ -12144,23 +13086,17 @@ "NodeUpgradeState", "NodeUpgradeStatus", "NodeUpgradeStatusTypedDict", - "Notification1", - "Notification1TypedDict", - "Notification2", - "Notification2TypedDict", - "Notification3", - "Notification3TypedDict", - "NotificationConfigForSMTPTarget1", - "NotificationConfigForSMTPTarget1TypedDict", - "NotificationConfigForSMTPTarget2", - "NotificationConfigForSMTPTarget2TypedDict", - "NotificationConfigForSMTPTarget3", - "NotificationConfigForSMTPTarget3TypedDict", - "NotificationMode1", - "NotificationMode2", - "NotificationMode3", - "NotificationUnion", - "NotificationUnionTypedDict", + "Notification", + "NotificationMode", + "NotificationSMTPTargetConfig", + "NotificationSMTPTargetConfigTypedDict", + "NotificationTargetConfig", + "NotificationTargetConfigTypedDict", + "NotificationTargetDetails", + "NotificationTargetDetailsTypedDict", + "NotificationTemplateTargetPair", + "NotificationTemplateTargetPairTypedDict", + "NotificationTypedDict", "NotifyConfiguration", "NotifyConfigurationTypedDict", "NumerifyFormatFix", @@ -12169,6 +13105,7 @@ "NumerifyFormatNone", "NumerifyFormatNoneFormat", "NumerifyFormatNoneTypedDict", + "OAuthSecretSource", "OauthHeaderConfInputServicenowTable", "OauthHeaderConfInputServicenowTableTypedDict", "OauthParamConfInputKafka", @@ -12188,7 +13125,7 @@ "OrganizationUsersTypedDict", "Organizations", "OrganizationsTypedDict", - "Origin", + "OriginOptionsCriblSourceProvenance", "OrphanFileRecoveryType", "OrphanFileRecoveryTypeTypedDict", "Os", @@ -12291,6 +13228,11 @@ "OutputDatabricks", "OutputDatabricksType", "OutputDatabricksTypedDict", + "OutputDatabricksZerobus", + "OutputDatabricksZerobusPqControls", + "OutputDatabricksZerobusPqControlsTypedDict", + "OutputDatabricksZerobusType", + "OutputDatabricksZerobusTypedDict", "OutputDatadog", "OutputDatadogPqControls", "OutputDatadogPqControlsTypedDict", @@ -12345,6 +13287,7 @@ "OutputElasticURL", "OutputElasticURLTypedDict", "OutputExabeam", + "OutputExabeamAuthenticationMethod", "OutputExabeamType", "OutputExabeamTypedDict", "OutputFieldMappings", @@ -12510,6 +13453,7 @@ "OutputResponseElasticVersion", "OutputResponseEndpointConfiguration", "OutputResponseEndpointType", + "OutputResponseEventFormat", "OutputResponseExtentTag", "OutputResponseExtentTagTypedDict", "OutputResponseExtraLogType", @@ -12526,6 +13470,7 @@ "OutputResponseMessageFormat", "OutputResponseMetadatum", "OutputResponseMetadatumTypedDict", + "OutputResponseOAuthSecretSource", "OutputResponseOutputAlibabaCloudS3", "OutputResponseOutputAlibabaCloudS3AuthenticationMethod", "OutputResponseOutputAlibabaCloudS3Type", @@ -12614,6 +13559,11 @@ "OutputResponseOutputDatabricks", "OutputResponseOutputDatabricksType", "OutputResponseOutputDatabricksTypedDict", + "OutputResponseOutputDatabricksZerobus", + "OutputResponseOutputDatabricksZerobusPqControls", + "OutputResponseOutputDatabricksZerobusPqControlsTypedDict", + "OutputResponseOutputDatabricksZerobusType", + "OutputResponseOutputDatabricksZerobusTypedDict", "OutputResponseOutputDatadog", "OutputResponseOutputDatadogPqControls", "OutputResponseOutputDatadogPqControlsTypedDict", @@ -12668,6 +13618,7 @@ "OutputResponseOutputElasticURL", "OutputResponseOutputElasticURLTypedDict", "OutputResponseOutputExabeam", + "OutputResponseOutputExabeamAuthenticationMethod", "OutputResponseOutputExabeamType", "OutputResponseOutputExabeamTypedDict", "OutputResponseOutputFilesystem", @@ -12901,6 +13852,12 @@ "OutputResponseOutputTcpjsonPqControls", "OutputResponseOutputTcpjsonPqControlsTypedDict", "OutputResponseOutputTcpjsonTypedDict", + "OutputResponseOutputTraversalOtlp", + "OutputResponseOutputTraversalOtlpAuthenticationType", + "OutputResponseOutputTraversalOtlpPqControls", + "OutputResponseOutputTraversalOtlpPqControlsTypedDict", + "OutputResponseOutputTraversalOtlpType", + "OutputResponseOutputTraversalOtlpTypedDict", "OutputResponseOutputWavefront", "OutputResponseOutputWavefrontPqControls", "OutputResponseOutputWavefrontPqControlsTypedDict", @@ -12949,6 +13906,7 @@ "OutputResponseReportMethod", "OutputResponseRule", "OutputResponseRuleTypedDict", + "OutputResponseSendAs", "OutputResponseSendEventsAs", "OutputResponseSendLogsAs", "OutputResponseStatsDestination", @@ -12958,6 +13916,7 @@ "OutputResponseTimestampPrecision", "OutputResponseTypedDict", "OutputResponseUDMType", + "OutputResponseWizDefendSourceType", "OutputResponseWriteAction", "OutputRing", "OutputRingDataFormat", @@ -13070,6 +14029,12 @@ "OutputTestRequestTypedDict", "OutputTestResponse", "OutputTestResponseTypedDict", + "OutputTraversalOtlp", + "OutputTraversalOtlpAuthenticationType", + "OutputTraversalOtlpPqControls", + "OutputTraversalOtlpPqControlsTypedDict", + "OutputTraversalOtlpType", + "OutputTraversalOtlpTypedDict", "OutputTypedDict", "OutputWavefront", "OutputWavefrontPqControls", @@ -13097,6 +14062,7 @@ "OutputWebhookWebhook2", "OutputWebhookWebhook2TypedDict", "OutputWizHec", + "OutputWizHecEventFormat", "OutputWizHecPqControls", "OutputWizHecPqControlsTypedDict", "OutputWizHecType", @@ -13149,6 +14115,8 @@ "PaginatedPackInfoTypedDict", "PaginatedPipeline", "PaginatedPipelineTypedDict", + "PaginatedRoutes", + "PaginatedRoutesTypedDict", "PaginatedSavedJobResponse", "PaginatedSavedJobResponseTypedDict", "PaginationOptionsRestDiscoveryDiscoverTypeHTTPPagination", @@ -13213,6 +14181,9 @@ "PipelineFunctionDNSLookup", "PipelineFunctionDNSLookupID", "PipelineFunctionDNSLookupTypedDict", + "PipelineFunctionDetectionRules", + "PipelineFunctionDetectionRulesID", + "PipelineFunctionDetectionRulesTypedDict", "PipelineFunctionDistinct", "PipelineFunctionDistinctID", "PipelineFunctionDistinctTypedDict", @@ -13278,6 +14249,9 @@ "PipelineFunctionLakeExport", "PipelineFunctionLakeExportID", "PipelineFunctionLakeExportTypedDict", + "PipelineFunctionLakehouseEngineMetricsNormalizer", + "PipelineFunctionLakehouseEngineMetricsNormalizerID", + "PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict", "PipelineFunctionLimit", "PipelineFunctionLimitID", "PipelineFunctionLimitTypedDict", @@ -13315,6 +14289,9 @@ "PipelineFunctionMetricsExportMode1", "PipelineFunctionMetricsExportMode2", "PipelineFunctionMetricsExportTypedDict", + "PipelineFunctionMetricsTimeRangeGate", + "PipelineFunctionMetricsTimeRangeGateID", + "PipelineFunctionMetricsTimeRangeGateTypedDict", "PipelineFunctionMvExpand", "PipelineFunctionMvExpandConf", "PipelineFunctionMvExpandConfTypedDict", @@ -14574,12 +15551,15 @@ "ScriptCollectorConfTypedDict", "SearchEngineExportConfiguration", "SearchEngineExportConfigurationTypedDict", + "SearchExecutionConfig", + "SearchExecutionConfigTypedDict", "SearchFilterConfInputPrometheus", "SearchFilterConfInputPrometheusTypedDict", "SearchVersion", "SecureVersion", "Security", "SecurityTypedDict", + "SendAs", "SendConfiguration", "SendConfigurationTypedDict", "SendEventsAs", @@ -14732,8 +15712,6 @@ "SplunkAuthenticationTokenTypedDict", "SplunkCollectorConf", "SplunkCollectorConfTypedDict", - "SplunkHecMetadata", - "SplunkHecMetadataTypedDict", "SqsAuthenticationMethodOptions", "Ssl", "SslTypeSystemSettingsConfAPI", @@ -14753,7 +15731,6 @@ "StoreFunctionConfiguration", "StoreFunctionConfigurationTypedDict", "Subscription", - "SubscriptionPlan", "SubscriptionPlanOptions", "SubscriptionTypedDict", "Summary", @@ -14766,15 +15743,9 @@ "SystemRestartResponseTypedDict", "SystemSettingsConf", "SystemSettingsConfResponse", - "SystemSettingsConfResponseAPI", - "SystemSettingsConfResponseAPITypedDict", - "SystemSettingsConfResponseSystem", - "SystemSettingsConfResponseSystemTypedDict", "SystemSettingsConfResponseTypedDict", "SystemSettingsConfTypedDict", "SystemSettingsConfUpdate", - "SystemSettingsConfUpdateAPI", - "SystemSettingsConfUpdateAPITypedDict", "SystemSettingsConfUpdateSystem", "SystemSettingsConfUpdateSystemTypedDict", "SystemSettingsConfUpdateTypedDict", @@ -14811,18 +15782,6 @@ "TagsTypePackInstallInfo", "TagsTypePackInstallInfoTypedDict", "Target", - "TargetConfig1", - "TargetConfig1TypedDict", - "TargetConfig2", - "TargetConfig2TypedDict", - "TargetConfig3", - "TargetConfig3TypedDict", - "TargetConfigUnion1", - "TargetConfigUnion1TypedDict", - "TargetConfigUnion2", - "TargetConfigUnion2TypedDict", - "TargetConfigUnion3", - "TargetConfigUnion3TypedDict", "TargetContext", "TargetTypedDict", "TaskErrorDetail", @@ -14834,11 +15793,8 @@ "TelemetryType", "TemplateDefinition", "TemplateDefinitionTypedDict", - "TemplateTargetPairConfFunctionConfSchemaNotificationPolicies", - "TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict", + "TemplateFamilyOptionsCriblSourceProvenance", "TimeRange", - "TimeWarningTypeRunnableJobCollectionScheduleRun", - "TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict", "TimeoutRetrySettingsType", "TimeoutRetrySettingsTypeTypedDict", "Timestamp", @@ -15039,11 +15995,14 @@ "UserAccessControlListTypedDict", "UsersAndGroups", "UsersAndGroupsTypedDict", + "V3AuthenticationKeyType", + "V3PrivacyKeyType", "V3User", "V3UserTypedDict", "Value", "ValueTypedDict", "WhereToCapture", + "WizDefendSourceType", "WorkerPQStatus", "WorkerPQStatusTypedDict", "WorkersTypeSystemSettingsConf", @@ -15078,9 +16037,10 @@ "AuthenticationMethodOptionsAPI": ".authenticationmethodoptionsapi", "AuthenticationMethodOptionsAuth": ".authenticationmethodoptionsauth", "AuthenticationMethodOptionsAuthManualManualAPIKey": ".authenticationmethodoptionsauthmanualmanualapikey", + "AuthenticationMethodOptionsAuthTokensExtItems": ".authenticationmethodoptionsauthtokensextitems", "AuthenticationMethodOptionsAuthTokensItems": ".authenticationmethodoptionsauthtokensitems", - "AuthenticationMethodOptionsAuthTokensItemsSecret": ".authenticationmethodoptionsauthtokensitemssecret", "AuthenticationMethodOptionsAutoSecret": ".authenticationmethodoptionsautosecret", + "AuthenticationMethodOptionsClientAssertionClientAssertionrpc": ".authenticationmethodoptionsclientassertionclientassertionrpc", "AuthenticationMethodOptionsManualSecret": ".authenticationmethodoptionsmanualsecret", "AuthenticationMethodOptionsS3CollectorConf": ".authenticationmethodoptionss3collectorconf", "AuthenticationMethodOptionsSasl": ".authenticationmethodoptionssasl", @@ -15107,8 +16067,6 @@ "AuthTokenConfInputCriblTCPTypedDict": ".authtokenconfinputcribltcp", "AuthTokenConfOutputCriblHTTP": ".authtokenconfoutputcriblhttp", "AuthTokenConfOutputCriblHTTPTypedDict": ".authtokenconfoutputcriblhttp", - "AuthTokensExtConfInputHTTP": ".authtokensextconfinputhttp", - "AuthTokensExtConfInputHTTPTypedDict": ".authtokensextconfinputhttp", "AuthType": ".authtype", "AuthTypeTypedDict": ".authtype", "AuthTypeTemplatemanualAPIKeyAuthType": ".authtypetemplatemanualapikeyauthtype", @@ -15223,6 +16181,7 @@ "ConfigGroupLookupsLookup": ".configgrouplookups", "ConfigGroupLookupsLookupTypedDict": ".configgrouplookups", "ConfigGroupLookupsTypedDict": ".configgrouplookups", + "DeployMode": ".configgrouplookups", "ConnectionConfInputCollection": ".connectionconfinputcollection", "ConnectionConfInputCollectionTypedDict": ".connectionconfinputcollection", "ConnectionProtocol": ".connectionprotocol", @@ -15303,127 +16262,39 @@ "CreateCriblLakeDatasetByLakeIDRequest": ".createcribllakedatasetbylakeidop", "CreateCriblLakeDatasetByLakeIDRequestTypedDict": ".createcribllakedatasetbylakeidop", "CreateInputAPIVersion": ".createinput_input", - "CreateInputAuth": ".createinput_input", - "CreateInputAuthTokensExt": ".createinput_input", - "CreateInputAuthTokensExtTypedDict": ".createinput_input", - "CreateInputAuthTypedDict": ".createinput_input", - "CreateInputAuthenticationMechanism": ".createinput_input", - "CreateInputAzureBlobStorage": ".createinput_input", - "CreateInputAzureBlobStorageTypedDict": ".createinput_input", - "CreateInputCertificate": ".createinput_input", - "CreateInputCertificateTypedDict": ".createinput_input", - "CreateInputCheckpointing": ".createinput_input", - "CreateInputCheckpointingTypedDict": ".createinput_input", - "CreateInputCollectors": ".createinput_input", - "CreateInputCollectorsTypedDict": ".createinput_input", "CreateInputCompression": ".createinput_input", - "CreateInputContainer": ".createinput_input", - "CreateInputContainerMode": ".createinput_input", - "CreateInputContainerTypedDict": ".createinput_input", - "CreateInputDNS": ".createinput_input", - "CreateInputDNSTypedDict": ".createinput_input", - "CreateInputDisksAndFileSystems": ".createinput_input", - "CreateInputDisksAndFileSystemsTypedDict": ".createinput_input", - "CreateInputElasticsearchMetadata": ".createinput_input", - "CreateInputElasticsearchMetadataTypedDict": ".createinput_input", "CreateInputEndpointHeader": ".createinput_input", "CreateInputEndpointHeaderTypedDict": ".createinput_input", "CreateInputEndpointParam": ".createinput_input", "CreateInputEndpointParamTypedDict": ".createinput_input", - "CreateInputFirewall": ".createinput_input", - "CreateInputFirewallTypedDict": ".createinput_input", - "CreateInputHostInfo": ".createinput_input", - "CreateInputHostInfoTypedDict": ".createinput_input", - "CreateInputHostsFile": ".createinput_input", - "CreateInputHostsFileTypedDict": ".createinput_input", "CreateInputInput": ".createinput_input", "CreateInputInputAzureBlob": ".createinput_input", "CreateInputInputAzureBlobTypedDict": ".createinput_input", + "CreateInputInputAzureVnetFlowLog": ".createinput_input", + "CreateInputInputAzureVnetFlowLogType": ".createinput_input", + "CreateInputInputAzureVnetFlowLogTypedDict": ".createinput_input", "CreateInputInputCollection": ".createinput_input", "CreateInputInputCollectionType": ".createinput_input", "CreateInputInputCollectionTypedDict": ".createinput_input", - "CreateInputInputConfluentCloud": ".createinput_input", - "CreateInputInputConfluentCloudTypedDict": ".createinput_input", - "CreateInputInputCribl": ".createinput_input", - "CreateInputInputCriblHTTP": ".createinput_input", - "CreateInputInputCriblHTTPType": ".createinput_input", - "CreateInputInputCriblHTTPTypedDict": ".createinput_input", - "CreateInputInputCriblLakeHTTP": ".createinput_input", - "CreateInputInputCriblLakeHTTPType": ".createinput_input", - "CreateInputInputCriblLakeHTTPTypedDict": ".createinput_input", - "CreateInputInputCriblTCP": ".createinput_input", - "CreateInputInputCriblTCPTypedDict": ".createinput_input", - "CreateInputInputCriblType": ".createinput_input", - "CreateInputInputCriblTypedDict": ".createinput_input", - "CreateInputInputEdgePrometheus": ".createinput_input", - "CreateInputInputEdgePrometheusAuthenticationMethod": ".createinput_input", - "CreateInputInputEdgePrometheusDiscoveryType": ".createinput_input", - "CreateInputInputEdgePrometheusType": ".createinput_input", - "CreateInputInputEdgePrometheusTypedDict": ".createinput_input", "CreateInputInputElastic": ".createinput_input", "CreateInputInputElasticAuthenticationMethod": ".createinput_input", "CreateInputInputElasticAuthenticationType": ".createinput_input", "CreateInputInputElasticProxyMode": ".createinput_input", "CreateInputInputElasticProxyModeTypedDict": ".createinput_input", - "CreateInputInputElasticType": ".createinput_input", "CreateInputInputElasticTypedDict": ".createinput_input", - "CreateInputInputEventhub": ".createinput_input", - "CreateInputInputEventhubAmqp": ".createinput_input", - "CreateInputInputEventhubAmqpAuthenticationMethod": ".createinput_input", - "CreateInputInputEventhubAmqpType": ".createinput_input", - "CreateInputInputEventhubAmqpTypedDict": ".createinput_input", - "CreateInputInputEventhubType": ".createinput_input", - "CreateInputInputEventhubTypedDict": ".createinput_input", - "CreateInputInputExec": ".createinput_input", - "CreateInputInputExecType": ".createinput_input", - "CreateInputInputExecTypedDict": ".createinput_input", - "CreateInputInputFirehose": ".createinput_input", - "CreateInputInputFirehoseType": ".createinput_input", - "CreateInputInputFirehoseTypedDict": ".createinput_input", - "CreateInputInputGooglePubsub": ".createinput_input", - "CreateInputInputGooglePubsubTypedDict": ".createinput_input", - "CreateInputInputGrafanaGrafana1": ".createinput_input", - "CreateInputInputGrafanaGrafana1TypedDict": ".createinput_input", - "CreateInputInputGrafanaGrafana2": ".createinput_input", - "CreateInputInputGrafanaGrafana2TypedDict": ".createinput_input", - "CreateInputInputGrafanaType1": ".createinput_input", - "CreateInputInputGrafanaType2": ".createinput_input", - "CreateInputInputGrafanaUnion": ".createinput_input", - "CreateInputInputGrafanaUnionTypedDict": ".createinput_input", "CreateInputInputHTTP": ".createinput_input", + "CreateInputInputHTTPAuthTokensExt": ".createinput_input", + "CreateInputInputHTTPAuthTokensExtTypedDict": ".createinput_input", + "CreateInputInputHTTPInputHTTPAuthTokensExtItemsType": ".createinput_input", + "CreateInputInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".createinput_input", + "CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint": ".createinput_input", + "CreateInputInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".createinput_input", "CreateInputInputHTTPType": ".createinput_input", "CreateInputInputHTTPTypedDict": ".createinput_input", "CreateInputInputKafka": ".createinput_input", "CreateInputInputKafkaTypedDict": ".createinput_input", - "CreateInputInputLoki": ".createinput_input", - "CreateInputInputLokiType": ".createinput_input", - "CreateInputInputLokiTypedDict": ".createinput_input", - "CreateInputInputMicrosoftGraph": ".createinput_input", - "CreateInputInputMicrosoftGraphAuthenticationMethod": ".createinput_input", - "CreateInputInputMicrosoftGraphType": ".createinput_input", - "CreateInputInputMicrosoftGraphTypedDict": ".createinput_input", "CreateInputInputMsk": ".createinput_input", "CreateInputInputMskTypedDict": ".createinput_input", - "CreateInputInputOffice365Mgmt": ".createinput_input", - "CreateInputInputOffice365MgmtContentConfig": ".createinput_input", - "CreateInputInputOffice365MgmtContentConfigTypedDict": ".createinput_input", - "CreateInputInputOffice365MgmtType": ".createinput_input", - "CreateInputInputOffice365MgmtTypedDict": ".createinput_input", - "CreateInputInputOffice365MsgTrace": ".createinput_input", - "CreateInputInputOffice365MsgTraceAuthenticationMethod": ".createinput_input", - "CreateInputInputOffice365MsgTraceType": ".createinput_input", - "CreateInputInputOffice365MsgTraceTypedDict": ".createinput_input", - "CreateInputInputOffice365Service": ".createinput_input", - "CreateInputInputOffice365ServiceContentConfig": ".createinput_input", - "CreateInputInputOffice365ServiceContentConfigTypedDict": ".createinput_input", - "CreateInputInputOffice365ServiceType": ".createinput_input", - "CreateInputInputOffice365ServiceTypedDict": ".createinput_input", - "CreateInputInputPrometheus": ".createinput_input", - "CreateInputInputPrometheusDiscoveryType": ".createinput_input", - "CreateInputInputPrometheusRw": ".createinput_input", - "CreateInputInputPrometheusRwType": ".createinput_input", - "CreateInputInputPrometheusRwTypedDict": ".createinput_input", - "CreateInputInputPrometheusTypedDict": ".createinput_input", "CreateInputInputSplunk": ".createinput_input", "CreateInputInputSplunkAuthToken": ".createinput_input", "CreateInputInputSplunkAuthTokenTypedDict": ".createinput_input", @@ -15438,672 +16309,772 @@ "CreateInputInputSplunkSearchType": ".createinput_input", "CreateInputInputSplunkSearchTypedDict": ".createinput_input", "CreateInputInputSplunkTypedDict": ".createinput_input", - "CreateInputInputSystemMetrics": ".createinput_input", - "CreateInputInputSystemMetricsCPU": ".createinput_input", - "CreateInputInputSystemMetricsCPUMode": ".createinput_input", - "CreateInputInputSystemMetricsCPUTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsCustom": ".createinput_input", - "CreateInputInputSystemMetricsCustomTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsDisk": ".createinput_input", - "CreateInputInputSystemMetricsDiskMode": ".createinput_input", - "CreateInputInputSystemMetricsDiskTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsFilter": ".createinput_input", - "CreateInputInputSystemMetricsFilterTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsHost": ".createinput_input", - "CreateInputInputSystemMetricsHostTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsMemory": ".createinput_input", - "CreateInputInputSystemMetricsMemoryMode": ".createinput_input", - "CreateInputInputSystemMetricsMemoryTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsNetwork": ".createinput_input", - "CreateInputInputSystemMetricsNetworkMode": ".createinput_input", - "CreateInputInputSystemMetricsNetworkTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsPersistence": ".createinput_input", - "CreateInputInputSystemMetricsPersistenceTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsSystem": ".createinput_input", - "CreateInputInputSystemMetricsSystemMode": ".createinput_input", - "CreateInputInputSystemMetricsSystemTypedDict": ".createinput_input", - "CreateInputInputSystemMetricsType": ".createinput_input", - "CreateInputInputSystemMetricsTypedDict": ".createinput_input", - "CreateInputInputSystemState": ".createinput_input", - "CreateInputInputSystemStatePersistence": ".createinput_input", - "CreateInputInputSystemStatePersistenceTypedDict": ".createinput_input", - "CreateInputInputSystemStateType": ".createinput_input", - "CreateInputInputSystemStateTypedDict": ".createinput_input", - "CreateInputInputTcpjson": ".createinput_input", - "CreateInputInputTcpjsonTypedDict": ".createinput_input", "CreateInputInputTypedDict": ".createinput_input", - "CreateInputInterfaces": ".createinput_input", - "CreateInputInterfacesTypedDict": ".createinput_input", - "CreateInputListeningPorts": ".createinput_input", - "CreateInputListeningPortsTypedDict": ".createinput_input", - "CreateInputLoggedInUsers": ".createinput_input", - "CreateInputLoggedInUsersTypedDict": ".createinput_input", - "CreateInputLokiAuth1": ".createinput_input", - "CreateInputLokiAuth1TypedDict": ".createinput_input", - "CreateInputLokiAuth2": ".createinput_input", - "CreateInputLokiAuth2TypedDict": ".createinput_input", "CreateInputMaxS2SVersion": ".createinput_input", - "CreateInputMetricsProtocol": ".createinput_input", - "CreateInputPodFilter": ".createinput_input", - "CreateInputPodFilterTypedDict": ".createinput_input", - "CreateInputPrometheusAuth1": ".createinput_input", - "CreateInputPrometheusAuth1TypedDict": ".createinput_input", - "CreateInputPrometheusAuth2": ".createinput_input", - "CreateInputPrometheusAuth2TypedDict": ".createinput_input", - "CreateInputRoutes": ".createinput_input", - "CreateInputRoutesTypedDict": ".createinput_input", - "CreateInputScheduleType": ".createinput_input", - "CreateInputServices": ".createinput_input", - "CreateInputServicesTypedDict": ".createinput_input", - "CreateInputSplunkHecMetadata": ".createinput_input", - "CreateInputSplunkHecMetadataTypedDict": ".createinput_input", - "CreateInputSubscriptionPlan": ".createinput_input", - "CreateInputTarget": ".createinput_input", - "CreateInputTargetTypedDict": ".createinput_input", - "CreateInputUsersAndGroups": ".createinput_input", - "CreateInputUsersAndGroupsTypedDict": ".createinput_input", - "CreateInputAccountType": ".createinput_inputkubemetrics", - "CreateInputActivities": ".createinput_inputkubemetrics", - "CreateInputActivitiesManageState": ".createinput_inputkubemetrics", - "CreateInputActivitiesManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputActivitiesTypedDict": ".createinput_inputkubemetrics", - "CreateInputAllow": ".createinput_inputkubemetrics", - "CreateInputAllowTypedDict": ".createinput_inputkubemetrics", - "CreateInputAuthMethodsExt": ".createinput_inputkubemetrics", - "CreateInputAuthMethodsExtAuthenticationType": ".createinput_inputkubemetrics", - "CreateInputAuthMethodsExtTypedDict": ".createinput_inputkubemetrics", - "CreateInputAuthenticationProtocol": ".createinput_inputkubemetrics", - "CreateInputChatMessages": ".createinput_inputkubemetrics", - "CreateInputChatMessagesManageState": ".createinput_inputkubemetrics", - "CreateInputChatMessagesManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputChatMessagesTypedDict": ".createinput_inputkubemetrics", - "CreateInputChats": ".createinput_inputkubemetrics", - "CreateInputChatsManageState": ".createinput_inputkubemetrics", - "CreateInputChatsManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputChatsTypedDict": ".createinput_inputkubemetrics", - "CreateInputEventFormat": ".createinput_inputkubemetrics", - "CreateInputFormat": ".createinput_inputkubemetrics", - "CreateInputGrantType": ".createinput_inputkubemetrics", - "CreateInputGroups": ".createinput_inputkubemetrics", - "CreateInputGroupsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputAnthropicCompliance": ".createinput_inputkubemetrics", - "CreateInputInputAnthropicComplianceType": ".createinput_inputkubemetrics", - "CreateInputInputAnthropicComplianceTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputAppleUnifiedLogs": ".createinput_inputkubemetrics", - "CreateInputInputAppleUnifiedLogsReadMode": ".createinput_inputkubemetrics", - "CreateInputInputAppleUnifiedLogsType": ".createinput_inputkubemetrics", - "CreateInputInputAppleUnifiedLogsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputAppscope": ".createinput_inputkubemetrics", - "CreateInputInputAppscopeFilter": ".createinput_inputkubemetrics", - "CreateInputInputAppscopeFilterTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputAppscopePersistence": ".createinput_inputkubemetrics", - "CreateInputInputAppscopePersistenceTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputAppscopeType": ".createinput_inputkubemetrics", - "CreateInputInputAppscopeTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputBedrockS3": ".createinput_inputkubemetrics", - "CreateInputInputBedrockS3Type": ".createinput_inputkubemetrics", - "CreateInputInputBedrockS3TypedDict": ".createinput_inputkubemetrics", - "CreateInputInputCloudflareHec": ".createinput_inputkubemetrics", - "CreateInputInputCloudflareHecType": ".createinput_inputkubemetrics", - "CreateInputInputCloudflareHecTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputCriblmetrics": ".createinput_inputkubemetrics", - "CreateInputInputCriblmetricsType": ".createinput_inputkubemetrics", - "CreateInputInputCriblmetricsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputCrowdstrike": ".createinput_inputkubemetrics", - "CreateInputInputCrowdstrikeType": ".createinput_inputkubemetrics", - "CreateInputInputCrowdstrikeTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputDatadogAgent": ".createinput_inputkubemetrics", - "CreateInputInputDatadogAgentProxyMode": ".createinput_inputkubemetrics", - "CreateInputInputDatadogAgentProxyModeTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputDatadogAgentType": ".createinput_inputkubemetrics", - "CreateInputInputDatadogAgentTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputDatagen": ".createinput_inputkubemetrics", - "CreateInputInputDatagenType": ".createinput_inputkubemetrics", - "CreateInputInputDatagenTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputFile": ".createinput_inputkubemetrics", - "CreateInputInputFileMode": ".createinput_inputkubemetrics", - "CreateInputInputFileType": ".createinput_inputkubemetrics", - "CreateInputInputFileTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputHTTPRaw": ".createinput_inputkubemetrics", - "CreateInputInputHTTPRawType": ".createinput_inputkubemetrics", - "CreateInputInputHTTPRawTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputJournalFiles": ".createinput_inputkubemetrics", - "CreateInputInputJournalFilesRule": ".createinput_inputkubemetrics", - "CreateInputInputJournalFilesRuleTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputJournalFilesType": ".createinput_inputkubemetrics", - "CreateInputInputJournalFilesTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputKinesis": ".createinput_inputkubemetrics", - "CreateInputInputKinesisTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputKubeEvents": ".createinput_inputkubemetrics", - "CreateInputInputKubeEventsType": ".createinput_inputkubemetrics", - "CreateInputInputKubeEventsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputKubeLogs": ".createinput_inputkubemetrics", - "CreateInputInputKubeLogsRule": ".createinput_inputkubemetrics", - "CreateInputInputKubeLogsRuleTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputKubeLogsType": ".createinput_inputkubemetrics", - "CreateInputInputKubeLogsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputKubeMetrics": ".createinput_inputkubemetrics", - "CreateInputInputKubeMetricsPersistence": ".createinput_inputkubemetrics", - "CreateInputInputKubeMetricsPersistenceTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputKubeMetricsType": ".createinput_inputkubemetrics", - "CreateInputInputKubeMetricsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputMetrics": ".createinput_inputkubemetrics", - "CreateInputInputMetricsType": ".createinput_inputkubemetrics", - "CreateInputInputMetricsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputModelDrivenTelemetry": ".createinput_inputkubemetrics", - "CreateInputInputModelDrivenTelemetryType": ".createinput_inputkubemetrics", - "CreateInputInputModelDrivenTelemetryTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputNetflow": ".createinput_inputkubemetrics", - "CreateInputInputNetflowTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOkta": ".createinput_inputkubemetrics", - "CreateInputInputOktaManageState": ".createinput_inputkubemetrics", - "CreateInputInputOktaManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOktaType": ".createinput_inputkubemetrics", - "CreateInputInputOktaTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOpenTelemetry": ".createinput_inputkubemetrics", - "CreateInputInputOpenTelemetryAuthenticationType": ".createinput_inputkubemetrics", - "CreateInputInputOpenTelemetryType": ".createinput_inputkubemetrics", - "CreateInputInputOpenTelemetryTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOpenai": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiComplianceLogs": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiComplianceLogsManageState": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiComplianceLogsManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiComplianceLogsType": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiComplianceLogsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiContentConfig": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiContentConfigTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiLogLevel": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiManageState": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiType": ".createinput_inputkubemetrics", - "CreateInputInputOpenaiTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputRawUDP": ".createinput_inputkubemetrics", - "CreateInputInputRawUDPType": ".createinput_inputkubemetrics", - "CreateInputInputRawUDPTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputS3": ".createinput_inputkubemetrics", - "CreateInputInputS3Inventory": ".createinput_inputkubemetrics", - "CreateInputInputS3InventoryType": ".createinput_inputkubemetrics", - "CreateInputInputS3InventoryTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputS3TypedDict": ".createinput_inputkubemetrics", - "CreateInputInputSecurityLake": ".createinput_inputkubemetrics", - "CreateInputInputSecurityLakeTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputServicenowTable": ".createinput_inputkubemetrics", - "CreateInputInputServicenowTableAuthenticationType": ".createinput_inputkubemetrics", - "CreateInputInputServicenowTableManageState": ".createinput_inputkubemetrics", - "CreateInputInputServicenowTableManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputServicenowTableType": ".createinput_inputkubemetrics", - "CreateInputInputServicenowTableTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputSnmp": ".createinput_inputkubemetrics", - "CreateInputInputSnmpTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputSqs": ".createinput_inputkubemetrics", - "CreateInputInputSqsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputSysdigHec": ".createinput_inputkubemetrics", - "CreateInputInputSysdigHecType": ".createinput_inputkubemetrics", - "CreateInputInputSysdigHecTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputSyslogSyslog1": ".createinput_inputkubemetrics", - "CreateInputInputSyslogSyslog1TypedDict": ".createinput_inputkubemetrics", - "CreateInputInputSyslogSyslog2": ".createinput_inputkubemetrics", - "CreateInputInputSyslogSyslog2TypedDict": ".createinput_inputkubemetrics", - "CreateInputInputSyslogUnion": ".createinput_inputkubemetrics", - "CreateInputInputSyslogUnionTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputTCP": ".createinput_inputkubemetrics", - "CreateInputInputTCPType": ".createinput_inputkubemetrics", - "CreateInputInputTCPTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputUpwindHec": ".createinput_inputkubemetrics", - "CreateInputInputUpwindHecType": ".createinput_inputkubemetrics", - "CreateInputInputUpwindHecTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWef": ".createinput_inputkubemetrics", - "CreateInputInputWefAuthenticationMethod": ".createinput_inputkubemetrics", - "CreateInputInputWefType": ".createinput_inputkubemetrics", - "CreateInputInputWefTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWinEventLogs": ".createinput_inputkubemetrics", - "CreateInputInputWinEventLogsReadMode": ".createinput_inputkubemetrics", - "CreateInputInputWinEventLogsType": ".createinput_inputkubemetrics", - "CreateInputInputWinEventLogsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetrics": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsCPU": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsCPUMode": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsCPUTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsCustom": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsCustomTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsDisk": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsDiskMode": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsDiskTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsHost": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsHostTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsMemory": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsMemoryMode": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsMemoryTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsNetwork": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsNetworkMode": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsNetworkTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsPersistence": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsPersistenceTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsSystem": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsSystemMode": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsSystemTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsType": ".createinput_inputkubemetrics", - "CreateInputInputWindowsMetricsTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWiz": ".createinput_inputkubemetrics", - "CreateInputInputWizContentConfig": ".createinput_inputkubemetrics", - "CreateInputInputWizContentConfigTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWizManageState": ".createinput_inputkubemetrics", - "CreateInputInputWizManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWizType": ".createinput_inputkubemetrics", - "CreateInputInputWizTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputWizWebhook": ".createinput_inputkubemetrics", - "CreateInputInputWizWebhookType": ".createinput_inputkubemetrics", - "CreateInputInputWizWebhookTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputZscalerHec": ".createinput_inputkubemetrics", - "CreateInputInputZscalerHecAuthToken": ".createinput_inputkubemetrics", - "CreateInputInputZscalerHecAuthTokenTypedDict": ".createinput_inputkubemetrics", - "CreateInputInputZscalerHecType": ".createinput_inputkubemetrics", - "CreateInputInputZscalerHecTypedDict": ".createinput_inputkubemetrics", - "CreateInputMTLSSettings": ".createinput_inputkubemetrics", - "CreateInputMTLSSettingsTypedDict": ".createinput_inputkubemetrics", - "CreateInputOTLPVersion": ".createinput_inputkubemetrics", - "CreateInputOrganizationRoles": ".createinput_inputkubemetrics", - "CreateInputOrganizationRolesTypedDict": ".createinput_inputkubemetrics", - "CreateInputOrganizationUsers": ".createinput_inputkubemetrics", - "CreateInputOrganizationUsersTypedDict": ".createinput_inputkubemetrics", - "CreateInputOrganizations": ".createinput_inputkubemetrics", - "CreateInputOrganizationsTypedDict": ".createinput_inputkubemetrics", - "CreateInputPaginationType": ".createinput_inputkubemetrics", - "CreateInputPrivacyProtocol": ".createinput_inputkubemetrics", - "CreateInputProjectDetails": ".createinput_inputkubemetrics", - "CreateInputProjectDetailsManageState": ".createinput_inputkubemetrics", - "CreateInputProjectDetailsManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputProjectDetailsTypedDict": ".createinput_inputkubemetrics", - "CreateInputProjects": ".createinput_inputkubemetrics", - "CreateInputProjectsManageState": ".createinput_inputkubemetrics", - "CreateInputProjectsManageStateTypedDict": ".createinput_inputkubemetrics", - "CreateInputProjectsTypedDict": ".createinput_inputkubemetrics", - "CreateInputProtocol": ".createinput_inputkubemetrics", - "CreateInputQuery": ".createinput_inputkubemetrics", - "CreateInputQueryBuilderMode": ".createinput_inputkubemetrics", - "CreateInputQueryTypedDict": ".createinput_inputkubemetrics", - "CreateInputQueueType": ".createinput_inputkubemetrics", - "CreateInputRecordDataFormat": ".createinput_inputkubemetrics", - "CreateInputSNMPv3Authentication": ".createinput_inputkubemetrics", - "CreateInputSNMPv3AuthenticationTypedDict": ".createinput_inputkubemetrics", - "CreateInputSample": ".createinput_inputkubemetrics", - "CreateInputSampleTypedDict": ".createinput_inputkubemetrics", - "CreateInputSamplingRule": ".createinput_inputkubemetrics", - "CreateInputSamplingRuleTypedDict": ".createinput_inputkubemetrics", - "CreateInputShardIteratorStart": ".createinput_inputkubemetrics", - "CreateInputShardLoadBalancing": ".createinput_inputkubemetrics", - "CreateInputSortDirection": ".createinput_inputkubemetrics", - "CreateInputSubscription": ".createinput_inputkubemetrics", - "CreateInputSubscriptionTypedDict": ".createinput_inputkubemetrics", - "CreateInputTLSSettingsServerSide": ".createinput_inputkubemetrics", - "CreateInputTLSSettingsServerSideTypedDict": ".createinput_inputkubemetrics", - "CreateInputUNIXSocketPermissions": ".createinput_inputkubemetrics", - "CreateInputUNIXSocketPermissionsTypedDict": ".createinput_inputkubemetrics", - "CreateInputV3User": ".createinput_inputkubemetrics", - "CreateInputV3UserTypedDict": ".createinput_inputkubemetrics", + "CreateInputAuth": ".createinput_inputelastic_type", + "CreateInputAuthTypedDict": ".createinput_inputelastic_type", + "CreateInputAuthenticationMechanism": ".createinput_inputelastic_type", + "CreateInputAzureBlobStorage": ".createinput_inputelastic_type", + "CreateInputAzureBlobStorageTypedDict": ".createinput_inputelastic_type", + "CreateInputCertificate": ".createinput_inputelastic_type", + "CreateInputCertificateTypedDict": ".createinput_inputelastic_type", + "CreateInputCheckpointing": ".createinput_inputelastic_type", + "CreateInputCheckpointingTypedDict": ".createinput_inputelastic_type", + "CreateInputCollectors": ".createinput_inputelastic_type", + "CreateInputCollectorsTypedDict": ".createinput_inputelastic_type", + "CreateInputContainer": ".createinput_inputelastic_type", + "CreateInputContainerMode": ".createinput_inputelastic_type", + "CreateInputContainerTypedDict": ".createinput_inputelastic_type", + "CreateInputDNS": ".createinput_inputelastic_type", + "CreateInputDNSTypedDict": ".createinput_inputelastic_type", + "CreateInputDisksAndFileSystems": ".createinput_inputelastic_type", + "CreateInputDisksAndFileSystemsTypedDict": ".createinput_inputelastic_type", + "CreateInputFirewall": ".createinput_inputelastic_type", + "CreateInputFirewallTypedDict": ".createinput_inputelastic_type", + "CreateInputHostInfo": ".createinput_inputelastic_type", + "CreateInputHostInfoTypedDict": ".createinput_inputelastic_type", + "CreateInputHostsFile": ".createinput_inputelastic_type", + "CreateInputHostsFileTypedDict": ".createinput_inputelastic_type", + "CreateInputInputConfluentCloud": ".createinput_inputelastic_type", + "CreateInputInputConfluentCloudTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCribl": ".createinput_inputelastic_type", + "CreateInputInputCriblHTTP": ".createinput_inputelastic_type", + "CreateInputInputCriblHTTPType": ".createinput_inputelastic_type", + "CreateInputInputCriblHTTPTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTP": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPAuthTokensExt": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPAuthTokensExtTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPType": ".createinput_inputelastic_type", + "CreateInputInputCriblLakeHTTPTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCriblTCP": ".createinput_inputelastic_type", + "CreateInputInputCriblTCPTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCriblType": ".createinput_inputelastic_type", + "CreateInputInputCriblTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCriblmetrics": ".createinput_inputelastic_type", + "CreateInputInputCriblmetricsType": ".createinput_inputelastic_type", + "CreateInputInputCriblmetricsTypedDict": ".createinput_inputelastic_type", + "CreateInputInputCrowdstrike": ".createinput_inputelastic_type", + "CreateInputInputCrowdstrikeType": ".createinput_inputelastic_type", + "CreateInputInputCrowdstrikeTypedDict": ".createinput_inputelastic_type", + "CreateInputInputDatadogAgent": ".createinput_inputelastic_type", + "CreateInputInputDatadogAgentProxyMode": ".createinput_inputelastic_type", + "CreateInputInputDatadogAgentProxyModeTypedDict": ".createinput_inputelastic_type", + "CreateInputInputDatadogAgentType": ".createinput_inputelastic_type", + "CreateInputInputDatadogAgentTypedDict": ".createinput_inputelastic_type", + "CreateInputInputDatagen": ".createinput_inputelastic_type", + "CreateInputInputDatagenType": ".createinput_inputelastic_type", + "CreateInputInputDatagenTypedDict": ".createinput_inputelastic_type", + "CreateInputInputEdgePrometheus": ".createinput_inputelastic_type", + "CreateInputInputEdgePrometheusAuthenticationMethod": ".createinput_inputelastic_type", + "CreateInputInputEdgePrometheusDiscoveryType": ".createinput_inputelastic_type", + "CreateInputInputEdgePrometheusType": ".createinput_inputelastic_type", + "CreateInputInputEdgePrometheusTypedDict": ".createinput_inputelastic_type", + "CreateInputInputElasticType": ".createinput_inputelastic_type", + "CreateInputInputEventhub": ".createinput_inputelastic_type", + "CreateInputInputEventhubAmqp": ".createinput_inputelastic_type", + "CreateInputInputEventhubAmqpType": ".createinput_inputelastic_type", + "CreateInputInputEventhubAmqpTypedDict": ".createinput_inputelastic_type", + "CreateInputInputEventhubType": ".createinput_inputelastic_type", + "CreateInputInputEventhubTypedDict": ".createinput_inputelastic_type", + "CreateInputInputExec": ".createinput_inputelastic_type", + "CreateInputInputExecType": ".createinput_inputelastic_type", + "CreateInputInputExecTypedDict": ".createinput_inputelastic_type", + "CreateInputInputFirehose": ".createinput_inputelastic_type", + "CreateInputInputFirehoseType": ".createinput_inputelastic_type", + "CreateInputInputFirehoseTypedDict": ".createinput_inputelastic_type", + "CreateInputInputGooglePubsub": ".createinput_inputelastic_type", + "CreateInputInputGooglePubsubTypedDict": ".createinput_inputelastic_type", + "CreateInputInputGrafanaGrafana1": ".createinput_inputelastic_type", + "CreateInputInputGrafanaGrafana1TypedDict": ".createinput_inputelastic_type", + "CreateInputInputGrafanaGrafana2": ".createinput_inputelastic_type", + "CreateInputInputGrafanaGrafana2TypedDict": ".createinput_inputelastic_type", + "CreateInputInputGrafanaType1": ".createinput_inputelastic_type", + "CreateInputInputGrafanaType2": ".createinput_inputelastic_type", + "CreateInputInputGrafanaUnion": ".createinput_inputelastic_type", + "CreateInputInputGrafanaUnionTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata": ".createinput_inputelastic_type", + "CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPRaw": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawAuthTokensExt": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawAuthTokensExtTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawAuthTokensExtUnion": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawAuthTokensExtUnionTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawType": ".createinput_inputelastic_type", + "CreateInputInputHTTPRawTypedDict": ".createinput_inputelastic_type", + "CreateInputInputKinesis": ".createinput_inputelastic_type", + "CreateInputInputKinesisTypedDict": ".createinput_inputelastic_type", + "CreateInputInputKubeEvents": ".createinput_inputelastic_type", + "CreateInputInputKubeEventsType": ".createinput_inputelastic_type", + "CreateInputInputKubeEventsTypedDict": ".createinput_inputelastic_type", + "CreateInputInputKubeLogs": ".createinput_inputelastic_type", + "CreateInputInputKubeLogsRule": ".createinput_inputelastic_type", + "CreateInputInputKubeLogsRuleTypedDict": ".createinput_inputelastic_type", + "CreateInputInputKubeLogsType": ".createinput_inputelastic_type", + "CreateInputInputKubeLogsTypedDict": ".createinput_inputelastic_type", + "CreateInputInputKubeMetrics": ".createinput_inputelastic_type", + "CreateInputInputKubeMetricsPersistence": ".createinput_inputelastic_type", + "CreateInputInputKubeMetricsPersistenceTypedDict": ".createinput_inputelastic_type", + "CreateInputInputKubeMetricsType": ".createinput_inputelastic_type", + "CreateInputInputKubeMetricsTypedDict": ".createinput_inputelastic_type", + "CreateInputInputLoki": ".createinput_inputelastic_type", + "CreateInputInputLokiType": ".createinput_inputelastic_type", + "CreateInputInputLokiTypedDict": ".createinput_inputelastic_type", + "CreateInputInputMetrics": ".createinput_inputelastic_type", + "CreateInputInputMetricsType": ".createinput_inputelastic_type", + "CreateInputInputMetricsTypedDict": ".createinput_inputelastic_type", + "CreateInputInputMicrosoftGraph": ".createinput_inputelastic_type", + "CreateInputInputMicrosoftGraphAuthenticationMethod": ".createinput_inputelastic_type", + "CreateInputInputMicrosoftGraphSubscriptionPlan": ".createinput_inputelastic_type", + "CreateInputInputMicrosoftGraphType": ".createinput_inputelastic_type", + "CreateInputInputMicrosoftGraphTypedDict": ".createinput_inputelastic_type", + "CreateInputInputOffice365Mgmt": ".createinput_inputelastic_type", + "CreateInputInputOffice365MgmtContentConfig": ".createinput_inputelastic_type", + "CreateInputInputOffice365MgmtContentConfigTypedDict": ".createinput_inputelastic_type", + "CreateInputInputOffice365MgmtType": ".createinput_inputelastic_type", + "CreateInputInputOffice365MgmtTypedDict": ".createinput_inputelastic_type", + "CreateInputInputOffice365MsgTrace": ".createinput_inputelastic_type", + "CreateInputInputOffice365MsgTraceAuthenticationMethod": ".createinput_inputelastic_type", + "CreateInputInputOffice365MsgTraceType": ".createinput_inputelastic_type", + "CreateInputInputOffice365MsgTraceTypedDict": ".createinput_inputelastic_type", + "CreateInputInputOffice365Service": ".createinput_inputelastic_type", + "CreateInputInputOffice365ServiceContentConfig": ".createinput_inputelastic_type", + "CreateInputInputOffice365ServiceContentConfigTypedDict": ".createinput_inputelastic_type", + "CreateInputInputOffice365ServiceType": ".createinput_inputelastic_type", + "CreateInputInputOffice365ServiceTypedDict": ".createinput_inputelastic_type", + "CreateInputInputPrometheus": ".createinput_inputelastic_type", + "CreateInputInputPrometheusDiscoveryType": ".createinput_inputelastic_type", + "CreateInputInputPrometheusRw": ".createinput_inputelastic_type", + "CreateInputInputPrometheusRwType": ".createinput_inputelastic_type", + "CreateInputInputPrometheusRwTypedDict": ".createinput_inputelastic_type", + "CreateInputInputPrometheusTypedDict": ".createinput_inputelastic_type", + "CreateInputInputS3": ".createinput_inputelastic_type", + "CreateInputInputS3Inventory": ".createinput_inputelastic_type", + "CreateInputInputS3InventoryType": ".createinput_inputelastic_type", + "CreateInputInputS3InventoryTypedDict": ".createinput_inputelastic_type", + "CreateInputInputS3TypedDict": ".createinput_inputelastic_type", + "CreateInputInputSnmp": ".createinput_inputelastic_type", + "CreateInputInputSnmpTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetrics": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsCPU": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsCPUMode": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsCPUTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsCustom": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsCustomTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsDisk": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsDiskMode": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsDiskTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsFilter": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsFilterTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsHost": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsHostTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsMemory": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsMemoryMode": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsMemoryTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsNetwork": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsNetworkMode": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsNetworkTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsPersistence": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsPersistenceTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsSystem": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsSystemMode": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsSystemTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsType": ".createinput_inputelastic_type", + "CreateInputInputSystemMetricsTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemState": ".createinput_inputelastic_type", + "CreateInputInputSystemStatePersistence": ".createinput_inputelastic_type", + "CreateInputInputSystemStatePersistenceTypedDict": ".createinput_inputelastic_type", + "CreateInputInputSystemStateType": ".createinput_inputelastic_type", + "CreateInputInputSystemStateTypedDict": ".createinput_inputelastic_type", + "CreateInputInputTcpjson": ".createinput_inputelastic_type", + "CreateInputInputTcpjsonTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetrics": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsCPU": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsCPUMode": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsCPUTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsCustom": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsCustomTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsDisk": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsDiskMode": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsDiskTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsHost": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsHostTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsMemory": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsMemoryMode": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsMemoryTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsNetwork": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsNetworkMode": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsNetworkTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsPersistence": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsPersistenceTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsSystem": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsSystemMode": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsSystemTypedDict": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsType": ".createinput_inputelastic_type", + "CreateInputInputWindowsMetricsTypedDict": ".createinput_inputelastic_type", + "CreateInputInterfaces": ".createinput_inputelastic_type", + "CreateInputInterfacesTypedDict": ".createinput_inputelastic_type", + "CreateInputListeningPorts": ".createinput_inputelastic_type", + "CreateInputListeningPortsTypedDict": ".createinput_inputelastic_type", + "CreateInputLoggedInUsers": ".createinput_inputelastic_type", + "CreateInputLoggedInUsersTypedDict": ".createinput_inputelastic_type", + "CreateInputLokiAuth1": ".createinput_inputelastic_type", + "CreateInputLokiAuth1TypedDict": ".createinput_inputelastic_type", + "CreateInputLokiAuth2": ".createinput_inputelastic_type", + "CreateInputLokiAuth2TypedDict": ".createinput_inputelastic_type", + "CreateInputMetricsProtocol": ".createinput_inputelastic_type", + "CreateInputPodFilter": ".createinput_inputelastic_type", + "CreateInputPodFilterTypedDict": ".createinput_inputelastic_type", + "CreateInputPrometheusAuth1": ".createinput_inputelastic_type", + "CreateInputPrometheusAuth1TypedDict": ".createinput_inputelastic_type", + "CreateInputPrometheusAuth2": ".createinput_inputelastic_type", + "CreateInputPrometheusAuth2TypedDict": ".createinput_inputelastic_type", + "CreateInputRecordDataFormat": ".createinput_inputelastic_type", + "CreateInputRoutes": ".createinput_inputelastic_type", + "CreateInputRoutesTypedDict": ".createinput_inputelastic_type", + "CreateInputSNMPv3Authentication": ".createinput_inputelastic_type", + "CreateInputSNMPv3AuthenticationTypedDict": ".createinput_inputelastic_type", + "CreateInputSample": ".createinput_inputelastic_type", + "CreateInputSampleTypedDict": ".createinput_inputelastic_type", + "CreateInputSamplingRule": ".createinput_inputelastic_type", + "CreateInputSamplingRuleTypedDict": ".createinput_inputelastic_type", + "CreateInputScheduleType": ".createinput_inputelastic_type", + "CreateInputServices": ".createinput_inputelastic_type", + "CreateInputServicesTypedDict": ".createinput_inputelastic_type", + "CreateInputShardIteratorStart": ".createinput_inputelastic_type", + "CreateInputShardLoadBalancing": ".createinput_inputelastic_type", + "CreateInputTarget": ".createinput_inputelastic_type", + "CreateInputTargetTypedDict": ".createinput_inputelastic_type", + "CreateInputUsersAndGroups": ".createinput_inputelastic_type", + "CreateInputUsersAndGroupsTypedDict": ".createinput_inputelastic_type", + "CreateInputAccountType": ".createinput_v3user", + "CreateInputActivities": ".createinput_v3user", + "CreateInputActivitiesManageState": ".createinput_v3user", + "CreateInputActivitiesManageStateTypedDict": ".createinput_v3user", + "CreateInputActivitiesTypedDict": ".createinput_v3user", + "CreateInputAllow": ".createinput_v3user", + "CreateInputAllowTypedDict": ".createinput_v3user", + "CreateInputAuthMethodsExt": ".createinput_v3user", + "CreateInputAuthMethodsExtAuthenticationType": ".createinput_v3user", + "CreateInputAuthMethodsExtTypedDict": ".createinput_v3user", + "CreateInputAuthenticationProtocol": ".createinput_v3user", + "CreateInputBucketWidth": ".createinput_v3user", + "CreateInputCertOptions": ".createinput_v3user", + "CreateInputCertOptionsTypedDict": ".createinput_v3user", + "CreateInputChatMessages": ".createinput_v3user", + "CreateInputChatMessagesManageState": ".createinput_v3user", + "CreateInputChatMessagesManageStateTypedDict": ".createinput_v3user", + "CreateInputChatMessagesTypedDict": ".createinput_v3user", + "CreateInputChats": ".createinput_v3user", + "CreateInputChatsManageState": ".createinput_v3user", + "CreateInputChatsManageStateTypedDict": ".createinput_v3user", + "CreateInputChatsTypedDict": ".createinput_v3user", + "CreateInputContentType": ".createinput_v3user", + "CreateInputEventFormat": ".createinput_v3user", + "CreateInputFeedType": ".createinput_v3user", + "CreateInputFormat": ".createinput_v3user", + "CreateInputGrantType": ".createinput_v3user", + "CreateInputGroupBy": ".createinput_v3user", + "CreateInputGroups": ".createinput_v3user", + "CreateInputGroupsTypedDict": ".createinput_v3user", + "CreateInputInputAkamaiHec": ".createinput_v3user", + "CreateInputInputAkamaiHecType": ".createinput_v3user", + "CreateInputInputAkamaiHecTypedDict": ".createinput_v3user", + "CreateInputInputAnthropicCompliance": ".createinput_v3user", + "CreateInputInputAnthropicComplianceType": ".createinput_v3user", + "CreateInputInputAnthropicComplianceTypedDict": ".createinput_v3user", + "CreateInputInputAnthropicEnterpriseAnalytics": ".createinput_v3user", + "CreateInputInputAnthropicEnterpriseAnalyticsContentConfig": ".createinput_v3user", + "CreateInputInputAnthropicEnterpriseAnalyticsContentConfigTypedDict": ".createinput_v3user", + "CreateInputInputAnthropicEnterpriseAnalyticsType": ".createinput_v3user", + "CreateInputInputAnthropicEnterpriseAnalyticsTypedDict": ".createinput_v3user", + "CreateInputInputAppleUnifiedLogs": ".createinput_v3user", + "CreateInputInputAppleUnifiedLogsReadMode": ".createinput_v3user", + "CreateInputInputAppleUnifiedLogsType": ".createinput_v3user", + "CreateInputInputAppleUnifiedLogsTypedDict": ".createinput_v3user", + "CreateInputInputAppscope": ".createinput_v3user", + "CreateInputInputAppscopeFilter": ".createinput_v3user", + "CreateInputInputAppscopeFilterTypedDict": ".createinput_v3user", + "CreateInputInputAppscopePersistence": ".createinput_v3user", + "CreateInputInputAppscopePersistenceTypedDict": ".createinput_v3user", + "CreateInputInputAppscopeType": ".createinput_v3user", + "CreateInputInputAppscopeTypedDict": ".createinput_v3user", + "CreateInputInputAquaSecurityHec": ".createinput_v3user", + "CreateInputInputAquaSecurityHecType": ".createinput_v3user", + "CreateInputInputAquaSecurityHecTypedDict": ".createinput_v3user", + "CreateInputInputBedrockS3": ".createinput_v3user", + "CreateInputInputBedrockS3Type": ".createinput_v3user", + "CreateInputInputBedrockS3TypedDict": ".createinput_v3user", + "CreateInputInputBeyondtrustHec": ".createinput_v3user", + "CreateInputInputBeyondtrustHecType": ".createinput_v3user", + "CreateInputInputBeyondtrustHecTypedDict": ".createinput_v3user", + "CreateInputInputCloudflareHec": ".createinput_v3user", + "CreateInputInputCloudflareHecType": ".createinput_v3user", + "CreateInputInputCloudflareHecTypedDict": ".createinput_v3user", + "CreateInputInputExtrahopRevealx360": ".createinput_v3user", + "CreateInputInputExtrahopRevealx360Type": ".createinput_v3user", + "CreateInputInputExtrahopRevealx360TypedDict": ".createinput_v3user", + "CreateInputInputF5BigIP": ".createinput_v3user", + "CreateInputInputF5BigIPType": ".createinput_v3user", + "CreateInputInputF5BigIPTypedDict": ".createinput_v3user", + "CreateInputInputFile": ".createinput_v3user", + "CreateInputInputFileMode": ".createinput_v3user", + "CreateInputInputFileType": ".createinput_v3user", + "CreateInputInputFileTypedDict": ".createinput_v3user", + "CreateInputInputGigamonHec": ".createinput_v3user", + "CreateInputInputGigamonHecType": ".createinput_v3user", + "CreateInputInputGigamonHecTypedDict": ".createinput_v3user", + "CreateInputInputHashicorpHcpVaultDedicated": ".createinput_v3user", + "CreateInputInputHashicorpHcpVaultDedicatedType": ".createinput_v3user", + "CreateInputInputHashicorpHcpVaultDedicatedTypedDict": ".createinput_v3user", + "CreateInputInputJournalFiles": ".createinput_v3user", + "CreateInputInputJournalFilesRule": ".createinput_v3user", + "CreateInputInputJournalFilesRuleTypedDict": ".createinput_v3user", + "CreateInputInputJournalFilesType": ".createinput_v3user", + "CreateInputInputJournalFilesTypedDict": ".createinput_v3user", + "CreateInputInputMicrosoftCopilot": ".createinput_v3user", + "CreateInputInputMicrosoftCopilotAuthenticationMethod": ".createinput_v3user", + "CreateInputInputMicrosoftCopilotManageState": ".createinput_v3user", + "CreateInputInputMicrosoftCopilotManageStateTypedDict": ".createinput_v3user", + "CreateInputInputMicrosoftCopilotSubscriptionPlan": ".createinput_v3user", + "CreateInputInputMicrosoftCopilotType": ".createinput_v3user", + "CreateInputInputMicrosoftCopilotTypedDict": ".createinput_v3user", + "CreateInputInputMimecastHec": ".createinput_v3user", + "CreateInputInputMimecastHecType": ".createinput_v3user", + "CreateInputInputMimecastHecTypedDict": ".createinput_v3user", + "CreateInputInputModelDrivenTelemetry": ".createinput_v3user", + "CreateInputInputModelDrivenTelemetryType": ".createinput_v3user", + "CreateInputInputModelDrivenTelemetryTypedDict": ".createinput_v3user", + "CreateInputInputNetflow": ".createinput_v3user", + "CreateInputInputNetflowTypedDict": ".createinput_v3user", + "CreateInputInputOkta": ".createinput_v3user", + "CreateInputInputOktaManageState": ".createinput_v3user", + "CreateInputInputOktaManageStateTypedDict": ".createinput_v3user", + "CreateInputInputOktaType": ".createinput_v3user", + "CreateInputInputOktaTypedDict": ".createinput_v3user", + "CreateInputInputOpenTelemetry": ".createinput_v3user", + "CreateInputInputOpenTelemetryAuthenticationType": ".createinput_v3user", + "CreateInputInputOpenTelemetryType": ".createinput_v3user", + "CreateInputInputOpenTelemetryTypedDict": ".createinput_v3user", + "CreateInputInputOpenai": ".createinput_v3user", + "CreateInputInputOpenaiComplianceLogs": ".createinput_v3user", + "CreateInputInputOpenaiComplianceLogsManageState": ".createinput_v3user", + "CreateInputInputOpenaiComplianceLogsManageStateTypedDict": ".createinput_v3user", + "CreateInputInputOpenaiComplianceLogsType": ".createinput_v3user", + "CreateInputInputOpenaiComplianceLogsTypedDict": ".createinput_v3user", + "CreateInputInputOpenaiContentConfig": ".createinput_v3user", + "CreateInputInputOpenaiContentConfigTypedDict": ".createinput_v3user", + "CreateInputInputOpenaiLogLevel": ".createinput_v3user", + "CreateInputInputOpenaiManageState": ".createinput_v3user", + "CreateInputInputOpenaiManageStateTypedDict": ".createinput_v3user", + "CreateInputInputOpenaiType": ".createinput_v3user", + "CreateInputInputOpenaiTypedDict": ".createinput_v3user", + "CreateInputInputPingIdentityPingone": ".createinput_v3user", + "CreateInputInputPingIdentityPingoneType": ".createinput_v3user", + "CreateInputInputPingIdentityPingoneTypedDict": ".createinput_v3user", + "CreateInputInputProofpointPod": ".createinput_v3user", + "CreateInputInputProofpointPodType": ".createinput_v3user", + "CreateInputInputProofpointPodTypedDict": ".createinput_v3user", + "CreateInputInputRawUDP": ".createinput_v3user", + "CreateInputInputRawUDPType": ".createinput_v3user", + "CreateInputInputRawUDPTypedDict": ".createinput_v3user", + "CreateInputInputSailpointHec": ".createinput_v3user", + "CreateInputInputSailpointHecType": ".createinput_v3user", + "CreateInputInputSailpointHecTypedDict": ".createinput_v3user", + "CreateInputInputSecurityLake": ".createinput_v3user", + "CreateInputInputSecurityLakeTypedDict": ".createinput_v3user", + "CreateInputInputServicenowTable": ".createinput_v3user", + "CreateInputInputServicenowTableAuthenticationType": ".createinput_v3user", + "CreateInputInputServicenowTableManageState": ".createinput_v3user", + "CreateInputInputServicenowTableManageStateTypedDict": ".createinput_v3user", + "CreateInputInputServicenowTableType": ".createinput_v3user", + "CreateInputInputServicenowTableTypedDict": ".createinput_v3user", + "CreateInputInputSqs": ".createinput_v3user", + "CreateInputInputSqsTypedDict": ".createinput_v3user", + "CreateInputInputSysdigHec": ".createinput_v3user", + "CreateInputInputSysdigHecType": ".createinput_v3user", + "CreateInputInputSysdigHecTypedDict": ".createinput_v3user", + "CreateInputInputSyslogSyslog1": ".createinput_v3user", + "CreateInputInputSyslogSyslog1TypedDict": ".createinput_v3user", + "CreateInputInputSyslogSyslog2": ".createinput_v3user", + "CreateInputInputSyslogSyslog2TypedDict": ".createinput_v3user", + "CreateInputInputSyslogUnion": ".createinput_v3user", + "CreateInputInputSyslogUnionTypedDict": ".createinput_v3user", + "CreateInputInputTCP": ".createinput_v3user", + "CreateInputInputTCPType": ".createinput_v3user", + "CreateInputInputTCPTypedDict": ".createinput_v3user", + "CreateInputInputTrellixHec": ".createinput_v3user", + "CreateInputInputTrellixHecType": ".createinput_v3user", + "CreateInputInputTrellixHecTypedDict": ".createinput_v3user", + "CreateInputInputTrendMicroVisionOne": ".createinput_v3user", + "CreateInputInputTrendMicroVisionOneType": ".createinput_v3user", + "CreateInputInputTrendMicroVisionOneTypedDict": ".createinput_v3user", + "CreateInputInputUpwindHec": ".createinput_v3user", + "CreateInputInputUpwindHecType": ".createinput_v3user", + "CreateInputInputUpwindHecTypedDict": ".createinput_v3user", + "CreateInputInputVectraAiHec": ".createinput_v3user", + "CreateInputInputVectraAiHecType": ".createinput_v3user", + "CreateInputInputVectraAiHecTypedDict": ".createinput_v3user", + "CreateInputInputWef": ".createinput_v3user", + "CreateInputInputWefAuthenticationMethod": ".createinput_v3user", + "CreateInputInputWefType": ".createinput_v3user", + "CreateInputInputWefTypedDict": ".createinput_v3user", + "CreateInputInputWinEventLogs": ".createinput_v3user", + "CreateInputInputWinEventLogsReadMode": ".createinput_v3user", + "CreateInputInputWinEventLogsType": ".createinput_v3user", + "CreateInputInputWinEventLogsTypedDict": ".createinput_v3user", + "CreateInputInputWiz": ".createinput_v3user", + "CreateInputInputWizContentConfig": ".createinput_v3user", + "CreateInputInputWizContentConfigTypedDict": ".createinput_v3user", + "CreateInputInputWizManageState": ".createinput_v3user", + "CreateInputInputWizManageStateTypedDict": ".createinput_v3user", + "CreateInputInputWizType": ".createinput_v3user", + "CreateInputInputWizTypedDict": ".createinput_v3user", + "CreateInputInputWizWebhook": ".createinput_v3user", + "CreateInputInputWizWebhookAuthTokensExt1": ".createinput_v3user", + "CreateInputInputWizWebhookAuthTokensExt1TypedDict": ".createinput_v3user", + "CreateInputInputWizWebhookAuthTokensExt2": ".createinput_v3user", + "CreateInputInputWizWebhookAuthTokensExt2TypedDict": ".createinput_v3user", + "CreateInputInputWizWebhookAuthTokensExtUnion": ".createinput_v3user", + "CreateInputInputWizWebhookAuthTokensExtUnionTypedDict": ".createinput_v3user", + "CreateInputInputWizWebhookType": ".createinput_v3user", + "CreateInputInputWizWebhookTypedDict": ".createinput_v3user", + "CreateInputInputZscalerHec": ".createinput_v3user", + "CreateInputInputZscalerHecAuthToken": ".createinput_v3user", + "CreateInputInputZscalerHecAuthTokenTypedDict": ".createinput_v3user", + "CreateInputInputZscalerHecType": ".createinput_v3user", + "CreateInputInputZscalerHecTypedDict": ".createinput_v3user", + "CreateInputMTLSSettings": ".createinput_v3user", + "CreateInputMTLSSettingsTypedDict": ".createinput_v3user", + "CreateInputOTLPVersion": ".createinput_v3user", + "CreateInputOrganizationRoles": ".createinput_v3user", + "CreateInputOrganizationRolesTypedDict": ".createinput_v3user", + "CreateInputOrganizationUsers": ".createinput_v3user", + "CreateInputOrganizationUsersTypedDict": ".createinput_v3user", + "CreateInputOrganizations": ".createinput_v3user", + "CreateInputOrganizationsTypedDict": ".createinput_v3user", + "CreateInputPaginationType": ".createinput_v3user", + "CreateInputPrivacyProtocol": ".createinput_v3user", + "CreateInputProjectDetails": ".createinput_v3user", + "CreateInputProjectDetailsManageState": ".createinput_v3user", + "CreateInputProjectDetailsManageStateTypedDict": ".createinput_v3user", + "CreateInputProjectDetailsTypedDict": ".createinput_v3user", + "CreateInputProjects": ".createinput_v3user", + "CreateInputProjectsManageState": ".createinput_v3user", + "CreateInputProjectsManageStateTypedDict": ".createinput_v3user", + "CreateInputProjectsTypedDict": ".createinput_v3user", + "CreateInputProtocol": ".createinput_v3user", + "CreateInputQuery": ".createinput_v3user", + "CreateInputQueryBuilderMode": ".createinput_v3user", + "CreateInputQueryTypedDict": ".createinput_v3user", + "CreateInputQueueType": ".createinput_v3user", + "CreateInputRetryRules": ".createinput_v3user", + "CreateInputRetryRulesTypedDict": ".createinput_v3user", + "CreateInputSortDirection": ".createinput_v3user", + "CreateInputSubscription": ".createinput_v3user", + "CreateInputSubscriptionTypedDict": ".createinput_v3user", + "CreateInputTLSSettingsServerSide": ".createinput_v3user", + "CreateInputTLSSettingsServerSideTypedDict": ".createinput_v3user", + "CreateInputUNIXSocketPermissions": ".createinput_v3user", + "CreateInputUNIXSocketPermissionsTypedDict": ".createinput_v3user", + "CreateInputV3AuthenticationKeyType": ".createinput_v3user", + "CreateInputV3PrivacyKeyType": ".createinput_v3user", + "CreateInputV3User": ".createinput_v3user", + "CreateInputV3UserTypedDict": ".createinput_v3user", "CreateInputHecTokenByIDRequest": ".createinputhectokenbyidop", "CreateInputHecTokenByIDRequestTypedDict": ".createinputhectokenbyidop", - "CreateInputSystemByPackAccountType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackActivities": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackActivitiesManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackActivitiesManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackActivitiesTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackAllow": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackAllowTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackAuthMethodsExt": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackAuthMethodsExtAuthenticationType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackAuthMethodsExtTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackAuthenticationProtocol": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChatMessages": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChatMessagesManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChatMessagesManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChatMessagesTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChats": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChatsManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChatsManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackChatsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackEventFormat": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackFormat": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackGrantType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackGroups": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackGroupsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAnthropicCompliance": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAnthropicComplianceType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAnthropicComplianceTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppleUnifiedLogs": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppleUnifiedLogsReadMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppleUnifiedLogsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppleUnifiedLogsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppscope": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppscopeFilter": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppscopeFilterTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppscopePersistence": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppscopePersistenceTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppscopeType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputAppscopeTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputBedrockS3": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputBedrockS3Type": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputBedrockS3TypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCloudflareHec": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCloudflareHecType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCloudflareHecTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCriblmetrics": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCriblmetricsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCriblmetricsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCrowdstrike": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCrowdstrikeType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputCrowdstrikeTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatadogAgent": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatadogAgentProxyMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatadogAgentProxyModeTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatadogAgentType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatadogAgentTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatagen": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatagenType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputDatagenTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputFile": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputFileMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputFileType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputFileTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputHTTPRaw": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputHTTPRawType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputHTTPRawTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputJournalFiles": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputJournalFilesRule": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputJournalFilesRuleTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputJournalFilesType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputJournalFilesTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKinesis": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKinesisTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeEvents": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeEventsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeEventsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeLogs": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeLogsRule": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeLogsRuleTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeLogsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeLogsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeMetrics": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeMetricsPersistence": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeMetricsPersistenceTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeMetricsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputKubeMetricsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputMetrics": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputMetricsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputMetricsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputModelDrivenTelemetry": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputModelDrivenTelemetryType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputModelDrivenTelemetryTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputNetflow": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputNetflowTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOkta": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOktaManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOktaManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOktaType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOktaTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenTelemetry": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenTelemetryAuthenticationType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenTelemetryType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenTelemetryTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenai": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiComplianceLogs": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiComplianceLogsManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiComplianceLogsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiContentConfig": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiContentConfigTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiLogLevel": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputOpenaiTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputRawUDP": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputRawUDPType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputRawUDPTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputS3": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputS3Inventory": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputS3InventoryType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputS3InventoryTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputS3TypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSecurityLake": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSecurityLakeTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputServicenowTable": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputServicenowTableAuthenticationType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputServicenowTableManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputServicenowTableManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputServicenowTableType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputServicenowTableTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSnmp": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSnmpTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSqs": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSqsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSysdigHec": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSysdigHecType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSysdigHecTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSyslogSyslog1": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSyslogSyslog1TypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSyslogSyslog2": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSyslogSyslog2TypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSyslogUnion": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputSyslogUnionTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputTCP": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputTCPType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputTCPTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputUpwindHec": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputUpwindHecType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputUpwindHecTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWef": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWefAuthenticationMethod": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWefType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWefTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWinEventLogs": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWinEventLogsReadMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWinEventLogsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWinEventLogsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetrics": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsCPU": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsCPUMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsCPUTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsCustom": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsCustomTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsDisk": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsDiskMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsDiskTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsHost": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsHostTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsMemory": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsMemoryMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsMemoryTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsNetwork": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsNetworkMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsNetworkTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsPersistence": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsPersistenceTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsSystem": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsSystemMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsSystemTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWindowsMetricsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWiz": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizContentConfig": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizContentConfigTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizWebhook": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizWebhookType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputWizWebhookTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputZscalerHec": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputZscalerHecAuthToken": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputZscalerHecType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackInputZscalerHecTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackMTLSSettings": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackMTLSSettingsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackOTLPVersion": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackOrganizationRoles": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackOrganizationRolesTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackOrganizationUsers": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackOrganizationUsersTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackOrganizations": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackOrganizationsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackPaginationType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackPrivacyProtocol": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjectDetails": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjectDetailsManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjectDetailsManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjectDetailsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjects": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjectsManageState": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjectsManageStateTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProjectsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackProtocol": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackQuery": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackQueryBuilderMode": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackQueryTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackQueueType": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackRecordDataFormat": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSNMPv3Authentication": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSNMPv3AuthenticationTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSample": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSampleTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSamplingRule": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSamplingRuleTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackShardIteratorStart": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackShardLoadBalancing": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSortDirection": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSubscription": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackSubscriptionTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackTLSSettingsServerSide": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackTLSSettingsServerSideTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackUNIXSocketPermissions": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackUNIXSocketPermissionsTypedDict": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackV3User": ".createinputsystembypack_inputkubemetrics", - "CreateInputSystemByPackV3UserTypedDict": ".createinputsystembypack_inputkubemetrics", + "CreateInputSystemByPackAuth": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackAuthTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackAuthenticationMechanism": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackAzureBlobStorage": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackAzureBlobStorageTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackCertificate": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackCertificateTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackCheckpointing": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackCheckpointingTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackCollectors": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackCollectorsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackContainer": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackContainerMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackContainerTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackDNS": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackDNSTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackDisksAndFileSystems": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackDisksAndFileSystemsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackFirewall": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackFirewallTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackHostInfo": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackHostInfoTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackHostsFile": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackHostsFileTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputConfluentCloud": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputConfluentCloudTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCribl": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblHTTP": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblHTTPType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblHTTPTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTP": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExtTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblLakeHTTPTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblTCP": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblTCPTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblmetrics": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblmetricsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCriblmetricsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCrowdstrike": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCrowdstrikeType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputCrowdstrikeTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatadogAgent": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatadogAgentProxyMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatadogAgentProxyModeTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatadogAgentType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatadogAgentTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatagen": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatagenType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputDatagenTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEdgePrometheus": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEdgePrometheusDiscoveryType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEdgePrometheusType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEdgePrometheusTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputElasticType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEventhub": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEventhubAmqp": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEventhubAmqpType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEventhubAmqpTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEventhubType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputEventhubTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputExec": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputExecType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputExecTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputFirehose": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputFirehoseType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputFirehoseTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGooglePubsub": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGooglePubsubTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaGrafana1": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaGrafana1TypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaGrafana2": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaGrafana2TypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaType1": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaType2": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaUnion": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputGrafanaUnionTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRaw": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawAuthTokensExt": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawAuthTokensExtTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawAuthTokensExtUnionTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputHTTPRawTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKinesis": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKinesisTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeEvents": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeEventsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeEventsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeLogs": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeLogsRule": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeLogsRuleTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeLogsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeLogsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeMetrics": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeMetricsPersistence": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeMetricsPersistenceTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeMetricsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputKubeMetricsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputLoki": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputLokiType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputLokiTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMetrics": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMetricsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMetricsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMicrosoftGraph": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMicrosoftGraphType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputMicrosoftGraphTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365Mgmt": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MgmtContentConfig": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MgmtType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MgmtTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MsgTrace": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MsgTraceType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365MsgTraceTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365Service": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365ServiceContentConfig": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365ServiceType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputOffice365ServiceTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputPrometheus": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputPrometheusDiscoveryType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputPrometheusRw": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputPrometheusRwType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputPrometheusRwTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputPrometheusTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputS3": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputS3Inventory": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputS3InventoryType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputS3InventoryTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputS3TypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSnmp": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSnmpTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetrics": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsCPU": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsCPUMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsCPUTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsCustom": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsCustomTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsDisk": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsDiskMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsDiskTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsFilter": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsFilterTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsHost": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsHostTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsMemory": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsMemoryMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsMemoryTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsNetwork": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsNetworkMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsNetworkTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsPersistence": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsSystem": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsSystemMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsSystemTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemMetricsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemState": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemStatePersistence": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemStatePersistenceTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemStateType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputSystemStateTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputTcpjson": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputTcpjsonTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetrics": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsCPU": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsCPUMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsCPUTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsCustom": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsCustomTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsDisk": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsDiskMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsDiskTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsHost": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsHostTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsMemory": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsMemoryMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsMemoryTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsNetwork": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsNetworkMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsNetworkTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsPersistence": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsPersistenceTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsSystem": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsSystemMode": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsSystemTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInputWindowsMetricsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInterfaces": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackInterfacesTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackListeningPorts": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackListeningPortsTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackLoggedInUsers": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackLoggedInUsersTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackLokiAuth1": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackLokiAuth1TypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackLokiAuth2": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackLokiAuth2TypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackMetricsProtocol": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackPodFilter": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackPodFilterTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackPrometheusAuth1": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackPrometheusAuth1TypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackPrometheusAuth2": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackPrometheusAuth2TypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackRecordDataFormat": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackRoutes": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackRoutesTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackSNMPv3Authentication": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackSNMPv3AuthenticationTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackSample": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackSampleTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackSamplingRule": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackSamplingRuleTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackScheduleType": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackServices": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackServicesTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackShardIteratorStart": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackShardLoadBalancing": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackTarget": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackTargetTypedDict": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackUsersAndGroups": ".createinputsystembypack_inputelastic_type", + "CreateInputSystemByPackUsersAndGroupsTypedDict": ".createinputsystembypack_inputelastic_type", "CreateInputSystemByPackAPIVersion": ".createinputsystembypack_request", - "CreateInputSystemByPackAuth": ".createinputsystembypack_request", - "CreateInputSystemByPackAuthTokensExt": ".createinputsystembypack_request", - "CreateInputSystemByPackAuthTokensExtTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackAuthTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackAuthenticationMechanism": ".createinputsystembypack_request", - "CreateInputSystemByPackAzureBlobStorage": ".createinputsystembypack_request", - "CreateInputSystemByPackAzureBlobStorageTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackCertificate": ".createinputsystembypack_request", - "CreateInputSystemByPackCertificateTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackCheckpointing": ".createinputsystembypack_request", - "CreateInputSystemByPackCheckpointingTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackCollectors": ".createinputsystembypack_request", - "CreateInputSystemByPackCollectorsTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackCompression": ".createinputsystembypack_request", - "CreateInputSystemByPackContainer": ".createinputsystembypack_request", - "CreateInputSystemByPackContainerMode": ".createinputsystembypack_request", - "CreateInputSystemByPackContainerTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackDNS": ".createinputsystembypack_request", - "CreateInputSystemByPackDNSTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackDisksAndFileSystems": ".createinputsystembypack_request", - "CreateInputSystemByPackDisksAndFileSystemsTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackElasticsearchMetadata": ".createinputsystembypack_request", - "CreateInputSystemByPackElasticsearchMetadataTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackEndpointHeader": ".createinputsystembypack_request", "CreateInputSystemByPackEndpointHeaderTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackEndpointParam": ".createinputsystembypack_request", "CreateInputSystemByPackEndpointParamTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackFirewall": ".createinputsystembypack_request", - "CreateInputSystemByPackFirewallTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackHostInfo": ".createinputsystembypack_request", - "CreateInputSystemByPackHostInfoTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackHostsFile": ".createinputsystembypack_request", - "CreateInputSystemByPackHostsFileTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInput": ".createinputsystembypack_request", "CreateInputSystemByPackInputAzureBlob": ".createinputsystembypack_request", "CreateInputSystemByPackInputAzureBlobTypedDict": ".createinputsystembypack_request", + "CreateInputSystemByPackInputAzureVnetFlowLog": ".createinputsystembypack_request", + "CreateInputSystemByPackInputAzureVnetFlowLogType": ".createinputsystembypack_request", + "CreateInputSystemByPackInputAzureVnetFlowLogTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputCollection": ".createinputsystembypack_request", "CreateInputSystemByPackInputCollectionType": ".createinputsystembypack_request", "CreateInputSystemByPackInputCollectionTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputConfluentCloud": ".createinputsystembypack_request", - "CreateInputSystemByPackInputConfluentCloudTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCribl": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblHTTP": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblHTTPType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblHTTPTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblLakeHTTP": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblLakeHTTPType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblLakeHTTPTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblTCP": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblTCPTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputCriblTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEdgePrometheus": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEdgePrometheusDiscoveryType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEdgePrometheusType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEdgePrometheusTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputElastic": ".createinputsystembypack_request", "CreateInputSystemByPackInputElasticAuthenticationMethod": ".createinputsystembypack_request", "CreateInputSystemByPackInputElasticAuthenticationType": ".createinputsystembypack_request", "CreateInputSystemByPackInputElasticProxyMode": ".createinputsystembypack_request", "CreateInputSystemByPackInputElasticProxyModeTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputElasticType": ".createinputsystembypack_request", "CreateInputSystemByPackInputElasticTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEventhub": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEventhubAmqp": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEventhubAmqpType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEventhubAmqpTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEventhubType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputEventhubTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputExec": ".createinputsystembypack_request", - "CreateInputSystemByPackInputExecType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputExecTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputFirehose": ".createinputsystembypack_request", - "CreateInputSystemByPackInputFirehoseType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputFirehoseTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGooglePubsub": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGooglePubsubTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaGrafana1": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaGrafana1TypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaGrafana2": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaGrafana2TypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaType1": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaType2": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaUnion": ".createinputsystembypack_request", - "CreateInputSystemByPackInputGrafanaUnionTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputHTTP": ".createinputsystembypack_request", + "CreateInputSystemByPackInputHTTPAuthTokensExt": ".createinputsystembypack_request", + "CreateInputSystemByPackInputHTTPAuthTokensExtTypedDict": ".createinputsystembypack_request", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType": ".createinputsystembypack_request", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".createinputsystembypack_request", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint": ".createinputsystembypack_request", + "CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputHTTPType": ".createinputsystembypack_request", "CreateInputSystemByPackInputHTTPTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputKafka": ".createinputsystembypack_request", "CreateInputSystemByPackInputKafkaTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputLoki": ".createinputsystembypack_request", - "CreateInputSystemByPackInputLokiType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputLokiTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputMicrosoftGraph": ".createinputsystembypack_request", - "CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod": ".createinputsystembypack_request", - "CreateInputSystemByPackInputMicrosoftGraphType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputMicrosoftGraphTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputMsk": ".createinputsystembypack_request", "CreateInputSystemByPackInputMskTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365Mgmt": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MgmtContentConfig": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MgmtType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MgmtTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MsgTrace": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MsgTraceType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365MsgTraceTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365Service": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365ServiceContentConfig": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365ServiceType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputOffice365ServiceTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputPrometheus": ".createinputsystembypack_request", - "CreateInputSystemByPackInputPrometheusDiscoveryType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputPrometheusRw": ".createinputsystembypack_request", - "CreateInputSystemByPackInputPrometheusRwType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputPrometheusRwTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputPrometheusTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputSplunk": ".createinputsystembypack_request", "CreateInputSystemByPackInputSplunkAuthToken": ".createinputsystembypack_request", "CreateInputSystemByPackInputSplunkAuthTokenTypedDict": ".createinputsystembypack_request", @@ -16118,1018 +17089,1222 @@ "CreateInputSystemByPackInputSplunkSearchType": ".createinputsystembypack_request", "CreateInputSystemByPackInputSplunkSearchTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputSplunkTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetrics": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsCPU": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsCPUMode": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsCPUTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsCustom": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsCustomTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsDisk": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsDiskMode": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsDiskTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsFilter": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsFilterTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsHost": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsHostTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsMemory": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsMemoryMode": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsMemoryTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsNetwork": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsNetworkMode": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsNetworkTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsPersistence": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsSystem": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsSystemMode": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsSystemTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemMetricsTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemState": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemStatePersistence": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemStatePersistenceTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemStateType": ".createinputsystembypack_request", - "CreateInputSystemByPackInputSystemStateTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInputTcpjson": ".createinputsystembypack_request", - "CreateInputSystemByPackInputTcpjsonTypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackInputTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackInterfaces": ".createinputsystembypack_request", - "CreateInputSystemByPackInterfacesTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackListeningPorts": ".createinputsystembypack_request", - "CreateInputSystemByPackListeningPortsTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackLoggedInUsers": ".createinputsystembypack_request", - "CreateInputSystemByPackLoggedInUsersTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackLokiAuth1": ".createinputsystembypack_request", - "CreateInputSystemByPackLokiAuth1TypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackLokiAuth2": ".createinputsystembypack_request", - "CreateInputSystemByPackLokiAuth2TypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackMaxS2SVersion": ".createinputsystembypack_request", - "CreateInputSystemByPackMetricsProtocol": ".createinputsystembypack_request", - "CreateInputSystemByPackPodFilter": ".createinputsystembypack_request", - "CreateInputSystemByPackPodFilterTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackPrometheusAuth1": ".createinputsystembypack_request", - "CreateInputSystemByPackPrometheusAuth1TypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackPrometheusAuth2": ".createinputsystembypack_request", - "CreateInputSystemByPackPrometheusAuth2TypedDict": ".createinputsystembypack_request", "CreateInputSystemByPackRequest": ".createinputsystembypack_request", "CreateInputSystemByPackRequestTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackRoutes": ".createinputsystembypack_request", - "CreateInputSystemByPackRoutesTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackScheduleType": ".createinputsystembypack_request", - "CreateInputSystemByPackServices": ".createinputsystembypack_request", - "CreateInputSystemByPackServicesTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackSplunkHecMetadata": ".createinputsystembypack_request", - "CreateInputSystemByPackSplunkHecMetadataTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackSubscriptionPlan": ".createinputsystembypack_request", - "CreateInputSystemByPackTarget": ".createinputsystembypack_request", - "CreateInputSystemByPackTargetTypedDict": ".createinputsystembypack_request", - "CreateInputSystemByPackUsersAndGroups": ".createinputsystembypack_request", - "CreateInputSystemByPackUsersAndGroupsTypedDict": ".createinputsystembypack_request", + "CreateInputSystemByPackAccountType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackActivities": ".createinputsystembypack_v3user", + "CreateInputSystemByPackActivitiesManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackActivitiesManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackActivitiesTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackAllow": ".createinputsystembypack_v3user", + "CreateInputSystemByPackAllowTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackAuthMethodsExt": ".createinputsystembypack_v3user", + "CreateInputSystemByPackAuthMethodsExtAuthenticationType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackAuthMethodsExtTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackAuthenticationProtocol": ".createinputsystembypack_v3user", + "CreateInputSystemByPackBucketWidth": ".createinputsystembypack_v3user", + "CreateInputSystemByPackCertOptions": ".createinputsystembypack_v3user", + "CreateInputSystemByPackCertOptionsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChatMessages": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChatMessagesManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChatMessagesManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChatMessagesTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChats": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChatsManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChatsManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackChatsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackContentType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackEventFormat": ".createinputsystembypack_v3user", + "CreateInputSystemByPackFeedType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackFormat": ".createinputsystembypack_v3user", + "CreateInputSystemByPackGrantType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackGroupBy": ".createinputsystembypack_v3user", + "CreateInputSystemByPackGroups": ".createinputsystembypack_v3user", + "CreateInputSystemByPackGroupsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAkamaiHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAkamaiHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAkamaiHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicCompliance": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicComplianceType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicComplianceTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalytics": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfigTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppleUnifiedLogs": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppleUnifiedLogsReadMode": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppleUnifiedLogsType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppleUnifiedLogsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppscope": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppscopeFilter": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppscopeFilterTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppscopePersistence": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppscopePersistenceTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppscopeType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAppscopeTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAquaSecurityHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAquaSecurityHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputAquaSecurityHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputBedrockS3": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputBedrockS3Type": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputBedrockS3TypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputBeyondtrustHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputBeyondtrustHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputBeyondtrustHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputCloudflareHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputCloudflareHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputCloudflareHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputExtrahopRevealx360": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputExtrahopRevealx360Type": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputExtrahopRevealx360TypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputF5BigIP": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputF5BigIPType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputF5BigIPTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputFile": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputFileMode": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputFileType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputFileTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputGigamonHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputGigamonHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputGigamonHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputHashicorpHcpVaultDedicated": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputHashicorpHcpVaultDedicatedTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputJournalFiles": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputJournalFilesRule": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputJournalFilesRuleTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputJournalFilesType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputJournalFilesTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMicrosoftCopilot": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMicrosoftCopilotManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMicrosoftCopilotManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMicrosoftCopilotType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMicrosoftCopilotTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMimecastHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMimecastHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputMimecastHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputModelDrivenTelemetry": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputModelDrivenTelemetryType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputModelDrivenTelemetryTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputNetflow": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputNetflowTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOkta": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOktaManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOktaManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOktaType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOktaTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenTelemetry": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenTelemetryAuthenticationType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenTelemetryType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenTelemetryTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenai": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiComplianceLogs": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiComplianceLogsManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiComplianceLogsType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiContentConfig": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiContentConfigTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiLogLevel": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputOpenaiTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputPingIdentityPingone": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputPingIdentityPingoneType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputPingIdentityPingoneTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputProofpointPod": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputProofpointPodType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputProofpointPodTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputRawUDP": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputRawUDPType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputRawUDPTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSailpointHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSailpointHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSailpointHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSecurityLake": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSecurityLakeTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputServicenowTable": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputServicenowTableAuthenticationType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputServicenowTableManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputServicenowTableManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputServicenowTableType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputServicenowTableTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSqs": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSqsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSysdigHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSysdigHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSysdigHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSyslogSyslog1": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSyslogSyslog1TypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSyslogSyslog2": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSyslogSyslog2TypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSyslogUnion": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputSyslogUnionTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTCP": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTCPType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTCPTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTrellixHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTrellixHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTrellixHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTrendMicroVisionOne": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTrendMicroVisionOneType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputTrendMicroVisionOneTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputUpwindHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputUpwindHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputUpwindHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputVectraAiHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputVectraAiHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputVectraAiHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWef": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWefAuthenticationMethod": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWefType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWefTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWinEventLogs": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWinEventLogsReadMode": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWinEventLogsType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWinEventLogsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWiz": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizContentConfig": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizContentConfigTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhook": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt1": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt1TypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt2": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookAuthTokensExt2TypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookAuthTokensExtUnionTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputWizWebhookTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputZscalerHec": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputZscalerHecAuthToken": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputZscalerHecType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackInputZscalerHecTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackMTLSSettings": ".createinputsystembypack_v3user", + "CreateInputSystemByPackMTLSSettingsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackOTLPVersion": ".createinputsystembypack_v3user", + "CreateInputSystemByPackOrganizationRoles": ".createinputsystembypack_v3user", + "CreateInputSystemByPackOrganizationRolesTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackOrganizationUsers": ".createinputsystembypack_v3user", + "CreateInputSystemByPackOrganizationUsersTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackOrganizations": ".createinputsystembypack_v3user", + "CreateInputSystemByPackOrganizationsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackPaginationType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackPrivacyProtocol": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjectDetails": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjectDetailsManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjectDetailsManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjectDetailsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjects": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjectsManageState": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjectsManageStateTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProjectsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackProtocol": ".createinputsystembypack_v3user", + "CreateInputSystemByPackQuery": ".createinputsystembypack_v3user", + "CreateInputSystemByPackQueryBuilderMode": ".createinputsystembypack_v3user", + "CreateInputSystemByPackQueryTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackQueueType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackRetryRules": ".createinputsystembypack_v3user", + "CreateInputSystemByPackRetryRulesTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackSortDirection": ".createinputsystembypack_v3user", + "CreateInputSystemByPackSubscription": ".createinputsystembypack_v3user", + "CreateInputSystemByPackSubscriptionTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackTLSSettingsServerSide": ".createinputsystembypack_v3user", + "CreateInputSystemByPackTLSSettingsServerSideTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackUNIXSocketPermissions": ".createinputsystembypack_v3user", + "CreateInputSystemByPackUNIXSocketPermissionsTypedDict": ".createinputsystembypack_v3user", + "CreateInputSystemByPackV3AuthenticationKeyType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackV3PrivacyKeyType": ".createinputsystembypack_v3user", + "CreateInputSystemByPackV3User": ".createinputsystembypack_v3user", + "CreateInputSystemByPackV3UserTypedDict": ".createinputsystembypack_v3user", "CreateInputSystemHecTokenByPackAndIDRequest": ".createinputsystemhectokenbypackandidop", "CreateInputSystemHecTokenByPackAndIDRequestTypedDict": ".createinputsystemhectokenbypackandidop", "CreateOutputOutput": ".createoutput_output", "CreateOutputOutputDefault": ".createoutput_output", + "CreateOutputOutputDefaultType": ".createoutput_output", "CreateOutputOutputDefaultTypedDict": ".createoutput_output", "CreateOutputOutputTypedDict": ".createoutput_output", - "CreateOutputAPIVersion": ".createoutput_outputdefault_type", - "CreateOutputAdditionalProperty": ".createoutput_outputdefault_type", - "CreateOutputAdditionalPropertyTypedDict": ".createoutput_outputdefault_type", - "CreateOutputAuthToken": ".createoutput_outputdefault_type", - "CreateOutputAuthTokenTypedDict": ".createoutput_outputdefault_type", - "CreateOutputAuthType": ".createoutput_outputdefault_type", - "CreateOutputBlobAccessTier": ".createoutput_outputdefault_type", - "CreateOutputCertificate": ".createoutput_outputdefault_type", - "CreateOutputCertificateTypedDict": ".createoutput_outputdefault_type", - "CreateOutputCompression": ".createoutput_outputdefault_type", - "CreateOutputElasticVersion": ".createoutput_outputdefault_type", - "CreateOutputEndpointConfiguration": ".createoutput_outputdefault_type", - "CreateOutputExtentTag": ".createoutput_outputdefault_type", - "CreateOutputExtentTagTypedDict": ".createoutput_outputdefault_type", - "CreateOutputExtraLogType": ".createoutput_outputdefault_type", - "CreateOutputExtraLogTypeTypedDict": ".createoutput_outputdefault_type", - "CreateOutputFacility": ".createoutput_outputdefault_type", - "CreateOutputFieldName": ".createoutput_outputdefault_type", - "CreateOutputIndexerDiscoveryConfigs": ".createoutput_outputdefault_type", - "CreateOutputIndexerDiscoveryConfigsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputIngestIfNotExist": ".createoutput_outputdefault_type", - "CreateOutputIngestIfNotExistTypedDict": ".createoutput_outputdefault_type", - "CreateOutputIngestionMode": ".createoutput_outputdefault_type", - "CreateOutputLogLocationType": ".createoutput_outputdefault_type", - "CreateOutputMessageFormat": ".createoutput_outputdefault_type", - "CreateOutputMetadatum": ".createoutput_outputdefault_type", - "CreateOutputMetadatumTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureBlob": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureBlobTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureDataExplorer": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureDataExplorerAuthenticationMethod": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureDataExplorerPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureDataExplorerPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureDataExplorerType": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureDataExplorerTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureEventhub": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureEventhubPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureEventhubPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureEventhubType": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureEventhubTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureLogs": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureLogsAuthenticationMethod": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureLogsPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureLogsPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureLogsType": ".createoutput_outputdefault_type", - "CreateOutputOutputAzureLogsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputCloudwatch": ".createoutput_outputdefault_type", - "CreateOutputOutputCloudwatchPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputCloudwatchPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputCloudwatchType": ".createoutput_outputdefault_type", - "CreateOutputOutputCloudwatchTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputConfluentCloud": ".createoutput_outputdefault_type", - "CreateOutputOutputConfluentCloudPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputConfluentCloudPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputConfluentCloudTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputDefaultType": ".createoutput_outputdefault_type", - "CreateOutputOutputDevnull": ".createoutput_outputdefault_type", - "CreateOutputOutputDevnullType": ".createoutput_outputdefault_type", - "CreateOutputOutputDevnullTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputElastic": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticCloud": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticCloudPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticCloudPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticCloudType": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticCloudTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticType": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticURL": ".createoutput_outputdefault_type", - "CreateOutputOutputElasticURLTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputExabeam": ".createoutput_outputdefault_type", - "CreateOutputOutputExabeamType": ".createoutput_outputdefault_type", - "CreateOutputOutputExabeamTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputFilesystem": ".createoutput_outputdefault_type", - "CreateOutputOutputFilesystemType": ".createoutput_outputdefault_type", - "CreateOutputOutputFilesystemTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleBigquery": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleBigqueryPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleBigqueryPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleBigqueryType": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleBigqueryTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleChronicle": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleChronicleAuthenticationMethod": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleChroniclePqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleChroniclePqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleChronicleType": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleChronicleTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudLogging": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudLoggingPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudLoggingType": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudLoggingTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservability": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityEndpoint": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityOtlpVersion": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityProtocol": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityType": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudObservabilityTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudStorage": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudStorageAuthenticationMethod": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudStorageType": ".createoutput_outputdefault_type", - "CreateOutputOutputGoogleCloudStorageTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGooglePubsub": ".createoutput_outputdefault_type", - "CreateOutputOutputGooglePubsubPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputGooglePubsubPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputGooglePubsubTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputHoneycomb": ".createoutput_outputdefault_type", - "CreateOutputOutputHoneycombPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputHoneycombPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputHoneycombType": ".createoutput_outputdefault_type", - "CreateOutputOutputHoneycombTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputInfluxdb": ".createoutput_outputdefault_type", - "CreateOutputOutputInfluxdbAuthenticationType": ".createoutput_outputdefault_type", - "CreateOutputOutputInfluxdbPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputInfluxdbPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputInfluxdbType": ".createoutput_outputdefault_type", - "CreateOutputOutputInfluxdbTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputKafka": ".createoutput_outputdefault_type", - "CreateOutputOutputKafkaPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputKafkaPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputKafkaTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputKinesis": ".createoutput_outputdefault_type", - "CreateOutputOutputKinesisPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputKinesisPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputKinesisTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputMinio": ".createoutput_outputdefault_type", - "CreateOutputOutputMinioType": ".createoutput_outputdefault_type", - "CreateOutputOutputMinioTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputMsk": ".createoutput_outputdefault_type", - "CreateOutputOutputMskPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputMskPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputMskTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelic": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicEvents": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicEventsPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicEventsPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicEventsType": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicEventsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicType": ".createoutput_outputdefault_type", - "CreateOutputOutputNewrelicTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputS3": ".createoutput_outputdefault_type", - "CreateOutputOutputS3TypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSentinel": ".createoutput_outputdefault_type", - "CreateOutputOutputSentinelFormat": ".createoutput_outputdefault_type", - "CreateOutputOutputSentinelPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputSentinelPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSentinelType": ".createoutput_outputdefault_type", - "CreateOutputOutputSentinelTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSignalfx": ".createoutput_outputdefault_type", - "CreateOutputOutputSignalfxPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputSignalfxPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSignalfxType": ".createoutput_outputdefault_type", - "CreateOutputOutputSignalfxTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunk": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkHec": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkHecPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkHecPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkHecType": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkHecTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkHecURL": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkHecURLTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkLb": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkLbPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkLbPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkLbType": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkLbTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSplunkTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsd": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdExt": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdExtPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdExtPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdExtTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdType": ".createoutput_outputdefault_type", - "CreateOutputOutputStatsdTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSyslog": ".createoutput_outputdefault_type", - "CreateOutputOutputSyslogPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputSyslogPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputSyslogProtocol": ".createoutput_outputdefault_type", - "CreateOutputOutputSyslogSeverity": ".createoutput_outputdefault_type", - "CreateOutputOutputSyslogTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputTcpjson": ".createoutput_outputdefault_type", - "CreateOutputOutputTcpjsonPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputTcpjsonPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputTcpjsonTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWavefront": ".createoutput_outputdefault_type", - "CreateOutputOutputWavefrontPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputWavefrontPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWavefrontType": ".createoutput_outputdefault_type", - "CreateOutputOutputWavefrontTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookAuthenticationType1": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookAuthenticationType2": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookFormat1": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookFormat2": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookPqControls1": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookPqControls1TypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookPqControls2": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookPqControls2TypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookType1": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookType2": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookURL1": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookURL1TypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookURL2": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookURL2TypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookUnion": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookUnionTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookWebhook1": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookWebhook1TypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookWebhook2": ".createoutput_outputdefault_type", - "CreateOutputOutputWebhookWebhook2TypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWizHec": ".createoutput_outputdefault_type", - "CreateOutputOutputWizHecPqControls": ".createoutput_outputdefault_type", - "CreateOutputOutputWizHecPqControlsTypedDict": ".createoutput_outputdefault_type", - "CreateOutputOutputWizHecType": ".createoutput_outputdefault_type", - "CreateOutputOutputWizHecTypedDict": ".createoutput_outputdefault_type", - "CreateOutputPayloadFormat": ".createoutput_outputdefault_type", - "CreateOutputPrefixOptional": ".createoutput_outputdefault_type", - "CreateOutputReportLevel": ".createoutput_outputdefault_type", - "CreateOutputReportMethod": ".createoutput_outputdefault_type", - "CreateOutputSendEventsAs": ".createoutput_outputdefault_type", - "CreateOutputTimestampFormat": ".createoutput_outputdefault_type", - "CreateOutputTimestampPrecision": ".createoutput_outputdefault_type", - "CreateOutputUDMType": ".createoutput_outputdefault_type", - "CreateOutputWriteAction": ".createoutput_outputdefault_type", - "CreateOutputAISIEMEndpointPath": ".createoutput_outputstatsdext_type", - "CreateOutputAuthentication": ".createoutput_outputstatsdext_type", - "CreateOutputAuthenticationTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputColumnMapping": ".createoutput_outputstatsdext_type", - "CreateOutputColumnMappingTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputCustomLabel": ".createoutput_outputstatsdext_type", - "CreateOutputCustomLabelTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputDataSetSite": ".createoutput_outputstatsdext_type", - "CreateOutputDatadogSite": ".createoutput_outputstatsdext_type", - "CreateOutputEndpointType": ".createoutput_outputstatsdext_type", - "CreateOutputMappingType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAlibabaCloudS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAlibabaCloudS3AuthenticationMethod": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAlibabaCloudS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAlibabaCloudS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAlphasocS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAlphasocS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAlphasocS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAmazonManagedPrometheus": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAmazonManagedPrometheusPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAmazonManagedPrometheusPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAmazonManagedPrometheusType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputAmazonManagedPrometheusTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputChronicle": ".createoutput_outputstatsdext_type", - "CreateOutputOutputChronicleAuthenticationMethod": ".createoutput_outputstatsdext_type", - "CreateOutputOutputChroniclePqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputChroniclePqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputChronicleType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputChronicleTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputClickHouse": ".createoutput_outputstatsdext_type", - "CreateOutputOutputClickHousePqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputClickHousePqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputClickHouseType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputClickHouseTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCloudflareR2": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCloudflareR2Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCloudflareR2TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCloudianS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCloudianS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCloudianS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblHTTP": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblHTTPPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblHTTPPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblHTTPType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblHTTPTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblLake": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblLakeFormat": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblLakeType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblLakeTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblSearchEngine": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblSearchEnginePqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblSearchEnginePqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblSearchEngineType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblSearchEngineTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblTCP": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblTCPPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblTCPPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCriblTCPTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCrowdstrikeNextGenSiem": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCrowdstrikeNextGenSiemPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCrowdstrikeNextGenSiemPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCrowdstrikeNextGenSiemType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCrowdstrikeNextGenSiemTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCustomerMetricsStorage": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCustomerMetricsStoragePqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCustomerMetricsStoragePqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCustomerMetricsStorageType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputCustomerMetricsStorageTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatabricks": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatabricksType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatabricksTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatadog": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatadogPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatadogPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatadogSeverity": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatadogType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatadogTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDataset": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatasetPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatasetPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatasetSeverity": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatasetType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDatasetTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDellS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDellS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDellS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDiskSpool": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDiskSpoolType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDiskSpoolTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDlS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDlS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDlS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTP": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTPAuthenticationType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTPEndpoint": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTPFormat": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTPPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTPPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTPType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceHTTPTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceOtlp": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceOtlpPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceOtlpPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceOtlpProtocol": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceOtlpType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputDynatraceOtlpTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudGrafanaCloud1": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudGrafanaCloud2": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudPqControls1": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudPqControls1TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudPqControls2": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudPqControls2TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudType1": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudType2": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudUnion": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGrafanaCloudUnionTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGraphite": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGraphitePqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGraphitePqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGraphiteType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputGraphiteTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputHumioHec": ".createoutput_outputstatsdext_type", - "CreateOutputOutputHumioHecPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputHumioHecPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputHumioHecType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputHumioHecTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputIbmCloudS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputIbmCloudS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputIbmCloudS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLocalSearchStorage": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLocalSearchStorageFormat": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLocalSearchStoragePqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLocalSearchStoragePqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLocalSearchStorageType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLocalSearchStorageTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLoki": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLokiPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLokiPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLokiType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputLokiTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputMicrosoftFabric": ".createoutput_outputstatsdext_type", - "CreateOutputOutputMicrosoftFabricPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputMicrosoftFabricPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputMicrosoftFabricType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputMicrosoftFabricTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputNetflow": ".createoutput_outputstatsdext_type", - "CreateOutputOutputNetflowHost": ".createoutput_outputstatsdext_type", - "CreateOutputOutputNetflowHostTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputNetflowTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputNutanixObjects": ".createoutput_outputstatsdext_type", - "CreateOutputOutputNutanixObjectsType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputNutanixObjectsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputOpenTelemetry": ".createoutput_outputstatsdext_type", - "CreateOutputOutputOpenTelemetryAuthenticationType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputOpenTelemetryOTLPVersion": ".createoutput_outputstatsdext_type", - "CreateOutputOutputOpenTelemetryPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputOpenTelemetryPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputOpenTelemetryType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputOpenTelemetryTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputPrometheus": ".createoutput_outputstatsdext_type", - "CreateOutputOutputPrometheusAuthenticationType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputPrometheusPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputPrometheusPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputPrometheusTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputRing": ".createoutput_outputstatsdext_type", - "CreateOutputOutputRingDataFormat": ".createoutput_outputstatsdext_type", - "CreateOutputOutputRingType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputRingTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputRouter": ".createoutput_outputstatsdext_type", - "CreateOutputOutputRouterType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputRouterTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputScalityS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputScalityS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputScalityS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSecurityLake": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSecurityLakeTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSentinelOneAiSiem": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSentinelOneAiSiemPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSentinelOneAiSiemPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSentinelOneAiSiemType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSentinelOneAiSiemTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputServiceNow": ".createoutput_outputstatsdext_type", - "CreateOutputOutputServiceNowPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputServiceNowPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputServiceNowType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputServiceNowTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnmp": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnmpHost": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnmpHostTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnmpTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnowflakeStreaming": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnowflakeStreamingPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnowflakeStreamingPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnowflakeStreamingType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnowflakeStreamingTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSns": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnsPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnsPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnsType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSnsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSqs": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSqsPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSqsPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSqsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputStatsdExtType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputStorjS3": ".createoutput_outputstatsdext_type", - "CreateOutputOutputStorjS3Type": ".createoutput_outputstatsdext_type", - "CreateOutputOutputStorjS3TypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSumoLogic": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSumoLogicDataFormat": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSumoLogicPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSumoLogicPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSumoLogicType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputSumoLogicTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiam": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiamAuthenticationMethod": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiamPqControls": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiamPqControlsTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiamType": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiamTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiamURL": ".createoutput_outputstatsdext_type", - "CreateOutputOutputXsiamURLTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputPrivateKey": ".createoutput_outputstatsdext_type", - "CreateOutputPrivateKeyTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputQueueType": ".createoutput_outputstatsdext_type", - "CreateOutputRegion": ".createoutput_outputstatsdext_type", - "CreateOutputRule": ".createoutput_outputstatsdext_type", - "CreateOutputRuleTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputSendLogsAs": ".createoutput_outputstatsdext_type", - "CreateOutputStatsDestination": ".createoutput_outputstatsdext_type", - "CreateOutputStatsDestinationTypedDict": ".createoutput_outputstatsdext_type", - "CreateOutputTelemetryType": ".createoutput_outputstatsdext_type", - "CreateOutputSystemByPackAPIVersion": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackAdditionalProperty": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackAdditionalPropertyTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackAuthToken": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackAuthTokenTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackAuthType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackBlobAccessTier": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackCertificate": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackCertificateTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackCompression": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackElasticVersion": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackEndpointConfiguration": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackExtentTag": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackExtentTagTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackExtraLogType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackExtraLogTypeTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackFacility": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackFieldName": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackIndexerDiscoveryConfigs": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackIngestIfNotExist": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackIngestIfNotExistTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackIngestionMode": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackLogLocationType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackMessageFormat": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackMetadatum": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackMetadatumTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureBlob": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureBlobTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureDataExplorer": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureDataExplorerPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureDataExplorerType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureDataExplorerTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureEventhub": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureEventhubPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureEventhubType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureEventhubTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureLogs": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureLogsPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureLogsType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputAzureLogsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputCloudwatch": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputCloudwatchPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputCloudwatchType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputCloudwatchTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputConfluentCloud": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputConfluentCloudPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputConfluentCloudTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputDefaultType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputDevnull": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputDevnullType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputDevnullTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElastic": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticCloud": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticCloudPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticCloudType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticCloudTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticURL": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputElasticURLTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputExabeam": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputExabeamType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputExabeamTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputFilesystem": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputFilesystemType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputFilesystemTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleBigquery": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleBigqueryPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleBigqueryType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleBigqueryTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleChronicle": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleChroniclePqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleChronicleType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleChronicleTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudLogging": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudLoggingType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservability": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudStorage": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudStorageType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGooglePubsub": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGooglePubsubPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputGooglePubsubTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputHoneycomb": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputHoneycombPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputHoneycombType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputHoneycombTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputInfluxdb": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputInfluxdbAuthenticationType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputInfluxdbPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputInfluxdbType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputInfluxdbTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKafka": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKafkaPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKafkaPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKafkaTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKinesis": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKinesisPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKinesisPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputKinesisTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputMinio": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputMinioType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputMinioTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputMsk": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputMskPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputMskPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputMskTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelic": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicEvents": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicEventsPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicEventsType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicEventsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputNewrelicTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputS3": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputS3TypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSentinel": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSentinelFormat": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSentinelPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSentinelPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSentinelType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSentinelTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSignalfx": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSignalfxPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSignalfxType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSignalfxTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunk": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkHec": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkHecPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkHecType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkHecTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkHecURL": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkHecURLTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkLb": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkLbPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkLbType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkLbTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSplunkTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsd": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdExt": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdExtPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdExtTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputStatsdTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSyslog": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSyslogPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSyslogPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSyslogProtocol": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSyslogSeverity": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputSyslogTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputTcpjson": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputTcpjsonPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputTcpjsonTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWavefront": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWavefrontPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWavefrontType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWavefrontTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookAuthenticationType1": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookAuthenticationType2": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookFormat1": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookFormat2": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookPqControls1": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookPqControls1TypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookPqControls2": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookPqControls2TypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookType1": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookType2": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookURL1": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookURL1TypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookURL2": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookURL2TypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookUnion": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookUnionTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookWebhook1": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookWebhook1TypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookWebhook2": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWebhookWebhook2TypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWizHec": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWizHecPqControls": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWizHecPqControlsTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWizHecType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackOutputWizHecTypedDict": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackPayloadFormat": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackPrefixOptional": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackReportLevel": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackReportMethod": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackSendEventsAs": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackTimestampFormat": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackTimestampPrecision": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackUDMType": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackWriteAction": ".createoutputsystembypack_outputdefault_type", - "CreateOutputSystemByPackAISIEMEndpointPath": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackAuthentication": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackAuthenticationTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackColumnMapping": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackColumnMappingTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackCustomLabel": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackCustomLabelTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackDataSetSite": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackDatadogSite": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackEndpointType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackMappingType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAlibabaCloudS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAlibabaCloudS3AuthenticationMethod": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAlibabaCloudS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAlibabaCloudS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAlphasocS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAlphasocS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAlphasocS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAmazonManagedPrometheus": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAmazonManagedPrometheusType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputAmazonManagedPrometheusTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputChronicle": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputChronicleAuthenticationMethod": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputChroniclePqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputChroniclePqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputChronicleType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputChronicleTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputClickHouse": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputClickHousePqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputClickHousePqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputClickHouseType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputClickHouseTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCloudflareR2": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCloudflareR2Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCloudflareR2TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCloudianS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCloudianS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCloudianS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblHTTP": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblHTTPPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblHTTPPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblHTTPType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblHTTPTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblLake": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblLakeFormat": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblLakeType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblLakeTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblSearchEngine": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblSearchEnginePqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblSearchEnginePqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblSearchEngineType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblSearchEngineTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblTCP": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblTCPPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblTCPPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCriblTCPTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiem": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCustomerMetricsStorage": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCustomerMetricsStoragePqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCustomerMetricsStoragePqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCustomerMetricsStorageType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatabricks": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatabricksType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatabricksTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatadog": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatadogPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatadogPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatadogSeverity": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatadogType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatadogTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDataset": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatasetPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatasetPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatasetSeverity": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatasetType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDatasetTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDellS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDellS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDellS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDiskSpool": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDiskSpoolType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDiskSpoolTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDlS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDlS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDlS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTP": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTPEndpoint": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTPFormat": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTPPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTPPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTPType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceHTTPTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceOtlp": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceOtlpPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceOtlpPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceOtlpProtocol": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceOtlpType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputDynatraceOtlpTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudPqControls1": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudPqControls1TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudPqControls2": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudPqControls2TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudType1": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudType2": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudUnion": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGraphite": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGraphitePqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGraphitePqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGraphiteType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputGraphiteTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputHumioHec": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputHumioHecPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputHumioHecPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputHumioHecType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputHumioHecTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputIbmCloudS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputIbmCloudS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputIbmCloudS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLocalSearchStorage": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLocalSearchStorageFormat": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLocalSearchStoragePqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLocalSearchStoragePqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLocalSearchStorageType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLocalSearchStorageTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLoki": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLokiPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLokiPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLokiType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputLokiTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputMicrosoftFabric": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputMicrosoftFabricPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputMicrosoftFabricPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputMicrosoftFabricType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputMicrosoftFabricTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputNetflow": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputNetflowHost": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputNetflowHostTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputNetflowTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputNutanixObjects": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputNutanixObjectsType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputNutanixObjectsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputOpenTelemetry": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputOpenTelemetryPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputOpenTelemetryPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputOpenTelemetryType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputOpenTelemetryTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputPrometheus": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputPrometheusAuthenticationType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputPrometheusPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputPrometheusPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputPrometheusTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputRing": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputRingDataFormat": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputRingType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputRingTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputRouter": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputRouterType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputRouterTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputScalityS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputScalityS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputScalityS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSecurityLake": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSecurityLakeTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSentinelOneAiSiem": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSentinelOneAiSiemPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSentinelOneAiSiemPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSentinelOneAiSiemType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSentinelOneAiSiemTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputServiceNow": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputServiceNowPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputServiceNowPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputServiceNowType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputServiceNowTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnmp": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnmpHost": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnmpHostTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnmpTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnowflakeStreaming": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnowflakeStreamingPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnowflakeStreamingPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnowflakeStreamingType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnowflakeStreamingTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSns": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnsPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnsPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnsType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSnsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSqs": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSqsPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSqsPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSqsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputStatsdExtType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputStorjS3": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputStorjS3Type": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputStorjS3TypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSumoLogic": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSumoLogicDataFormat": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSumoLogicPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSumoLogicPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSumoLogicType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputSumoLogicTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiam": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiamAuthenticationMethod": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiamPqControls": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiamPqControlsTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiamType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiamTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiamURL": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackOutputXsiamURLTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackPrivateKey": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackPrivateKeyTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackQueueType": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackRegion": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackRule": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackRuleTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackSendLogsAs": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackStatsDestination": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackStatsDestinationTypedDict": ".createoutputsystembypack_outputstatsdext_type", - "CreateOutputSystemByPackTelemetryType": ".createoutputsystembypack_outputstatsdext_type", + "CreateOutputOutputWebhookAuthenticationType1": ".createoutput_output", + "CreateOutputOutputWebhookAuthenticationType2": ".createoutput_output", + "CreateOutputOutputWebhookFormat1": ".createoutput_output", + "CreateOutputOutputWebhookPqControls1": ".createoutput_output", + "CreateOutputOutputWebhookPqControls1TypedDict": ".createoutput_output", + "CreateOutputOutputWebhookPqControls2": ".createoutput_output", + "CreateOutputOutputWebhookPqControls2TypedDict": ".createoutput_output", + "CreateOutputOutputWebhookType1": ".createoutput_output", + "CreateOutputOutputWebhookURL1": ".createoutput_output", + "CreateOutputOutputWebhookURL1TypedDict": ".createoutput_output", + "CreateOutputOutputWebhookURL2": ".createoutput_output", + "CreateOutputOutputWebhookURL2TypedDict": ".createoutput_output", + "CreateOutputOutputWebhookUnion": ".createoutput_output", + "CreateOutputOutputWebhookUnionTypedDict": ".createoutput_output", + "CreateOutputOutputWebhookWebhook1": ".createoutput_output", + "CreateOutputOutputWebhookWebhook1TypedDict": ".createoutput_output", + "CreateOutputOutputWebhookWebhook2": ".createoutput_output", + "CreateOutputOutputWebhookWebhook2TypedDict": ".createoutput_output", + "CreateOutputAISIEMEndpointPath": ".createoutput_outputsns_pqcontrols", + "CreateOutputAuthentication": ".createoutput_outputsns_pqcontrols", + "CreateOutputAuthenticationTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputColumnMapping": ".createoutput_outputsns_pqcontrols", + "CreateOutputColumnMappingTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputCustomLabel": ".createoutput_outputsns_pqcontrols", + "CreateOutputCustomLabelTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputDataSetSite": ".createoutput_outputsns_pqcontrols", + "CreateOutputDatadogSite": ".createoutput_outputsns_pqcontrols", + "CreateOutputEndpointType": ".createoutput_outputsns_pqcontrols", + "CreateOutputMappingType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAlibabaCloudS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAlibabaCloudS3AuthenticationMethod": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAlibabaCloudS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAlibabaCloudS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAlphasocS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAlphasocS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAlphasocS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAmazonManagedPrometheus": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAmazonManagedPrometheusPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAmazonManagedPrometheusPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAmazonManagedPrometheusType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputAmazonManagedPrometheusTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputChronicle": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputChronicleAuthenticationMethod": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputChroniclePqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputChroniclePqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputChronicleType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputChronicleTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputClickHouse": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputClickHousePqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputClickHousePqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputClickHouseType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputClickHouseTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCloudflareR2": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCloudflareR2Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCloudflareR2TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCloudianS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCloudianS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCloudianS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblHTTP": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblHTTPPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblHTTPPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblHTTPType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblHTTPTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblLake": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblLakeFormat": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblLakeType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblLakeTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblSearchEngine": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblSearchEnginePqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblSearchEnginePqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblSearchEngineType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblSearchEngineTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblTCP": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblTCPPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblTCPPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCriblTCPTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCrowdstrikeNextGenSiem": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCrowdstrikeNextGenSiemPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCrowdstrikeNextGenSiemPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCrowdstrikeNextGenSiemType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCrowdstrikeNextGenSiemTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCustomerMetricsStorage": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCustomerMetricsStoragePqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCustomerMetricsStoragePqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCustomerMetricsStorageType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputCustomerMetricsStorageTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricks": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricksType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricksTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricksZerobus": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricksZerobusPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricksZerobusPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricksZerobusType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatabricksZerobusTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatadog": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatadogPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatadogPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatadogSeverity": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatadogType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatadogTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDataset": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatasetPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatasetPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatasetSeverity": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatasetType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDatasetTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDellS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDellS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDellS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDiskSpool": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDiskSpoolType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDiskSpoolTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDlS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDlS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDlS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTP": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTPAuthenticationType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTPEndpoint": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTPFormat": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTPPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTPPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTPType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceHTTPTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceOtlp": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceOtlpPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceOtlpPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceOtlpProtocol": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceOtlpType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputDynatraceOtlpTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudGrafanaCloud1": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudGrafanaCloud2": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudPqControls1": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudPqControls1TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudPqControls2": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudPqControls2TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudType1": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudType2": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudUnion": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputGrafanaCloudUnionTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputHumioHec": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputHumioHecPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputHumioHecPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputHumioHecType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputHumioHecTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputIbmCloudS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputIbmCloudS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputIbmCloudS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLocalSearchStorage": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLocalSearchStorageFormat": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLocalSearchStoragePqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLocalSearchStoragePqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLocalSearchStorageType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLocalSearchStorageTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLoki": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLokiPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLokiPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLokiType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputLokiTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputMicrosoftFabric": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputMicrosoftFabricPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputMicrosoftFabricPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputMicrosoftFabricType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputMicrosoftFabricTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputNetflow": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputNetflowHost": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputNetflowHostTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputNetflowTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputNutanixObjects": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputNutanixObjectsType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputNutanixObjectsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputOpenTelemetry": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputOpenTelemetryAuthenticationType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputOpenTelemetryOTLPVersion": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputOpenTelemetryPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputOpenTelemetryPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputOpenTelemetryType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputOpenTelemetryTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputPrometheus": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputPrometheusAuthenticationType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputPrometheusPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputPrometheusPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputPrometheusTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputRing": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputRingDataFormat": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputRingType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputRingTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputScalityS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputScalityS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputScalityS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSecurityLake": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSecurityLakeTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSentinelOneAiSiem": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSentinelOneAiSiemPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSentinelOneAiSiemPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSentinelOneAiSiemType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSentinelOneAiSiemTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputServiceNow": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputServiceNowPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputServiceNowPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputServiceNowType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputServiceNowTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnmp": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnmpHost": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnmpHostTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnmpTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnowflakeStreaming": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnowflakeStreamingPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnowflakeStreamingPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnowflakeStreamingType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnowflakeStreamingTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnsPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnsPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSnsType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSqs": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSqsPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSqsPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSqsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputStorjS3": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputStorjS3Type": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputStorjS3TypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSumoLogic": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSumoLogicDataFormat": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSumoLogicPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSumoLogicPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSumoLogicType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputSumoLogicTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputTraversalOtlp": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputTraversalOtlpAuthenticationType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputTraversalOtlpPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputTraversalOtlpPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputTraversalOtlpType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputTraversalOtlpTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiam": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiamAuthenticationMethod": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiamPqControls": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiamPqControlsTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiamType": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiamTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiamURL": ".createoutput_outputsns_pqcontrols", + "CreateOutputOutputXsiamURLTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputPrivateKey": ".createoutput_outputsns_pqcontrols", + "CreateOutputPrivateKeyTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputQueueType": ".createoutput_outputsns_pqcontrols", + "CreateOutputRegion": ".createoutput_outputsns_pqcontrols", + "CreateOutputSendAs": ".createoutput_outputsns_pqcontrols", + "CreateOutputSendLogsAs": ".createoutput_outputsns_pqcontrols", + "CreateOutputStatsDestination": ".createoutput_outputsns_pqcontrols", + "CreateOutputStatsDestinationTypedDict": ".createoutput_outputsns_pqcontrols", + "CreateOutputTelemetryType": ".createoutput_outputsns_pqcontrols", + "CreateOutputAPIVersion": ".createoutput_outputwebhook_format_2", + "CreateOutputAdditionalProperty": ".createoutput_outputwebhook_format_2", + "CreateOutputAdditionalPropertyTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputAuthToken": ".createoutput_outputwebhook_format_2", + "CreateOutputAuthTokenTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputAuthType": ".createoutput_outputwebhook_format_2", + "CreateOutputBlobAccessTier": ".createoutput_outputwebhook_format_2", + "CreateOutputCertificate": ".createoutput_outputwebhook_format_2", + "CreateOutputCertificateTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputCompression": ".createoutput_outputwebhook_format_2", + "CreateOutputElasticVersion": ".createoutput_outputwebhook_format_2", + "CreateOutputEndpointConfiguration": ".createoutput_outputwebhook_format_2", + "CreateOutputEventFormat": ".createoutput_outputwebhook_format_2", + "CreateOutputExtentTag": ".createoutput_outputwebhook_format_2", + "CreateOutputExtentTagTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputExtraLogType": ".createoutput_outputwebhook_format_2", + "CreateOutputExtraLogTypeTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputFacility": ".createoutput_outputwebhook_format_2", + "CreateOutputFieldName": ".createoutput_outputwebhook_format_2", + "CreateOutputIndexerDiscoveryConfigs": ".createoutput_outputwebhook_format_2", + "CreateOutputIndexerDiscoveryConfigsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputIngestIfNotExist": ".createoutput_outputwebhook_format_2", + "CreateOutputIngestIfNotExistTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputIngestionMode": ".createoutput_outputwebhook_format_2", + "CreateOutputLogLocationType": ".createoutput_outputwebhook_format_2", + "CreateOutputMessageFormat": ".createoutput_outputwebhook_format_2", + "CreateOutputMetadatum": ".createoutput_outputwebhook_format_2", + "CreateOutputMetadatumTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOAuthSecretSource": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureBlob": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureBlobTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureDataExplorer": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureDataExplorerAuthenticationMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureDataExplorerPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureDataExplorerPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureDataExplorerType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureDataExplorerTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureEventhub": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureEventhubPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureEventhubPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureEventhubType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureEventhubTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureLogs": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureLogsAuthenticationMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureLogsPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureLogsPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureLogsType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputAzureLogsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputCloudwatch": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputCloudwatchPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputCloudwatchPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputCloudwatchType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputCloudwatchTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputConfluentCloud": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputConfluentCloudPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputConfluentCloudPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputConfluentCloudTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputDevnull": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputDevnullType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputDevnullTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElastic": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticCloud": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticCloudPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticCloudPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticCloudType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticCloudTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticURL": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputElasticURLTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputExabeam": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputExabeamAuthenticationMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputExabeamType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputExabeamTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputFilesystem": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputFilesystemType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputFilesystemTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleBigquery": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleBigqueryPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleBigqueryPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleBigqueryType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleBigqueryTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleChronicle": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleChronicleAuthenticationMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleChroniclePqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleChroniclePqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleChronicleType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleChronicleTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudLogging": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudLoggingPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudLoggingType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudLoggingTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservability": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityEndpoint": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityOtlpVersion": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityProtocol": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudObservabilityTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudStorage": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudStorageAuthenticationMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudStorageType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGoogleCloudStorageTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGooglePubsub": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGooglePubsubPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGooglePubsubPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGooglePubsubTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGraphite": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGraphitePqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGraphitePqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGraphiteType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputGraphiteTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputHoneycomb": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputHoneycombPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputHoneycombPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputHoneycombType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputHoneycombTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputInfluxdb": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputInfluxdbAuthenticationType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputInfluxdbPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputInfluxdbPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputInfluxdbType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputInfluxdbTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKafka": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKafkaPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKafkaPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKafkaTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKinesis": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKinesisPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKinesisPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputKinesisTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputMinio": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputMinioType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputMinioTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputMsk": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputMskPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputMskPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputMskTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelic": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicEvents": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicEventsPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicEventsPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicEventsType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicEventsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputNewrelicTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputRouter": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputRouterType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputRouterTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputS3": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputS3TypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSentinel": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSentinelFormat": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSentinelPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSentinelPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSentinelType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSentinelTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSignalfx": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSignalfxPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSignalfxPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSignalfxType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSignalfxTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSns": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSnsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunk": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkHec": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkHecPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkHecPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkHecType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkHecTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkHecURL": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkHecURLTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkLb": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkLbPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkLbPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkLbType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkLbTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSplunkTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsd": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdExt": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdExtPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdExtPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdExtType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdExtTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputStatsdTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSyslog": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSyslogPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSyslogPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSyslogProtocol": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSyslogSeverity": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputSyslogTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputTcpjson": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputTcpjsonPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputTcpjsonPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputTcpjsonTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWavefront": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWavefrontPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWavefrontPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWavefrontType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWavefrontTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWebhookFormat2": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWebhookType2": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWizHec": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWizHecPqControls": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWizHecPqControlsTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWizHecType": ".createoutput_outputwebhook_format_2", + "CreateOutputOutputWizHecTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputPayloadFormat": ".createoutput_outputwebhook_format_2", + "CreateOutputPrefixOptional": ".createoutput_outputwebhook_format_2", + "CreateOutputReportLevel": ".createoutput_outputwebhook_format_2", + "CreateOutputReportMethod": ".createoutput_outputwebhook_format_2", + "CreateOutputRule": ".createoutput_outputwebhook_format_2", + "CreateOutputRuleTypedDict": ".createoutput_outputwebhook_format_2", + "CreateOutputSendEventsAs": ".createoutput_outputwebhook_format_2", + "CreateOutputTimestampFormat": ".createoutput_outputwebhook_format_2", + "CreateOutputTimestampPrecision": ".createoutput_outputwebhook_format_2", + "CreateOutputUDMType": ".createoutput_outputwebhook_format_2", + "CreateOutputWizDefendSourceType": ".createoutput_outputwebhook_format_2", + "CreateOutputWriteAction": ".createoutput_outputwebhook_format_2", + "CreateOutputSystemByPackAISIEMEndpointPath": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackAuthentication": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackAuthenticationTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackColumnMapping": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackColumnMappingTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackCustomLabel": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackCustomLabelTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackDataSetSite": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackDatadogSite": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackEndpointType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackMappingType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAlibabaCloudS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAlibabaCloudS3AuthenticationMethod": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAlibabaCloudS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAlibabaCloudS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAlphasocS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAlphasocS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAlphasocS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAmazonManagedPrometheus": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAmazonManagedPrometheusType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputAmazonManagedPrometheusTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputChronicle": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputChronicleAuthenticationMethod": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputChroniclePqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputChroniclePqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputChronicleType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputChronicleTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputClickHouse": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputClickHousePqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputClickHousePqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputClickHouseType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputClickHouseTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCloudflareR2": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCloudflareR2Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCloudflareR2TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCloudianS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCloudianS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCloudianS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblHTTP": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblHTTPPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblHTTPPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblHTTPType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblHTTPTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblLake": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblLakeFormat": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblLakeType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblLakeTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblSearchEngine": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblSearchEnginePqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblSearchEnginePqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblSearchEngineType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblSearchEngineTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblTCP": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblTCPPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblTCPPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCriblTCPTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiem": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCustomerMetricsStorage": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCustomerMetricsStoragePqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCustomerMetricsStoragePqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCustomerMetricsStorageType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricks": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricksType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricksTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricksZerobus": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricksZerobusPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricksZerobusPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricksZerobusType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatabricksZerobusTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatadog": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatadogPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatadogPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatadogSeverity": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatadogType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatadogTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDataset": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatasetPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatasetPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatasetSeverity": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatasetType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDatasetTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDellS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDellS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDellS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDiskSpool": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDiskSpoolType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDiskSpoolTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDlS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDlS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDlS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTP": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTPEndpoint": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTPFormat": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTPPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTPPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTPType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceHTTPTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceOtlp": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceOtlpPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceOtlpPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceOtlpProtocol": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceOtlpType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputDynatraceOtlpTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudPqControls1": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudPqControls1TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudPqControls2": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudPqControls2TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudType1": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudType2": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudUnion": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputHumioHec": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputHumioHecPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputHumioHecPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputHumioHecType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputHumioHecTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputIbmCloudS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputIbmCloudS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputIbmCloudS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLocalSearchStorage": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLocalSearchStorageFormat": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLocalSearchStoragePqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLocalSearchStoragePqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLocalSearchStorageType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLocalSearchStorageTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLoki": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLokiPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLokiPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLokiType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputLokiTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputMicrosoftFabric": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputMicrosoftFabricPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputMicrosoftFabricPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputMicrosoftFabricType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputMicrosoftFabricTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputNetflow": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputNetflowHost": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputNetflowHostTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputNetflowTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputNutanixObjects": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputNutanixObjectsType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputNutanixObjectsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputOpenTelemetry": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputOpenTelemetryPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputOpenTelemetryPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputOpenTelemetryType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputOpenTelemetryTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputPrometheus": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputPrometheusAuthenticationType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputPrometheusPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputPrometheusPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputPrometheusTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputRing": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputRingDataFormat": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputRingType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputRingTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputScalityS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputScalityS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputScalityS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSecurityLake": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSecurityLakeTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSentinelOneAiSiem": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSentinelOneAiSiemPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSentinelOneAiSiemPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSentinelOneAiSiemType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSentinelOneAiSiemTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputServiceNow": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputServiceNowPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputServiceNowPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputServiceNowType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputServiceNowTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnmp": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnmpHost": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnmpHostTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnmpTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnowflakeStreaming": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnowflakeStreamingPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnowflakeStreamingPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnowflakeStreamingType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnowflakeStreamingTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnsPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnsPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSnsType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSqs": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSqsPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSqsPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSqsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputStorjS3": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputStorjS3Type": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputStorjS3TypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSumoLogic": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSumoLogicDataFormat": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSumoLogicPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSumoLogicPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSumoLogicType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputSumoLogicTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputTraversalOtlp": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputTraversalOtlpPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputTraversalOtlpPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputTraversalOtlpType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputTraversalOtlpTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiam": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiamAuthenticationMethod": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiamPqControls": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiamPqControlsTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiamType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiamTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiamURL": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackOutputXsiamURLTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackPrivateKey": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackPrivateKeyTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackQueueType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackRegion": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackSendAs": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackSendLogsAs": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackStatsDestination": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackStatsDestinationTypedDict": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackTelemetryType": ".createoutputsystembypack_outputsns_pqcontrols", + "CreateOutputSystemByPackAPIVersion": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackAdditionalProperty": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackAdditionalPropertyTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackAuthToken": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackAuthTokenTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackAuthType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackBlobAccessTier": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackCertificate": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackCertificateTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackCompression": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackElasticVersion": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackEndpointConfiguration": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackEventFormat": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackExtentTag": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackExtentTagTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackExtraLogType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackExtraLogTypeTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackFacility": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackFieldName": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackIndexerDiscoveryConfigs": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackIngestIfNotExist": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackIngestIfNotExistTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackIngestionMode": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackLogLocationType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackMessageFormat": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackMetadatum": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackMetadatumTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOAuthSecretSource": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureBlob": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureBlobTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureDataExplorer": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureDataExplorerPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureDataExplorerType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureDataExplorerTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureEventhub": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureEventhubPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureEventhubType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureEventhubTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureLogs": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureLogsPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureLogsType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputAzureLogsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputCloudwatch": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputCloudwatchPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputCloudwatchType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputCloudwatchTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputConfluentCloud": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputConfluentCloudPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputConfluentCloudTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputDevnull": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputDevnullType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputDevnullTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElastic": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticCloud": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticCloudPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticCloudType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticCloudTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticURL": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputElasticURLTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputExabeam": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputExabeamAuthenticationMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputExabeamType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputExabeamTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputFilesystem": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputFilesystemType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputFilesystemTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleBigquery": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleBigqueryPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleBigqueryType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleBigqueryTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleChronicle": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleChroniclePqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleChronicleType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleChronicleTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudLogging": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudLoggingType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservability": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudStorage": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudStorageType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGooglePubsub": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGooglePubsubPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGooglePubsubTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGraphite": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGraphitePqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGraphitePqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGraphiteType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputGraphiteTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputHoneycomb": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputHoneycombPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputHoneycombType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputHoneycombTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputInfluxdb": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputInfluxdbAuthenticationType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputInfluxdbPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputInfluxdbType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputInfluxdbTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKafka": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKafkaPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKafkaPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKafkaTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKinesis": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKinesisPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKinesisPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputKinesisTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputMinio": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputMinioType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputMinioTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputMsk": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputMskPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputMskPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputMskTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelic": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicEvents": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicEventsPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicEventsType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicEventsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputNewrelicTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputRouter": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputRouterType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputRouterTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputS3": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputS3TypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSentinel": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSentinelFormat": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSentinelPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSentinelPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSentinelType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSentinelTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSignalfx": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSignalfxPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSignalfxType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSignalfxTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSns": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSnsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunk": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkHec": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkHecPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkHecType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkHecTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkHecURL": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkHecURLTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkLb": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkLbPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkLbType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkLbTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSplunkTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsd": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdExt": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdExtPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdExtType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdExtTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputStatsdTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSyslog": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSyslogPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSyslogPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSyslogProtocol": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSyslogSeverity": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputSyslogTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputTcpjson": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputTcpjsonPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputTcpjsonTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWavefront": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWavefrontPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWavefrontType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWavefrontTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWebhookFormat2": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWebhookType2": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWizHec": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWizHecPqControls": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWizHecPqControlsTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWizHecType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackOutputWizHecTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackPayloadFormat": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackPrefixOptional": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackReportLevel": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackReportMethod": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackRule": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackRuleTypedDict": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackSendEventsAs": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackTimestampFormat": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackTimestampPrecision": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackUDMType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackWizDefendSourceType": ".createoutputsystembypack_outputwebhook_format_2", + "CreateOutputSystemByPackWriteAction": ".createoutputsystembypack_outputwebhook_format_2", "CreateOutputSystemByPackOutput": ".createoutputsystembypack_request", "CreateOutputSystemByPackOutputDefault": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputDefaultType": ".createoutputsystembypack_request", "CreateOutputSystemByPackOutputDefaultTypedDict": ".createoutputsystembypack_request", "CreateOutputSystemByPackOutputTypedDict": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookAuthenticationType1": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookAuthenticationType2": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookFormat1": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookPqControls1": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookPqControls1TypedDict": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookPqControls2": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookPqControls2TypedDict": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookType1": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookURL1": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookURL1TypedDict": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookURL2": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookURL2TypedDict": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookUnion": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookUnionTypedDict": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookWebhook1": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookWebhook1TypedDict": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookWebhook2": ".createoutputsystembypack_request", + "CreateOutputSystemByPackOutputWebhookWebhook2TypedDict": ".createoutputsystembypack_request", "CreateOutputSystemByPackRequest": ".createoutputsystembypack_request", "CreateOutputSystemByPackRequestTypedDict": ".createoutputsystembypack_request", "CreateOutputSystemTestByPackAndIDRequest": ".createoutputsystemtestbypackandidop", @@ -17242,12 +18417,12 @@ "DistributedSummaryTypedDict": ".distributedsummary", "DistributedSummaryWorkers": ".distributedsummary", "DistributedSummaryWorkersTypedDict": ".distributedsummary", + "EmailRecipient": ".emailrecipient", + "EmailRecipientTypedDict": ".emailrecipient", "EmptyObject": ".emptyobject", "EmptyObjectTypedDict": ".emptyobject", "EstimatedIngestRateOptionsConfigGroup": ".estimatedingestrateoptionsconfiggroup", "EventBreakerTypeOptionsEventBreakerExistingOrNewNew": ".eventbreakertypeoptionseventbreakerexistingornewnew", - "ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor": ".executorspecificsettingstyperunnablejobexecutorexecutor", - "ExecutorSpecificSettingsTypeRunnableJobExecutorExecutorTypedDict": ".executorspecificsettingstyperunnablejobexecutorexecutor", "ExecutorTypeRunnableJobExecutor": ".executortyperunnablejobexecutor", "ExecutorTypeRunnableJobExecutorTypedDict": ".executortyperunnablejobexecutor", "ExtraHTTPHeaderConfInputElastic": ".extrahttpheaderconfinputelastic", @@ -17306,6 +18481,17 @@ "FunctionConfSchemaCodeTypedDict": ".functionconfschemacode", "FunctionConfSchemaComment": ".functionconfschemacomment", "FunctionConfSchemaCommentTypedDict": ".functionconfschemacomment", + "Confidence": ".functionconfschemadetectionrules", + "FieldOverride": ".functionconfschemadetectionrules", + "FieldOverrideTypedDict": ".functionconfschemadetectionrules", + "FunctionConfSchemaDetectionRules": ".functionconfschemadetectionrules", + "FunctionConfSchemaDetectionRulesSeverity": ".functionconfschemadetectionrules", + "FunctionConfSchemaDetectionRulesTypedDict": ".functionconfschemadetectionrules", + "Impact": ".functionconfschemadetectionrules", + "InlineRule": ".functionconfschemadetectionrules", + "InlineRuleTypedDict": ".functionconfschemadetectionrules", + "LocalOverrides": ".functionconfschemadetectionrules", + "LocalOverridesTypedDict": ".functionconfschemadetectionrules", "DNSLookupField": ".functionconfschemadnslookup", "DNSLookupFieldTypedDict": ".functionconfschemadnslookup", "FunctionConfSchemaDNSLookup": ".functionconfschemadnslookup", @@ -17328,6 +18514,8 @@ "FunctionConfSchemaFoldkeysTypedDict": ".functionconfschemafoldkeys", "FunctionConfSchemaGenStats": ".functionconfschemagenstats", "FunctionConfSchemaGenStatsTypedDict": ".functionconfschemagenstats", + "FunctionConfSchemaLakehouseEngineMetricsNormalizer": ".functionconfschemalakehouseenginemetricsnormalizer", + "FunctionConfSchemaLakehouseEngineMetricsNormalizerTypedDict": ".functionconfschemalakehouseenginemetricsnormalizer", "FunctionConfSchemaLimit": ".functionconfschemalimit", "FunctionConfSchemaLimitTypedDict": ".functionconfschemalimit", "FunctionConfSchemaLocalSearchDatatypeParser": ".functionconfschemalocalsearchdatatypeparser", @@ -17343,9 +18531,13 @@ "FunctionConfSchemaLocalSearchTimeRangeNormalizerTypedDict": ".functionconfschemalocalsearchtimerangenormalizer", "FunctionConfSchemaLocalSearchTransformer": ".functionconfschemalocalsearchtransformer", "FunctionConfSchemaLocalSearchTransformerTypedDict": ".functionconfschemalocalsearchtransformer", + "FunctionConfSchemaMetricsTimeRangeGate": ".functionconfschemametricstimerangegate", + "FunctionConfSchemaMetricsTimeRangeGateTypedDict": ".functionconfschemametricstimerangegate", "Condition": ".functionconfschemanotificationpolicies", "ConditionTypedDict": ".functionconfschemanotificationpolicies", "FunctionConfSchemaNotificationPolicies": ".functionconfschemanotificationpolicies", + "FunctionConfSchemaNotificationPoliciesTemplateTargetPair": ".functionconfschemanotificationpolicies", + "FunctionConfSchemaNotificationPoliciesTemplateTargetPairTypedDict": ".functionconfschemanotificationpolicies", "FunctionConfSchemaNotificationPoliciesTypedDict": ".functionconfschemanotificationpolicies", "Operator": ".functionconfschemanotificationpolicies", "Policy": ".functionconfschemanotificationpolicies", @@ -17412,6 +18604,9 @@ "V3UserTypedDict": ".functionconfschemasnmptrapserialize", "FunctionConfSchemaTrimTimestamp": ".functionconfschematrimtimestamp", "FunctionConfSchemaTrimTimestampTypedDict": ".functionconfschematrimtimestamp", + "FunctionDetectionRules": ".functiondetectionrules", + "FunctionDetectionRulesID": ".functiondetectionrules", + "FunctionDetectionRulesTypedDict": ".functiondetectionrules", "FunctionDistinct": ".functiondistinct", "FunctionDistinctID": ".functiondistinct", "FunctionDistinctTypedDict": ".functiondistinct", @@ -17466,6 +18661,9 @@ "FunctionLakeExport": ".functionlakeexport", "FunctionLakeExportID": ".functionlakeexport", "FunctionLakeExportTypedDict": ".functionlakeexport", + "FunctionLakehouseEngineMetricsNormalizer": ".functionlakehouseenginemetricsnormalizer", + "FunctionLakehouseEngineMetricsNormalizerID": ".functionlakehouseenginemetricsnormalizer", + "FunctionLakehouseEngineMetricsNormalizerTypedDict": ".functionlakehouseenginemetricsnormalizer", "FunctionLimit": ".functionlimit", "FunctionLimitID": ".functionlimit", "FunctionLimitTypedDict": ".functionlimit", @@ -17493,6 +18691,9 @@ "FunctionMetricsExport": ".functionmetricsexport", "FunctionMetricsExportID": ".functionmetricsexport", "FunctionMetricsExportTypedDict": ".functionmetricsexport", + "FunctionMetricsTimeRangeGate": ".functionmetricstimerangegate", + "FunctionMetricsTimeRangeGateID": ".functionmetricstimerangegate", + "FunctionMetricsTimeRangeGateTypedDict": ".functionmetricstimerangegate", "FunctionMvExpand": ".functionmvexpand", "FunctionMvExpandID": ".functionmvexpand", "FunctionMvExpandTypedDict": ".functionmvexpand", @@ -17619,6 +18820,10 @@ "GetFunctionsResponseTypedDict": ".getfunctionsop", "GetInputByIDRequest": ".getinputbyidop", "GetInputByIDRequestTypedDict": ".getinputbyidop", + "GetInputRequest": ".getinputop", + "GetInputRequestTypedDict": ".getinputop", + "GetInputResponse": ".getinputop", + "GetInputResponseTypedDict": ".getinputop", "GetInputPqByIDRequest": ".getinputpqbyidop", "GetInputPqByIDRequestTypedDict": ".getinputpqbyidop", "GetInputStatusByIDRequest": ".getinputstatusbyidop", @@ -17643,6 +18848,10 @@ "GetInputSystemPqByPackAndIDRequestTypedDict": ".getinputsystempqbypackandidop", "GetOutputByIDRequest": ".getoutputbyidop", "GetOutputByIDRequestTypedDict": ".getoutputbyidop", + "GetOutputRequest": ".getoutputop", + "GetOutputRequestTypedDict": ".getoutputop", + "GetOutputResponse": ".getoutputop", + "GetOutputResponseTypedDict": ".getoutputop", "GetOutputPqByIDRequest": ".getoutputpqbyidop", "GetOutputPqByIDRequestTypedDict": ".getoutputpqbyidop", "GetOutputSamplesByIDRequest": ".getoutputsamplesbyidop", @@ -17717,6 +18926,12 @@ "GetRoutesByPackAndIDRequestTypedDict": ".getroutesbypackandidop", "GetRoutesByPackRequest": ".getroutesbypackop", "GetRoutesByPackRequestTypedDict": ".getroutesbypackop", + "GetRoutesByPackResponse": ".getroutesbypackop", + "GetRoutesByPackResponseTypedDict": ".getroutesbypackop", + "GetRoutesRequest": ".getroutesop", + "GetRoutesRequestTypedDict": ".getroutesop", + "GetRoutesResponse": ".getroutesop", + "GetRoutesResponseTypedDict": ".getroutesop", "GetSavedJobByIDRequest": ".getsavedjobbyidop", "GetSavedJobByIDRequestTypedDict": ".getsavedjobbyidop", "GetSavedJobRequest": ".getsavedjobop", @@ -18225,6 +19440,9 @@ "HostOsTypeHeartbeatMetadataTypedDict": ".hostostypeheartbeatmetadata", "Input": ".input", "InputTypedDict": ".input", + "InputAkamaiHecInput": ".inputakamaihec_input", + "InputAkamaiHecInputTypedDict": ".inputakamaihec_input", + "InputAkamaiHecType": ".inputakamaihec_input", "Activities": ".inputanthropiccompliance_input", "ActivitiesManageState": ".inputanthropiccompliance_input", "ActivitiesManageStateTypedDict": ".inputanthropiccompliance_input", @@ -18256,6 +19474,14 @@ "ProjectsManageState": ".inputanthropiccompliance_input", "ProjectsManageStateTypedDict": ".inputanthropiccompliance_input", "ProjectsTypedDict": ".inputanthropiccompliance_input", + "BucketWidth": ".inputanthropicenterpriseanalytics_input", + "ContentType": ".inputanthropicenterpriseanalytics_input", + "GroupBy": ".inputanthropicenterpriseanalytics_input", + "InputAnthropicEnterpriseAnalyticsContentConfig": ".inputanthropicenterpriseanalytics_input", + "InputAnthropicEnterpriseAnalyticsContentConfigTypedDict": ".inputanthropicenterpriseanalytics_input", + "InputAnthropicEnterpriseAnalyticsInput": ".inputanthropicenterpriseanalytics_input", + "InputAnthropicEnterpriseAnalyticsInputTypedDict": ".inputanthropicenterpriseanalytics_input", + "InputAnthropicEnterpriseAnalyticsType": ".inputanthropicenterpriseanalytics_input", "InputAppleUnifiedLogsInput": ".inputappleunifiedlogs_input", "InputAppleUnifiedLogsInputTypedDict": ".inputappleunifiedlogs_input", "InputAppleUnifiedLogsReadMode": ".inputappleunifiedlogs_input", @@ -18271,11 +19497,20 @@ "InputAppscopeType": ".inputappscope_input", "UNIXSocketPermissions": ".inputappscope_input", "UNIXSocketPermissionsTypedDict": ".inputappscope_input", + "InputAquaSecurityHecInput": ".inputaquasecurityhec_input", + "InputAquaSecurityHecInputTypedDict": ".inputaquasecurityhec_input", + "InputAquaSecurityHecType": ".inputaquasecurityhec_input", "InputAzureBlobInput": ".inputazureblob_input", "InputAzureBlobInputTypedDict": ".inputazureblob_input", + "InputAzureVnetFlowLogInput": ".inputazurevnetflowlog_input", + "InputAzureVnetFlowLogInputTypedDict": ".inputazurevnetflowlog_input", + "InputAzureVnetFlowLogType": ".inputazurevnetflowlog_input", "InputBedrockS3Input": ".inputbedrocks3_input", "InputBedrockS3InputTypedDict": ".inputbedrocks3_input", "InputBedrockS3Type": ".inputbedrocks3_input", + "InputBeyondtrustHecInput": ".inputbeyondtrusthec_input", + "InputBeyondtrustHecInputTypedDict": ".inputbeyondtrusthec_input", + "InputBeyondtrustHecType": ".inputbeyondtrusthec_input", "InputCloudflareHecInput": ".inputcloudflarehec_input", "InputCloudflareHecInputTypedDict": ".inputcloudflarehec_input", "InputCloudflareHecType": ".inputcloudflarehec_input", @@ -18284,9 +19519,6 @@ "InputCollectionInput": ".inputcollection_input", "InputCollectionInputTypedDict": ".inputcollection_input", "InputCollectionType": ".inputcollection_input", - "InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint": ".inputcollectionorigindatasourcediscoverywithdestinationarnconstraint", - "InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict": ".inputcollectionorigindatasourcediscoverywithdestinationarnconstraint", - "Origin": ".inputcollectionorigindatasourcediscoverywithdestinationarnconstraint", "InputConfluentCloudInput": ".inputconfluentcloud_input", "InputConfluentCloudInputTypedDict": ".inputconfluentcloud_input", "InputCriblInput": ".inputcribl_input", @@ -18295,15 +19527,23 @@ "InputCriblHTTPInput": ".inputcriblhttp_input", "InputCriblHTTPInputTypedDict": ".inputcriblhttp_input", "InputCriblHTTPType": ".inputcriblhttp_input", - "AuthTokensExt": ".inputcribllakehttp_input", - "AuthTokensExtTypedDict": ".inputcribllakehttp_input", - "ElasticsearchMetadata": ".inputcribllakehttp_input", - "ElasticsearchMetadataTypedDict": ".inputcribllakehttp_input", + "InputCriblLakeHTTPAuthTokensExt": ".inputcribllakehttp_input", + "InputCriblLakeHTTPAuthTokensExtTypedDict": ".inputcribllakehttp_input", "InputCriblLakeHTTPInput": ".inputcribllakehttp_input", + "InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType": ".inputcribllakehttp_input", + "InputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".inputcribllakehttp_input", + "InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint": ".inputcribllakehttp_input", + "InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".inputcribllakehttp_input", "InputCriblLakeHTTPInputTypedDict": ".inputcribllakehttp_input", "InputCriblLakeHTTPType": ".inputcribllakehttp_input", - "SplunkHecMetadata": ".inputcribllakehttp_input", - "SplunkHecMetadataTypedDict": ".inputcribllakehttp_input", + "InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata": ".inputcribllakehttp_input", + "InputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict": ".inputcribllakehttp_input", + "InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata": ".inputcribllakehttp_input", + "InputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict": ".inputcribllakehttp_input", + "InputHTTPAuthTypeSecretConstraintElasticsearchMetadata": ".inputcribllakehttp_input", + "InputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict": ".inputcribllakehttp_input", + "InputHTTPAuthTypeSecretConstraintSplunkHecMetadata": ".inputcribllakehttp_input", + "InputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict": ".inputcribllakehttp_input", "InputCriblmetricsInput": ".inputcriblmetrics_input", "InputCriblmetricsInputTypedDict": ".inputcriblmetrics_input", "InputCriblmetricsType": ".inputcriblmetrics_input", @@ -18351,7 +19591,6 @@ "AzureBlobStorageTypedDict": ".inputeventhubamqp_input", "Checkpointing": ".inputeventhubamqp_input", "CheckpointingTypedDict": ".inputeventhubamqp_input", - "InputEventhubAmqpAuthenticationMethod": ".inputeventhubamqp_input", "InputEventhubAmqpCertificate": ".inputeventhubamqp_input", "InputEventhubAmqpCertificateTypedDict": ".inputeventhubamqp_input", "InputEventhubAmqpInput": ".inputeventhubamqp_input", @@ -18361,6 +19600,12 @@ "InputExecInputTypedDict": ".inputexec_input", "InputExecType": ".inputexec_input", "ScheduleType": ".inputexec_input", + "InputExtrahopRevealx360Input": ".inputextrahoprevealx360_input", + "InputExtrahopRevealx360InputTypedDict": ".inputextrahoprevealx360_input", + "InputExtrahopRevealx360Type": ".inputextrahoprevealx360_input", + "InputF5BigIPInput": ".inputf5bigip_input", + "InputF5BigIPInputTypedDict": ".inputf5bigip_input", + "InputF5BigIPType": ".inputf5bigip_input", "InputFileInput": ".inputfile_input", "InputFileInputTypedDict": ".inputfile_input", "InputFileMode": ".inputfile_input", @@ -18368,6 +19613,9 @@ "InputFirehoseInput": ".inputfirehose_input", "InputFirehoseInputTypedDict": ".inputfirehose_input", "InputFirehoseType": ".inputfirehose_input", + "InputGigamonHecInput": ".inputgigamonhec_input", + "InputGigamonHecInputTypedDict": ".inputgigamonhec_input", + "InputGigamonHecType": ".inputgigamonhec_input", "InputGooglePubsubInput": ".inputgooglepubsub_input", "InputGooglePubsubInputTypedDict": ".inputgooglepubsub_input", "InputGrafanaGrafanaInput1": ".inputgrafana_input_union", @@ -18386,10 +19634,25 @@ "PrometheusAuth1TypedDict": ".inputgrafana_input_union", "PrometheusAuth2": ".inputgrafana_input_union", "PrometheusAuth2TypedDict": ".inputgrafana_input_union", + "InputHashicorpHcpVaultDedicatedInput": ".inputhashicorphcpvaultdedicated_input", + "InputHashicorpHcpVaultDedicatedInputTypedDict": ".inputhashicorphcpvaultdedicated_input", + "InputHashicorpHcpVaultDedicatedType": ".inputhashicorphcpvaultdedicated_input", + "InputHTTPAuthTokensExt": ".inputhttp_input", + "InputHTTPAuthTokensExtTypedDict": ".inputhttp_input", "InputHTTPInput": ".inputhttp_input", + "InputHTTPInputHTTPAuthTokensExtItemsType": ".inputhttp_input", + "InputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".inputhttp_input", + "InputHTTPInputHTTPAuthTypeSecretConstraint": ".inputhttp_input", + "InputHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".inputhttp_input", "InputHTTPInputTypedDict": ".inputhttp_input", "InputHTTPType": ".inputhttp_input", + "InputHTTPRawAuthTokensExt": ".inputhttpraw_input", + "InputHTTPRawAuthTokensExtTypedDict": ".inputhttpraw_input", + "InputHTTPRawAuthTokensExtUnion": ".inputhttpraw_input", + "InputHTTPRawAuthTokensExtUnionTypedDict": ".inputhttpraw_input", "InputHTTPRawInput": ".inputhttpraw_input", + "InputHTTPRawInputHTTPAuthTypeSecretConstraint": ".inputhttpraw_input", + "InputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict": ".inputhttpraw_input", "InputHTTPRawInputTypedDict": ".inputhttpraw_input", "InputHTTPRawType": ".inputhttpraw_input", "InputJournalFilesInput": ".inputjournalfiles_input", @@ -18423,11 +19686,25 @@ "InputMetricsInput": ".inputmetrics_input", "InputMetricsInputTypedDict": ".inputmetrics_input", "InputMetricsType": ".inputmetrics_input", + "CertOptions": ".inputmicrosoftcopilot_input", + "CertOptionsTypedDict": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotAuthenticationMethod": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotInput": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotInputTypedDict": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotManageState": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotManageStateTypedDict": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotRetryRules": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotRetryRulesTypedDict": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotSubscriptionPlan": ".inputmicrosoftcopilot_input", + "InputMicrosoftCopilotType": ".inputmicrosoftcopilot_input", "InputMicrosoftGraphAuthenticationMethod": ".inputmicrosoftgraph_input", "InputMicrosoftGraphInput": ".inputmicrosoftgraph_input", "InputMicrosoftGraphInputTypedDict": ".inputmicrosoftgraph_input", + "InputMicrosoftGraphSubscriptionPlan": ".inputmicrosoftgraph_input", "InputMicrosoftGraphType": ".inputmicrosoftgraph_input", - "SubscriptionPlan": ".inputmicrosoftgraph_input", + "InputMimecastHecInput": ".inputmimecasthec_input", + "InputMimecastHecInputTypedDict": ".inputmimecasthec_input", + "InputMimecastHecType": ".inputmimecasthec_input", "InputModelDrivenTelemetryInput": ".inputmodeldriventelemetry_input", "InputModelDrivenTelemetryInputTypedDict": ".inputmodeldriventelemetry_input", "InputModelDrivenTelemetryType": ".inputmodeldriventelemetry_input", @@ -18478,6 +19755,9 @@ "InputOpenTelemetryOTLPVersion": ".inputopentelemetry_input", "InputOpenTelemetryProtocol": ".inputopentelemetry_input", "InputOpenTelemetryType": ".inputopentelemetry_input", + "InputPingIdentityPingoneInput": ".inputpingidentitypingone_input", + "InputPingIdentityPingoneInputTypedDict": ".inputpingidentitypingone_input", + "InputPingIdentityPingoneType": ".inputpingidentitypingone_input", "InputPrometheusDiscoveryType": ".inputprometheus_input", "InputPrometheusInput": ".inputprometheus_input", "InputPrometheusInputTypedDict": ".inputprometheus_input", @@ -18485,131 +19765,49 @@ "InputPrometheusRwInput": ".inputprometheusrw_input", "InputPrometheusRwInputTypedDict": ".inputprometheusrw_input", "InputPrometheusRwType": ".inputprometheusrw_input", + "FeedType": ".inputproofpointpod_input", + "InputProofpointPodInput": ".inputproofpointpod_input", + "InputProofpointPodInputTypedDict": ".inputproofpointpod_input", + "InputProofpointPodType": ".inputproofpointpod_input", + "InputProvenanceTypeOptional": ".inputprovenancetypeoptional", + "InputProvenanceTypeOptionalTypedDict": ".inputprovenancetypeoptional", "InputRawUDPInput": ".inputrawudp_input", "InputRawUDPInputTypedDict": ".inputrawudp_input", "InputRawUDPType": ".inputrawudp_input", "InputResponse": ".inputresponse", "InputResponseAPIVersion": ".inputresponse", - "InputResponseAuth": ".inputresponse", - "InputResponseAuthTokensExt": ".inputresponse", - "InputResponseAuthTokensExtTypedDict": ".inputresponse", - "InputResponseAuthTypedDict": ".inputresponse", - "InputResponseAuthenticationMechanism": ".inputresponse", - "InputResponseAzureBlobStorage": ".inputresponse", - "InputResponseAzureBlobStorageTypedDict": ".inputresponse", - "InputResponseCertificate": ".inputresponse", - "InputResponseCertificateTypedDict": ".inputresponse", - "InputResponseCheckpointing": ".inputresponse", - "InputResponseCheckpointingTypedDict": ".inputresponse", - "InputResponseCollectors": ".inputresponse", - "InputResponseCollectorsTypedDict": ".inputresponse", "InputResponseCompression": ".inputresponse", - "InputResponseContainer": ".inputresponse", - "InputResponseContainerMode": ".inputresponse", - "InputResponseContainerTypedDict": ".inputresponse", - "InputResponseDNS": ".inputresponse", - "InputResponseDNSTypedDict": ".inputresponse", - "InputResponseDisksAndFileSystems": ".inputresponse", - "InputResponseDisksAndFileSystemsTypedDict": ".inputresponse", - "InputResponseElasticsearchMetadata": ".inputresponse", - "InputResponseElasticsearchMetadataTypedDict": ".inputresponse", "InputResponseEndpointHeader": ".inputresponse", "InputResponseEndpointHeaderTypedDict": ".inputresponse", "InputResponseEndpointParam": ".inputresponse", "InputResponseEndpointParamTypedDict": ".inputresponse", - "InputResponseFirewall": ".inputresponse", - "InputResponseFirewallTypedDict": ".inputresponse", - "InputResponseHostInfo": ".inputresponse", - "InputResponseHostInfoTypedDict": ".inputresponse", - "InputResponseHostsFile": ".inputresponse", - "InputResponseHostsFileTypedDict": ".inputresponse", "InputResponseInputAzureBlob": ".inputresponse", "InputResponseInputAzureBlobTypedDict": ".inputresponse", + "InputResponseInputAzureVnetFlowLog": ".inputresponse", + "InputResponseInputAzureVnetFlowLogType": ".inputresponse", + "InputResponseInputAzureVnetFlowLogTypedDict": ".inputresponse", "InputResponseInputCollection": ".inputresponse", "InputResponseInputCollectionType": ".inputresponse", "InputResponseInputCollectionTypedDict": ".inputresponse", - "InputResponseInputConfluentCloud": ".inputresponse", - "InputResponseInputConfluentCloudTypedDict": ".inputresponse", - "InputResponseInputCribl": ".inputresponse", - "InputResponseInputCriblHTTP": ".inputresponse", - "InputResponseInputCriblHTTPType": ".inputresponse", - "InputResponseInputCriblHTTPTypedDict": ".inputresponse", - "InputResponseInputCriblLakeHTTP": ".inputresponse", - "InputResponseInputCriblLakeHTTPType": ".inputresponse", - "InputResponseInputCriblLakeHTTPTypedDict": ".inputresponse", - "InputResponseInputCriblTCP": ".inputresponse", - "InputResponseInputCriblTCPTypedDict": ".inputresponse", - "InputResponseInputCriblType": ".inputresponse", - "InputResponseInputCriblTypedDict": ".inputresponse", - "InputResponseInputEdgePrometheus": ".inputresponse", - "InputResponseInputEdgePrometheusAuthenticationMethod": ".inputresponse", - "InputResponseInputEdgePrometheusDiscoveryType": ".inputresponse", - "InputResponseInputEdgePrometheusType": ".inputresponse", - "InputResponseInputEdgePrometheusTypedDict": ".inputresponse", "InputResponseInputElastic": ".inputresponse", "InputResponseInputElasticAuthenticationMethod": ".inputresponse", "InputResponseInputElasticAuthenticationType": ".inputresponse", "InputResponseInputElasticProxyMode": ".inputresponse", "InputResponseInputElasticProxyModeTypedDict": ".inputresponse", - "InputResponseInputElasticType": ".inputresponse", "InputResponseInputElasticTypedDict": ".inputresponse", - "InputResponseInputEventhub": ".inputresponse", - "InputResponseInputEventhubAmqp": ".inputresponse", - "InputResponseInputEventhubAmqpAuthenticationMethod": ".inputresponse", - "InputResponseInputEventhubAmqpType": ".inputresponse", - "InputResponseInputEventhubAmqpTypedDict": ".inputresponse", - "InputResponseInputEventhubType": ".inputresponse", - "InputResponseInputEventhubTypedDict": ".inputresponse", - "InputResponseInputExec": ".inputresponse", - "InputResponseInputExecType": ".inputresponse", - "InputResponseInputExecTypedDict": ".inputresponse", - "InputResponseInputFirehose": ".inputresponse", - "InputResponseInputFirehoseType": ".inputresponse", - "InputResponseInputFirehoseTypedDict": ".inputresponse", - "InputResponseInputGooglePubsub": ".inputresponse", - "InputResponseInputGooglePubsubTypedDict": ".inputresponse", - "InputResponseInputGrafanaGrafana1": ".inputresponse", - "InputResponseInputGrafanaGrafana1TypedDict": ".inputresponse", - "InputResponseInputGrafanaGrafana2": ".inputresponse", - "InputResponseInputGrafanaGrafana2TypedDict": ".inputresponse", - "InputResponseInputGrafanaType1": ".inputresponse", - "InputResponseInputGrafanaType2": ".inputresponse", - "InputResponseInputGrafanaUnion": ".inputresponse", - "InputResponseInputGrafanaUnionTypedDict": ".inputresponse", "InputResponseInputHTTP": ".inputresponse", + "InputResponseInputHTTPAuthTokensExt": ".inputresponse", + "InputResponseInputHTTPAuthTokensExtTypedDict": ".inputresponse", + "InputResponseInputHTTPInputHTTPAuthTokensExtItemsType": ".inputresponse", + "InputResponseInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".inputresponse", + "InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint": ".inputresponse", + "InputResponseInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".inputresponse", "InputResponseInputHTTPType": ".inputresponse", "InputResponseInputHTTPTypedDict": ".inputresponse", "InputResponseInputKafka": ".inputresponse", "InputResponseInputKafkaTypedDict": ".inputresponse", - "InputResponseInputLoki": ".inputresponse", - "InputResponseInputLokiType": ".inputresponse", - "InputResponseInputLokiTypedDict": ".inputresponse", - "InputResponseInputMicrosoftGraph": ".inputresponse", - "InputResponseInputMicrosoftGraphAuthenticationMethod": ".inputresponse", - "InputResponseInputMicrosoftGraphType": ".inputresponse", - "InputResponseInputMicrosoftGraphTypedDict": ".inputresponse", "InputResponseInputMsk": ".inputresponse", "InputResponseInputMskTypedDict": ".inputresponse", - "InputResponseInputOffice365Mgmt": ".inputresponse", - "InputResponseInputOffice365MgmtContentConfig": ".inputresponse", - "InputResponseInputOffice365MgmtContentConfigTypedDict": ".inputresponse", - "InputResponseInputOffice365MgmtType": ".inputresponse", - "InputResponseInputOffice365MgmtTypedDict": ".inputresponse", - "InputResponseInputOffice365MsgTrace": ".inputresponse", - "InputResponseInputOffice365MsgTraceAuthenticationMethod": ".inputresponse", - "InputResponseInputOffice365MsgTraceType": ".inputresponse", - "InputResponseInputOffice365MsgTraceTypedDict": ".inputresponse", - "InputResponseInputOffice365Service": ".inputresponse", - "InputResponseInputOffice365ServiceContentConfig": ".inputresponse", - "InputResponseInputOffice365ServiceContentConfigTypedDict": ".inputresponse", - "InputResponseInputOffice365ServiceType": ".inputresponse", - "InputResponseInputOffice365ServiceTypedDict": ".inputresponse", - "InputResponseInputPrometheus": ".inputresponse", - "InputResponseInputPrometheusDiscoveryType": ".inputresponse", - "InputResponseInputPrometheusRw": ".inputresponse", - "InputResponseInputPrometheusRwType": ".inputresponse", - "InputResponseInputPrometheusRwTypedDict": ".inputresponse", - "InputResponseInputPrometheusTypedDict": ".inputresponse", "InputResponseInputSplunk": ".inputresponse", "InputResponseInputSplunkAuthToken": ".inputresponse", "InputResponseInputSplunkAuthTokenTypedDict": ".inputresponse", @@ -18624,315 +19822,498 @@ "InputResponseInputSplunkSearchType": ".inputresponse", "InputResponseInputSplunkSearchTypedDict": ".inputresponse", "InputResponseInputSplunkTypedDict": ".inputresponse", - "InputResponseInputSystemMetrics": ".inputresponse", - "InputResponseInputSystemMetricsCPU": ".inputresponse", - "InputResponseInputSystemMetricsCPUMode": ".inputresponse", - "InputResponseInputSystemMetricsCPUTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsCustom": ".inputresponse", - "InputResponseInputSystemMetricsCustomTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsDisk": ".inputresponse", - "InputResponseInputSystemMetricsDiskMode": ".inputresponse", - "InputResponseInputSystemMetricsDiskTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsFilter": ".inputresponse", - "InputResponseInputSystemMetricsFilterTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsHost": ".inputresponse", - "InputResponseInputSystemMetricsHostTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsMemory": ".inputresponse", - "InputResponseInputSystemMetricsMemoryMode": ".inputresponse", - "InputResponseInputSystemMetricsMemoryTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsNetwork": ".inputresponse", - "InputResponseInputSystemMetricsNetworkMode": ".inputresponse", - "InputResponseInputSystemMetricsNetworkTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsPersistence": ".inputresponse", - "InputResponseInputSystemMetricsPersistenceTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsSystem": ".inputresponse", - "InputResponseInputSystemMetricsSystemMode": ".inputresponse", - "InputResponseInputSystemMetricsSystemTypedDict": ".inputresponse", - "InputResponseInputSystemMetricsType": ".inputresponse", - "InputResponseInputSystemMetricsTypedDict": ".inputresponse", - "InputResponseInputSystemState": ".inputresponse", - "InputResponseInputSystemStatePersistence": ".inputresponse", - "InputResponseInputSystemStatePersistenceTypedDict": ".inputresponse", - "InputResponseInputSystemStateType": ".inputresponse", - "InputResponseInputSystemStateTypedDict": ".inputresponse", - "InputResponseInputTcpjson": ".inputresponse", - "InputResponseInputTcpjsonTypedDict": ".inputresponse", - "InputResponseInterfaces": ".inputresponse", - "InputResponseInterfacesTypedDict": ".inputresponse", - "InputResponseListeningPorts": ".inputresponse", - "InputResponseListeningPortsTypedDict": ".inputresponse", - "InputResponseLoggedInUsers": ".inputresponse", - "InputResponseLoggedInUsersTypedDict": ".inputresponse", - "InputResponseLokiAuth1": ".inputresponse", - "InputResponseLokiAuth1TypedDict": ".inputresponse", - "InputResponseLokiAuth2": ".inputresponse", - "InputResponseLokiAuth2TypedDict": ".inputresponse", "InputResponseMaxS2SVersion": ".inputresponse", - "InputResponseMetricsProtocol": ".inputresponse", - "InputResponsePodFilter": ".inputresponse", - "InputResponsePodFilterTypedDict": ".inputresponse", - "InputResponsePrometheusAuth1": ".inputresponse", - "InputResponsePrometheusAuth1TypedDict": ".inputresponse", - "InputResponsePrometheusAuth2": ".inputresponse", - "InputResponsePrometheusAuth2TypedDict": ".inputresponse", - "InputResponseRoutes": ".inputresponse", - "InputResponseRoutesTypedDict": ".inputresponse", - "InputResponseScheduleType": ".inputresponse", - "InputResponseServices": ".inputresponse", - "InputResponseServicesTypedDict": ".inputresponse", - "InputResponseSplunkHecMetadata": ".inputresponse", - "InputResponseSplunkHecMetadataTypedDict": ".inputresponse", - "InputResponseSubscriptionPlan": ".inputresponse", - "InputResponseTarget": ".inputresponse", - "InputResponseTargetTypedDict": ".inputresponse", "InputResponseTypedDict": ".inputresponse", - "InputResponseUsersAndGroups": ".inputresponse", - "InputResponseUsersAndGroupsTypedDict": ".inputresponse", "UnknownInputResponse": ".inputresponse", - "InputResponseAccountType": ".inputresponse_inputkubemetrics", - "InputResponseActivities": ".inputresponse_inputkubemetrics", - "InputResponseActivitiesManageState": ".inputresponse_inputkubemetrics", - "InputResponseActivitiesManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseActivitiesTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseAllow": ".inputresponse_inputkubemetrics", - "InputResponseAllowTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseAuthMethodsExt": ".inputresponse_inputkubemetrics", - "InputResponseAuthMethodsExtAuthenticationType": ".inputresponse_inputkubemetrics", - "InputResponseAuthMethodsExtTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseAuthenticationProtocol": ".inputresponse_inputkubemetrics", - "InputResponseChatMessages": ".inputresponse_inputkubemetrics", - "InputResponseChatMessagesManageState": ".inputresponse_inputkubemetrics", - "InputResponseChatMessagesManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseChatMessagesTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseChats": ".inputresponse_inputkubemetrics", - "InputResponseChatsManageState": ".inputresponse_inputkubemetrics", - "InputResponseChatsManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseChatsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseEventFormat": ".inputresponse_inputkubemetrics", - "InputResponseFormat": ".inputresponse_inputkubemetrics", - "InputResponseGrantType": ".inputresponse_inputkubemetrics", - "InputResponseGroups": ".inputresponse_inputkubemetrics", - "InputResponseGroupsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputAnthropicCompliance": ".inputresponse_inputkubemetrics", - "InputResponseInputAnthropicComplianceType": ".inputresponse_inputkubemetrics", - "InputResponseInputAnthropicComplianceTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputAppleUnifiedLogs": ".inputresponse_inputkubemetrics", - "InputResponseInputAppleUnifiedLogsReadMode": ".inputresponse_inputkubemetrics", - "InputResponseInputAppleUnifiedLogsType": ".inputresponse_inputkubemetrics", - "InputResponseInputAppleUnifiedLogsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputAppscope": ".inputresponse_inputkubemetrics", - "InputResponseInputAppscopeFilter": ".inputresponse_inputkubemetrics", - "InputResponseInputAppscopeFilterTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputAppscopePersistence": ".inputresponse_inputkubemetrics", - "InputResponseInputAppscopePersistenceTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputAppscopeType": ".inputresponse_inputkubemetrics", - "InputResponseInputAppscopeTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputBedrockS3": ".inputresponse_inputkubemetrics", - "InputResponseInputBedrockS3Type": ".inputresponse_inputkubemetrics", - "InputResponseInputBedrockS3TypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputCloudflareHec": ".inputresponse_inputkubemetrics", - "InputResponseInputCloudflareHecType": ".inputresponse_inputkubemetrics", - "InputResponseInputCloudflareHecTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputCriblmetrics": ".inputresponse_inputkubemetrics", - "InputResponseInputCriblmetricsType": ".inputresponse_inputkubemetrics", - "InputResponseInputCriblmetricsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputCrowdstrike": ".inputresponse_inputkubemetrics", - "InputResponseInputCrowdstrikeType": ".inputresponse_inputkubemetrics", - "InputResponseInputCrowdstrikeTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputDatadogAgent": ".inputresponse_inputkubemetrics", - "InputResponseInputDatadogAgentProxyMode": ".inputresponse_inputkubemetrics", - "InputResponseInputDatadogAgentProxyModeTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputDatadogAgentType": ".inputresponse_inputkubemetrics", - "InputResponseInputDatadogAgentTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputDatagen": ".inputresponse_inputkubemetrics", - "InputResponseInputDatagenType": ".inputresponse_inputkubemetrics", - "InputResponseInputDatagenTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputFile": ".inputresponse_inputkubemetrics", - "InputResponseInputFileMode": ".inputresponse_inputkubemetrics", - "InputResponseInputFileType": ".inputresponse_inputkubemetrics", - "InputResponseInputFileTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputHTTPRaw": ".inputresponse_inputkubemetrics", - "InputResponseInputHTTPRawType": ".inputresponse_inputkubemetrics", - "InputResponseInputHTTPRawTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputJournalFiles": ".inputresponse_inputkubemetrics", - "InputResponseInputJournalFilesRule": ".inputresponse_inputkubemetrics", - "InputResponseInputJournalFilesRuleTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputJournalFilesType": ".inputresponse_inputkubemetrics", - "InputResponseInputJournalFilesTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputKinesis": ".inputresponse_inputkubemetrics", - "InputResponseInputKinesisTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeEvents": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeEventsType": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeEventsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeLogs": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeLogsRule": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeLogsRuleTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeLogsType": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeLogsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeMetrics": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeMetricsPersistence": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeMetricsPersistenceTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeMetricsType": ".inputresponse_inputkubemetrics", - "InputResponseInputKubeMetricsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputMetrics": ".inputresponse_inputkubemetrics", - "InputResponseInputMetricsType": ".inputresponse_inputkubemetrics", - "InputResponseInputMetricsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputModelDrivenTelemetry": ".inputresponse_inputkubemetrics", - "InputResponseInputModelDrivenTelemetryType": ".inputresponse_inputkubemetrics", - "InputResponseInputModelDrivenTelemetryTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputNetflow": ".inputresponse_inputkubemetrics", - "InputResponseInputNetflowTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOkta": ".inputresponse_inputkubemetrics", - "InputResponseInputOktaManageState": ".inputresponse_inputkubemetrics", - "InputResponseInputOktaManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOktaType": ".inputresponse_inputkubemetrics", - "InputResponseInputOktaTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenTelemetry": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenTelemetryAuthenticationType": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenTelemetryType": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenTelemetryTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenai": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiComplianceLogs": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiComplianceLogsManageState": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiComplianceLogsManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiComplianceLogsType": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiComplianceLogsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiContentConfig": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiContentConfigTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiLogLevel": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiManageState": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiType": ".inputresponse_inputkubemetrics", - "InputResponseInputOpenaiTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputRawUDP": ".inputresponse_inputkubemetrics", - "InputResponseInputRawUDPType": ".inputresponse_inputkubemetrics", - "InputResponseInputRawUDPTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputS3": ".inputresponse_inputkubemetrics", - "InputResponseInputS3Inventory": ".inputresponse_inputkubemetrics", - "InputResponseInputS3InventoryType": ".inputresponse_inputkubemetrics", - "InputResponseInputS3InventoryTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputS3TypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputSecurityLake": ".inputresponse_inputkubemetrics", - "InputResponseInputSecurityLakeTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputServicenowTable": ".inputresponse_inputkubemetrics", - "InputResponseInputServicenowTableAuthenticationType": ".inputresponse_inputkubemetrics", - "InputResponseInputServicenowTableManageState": ".inputresponse_inputkubemetrics", - "InputResponseInputServicenowTableManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputServicenowTableType": ".inputresponse_inputkubemetrics", - "InputResponseInputServicenowTableTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputSnmp": ".inputresponse_inputkubemetrics", - "InputResponseInputSnmpTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputSqs": ".inputresponse_inputkubemetrics", - "InputResponseInputSqsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputSysdigHec": ".inputresponse_inputkubemetrics", - "InputResponseInputSysdigHecType": ".inputresponse_inputkubemetrics", - "InputResponseInputSysdigHecTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputSyslogSyslog1": ".inputresponse_inputkubemetrics", - "InputResponseInputSyslogSyslog1TypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputSyslogSyslog2": ".inputresponse_inputkubemetrics", - "InputResponseInputSyslogSyslog2TypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputSyslogUnion": ".inputresponse_inputkubemetrics", - "InputResponseInputSyslogUnionTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputTCP": ".inputresponse_inputkubemetrics", - "InputResponseInputTCPType": ".inputresponse_inputkubemetrics", - "InputResponseInputTCPTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputUpwindHec": ".inputresponse_inputkubemetrics", - "InputResponseInputUpwindHecType": ".inputresponse_inputkubemetrics", - "InputResponseInputUpwindHecTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWef": ".inputresponse_inputkubemetrics", - "InputResponseInputWefAuthenticationMethod": ".inputresponse_inputkubemetrics", - "InputResponseInputWefType": ".inputresponse_inputkubemetrics", - "InputResponseInputWefTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWinEventLogs": ".inputresponse_inputkubemetrics", - "InputResponseInputWinEventLogsReadMode": ".inputresponse_inputkubemetrics", - "InputResponseInputWinEventLogsType": ".inputresponse_inputkubemetrics", - "InputResponseInputWinEventLogsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetrics": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsCPU": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsCPUMode": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsCPUTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsCustom": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsCustomTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsDisk": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsDiskMode": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsDiskTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsHost": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsHostTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsMemory": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsMemoryMode": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsMemoryTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsNetwork": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsNetworkMode": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsNetworkTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsPersistence": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsPersistenceTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsSystem": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsSystemMode": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsSystemTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsType": ".inputresponse_inputkubemetrics", - "InputResponseInputWindowsMetricsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWiz": ".inputresponse_inputkubemetrics", - "InputResponseInputWizContentConfig": ".inputresponse_inputkubemetrics", - "InputResponseInputWizContentConfigTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWizManageState": ".inputresponse_inputkubemetrics", - "InputResponseInputWizManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWizType": ".inputresponse_inputkubemetrics", - "InputResponseInputWizTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputWizWebhook": ".inputresponse_inputkubemetrics", - "InputResponseInputWizWebhookType": ".inputresponse_inputkubemetrics", - "InputResponseInputWizWebhookTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputZscalerHec": ".inputresponse_inputkubemetrics", - "InputResponseInputZscalerHecAuthToken": ".inputresponse_inputkubemetrics", - "InputResponseInputZscalerHecAuthTokenTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseInputZscalerHecType": ".inputresponse_inputkubemetrics", - "InputResponseInputZscalerHecTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseMTLSSettings": ".inputresponse_inputkubemetrics", - "InputResponseMTLSSettingsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseOTLPVersion": ".inputresponse_inputkubemetrics", - "InputResponseOrganizationRoles": ".inputresponse_inputkubemetrics", - "InputResponseOrganizationRolesTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseOrganizationUsers": ".inputresponse_inputkubemetrics", - "InputResponseOrganizationUsersTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseOrganizations": ".inputresponse_inputkubemetrics", - "InputResponseOrganizationsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponsePaginationType": ".inputresponse_inputkubemetrics", - "InputResponsePrivacyProtocol": ".inputresponse_inputkubemetrics", - "InputResponseProjectDetails": ".inputresponse_inputkubemetrics", - "InputResponseProjectDetailsManageState": ".inputresponse_inputkubemetrics", - "InputResponseProjectDetailsManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseProjectDetailsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseProjects": ".inputresponse_inputkubemetrics", - "InputResponseProjectsManageState": ".inputresponse_inputkubemetrics", - "InputResponseProjectsManageStateTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseProjectsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseProtocol": ".inputresponse_inputkubemetrics", - "InputResponseQuery": ".inputresponse_inputkubemetrics", - "InputResponseQueryBuilderMode": ".inputresponse_inputkubemetrics", - "InputResponseQueryTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseQueueType": ".inputresponse_inputkubemetrics", - "InputResponseRecordDataFormat": ".inputresponse_inputkubemetrics", - "InputResponseSNMPv3Authentication": ".inputresponse_inputkubemetrics", - "InputResponseSNMPv3AuthenticationTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseSample": ".inputresponse_inputkubemetrics", - "InputResponseSampleTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseSamplingRule": ".inputresponse_inputkubemetrics", - "InputResponseSamplingRuleTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseShardIteratorStart": ".inputresponse_inputkubemetrics", - "InputResponseShardLoadBalancing": ".inputresponse_inputkubemetrics", - "InputResponseSortDirection": ".inputresponse_inputkubemetrics", - "InputResponseSubscription": ".inputresponse_inputkubemetrics", - "InputResponseSubscriptionTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseTLSSettingsServerSide": ".inputresponse_inputkubemetrics", - "InputResponseTLSSettingsServerSideTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseUNIXSocketPermissions": ".inputresponse_inputkubemetrics", - "InputResponseUNIXSocketPermissionsTypedDict": ".inputresponse_inputkubemetrics", - "InputResponseV3User": ".inputresponse_inputkubemetrics", - "InputResponseV3UserTypedDict": ".inputresponse_inputkubemetrics", + "InputResponseAuth": ".inputresponse_inputelastic_type", + "InputResponseAuthTypedDict": ".inputresponse_inputelastic_type", + "InputResponseAuthenticationMechanism": ".inputresponse_inputelastic_type", + "InputResponseAzureBlobStorage": ".inputresponse_inputelastic_type", + "InputResponseAzureBlobStorageTypedDict": ".inputresponse_inputelastic_type", + "InputResponseCertificate": ".inputresponse_inputelastic_type", + "InputResponseCertificateTypedDict": ".inputresponse_inputelastic_type", + "InputResponseCheckpointing": ".inputresponse_inputelastic_type", + "InputResponseCheckpointingTypedDict": ".inputresponse_inputelastic_type", + "InputResponseCollectors": ".inputresponse_inputelastic_type", + "InputResponseCollectorsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseContainer": ".inputresponse_inputelastic_type", + "InputResponseContainerMode": ".inputresponse_inputelastic_type", + "InputResponseContainerTypedDict": ".inputresponse_inputelastic_type", + "InputResponseDNS": ".inputresponse_inputelastic_type", + "InputResponseDNSTypedDict": ".inputresponse_inputelastic_type", + "InputResponseDisksAndFileSystems": ".inputresponse_inputelastic_type", + "InputResponseDisksAndFileSystemsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseFirewall": ".inputresponse_inputelastic_type", + "InputResponseFirewallTypedDict": ".inputresponse_inputelastic_type", + "InputResponseHostInfo": ".inputresponse_inputelastic_type", + "InputResponseHostInfoTypedDict": ".inputresponse_inputelastic_type", + "InputResponseHostsFile": ".inputresponse_inputelastic_type", + "InputResponseHostsFileTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputConfluentCloud": ".inputresponse_inputelastic_type", + "InputResponseInputConfluentCloudTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCribl": ".inputresponse_inputelastic_type", + "InputResponseInputCriblHTTP": ".inputresponse_inputelastic_type", + "InputResponseInputCriblHTTPType": ".inputresponse_inputelastic_type", + "InputResponseInputCriblHTTPTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTP": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPAuthTokensExt": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPAuthTokensExtTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPType": ".inputresponse_inputelastic_type", + "InputResponseInputCriblLakeHTTPTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCriblTCP": ".inputresponse_inputelastic_type", + "InputResponseInputCriblTCPTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCriblType": ".inputresponse_inputelastic_type", + "InputResponseInputCriblTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCriblmetrics": ".inputresponse_inputelastic_type", + "InputResponseInputCriblmetricsType": ".inputresponse_inputelastic_type", + "InputResponseInputCriblmetricsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputCrowdstrike": ".inputresponse_inputelastic_type", + "InputResponseInputCrowdstrikeType": ".inputresponse_inputelastic_type", + "InputResponseInputCrowdstrikeTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputDatadogAgent": ".inputresponse_inputelastic_type", + "InputResponseInputDatadogAgentProxyMode": ".inputresponse_inputelastic_type", + "InputResponseInputDatadogAgentProxyModeTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputDatadogAgentType": ".inputresponse_inputelastic_type", + "InputResponseInputDatadogAgentTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputDatagen": ".inputresponse_inputelastic_type", + "InputResponseInputDatagenType": ".inputresponse_inputelastic_type", + "InputResponseInputDatagenTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputEdgePrometheus": ".inputresponse_inputelastic_type", + "InputResponseInputEdgePrometheusAuthenticationMethod": ".inputresponse_inputelastic_type", + "InputResponseInputEdgePrometheusDiscoveryType": ".inputresponse_inputelastic_type", + "InputResponseInputEdgePrometheusType": ".inputresponse_inputelastic_type", + "InputResponseInputEdgePrometheusTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputElasticType": ".inputresponse_inputelastic_type", + "InputResponseInputEventhub": ".inputresponse_inputelastic_type", + "InputResponseInputEventhubAmqp": ".inputresponse_inputelastic_type", + "InputResponseInputEventhubAmqpType": ".inputresponse_inputelastic_type", + "InputResponseInputEventhubAmqpTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputEventhubType": ".inputresponse_inputelastic_type", + "InputResponseInputEventhubTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputExec": ".inputresponse_inputelastic_type", + "InputResponseInputExecType": ".inputresponse_inputelastic_type", + "InputResponseInputExecTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputFirehose": ".inputresponse_inputelastic_type", + "InputResponseInputFirehoseType": ".inputresponse_inputelastic_type", + "InputResponseInputFirehoseTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputGooglePubsub": ".inputresponse_inputelastic_type", + "InputResponseInputGooglePubsubTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaGrafana1": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaGrafana1TypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaGrafana2": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaGrafana2TypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaType1": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaType2": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaUnion": ".inputresponse_inputelastic_type", + "InputResponseInputGrafanaUnionTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRaw": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawAuthTokensExt": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawAuthTokensExtTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawAuthTokensExtUnion": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawAuthTokensExtUnionTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawType": ".inputresponse_inputelastic_type", + "InputResponseInputHTTPRawTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputKinesis": ".inputresponse_inputelastic_type", + "InputResponseInputKinesisTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputKubeEvents": ".inputresponse_inputelastic_type", + "InputResponseInputKubeEventsType": ".inputresponse_inputelastic_type", + "InputResponseInputKubeEventsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputKubeLogs": ".inputresponse_inputelastic_type", + "InputResponseInputKubeLogsRule": ".inputresponse_inputelastic_type", + "InputResponseInputKubeLogsRuleTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputKubeLogsType": ".inputresponse_inputelastic_type", + "InputResponseInputKubeLogsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputKubeMetrics": ".inputresponse_inputelastic_type", + "InputResponseInputKubeMetricsPersistence": ".inputresponse_inputelastic_type", + "InputResponseInputKubeMetricsPersistenceTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputKubeMetricsType": ".inputresponse_inputelastic_type", + "InputResponseInputKubeMetricsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputLoki": ".inputresponse_inputelastic_type", + "InputResponseInputLokiType": ".inputresponse_inputelastic_type", + "InputResponseInputLokiTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputMetrics": ".inputresponse_inputelastic_type", + "InputResponseInputMetricsType": ".inputresponse_inputelastic_type", + "InputResponseInputMetricsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputMicrosoftGraph": ".inputresponse_inputelastic_type", + "InputResponseInputMicrosoftGraphAuthenticationMethod": ".inputresponse_inputelastic_type", + "InputResponseInputMicrosoftGraphSubscriptionPlan": ".inputresponse_inputelastic_type", + "InputResponseInputMicrosoftGraphType": ".inputresponse_inputelastic_type", + "InputResponseInputMicrosoftGraphTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365Mgmt": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MgmtContentConfig": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MgmtContentConfigTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MgmtType": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MgmtTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MsgTrace": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MsgTraceAuthenticationMethod": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MsgTraceType": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365MsgTraceTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365Service": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365ServiceContentConfig": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365ServiceContentConfigTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365ServiceType": ".inputresponse_inputelastic_type", + "InputResponseInputOffice365ServiceTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputPrometheus": ".inputresponse_inputelastic_type", + "InputResponseInputPrometheusDiscoveryType": ".inputresponse_inputelastic_type", + "InputResponseInputPrometheusRw": ".inputresponse_inputelastic_type", + "InputResponseInputPrometheusRwType": ".inputresponse_inputelastic_type", + "InputResponseInputPrometheusRwTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputPrometheusTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputS3": ".inputresponse_inputelastic_type", + "InputResponseInputS3Inventory": ".inputresponse_inputelastic_type", + "InputResponseInputS3InventoryType": ".inputresponse_inputelastic_type", + "InputResponseInputS3InventoryTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputS3TypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSnmp": ".inputresponse_inputelastic_type", + "InputResponseInputSnmpTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetrics": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsCPU": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsCPUMode": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsCPUTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsCustom": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsCustomTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsDisk": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsDiskMode": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsDiskTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsFilter": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsFilterTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsHost": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsHostTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsMemory": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsMemoryMode": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsMemoryTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsNetwork": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsNetworkMode": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsNetworkTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsPersistence": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsPersistenceTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsSystem": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsSystemMode": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsSystemTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsType": ".inputresponse_inputelastic_type", + "InputResponseInputSystemMetricsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemState": ".inputresponse_inputelastic_type", + "InputResponseInputSystemStatePersistence": ".inputresponse_inputelastic_type", + "InputResponseInputSystemStatePersistenceTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputSystemStateType": ".inputresponse_inputelastic_type", + "InputResponseInputSystemStateTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputTcpjson": ".inputresponse_inputelastic_type", + "InputResponseInputTcpjsonTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetrics": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsCPU": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsCPUMode": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsCPUTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsCustom": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsCustomTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsDisk": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsDiskMode": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsDiskTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsHost": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsHostTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsMemory": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsMemoryMode": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsMemoryTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsNetwork": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsNetworkMode": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsNetworkTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsPersistence": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsPersistenceTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsSystem": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsSystemMode": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsSystemTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsType": ".inputresponse_inputelastic_type", + "InputResponseInputWindowsMetricsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseInterfaces": ".inputresponse_inputelastic_type", + "InputResponseInterfacesTypedDict": ".inputresponse_inputelastic_type", + "InputResponseListeningPorts": ".inputresponse_inputelastic_type", + "InputResponseListeningPortsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseLoggedInUsers": ".inputresponse_inputelastic_type", + "InputResponseLoggedInUsersTypedDict": ".inputresponse_inputelastic_type", + "InputResponseLokiAuth1": ".inputresponse_inputelastic_type", + "InputResponseLokiAuth1TypedDict": ".inputresponse_inputelastic_type", + "InputResponseLokiAuth2": ".inputresponse_inputelastic_type", + "InputResponseLokiAuth2TypedDict": ".inputresponse_inputelastic_type", + "InputResponseMetricsProtocol": ".inputresponse_inputelastic_type", + "InputResponsePodFilter": ".inputresponse_inputelastic_type", + "InputResponsePodFilterTypedDict": ".inputresponse_inputelastic_type", + "InputResponsePrometheusAuth1": ".inputresponse_inputelastic_type", + "InputResponsePrometheusAuth1TypedDict": ".inputresponse_inputelastic_type", + "InputResponsePrometheusAuth2": ".inputresponse_inputelastic_type", + "InputResponsePrometheusAuth2TypedDict": ".inputresponse_inputelastic_type", + "InputResponseRecordDataFormat": ".inputresponse_inputelastic_type", + "InputResponseRoutes": ".inputresponse_inputelastic_type", + "InputResponseRoutesTypedDict": ".inputresponse_inputelastic_type", + "InputResponseSNMPv3Authentication": ".inputresponse_inputelastic_type", + "InputResponseSNMPv3AuthenticationTypedDict": ".inputresponse_inputelastic_type", + "InputResponseSample": ".inputresponse_inputelastic_type", + "InputResponseSampleTypedDict": ".inputresponse_inputelastic_type", + "InputResponseSamplingRule": ".inputresponse_inputelastic_type", + "InputResponseSamplingRuleTypedDict": ".inputresponse_inputelastic_type", + "InputResponseScheduleType": ".inputresponse_inputelastic_type", + "InputResponseServices": ".inputresponse_inputelastic_type", + "InputResponseServicesTypedDict": ".inputresponse_inputelastic_type", + "InputResponseShardIteratorStart": ".inputresponse_inputelastic_type", + "InputResponseShardLoadBalancing": ".inputresponse_inputelastic_type", + "InputResponseTarget": ".inputresponse_inputelastic_type", + "InputResponseTargetTypedDict": ".inputresponse_inputelastic_type", + "InputResponseUsersAndGroups": ".inputresponse_inputelastic_type", + "InputResponseUsersAndGroupsTypedDict": ".inputresponse_inputelastic_type", + "InputResponseAccountType": ".inputresponse_v3user", + "InputResponseActivities": ".inputresponse_v3user", + "InputResponseActivitiesManageState": ".inputresponse_v3user", + "InputResponseActivitiesManageStateTypedDict": ".inputresponse_v3user", + "InputResponseActivitiesTypedDict": ".inputresponse_v3user", + "InputResponseAllow": ".inputresponse_v3user", + "InputResponseAllowTypedDict": ".inputresponse_v3user", + "InputResponseAuthMethodsExt": ".inputresponse_v3user", + "InputResponseAuthMethodsExtAuthenticationType": ".inputresponse_v3user", + "InputResponseAuthMethodsExtTypedDict": ".inputresponse_v3user", + "InputResponseAuthenticationProtocol": ".inputresponse_v3user", + "InputResponseBucketWidth": ".inputresponse_v3user", + "InputResponseCertOptions": ".inputresponse_v3user", + "InputResponseCertOptionsTypedDict": ".inputresponse_v3user", + "InputResponseChatMessages": ".inputresponse_v3user", + "InputResponseChatMessagesManageState": ".inputresponse_v3user", + "InputResponseChatMessagesManageStateTypedDict": ".inputresponse_v3user", + "InputResponseChatMessagesTypedDict": ".inputresponse_v3user", + "InputResponseChats": ".inputresponse_v3user", + "InputResponseChatsManageState": ".inputresponse_v3user", + "InputResponseChatsManageStateTypedDict": ".inputresponse_v3user", + "InputResponseChatsTypedDict": ".inputresponse_v3user", + "InputResponseContentType": ".inputresponse_v3user", + "InputResponseEventFormat": ".inputresponse_v3user", + "InputResponseFeedType": ".inputresponse_v3user", + "InputResponseFormat": ".inputresponse_v3user", + "InputResponseGrantType": ".inputresponse_v3user", + "InputResponseGroupBy": ".inputresponse_v3user", + "InputResponseGroups": ".inputresponse_v3user", + "InputResponseGroupsTypedDict": ".inputresponse_v3user", + "InputResponseInputAkamaiHec": ".inputresponse_v3user", + "InputResponseInputAkamaiHecType": ".inputresponse_v3user", + "InputResponseInputAkamaiHecTypedDict": ".inputresponse_v3user", + "InputResponseInputAnthropicCompliance": ".inputresponse_v3user", + "InputResponseInputAnthropicComplianceType": ".inputresponse_v3user", + "InputResponseInputAnthropicComplianceTypedDict": ".inputresponse_v3user", + "InputResponseInputAnthropicEnterpriseAnalytics": ".inputresponse_v3user", + "InputResponseInputAnthropicEnterpriseAnalyticsContentConfig": ".inputresponse_v3user", + "InputResponseInputAnthropicEnterpriseAnalyticsContentConfigTypedDict": ".inputresponse_v3user", + "InputResponseInputAnthropicEnterpriseAnalyticsType": ".inputresponse_v3user", + "InputResponseInputAnthropicEnterpriseAnalyticsTypedDict": ".inputresponse_v3user", + "InputResponseInputAppleUnifiedLogs": ".inputresponse_v3user", + "InputResponseInputAppleUnifiedLogsReadMode": ".inputresponse_v3user", + "InputResponseInputAppleUnifiedLogsType": ".inputresponse_v3user", + "InputResponseInputAppleUnifiedLogsTypedDict": ".inputresponse_v3user", + "InputResponseInputAppscope": ".inputresponse_v3user", + "InputResponseInputAppscopeFilter": ".inputresponse_v3user", + "InputResponseInputAppscopeFilterTypedDict": ".inputresponse_v3user", + "InputResponseInputAppscopePersistence": ".inputresponse_v3user", + "InputResponseInputAppscopePersistenceTypedDict": ".inputresponse_v3user", + "InputResponseInputAppscopeType": ".inputresponse_v3user", + "InputResponseInputAppscopeTypedDict": ".inputresponse_v3user", + "InputResponseInputAquaSecurityHec": ".inputresponse_v3user", + "InputResponseInputAquaSecurityHecType": ".inputresponse_v3user", + "InputResponseInputAquaSecurityHecTypedDict": ".inputresponse_v3user", + "InputResponseInputBedrockS3": ".inputresponse_v3user", + "InputResponseInputBedrockS3Type": ".inputresponse_v3user", + "InputResponseInputBedrockS3TypedDict": ".inputresponse_v3user", + "InputResponseInputBeyondtrustHec": ".inputresponse_v3user", + "InputResponseInputBeyondtrustHecType": ".inputresponse_v3user", + "InputResponseInputBeyondtrustHecTypedDict": ".inputresponse_v3user", + "InputResponseInputCloudflareHec": ".inputresponse_v3user", + "InputResponseInputCloudflareHecType": ".inputresponse_v3user", + "InputResponseInputCloudflareHecTypedDict": ".inputresponse_v3user", + "InputResponseInputExtrahopRevealx360": ".inputresponse_v3user", + "InputResponseInputExtrahopRevealx360Type": ".inputresponse_v3user", + "InputResponseInputExtrahopRevealx360TypedDict": ".inputresponse_v3user", + "InputResponseInputF5BigIP": ".inputresponse_v3user", + "InputResponseInputF5BigIPType": ".inputresponse_v3user", + "InputResponseInputF5BigIPTypedDict": ".inputresponse_v3user", + "InputResponseInputFile": ".inputresponse_v3user", + "InputResponseInputFileMode": ".inputresponse_v3user", + "InputResponseInputFileType": ".inputresponse_v3user", + "InputResponseInputFileTypedDict": ".inputresponse_v3user", + "InputResponseInputGigamonHec": ".inputresponse_v3user", + "InputResponseInputGigamonHecType": ".inputresponse_v3user", + "InputResponseInputGigamonHecTypedDict": ".inputresponse_v3user", + "InputResponseInputHashicorpHcpVaultDedicated": ".inputresponse_v3user", + "InputResponseInputHashicorpHcpVaultDedicatedType": ".inputresponse_v3user", + "InputResponseInputHashicorpHcpVaultDedicatedTypedDict": ".inputresponse_v3user", + "InputResponseInputJournalFiles": ".inputresponse_v3user", + "InputResponseInputJournalFilesRule": ".inputresponse_v3user", + "InputResponseInputJournalFilesRuleTypedDict": ".inputresponse_v3user", + "InputResponseInputJournalFilesType": ".inputresponse_v3user", + "InputResponseInputJournalFilesTypedDict": ".inputresponse_v3user", + "InputResponseInputMicrosoftCopilot": ".inputresponse_v3user", + "InputResponseInputMicrosoftCopilotAuthenticationMethod": ".inputresponse_v3user", + "InputResponseInputMicrosoftCopilotManageState": ".inputresponse_v3user", + "InputResponseInputMicrosoftCopilotManageStateTypedDict": ".inputresponse_v3user", + "InputResponseInputMicrosoftCopilotSubscriptionPlan": ".inputresponse_v3user", + "InputResponseInputMicrosoftCopilotType": ".inputresponse_v3user", + "InputResponseInputMicrosoftCopilotTypedDict": ".inputresponse_v3user", + "InputResponseInputMimecastHec": ".inputresponse_v3user", + "InputResponseInputMimecastHecType": ".inputresponse_v3user", + "InputResponseInputMimecastHecTypedDict": ".inputresponse_v3user", + "InputResponseInputModelDrivenTelemetry": ".inputresponse_v3user", + "InputResponseInputModelDrivenTelemetryType": ".inputresponse_v3user", + "InputResponseInputModelDrivenTelemetryTypedDict": ".inputresponse_v3user", + "InputResponseInputNetflow": ".inputresponse_v3user", + "InputResponseInputNetflowTypedDict": ".inputresponse_v3user", + "InputResponseInputOkta": ".inputresponse_v3user", + "InputResponseInputOktaManageState": ".inputresponse_v3user", + "InputResponseInputOktaManageStateTypedDict": ".inputresponse_v3user", + "InputResponseInputOktaType": ".inputresponse_v3user", + "InputResponseInputOktaTypedDict": ".inputresponse_v3user", + "InputResponseInputOpenTelemetry": ".inputresponse_v3user", + "InputResponseInputOpenTelemetryAuthenticationType": ".inputresponse_v3user", + "InputResponseInputOpenTelemetryType": ".inputresponse_v3user", + "InputResponseInputOpenTelemetryTypedDict": ".inputresponse_v3user", + "InputResponseInputOpenai": ".inputresponse_v3user", + "InputResponseInputOpenaiComplianceLogs": ".inputresponse_v3user", + "InputResponseInputOpenaiComplianceLogsManageState": ".inputresponse_v3user", + "InputResponseInputOpenaiComplianceLogsManageStateTypedDict": ".inputresponse_v3user", + "InputResponseInputOpenaiComplianceLogsType": ".inputresponse_v3user", + "InputResponseInputOpenaiComplianceLogsTypedDict": ".inputresponse_v3user", + "InputResponseInputOpenaiContentConfig": ".inputresponse_v3user", + "InputResponseInputOpenaiContentConfigTypedDict": ".inputresponse_v3user", + "InputResponseInputOpenaiLogLevel": ".inputresponse_v3user", + "InputResponseInputOpenaiManageState": ".inputresponse_v3user", + "InputResponseInputOpenaiManageStateTypedDict": ".inputresponse_v3user", + "InputResponseInputOpenaiType": ".inputresponse_v3user", + "InputResponseInputOpenaiTypedDict": ".inputresponse_v3user", + "InputResponseInputPingIdentityPingone": ".inputresponse_v3user", + "InputResponseInputPingIdentityPingoneType": ".inputresponse_v3user", + "InputResponseInputPingIdentityPingoneTypedDict": ".inputresponse_v3user", + "InputResponseInputProofpointPod": ".inputresponse_v3user", + "InputResponseInputProofpointPodType": ".inputresponse_v3user", + "InputResponseInputProofpointPodTypedDict": ".inputresponse_v3user", + "InputResponseInputRawUDP": ".inputresponse_v3user", + "InputResponseInputRawUDPType": ".inputresponse_v3user", + "InputResponseInputRawUDPTypedDict": ".inputresponse_v3user", + "InputResponseInputSailpointHec": ".inputresponse_v3user", + "InputResponseInputSailpointHecType": ".inputresponse_v3user", + "InputResponseInputSailpointHecTypedDict": ".inputresponse_v3user", + "InputResponseInputSecurityLake": ".inputresponse_v3user", + "InputResponseInputSecurityLakeTypedDict": ".inputresponse_v3user", + "InputResponseInputServicenowTable": ".inputresponse_v3user", + "InputResponseInputServicenowTableAuthenticationType": ".inputresponse_v3user", + "InputResponseInputServicenowTableManageState": ".inputresponse_v3user", + "InputResponseInputServicenowTableManageStateTypedDict": ".inputresponse_v3user", + "InputResponseInputServicenowTableType": ".inputresponse_v3user", + "InputResponseInputServicenowTableTypedDict": ".inputresponse_v3user", + "InputResponseInputSqs": ".inputresponse_v3user", + "InputResponseInputSqsTypedDict": ".inputresponse_v3user", + "InputResponseInputSysdigHec": ".inputresponse_v3user", + "InputResponseInputSysdigHecType": ".inputresponse_v3user", + "InputResponseInputSysdigHecTypedDict": ".inputresponse_v3user", + "InputResponseInputSyslogSyslog1": ".inputresponse_v3user", + "InputResponseInputSyslogSyslog1TypedDict": ".inputresponse_v3user", + "InputResponseInputSyslogSyslog2": ".inputresponse_v3user", + "InputResponseInputSyslogSyslog2TypedDict": ".inputresponse_v3user", + "InputResponseInputSyslogUnion": ".inputresponse_v3user", + "InputResponseInputSyslogUnionTypedDict": ".inputresponse_v3user", + "InputResponseInputTCP": ".inputresponse_v3user", + "InputResponseInputTCPType": ".inputresponse_v3user", + "InputResponseInputTCPTypedDict": ".inputresponse_v3user", + "InputResponseInputTrellixHec": ".inputresponse_v3user", + "InputResponseInputTrellixHecType": ".inputresponse_v3user", + "InputResponseInputTrellixHecTypedDict": ".inputresponse_v3user", + "InputResponseInputTrendMicroVisionOne": ".inputresponse_v3user", + "InputResponseInputTrendMicroVisionOneType": ".inputresponse_v3user", + "InputResponseInputTrendMicroVisionOneTypedDict": ".inputresponse_v3user", + "InputResponseInputUpwindHec": ".inputresponse_v3user", + "InputResponseInputUpwindHecType": ".inputresponse_v3user", + "InputResponseInputUpwindHecTypedDict": ".inputresponse_v3user", + "InputResponseInputVectraAiHec": ".inputresponse_v3user", + "InputResponseInputVectraAiHecType": ".inputresponse_v3user", + "InputResponseInputVectraAiHecTypedDict": ".inputresponse_v3user", + "InputResponseInputWef": ".inputresponse_v3user", + "InputResponseInputWefAuthenticationMethod": ".inputresponse_v3user", + "InputResponseInputWefType": ".inputresponse_v3user", + "InputResponseInputWefTypedDict": ".inputresponse_v3user", + "InputResponseInputWinEventLogs": ".inputresponse_v3user", + "InputResponseInputWinEventLogsReadMode": ".inputresponse_v3user", + "InputResponseInputWinEventLogsType": ".inputresponse_v3user", + "InputResponseInputWinEventLogsTypedDict": ".inputresponse_v3user", + "InputResponseInputWiz": ".inputresponse_v3user", + "InputResponseInputWizContentConfig": ".inputresponse_v3user", + "InputResponseInputWizContentConfigTypedDict": ".inputresponse_v3user", + "InputResponseInputWizManageState": ".inputresponse_v3user", + "InputResponseInputWizManageStateTypedDict": ".inputresponse_v3user", + "InputResponseInputWizType": ".inputresponse_v3user", + "InputResponseInputWizTypedDict": ".inputresponse_v3user", + "InputResponseInputWizWebhook": ".inputresponse_v3user", + "InputResponseInputWizWebhookAuthTokensExt1": ".inputresponse_v3user", + "InputResponseInputWizWebhookAuthTokensExt1TypedDict": ".inputresponse_v3user", + "InputResponseInputWizWebhookAuthTokensExt2": ".inputresponse_v3user", + "InputResponseInputWizWebhookAuthTokensExt2TypedDict": ".inputresponse_v3user", + "InputResponseInputWizWebhookAuthTokensExtUnion": ".inputresponse_v3user", + "InputResponseInputWizWebhookAuthTokensExtUnionTypedDict": ".inputresponse_v3user", + "InputResponseInputWizWebhookType": ".inputresponse_v3user", + "InputResponseInputWizWebhookTypedDict": ".inputresponse_v3user", + "InputResponseInputZscalerHec": ".inputresponse_v3user", + "InputResponseInputZscalerHecAuthToken": ".inputresponse_v3user", + "InputResponseInputZscalerHecAuthTokenTypedDict": ".inputresponse_v3user", + "InputResponseInputZscalerHecType": ".inputresponse_v3user", + "InputResponseInputZscalerHecTypedDict": ".inputresponse_v3user", + "InputResponseMTLSSettings": ".inputresponse_v3user", + "InputResponseMTLSSettingsTypedDict": ".inputresponse_v3user", + "InputResponseOTLPVersion": ".inputresponse_v3user", + "InputResponseOrganizationRoles": ".inputresponse_v3user", + "InputResponseOrganizationRolesTypedDict": ".inputresponse_v3user", + "InputResponseOrganizationUsers": ".inputresponse_v3user", + "InputResponseOrganizationUsersTypedDict": ".inputresponse_v3user", + "InputResponseOrganizations": ".inputresponse_v3user", + "InputResponseOrganizationsTypedDict": ".inputresponse_v3user", + "InputResponsePaginationType": ".inputresponse_v3user", + "InputResponsePrivacyProtocol": ".inputresponse_v3user", + "InputResponseProjectDetails": ".inputresponse_v3user", + "InputResponseProjectDetailsManageState": ".inputresponse_v3user", + "InputResponseProjectDetailsManageStateTypedDict": ".inputresponse_v3user", + "InputResponseProjectDetailsTypedDict": ".inputresponse_v3user", + "InputResponseProjects": ".inputresponse_v3user", + "InputResponseProjectsManageState": ".inputresponse_v3user", + "InputResponseProjectsManageStateTypedDict": ".inputresponse_v3user", + "InputResponseProjectsTypedDict": ".inputresponse_v3user", + "InputResponseProtocol": ".inputresponse_v3user", + "InputResponseQuery": ".inputresponse_v3user", + "InputResponseQueryBuilderMode": ".inputresponse_v3user", + "InputResponseQueryTypedDict": ".inputresponse_v3user", + "InputResponseQueueType": ".inputresponse_v3user", + "InputResponseRetryRules": ".inputresponse_v3user", + "InputResponseRetryRulesTypedDict": ".inputresponse_v3user", + "InputResponseSortDirection": ".inputresponse_v3user", + "InputResponseSubscription": ".inputresponse_v3user", + "InputResponseSubscriptionTypedDict": ".inputresponse_v3user", + "InputResponseTLSSettingsServerSide": ".inputresponse_v3user", + "InputResponseTLSSettingsServerSideTypedDict": ".inputresponse_v3user", + "InputResponseUNIXSocketPermissions": ".inputresponse_v3user", + "InputResponseUNIXSocketPermissionsTypedDict": ".inputresponse_v3user", + "InputResponseV3AuthenticationKeyType": ".inputresponse_v3user", + "InputResponseV3PrivacyKeyType": ".inputresponse_v3user", + "InputResponseV3User": ".inputresponse_v3user", + "InputResponseV3UserTypedDict": ".inputresponse_v3user", "InputS3Input": ".inputs3_input", "InputS3InputTypedDict": ".inputs3_input", "InputS3InventoryInput": ".inputs3inventory_input", "InputS3InventoryInputTypedDict": ".inputs3inventory_input", "InputS3InventoryType": ".inputs3inventory_input", + "InputSailpointHecInput": ".inputsailpointhec_input", + "InputSailpointHecInputTypedDict": ".inputsailpointhec_input", + "InputSailpointHecType": ".inputsailpointhec_input", "InputSecurityLakeInput": ".inputsecuritylake_input", "InputSecurityLakeInputTypedDict": ".inputsecuritylake_input", "GrantType": ".inputservicenowtable_input", @@ -18951,6 +20332,8 @@ "PrivacyProtocol": ".inputsnmp_input", "SNMPv3Authentication": ".inputsnmp_input", "SNMPv3AuthenticationTypedDict": ".inputsnmp_input", + "V3AuthenticationKeyType": ".inputsnmp_input", + "V3PrivacyKeyType": ".inputsnmp_input", "InputSplunkAuthToken": ".inputsplunk_input", "InputSplunkAuthTokenTypedDict": ".inputsplunk_input", "InputSplunkCompression": ".inputsplunk_input", @@ -19050,11 +20433,20 @@ "InputTCPType": ".inputtcp_input", "InputTcpjsonInput": ".inputtcpjson_input", "InputTcpjsonInputTypedDict": ".inputtcpjson_input", + "InputTrellixHecInput": ".inputtrellixhec_input", + "InputTrellixHecInputTypedDict": ".inputtrellixhec_input", + "InputTrellixHecType": ".inputtrellixhec_input", + "InputTrendMicroVisionOneInput": ".inputtrendmicrovisionone_input", + "InputTrendMicroVisionOneInputTypedDict": ".inputtrendmicrovisionone_input", + "InputTrendMicroVisionOneType": ".inputtrendmicrovisionone_input", "InputTypeRunnableJobCollection": ".inputtyperunnablejobcollection", "InputTypeRunnableJobCollectionTypedDict": ".inputtyperunnablejobcollection", "InputUpwindHecInput": ".inputupwindhec_input", "InputUpwindHecInputTypedDict": ".inputupwindhec_input", "InputUpwindHecType": ".inputupwindhec_input", + "InputVectraAiHecInput": ".inputvectraaihec_input", + "InputVectraAiHecInputTypedDict": ".inputvectraaihec_input", + "InputVectraAiHecType": ".inputvectraaihec_input", "InputWefAuthenticationMethod": ".inputwef_input", "InputWefFormat": ".inputwef_input", "InputWefInput": ".inputwef_input", @@ -19091,7 +20483,7 @@ "InputWindowsMetricsSystemMode": ".inputwindowsmetrics_input", "InputWindowsMetricsSystemTypedDict": ".inputwindowsmetrics_input", "InputWindowsMetricsType": ".inputwindowsmetrics_input", - "EventFormat": ".inputwineventlogs_input", + "InputWinEventLogsEventFormat": ".inputwineventlogs_input", "InputWinEventLogsInput": ".inputwineventlogs_input", "InputWinEventLogsInputTypedDict": ".inputwineventlogs_input", "InputWinEventLogsReadMode": ".inputwineventlogs_input", @@ -19103,6 +20495,12 @@ "InputWizManageState": ".inputwiz_input", "InputWizManageStateTypedDict": ".inputwiz_input", "InputWizType": ".inputwiz_input", + "InputWizWebhookAuthTokensExt1": ".inputwizwebhook_input", + "InputWizWebhookAuthTokensExt1TypedDict": ".inputwizwebhook_input", + "InputWizWebhookAuthTokensExt2": ".inputwizwebhook_input", + "InputWizWebhookAuthTokensExt2TypedDict": ".inputwizwebhook_input", + "InputWizWebhookAuthTokensExtUnion": ".inputwizwebhook_input", + "InputWizWebhookAuthTokensExtUnionTypedDict": ".inputwizwebhook_input", "InputWizWebhookInput": ".inputwizwebhook_input", "InputWizWebhookInputTypedDict": ".inputwizwebhook_input", "InputWizWebhookType": ".inputwizwebhook_input", @@ -19130,14 +20528,6 @@ "LakeDatasetSearchConfig": ".lakedatasetsearchconfig", "LakeDatasetSearchConfigTypedDict": ".lakedatasetsearchconfig", "LakehouseConnectionType": ".lakehouseconnectiontype", - "ListInputRequest": ".listinputop", - "ListInputRequestTypedDict": ".listinputop", - "ListInputResponse": ".listinputop", - "ListInputResponseTypedDict": ".listinputop", - "ListOutputRequest": ".listoutputop", - "ListOutputRequestTypedDict": ".listoutputop", - "ListOutputResponse": ".listoutputop", - "ListOutputResponseTypedDict": ".listoutputop", "LoginInfo": ".logininfo", "LoginInfoTypedDict": ".logininfo", "LogLabelConfOutputGoogleCloudLogging": ".loglabelconfoutputgooglecloudlogging", @@ -19161,6 +20551,8 @@ "MetadataConfAddHecTokenRequestTypedDict": ".metadataconfaddhectokenrequest", "MetadataConfInputCollection": ".metadataconfinputcollection", "MetadataConfInputCollectionTypedDict": ".metadataconfinputcollection", + "MetadataItem": ".metadataitem", + "MetadataItemTypedDict": ".metadataitem", "MethodOptions": ".methodoptions", "MicrosoftEntraIDAuthenticationEndpointOptionsSasl": ".microsoftentraidauthenticationendpointoptionssasl", "MinimumTLSVersionOptionsRedisDeploymentTypeStandaloneTLSOptions": ".minimumtlsversionoptionsredisdeploymenttypestandalonetlsoptions", @@ -19188,47 +20580,17 @@ "NodeUpgradeState": ".nodeupgradestate", "NodeUpgradeStatus": ".nodeupgradestatus", "NodeUpgradeStatusTypedDict": ".nodeupgradestatus", - "ConditionSpecificConfigurations1": ".notification_union", - "ConditionSpecificConfigurations1TypedDict": ".notification_union", - "ConditionSpecificConfigurations2": ".notification_union", - "ConditionSpecificConfigurations2TypedDict": ".notification_union", - "ConditionSpecificConfigurations3": ".notification_union", - "ConditionSpecificConfigurations3TypedDict": ".notification_union", - "EmailRecipient1": ".notification_union", - "EmailRecipient1TypedDict": ".notification_union", - "EmailRecipient2": ".notification_union", - "EmailRecipient2TypedDict": ".notification_union", - "EmailRecipient3": ".notification_union", - "EmailRecipient3TypedDict": ".notification_union", - "Notification1": ".notification_union", - "Notification1TypedDict": ".notification_union", - "Notification2": ".notification_union", - "Notification2TypedDict": ".notification_union", - "Notification3": ".notification_union", - "Notification3TypedDict": ".notification_union", - "NotificationConfigForSMTPTarget1": ".notification_union", - "NotificationConfigForSMTPTarget1TypedDict": ".notification_union", - "NotificationConfigForSMTPTarget2": ".notification_union", - "NotificationConfigForSMTPTarget2TypedDict": ".notification_union", - "NotificationConfigForSMTPTarget3": ".notification_union", - "NotificationConfigForSMTPTarget3TypedDict": ".notification_union", - "NotificationMode1": ".notification_union", - "NotificationMode2": ".notification_union", - "NotificationMode3": ".notification_union", - "NotificationUnion": ".notification_union", - "NotificationUnionTypedDict": ".notification_union", - "TargetConfig1": ".notification_union", - "TargetConfig1TypedDict": ".notification_union", - "TargetConfig2": ".notification_union", - "TargetConfig2TypedDict": ".notification_union", - "TargetConfig3": ".notification_union", - "TargetConfig3TypedDict": ".notification_union", - "TargetConfigUnion1": ".notification_union", - "TargetConfigUnion1TypedDict": ".notification_union", - "TargetConfigUnion2": ".notification_union", - "TargetConfigUnion2TypedDict": ".notification_union", - "TargetConfigUnion3": ".notification_union", - "TargetConfigUnion3TypedDict": ".notification_union", + "Notification": ".notification", + "NotificationTemplateTargetPair": ".notification", + "NotificationTemplateTargetPairTypedDict": ".notification", + "NotificationTypedDict": ".notification", + "NotificationMode": ".notificationmode", + "NotificationSMTPTargetConfig": ".notificationsmtptargetconfig", + "NotificationSMTPTargetConfigTypedDict": ".notificationsmtptargetconfig", + "NotificationTargetConfig": ".notificationtargetconfig", + "NotificationTargetConfigTypedDict": ".notificationtargetconfig", + "NotificationTargetDetails": ".notificationtargetdetails", + "NotificationTargetDetailsTypedDict": ".notificationtargetdetails", "OauthHeaderConfInputServicenowTable": ".oauthheaderconfinputservicenowtable", "OauthHeaderConfInputServicenowTableTypedDict": ".oauthheaderconfinputservicenowtable", "OauthParamConfInputKafka": ".oauthparamconfinputkafka", @@ -19239,6 +20601,7 @@ "ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol": ".objectacloptionsauthenticatedreadbucketownerfullcontrol", "ObjectStorageFilter": ".objectstoragefilter", "ObjectStorageFilterTypedDict": ".objectstoragefilter", + "OriginOptionsCriblSourceProvenance": ".originoptionscriblsourceprovenance", "OrphanFileRecoveryType": ".orphanfilerecoverytype", "OrphanFileRecoveryTypeTypedDict": ".orphanfilerecoverytype", "OsTypeHeartbeatMetadata": ".ostypeheartbeatmetadata", @@ -19334,6 +20697,7 @@ "OutputCriblSearchEnginePqControlsTypedDict": ".outputcriblsearchengine", "OutputCriblSearchEngineType": ".outputcriblsearchengine", "OutputCriblSearchEngineTypedDict": ".outputcriblsearchengine", + "SendAs": ".outputcriblsearchengine", "OutputCriblTCP": ".outputcribltcp", "OutputCriblTCPPqControls": ".outputcribltcp", "OutputCriblTCPPqControlsTypedDict": ".outputcribltcp", @@ -19351,6 +20715,11 @@ "OutputDatabricks": ".outputdatabricks", "OutputDatabricksType": ".outputdatabricks", "OutputDatabricksTypedDict": ".outputdatabricks", + "OutputDatabricksZerobus": ".outputdatabrickszerobus", + "OutputDatabricksZerobusPqControls": ".outputdatabrickszerobus", + "OutputDatabricksZerobusPqControlsTypedDict": ".outputdatabrickszerobus", + "OutputDatabricksZerobusType": ".outputdatabrickszerobus", + "OutputDatabricksZerobusTypedDict": ".outputdatabrickszerobus", "DatadogSite": ".outputdatadog", "OutputDatadog": ".outputdatadog", "OutputDatadogPqControls": ".outputdatadog", @@ -19412,6 +20781,7 @@ "OutputElasticCloudType": ".outputelasticcloud", "OutputElasticCloudTypedDict": ".outputelasticcloud", "OutputExabeam": ".outputexabeam", + "OutputExabeamAuthenticationMethod": ".outputexabeam", "OutputExabeamType": ".outputexabeam", "OutputExabeamTypedDict": ".outputexabeam", "OutputFilesystem": ".outputfilesystem", @@ -19569,477 +20939,493 @@ "OutputPrometheusTypedDict": ".outputprometheus", "OutputResponse": ".outputresponse", "OutputResponseOutputDefault": ".outputresponse", + "OutputResponseOutputDefaultType": ".outputresponse", "OutputResponseOutputDefaultTypedDict": ".outputresponse", + "OutputResponseOutputWebhookAuthenticationType1": ".outputresponse", + "OutputResponseOutputWebhookAuthenticationType2": ".outputresponse", + "OutputResponseOutputWebhookFormat1": ".outputresponse", + "OutputResponseOutputWebhookPqControls1": ".outputresponse", + "OutputResponseOutputWebhookPqControls1TypedDict": ".outputresponse", + "OutputResponseOutputWebhookPqControls2": ".outputresponse", + "OutputResponseOutputWebhookPqControls2TypedDict": ".outputresponse", + "OutputResponseOutputWebhookType1": ".outputresponse", + "OutputResponseOutputWebhookURL1": ".outputresponse", + "OutputResponseOutputWebhookURL1TypedDict": ".outputresponse", + "OutputResponseOutputWebhookURL2": ".outputresponse", + "OutputResponseOutputWebhookURL2TypedDict": ".outputresponse", + "OutputResponseOutputWebhookUnion": ".outputresponse", + "OutputResponseOutputWebhookUnionTypedDict": ".outputresponse", + "OutputResponseOutputWebhookWebhook1": ".outputresponse", + "OutputResponseOutputWebhookWebhook1TypedDict": ".outputresponse", + "OutputResponseOutputWebhookWebhook2": ".outputresponse", + "OutputResponseOutputWebhookWebhook2TypedDict": ".outputresponse", "OutputResponseTypedDict": ".outputresponse", "UnknownOutputResponse": ".outputresponse", - "OutputResponseAPIVersion": ".outputresponse_outputdefault_type", - "OutputResponseAdditionalProperty": ".outputresponse_outputdefault_type", - "OutputResponseAdditionalPropertyTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseAuthToken": ".outputresponse_outputdefault_type", - "OutputResponseAuthTokenTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseAuthType": ".outputresponse_outputdefault_type", - "OutputResponseBlobAccessTier": ".outputresponse_outputdefault_type", - "OutputResponseCertificate": ".outputresponse_outputdefault_type", - "OutputResponseCertificateTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseCompression": ".outputresponse_outputdefault_type", - "OutputResponseElasticVersion": ".outputresponse_outputdefault_type", - "OutputResponseEndpointConfiguration": ".outputresponse_outputdefault_type", - "OutputResponseExtentTag": ".outputresponse_outputdefault_type", - "OutputResponseExtentTagTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseExtraLogType": ".outputresponse_outputdefault_type", - "OutputResponseExtraLogTypeTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseFacility": ".outputresponse_outputdefault_type", - "OutputResponseFieldName": ".outputresponse_outputdefault_type", - "OutputResponseIndexerDiscoveryConfigs": ".outputresponse_outputdefault_type", - "OutputResponseIndexerDiscoveryConfigsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseIngestIfNotExist": ".outputresponse_outputdefault_type", - "OutputResponseIngestIfNotExistTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseIngestionMode": ".outputresponse_outputdefault_type", - "OutputResponseLogLocationType": ".outputresponse_outputdefault_type", - "OutputResponseMessageFormat": ".outputresponse_outputdefault_type", - "OutputResponseMetadatum": ".outputresponse_outputdefault_type", - "OutputResponseMetadatumTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureBlob": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureBlobTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureDataExplorer": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureDataExplorerAuthenticationMethod": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureDataExplorerPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureDataExplorerPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureDataExplorerType": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureDataExplorerTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureEventhub": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureEventhubPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureEventhubPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureEventhubType": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureEventhubTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureLogs": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureLogsAuthenticationMethod": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureLogsPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureLogsPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureLogsType": ".outputresponse_outputdefault_type", - "OutputResponseOutputAzureLogsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputCloudwatch": ".outputresponse_outputdefault_type", - "OutputResponseOutputCloudwatchPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputCloudwatchPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputCloudwatchType": ".outputresponse_outputdefault_type", - "OutputResponseOutputCloudwatchTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputConfluentCloud": ".outputresponse_outputdefault_type", - "OutputResponseOutputConfluentCloudPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputConfluentCloudPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputConfluentCloudTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputDefaultType": ".outputresponse_outputdefault_type", - "OutputResponseOutputDevnull": ".outputresponse_outputdefault_type", - "OutputResponseOutputDevnullType": ".outputresponse_outputdefault_type", - "OutputResponseOutputDevnullTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputElastic": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticCloud": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticCloudPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticCloudPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticCloudType": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticCloudTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticType": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticURL": ".outputresponse_outputdefault_type", - "OutputResponseOutputElasticURLTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputExabeam": ".outputresponse_outputdefault_type", - "OutputResponseOutputExabeamType": ".outputresponse_outputdefault_type", - "OutputResponseOutputExabeamTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputFilesystem": ".outputresponse_outputdefault_type", - "OutputResponseOutputFilesystemType": ".outputresponse_outputdefault_type", - "OutputResponseOutputFilesystemTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleBigquery": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleBigqueryPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleBigqueryPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleBigqueryType": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleBigqueryTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleChronicle": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleChronicleAuthenticationMethod": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleChroniclePqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleChroniclePqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleChronicleType": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleChronicleTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudLogging": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudLoggingPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudLoggingType": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudLoggingTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservability": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityEndpoint": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityOtlpVersion": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityProtocol": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityType": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudObservabilityTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudStorage": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudStorageAuthenticationMethod": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudStorageType": ".outputresponse_outputdefault_type", - "OutputResponseOutputGoogleCloudStorageTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGooglePubsub": ".outputresponse_outputdefault_type", - "OutputResponseOutputGooglePubsubPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputGooglePubsubPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputGooglePubsubTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputHoneycomb": ".outputresponse_outputdefault_type", - "OutputResponseOutputHoneycombPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputHoneycombPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputHoneycombType": ".outputresponse_outputdefault_type", - "OutputResponseOutputHoneycombTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputInfluxdb": ".outputresponse_outputdefault_type", - "OutputResponseOutputInfluxdbAuthenticationType": ".outputresponse_outputdefault_type", - "OutputResponseOutputInfluxdbPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputInfluxdbPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputInfluxdbType": ".outputresponse_outputdefault_type", - "OutputResponseOutputInfluxdbTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputKafka": ".outputresponse_outputdefault_type", - "OutputResponseOutputKafkaPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputKafkaPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputKafkaTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputKinesis": ".outputresponse_outputdefault_type", - "OutputResponseOutputKinesisPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputKinesisPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputKinesisTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputMinio": ".outputresponse_outputdefault_type", - "OutputResponseOutputMinioType": ".outputresponse_outputdefault_type", - "OutputResponseOutputMinioTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputMsk": ".outputresponse_outputdefault_type", - "OutputResponseOutputMskPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputMskPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputMskTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelic": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicEvents": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicEventsPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicEventsPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicEventsType": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicEventsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicType": ".outputresponse_outputdefault_type", - "OutputResponseOutputNewrelicTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputS3": ".outputresponse_outputdefault_type", - "OutputResponseOutputS3TypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSentinel": ".outputresponse_outputdefault_type", - "OutputResponseOutputSentinelFormat": ".outputresponse_outputdefault_type", - "OutputResponseOutputSentinelPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputSentinelPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSentinelType": ".outputresponse_outputdefault_type", - "OutputResponseOutputSentinelTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSignalfx": ".outputresponse_outputdefault_type", - "OutputResponseOutputSignalfxPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputSignalfxPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSignalfxType": ".outputresponse_outputdefault_type", - "OutputResponseOutputSignalfxTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunk": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkHec": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkHecPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkHecPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkHecType": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkHecTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkHecURL": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkHecURLTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkLb": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkLbPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkLbPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkLbType": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkLbTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSplunkTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsd": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdExt": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdExtPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdExtPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdExtTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdType": ".outputresponse_outputdefault_type", - "OutputResponseOutputStatsdTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSyslog": ".outputresponse_outputdefault_type", - "OutputResponseOutputSyslogPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputSyslogPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputSyslogProtocol": ".outputresponse_outputdefault_type", - "OutputResponseOutputSyslogSeverity": ".outputresponse_outputdefault_type", - "OutputResponseOutputSyslogTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputTcpjson": ".outputresponse_outputdefault_type", - "OutputResponseOutputTcpjsonPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputTcpjsonPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputTcpjsonTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWavefront": ".outputresponse_outputdefault_type", - "OutputResponseOutputWavefrontPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputWavefrontPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWavefrontType": ".outputresponse_outputdefault_type", - "OutputResponseOutputWavefrontTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookAuthenticationType1": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookAuthenticationType2": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookFormat1": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookFormat2": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookPqControls1": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookPqControls1TypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookPqControls2": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookPqControls2TypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookType1": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookType2": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookURL1": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookURL1TypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookURL2": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookURL2TypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookUnion": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookUnionTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookWebhook1": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookWebhook1TypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookWebhook2": ".outputresponse_outputdefault_type", - "OutputResponseOutputWebhookWebhook2TypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWizHec": ".outputresponse_outputdefault_type", - "OutputResponseOutputWizHecPqControls": ".outputresponse_outputdefault_type", - "OutputResponseOutputWizHecPqControlsTypedDict": ".outputresponse_outputdefault_type", - "OutputResponseOutputWizHecType": ".outputresponse_outputdefault_type", - "OutputResponseOutputWizHecTypedDict": ".outputresponse_outputdefault_type", - "OutputResponsePayloadFormat": ".outputresponse_outputdefault_type", - "OutputResponsePrefixOptional": ".outputresponse_outputdefault_type", - "OutputResponseReportLevel": ".outputresponse_outputdefault_type", - "OutputResponseReportMethod": ".outputresponse_outputdefault_type", - "OutputResponseSendEventsAs": ".outputresponse_outputdefault_type", - "OutputResponseTimestampFormat": ".outputresponse_outputdefault_type", - "OutputResponseTimestampPrecision": ".outputresponse_outputdefault_type", - "OutputResponseUDMType": ".outputresponse_outputdefault_type", - "OutputResponseWriteAction": ".outputresponse_outputdefault_type", - "OutputResponseAISIEMEndpointPath": ".outputresponse_outputstatsdext_type", - "OutputResponseAuthentication": ".outputresponse_outputstatsdext_type", - "OutputResponseAuthenticationTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseColumnMapping": ".outputresponse_outputstatsdext_type", - "OutputResponseColumnMappingTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseCustomLabel": ".outputresponse_outputstatsdext_type", - "OutputResponseCustomLabelTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseDataSetSite": ".outputresponse_outputstatsdext_type", - "OutputResponseDatadogSite": ".outputresponse_outputstatsdext_type", - "OutputResponseEndpointType": ".outputresponse_outputstatsdext_type", - "OutputResponseMappingType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAlibabaCloudS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAlibabaCloudS3AuthenticationMethod": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAlibabaCloudS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAlibabaCloudS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAlphasocS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAlphasocS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAlphasocS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAmazonManagedPrometheus": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAmazonManagedPrometheusPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAmazonManagedPrometheusPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAmazonManagedPrometheusType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputAmazonManagedPrometheusTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputChronicle": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputChronicleAuthenticationMethod": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputChroniclePqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputChroniclePqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputChronicleType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputChronicleTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputClickHouse": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputClickHousePqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputClickHousePqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputClickHouseType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputClickHouseTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCloudflareR2": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCloudflareR2Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCloudflareR2TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCloudianS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCloudianS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCloudianS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblHTTP": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblHTTPPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblHTTPPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblHTTPType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblHTTPTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblLake": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblLakeFormat": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblLakeType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblLakeTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblSearchEngine": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblSearchEnginePqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblSearchEnginePqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblSearchEngineType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblSearchEngineTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblTCP": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblTCPPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblTCPPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCriblTCPTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCrowdstrikeNextGenSiem": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCrowdstrikeNextGenSiemPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCrowdstrikeNextGenSiemPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCrowdstrikeNextGenSiemType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCrowdstrikeNextGenSiemTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCustomerMetricsStorage": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCustomerMetricsStoragePqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCustomerMetricsStoragePqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCustomerMetricsStorageType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputCustomerMetricsStorageTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatabricks": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatabricksType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatabricksTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatadog": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatadogPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatadogPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatadogSeverity": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatadogType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatadogTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDataset": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatasetPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatasetPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatasetSeverity": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatasetType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDatasetTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDellS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDellS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDellS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDiskSpool": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDiskSpoolType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDiskSpoolTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDlS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDlS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDlS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTP": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTPAuthenticationType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTPEndpoint": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTPFormat": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTPPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTPPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTPType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceHTTPTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceOtlp": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceOtlpPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceOtlpPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceOtlpProtocol": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceOtlpType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputDynatraceOtlpTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudGrafanaCloud1": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudGrafanaCloud2": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudPqControls1": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudPqControls1TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudPqControls2": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudPqControls2TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudType1": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudType2": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudUnion": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGrafanaCloudUnionTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGraphite": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGraphitePqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGraphitePqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGraphiteType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputGraphiteTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputHumioHec": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputHumioHecPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputHumioHecPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputHumioHecType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputHumioHecTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputIbmCloudS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputIbmCloudS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputIbmCloudS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLocalSearchStorage": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLocalSearchStorageFormat": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLocalSearchStoragePqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLocalSearchStoragePqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLocalSearchStorageType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLocalSearchStorageTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLoki": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLokiPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLokiPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLokiType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputLokiTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputMicrosoftFabric": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputMicrosoftFabricPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputMicrosoftFabricPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputMicrosoftFabricType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputMicrosoftFabricTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputNetflow": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputNetflowHost": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputNetflowHostTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputNetflowTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputNutanixObjects": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputNutanixObjectsType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputNutanixObjectsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputOpenTelemetry": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputOpenTelemetryAuthenticationType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputOpenTelemetryOTLPVersion": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputOpenTelemetryPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputOpenTelemetryPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputOpenTelemetryType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputOpenTelemetryTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputPrometheus": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputPrometheusAuthenticationType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputPrometheusPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputPrometheusPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputPrometheusTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputRing": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputRingDataFormat": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputRingType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputRingTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputRouter": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputRouterType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputRouterTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputScalityS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputScalityS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputScalityS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSecurityLake": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSecurityLakeTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSentinelOneAiSiem": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSentinelOneAiSiemPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSentinelOneAiSiemPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSentinelOneAiSiemType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSentinelOneAiSiemTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputServiceNow": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputServiceNowPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputServiceNowPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputServiceNowType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputServiceNowTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnmp": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnmpHost": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnmpHostTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnmpTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnowflakeStreaming": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnowflakeStreamingPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnowflakeStreamingPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnowflakeStreamingType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnowflakeStreamingTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSns": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnsPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnsPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnsType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSnsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSqs": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSqsPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSqsPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSqsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputStatsdExtType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputStorjS3": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputStorjS3Type": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputStorjS3TypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSumoLogic": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSumoLogicDataFormat": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSumoLogicPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSumoLogicPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSumoLogicType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputSumoLogicTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiam": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiamAuthenticationMethod": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiamPqControls": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiamPqControlsTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiamType": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiamTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiamURL": ".outputresponse_outputstatsdext_type", - "OutputResponseOutputXsiamURLTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponsePrivateKey": ".outputresponse_outputstatsdext_type", - "OutputResponsePrivateKeyTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseQueueType": ".outputresponse_outputstatsdext_type", - "OutputResponseRegion": ".outputresponse_outputstatsdext_type", - "OutputResponseRule": ".outputresponse_outputstatsdext_type", - "OutputResponseRuleTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseSendLogsAs": ".outputresponse_outputstatsdext_type", - "OutputResponseStatsDestination": ".outputresponse_outputstatsdext_type", - "OutputResponseStatsDestinationTypedDict": ".outputresponse_outputstatsdext_type", - "OutputResponseTelemetryType": ".outputresponse_outputstatsdext_type", + "OutputResponseAISIEMEndpointPath": ".outputresponse_outputsns_pqcontrols", + "OutputResponseAuthentication": ".outputresponse_outputsns_pqcontrols", + "OutputResponseAuthenticationTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseColumnMapping": ".outputresponse_outputsns_pqcontrols", + "OutputResponseColumnMappingTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseCustomLabel": ".outputresponse_outputsns_pqcontrols", + "OutputResponseCustomLabelTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseDataSetSite": ".outputresponse_outputsns_pqcontrols", + "OutputResponseDatadogSite": ".outputresponse_outputsns_pqcontrols", + "OutputResponseEndpointType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseMappingType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAlibabaCloudS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAlibabaCloudS3AuthenticationMethod": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAlibabaCloudS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAlibabaCloudS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAlphasocS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAlphasocS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAlphasocS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAmazonManagedPrometheus": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAmazonManagedPrometheusPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAmazonManagedPrometheusPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAmazonManagedPrometheusType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputAmazonManagedPrometheusTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputChronicle": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputChronicleAuthenticationMethod": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputChroniclePqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputChroniclePqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputChronicleType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputChronicleTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputClickHouse": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputClickHousePqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputClickHousePqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputClickHouseType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputClickHouseTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCloudflareR2": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCloudflareR2Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCloudflareR2TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCloudianS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCloudianS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCloudianS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblHTTP": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblHTTPPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblHTTPPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblHTTPType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblHTTPTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblLake": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblLakeFormat": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblLakeType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblLakeTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblSearchEngine": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblSearchEnginePqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblSearchEnginePqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblSearchEngineType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblSearchEngineTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblTCP": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblTCPPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblTCPPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCriblTCPTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCrowdstrikeNextGenSiem": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCrowdstrikeNextGenSiemPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCrowdstrikeNextGenSiemPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCrowdstrikeNextGenSiemType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCrowdstrikeNextGenSiemTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCustomerMetricsStorage": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCustomerMetricsStoragePqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCustomerMetricsStoragePqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCustomerMetricsStorageType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputCustomerMetricsStorageTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricks": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricksType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricksTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricksZerobus": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricksZerobusPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricksZerobusPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricksZerobusType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatabricksZerobusTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatadog": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatadogPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatadogPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatadogSeverity": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatadogType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatadogTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDataset": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatasetPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatasetPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatasetSeverity": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatasetType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDatasetTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDellS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDellS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDellS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDiskSpool": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDiskSpoolType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDiskSpoolTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDlS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDlS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDlS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTP": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTPAuthenticationType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTPEndpoint": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTPFormat": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTPPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTPPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTPType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceHTTPTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceOtlp": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceOtlpPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceOtlpPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceOtlpProtocol": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceOtlpType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputDynatraceOtlpTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudGrafanaCloud1": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudGrafanaCloud2": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudPqControls1": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudPqControls1TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudPqControls2": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudPqControls2TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudType1": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudType2": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudUnion": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputGrafanaCloudUnionTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputHumioHec": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputHumioHecPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputHumioHecPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputHumioHecType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputHumioHecTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputIbmCloudS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputIbmCloudS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputIbmCloudS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLocalSearchStorage": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLocalSearchStorageFormat": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLocalSearchStoragePqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLocalSearchStoragePqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLocalSearchStorageType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLocalSearchStorageTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLoki": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLokiPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLokiPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLokiType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputLokiTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputMicrosoftFabric": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputMicrosoftFabricPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputMicrosoftFabricPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputMicrosoftFabricType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputMicrosoftFabricTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputNetflow": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputNetflowHost": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputNetflowHostTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputNetflowTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputNutanixObjects": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputNutanixObjectsType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputNutanixObjectsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputOpenTelemetry": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputOpenTelemetryAuthenticationType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputOpenTelemetryOTLPVersion": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputOpenTelemetryPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputOpenTelemetryPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputOpenTelemetryType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputOpenTelemetryTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputPrometheus": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputPrometheusAuthenticationType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputPrometheusPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputPrometheusPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputPrometheusTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputRing": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputRingDataFormat": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputRingType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputRingTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputScalityS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputScalityS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputScalityS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSecurityLake": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSecurityLakeTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSentinelOneAiSiem": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSentinelOneAiSiemPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSentinelOneAiSiemPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSentinelOneAiSiemType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSentinelOneAiSiemTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputServiceNow": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputServiceNowPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputServiceNowPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputServiceNowType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputServiceNowTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnmp": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnmpHost": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnmpHostTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnmpTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnowflakeStreaming": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnowflakeStreamingPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnowflakeStreamingPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnowflakeStreamingType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnowflakeStreamingTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnsPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnsPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSnsType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSqs": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSqsPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSqsPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSqsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputStorjS3": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputStorjS3Type": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputStorjS3TypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSumoLogic": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSumoLogicDataFormat": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSumoLogicPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSumoLogicPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSumoLogicType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputSumoLogicTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputTraversalOtlp": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputTraversalOtlpAuthenticationType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputTraversalOtlpPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputTraversalOtlpPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputTraversalOtlpType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputTraversalOtlpTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiam": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiamAuthenticationMethod": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiamPqControls": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiamPqControlsTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiamType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiamTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiamURL": ".outputresponse_outputsns_pqcontrols", + "OutputResponseOutputXsiamURLTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponsePrivateKey": ".outputresponse_outputsns_pqcontrols", + "OutputResponsePrivateKeyTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseQueueType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseRegion": ".outputresponse_outputsns_pqcontrols", + "OutputResponseSendAs": ".outputresponse_outputsns_pqcontrols", + "OutputResponseSendLogsAs": ".outputresponse_outputsns_pqcontrols", + "OutputResponseStatsDestination": ".outputresponse_outputsns_pqcontrols", + "OutputResponseStatsDestinationTypedDict": ".outputresponse_outputsns_pqcontrols", + "OutputResponseTelemetryType": ".outputresponse_outputsns_pqcontrols", + "OutputResponseAPIVersion": ".outputresponse_outputwebhook_format_2", + "OutputResponseAdditionalProperty": ".outputresponse_outputwebhook_format_2", + "OutputResponseAdditionalPropertyTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseAuthToken": ".outputresponse_outputwebhook_format_2", + "OutputResponseAuthTokenTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseAuthType": ".outputresponse_outputwebhook_format_2", + "OutputResponseBlobAccessTier": ".outputresponse_outputwebhook_format_2", + "OutputResponseCertificate": ".outputresponse_outputwebhook_format_2", + "OutputResponseCertificateTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseCompression": ".outputresponse_outputwebhook_format_2", + "OutputResponseElasticVersion": ".outputresponse_outputwebhook_format_2", + "OutputResponseEndpointConfiguration": ".outputresponse_outputwebhook_format_2", + "OutputResponseEventFormat": ".outputresponse_outputwebhook_format_2", + "OutputResponseExtentTag": ".outputresponse_outputwebhook_format_2", + "OutputResponseExtentTagTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseExtraLogType": ".outputresponse_outputwebhook_format_2", + "OutputResponseExtraLogTypeTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseFacility": ".outputresponse_outputwebhook_format_2", + "OutputResponseFieldName": ".outputresponse_outputwebhook_format_2", + "OutputResponseIndexerDiscoveryConfigs": ".outputresponse_outputwebhook_format_2", + "OutputResponseIndexerDiscoveryConfigsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseIngestIfNotExist": ".outputresponse_outputwebhook_format_2", + "OutputResponseIngestIfNotExistTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseIngestionMode": ".outputresponse_outputwebhook_format_2", + "OutputResponseLogLocationType": ".outputresponse_outputwebhook_format_2", + "OutputResponseMessageFormat": ".outputresponse_outputwebhook_format_2", + "OutputResponseMetadatum": ".outputresponse_outputwebhook_format_2", + "OutputResponseMetadatumTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOAuthSecretSource": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureBlob": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureBlobTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureDataExplorer": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureDataExplorerAuthenticationMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureDataExplorerPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureDataExplorerPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureDataExplorerType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureDataExplorerTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureEventhub": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureEventhubPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureEventhubPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureEventhubType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureEventhubTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureLogs": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureLogsAuthenticationMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureLogsPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureLogsPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureLogsType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputAzureLogsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputCloudwatch": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputCloudwatchPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputCloudwatchPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputCloudwatchType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputCloudwatchTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputConfluentCloud": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputConfluentCloudPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputConfluentCloudPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputConfluentCloudTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputDevnull": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputDevnullType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputDevnullTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElastic": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticCloud": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticCloudPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticCloudPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticCloudType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticCloudTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticURL": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputElasticURLTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputExabeam": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputExabeamAuthenticationMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputExabeamType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputExabeamTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputFilesystem": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputFilesystemType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputFilesystemTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleBigquery": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleBigqueryPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleBigqueryPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleBigqueryType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleBigqueryTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleChronicle": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleChronicleAuthenticationMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleChroniclePqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleChroniclePqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleChronicleType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleChronicleTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudLogging": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudLoggingPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudLoggingType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudLoggingTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservability": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityEndpoint": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityOtlpVersion": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityProtocol": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudObservabilityTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudStorage": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudStorageAuthenticationMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudStorageType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGoogleCloudStorageTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGooglePubsub": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGooglePubsubPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGooglePubsubPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGooglePubsubTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGraphite": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGraphitePqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGraphitePqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGraphiteType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputGraphiteTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputHoneycomb": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputHoneycombPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputHoneycombPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputHoneycombType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputHoneycombTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputInfluxdb": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputInfluxdbAuthenticationType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputInfluxdbPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputInfluxdbPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputInfluxdbType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputInfluxdbTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKafka": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKafkaPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKafkaPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKafkaTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKinesis": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKinesisPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKinesisPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputKinesisTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputMinio": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputMinioType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputMinioTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputMsk": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputMskPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputMskPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputMskTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelic": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicEvents": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicEventsPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicEventsPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicEventsType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicEventsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputNewrelicTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputRouter": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputRouterType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputRouterTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputS3": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputS3TypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSentinel": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSentinelFormat": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSentinelPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSentinelPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSentinelType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSentinelTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSignalfx": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSignalfxPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSignalfxPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSignalfxType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSignalfxTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSns": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSnsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunk": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkHec": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkHecPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkHecPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkHecType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkHecTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkHecURL": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkHecURLTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkLb": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkLbPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkLbPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkLbType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkLbTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSplunkTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsd": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdExt": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdExtPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdExtPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdExtType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdExtTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputStatsdTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSyslog": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSyslogPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSyslogPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSyslogProtocol": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSyslogSeverity": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputSyslogTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputTcpjson": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputTcpjsonPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputTcpjsonPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputTcpjsonTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWavefront": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWavefrontPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWavefrontPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWavefrontType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWavefrontTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWebhookFormat2": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWebhookType2": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWizHec": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWizHecPqControls": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWizHecPqControlsTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWizHecType": ".outputresponse_outputwebhook_format_2", + "OutputResponseOutputWizHecTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponsePayloadFormat": ".outputresponse_outputwebhook_format_2", + "OutputResponsePrefixOptional": ".outputresponse_outputwebhook_format_2", + "OutputResponseReportLevel": ".outputresponse_outputwebhook_format_2", + "OutputResponseReportMethod": ".outputresponse_outputwebhook_format_2", + "OutputResponseRule": ".outputresponse_outputwebhook_format_2", + "OutputResponseRuleTypedDict": ".outputresponse_outputwebhook_format_2", + "OutputResponseSendEventsAs": ".outputresponse_outputwebhook_format_2", + "OutputResponseTimestampFormat": ".outputresponse_outputwebhook_format_2", + "OutputResponseTimestampPrecision": ".outputresponse_outputwebhook_format_2", + "OutputResponseUDMType": ".outputresponse_outputwebhook_format_2", + "OutputResponseWizDefendSourceType": ".outputresponse_outputwebhook_format_2", + "OutputResponseWriteAction": ".outputresponse_outputwebhook_format_2", "OutputRing": ".outputring", "OutputRingDataFormat": ".outputring", "OutputRingType": ".outputring", @@ -20060,6 +21446,7 @@ "OutputSecurityLakeTypedDict": ".outputsecuritylake", "AuthTypeEnum": ".outputsentinel", "EndpointConfiguration": ".outputsentinel", + "OAuthSecretSource": ".outputsentinel", "OutputSentinel": ".outputsentinel", "OutputSentinelFormat": ".outputsentinel", "OutputSentinelPqControls": ".outputsentinel", @@ -20162,6 +21549,12 @@ "OutputTestRequestTypedDict": ".outputtestrequest", "OutputTestResponse": ".outputtestresponse", "OutputTestResponseTypedDict": ".outputtestresponse", + "OutputTraversalOtlp": ".outputtraversalotlp", + "OutputTraversalOtlpAuthenticationType": ".outputtraversalotlp", + "OutputTraversalOtlpPqControls": ".outputtraversalotlp", + "OutputTraversalOtlpPqControlsTypedDict": ".outputtraversalotlp", + "OutputTraversalOtlpType": ".outputtraversalotlp", + "OutputTraversalOtlpTypedDict": ".outputtraversalotlp", "OutputWavefront": ".outputwavefront", "OutputWavefrontPqControls": ".outputwavefront", "OutputWavefrontPqControlsTypedDict": ".outputwavefront", @@ -20188,10 +21581,12 @@ "OutputWebhookWebhook2": ".outputwebhook_union", "OutputWebhookWebhook2TypedDict": ".outputwebhook_union", "OutputWizHec": ".outputwizhec", + "OutputWizHecEventFormat": ".outputwizhec", "OutputWizHecPqControls": ".outputwizhec", "OutputWizHecPqControlsTypedDict": ".outputwizhec", "OutputWizHecType": ".outputwizhec", "OutputWizHecTypedDict": ".outputwizhec", + "WizDefendSourceType": ".outputwizhec", "OutputXsiam": ".outputxsiam", "OutputXsiamAuthenticationMethod": ".outputxsiam", "OutputXsiamPqControls": ".outputxsiam", @@ -20244,6 +21639,8 @@ "PaginatedPackInfoTypedDict": ".paginatedpackinfo", "PaginatedPipeline": ".paginatedpipeline", "PaginatedPipelineTypedDict": ".paginatedpipeline", + "PaginatedRoutes": ".paginatedroutes", + "PaginatedRoutesTypedDict": ".paginatedroutes", "PaginatedSavedJobResponse": ".paginatedsavedjobresponse", "PaginatedSavedJobResponseTypedDict": ".paginatedsavedjobresponse", "PaginationOptionsRestDiscoveryDiscoverTypeHTTPPagination": ".paginationoptionsrestdiscoverydiscovertypehttppagination", @@ -20328,6 +21725,9 @@ "UnknownPipelineFunctionConf": ".pipelinefunctionconf", "PipelineFunctionConfInput": ".pipelinefunctionconf_input", "PipelineFunctionConfInputTypedDict": ".pipelinefunctionconf_input", + "PipelineFunctionDetectionRules": ".pipelinefunctiondetectionrules", + "PipelineFunctionDetectionRulesID": ".pipelinefunctiondetectionrules", + "PipelineFunctionDetectionRulesTypedDict": ".pipelinefunctiondetectionrules", "DistinctConfiguration": ".pipelinefunctiondistinct", "DistinctConfigurationTypedDict": ".pipelinefunctiondistinct", "PipelineFunctionDistinct": ".pipelinefunctiondistinct", @@ -20435,6 +21835,9 @@ "PipelineFunctionLakeExport": ".pipelinefunctionlakeexport", "PipelineFunctionLakeExportID": ".pipelinefunctionlakeexport", "PipelineFunctionLakeExportTypedDict": ".pipelinefunctionlakeexport", + "PipelineFunctionLakehouseEngineMetricsNormalizer": ".pipelinefunctionlakehouseenginemetricsnormalizer", + "PipelineFunctionLakehouseEngineMetricsNormalizerID": ".pipelinefunctionlakehouseenginemetricsnormalizer", + "PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict": ".pipelinefunctionlakehouseenginemetricsnormalizer", "PipelineFunctionLimit": ".pipelinefunctionlimit", "PipelineFunctionLimitID": ".pipelinefunctionlimit", "PipelineFunctionLimitTypedDict": ".pipelinefunctionlimit", @@ -20486,6 +21889,9 @@ "PipelineFunctionMetricsExportMode1": ".pipelinefunctionmetricsexport", "PipelineFunctionMetricsExportMode2": ".pipelinefunctionmetricsexport", "PipelineFunctionMetricsExportTypedDict": ".pipelinefunctionmetricsexport", + "PipelineFunctionMetricsTimeRangeGate": ".pipelinefunctionmetricstimerangegate", + "PipelineFunctionMetricsTimeRangeGateID": ".pipelinefunctionmetricstimerangegate", + "PipelineFunctionMetricsTimeRangeGateTypedDict": ".pipelinefunctionmetricstimerangegate", "BagExpansionMode": ".pipelinefunctionmvexpand", "PipelineFunctionMvExpand": ".pipelinefunctionmvexpand", "PipelineFunctionMvExpandConf": ".pipelinefunctionmvexpand", @@ -21793,6 +23199,9 @@ "EnvVarTypedDict": ".scriptcollectorconf", "ScriptCollectorConf": ".scriptcollectorconf", "ScriptCollectorConfTypedDict": ".scriptcollectorconf", + "BackendID": ".searchexecutionconfig", + "SearchExecutionConfig": ".searchexecutionconfig", + "SearchExecutionConfigTypedDict": ".searchexecutionconfig", "SearchFilterConfInputPrometheus": ".searchfilterconfinputprometheus", "SearchFilterConfInputPrometheusTypedDict": ".searchfilterconfinputprometheus", "SearchVersion": ".searchversion", @@ -21913,11 +23322,9 @@ "SystemSettingsConf": ".systemsettingsconf", "SystemSettingsConfTypedDict": ".systemsettingsconf", "SystemSettingsConfResponse": ".systemsettingsconfresponse", - "SystemSettingsConfResponseAPI": ".systemsettingsconfresponse", - "SystemSettingsConfResponseAPITypedDict": ".systemsettingsconfresponse", - "SystemSettingsConfResponseSystem": ".systemsettingsconfresponse", - "SystemSettingsConfResponseSystemTypedDict": ".systemsettingsconfresponse", "SystemSettingsConfResponseTypedDict": ".systemsettingsconfresponse", + "API": ".systemsettingsconfupdate", + "APITypedDict": ".systemsettingsconfupdate", "Apps": ".systemsettingsconfupdate", "AppsTypedDict": ".systemsettingsconfupdate", "CustomLogo": ".systemsettingsconfupdate", @@ -21933,8 +23340,6 @@ "Support": ".systemsettingsconfupdate", "SupportTypedDict": ".systemsettingsconfupdate", "SystemSettingsConfUpdate": ".systemsettingsconfupdate", - "SystemSettingsConfUpdateAPI": ".systemsettingsconfupdate", - "SystemSettingsConfUpdateAPITypedDict": ".systemsettingsconfupdate", "SystemSettingsConfUpdateSystem": ".systemsettingsconfupdate", "SystemSettingsConfUpdateSystemTypedDict": ".systemsettingsconfupdate", "SystemSettingsConfUpdateTypedDict": ".systemsettingsconfupdate", @@ -21952,8 +23357,7 @@ "TaskErrorInfoTypedDict": ".taskerrorinfo", "TeamAccessControlList": ".teamaccesscontrollist", "TeamAccessControlListTypedDict": ".teamaccesscontrollist", - "TemplateTargetPairConfFunctionConfSchemaNotificationPolicies": ".templatetargetpairconffunctionconfschemanotificationpolicies", - "TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict": ".templatetargetpairconffunctionconfschemanotificationpolicies", + "TemplateFamilyOptionsCriblSourceProvenance": ".templatefamilyoptionscriblsourceprovenance", "TimeoutRetrySettingsType": ".timeoutretrysettingstype", "TimeoutRetrySettingsTypeTypedDict": ".timeoutretrysettingstype", "EventBreakerExistingOrNewNewTimestampTypeAuto": ".timestampformattypeeventbreakerexistingornewnew", @@ -21966,8 +23370,6 @@ "TimestampFormatTypeEventBreakerExistingOrNewNewTypedDict": ".timestampformattypeeventbreakerexistingornewnew", "UnknownTimestampFormatTypeEventBreakerExistingOrNewNew": ".timestampformattypeeventbreakerexistingornewnew", "TimestampTypeOptionsEventBreakerExistingOrNewNewTimestamp": ".timestamptypeoptionseventbreakerexistingornewnewtimestamp", - "TimeWarningTypeRunnableJobCollectionScheduleRun": ".timewarningtyperunnablejobcollectionschedulerun", - "TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict": ".timewarningtyperunnablejobcollectionschedulerun", "TLSClientParams": ".tlsclientparams", "TLSClientParamsTypedDict": ".tlsclientparams", "TLSOptionsHostsItems": ".tlsoptionshostsitems", diff --git a/src/cribl_control_plane/models/appstypesystemsettingsconf.py b/src/cribl_control_plane/models/appstypesystemsettingsconf.py index c0baa8b6a..5757d8e01 100644 --- a/src/cribl_control_plane/models/appstypesystemsettingsconf.py +++ b/src/cribl_control_plane/models/appstypesystemsettingsconf.py @@ -1,8 +1,11 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from cribl_control_plane.types import BaseModel -from typing_extensions import TypedDict +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +import pydantic +from pydantic import model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict class AppsTypeSystemSettingsConfTypedDict(TypedDict): @@ -10,6 +13,20 @@ class AppsTypeSystemSettingsConfTypedDict(TypedDict): enabled: bool r"""If true, enable Apps. Otherwise, false.""" + app_backend_broker_origin: NotRequired[str] + r"""Public origin for App Platform backend broker callbacks (standalone/on-prem only). Must be an absolute HTTP(S) URL.""" + app_backend_max_callbacks_per_installation: NotRequired[int] + r"""Maximum number of broker callbacks per minute a single app backend installation may make. Over-limit callbacks receive HTTP 429.""" + app_backend_max_callbacks_total: NotRequired[int] + r"""Maximum number of broker callbacks per minute across all app backend installations on this Leader. Unlimited when unset. Over-limit callbacks receive HTTP 429.""" + app_backend_max_in_flight: NotRequired[int] + r"""Maximum number of concurrent App Platform backend invocations across all apps on this Leader.""" + app_schedule_body_expression_max_length: NotRequired[int] + r"""Maximum number of characters allowed in a schedule bodyExpression.""" + app_scheduled_concurrent_job_limit: NotRequired[int] + r"""Maximum number of concurrent scheduled App Platform function jobs across all apps on this Leader (group-wide). Changes require a Leader restart.""" + app_schedules_max: NotRequired[int] + r"""Maximum number of schedule records a single App may declare.""" class AppsTypeSystemSettingsConf(BaseModel): @@ -17,3 +34,70 @@ class AppsTypeSystemSettingsConf(BaseModel): enabled: bool r"""If true, enable Apps. Otherwise, false.""" + + app_backend_broker_origin: Annotated[ + Optional[str], pydantic.Field(alias="appBackendBrokerOrigin") + ] = None + r"""Public origin for App Platform backend broker callbacks (standalone/on-prem only). Must be an absolute HTTP(S) URL.""" + + app_backend_max_callbacks_per_installation: Annotated[ + Optional[int], pydantic.Field(alias="appBackendMaxCallbacksPerInstallation") + ] = None + r"""Maximum number of broker callbacks per minute a single app backend installation may make. Over-limit callbacks receive HTTP 429.""" + + app_backend_max_callbacks_total: Annotated[ + Optional[int], pydantic.Field(alias="appBackendMaxCallbacksTotal") + ] = None + r"""Maximum number of broker callbacks per minute across all app backend installations on this Leader. Unlimited when unset. Over-limit callbacks receive HTTP 429.""" + + app_backend_max_in_flight: Annotated[ + Optional[int], pydantic.Field(alias="appBackendMaxInFlight") + ] = None + r"""Maximum number of concurrent App Platform backend invocations across all apps on this Leader.""" + + app_schedule_body_expression_max_length: Annotated[ + Optional[int], pydantic.Field(alias="appScheduleBodyExpressionMaxLength") + ] = None + r"""Maximum number of characters allowed in a schedule bodyExpression.""" + + app_scheduled_concurrent_job_limit: Annotated[ + Optional[int], pydantic.Field(alias="appScheduledConcurrentJobLimit") + ] = None + r"""Maximum number of concurrent scheduled App Platform function jobs across all apps on this Leader (group-wide). Changes require a Leader restart.""" + + app_schedules_max: Annotated[ + Optional[int], pydantic.Field(alias="appSchedulesMax") + ] = None + r"""Maximum number of schedule records a single App may declare.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "appBackendBrokerOrigin", + "appBackendMaxCallbacksPerInstallation", + "appBackendMaxCallbacksTotal", + "appBackendMaxInFlight", + "appScheduleBodyExpressionMaxLength", + "appScheduledConcurrentJobLimit", + "appSchedulesMax", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + AppsTypeSystemSettingsConf.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitemssecret.py b/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensextitems.py similarity index 56% rename from src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitemssecret.py rename to src/cribl_control_plane/models/authenticationmethodoptionsauthtokensextitems.py index 9567338ca..629388c82 100644 --- a/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitemssecret.py +++ b/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensextitems.py @@ -5,9 +5,10 @@ from enum import Enum -class AuthenticationMethodOptionsAuthTokensItemsSecret( +class AuthenticationMethodOptionsAuthTokensExtItems( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Select Secret to use a text secret to authenticate""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + MANUAL = "manual" SECRET = "secret" diff --git a/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitems.py b/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitems.py index 8b047531e..b90c7efaa 100644 --- a/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitems.py +++ b/src/cribl_control_plane/models/authenticationmethodoptionsauthtokensitems.py @@ -8,7 +8,6 @@ class AuthenticationMethodOptionsAuthTokensItems( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Select Secret to use a text secret to authenticate""" - MANUAL = "manual" SECRET = "secret" diff --git a/src/cribl_control_plane/models/authenticationmethodoptionsclientassertionclientassertionrpc.py b/src/cribl_control_plane/models/authenticationmethodoptionsclientassertionclientassertionrpc.py new file mode 100644 index 000000000..2a696ff68 --- /dev/null +++ b/src/cribl_control_plane/models/authenticationmethodoptionsclientassertionclientassertionrpc.py @@ -0,0 +1,17 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane import utils +from enum import Enum + + +class AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method""" + + SECRET = "secret" + CLIENT_SECRET = "clientSecret" + CLIENT_CERT = "clientCert" + CLIENT_ASSERTION = "clientAssertion" + CLIENT_ASSERTION_RPC = "clientAssertion_rpc" diff --git a/src/cribl_control_plane/models/authtoken.py b/src/cribl_control_plane/models/authtoken.py index 354cb79a7..d401308ea 100644 --- a/src/cribl_control_plane/models/authtoken.py +++ b/src/cribl_control_plane/models/authtoken.py @@ -8,13 +8,17 @@ class AuthTokenTypedDict(TypedDict): force_password_change: bool + r"""If true, the user must change their password before accessing the API. Otherwise, false.""" token: str + r"""Bearer token to include in the Authorization header for subsequent API requests.""" class AuthToken(BaseModel): force_password_change: Annotated[bool, pydantic.Field(alias="forcePasswordChange")] + r"""If true, the user must change their password before accessing the API. Otherwise, false.""" token: str + r"""Bearer token to include in the Authorization header for subsequent API requests.""" try: diff --git a/src/cribl_control_plane/models/authtokenconfinputcloudflarehec.py b/src/cribl_control_plane/models/authtokenconfinputcloudflarehec.py index f1fdcd957..cd782604f 100644 --- a/src/cribl_control_plane/models/authtokenconfinputcloudflarehec.py +++ b/src/cribl_control_plane/models/authtokenconfinputcloudflarehec.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitemssecret import ( - AuthenticationMethodOptionsAuthTokensItemsSecret, +from .authenticationmethodoptionsauthtokensitems import ( + AuthenticationMethodOptionsAuthTokensItems, ) from .metadataconfinputcollection import ( MetadataConfInputCollection, @@ -17,7 +17,7 @@ class AuthTokenConfInputCloudflareHecTypedDict(TypedDict): - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItemsSecret] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] r"""Select Secret to use a text secret to authenticate""" token_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -35,7 +35,7 @@ class AuthTokenConfInputCloudflareHecTypedDict(TypedDict): class AuthTokenConfInputCloudflareHec(BaseModel): auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItemsSecret], + Optional[AuthenticationMethodOptionsAuthTokensItems], pydantic.Field(alias="authType"), ] = None r"""Select Secret to use a text secret to authenticate""" @@ -64,7 +64,7 @@ class AuthTokenConfInputCloudflareHec(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItemsSecret(value) + return models.AuthenticationMethodOptionsAuthTokensItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/authtokensextconfinputhttp.py b/src/cribl_control_plane/models/authtokensextconfinputhttp.py deleted file mode 100644 index 97e65b884..000000000 --- a/src/cribl_control_plane/models/authtokensextconfinputhttp.py +++ /dev/null @@ -1,47 +0,0 @@ -"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" - -from __future__ import annotations -from .metadataconfinputcollection import ( - MetadataConfInputCollection, - MetadataConfInputCollectionTypedDict, -) -from cribl_control_plane.types import BaseModel, UNSET_SENTINEL -from pydantic import model_serializer -from typing import List, Optional -from typing_extensions import NotRequired, TypedDict - - -class AuthTokensExtConfInputHTTPTypedDict(TypedDict): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" - description: NotRequired[str] - r"""Description""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this token""" - - -class AuthTokensExtConfInputHTTP(BaseModel): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" - - description: Optional[str] = None - r"""Description""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this token""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description", "metadata"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m diff --git a/src/cribl_control_plane/models/branchinfo.py b/src/cribl_control_plane/models/branchinfo.py index 3195c05fc..c1e5552a3 100644 --- a/src/cribl_control_plane/models/branchinfo.py +++ b/src/cribl_control_plane/models/branchinfo.py @@ -1,15 +1,52 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from cribl_control_plane.types import BaseModel -from typing_extensions import TypedDict +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +import pydantic +from pydantic import model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict class BranchInfoTypedDict(TypedDict): id: str r"""Unique identifier.""" + src_group: NotRequired[str] + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + src_overridden: NotRequired[bool] + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" class BranchInfo(BaseModel): id: str r"""Unique identifier.""" + + src_group: Annotated[Optional[str], pydantic.Field(alias="__srcGroup")] = None + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + + src_overridden: Annotated[ + Optional[bool], pydantic.Field(alias="__srcOverridden") + ] = None + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["__srcGroup", "__srcOverridden"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + BranchInfo.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/configgroup.py b/src/cribl_control_plane/models/configgroup.py index 96e48df8d..d95efe1b6 100644 --- a/src/cribl_control_plane/models/configgroup.py +++ b/src/cribl_control_plane/models/configgroup.py @@ -59,6 +59,10 @@ class ConfigGroupTypedDict(TypedDict): id: str r"""Unique identifier.""" + src_group: NotRequired[str] + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + src_overridden: NotRequired[bool] + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" cloud: NotRequired[ConfigGroupCloudTypedDict] collectors_ha_enabled: NotRequired[bool] r"""Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups.""" @@ -110,6 +114,14 @@ class ConfigGroup(BaseModel): id: str r"""Unique identifier.""" + src_group: Annotated[Optional[str], pydantic.Field(alias="__srcGroup")] = None + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + + src_overridden: Annotated[ + Optional[bool], pydantic.Field(alias="__srcOverridden") + ] = None + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" + cloud: Optional[ConfigGroupCloud] = None collectors_ha_enabled: Annotated[ @@ -233,6 +245,8 @@ def serialize_type(self, value): def serialize_model(self, handler): optional_fields = set( [ + "__srcGroup", + "__srcOverridden", "cloud", "collectorsHaEnabled", "configVersion", diff --git a/src/cribl_control_plane/models/configgrouplookups.py b/src/cribl_control_plane/models/configgrouplookups.py index 1a0cc4a77..febe40431 100644 --- a/src/cribl_control_plane/models/configgrouplookups.py +++ b/src/cribl_control_plane/models/configgrouplookups.py @@ -1,16 +1,27 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations +from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum import pydantic -from pydantic import model_serializer +from pydantic import field_serializer, model_serializer from typing import List, Optional from typing_extensions import Annotated, NotRequired, TypedDict +class DeployMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Deploy mode configured on the lookup file.""" + + AUTO = "auto" + MANUAL = "manual" + + class ConfigGroupLookupsLookupTypedDict(TypedDict): file: str r"""File name of the deployed lookup.""" + deploy_mode: NotRequired[DeployMode] + r"""Deploy mode configured on the lookup file.""" deployed_version: NotRequired[str] r"""Version of the lookup file currently deployed on the Worker or Node.""" version: NotRequired[str] @@ -21,6 +32,11 @@ class ConfigGroupLookupsLookup(BaseModel): file: str r"""File name of the deployed lookup.""" + deploy_mode: Annotated[Optional[DeployMode], pydantic.Field(alias="deployMode")] = ( + None + ) + r"""Deploy mode configured on the lookup file.""" + deployed_version: Annotated[ Optional[str], pydantic.Field(alias="deployedVersion") ] = None @@ -29,9 +45,18 @@ class ConfigGroupLookupsLookup(BaseModel): version: Optional[str] = None r"""Version of the lookup file currently staged for deployment.""" + @field_serializer("deploy_mode") + def serialize_deploy_mode(self, value): + if isinstance(value, str): + try: + return models.DeployMode(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["deployedVersion", "version"]) + optional_fields = set(["deployMode", "deployedVersion", "version"]) serialized = handler(self) m = {} diff --git a/src/cribl_control_plane/models/countedboolean.py b/src/cribl_control_plane/models/countedboolean.py index b953ed6c6..6863f076c 100644 --- a/src/cribl_control_plane/models/countedboolean.py +++ b/src/cribl_control_plane/models/countedboolean.py @@ -8,14 +8,14 @@ class CountedBooleanTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[bool] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedBoolean(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[bool] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedbranchinfo.py b/src/cribl_control_plane/models/countedbranchinfo.py index 453fbf93c..b9e791dd3 100644 --- a/src/cribl_control_plane/models/countedbranchinfo.py +++ b/src/cribl_control_plane/models/countedbranchinfo.py @@ -9,14 +9,14 @@ class CountedBranchInfoTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[BranchInfoTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedBranchInfo(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[BranchInfo] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedconfiggroup.py b/src/cribl_control_plane/models/countedconfiggroup.py index 53b7db790..c72405fc0 100644 --- a/src/cribl_control_plane/models/countedconfiggroup.py +++ b/src/cribl_control_plane/models/countedconfiggroup.py @@ -9,14 +9,14 @@ class CountedConfigGroupTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[ConfigGroupTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedConfigGroup(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[ConfigGroup] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedcribllakedataset.py b/src/cribl_control_plane/models/countedcribllakedataset.py index f190f42b9..794235633 100644 --- a/src/cribl_control_plane/models/countedcribllakedataset.py +++ b/src/cribl_control_plane/models/countedcribllakedataset.py @@ -9,14 +9,14 @@ class CountedCriblLakeDatasetTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[CriblLakeDatasetTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedCriblLakeDataset(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[CriblLakeDataset] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedfunctionresponse.py b/src/cribl_control_plane/models/countedfunctionresponse.py index e042e45f4..2a4452fad 100644 --- a/src/cribl_control_plane/models/countedfunctionresponse.py +++ b/src/cribl_control_plane/models/countedfunctionresponse.py @@ -9,14 +9,14 @@ class CountedFunctionResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[FunctionResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedFunctionResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[FunctionResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitcommitsummary.py b/src/cribl_control_plane/models/countedgitcommitsummary.py index cafae527a..46b4c09ec 100644 --- a/src/cribl_control_plane/models/countedgitcommitsummary.py +++ b/src/cribl_control_plane/models/countedgitcommitsummary.py @@ -9,14 +9,14 @@ class CountedGitCommitSummaryTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitCommitSummaryTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitCommitSummary(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitCommitSummary] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitcountresult.py b/src/cribl_control_plane/models/countedgitcountresult.py index e24324590..7a4f0e329 100644 --- a/src/cribl_control_plane/models/countedgitcountresult.py +++ b/src/cribl_control_plane/models/countedgitcountresult.py @@ -9,14 +9,14 @@ class CountedGitCountResultTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitCountResultTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitCountResult(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitCountResult] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitdiffresult.py b/src/cribl_control_plane/models/countedgitdiffresult.py index a42f523f7..42a780c20 100644 --- a/src/cribl_control_plane/models/countedgitdiffresult.py +++ b/src/cribl_control_plane/models/countedgitdiffresult.py @@ -9,14 +9,14 @@ class CountedGitDiffResultTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitDiffResultTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitDiffResult(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitDiffResult] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitfilesresponse.py b/src/cribl_control_plane/models/countedgitfilesresponse.py index 267888cec..f12160a71 100644 --- a/src/cribl_control_plane/models/countedgitfilesresponse.py +++ b/src/cribl_control_plane/models/countedgitfilesresponse.py @@ -9,14 +9,14 @@ class CountedGitFilesResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitFilesResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitFilesResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitFilesResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitinfo.py b/src/cribl_control_plane/models/countedgitinfo.py index e7d1a4c2e..ab09dfb70 100644 --- a/src/cribl_control_plane/models/countedgitinfo.py +++ b/src/cribl_control_plane/models/countedgitinfo.py @@ -9,14 +9,14 @@ class CountedGitInfoTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitInfoTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitInfo(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitInfo] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitrevertresult.py b/src/cribl_control_plane/models/countedgitrevertresult.py index 9cbcd4e48..ec0a824f3 100644 --- a/src/cribl_control_plane/models/countedgitrevertresult.py +++ b/src/cribl_control_plane/models/countedgitrevertresult.py @@ -9,14 +9,14 @@ class CountedGitRevertResultTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitRevertResultTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitRevertResult(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitRevertResult] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitshowresult.py b/src/cribl_control_plane/models/countedgitshowresult.py index abed6a930..4d6c7f899 100644 --- a/src/cribl_control_plane/models/countedgitshowresult.py +++ b/src/cribl_control_plane/models/countedgitshowresult.py @@ -9,14 +9,14 @@ class CountedGitShowResultTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitShowResultTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitShowResult(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitShowResult] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedgitstatusresult.py b/src/cribl_control_plane/models/countedgitstatusresult.py index 3247b0b44..020c6ad4d 100644 --- a/src/cribl_control_plane/models/countedgitstatusresult.py +++ b/src/cribl_control_plane/models/countedgitstatusresult.py @@ -9,14 +9,14 @@ class CountedGitStatusResultTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitStatusResultTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedGitStatusResult(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[GitStatusResult] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedinputresponse.py b/src/cribl_control_plane/models/countedinputresponse.py index 590680ac8..207f076d6 100644 --- a/src/cribl_control_plane/models/countedinputresponse.py +++ b/src/cribl_control_plane/models/countedinputresponse.py @@ -9,14 +9,14 @@ class CountedInputResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[InputResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedInputResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[InputResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedinputsplunkhec.py b/src/cribl_control_plane/models/countedinputsplunkhec.py index 7de4bdb18..3807ca892 100644 --- a/src/cribl_control_plane/models/countedinputsplunkhec.py +++ b/src/cribl_control_plane/models/countedinputsplunkhec.py @@ -9,14 +9,14 @@ class CountedInputSplunkHecTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[InputSplunkHecTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedInputSplunkHec(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[InputSplunkHec] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedinputstatus.py b/src/cribl_control_plane/models/countedinputstatus.py index 10adbd50f..f3bd0a3e1 100644 --- a/src/cribl_control_plane/models/countedinputstatus.py +++ b/src/cribl_control_plane/models/countedinputstatus.py @@ -9,14 +9,14 @@ class CountedInputStatusTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[InputStatusTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedInputStatus(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[InputStatus] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedjobinfo.py b/src/cribl_control_plane/models/countedjobinfo.py index 4e5963540..1ed7f6a69 100644 --- a/src/cribl_control_plane/models/countedjobinfo.py +++ b/src/cribl_control_plane/models/countedjobinfo.py @@ -9,14 +9,14 @@ class CountedJobInfoTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[JobInfoTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedJobInfo(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[JobInfo] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedmasterworkerentry.py b/src/cribl_control_plane/models/countedmasterworkerentry.py index 67745d57d..70056e829 100644 --- a/src/cribl_control_plane/models/countedmasterworkerentry.py +++ b/src/cribl_control_plane/models/countedmasterworkerentry.py @@ -9,14 +9,14 @@ class CountedMasterWorkerEntryTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[MasterWorkerEntryTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedMasterWorkerEntry(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[MasterWorkerEntry] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countednumber.py b/src/cribl_control_plane/models/countednumber.py index 1f02fc1ec..bb7c9e372 100644 --- a/src/cribl_control_plane/models/countednumber.py +++ b/src/cribl_control_plane/models/countednumber.py @@ -8,14 +8,14 @@ class CountedNumberTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[float] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedNumber(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[float] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedoutputresponse.py b/src/cribl_control_plane/models/countedoutputresponse.py index c93368e43..56cae71b5 100644 --- a/src/cribl_control_plane/models/countedoutputresponse.py +++ b/src/cribl_control_plane/models/countedoutputresponse.py @@ -9,14 +9,14 @@ class CountedOutputResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedOutputResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedoutputsamplesresponse.py b/src/cribl_control_plane/models/countedoutputsamplesresponse.py index 2d2b69ced..7bb206047 100644 --- a/src/cribl_control_plane/models/countedoutputsamplesresponse.py +++ b/src/cribl_control_plane/models/countedoutputsamplesresponse.py @@ -9,14 +9,14 @@ class CountedOutputSamplesResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputSamplesResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedOutputSamplesResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputSamplesResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedoutputstatus.py b/src/cribl_control_plane/models/countedoutputstatus.py index 680532f35..d90ef0bfd 100644 --- a/src/cribl_control_plane/models/countedoutputstatus.py +++ b/src/cribl_control_plane/models/countedoutputstatus.py @@ -9,14 +9,14 @@ class CountedOutputStatusTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputStatusTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedOutputStatus(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputStatus] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedoutputtestresponse.py b/src/cribl_control_plane/models/countedoutputtestresponse.py index e63d095fe..6f11bc241 100644 --- a/src/cribl_control_plane/models/countedoutputtestresponse.py +++ b/src/cribl_control_plane/models/countedoutputtestresponse.py @@ -9,14 +9,14 @@ class CountedOutputTestResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputTestResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedOutputTestResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[OutputTestResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedpackinfo.py b/src/cribl_control_plane/models/countedpackinfo.py index c11a6cfae..6a452c404 100644 --- a/src/cribl_control_plane/models/countedpackinfo.py +++ b/src/cribl_control_plane/models/countedpackinfo.py @@ -9,14 +9,14 @@ class CountedPackInfoTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[PackInfoTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedPackInfo(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[PackInfo] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedpackinstallinfo.py b/src/cribl_control_plane/models/countedpackinstallinfo.py index 9154d4520..adb1437b8 100644 --- a/src/cribl_control_plane/models/countedpackinstallinfo.py +++ b/src/cribl_control_plane/models/countedpackinstallinfo.py @@ -9,14 +9,14 @@ class CountedPackInstallInfoTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[PackInstallInfoTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedPackInstallInfo(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[PackInstallInfo] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedpackuninstallinfo.py b/src/cribl_control_plane/models/countedpackuninstallinfo.py index ce7660931..e44e3469a 100644 --- a/src/cribl_control_plane/models/countedpackuninstallinfo.py +++ b/src/cribl_control_plane/models/countedpackuninstallinfo.py @@ -9,14 +9,14 @@ class CountedPackUninstallInfoTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[PackUninstallInfoTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedPackUninstallInfo(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[PackUninstallInfo] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedpipeline.py b/src/cribl_control_plane/models/countedpipeline.py index 9c8f32823..72c281886 100644 --- a/src/cribl_control_plane/models/countedpipeline.py +++ b/src/cribl_control_plane/models/countedpipeline.py @@ -9,14 +9,14 @@ class CountedPipelineTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[PipelineTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedPipeline(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[Pipeline] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedrestartresponse.py b/src/cribl_control_plane/models/countedrestartresponse.py index 044c5281b..87d927d2e 100644 --- a/src/cribl_control_plane/models/countedrestartresponse.py +++ b/src/cribl_control_plane/models/countedrestartresponse.py @@ -9,14 +9,14 @@ class CountedRestartResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[RestartResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedRestartResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[RestartResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedroutes.py b/src/cribl_control_plane/models/countedroutes.py index c5145245d..99327414a 100644 --- a/src/cribl_control_plane/models/countedroutes.py +++ b/src/cribl_control_plane/models/countedroutes.py @@ -9,14 +9,14 @@ class CountedRoutesTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[RoutesTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedRoutes(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[Routes] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedsavedjobresponse.py b/src/cribl_control_plane/models/countedsavedjobresponse.py index 2a05c6ebe..f094ebda1 100644 --- a/src/cribl_control_plane/models/countedsavedjobresponse.py +++ b/src/cribl_control_plane/models/countedsavedjobresponse.py @@ -9,14 +9,14 @@ class CountedSavedJobResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SavedJobResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedSavedJobResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SavedJobResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedstring.py b/src/cribl_control_plane/models/countedstring.py index a7c6d80a5..3c80f462c 100644 --- a/src/cribl_control_plane/models/countedstring.py +++ b/src/cribl_control_plane/models/countedstring.py @@ -8,14 +8,14 @@ class CountedStringTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[str] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedString(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[str] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedsystemrestartresponse.py b/src/cribl_control_plane/models/countedsystemrestartresponse.py index fd5b65324..ebfe4aa41 100644 --- a/src/cribl_control_plane/models/countedsystemrestartresponse.py +++ b/src/cribl_control_plane/models/countedsystemrestartresponse.py @@ -9,14 +9,14 @@ class CountedSystemRestartResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SystemRestartResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedSystemRestartResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SystemRestartResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedsystemsettingsconf.py b/src/cribl_control_plane/models/countedsystemsettingsconf.py index 5cb269f10..20c2985d0 100644 --- a/src/cribl_control_plane/models/countedsystemsettingsconf.py +++ b/src/cribl_control_plane/models/countedsystemsettingsconf.py @@ -9,14 +9,14 @@ class CountedSystemSettingsConfTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SystemSettingsConfTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedSystemSettingsConf(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SystemSettingsConf] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedsystemsettingsconfresponse.py b/src/cribl_control_plane/models/countedsystemsettingsconfresponse.py index 720730782..01d04638f 100644 --- a/src/cribl_control_plane/models/countedsystemsettingsconfresponse.py +++ b/src/cribl_control_plane/models/countedsystemsettingsconfresponse.py @@ -12,14 +12,14 @@ class CountedSystemSettingsConfResponseTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SystemSettingsConfResponseTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedSystemSettingsConfResponse(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[SystemSettingsConfResponse] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/countedteamaccesscontrollist.py b/src/cribl_control_plane/models/countedteamaccesscontrollist.py index 0d7cdba5d..eba04e36b 100644 --- a/src/cribl_control_plane/models/countedteamaccesscontrollist.py +++ b/src/cribl_control_plane/models/countedteamaccesscontrollist.py @@ -9,14 +9,14 @@ class CountedTeamAccessControlListTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[TeamAccessControlListTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedTeamAccessControlList(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[TeamAccessControlList] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/counteduseraccesscontrollist.py b/src/cribl_control_plane/models/counteduseraccesscontrollist.py index 9dc02dd25..6686ded3c 100644 --- a/src/cribl_control_plane/models/counteduseraccesscontrollist.py +++ b/src/cribl_control_plane/models/counteduseraccesscontrollist.py @@ -9,14 +9,14 @@ class CountedUserAccessControlListTypedDict(TypedDict): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[UserAccessControlListTypedDict] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" class CountedUserAccessControlList(BaseModel): count: int - r"""number of items present in the items array""" + r"""Number of items returned in the items array.""" items: List[UserAccessControlList] - r"""List of items in this response.""" + r"""The list of items returned in this response.""" diff --git a/src/cribl_control_plane/models/createcribllakedatasetbylakeidop.py b/src/cribl_control_plane/models/createcribllakedatasetbylakeidop.py index 7dfe7cee2..4adaaad17 100644 --- a/src/cribl_control_plane/models/createcribllakedatasetbylakeidop.py +++ b/src/cribl_control_plane/models/createcribllakedatasetbylakeidop.py @@ -10,7 +10,7 @@ class CreateCriblLakeDatasetByLakeIDRequestTypedDict(TypedDict): lake_id: str - r"""The id of the Lake to create the Lake Dataset in.""" + r"""The id of the Lake to create the Lake Datasets in.""" cribl_lake_dataset: CriblLakeDatasetTypedDict r"""CriblLakeDataset object.""" @@ -21,7 +21,7 @@ class CreateCriblLakeDatasetByLakeIDRequest(BaseModel): pydantic.Field(alias="lakeId"), FieldMetadata(path=PathParamMetadata(style="simple", explode=False)), ] - r"""The id of the Lake to create the Lake Dataset in.""" + r"""The id of the Lake to create the Lake Datasets in.""" cribl_lake_dataset: Annotated[ CriblLakeDataset, diff --git a/src/cribl_control_plane/models/createinput_input.py b/src/cribl_control_plane/models/createinput_input.py index cc28599a3..cb25ab96b 100644 --- a/src/cribl_control_plane/models/createinput_input.py +++ b/src/cribl_control_plane/models/createinput_input.py @@ -2,48 +2,32 @@ from __future__ import annotations from .authenticationmethodoptions import AuthenticationMethodOptions -from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) -from .authenticationmethodoptionsmanualsecret import ( - AuthenticationMethodOptionsManualSecret, +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, ) from .authenticationmethodoptionss3collectorconf import ( AuthenticationMethodOptionsS3CollectorConf, ) -from .authenticationmethodoptionssasl import AuthenticationMethodOptionsSasl from .authenticationtype import AuthenticationType, AuthenticationTypeTypedDict -from .authenticationtypeoptionslokiauth import AuthenticationTypeOptionsLokiAuth -from .authenticationtypeoptionsprometheusauth import ( - AuthenticationTypeOptionsPrometheusAuth, -) -from .authenticationtypeuse import AuthenticationTypeUse, AuthenticationTypeUseTypedDict -from .authtokenconfinputcribltcp import ( - AuthTokenConfInputCriblTCP, - AuthTokenConfInputCriblTCPTypedDict, -) -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, -) from .certificatetype import CertificateType, CertificateTypeTypedDict -from .certoptionstype import CertOptionsType, CertOptionsTypeTypedDict from .connectionconfinputcollection import ( ConnectionConfInputCollection, ConnectionConfInputCollectionTypedDict, ) -from .createinput_inputkubemetrics import ( - CreateInputInputAnthropicCompliance, - CreateInputInputAnthropicComplianceTypedDict, - CreateInputInputAppleUnifiedLogs, - CreateInputInputAppleUnifiedLogsTypedDict, - CreateInputInputAppscope, - CreateInputInputAppscopeTypedDict, - CreateInputInputBedrockS3, - CreateInputInputBedrockS3TypedDict, - CreateInputInputCloudflareHec, - CreateInputInputCloudflareHecTypedDict, +from .createinput_inputelastic_type import ( + CreateInputInputConfluentCloud, + CreateInputInputConfluentCloudTypedDict, + CreateInputInputCribl, + CreateInputInputCriblHTTP, + CreateInputInputCriblHTTPTypedDict, + CreateInputInputCriblLakeHTTP, + CreateInputInputCriblLakeHTTPTypedDict, + CreateInputInputCriblTCP, + CreateInputInputCriblTCPTypedDict, + CreateInputInputCriblTypedDict, CreateInputInputCriblmetrics, CreateInputInputCriblmetricsTypedDict, CreateInputInputCrowdstrike, @@ -52,12 +36,23 @@ CreateInputInputDatadogAgentTypedDict, CreateInputInputDatagen, CreateInputInputDatagenTypedDict, - CreateInputInputFile, - CreateInputInputFileTypedDict, + CreateInputInputEdgePrometheus, + CreateInputInputEdgePrometheusTypedDict, + CreateInputInputElasticType, + CreateInputInputEventhub, + CreateInputInputEventhubAmqp, + CreateInputInputEventhubAmqpTypedDict, + CreateInputInputEventhubTypedDict, + CreateInputInputExec, + CreateInputInputExecTypedDict, + CreateInputInputFirehose, + CreateInputInputFirehoseTypedDict, + CreateInputInputGooglePubsub, + CreateInputInputGooglePubsubTypedDict, + CreateInputInputGrafanaUnion, + CreateInputInputGrafanaUnionTypedDict, CreateInputInputHTTPRaw, CreateInputInputHTTPRawTypedDict, - CreateInputInputJournalFiles, - CreateInputInputJournalFilesTypedDict, CreateInputInputKinesis, CreateInputInputKinesisTypedDict, CreateInputInputKubeEvents, @@ -66,8 +61,72 @@ CreateInputInputKubeLogsTypedDict, CreateInputInputKubeMetrics, CreateInputInputKubeMetricsTypedDict, + CreateInputInputLoki, + CreateInputInputLokiTypedDict, CreateInputInputMetrics, CreateInputInputMetricsTypedDict, + CreateInputInputMicrosoftGraph, + CreateInputInputMicrosoftGraphTypedDict, + CreateInputInputOffice365Mgmt, + CreateInputInputOffice365MgmtTypedDict, + CreateInputInputOffice365MsgTrace, + CreateInputInputOffice365MsgTraceTypedDict, + CreateInputInputOffice365Service, + CreateInputInputOffice365ServiceTypedDict, + CreateInputInputPrometheus, + CreateInputInputPrometheusRw, + CreateInputInputPrometheusRwTypedDict, + CreateInputInputPrometheusTypedDict, + CreateInputInputS3, + CreateInputInputS3Inventory, + CreateInputInputS3InventoryTypedDict, + CreateInputInputS3TypedDict, + CreateInputInputSnmp, + CreateInputInputSnmpTypedDict, + CreateInputInputSystemMetrics, + CreateInputInputSystemMetricsTypedDict, + CreateInputInputSystemState, + CreateInputInputSystemStateTypedDict, + CreateInputInputTcpjson, + CreateInputInputTcpjsonTypedDict, + CreateInputInputWindowsMetrics, + CreateInputInputWindowsMetricsTypedDict, +) +from .createinput_v3user import ( + CreateInputInputAkamaiHec, + CreateInputInputAkamaiHecTypedDict, + CreateInputInputAnthropicCompliance, + CreateInputInputAnthropicComplianceTypedDict, + CreateInputInputAnthropicEnterpriseAnalytics, + CreateInputInputAnthropicEnterpriseAnalyticsTypedDict, + CreateInputInputAppleUnifiedLogs, + CreateInputInputAppleUnifiedLogsTypedDict, + CreateInputInputAppscope, + CreateInputInputAppscopeTypedDict, + CreateInputInputAquaSecurityHec, + CreateInputInputAquaSecurityHecTypedDict, + CreateInputInputBedrockS3, + CreateInputInputBedrockS3TypedDict, + CreateInputInputBeyondtrustHec, + CreateInputInputBeyondtrustHecTypedDict, + CreateInputInputCloudflareHec, + CreateInputInputCloudflareHecTypedDict, + CreateInputInputExtrahopRevealx360, + CreateInputInputExtrahopRevealx360TypedDict, + CreateInputInputF5BigIP, + CreateInputInputF5BigIPTypedDict, + CreateInputInputFile, + CreateInputInputFileTypedDict, + CreateInputInputGigamonHec, + CreateInputInputGigamonHecTypedDict, + CreateInputInputHashicorpHcpVaultDedicated, + CreateInputInputHashicorpHcpVaultDedicatedTypedDict, + CreateInputInputJournalFiles, + CreateInputInputJournalFilesTypedDict, + CreateInputInputMicrosoftCopilot, + CreateInputInputMicrosoftCopilotTypedDict, + CreateInputInputMimecastHec, + CreateInputInputMimecastHecTypedDict, CreateInputInputModelDrivenTelemetry, CreateInputInputModelDrivenTelemetryTypedDict, CreateInputInputNetflow, @@ -80,18 +139,18 @@ CreateInputInputOpenaiComplianceLogs, CreateInputInputOpenaiComplianceLogsTypedDict, CreateInputInputOpenaiTypedDict, + CreateInputInputPingIdentityPingone, + CreateInputInputPingIdentityPingoneTypedDict, + CreateInputInputProofpointPod, + CreateInputInputProofpointPodTypedDict, CreateInputInputRawUDP, CreateInputInputRawUDPTypedDict, - CreateInputInputS3, - CreateInputInputS3Inventory, - CreateInputInputS3InventoryTypedDict, - CreateInputInputS3TypedDict, + CreateInputInputSailpointHec, + CreateInputInputSailpointHecTypedDict, CreateInputInputSecurityLake, CreateInputInputSecurityLakeTypedDict, CreateInputInputServicenowTable, CreateInputInputServicenowTableTypedDict, - CreateInputInputSnmp, - CreateInputInputSnmpTypedDict, CreateInputInputSqs, CreateInputInputSqsTypedDict, CreateInputInputSysdigHec, @@ -100,14 +159,18 @@ CreateInputInputSyslogUnionTypedDict, CreateInputInputTCP, CreateInputInputTCPTypedDict, + CreateInputInputTrellixHec, + CreateInputInputTrellixHecTypedDict, + CreateInputInputTrendMicroVisionOne, + CreateInputInputTrendMicroVisionOneTypedDict, CreateInputInputUpwindHec, CreateInputInputUpwindHecTypedDict, + CreateInputInputVectraAiHec, + CreateInputInputVectraAiHecTypedDict, CreateInputInputWef, CreateInputInputWefTypedDict, CreateInputInputWinEventLogs, CreateInputInputWinEventLogsTypedDict, - CreateInputInputWindowsMetrics, - CreateInputInputWindowsMetricsTypedDict, CreateInputInputWiz, CreateInputInputWizTypedDict, CreateInputInputWizWebhook, @@ -115,55 +178,22 @@ CreateInputInputZscalerHec, CreateInputInputZscalerHecTypedDict, ) -from .datacompressionformatoptionspersistence import ( - DataCompressionFormatOptionsPersistence, -) -from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict from .extrahttpheaderconfinputelastic import ( ExtraHTTPHeaderConfInputElastic, ExtraHTTPHeaderConfInputElasticTypedDict, ) -from .googleauthenticationmethodoptions import GoogleAuthenticationMethodOptions -from .gputype import GpuType, GpuTypeTypedDict from .kafkaschemaregistryauthenticationtype import ( KafkaSchemaRegistryAuthenticationType, KafkaSchemaRegistryAuthenticationTypeTypedDict, ) -from .logleveloptions import LogLevelOptions -from .logleveloptionscontentconfigitems import LogLevelOptionsContentConfigItems -from .logleveloptionsdebugerror import LogLevelOptionsDebugError from .metadataconfinputcollection import ( MetadataConfInputCollection, MetadataConfInputCollectionTypedDict, ) -from .microsoftentraidauthenticationendpointoptionssasl import ( - MicrosoftEntraIDAuthenticationEndpointOptionsSasl, -) -from .modeoptionshost import ModeOptionsHost from .outputmodeoptionssplunkcollectorconf import OutputModeOptionsSplunkCollectorConf from .pqtype import PqType, PqTypeTypedDict from .preprocesstype import PreprocessType, PreprocessTypeTypedDict -from .processtype import ProcessType, ProcessTypeTypedDict -from .protocoloptionstargetsitems import ProtocolOptionsTargetsItems -from .recordtypeoptions import RecordTypeOptions -from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( - RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, - RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, -) from .retryrulestype import RetryRulesType, RetryRulesTypeTypedDict -from .retryrulestypecodesenableheader import ( - RetryRulesTypeCodesEnableHeader, - RetryRulesTypeCodesEnableHeaderTypedDict, -) -from .searchfilterconfinputprometheus import ( - SearchFilterConfInputPrometheus, - SearchFilterConfInputPrometheusTypedDict, -) -from .subscriptionplanoptions import SubscriptionPlanOptions -from .tlssettingsclientsidetype import ( - TLSSettingsClientSideType, - TLSSettingsClientSideTypeTypedDict, -) from .tlssettingsclientsidetypecapathcertpath import ( TLSSettingsClientSideTypeCaPathCertPath, TLSSettingsClientSideTypeCaPathCertPathTypedDict, @@ -174,13 +204,8 @@ ) from .typeoptions import TypeOptions from .typeoptionsazureblob import TypeOptionsAzureblob -from .typeoptionsconfluentcloud import TypeOptionsConfluentcloud -from .typeoptionscribltcp import TypeOptionsCribltcp -from .typeoptionsgooglepubsub import TypeOptionsGooglepubsub from .typeoptionsmsk import TypeOptionsMsk -from .typeoptionsprometheus import TypeOptionsPrometheus from .typeoptionssplunk import TypeOptionsSplunk -from .typeoptionstcpjson import TypeOptionsTcpjson from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from cribl_control_plane.utils import get_discriminator @@ -191,178 +216,131 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict -class CreateInputInputSystemStateType(str, Enum): - r"""Connector type identifier.""" - - SYSTEM_STATE = "system_state" - - -class CreateInputHostsFileTypedDict(TypedDict): - r"""Creates events based on entries collected from the hosts file""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputHostsFile(BaseModel): - r"""Creates events based on entries collected from the hosts file""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInterfacesTypedDict(TypedDict): - r"""Creates events for each of the host’s network interfaces""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputInterfaces(BaseModel): - r"""Creates events for each of the host’s network interfaces""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputDisksAndFileSystemsTypedDict(TypedDict): - r"""Creates events for physical disks, partitions, and file systems""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputDisksAndFileSystems(BaseModel): - r"""Creates events for physical disks, partitions, and file systems""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputHostInfoTypedDict(TypedDict): - r"""Creates events based on the host system’s current state""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputHostInfo(BaseModel): - r"""Creates events based on the host system’s current state""" +class CreateInputInputElasticAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" - enable: Optional[bool] = None - r"""Enabled""" + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Auth Tokens + AUTH_TOKENS = "authTokens" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateInputAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The API version to use for communicating with the server""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + # 6.8.4 + SIX_DOT_8_DOT_4 = "6.8.4" + # 8.3.2 + EIGHT_DOT_3_DOT_2 = "8.3.2" + # Custom + CUSTOM = "custom" - return m +class CreateInputInputElasticAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter credentials directly, or select a stored secret""" -class CreateInputRoutesTypedDict(TypedDict): - r"""Creates events based on entries collected from the host’s network routes""" + NONE = "none" + MANUAL = "manual" + SECRET = "secret" - enable: NotRequired[bool] - r"""Enabled""" +class CreateInputInputElasticProxyModeTypedDict(TypedDict): + enabled: bool + r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" + auth_type: NotRequired[CreateInputInputElasticAuthenticationMethod] + r"""Enter credentials directly, or select a stored secret""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + url: NotRequired[str] + r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + remove_headers: NotRequired[List[str]] + r"""List of headers to remove from the request to proxy""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateInputRoutes(BaseModel): - r"""Creates events based on entries collected from the host’s network routes""" - enable: Optional[bool] = None - r"""Enabled""" +class CreateInputInputElasticProxyMode(BaseModel): + enabled: bool + r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} + auth_type: Annotated[ + Optional[CreateInputInputElasticAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter credentials directly, or select a stored secret""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + username: Optional[str] = None + r"""Username""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + password: Optional[str] = None + r"""Password""" - return m + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + url: Optional[str] = None + r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" -class CreateInputDNSTypedDict(TypedDict): - r"""Creates events for DNS resolvers and search entries""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - enable: NotRequired[bool] - r"""Enabled""" + remove_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="removeHeaders") + ] = None + r"""List of headers to remove from the request to proxy""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" -class CreateInputDNS(BaseModel): - r"""Creates events for DNS resolvers and search entries""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - enable: Optional[bool] = None - r"""Enabled""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputElasticAuthenticationMethod(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["enable"]) + optional_fields = set( + [ + "authType", + "username", + "password", + "credentialsSecret", + "url", + "rejectUnauthorized", + "removeHeaders", + "timeoutSec", + "__template_url", + ] + ) serialized = handler(self) m = {} @@ -377,322 +355,17 @@ def serialize_model(self, handler): return m -class CreateInputUsersAndGroupsTypedDict(TypedDict): - r"""Creates events for local users and groups""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputUsersAndGroups(BaseModel): - r"""Creates events for local users and groups""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputFirewallTypedDict(TypedDict): - r"""Creates events for Firewall rules entries""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputFirewall(BaseModel): - r"""Creates events for Firewall rules entries""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputServicesTypedDict(TypedDict): - r"""Creates events from the list of services""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputServices(BaseModel): - r"""Creates events from the list of services""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputListeningPortsTypedDict(TypedDict): - r"""Creates events from list of listening ports""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputListeningPorts(BaseModel): - r"""Creates events from list of listening ports""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputLoggedInUsersTypedDict(TypedDict): - r"""Creates events from list of logged-in users""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputLoggedInUsers(BaseModel): - r"""Creates events from list of logged-in users""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputCollectorsTypedDict(TypedDict): - hostsfile: NotRequired[CreateInputHostsFileTypedDict] - r"""Creates events based on entries collected from the hosts file""" - interfaces: NotRequired[CreateInputInterfacesTypedDict] - r"""Creates events for each of the host’s network interfaces""" - disk: NotRequired[CreateInputDisksAndFileSystemsTypedDict] - r"""Creates events for physical disks, partitions, and file systems""" - metadata: NotRequired[CreateInputHostInfoTypedDict] - r"""Creates events based on the host system’s current state""" - routes: NotRequired[CreateInputRoutesTypedDict] - r"""Creates events based on entries collected from the host’s network routes""" - dns: NotRequired[CreateInputDNSTypedDict] - r"""Creates events for DNS resolvers and search entries""" - user: NotRequired[CreateInputUsersAndGroupsTypedDict] - r"""Creates events for local users and groups""" - firewall: NotRequired[CreateInputFirewallTypedDict] - r"""Creates events for Firewall rules entries""" - services: NotRequired[CreateInputServicesTypedDict] - r"""Creates events from the list of services""" - ports: NotRequired[CreateInputListeningPortsTypedDict] - r"""Creates events from list of listening ports""" - login_users: NotRequired[CreateInputLoggedInUsersTypedDict] - r"""Creates events from list of logged-in users""" - - -class CreateInputCollectors(BaseModel): - hostsfile: Optional[CreateInputHostsFile] = None - r"""Creates events based on entries collected from the hosts file""" - - interfaces: Optional[CreateInputInterfaces] = None - r"""Creates events for each of the host’s network interfaces""" - - disk: Optional[CreateInputDisksAndFileSystems] = None - r"""Creates events for physical disks, partitions, and file systems""" - - metadata: Optional[CreateInputHostInfo] = None - r"""Creates events based on the host system’s current state""" - - routes: Optional[CreateInputRoutes] = None - r"""Creates events based on entries collected from the host’s network routes""" - - dns: Optional[CreateInputDNS] = None - r"""Creates events for DNS resolvers and search entries""" - - user: Optional[CreateInputUsersAndGroups] = None - r"""Creates events for local users and groups""" - - firewall: Optional[CreateInputFirewall] = None - r"""Creates events for Firewall rules entries""" - - services: Optional[CreateInputServices] = None - r"""Creates events from the list of services""" - - ports: Optional[CreateInputListeningPorts] = None - r"""Creates events from list of listening ports""" - - login_users: Annotated[ - Optional[CreateInputLoggedInUsers], pydantic.Field(alias="loginUsers") - ] = None - r"""Creates events from list of logged-in users""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "hostsfile", - "interfaces", - "disk", - "metadata", - "routes", - "dns", - "user", - "firewall", - "services", - "ports", - "loginUsers", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemStatePersistenceTypedDict(TypedDict): - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" - - -class CreateInputInputSystemStatePersistence(BaseModel): - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemStateTypedDict(TypedDict): +class CreateInputInputElasticTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputSystemStateType - r"""Connector type identifier.""" + type: CreateInputInputElasticType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + elastic_api: str + r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -708,30 +381,80 @@ class CreateInputInputSystemStateTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[CreateInputInputElasticAuthenticationType] + r"""Authentication type""" + api_version: NotRequired[CreateInputAPIVersion] + r"""The API version to use for communicating with the server""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - collectors: NotRequired[CreateInputCollectorsTypedDict] - persistence: NotRequired[CreateInputInputSystemStatePersistenceTypedDict] - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" - disable_native_last_log_module: NotRequired[bool] - r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + proxy_mode: NotRequired[CreateInputInputElasticProxyModeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + auth_tokens: NotRequired[List[str]] + r"""Bearer tokens to include in the authorization header""" + custom_api_version: NotRequired[str] + r"""Custom version information to respond to requests""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_elastic_api: NotRequired[str] + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" -class CreateInputInputSystemState(BaseModel): +class CreateInputInputElastic(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputSystemStateType - r"""Connector type identifier.""" + type: CreateInputInputElasticType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + elastic_api: Annotated[str, pydantic.Field(alias="elasticAPI")] + r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -758,8066 +481,90 @@ class CreateInputInputSystemState(BaseModel): pq: Optional[PqType] = None - interval: Optional[float] = None - r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - collectors: Optional[CreateInputCollectors] = None + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - persistence: Optional[CreateInputInputSystemStatePersistence] = None + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - disable_native_last_log_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeLastLogModule") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "interval", - "metadata", - "collectors", - "persistence", - "disableNativeModule", - "disableNativeLastLogModule", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsType(str, Enum): - r"""Connector type identifier.""" - - SYSTEM_METRICS = "system_metrics" - - -class CreateInputInputSystemMetricsSystemMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for system metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputInputSystemMetricsSystemTypedDict(TypedDict): - mode: NotRequired[CreateInputInputSystemMetricsSystemMode] - r"""Select the level of detail for system metrics""" - processes: NotRequired[bool] - r"""Generate metrics for the numbers of processes in various states""" - - -class CreateInputInputSystemMetricsSystem(BaseModel): - mode: Optional[CreateInputInputSystemMetricsSystemMode] = None - r"""Select the level of detail for system metrics""" - - processes: Optional[bool] = None - r"""Generate metrics for the numbers of processes in various states""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputSystemMetricsSystemMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "processes"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for CPU metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputInputSystemMetricsCPUTypedDict(TypedDict): - mode: NotRequired[CreateInputInputSystemMetricsCPUMode] - r"""Select the level of detail for CPU metrics""" - per_cpu: NotRequired[bool] - r"""Generate metrics for each CPU""" - detail: NotRequired[bool] - r"""Generate metrics for all CPU states""" - time: NotRequired[bool] - r"""Generate raw, monotonic CPU time counters""" - - -class CreateInputInputSystemMetricsCPU(BaseModel): - mode: Optional[CreateInputInputSystemMetricsCPUMode] = None - r"""Select the level of detail for CPU metrics""" - - per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None - r"""Generate metrics for each CPU""" - - detail: Optional[bool] = None - r"""Generate metrics for all CPU states""" - - time: Optional[bool] = None - r"""Generate raw, monotonic CPU time counters""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputSystemMetricsCPUMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perCpu", "detail", "time"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsMemoryMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for memory metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputInputSystemMetricsMemoryTypedDict(TypedDict): - mode: NotRequired[CreateInputInputSystemMetricsMemoryMode] - r"""Select the level of detail for memory metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all memory states""" - - -class CreateInputInputSystemMetricsMemory(BaseModel): - mode: Optional[CreateInputInputSystemMetricsMemoryMode] = None - r"""Select the level of detail for memory metrics""" - - detail: Optional[bool] = None - r"""Generate metrics for all memory states""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputSystemMetricsMemoryMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsNetworkMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for network metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputInputSystemMetricsNetworkTypedDict(TypedDict): - mode: NotRequired[CreateInputInputSystemMetricsNetworkMode] - r"""Select the level of detail for network metrics""" - detail: NotRequired[bool] - r"""Generate full network metrics""" - protocols: NotRequired[bool] - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - devices: NotRequired[List[str]] - r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" - per_interface: NotRequired[bool] - r"""Generate separate metrics for each interface""" - - -class CreateInputInputSystemMetricsNetwork(BaseModel): - mode: Optional[CreateInputInputSystemMetricsNetworkMode] = None - r"""Select the level of detail for network metrics""" - - detail: Optional[bool] = None - r"""Generate full network metrics""" - - protocols: Optional[bool] = None - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - - devices: Optional[List[str]] = None - r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" - - per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( - None - ) - r"""Generate separate metrics for each interface""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputSystemMetricsNetworkMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["mode", "detail", "protocols", "devices", "perInterface"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for disk metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputInputSystemMetricsDiskTypedDict(TypedDict): - mode: NotRequired[CreateInputInputSystemMetricsDiskMode] - r"""Select the level of detail for disk metrics""" - detail: NotRequired[bool] - r"""Generate full disk metrics""" - inodes: NotRequired[bool] - r"""Generate filesystem inode metrics""" - devices: NotRequired[List[str]] - r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" - mountpoints: NotRequired[List[str]] - r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" - fstypes: NotRequired[List[str]] - r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" - per_device: NotRequired[bool] - r"""Generate separate metrics for each device""" - - -class CreateInputInputSystemMetricsDisk(BaseModel): - mode: Optional[CreateInputInputSystemMetricsDiskMode] = None - r"""Select the level of detail for disk metrics""" - - detail: Optional[bool] = None - r"""Generate full disk metrics""" - - inodes: Optional[bool] = None - r"""Generate filesystem inode metrics""" - - devices: Optional[List[str]] = None - r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" - - mountpoints: Optional[List[str]] = None - r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" - - fstypes: Optional[List[str]] = None - r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" - - per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None - r"""Generate separate metrics for each device""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputSystemMetricsDiskMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mode", - "detail", - "inodes", - "devices", - "mountpoints", - "fstypes", - "perDevice", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsCustomTypedDict(TypedDict): - system: NotRequired[CreateInputInputSystemMetricsSystemTypedDict] - cpu: NotRequired[CreateInputInputSystemMetricsCPUTypedDict] - memory: NotRequired[CreateInputInputSystemMetricsMemoryTypedDict] - network: NotRequired[CreateInputInputSystemMetricsNetworkTypedDict] - disk: NotRequired[CreateInputInputSystemMetricsDiskTypedDict] - - -class CreateInputInputSystemMetricsCustom(BaseModel): - system: Optional[CreateInputInputSystemMetricsSystem] = None - - cpu: Optional[CreateInputInputSystemMetricsCPU] = None - - memory: Optional[CreateInputInputSystemMetricsMemory] = None - - network: Optional[CreateInputInputSystemMetricsNetwork] = None - - disk: Optional[CreateInputInputSystemMetricsDisk] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["system", "cpu", "memory", "network", "disk"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsHostTypedDict(TypedDict): - mode: NotRequired[ModeOptionsHost] - r"""Select level of detail for host metrics""" - custom: NotRequired[CreateInputInputSystemMetricsCustomTypedDict] - - -class CreateInputInputSystemMetricsHost(BaseModel): - mode: Optional[ModeOptionsHost] = None - r"""Select level of detail for host metrics""" - - custom: Optional[CreateInputInputSystemMetricsCustom] = None - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptionsHost(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "custom"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputContainerMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for container metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputInputSystemMetricsFilterTypedDict(TypedDict): - expr: str - r"""Expression""" - - -class CreateInputInputSystemMetricsFilter(BaseModel): - expr: str - r"""Expression""" - - -class CreateInputContainerTypedDict(TypedDict): - mode: NotRequired[CreateInputContainerMode] - r"""Select the level of detail for container metrics""" - docker_socket: NotRequired[List[str]] - r"""Full paths for Docker's UNIX-domain socket""" - docker_timeout: NotRequired[float] - r"""Timeout, in seconds, for the Docker API""" - filters: NotRequired[List[CreateInputInputSystemMetricsFilterTypedDict]] - r"""Containers matching any of these will be included. All are included if no filters are added.""" - all_containers: NotRequired[bool] - r"""Include stopped and paused containers""" - per_device: NotRequired[bool] - r"""Generate separate metrics for each device""" - detail: NotRequired[bool] - r"""Generate full container metrics""" - - -class CreateInputContainer(BaseModel): - mode: Optional[CreateInputContainerMode] = None - r"""Select the level of detail for container metrics""" - - docker_socket: Annotated[ - Optional[List[str]], pydantic.Field(alias="dockerSocket") - ] = None - r"""Full paths for Docker's UNIX-domain socket""" - - docker_timeout: Annotated[ - Optional[float], pydantic.Field(alias="dockerTimeout") - ] = None - r"""Timeout, in seconds, for the Docker API""" - - filters: Optional[List[CreateInputInputSystemMetricsFilter]] = None - r"""Containers matching any of these will be included. All are included if no filters are added.""" - - all_containers: Annotated[Optional[bool], pydantic.Field(alias="allContainers")] = ( - None - ) - r"""Include stopped and paused containers""" - - per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None - r"""Generate separate metrics for each device""" - - detail: Optional[bool] = None - r"""Generate full container metrics""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputContainerMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mode", - "dockerSocket", - "dockerTimeout", - "filters", - "allContainers", - "perDevice", - "detail", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" - - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" - - -class CreateInputInputSystemMetricsPersistence(BaseModel): - r"""persistence""" - - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputSystemMetricsTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputSystemMetricsType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - host: NotRequired[CreateInputInputSystemMetricsHostTypedDict] - process: NotRequired[ProcessTypeTypedDict] - container: NotRequired[CreateInputContainerTypedDict] - gpu: NotRequired[GpuTypeTypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - persistence: NotRequired[CreateInputInputSystemMetricsPersistenceTypedDict] - r"""persistence""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputInputSystemMetrics(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputSystemMetricsType - r"""Connector type identifier.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - - host: Optional[CreateInputInputSystemMetricsHost] = None - - process: Optional[ProcessType] = None - - container: Optional[CreateInputContainer] = None - - gpu: Optional[GpuType] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - persistence: Optional[CreateInputInputSystemMetricsPersistence] = None - r"""persistence""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "interval", - "host", - "process", - "container", - "gpu", - "metadata", - "persistence", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputTcpjsonTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsTcpjson - r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateInputInputTcpjson(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsTcpjson - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") - ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") - ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") - ] = None - r"""Load balance traffic across all Worker Processes""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "enableLoadBalancing", - "authType", - "description", - "authToken", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputCriblLakeHTTPType(str, Enum): - r"""Source type identifier.""" - - CRIBL_LAKE_HTTP = "cribl_lake_http" - - -class CreateInputSplunkHecMetadataTypedDict(TypedDict): - enabled: NotRequired[bool] - r"""When enabled, the token value is available on events as __hecToken""" - default_dataset: NotRequired[str] - allowed_indexes_at_token: NotRequired[List[str]] - - -class CreateInputSplunkHecMetadata(BaseModel): - enabled: Optional[bool] = None - r"""When enabled, the token value is available on events as __hecToken""" - - default_dataset: Annotated[ - Optional[str], pydantic.Field(alias="defaultDataset") - ] = None - - allowed_indexes_at_token: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputElasticsearchMetadataTypedDict(TypedDict): - enabled: NotRequired[bool] - r"""Elasticsearch""" - default_dataset: NotRequired[str] - - -class CreateInputElasticsearchMetadata(BaseModel): - enabled: Optional[bool] = None - r"""Elasticsearch""" - - default_dataset: Annotated[ - Optional[str], pydantic.Field(alias="defaultDataset") - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "defaultDataset"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputAuthTokensExtTypedDict(TypedDict): - token: str - r"""Token""" - description: NotRequired[str] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this token""" - splunk_hec_metadata: NotRequired[CreateInputSplunkHecMetadataTypedDict] - elasticsearch_metadata: NotRequired[CreateInputElasticsearchMetadataTypedDict] - - -class CreateInputAuthTokensExt(BaseModel): - token: str - r"""Token""" - - description: Optional[str] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this token""" - - splunk_hec_metadata: Annotated[ - Optional[CreateInputSplunkHecMetadata], - pydantic.Field(alias="splunkHecMetadata"), - ] = None - - elasticsearch_metadata: Annotated[ - Optional[CreateInputElasticsearchMetadata], - pydantic.Field(alias="elasticsearchMetadata"), - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["description", "metadata", "splunkHecMetadata", "elasticsearchMetadata"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputCriblLakeHTTPTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputCriblLakeHTTPType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - cribl_api: NotRequired[str] - r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" - elastic_api: NotRequired[str] - r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" - splunk_hec_api: NotRequired[str] - r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" - splunk_hec_acks: NotRequired[bool] - r"""Enable Splunk HEC acknowledgements""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[CreateInputAuthTokensExtTypedDict]] - r"""Auth tokens""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_cribl_api: NotRequired[str] - r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" - template_elastic_api: NotRequired[str] - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - template_splunk_hec_api: NotRequired[str] - r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - - -class CreateInputInputCriblLakeHTTP(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputCriblLakeHTTPType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - cribl_api: Annotated[Optional[str], pydantic.Field(alias="criblAPI")] = None - r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" - - elastic_api: Annotated[Optional[str], pydantic.Field(alias="elasticAPI")] = None - r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" - - splunk_hec_api: Annotated[Optional[str], pydantic.Field(alias="splunkHecAPI")] = ( - None - ) - r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" - - splunk_hec_acks: Annotated[ - Optional[bool], pydantic.Field(alias="splunkHecAcks") - ] = None - r"""Enable Splunk HEC acknowledgements""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_tokens_ext: Annotated[ - Optional[List[CreateInputAuthTokensExt]], pydantic.Field(alias="authTokensExt") - ] = None - r"""Auth tokens""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - template_cribl_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_criblAPI") - ] = None - r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" - - template_elastic_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticAPI") - ] = None - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - - template_splunk_hec_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_splunkHecAPI") - ] = None - r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "criblAPI", - "elasticAPI", - "splunkHecAPI", - "splunkHecAcks", - "metadata", - "authTokensExt", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_criblAPI", - "__template_elasticAPI", - "__template_splunkHecAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputCriblHTTPType(str, Enum): - r"""Source type identifier.""" - - CRIBL_HTTP = "cribl_http" - - -class CreateInputInputCriblHTTPTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputCriblHTTPType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateInputInputCriblHTTP(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputCriblHTTPType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputCriblTCPTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsCribltcp - r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateInputInputCriblTCP(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsCribltcp - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") - ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") - ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") - ] = None - r"""Load balance traffic across all Worker Processes""" - - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "enableLoadBalancing", - "authTokens", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputCriblType(str, Enum): - r"""Connector type identifier.""" - - CRIBL = "cribl" - - -class CreateInputInputCriblTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputCriblType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - filter_: NotRequired[str] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputInputCribl(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputCriblType - r"""Connector type identifier.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "filter", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputGooglePubsubTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsGooglepubsub - r"""Connector type identifier.""" - topic_name: str - r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" - subscription_name: str - r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - monitor_subscription: NotRequired[bool] - r"""Use when the subscription is not created by this Source and topic is not known""" - create_topic: NotRequired[bool] - r"""Create topic if it does not exist""" - create_subscription: NotRequired[bool] - r"""Create subscription if it does not exist""" - region: NotRequired[str] - r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - max_backlog: NotRequired[float] - r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" - concurrency: NotRequired[float] - r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" - request_timeout: NotRequired[float] - r"""Pull request timeout, in milliseconds""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - ordered_delivery: NotRequired[bool] - r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: NotRequired[str] - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - template_subscription_name: NotRequired[str] - r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - -class CreateInputInputGooglePubsub(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsGooglepubsub - r"""Connector type identifier.""" - - topic_name: Annotated[str, pydantic.Field(alias="topicName")] - r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" - - subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] - r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - monitor_subscription: Annotated[ - Optional[bool], pydantic.Field(alias="monitorSubscription") - ] = None - r"""Use when the subscription is not created by this Source and topic is not known""" - - create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None - r"""Create topic if it does not exist""" - - create_subscription: Annotated[ - Optional[bool], pydantic.Field(alias="createSubscription") - ] = None - r"""Create subscription if it does not exist""" - - region: Optional[str] = None - r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - - google_auth_method: Annotated[ - Optional[GoogleAuthenticationMethodOptions], - pydantic.Field(alias="googleAuthMethod"), - ] = None - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") - ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - - secret: Optional[str] = None - r"""Select or create a stored text secret""" - - max_backlog: Annotated[Optional[float], pydantic.Field(alias="maxBacklog")] = None - r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" - - concurrency: Optional[float] = None - r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Pull request timeout, in milliseconds""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - ordered_delivery: Annotated[ - Optional[bool], pydantic.Field(alias="orderedDelivery") - ] = None - r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_topic_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicName") - ] = None - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - - template_subscription_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_subscriptionName") - ] = None - r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): - if isinstance(value, str): - try: - return models.GoogleAuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "monitorSubscription", - "createTopic", - "createSubscription", - "region", - "googleAuthMethod", - "serviceAccountCredentials", - "secret", - "maxBacklog", - "concurrency", - "requestTimeout", - "metadata", - "description", - "orderedDelivery", - "__template_environment", - "__template_streamtags", - "__template_topicName", - "__template_subscriptionName", - "__template_region", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputFirehoseType(str, Enum): - r"""Source type identifier.""" - - FIREHOSE = "firehose" - - -class CreateInputInputFirehoseTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputFirehoseType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - -class CreateInputInputFirehose(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputFirehoseType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputExecType(str, Enum): - r"""Connector type identifier.""" - - EXEC = "exec" - - -class CreateInputScheduleType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - - INTERVAL = "interval" - CRON_SCHEDULE = "cronSchedule" - - -class CreateInputInputExecTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputExecType - r"""Connector type identifier.""" - command: str - r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" - disabled: NotRequired[bool] - r"""Disabled""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - script: NotRequired[str] - r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" - retries: NotRequired[float] - r"""Maximum number of retry attempts in the event that the command fails""" - schedule_type: NotRequired[CreateInputScheduleType] - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - interval: NotRequired[float] - r"""Interval between command executions in seconds.""" - cron_schedule: NotRequired[str] - r"""Cron schedule to execute the command on.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputInputExec(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputExecType - r"""Connector type identifier.""" - - command: str - r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" - - disabled: Optional[bool] = None - r"""Disabled""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - script: Optional[str] = None - r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" - - retries: Optional[float] = None - r"""Maximum number of retry attempts in the event that the command fails""" - - schedule_type: Annotated[ - Optional[CreateInputScheduleType], pydantic.Field(alias="scheduleType") - ] = None - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - interval: Optional[float] = None - r"""Interval between command executions in seconds.""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Cron schedule to execute the command on.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @field_serializer("schedule_type") - def serialize_schedule_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputScheduleType(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "script", - "retries", - "scheduleType", - "breakerRulesets", - "staleChannelFlushMs", - "metadata", - "description", - "interval", - "cronSchedule", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputEventhubAmqpType(str, Enum): - r"""Connector type identifier.""" - - EVENTHUB_AMQP = "eventhub_amqp" - - -class CreateInputAuthenticationMechanism(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Authentication mechanism""" - - # Connection String - CONNECTION_STRING = "connection-string" - # OAuth Bearer - OAUTH_BEARER = "oauth-bearer" - - -class CreateInputCertificateTypedDict(TypedDict): - certificate_name: str - r"""The certificate you registered as credentials for your app in the Azure portal""" - cert_path: str - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - priv_key_path: str - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - - -class CreateInputCertificate(BaseModel): - certificate_name: Annotated[str, pydantic.Field(alias="certificateName")] - r"""The certificate you registered as credentials for your app in the Azure portal""" - - cert_path: Annotated[str, pydantic.Field(alias="certPath")] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - - priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["passphrase"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputAuthTypedDict(TypedDict): - mechanism: CreateInputAuthenticationMechanism - r"""Authentication mechanism""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] - r"""Authentication method""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CreateInputCertificateTypedDict] - oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] - r"""Endpoint used to acquire authentication tokens from Azure""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory""" - fully_qualified_namespace: NotRequired[str] - r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" - template_oauth_endpoint: NotRequired[str] - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_fully_qualified_namespace: NotRequired[str] - r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" - - -class CreateInputAuth(BaseModel): - mechanism: CreateInputAuthenticationMechanism - r"""Authentication mechanism""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - client_secret_auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuth], - pydantic.Field(alias="clientSecretAuthType"), - ] = None - r"""Authentication method""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[CreateInputCertificate] = None - - oauth_endpoint: Annotated[ - Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], - pydantic.Field(alias="oauthEndpoint"), - ] = None - r"""Endpoint used to acquire authentication tokens from Azure""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory""" - - fully_qualified_namespace: Annotated[ - Optional[str], pydantic.Field(alias="fullyQualifiedNamespace") - ] = None - r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" - - template_oauth_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_oauthEndpoint") - ] = None - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_fully_qualified_namespace: Annotated[ - Optional[str], pydantic.Field(alias="__template_fullyQualifiedNamespace") - ] = None - r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" - - @field_serializer("mechanism") - def serialize_mechanism(self, value): - if isinstance(value, str): - try: - return models.CreateInputAuthenticationMechanism(value) - except ValueError: - return value - return value - - @field_serializer("client_secret_auth_type") - def serialize_client_secret_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuth(value) - except ValueError: - return value - return value - - @field_serializer("oauth_endpoint") - def serialize_oauth_endpoint(self, value): - if isinstance(value, str): - try: - return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "textSecret", - "clientSecretAuthType", - "clientTextSecret", - "certificate", - "oauthEndpoint", - "clientId", - "tenantId", - "fullyQualifiedNamespace", - "__template_oauthEndpoint", - "__template_clientId", - "__template_tenantId", - "__template_fullyQualifiedNamespace", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputEventhubAmqpAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method""" - - SECRET = "secret" - CLIENT_SECRET = "clientSecret" - CLIENT_CERT = "clientCert" - CLIENT_ASSERTION = "clientAssertion" - CLIENT_ASSERTION_RPC = "clientAssertion_rpc" - - -class CreateInputAzureBlobStorageTypedDict(TypedDict): - r"""Azure Blob Storage""" - - container_name: str - r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" - auth_type: NotRequired[CreateInputInputEventhubAmqpAuthenticationMethod] - r"""Authentication method""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - storage_account_name: NotRequired[str] - r"""The name of your Azure storage account""" - tenant_id: NotRequired[str] - r"""The service principal's tenant ID""" - client_id: NotRequired[str] - r"""The service principal's client ID""" - azure_cloud: NotRequired[str] - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - endpoint_suffix: NotRequired[str] - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CertificateTypeTypedDict] - template_storage_account_name: NotRequired[str] - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_azure_cloud: NotRequired[str] - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - -class CreateInputAzureBlobStorage(BaseModel): - r"""Azure Blob Storage""" - - container_name: Annotated[str, pydantic.Field(alias="containerName")] - r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" - - auth_type: Annotated[ - Optional[CreateInputInputEventhubAmqpAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Authentication method""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="storageAccountName") - ] = None - r"""The name of your Azure storage account""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""The service principal's tenant ID""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""The service principal's client ID""" - - azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - - endpoint_suffix: Annotated[ - Optional[str], pydantic.Field(alias="endpointSuffix") - ] = None - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[CertificateType] = None - - template_storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageAccountName") - ] = None - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_azure_cloud: Annotated[ - Optional[str], pydantic.Field(alias="__template_azureCloud") - ] = None - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputEventhubAmqpAuthenticationMethod(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "textSecret", - "storageAccountName", - "tenantId", - "clientId", - "azureCloud", - "endpointSuffix", - "clientTextSecret", - "certificate", - "__template_storageAccountName", - "__template_tenantId", - "__template_clientId", - "__template_azureCloud", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputCheckpointingTypedDict(TypedDict): - blob_store: CreateInputAzureBlobStorageTypedDict - r"""Azure Blob Storage""" - - -class CreateInputCheckpointing(BaseModel): - blob_store: Annotated[ - CreateInputAzureBlobStorage, pydantic.Field(alias="blobStore") - ] - r"""Azure Blob Storage""" - - -class CreateInputInputEventhubAmqpTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputEventhubAmqpType - r"""Connector type identifier.""" - consumer_group: str - r"""The consumer group this instance belongs to. Default is '$Default'.""" - checkpointing: CreateInputCheckpointingTypedDict - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - event_hub_name: NotRequired[str] - r"""The name of the Event Hub to consume from""" - auth: NotRequired[CreateInputAuthTypedDict] - from_beginning: NotRequired[bool] - r"""Start reading from earliest available data; relevant only during initial subscription""" - max_batch_size: NotRequired[int] - r"""Maximum number of events in each batch delivered to the consumer""" - max_wait_time_in_seconds: NotRequired[int] - r"""Maximum time to wait for a batch of events before delivering a partial batch""" - prefetch_count: NotRequired[int] - r"""Number of events to prefetch from the service for processing""" - max_retries: NotRequired[int] - r"""Maximum number of retries per operation""" - initial_backoff: NotRequired[int] - r"""Initial delay before the first retry, in milliseconds""" - max_backoff: NotRequired[int] - r"""Maximum delay between retries, in milliseconds""" - timeout_in_ms: NotRequired[int] - r"""Maximum time to wait for a request to complete""" - connection_initial_backoff: NotRequired[int] - r"""Initial delay before the first reconnection attempt, in milliseconds""" - connection_max_backoff: NotRequired[int] - r"""Maximum delay between reconnection attempts, in milliseconds""" - connection_timeout_in_ms: NotRequired[int] - r"""Maximum time to wait for a connection to complete""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputInputEventhubAmqp(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputEventhubAmqpType - r"""Connector type identifier.""" - - consumer_group: Annotated[str, pydantic.Field(alias="consumerGroup")] - r"""The consumer group this instance belongs to. Default is '$Default'.""" - - checkpointing: CreateInputCheckpointing - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - event_hub_name: Annotated[Optional[str], pydantic.Field(alias="eventHubName")] = ( - None - ) - r"""The name of the Event Hub to consume from""" - - auth: Optional[CreateInputAuth] = None - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Start reading from earliest available data; relevant only during initial subscription""" - - max_batch_size: Annotated[Optional[int], pydantic.Field(alias="maxBatchSize")] = ( - None - ) - r"""Maximum number of events in each batch delivered to the consumer""" - - max_wait_time_in_seconds: Annotated[ - Optional[int], pydantic.Field(alias="maxWaitTimeInSeconds") - ] = None - r"""Maximum time to wait for a batch of events before delivering a partial batch""" - - prefetch_count: Annotated[Optional[int], pydantic.Field(alias="prefetchCount")] = ( - None - ) - r"""Number of events to prefetch from the service for processing""" - - max_retries: Annotated[Optional[int], pydantic.Field(alias="maxRetries")] = None - r"""Maximum number of retries per operation""" - - initial_backoff: Annotated[ - Optional[int], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial delay before the first retry, in milliseconds""" - - max_backoff: Annotated[Optional[int], pydantic.Field(alias="maxBackoff")] = None - r"""Maximum delay between retries, in milliseconds""" - - timeout_in_ms: Annotated[Optional[int], pydantic.Field(alias="timeoutInMs")] = None - r"""Maximum time to wait for a request to complete""" - - connection_initial_backoff: Annotated[ - Optional[int], pydantic.Field(alias="connectionInitialBackoff") - ] = None - r"""Initial delay before the first reconnection attempt, in milliseconds""" - - connection_max_backoff: Annotated[ - Optional[int], pydantic.Field(alias="connectionMaxBackoff") - ] = None - r"""Maximum delay between reconnection attempts, in milliseconds""" - - connection_timeout_in_ms: Annotated[ - Optional[int], pydantic.Field(alias="connectionTimeoutInMs") - ] = None - r"""Maximum time to wait for a connection to complete""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "eventHubName", - "auth", - "fromBeginning", - "maxBatchSize", - "maxWaitTimeInSeconds", - "prefetchCount", - "maxRetries", - "initialBackoff", - "maxBackoff", - "timeoutInMs", - "connectionInitialBackoff", - "connectionMaxBackoff", - "connectionTimeoutInMs", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputEventhubType(str, Enum): - r"""Connector type identifier.""" - - EVENTHUB = "eventhub" - - -class CreateInputInputEventhubTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputEventhubType - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - topics: List[str] - r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - group_id: NotRequired[str] - r"""The consumer group this instance belongs to. Default is 'Cribl'.""" - from_beginning: NotRequired[bool] - r"""Start reading from earliest available data; relevant only during initial subscription""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeUseTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeTypedDict] - r"""TLS settings (client side)""" - session_timeout: NotRequired[float] - r""" - Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - rebalance_timeout: NotRequired[float] - r""" - Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - heartbeat_interval: NotRequired[float] - r""" - Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - auto_commit_interval: NotRequired[float] - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - auto_commit_threshold: NotRequired[float] - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - max_bytes_per_partition: NotRequired[float] - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - max_bytes: NotRequired[float] - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - max_socket_errors: NotRequired[float] - r"""Maximum number of network errors before the consumer re-creates a socket""" - minimize_duplicates: NotRequired[bool] - r"""Minimize duplicate events by starting only one consumer for each topic partition""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topics: NotRequired[str] - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - template_group_id: NotRequired[str] - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - -class CreateInputInputEventhub(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputEventhubType - r"""Connector type identifier.""" - - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - - topics: List[str] - r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None - r"""The consumer group this instance belongs to. Default is 'Cribl'.""" - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Start reading from earliest available data; relevant only during initial subscription""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Maximum time to wait for a connection to complete successfully""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" - - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") - ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - - sasl: Optional[AuthenticationTypeUse] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - - tls: Optional[TLSSettingsClientSideType] = None - r"""TLS settings (client side)""" - - session_timeout: Annotated[ - Optional[float], pydantic.Field(alias="sessionTimeout") - ] = None - r""" - Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - rebalance_timeout: Annotated[ - Optional[float], pydantic.Field(alias="rebalanceTimeout") - ] = None - r""" - Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - heartbeat_interval: Annotated[ - Optional[float], pydantic.Field(alias="heartbeatInterval") - ] = None - r""" - Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - auto_commit_interval: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitInterval") - ] = None - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - auto_commit_threshold: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitThreshold") - ] = None - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - max_bytes_per_partition: Annotated[ - Optional[float], pydantic.Field(alias="maxBytesPerPartition") - ] = None - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - - max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - - max_socket_errors: Annotated[ - Optional[float], pydantic.Field(alias="maxSocketErrors") - ] = None - r"""Maximum number of network errors before the consumer re-creates a socket""" - - minimize_duplicates: Annotated[ - Optional[bool], pydantic.Field(alias="minimizeDuplicates") - ] = None - r"""Minimize duplicate events by starting only one consumer for each topic partition""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") - ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - - template_topics: Annotated[ - Optional[str], pydantic.Field(alias="__template_topics") - ] = None - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - - template_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_groupId") - ] = None - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "groupId", - "fromBeginning", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "tls", - "sessionTimeout", - "rebalanceTimeout", - "heartbeatInterval", - "autoCommitInterval", - "autoCommitThreshold", - "maxBytesPerPartition", - "maxBytes", - "maxSocketErrors", - "minimizeDuplicates", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_brokers", - "__template_topics", - "__template_groupId", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputMicrosoftGraphType(str, Enum): - r"""Connector type identifier.""" - - MICROSOFT_GRAPH = "microsoft_graph" - - -class CreateInputInputMicrosoftGraphAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select authentication method.""" - - OAUTH = "oauth" - OAUTH_SECRET = "oauthSecret" - OAUTH_CERT = "oauthCert" - - -class CreateInputSubscriptionPlan(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - # Microsoft 365 Enterprise - ENTERPRISE_GCC = "enterprise_gcc" - # Microsoft 365 GCC - GCC = "gcc" - # Microsoft 365 GCC High - GCC_HIGH = "gcc_high" - # Microsoft 365 DoD - DOD = "dod" - # Microsoft 365 China (21Vianet) - CHINA = "china" - - -class CreateInputInputMicrosoftGraphTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputMicrosoftGraphType - r"""Connector type identifier.""" - url: str - r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - start_date: NotRequired[str] - r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - end_date: NotRequired[str] - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - disable_time_filter: NotRequired[bool] - r"""Disables time filtering of events when a date range is specified.""" - max_pages: NotRequired[int] - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - auth_type: NotRequired[CreateInputInputMicrosoftGraphAuthenticationMethod] - r"""Select authentication method.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - reschedule_dropped_tasks: NotRequired[bool] - r"""Reschedule tasks that failed with non-fatal errors""" - max_task_reschedule: NotRequired[float] - r"""Maximum number of times a task can be rescheduled""" - log_level: NotRequired[LogLevelOptionsDebugError] - r"""Log Level (verbosity) for collection runtime behavior.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""client_secret to pass in the OAuth request parameter.""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter.""" - resource: NotRequired[str] - r"""Resource to pass in the OAuth request parameter.""" - plan_type: NotRequired[CreateInputSubscriptionPlan] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - text_secret: NotRequired[str] - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - cert_options: NotRequired[CertOptionsTypeTypedDict] - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_resource: NotRequired[str] - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - -class CreateInputInputMicrosoftGraph(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputMicrosoftGraphType - r"""Connector type identifier.""" - - url: str - r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" - - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None - r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - - end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - - disable_time_filter: Annotated[ - Optional[bool], pydantic.Field(alias="disableTimeFilter") - ] = None - r"""Disables time filtering of events when a date range is specified.""" - - max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - - auth_type: Annotated[ - Optional[CreateInputInputMicrosoftGraphAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Select authentication method.""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - reschedule_dropped_tasks: Annotated[ - Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") - ] = None - r"""Reschedule tasks that failed with non-fatal errors""" - - max_task_reschedule: Annotated[ - Optional[float], pydantic.Field(alias="maxTaskReschedule") - ] = None - r"""Maximum number of times a task can be rescheduled""" - - log_level: Annotated[ - Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") - ] = None - r"""Log Level (verbosity) for collection runtime behavior.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""client_secret to pass in the OAuth request parameter.""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter.""" - - resource: Optional[str] = None - r"""Resource to pass in the OAuth request parameter.""" - - plan_type: Annotated[ - Optional[CreateInputSubscriptionPlan], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - - cert_options: Annotated[ - Optional[CertOptionsType], pydantic.Field(alias="certOptions") - ] = None - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_resource: Annotated[ - Optional[str], pydantic.Field(alias="__template_resource") - ] = None - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputMicrosoftGraphAuthenticationMethod(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsDebugError(value) - except ValueError: - return value - return value - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSubscriptionPlan(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "startDate", - "endDate", - "timeout", - "disableTimeFilter", - "maxPages", - "authType", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "rescheduleDroppedTasks", - "maxTaskReschedule", - "logLevel", - "retryRules", - "breakerRulesets", - "staleChannelFlushMs", - "description", - "clientSecret", - "tenantId", - "clientId", - "resource", - "planType", - "textSecret", - "certOptions", - "__template_environment", - "__template_streamtags", - "__template_url", - "__template_tenantId", - "__template_clientId", - "__template_resource", - "__template_planType", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputOffice365MsgTraceType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_MSG_TRACE = "office365_msg_trace" - - -class CreateInputInputOffice365MsgTraceAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select authentication method.""" - - MANUAL = "manual" - SECRET = "secret" - OAUTH = "oauth" - OAUTH_SECRET = "oauthSecret" - OAUTH_CERT = "oauthCert" - - -class CreateInputInputOffice365MsgTraceTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputOffice365MsgTraceType - r"""Connector type identifier.""" - url: str - r"""URL to use when retrieving report data.""" - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - start_date: NotRequired[str] - r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - end_date: NotRequired[str] - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - disable_time_filter: NotRequired[bool] - r"""Disables time filtering of events when a date range is specified.""" - auth_type: NotRequired[CreateInputInputOffice365MsgTraceAuthenticationMethod] - r"""Select authentication method.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - reschedule_dropped_tasks: NotRequired[bool] - r"""Reschedule tasks that failed with non-fatal errors""" - max_task_reschedule: NotRequired[float] - r"""Maximum number of times a task can be rescheduled""" - log_level: NotRequired[LogLevelOptionsDebugError] - r"""Log Level (verbosity) for collection runtime behavior.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username to run Message Trace API call.""" - password: NotRequired[str] - r"""Password to run Message Trace API call.""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials.""" - client_secret: NotRequired[str] - r"""client_secret to pass in the OAuth request parameter.""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter.""" - resource: NotRequired[str] - r"""Resource to pass in the OAuth request parameter.""" - plan_type: NotRequired[SubscriptionPlanOptions] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - text_secret: NotRequired[str] - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - cert_options: NotRequired[CertOptionsTypeTypedDict] - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_resource: NotRequired[str] - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - -class CreateInputInputOffice365MsgTrace(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputOffice365MsgTraceType - r"""Connector type identifier.""" - - url: str - r"""URL to use when retrieving report data.""" - - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None - r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - - end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - - disable_time_filter: Annotated[ - Optional[bool], pydantic.Field(alias="disableTimeFilter") - ] = None - r"""Disables time filtering of events when a date range is specified.""" - - auth_type: Annotated[ - Optional[CreateInputInputOffice365MsgTraceAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Select authentication method.""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - reschedule_dropped_tasks: Annotated[ - Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") - ] = None - r"""Reschedule tasks that failed with non-fatal errors""" - - max_task_reschedule: Annotated[ - Optional[float], pydantic.Field(alias="maxTaskReschedule") - ] = None - r"""Maximum number of times a task can be rescheduled""" - - log_level: Annotated[ - Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") - ] = None - r"""Log Level (verbosity) for collection runtime behavior.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username to run Message Trace API call.""" - - password: Optional[str] = None - r"""Password to run Message Trace API call.""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""client_secret to pass in the OAuth request parameter.""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter.""" - - resource: Optional[str] = None - r"""Resource to pass in the OAuth request parameter.""" - - plan_type: Annotated[ - Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - - cert_options: Annotated[ - Optional[CertOptionsType], pydantic.Field(alias="certOptions") - ] = None - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_resource: Annotated[ - Optional[str], pydantic.Field(alias="__template_resource") - ] = None - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputOffice365MsgTraceAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsDebugError(value) - except ValueError: - return value - return value - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "startDate", - "endDate", - "timeout", - "disableTimeFilter", - "authType", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "rescheduleDroppedTasks", - "maxTaskReschedule", - "logLevel", - "retryRules", - "description", - "username", - "password", - "credentialsSecret", - "clientSecret", - "tenantId", - "clientId", - "resource", - "planType", - "textSecret", - "certOptions", - "__template_environment", - "__template_streamtags", - "__template_url", - "__template_tenantId", - "__template_clientId", - "__template_resource", - "__template_planType", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputOffice365ServiceType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_SERVICE = "office365_service" - - -class CreateInputInputOffice365ServiceContentConfigTypedDict(TypedDict): - content_type: NotRequired[str] - r"""Microsoft 365 Services API Content Type""" - description: NotRequired[str] - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - interval: NotRequired[float] - r"""Interval""" - log_level: NotRequired[LogLevelOptionsContentConfigItems] - r"""Collector runtime Log Level""" - enabled: NotRequired[bool] - r"""Enabled""" - - -class CreateInputInputOffice365ServiceContentConfig(BaseModel): - content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None - r"""Microsoft 365 Services API Content Type""" - - description: Optional[str] = None - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - - interval: Optional[float] = None - r"""Interval""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime Log Level""" - - enabled: Optional[bool] = None - r"""Enabled""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["contentType", "description", "interval", "logLevel", "enabled"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputOffice365ServiceTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputOffice365ServiceType - r"""Connector type identifier.""" - tenant_id: str - r"""Microsoft 365 Azure Tenant ID""" - app_id: str - r"""Microsoft 365 Azure Application ID""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - plan_type: NotRequired[SubscriptionPlanOptions] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout, use 0 to disable""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - content_config: NotRequired[ - List[CreateInputInputOffice365ServiceContentConfigTypedDict] - ] - r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""Microsoft 365 Azure client secret""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_app_id: NotRequired[str] - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - -class CreateInputInputOffice365Service(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputOffice365ServiceType - r"""Connector type identifier.""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Microsoft 365 Azure Tenant ID""" - - app_id: Annotated[str, pydantic.Field(alias="appId")] - r"""Microsoft 365 Azure Application ID""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - plan_type: Annotated[ - Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout, use 0 to disable""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - content_config: Annotated[ - Optional[List[CreateInputInputOffice365ServiceContentConfig]], - pydantic.Field(alias="contentConfig"), - ] = None - r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""Microsoft 365 Azure client secret""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_app_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_appId") - ] = None - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsManualSecret(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "planType", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "contentConfig", - "retryRules", - "authType", - "description", - "clientSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_planType", - "__template_tenantId", - "__template_appId", - "__template_clientSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputOffice365MgmtType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_MGMT = "office365_mgmt" - - -class CreateInputInputOffice365MgmtContentConfigTypedDict(TypedDict): - content_type: NotRequired[str] - r"""Microsoft 365 Management Activity API Content Type""" - description: NotRequired[str] - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - interval: NotRequired[float] - r"""Interval""" - log_level: NotRequired[LogLevelOptionsContentConfigItems] - r"""Collector runtime Log Level""" - enabled: NotRequired[bool] - r"""Enabled""" - - -class CreateInputInputOffice365MgmtContentConfig(BaseModel): - content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None - r"""Microsoft 365 Management Activity API Content Type""" - - description: Optional[str] = None - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - - interval: Optional[float] = None - r"""Interval""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime Log Level""" - - enabled: Optional[bool] = None - r"""Enabled""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["contentType", "description", "interval", "logLevel", "enabled"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputOffice365MgmtTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputOffice365MgmtType - r"""Connector type identifier.""" - plan_type: SubscriptionPlanOptions - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - tenant_id: str - r"""Microsoft 365 Azure Tenant ID""" - app_id: str - r"""Microsoft 365 Azure Application ID""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - timeout: NotRequired[float] - r"""HTTP request inactivity timeout, use 0 to disable""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - publisher_identifier: NotRequired[str] - r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" - content_config: NotRequired[ - List[CreateInputInputOffice365MgmtContentConfigTypedDict] - ] - r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" - ingestion_lag: NotRequired[float] - r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""Microsoft 365 Azure client secret""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_app_id: NotRequired[str] - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - template_publisher_identifier: NotRequired[str] - r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - -class CreateInputInputOffice365Mgmt(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputOffice365MgmtType - r"""Connector type identifier.""" - - plan_type: Annotated[SubscriptionPlanOptions, pydantic.Field(alias="planType")] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Microsoft 365 Azure Tenant ID""" - - app_id: Annotated[str, pydantic.Field(alias="appId")] - r"""Microsoft 365 Azure Application ID""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout, use 0 to disable""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - publisher_identifier: Annotated[ - Optional[str], pydantic.Field(alias="publisherIdentifier") - ] = None - r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" - - content_config: Annotated[ - Optional[List[CreateInputInputOffice365MgmtContentConfig]], - pydantic.Field(alias="contentConfig"), - ] = None - r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" - - ingestion_lag: Annotated[Optional[float], pydantic.Field(alias="ingestionLag")] = ( - None - ) - r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""Microsoft 365 Azure client secret""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_app_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_appId") - ] = None - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - - template_publisher_identifier: Annotated[ - Optional[str], pydantic.Field(alias="__template_publisherIdentifier") - ] = None - r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsManualSecret(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "publisherIdentifier", - "contentConfig", - "ingestionLag", - "retryRules", - "authType", - "description", - "clientSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_planType", - "__template_tenantId", - "__template_appId", - "__template_publisherIdentifier", - "__template_clientSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputEdgePrometheusType(str, Enum): - r"""Connector type identifier.""" - - EDGE_PROMETHEUS = "edge_prometheus" - - -class CreateInputInputEdgePrometheusDiscoveryType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - # Static - STATIC = "static" - # DNS - DNS = "dns" - # AWS EC2 - EC2 = "ec2" - # Kubernetes Node - K8S_NODE = "k8s-node" - # Kubernetes Pods - K8S_PODS = "k8s-pods" - # Kubernetes Service Monitor (v4.18+) - K8S_SERVICE_MONITOR = "k8s-service-monitor" - # HTTP SD - HTTP_SD = "http_sd" - - -class CreateInputInputEdgePrometheusAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter credentials directly, or select a stored secret""" - - MANUAL = "manual" - SECRET = "secret" - KUBERNETES = "kubernetes" - - -class CreateInputTargetTypedDict(TypedDict): - host: str - r"""Name of host from which to pull metrics.""" - protocol: NotRequired[ProtocolOptionsTargetsItems] - r"""Protocol to use when collecting metrics""" - port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets.""" - path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - - -class CreateInputTarget(BaseModel): - host: str - r"""Name of host from which to pull metrics.""" - - protocol: Optional[ProtocolOptionsTargetsItems] = None - r"""Protocol to use when collecting metrics""" - - port: Optional[float] = None - r"""The port number in the metrics URL for discovered targets.""" - - path: Optional[str] = None - r"""Path to use when collecting metrics from discovered targets""" - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptionsTargetsItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["protocol", "port", "path"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputPodFilterTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" - description: NotRequired[str] - r"""Optional description of this rule's purpose""" - - -class CreateInputPodFilter(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" - - description: Optional[str] = None - r"""Optional description of this rule's purpose""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputEdgePrometheusTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputEdgePrometheusType - r"""Connector type identifier.""" - discovery_type: CreateInputInputEdgePrometheusDiscoveryType - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - interval: float - r"""How often in seconds to scrape targets for metrics.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - dimension_list: NotRequired[List[str]] - r"""Other dimensions to include in events""" - field_per_metric: NotRequired[bool] - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - timeout: NotRequired[float] - r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" - persistence: NotRequired[DiskSpoolingTypeTypedDict] - r"""Disk Spooling""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_type: NotRequired[CreateInputInputEdgePrometheusAuthenticationMethod] - r"""Enter credentials directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - targets: NotRequired[List[CreateInputTargetTypedDict]] - r"""Targets""" - record_type: NotRequired[RecordTypeOptions] - r"""DNS record type to resolve""" - scrape_port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets.""" - name_list: NotRequired[List[str]] - r"""List of DNS names to resolve""" - scrape_protocol: NotRequired[ProtocolOptionsTargetsItems] - r"""Protocol to use when collecting metrics""" - scrape_path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - use_public_ip: NotRequired[bool] - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] - r"""Filter to apply when searching for EC2 instances""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the EC2 is located""" - endpoint: NotRequired[str] - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access EC2""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - service_monitor_namespace: NotRequired[str] - r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" - scrape_protocol_expr: NotRequired[str] - r"""Protocol to use when collecting metrics""" - scrape_port_expr: NotRequired[str] - r"""The port number in the metrics URL for discovered targets.""" - scrape_path_expr: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - pod_filter: NotRequired[List[CreateInputPodFilterTypedDict]] - r""" - Add rules to decide which pods to discover for metrics. - Pods are searched if no rules are given or of all the rules' - expressions evaluate to true. - - """ - http_discovery_url: NotRequired[str] - r"""URL to fetch target groups from (must be http or https)""" - http_discovery_headers: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Extra headers to send with the discovery request""" - http_discovery_reject_unauthorized: NotRequired[bool] - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - max_response_body_size: NotRequired[str] - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - username: NotRequired[str] - r"""Username for Prometheus Basic authentication""" - password: NotRequired[str] - r"""Password for Prometheus Basic authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_dimension_list: NotRequired[str] - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - template_name_list: NotRequired[str] - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - -class CreateInputInputEdgePrometheus(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputEdgePrometheusType - r"""Connector type identifier.""" - - discovery_type: Annotated[ - CreateInputInputEdgePrometheusDiscoveryType, - pydantic.Field(alias="discoveryType"), - ] - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - interval: float - r"""How often in seconds to scrape targets for metrics.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - dimension_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="dimensionList") - ] = None - r"""Other dimensions to include in events""" - - field_per_metric: Annotated[ - Optional[bool], pydantic.Field(alias="fieldPerMetric") - ] = None - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - - timeout: Optional[float] = None - r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" - - persistence: Optional[DiskSpoolingType] = None - r"""Disk Spooling""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_type: Annotated[ - Optional[CreateInputInputEdgePrometheusAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Enter credentials directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - targets: Optional[List[CreateInputTarget]] = None - r"""Targets""" - - record_type: Annotated[ - Optional[RecordTypeOptions], pydantic.Field(alias="recordType") - ] = None - r"""DNS record type to resolve""" - - scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None - r"""The port number in the metrics URL for discovered targets.""" - - name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None - r"""List of DNS names to resolve""" - - scrape_protocol: Annotated[ - Optional[ProtocolOptionsTargetsItems], pydantic.Field(alias="scrapeProtocol") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None - r"""Path to use when collecting metrics from discovered targets""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - - search_filter: Annotated[ - Optional[List[SearchFilterConfInputPrometheus]], - pydantic.Field(alias="searchFilter"), - ] = None - r"""Filter to apply when searching for EC2 instances""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""Region where the EC2 is located""" - - endpoint: Optional[str] = None - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access EC2""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - service_monitor_namespace: Annotated[ - Optional[str], pydantic.Field(alias="serviceMonitorNamespace") - ] = None - r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" - - scrape_protocol_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapeProtocolExpr") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_port_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapePortExpr") - ] = None - r"""The port number in the metrics URL for discovered targets.""" - - scrape_path_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapePathExpr") - ] = None - r"""Path to use when collecting metrics from discovered targets""" - - pod_filter: Annotated[ - Optional[List[CreateInputPodFilter]], pydantic.Field(alias="podFilter") - ] = None - r""" - Add rules to decide which pods to discover for metrics. - Pods are searched if no rules are given or of all the rules' - expressions evaluate to true. - - """ - - http_discovery_url: Annotated[ - Optional[str], pydantic.Field(alias="httpDiscoveryUrl") - ] = None - r"""URL to fetch target groups from (must be http or https)""" - - http_discovery_headers: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="httpDiscoveryHeaders"), - ] = None - r"""Extra headers to send with the discovery request""" - - http_discovery_reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") - ] = None - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - - max_response_body_size: Annotated[ - Optional[str], pydantic.Field(alias="maxResponseBodySize") - ] = None - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - - username: Optional[str] = None - r"""Username for Prometheus Basic authentication""" - - password: Optional[str] = None - r"""Password for Prometheus Basic authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_dimension_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_dimensionList") - ] = None - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - - template_name_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_nameList") - ] = None - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - @field_serializer("discovery_type") - def serialize_discovery_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputEdgePrometheusDiscoveryType(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputEdgePrometheusAuthenticationMethod(value) - except ValueError: - return value - return value - - @field_serializer("record_type") - def serialize_record_type(self, value): - if isinstance(value, str): - try: - return models.RecordTypeOptions(value) - except ValueError: - return value - return value - - @field_serializer("scrape_protocol") - def serialize_scrape_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptionsTargetsItems(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "dimensionList", - "fieldPerMetric", - "timeout", - "persistence", - "metadata", - "authType", - "description", - "targets", - "recordType", - "scrapePort", - "nameList", - "scrapeProtocol", - "scrapePath", - "awsAuthenticationMethod", - "awsApiKey", - "awsSecret", - "usePublicIp", - "searchFilter", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "serviceMonitorNamespace", - "scrapeProtocolExpr", - "scrapePortExpr", - "scrapePathExpr", - "podFilter", - "httpDiscoveryUrl", - "httpDiscoveryHeaders", - "httpDiscoveryRejectUnauthorized", - "maxResponseBodySize", - "username", - "password", - "credentialsSecret", - "__template_environment", - "__template_streamtags", - "__template_dimensionList", - "__template_nameList", - "__template_awsApiKey", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputPrometheusDiscoveryType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - # Static - STATIC = "static" - # DNS - DNS = "dns" - # AWS EC2 - EC2 = "ec2" - # HTTP SD - HTTP_SD = "http_sd" - - -class CreateInputMetricsProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Protocol to use when collecting metrics""" - - HTTP = "http" - HTTPS = "https" - - -class CreateInputInputPrometheusTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsPrometheus - r"""Connector type identifier.""" - interval: float - r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" - log_level: LogLevelOptions - r"""Collector runtime log level""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - dimension_list: NotRequired[List[str]] - r"""Other dimensions to include in events""" - field_per_metric: NotRequired[bool] - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - discovery_type: NotRequired[CreateInputInputPrometheusDiscoveryType] - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - timeout: NotRequired[float] - r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_type: NotRequired[AuthenticationMethodOptionsSasl] - r"""Enter credentials directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - target_list: NotRequired[List[str]] - r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" - record_type: NotRequired[RecordTypeOptions] - r"""DNS record type to resolve""" - scrape_port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets""" - name_list: NotRequired[List[str]] - r"""List of DNS names to resolve""" - scrape_protocol: NotRequired[CreateInputMetricsProtocol] - r"""Protocol to use when collecting metrics""" - scrape_path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - use_public_ip: NotRequired[bool] - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] - r"""Filter to apply when searching for EC2 instances""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the EC2 is located""" - endpoint: NotRequired[str] - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access EC2""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - http_discovery_url: NotRequired[str] - r"""URL to fetch target groups from (must be http or https)""" - http_discovery_headers: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Extra headers to send with the discovery request""" - http_discovery_reject_unauthorized: NotRequired[bool] - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - max_response_body_size: NotRequired[str] - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - username: NotRequired[str] - r"""Username for Prometheus Basic authentication""" - password: NotRequired[str] - r"""Password for Prometheus Basic authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_dimension_list: NotRequired[str] - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - template_discovery_type: NotRequired[str] - r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" - template_log_level: NotRequired[str] - r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - template_target_list: NotRequired[str] - r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" - template_name_list: NotRequired[str] - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - template_password: NotRequired[str] - r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" - - -class CreateInputInputPrometheus(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsPrometheus - r"""Connector type identifier.""" - - interval: float - r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" - - log_level: Annotated[LogLevelOptions, pydantic.Field(alias="logLevel")] - r"""Collector runtime log level""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - dimension_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="dimensionList") - ] = None - r"""Other dimensions to include in events""" - - field_per_metric: Annotated[ - Optional[bool], pydantic.Field(alias="fieldPerMetric") - ] = None - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - - discovery_type: Annotated[ - Optional[CreateInputInputPrometheusDiscoveryType], - pydantic.Field(alias="discoveryType"), - ] = None - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - timeout: Optional[float] = None - r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsSasl], pydantic.Field(alias="authType") - ] = None - r"""Enter credentials directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - target_list: Annotated[Optional[List[str]], pydantic.Field(alias="targetList")] = ( - None - ) - r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" - - record_type: Annotated[ - Optional[RecordTypeOptions], pydantic.Field(alias="recordType") - ] = None - r"""DNS record type to resolve""" - - scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None - r"""The port number in the metrics URL for discovered targets""" - - name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None - r"""List of DNS names to resolve""" - - scrape_protocol: Annotated[ - Optional[CreateInputMetricsProtocol], pydantic.Field(alias="scrapeProtocol") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None - r"""Path to use when collecting metrics from discovered targets""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - - search_filter: Annotated[ - Optional[List[SearchFilterConfInputPrometheus]], - pydantic.Field(alias="searchFilter"), - ] = None - r"""Filter to apply when searching for EC2 instances""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""Region where the EC2 is located""" - - endpoint: Optional[str] = None - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access EC2""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - http_discovery_url: Annotated[ - Optional[str], pydantic.Field(alias="httpDiscoveryUrl") - ] = None - r"""URL to fetch target groups from (must be http or https)""" - - http_discovery_headers: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="httpDiscoveryHeaders"), - ] = None - r"""Extra headers to send with the discovery request""" - - http_discovery_reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") - ] = None - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - - max_response_body_size: Annotated[ - Optional[str], pydantic.Field(alias="maxResponseBodySize") - ] = None - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - - username: Optional[str] = None - r"""Username for Prometheus Basic authentication""" - - password: Optional[str] = None - r"""Password for Prometheus Basic authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_dimension_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_dimensionList") - ] = None - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - - template_discovery_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_discoveryType") - ] = None - r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" - - template_log_level: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLevel") - ] = None - r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - - template_target_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_targetList") - ] = None - r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" - - template_name_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_nameList") - ] = None - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - template_password: Annotated[ - Optional[str], pydantic.Field(alias="__template_password") - ] = None - r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" - - @field_serializer("discovery_type") - def serialize_discovery_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputPrometheusDiscoveryType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsSasl(value) - except ValueError: - return value - return value - - @field_serializer("record_type") - def serialize_record_type(self, value): - if isinstance(value, str): - try: - return models.RecordTypeOptions(value) - except ValueError: - return value - return value - - @field_serializer("scrape_protocol") - def serialize_scrape_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateInputMetricsProtocol(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "dimensionList", - "fieldPerMetric", - "discoveryType", - "rejectUnauthorized", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "authType", - "description", - "targetList", - "recordType", - "scrapePort", - "nameList", - "scrapeProtocol", - "scrapePath", - "awsAuthenticationMethod", - "awsApiKey", - "awsSecret", - "usePublicIp", - "searchFilter", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "httpDiscoveryUrl", - "httpDiscoveryHeaders", - "httpDiscoveryRejectUnauthorized", - "maxResponseBodySize", - "username", - "password", - "credentialsSecret", - "__template_environment", - "__template_streamtags", - "__template_dimensionList", - "__template_discoveryType", - "__template_logLevel", - "__template_targetList", - "__template_nameList", - "__template_awsApiKey", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_username", - "__template_password", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputPrometheusRwType(str, Enum): - r"""Source type identifier.""" - - PROMETHEUS_RW = "prometheus_rw" - - -class CreateInputInputPrometheusRwTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputPrometheusRwType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - prometheus_api: str - r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - -class CreateInputInputPrometheusRw(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputPrometheusRwType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] - r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "metadata", - "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_username", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputLokiType(str, Enum): - r"""Source type identifier.""" - - LOKI = "loki" - - -class CreateInputInputLokiTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputLokiType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - loki_api: str - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - -class CreateInputInputLoki(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputLokiType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "metadata", - "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_lokiAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputGrafanaType2(str, Enum): - r"""Source type identifier.""" - - GRAFANA = "grafana" - - -class CreateInputPrometheusAuth2TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputPrometheusAuth2(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputLokiAuth2TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputLokiAuth2(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputGrafanaGrafana2TypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputGrafanaType2 - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - loki_api: str - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - prometheus_api: NotRequired[str] - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - prometheus_auth: NotRequired[CreateInputPrometheusAuth2TypedDict] - loki_auth: NotRequired[CreateInputLokiAuth2TypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - -class CreateInputInputGrafanaGrafana2(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputGrafanaType2 - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - prometheus_api: Annotated[Optional[str], pydantic.Field(alias="prometheusAPI")] = ( - None - ) - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - - prometheus_auth: Annotated[ - Optional[CreateInputPrometheusAuth2], pydantic.Field(alias="prometheusAuth") - ] = None - - loki_auth: Annotated[ - Optional[CreateInputLokiAuth2], pydantic.Field(alias="lokiAuth") - ] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "prometheusAPI", - "prometheusAuth", - "lokiAuth", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_lokiAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputGrafanaType1(str, Enum): - r"""Source type identifier.""" - - GRAFANA = "grafana" - - -class CreateInputPrometheusAuth1TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputPrometheusAuth1(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputLokiAuth1TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputLokiAuth1(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputGrafanaGrafana1TypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputGrafanaType1 - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - prometheus_api: str - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - loki_api: NotRequired[str] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - prometheus_auth: NotRequired[CreateInputPrometheusAuth1TypedDict] - loki_auth: NotRequired[CreateInputLokiAuth1TypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - -class CreateInputInputGrafanaGrafana1(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputInputGrafanaType1 - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - loki_api: Annotated[Optional[str], pydantic.Field(alias="lokiAPI")] = None - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - - prometheus_auth: Annotated[ - Optional[CreateInputPrometheusAuth1], pydantic.Field(alias="prometheusAuth") - ] = None - - loki_auth: Annotated[ - Optional[CreateInputLokiAuth1], pydantic.Field(alias="lokiAuth") - ] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "lokiAPI", - "prometheusAuth", - "lokiAuth", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_lokiAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -CreateInputInputGrafanaUnionTypedDict = TypeAliasType( - "CreateInputInputGrafanaUnionTypedDict", - Union[ - CreateInputInputGrafanaGrafana1TypedDict, - CreateInputInputGrafanaGrafana2TypedDict, - ], -) - - -CreateInputInputGrafanaUnion = TypeAliasType( - "CreateInputInputGrafanaUnion", - Union[CreateInputInputGrafanaGrafana1, CreateInputInputGrafanaGrafana2], -) - - -class CreateInputInputConfluentCloudTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsConfluentcloud - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" - topics: List[str] - r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - group_id: NotRequired[str] - r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" - from_beginning: NotRequired[bool] - r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" - kafka_schema_registry: NotRequired[KafkaSchemaRegistryAuthenticationTypeTypedDict] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - session_timeout: NotRequired[float] - r""" - Timeout used to detect client failures when using Kafka's group-management facilities. - If the client sends no heartbeats to the broker before the timeout expires, - the broker will remove the client from the group and initiate a rebalance. - Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. - See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. - """ - rebalance_timeout: NotRequired[float] - r""" - Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. - """ - heartbeat_interval: NotRequired[float] - r""" - Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. - """ - auto_commit_interval: NotRequired[float] - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - auto_commit_threshold: NotRequired[float] - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - max_bytes_per_partition: NotRequired[float] - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - max_bytes: NotRequired[float] - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - max_socket_errors: NotRequired[float] - r"""Maximum number of network errors before the consumer re-creates a socket""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topics: NotRequired[str] - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - template_group_id: NotRequired[str] - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - -class CreateInputInputConfluentCloud(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsConfluentcloud - r"""Connector type identifier.""" - - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" - - topics: List[str] - r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None - r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" - - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationType], - pydantic.Field(alias="kafkaSchemaRegistry"), - ] = None - r"""Kafka Schema Registry Authentication""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Maximum time to wait for a connection to complete successfully""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" - - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") - ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - - session_timeout: Annotated[ - Optional[float], pydantic.Field(alias="sessionTimeout") - ] = None - r""" - Timeout used to detect client failures when using Kafka's group-management facilities. - If the client sends no heartbeats to the broker before the timeout expires, - the broker will remove the client from the group and initiate a rebalance. - Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. - See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. - """ - - rebalance_timeout: Annotated[ - Optional[float], pydantic.Field(alias="rebalanceTimeout") - ] = None - r""" - Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. - """ - - heartbeat_interval: Annotated[ - Optional[float], pydantic.Field(alias="heartbeatInterval") - ] = None - r""" - Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. - """ - - auto_commit_interval: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitInterval") - ] = None - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - auto_commit_threshold: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitThreshold") - ] = None - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - max_bytes_per_partition: Annotated[ - Optional[float], pydantic.Field(alias="maxBytesPerPartition") - ] = None - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - - max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - - max_socket_errors: Annotated[ - Optional[float], pydantic.Field(alias="maxSocketErrors") - ] = None - r"""Maximum number of network errors before the consumer re-creates a socket""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + r"""Add request headers to events, in the __headers field""" - template_topics: Annotated[ - Optional[str], pydantic.Field(alias="__template_topics") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - template_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_groupId") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "groupId", - "fromBeginning", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "sessionTimeout", - "rebalanceTimeout", - "heartbeatInterval", - "autoCommitInterval", - "autoCommitThreshold", - "maxBytesPerPartition", - "maxBytes", - "maxSocketErrors", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_brokers", - "__template_topics", - "__template_groupId", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - return m + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class CreateInputInputElasticType(str, Enum): - r"""Source type identifier.""" + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ELASTIC = "elastic" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" -class CreateInputInputElasticAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): + auth_type: Annotated[ + Optional[CreateInputInputElasticAuthenticationType], + pydantic.Field(alias="authType"), + ] = None r"""Authentication type""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Auth Tokens - AUTH_TOKENS = "authTokens" - - -class CreateInputAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): + api_version: Annotated[ + Optional[CreateInputAPIVersion], pydantic.Field(alias="apiVersion") + ] = None r"""The API version to use for communicating with the server""" - # 6.8.4 - SIX_DOT_8_DOT_4 = "6.8.4" - # 8.3.2 - EIGHT_DOT_3_DOT_2 = "8.3.2" - # Custom - CUSTOM = "custom" - - -class CreateInputInputElasticAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter credentials directly, or select a stored secret""" - - NONE = "none" - MANUAL = "manual" - SECRET = "secret" - - -class CreateInputInputElasticProxyModeTypedDict(TypedDict): - enabled: bool - r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" - auth_type: NotRequired[CreateInputInputElasticAuthenticationMethod] - r"""Enter credentials directly, or select a stored secret""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - url: NotRequired[str] - r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - remove_headers: NotRequired[List[str]] - r"""List of headers to remove from the request to proxy""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" -class CreateInputInputElasticProxyMode(BaseModel): - enabled: bool - r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - auth_type: Annotated[ - Optional[CreateInputInputElasticAuthenticationMethod], - pydantic.Field(alias="authType"), + proxy_mode: Annotated[ + Optional[CreateInputInputElasticProxyMode], pydantic.Field(alias="proxyMode") ] = None - r"""Enter credentials directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" username: Optional[str] = None r"""Username""" @@ -8830,32 +577,60 @@ class CreateInputInputElasticProxyMode(BaseModel): ] = None r"""Select or create a secret that references your credentials""" - url: Optional[str] = None - r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Bearer tokens to include in the authorization header""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + custom_api_version: Annotated[ + Optional[str], pydantic.Field(alias="customAPIVersion") ] = None - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + r"""Custom version information to respond to requests""" - remove_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="removeHeaders") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""List of headers to remove from the request to proxy""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_elastic_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticAPI") + ] = None + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputInputElasticAuthenticationMethod(value) + return models.CreateInputInputElasticAuthenticationType(value) + except ValueError: + return value + return value + + @field_serializer("api_version") + def serialize_api_version(self, value): + if isinstance(value, str): + try: + return models.CreateInputAPIVersion(value) except ValueError: return value return value @@ -8864,15 +639,43 @@ def serialize_auth_type(self, value): def serialize_model(self, handler): optional_fields = set( [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", "authType", + "apiVersion", + "extraHttpHeaders", + "metadata", + "proxyMode", + "description", "username", "password", "credentialsSecret", - "url", - "rejectUnauthorized", - "removeHeaders", - "timeoutSec", - "__template_url", + "authTokens", + "customAPIVersion", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_elasticAPI", + "__template_authTokens", ] ) serialized = handler(self) @@ -8889,17 +692,19 @@ def serialize_model(self, handler): return m -class CreateInputInputElasticTypedDict(TypedDict): +class CreateInputInputAzureVnetFlowLogType(str, Enum): + r"""Connector type identifier.""" + + AZURE_VNET_FLOW_LOG = "azure_vnet_flow_log" + + +class CreateInputInputAzureVnetFlowLogTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputElasticType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - elastic_api: str - r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" + type: CreateInputInputAzureVnetFlowLogType + r"""Connector type identifier.""" + queue_name: str + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8915,80 +720,68 @@ class CreateInputInputElasticTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[CreateInputInputElasticAuthenticationType] - r"""Authentication type""" - api_version: NotRequired[CreateInputAPIVersion] - r"""The API version to use for communicating with the server""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + visibility_timeout: NotRequired[float] + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + max_messages: NotRequired[float] + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" + max_dequeue_count: NotRequired[float] + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" + service_period_secs: NotRequired[float] + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - proxy_mode: NotRequired[CreateInputInputElasticProxyModeTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] + r"""Authentication method""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - auth_tokens: NotRequired[List[str]] - r"""Bearer tokens to include in the authorization header""" - custom_api_version: NotRequired[str] - r"""Custom version information to respond to requests""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_elastic_api: NotRequired[str] - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" -class CreateInputInputElastic(BaseModel): +class CreateInputInputAzureVnetFlowLog(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputElasticType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" + type: CreateInputInputAzureVnetFlowLogType + r"""Connector type identifier.""" - elastic_api: Annotated[str, pydantic.Field(alias="elasticAPI")] - r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -9015,111 +808,82 @@ class CreateInputInputElastic(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") ] = None - r"""Add request headers to events, in the __headers field""" + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + max_dequeue_count: Annotated[ + Optional[float], pydantic.Field(alias="maxDequeueCount") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + service_period_secs: Annotated[ + Optional[float], pydantic.Field(alias="servicePeriodSecs") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" auth_type: Annotated[ - Optional[CreateInputInputElasticAuthenticationType], + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], pydantic.Field(alias="authType"), ] = None - r"""Authentication type""" - - api_version: Annotated[ - Optional[CreateInputAPIVersion], pydantic.Field(alias="apiVersion") - ] = None - r"""The API version to use for communicating with the server""" + r"""Authentication method""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - proxy_mode: Annotated[ - Optional[CreateInputInputElasticProxyMode], pydantic.Field(alias="proxyMode") + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") ] = None + r"""The name of your Azure storage account""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" - username: Optional[str] = None - r"""Username""" + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" - password: Optional[str] = None - r"""Password""" + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") ] = None - r"""Select or create a secret that references your credentials""" - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Bearer tokens to include in the authorization header""" + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - custom_api_version: Annotated[ - Optional[str], pydantic.Field(alias="customAPIVersion") + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") ] = None - r"""Custom version information to respond to requests""" + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -9131,40 +895,40 @@ class CreateInputInputElastic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_elastic_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticAPI") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputInputElasticAuthenticationType(value) - except ValueError: - return value - return value - - @field_serializer("api_version") - def serialize_api_version(self, value): - if isinstance(value, str): - try: - return models.CreateInputAPIVersion(value) + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) + ) except ValueError: return value return value @@ -9181,35 +945,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "apiVersion", - "extraHttpHeaders", + "fileFilter", + "visibilityTimeout", + "numReceivers", + "maxMessages", + "maxDequeueCount", + "servicePeriodSecs", "metadata", - "proxyMode", + "breakerRulesets", + "staleChannelFlushMs", + "authType", "description", - "username", - "password", - "credentialsSecret", - "authTokens", - "customAPIVersion", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", - "__template_elasticAPI", - "__template_authTokens", + "__template_queueName", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", ] ) serialized = handler(self) @@ -9260,6 +1021,8 @@ class CreateInputInputAzureBlobTypedDict(TypedDict): r"""The duration (in seconds) which pollers should be validated and restarted if exited""" skip_on_error: NotRequired[bool] r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] @@ -9272,6 +1035,8 @@ class CreateInputInputAzureBlobTypedDict(TypedDict): r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" auth_type: NotRequired[AuthenticationMethodOptions] r"""Authentication method""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" connection_string: NotRequired[str] @@ -9368,6 +1133,9 @@ class CreateInputInputAzureBlob(BaseModel): skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -9396,6 +1164,9 @@ class CreateInputInputAzureBlob(BaseModel): ] = None r"""Authentication method""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -9500,12 +1271,14 @@ def serialize_model(self, handler): "maxMessages", "servicePeriodSecs", "skipOnError", + "encoding", "metadata", "breakerRulesets", "staleChannelFlushMs", "parquetChunkSizeMB", "parquetChunkDownloadTimeout", "authType", + "autoParse", "description", "connectionString", "textSecret", @@ -9549,7 +1322,7 @@ class CreateInputInputSplunkHecType(str, Enum): class CreateInputInputSplunkHecAuthTokenTypedDict(TypedDict): token: str r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" token_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -9568,7 +1341,7 @@ class CreateInputInputSplunkHecAuthToken(BaseModel): r"""Shared secret to be provided by any client (Authorization: )""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -9594,7 +1367,7 @@ class CreateInputInputSplunkHecAuthToken(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -9685,6 +1458,8 @@ class CreateInputInputSplunkHecTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" use_fwd_timezone: NotRequired[bool] r"""Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event""" drop_control_fields: NotRequired[bool] @@ -9834,6 +1609,9 @@ class CreateInputInputSplunkHec(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + use_fwd_timezone: Annotated[ Optional[bool], pydantic.Field(alias="useFwdTimezone") ] = None @@ -9921,6 +1699,7 @@ def serialize_model(self, handler): "splunkHecAcks", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "useFwdTimezone", "dropControlFields", "extractMetrics", @@ -10388,22 +2167,44 @@ def serialize_model(self, handler): class CreateInputInputSplunkAuthTokenTypedDict(TypedDict): - token: str + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Description""" class CreateInputInputSplunkAuthToken(BaseModel): - token: str + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: Optional[str] = None r"""Description""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description"]) + optional_fields = set(["authType", "tokenSecret", "token", "description"]) serialized = handler(self) m = {} @@ -10482,6 +2283,8 @@ class CreateInputInputSplunkTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" auth_tokens: NotRequired[List[CreateInputInputSplunkAuthTokenTypedDict]] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" max_s2_sversion: NotRequired[CreateInputMaxS2SVersion] @@ -10594,6 +2397,9 @@ class CreateInputInputSplunk(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + auth_tokens: Annotated[ Optional[List[CreateInputInputSplunkAuthToken]], pydantic.Field(alias="authTokens"), @@ -10651,66 +2457,188 @@ class CreateInputInputSplunk(BaseModel): ] = None r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): + if isinstance(value, str): + try: + return models.CreateInputMaxS2SVersion(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CreateInputCompression(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "authTokens", + "maxS2Sversion", + "description", + "useFwdTimezone", + "dropControlFields", + "extractMetrics", + "compress", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_maxS2Sversion", + "__template_compress", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputHTTPType(str, Enum): + r"""Source type identifier.""" + + HTTP = "http" + + +class CreateInputInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputInputHTTPInputHTTPAuthTokensExtItemsType(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): - if isinstance(value, str): - try: - return models.CreateInputMaxS2SVersion(value) - except ValueError: - return value - return value + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" - @field_serializer("compress") - def serialize_compress(self, value): + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputCompression(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "authTokens", - "maxS2Sversion", - "description", - "useFwdTimezone", - "dropControlFields", - "extractMetrics", - "compress", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_maxS2Sversion", - "__template_compress", - ] - ) + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) serialized = handler(self) m = {} @@ -10725,10 +2653,22 @@ def serialize_model(self, handler): return m -class CreateInputInputHTTPType(str, Enum): - r"""Source type identifier.""" +CreateInputInputHTTPAuthTokensExtTypedDict = TypeAliasType( + "CreateInputInputHTTPAuthTokensExtTypedDict", + Union[ + CreateInputInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) - HTTP = "http" + +CreateInputInputHTTPAuthTokensExt = TypeAliasType( + "CreateInputInputHTTPAuthTokensExt", + Union[ + CreateInputInputHTTPInputHTTPAuthTokensExtItemsType, + CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint, + ], +) class CreateInputInputHTTPTypedDict(TypedDict): @@ -10791,7 +2731,7 @@ class CreateInputInputHTTPTypedDict(TypedDict): r"""Enable Splunk HEC acknowledgements""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] + auth_tokens_ext: NotRequired[List[CreateInputInputHTTPAuthTokensExtTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -10934,7 +2874,7 @@ class CreateInputInputHTTP(BaseModel): r"""Fields to add to events from this input""" auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], + Optional[List[CreateInputInputHTTPAuthTokensExt]], pydantic.Field(alias="authTokensExt"), ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -11134,6 +3074,8 @@ class CreateInputInputMskTypedDict(TypedDict): r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" max_socket_errors: NotRequired[float] r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] @@ -11351,6 +3293,9 @@ class CreateInputInputMsk(BaseModel): ] = None r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11465,6 +3410,7 @@ def serialize_model(self, handler): "maxBytesPerPartition", "maxBytes", "maxSocketErrors", + "autoParse", "description", "awsApiKey", "awsSecret", @@ -11573,6 +3519,8 @@ class CreateInputInputKafkaTypedDict(TypedDict): r"""Maximum number of network errors before the consumer re-creates a socket""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -11730,6 +3678,9 @@ class CreateInputInputKafka(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11792,6 +3743,7 @@ def serialize_model(self, handler): "maxBytes", "maxSocketErrors", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", @@ -11967,74 +3919,91 @@ def serialize_model(self, handler): CreateInputInputTypedDict = TypeAliasType( "CreateInputInputTypedDict", Union[ - CreateInputInputDatagenTypedDict, - CreateInputInputKubeEventsTypedDict, CreateInputInputCriblTypedDict, - CreateInputInputAppleUnifiedLogsTypedDict, + CreateInputInputKubeEventsTypedDict, + CreateInputInputDatagenTypedDict, CreateInputInputCriblmetricsTypedDict, + CreateInputInputAppleUnifiedLogsTypedDict, CreateInputInputCollectionTypedDict, CreateInputInputKubeMetricsTypedDict, CreateInputInputSystemStateTypedDict, - CreateInputInputSystemMetricsTypedDict, CreateInputInputWindowsMetricsTypedDict, + CreateInputInputSystemMetricsTypedDict, CreateInputInputJournalFilesTypedDict, + CreateInputInputKubeLogsTypedDict, CreateInputInputModelDrivenTelemetryTypedDict, CreateInputInputExecTypedDict, + CreateInputInputProofpointPodTypedDict, CreateInputInputRawUDPTypedDict, - CreateInputInputKubeLogsTypedDict, CreateInputInputSnmpTypedDict, CreateInputInputWinEventLogsTypedDict, + CreateInputInputAnthropicEnterpriseAnalyticsTypedDict, CreateInputInputMetricsTypedDict, CreateInputInputNetflowTypedDict, CreateInputInputCriblTCPTypedDict, CreateInputInputOpenaiTypedDict, - CreateInputInputEventhubAmqpTypedDict, CreateInputInputTcpjsonTypedDict, CreateInputInputOktaTypedDict, - CreateInputInputGooglePubsubTypedDict, + CreateInputInputEventhubAmqpTypedDict, CreateInputInputCriblHTTPTypedDict, - CreateInputInputTCPTypedDict, + CreateInputInputGooglePubsubTypedDict, CreateInputInputFirehoseTypedDict, + CreateInputInputSailpointHecTypedDict, CreateInputInputOffice365ServiceTypedDict, - CreateInputInputAnthropicComplianceTypedDict, + CreateInputInputTCPTypedDict, CreateInputInputWizTypedDict, + CreateInputInputAkamaiHecTypedDict, + CreateInputInputAnthropicComplianceTypedDict, CreateInputInputDatadogAgentTypedDict, + CreateInputInputOffice365MgmtTypedDict, CreateInputInputAppscopeTypedDict, - CreateInputInputFileTypedDict, CreateInputInputSplunkTypedDict, - CreateInputInputOffice365MgmtTypedDict, + CreateInputInputBeyondtrustHecTypedDict, CreateInputInputWefTypedDict, - CreateInputInputLokiTypedDict, + CreateInputInputAzureVnetFlowLogTypedDict, CreateInputInputWizWebhookTypedDict, - CreateInputInputUpwindHecTypedDict, + CreateInputInputLokiTypedDict, CreateInputInputSysdigHecTypedDict, + CreateInputInputVectraAiHecTypedDict, + CreateInputInputGigamonHecTypedDict, + CreateInputInputUpwindHecTypedDict, + CreateInputInputPingIdentityPingoneTypedDict, + CreateInputInputExtrahopRevealx360TypedDict, + CreateInputInputFileTypedDict, + CreateInputInputTrellixHecTypedDict, CreateInputInputPrometheusRwTypedDict, - CreateInputInputConfluentCloudTypedDict, - CreateInputInputKafkaTypedDict, + CreateInputInputAquaSecurityHecTypedDict, + CreateInputInputHashicorpHcpVaultDedicatedTypedDict, + CreateInputInputMimecastHecTypedDict, + CreateInputInputTrendMicroVisionOneTypedDict, CreateInputInputZscalerHecTypedDict, - CreateInputInputCriblLakeHTTPTypedDict, CreateInputInputHTTPTypedDict, - CreateInputInputEventhubTypedDict, - CreateInputInputAzureBlobTypedDict, - CreateInputInputOpenaiComplianceLogsTypedDict, + CreateInputInputCriblLakeHTTPTypedDict, + CreateInputInputF5BigIPTypedDict, CreateInputInputCloudflareHecTypedDict, + CreateInputInputKafkaTypedDict, + CreateInputInputOpenaiComplianceLogsTypedDict, + CreateInputInputConfluentCloudTypedDict, + CreateInputInputMicrosoftCopilotTypedDict, + CreateInputInputEventhubTypedDict, CreateInputInputElasticTypedDict, - CreateInputInputOpenTelemetryTypedDict, CreateInputInputSplunkHecTypedDict, + CreateInputInputAzureBlobTypedDict, + CreateInputInputOpenTelemetryTypedDict, CreateInputInputSqsTypedDict, - CreateInputInputKinesisTypedDict, - CreateInputInputOffice365MsgTraceTypedDict, CreateInputInputMicrosoftGraphTypedDict, + CreateInputInputOffice365MsgTraceTypedDict, + CreateInputInputKinesisTypedDict, CreateInputInputHTTPRawTypedDict, CreateInputInputSplunkSearchTypedDict, CreateInputInputServicenowTableTypedDict, CreateInputInputMskTypedDict, CreateInputInputEdgePrometheusTypedDict, CreateInputInputCrowdstrikeTypedDict, - CreateInputInputS3TypedDict, + CreateInputInputPrometheusTypedDict, CreateInputInputBedrockS3TypedDict, CreateInputInputSecurityLakeTypedDict, - CreateInputInputPrometheusTypedDict, + CreateInputInputS3TypedDict, CreateInputInputS3InventoryTypedDict, CreateInputInputGrafanaUnionTypedDict, CreateInputInputSyslogUnionTypedDict, @@ -12053,6 +4022,7 @@ def serialize_model(self, handler): Annotated[CreateInputInputSplunkSearch, Tag("splunk_search")], Annotated[CreateInputInputSplunkHec, Tag("splunk_hec")], Annotated[CreateInputInputAzureBlob, Tag("azure_blob")], + Annotated[CreateInputInputAzureVnetFlowLog, Tag("azure_vnet_flow_log")], Annotated[CreateInputInputElastic, Tag("elastic")], Annotated[CreateInputInputConfluentCloud, Tag("confluent_cloud")], Annotated[CreateInputInputGrafanaUnion, Tag("grafana")], @@ -12109,13 +4079,35 @@ def serialize_model(self, handler): Annotated[CreateInputInputSecurityLake, Tag("security_lake")], Annotated[CreateInputInputBedrockS3, Tag("bedrock_s3")], Annotated[CreateInputInputServicenowTable, Tag("servicenow_table")], + Annotated[CreateInputInputProofpointPod, Tag("proofpoint_pod")], Annotated[CreateInputInputZscalerHec, Tag("zscaler_hec")], Annotated[CreateInputInputCloudflareHec, Tag("cloudflare_hec")], Annotated[CreateInputInputSysdigHec, Tag("sysdig_hec")], Annotated[CreateInputInputUpwindHec, Tag("upwind_hec")], + Annotated[CreateInputInputTrellixHec, Tag("trellix_hec")], + Annotated[CreateInputInputSailpointHec, Tag("sailpoint_hec")], + Annotated[CreateInputInputExtrahopRevealx360, Tag("extrahop_revealx_360")], + Annotated[CreateInputInputAquaSecurityHec, Tag("aqua_security_hec")], Annotated[CreateInputInputOpenaiComplianceLogs, Tag("openai_compliance_logs")], Annotated[CreateInputInputAnthropicCompliance, Tag("anthropic_compliance")], + Annotated[ + CreateInputInputAnthropicEnterpriseAnalytics, + Tag("anthropic_enterprise_analytics"), + ], + Annotated[CreateInputInputMicrosoftCopilot, Tag("microsoft_copilot")], Annotated[CreateInputInputOkta, Tag("okta")], + Annotated[CreateInputInputAkamaiHec, Tag("akamai_hec")], + Annotated[CreateInputInputPingIdentityPingone, Tag("ping_identity_pingone")], + Annotated[CreateInputInputGigamonHec, Tag("gigamon_hec")], + Annotated[CreateInputInputVectraAiHec, Tag("vectra_ai_hec")], + Annotated[CreateInputInputF5BigIP, Tag("f5_big_ip")], + Annotated[CreateInputInputBeyondtrustHec, Tag("beyondtrust_hec")], + Annotated[ + CreateInputInputHashicorpHcpVaultDedicated, + Tag("hashicorp_hcp_vault_dedicated"), + ], + Annotated[CreateInputInputMimecastHec, Tag("mimecast_hec")], + Annotated[CreateInputInputTrendMicroVisionOne, Tag("trend_micro_vision_one")], ], Discriminator(lambda m: get_discriminator(m, "type", "type")), ] @@ -12123,207 +4115,47 @@ def serialize_model(self, handler): try: - CreateInputCollectors.model_rebuild() -except NameError: - pass -try: - CreateInputInputSystemStatePersistence.model_rebuild() -except NameError: - pass -try: - CreateInputInputSystemState.model_rebuild() -except NameError: - pass -try: - CreateInputInputSystemMetricsCPU.model_rebuild() -except NameError: - pass -try: - CreateInputInputSystemMetricsNetwork.model_rebuild() -except NameError: - pass -try: - CreateInputInputSystemMetricsDisk.model_rebuild() -except NameError: - pass -try: - CreateInputContainer.model_rebuild() -except NameError: - pass -try: - CreateInputInputSystemMetricsPersistence.model_rebuild() -except NameError: - pass -try: - CreateInputInputSystemMetrics.model_rebuild() -except NameError: - pass -try: - CreateInputInputTcpjson.model_rebuild() -except NameError: - pass -try: - CreateInputSplunkHecMetadata.model_rebuild() -except NameError: - pass -try: - CreateInputElasticsearchMetadata.model_rebuild() -except NameError: - pass -try: - CreateInputAuthTokensExt.model_rebuild() -except NameError: - pass -try: - CreateInputInputCriblLakeHTTP.model_rebuild() -except NameError: - pass -try: - CreateInputInputCriblHTTP.model_rebuild() -except NameError: - pass -try: - CreateInputInputCriblTCP.model_rebuild() -except NameError: - pass -try: - CreateInputInputCribl.model_rebuild() -except NameError: - pass -try: - CreateInputInputGooglePubsub.model_rebuild() -except NameError: - pass -try: - CreateInputInputFirehose.model_rebuild() -except NameError: - pass -try: - CreateInputInputExec.model_rebuild() -except NameError: - pass -try: - CreateInputCertificate.model_rebuild() -except NameError: - pass -try: - CreateInputAuth.model_rebuild() -except NameError: - pass -try: - CreateInputAzureBlobStorage.model_rebuild() -except NameError: - pass -try: - CreateInputCheckpointing.model_rebuild() -except NameError: - pass -try: - CreateInputInputEventhubAmqp.model_rebuild() -except NameError: - pass -try: - CreateInputInputEventhub.model_rebuild() -except NameError: - pass -try: - CreateInputInputMicrosoftGraph.model_rebuild() -except NameError: - pass -try: - CreateInputInputOffice365MsgTrace.model_rebuild() -except NameError: - pass -try: - CreateInputInputOffice365ServiceContentConfig.model_rebuild() -except NameError: - pass -try: - CreateInputInputOffice365Service.model_rebuild() -except NameError: - pass -try: - CreateInputInputOffice365MgmtContentConfig.model_rebuild() -except NameError: - pass -try: - CreateInputInputOffice365Mgmt.model_rebuild() -except NameError: - pass -try: - CreateInputPodFilter.model_rebuild() -except NameError: - pass -try: - CreateInputInputEdgePrometheus.model_rebuild() -except NameError: - pass -try: - CreateInputInputPrometheus.model_rebuild() -except NameError: - pass -try: - CreateInputInputPrometheusRw.model_rebuild() -except NameError: - pass -try: - CreateInputInputLoki.model_rebuild() -except NameError: - pass -try: - CreateInputPrometheusAuth2.model_rebuild() -except NameError: - pass -try: - CreateInputLokiAuth2.model_rebuild() -except NameError: - pass -try: - CreateInputInputGrafanaGrafana2.model_rebuild() -except NameError: - pass -try: - CreateInputPrometheusAuth1.model_rebuild() + CreateInputInputElasticProxyMode.model_rebuild() except NameError: pass try: - CreateInputLokiAuth1.model_rebuild() + CreateInputInputElastic.model_rebuild() except NameError: pass try: - CreateInputInputGrafanaGrafana1.model_rebuild() + CreateInputInputAzureVnetFlowLog.model_rebuild() except NameError: pass try: - CreateInputInputConfluentCloud.model_rebuild() + CreateInputInputAzureBlob.model_rebuild() except NameError: pass try: - CreateInputInputElasticProxyMode.model_rebuild() + CreateInputInputSplunkHecAuthToken.model_rebuild() except NameError: pass try: - CreateInputInputElastic.model_rebuild() + CreateInputInputSplunkHec.model_rebuild() except NameError: pass try: - CreateInputInputAzureBlob.model_rebuild() + CreateInputInputSplunkSearch.model_rebuild() except NameError: pass try: - CreateInputInputSplunkHecAuthToken.model_rebuild() + CreateInputInputSplunkAuthToken.model_rebuild() except NameError: pass try: - CreateInputInputSplunkHec.model_rebuild() + CreateInputInputSplunk.model_rebuild() except NameError: pass try: - CreateInputInputSplunkSearch.model_rebuild() + CreateInputInputHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() except NameError: pass try: - CreateInputInputSplunk.model_rebuild() + CreateInputInputHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() except NameError: pass try: diff --git a/src/cribl_control_plane/models/createinput_inputelastic_type.py b/src/cribl_control_plane/models/createinput_inputelastic_type.py new file mode 100644 index 000000000..fa0bf0612 --- /dev/null +++ b/src/cribl_control_plane/models/createinput_inputelastic_type.py @@ -0,0 +1,13871 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, +) +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, +) +from .authenticationmethodoptionsmanualsecret import ( + AuthenticationMethodOptionsManualSecret, +) +from .authenticationmethodoptionss3collectorconf import ( + AuthenticationMethodOptionsS3CollectorConf, +) +from .authenticationmethodoptionssasl import AuthenticationMethodOptionsSasl +from .authenticationtype import AuthenticationType, AuthenticationTypeTypedDict +from .authenticationtypeoptionslokiauth import AuthenticationTypeOptionsLokiAuth +from .authenticationtypeoptionsprometheusauth import ( + AuthenticationTypeOptionsPrometheusAuth, +) +from .authenticationtypeuse import AuthenticationTypeUse, AuthenticationTypeUseTypedDict +from .authtokenconfinputcribltcp import ( + AuthTokenConfInputCriblTCP, + AuthTokenConfInputCriblTCPTypedDict, +) +from .certificatetype import CertificateType, CertificateTypeTypedDict +from .certoptionstype import CertOptionsType, CertOptionsTypeTypedDict +from .checkpointingtype import CheckpointingType, CheckpointingTypeTypedDict +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .createinput_v3user import CreateInputV3User, CreateInputV3UserTypedDict +from .datacompressionformatoptionspersistence import ( + DataCompressionFormatOptionsPersistence, +) +from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict +from .googleauthenticationmethodoptions import GoogleAuthenticationMethodOptions +from .gputype import GpuType, GpuTypeTypedDict +from .kafkaschemaregistryauthenticationtype import ( + KafkaSchemaRegistryAuthenticationType, + KafkaSchemaRegistryAuthenticationTypeTypedDict, +) +from .logleveloptions import LogLevelOptions +from .logleveloptionscontentconfigitems import LogLevelOptionsContentConfigItems +from .logleveloptionsdebugerror import LogLevelOptionsDebugError +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .microsoftentraidauthenticationendpointoptionssasl import ( + MicrosoftEntraIDAuthenticationEndpointOptionsSasl, +) +from .modeoptionshost import ModeOptionsHost +from .pqtype import PqType, PqTypeTypedDict +from .preprocesstype import PreprocessType, PreprocessTypeTypedDict +from .processtype import ProcessType, ProcessTypeTypedDict +from .protocoloptionstargetsitems import ProtocolOptionsTargetsItems +from .recordtypeoptions import RecordTypeOptions +from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( + RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, +) +from .retryrulestypecodesenableheader import ( + RetryRulesTypeCodesEnableHeader, + RetryRulesTypeCodesEnableHeaderTypedDict, +) +from .ruleconfinputkubemetrics import ( + RuleConfInputKubeMetrics, + RuleConfInputKubeMetricsTypedDict, +) +from .searchfilterconfinputprometheus import ( + SearchFilterConfInputPrometheus, + SearchFilterConfInputPrometheusTypedDict, +) +from .sqsauthenticationmethodoptions import SqsAuthenticationMethodOptions +from .subscriptionplanoptions import SubscriptionPlanOptions +from .tagafterprocessingoptions import TagAfterProcessingOptions +from .tlssettingsclientsidetype import ( + TLSSettingsClientSideType, + TLSSettingsClientSideTypeTypedDict, +) +from .tlssettingsclientsidetypecapathcertpath import ( + TLSSettingsClientSideTypeCaPathCertPath, + TLSSettingsClientSideTypeCaPathCertPathTypedDict, +) +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from .typeoptionsconfluentcloud import TypeOptionsConfluentcloud +from .typeoptionscribltcp import TypeOptionsCribltcp +from .typeoptionsgooglepubsub import TypeOptionsGooglepubsub +from .typeoptionskinesis import TypeOptionsKinesis +from .typeoptionsprometheus import TypeOptionsPrometheus +from .typeoptionss3 import TypeOptionsS3 +from .typeoptionssnmp import TypeOptionsSnmp +from .typeoptionstcpjson import TypeOptionsTcpjson +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class CreateInputSNMPv3AuthenticationTypedDict(TypedDict): + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + v3_auth_enabled: bool + r"""Enabled""" + allow_unmatched_trap: NotRequired[bool] + r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" + v3_users: NotRequired[List[CreateInputV3UserTypedDict]] + r"""User credentials for receiving v3 traps""" + + +class CreateInputSNMPv3Authentication(BaseModel): + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + v3_auth_enabled: Annotated[bool, pydantic.Field(alias="v3AuthEnabled")] + r"""Enabled""" + + allow_unmatched_trap: Annotated[ + Optional[bool], pydantic.Field(alias="allowUnmatchedTrap") + ] = None + r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" + + v3_users: Annotated[ + Optional[List[CreateInputV3User]], pydantic.Field(alias="v3Users") + ] = None + r"""User credentials for receiving v3 traps""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["allowUnmatchedTrap", "v3Users"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSnmpTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsSnmp + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""UDP port to receive SNMP traps on. Defaults to 162.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + snmp_v3_auth: NotRequired[CreateInputSNMPv3AuthenticationTypedDict] + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + varbinds_with_types: NotRequired[bool] + r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + best_effort_parsing: NotRequired[bool] + r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputInputSnmp(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsSnmp + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + + port: float + r"""UDP port to receive SNMP traps on. Defaults to 162.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + snmp_v3_auth: Annotated[ + Optional[CreateInputSNMPv3Authentication], pydantic.Field(alias="snmpV3Auth") + ] = None + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking.""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + varbinds_with_types: Annotated[ + Optional[bool], pydantic.Field(alias="varbindsWithTypes") + ] = None + r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + + best_effort_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="bestEffortParsing") + ] = None + r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "snmpV3Auth", + "maxBufferSize", + "ipWhitelistRegex", + "metadata", + "udpSocketRxBufSize", + "varbindsWithTypes", + "bestEffortParsing", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputS3InventoryType(str, Enum): + r"""Connector type identifier.""" + + S3_INVENTORY = "s3_inventory" + + +class CreateInputInputS3InventoryTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputS3InventoryType + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + checksum_suffix: NotRequired[str] + r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ + max_manifest_size_kb: NotRequired[int] + r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" + validate_inventory_files: NotRequired[bool] + r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + +class CreateInputInputS3Inventory(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputS3InventoryType + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + checksum_suffix: Annotated[ + Optional[str], pydantic.Field(alias="checksumSuffix") + ] = None + r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ + + max_manifest_size_kb: Annotated[ + Optional[int], pydantic.Field(alias="maxManifestSizeKB") + ] = None + r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" + + validate_inventory_files: Annotated[ + Optional[bool], pydantic.Field(alias="validateInventoryFiles") + ] = None + r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "checksumSuffix", + "maxManifestSizeKB", + "validateInventoryFiles", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputS3TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsS3 + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + tag_after_processing: NotRequired[bool] + r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + +class CreateInputInputS3(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsS3 + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + + tag_after_processing: Annotated[ + Optional[bool], pydantic.Field(alias="tagAfterProcessing") + ] = None + r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "encoding", + "tagAfterProcessing", + "autoParse", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputMetricsType(str, Enum): + r"""Connector type identifier.""" + + METRICS = "metrics" + + +class CreateInputInputMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputMetricsType + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + udp_port: NotRequired[float] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + tcp_port: NotRequired[float] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + + +class CreateInputInputMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputMetricsType + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + + tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "udpPort", + "tcpPort", + "maxBufferSize", + "ipWhitelistRegex", + "enableProxyHeader", + "tls", + "metadata", + "udpSocketRxBufSize", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCriblmetricsType(str, Enum): + r"""Connector type identifier.""" + + CRIBLMETRICS = "criblmetrics" + + +class CreateInputInputCriblmetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputCriblmetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + prefix: NotRequired[str] + r"""A prefix that is applied to the metrics provided by Cribl Stream""" + full_fidelity: NotRequired[bool] + r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputCriblmetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputCriblmetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + prefix: Optional[str] = None + r"""A prefix that is applied to the metrics provided by Cribl Stream""" + + full_fidelity: Annotated[Optional[bool], pydantic.Field(alias="fullFidelity")] = ( + None + ) + r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "prefix", + "fullFidelity", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputShardIteratorStart(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Location at which to start reading a shard for the first time""" + + # Earliest record + TRIM_HORIZON = "TRIM_HORIZON" + # Latest record + LATEST = "LATEST" + + +class CreateInputRecordDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + + # Cribl + CRIBL = "cribl" + # Newline JSON + NDJSON = "ndjson" + # Cloudwatch Logs + CLOUDWATCH = "cloudwatch" + # Event per line + LINE = "line" + + +class CreateInputShardLoadBalancing(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + + # Consistent Hashing + CONSISTENT_HASHING = "ConsistentHashing" + # Round Robin + ROUND_ROBIN = "RoundRobin" + + +class CreateInputInputKinesisTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsKinesis + r"""Connector type identifier.""" + stream_name: str + r"""Kinesis Data Stream to read data from""" + region: str + r"""Region where the Kinesis stream is located""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + service_interval: NotRequired[float] + r"""Time interval in minutes between consecutive service calls""" + shard_expr: NotRequired[str] + r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + shard_iterator_type: NotRequired[CreateInputShardIteratorStart] + r"""Location at which to start reading a shard for the first time""" + payload_format: NotRequired[CreateInputRecordDataFormat] + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + get_records_limit: NotRequired[float] + r"""Maximum number of records per getRecords call""" + get_records_limit_total: NotRequired[float] + r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + load_balancing_algorithm: NotRequired[CreateInputShardLoadBalancing] + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Kinesis stream""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + verify_kpl_check_sums: NotRequired[bool] + r"""Verify Kinesis Producer Library (KPL) event checksums""" + avoid_duplicates: NotRequired[bool] + r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + template_shard_iterator_type: NotRequired[str] + r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + template_payload_format: NotRequired[str] + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + +class CreateInputInputKinesis(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsKinesis + r"""Connector type identifier.""" + + stream_name: Annotated[str, pydantic.Field(alias="streamName")] + r"""Kinesis Data Stream to read data from""" + + region: str + r"""Region where the Kinesis stream is located""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + service_interval: Annotated[ + Optional[float], pydantic.Field(alias="serviceInterval") + ] = None + r"""Time interval in minutes between consecutive service calls""" + + shard_expr: Annotated[Optional[str], pydantic.Field(alias="shardExpr")] = None + r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + + shard_iterator_type: Annotated[ + Optional[CreateInputShardIteratorStart], + pydantic.Field(alias="shardIteratorType"), + ] = None + r"""Location at which to start reading a shard for the first time""" + + payload_format: Annotated[ + Optional[CreateInputRecordDataFormat], pydantic.Field(alias="payloadFormat") + ] = None + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + + get_records_limit: Annotated[ + Optional[float], pydantic.Field(alias="getRecordsLimit") + ] = None + r"""Maximum number of records per getRecords call""" + + get_records_limit_total: Annotated[ + Optional[float], pydantic.Field(alias="getRecordsLimitTotal") + ] = None + r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + + load_balancing_algorithm: Annotated[ + Optional[CreateInputShardLoadBalancing], + pydantic.Field(alias="loadBalancingAlgorithm"), + ] = None + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + endpoint: Optional[str] = None + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Kinesis stream""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + verify_kpl_check_sums: Annotated[ + Optional[bool], pydantic.Field(alias="verifyKPLCheckSums") + ] = None + r"""Verify Kinesis Producer Library (KPL) event checksums""" + + avoid_duplicates: Annotated[ + Optional[bool], pydantic.Field(alias="avoidDuplicates") + ] = None + r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") + ] = None + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + + template_shard_iterator_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_shardIteratorType") + ] = None + r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + + template_payload_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadFormat") + ] = None + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("shard_iterator_type") + def serialize_shard_iterator_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputShardIteratorStart(value) + except ValueError: + return value + return value + + @field_serializer("payload_format") + def serialize_payload_format(self, value): + if isinstance(value, str): + try: + return models.CreateInputRecordDataFormat(value) + except ValueError: + return value + return value + + @field_serializer("load_balancing_algorithm") + def serialize_load_balancing_algorithm(self, value): + if isinstance(value, str): + try: + return models.CreateInputShardLoadBalancing(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "serviceInterval", + "shardExpr", + "shardIteratorType", + "payloadFormat", + "getRecordsLimit", + "getRecordsLimitTotal", + "loadBalancingAlgorithm", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "verifyKPLCheckSums", + "avoidDuplicates", + "metadata", + "autoParse", + "description", + "awsApiKey", + "awsSecret", + "__template_environment", + "__template_streamtags", + "__template_streamName", + "__template_shardIteratorType", + "__template_payloadFormat", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputHTTPRawType(str, Enum): + r"""Source type identifier.""" + + HTTP_RAW = "http_raw" + + +class CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputHTTPRawAuthTokensExtTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputInputHTTPRawAuthTokensExt(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateInputInputHTTPRawAuthTokensExtUnionTypedDict = TypeAliasType( + "CreateInputInputHTTPRawAuthTokensExtUnionTypedDict", + Union[ + CreateInputInputHTTPRawAuthTokensExtTypedDict, + CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +CreateInputInputHTTPRawAuthTokensExtUnion = TypeAliasType( + "CreateInputInputHTTPRawAuthTokensExtUnion", + Union[ + CreateInputInputHTTPRawAuthTokensExt, + CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint, + ], +) + + +class CreateInputInputHTTPRawTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputHTTPRawType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + allowed_paths: NotRequired[List[str]] + r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" + allowed_methods: NotRequired[List[str]] + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + auth_tokens_ext: NotRequired[ + List[CreateInputInputHTTPRawAuthTokensExtUnionTypedDict] + ] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + access_control_allow_methods: NotRequired[List[str]] + r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + access_control_expose_headers: NotRequired[List[str]] + r"""Headers the browser is allowed to access from the response""" + access_control_allow_credentials: NotRequired[bool] + r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + access_control_max_age: NotRequired[float] + r"""How long browsers should cache the preflight response""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_allowed_paths: NotRequired[str] + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class CreateInputInputHTTPRaw(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputHTTPRawType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + allowed_paths: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedPaths") + ] = None + r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" + + allowed_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedMethods") + ] = None + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + + auth_tokens_ext: Annotated[ + Optional[List[CreateInputInputHTTPRawAuthTokensExtUnion]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + + access_control_allow_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowMethods") + ] = None + r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + + access_control_expose_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlExposeHeaders") + ] = None + r"""Headers the browser is allowed to access from the response""" + + access_control_allow_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="accessControlAllowCredentials") + ] = None + r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + + access_control_max_age: Annotated[ + Optional[float], pydantic.Field(alias="accessControlMaxAge") + ] = None + r"""How long browsers should cache the preflight response""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + template_allowed_paths: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedPaths") + ] = None + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "metadata", + "allowedPaths", + "allowedMethods", + "authTokensExt", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "accessControlAllowMethods", + "accessControlExposeHeaders", + "accessControlAllowCredentials", + "accessControlMaxAge", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + "__template_allowedPaths", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputDatagenType(str, Enum): + r"""Connector type identifier.""" + + DATAGEN = "datagen" + + +class CreateInputSampleTypedDict(TypedDict): + sample: str + r"""Data Generator File Name""" + events_per_sec: float + r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" + + +class CreateInputSample(BaseModel): + sample: str + r"""Data Generator File Name""" + + events_per_sec: Annotated[float, pydantic.Field(alias="eventsPerSec")] + r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" + + +class CreateInputInputDatagenTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputDatagenType + r"""Connector type identifier.""" + samples: List[CreateInputSampleTypedDict] + r"""Datagens""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputDatagen(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputDatagenType + r"""Connector type identifier.""" + + samples: List[CreateInputSample] + r"""Datagens""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputDatadogAgentType(str, Enum): + r"""Source type identifier.""" + + DATADOG_AGENT = "datadog_agent" + + +class CreateInputSamplingRuleTypedDict(TypedDict): + service: str + r"""Datadog service name""" + environment: str + r"""Datadog environment name (example: prod, staging)""" + rate: float + r"""Sampling rate for this service/environment combination (0.0–1.0)""" + + +class CreateInputSamplingRule(BaseModel): + service: str + r"""Datadog service name""" + + environment: str + r"""Datadog environment name (example: prod, staging)""" + + rate: float + r"""Sampling rate for this service/environment combination (0.0–1.0)""" + + +class CreateInputInputDatadogAgentProxyModeTypedDict(TypedDict): + enabled: bool + r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" + reject_unauthorized: NotRequired[bool] + r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + + +class CreateInputInputDatadogAgentProxyMode(BaseModel): + enabled: bool + r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["rejectUnauthorized"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputDatadogAgentTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputDatadogAgentType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + extract_metrics: NotRequired[bool] + r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + sampling_rate: NotRequired[float] + r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + sampling_rules: NotRequired[List[CreateInputSamplingRuleTypedDict]] + r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + proxy_mode: NotRequired[CreateInputInputDatadogAgentProxyModeTypedDict] + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputInputDatadogAgent(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputDatadogAgentType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + extract_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="extractMetrics") + ] = None + r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + + sampling_rate: Annotated[Optional[float], pydantic.Field(alias="samplingRate")] = ( + None + ) + r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + + sampling_rules: Annotated[ + Optional[List[CreateInputSamplingRule]], pydantic.Field(alias="samplingRules") + ] = None + r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + proxy_mode: Annotated[ + Optional[CreateInputInputDatadogAgentProxyMode], + pydantic.Field(alias="proxyMode"), + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "extractMetrics", + "samplingRate", + "samplingRules", + "metadata", + "proxyMode", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCrowdstrikeType(str, Enum): + r"""Connector type identifier.""" + + CROWDSTRIKE = "crowdstrike" + + +class CreateInputInputCrowdstrikeTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputCrowdstrikeType + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + +class CreateInputInputCrowdstrike(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputCrowdstrikeType + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "checkpointing", + "pollTimeout", + "encoding", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsType(str, Enum): + r"""Connector type identifier.""" + + WINDOWS_METRICS = "windows_metrics" + + +class CreateInputInputWindowsMetricsSystemMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of details for system metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputWindowsMetricsSystemTypedDict(TypedDict): + mode: NotRequired[CreateInputInputWindowsMetricsSystemMode] + r"""Select the level of details for system metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all system information""" + + +class CreateInputInputWindowsMetricsSystem(BaseModel): + mode: Optional[CreateInputInputWindowsMetricsSystemMode] = None + r"""Select the level of details for system metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all system information""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputWindowsMetricsSystemMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of details for CPU metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputWindowsMetricsCPUTypedDict(TypedDict): + mode: NotRequired[CreateInputInputWindowsMetricsCPUMode] + r"""Select the level of details for CPU metrics""" + per_cpu: NotRequired[bool] + r"""Generate metrics for each CPU""" + detail: NotRequired[bool] + r"""Generate metrics for all CPU states""" + time: NotRequired[bool] + r"""Generate raw, monotonic CPU time counters""" + + +class CreateInputInputWindowsMetricsCPU(BaseModel): + mode: Optional[CreateInputInputWindowsMetricsCPUMode] = None + r"""Select the level of details for CPU metrics""" + + per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None + r"""Generate metrics for each CPU""" + + detail: Optional[bool] = None + r"""Generate metrics for all CPU states""" + + time: Optional[bool] = None + r"""Generate raw, monotonic CPU time counters""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputWindowsMetricsCPUMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perCpu", "detail", "time"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsMemoryMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of details for memory metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputWindowsMetricsMemoryTypedDict(TypedDict): + mode: NotRequired[CreateInputInputWindowsMetricsMemoryMode] + r"""Select the level of details for memory metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all memory states""" + + +class CreateInputInputWindowsMetricsMemory(BaseModel): + mode: Optional[CreateInputInputWindowsMetricsMemoryMode] = None + r"""Select the level of details for memory metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all memory states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputWindowsMetricsMemoryMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsNetworkMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for network metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputWindowsMetricsNetworkTypedDict(TypedDict): + mode: NotRequired[CreateInputInputWindowsMetricsNetworkMode] + r"""Select the level of details for network metrics""" + detail: NotRequired[bool] + r"""Generate full network metrics""" + protocols: NotRequired[bool] + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + devices: NotRequired[List[str]] + r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + per_interface: NotRequired[bool] + r"""Generate separate metrics for each interface""" + + +class CreateInputInputWindowsMetricsNetwork(BaseModel): + mode: Optional[CreateInputInputWindowsMetricsNetworkMode] = None + r"""Select the level of details for network metrics""" + + detail: Optional[bool] = None + r"""Generate full network metrics""" + + protocols: Optional[bool] = None + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + + devices: Optional[List[str]] = None + r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + + per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + None + ) + r"""Generate separate metrics for each interface""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputWindowsMetricsNetworkMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["mode", "detail", "protocols", "devices", "perInterface"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of details for disk metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputWindowsMetricsDiskTypedDict(TypedDict): + mode: NotRequired[CreateInputInputWindowsMetricsDiskMode] + r"""Select the level of details for disk metrics""" + per_volume: NotRequired[bool] + r"""Generate separate metrics for each volume""" + detail: NotRequired[bool] + r"""Generate full disk metrics""" + volumes: NotRequired[List[str]] + r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" + + +class CreateInputInputWindowsMetricsDisk(BaseModel): + mode: Optional[CreateInputInputWindowsMetricsDiskMode] = None + r"""Select the level of details for disk metrics""" + + per_volume: Annotated[Optional[bool], pydantic.Field(alias="perVolume")] = None + r"""Generate separate metrics for each volume""" + + detail: Optional[bool] = None + r"""Generate full disk metrics""" + + volumes: Optional[List[str]] = None + r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputWindowsMetricsDiskMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perVolume", "detail", "volumes"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsCustomTypedDict(TypedDict): + system: NotRequired[CreateInputInputWindowsMetricsSystemTypedDict] + cpu: NotRequired[CreateInputInputWindowsMetricsCPUTypedDict] + memory: NotRequired[CreateInputInputWindowsMetricsMemoryTypedDict] + network: NotRequired[CreateInputInputWindowsMetricsNetworkTypedDict] + disk: NotRequired[CreateInputInputWindowsMetricsDiskTypedDict] + + +class CreateInputInputWindowsMetricsCustom(BaseModel): + system: Optional[CreateInputInputWindowsMetricsSystem] = None + + cpu: Optional[CreateInputInputWindowsMetricsCPU] = None + + memory: Optional[CreateInputInputWindowsMetricsMemory] = None + + network: Optional[CreateInputInputWindowsMetricsNetwork] = None + + disk: Optional[CreateInputInputWindowsMetricsDisk] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["system", "cpu", "memory", "network", "disk"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsHostTypedDict(TypedDict): + mode: NotRequired[ModeOptionsHost] + r"""Select level of detail for host metrics""" + custom: NotRequired[CreateInputInputWindowsMetricsCustomTypedDict] + + +class CreateInputInputWindowsMetricsHost(BaseModel): + mode: Optional[ModeOptionsHost] = None + r"""Select level of detail for host metrics""" + + custom: Optional[CreateInputInputWindowsMetricsCustom] = None + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptionsHost(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "custom"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + + +class CreateInputInputWindowsMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWindowsMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputWindowsMetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + host: NotRequired[CreateInputInputWindowsMetricsHostTypedDict] + process: NotRequired[ProcessTypeTypedDict] + gpu: NotRequired[GpuTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[CreateInputInputWindowsMetricsPersistenceTypedDict] + r"""persistence""" + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputWindowsMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputWindowsMetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + + host: Optional[CreateInputInputWindowsMetricsHost] = None + + process: Optional[ProcessType] = None + + gpu: Optional[GpuType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[CreateInputInputWindowsMetricsPersistence] = None + r"""persistence""" + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "host", + "process", + "gpu", + "metadata", + "persistence", + "disableNativeModule", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputKubeEventsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_EVENTS = "kube_events" + + +class CreateInputInputKubeEventsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputKubeEventsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] + r"""Filtering on event fields""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputKubeEvents(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputKubeEventsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + rules: Optional[List[RuleConfInputKubeMetrics]] = None + r"""Filtering on event fields""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "rules", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputKubeLogsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_LOGS = "kube_logs" + + +class CreateInputInputKubeLogsRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class CreateInputInputKubeLogsRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputKubeLogsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputKubeLogsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + rules: NotRequired[List[CreateInputInputKubeLogsRuleTypedDict]] + r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + timestamps: NotRequired[bool] + r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + line_buffer_limit: NotRequired[float] + r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + lb_disable_assembly: NotRequired[bool] + r"""Internal flag to disable LB worker payload reassembly.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[DiskSpoolingTypeTypedDict] + r"""Disk Spooling""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputKubeLogs(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputKubeLogsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + + rules: Optional[List[CreateInputInputKubeLogsRule]] = None + r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + + timestamps: Optional[bool] = None + r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + + line_buffer_limit: Annotated[ + Optional[float], pydantic.Field(alias="lineBufferLimit") + ] = None + r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + + lb_disable_assembly: Annotated[ + Optional[bool], pydantic.Field(alias="__LBDisableAssembly") + ] = None + r"""Internal flag to disable LB worker payload reassembly.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[DiskSpoolingType] = None + r"""Disk Spooling""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "rules", + "timestamps", + "lineBufferLimit", + "__LBDisableAssembly", + "metadata", + "persistence", + "breakerRulesets", + "staleChannelFlushMs", + "enableLoadBalancing", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputKubeMetricsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_METRICS = "kube_metrics" + + +class CreateInputInputKubeMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics on disk for Cribl Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + + +class CreateInputInputKubeMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics on disk for Cribl Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputKubeMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputKubeMetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + scrape_kubelet: NotRequired[bool] + r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + scrape_cadvisor: NotRequired[bool] + r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] + r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[CreateInputInputKubeMetricsPersistenceTypedDict] + r"""persistence""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputKubeMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputKubeMetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + + scrape_kubelet: Annotated[Optional[bool], pydantic.Field(alias="scrapeKubelet")] = ( + None + ) + r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + + scrape_cadvisor: Annotated[ + Optional[bool], pydantic.Field(alias="scrapeCadvisor") + ] = None + r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + + rules: Optional[List[RuleConfInputKubeMetrics]] = None + r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[CreateInputInputKubeMetricsPersistence] = None + r"""persistence""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "scrapeKubelet", + "scrapeCadvisor", + "rules", + "metadata", + "persistence", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemStateType(str, Enum): + r"""Connector type identifier.""" + + SYSTEM_STATE = "system_state" + + +class CreateInputHostsFileTypedDict(TypedDict): + r"""Creates events based on entries collected from the hosts file""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputHostsFile(BaseModel): + r"""Creates events based on entries collected from the hosts file""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInterfacesTypedDict(TypedDict): + r"""Creates events for each of the host’s network interfaces""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputInterfaces(BaseModel): + r"""Creates events for each of the host’s network interfaces""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputDisksAndFileSystemsTypedDict(TypedDict): + r"""Creates events for physical disks, partitions, and file systems""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputDisksAndFileSystems(BaseModel): + r"""Creates events for physical disks, partitions, and file systems""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputHostInfoTypedDict(TypedDict): + r"""Creates events based on the host system’s current state""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputHostInfo(BaseModel): + r"""Creates events based on the host system’s current state""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputRoutesTypedDict(TypedDict): + r"""Creates events based on entries collected from the host’s network routes""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputRoutes(BaseModel): + r"""Creates events based on entries collected from the host’s network routes""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputDNSTypedDict(TypedDict): + r"""Creates events for DNS resolvers and search entries""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputDNS(BaseModel): + r"""Creates events for DNS resolvers and search entries""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputUsersAndGroupsTypedDict(TypedDict): + r"""Creates events for local users and groups""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputUsersAndGroups(BaseModel): + r"""Creates events for local users and groups""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputFirewallTypedDict(TypedDict): + r"""Creates events for Firewall rules entries""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputFirewall(BaseModel): + r"""Creates events for Firewall rules entries""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputServicesTypedDict(TypedDict): + r"""Creates events from the list of services""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputServices(BaseModel): + r"""Creates events from the list of services""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputListeningPortsTypedDict(TypedDict): + r"""Creates events from list of listening ports""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputListeningPorts(BaseModel): + r"""Creates events from list of listening ports""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputLoggedInUsersTypedDict(TypedDict): + r"""Creates events from list of logged-in users""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputLoggedInUsers(BaseModel): + r"""Creates events from list of logged-in users""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputCollectorsTypedDict(TypedDict): + hostsfile: NotRequired[CreateInputHostsFileTypedDict] + r"""Creates events based on entries collected from the hosts file""" + interfaces: NotRequired[CreateInputInterfacesTypedDict] + r"""Creates events for each of the host’s network interfaces""" + disk: NotRequired[CreateInputDisksAndFileSystemsTypedDict] + r"""Creates events for physical disks, partitions, and file systems""" + metadata: NotRequired[CreateInputHostInfoTypedDict] + r"""Creates events based on the host system’s current state""" + routes: NotRequired[CreateInputRoutesTypedDict] + r"""Creates events based on entries collected from the host’s network routes""" + dns: NotRequired[CreateInputDNSTypedDict] + r"""Creates events for DNS resolvers and search entries""" + user: NotRequired[CreateInputUsersAndGroupsTypedDict] + r"""Creates events for local users and groups""" + firewall: NotRequired[CreateInputFirewallTypedDict] + r"""Creates events for Firewall rules entries""" + services: NotRequired[CreateInputServicesTypedDict] + r"""Creates events from the list of services""" + ports: NotRequired[CreateInputListeningPortsTypedDict] + r"""Creates events from list of listening ports""" + login_users: NotRequired[CreateInputLoggedInUsersTypedDict] + r"""Creates events from list of logged-in users""" + + +class CreateInputCollectors(BaseModel): + hostsfile: Optional[CreateInputHostsFile] = None + r"""Creates events based on entries collected from the hosts file""" + + interfaces: Optional[CreateInputInterfaces] = None + r"""Creates events for each of the host’s network interfaces""" + + disk: Optional[CreateInputDisksAndFileSystems] = None + r"""Creates events for physical disks, partitions, and file systems""" + + metadata: Optional[CreateInputHostInfo] = None + r"""Creates events based on the host system’s current state""" + + routes: Optional[CreateInputRoutes] = None + r"""Creates events based on entries collected from the host’s network routes""" + + dns: Optional[CreateInputDNS] = None + r"""Creates events for DNS resolvers and search entries""" + + user: Optional[CreateInputUsersAndGroups] = None + r"""Creates events for local users and groups""" + + firewall: Optional[CreateInputFirewall] = None + r"""Creates events for Firewall rules entries""" + + services: Optional[CreateInputServices] = None + r"""Creates events from the list of services""" + + ports: Optional[CreateInputListeningPorts] = None + r"""Creates events from list of listening ports""" + + login_users: Annotated[ + Optional[CreateInputLoggedInUsers], pydantic.Field(alias="loginUsers") + ] = None + r"""Creates events from list of logged-in users""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "hostsfile", + "interfaces", + "disk", + "metadata", + "routes", + "dns", + "user", + "firewall", + "services", + "ports", + "loginUsers", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemStatePersistenceTypedDict(TypedDict): + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" + + +class CreateInputInputSystemStatePersistence(BaseModel): + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemStateTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputSystemStateType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + collectors: NotRequired[CreateInputCollectorsTypedDict] + persistence: NotRequired[CreateInputInputSystemStatePersistenceTypedDict] + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + disable_native_last_log_module: NotRequired[bool] + r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputSystemState(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputSystemStateType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + collectors: Optional[CreateInputCollectors] = None + + persistence: Optional[CreateInputInputSystemStatePersistence] = None + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + + disable_native_last_log_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeLastLogModule") + ] = None + r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "metadata", + "collectors", + "persistence", + "disableNativeModule", + "disableNativeLastLogModule", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsType(str, Enum): + r"""Connector type identifier.""" + + SYSTEM_METRICS = "system_metrics" + + +class CreateInputInputSystemMetricsSystemMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for system metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputSystemMetricsSystemTypedDict(TypedDict): + mode: NotRequired[CreateInputInputSystemMetricsSystemMode] + r"""Select the level of detail for system metrics""" + processes: NotRequired[bool] + r"""Generate metrics for the numbers of processes in various states""" + + +class CreateInputInputSystemMetricsSystem(BaseModel): + mode: Optional[CreateInputInputSystemMetricsSystemMode] = None + r"""Select the level of detail for system metrics""" + + processes: Optional[bool] = None + r"""Generate metrics for the numbers of processes in various states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputSystemMetricsSystemMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "processes"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for CPU metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputSystemMetricsCPUTypedDict(TypedDict): + mode: NotRequired[CreateInputInputSystemMetricsCPUMode] + r"""Select the level of detail for CPU metrics""" + per_cpu: NotRequired[bool] + r"""Generate metrics for each CPU""" + detail: NotRequired[bool] + r"""Generate metrics for all CPU states""" + time: NotRequired[bool] + r"""Generate raw, monotonic CPU time counters""" + + +class CreateInputInputSystemMetricsCPU(BaseModel): + mode: Optional[CreateInputInputSystemMetricsCPUMode] = None + r"""Select the level of detail for CPU metrics""" + + per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None + r"""Generate metrics for each CPU""" + + detail: Optional[bool] = None + r"""Generate metrics for all CPU states""" + + time: Optional[bool] = None + r"""Generate raw, monotonic CPU time counters""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputSystemMetricsCPUMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perCpu", "detail", "time"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsMemoryMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for memory metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputSystemMetricsMemoryTypedDict(TypedDict): + mode: NotRequired[CreateInputInputSystemMetricsMemoryMode] + r"""Select the level of detail for memory metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all memory states""" + + +class CreateInputInputSystemMetricsMemory(BaseModel): + mode: Optional[CreateInputInputSystemMetricsMemoryMode] = None + r"""Select the level of detail for memory metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all memory states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputSystemMetricsMemoryMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsNetworkMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for network metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputSystemMetricsNetworkTypedDict(TypedDict): + mode: NotRequired[CreateInputInputSystemMetricsNetworkMode] + r"""Select the level of detail for network metrics""" + detail: NotRequired[bool] + r"""Generate full network metrics""" + protocols: NotRequired[bool] + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + devices: NotRequired[List[str]] + r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" + per_interface: NotRequired[bool] + r"""Generate separate metrics for each interface""" + + +class CreateInputInputSystemMetricsNetwork(BaseModel): + mode: Optional[CreateInputInputSystemMetricsNetworkMode] = None + r"""Select the level of detail for network metrics""" + + detail: Optional[bool] = None + r"""Generate full network metrics""" + + protocols: Optional[bool] = None + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + + devices: Optional[List[str]] = None + r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" + + per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + None + ) + r"""Generate separate metrics for each interface""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputSystemMetricsNetworkMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["mode", "detail", "protocols", "devices", "perInterface"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for disk metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputSystemMetricsDiskTypedDict(TypedDict): + mode: NotRequired[CreateInputInputSystemMetricsDiskMode] + r"""Select the level of detail for disk metrics""" + detail: NotRequired[bool] + r"""Generate full disk metrics""" + inodes: NotRequired[bool] + r"""Generate filesystem inode metrics""" + devices: NotRequired[List[str]] + r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" + mountpoints: NotRequired[List[str]] + r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" + fstypes: NotRequired[List[str]] + r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" + per_device: NotRequired[bool] + r"""Generate separate metrics for each device""" + + +class CreateInputInputSystemMetricsDisk(BaseModel): + mode: Optional[CreateInputInputSystemMetricsDiskMode] = None + r"""Select the level of detail for disk metrics""" + + detail: Optional[bool] = None + r"""Generate full disk metrics""" + + inodes: Optional[bool] = None + r"""Generate filesystem inode metrics""" + + devices: Optional[List[str]] = None + r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" + + mountpoints: Optional[List[str]] = None + r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" + + fstypes: Optional[List[str]] = None + r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" + + per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None + r"""Generate separate metrics for each device""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputSystemMetricsDiskMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "mode", + "detail", + "inodes", + "devices", + "mountpoints", + "fstypes", + "perDevice", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsCustomTypedDict(TypedDict): + system: NotRequired[CreateInputInputSystemMetricsSystemTypedDict] + cpu: NotRequired[CreateInputInputSystemMetricsCPUTypedDict] + memory: NotRequired[CreateInputInputSystemMetricsMemoryTypedDict] + network: NotRequired[CreateInputInputSystemMetricsNetworkTypedDict] + disk: NotRequired[CreateInputInputSystemMetricsDiskTypedDict] + + +class CreateInputInputSystemMetricsCustom(BaseModel): + system: Optional[CreateInputInputSystemMetricsSystem] = None + + cpu: Optional[CreateInputInputSystemMetricsCPU] = None + + memory: Optional[CreateInputInputSystemMetricsMemory] = None + + network: Optional[CreateInputInputSystemMetricsNetwork] = None + + disk: Optional[CreateInputInputSystemMetricsDisk] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["system", "cpu", "memory", "network", "disk"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsHostTypedDict(TypedDict): + mode: NotRequired[ModeOptionsHost] + r"""Select level of detail for host metrics""" + custom: NotRequired[CreateInputInputSystemMetricsCustomTypedDict] + + +class CreateInputInputSystemMetricsHost(BaseModel): + mode: Optional[ModeOptionsHost] = None + r"""Select level of detail for host metrics""" + + custom: Optional[CreateInputInputSystemMetricsCustom] = None + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptionsHost(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "custom"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputContainerMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for container metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputInputSystemMetricsFilterTypedDict(TypedDict): + expr: str + r"""Expression""" + + +class CreateInputInputSystemMetricsFilter(BaseModel): + expr: str + r"""Expression""" + + +class CreateInputContainerTypedDict(TypedDict): + mode: NotRequired[CreateInputContainerMode] + r"""Select the level of detail for container metrics""" + docker_socket: NotRequired[List[str]] + r"""Full paths for Docker's UNIX-domain socket""" + docker_timeout: NotRequired[float] + r"""Timeout, in seconds, for the Docker API""" + filters: NotRequired[List[CreateInputInputSystemMetricsFilterTypedDict]] + r"""Containers matching any of these will be included. All are included if no filters are added.""" + all_containers: NotRequired[bool] + r"""Include stopped and paused containers""" + per_device: NotRequired[bool] + r"""Generate separate metrics for each device""" + detail: NotRequired[bool] + r"""Generate full container metrics""" + + +class CreateInputContainer(BaseModel): + mode: Optional[CreateInputContainerMode] = None + r"""Select the level of detail for container metrics""" + + docker_socket: Annotated[ + Optional[List[str]], pydantic.Field(alias="dockerSocket") + ] = None + r"""Full paths for Docker's UNIX-domain socket""" + + docker_timeout: Annotated[ + Optional[float], pydantic.Field(alias="dockerTimeout") + ] = None + r"""Timeout, in seconds, for the Docker API""" + + filters: Optional[List[CreateInputInputSystemMetricsFilter]] = None + r"""Containers matching any of these will be included. All are included if no filters are added.""" + + all_containers: Annotated[Optional[bool], pydantic.Field(alias="allContainers")] = ( + None + ) + r"""Include stopped and paused containers""" + + per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None + r"""Generate separate metrics for each device""" + + detail: Optional[bool] = None + r"""Generate full container metrics""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputContainerMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "mode", + "dockerSocket", + "dockerTimeout", + "filters", + "allContainers", + "perDevice", + "detail", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" + + +class CreateInputInputSystemMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputSystemMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputSystemMetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + host: NotRequired[CreateInputInputSystemMetricsHostTypedDict] + process: NotRequired[ProcessTypeTypedDict] + container: NotRequired[CreateInputContainerTypedDict] + gpu: NotRequired[GpuTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[CreateInputInputSystemMetricsPersistenceTypedDict] + r"""persistence""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputSystemMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputSystemMetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + + host: Optional[CreateInputInputSystemMetricsHost] = None + + process: Optional[ProcessType] = None + + container: Optional[CreateInputContainer] = None + + gpu: Optional[GpuType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[CreateInputInputSystemMetricsPersistence] = None + r"""persistence""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "host", + "process", + "container", + "gpu", + "metadata", + "persistence", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputTcpjsonTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsTcpjson + r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputInputTcpjson(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsTcpjson + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to establish a connection""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "enableLoadBalancing", + "authType", + "description", + "authToken", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCriblLakeHTTPType(str, Enum): + r"""Source type identifier.""" + + CRIBL_LAKE_HTTP = "cribl_lake_http" + + +class CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict(TypedDict): + enabled: NotRequired[bool] + r"""When enabled, the token value is available on events as __hecToken""" + default_dataset: NotRequired[str] + allowed_indexes_at_token: NotRequired[List[str]] + + +class CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata(BaseModel): + enabled: Optional[bool] = None + r"""When enabled, the token value is available on events as __hecToken""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""Elasticsearch""" + default_dataset: NotRequired[str] + + +class CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata(BaseModel): + enabled: Optional[bool] = None + r"""Elasticsearch""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict( + TypedDict +): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Token""" + description: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + splunk_hec_metadata: NotRequired[ + CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict + ] + + +class CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Token""" + + description: Optional[str] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + splunk_hec_metadata: Annotated[ + Optional[CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata], + pydantic.Field(alias="splunkHecMetadata"), + ] = None + + elasticsearch_metadata: Annotated[ + Optional[CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata], + pydantic.Field(alias="elasticsearchMetadata"), + ] = None + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "tokenSecret", + "token", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict(TypedDict): + enabled: NotRequired[bool] + r"""When enabled, the token value is available on events as __hecToken""" + default_dataset: NotRequired[str] + allowed_indexes_at_token: NotRequired[List[str]] + + +class CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata(BaseModel): + enabled: Optional[bool] = None + r"""When enabled, the token value is available on events as __hecToken""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""Elasticsearch""" + default_dataset: NotRequired[str] + + +class CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata(BaseModel): + enabled: Optional[bool] = None + r"""Elasticsearch""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict(TypedDict): + token: str + r"""Token""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + splunk_hec_metadata: NotRequired[ + CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict + ] + + +class CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType(BaseModel): + token: str + r"""Token""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + splunk_hec_metadata: Annotated[ + Optional[CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata], + pydantic.Field(alias="splunkHecMetadata"), + ] = None + + elasticsearch_metadata: Annotated[ + Optional[CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata], + pydantic.Field(alias="elasticsearchMetadata"), + ] = None + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "tokenSecret", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateInputInputCriblLakeHTTPAuthTokensExtTypedDict = TypeAliasType( + "CreateInputInputCriblLakeHTTPAuthTokensExtTypedDict", + Union[ + CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +CreateInputInputCriblLakeHTTPAuthTokensExt = TypeAliasType( + "CreateInputInputCriblLakeHTTPAuthTokensExt", + Union[ + CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + ], +) + + +class CreateInputInputCriblLakeHTTPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputCriblLakeHTTPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + cribl_api: NotRequired[str] + r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" + elastic_api: NotRequired[str] + r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" + splunk_hec_api: NotRequired[str] + r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" + splunk_hec_acks: NotRequired[bool] + r"""Enable Splunk HEC acknowledgements""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_tokens_ext: NotRequired[ + List[CreateInputInputCriblLakeHTTPAuthTokensExtTypedDict] + ] + r"""Auth tokens""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_cribl_api: NotRequired[str] + r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" + template_elastic_api: NotRequired[str] + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + template_splunk_hec_api: NotRequired[str] + r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" + + +class CreateInputInputCriblLakeHTTP(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputCriblLakeHTTPType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + cribl_api: Annotated[Optional[str], pydantic.Field(alias="criblAPI")] = None + r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" + + elastic_api: Annotated[Optional[str], pydantic.Field(alias="elasticAPI")] = None + r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" + + splunk_hec_api: Annotated[Optional[str], pydantic.Field(alias="splunkHecAPI")] = ( + None + ) + r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" + + splunk_hec_acks: Annotated[ + Optional[bool], pydantic.Field(alias="splunkHecAcks") + ] = None + r"""Enable Splunk HEC acknowledgements""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_tokens_ext: Annotated[ + Optional[List[CreateInputInputCriblLakeHTTPAuthTokensExt]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Auth tokens""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + template_cribl_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_criblAPI") + ] = None + r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" + + template_elastic_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticAPI") + ] = None + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + + template_splunk_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_splunkHecAPI") + ] = None + r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "criblAPI", + "elasticAPI", + "splunkHecAPI", + "splunkHecAcks", + "metadata", + "authTokensExt", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + "__template_criblAPI", + "__template_elasticAPI", + "__template_splunkHecAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCriblHTTPType(str, Enum): + r"""Source type identifier.""" + + CRIBL_HTTP = "cribl_http" + + +class CreateInputInputCriblHTTPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputCriblHTTPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputInputCriblHTTP(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputCriblHTTPType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + ] = None + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCriblTCPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsCribltcp + r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputInputCriblTCP(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsCribltcp + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + ] = None + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "enableLoadBalancing", + "authTokens", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputCriblType(str, Enum): + r"""Connector type identifier.""" + + CRIBL = "cribl" + + +class CreateInputInputCriblTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputCriblType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + filter_: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputCribl(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputCriblType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "filter", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputGooglePubsubTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsGooglepubsub + r"""Connector type identifier.""" + topic_name: str + r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" + subscription_name: str + r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + monitor_subscription: NotRequired[bool] + r"""Use when the subscription is not created by this Source and topic is not known""" + create_topic: NotRequired[bool] + r"""Create topic if it does not exist""" + create_subscription: NotRequired[bool] + r"""Create subscription if it does not exist""" + region: NotRequired[str] + r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + max_backlog: NotRequired[float] + r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" + concurrency: NotRequired[float] + r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" + request_timeout: NotRequired[float] + r"""Pull request timeout, in milliseconds""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + ordered_delivery: NotRequired[bool] + r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_name: NotRequired[str] + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + template_subscription_name: NotRequired[str] + r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + +class CreateInputInputGooglePubsub(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsGooglepubsub + r"""Connector type identifier.""" + + topic_name: Annotated[str, pydantic.Field(alias="topicName")] + r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" + + subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] + r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + monitor_subscription: Annotated[ + Optional[bool], pydantic.Field(alias="monitorSubscription") + ] = None + r"""Use when the subscription is not created by this Source and topic is not known""" + + create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None + r"""Create topic if it does not exist""" + + create_subscription: Annotated[ + Optional[bool], pydantic.Field(alias="createSubscription") + ] = None + r"""Create subscription if it does not exist""" + + region: Optional[str] = None + r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + + google_auth_method: Annotated[ + Optional[GoogleAuthenticationMethodOptions], + pydantic.Field(alias="googleAuthMethod"), + ] = None + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + secret: Optional[str] = None + r"""Select or create a stored text secret""" + + max_backlog: Annotated[Optional[float], pydantic.Field(alias="maxBacklog")] = None + r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" + + concurrency: Optional[float] = None + r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Pull request timeout, in milliseconds""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + ordered_delivery: Annotated[ + Optional[bool], pydantic.Field(alias="orderedDelivery") + ] = None + r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_topic_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicName") + ] = None + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + + template_subscription_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_subscriptionName") + ] = None + r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): + if isinstance(value, str): + try: + return models.GoogleAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "monitorSubscription", + "createTopic", + "createSubscription", + "region", + "googleAuthMethod", + "serviceAccountCredentials", + "secret", + "maxBacklog", + "concurrency", + "requestTimeout", + "metadata", + "autoParse", + "description", + "orderedDelivery", + "__template_environment", + "__template_streamtags", + "__template_topicName", + "__template_subscriptionName", + "__template_region", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputFirehoseType(str, Enum): + r"""Source type identifier.""" + + FIREHOSE = "firehose" + + +class CreateInputInputFirehoseTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputFirehoseType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + +class CreateInputInputFirehose(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputFirehoseType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputExecType(str, Enum): + r"""Connector type identifier.""" + + EXEC = "exec" + + +class CreateInputScheduleType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + + INTERVAL = "interval" + CRON_SCHEDULE = "cronSchedule" + + +class CreateInputInputExecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputExecType + r"""Connector type identifier.""" + command: str + r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" + disabled: NotRequired[bool] + r"""Disabled""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + script: NotRequired[str] + r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" + retries: NotRequired[float] + r"""Maximum number of retry attempts in the event that the command fails""" + schedule_type: NotRequired[CreateInputScheduleType] + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + interval: NotRequired[float] + r"""Interval between command executions in seconds.""" + cron_schedule: NotRequired[str] + r"""Cron schedule to execute the command on.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputExec(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputExecType + r"""Connector type identifier.""" + + command: str + r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" + + disabled: Optional[bool] = None + r"""Disabled""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + script: Optional[str] = None + r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" + + retries: Optional[float] = None + r"""Maximum number of retry attempts in the event that the command fails""" + + schedule_type: Annotated[ + Optional[CreateInputScheduleType], pydantic.Field(alias="scheduleType") + ] = None + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + interval: Optional[float] = None + r"""Interval between command executions in seconds.""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Cron schedule to execute the command on.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @field_serializer("schedule_type") + def serialize_schedule_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputScheduleType(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "script", + "retries", + "scheduleType", + "breakerRulesets", + "staleChannelFlushMs", + "metadata", + "autoParse", + "description", + "interval", + "cronSchedule", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputEventhubAmqpType(str, Enum): + r"""Connector type identifier.""" + + EVENTHUB_AMQP = "eventhub_amqp" + + +class CreateInputAuthenticationMechanism(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Authentication mechanism""" + + # Connection String + CONNECTION_STRING = "connection-string" + # OAuth Bearer + OAUTH_BEARER = "oauth-bearer" + + +class CreateInputCertificateTypedDict(TypedDict): + certificate_name: str + r"""The certificate you registered as credentials for your app in the Azure portal""" + cert_path: str + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + priv_key_path: str + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + + +class CreateInputCertificate(BaseModel): + certificate_name: Annotated[str, pydantic.Field(alias="certificateName")] + r"""The certificate you registered as credentials for your app in the Azure portal""" + + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["passphrase"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputAuthTypedDict(TypedDict): + mechanism: CreateInputAuthenticationMechanism + r"""Authentication mechanism""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] + r"""Authentication method""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CreateInputCertificateTypedDict] + oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] + r"""Endpoint used to acquire authentication tokens from Azure""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory""" + fully_qualified_namespace: NotRequired[str] + r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" + template_oauth_endpoint: NotRequired[str] + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_fully_qualified_namespace: NotRequired[str] + r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" + + +class CreateInputAuth(BaseModel): + mechanism: CreateInputAuthenticationMechanism + r"""Authentication mechanism""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + client_secret_auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuth], + pydantic.Field(alias="clientSecretAuthType"), + ] = None + r"""Authentication method""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CreateInputCertificate] = None + + oauth_endpoint: Annotated[ + Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], + pydantic.Field(alias="oauthEndpoint"), + ] = None + r"""Endpoint used to acquire authentication tokens from Azure""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory""" + + fully_qualified_namespace: Annotated[ + Optional[str], pydantic.Field(alias="fullyQualifiedNamespace") + ] = None + r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" + + template_oauth_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_oauthEndpoint") + ] = None + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_fully_qualified_namespace: Annotated[ + Optional[str], pydantic.Field(alias="__template_fullyQualifiedNamespace") + ] = None + r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" + + @field_serializer("mechanism") + def serialize_mechanism(self, value): + if isinstance(value, str): + try: + return models.CreateInputAuthenticationMechanism(value) + except ValueError: + return value + return value + + @field_serializer("client_secret_auth_type") + def serialize_client_secret_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuth(value) + except ValueError: + return value + return value + + @field_serializer("oauth_endpoint") + def serialize_oauth_endpoint(self, value): + if isinstance(value, str): + try: + return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "textSecret", + "clientSecretAuthType", + "clientTextSecret", + "certificate", + "oauthEndpoint", + "clientId", + "tenantId", + "fullyQualifiedNamespace", + "__template_oauthEndpoint", + "__template_clientId", + "__template_tenantId", + "__template_fullyQualifiedNamespace", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputAzureBlobStorageTypedDict(TypedDict): + r"""Azure Blob Storage""" + + container_name: str + r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] + r"""Authentication method""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + +class CreateInputAzureBlobStorage(BaseModel): + r"""Azure Blob Storage""" + + container_name: Annotated[str, pydantic.Field(alias="containerName")] + r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") + ] = None + r"""The name of your Azure storage account""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" + + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") + ] = None + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") + ] = None + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputCheckpointingTypedDict(TypedDict): + blob_store: CreateInputAzureBlobStorageTypedDict + r"""Azure Blob Storage""" + + +class CreateInputCheckpointing(BaseModel): + blob_store: Annotated[ + CreateInputAzureBlobStorage, pydantic.Field(alias="blobStore") + ] + r"""Azure Blob Storage""" + + +class CreateInputInputEventhubAmqpTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputEventhubAmqpType + r"""Connector type identifier.""" + consumer_group: str + r"""The consumer group this instance belongs to. Default is '$Default'.""" + checkpointing: CreateInputCheckpointingTypedDict + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + event_hub_name: NotRequired[str] + r"""The name of the Event Hub to consume from""" + auth: NotRequired[CreateInputAuthTypedDict] + from_beginning: NotRequired[bool] + r"""Start reading from earliest available data; relevant only during initial subscription""" + max_batch_size: NotRequired[int] + r"""Maximum number of events in each batch delivered to the consumer""" + max_wait_time_in_seconds: NotRequired[int] + r"""Maximum time to wait for a batch of events before delivering a partial batch""" + prefetch_count: NotRequired[int] + r"""Number of events to prefetch from the service for processing""" + max_retries: NotRequired[int] + r"""Maximum number of retries per operation""" + initial_backoff: NotRequired[int] + r"""Initial delay before the first retry, in milliseconds""" + max_backoff: NotRequired[int] + r"""Maximum delay between retries, in milliseconds""" + timeout_in_ms: NotRequired[int] + r"""Maximum time to wait for a request to complete""" + connection_initial_backoff: NotRequired[int] + r"""Initial delay before the first reconnection attempt, in milliseconds""" + connection_max_backoff: NotRequired[int] + r"""Maximum delay between reconnection attempts, in milliseconds""" + connection_timeout_in_ms: NotRequired[int] + r"""Maximum time to wait for a connection to complete""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputInputEventhubAmqp(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputEventhubAmqpType + r"""Connector type identifier.""" + + consumer_group: Annotated[str, pydantic.Field(alias="consumerGroup")] + r"""The consumer group this instance belongs to. Default is '$Default'.""" + + checkpointing: CreateInputCheckpointing + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + event_hub_name: Annotated[Optional[str], pydantic.Field(alias="eventHubName")] = ( + None + ) + r"""The name of the Event Hub to consume from""" + + auth: Optional[CreateInputAuth] = None + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Start reading from earliest available data; relevant only during initial subscription""" + + max_batch_size: Annotated[Optional[int], pydantic.Field(alias="maxBatchSize")] = ( + None + ) + r"""Maximum number of events in each batch delivered to the consumer""" + + max_wait_time_in_seconds: Annotated[ + Optional[int], pydantic.Field(alias="maxWaitTimeInSeconds") + ] = None + r"""Maximum time to wait for a batch of events before delivering a partial batch""" + + prefetch_count: Annotated[Optional[int], pydantic.Field(alias="prefetchCount")] = ( + None + ) + r"""Number of events to prefetch from the service for processing""" + + max_retries: Annotated[Optional[int], pydantic.Field(alias="maxRetries")] = None + r"""Maximum number of retries per operation""" + + initial_backoff: Annotated[ + Optional[int], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial delay before the first retry, in milliseconds""" + + max_backoff: Annotated[Optional[int], pydantic.Field(alias="maxBackoff")] = None + r"""Maximum delay between retries, in milliseconds""" + + timeout_in_ms: Annotated[Optional[int], pydantic.Field(alias="timeoutInMs")] = None + r"""Maximum time to wait for a request to complete""" + + connection_initial_backoff: Annotated[ + Optional[int], pydantic.Field(alias="connectionInitialBackoff") + ] = None + r"""Initial delay before the first reconnection attempt, in milliseconds""" + + connection_max_backoff: Annotated[ + Optional[int], pydantic.Field(alias="connectionMaxBackoff") + ] = None + r"""Maximum delay between reconnection attempts, in milliseconds""" + + connection_timeout_in_ms: Annotated[ + Optional[int], pydantic.Field(alias="connectionTimeoutInMs") + ] = None + r"""Maximum time to wait for a connection to complete""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "eventHubName", + "auth", + "fromBeginning", + "maxBatchSize", + "maxWaitTimeInSeconds", + "prefetchCount", + "maxRetries", + "initialBackoff", + "maxBackoff", + "timeoutInMs", + "connectionInitialBackoff", + "connectionMaxBackoff", + "connectionTimeoutInMs", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputEventhubType(str, Enum): + r"""Connector type identifier.""" + + EVENTHUB = "eventhub" + + +class CreateInputInputEventhubTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputEventhubType + r"""Connector type identifier.""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + topics: List[str] + r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + group_id: NotRequired[str] + r"""The consumer group this instance belongs to. Default is 'Cribl'.""" + from_beginning: NotRequired[bool] + r"""Start reading from earliest available data; relevant only during initial subscription""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeUseTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeTypedDict] + r"""TLS settings (client side)""" + session_timeout: NotRequired[float] + r""" + Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + rebalance_timeout: NotRequired[float] + r""" + Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + heartbeat_interval: NotRequired[float] + r""" + Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + auto_commit_interval: NotRequired[float] + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + auto_commit_threshold: NotRequired[float] + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + max_bytes_per_partition: NotRequired[float] + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + max_bytes: NotRequired[float] + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + max_socket_errors: NotRequired[float] + r"""Maximum number of network errors before the consumer re-creates a socket""" + minimize_duplicates: NotRequired[bool] + r"""Minimize duplicate events by starting only one consumer for each topic partition""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topics: NotRequired[str] + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + template_group_id: NotRequired[str] + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + +class CreateInputInputEventhub(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputEventhubType + r"""Connector type identifier.""" + + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + + topics: List[str] + r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""The consumer group this instance belongs to. Default is 'Cribl'.""" + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Start reading from earliest available data; relevant only during initial subscription""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" + + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationTypeUse] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideType] = None + r"""TLS settings (client side)""" + + session_timeout: Annotated[ + Optional[float], pydantic.Field(alias="sessionTimeout") + ] = None + r""" + Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + rebalance_timeout: Annotated[ + Optional[float], pydantic.Field(alias="rebalanceTimeout") + ] = None + r""" + Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + heartbeat_interval: Annotated[ + Optional[float], pydantic.Field(alias="heartbeatInterval") + ] = None + r""" + Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + auto_commit_interval: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitInterval") + ] = None + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + auto_commit_threshold: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitThreshold") + ] = None + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + max_bytes_per_partition: Annotated[ + Optional[float], pydantic.Field(alias="maxBytesPerPartition") + ] = None + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + + max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + + max_socket_errors: Annotated[ + Optional[float], pydantic.Field(alias="maxSocketErrors") + ] = None + r"""Maximum number of network errors before the consumer re-creates a socket""" + + minimize_duplicates: Annotated[ + Optional[bool], pydantic.Field(alias="minimizeDuplicates") + ] = None + r"""Minimize duplicate events by starting only one consumer for each topic partition""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") + ] = None + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + + template_topics: Annotated[ + Optional[str], pydantic.Field(alias="__template_topics") + ] = None + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + + template_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_groupId") + ] = None + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "groupId", + "fromBeginning", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", + "sessionTimeout", + "rebalanceTimeout", + "heartbeatInterval", + "autoCommitInterval", + "autoCommitThreshold", + "maxBytesPerPartition", + "maxBytes", + "maxSocketErrors", + "minimizeDuplicates", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "__template_brokers", + "__template_topics", + "__template_groupId", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputMicrosoftGraphType(str, Enum): + r"""Connector type identifier.""" + + MICROSOFT_GRAPH = "microsoft_graph" + + +class CreateInputInputMicrosoftGraphAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + OAUTH = "oauth" + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class CreateInputInputMicrosoftGraphSubscriptionPlan( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + # Microsoft 365 Enterprise + ENTERPRISE_GCC = "enterprise_gcc" + # Microsoft 365 GCC + GCC = "gcc" + # Microsoft 365 GCC High + GCC_HIGH = "gcc_high" + # Microsoft 365 DoD + DOD = "dod" + # Microsoft 365 China (21Vianet) + CHINA = "china" + + +class CreateInputInputMicrosoftGraphTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputMicrosoftGraphType + r"""Connector type identifier.""" + url: str + r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + start_date: NotRequired[str] + r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + end_date: NotRequired[str] + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + disable_time_filter: NotRequired[bool] + r"""Disables time filtering of events when a date range is specified.""" + max_pages: NotRequired[int] + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + auth_type: NotRequired[CreateInputInputMicrosoftGraphAuthenticationMethod] + r"""Select authentication method.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + reschedule_dropped_tasks: NotRequired[bool] + r"""Reschedule tasks that failed with non-fatal errors""" + max_task_reschedule: NotRequired[float] + r"""Maximum number of times a task can be rescheduled""" + log_level: NotRequired[LogLevelOptionsDebugError] + r"""Log Level (verbosity) for collection runtime behavior.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""client_secret to pass in the OAuth request parameter.""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter.""" + resource: NotRequired[str] + r"""Resource to pass in the OAuth request parameter.""" + plan_type: NotRequired[CreateInputInputMicrosoftGraphSubscriptionPlan] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + text_secret: NotRequired[str] + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + cert_options: NotRequired[CertOptionsTypeTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_resource: NotRequired[str] + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + +class CreateInputInputMicrosoftGraph(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputMicrosoftGraphType + r"""Connector type identifier.""" + + url: str + r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" + + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None + r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + + end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + + disable_time_filter: Annotated[ + Optional[bool], pydantic.Field(alias="disableTimeFilter") + ] = None + r"""Disables time filtering of events when a date range is specified.""" + + max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + + auth_type: Annotated[ + Optional[CreateInputInputMicrosoftGraphAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + reschedule_dropped_tasks: Annotated[ + Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") + ] = None + r"""Reschedule tasks that failed with non-fatal errors""" + + max_task_reschedule: Annotated[ + Optional[float], pydantic.Field(alias="maxTaskReschedule") + ] = None + r"""Maximum number of times a task can be rescheduled""" + + log_level: Annotated[ + Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") + ] = None + r"""Log Level (verbosity) for collection runtime behavior.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""client_secret to pass in the OAuth request parameter.""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter.""" + + resource: Optional[str] = None + r"""Resource to pass in the OAuth request parameter.""" + + plan_type: Annotated[ + Optional[CreateInputInputMicrosoftGraphSubscriptionPlan], + pydantic.Field(alias="planType"), + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + + cert_options: Annotated[ + Optional[CertOptionsType], pydantic.Field(alias="certOptions") + ] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_resource: Annotated[ + Optional[str], pydantic.Field(alias="__template_resource") + ] = None + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputMicrosoftGraphAuthenticationMethod(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsDebugError(value) + except ValueError: + return value + return value + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputMicrosoftGraphSubscriptionPlan(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "startDate", + "endDate", + "timeout", + "disableTimeFilter", + "maxPages", + "authType", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "rescheduleDroppedTasks", + "maxTaskReschedule", + "logLevel", + "retryRules", + "breakerRulesets", + "staleChannelFlushMs", + "description", + "clientSecret", + "tenantId", + "clientId", + "resource", + "planType", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_url", + "__template_tenantId", + "__template_clientId", + "__template_resource", + "__template_planType", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputOffice365MsgTraceType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_MSG_TRACE = "office365_msg_trace" + + +class CreateInputInputOffice365MsgTraceAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + MANUAL = "manual" + SECRET = "secret" + OAUTH = "oauth" + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class CreateInputInputOffice365MsgTraceTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputOffice365MsgTraceType + r"""Connector type identifier.""" + url: str + r"""URL to use when retrieving report data.""" + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + start_date: NotRequired[str] + r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + end_date: NotRequired[str] + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + disable_time_filter: NotRequired[bool] + r"""Disables time filtering of events when a date range is specified.""" + auth_type: NotRequired[CreateInputInputOffice365MsgTraceAuthenticationMethod] + r"""Select authentication method.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + reschedule_dropped_tasks: NotRequired[bool] + r"""Reschedule tasks that failed with non-fatal errors""" + max_task_reschedule: NotRequired[float] + r"""Maximum number of times a task can be rescheduled""" + log_level: NotRequired[LogLevelOptionsDebugError] + r"""Log Level (verbosity) for collection runtime behavior.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username to run Message Trace API call.""" + password: NotRequired[str] + r"""Password to run Message Trace API call.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials.""" + client_secret: NotRequired[str] + r"""client_secret to pass in the OAuth request parameter.""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter.""" + resource: NotRequired[str] + r"""Resource to pass in the OAuth request parameter.""" + plan_type: NotRequired[SubscriptionPlanOptions] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + text_secret: NotRequired[str] + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + cert_options: NotRequired[CertOptionsTypeTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_resource: NotRequired[str] + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + +class CreateInputInputOffice365MsgTrace(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputOffice365MsgTraceType + r"""Connector type identifier.""" + + url: str + r"""URL to use when retrieving report data.""" + + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None + r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + + end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + + disable_time_filter: Annotated[ + Optional[bool], pydantic.Field(alias="disableTimeFilter") + ] = None + r"""Disables time filtering of events when a date range is specified.""" + + auth_type: Annotated[ + Optional[CreateInputInputOffice365MsgTraceAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + reschedule_dropped_tasks: Annotated[ + Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") + ] = None + r"""Reschedule tasks that failed with non-fatal errors""" + + max_task_reschedule: Annotated[ + Optional[float], pydantic.Field(alias="maxTaskReschedule") + ] = None + r"""Maximum number of times a task can be rescheduled""" + + log_level: Annotated[ + Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") + ] = None + r"""Log Level (verbosity) for collection runtime behavior.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username to run Message Trace API call.""" + + password: Optional[str] = None + r"""Password to run Message Trace API call.""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""client_secret to pass in the OAuth request parameter.""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter.""" + + resource: Optional[str] = None + r"""Resource to pass in the OAuth request parameter.""" + + plan_type: Annotated[ + Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + + cert_options: Annotated[ + Optional[CertOptionsType], pydantic.Field(alias="certOptions") + ] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_resource: Annotated[ + Optional[str], pydantic.Field(alias="__template_resource") + ] = None + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputOffice365MsgTraceAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsDebugError(value) + except ValueError: + return value + return value + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "startDate", + "endDate", + "timeout", + "disableTimeFilter", + "authType", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "rescheduleDroppedTasks", + "maxTaskReschedule", + "logLevel", + "retryRules", + "description", + "username", + "password", + "credentialsSecret", + "clientSecret", + "tenantId", + "clientId", + "resource", + "planType", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_url", + "__template_tenantId", + "__template_clientId", + "__template_resource", + "__template_planType", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputOffice365ServiceType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_SERVICE = "office365_service" + + +class CreateInputInputOffice365ServiceContentConfigTypedDict(TypedDict): + content_type: NotRequired[str] + r"""Microsoft 365 Services API Content Type""" + description: NotRequired[str] + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + interval: NotRequired[float] + r"""Interval""" + log_level: NotRequired[LogLevelOptionsContentConfigItems] + r"""Collector runtime Log Level""" + enabled: NotRequired[bool] + r"""Enabled""" + + +class CreateInputInputOffice365ServiceContentConfig(BaseModel): + content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None + r"""Microsoft 365 Services API Content Type""" + + description: Optional[str] = None + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + + interval: Optional[float] = None + r"""Interval""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime Log Level""" + + enabled: Optional[bool] = None + r"""Enabled""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["contentType", "description", "interval", "logLevel", "enabled"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputOffice365ServiceTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputOffice365ServiceType + r"""Connector type identifier.""" + tenant_id: str + r"""Microsoft 365 Azure Tenant ID""" + app_id: str + r"""Microsoft 365 Azure Application ID""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + plan_type: NotRequired[SubscriptionPlanOptions] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, use 0 to disable""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + content_config: NotRequired[ + List[CreateInputInputOffice365ServiceContentConfigTypedDict] + ] + r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""Microsoft 365 Azure client secret""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_app_id: NotRequired[str] + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + +class CreateInputInputOffice365Service(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputOffice365ServiceType + r"""Connector type identifier.""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Microsoft 365 Azure Tenant ID""" + + app_id: Annotated[str, pydantic.Field(alias="appId")] + r"""Microsoft 365 Azure Application ID""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + plan_type: Annotated[ + Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, use 0 to disable""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + content_config: Annotated[ + Optional[List[CreateInputInputOffice365ServiceContentConfig]], + pydantic.Field(alias="contentConfig"), + ] = None + r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), + ] = None + r"""Enter client secret directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""Microsoft 365 Azure client secret""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_app_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_appId") + ] = None + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") + ] = None + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "planType", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "contentConfig", + "retryRules", + "authType", + "description", + "clientSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_planType", + "__template_tenantId", + "__template_appId", + "__template_clientSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputOffice365MgmtType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_MGMT = "office365_mgmt" + + +class CreateInputInputOffice365MgmtContentConfigTypedDict(TypedDict): + content_type: NotRequired[str] + r"""Microsoft 365 Management Activity API Content Type""" + description: NotRequired[str] + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + interval: NotRequired[float] + r"""Interval""" + log_level: NotRequired[LogLevelOptionsContentConfigItems] + r"""Collector runtime Log Level""" + enabled: NotRequired[bool] + r"""Enabled""" + + +class CreateInputInputOffice365MgmtContentConfig(BaseModel): + content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None + r"""Microsoft 365 Management Activity API Content Type""" + + description: Optional[str] = None + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + + interval: Optional[float] = None + r"""Interval""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime Log Level""" + + enabled: Optional[bool] = None + r"""Enabled""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["contentType", "description", "interval", "logLevel", "enabled"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputOffice365MgmtTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputOffice365MgmtType + r"""Connector type identifier.""" + plan_type: SubscriptionPlanOptions + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + tenant_id: str + r"""Microsoft 365 Azure Tenant ID""" + app_id: str + r"""Microsoft 365 Azure Application ID""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, use 0 to disable""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + publisher_identifier: NotRequired[str] + r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" + content_config: NotRequired[ + List[CreateInputInputOffice365MgmtContentConfigTypedDict] + ] + r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" + ingestion_lag: NotRequired[float] + r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""Microsoft 365 Azure client secret""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_app_id: NotRequired[str] + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + template_publisher_identifier: NotRequired[str] + r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + +class CreateInputInputOffice365Mgmt(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputOffice365MgmtType + r"""Connector type identifier.""" + + plan_type: Annotated[SubscriptionPlanOptions, pydantic.Field(alias="planType")] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Microsoft 365 Azure Tenant ID""" + + app_id: Annotated[str, pydantic.Field(alias="appId")] + r"""Microsoft 365 Azure Application ID""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, use 0 to disable""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + publisher_identifier: Annotated[ + Optional[str], pydantic.Field(alias="publisherIdentifier") + ] = None + r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" + + content_config: Annotated[ + Optional[List[CreateInputInputOffice365MgmtContentConfig]], + pydantic.Field(alias="contentConfig"), + ] = None + r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" + + ingestion_lag: Annotated[Optional[float], pydantic.Field(alias="ingestionLag")] = ( + None + ) + r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), + ] = None + r"""Enter client secret directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""Microsoft 365 Azure client secret""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_app_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_appId") + ] = None + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + + template_publisher_identifier: Annotated[ + Optional[str], pydantic.Field(alias="__template_publisherIdentifier") + ] = None + r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" + + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") + ] = None + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "publisherIdentifier", + "contentConfig", + "ingestionLag", + "retryRules", + "authType", + "description", + "clientSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_planType", + "__template_tenantId", + "__template_appId", + "__template_publisherIdentifier", + "__template_clientSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputEdgePrometheusType(str, Enum): + r"""Connector type identifier.""" + + EDGE_PROMETHEUS = "edge_prometheus" + + +class CreateInputInputEdgePrometheusDiscoveryType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + # Static + STATIC = "static" + # DNS + DNS = "dns" + # AWS EC2 + EC2 = "ec2" + # Kubernetes Node + K8S_NODE = "k8s-node" + # Kubernetes Pods + K8S_PODS = "k8s-pods" + # Kubernetes Service Monitor (v4.18+) + K8S_SERVICE_MONITOR = "k8s-service-monitor" + # HTTP SD + HTTP_SD = "http_sd" + + +class CreateInputInputEdgePrometheusAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter credentials directly, or select a stored secret""" + + MANUAL = "manual" + SECRET = "secret" + KUBERNETES = "kubernetes" + + +class CreateInputTargetTypedDict(TypedDict): + host: str + r"""Name of host from which to pull metrics.""" + protocol: NotRequired[ProtocolOptionsTargetsItems] + r"""Protocol to use when collecting metrics""" + port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets.""" + path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + + +class CreateInputTarget(BaseModel): + host: str + r"""Name of host from which to pull metrics.""" + + protocol: Optional[ProtocolOptionsTargetsItems] = None + r"""Protocol to use when collecting metrics""" + + port: Optional[float] = None + r"""The port number in the metrics URL for discovered targets.""" + + path: Optional[str] = None + r"""Path to use when collecting metrics from discovered targets""" + + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptionsTargetsItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["protocol", "port", "path"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputPodFilterTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class CreateInputPodFilter(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputEdgePrometheusTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputEdgePrometheusType + r"""Connector type identifier.""" + discovery_type: CreateInputInputEdgePrometheusDiscoveryType + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + interval: float + r"""How often in seconds to scrape targets for metrics.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + dimension_list: NotRequired[List[str]] + r"""Other dimensions to include in events""" + field_per_metric: NotRequired[bool] + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + timeout: NotRequired[float] + r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" + persistence: NotRequired[DiskSpoolingTypeTypedDict] + r"""Disk Spooling""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_type: NotRequired[CreateInputInputEdgePrometheusAuthenticationMethod] + r"""Enter credentials directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + targets: NotRequired[List[CreateInputTargetTypedDict]] + r"""Targets""" + record_type: NotRequired[RecordTypeOptions] + r"""DNS record type to resolve""" + scrape_port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets.""" + name_list: NotRequired[List[str]] + r"""List of DNS names to resolve""" + scrape_protocol: NotRequired[ProtocolOptionsTargetsItems] + r"""Protocol to use when collecting metrics""" + scrape_path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + use_public_ip: NotRequired[bool] + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] + r"""Filter to apply when searching for EC2 instances""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the EC2 is located""" + endpoint: NotRequired[str] + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access EC2""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + service_monitor_namespace: NotRequired[str] + r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" + scrape_protocol_expr: NotRequired[str] + r"""Protocol to use when collecting metrics""" + scrape_port_expr: NotRequired[str] + r"""The port number in the metrics URL for discovered targets.""" + scrape_path_expr: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + pod_filter: NotRequired[List[CreateInputPodFilterTypedDict]] + r""" + Add rules to decide which pods to discover for metrics. + Pods are searched if no rules are given or of all the rules' + expressions evaluate to true. + + """ + http_discovery_url: NotRequired[str] + r"""URL to fetch target groups from (must be http or https)""" + http_discovery_headers: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Extra headers to send with the discovery request""" + http_discovery_reject_unauthorized: NotRequired[bool] + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + max_response_body_size: NotRequired[str] + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + username: NotRequired[str] + r"""Username for Prometheus Basic authentication""" + password: NotRequired[str] + r"""Password for Prometheus Basic authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_dimension_list: NotRequired[str] + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + template_name_list: NotRequired[str] + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + +class CreateInputInputEdgePrometheus(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputEdgePrometheusType + r"""Connector type identifier.""" + + discovery_type: Annotated[ + CreateInputInputEdgePrometheusDiscoveryType, + pydantic.Field(alias="discoveryType"), + ] + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + interval: float + r"""How often in seconds to scrape targets for metrics.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + dimension_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="dimensionList") + ] = None + r"""Other dimensions to include in events""" + + field_per_metric: Annotated[ + Optional[bool], pydantic.Field(alias="fieldPerMetric") + ] = None + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + + timeout: Optional[float] = None + r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" + + persistence: Optional[DiskSpoolingType] = None + r"""Disk Spooling""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_type: Annotated[ + Optional[CreateInputInputEdgePrometheusAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter credentials directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + targets: Optional[List[CreateInputTarget]] = None + r"""Targets""" + + record_type: Annotated[ + Optional[RecordTypeOptions], pydantic.Field(alias="recordType") + ] = None + r"""DNS record type to resolve""" + + scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None + r"""The port number in the metrics URL for discovered targets.""" + + name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None + r"""List of DNS names to resolve""" + + scrape_protocol: Annotated[ + Optional[ProtocolOptionsTargetsItems], pydantic.Field(alias="scrapeProtocol") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None + r"""Path to use when collecting metrics from discovered targets""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + + search_filter: Annotated[ + Optional[List[SearchFilterConfInputPrometheus]], + pydantic.Field(alias="searchFilter"), + ] = None + r"""Filter to apply when searching for EC2 instances""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""Region where the EC2 is located""" + + endpoint: Optional[str] = None + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access EC2""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + service_monitor_namespace: Annotated[ + Optional[str], pydantic.Field(alias="serviceMonitorNamespace") + ] = None + r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" + + scrape_protocol_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapeProtocolExpr") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_port_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapePortExpr") + ] = None + r"""The port number in the metrics URL for discovered targets.""" + + scrape_path_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapePathExpr") + ] = None + r"""Path to use when collecting metrics from discovered targets""" + + pod_filter: Annotated[ + Optional[List[CreateInputPodFilter]], pydantic.Field(alias="podFilter") + ] = None + r""" + Add rules to decide which pods to discover for metrics. + Pods are searched if no rules are given or of all the rules' + expressions evaluate to true. + + """ + + http_discovery_url: Annotated[ + Optional[str], pydantic.Field(alias="httpDiscoveryUrl") + ] = None + r"""URL to fetch target groups from (must be http or https)""" + + http_discovery_headers: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="httpDiscoveryHeaders"), + ] = None + r"""Extra headers to send with the discovery request""" + + http_discovery_reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") + ] = None + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + + max_response_body_size: Annotated[ + Optional[str], pydantic.Field(alias="maxResponseBodySize") + ] = None + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + + username: Optional[str] = None + r"""Username for Prometheus Basic authentication""" + + password: Optional[str] = None + r"""Password for Prometheus Basic authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_dimension_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_dimensionList") + ] = None + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + + template_name_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_nameList") + ] = None + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + @field_serializer("discovery_type") + def serialize_discovery_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputEdgePrometheusDiscoveryType(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputEdgePrometheusAuthenticationMethod(value) + except ValueError: + return value + return value + + @field_serializer("record_type") + def serialize_record_type(self, value): + if isinstance(value, str): + try: + return models.RecordTypeOptions(value) + except ValueError: + return value + return value + + @field_serializer("scrape_protocol") + def serialize_scrape_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptionsTargetsItems(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "dimensionList", + "fieldPerMetric", + "timeout", + "persistence", + "metadata", + "authType", + "description", + "targets", + "recordType", + "scrapePort", + "nameList", + "scrapeProtocol", + "scrapePath", + "awsAuthenticationMethod", + "awsApiKey", + "awsSecret", + "usePublicIp", + "searchFilter", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "serviceMonitorNamespace", + "scrapeProtocolExpr", + "scrapePortExpr", + "scrapePathExpr", + "podFilter", + "httpDiscoveryUrl", + "httpDiscoveryHeaders", + "httpDiscoveryRejectUnauthorized", + "maxResponseBodySize", + "username", + "password", + "credentialsSecret", + "__template_environment", + "__template_streamtags", + "__template_dimensionList", + "__template_nameList", + "__template_awsApiKey", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputPrometheusDiscoveryType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + # Static + STATIC = "static" + # DNS + DNS = "dns" + # AWS EC2 + EC2 = "ec2" + # HTTP SD + HTTP_SD = "http_sd" + + +class CreateInputMetricsProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Protocol to use when collecting metrics""" + + HTTP = "http" + HTTPS = "https" + + +class CreateInputInputPrometheusTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsPrometheus + r"""Connector type identifier.""" + interval: float + r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" + log_level: LogLevelOptions + r"""Collector runtime log level""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + dimension_list: NotRequired[List[str]] + r"""Other dimensions to include in events""" + field_per_metric: NotRequired[bool] + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + discovery_type: NotRequired[CreateInputInputPrometheusDiscoveryType] + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + timeout: NotRequired[float] + r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_type: NotRequired[AuthenticationMethodOptionsSasl] + r"""Enter credentials directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + target_list: NotRequired[List[str]] + r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" + record_type: NotRequired[RecordTypeOptions] + r"""DNS record type to resolve""" + scrape_port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets""" + name_list: NotRequired[List[str]] + r"""List of DNS names to resolve""" + scrape_protocol: NotRequired[CreateInputMetricsProtocol] + r"""Protocol to use when collecting metrics""" + scrape_path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + use_public_ip: NotRequired[bool] + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] + r"""Filter to apply when searching for EC2 instances""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the EC2 is located""" + endpoint: NotRequired[str] + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access EC2""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + http_discovery_url: NotRequired[str] + r"""URL to fetch target groups from (must be http or https)""" + http_discovery_headers: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Extra headers to send with the discovery request""" + http_discovery_reject_unauthorized: NotRequired[bool] + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + max_response_body_size: NotRequired[str] + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + username: NotRequired[str] + r"""Username for Prometheus Basic authentication""" + password: NotRequired[str] + r"""Password for Prometheus Basic authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_dimension_list: NotRequired[str] + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + template_discovery_type: NotRequired[str] + r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" + template_log_level: NotRequired[str] + r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" + template_target_list: NotRequired[str] + r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" + template_name_list: NotRequired[str] + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + template_password: NotRequired[str] + r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" + + +class CreateInputInputPrometheus(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsPrometheus + r"""Connector type identifier.""" + + interval: float + r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" + + log_level: Annotated[LogLevelOptions, pydantic.Field(alias="logLevel")] + r"""Collector runtime log level""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + dimension_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="dimensionList") + ] = None + r"""Other dimensions to include in events""" + + field_per_metric: Annotated[ + Optional[bool], pydantic.Field(alias="fieldPerMetric") + ] = None + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + + discovery_type: Annotated[ + Optional[CreateInputInputPrometheusDiscoveryType], + pydantic.Field(alias="discoveryType"), + ] = None + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + timeout: Optional[float] = None + r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsSasl], pydantic.Field(alias="authType") + ] = None + r"""Enter credentials directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + target_list: Annotated[Optional[List[str]], pydantic.Field(alias="targetList")] = ( + None + ) + r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" + + record_type: Annotated[ + Optional[RecordTypeOptions], pydantic.Field(alias="recordType") + ] = None + r"""DNS record type to resolve""" + + scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None + r"""The port number in the metrics URL for discovered targets""" + + name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None + r"""List of DNS names to resolve""" + + scrape_protocol: Annotated[ + Optional[CreateInputMetricsProtocol], pydantic.Field(alias="scrapeProtocol") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None + r"""Path to use when collecting metrics from discovered targets""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + + search_filter: Annotated[ + Optional[List[SearchFilterConfInputPrometheus]], + pydantic.Field(alias="searchFilter"), + ] = None + r"""Filter to apply when searching for EC2 instances""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""Region where the EC2 is located""" + + endpoint: Optional[str] = None + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access EC2""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + http_discovery_url: Annotated[ + Optional[str], pydantic.Field(alias="httpDiscoveryUrl") + ] = None + r"""URL to fetch target groups from (must be http or https)""" + + http_discovery_headers: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="httpDiscoveryHeaders"), + ] = None + r"""Extra headers to send with the discovery request""" + + http_discovery_reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") + ] = None + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + + max_response_body_size: Annotated[ + Optional[str], pydantic.Field(alias="maxResponseBodySize") + ] = None + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + + username: Optional[str] = None + r"""Username for Prometheus Basic authentication""" + + password: Optional[str] = None + r"""Password for Prometheus Basic authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_dimension_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_dimensionList") + ] = None + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + + template_discovery_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_discoveryType") + ] = None + r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" + + template_log_level: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLevel") + ] = None + r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" + + template_target_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_targetList") + ] = None + r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" + + template_name_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_nameList") + ] = None + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") + ] = None + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + template_password: Annotated[ + Optional[str], pydantic.Field(alias="__template_password") + ] = None + r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" + + @field_serializer("discovery_type") + def serialize_discovery_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputPrometheusDiscoveryType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsSasl(value) + except ValueError: + return value + return value + + @field_serializer("record_type") + def serialize_record_type(self, value): + if isinstance(value, str): + try: + return models.RecordTypeOptions(value) + except ValueError: + return value + return value + + @field_serializer("scrape_protocol") + def serialize_scrape_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputMetricsProtocol(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "dimensionList", + "fieldPerMetric", + "discoveryType", + "rejectUnauthorized", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "authType", + "description", + "targetList", + "recordType", + "scrapePort", + "nameList", + "scrapeProtocol", + "scrapePath", + "awsAuthenticationMethod", + "awsApiKey", + "awsSecret", + "usePublicIp", + "searchFilter", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "httpDiscoveryUrl", + "httpDiscoveryHeaders", + "httpDiscoveryRejectUnauthorized", + "maxResponseBodySize", + "username", + "password", + "credentialsSecret", + "__template_environment", + "__template_streamtags", + "__template_dimensionList", + "__template_discoveryType", + "__template_logLevel", + "__template_targetList", + "__template_nameList", + "__template_awsApiKey", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_username", + "__template_password", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputPrometheusRwType(str, Enum): + r"""Source type identifier.""" + + PROMETHEUS_RW = "prometheus_rw" + + +class CreateInputInputPrometheusRwTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputPrometheusRwType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + prometheus_api: str + r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + +class CreateInputInputPrometheusRw(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputPrometheusRwType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] + r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") + ] = None + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "authType", + "metadata", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_username", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputLokiType(str, Enum): + r"""Source type identifier.""" + + LOKI = "loki" + + +class CreateInputInputLokiTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputLokiType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + loki_api: str + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + +class CreateInputInputLoki(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputLokiType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "authType", + "metadata", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_lokiAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputGrafanaType2(str, Enum): + r"""Source type identifier.""" + + GRAFANA = "grafana" + + +class CreateInputPrometheusAuth2TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputPrometheusAuth2(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputLokiAuth2TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputLokiAuth2(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputGrafanaGrafana2TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputGrafanaType2 + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + loki_api: str + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + prometheus_api: NotRequired[str] + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + prometheus_auth: NotRequired[CreateInputPrometheusAuth2TypedDict] + loki_auth: NotRequired[CreateInputLokiAuth2TypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + +class CreateInputInputGrafanaGrafana2(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputGrafanaType2 + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + prometheus_api: Annotated[Optional[str], pydantic.Field(alias="prometheusAPI")] = ( + None + ) + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + + prometheus_auth: Annotated[ + Optional[CreateInputPrometheusAuth2], pydantic.Field(alias="prometheusAuth") + ] = None + + loki_auth: Annotated[ + Optional[CreateInputLokiAuth2], pydantic.Field(alias="lokiAuth") + ] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "prometheusAPI", + "prometheusAuth", + "lokiAuth", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_lokiAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputGrafanaType1(str, Enum): + r"""Source type identifier.""" + + GRAFANA = "grafana" + + +class CreateInputPrometheusAuth1TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputPrometheusAuth1(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputLokiAuth1TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputLokiAuth1(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputGrafanaGrafana1TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputGrafanaType1 + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + prometheus_api: str + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + loki_api: NotRequired[str] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + prometheus_auth: NotRequired[CreateInputPrometheusAuth1TypedDict] + loki_auth: NotRequired[CreateInputLokiAuth1TypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + +class CreateInputInputGrafanaGrafana1(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputInputGrafanaType1 + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + loki_api: Annotated[Optional[str], pydantic.Field(alias="lokiAPI")] = None + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + + prometheus_auth: Annotated[ + Optional[CreateInputPrometheusAuth1], pydantic.Field(alias="prometheusAuth") + ] = None + + loki_auth: Annotated[ + Optional[CreateInputLokiAuth1], pydantic.Field(alias="lokiAuth") + ] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "lokiAPI", + "prometheusAuth", + "lokiAuth", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_lokiAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateInputInputGrafanaUnionTypedDict = TypeAliasType( + "CreateInputInputGrafanaUnionTypedDict", + Union[ + CreateInputInputGrafanaGrafana1TypedDict, + CreateInputInputGrafanaGrafana2TypedDict, + ], +) + + +CreateInputInputGrafanaUnion = TypeAliasType( + "CreateInputInputGrafanaUnion", + Union[CreateInputInputGrafanaGrafana1, CreateInputInputGrafanaGrafana2], +) + + +class CreateInputInputConfluentCloudTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsConfluentcloud + r"""Connector type identifier.""" + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" + topics: List[str] + r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + group_id: NotRequired[str] + r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" + from_beginning: NotRequired[bool] + r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" + kafka_schema_registry: NotRequired[KafkaSchemaRegistryAuthenticationTypeTypedDict] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + session_timeout: NotRequired[float] + r""" + Timeout used to detect client failures when using Kafka's group-management facilities. + If the client sends no heartbeats to the broker before the timeout expires, + the broker will remove the client from the group and initiate a rebalance. + Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. + See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. + """ + rebalance_timeout: NotRequired[float] + r""" + Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. + """ + heartbeat_interval: NotRequired[float] + r""" + Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. + """ + auto_commit_interval: NotRequired[float] + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + auto_commit_threshold: NotRequired[float] + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + max_bytes_per_partition: NotRequired[float] + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + max_bytes: NotRequired[float] + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + max_socket_errors: NotRequired[float] + r"""Maximum number of network errors before the consumer re-creates a socket""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topics: NotRequired[str] + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + template_group_id: NotRequired[str] + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + +class CreateInputInputConfluentCloud(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsConfluentcloud + r"""Connector type identifier.""" + + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" + + topics: List[str] + r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" + + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationType], + pydantic.Field(alias="kafkaSchemaRegistry"), + ] = None + r"""Kafka Schema Registry Authentication""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" + + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + session_timeout: Annotated[ + Optional[float], pydantic.Field(alias="sessionTimeout") + ] = None + r""" + Timeout used to detect client failures when using Kafka's group-management facilities. + If the client sends no heartbeats to the broker before the timeout expires, + the broker will remove the client from the group and initiate a rebalance. + Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. + See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. + """ + + rebalance_timeout: Annotated[ + Optional[float], pydantic.Field(alias="rebalanceTimeout") + ] = None + r""" + Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. + """ + + heartbeat_interval: Annotated[ + Optional[float], pydantic.Field(alias="heartbeatInterval") + ] = None + r""" + Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. + """ + + auto_commit_interval: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitInterval") + ] = None + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + auto_commit_threshold: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitThreshold") + ] = None + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + max_bytes_per_partition: Annotated[ + Optional[float], pydantic.Field(alias="maxBytesPerPartition") + ] = None + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + + max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + + max_socket_errors: Annotated[ + Optional[float], pydantic.Field(alias="maxSocketErrors") + ] = None + r"""Maximum number of network errors before the consumer re-creates a socket""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") + ] = None + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + + template_topics: Annotated[ + Optional[str], pydantic.Field(alias="__template_topics") + ] = None + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + + template_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_groupId") + ] = None + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "groupId", + "fromBeginning", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "sessionTimeout", + "rebalanceTimeout", + "heartbeatInterval", + "autoCommitInterval", + "autoCommitThreshold", + "maxBytesPerPartition", + "maxBytes", + "maxSocketErrors", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "__template_brokers", + "__template_topics", + "__template_groupId", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputElasticType(str, Enum): + r"""Source type identifier.""" + + ELASTIC = "elastic" + + +try: + CreateInputSNMPv3Authentication.model_rebuild() +except NameError: + pass +try: + CreateInputInputSnmp.model_rebuild() +except NameError: + pass +try: + CreateInputInputS3Inventory.model_rebuild() +except NameError: + pass +try: + CreateInputInputS3.model_rebuild() +except NameError: + pass +try: + CreateInputInputMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputInputCriblmetrics.model_rebuild() +except NameError: + pass +try: + CreateInputInputKinesis.model_rebuild() +except NameError: + pass +try: + CreateInputInputHTTPRawInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + CreateInputInputHTTPRawAuthTokensExt.model_rebuild() +except NameError: + pass +try: + CreateInputInputHTTPRaw.model_rebuild() +except NameError: + pass +try: + CreateInputSample.model_rebuild() +except NameError: + pass +try: + CreateInputInputDatagen.model_rebuild() +except NameError: + pass +try: + CreateInputInputDatadogAgentProxyMode.model_rebuild() +except NameError: + pass +try: + CreateInputInputDatadogAgent.model_rebuild() +except NameError: + pass +try: + CreateInputInputCrowdstrike.model_rebuild() +except NameError: + pass +try: + CreateInputInputWindowsMetricsCPU.model_rebuild() +except NameError: + pass +try: + CreateInputInputWindowsMetricsNetwork.model_rebuild() +except NameError: + pass +try: + CreateInputInputWindowsMetricsDisk.model_rebuild() +except NameError: + pass +try: + CreateInputInputWindowsMetricsPersistence.model_rebuild() +except NameError: + pass +try: + CreateInputInputWindowsMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputInputKubeEvents.model_rebuild() +except NameError: + pass +try: + CreateInputInputKubeLogsRule.model_rebuild() +except NameError: + pass +try: + CreateInputInputKubeLogs.model_rebuild() +except NameError: + pass +try: + CreateInputInputKubeMetricsPersistence.model_rebuild() +except NameError: + pass +try: + CreateInputInputKubeMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputCollectors.model_rebuild() +except NameError: + pass +try: + CreateInputInputSystemStatePersistence.model_rebuild() +except NameError: + pass +try: + CreateInputInputSystemState.model_rebuild() +except NameError: + pass +try: + CreateInputInputSystemMetricsCPU.model_rebuild() +except NameError: + pass +try: + CreateInputInputSystemMetricsNetwork.model_rebuild() +except NameError: + pass +try: + CreateInputInputSystemMetricsDisk.model_rebuild() +except NameError: + pass +try: + CreateInputContainer.model_rebuild() +except NameError: + pass +try: + CreateInputInputSystemMetricsPersistence.model_rebuild() +except NameError: + pass +try: + CreateInputInputSystemMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputInputTcpjson.model_rebuild() +except NameError: + pass +try: + CreateInputInputHTTPAuthTypeSecretConstraintSplunkHecMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputInputHTTPAuthTypeSecretConstraintElasticsearchMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + CreateInputInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() +except NameError: + pass +try: + CreateInputInputCriblLakeHTTP.model_rebuild() +except NameError: + pass +try: + CreateInputInputCriblHTTP.model_rebuild() +except NameError: + pass +try: + CreateInputInputCriblTCP.model_rebuild() +except NameError: + pass +try: + CreateInputInputCribl.model_rebuild() +except NameError: + pass +try: + CreateInputInputGooglePubsub.model_rebuild() +except NameError: + pass +try: + CreateInputInputFirehose.model_rebuild() +except NameError: + pass +try: + CreateInputInputExec.model_rebuild() +except NameError: + pass +try: + CreateInputCertificate.model_rebuild() +except NameError: + pass +try: + CreateInputAuth.model_rebuild() +except NameError: + pass +try: + CreateInputAzureBlobStorage.model_rebuild() +except NameError: + pass +try: + CreateInputCheckpointing.model_rebuild() +except NameError: + pass +try: + CreateInputInputEventhubAmqp.model_rebuild() +except NameError: + pass +try: + CreateInputInputEventhub.model_rebuild() +except NameError: + pass +try: + CreateInputInputMicrosoftGraph.model_rebuild() +except NameError: + pass +try: + CreateInputInputOffice365MsgTrace.model_rebuild() +except NameError: + pass +try: + CreateInputInputOffice365ServiceContentConfig.model_rebuild() +except NameError: + pass +try: + CreateInputInputOffice365Service.model_rebuild() +except NameError: + pass +try: + CreateInputInputOffice365MgmtContentConfig.model_rebuild() +except NameError: + pass +try: + CreateInputInputOffice365Mgmt.model_rebuild() +except NameError: + pass +try: + CreateInputPodFilter.model_rebuild() +except NameError: + pass +try: + CreateInputInputEdgePrometheus.model_rebuild() +except NameError: + pass +try: + CreateInputInputPrometheus.model_rebuild() +except NameError: + pass +try: + CreateInputInputPrometheusRw.model_rebuild() +except NameError: + pass +try: + CreateInputInputLoki.model_rebuild() +except NameError: + pass +try: + CreateInputPrometheusAuth2.model_rebuild() +except NameError: + pass +try: + CreateInputLokiAuth2.model_rebuild() +except NameError: + pass +try: + CreateInputInputGrafanaGrafana2.model_rebuild() +except NameError: + pass +try: + CreateInputPrometheusAuth1.model_rebuild() +except NameError: + pass +try: + CreateInputLokiAuth1.model_rebuild() +except NameError: + pass +try: + CreateInputInputGrafanaGrafana1.model_rebuild() +except NameError: + pass +try: + CreateInputInputConfluentCloud.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/createinput_inputkubemetrics.py b/src/cribl_control_plane/models/createinput_v3user.py similarity index 75% rename from src/cribl_control_plane/models/createinput_inputkubemetrics.py rename to src/cribl_control_plane/models/createinput_v3user.py index 960af388a..628dcfb06 100644 --- a/src/cribl_control_plane/models/createinput_inputkubemetrics.py +++ b/src/cribl_control_plane/models/createinput_v3user.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionsmanualsecret import ( AuthenticationMethodOptionsManualSecret, @@ -14,10 +14,6 @@ AuthTokenConfInputCloudflareHec, AuthTokenConfInputCloudflareHecTypedDict, ) -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, -) from .checkpointingtype import CheckpointingType, CheckpointingTypeTypedDict from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -26,8 +22,6 @@ from .datacompressionformatoptionspersistence import ( DataCompressionFormatOptionsPersistence, ) -from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict -from .gputype import GpuType, GpuTypeTypedDict from .logleveloptions import LogLevelOptions from .logleveloptionscontentconfigitemsdebugerror import ( LogLevelOptionsContentConfigItemsDebugError, @@ -38,7 +32,6 @@ MetadataConfInputCollectionTypedDict, ) from .minimumtlsversionoptionstls import MinimumTLSVersionOptionsTLS -from .modeoptionshost import ModeOptionsHost from .oauthheaderconfinputservicenowtable import ( OauthHeaderConfInputServicenowTable, OauthHeaderConfInputServicenowTableTypedDict, @@ -49,27 +42,26 @@ ) from .pqtype import PqType, PqTypeTypedDict from .preprocesstype import PreprocessType, PreprocessTypeTypedDict -from .processtype import ProcessType, ProcessTypeTypedDict from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, ) from .retryrulestype import RetryRulesType, RetryRulesTypeTypedDict -from .ruleconfinputkubemetrics import ( - RuleConfInputKubeMetrics, - RuleConfInputKubeMetricsTypedDict, +from .retrytypeoptionshealthcheckcollectorconfretryrules import ( + RetryTypeOptionsHealthCheckCollectorConfRetryRules, ) from .sqsauthenticationmethodoptions import SqsAuthenticationMethodOptions from .tagafterprocessingoptions import TagAfterProcessingOptions +from .tlssettingsclientsidetypecapathcertpath import ( + TLSSettingsClientSideTypeCaPathCertPath, + TLSSettingsClientSideTypeCaPathCertPathTypedDict, +) from .tlssettingsserversidetype import ( TLSSettingsServerSideType, TLSSettingsServerSideTypeTypedDict, ) -from .typeoptionskinesis import TypeOptionsKinesis from .typeoptionsnetflow import TypeOptionsNetflow -from .typeoptionss3 import TypeOptionsS3 from .typeoptionssecuritylake import TypeOptionsSecuritylake -from .typeoptionssnmp import TypeOptionsSnmp from .typeoptionssqs import TypeOptionsSqs from .typeoptionssyslog import TypeOptionsSyslog from cribl_control_plane import models, utils @@ -81,29 +73,23 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict -class CreateInputInputOktaType(str, Enum): - r"""Connector type identifier.""" - - OKTA = "okta" - - -class CreateInputInputOktaManageStateTypedDict(TypedDict): - pass - +class CreateInputInputTrendMicroVisionOneType(str, Enum): + r"""Source type identifier.""" -class CreateInputInputOktaManageState(BaseModel): - pass + TREND_MICRO_VISION_ONE = "trend_micro_vision_one" -class CreateInputInputOktaTypedDict(TypedDict): +class CreateInputInputTrendMicroVisionOneTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputOktaType - r"""Connector type identifier.""" - okta_domain: str - r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" - text_secret: str - r"""Select or create a stored text secret""" + type: CreateInputInputTrendMicroVisionOneType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -119,52 +105,75 @@ class CreateInputInputOktaTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - okta_token: NotRequired[str] - r"""Your Okta API token for authentication""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - manage_state: NotRequired[CreateInputInputOktaManageStateTypedDict] - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_okta_domain: NotRequired[str] - r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputOkta(BaseModel): +class CreateInputInputTrendMicroVisionOne(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputOktaType - r"""Connector type identifier.""" + type: CreateInputInputTrendMicroVisionOneType + r"""Source type identifier.""" - okta_domain: Annotated[str, pydantic.Field(alias="oktaDomain")] - r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored text secret""" + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -191,54 +200,87 @@ class CreateInputInputOkta(BaseModel): pq: Optional[PqType] = None - okta_token: Annotated[Optional[str], pydantic.Field(alias="oktaToken")] = None - r"""Your Okta API token for authentication""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - manage_state: Annotated[ - Optional[CreateInputInputOktaManageState], pydantic.Field(alias="manageState") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -253,10 +295,35 @@ class CreateInputInputOkta(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_okta_domain: Annotated[ - Optional[str], pydantic.Field(alias="__template_oktaDomain") + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -270,25 +337,34 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "oktaToken", - "cronSchedule", - "earliest", - "latest", - "manageState", - "jobTimeout", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "retryRules", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", - "__template_oktaDomain", - ] - ) + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) serialized = handler(self) m = {} @@ -303,188 +379,296 @@ def serialize_model(self, handler): return m -class CreateInputInputAnthropicComplianceType(str, Enum): - r"""Connector type identifier.""" +class CreateInputInputMimecastHecType(str, Enum): + r"""Source type identifier.""" - ANTHROPIC_COMPLIANCE = "anthropic_compliance" + MIMECAST_HEC = "mimecast_hec" -class CreateInputActivitiesManageStateTypedDict(TypedDict): - pass +class CreateInputInputMimecastHecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputMimecastHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputActivitiesManageState(BaseModel): - pass +class CreateInputInputMimecastHec(BaseModel): + id: str + r"""Unique ID for this input""" + type: CreateInputInputMimecastHecType + r"""Source type identifier.""" -class CreateInputActivitiesTypedDict(TypedDict): - r"""Activities""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputActivitiesManageStateTypedDict] + port: float + r"""Port to listen on""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" -class CreateInputActivities(BaseModel): - r"""Activities""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - enabled: Optional[bool] = None - r"""Enabled""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - manage_state: Annotated[ - Optional[CreateInputActivitiesManageState], pydantic.Field(alias="manageState") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None + r"""Add request headers to events, in the __headers field""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - return m + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" -class CreateInputChatsManageStateTypedDict(TypedDict): - pass + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class CreateInputChatsManageState(BaseModel): - pass + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" -class CreateInputChatsTypedDict(TypedDict): - r"""Chats""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputChatsManageStateTypedDict] - - -class CreateInputChats(BaseModel): - r"""Chats""" - - enabled: Optional[bool] = None - r"""Enabled""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - manage_state: Annotated[ - Optional[CreateInputChatsManageState], pydantic.Field(alias="manageState") + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -501,183 +685,296 @@ def serialize_model(self, handler): return m -class CreateInputProjectsManageStateTypedDict(TypedDict): - pass - +class CreateInputInputHashicorpHcpVaultDedicatedType(str, Enum): + r"""Source type identifier.""" -class CreateInputProjectsManageState(BaseModel): - pass + HASHICORP_HCP_VAULT_DEDICATED = "hashicorp_hcp_vault_dedicated" -class CreateInputProjectsTypedDict(TypedDict): - r"""Projects""" +class CreateInputInputHashicorpHcpVaultDedicatedTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputProjectsManageStateTypedDict] +class CreateInputInputHashicorpHcpVaultDedicated(BaseModel): + id: str + r"""Unique ID for this input""" -class CreateInputProjects(BaseModel): - r"""Projects""" + type: CreateInputInputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" - enabled: Optional[bool] = None - r"""Enabled""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + port: float + r"""Port to listen on""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Select whether to send data to Routes, or directly to Destinations.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - manage_state: Annotated[ - Optional[CreateInputProjectsManageState], pydantic.Field(alias="manageState") + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - return m + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" -class CreateInputChatMessagesManageStateTypedDict(TypedDict): - pass + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" -class CreateInputChatMessagesManageState(BaseModel): - pass + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class CreateInputChatMessagesTypedDict(TypedDict): - r"""Chat Messages""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputChatMessagesManageStateTypedDict] + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class CreateInputChatMessages(BaseModel): - r"""Chat Messages""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - enabled: Optional[bool] = None - r"""Enabled""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - manage_state: Annotated[ - Optional[CreateInputChatMessagesManageState], - pydantic.Field(alias="manageState"), + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -694,249 +991,282 @@ def serialize_model(self, handler): return m -class CreateInputProjectDetailsManageStateTypedDict(TypedDict): - pass - - -class CreateInputProjectDetailsManageState(BaseModel): - pass - - -class CreateInputProjectDetailsTypedDict(TypedDict): - r"""Project Details""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputProjectDetailsManageStateTypedDict] - - -class CreateInputProjectDetails(BaseModel): - r"""Project Details""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" - - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" +class CreateInputInputBeyondtrustHecType(str, Enum): + r"""Source type identifier.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" + BEYONDTRUST_HEC = "beyondtrust_hec" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: Annotated[ - Optional[CreateInputProjectDetailsManageState], - pydantic.Field(alias="manageState"), - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} +class CreateInputInputBeyondtrustHecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputBeyondtrustHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateInputInputBeyondtrustHec(BaseModel): + id: str + r"""Unique ID for this input""" - return m + type: CreateInputInputBeyondtrustHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" -class CreateInputGroupsTypedDict(TypedDict): - r"""Groups""" + port: float + r"""Port to listen on""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" -class CreateInputGroups(BaseModel): - r"""Groups""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - enabled: Optional[bool] = None - r"""Enabled""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + pq: Optional[PqType] = None - return m + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" -class CreateInputOrganizationsTypedDict(TypedDict): - r"""Organizations""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" -class CreateInputOrganizations(BaseModel): - r"""Organizations""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - enabled: Optional[bool] = None - r"""Enabled""" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - return m + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" -class CreateInputOrganizationUsersTypedDict(TypedDict): - r"""Organization Users""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: Optional[str] = None + r"""Optional description for this configuration.""" -class CreateInputOrganizationUsers(BaseModel): - r"""Organization Users""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputOrganizationRolesTypedDict(TypedDict): - r"""Organization Roles""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" -class CreateInputOrganizationRoles(BaseModel): - r"""Organization Roles""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - enabled: Optional[bool] = None - r"""Enabled""" + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) serialized = handler(self) m = {} @@ -951,13 +1281,23 @@ def serialize_model(self, handler): return m -class CreateInputInputAnthropicComplianceTypedDict(TypedDict): +class CreateInputInputF5BigIPType(str, Enum): + r"""Source type identifier.""" + + F5_BIG_IP = "f5_big_ip" + + +class CreateInputInputF5BigIPTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputAnthropicComplianceType - r"""Connector type identifier.""" - text_secret: str - r"""Select or create a stored Anthropic API key""" + type: CreateInputInputF5BigIPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -973,60 +1313,77 @@ class CreateInputInputAnthropicComplianceTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - api_key: NotRequired[str] - r"""API key""" - activities: NotRequired[CreateInputActivitiesTypedDict] - r"""Activities""" - chats: NotRequired[CreateInputChatsTypedDict] - r"""Chats""" - projects: NotRequired[CreateInputProjectsTypedDict] - r"""Projects""" - chat_messages: NotRequired[CreateInputChatMessagesTypedDict] - r"""Chat Messages""" - project_details: NotRequired[CreateInputProjectDetailsTypedDict] - r"""Project Details""" - groups: NotRequired[CreateInputGroupsTypedDict] - r"""Groups""" - organizations: NotRequired[CreateInputOrganizationsTypedDict] - r"""Organizations""" - org_users: NotRequired[CreateInputOrganizationUsersTypedDict] - r"""Organization Users""" - org_roles: NotRequired[CreateInputOrganizationRolesTypedDict] - r"""Organization Roles""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputAnthropicCompliance(BaseModel): +class CreateInputInputF5BigIP(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputAnthropicComplianceType - r"""Connector type identifier.""" + type: CreateInputInputF5BigIPType + r"""Source type identifier.""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored Anthropic API key""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -1053,75 +1410,90 @@ class CreateInputInputAnthropicCompliance(BaseModel): pq: Optional[PqType] = None - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" - - activities: Optional[CreateInputActivities] = None - r"""Activities""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - chats: Optional[CreateInputChats] = None - r"""Chats""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - projects: Optional[CreateInputProjects] = None - r"""Projects""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - chat_messages: Optional[CreateInputChatMessages] = None - r"""Chat Messages""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - project_details: Optional[CreateInputProjectDetails] = None - r"""Project Details""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - groups: Optional[CreateInputGroups] = None - r"""Groups""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - organizations: Optional[CreateInputOrganizations] = None - r"""Organizations""" - - org_users: Optional[CreateInputOrganizationUsers] = None - r"""Organization Users""" - - org_roles: Optional[CreateInputOrganizationRoles] = None - r"""Organization Roles""" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -1136,6 +1508,36 @@ class CreateInputInputAnthropicCompliance(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -1148,28 +1550,33 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "apiKey", - "activities", - "chats", - "projects", - "chat_messages", - "project_details", - "groups", - "organizations", - "org_users", - "org_roles", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", - "breakerRulesets", - "staleChannelFlushMs", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "retryRules", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -1186,40 +1593,23 @@ def serialize_model(self, handler): return m -class CreateInputInputOpenaiComplianceLogsType(str, Enum): - r"""Connector type identifier.""" - - OPENAI_COMPLIANCE_LOGS = "openai_compliance_logs" - - -class CreateInputAccountType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Account type""" - - # Workspace - WORKSPACE = "workspace" - # Organization - ORGANIZATION = "organization" - - -class CreateInputInputOpenaiComplianceLogsManageStateTypedDict(TypedDict): - pass - +class CreateInputInputVectraAiHecType(str, Enum): + r"""Source type identifier.""" -class CreateInputInputOpenaiComplianceLogsManageState(BaseModel): - pass + VECTRA_AI_HEC = "vectra_ai_hec" -class CreateInputInputOpenaiComplianceLogsTypedDict(TypedDict): +class CreateInputInputVectraAiHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputOpenaiComplianceLogsType - r"""Connector type identifier.""" - text_secret: str - r"""Select or create a stored text secret""" - account_type: CreateInputAccountType - r"""Account type""" - cron_schedule: str - r"""Cron schedule""" + type: CreateInputInputVectraAiHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -1235,77 +1625,75 @@ class CreateInputInputOpenaiComplianceLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - api_key: NotRequired[str] - r"""API key""" - earliest: NotRequired[str] - r"""Relative to the current time. Format: [+|-]""" - latest: NotRequired[str] - r"""Relative to the current time. Format: [+|-]""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] - r"""Collector runtime log level""" - max_pages: NotRequired[float] - r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - workspace_id: NotRequired[str] - r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" - workspace_event_types: NotRequired[List[str]] - r"""One or more compliance log categories to collect""" - organization_id: NotRequired[str] - r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" - organization_event_types: NotRequired[List[str]] - r"""One or more compliance log categories to collect""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[CreateInputInputOpenaiComplianceLogsManageStateTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_workspace_id: NotRequired[str] - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_organization_id: NotRequired[str] - r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputOpenaiComplianceLogs(BaseModel): +class CreateInputInputVectraAiHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputOpenaiComplianceLogsType - r"""Connector type identifier.""" + type: CreateInputInputVectraAiHecType + r"""Source type identifier.""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored text secret""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - account_type: Annotated[CreateInputAccountType, pydantic.Field(alias="accountType")] - r"""Account type""" + port: float + r"""Port to listen on""" - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""Cron schedule""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -1332,107 +1720,90 @@ class CreateInputInputOpenaiComplianceLogs(BaseModel): pq: Optional[PqType] = None - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" - - earliest: Optional[str] = None - r"""Relative to the current time. Format: [+|-]""" - - latest: Optional[str] = None - r"""Relative to the current time. Format: [+|-]""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItemsDebugError], - pydantic.Field(alias="logLevel"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Collector runtime log level""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + r"""Add request headers to events, in the __headers field""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None - r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" - - workspace_event_types: Annotated[ - Optional[List[str]], pydantic.Field(alias="workspaceEventTypes") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""One or more compliance log categories to collect""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - organization_id: Annotated[ - Optional[str], pydantic.Field(alias="organizationId") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - organization_event_types: Annotated[ - Optional[List[str]], pydantic.Field(alias="organizationEventTypes") + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") ] = None - r"""One or more compliance log categories to collect""" + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - manage_state: Annotated[ - Optional[CreateInputInputOpenaiComplianceLogsManageState], - pydantic.Field(alias="manageState"), + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -1444,33 +1815,35 @@ class CreateInputInputOpenaiComplianceLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_workspace_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceId") + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_organization_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_organizationId") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - @field_serializer("account_type") - def serialize_account_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputAccountType(value) - except ValueError: - return value - return value + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItemsDebugError(value) - except ValueError: - return value - return value + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -1484,34 +1857,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "apiKey", - "earliest", - "latest", - "jobTimeout", - "logLevel", - "maxPages", - "stateTracking", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "retryRules", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", - "workspaceId", - "workspaceEventTypes", - "organizationId", - "organizationEventTypes", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", "__template_environment", "__template_streamtags", - "__template_workspaceId", - "__template_organizationId", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -1528,23 +1899,23 @@ def serialize_model(self, handler): return m -class CreateInputInputUpwindHecType(str, Enum): +class CreateInputInputGigamonHecType(str, Enum): r"""Source type identifier.""" - UPWIND_HEC = "upwind_hec" + GIGAMON_HEC = "gigamon_hec" -class CreateInputInputUpwindHecTypedDict(TypedDict): +class CreateInputInputGigamonHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputUpwindHecType + type: CreateInputInputGigamonHecType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -1614,11 +1985,11 @@ class CreateInputInputUpwindHecTypedDict(TypedDict): r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputUpwindHec(BaseModel): +class CreateInputInputGigamonHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputUpwindHecType + type: CreateInputInputGigamonHecType r"""Source type identifier.""" host: str @@ -1628,7 +1999,7 @@ class CreateInputInputUpwindHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -1834,23 +2205,23 @@ def serialize_model(self, handler): return m -class CreateInputInputSysdigHecType(str, Enum): +class CreateInputInputPingIdentityPingoneType(str, Enum): r"""Source type identifier.""" - SYSDIG_HEC = "sysdig_hec" + PING_IDENTITY_PINGONE = "ping_identity_pingone" -class CreateInputInputSysdigHecTypedDict(TypedDict): +class CreateInputInputPingIdentityPingoneTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputSysdigHecType + type: CreateInputInputPingIdentityPingoneType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -1920,11 +2291,11 @@ class CreateInputInputSysdigHecTypedDict(TypedDict): r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputSysdigHec(BaseModel): +class CreateInputInputPingIdentityPingone(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputSysdigHecType + type: CreateInputInputPingIdentityPingoneType r"""Source type identifier.""" host: str @@ -1934,7 +2305,7 @@ class CreateInputInputSysdigHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -2140,145 +2511,23 @@ def serialize_model(self, handler): return m -class CreateInputInputCloudflareHecType(str, Enum): +class CreateInputInputAkamaiHecType(str, Enum): r"""Source type identifier.""" - CLOUDFLARE_HEC = "cloudflare_hec" - + AKAMAI_HEC = "akamai_hec" -class CreateInputTLSSettingsServerSideTypedDict(TypedDict): - r"""TLS settings (server side)""" - disabled: NotRequired[bool] - r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - request_cert: NotRequired[bool] - r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" - common_name_regex: NotRequired[str] - r"""Regex matching allowable common names in peer certificates' subject attribute""" - certificate_name: NotRequired[str] - r"""The name of the predefined certificate""" - priv_key_path: NotRequired[str] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - cert_path: NotRequired[str] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - ca_path: NotRequired[str] - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - min_version: NotRequired[MinimumTLSVersionOptionsTLS] - r"""Minimum TLS version""" - max_version: NotRequired[MaximumTLSVersionOptionsTLS] - r"""Maximum TLS version""" - - -class CreateInputTLSSettingsServerSide(BaseModel): - r"""TLS settings (server side)""" - - disabled: Optional[bool] = None - r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - - request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None - r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" - - common_name_regex: Annotated[ - Optional[str], pydantic.Field(alias="commonNameRegex") - ] = None - r"""Regex matching allowable common names in peer certificates' subject attribute""" - - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") - ] = None - r"""The name of the predefined certificate""" - - priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" - - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" - - cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - - ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - - min_version: Annotated[ - Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") - ] = None - r"""Minimum TLS version""" - - max_version: Annotated[ - Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") - ] = None - r"""Maximum TLS version""" - - @field_serializer("min_version") - def serialize_min_version(self, value): - if isinstance(value, str): - try: - return models.MinimumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value - - @field_serializer("max_version") - def serialize_max_version(self, value): - if isinstance(value, str): - try: - return models.MaximumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "requestCert", - "rejectUnauthorized", - "commonNameRegex", - "certificateName", - "privKeyPath", - "passphrase", - "certPath", - "caPath", - "minVersion", - "maxVersion", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputCloudflareHecTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputCloudflareHecType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - hec_api: str - r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" +class CreateInputInputAkamaiHecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputAkamaiHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -2296,7 +2545,7 @@ class CreateInputInputCloudflareHecTypedDict(TypedDict): pq: NotRequired[PqTypeTypedDict] auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[CreateInputTLSSettingsServerSideTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" @@ -2320,18 +2569,8 @@ class CreateInputInputCloudflareHecTypedDict(TypedDict): r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - allowed_indexes: NotRequired[List[str]] - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - access_control_allow_origin: NotRequired[List[str]] - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - access_control_allow_headers: NotRequired[List[str]] - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - emit_token_metrics: NotRequired[bool] - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -2344,19 +2583,13 @@ class CreateInputInputCloudflareHecTypedDict(TypedDict): r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_hec_api: NotRequired[str] r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_allowed_indexes: NotRequired[str] - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - template_access_control_allow_origin: NotRequired[str] - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_access_control_allow_headers: NotRequired[str] - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputCloudflareHec(BaseModel): +class CreateInputInputAkamaiHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputCloudflareHecType + type: CreateInputInputAkamaiHecType r"""Source type identifier.""" host: str @@ -2366,7 +2599,7 @@ class CreateInputInputCloudflareHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -2399,7 +2632,7 @@ class CreateInputInputCloudflareHec(BaseModel): ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: Optional[CreateInputTLSSettingsServerSide] = None + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( @@ -2455,35 +2688,8 @@ class CreateInputInputCloudflareHec(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - allowed_indexes: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexes") - ] = None - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - - access_control_allow_origin: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") - ] = None - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - - access_control_allow_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") - ] = None - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - - emit_token_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="emitTokenMetrics") - ] = None - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -2513,21 +2719,6 @@ class CreateInputInputCloudflareHec(BaseModel): ] = None r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_allowed_indexes: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedIndexes") - ] = None - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - - template_access_control_allow_origin: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") - ] = None - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - - template_access_control_allow_headers: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") - ] = None - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -2553,21 +2744,13 @@ def serialize_model(self, handler): "ipAllowlistRegex", "ipDenylistRegex", "metadata", - "allowedIndexes", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "emitTokenMetrics", - "breakerRulesets", - "staleChannelFlushMs", + "hecAcks", "description", "__template_environment", "__template_streamtags", "__template_host", "__template_port", "__template_hecAPI", - "__template_allowedIndexes", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -2584,102 +2767,29 @@ def serialize_model(self, handler): return m -class CreateInputInputZscalerHecType(str, Enum): - r"""Source type identifier.""" +class CreateInputInputOktaType(str, Enum): + r"""Connector type identifier.""" - ZSCALER_HEC = "zscaler_hec" + OKTA = "okta" -class CreateInputInputZscalerHecAuthTokenTypedDict(TypedDict): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - token_secret: NotRequired[str] - r"""Select or create a stored text secret""" - enabled: NotRequired[bool] - r"""Enable token""" - description: NotRequired[str] - r"""Description""" - allowed_indexes_at_token: NotRequired[List[str]] - r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this token""" +class CreateInputInputOktaManageStateTypedDict(TypedDict): + pass -class CreateInputInputZscalerHecAuthToken(BaseModel): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" +class CreateInputInputOktaManageState(BaseModel): + pass - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None +class CreateInputInputOktaTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputOktaType + r"""Connector type identifier.""" + okta_domain: str + r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" + text_secret: str r"""Select or create a stored text secret""" - - enabled: Optional[bool] = None - r"""Enable token""" - - description: Optional[str] = None - r"""Description""" - - allowed_indexes_at_token: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") - ] = None - r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this token""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "tokenSecret", - "enabled", - "description", - "allowedIndexesAtToken", - "metadata", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputZscalerHecTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputZscalerHecType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - hec_api: str - r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -2695,77 +2805,52 @@ class CreateInputInputZscalerHecTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[CreateInputInputZscalerHecAuthTokenTypedDict]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + okta_token: NotRequired[str] + r"""Your Okta API token for authentication""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + manage_state: NotRequired[CreateInputInputOktaManageStateTypedDict] + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - allowed_indexes: NotRequired[List[str]] - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - access_control_allow_origin: NotRequired[List[str]] - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - access_control_allow_headers: NotRequired[List[str]] - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - emit_token_metrics: NotRequired[bool] - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - hec_acks: NotRequired[bool] - r"""Whether to enable Zscaler HEC acknowledgements""" + r"""Fields to add to events from this input""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_hec_api: NotRequired[str] - r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_allowed_indexes: NotRequired[str] - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - template_access_control_allow_origin: NotRequired[str] - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_access_control_allow_headers: NotRequired[str] - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + template_okta_domain: NotRequired[str] + r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" -class CreateInputInputZscalerHec(BaseModel): +class CreateInputInputOkta(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputZscalerHecType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + type: CreateInputInputOktaType + r"""Connector type identifier.""" - port: float - r"""Port to listen on""" + okta_domain: Annotated[str, pydantic.Field(alias="oktaDomain")] + r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" - hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -2792,90 +2877,54 @@ class CreateInputInputZscalerHec(BaseModel): pq: Optional[PqType] = None - auth_tokens: Annotated[ - Optional[List[CreateInputInputZscalerHecAuthToken]], - pydantic.Field(alias="authTokens"), - ] = None - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + okta_token: Annotated[Optional[str], pydantic.Field(alias="oktaToken")] = None + r"""Your Okta API token for authentication""" - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") + manage_state: Annotated[ + Optional[CreateInputInputOktaManageState], pydantic.Field(alias="manageState") ] = None - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - - allowed_indexes: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexes") - ] = None - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - - access_control_allow_origin: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") - ] = None - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - - access_control_allow_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") - ] = None - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + r"""Fields to add to events from this input""" - emit_token_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="emitTokenMetrics") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - - hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None - r"""Whether to enable Zscaler HEC acknowledgements""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -2890,35 +2939,10 @@ class CreateInputInputZscalerHec(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_hec_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_hecAPI") - ] = None - r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - - template_allowed_indexes: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedIndexes") + template_okta_domain: Annotated[ + Optional[str], pydantic.Field(alias="__template_oktaDomain") ] = None - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - - template_access_control_allow_origin: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") - ] = None - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - - template_access_control_allow_headers: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") - ] = None - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -2932,33 +2956,23 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", + "oktaToken", + "cronSchedule", + "earliest", + "latest", + "manageState", + "jobTimeout", "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "ipAllowlistRegex", - "ipDenylistRegex", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "allowedIndexes", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "emitTokenMetrics", - "hecAcks", + "retryRules", "description", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", - "__template_hecAPI", - "__template_allowedIndexes", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", + "__template_oktaDomain", ] ) serialized = handler(self) @@ -2975,66 +2989,178 @@ def serialize_model(self, handler): return m -class CreateInputInputServicenowTableType(str, Enum): +class CreateInputInputMicrosoftCopilotType(str, Enum): r"""Connector type identifier.""" - SERVICENOW_TABLE = "servicenow_table" - - -class CreateInputSortDirection(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Used only when Sort by field is set.""" - - # Ascending - ASC = "asc" - # Descending - DESC = "desc" + MICROSOFT_COPILOT = "microsoft_copilot" -class CreateInputInputServicenowTableAuthenticationType( +class CreateInputInputMicrosoftCopilotAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""ServiceNow Table API authentication method""" + r"""Select authentication method.""" - # None - NONE = "none" - # Basic - BASIC_SECRET = "basicSecret" - # OAuth OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" -class CreateInputGrantType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""ServiceNow OAuth grant type used for token requests""" +class CreateInputInputMicrosoftCopilotSubscriptionPlan( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" - # Password - CLIENT_CREDENTIALS = "client_credentials" - # Client credentials - PASSWORD = "password" + ENTERPRISE_GCC = "enterprise_gcc" + GCC = "gcc" + GCC_HIGH = "gcc_high" + DOD = "dod" -class CreateInputInputServicenowTableManageStateTypedDict(TypedDict): +class CreateInputInputMicrosoftCopilotManageStateTypedDict(TypedDict): pass -class CreateInputInputServicenowTableManageState(BaseModel): +class CreateInputInputMicrosoftCopilotManageState(BaseModel): pass -class CreateInputInputServicenowTableTypedDict(TypedDict): +class CreateInputRetryRulesTypedDict(TypedDict): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + interval: NotRequired[float] + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + limit: NotRequired[float] + r"""The maximum number of times to retry a failed HTTP request""" + multiplier: NotRequired[float] + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + codes: NotRequired[List[float]] + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + enable_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + retry_connect_timeout: NotRequired[bool] + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + retry_connect_reset: NotRequired[bool] + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + +class CreateInputRetryRules(BaseModel): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + + interval: Optional[float] = None + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + + limit: Optional[float] = None + r"""The maximum number of times to retry a failed HTTP request""" + + multiplier: Optional[float] = None + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + + codes: Optional[List[float]] = None + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( + None + ) + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + + retry_connect_timeout: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectTimeout") + ] = None + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + + retry_connect_reset: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectReset") + ] = None + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + @field_serializer("type") + def serialize_type(self, value): + if isinstance(value, str): + try: + return models.RetryTypeOptionsHealthCheckCollectorConfRetryRules(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "interval", + "limit", + "multiplier", + "codes", + "enableHeader", + "retryConnectTimeout", + "retryConnectReset", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputCertOptionsTypedDict(TypedDict): + priv_key_path: str + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + cert_path: str + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + certificate_name: NotRequired[str] + r"""The name of a predefined certificate""" + passphrase: NotRequired[str] + r"""Passphrase to decrypt the private key""" + + +class CreateInputCertOptions(BaseModel): + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The name of a predefined certificate""" + + passphrase: Optional[str] = None + r"""Passphrase to decrypt the private key""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["certificateName", "passphrase"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputMicrosoftCopilotTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputServicenowTableType + type: CreateInputInputMicrosoftCopilotType r"""Connector type identifier.""" - instance: str - r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - table_name: str - r"""ServiceNow table name to collect from.""" - cron_schedule: str - r"""Cron schedule on which to run this job""" - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + tenant_id: str + r"""Directory (tenant) ID from Azure Active Directory""" + client_id: str + r"""Application (client) ID from the app registration""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -3050,34 +3176,33 @@ class CreateInputInputServicenowTableTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - fields: NotRequired[List[str]] - r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - order_by_field: NotRequired[str] - r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" - order_by_direction: NotRequired[CreateInputSortDirection] - r"""Used only when Sort by field is set.""" - query: NotRequired[str] - r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + resource: NotRequired[str] + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" + auth_type: NotRequired[CreateInputInputMicrosoftCopilotAuthenticationMethod] + r"""Select authentication method.""" + plan_type: NotRequired[CreateInputInputMicrosoftCopilotSubscriptionPlan] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + cron_schedule: NotRequired[str] + r"""Cron schedule for collection runs""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" page_size: NotRequired[int] - r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" - max_pages: NotRequired[int] - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - auth_type: NotRequired[CreateInputInputServicenowTableAuthenticationType] - r"""ServiceNow Table API authentication method""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - log_level: NotRequired[LogLevelOptions] - r"""Collector runtime log level""" - request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - use_round_robin_dns: NotRequired[bool] - r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" + r"""Number of interactions to request per page ($top). Maximum 1000.""" + app_class_filter: NotRequired[List[str]] + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" + filter_by_license: NotRequired[bool] + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" + sku_ids: NotRequired[List[str]] + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" + manage_state: NotRequired[CreateInputInputMicrosoftCopilotManageStateTypedDict] + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" keep_alive_time: NotRequired[float] r"""How often workers should check in with the scheduler to keep job subscription alive""" job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" max_missed_keep_alives: NotRequired[float] r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" ttl: NotRequired[str] @@ -3086,69 +3211,40 @@ class CreateInputInputServicenowTableTypedDict(TypedDict): r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + retry_rules: NotRequired[CreateInputRetryRulesTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" description: NotRequired[str] r"""Optional description for this configuration.""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - oauth_grant_type: NotRequired[CreateInputGrantType] - r"""ServiceNow OAuth grant type used for token requests""" - username: NotRequired[str] - r"""ServiceNow username for the password grant type""" text_secret: NotRequired[str] - r"""Select or create a stored text secret for the ServiceNow password value""" - use_custom_o_auth_params_or_headers: NotRequired[bool] - r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - client_id: NotRequired[str] - r"""ServiceNow OAuth client ID""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret for the OAuth client secret value""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[CreateInputInputServicenowTableManageStateTypedDict] + r"""Select or create a secret that references the client secret from your app registration""" + cert_options: NotRequired[CreateInputCertOptionsTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_instance: NotRequired[str] - r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - template_order_by_field: NotRequired[str] - r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - template_query: NotRequired[str] - r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" template_client_id: NotRequired[str] r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" -class CreateInputInputServicenowTable(BaseModel): +class CreateInputInputMicrosoftCopilot(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputServicenowTableType + type: CreateInputInputMicrosoftCopilotType r"""Connector type identifier.""" - instance: str - r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - - table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""ServiceNow table name to collect from.""" - - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""Cron schedule on which to run this job""" - - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Directory (tenant) ID from Azure Active Directory""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""Application (client) ID from the app registration""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -3175,58 +3271,53 @@ class CreateInputInputServicenowTable(BaseModel): pq: Optional[PqType] = None - fields: Optional[List[str]] = None - r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" + resource: Optional[str] = None + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" - order_by_field: Annotated[Optional[str], pydantic.Field(alias="orderByField")] = ( - None - ) - r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" + auth_type: Annotated[ + Optional[CreateInputInputMicrosoftCopilotAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" - order_by_direction: Annotated[ - Optional[CreateInputSortDirection], pydantic.Field(alias="orderByDirection") + plan_type: Annotated[ + Optional[CreateInputInputMicrosoftCopilotSubscriptionPlan], + pydantic.Field(alias="planType"), ] = None - r"""Used only when Sort by field is set.""" + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" - query: Optional[str] = None - r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Cron schedule for collection runs""" - page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None - r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" - max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None + r"""Number of interactions to request per page ($top). Maximum 1000.""" - auth_type: Annotated[ - Optional[CreateInputInputServicenowTableAuthenticationType], - pydantic.Field(alias="authType"), + app_class_filter: Annotated[ + Optional[List[str]], pydantic.Field(alias="appClassFilter") ] = None - r"""ServiceNow Table API authentication method""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" - log_level: Annotated[ - Optional[LogLevelOptions], pydantic.Field(alias="logLevel") + filter_by_license: Annotated[ + Optional[bool], pydantic.Field(alias="filterByLicense") ] = None - r"""Collector runtime log level""" + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + sku_ids: Annotated[Optional[List[str]], pydantic.Field(alias="skuIds")] = None + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + manage_state: Annotated[ + Optional[CreateInputInputMicrosoftCopilotManageState], + pydantic.Field(alias="manageState"), ] = None - r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" keep_alive_time: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTime") @@ -3234,7 +3325,7 @@ class CreateInputInputServicenowTable(BaseModel): r"""How often workers should check in with the scheduler to keep job subscription alive""" job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" max_missed_keep_alives: Annotated[ Optional[float], pydantic.Field(alias="maxMissedKeepAlives") @@ -3253,66 +3344,27 @@ class CreateInputInputServicenowTable(BaseModel): r"""Fields to add to events from this input""" retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + Optional[CreateInputRetryRules], pydantic.Field(alias="retryRules") ] = None - description: Optional[str] = None - r"""Optional description for this configuration.""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Select or create a secret that references your credentials""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - oauth_grant_type: Annotated[ - Optional[CreateInputGrantType], pydantic.Field(alias="oauthGrantType") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""ServiceNow OAuth grant type used for token requests""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - username: Optional[str] = None - r"""ServiceNow username for the password grant type""" + description: Optional[str] = None + r"""Optional description for this configuration.""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret for the ServiceNow password value""" - - use_custom_o_auth_params_or_headers: Annotated[ - Optional[bool], pydantic.Field(alias="useCustomOAuthParamsOrHeaders") - ] = None - r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""ServiceNow OAuth client ID""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret for the OAuth client secret value""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + r"""Select or create a secret that references the client secret from your app registration""" - manage_state: Annotated[ - Optional[CreateInputInputServicenowTableManageState], - pydantic.Field(alias="manageState"), + cert_options: Annotated[ + Optional[CreateInputCertOptions], pydantic.Field(alias="certOptions") ] = None template_environment: Annotated[ @@ -3325,63 +3377,37 @@ class CreateInputInputServicenowTable(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_instance: Annotated[ - Optional[str], pydantic.Field(alias="__template_instance") - ] = None - r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - - template_order_by_field: Annotated[ - Optional[str], pydantic.Field(alias="__template_orderByField") - ] = None - r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - - template_query: Annotated[ - Optional[str], pydantic.Field(alias="__template_query") - ] = None - r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" template_client_id: Annotated[ Optional[str], pydantic.Field(alias="__template_clientId") ] = None r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - @field_serializer("order_by_direction") - def serialize_order_by_direction(self, value): - if isinstance(value, str): - try: - return models.CreateInputSortDirection(value) - except ValueError: - return value - return value + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputInputServicenowTableAuthenticationType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptions(value) + return models.CreateInputInputMicrosoftCopilotAuthenticationMethod( + value + ) except ValueError: return value return value - @field_serializer("oauth_grant_type") - def serialize_oauth_grant_type(self, value): + @field_serializer("plan_type") + def serialize_plan_type(self, value): if isinstance(value, str): try: - return models.CreateInputGrantType(value) + return models.CreateInputInputMicrosoftCopilotSubscriptionPlan(value) except ValueError: return value return value @@ -3398,18 +3424,18 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "fields", - "orderByField", - "orderByDirection", - "query", - "pageSize", - "maxPages", - "rejectUnauthorized", + "resource", "authType", - "stateTracking", - "logLevel", - "requestTimeout", - "useRoundRobinDns", + "planType", + "cronSchedule", + "earliest", + "latest", + "pageSize", + "appClassFilter", + "filterByLicense", + "skuIds", + "manageState", + "timeout", "keepAliveTime", "jobTimeout", "maxMissedKeepAlives", @@ -3417,26 +3443,16 @@ def serialize_model(self, handler): "ignoreGroupJobsLimit", "metadata", "retryRules", + "breakerRulesets", + "staleChannelFlushMs", "description", - "credentialsSecret", - "oauthGrantType", - "username", "textSecret", - "useCustomOAuthParamsOrHeaders", - "oauthParams", - "oauthHeaders", - "clientId", - "clientTextSecret", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", + "certOptions", "__template_environment", "__template_streamtags", - "__template_instance", - "__template_orderByField", - "__template_query", - "__template_username", + "__template_tenantId", "__template_clientId", + "__template_planType", ] ) serialized = handler(self) @@ -3453,19 +3469,170 @@ def serialize_model(self, handler): return m -class CreateInputInputBedrockS3Type(str, Enum): +class CreateInputInputAnthropicEnterpriseAnalyticsType(str, Enum): r"""Connector type identifier.""" - BEDROCK_S3 = "bedrock_s3" + ANTHROPIC_ENTERPRISE_ANALYTICS = "anthropic_enterprise_analytics" -class CreateInputInputBedrockS3TypedDict(TypedDict): +class CreateInputContentType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Content type""" + + USAGE_REPORT = "Usage Report" + COST_REPORT = "Cost Report" + + +class CreateInputGroupBy(str, Enum, metaclass=utils.OpenEnumMeta): + MODEL = "model" + PRODUCT = "product" + CONTEXT_WINDOW = "context_window" + INFERENCE_GEO = "inference_geo" + SPEED = "speed" + RBAC_GROUP_ID = "rbac_group_id" + SLACK_CHANNEL_ID = "slack_channel_id" + TEAMS_CHANNEL_ID = "teams_channel_id" + COST_TYPE = "cost_type" + TOKEN_TYPE = "token_type" + + +class CreateInputBucketWidth(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + + # Daily (1d) + ONED = "1d" + # Hourly (1h) + ONEH = "1h" + # Per-minute (1m) + ONEM = "1m" + + +class CreateInputInputAnthropicEnterpriseAnalyticsContentConfigTypedDict(TypedDict): + content_type: CreateInputContentType + r"""Content type""" + cron_schedule: str + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + disabled: NotRequired[bool] + r"""Enabled""" + state_tracking: NotRequired[bool] + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + state_update_expression: NotRequired[str] + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" + manage_state: NotRequired[bool] + r"""Manage state""" + group_by: NotRequired[List[CreateInputGroupBy]] + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" + bucket_width: NotRequired[CreateInputBucketWidth] + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + +class CreateInputInputAnthropicEnterpriseAnalyticsContentConfig(BaseModel): + content_type: Annotated[CreateInputContentType, pydantic.Field(alias="contentType")] + r"""Content type""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + + disabled: Optional[bool] = None + r"""Enabled""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" + + manage_state: Annotated[Optional[bool], pydantic.Field(alias="manageState")] = None + r"""Manage state""" + + group_by: Annotated[ + Optional[List[CreateInputGroupBy]], pydantic.Field(alias="groupBy") + ] = None + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" + + bucket_width: Annotated[ + Optional[CreateInputBucketWidth], pydantic.Field(alias="bucketWidth") + ] = None + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @field_serializer("content_type") + def serialize_content_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputContentType(value) + except ValueError: + return value + return value + + @field_serializer("bucket_width") + def serialize_bucket_width(self, value): + if isinstance(value, str): + try: + return models.CreateInputBucketWidth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "groupBy", + "bucketWidth", + "earliest", + "jobTimeout", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputAnthropicEnterpriseAnalyticsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputBedrockS3Type + type: CreateInputInputAnthropicEnterpriseAnalyticsType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + text_secret: str + r"""Select or create a stored API key with read:analytics scope""" + content_config: List[ + CreateInputInputAnthropicEnterpriseAnalyticsContentConfigTypedDict + ] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -3481,125 +3648,48 @@ class CreateInputInputBedrockS3TypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + api_key: NotRequired[str] + r"""API key""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputInputBedrockS3(BaseModel): +class CreateInputInputAnthropicEnterpriseAnalytics(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputBedrockS3Type + type: CreateInputInputAnthropicEnterpriseAnalyticsType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored API key with read:analytics scope""" + + content_config: Annotated[ + List[CreateInputInputAnthropicEnterpriseAnalyticsContentConfig], + pydantic.Field(alias="contentConfig"), + ] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -3626,40 +3716,13 @@ class CreateInputInputBedrockS3(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -3671,147 +3734,36 @@ class CreateInputInputBedrockS3(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Use the same settings for S3 and SQS""" - - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" - - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - - checkpointing: Optional[CheckpointingType] = None - - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" - - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" - - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None - - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" @@ -3820,88 +3772,6 @@ class CreateInputInputBedrockS3(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") - ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") - ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -3914,61 +3784,19 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", + "apiKey", + "requestTimeout", "breakerRulesets", "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", + "retryRules", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", ] ) serialized = handler(self) @@ -3985,516 +3813,381 @@ def serialize_model(self, handler): return m -class CreateInputInputSecurityLakeTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsSecuritylake +class CreateInputInputAnthropicComplianceType(str, Enum): r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + ANTHROPIC_COMPLIANCE = "anthropic_compliance" -class CreateInputInputSecurityLake(BaseModel): - id: str - r"""Unique ID for this input""" - type: TypeOptionsSecuritylake - r"""Connector type identifier.""" +class CreateInputActivitiesManageStateTypedDict(TypedDict): + pass - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" +class CreateInputActivitiesManageState(BaseModel): + pass - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" +class CreateInputActivitiesTypedDict(TypedDict): + r"""Activities""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputActivitiesManageStateTypedDict] - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class CreateInputActivities(BaseModel): + r"""Activities""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + enabled: Optional[bool] = None + r"""Enabled""" - pq: Optional[PqType] = None + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Track collection progress between consecutive scheduled executions""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + manage_state: Annotated[ + Optional[CreateInputActivitiesManageState], pydantic.Field(alias="manageState") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + return m - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" +class CreateInputChatsManageStateTypedDict(TypedDict): + pass - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" +class CreateInputChatsManageState(BaseModel): + pass - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" +class CreateInputChatsTypedDict(TypedDict): + r"""Chats""" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputChatsManageStateTypedDict] - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" +class CreateInputChats(BaseModel): + r"""Chats""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + enabled: Optional[bool] = None + r"""Enabled""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" + + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Maximum file size for each Parquet chunk""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - checkpointing: Optional[CheckpointingType] = None + manage_state: Annotated[ + Optional[CreateInputChatsManageState], pydantic.Field(alias="manageState") + ] = None - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - description: Optional[str] = None - r"""Optional description for this configuration.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" + return m - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" +class CreateInputProjectsManageStateTypedDict(TypedDict): + pass - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" +class CreateInputProjectsManageState(BaseModel): + pass - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" +class CreateInputProjectsTypedDict(TypedDict): + r"""Projects""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputProjectsManageStateTypedDict] - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" +class CreateInputProjects(BaseModel): + r"""Projects""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + enabled: Optional[bool] = None + r"""Enabled""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + manage_state: Annotated[ + Optional[CreateInputProjectsManageState], pydantic.Field(alias="manageState") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") - ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + return m - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") - ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value +class CreateInputChatMessagesManageStateTypedDict(TypedDict): + pass - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value +class CreateInputChatMessagesManageState(BaseModel): + pass + + +class CreateInputChatMessagesTypedDict(TypedDict): + r"""Chat Messages""" + + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputChatMessagesManageStateTypedDict] + + +class CreateInputChatMessages(BaseModel): + r"""Chat Messages""" + + enabled: Optional[bool] = None + r"""Enabled""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" + + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputChatMessagesManageState], + pydantic.Field(alias="manageState"), + ] = None @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", - "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", ] ) serialized = handler(self) @@ -4511,188 +4204,129 @@ def serialize_model(self, handler): return m -class CreateInputInputNetflowTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsNetflow - r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - enable_pass_through: NotRequired[bool] - r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - template_cache_minutes: NotRequired[float] - r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" - v5_enabled: NotRequired[bool] - r"""Accept messages in Netflow V5 format.""" - v9_enabled: NotRequired[bool] - r"""Accept messages in Netflow V9 format.""" - ipfix_enabled: NotRequired[bool] - r"""Accept messages in IPFIX format.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" +class CreateInputProjectDetailsManageStateTypedDict(TypedDict): + pass -class CreateInputInputNetflow(BaseModel): - id: str - r"""Unique ID for this input""" +class CreateInputProjectDetailsManageState(BaseModel): + pass - type: TypeOptionsNetflow - r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" +class CreateInputProjectDetailsTypedDict(TypedDict): + r"""Project Details""" - port: float - r"""Port to listen on""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputProjectDetailsManageStateTypedDict] - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" +class CreateInputProjectDetails(BaseModel): + r"""Project Details""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" + enabled: Optional[bool] = None + r"""Enabled""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - pq: Optional[PqType] = None + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" - enable_pass_through: Annotated[ - Optional[bool], pydantic.Field(alias="enablePassThrough") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + manage_state: Annotated[ + Optional[CreateInputProjectDetailsManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") - ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - template_cache_minutes: Annotated[ - Optional[float], pydantic.Field(alias="templateCacheMinutes") - ] = None - r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - v5_enabled: Annotated[Optional[bool], pydantic.Field(alias="v5Enabled")] = None - r"""Accept messages in Netflow V5 format.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - v9_enabled: Annotated[Optional[bool], pydantic.Field(alias="v9Enabled")] = None - r"""Accept messages in Netflow V9 format.""" + return m - ipfix_enabled: Annotated[Optional[bool], pydantic.Field(alias="ipfixEnabled")] = ( - None - ) - r"""Accept messages in IPFIX format.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" +class CreateInputGroupsTypedDict(TypedDict): + r"""Groups""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" +class CreateInputGroups(BaseModel): + r"""Groups""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + enabled: Optional[bool] = None + r"""Enabled""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "enablePassThrough", - "ipAllowlistRegex", - "ipDenylistRegex", - "udpSocketRxBufSize", - "templateCacheMinutes", - "v5Enabled", - "v9Enabled", - "ipfixEnabled", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - ] - ) + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) serialized = handler(self) m = {} @@ -4707,21 +4341,133 @@ def serialize_model(self, handler): return m -class CreateInputInputWizWebhookType(str, Enum): - r"""Source type identifier.""" +class CreateInputOrganizationsTypedDict(TypedDict): + r"""Organizations""" - WIZ_WEBHOOK = "wiz_webhook" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" -class CreateInputInputWizWebhookTypedDict(TypedDict): +class CreateInputOrganizations(BaseModel): + r"""Organizations""" + + enabled: Optional[bool] = None + r"""Enabled""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputOrganizationUsersTypedDict(TypedDict): + r"""Organization Users""" + + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + +class CreateInputOrganizationUsers(BaseModel): + r"""Organization Users""" + + enabled: Optional[bool] = None + r"""Enabled""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputOrganizationRolesTypedDict(TypedDict): + r"""Organization Roles""" + + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + +class CreateInputOrganizationRoles(BaseModel): + r"""Organization Roles""" + + enabled: Optional[bool] = None + r"""Enabled""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputAnthropicComplianceTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputWizWebhookType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" + type: CreateInputInputAnthropicComplianceType + r"""Connector type identifier.""" + text_secret: str + r"""Select or create a stored Anthropic API key""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -4737,72 +4483,60 @@ class CreateInputInputWizWebhookTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + api_key: NotRequired[str] + r"""API key""" + activities: NotRequired[CreateInputActivitiesTypedDict] + r"""Activities""" + chats: NotRequired[CreateInputChatsTypedDict] + r"""Chats""" + projects: NotRequired[CreateInputProjectsTypedDict] + r"""Projects""" + chat_messages: NotRequired[CreateInputChatMessagesTypedDict] + r"""Chat Messages""" + project_details: NotRequired[CreateInputProjectDetailsTypedDict] + r"""Project Details""" + groups: NotRequired[CreateInputGroupsTypedDict] + r"""Groups""" + organizations: NotRequired[CreateInputOrganizationsTypedDict] + r"""Organizations""" + org_users: NotRequired[CreateInputOrganizationUsersTypedDict] + r"""Organization Users""" + org_roles: NotRequired[CreateInputOrganizationRolesTypedDict] + r"""Organization Roles""" request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - allowed_paths: NotRequired[List[str]] - r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" - allowed_methods: NotRequired[List[str]] - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_allowed_paths: NotRequired[str] - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" -class CreateInputInputWizWebhook(BaseModel): +class CreateInputInputAnthropicCompliance(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputWizWebhookType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + type: CreateInputInputAnthropicComplianceType + r"""Connector type identifier.""" - port: float - r"""Port to listen on""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored Anthropic API key""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -4829,68 +4563,40 @@ class CreateInputInputWizWebhook(BaseModel): pq: Optional[PqType] = None - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + activities: Optional[CreateInputActivities] = None + r"""Activities""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + chats: Optional[CreateInputChats] = None + r"""Chats""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" + projects: Optional[CreateInputProjects] = None + r"""Projects""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + chat_messages: Optional[CreateInputChatMessages] = None + r"""Chat Messages""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + project_details: Optional[CreateInputProjectDetails] = None + r"""Project Details""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + groups: Optional[CreateInputGroups] = None + r"""Groups""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + organizations: Optional[CreateInputOrganizations] = None + r"""Organizations""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + org_users: Optional[CreateInputOrganizationUsers] = None + r"""Organization Users""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + org_roles: Optional[CreateInputOrganizationRoles] = None + r"""Organization Roles""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -4902,24 +4608,30 @@ class CreateInputInputWizWebhook(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" - allowed_paths: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedPaths") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - allowed_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedMethods") + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], - pydantic.Field(alias="authTokensExt"), + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -4934,26 +4646,6 @@ class CreateInputInputWizWebhook(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - template_allowed_paths: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedPaths") - ] = None - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -4966,32 +4658,28 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", + "apiKey", + "activities", + "chats", + "projects", + "chat_messages", + "project_details", + "groups", + "organizations", + "org_users", + "org_roles", "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", "breakerRulesets", "staleChannelFlushMs", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "allowedPaths", - "allowedMethods", - "authTokensExt", + "retryRules", "description", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_allowedPaths", ] ) serialized = handler(self) @@ -5008,223 +4696,40 @@ def serialize_model(self, handler): return m -class CreateInputInputOpenaiType(str, Enum): +class CreateInputInputOpenaiComplianceLogsType(str, Enum): r"""Connector type identifier.""" - OPENAI = "openai" + OPENAI_COMPLIANCE_LOGS = "openai_compliance_logs" -class CreateInputInputOpenaiManageStateTypedDict(TypedDict): - pass +class CreateInputAccountType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Account type""" + + # Workspace + WORKSPACE = "workspace" + # Organization + ORGANIZATION = "organization" -class CreateInputInputOpenaiManageState(BaseModel): +class CreateInputInputOpenaiComplianceLogsManageStateTypedDict(TypedDict): pass -class CreateInputPaginationType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Pagination type""" +class CreateInputInputOpenaiComplianceLogsManageState(BaseModel): + pass - # None - NONE = "none" - # Response Body Attribute - RESPONSE_BODY = "response_body" - # Response Header Attribute - RESPONSE_HEADER = "response_header" - # RFC 5988 Link Header - RESPONSE_HEADER_LINK = "response_header_link" - - -class CreateInputInputOpenaiLogLevel(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Collector runtime log level.""" - - ERROR = "error" - WARN = "warn" - INFO = "info" - DEBUG = "debug" - SILLY = "silly" - - -class CreateInputInputOpenaiContentConfigTypedDict(TypedDict): - request_params: List[ - RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict - ] - r"""Query-string parameters to send with this endpoint""" - pagination_type: CreateInputPaginationType - r"""Pagination type""" - cron_schedule: str - r"""A cron schedule on which to run this job""" - earliest: str - r"""Relative to the current time""" - latest: str - r"""Relative to the current time""" - disabled: NotRequired[bool] - r"""Enabled""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions.""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputInputOpenaiManageStateTypedDict] - pagination_attribute: NotRequired[List[str]] - r"""Pagination attributes""" - pagination_last_page_expr: NotRequired[str] - r"""Last page expression""" - max_pages: NotRequired[float] - r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" - pagination_next_relation_attribute: NotRequired[str] - r"""Used only for RFC 5988 link-header pagination""" - pagination_cur_relation_attribute: NotRequired[str] - r"""Optional relation that represents the current page""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: NotRequired[CreateInputInputOpenaiLogLevel] - r"""Collector runtime log level.""" - endpoint_metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields automatically added to events from this Content Type""" - - -class CreateInputInputOpenaiContentConfig(BaseModel): - request_params: Annotated[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret], - pydantic.Field(alias="requestParams"), - ] - r"""Query-string parameters to send with this endpoint""" - - pagination_type: Annotated[ - CreateInputPaginationType, pydantic.Field(alias="paginationType") - ] - r"""Pagination type""" - - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""A cron schedule on which to run this job""" - - earliest: str - r"""Relative to the current time""" - - latest: str - r"""Relative to the current time""" - - disabled: Optional[bool] = None - r"""Enabled""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions.""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" - - manage_state: Annotated[ - Optional[CreateInputInputOpenaiManageState], pydantic.Field(alias="manageState") - ] = None - - pagination_attribute: Annotated[ - Optional[List[str]], pydantic.Field(alias="paginationAttribute") - ] = None - r"""Pagination attributes""" - - pagination_last_page_expr: Annotated[ - Optional[str], pydantic.Field(alias="paginationLastPageExpr") - ] = None - r"""Last page expression""" - - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" - - pagination_next_relation_attribute: Annotated[ - Optional[str], pydantic.Field(alias="paginationNextRelationAttribute") - ] = None - r"""Used only for RFC 5988 link-header pagination""" - - pagination_cur_relation_attribute: Annotated[ - Optional[str], pydantic.Field(alias="paginationCurRelationAttribute") - ] = None - r"""Optional relation that represents the current page""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - log_level: Annotated[ - Optional[CreateInputInputOpenaiLogLevel], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime log level.""" - - endpoint_metadata: Annotated[ - Optional[List[MetadataConfInputCollection]], - pydantic.Field(alias="endpointMetadata"), - ] = None - r"""Fields automatically added to events from this Content Type""" - @field_serializer("pagination_type") - def serialize_pagination_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputPaginationType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputOpenaiLogLevel(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - "paginationAttribute", - "paginationLastPageExpr", - "maxPages", - "paginationNextRelationAttribute", - "paginationCurRelationAttribute", - "jobTimeout", - "logLevel", - "endpointMetadata", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputOpenaiTypedDict(TypedDict): +class CreateInputInputOpenaiComplianceLogsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputOpenaiType + type: CreateInputInputOpenaiComplianceLogsType r"""Connector type identifier.""" - content_config: List[CreateInputInputOpenaiContentConfigTypedDict] - r"""Content Types""" text_secret: str - r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" + r"""Select or create a stored text secret""" + account_type: CreateInputAccountType + r"""Account type""" + cron_schedule: str + r"""Cron schedule""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -5240,14 +4745,22 @@ class CreateInputInputOpenaiTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - openai_organization: NotRequired[str] - r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" - openai_project: NotRequired[str] - r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" - request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" api_key: NotRequired[str] r"""API key""" + earliest: NotRequired[str] + r"""Relative to the current time. Format: [+|-]""" + latest: NotRequired[str] + r"""Relative to the current time. Format: [+|-]""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] + r"""Collector runtime log level""" + max_pages: NotRequired[float] + r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" keep_alive_time: NotRequired[float] r"""How often workers should check in with the scheduler to keep job subscription alive""" max_missed_keep_alives: NotRequired[float] @@ -5258,33 +4771,51 @@ class CreateInputInputOpenaiTypedDict(TypedDict): r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" + workspace_id: NotRequired[str] + r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" + workspace_event_types: NotRequired[List[str]] + r"""One or more compliance log categories to collect""" + organization_id: NotRequired[str] + r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + organization_event_types: NotRequired[List[str]] + r"""One or more compliance log categories to collect""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputInputOpenaiComplianceLogsManageStateTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_openai_organization: NotRequired[str] - r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - template_openai_project: NotRequired[str] - r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" + template_workspace_id: NotRequired[str] + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + template_organization_id: NotRequired[str] + r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" -class CreateInputInputOpenai(BaseModel): +class CreateInputInputOpenaiComplianceLogs(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputOpenaiType + type: CreateInputInputOpenaiComplianceLogsType r"""Connector type identifier.""" - content_config: Annotated[ - List[CreateInputInputOpenaiContentConfig], pydantic.Field(alias="contentConfig") - ] - r"""Content Types""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" + r"""Select or create a stored text secret""" + + account_type: Annotated[CreateInputAccountType, pydantic.Field(alias="accountType")] + r"""Account type""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -5311,24 +4842,37 @@ class CreateInputInputOpenai(BaseModel): pq: Optional[PqType] = None - openai_organization: Annotated[ - Optional[str], pydantic.Field(alias="openaiOrganization") - ] = None - r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - openai_project: Annotated[Optional[str], pydantic.Field(alias="openaiProject")] = ( + earliest: Optional[str] = None + r"""Relative to the current time. Format: [+|-]""" + + latest: Optional[str] = None + r"""Relative to the current time. Format: [+|-]""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItemsDebugError], + pydantic.Field(alias="logLevel"), + ] = None + r"""Collector runtime log level""" + + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" + r"""Track collection progress between consecutive scheduled executions""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None r"""HTTP request inactivity timeout. Use 0 to disable.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" - keep_alive_time: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTime") ] = None @@ -5350,6 +4894,16 @@ class CreateInputInputOpenai(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + retry_rules: Annotated[ Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None @@ -5357,6 +4911,39 @@ class CreateInputInputOpenai(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None + r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" + + workspace_event_types: Annotated[ + Optional[List[str]], pydantic.Field(alias="workspaceEventTypes") + ] = None + r"""One or more compliance log categories to collect""" + + organization_id: Annotated[ + Optional[str], pydantic.Field(alias="organizationId") + ] = None + r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + + organization_event_types: Annotated[ + Optional[List[str]], pydantic.Field(alias="organizationEventTypes") + ] = None + r"""One or more compliance log categories to collect""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputInputOpenaiComplianceLogsManageState], + pydantic.Field(alias="manageState"), + ] = None + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -5367,15 +4954,33 @@ class CreateInputInputOpenai(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_openai_organization: Annotated[ - Optional[str], pydantic.Field(alias="__template_openaiOrganization") + template_workspace_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceId") ] = None - r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_openai_project: Annotated[ - Optional[str], pydantic.Field(alias="__template_openaiProject") + template_organization_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_organizationId") ] = None - r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" + r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" + + @field_serializer("account_type") + def serialize_account_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputAccountType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItemsDebugError(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -5389,21 +4994,34 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "openaiOrganization", - "openaiProject", - "requestTimeout", "apiKey", + "earliest", + "latest", + "jobTimeout", + "logLevel", + "maxPages", + "stateTracking", + "requestTimeout", "keepAliveTime", "maxMissedKeepAlives", "ttl", "ignoreGroupJobsLimit", "metadata", + "breakerRulesets", + "staleChannelFlushMs", "retryRules", "description", + "workspaceId", + "workspaceEventTypes", + "organizationId", + "organizationEventTypes", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", "__template_environment", "__template_streamtags", - "__template_openaiOrganization", - "__template_openaiProject", + "__template_workspaceId", + "__template_organizationId", ] ) serialized = handler(self) @@ -5420,127 +5038,294 @@ def serialize_model(self, handler): return m -class CreateInputInputWizType(str, Enum): - r"""Connector type identifier.""" - - WIZ = "wiz" +class CreateInputInputAquaSecurityHecType(str, Enum): + r"""Source type identifier.""" + AQUA_SECURITY_HEC = "aqua_security_hec" -class CreateInputInputWizManageStateTypedDict(TypedDict): - pass +class CreateInputInputAquaSecurityHecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputAquaSecurityHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputWizManageState(BaseModel): - pass +class CreateInputInputAquaSecurityHec(BaseModel): + id: str + r"""Unique ID for this input""" -class CreateInputInputWizContentConfigTypedDict(TypedDict): - content_type: str - r"""The name of the Wiz query""" - content_query: str - r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" - cron_schedule: str - r"""A cron schedule on which to run this job""" - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - content_description: NotRequired[str] - r"""Description""" - enabled: NotRequired[bool] - r"""Enable content""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[CreateInputInputWizManageStateTypedDict] - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" - log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] - r"""Collector runtime log level""" - max_pages: NotRequired[float] - r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" + type: CreateInputInputAquaSecurityHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" -class CreateInputInputWizContentConfig(BaseModel): - content_type: Annotated[str, pydantic.Field(alias="contentType")] - r"""The name of the Wiz query""" + port: float + r"""Port to listen on""" - content_query: Annotated[str, pydantic.Field(alias="contentQuery")] - r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""A cron schedule on which to run this job""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - content_description: Annotated[ - Optional[str], pydantic.Field(alias="contentDescription") + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Description""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - enabled: Optional[bool] = None - r"""Enable content""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + r"""Add request headers to events, in the __headers field""" - manage_state: Annotated[ - Optional[CreateInputInputWizManageState], pydantic.Field(alias="manageState") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItemsDebugError], - pydantic.Field(alias="logLevel"), + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""Collector runtime log level""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItemsDebugError(value) - except ValueError: - return value - return value + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "contentDescription", - "enabled", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - "jobTimeout", - "logLevel", - "maxPages", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -5557,19 +5342,23 @@ def serialize_model(self, handler): return m -class CreateInputInputWizTypedDict(TypedDict): +class CreateInputInputExtrahopRevealx360Type(str, Enum): + r"""Source type identifier.""" + + EXTRAHOP_REVEALX_360 = "extrahop_revealx_360" + + +class CreateInputInputExtrahopRevealx360TypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputWizType - r"""Connector type identifier.""" - endpoint: str - r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" - auth_url: str - r"""The authentication URL to generate an OAuth token""" - client_id: str - r"""The client ID of the Wiz application""" - content_config: List[CreateInputInputWizContentConfigTypedDict] - r"""Content types""" + type: CreateInputInputExtrahopRevealx360Type + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -5585,65 +5374,75 @@ class CreateInputInputWizTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_audience_override: NotRequired[str] - r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""The client secret of the Wiz application""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_auth_url: NotRequired[str] - r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputWiz(BaseModel): +class CreateInputInputExtrahopRevealx360(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputWizType - r"""Connector type identifier.""" - - endpoint: str - r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" + type: CreateInputInputExtrahopRevealx360Type + r"""Source type identifier.""" - auth_url: Annotated[str, pydantic.Field(alias="authUrl")] - r"""The authentication URL to generate an OAuth token""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - client_id: Annotated[str, pydantic.Field(alias="clientId")] - r"""The client ID of the Wiz application""" + port: float + r"""Port to listen on""" - content_config: Annotated[ - List[CreateInputInputWizContentConfig], pydantic.Field(alias="contentConfig") - ] - r"""Content types""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -5670,66 +5469,91 @@ class CreateInputInputWiz(BaseModel): pq: Optional[PqType] = None - auth_audience_override: Annotated[ - Optional[str], pydantic.Field(alias="authAudienceOverride") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None - r"""Enter client secret directly, or select a stored secret""" + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""The client secret of the Wiz application""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -5740,29 +5564,35 @@ class CreateInputInputWiz(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_auth_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_authUrl") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsManualSecret(value) - except ValueError: - return value - return value + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -5776,25 +5606,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "authAudienceOverride", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "retryRules", - "authType", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", - "clientSecret", - "textSecret", "__template_environment", "__template_streamtags", - "__template_endpoint", - "__template_authUrl", - "__template_clientId", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -5811,52 +5648,23 @@ def serialize_model(self, handler): return m -class CreateInputInputJournalFilesType(str, Enum): - r"""Connector type identifier.""" - - JOURNAL_FILES = "journal_files" - - -class CreateInputInputJournalFilesRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" - description: NotRequired[str] - r"""Optional description of this rule's purpose""" - - -class CreateInputInputJournalFilesRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" - - description: Optional[str] = None - r"""Optional description of this rule's purpose""" +class CreateInputInputSailpointHecType(str, Enum): + r"""Source type identifier.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} + SAILPOINT_HEC = "sailpoint_hec" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputInputJournalFilesTypedDict(TypedDict): +class CreateInputInputSailpointHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputJournalFilesType - r"""Connector type identifier.""" - path: str - r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" - journals: List[str] - r"""The full path of discovered journals are matched against this wildcard list.""" + type: CreateInputInputSailpointHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -5872,38 +5680,61 @@ class CreateInputInputJournalFilesTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between scanning for journals.""" - rules: NotRequired[List[CreateInputInputJournalFilesRuleTypedDict]] - r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" - current_boot: NotRequired[bool] - r"""Skip log messages that are not part of the current boot session""" - max_age_dur: NotRequired[str] - r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" - suppress_missing_path_errors: NotRequired[bool] - r"""Suppress errors when search path does not exist""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" -class CreateInputInputJournalFiles(BaseModel): +class CreateInputInputSailpointHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputJournalFilesType - r"""Connector type identifier.""" + type: CreateInputInputSailpointHecType + r"""Source type identifier.""" - path: str - r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - journals: List[str] - r"""The full path of discovered journals are matched against this wildcard list.""" + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -5930,25 +5761,67 @@ class CreateInputInputJournalFiles(BaseModel): pq: Optional[PqType] = None - interval: Optional[float] = None - r"""Time, in seconds, between scanning for journals.""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - rules: Optional[List[CreateInputInputJournalFilesRule]] = None - r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - current_boot: Annotated[Optional[bool], pydantic.Field(alias="currentBoot")] = None - r"""Skip log messages that are not part of the current boot session""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None - r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - suppress_missing_path_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Suppress errors when search path does not exist""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -5963,6 +5836,21 @@ class CreateInputInputJournalFiles(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -5975,15 +5863,25 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "interval", - "rules", - "currentBoot", - "maxAgeDur", - "suppressMissingPathErrors", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", ] ) serialized = handler(self) @@ -6000,21 +5898,23 @@ def serialize_model(self, handler): return m -class CreateInputInputRawUDPType(str, Enum): - r"""Connector type identifier.""" +class CreateInputInputTrellixHecType(str, Enum): + r"""Source type identifier.""" - RAW_UDP = "raw_udp" + TRELLIX_HEC = "trellix_hec" -class CreateInputInputRawUDPTypedDict(TypedDict): +class CreateInputInputTrellixHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputRawUDPType - r"""Connector type identifier.""" + type: CreateInputInputTrellixHecType + r"""Source type identifier.""" host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6030,18 +5930,40 @@ class CreateInputInputRawUDPTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - single_msg_udp_packets: NotRequired[bool] - r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" - ingest_raw_bytes: NotRequired[bool] - r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -6052,21 +5974,32 @@ class CreateInputInputRawUDPTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputRawUDP(BaseModel): +class CreateInputInputTrellixHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputRawUDPType - r"""Connector type identifier.""" + type: CreateInputInputTrellixHecType + r"""Source type identifier.""" host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -6092,33 +6025,87 @@ class CreateInputInputRawUDP(BaseModel): pq: Optional[PqType] = None - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Maximum number of events to buffer when downstream is blocking.""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to send data""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - ingest_raw_bytes: Annotated[ - Optional[bool], pydantic.Field(alias="ingestRawBytes") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -6143,6 +6130,26 @@ class CreateInputInputRawUDP(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -6155,17 +6162,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "maxBufferSize", - "ipWhitelistRegex", - "singleMsgUdpPackets", - "ingestRawBytes", - "udpSocketRxBufSize", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -6182,28 +6204,23 @@ def serialize_model(self, handler): return m -class CreateInputInputAppleUnifiedLogsType(str, Enum): - r"""Connector type identifier.""" - - APPLE_UNIFIED_LOGS = "apple_unified_logs" - - -class CreateInputInputAppleUnifiedLogsReadMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" +class CreateInputInputUpwindHecType(str, Enum): + r"""Source type identifier.""" - # Entire log - OLDEST = "oldest" - # From last entry - NEWEST = "newest" + UPWIND_HEC = "upwind_hec" -class CreateInputInputAppleUnifiedLogsTypedDict(TypedDict): +class CreateInputInputUpwindHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputAppleUnifiedLogsType - r"""Connector type identifier.""" - predicate: str - r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" + type: CreateInputInputUpwindHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6219,27 +6236,75 @@ class CreateInputInputAppleUnifiedLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - read_mode: NotRequired[CreateInputInputAppleUnifiedLogsReadMode] - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputAppleUnifiedLogs(BaseModel): +class CreateInputInputUpwindHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputAppleUnifiedLogsType - r"""Connector type identifier.""" + type: CreateInputInputUpwindHecType + r"""Source type identifier.""" - predicate: str - r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -6266,39 +6331,133 @@ class CreateInputInputAppleUnifiedLogs(BaseModel): pq: Optional[PqType] = None - read_mode: Annotated[ - Optional[CreateInputInputAppleUnifiedLogsReadMode], - pydantic.Field(alias="readMode"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @field_serializer("read_mode") - def serialize_read_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputAppleUnifiedLogsReadMode(value) - except ValueError: - return value - return value + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): optional_fields = set( [ "disabled", @@ -6309,11 +6468,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "readMode", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -6330,37 +6510,23 @@ def serialize_model(self, handler): return m -class CreateInputInputWinEventLogsType(str, Enum): - r"""Connector type identifier.""" - - WIN_EVENT_LOGS = "win_event_logs" - - -class CreateInputInputWinEventLogsReadMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Read all stored and future event logs, or only future events""" - - # Entire log - OLDEST = "oldest" - # From last entry - NEWEST = "newest" - - -class CreateInputEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of individual events""" +class CreateInputInputSysdigHecType(str, Enum): + r"""Source type identifier.""" - # JSON - JSON = "json" - # XML - XML = "xml" + SYSDIG_HEC = "sysdig_hec" -class CreateInputInputWinEventLogsTypedDict(TypedDict): +class CreateInputInputSysdigHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputWinEventLogsType - r"""Connector type identifier.""" - log_names: List[str] - r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + type: CreateInputInputSysdigHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6376,43 +6542,75 @@ class CreateInputInputWinEventLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - suppress_missing_log_errors: NotRequired[bool] - r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - read_mode: NotRequired[CreateInputInputWinEventLogsReadMode] - r"""Read all stored and future event logs, or only future events""" - event_format: NotRequired[CreateInputEventFormat] - r"""Format of individual events""" - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" - interval: NotRequired[float] - r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" - batch_size: NotRequired[float] - r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - max_event_bytes: NotRequired[int] - r"""The maximum number of bytes in an event before it is flushed to the pipelines""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - disable_json_rendering: NotRequired[bool] - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" - disable_xml_rendering: NotRequired[bool] - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputWinEventLogs(BaseModel): +class CreateInputInputSysdigHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputWinEventLogsType - r"""Connector type identifier.""" + type: CreateInputInputSysdigHecType + r"""Source type identifier.""" - log_names: Annotated[List[str], pydantic.Field(alias="logNames")] - r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -6439,52 +6637,90 @@ class CreateInputInputWinEventLogs(BaseModel): pq: Optional[PqType] = None - suppress_missing_log_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingLogErrors") - ] = None - r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - - read_mode: Annotated[ - Optional[CreateInputInputWinEventLogsReadMode], pydantic.Field(alias="readMode") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Read all stored and future event logs, or only future events""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - event_format: Annotated[ - Optional[CreateInputEventFormat], pydantic.Field(alias="eventFormat") + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Format of individual events""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - interval: Optional[float] = None - r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None - r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - max_event_bytes: Annotated[Optional[int], pydantic.Field(alias="maxEventBytes")] = ( - None - ) - r"""The maximum number of bytes in an event before it is flushed to the pipelines""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - disable_json_rendering: Annotated[ - Optional[bool], pydantic.Field(alias="disableJsonRendering") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - disable_xml_rendering: Annotated[ - Optional[bool], pydantic.Field(alias="disableXmlRendering") + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -6496,23 +6732,35 @@ class CreateInputInputWinEventLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - @field_serializer("read_mode") - def serialize_read_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputWinEventLogsReadMode(value) - except ValueError: - return value - return value + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - @field_serializer("event_format") - def serialize_event_format(self, value): - if isinstance(value, str): - try: - return models.CreateInputEventFormat(value) - except ValueError: - return value - return value + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -6526,19 +6774,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "suppressMissingLogErrors", - "readMode", - "eventFormat", - "disableNativeModule", - "interval", - "batchSize", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "maxEventBytes", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", - "disableJsonRendering", - "disableXmlRendering", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -6555,87 +6816,74 @@ def serialize_model(self, handler): return m -class CreateInputInputWefType(str, Enum): - r"""Connector type identifier.""" - - WEF = "wef" - - -class CreateInputInputWefAuthenticationMethod(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How to authenticate incoming client connections""" +class CreateInputInputCloudflareHecType(str, Enum): + r"""Source type identifier.""" - # Client certificate - CLIENT_CERT = "clientCert" - # Kerberos - KERBEROS = "kerberos" + CLOUDFLARE_HEC = "cloudflare_hec" -class CreateInputMTLSSettingsTypedDict(TypedDict): - r"""mTLS settings""" +class CreateInputTLSSettingsServerSideTypedDict(TypedDict): + r"""TLS settings (server side)""" - priv_key_path: str - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - cert_path: str - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - ca_path: str - r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" disabled: NotRequired[bool] - r"""Enable TLS""" - reject_unauthorized: NotRequired[bool] - r"""Required for WEF certificate authentication""" + r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" request_cert: NotRequired[bool] - r"""Required for WEF certificate authentication""" + r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" + ca_path: NotRequired[str] + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" + common_name_regex: NotRequired[str] + r"""Regex matching allowable common names in peer certificates' subject attribute""" certificate_name: NotRequired[str] - r"""Name of the predefined certificate""" + r"""The name of the predefined certificate""" + priv_key_path: NotRequired[str] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" passphrase: NotRequired[str] r"""Passphrase to use to decrypt private key""" - common_name_regex: NotRequired[str] - r"""Regex matching allowable common names in peer certificates' subject attribute""" + cert_path: NotRequired[str] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" min_version: NotRequired[MinimumTLSVersionOptionsTLS] r"""Minimum TLS version""" max_version: NotRequired[MaximumTLSVersionOptionsTLS] r"""Maximum TLS version""" - ocsp_check: NotRequired[bool] - r"""Enable OCSP check of certificate""" - ocsp_check_fail_close: NotRequired[bool] - r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" -class CreateInputMTLSSettings(BaseModel): - r"""mTLS settings""" - - priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" +class CreateInputTLSSettingsServerSide(BaseModel): + r"""TLS settings (server side)""" - cert_path: Annotated[str, pydantic.Field(alias="certPath")] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + disabled: Optional[bool] = None + r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - ca_path: Annotated[str, pydantic.Field(alias="caPath")] - r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" + request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None + r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - disabled: Optional[bool] = None - r"""Enable TLS""" + ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Required for WEF certificate authentication""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" - request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None - r"""Required for WEF certificate authentication""" + common_name_regex: Annotated[ + Optional[str], pydantic.Field(alias="commonNameRegex") + ] = None + r"""Regex matching allowable common names in peer certificates' subject attribute""" certificate_name: Annotated[ Optional[str], pydantic.Field(alias="certificateName") ] = None - r"""Name of the predefined certificate""" + r"""The name of the predefined certificate""" + + priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" passphrase: Optional[str] = None r"""Passphrase to use to decrypt private key""" - common_name_regex: Annotated[ - Optional[str], pydantic.Field(alias="commonNameRegex") - ] = None - r"""Regex matching allowable common names in peer certificates' subject attribute""" + cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" min_version: Annotated[ Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") @@ -6647,14 +6895,6 @@ class CreateInputMTLSSettings(BaseModel): ] = None r"""Maximum TLS version""" - ocsp_check: Annotated[Optional[bool], pydantic.Field(alias="ocspCheck")] = None - r"""Enable OCSP check of certificate""" - - ocsp_check_fail_close: Annotated[ - Optional[bool], pydantic.Field(alias="ocspCheckFailClose") - ] = None - r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" - @field_serializer("min_version") def serialize_min_version(self, value): if isinstance(value, str): @@ -6678,171 +6918,16 @@ def serialize_model(self, handler): optional_fields = set( [ "disabled", - "rejectUnauthorized", "requestCert", + "caPath", + "rejectUnauthorized", + "commonNameRegex", "certificateName", + "privKeyPath", "passphrase", - "commonNameRegex", + "certPath", "minVersion", "maxVersion", - "ocspCheck", - "ocspCheckFailClose", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Content format in which the endpoint should deliver events""" - - RAW = "Raw" - RENDERED_TEXT = "RenderedText" - - -class CreateInputQueryBuilderMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Query builder mode""" - - SIMPLE = "simple" - XML = "xml" - - -class CreateInputQueryTypedDict(TypedDict): - path: str - r"""The Path attribute from the relevant XML Select element""" - query_expression: str - r"""The XPath query inside the relevant XML Select element""" - - -class CreateInputQuery(BaseModel): - path: str - r"""The Path attribute from the relevant XML Select element""" - - query_expression: Annotated[str, pydantic.Field(alias="queryExpression")] - r"""The XPath query inside the relevant XML Select element""" - - -class CreateInputSubscriptionTypedDict(TypedDict): - subscription_name: str - r"""Subscription name""" - content_format: CreateInputFormat - r"""Content format in which the endpoint should deliver events""" - heartbeat_interval: float - r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" - batch_timeout: float - r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" - targets: List[str] - r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" - version: NotRequired[str] - r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" - read_existing_events: NotRequired[bool] - r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" - send_bookmarks: NotRequired[bool] - r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - compress: NotRequired[bool] - r"""Receive compressed events from the source""" - locale: NotRequired[str] - r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" - query_selector: NotRequired[CreateInputQueryBuilderMode] - r"""Query builder mode""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events ingested under this subscription""" - queries: NotRequired[List[CreateInputQueryTypedDict]] - r"""Queries""" - xml_query: NotRequired[str] - r"""The XPath query to use for selecting events""" - - -class CreateInputSubscription(BaseModel): - subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] - r"""Subscription name""" - - content_format: Annotated[CreateInputFormat, pydantic.Field(alias="contentFormat")] - r"""Content format in which the endpoint should deliver events""" - - heartbeat_interval: Annotated[float, pydantic.Field(alias="heartbeatInterval")] - r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" - - batch_timeout: Annotated[float, pydantic.Field(alias="batchTimeout")] - r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" - - targets: List[str] - r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" - - version: Optional[str] = None - r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" - - read_existing_events: Annotated[ - Optional[bool], pydantic.Field(alias="readExistingEvents") - ] = None - r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" - - send_bookmarks: Annotated[Optional[bool], pydantic.Field(alias="sendBookmarks")] = ( - None - ) - r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - - compress: Optional[bool] = None - r"""Receive compressed events from the source""" - - locale: Optional[str] = None - r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" - - query_selector: Annotated[ - Optional[CreateInputQueryBuilderMode], pydantic.Field(alias="querySelector") - ] = None - r"""Query builder mode""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events ingested under this subscription""" - - queries: Optional[List[CreateInputQuery]] = None - r"""Queries""" - - xml_query: Annotated[Optional[str], pydantic.Field(alias="xmlQuery")] = None - r"""The XPath query to use for selecting events""" - - @field_serializer("content_format") - def serialize_content_format(self, value): - if isinstance(value, str): - try: - return models.CreateInputFormat(value) - except ValueError: - return value - return value - - @field_serializer("query_selector") - def serialize_query_selector(self, value): - if isinstance(value, str): - try: - return models.CreateInputQueryBuilderMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "version", - "readExistingEvents", - "sendBookmarks", - "compress", - "locale", - "querySelector", - "metadata", - "queries", - "xmlQuery", ] ) serialized = handler(self) @@ -6859,17 +6944,17 @@ def serialize_model(self, handler): return m -class CreateInputInputWefTypedDict(TypedDict): +class CreateInputInputCloudflareHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputWefType - r"""Connector type identifier.""" + type: CreateInputInputCloudflareHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" - subscriptions: List[CreateInputSubscriptionTypedDict] - r"""Subscriptions to events on forwarding endpoints""" + hec_api: str + r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6885,42 +6970,46 @@ class CreateInputInputWefTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_method: NotRequired[CreateInputInputWefAuthenticationMethod] - r"""How to authenticate incoming client connections""" - tls: NotRequired[CreateInputMTLSSettingsTypedDict] - r"""mTLS settings""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[CreateInputTLSSettingsServerSideTypedDict] + r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" max_requests_per_socket: NotRequired[int] r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" capture_headers: NotRequired[bool] - r"""Add request headers to events in the __headers field""" + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: NotRequired[float] r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" ip_allowlist_regex: NotRequired[str] r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - ca_fingerprint: NotRequired[str] - r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" - keytab: NotRequired[str] - r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" - principal: NotRequired[str] - r"""Kerberos principal used for authentication, typically in the form HTTP/@""" - allow_machine_id_mismatch: NotRequired[bool] - r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" description: NotRequired[str] r"""Optional description for this configuration.""" - log_fingerprint_mismatch: NotRequired[bool] - r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -6929,18 +7018,22 @@ class CreateInputInputWefTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_keytab: NotRequired[str] - r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" - template_principal: NotRequired[str] - r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputWef(BaseModel): +class CreateInputInputCloudflareHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputWefType - r"""Connector type identifier.""" + type: CreateInputInputCloudflareHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -6948,8 +7041,8 @@ class CreateInputInputWef(BaseModel): port: float r"""Port to listen on""" - subscriptions: List[CreateInputSubscription] - r"""Subscriptions to events on forwarding endpoints""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -6976,14 +7069,14 @@ class CreateInputInputWef(BaseModel): pq: Optional[PqType] = None - auth_method: Annotated[ - Optional[CreateInputInputWefAuthenticationMethod], - pydantic.Field(alias="authMethod"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""How to authenticate incoming client connections""" - - tls: Optional[CreateInputMTLSSettings] = None - r"""mTLS settings""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[CreateInputTLSSettingsServerSide] = None + r"""TLS settings (server side)""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None @@ -6998,23 +7091,33 @@ class CreateInputInputWef(BaseModel): enable_proxy_header: Annotated[ Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" capture_headers: Annotated[ Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Add request headers to events in the __headers field""" + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None @@ -7025,38 +7128,42 @@ class CreateInputInputWef(BaseModel): ] = None r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - ca_fingerprint: Annotated[Optional[str], pydantic.Field(alias="caFingerprint")] = ( - None - ) - r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - keytab: Optional[str] = None - r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - principal: Optional[str] = None - r"""Kerberos principal used for authentication, typically in the form HTTP/@""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - allow_machine_id_mismatch: Annotated[ - Optional[bool], pydantic.Field(alias="allowMachineIdMismatch") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" description: Optional[str] = None r"""Optional description for this configuration.""" - log_fingerprint_mismatch: Annotated[ - Optional[bool], pydantic.Field(alias="logFingerprintMismatch") - ] = None - r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -7077,24 +7184,25 @@ class CreateInputInputWef(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_keytab: Annotated[ - Optional[str], pydantic.Field(alias="__template_keytab") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_principal: Annotated[ - Optional[str], pydantic.Field(alias="__template_principal") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - @field_serializer("auth_method") - def serialize_auth_method(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputWefAuthenticationMethod(value) - except ValueError: - return value - return value + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -7108,30 +7216,34 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "authMethod", + "authTokens", "tls", "maxActiveReq", "maxRequestsPerSocket", "enableProxyHeader", "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", "keepAliveTimeout", - "enableHealthCheck", "ipAllowlistRegex", "ipDenylistRegex", - "socketTimeout", - "caFingerprint", - "keytab", - "principal", - "allowMachineIdMismatch", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "breakerRulesets", + "staleChannelFlushMs", "description", - "logFingerprintMismatch", "__template_environment", "__template_streamtags", "__template_host", "__template_port", - "__template_keytab", - "__template_principal", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -7148,65 +7260,77 @@ def serialize_model(self, handler): return m -class CreateInputInputAppscopeType(str, Enum): - r"""Connector type identifier.""" - - APPSCOPE = "appscope" - - -class CreateInputAllowTypedDict(TypedDict): - procname: str - r"""Specify the name of a process or family of processes.""" - config: str - r"""Choose a config to apply to processes that match the process name and/or argument.""" - arg: NotRequired[str] - r"""Specify a string to substring-match against process command-line.""" - +class CreateInputInputZscalerHecType(str, Enum): + r"""Source type identifier.""" -class CreateInputAllow(BaseModel): - procname: str - r"""Specify the name of a process or family of processes.""" + ZSCALER_HEC = "zscaler_hec" - config: str - r"""Choose a config to apply to processes that match the process name and/or argument.""" - arg: Optional[str] = None - r"""Specify a string to substring-match against process command-line.""" +class CreateInputInputZscalerHecAuthTokenTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + enabled: NotRequired[bool] + r"""Enable token""" + description: NotRequired[str] + r"""Description""" + allowed_indexes_at_token: NotRequired[List[str]] + r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["arg"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateInputInputZscalerHecAuthToken(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - return m + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + enabled: Optional[bool] = None + r"""Enable token""" -class CreateInputInputAppscopeFilterTypedDict(TypedDict): - allow: NotRequired[List[CreateInputAllowTypedDict]] - r"""Specify processes that AppScope should be loaded into, and the config to use.""" - transport_url: NotRequired[str] - r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" + description: Optional[str] = None + r"""Description""" + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" -class CreateInputInputAppscopeFilter(BaseModel): - allow: Optional[List[CreateInputAllow]] = None - r"""Specify processes that AppScope should be loaded into, and the config to use.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" - transport_url: Annotated[Optional[str], pydantic.Field(alias="transportURL")] = None - r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["allow", "transportURL"]) + optional_fields = set( + [ + "authType", + "tokenSecret", + "enabled", + "description", + "allowedIndexesAtToken", + "metadata", + ] + ) serialized = handler(self) m = {} @@ -7221,96 +7345,17 @@ def serialize_model(self, handler): return m -class CreateInputInputAppscopePersistenceTypedDict(TypedDict): - r"""Persistence""" - - enable: NotRequired[bool] - r"""Spool events and metrics on disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" - - -class CreateInputInputAppscopePersistence(BaseModel): - r"""Persistence""" - - enable: Optional[bool] = None - r"""Spool events and metrics on disk for Cribl Edge and Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -CreateInputUNIXSocketPermissionsTypedDict = TypeAliasType( - "CreateInputUNIXSocketPermissionsTypedDict", Union[str, float] -) -r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - -CreateInputUNIXSocketPermissions = TypeAliasType( - "CreateInputUNIXSocketPermissions", Union[str, float] -) -r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - -class CreateInputInputAppscopeTypedDict(TypedDict): +class CreateInputInputZscalerHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputAppscopeType - r"""Connector type identifier.""" + type: CreateInputInputZscalerHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -7326,47 +7371,44 @@ class CreateInputInputAppscopeTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + auth_tokens: NotRequired[List[CreateInputInputZscalerHecAuthTokenTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_unix_path: NotRequired[bool] - r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" - filter_: NotRequired[CreateInputInputAppscopeFilterTypedDict] - persistence: NotRequired[CreateInputInputAppscopePersistenceTypedDict] - r"""Persistence""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + hec_acks: NotRequired[bool] + r"""Whether to enable Zscaler HEC acknowledgements""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: NotRequired[float] - r"""Port to listen on""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - unix_socket_path: NotRequired[str] - r"""Path to the UNIX domain socket to listen on.""" - unix_socket_perms: NotRequired[CreateInputUNIXSocketPermissionsTypedDict] - r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -7375,14 +7417,31 @@ class CreateInputInputAppscopeTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputInputAppscope(BaseModel): +class CreateInputInputZscalerHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputAppscopeType - r"""Connector type identifier.""" + type: CreateInputInputZscalerHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -7409,95 +7468,93 @@ class CreateInputInputAppscope(BaseModel): pq: Optional[PqType] = None - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + auth_tokens: Annotated[ + Optional[List[CreateInputInputZscalerHecAuthToken]], + pydantic.Field(alias="authTokens"), ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Add request headers to events, in the __headers field""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_unix_path: Annotated[ - Optional[bool], pydantic.Field(alias="enableUnixPath") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - filter_: Annotated[ - Optional[CreateInputInputAppscopeFilter], pydantic.Field(alias="filter") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - persistence: Optional[CreateInputInputAppscopePersistence] = None - r"""Persistence""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - host: Optional[str] = None - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - port: Optional[float] = None - r"""Port to listen on""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable Zscaler HEC acknowledgements""" - unix_socket_path: Annotated[ - Optional[str], pydantic.Field(alias="unixSocketPath") - ] = None - r"""Path to the UNIX domain socket to listen on.""" - - unix_socket_perms: Annotated[ - Optional[CreateInputUNIXSocketPermissions], - pydantic.Field(alias="unixSocketPerms"), - ] = None - r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -7519,14 +7576,25 @@ class CreateInputInputAppscope(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -7540,31 +7608,33 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "enableUnixPath", - "filter", - "persistence", - "authType", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "hecAcks", "description", - "host", - "port", - "tls", - "unixSocketPath", - "unixSocketPerms", - "authToken", - "textSecret", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -7581,21 +7651,34 @@ def serialize_model(self, handler): return m -class CreateInputInputTCPType(str, Enum): +class CreateInputInputProofpointPodType(str, Enum): r"""Connector type identifier.""" - TCP = "tcp" + PROOFPOINT_POD = "proofpoint_pod" -class CreateInputInputTCPTypedDict(TypedDict): +class CreateInputFeedType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Proofpoint on Demand feed to ingest.""" + + # Message + MESSAGE = "message" + # Mail log + MAILLOG = "maillog" + # Audit + AUDIT = "audit" + + +class CreateInputInputProofpointPodTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputTCPType + type: CreateInputInputProofpointPodType r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" + cluster_id: str + r"""Proofpoint on Demand cluster ID.""" + feed_type: CreateInputFeedType + r"""Proofpoint on Demand feed to ingest.""" + text_secret: str + r"""Select or create a stored text secret""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -7611,60 +7694,45 @@ class CreateInputInputTCPTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_header: NotRequired[bool] - r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + compress: NotRequired[bool] + r"""Compress the feed connection.""" + handshake_timeout: NotRequired[float] + r"""Maximum time to wait for the connection handshake to complete.""" + keep_alive_interval_sec: NotRequired[float] + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" + max_missed_keep_alives: NotRequired[float] + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" + max_message_size: NotRequired[str] + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" + read_buffer_size: NotRequired[str] + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" description: NotRequired[str] r"""Optional description for this configuration.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_cluster_id: NotRequired[str] + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" -class CreateInputInputTCP(BaseModel): +class CreateInputInputProofpointPod(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputTCPType + type: CreateInputInputProofpointPodType r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + cluster_id: Annotated[str, pydantic.Field(alias="clusterId")] + r"""Proofpoint on Demand cluster ID.""" - port: float - r"""Port to listen on""" + feed_type: Annotated[CreateInputFeedType, pydantic.Field(alias="feedType")] + r"""Proofpoint on Demand feed to ingest.""" + + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -7691,75 +7759,40 @@ class CreateInputInputTCP(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + compress: Optional[bool] = None + r"""Compress the feed connection.""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + handshake_timeout: Annotated[ + Optional[float], pydantic.Field(alias="handshakeTimeout") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Maximum time to wait for the connection handshake to complete.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + keep_alive_interval_sec: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveIntervalSec") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + max_message_size: Annotated[ + Optional[str], pydantic.Field(alias="maxMessageSize") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + read_buffer_size: Annotated[ + Optional[str], pydantic.Field(alias="readBufferSize") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( - None - ) - r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" - - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" description: Optional[str] = None r"""Optional description for this configuration.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -7770,21 +7803,16 @@ class CreateInputInputTCP(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_cluster_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clusterId") + ] = None + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("feed_type") + def serialize_feed_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.CreateInputFeedType(value) except ValueError: return value return value @@ -7802,25 +7830,16 @@ def serialize_model(self, handler): "connections", "pq", "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "enableHeader", - "preprocess", + "compress", + "handshakeTimeout", + "keepAliveIntervalSec", + "maxMissedKeepAlives", + "maxMessageSize", + "readBufferSize", "description", - "authToken", - "authType", - "textSecret", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", + "__template_clusterId", ] ) serialized = handler(self) @@ -7837,100 +7856,181 @@ def serialize_model(self, handler): return m -class CreateInputInputFileType(str, Enum): +class CreateInputInputServicenowTableType(str, Enum): r"""Connector type identifier.""" - FILE = "file" + SERVICENOW_TABLE = "servicenow_table" -class CreateInputInputFileMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Choose how to discover files to monitor""" +class CreateInputSortDirection(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Used only when Sort by field is set.""" - # Manual - MANUAL = "manual" - # Auto - AUTO = "auto" + # Ascending + ASC = "asc" + # Descending + DESC = "desc" -class CreateInputInputFileTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputFileType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" +class CreateInputInputServicenowTableAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""ServiceNow Table API authentication method""" + + # None + NONE = "none" + # Basic + BASIC_SECRET = "basicSecret" + # OAuth + OAUTH_SECRET = "oauthSecret" + + +class CreateInputGrantType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""ServiceNow OAuth grant type used for token requests""" + + # Password + CLIENT_CREDENTIALS = "client_credentials" + # Client credentials + PASSWORD = "password" + + +class CreateInputInputServicenowTableManageStateTypedDict(TypedDict): + pass + + +class CreateInputInputServicenowTableManageState(BaseModel): + pass + + +class CreateInputInputServicenowTableTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputServicenowTableType + r"""Connector type identifier.""" + instance: str + r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" + table_name: str + r"""ServiceNow table name to collect from.""" + cron_schedule: str + r"""Cron schedule on which to run this job""" + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - mode: NotRequired[CreateInputInputFileMode] - r"""Choose how to discover files to monitor""" - interval: NotRequired[float] - r"""Time, in seconds, between scanning for files""" - filenames: NotRequired[List[str]] - r"""The full path of discovered files are matched against this wildcard list""" - filter_archived_files: NotRequired[bool] - r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - tail_only: NotRequired[bool] - r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" - idle_timeout: NotRequired[float] - r"""Time, in seconds, before an idle file is closed""" - min_age_dur: NotRequired[str] - r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" - max_age_dur: NotRequired[str] - r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" - check_file_mod_time: NotRequired[bool] - r"""Skip files with modification times earlier than the maximum age duration""" - force_text: NotRequired[bool] - r"""Forces files containing binary data to be streamed as text""" - hash_len: NotRequired[float] - r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + fields: NotRequired[List[str]] + r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" + order_by_field: NotRequired[str] + r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" + order_by_direction: NotRequired[CreateInputSortDirection] + r"""Used only when Sort by field is set.""" + query: NotRequired[str] + r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + page_size: NotRequired[int] + r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" + max_pages: NotRequired[int] + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + auth_type: NotRequired[CreateInputInputServicenowTableAuthenticationType] + r"""ServiceNow Table API authentication method""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + log_level: NotRequired[LogLevelOptions] + r"""Collector runtime log level""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + use_round_robin_dns: NotRequired[bool] + r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - disable_stale_channel_flush: NotRequired[bool] - r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - path: NotRequired[str] - r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" - depth: NotRequired[float] - r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" - suppress_missing_path_errors: NotRequired[bool] - r"""Suppress errors when search path does not exist""" - delete_files: NotRequired[bool] - r"""Delete files after they have been collected""" - salt_hash: NotRequired[bool] - r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" - optimize_leaf_directories: NotRequired[bool] - r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" - include_unidentifiable_binary: NotRequired[bool] - r"""Stream binary files as Base64-encoded chunks""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + oauth_grant_type: NotRequired[CreateInputGrantType] + r"""ServiceNow OAuth grant type used for token requests""" + username: NotRequired[str] + r"""ServiceNow username for the password grant type""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret for the ServiceNow password value""" + use_custom_o_auth_params_or_headers: NotRequired[bool] + r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + client_id: NotRequired[str] + r"""ServiceNow OAuth client ID""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth client secret value""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputInputServicenowTableManageStateTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_instance: NotRequired[str] + r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" + template_order_by_field: NotRequired[str] + r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" + template_query: NotRequired[str] + r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" -class CreateInputInputFile(BaseModel): +class CreateInputInputServicenowTable(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputFileType + type: CreateInputInputServicenowTableType r"""Connector type identifier.""" + instance: str + r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""ServiceNow table name to collect from.""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule on which to run this job""" + + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -7956,90 +8056,145 @@ class CreateInputInputFile(BaseModel): pq: Optional[PqType] = None - mode: Optional[CreateInputInputFileMode] = None - r"""Choose how to discover files to monitor""" - - interval: Optional[float] = None - r"""Time, in seconds, between scanning for files""" + fields: Optional[List[str]] = None + r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - filenames: Optional[List[str]] = None - r"""The full path of discovered files are matched against this wildcard list""" + order_by_field: Annotated[Optional[str], pydantic.Field(alias="orderByField")] = ( + None + ) + r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" - filter_archived_files: Annotated[ - Optional[bool], pydantic.Field(alias="filterArchivedFiles") + order_by_direction: Annotated[ + Optional[CreateInputSortDirection], pydantic.Field(alias="orderByDirection") ] = None - r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - - tail_only: Annotated[Optional[bool], pydantic.Field(alias="tailOnly")] = None - r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" + r"""Used only when Sort by field is set.""" - idle_timeout: Annotated[Optional[float], pydantic.Field(alias="idleTimeout")] = None - r"""Time, in seconds, before an idle file is closed""" + query: Optional[str] = None + r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" - min_age_dur: Annotated[Optional[str], pydantic.Field(alias="minAgeDur")] = None - r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" + page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None + r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" - max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None - r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" + max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - check_file_mod_time: Annotated[ - Optional[bool], pydantic.Field(alias="checkFileModTime") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Skip files with modification times earlier than the maximum age duration""" - - force_text: Annotated[Optional[bool], pydantic.Field(alias="forceText")] = None - r"""Forces files containing binary data to be streamed as text""" + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - hash_len: Annotated[Optional[float], pydantic.Field(alias="hashLen")] = None - r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + auth_type: Annotated[ + Optional[CreateInputInputServicenowTableAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""ServiceNow Table API authentication method""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + log_level: Annotated[ + Optional[LogLevelOptions], pydantic.Field(alias="logLevel") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""Collector runtime log level""" - disable_stale_channel_flush: Annotated[ - Optional[bool], pydantic.Field(alias="disableStaleChannelFlush") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" description: Optional[str] = None r"""Optional description for this configuration.""" - path: Optional[str] = None - r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" - depth: Optional[float] = None - r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" + oauth_grant_type: Annotated[ + Optional[CreateInputGrantType], pydantic.Field(alias="oauthGrantType") + ] = None + r"""ServiceNow OAuth grant type used for token requests""" - suppress_missing_path_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + username: Optional[str] = None + r"""ServiceNow username for the password grant type""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret for the ServiceNow password value""" + + use_custom_o_auth_params_or_headers: Annotated[ + Optional[bool], pydantic.Field(alias="useCustomOAuthParamsOrHeaders") ] = None - r"""Suppress errors when search path does not exist""" + r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - delete_files: Annotated[Optional[bool], pydantic.Field(alias="deleteFiles")] = None - r"""Delete files after they have been collected""" + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - salt_hash: Annotated[Optional[bool], pydantic.Field(alias="saltHash")] = None - r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - optimize_leaf_directories: Annotated[ - Optional[bool], pydantic.Field(alias="optimizeLeafDirectories") + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""ServiceNow OAuth client ID""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") ] = None - r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" + r"""Select or create a stored text secret for the OAuth client secret value""" - include_unidentifiable_binary: Annotated[ - Optional[bool], pydantic.Field(alias="includeUnidentifiableBinary") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputInputServicenowTableManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Stream binary files as Base64-encoded chunks""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -8051,11 +8206,63 @@ class CreateInputInputFile(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - @field_serializer("mode") - def serialize_mode(self, value): + template_instance: Annotated[ + Optional[str], pydantic.Field(alias="__template_instance") + ] = None + r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" + + template_order_by_field: Annotated[ + Optional[str], pydantic.Field(alias="__template_orderByField") + ] = None + r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" + + template_query: Annotated[ + Optional[str], pydantic.Field(alias="__template_query") + ] = None + r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") + ] = None + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + @field_serializer("order_by_direction") + def serialize_order_by_direction(self, value): if isinstance(value, str): try: - return models.CreateInputInputFileMode(value) + return models.CreateInputSortDirection(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputServicenowTableAuthenticationType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("oauth_grant_type") + def serialize_oauth_grant_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputGrantType(value) except ValueError: return value return value @@ -8072,31 +8279,45 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "mode", - "interval", - "filenames", - "filterArchivedFiles", - "tailOnly", - "idleTimeout", - "minAgeDur", - "maxAgeDur", - "checkFileModTime", - "forceText", - "hashLen", + "fields", + "orderByField", + "orderByDirection", + "query", + "pageSize", + "maxPages", + "rejectUnauthorized", + "authType", + "stateTracking", + "logLevel", + "requestTimeout", + "useRoundRobinDns", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "breakerRulesets", - "disableStaleChannelFlush", - "staleChannelFlushMs", + "retryRules", "description", - "path", - "depth", - "suppressMissingPathErrors", - "deleteFiles", - "saltHash", - "optimizeLeafDirectories", - "includeUnidentifiableBinary", + "credentialsSecret", + "oauthGrantType", + "username", + "textSecret", + "useCustomOAuthParamsOrHeaders", + "oauthParams", + "oauthHeaders", + "clientId", + "clientTextSecret", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", "__template_environment", "__template_streamtags", + "__template_instance", + "__template_orderByField", + "__template_query", + "__template_username", + "__template_clientId", ] ) serialized = handler(self) @@ -8113,15 +8334,19 @@ def serialize_model(self, handler): return m -class CreateInputInputSyslogSyslog2TypedDict(TypedDict): +class CreateInputInputBedrockS3Type(str, Enum): + r"""Connector type identifier.""" + + BEDROCK_S3 = "bedrock_s3" + + +class CreateInputInputBedrockS3TypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: CreateInputInputBedrockS3Type r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - tcp_port: float - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8137,74 +8362,125 @@ class CreateInputInputSyslogSyslog2TypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - udp_port: NotRequired[float] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - timestamp_timezone: NotRequired[str] - r"""Timezone to assign to timestamps without timezone info""" - single_msg_udp_packets: NotRequired[bool] - r"""Treat UDP packet data received as full syslog message""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - keep_fields_list: NotRequired[List[str]] - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - octet_counting: NotRequired[bool] - r"""Enable if incoming messages use octet counting per RFC 6587.""" - infer_framing: NotRequired[bool] - r"""Enable if we should infer the syslog framing of the incoming messages.""" - strictly_infer_octet_counting: NotRequired[bool] - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - allow_non_standard_app_name: NotRequired[bool] - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: NotRequired[bool] - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - template_timestamp_timezone: NotRequired[str] - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputInputSyslogSyslog2(BaseModel): +class CreateInputInputBedrockS3(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: CreateInputInputBedrockS3Type r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - - tcp_port: Annotated[float, pydantic.Field(alias="tcpPort")] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -8231,102 +8507,189 @@ class CreateInputInputSyslogSyslog2(BaseModel): pq: Optional[PqType] = None - udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Reuse connections between requests, which can improve performance""" - timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="timestampTimezone") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Timezone to assign to timestamps without timezone info""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Treat UDP packet data received as full syslog message""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - keep_fields_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="keepFieldsList") + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") ] = None - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( None ) - r"""Enable if incoming messages use octet counting per RFC 6587.""" + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( - None - ) - r"""Enable if we should infer the syslog framing of the incoming messages.""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - strictly_infer_octet_counting: Annotated[ - Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") ] = None - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - allow_non_standard_app_name: Annotated[ - Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + r"""Use Assume Role credentials to access Amazon S3""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + r"""Amazon Resource Name (ARN) of the role to assume""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""External ID to use when assuming role""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Use Assume Role credentials when accessing Amazon SQS""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""Maximum file size for each Parquet chunk""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: Optional[str] = None r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") ] = None - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -8338,25 +8701,87 @@ class CreateInputInputSyslogSyslog2(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="__template_timestampTimezone") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -8370,33 +8795,61 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "udpPort", - "maxBufferSize", - "ipWhitelistRegex", - "timestampTimezone", - "singleMsgUdpPackets", - "enableProxyHeader", - "keepFieldsList", - "octetCounting", - "inferFraming", - "strictlyInferOctetCounting", - "allowNonStandardAppName", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "tls", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", "metadata", - "udpSocketRxBufSize", - "enableLoadBalancing", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "encoding", "description", - "enableEnhancedProxyHeaderParsing", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", "__template_environment", "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", - "__template_timestampTimezone", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", ] ) serialized = handler(self) @@ -8413,15 +8866,13 @@ def serialize_model(self, handler): return m -class CreateInputInputSyslogSyslog1TypedDict(TypedDict): +class CreateInputInputSecurityLakeTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: TypeOptionsSecuritylake r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - udp_port: float - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8437,74 +8888,125 @@ class CreateInputInputSyslogSyslog1TypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tcp_port: NotRequired[float] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - timestamp_timezone: NotRequired[str] - r"""Timezone to assign to timestamps without timezone info""" - single_msg_udp_packets: NotRequired[bool] - r"""Treat UDP packet data received as full syslog message""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - keep_fields_list: NotRequired[List[str]] - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - octet_counting: NotRequired[bool] - r"""Enable if incoming messages use octet counting per RFC 6587.""" - infer_framing: NotRequired[bool] - r"""Enable if we should infer the syslog framing of the incoming messages.""" - strictly_infer_octet_counting: NotRequired[bool] - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - allow_non_standard_app_name: NotRequired[bool] - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: NotRequired[bool] - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - template_timestamp_timezone: NotRequired[str] - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputInputSyslogSyslog1(BaseModel): +class CreateInputInputSecurityLake(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: TypeOptionsSecuritylake r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - - udp_port: Annotated[float, pydantic.Field(alias="udpPort")] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -8531,102 +9033,189 @@ class CreateInputInputSyslogSyslog1(BaseModel): pq: Optional[PqType] = None - tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Reuse connections between requests, which can improve performance""" - timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="timestampTimezone") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Timezone to assign to timestamps without timezone info""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Treat UDP packet data received as full syslog message""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - keep_fields_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="keepFieldsList") + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") ] = None - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( None ) - r"""Enable if incoming messages use octet counting per RFC 6587.""" + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( - None - ) - r"""Enable if we should infer the syslog framing of the incoming messages.""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - strictly_infer_octet_counting: Annotated[ - Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") ] = None - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - allow_non_standard_app_name: Annotated[ - Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + r"""Use Assume Role credentials to access Amazon S3""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + r"""Amazon Resource Name (ARN) of the role to assume""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""External ID to use when assuming role""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + r"""Use Assume Role credentials when accessing Amazon SQS""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""Use the same settings for S3 and SQS""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: Optional[str] = None r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") ] = None - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -8638,25 +9227,87 @@ class CreateInputInputSyslogSyslog1(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="__template_timestampTimezone") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -8670,33 +9321,61 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "tcpPort", - "maxBufferSize", - "ipWhitelistRegex", - "timestampTimezone", - "singleMsgUdpPackets", - "enableProxyHeader", - "keepFieldsList", - "octetCounting", - "inferFraming", - "strictlyInferOctetCounting", - "allowNonStandardAppName", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "tls", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", "metadata", - "udpSocketRxBufSize", - "enableLoadBalancing", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "encoding", "description", - "enableEnhancedProxyHeaderParsing", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", "__template_environment", "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", - "__template_timestampTimezone", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", ] ) serialized = handler(self) @@ -8713,38 +9392,15 @@ def serialize_model(self, handler): return m -CreateInputInputSyslogUnionTypedDict = TypeAliasType( - "CreateInputInputSyslogUnionTypedDict", - Union[ - CreateInputInputSyslogSyslog1TypedDict, CreateInputInputSyslogSyslog2TypedDict - ], -) - - -CreateInputInputSyslogUnion = TypeAliasType( - "CreateInputInputSyslogUnion", - Union[CreateInputInputSyslogSyslog1, CreateInputInputSyslogSyslog2], -) - - -class CreateInputQueueType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The queue type used (or created)""" - - # Standard - STANDARD = "standard" - # FIFO - FIFO = "fifo" - - -class CreateInputInputSqsTypedDict(TypedDict): +class CreateInputInputNetflowTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSqs + type: TypeOptionsNetflow r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - queue_type: CreateInputQueueType - r"""The queue type used (or created)""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""Port to listen on""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8760,82 +9416,48 @@ class CreateInputInputSqsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - create_queue: NotRequired[bool] - r"""Create queue if it does not exist""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SQS""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + enable_pass_through: NotRequired[bool] + r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + template_cache_minutes: NotRequired[float] + r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" + v5_enabled: NotRequired[bool] + r"""Accept messages in Netflow V5 format.""" + v9_enabled: NotRequired[bool] + r"""Accept messages in Netflow V9 format.""" + ipfix_enabled: NotRequired[bool] + r"""Accept messages in IPFIX format.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: NotRequired[str] - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateInputInputSqs(BaseModel): +class CreateInputInputNetflow(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSqs + type: TypeOptionsNetflow r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - queue_type: Annotated[CreateInputQueueType, pydantic.Field(alias="queueType")] - r"""The queue type used (or created)""" + port: float + r"""Port to listen on""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -8862,89 +9484,48 @@ class CreateInputInputSqs(BaseModel): pq: Optional[PqType] = None - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None - r"""Create queue if it does not exist""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + enable_pass_through: Annotated[ + Optional[bool], pydantic.Field(alias="enablePassThrough") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") ] = None - r"""Use Assume Role credentials to access SQS""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + template_cache_minutes: Annotated[ + Optional[float], pydantic.Field(alias="templateCacheMinutes") ] = None - r"""External ID to use when assuming role""" + r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + v5_enabled: Annotated[Optional[bool], pydantic.Field(alias="v5Enabled")] = None + r"""Accept messages in Netflow V5 format.""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + v9_enabled: Annotated[Optional[bool], pydantic.Field(alias="v9Enabled")] = None + r"""Accept messages in Netflow V9 format.""" - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + ipfix_enabled: Annotated[Optional[bool], pydantic.Field(alias="ipfixEnabled")] = ( + None + ) + r"""Accept messages in IPFIX format.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -8955,114 +9536,165 @@ class CreateInputInputSqs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_queue_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueType") - ] = None - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "enablePassThrough", + "ipAllowlistRegex", + "ipDenylistRegex", + "udpSocketRxBufSize", + "templateCacheMinutes", + "v5Enabled", + "v9Enabled", + "ipfixEnabled", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + return m - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" +class CreateInputInputWizWebhookType(str, Enum): + r"""Source type identifier.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + WIZ_WEBHOOK = "wiz_webhook" - @field_serializer("queue_type") - def serialize_queue_type(self, value): + +class CreateInputInputWizWebhookAuthTokensExt2TypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: str + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputInputWizWebhookAuthTokensExt2(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputQueueType(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputWizWebhookAuthTokensExt1TypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputInputWizWebhookAuthTokensExt1(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "awsAccountId", - "createQueue", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "maxMessages", - "visibilityTimeout", - "metadata", - "pollTimeout", - "description", - "awsApiKey", - "awsSecret", - "numReceivers", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_queueType", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - ] - ) + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) serialized = handler(self) m = {} @@ -9077,17 +9709,29 @@ def serialize_model(self, handler): return m -class CreateInputInputModelDrivenTelemetryType(str, Enum): - r"""Connector type identifier.""" +CreateInputInputWizWebhookAuthTokensExtUnionTypedDict = TypeAliasType( + "CreateInputInputWizWebhookAuthTokensExtUnionTypedDict", + Union[ + CreateInputInputWizWebhookAuthTokensExt1TypedDict, + CreateInputInputWizWebhookAuthTokensExt2TypedDict, + ], +) - MODEL_DRIVEN_TELEMETRY = "model_driven_telemetry" + +CreateInputInputWizWebhookAuthTokensExtUnion = TypeAliasType( + "CreateInputInputWizWebhookAuthTokensExtUnion", + Union[ + CreateInputInputWizWebhookAuthTokensExt1, + CreateInputInputWizWebhookAuthTokensExt2, + ], +) -class CreateInputInputModelDrivenTelemetryTypedDict(TypedDict): +class CreateInputInputWizWebhookTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputModelDrivenTelemetryType - r"""Connector type identifier.""" + type: CreateInputInputWizWebhookType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float @@ -9107,14 +9751,46 @@ class CreateInputInputModelDrivenTelemetryTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - shutdown_timeout_ms: NotRequired[float] - r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" + allowed_paths: NotRequired[List[str]] + r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" + allowed_methods: NotRequired[List[str]] + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + auth_tokens_ext: NotRequired[ + List[CreateInputInputWizWebhookAuthTokensExtUnionTypedDict] + ] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -9125,14 +9801,18 @@ class CreateInputInputModelDrivenTelemetryTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_allowed_paths: NotRequired[str] + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" -class CreateInputInputModelDrivenTelemetry(BaseModel): +class CreateInputInputWizWebhook(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputModelDrivenTelemetryType - r"""Connector type identifier.""" + type: CreateInputInputWizWebhookType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -9165,45 +9845,131 @@ class CreateInputInputModelDrivenTelemetry(BaseModel): pq: Optional[PqType] = None + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - shutdown_timeout_ms: Annotated[ - Optional[float], pydantic.Field(alias="shutdownTimeoutMs") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Add request headers to events, in the __headers field""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + allowed_paths: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedPaths") + ] = None + r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" + + allowed_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedMethods") + ] = None + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + + auth_tokens_ext: Annotated[ + Optional[List[CreateInputInputWizWebhookAuthTokensExtUnion]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + template_allowed_paths: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedPaths") + ] = None + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -9216,15 +9982,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", + "authTokens", "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "breakerRulesets", + "staleChannelFlushMs", "metadata", - "maxActiveCxn", - "shutdownTimeoutMs", + "allowedPaths", + "allowedMethods", + "authTokensExt", "description", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_authTokens", + "__template_allowedPaths", ] ) serialized = handler(self) @@ -9241,120 +10024,177 @@ def serialize_model(self, handler): return m -class CreateInputInputOpenTelemetryType(str, Enum): - r"""Source type identifier.""" - - OPEN_TELEMETRY = "open_telemetry" - +class CreateInputInputOpenaiType(str, Enum): + r"""Connector type identifier.""" -class CreateInputProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" + OPENAI = "openai" - # gRPC - GRPC = "grpc" - # HTTP - HTTP = "http" +class CreateInputInputOpenaiManageStateTypedDict(TypedDict): + pass -class CreateInputOTLPVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - # 0.10.0 - ZERO_DOT_10_DOT_0 = "0.10.0" - # 1.3.1 - ONE_DOT_3_DOT_1 = "1.3.1" +class CreateInputInputOpenaiManageState(BaseModel): + pass -class CreateInputInputOpenTelemetryAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""OpenTelemetry authentication type""" +class CreateInputPaginationType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Pagination type""" # None NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" + # Response Body Attribute + RESPONSE_BODY = "response_body" + # Response Header Attribute + RESPONSE_HEADER = "response_header" + # RFC 5988 Link Header + RESPONSE_HEADER_LINK = "response_header_link" -class CreateInputAuthMethodsExtAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" +class CreateInputInputOpenaiLogLevel(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Collector runtime log level.""" - # Token - TOKEN = "token" - # Token (secret) - TOKEN_SECRET = "tokenSecret" - # Basic - BASIC = "basic" - # Basic (credentials secret) - BASIC_SECRET = "basicSecret" + ERROR = "error" + WARN = "warn" + INFO = "info" + DEBUG = "debug" + SILLY = "silly" -class CreateInputAuthMethodsExtTypedDict(TypedDict): - auth_type: CreateInputAuthMethodsExtAuthenticationType - r"""Authentication type""" - token: NotRequired[str] - r"""Bearer token for Authorization header""" - description: NotRequired[str] - r"""Description""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this auth method""" - enabled: NotRequired[bool] - r"""Enable""" - token_secret: NotRequired[str] - r"""Select or create a stored text secret""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" +class CreateInputInputOpenaiContentConfigTypedDict(TypedDict): + request_params: List[ + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict + ] + r"""Query-string parameters to send with this endpoint""" + pagination_type: CreateInputPaginationType + r"""Pagination type""" + cron_schedule: str + r"""A cron schedule on which to run this job""" + earliest: str + r"""Relative to the current time""" + latest: str + r"""Relative to the current time""" + disabled: NotRequired[bool] + r"""Enabled""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions.""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputInputOpenaiManageStateTypedDict] + pagination_attribute: NotRequired[List[str]] + r"""Pagination attributes""" + pagination_last_page_expr: NotRequired[str] + r"""Last page expression""" + max_pages: NotRequired[float] + r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" + pagination_next_relation_attribute: NotRequired[str] + r"""Used only for RFC 5988 link-header pagination""" + pagination_cur_relation_attribute: NotRequired[str] + r"""Optional relation that represents the current page""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + log_level: NotRequired[CreateInputInputOpenaiLogLevel] + r"""Collector runtime log level.""" + endpoint_metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields automatically added to events from this Content Type""" -class CreateInputAuthMethodsExt(BaseModel): - auth_type: Annotated[ - CreateInputAuthMethodsExtAuthenticationType, pydantic.Field(alias="authType") +class CreateInputInputOpenaiContentConfig(BaseModel): + request_params: Annotated[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret], + pydantic.Field(alias="requestParams"), ] - r"""Authentication type""" - - token: Optional[str] = None - r"""Bearer token for Authorization header""" + r"""Query-string parameters to send with this endpoint""" - description: Optional[str] = None - r"""Description""" + pagination_type: Annotated[ + CreateInputPaginationType, pydantic.Field(alias="paginationType") + ] + r"""Pagination type""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this auth method""" + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""A cron schedule on which to run this job""" - enabled: Optional[bool] = None - r"""Enable""" + earliest: str + r"""Relative to the current time""" - token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None - r"""Select or create a stored text secret""" + latest: str + r"""Relative to the current time""" - username: Optional[str] = None - r"""Username""" + disabled: Optional[bool] = None + r"""Enabled""" - password: Optional[str] = None - r"""Password""" + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Select or create a secret that references your credentials""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputInputOpenaiManageState], pydantic.Field(alias="manageState") + ] = None + + pagination_attribute: Annotated[ + Optional[List[str]], pydantic.Field(alias="paginationAttribute") + ] = None + r"""Pagination attributes""" + + pagination_last_page_expr: Annotated[ + Optional[str], pydantic.Field(alias="paginationLastPageExpr") + ] = None + r"""Last page expression""" + + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" + + pagination_next_relation_attribute: Annotated[ + Optional[str], pydantic.Field(alias="paginationNextRelationAttribute") + ] = None + r"""Used only for RFC 5988 link-header pagination""" + + pagination_cur_relation_attribute: Annotated[ + Optional[str], pydantic.Field(alias="paginationCurRelationAttribute") + ] = None + r"""Optional relation that represents the current page""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + log_level: Annotated[ + Optional[CreateInputInputOpenaiLogLevel], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime log level.""" + + endpoint_metadata: Annotated[ + Optional[List[MetadataConfInputCollection]], + pydantic.Field(alias="endpointMetadata"), + ] = None + r"""Fields automatically added to events from this Content Type""" + + @field_serializer("pagination_type") + def serialize_pagination_type(self, value): if isinstance(value, str): try: - return models.CreateInputAuthMethodsExtAuthenticationType(value) + return models.CreateInputPaginationType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputOpenaiLogLevel(value) except ValueError: return value return value @@ -9363,14 +10203,19 @@ def serialize_auth_type(self, value): def serialize_model(self, handler): optional_fields = set( [ - "token", - "description", - "metadata", - "enabled", - "tokenSecret", - "username", - "password", - "credentialsSecret", + "disabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "paginationAttribute", + "paginationLastPageExpr", + "maxPages", + "paginationNextRelationAttribute", + "paginationCurRelationAttribute", + "jobTimeout", + "logLevel", + "endpointMetadata", ] ) serialized = handler(self) @@ -9387,15 +10232,15 @@ def serialize_model(self, handler): return m -class CreateInputInputOpenTelemetryTypedDict(TypedDict): +class CreateInputInputOpenaiTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputOpenTelemetryType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" + type: CreateInputInputOpenaiType + r"""Connector type identifier.""" + content_config: List[CreateInputInputOpenaiContentConfigTypedDict] + r"""Content Types""" + text_secret: str + r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -9411,80 +10256,51 @@ class CreateInputInputOpenTelemetryTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + openai_organization: NotRequired[str] + r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" + openai_project: NotRequired[str] + r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" - enable_health_check: NotRequired[bool] - r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - protocol: NotRequired[CreateInputProtocol] - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - extract_spans: NotRequired[bool] - r"""Enable to extract each incoming span to a separate event""" - extract_metrics: NotRequired[bool] - r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - otlp_version: NotRequired[CreateInputOTLPVersion] - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - auth_type: NotRequired[CreateInputInputOpenTelemetryAuthenticationType] - r"""OpenTelemetry authentication type""" - auth_methods_ext: NotRequired[List[CreateInputAuthMethodsExtTypedDict]] - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" + api_key: NotRequired[str] + r"""API key""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - extract_logs: NotRequired[bool] - r"""Enable to extract each incoming log record to a separate event""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_protocol: NotRequired[str] - r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" - template_otlp_version: NotRequired[str] - r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" + template_openai_organization: NotRequired[str] + r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" + template_openai_project: NotRequired[str] + r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" -class CreateInputInputOpenTelemetry(BaseModel): +class CreateInputInputOpenai(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputOpenTelemetryType - r"""Source type identifier.""" + type: CreateInputInputOpenaiType + r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + content_config: Annotated[ + List[CreateInputInputOpenaiContentConfig], pydantic.Field(alias="contentConfig") + ] + r"""Content Types""" - port: float - r"""Port to listen on""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -9511,110 +10327,52 @@ class CreateInputInputOpenTelemetry(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + openai_organization: Annotated[ + Optional[str], pydantic.Field(alias="openaiOrganization") + ] = None + r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + openai_project: Annotated[Optional[str], pydantic.Field(alias="openaiProject")] = ( None ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - protocol: Optional[CreateInputProtocol] = None - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - extract_spans: Annotated[Optional[bool], pydantic.Field(alias="extractSpans")] = ( - None - ) - r"""Enable to extract each incoming span to a separate event""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - extract_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="extractMetrics") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - - otlp_version: Annotated[ - Optional[CreateInputOTLPVersion], pydantic.Field(alias="otlpVersion") - ] = None - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - - auth_type: Annotated[ - Optional[CreateInputInputOpenTelemetryAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""OpenTelemetry authentication type""" - - auth_methods_ext: Annotated[ - Optional[List[CreateInputAuthMethodsExt]], - pydantic.Field(alias="authMethodsExt"), - ] = None - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" description: Optional[str] = None r"""Optional description for this configuration.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - extract_logs: Annotated[Optional[bool], pydantic.Field(alias="extractLogs")] = None - r"""Enable to extract each incoming log record to a separate event""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -9625,52 +10383,15 @@ class CreateInputInputOpenTelemetry(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_protocol: Annotated[ - Optional[str], pydantic.Field(alias="__template_protocol") + template_openai_organization: Annotated[ + Optional[str], pydantic.Field(alias="__template_openaiOrganization") ] = None - r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - template_otlp_version: Annotated[ - Optional[str], pydantic.Field(alias="__template_otlpVersion") + template_openai_project: Annotated[ + Optional[str], pydantic.Field(alias="__template_openaiProject") ] = None - r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateInputProtocol(value) - except ValueError: - return value - return value - - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.CreateInputOTLPVersion(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputOpenTelemetryAuthenticationType(value) - except ValueError: - return value - return value + r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -9684,36 +10405,21 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", + "openaiOrganization", + "openaiProject", "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "protocol", - "extractSpans", - "extractMetrics", - "otlpVersion", - "authType", - "authMethodsExt", + "apiKey", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "maxActiveCxn", + "retryRules", "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "extractLogs", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", - "__template_protocol", - "__template_otlpVersion", + "__template_openaiOrganization", + "__template_openaiProject", ] ) serialized = handler(self) @@ -9730,139 +10436,129 @@ def serialize_model(self, handler): return m -class CreateInputAuthenticationProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Authentication protocol""" +class CreateInputInputWizType(str, Enum): + r"""Connector type identifier.""" - # None - NONE = "none" - # MD5 - MD5 = "md5" - # SHA1 - SHA = "sha" - # SHA224 - SHA224 = "sha224" - # SHA256 - SHA256 = "sha256" - # SHA384 - SHA384 = "sha384" - # SHA512 - SHA512 = "sha512" + WIZ = "wiz" -class CreateInputPrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Privacy protocol""" +class CreateInputInputWizManageStateTypedDict(TypedDict): + pass - # None - NONE = "none" - # DES - DES = "des" - # AES128 - AES = "aes" - # AES256b (Blumenthal) - AES256B = "aes256b" - # AES256r (Reeder) - AES256R = "aes256r" +class CreateInputInputWizManageState(BaseModel): + pass -class CreateInputV3UserTypedDict(TypedDict): - name: str - r"""V3 name""" - auth_protocol: NotRequired[CreateInputAuthenticationProtocol] - r"""Authentication protocol""" - auth_key: NotRequired[str] - r"""V3 authentication key""" - priv_protocol: NotRequired[CreateInputPrivacyProtocol] - r"""Privacy protocol""" - priv_key: NotRequired[str] - r"""V3 privacy key""" +class CreateInputInputWizContentConfigTypedDict(TypedDict): + content_type: str + r"""The name of the Wiz query""" + content_query: str + r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" + cron_schedule: str + r"""A cron schedule on which to run this job""" + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + content_description: NotRequired[str] + r"""Description""" + enabled: NotRequired[bool] + r"""Enable content""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputInputWizManageStateTypedDict] + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" + log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] + r"""Collector runtime log level""" + max_pages: NotRequired[float] + r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" -class CreateInputV3User(BaseModel): - name: str - r"""V3 name""" - auth_protocol: Annotated[ - Optional[CreateInputAuthenticationProtocol], - pydantic.Field(alias="authProtocol"), - ] = None - r"""Authentication protocol""" +class CreateInputInputWizContentConfig(BaseModel): + content_type: Annotated[str, pydantic.Field(alias="contentType")] + r"""The name of the Wiz query""" - auth_key: Annotated[Optional[str], pydantic.Field(alias="authKey")] = None - r"""V3 authentication key""" + content_query: Annotated[str, pydantic.Field(alias="contentQuery")] + r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" - priv_protocol: Annotated[ - Optional[CreateInputPrivacyProtocol], pydantic.Field(alias="privProtocol") - ] = None - r"""Privacy protocol""" + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""A cron schedule on which to run this job""" - priv_key: Annotated[Optional[str], pydantic.Field(alias="privKey")] = None - r"""V3 privacy key""" + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - @field_serializer("auth_protocol") - def serialize_auth_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateInputAuthenticationProtocol(value) - except ValueError: - return value - return value + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - @field_serializer("priv_protocol") - def serialize_priv_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateInputPrivacyProtocol(value) - except ValueError: - return value - return value + content_description: Annotated[ + Optional[str], pydantic.Field(alias="contentDescription") + ] = None + r"""Description""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["authProtocol", "authKey", "privProtocol", "privKey"]) - serialized = handler(self) - m = {} + enabled: Optional[bool] = None + r"""Enable content""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSNMPv3AuthenticationTypedDict(TypedDict): - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" - v3_auth_enabled: bool - r"""Enabled""" - allow_unmatched_trap: NotRequired[bool] - r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" - v3_users: NotRequired[List[CreateInputV3UserTypedDict]] - r"""User credentials for receiving v3 traps""" + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" -class CreateInputSNMPv3Authentication(BaseModel): - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + manage_state: Annotated[ + Optional[CreateInputInputWizManageState], pydantic.Field(alias="manageState") + ] = None - v3_auth_enabled: Annotated[bool, pydantic.Field(alias="v3AuthEnabled")] - r"""Enabled""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" - allow_unmatched_trap: Annotated[ - Optional[bool], pydantic.Field(alias="allowUnmatchedTrap") + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItemsDebugError], + pydantic.Field(alias="logLevel"), ] = None - r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" + r"""Collector runtime log level""" - v3_users: Annotated[ - Optional[List[CreateInputV3User]], pydantic.Field(alias="v3Users") - ] = None - r"""User credentials for receiving v3 traps""" + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItemsDebugError(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["allowUnmatchedTrap", "v3Users"]) + optional_fields = set( + [ + "contentDescription", + "enabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "jobTimeout", + "logLevel", + "maxPages", + ] + ) serialized = handler(self) m = {} @@ -9877,15 +10573,19 @@ def serialize_model(self, handler): return m -class CreateInputInputSnmpTypedDict(TypedDict): +class CreateInputInputWizTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSnmp + type: CreateInputInputWizType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - port: float - r"""UDP port to receive SNMP traps on. Defaults to 162.""" + endpoint: str + r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" + auth_url: str + r"""The authentication URL to generate an OAuth token""" + client_id: str + r"""The client ID of the Wiz application""" + content_config: List[CreateInputInputWizContentConfigTypedDict] + r"""Content types""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -9901,44 +10601,65 @@ class CreateInputInputSnmpTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - snmp_v3_auth: NotRequired[CreateInputSNMPv3AuthenticationTypedDict] - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" + auth_audience_override: NotRequired[str] + r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - varbinds_with_types: NotRequired[bool] - r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" - best_effort_parsing: NotRequired[bool] - r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""The client secret of the Wiz application""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_auth_url: NotRequired[str] + r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" -class CreateInputInputSnmp(BaseModel): +class CreateInputInputWiz(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSnmp + type: CreateInputInputWizType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + endpoint: str + r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" - port: float - r"""UDP port to receive SNMP traps on. Defaults to 162.""" + auth_url: Annotated[str, pydantic.Field(alias="authUrl")] + r"""The authentication URL to generate an OAuth token""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""The client ID of the Wiz application""" + + content_config: Annotated[ + List[CreateInputInputWizContentConfig], pydantic.Field(alias="contentConfig") + ] + r"""Content types""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -9965,42 +10686,66 @@ class CreateInputInputSnmp(BaseModel): pq: Optional[PqType] = None - snmp_v3_auth: Annotated[ - Optional[CreateInputSNMPv3Authentication], pydantic.Field(alias="snmpV3Auth") + auth_audience_override: Annotated[ + Optional[str], pydantic.Field(alias="authAudienceOverride") + ] = None + r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""Maximum number of events to buffer when downstream is blocking.""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - varbinds_with_types: Annotated[ - Optional[bool], pydantic.Field(alias="varbindsWithTypes") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" - best_effort_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="bestEffortParsing") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), ] = None - r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + r"""Enter client secret directly, or select a stored secret""" description: Optional[str] = None r"""Optional description for this configuration.""" + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""The client secret of the Wiz application""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -10011,15 +10756,29 @@ class CreateInputInputSnmp(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_authUrl") + ] = None + r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -10033,18 +10792,25 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "snmpV3Auth", - "maxBufferSize", - "ipWhitelistRegex", + "authAudienceOverride", + "requestTimeout", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "udpSocketRxBufSize", - "varbindsWithTypes", - "bestEffortParsing", + "breakerRulesets", + "staleChannelFlushMs", + "retryRules", + "authType", "description", + "clientSecret", + "textSecret", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", + "__template_endpoint", + "__template_authUrl", + "__template_clientId", ] ) serialized = handler(self) @@ -10061,157 +10827,101 @@ def serialize_model(self, handler): return m -class CreateInputInputS3InventoryType(str, Enum): +class CreateInputInputJournalFilesType(str, Enum): r"""Connector type identifier.""" - S3_INVENTORY = "s3_inventory" + JOURNAL_FILES = "journal_files" -class CreateInputInputS3InventoryTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputS3InventoryType - r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" +class CreateInputInputJournalFilesRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class CreateInputInputJournalFilesRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputInputJournalFilesTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputJournalFilesType + r"""Connector type identifier.""" + path: str + r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + journals: List[str] + r"""The full path of discovered journals are matched against this wildcard list.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between scanning for journals.""" + rules: NotRequired[List[CreateInputInputJournalFilesRuleTypedDict]] + r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" + current_boot: NotRequired[bool] + r"""Skip log messages that are not part of the current boot session""" + max_age_dur: NotRequired[str] + r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" + suppress_missing_path_errors: NotRequired[bool] + r"""Suppress errors when search path does not exist""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - checksum_suffix: NotRequired[str] - r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ - max_manifest_size_kb: NotRequired[int] - r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" - validate_inventory_files: NotRequired[bool] - r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputInputS3Inventory(BaseModel): +class CreateInputInputJournalFiles(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputS3InventoryType + type: CreateInputInputJournalFilesType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + path: str + r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + + journals: List[str] + r"""The full path of discovered journals are matched against this wildcard list.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -10238,201 +10948,207 @@ class CreateInputInputS3Inventory(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" + interval: Optional[float] = None + r"""Time, in seconds, between scanning for journals.""" - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + rules: Optional[List[CreateInputInputJournalFilesRule]] = None + r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + current_boot: Annotated[Optional[bool], pydantic.Field(alias="currentBoot")] = None + r"""Skip log messages that are not part of the current boot session""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None + r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + suppress_missing_path_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + ] = None + r"""Suppress errors when search path does not exist""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "rules", + "currentBoot", + "maxAgeDur", + "suppressMissingPathErrors", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" + return m - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" +class CreateInputInputRawUDPType(str, Enum): + r"""Connector type identifier.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + RAW_UDP = "raw_udp" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" +class CreateInputInputRawUDPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputRawUDPType + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + single_msg_udp_packets: NotRequired[bool] + r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" + ingest_raw_bytes: NotRequired[bool] + r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" +class CreateInputInputRawUDP(BaseModel): + id: str + r"""Unique ID for this input""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + type: CreateInputInputRawUDPType + r"""Connector type identifier.""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + port: float + r"""Port to listen on""" - checkpointing: Optional[CheckpointingType] = None + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - checksum_suffix: Annotated[ - Optional[str], pydantic.Field(alias="checksumSuffix") - ] = None - r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - max_manifest_size_kb: Annotated[ - Optional[int], pydantic.Field(alias="maxManifestSizeKB") - ] = None - r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - validate_inventory_files: Annotated[ - Optional[bool], pydantic.Field(alias="validateInventoryFiles") - ] = None - r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + pq: Optional[PqType] = None - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""Maximum number of events to buffer when downstream is blocking.""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") ] = None - r"""External ID to use when assuming role""" + r"""Regex matching IP addresses that are allowed to send data""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ingest_raw_bytes: Annotated[ + Optional[bool], pydantic.Field(alias="ingestRawBytes") ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" + r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") ] = None - r"""SQS secret key""" + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -10444,180 +11160,78 @@ class CreateInputInputS3Inventory(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "maxBufferSize", + "ipWhitelistRegex", + "singleMsgUdpPackets", + "ingestRawBytes", + "udpSocketRxBufSize", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") - ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") - ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + return m - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value +class CreateInputInputAppleUnifiedLogsType(str, Enum): + r"""Connector type identifier.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "checksumSuffix", - "maxManifestSizeKB", - "validateInventoryFiles", - "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", - ] - ) - serialized = handler(self) - m = {} + APPLE_UNIFIED_LOGS = "apple_unified_logs" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateInputInputAppleUnifiedLogsReadMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" - return m + # Entire log + OLDEST = "oldest" + # From last entry + NEWEST = "newest" -class CreateInputInputS3TypedDict(TypedDict): +class CreateInputInputAppleUnifiedLogsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsS3 + type: CreateInputInputAppleUnifiedLogsType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + predicate: str + r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -10633,126 +11247,27 @@ class CreateInputInputS3TypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + read_mode: NotRequired[CreateInputInputAppleUnifiedLogsReadMode] + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - tag_after_processing: NotRequired[bool] - r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputInputS3(BaseModel): +class CreateInputInputAppleUnifiedLogs(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsS3 + type: CreateInputInputAppleUnifiedLogsType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + predicate: str + r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -10779,270 +11294,257 @@ class CreateInputInputS3(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + read_mode: Annotated[ + Optional[CreateInputInputAppleUnifiedLogsReadMode], + pydantic.Field(alias="readMode"), ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + @field_serializer("read_mode") + def serialize_read_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputAppleUnifiedLogsReadMode(value) + except ValueError: + return value + return value - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "readMode", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + return m - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" +class CreateInputInputWinEventLogsType(str, Enum): + r"""Connector type identifier.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" + WIN_EVENT_LOGS = "win_event_logs" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" +class CreateInputInputWinEventLogsReadMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Read all stored and future event logs, or only future events""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + # Entire log + OLDEST = "oldest" + # From last entry + NEWEST = "newest" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" +class CreateInputEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of individual events""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" + # JSON + JSON = "json" + # XML + XML = "xml" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: Optional[List[MetadataConfInputCollection]] = None +class CreateInputInputWinEventLogsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputInputWinEventLogsType + r"""Connector type identifier.""" + log_names: List[str] + r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + suppress_missing_log_errors: NotRequired[bool] + r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" + read_mode: NotRequired[CreateInputInputWinEventLogsReadMode] + r"""Read all stored and future event logs, or only future events""" + event_format: NotRequired[CreateInputEventFormat] + r"""Format of individual events""" + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" + interval: NotRequired[float] + r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + batch_size: NotRequired[float] + r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + max_event_bytes: NotRequired[int] + r"""The maximum number of bytes in an event before it is flushed to the pipelines""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + disable_json_rendering: NotRequired[bool] + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + include_empty_json_fields: NotRequired[bool] + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" + disable_xml_rendering: NotRequired[bool] + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" +class CreateInputInputWinEventLogs(BaseModel): + id: str + r"""Unique ID for this input""" - checkpointing: Optional[CheckpointingType] = None + type: CreateInputInputWinEventLogsType + r"""Connector type identifier.""" - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + log_names: Annotated[List[str], pydantic.Field(alias="logNames")] + r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - tag_after_processing: Annotated[ - Optional[bool], pydantic.Field(alias="tagAfterProcessing") - ] = None - r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + pq: Optional[PqType] = None - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" - - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") + suppress_missing_log_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingLogErrors") ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + read_mode: Annotated[ + Optional[CreateInputInputWinEventLogsReadMode], pydantic.Field(alias="readMode") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Read all stored and future event logs, or only future events""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + event_format: Annotated[ + Optional[CreateInputEventFormat], pydantic.Field(alias="eventFormat") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Format of individual events""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + interval: Optional[float] = None + r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None + r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + max_event_bytes: Annotated[Optional[int], pydantic.Field(alias="maxEventBytes")] = ( + None + ) + r"""The maximum number of bytes in an event before it is flushed to the pipelines""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + disable_json_rendering: Annotated[ + Optional[bool], pydantic.Field(alias="disableJsonRendering") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + include_empty_json_fields: Annotated[ + Optional[bool], pydantic.Field(alias="includeEmptyJsonFields") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + disable_xml_rendering: Annotated[ + Optional[bool], pydantic.Field(alias="disableXmlRendering") ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("read_mode") + def serialize_read_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.CreateInputInputWinEventLogsReadMode(value) except ValueError: return value return value - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): + @field_serializer("event_format") + def serialize_event_format(self, value): if isinstance(value, str): try: - return models.SqsAuthenticationMethodOptions(value) + return models.CreateInputEventFormat(value) except ValueError: return value return value @@ -11059,61 +11561,20 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", + "suppressMissingLogErrors", + "readMode", + "eventFormat", + "disableNativeModule", + "interval", + "batchSize", "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", - "tagAfterProcessing", + "maxEventBytes", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "processedTagKey", - "processedTagValue", + "disableJsonRendering", + "includeEmptyJsonFields", + "disableXmlRendering", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", ] ) serialized = handler(self) @@ -11130,185 +11591,140 @@ def serialize_model(self, handler): return m -class CreateInputInputMetricsType(str, Enum): - r"""Connector type identifier.""" - - METRICS = "metrics" - - -class CreateInputInputMetricsTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputMetricsType +class CreateInputInputWefType(str, Enum): r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - udp_port: NotRequired[float] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - tcp_port: NotRequired[float] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - - -class CreateInputInputMetrics(BaseModel): - id: str - r"""Unique ID for this input""" - type: CreateInputInputMetricsType - r"""Connector type identifier.""" + WEF = "wef" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" +class CreateInputInputWefAuthenticationMethod(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How to authenticate incoming client connections""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" + # Client certificate + CLIENT_CERT = "clientCert" + # Kerberos + KERBEROS = "kerberos" + # Negotiate (SPNEGO) + NEGOTIATE = "negotiate" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" +class CreateInputMTLSSettingsTypedDict(TypedDict): + r"""mTLS settings""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + priv_key_path: str + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + cert_path: str + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + ca_path: str + r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" + disabled: NotRequired[bool] + r"""Enable TLS""" + reject_unauthorized: NotRequired[bool] + r"""Required for WEF certificate authentication""" + request_cert: NotRequired[bool] + r"""Required for WEF certificate authentication""" + certificate_name: NotRequired[str] + r"""Name of the predefined certificate""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + common_name_regex: NotRequired[str] + r"""Regex matching allowable common names in peer certificates' subject attribute""" + min_version: NotRequired[MinimumTLSVersionOptionsTLS] + r"""Minimum TLS version""" + max_version: NotRequired[MaximumTLSVersionOptionsTLS] + r"""Maximum TLS version""" + ocsp_check: NotRequired[bool] + r"""Enable OCSP check of certificate""" + ocsp_check_fail_close: NotRequired[bool] + r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" +class CreateInputMTLSSettings(BaseModel): + r"""mTLS settings""" - pq: Optional[PqType] = None + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + ca_path: Annotated[str, pydantic.Field(alias="caPath")] + r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") - ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + disabled: Optional[bool] = None + r"""Enable TLS""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Required for WEF certificate authentication""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None + r"""Required for WEF certificate authentication""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""Name of the predefined certificate""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + common_name_regex: Annotated[ + Optional[str], pydantic.Field(alias="commonNameRegex") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""Regex matching allowable common names in peer certificates' subject attribute""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + min_version: Annotated[ + Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Minimum TLS version""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + max_version: Annotated[ + Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Maximum TLS version""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + ocsp_check: Annotated[Optional[bool], pydantic.Field(alias="ocspCheck")] = None + r"""Enable OCSP check of certificate""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") + ocsp_check_fail_close: Annotated[ + Optional[bool], pydantic.Field(alias="ocspCheckFailClose") ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") - ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + @field_serializer("min_version") + def serialize_min_version(self, value): + if isinstance(value, str): + try: + return models.MinimumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value + + @field_serializer("max_version") + def serialize_max_version(self, value): + if isinstance(value, str): + try: + return models.MaximumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "udpPort", - "tcpPort", - "maxBufferSize", - "ipWhitelistRegex", - "enableProxyHeader", - "tls", - "metadata", - "udpSocketRxBufSize", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", + "rejectUnauthorized", + "requestCert", + "certificateName", + "passphrase", + "commonNameRegex", + "minVersion", + "maxVersion", + "ocspCheck", + "ocspCheckFailClose", ] ) serialized = handler(self) @@ -11325,120 +11741,146 @@ def serialize_model(self, handler): return m -class CreateInputInputCriblmetricsType(str, Enum): - r"""Connector type identifier.""" +class CreateInputFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Content format in which the endpoint should deliver events""" - CRIBLMETRICS = "criblmetrics" + RAW = "Raw" + RENDERED_TEXT = "RenderedText" -class CreateInputInputCriblmetricsTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputCriblmetricsType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - prefix: NotRequired[str] - r"""A prefix that is applied to the metrics provided by Cribl Stream""" - full_fidelity: NotRequired[bool] - r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" +class CreateInputQueryBuilderMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Query builder mode""" + SIMPLE = "simple" + XML = "xml" -class CreateInputInputCriblmetrics(BaseModel): - id: str - r"""Unique ID for this input""" - type: CreateInputInputCriblmetricsType - r"""Connector type identifier.""" +class CreateInputQueryTypedDict(TypedDict): + path: str + r"""The Path attribute from the relevant XML Select element""" + query_expression: str + r"""The XPath query inside the relevant XML Select element""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" +class CreateInputQuery(BaseModel): + path: str + r"""The Path attribute from the relevant XML Select element""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" + query_expression: Annotated[str, pydantic.Field(alias="queryExpression")] + r"""The XPath query inside the relevant XML Select element""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" +class CreateInputSubscriptionTypedDict(TypedDict): + subscription_name: str + r"""Subscription name""" + content_format: CreateInputFormat + r"""Content format in which the endpoint should deliver events""" + heartbeat_interval: float + r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" + batch_timeout: float + r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" + targets: List[str] + r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" + version: NotRequired[str] + r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" + read_existing_events: NotRequired[bool] + r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" + send_bookmarks: NotRequired[bool] + r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" + compress: NotRequired[bool] + r"""Receive compressed events from the source""" + locale: NotRequired[str] + r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" + query_selector: NotRequired[CreateInputQueryBuilderMode] + r"""Query builder mode""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events ingested under this subscription""" + queries: NotRequired[List[CreateInputQueryTypedDict]] + r"""Queries""" + xml_query: NotRequired[str] + r"""The XPath query to use for selecting events""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" +class CreateInputSubscription(BaseModel): + subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] + r"""Subscription name""" - pq: Optional[PqType] = None + content_format: Annotated[CreateInputFormat, pydantic.Field(alias="contentFormat")] + r"""Content format in which the endpoint should deliver events""" - prefix: Optional[str] = None - r"""A prefix that is applied to the metrics provided by Cribl Stream""" + heartbeat_interval: Annotated[float, pydantic.Field(alias="heartbeatInterval")] + r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" - full_fidelity: Annotated[Optional[bool], pydantic.Field(alias="fullFidelity")] = ( + batch_timeout: Annotated[float, pydantic.Field(alias="batchTimeout")] + r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" + + targets: List[str] + r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" + + version: Optional[str] = None + r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" + + read_existing_events: Annotated[ + Optional[bool], pydantic.Field(alias="readExistingEvents") + ] = None + r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" + + send_bookmarks: Annotated[Optional[bool], pydantic.Field(alias="sendBookmarks")] = ( None ) - r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + compress: Optional[bool] = None + r"""Receive compressed events from the source""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + locale: Optional[str] = None + r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + query_selector: Annotated[ + Optional[CreateInputQueryBuilderMode], pydantic.Field(alias="querySelector") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Query builder mode""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events ingested under this subscription""" + + queries: Optional[List[CreateInputQuery]] = None + r"""Queries""" + + xml_query: Annotated[Optional[str], pydantic.Field(alias="xmlQuery")] = None + r"""The XPath query to use for selecting events""" + + @field_serializer("content_format") + def serialize_content_format(self, value): + if isinstance(value, str): + try: + return models.CreateInputFormat(value) + except ValueError: + return value + return value + + @field_serializer("query_selector") + def serialize_query_selector(self, value): + if isinstance(value, str): + try: + return models.CreateInputQueryBuilderMode(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "prefix", - "fullFidelity", + "version", + "readExistingEvents", + "sendBookmarks", + "compress", + "locale", + "querySelector", "metadata", - "description", - "__template_environment", - "__template_streamtags", + "queries", + "xmlQuery", ] ) serialized = handler(self) @@ -11455,46 +11897,17 @@ def serialize_model(self, handler): return m -class CreateInputShardIteratorStart(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Location at which to start reading a shard for the first time""" - - # Earliest record - TRIM_HORIZON = "TRIM_HORIZON" - # Latest record - LATEST = "LATEST" - - -class CreateInputRecordDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" - - # Cribl - CRIBL = "cribl" - # Newline JSON - NDJSON = "ndjson" - # Cloudwatch Logs - CLOUDWATCH = "cloudwatch" - # Event per line - LINE = "line" - - -class CreateInputShardLoadBalancing(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" - - # Consistent Hashing - CONSISTENT_HASHING = "ConsistentHashing" - # Round Robin - ROUND_ROBIN = "RoundRobin" - - -class CreateInputInputKinesisTypedDict(TypedDict): +class CreateInputInputWefTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsKinesis + type: CreateInputInputWefType r"""Connector type identifier.""" - stream_name: str - r"""Kinesis Data Stream to read data from""" - region: str - r"""Region where the Kinesis stream is located""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + subscriptions: List[CreateInputSubscriptionTypedDict] + r"""Subscriptions to events on forwarding endpoints""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -11510,86 +11923,71 @@ class CreateInputInputKinesisTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - service_interval: NotRequired[float] - r"""Time interval in minutes between consecutive service calls""" - shard_expr: NotRequired[str] - r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" - shard_iterator_type: NotRequired[CreateInputShardIteratorStart] - r"""Location at which to start reading a shard for the first time""" - payload_format: NotRequired[CreateInputRecordDataFormat] - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" - get_records_limit: NotRequired[float] - r"""Maximum number of records per getRecords call""" - get_records_limit_total: NotRequired[float] - r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" - load_balancing_algorithm: NotRequired[CreateInputShardLoadBalancing] - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Kinesis stream""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - verify_kpl_check_sums: NotRequired[bool] - r"""Verify Kinesis Producer Library (KPL) event checksums""" - avoid_duplicates: NotRequired[bool] - r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + auth_method: NotRequired[CreateInputInputWefAuthenticationMethod] + r"""How to authenticate incoming client connections""" + tls: NotRequired[CreateInputMTLSSettingsTypedDict] + r"""mTLS settings""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events in the __headers field""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + ca_fingerprint: NotRequired[str] + r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" + keytab: NotRequired[str] + r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" + principal: NotRequired[str] + r"""Kerberos principal used for authentication, typically in the form HTTP/@""" + allow_machine_id_mismatch: NotRequired[bool] + r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + log_fingerprint_mismatch: NotRequired[bool] + r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - template_shard_iterator_type: NotRequired[str] - r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" - template_payload_format: NotRequired[str] - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_keytab: NotRequired[str] + r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" + template_principal: NotRequired[str] + r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" -class CreateInputInputKinesis(BaseModel): +class CreateInputInputWef(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsKinesis + type: CreateInputInputWefType r"""Connector type identifier.""" - stream_name: Annotated[str, pydantic.Field(alias="streamName")] - r"""Kinesis Data Stream to read data from""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" - region: str - r"""Region where the Kinesis stream is located""" + subscriptions: List[CreateInputSubscription] + r"""Subscriptions to events on forwarding endpoints""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -11616,94 +12014,75 @@ class CreateInputInputKinesis(BaseModel): pq: Optional[PqType] = None - service_interval: Annotated[ - Optional[float], pydantic.Field(alias="serviceInterval") + auth_method: Annotated[ + Optional[CreateInputInputWefAuthenticationMethod], + pydantic.Field(alias="authMethod"), ] = None - r"""Time interval in minutes between consecutive service calls""" + r"""How to authenticate incoming client connections""" - shard_expr: Annotated[Optional[str], pydantic.Field(alias="shardExpr")] = None - r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + tls: Optional[CreateInputMTLSSettings] = None + r"""mTLS settings""" - shard_iterator_type: Annotated[ - Optional[CreateInputShardIteratorStart], - pydantic.Field(alias="shardIteratorType"), - ] = None - r"""Location at which to start reading a shard for the first time""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - payload_format: Annotated[ - Optional[CreateInputRecordDataFormat], pydantic.Field(alias="payloadFormat") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - get_records_limit: Annotated[ - Optional[float], pydantic.Field(alias="getRecordsLimit") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Maximum number of records per getRecords call""" + r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" - get_records_limit_total: Annotated[ - Optional[float], pydantic.Field(alias="getRecordsLimitTotal") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + r"""Add request headers to events in the __headers field""" - load_balancing_algorithm: Annotated[ - Optional[CreateInputShardLoadBalancing], - pydantic.Field(alias="loadBalancingAlgorithm"), + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - endpoint: Optional[str] = None - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""Use Assume Role credentials to access Kinesis stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + ca_fingerprint: Annotated[Optional[str], pydantic.Field(alias="caFingerprint")] = ( None ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + keytab: Optional[str] = None + r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" - verify_kpl_check_sums: Annotated[ - Optional[bool], pydantic.Field(alias="verifyKPLCheckSums") - ] = None - r"""Verify Kinesis Producer Library (KPL) event checksums""" + principal: Optional[str] = None + r"""Kerberos principal used for authentication, typically in the form HTTP/@""" - avoid_duplicates: Annotated[ - Optional[bool], pydantic.Field(alias="avoidDuplicates") + allow_machine_id_mismatch: Annotated[ + Optional[bool], pydantic.Field(alias="allowMachineIdMismatch") ] = None - r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -11711,11 +12090,10 @@ class CreateInputInputKinesis(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + log_fingerprint_mismatch: Annotated[ + Optional[bool], pydantic.Field(alias="logFingerprintMismatch") + ] = None + r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -11727,83 +12105,31 @@ class CreateInputInputKinesis(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") - ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - - template_shard_iterator_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_shardIteratorType") - ] = None - r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" - - template_payload_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadFormat") - ] = None - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_keytab: Annotated[ + Optional[str], pydantic.Field(alias="__template_keytab") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + template_principal: Annotated[ + Optional[str], pydantic.Field(alias="__template_principal") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - @field_serializer("shard_iterator_type") - def serialize_shard_iterator_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputShardIteratorStart(value) - except ValueError: - return value - return value - - @field_serializer("payload_format") - def serialize_payload_format(self, value): - if isinstance(value, str): - try: - return models.CreateInputRecordDataFormat(value) - except ValueError: - return value - return value - - @field_serializer("load_balancing_algorithm") - def serialize_load_balancing_algorithm(self, value): - if isinstance(value, str): - try: - return models.CreateInputShardLoadBalancing(value) - except ValueError: - return value - return value + r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("auth_method") + def serialize_auth_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.CreateInputInputWefAuthenticationMethod(value) except ValueError: return value return value @@ -11820,39 +12146,30 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "serviceInterval", - "shardExpr", - "shardIteratorType", - "payloadFormat", - "getRecordsLimit", - "getRecordsLimitTotal", - "loadBalancingAlgorithm", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "verifyKPLCheckSums", - "avoidDuplicates", + "authMethod", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "socketTimeout", + "caFingerprint", + "keytab", + "principal", + "allowMachineIdMismatch", "metadata", "description", - "awsApiKey", - "awsSecret", + "logFingerprintMismatch", "__template_environment", "__template_streamtags", - "__template_streamName", - "__template_shardIteratorType", - "__template_payloadFormat", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", + "__template_host", + "__template_port", + "__template_keytab", + "__template_principal", ] ) serialized = handler(self) @@ -11869,355 +12186,136 @@ def serialize_model(self, handler): return m -class CreateInputInputHTTPRawType(str, Enum): - r"""Source type identifier.""" +class CreateInputInputAppscopeType(str, Enum): + r"""Connector type identifier.""" - HTTP_RAW = "http_raw" + APPSCOPE = "appscope" -class CreateInputInputHTTPRawTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputHTTPRawType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - allowed_paths: NotRequired[List[str]] - r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" - allowed_methods: NotRequired[List[str]] - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - access_control_allow_origin: NotRequired[List[str]] - r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" - access_control_allow_headers: NotRequired[List[str]] - r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" - access_control_allow_methods: NotRequired[List[str]] - r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" - access_control_expose_headers: NotRequired[List[str]] - r"""Headers the browser is allowed to access from the response""" - access_control_allow_credentials: NotRequired[bool] - r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" - access_control_max_age: NotRequired[float] - r"""How long browsers should cache the preflight response""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_allowed_paths: NotRequired[str] - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - template_access_control_allow_origin: NotRequired[str] - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_access_control_allow_headers: NotRequired[str] - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" +class CreateInputAllowTypedDict(TypedDict): + procname: str + r"""Specify the name of a process or family of processes.""" + config: str + r"""Choose a config to apply to processes that match the process name and/or argument.""" + arg: NotRequired[str] + r"""Specify a string to substring-match against process command-line.""" -class CreateInputInputHTTPRaw(BaseModel): - id: str - r"""Unique ID for this input""" +class CreateInputAllow(BaseModel): + procname: str + r"""Specify the name of a process or family of processes.""" - type: CreateInputInputHTTPRawType - r"""Source type identifier.""" + config: str + r"""Choose a config to apply to processes that match the process name and/or argument.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + arg: Optional[str] = None + r"""Specify a string to substring-match against process command-line.""" - port: float - r"""Port to listen on""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["arg"]) + serialized = handler(self) + m = {} - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" + return m - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" +class CreateInputInputAppscopeFilterTypedDict(TypedDict): + allow: NotRequired[List[CreateInputAllowTypedDict]] + r"""Specify processes that AppScope should be loaded into, and the config to use.""" + transport_url: NotRequired[str] + r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" +class CreateInputInputAppscopeFilter(BaseModel): + allow: Optional[List[CreateInputAllow]] = None + r"""Specify processes that AppScope should be loaded into, and the config to use.""" - pq: Optional[PqType] = None + transport_url: Annotated[Optional[str], pydantic.Field(alias="transportURL")] = None + r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - allowed_paths: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedPaths") - ] = None - r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" - - allowed_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedMethods") - ] = None - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - - auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], - pydantic.Field(alias="authTokensExt"), - ] = None - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["allow", "transportURL"]) + serialized = handler(self) + m = {} - access_control_allow_origin: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") - ] = None - r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - access_control_allow_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") - ] = None - r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - access_control_allow_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowMethods") - ] = None - r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + return m - access_control_expose_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlExposeHeaders") - ] = None - r"""Headers the browser is allowed to access from the response""" - access_control_allow_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="accessControlAllowCredentials") - ] = None - r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" +class CreateInputInputAppscopePersistenceTypedDict(TypedDict): + r"""Persistence""" - access_control_max_age: Annotated[ - Optional[float], pydantic.Field(alias="accessControlMaxAge") - ] = None - r"""How long browsers should cache the preflight response""" + enable: NotRequired[bool] + r"""Spool events and metrics on disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" +class CreateInputInputAppscopePersistence(BaseModel): + r"""Persistence""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + enable: Optional[bool] = None + r"""Spool events and metrics on disk for Cribl Edge and Search""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - template_allowed_paths: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedPaths") - ] = None - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" - template_access_control_allow_origin: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") - ] = None - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" - template_access_control_allow_headers: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") - ] = None - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "breakerRulesets", - "staleChannelFlushMs", - "metadata", - "allowedPaths", - "allowedMethods", - "authTokensExt", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "accessControlAllowMethods", - "accessControlExposeHeaders", - "accessControlAllowCredentials", - "accessControlMaxAge", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_allowedPaths", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", ] ) serialized = handler(self) @@ -12234,34 +12332,23 @@ def serialize_model(self, handler): return m -class CreateInputInputDatagenType(str, Enum): - r"""Connector type identifier.""" - - DATAGEN = "datagen" - - -class CreateInputSampleTypedDict(TypedDict): - sample: str - r"""Data Generator File Name""" - events_per_sec: float - r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" - +CreateInputUNIXSocketPermissionsTypedDict = TypeAliasType( + "CreateInputUNIXSocketPermissionsTypedDict", Union[str, float] +) +r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" -class CreateInputSample(BaseModel): - sample: str - r"""Data Generator File Name""" - events_per_sec: Annotated[float, pydantic.Field(alias="eventsPerSec")] - r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" +CreateInputUNIXSocketPermissions = TypeAliasType( + "CreateInputUNIXSocketPermissions", Union[str, float] +) +r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" -class CreateInputInputDatagenTypedDict(TypedDict): +class CreateInputInputAppscopeTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputDatagenType + type: CreateInputInputAppscopeType r"""Connector type identifier.""" - samples: List[CreateInputSampleTypedDict] - r"""Datagens""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -12277,26 +12364,64 @@ class CreateInputInputDatagenTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputInputDatagen(BaseModel): + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + enable_unix_path: NotRequired[bool] + r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" + filter_: NotRequired[CreateInputInputAppscopeFilterTypedDict] + persistence: NotRequired[CreateInputInputAppscopePersistenceTypedDict] + r"""Persistence""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + host: NotRequired[str] + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: NotRequired[float] + r"""Port to listen on""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + unix_socket_path: NotRequired[str] + r"""Path to the UNIX domain socket to listen on.""" + unix_socket_perms: NotRequired[CreateInputUNIXSocketPermissionsTypedDict] + r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputInputAppscope(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputDatagenType + type: CreateInputInputAppscopeType r"""Connector type identifier.""" - samples: List[CreateInputSample] - r"""Datagens""" - disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -12322,12 +12447,96 @@ class CreateInputInputDatagen(BaseModel): pq: Optional[PqType] = None + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to establish a connection""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + enable_unix_path: Annotated[ + Optional[bool], pydantic.Field(alias="enableUnixPath") + ] = None + r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" + + filter_: Annotated[ + Optional[CreateInputInputAppscopeFilter], pydantic.Field(alias="filter") + ] = None + + persistence: Optional[CreateInputInputAppscopePersistence] = None + r"""Persistence""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: Optional[str] = None r"""Optional description for this configuration.""" + host: Optional[str] = None + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: Optional[float] = None + r"""Port to listen on""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + unix_socket_path: Annotated[ + Optional[str], pydantic.Field(alias="unixSocketPath") + ] = None + r"""Path to the UNIX domain socket to listen on.""" + + unix_socket_perms: Annotated[ + Optional[CreateInputUNIXSocketPermissions], + pydantic.Field(alias="unixSocketPerms"), + ] = None + r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -12338,6 +12547,25 @@ class CreateInputInputDatagen(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -12350,10 +12578,31 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", "metadata", + "breakerRulesets", + "staleChannelFlushMs", + "enableUnixPath", + "filter", + "persistence", + "authType", "description", + "host", + "port", + "tls", + "unixSocketPath", + "unixSocketPerms", + "authToken", + "textSecret", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -12370,70 +12619,17 @@ def serialize_model(self, handler): return m -class CreateInputInputDatadogAgentType(str, Enum): - r"""Source type identifier.""" - - DATADOG_AGENT = "datadog_agent" - - -class CreateInputSamplingRuleTypedDict(TypedDict): - service: str - r"""Datadog service name""" - environment: str - r"""Datadog environment name (example: prod, staging)""" - rate: float - r"""Sampling rate for this service/environment combination (0.0–1.0)""" - - -class CreateInputSamplingRule(BaseModel): - service: str - r"""Datadog service name""" - - environment: str - r"""Datadog environment name (example: prod, staging)""" - - rate: float - r"""Sampling rate for this service/environment combination (0.0–1.0)""" - - -class CreateInputInputDatadogAgentProxyModeTypedDict(TypedDict): - enabled: bool - r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" - reject_unauthorized: NotRequired[bool] - r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - - -class CreateInputInputDatadogAgentProxyMode(BaseModel): - enabled: bool - r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["rejectUnauthorized"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateInputInputTCPType(str, Enum): + r"""Connector type identifier.""" - return m + TCP = "tcp" -class CreateInputInputDatadogAgentTypedDict(TypedDict): +class CreateInputInputTCPTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputDatadogAgentType - r"""Source type identifier.""" + type: CreateInputInputTCPType + r"""Connector type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float @@ -12455,39 +12651,38 @@ class CreateInputInputDatadogAgentTypedDict(TypedDict): pq: NotRequired[PqTypeTypedDict] tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - extract_metrics: NotRequired[bool] - r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" - sampling_rate: NotRequired[float] - r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" - sampling_rules: NotRequired[List[CreateInputSamplingRuleTypedDict]] - r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - proxy_mode: NotRequired[CreateInputInputDatadogAgentProxyModeTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + enable_header: NotRequired[bool] + r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" description: NotRequired[str] r"""Optional description for this configuration.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -12498,12 +12693,12 @@ class CreateInputInputDatadogAgentTypedDict(TypedDict): r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateInputInputDatadogAgent(BaseModel): +class CreateInputInputTCP(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputDatadogAgentType - r"""Source type identifier.""" + type: CreateInputInputTCPType + r"""Connector type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -12539,86 +12734,74 @@ class CreateInputInputDatadogAgent(BaseModel): tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to establish a connection""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( None ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - extract_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="extractMetrics") - ] = None - r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - sampling_rate: Annotated[Optional[float], pydantic.Field(alias="samplingRate")] = ( + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( None ) - r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" - sampling_rules: Annotated[ - Optional[List[CreateInputSamplingRule]], pydantic.Field(alias="samplingRules") - ] = None - r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - proxy_mode: Annotated[ - Optional[CreateInputInputDatadogAgentProxyMode], - pydantic.Field(alias="proxyMode"), + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -12640,6 +12823,15 @@ class CreateInputInputDatadogAgent(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -12653,23 +12845,22 @@ def serialize_model(self, handler): "connections", "pq", "tls", - "maxActiveReq", - "maxRequestsPerSocket", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "extractMetrics", - "samplingRate", - "samplingRules", "metadata", - "proxyMode", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "enableHeader", + "preprocess", "description", + "authToken", + "authType", + "textSecret", "__template_environment", "__template_streamtags", "__template_host", @@ -12690,19 +12881,26 @@ def serialize_model(self, handler): return m -class CreateInputInputCrowdstrikeType(str, Enum): +class CreateInputInputFileType(str, Enum): r"""Connector type identifier.""" - CROWDSTRIKE = "crowdstrike" + FILE = "file" + + +class CreateInputInputFileMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Choose how to discover files to monitor""" + + # Manual + MANUAL = "manual" + # Auto + AUTO = "auto" -class CreateInputInputCrowdstrikeTypedDict(TypedDict): +class CreateInputInputFileTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputCrowdstrikeType + type: CreateInputInputFileType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -12718,122 +12916,73 @@ class CreateInputInputCrowdstrikeTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + mode: NotRequired[CreateInputInputFileMode] + r"""Choose how to discover files to monitor""" + interval: NotRequired[float] + r"""Time, in seconds, between scanning for files""" + filenames: NotRequired[List[str]] + r"""The full path of discovered files are matched against this wildcard list""" + filter_archived_files: NotRequired[bool] + r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" + tail_only: NotRequired[bool] + r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" + idle_timeout: NotRequired[float] + r"""Time, in seconds, before an idle file is closed""" + min_age_dur: NotRequired[str] + r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" + max_age_dur: NotRequired[str] + r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" + check_file_mod_time: NotRequired[bool] + r"""Skip files with modification times earlier than the maximum age duration""" + force_text: NotRequired[bool] + r"""Forces files containing binary data to be streamed as text""" + hash_len: NotRequired[float] + r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + disable_stale_channel_flush: NotRequired[bool] + r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + path: NotRequired[str] + r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" + depth: NotRequired[float] + r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" + suppress_missing_path_errors: NotRequired[bool] + r"""Suppress errors when search path does not exist""" + delete_files: NotRequired[bool] + r"""Delete files after they have been collected""" + salt_hash: NotRequired[bool] + r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" + optimize_leaf_directories: NotRequired[bool] + r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" + enable_discovery_throttle: NotRequired[bool] + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" + discovery_throttle_cpu_percent: NotRequired[float] + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" + include_unidentifiable_binary: NotRequired[bool] + r"""Stream binary files as Base64-encoded chunks""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputInputCrowdstrike(BaseModel): +class CreateInputInputFile(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputCrowdstrikeType + type: CreateInputInputFileType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -12859,398 +13008,171 @@ class CreateInputInputCrowdstrike(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" - - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" - - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" - - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - checkpointing: Optional[CheckpointingType] = None - - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" - - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" - - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None - - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + mode: Optional[CreateInputInputFileMode] = None + r"""Choose how to discover files to monitor""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + interval: Optional[float] = None + r"""Time, in seconds, between scanning for files""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + filenames: Optional[List[str]] = None + r"""The full path of discovered files are matched against this wildcard list""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + filter_archived_files: Annotated[ + Optional[bool], pydantic.Field(alias="filterArchivedFiles") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + tail_only: Annotated[Optional[bool], pydantic.Field(alias="tailOnly")] = None + r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + idle_timeout: Annotated[Optional[float], pydantic.Field(alias="idleTimeout")] = None + r"""Time, in seconds, before an idle file is closed""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + min_age_dur: Annotated[Optional[str], pydantic.Field(alias="minAgeDur")] = None + r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None + r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + check_file_mod_time: Annotated[ + Optional[bool], pydantic.Field(alias="checkFileModTime") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Skip files with modification times earlier than the maximum age duration""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + force_text: Annotated[Optional[bool], pydantic.Field(alias="forceText")] = None + r"""Forces files containing binary data to be streamed as text""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") - ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + hash_len: Annotated[Optional[float], pydantic.Field(alias="hashLen")] = None + r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "checkpointing", - "pollTimeout", - "encoding", - "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", - ] - ) - serialized = handler(self) - m = {} + r"""Load balance traffic across all Worker Processes""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - return m + disable_stale_channel_flush: Annotated[ + Optional[bool], pydantic.Field(alias="disableStaleChannelFlush") + ] = None + r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" -class CreateInputInputWindowsMetricsType(str, Enum): - r"""Connector type identifier.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - WINDOWS_METRICS = "windows_metrics" + description: Optional[str] = None + r"""Optional description for this configuration.""" + path: Optional[str] = None + r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" -class CreateInputInputWindowsMetricsSystemMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of details for system metrics""" + depth: Optional[float] = None + r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + suppress_missing_path_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + ] = None + r"""Suppress errors when search path does not exist""" + + delete_files: Annotated[Optional[bool], pydantic.Field(alias="deleteFiles")] = None + r"""Delete files after they have been collected""" + + salt_hash: Annotated[Optional[bool], pydantic.Field(alias="saltHash")] = None + r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" + optimize_leaf_directories: Annotated[ + Optional[bool], pydantic.Field(alias="optimizeLeafDirectories") + ] = None + r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" -class CreateInputInputWindowsMetricsSystemTypedDict(TypedDict): - mode: NotRequired[CreateInputInputWindowsMetricsSystemMode] - r"""Select the level of details for system metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all system information""" + enable_discovery_throttle: Annotated[ + Optional[bool], pydantic.Field(alias="enableDiscoveryThrottle") + ] = None + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" + + discovery_throttle_cpu_percent: Annotated[ + Optional[float], pydantic.Field(alias="discoveryThrottleCpuPercent") + ] = None + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" + include_unidentifiable_binary: Annotated[ + Optional[bool], pydantic.Field(alias="includeUnidentifiableBinary") + ] = None + r"""Stream binary files as Base64-encoded chunks""" -class CreateInputInputWindowsMetricsSystem(BaseModel): - mode: Optional[CreateInputInputWindowsMetricsSystemMode] = None - r"""Select the level of details for system metrics""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - detail: Optional[bool] = None - r"""Generate metrics for all system information""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @field_serializer("mode") def serialize_mode(self, value): if isinstance(value, str): try: - return models.CreateInputInputWindowsMetricsSystemMode(value) + return models.CreateInputInputFileMode(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "mode", + "interval", + "filenames", + "filterArchivedFiles", + "tailOnly", + "idleTimeout", + "minAgeDur", + "maxAgeDur", + "checkFileModTime", + "forceText", + "hashLen", + "enableLoadBalancing", + "metadata", + "breakerRulesets", + "disableStaleChannelFlush", + "staleChannelFlushMs", + "autoParse", + "description", + "path", + "depth", + "suppressMissingPathErrors", + "deleteFiles", + "saltHash", + "optimizeLeafDirectories", + "enableDiscoveryThrottle", + "discoveryThrottleCpuPercent", + "includeUnidentifiableBinary", + "__template_environment", + "__template_streamtags", + ] + ) serialized = handler(self) m = {} @@ -13265,181 +13187,297 @@ def serialize_model(self, handler): return m -class CreateInputInputWindowsMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of details for CPU metrics""" +class CreateInputInputSyslogSyslog2TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsSyslog + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + tcp_port: float + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + udp_port: NotRequired[float] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + timestamp_timezone: NotRequired[str] + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: NotRequired[bool] + r"""Treat UDP packet data received as full syslog message""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: NotRequired[List[str]] + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + octet_counting: NotRequired[bool] + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: NotRequired[bool] + r"""Enable if we should infer the syslog framing of the incoming messages.""" + strictly_infer_octet_counting: NotRequired[bool] + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + allow_non_standard_app_name: NotRequired[bool] + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: NotRequired[bool] + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + template_timestamp_timezone: NotRequired[str] + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" +class CreateInputInputSyslogSyslog2(BaseModel): + id: str + r"""Unique ID for this input""" + type: TypeOptionsSyslog + r"""Connector type identifier.""" -class CreateInputInputWindowsMetricsCPUTypedDict(TypedDict): - mode: NotRequired[CreateInputInputWindowsMetricsCPUMode] - r"""Select the level of details for CPU metrics""" - per_cpu: NotRequired[bool] - r"""Generate metrics for each CPU""" - detail: NotRequired[bool] - r"""Generate metrics for all CPU states""" - time: NotRequired[bool] - r"""Generate raw, monotonic CPU time counters""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + tcp_port: Annotated[float, pydantic.Field(alias="tcpPort")] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" -class CreateInputInputWindowsMetricsCPU(BaseModel): - mode: Optional[CreateInputInputWindowsMetricsCPUMode] = None - r"""Select the level of details for CPU metrics""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None - r"""Generate metrics for each CPU""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - detail: Optional[bool] = None - r"""Generate metrics for all CPU states""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - time: Optional[bool] = None - r"""Generate raw, monotonic CPU time counters""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputWindowsMetricsCPUMode(value) - except ValueError: - return value - return value + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perCpu", "detail", "time"]) - serialized = handler(self) - m = {} + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + pq: Optional[PqType] = None - return m + udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" -class CreateInputInputWindowsMetricsMemoryMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of details for memory metrics""" + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="timestampTimezone") + ] = None + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + ] = None + r"""Treat UDP packet data received as full syslog message""" -class CreateInputInputWindowsMetricsMemoryTypedDict(TypedDict): - mode: NotRequired[CreateInputInputWindowsMetricsMemoryMode] - r"""Select the level of details for memory metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all memory states""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="keepFieldsList") + ] = None + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" -class CreateInputInputWindowsMetricsMemory(BaseModel): - mode: Optional[CreateInputInputWindowsMetricsMemoryMode] = None - r"""Select the level of details for memory metrics""" + octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + None + ) + r"""Enable if incoming messages use octet counting per RFC 6587.""" - detail: Optional[bool] = None - r"""Generate metrics for all memory states""" + infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( + None + ) + r"""Enable if we should infer the syslog framing of the incoming messages.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputWindowsMetricsMemoryMode(value) - except ValueError: - return value - return value + strictly_infer_octet_counting: Annotated[ + Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + ] = None + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) - serialized = handler(self) - m = {} + allow_non_standard_app_name: Annotated[ + Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ] = None + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - return m + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" -class CreateInputInputWindowsMetricsNetworkMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for network metrics""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" -class CreateInputInputWindowsMetricsNetworkTypedDict(TypedDict): - mode: NotRequired[CreateInputInputWindowsMetricsNetworkMode] - r"""Select the level of details for network metrics""" - detail: NotRequired[bool] - r"""Generate full network metrics""" - protocols: NotRequired[bool] - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - devices: NotRequired[List[str]] - r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" - per_interface: NotRequired[bool] - r"""Generate separate metrics for each interface""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" -class CreateInputInputWindowsMetricsNetwork(BaseModel): - mode: Optional[CreateInputInputWindowsMetricsNetworkMode] = None - r"""Select the level of details for network metrics""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - detail: Optional[bool] = None - r"""Generate full network metrics""" + enable_enhanced_proxy_header_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + ] = None + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" - protocols: Optional[bool] = None - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - devices: Optional[List[str]] = None - r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Generate separate metrics for each interface""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputWindowsMetricsNetworkMode(value) - except ValueError: - return value - return value + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + + template_timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="__template_timestampTimezone") + ] = None + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( - ["mode", "detail", "protocols", "devices", "perInterface"] + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "udpPort", + "maxBufferSize", + "ipWhitelistRegex", + "timestampTimezone", + "singleMsgUdpPackets", + "enableProxyHeader", + "keepFieldsList", + "octetCounting", + "inferFraming", + "strictlyInferOctetCounting", + "allowNonStandardAppName", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "tls", + "metadata", + "udpSocketRxBufSize", + "enableLoadBalancing", + "autoParse", + "description", + "enableEnhancedProxyHeaderParsing", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + "__template_timestampTimezone", + ] ) serialized = handler(self) m = {} @@ -13455,200 +13493,296 @@ def serialize_model(self, handler): return m -class CreateInputInputWindowsMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of details for disk metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputInputWindowsMetricsDiskTypedDict(TypedDict): - mode: NotRequired[CreateInputInputWindowsMetricsDiskMode] - r"""Select the level of details for disk metrics""" - per_volume: NotRequired[bool] - r"""Generate separate metrics for each volume""" - detail: NotRequired[bool] - r"""Generate full disk metrics""" - volumes: NotRequired[List[str]] - r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" - - -class CreateInputInputWindowsMetricsDisk(BaseModel): - mode: Optional[CreateInputInputWindowsMetricsDiskMode] = None - r"""Select the level of details for disk metrics""" - - per_volume: Annotated[Optional[bool], pydantic.Field(alias="perVolume")] = None - r"""Generate separate metrics for each volume""" +class CreateInputInputSyslogSyslog1TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsSyslog + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + udp_port: float + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tcp_port: NotRequired[float] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + timestamp_timezone: NotRequired[str] + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: NotRequired[bool] + r"""Treat UDP packet data received as full syslog message""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: NotRequired[List[str]] + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + octet_counting: NotRequired[bool] + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: NotRequired[bool] + r"""Enable if we should infer the syslog framing of the incoming messages.""" + strictly_infer_octet_counting: NotRequired[bool] + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + allow_non_standard_app_name: NotRequired[bool] + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: NotRequired[bool] + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + template_timestamp_timezone: NotRequired[str] + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" - detail: Optional[bool] = None - r"""Generate full disk metrics""" - volumes: Optional[List[str]] = None - r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" +class CreateInputInputSyslogSyslog1(BaseModel): + id: str + r"""Unique ID for this input""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputInputWindowsMetricsDiskMode(value) - except ValueError: - return value - return value + type: TypeOptionsSyslog + r"""Connector type identifier.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perVolume", "detail", "volumes"]) - serialized = handler(self) - m = {} + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + udp_port: Annotated[float, pydantic.Field(alias="udpPort")] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - return m + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" -class CreateInputInputWindowsMetricsCustomTypedDict(TypedDict): - system: NotRequired[CreateInputInputWindowsMetricsSystemTypedDict] - cpu: NotRequired[CreateInputInputWindowsMetricsCPUTypedDict] - memory: NotRequired[CreateInputInputWindowsMetricsMemoryTypedDict] - network: NotRequired[CreateInputInputWindowsMetricsNetworkTypedDict] - disk: NotRequired[CreateInputInputWindowsMetricsDiskTypedDict] + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" -class CreateInputInputWindowsMetricsCustom(BaseModel): - system: Optional[CreateInputInputWindowsMetricsSystem] = None + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - cpu: Optional[CreateInputInputWindowsMetricsCPU] = None + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - memory: Optional[CreateInputInputWindowsMetricsMemory] = None + pq: Optional[PqType] = None - network: Optional[CreateInputInputWindowsMetricsNetwork] = None + tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - disk: Optional[CreateInputInputWindowsMetricsDisk] = None + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["system", "cpu", "memory", "network", "disk"]) - serialized = handler(self) - m = {} + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="timestampTimezone") + ] = None + r"""Timezone to assign to timestamps without timezone info""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + ] = None + r"""Treat UDP packet data received as full syslog message""" - return m + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="keepFieldsList") + ] = None + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" -class CreateInputInputWindowsMetricsHostTypedDict(TypedDict): - mode: NotRequired[ModeOptionsHost] - r"""Select level of detail for host metrics""" - custom: NotRequired[CreateInputInputWindowsMetricsCustomTypedDict] + octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + None + ) + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( + None + ) + r"""Enable if we should infer the syslog framing of the incoming messages.""" -class CreateInputInputWindowsMetricsHost(BaseModel): - mode: Optional[ModeOptionsHost] = None - r"""Select level of detail for host metrics""" + strictly_infer_octet_counting: Annotated[ + Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + ] = None + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - custom: Optional[CreateInputInputWindowsMetricsCustom] = None + allow_non_standard_app_name: Annotated[ + Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ] = None + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptionsHost(value) - except ValueError: - return value - return value + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "custom"]) - serialized = handler(self) - m = {} + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - return m + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" -class CreateInputInputWindowsMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" -class CreateInputInputWindowsMetricsPersistence(BaseModel): - r"""persistence""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" + enable_enhanced_proxy_header_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + ] = None + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value + template_timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="__template_timestampTimezone") + ] = None + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tcpPort", + "maxBufferSize", + "ipWhitelistRegex", + "timestampTimezone", + "singleMsgUdpPackets", + "enableProxyHeader", + "keepFieldsList", + "octetCounting", + "inferFraming", + "strictlyInferOctetCounting", + "allowNonStandardAppName", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "tls", + "metadata", + "udpSocketRxBufSize", + "enableLoadBalancing", + "autoParse", + "description", + "enableEnhancedProxyHeaderParsing", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + "__template_timestampTimezone", ] ) serialized = handler(self) @@ -13665,11 +13799,38 @@ def serialize_model(self, handler): return m -class CreateInputInputWindowsMetricsTypedDict(TypedDict): +CreateInputInputSyslogUnionTypedDict = TypeAliasType( + "CreateInputInputSyslogUnionTypedDict", + Union[ + CreateInputInputSyslogSyslog1TypedDict, CreateInputInputSyslogSyslog2TypedDict + ], +) + + +CreateInputInputSyslogUnion = TypeAliasType( + "CreateInputInputSyslogUnion", + Union[CreateInputInputSyslogSyslog1, CreateInputInputSyslogSyslog2], +) + + +class CreateInputQueueType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The queue type used (or created)""" + + # Standard + STANDARD = "standard" + # FIFO + FIFO = "fifo" + + +class CreateInputInputSqsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputWindowsMetricsType + type: TypeOptionsSqs r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + queue_type: CreateInputQueueType + r"""The queue type used (or created)""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -13685,32 +13846,85 @@ class CreateInputInputWindowsMetricsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - host: NotRequired[CreateInputInputWindowsMetricsHostTypedDict] - process: NotRequired[ProcessTypeTypedDict] - gpu: NotRequired[GpuTypeTypedDict] + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + create_queue: NotRequired[bool] + r"""Create queue if it does not exist""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SQS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - persistence: NotRequired[CreateInputInputWindowsMetricsPersistenceTypedDict] - r"""persistence""" - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_queue_type: NotRequired[str] + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateInputInputWindowsMetrics(BaseModel): +class CreateInputInputSqs(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputWindowsMetricsType + type: TypeOptionsSqs r"""Connector type identifier.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + queue_type: Annotated[CreateInputQueueType, pydantic.Field(alias="queueType")] + r"""The queue type used (or created)""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -13736,29 +13950,92 @@ class CreateInputInputWindowsMetrics(BaseModel): pq: Optional[PqType] = None - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None + r"""Create queue if it does not exist""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SQS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" - host: Optional[CreateInputInputWindowsMetricsHost] = None + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - process: Optional[ProcessType] = None + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - gpu: Optional[GpuType] = None + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - persistence: Optional[CreateInputInputWindowsMetricsPersistence] = None - r"""persistence""" + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") - ] = None - r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: Optional[str] = None r"""Optional description for this configuration.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -13769,6 +14046,69 @@ class CreateInputInputWindowsMetrics(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_queue_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueType") + ] = None + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("queue_type") + def serialize_queue_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputQueueType(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -13781,16 +14121,38 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "interval", - "host", - "process", - "gpu", + "awsAccountId", + "createQueue", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxMessages", + "visibilityTimeout", "metadata", - "persistence", - "disableNativeModule", + "pollTimeout", + "autoParse", "description", + "awsApiKey", + "awsSecret", + "numReceivers", "__template_environment", "__template_streamtags", + "__template_queueName", + "__template_queueType", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -13807,17 +14169,21 @@ def serialize_model(self, handler): return m -class CreateInputInputKubeEventsType(str, Enum): +class CreateInputInputModelDrivenTelemetryType(str, Enum): r"""Connector type identifier.""" - KUBE_EVENTS = "kube_events" + MODEL_DRIVEN_TELEMETRY = "model_driven_telemetry" -class CreateInputInputKubeEventsTypedDict(TypedDict): +class CreateInputInputModelDrivenTelemetryTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputKubeEventsType + type: CreateInputInputModelDrivenTelemetryType r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -13833,25 +14199,43 @@ class CreateInputInputKubeEventsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] - r"""Filtering on event fields""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" + shutdown_timeout_ms: NotRequired[float] + r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateInputInputKubeEvents(BaseModel): +class CreateInputInputModelDrivenTelemetry(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputKubeEventsType + type: CreateInputInputModelDrivenTelemetryType r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -13877,12 +14261,32 @@ class CreateInputInputKubeEvents(BaseModel): pq: Optional[PqType] = None - rules: Optional[List[RuleConfInputKubeMetrics]] = None - r"""Filtering on event fields""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") + ] = None + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") + ] = None + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" + + shutdown_timeout_ms: Annotated[ + Optional[float], pydantic.Field(alias="shutdownTimeoutMs") + ] = None + r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -13896,6 +14300,16 @@ class CreateInputInputKubeEvents(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -13908,11 +14322,17 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "rules", + "tls", "metadata", + "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", + "shutdownTimeoutMs", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -13929,29 +14349,164 @@ def serialize_model(self, handler): return m -class CreateInputInputKubeLogsType(str, Enum): - r"""Connector type identifier.""" +class CreateInputInputOpenTelemetryType(str, Enum): + r"""Source type identifier.""" + + OPEN_TELEMETRY = "open_telemetry" - KUBE_LOGS = "kube_logs" +class CreateInputProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" -class CreateInputInputKubeLogsRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + # gRPC + GRPC = "grpc" + # HTTP + HTTP = "http" + + +class CreateInputOTLPVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" + + # 0.10.0 + ZERO_DOT_10_DOT_0 = "0.10.0" + # 1.3.1 + ONE_DOT_3_DOT_1 = "1.3.1" + + +class CreateInputInputOpenTelemetryAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""OpenTelemetry authentication type""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + + +class CreateInputAuthMethodsExtAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" + + # Token + TOKEN = "token" + # Token (secret) + TOKEN_SECRET = "tokenSecret" + # Basic + BASIC = "basic" + # Basic (credentials secret) + BASIC_SECRET = "basicSecret" + # OAuth + OAUTH = "oauth" + + +class CreateInputAuthMethodsExtTypedDict(TypedDict): + auth_type: CreateInputAuthMethodsExtAuthenticationType + r"""Authentication type""" + token: NotRequired[str] + r"""Bearer token for Authorization header""" description: NotRequired[str] - r"""Optional description of this rule's purpose""" + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this auth method""" + enabled: NotRequired[bool] + r"""Enable""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + issuer: NotRequired[str] + r"""Expected token issuer (iss claim)""" + jwks_uri: NotRequired[str] + r"""URL of the JWKS endpoint used to fetch signing keys""" + audience: NotRequired[str] + r"""Expected token audience (aud claim)""" + scopes: NotRequired[List[str]] + r"""Scopes the token must grant (optional)""" -class CreateInputInputKubeLogsRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" +class CreateInputAuthMethodsExt(BaseModel): + auth_type: Annotated[ + CreateInputAuthMethodsExtAuthenticationType, pydantic.Field(alias="authType") + ] + r"""Authentication type""" + + token: Optional[str] = None + r"""Bearer token for Authorization header""" description: Optional[str] = None - r"""Optional description of this rule's purpose""" + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this auth method""" + + enabled: Optional[bool] = None + r"""Enable""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + issuer: Optional[str] = None + r"""Expected token issuer (iss claim)""" + + jwks_uri: Annotated[Optional[str], pydantic.Field(alias="jwksUri")] = None + r"""URL of the JWKS endpoint used to fetch signing keys""" + + audience: Optional[str] = None + r"""Expected token audience (aud claim)""" + + scopes: Optional[List[str]] = None + r"""Scopes the token must grant (optional)""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputAuthMethodsExtAuthenticationType(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description"]) + optional_fields = set( + [ + "token", + "description", + "metadata", + "enabled", + "tokenSecret", + "username", + "password", + "credentialsSecret", + "issuer", + "jwksUri", + "audience", + "scopes", + ] + ) serialized = handler(self) m = {} @@ -13966,11 +14521,15 @@ def serialize_model(self, handler): return m -class CreateInputInputKubeLogsTypedDict(TypedDict): +class CreateInputInputOpenTelemetryTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputInputKubeLogsType - r"""Connector type identifier.""" + type: CreateInputInputOpenTelemetryType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -13986,109 +14545,224 @@ class CreateInputInputKubeLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" - rules: NotRequired[List[CreateInputInputKubeLogsRuleTypedDict]] - r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" - timestamps: NotRequired[bool] - r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" - line_buffer_limit: NotRequired[float] - r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" - lb_disable_assembly: NotRequired[bool] - r"""Internal flag to disable LB worker payload reassembly.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + enable_health_check: NotRequired[bool] + r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + protocol: NotRequired[CreateInputProtocol] + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" + extract_spans: NotRequired[bool] + r"""Enable to extract each incoming span to a separate event""" + extract_metrics: NotRequired[bool] + r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" + otlp_version: NotRequired[CreateInputOTLPVersion] + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" + auth_type: NotRequired[CreateInputInputOpenTelemetryAuthenticationType] + r"""OpenTelemetry authentication type""" + auth_methods_ext: NotRequired[List[CreateInputAuthMethodsExtTypedDict]] + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - persistence: NotRequired[DiskSpoolingTypeTypedDict] - r"""Disk Spooling""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + extract_logs: NotRequired[bool] + r"""Enable to extract each incoming log record to a separate event""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_protocol: NotRequired[str] + r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + template_otlp_version: NotRequired[str] + r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" -class CreateInputInputKubeLogs(BaseModel): +class CreateInputInputOpenTelemetry(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputInputKubeLogsType - r"""Connector type identifier.""" + type: CreateInputInputOpenTelemetryType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - pq: Optional[PqType] = None + protocol: Optional[CreateInputProtocol] = None + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - interval: Optional[float] = None - r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + extract_spans: Annotated[Optional[bool], pydantic.Field(alias="extractSpans")] = ( + None + ) + r"""Enable to extract each incoming span to a separate event""" - rules: Optional[List[CreateInputInputKubeLogsRule]] = None - r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + extract_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="extractMetrics") + ] = None + r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - timestamps: Optional[bool] = None - r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + otlp_version: Annotated[ + Optional[CreateInputOTLPVersion], pydantic.Field(alias="otlpVersion") + ] = None + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - line_buffer_limit: Annotated[ - Optional[float], pydantic.Field(alias="lineBufferLimit") + auth_type: Annotated[ + Optional[CreateInputInputOpenTelemetryAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + r"""OpenTelemetry authentication type""" - lb_disable_assembly: Annotated[ - Optional[bool], pydantic.Field(alias="__LBDisableAssembly") + auth_methods_ext: Annotated[ + Optional[List[CreateInputAuthMethodsExt]], + pydantic.Field(alias="authMethodsExt"), ] = None - r"""Internal flag to disable LB worker payload reassembly.""" + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - persistence: Optional[DiskSpoolingType] = None - r"""Disk Spooling""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: Optional[str] = None r"""Optional description for this configuration.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + extract_logs: Annotated[Optional[bool], pydantic.Field(alias="extractLogs")] = None + r"""Enable to extract each incoming log record to a separate event""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -14099,6 +14773,53 @@ class CreateInputInputKubeLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_protocol: Annotated[ + Optional[str], pydantic.Field(alias="__template_protocol") + ] = None + r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + + template_otlp_version: Annotated[ + Optional[str], pydantic.Field(alias="__template_otlpVersion") + ] = None + r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" + + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputProtocol(value) + except ValueError: + return value + return value + + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): + if isinstance(value, str): + try: + return models.CreateInputOTLPVersion(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputInputOpenTelemetryAuthenticationType(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -14111,19 +14832,38 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "interval", - "rules", - "timestamps", - "lineBufferLimit", - "__LBDisableAssembly", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "protocol", + "extractSpans", + "extractMetrics", + "otlpVersion", + "authType", + "authMethodsExt", "metadata", - "persistence", - "breakerRulesets", - "staleChannelFlushMs", - "enableLoadBalancing", + "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "extractLogs", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_protocol", + "__template_otlpVersion", ] ) serialized = handler(self) @@ -14140,213 +14880,169 @@ def serialize_model(self, handler): return m -class CreateInputInputKubeMetricsType(str, Enum): - r"""Connector type identifier.""" - - KUBE_METRICS = "kube_metrics" - - -class CreateInputInputKubeMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" - - enable: NotRequired[bool] - r"""Spool metrics on disk for Cribl Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - - -class CreateInputInputKubeMetricsPersistence(BaseModel): - r"""persistence""" - - enable: Optional[bool] = None - r"""Spool metrics on disk for Cribl Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateInputAuthenticationProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Authentication protocol""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + # None + NONE = "none" + # MD5 + MD5 = "md5" + # SHA1 + SHA = "sha" + # SHA224 + SHA224 = "sha224" + # SHA256 + SHA256 = "sha256" + # SHA384 + SHA384 = "sha384" + # SHA512 + SHA512 = "sha512" - return m +class CreateInputV3AuthenticationKeyType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" -class CreateInputInputKubeMetricsTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputInputKubeMetricsType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" - scrape_kubelet: NotRequired[bool] - r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" - scrape_cadvisor: NotRequired[bool] - r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" - rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] - r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - persistence: NotRequired[CreateInputInputKubeMetricsPersistenceTypedDict] - r"""persistence""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" -class CreateInputInputKubeMetrics(BaseModel): - id: str - r"""Unique ID for this input""" +class CreateInputPrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Privacy protocol""" - type: CreateInputInputKubeMetricsType - r"""Connector type identifier.""" + # None + NONE = "none" + # DES + DES = "des" + # AES128 + AES = "aes" + # AES256b (Blumenthal) + AES256B = "aes256b" + # AES256r (Reeder) + AES256R = "aes256r" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" +class CreateInputV3PrivacyKeyType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" +class CreateInputV3UserTypedDict(TypedDict): + name: str + r"""V3 name""" + auth_protocol: NotRequired[CreateInputAuthenticationProtocol] + r"""Authentication protocol""" + auth_key_type: NotRequired[CreateInputV3AuthenticationKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + auth_key: NotRequired[str] + r"""V3 authentication key""" + auth_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" + priv_protocol: NotRequired[CreateInputPrivacyProtocol] + r"""Privacy protocol""" + priv_key_type: NotRequired[CreateInputV3PrivacyKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + priv_key: NotRequired[str] + r"""V3 privacy key""" + priv_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" +class CreateInputV3User(BaseModel): + name: str + r"""V3 name""" - pq: Optional[PqType] = None + auth_protocol: Annotated[ + Optional[CreateInputAuthenticationProtocol], + pydantic.Field(alias="authProtocol"), + ] = None + r"""Authentication protocol""" - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + auth_key_type: Annotated[ + Optional[CreateInputV3AuthenticationKeyType], + pydantic.Field(alias="authKeyType"), + ] = None + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + + auth_key: Annotated[Optional[str], pydantic.Field(alias="authKey")] = None + r"""V3 authentication key""" - scrape_kubelet: Annotated[Optional[bool], pydantic.Field(alias="scrapeKubelet")] = ( + auth_key_secret: Annotated[Optional[str], pydantic.Field(alias="authKeySecret")] = ( None ) - r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + r"""Select or create a stored text secret""" - scrape_cadvisor: Annotated[ - Optional[bool], pydantic.Field(alias="scrapeCadvisor") + priv_protocol: Annotated[ + Optional[CreateInputPrivacyProtocol], pydantic.Field(alias="privProtocol") ] = None - r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + r"""Privacy protocol""" - rules: Optional[List[RuleConfInputKubeMetrics]] = None - r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + priv_key_type: Annotated[ + Optional[CreateInputV3PrivacyKeyType], pydantic.Field(alias="privKeyType") + ] = None + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + priv_key: Annotated[Optional[str], pydantic.Field(alias="privKey")] = None + r"""V3 privacy key""" - persistence: Optional[CreateInputInputKubeMetricsPersistence] = None - r"""persistence""" + priv_key_secret: Annotated[Optional[str], pydantic.Field(alias="privKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + @field_serializer("auth_protocol") + def serialize_auth_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputAuthenticationProtocol(value) + except ValueError: + return value + return value - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + @field_serializer("auth_key_type") + def serialize_auth_key_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputV3AuthenticationKeyType(value) + except ValueError: + return value + return value - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + @field_serializer("priv_protocol") + def serialize_priv_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputPrivacyProtocol(value) + except ValueError: + return value + return value + + @field_serializer("priv_key_type") + def serialize_priv_key_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputV3PrivacyKeyType(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "interval", - "scrapeKubelet", - "scrapeCadvisor", - "rules", - "metadata", - "persistence", - "description", - "__template_environment", - "__template_streamtags", + "authProtocol", + "authKeyType", + "authKey", + "authKeySecret", + "privProtocol", + "privKeyType", + "privKey", + "privKeySecret", ] ) serialized = handler(self) @@ -14364,286 +15060,278 @@ def serialize_model(self, handler): try: - CreateInputInputOkta.model_rebuild() -except NameError: - pass -try: - CreateInputActivities.model_rebuild() -except NameError: - pass -try: - CreateInputChats.model_rebuild() + CreateInputInputTrendMicroVisionOne.model_rebuild() except NameError: pass try: - CreateInputProjects.model_rebuild() + CreateInputInputMimecastHec.model_rebuild() except NameError: pass try: - CreateInputChatMessages.model_rebuild() + CreateInputInputHashicorpHcpVaultDedicated.model_rebuild() except NameError: pass try: - CreateInputProjectDetails.model_rebuild() + CreateInputInputBeyondtrustHec.model_rebuild() except NameError: pass try: - CreateInputGroups.model_rebuild() + CreateInputInputF5BigIP.model_rebuild() except NameError: pass try: - CreateInputOrganizations.model_rebuild() + CreateInputInputVectraAiHec.model_rebuild() except NameError: pass try: - CreateInputOrganizationUsers.model_rebuild() + CreateInputInputGigamonHec.model_rebuild() except NameError: pass try: - CreateInputOrganizationRoles.model_rebuild() + CreateInputInputPingIdentityPingone.model_rebuild() except NameError: pass try: - CreateInputInputAnthropicCompliance.model_rebuild() + CreateInputInputAkamaiHec.model_rebuild() except NameError: pass try: - CreateInputInputOpenaiComplianceLogs.model_rebuild() + CreateInputInputOkta.model_rebuild() except NameError: pass try: - CreateInputInputUpwindHec.model_rebuild() + CreateInputRetryRules.model_rebuild() except NameError: pass try: - CreateInputInputSysdigHec.model_rebuild() + CreateInputCertOptions.model_rebuild() except NameError: pass try: - CreateInputTLSSettingsServerSide.model_rebuild() + CreateInputInputMicrosoftCopilot.model_rebuild() except NameError: pass try: - CreateInputInputCloudflareHec.model_rebuild() + CreateInputInputAnthropicEnterpriseAnalyticsContentConfig.model_rebuild() except NameError: pass try: - CreateInputInputZscalerHecAuthToken.model_rebuild() + CreateInputInputAnthropicEnterpriseAnalytics.model_rebuild() except NameError: pass try: - CreateInputInputZscalerHec.model_rebuild() + CreateInputActivities.model_rebuild() except NameError: pass try: - CreateInputInputServicenowTable.model_rebuild() + CreateInputChats.model_rebuild() except NameError: pass try: - CreateInputInputBedrockS3.model_rebuild() + CreateInputProjects.model_rebuild() except NameError: pass try: - CreateInputInputSecurityLake.model_rebuild() + CreateInputChatMessages.model_rebuild() except NameError: pass try: - CreateInputInputNetflow.model_rebuild() + CreateInputProjectDetails.model_rebuild() except NameError: pass try: - CreateInputInputWizWebhook.model_rebuild() + CreateInputGroups.model_rebuild() except NameError: pass try: - CreateInputInputOpenaiContentConfig.model_rebuild() + CreateInputOrganizations.model_rebuild() except NameError: pass try: - CreateInputInputOpenai.model_rebuild() + CreateInputOrganizationUsers.model_rebuild() except NameError: pass try: - CreateInputInputWizContentConfig.model_rebuild() + CreateInputOrganizationRoles.model_rebuild() except NameError: pass try: - CreateInputInputWiz.model_rebuild() + CreateInputInputAnthropicCompliance.model_rebuild() except NameError: pass try: - CreateInputInputJournalFilesRule.model_rebuild() + CreateInputInputOpenaiComplianceLogs.model_rebuild() except NameError: pass try: - CreateInputInputJournalFiles.model_rebuild() + CreateInputInputAquaSecurityHec.model_rebuild() except NameError: pass try: - CreateInputInputRawUDP.model_rebuild() + CreateInputInputExtrahopRevealx360.model_rebuild() except NameError: pass try: - CreateInputInputAppleUnifiedLogs.model_rebuild() + CreateInputInputSailpointHec.model_rebuild() except NameError: pass try: - CreateInputInputWinEventLogs.model_rebuild() + CreateInputInputTrellixHec.model_rebuild() except NameError: pass try: - CreateInputMTLSSettings.model_rebuild() + CreateInputInputUpwindHec.model_rebuild() except NameError: pass try: - CreateInputQuery.model_rebuild() + CreateInputInputSysdigHec.model_rebuild() except NameError: pass try: - CreateInputSubscription.model_rebuild() + CreateInputTLSSettingsServerSide.model_rebuild() except NameError: pass try: - CreateInputInputWef.model_rebuild() + CreateInputInputCloudflareHec.model_rebuild() except NameError: pass try: - CreateInputInputAppscopeFilter.model_rebuild() + CreateInputInputZscalerHecAuthToken.model_rebuild() except NameError: pass try: - CreateInputInputAppscopePersistence.model_rebuild() + CreateInputInputZscalerHec.model_rebuild() except NameError: pass try: - CreateInputInputAppscope.model_rebuild() + CreateInputInputProofpointPod.model_rebuild() except NameError: pass try: - CreateInputInputTCP.model_rebuild() + CreateInputInputServicenowTable.model_rebuild() except NameError: pass try: - CreateInputInputFile.model_rebuild() + CreateInputInputBedrockS3.model_rebuild() except NameError: pass try: - CreateInputInputSyslogSyslog2.model_rebuild() + CreateInputInputSecurityLake.model_rebuild() except NameError: pass try: - CreateInputInputSyslogSyslog1.model_rebuild() + CreateInputInputNetflow.model_rebuild() except NameError: pass try: - CreateInputInputSqs.model_rebuild() + CreateInputInputWizWebhookAuthTokensExt2.model_rebuild() except NameError: pass try: - CreateInputInputModelDrivenTelemetry.model_rebuild() + CreateInputInputWizWebhookAuthTokensExt1.model_rebuild() except NameError: pass try: - CreateInputAuthMethodsExt.model_rebuild() + CreateInputInputWizWebhook.model_rebuild() except NameError: pass try: - CreateInputInputOpenTelemetry.model_rebuild() + CreateInputInputOpenaiContentConfig.model_rebuild() except NameError: pass try: - CreateInputV3User.model_rebuild() + CreateInputInputOpenai.model_rebuild() except NameError: pass try: - CreateInputSNMPv3Authentication.model_rebuild() + CreateInputInputWizContentConfig.model_rebuild() except NameError: pass try: - CreateInputInputSnmp.model_rebuild() + CreateInputInputWiz.model_rebuild() except NameError: pass try: - CreateInputInputS3Inventory.model_rebuild() + CreateInputInputJournalFilesRule.model_rebuild() except NameError: pass try: - CreateInputInputS3.model_rebuild() + CreateInputInputJournalFiles.model_rebuild() except NameError: pass try: - CreateInputInputMetrics.model_rebuild() + CreateInputInputRawUDP.model_rebuild() except NameError: pass try: - CreateInputInputCriblmetrics.model_rebuild() + CreateInputInputAppleUnifiedLogs.model_rebuild() except NameError: pass try: - CreateInputInputKinesis.model_rebuild() + CreateInputInputWinEventLogs.model_rebuild() except NameError: pass try: - CreateInputInputHTTPRaw.model_rebuild() + CreateInputMTLSSettings.model_rebuild() except NameError: pass try: - CreateInputSample.model_rebuild() + CreateInputQuery.model_rebuild() except NameError: pass try: - CreateInputInputDatagen.model_rebuild() + CreateInputSubscription.model_rebuild() except NameError: pass try: - CreateInputInputDatadogAgentProxyMode.model_rebuild() + CreateInputInputWef.model_rebuild() except NameError: pass try: - CreateInputInputDatadogAgent.model_rebuild() + CreateInputInputAppscopeFilter.model_rebuild() except NameError: pass try: - CreateInputInputCrowdstrike.model_rebuild() + CreateInputInputAppscopePersistence.model_rebuild() except NameError: pass try: - CreateInputInputWindowsMetricsCPU.model_rebuild() + CreateInputInputAppscope.model_rebuild() except NameError: pass try: - CreateInputInputWindowsMetricsNetwork.model_rebuild() + CreateInputInputTCP.model_rebuild() except NameError: pass try: - CreateInputInputWindowsMetricsDisk.model_rebuild() + CreateInputInputFile.model_rebuild() except NameError: pass try: - CreateInputInputWindowsMetricsPersistence.model_rebuild() + CreateInputInputSyslogSyslog2.model_rebuild() except NameError: pass try: - CreateInputInputWindowsMetrics.model_rebuild() + CreateInputInputSyslogSyslog1.model_rebuild() except NameError: pass try: - CreateInputInputKubeEvents.model_rebuild() + CreateInputInputSqs.model_rebuild() except NameError: pass try: - CreateInputInputKubeLogsRule.model_rebuild() + CreateInputInputModelDrivenTelemetry.model_rebuild() except NameError: pass try: - CreateInputInputKubeLogs.model_rebuild() + CreateInputAuthMethodsExt.model_rebuild() except NameError: pass try: - CreateInputInputKubeMetricsPersistence.model_rebuild() + CreateInputInputOpenTelemetry.model_rebuild() except NameError: pass try: - CreateInputInputKubeMetrics.model_rebuild() + CreateInputV3User.model_rebuild() except NameError: pass diff --git a/src/cribl_control_plane/models/createinputsystembypack_inputelastic_type.py b/src/cribl_control_plane/models/createinputsystembypack_inputelastic_type.py new file mode 100644 index 000000000..94ea726e0 --- /dev/null +++ b/src/cribl_control_plane/models/createinputsystembypack_inputelastic_type.py @@ -0,0 +1,13972 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, +) +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, +) +from .authenticationmethodoptionsmanualsecret import ( + AuthenticationMethodOptionsManualSecret, +) +from .authenticationmethodoptionss3collectorconf import ( + AuthenticationMethodOptionsS3CollectorConf, +) +from .authenticationmethodoptionssasl import AuthenticationMethodOptionsSasl +from .authenticationtype import AuthenticationType, AuthenticationTypeTypedDict +from .authenticationtypeoptionslokiauth import AuthenticationTypeOptionsLokiAuth +from .authenticationtypeoptionsprometheusauth import ( + AuthenticationTypeOptionsPrometheusAuth, +) +from .authenticationtypeuse import AuthenticationTypeUse, AuthenticationTypeUseTypedDict +from .authtokenconfinputcribltcp import ( + AuthTokenConfInputCriblTCP, + AuthTokenConfInputCriblTCPTypedDict, +) +from .certificatetype import CertificateType, CertificateTypeTypedDict +from .certoptionstype import CertOptionsType, CertOptionsTypeTypedDict +from .checkpointingtype import CheckpointingType, CheckpointingTypeTypedDict +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .createinputsystembypack_v3user import ( + CreateInputSystemByPackV3User, + CreateInputSystemByPackV3UserTypedDict, +) +from .datacompressionformatoptionspersistence import ( + DataCompressionFormatOptionsPersistence, +) +from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict +from .googleauthenticationmethodoptions import GoogleAuthenticationMethodOptions +from .gputype import GpuType, GpuTypeTypedDict +from .kafkaschemaregistryauthenticationtype import ( + KafkaSchemaRegistryAuthenticationType, + KafkaSchemaRegistryAuthenticationTypeTypedDict, +) +from .logleveloptions import LogLevelOptions +from .logleveloptionscontentconfigitems import LogLevelOptionsContentConfigItems +from .logleveloptionsdebugerror import LogLevelOptionsDebugError +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .microsoftentraidauthenticationendpointoptionssasl import ( + MicrosoftEntraIDAuthenticationEndpointOptionsSasl, +) +from .modeoptionshost import ModeOptionsHost +from .pqtype import PqType, PqTypeTypedDict +from .preprocesstype import PreprocessType, PreprocessTypeTypedDict +from .processtype import ProcessType, ProcessTypeTypedDict +from .protocoloptionstargetsitems import ProtocolOptionsTargetsItems +from .recordtypeoptions import RecordTypeOptions +from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( + RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, +) +from .retryrulestypecodesenableheader import ( + RetryRulesTypeCodesEnableHeader, + RetryRulesTypeCodesEnableHeaderTypedDict, +) +from .ruleconfinputkubemetrics import ( + RuleConfInputKubeMetrics, + RuleConfInputKubeMetricsTypedDict, +) +from .searchfilterconfinputprometheus import ( + SearchFilterConfInputPrometheus, + SearchFilterConfInputPrometheusTypedDict, +) +from .sqsauthenticationmethodoptions import SqsAuthenticationMethodOptions +from .subscriptionplanoptions import SubscriptionPlanOptions +from .tagafterprocessingoptions import TagAfterProcessingOptions +from .tlssettingsclientsidetype import ( + TLSSettingsClientSideType, + TLSSettingsClientSideTypeTypedDict, +) +from .tlssettingsclientsidetypecapathcertpath import ( + TLSSettingsClientSideTypeCaPathCertPath, + TLSSettingsClientSideTypeCaPathCertPathTypedDict, +) +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from .typeoptionsconfluentcloud import TypeOptionsConfluentcloud +from .typeoptionscribltcp import TypeOptionsCribltcp +from .typeoptionsgooglepubsub import TypeOptionsGooglepubsub +from .typeoptionskinesis import TypeOptionsKinesis +from .typeoptionsprometheus import TypeOptionsPrometheus +from .typeoptionss3 import TypeOptionsS3 +from .typeoptionssnmp import TypeOptionsSnmp +from .typeoptionstcpjson import TypeOptionsTcpjson +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class CreateInputSystemByPackSNMPv3AuthenticationTypedDict(TypedDict): + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + v3_auth_enabled: bool + r"""Enabled""" + allow_unmatched_trap: NotRequired[bool] + r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" + v3_users: NotRequired[List[CreateInputSystemByPackV3UserTypedDict]] + r"""User credentials for receiving v3 traps""" + + +class CreateInputSystemByPackSNMPv3Authentication(BaseModel): + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + v3_auth_enabled: Annotated[bool, pydantic.Field(alias="v3AuthEnabled")] + r"""Enabled""" + + allow_unmatched_trap: Annotated[ + Optional[bool], pydantic.Field(alias="allowUnmatchedTrap") + ] = None + r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" + + v3_users: Annotated[ + Optional[List[CreateInputSystemByPackV3User]], pydantic.Field(alias="v3Users") + ] = None + r"""User credentials for receiving v3 traps""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["allowUnmatchedTrap", "v3Users"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSnmpTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsSnmp + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""UDP port to receive SNMP traps on. Defaults to 162.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + snmp_v3_auth: NotRequired[CreateInputSystemByPackSNMPv3AuthenticationTypedDict] + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + varbinds_with_types: NotRequired[bool] + r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + best_effort_parsing: NotRequired[bool] + r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputSystemByPackInputSnmp(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsSnmp + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + + port: float + r"""UDP port to receive SNMP traps on. Defaults to 162.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + snmp_v3_auth: Annotated[ + Optional[CreateInputSystemByPackSNMPv3Authentication], + pydantic.Field(alias="snmpV3Auth"), + ] = None + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking.""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + varbinds_with_types: Annotated[ + Optional[bool], pydantic.Field(alias="varbindsWithTypes") + ] = None + r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + + best_effort_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="bestEffortParsing") + ] = None + r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "snmpV3Auth", + "maxBufferSize", + "ipWhitelistRegex", + "metadata", + "udpSocketRxBufSize", + "varbindsWithTypes", + "bestEffortParsing", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputS3InventoryType(str, Enum): + r"""Connector type identifier.""" + + S3_INVENTORY = "s3_inventory" + + +class CreateInputSystemByPackInputS3InventoryTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputS3InventoryType + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + checksum_suffix: NotRequired[str] + r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ + max_manifest_size_kb: NotRequired[int] + r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" + validate_inventory_files: NotRequired[bool] + r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + +class CreateInputSystemByPackInputS3Inventory(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputS3InventoryType + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + checksum_suffix: Annotated[ + Optional[str], pydantic.Field(alias="checksumSuffix") + ] = None + r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ + + max_manifest_size_kb: Annotated[ + Optional[int], pydantic.Field(alias="maxManifestSizeKB") + ] = None + r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" + + validate_inventory_files: Annotated[ + Optional[bool], pydantic.Field(alias="validateInventoryFiles") + ] = None + r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "checksumSuffix", + "maxManifestSizeKB", + "validateInventoryFiles", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputS3TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsS3 + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + tag_after_processing: NotRequired[bool] + r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + +class CreateInputSystemByPackInputS3(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsS3 + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + + tag_after_processing: Annotated[ + Optional[bool], pydantic.Field(alias="tagAfterProcessing") + ] = None + r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "encoding", + "tagAfterProcessing", + "autoParse", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputMetricsType(str, Enum): + r"""Connector type identifier.""" + + METRICS = "metrics" + + +class CreateInputSystemByPackInputMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputMetricsType + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + udp_port: NotRequired[float] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + tcp_port: NotRequired[float] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + + +class CreateInputSystemByPackInputMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputMetricsType + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + + tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "udpPort", + "tcpPort", + "maxBufferSize", + "ipWhitelistRegex", + "enableProxyHeader", + "tls", + "metadata", + "udpSocketRxBufSize", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCriblmetricsType(str, Enum): + r"""Connector type identifier.""" + + CRIBLMETRICS = "criblmetrics" + + +class CreateInputSystemByPackInputCriblmetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputCriblmetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + prefix: NotRequired[str] + r"""A prefix that is applied to the metrics provided by Cribl Stream""" + full_fidelity: NotRequired[bool] + r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputCriblmetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputCriblmetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + prefix: Optional[str] = None + r"""A prefix that is applied to the metrics provided by Cribl Stream""" + + full_fidelity: Annotated[Optional[bool], pydantic.Field(alias="fullFidelity")] = ( + None + ) + r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "prefix", + "fullFidelity", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackShardIteratorStart( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Location at which to start reading a shard for the first time""" + + # Earliest record + TRIM_HORIZON = "TRIM_HORIZON" + # Latest record + LATEST = "LATEST" + + +class CreateInputSystemByPackRecordDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + + # Cribl + CRIBL = "cribl" + # Newline JSON + NDJSON = "ndjson" + # Cloudwatch Logs + CLOUDWATCH = "cloudwatch" + # Event per line + LINE = "line" + + +class CreateInputSystemByPackShardLoadBalancing( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + + # Consistent Hashing + CONSISTENT_HASHING = "ConsistentHashing" + # Round Robin + ROUND_ROBIN = "RoundRobin" + + +class CreateInputSystemByPackInputKinesisTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsKinesis + r"""Connector type identifier.""" + stream_name: str + r"""Kinesis Data Stream to read data from""" + region: str + r"""Region where the Kinesis stream is located""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + service_interval: NotRequired[float] + r"""Time interval in minutes between consecutive service calls""" + shard_expr: NotRequired[str] + r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + shard_iterator_type: NotRequired[CreateInputSystemByPackShardIteratorStart] + r"""Location at which to start reading a shard for the first time""" + payload_format: NotRequired[CreateInputSystemByPackRecordDataFormat] + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + get_records_limit: NotRequired[float] + r"""Maximum number of records per getRecords call""" + get_records_limit_total: NotRequired[float] + r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + load_balancing_algorithm: NotRequired[CreateInputSystemByPackShardLoadBalancing] + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Kinesis stream""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + verify_kpl_check_sums: NotRequired[bool] + r"""Verify Kinesis Producer Library (KPL) event checksums""" + avoid_duplicates: NotRequired[bool] + r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + template_shard_iterator_type: NotRequired[str] + r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + template_payload_format: NotRequired[str] + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + +class CreateInputSystemByPackInputKinesis(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsKinesis + r"""Connector type identifier.""" + + stream_name: Annotated[str, pydantic.Field(alias="streamName")] + r"""Kinesis Data Stream to read data from""" + + region: str + r"""Region where the Kinesis stream is located""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + service_interval: Annotated[ + Optional[float], pydantic.Field(alias="serviceInterval") + ] = None + r"""Time interval in minutes between consecutive service calls""" + + shard_expr: Annotated[Optional[str], pydantic.Field(alias="shardExpr")] = None + r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + + shard_iterator_type: Annotated[ + Optional[CreateInputSystemByPackShardIteratorStart], + pydantic.Field(alias="shardIteratorType"), + ] = None + r"""Location at which to start reading a shard for the first time""" + + payload_format: Annotated[ + Optional[CreateInputSystemByPackRecordDataFormat], + pydantic.Field(alias="payloadFormat"), + ] = None + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + + get_records_limit: Annotated[ + Optional[float], pydantic.Field(alias="getRecordsLimit") + ] = None + r"""Maximum number of records per getRecords call""" + + get_records_limit_total: Annotated[ + Optional[float], pydantic.Field(alias="getRecordsLimitTotal") + ] = None + r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + + load_balancing_algorithm: Annotated[ + Optional[CreateInputSystemByPackShardLoadBalancing], + pydantic.Field(alias="loadBalancingAlgorithm"), + ] = None + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + endpoint: Optional[str] = None + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Kinesis stream""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + verify_kpl_check_sums: Annotated[ + Optional[bool], pydantic.Field(alias="verifyKPLCheckSums") + ] = None + r"""Verify Kinesis Producer Library (KPL) event checksums""" + + avoid_duplicates: Annotated[ + Optional[bool], pydantic.Field(alias="avoidDuplicates") + ] = None + r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") + ] = None + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + + template_shard_iterator_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_shardIteratorType") + ] = None + r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + + template_payload_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadFormat") + ] = None + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("shard_iterator_type") + def serialize_shard_iterator_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackShardIteratorStart(value) + except ValueError: + return value + return value + + @field_serializer("payload_format") + def serialize_payload_format(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackRecordDataFormat(value) + except ValueError: + return value + return value + + @field_serializer("load_balancing_algorithm") + def serialize_load_balancing_algorithm(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackShardLoadBalancing(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "serviceInterval", + "shardExpr", + "shardIteratorType", + "payloadFormat", + "getRecordsLimit", + "getRecordsLimitTotal", + "loadBalancingAlgorithm", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "verifyKPLCheckSums", + "avoidDuplicates", + "metadata", + "autoParse", + "description", + "awsApiKey", + "awsSecret", + "__template_environment", + "__template_streamtags", + "__template_streamName", + "__template_shardIteratorType", + "__template_payloadFormat", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputHTTPRawType(str, Enum): + r"""Source type identifier.""" + + HTTP_RAW = "http_raw" + + +class CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict( + TypedDict +): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputHTTPRawAuthTokensExtTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputSystemByPackInputHTTPRawAuthTokensExt(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateInputSystemByPackInputHTTPRawAuthTokensExtUnionTypedDict = TypeAliasType( + "CreateInputSystemByPackInputHTTPRawAuthTokensExtUnionTypedDict", + Union[ + CreateInputSystemByPackInputHTTPRawAuthTokensExtTypedDict, + CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion = TypeAliasType( + "CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion", + Union[ + CreateInputSystemByPackInputHTTPRawAuthTokensExt, + CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint, + ], +) + + +class CreateInputSystemByPackInputHTTPRawTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputHTTPRawType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + allowed_paths: NotRequired[List[str]] + r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" + allowed_methods: NotRequired[List[str]] + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + auth_tokens_ext: NotRequired[ + List[CreateInputSystemByPackInputHTTPRawAuthTokensExtUnionTypedDict] + ] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + access_control_allow_methods: NotRequired[List[str]] + r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + access_control_expose_headers: NotRequired[List[str]] + r"""Headers the browser is allowed to access from the response""" + access_control_allow_credentials: NotRequired[bool] + r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + access_control_max_age: NotRequired[float] + r"""How long browsers should cache the preflight response""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_allowed_paths: NotRequired[str] + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class CreateInputSystemByPackInputHTTPRaw(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputHTTPRawType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + allowed_paths: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedPaths") + ] = None + r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" + + allowed_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedMethods") + ] = None + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + + auth_tokens_ext: Annotated[ + Optional[List[CreateInputSystemByPackInputHTTPRawAuthTokensExtUnion]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + + access_control_allow_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowMethods") + ] = None + r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + + access_control_expose_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlExposeHeaders") + ] = None + r"""Headers the browser is allowed to access from the response""" + + access_control_allow_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="accessControlAllowCredentials") + ] = None + r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + + access_control_max_age: Annotated[ + Optional[float], pydantic.Field(alias="accessControlMaxAge") + ] = None + r"""How long browsers should cache the preflight response""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + template_allowed_paths: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedPaths") + ] = None + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "metadata", + "allowedPaths", + "allowedMethods", + "authTokensExt", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "accessControlAllowMethods", + "accessControlExposeHeaders", + "accessControlAllowCredentials", + "accessControlMaxAge", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + "__template_allowedPaths", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputDatagenType(str, Enum): + r"""Connector type identifier.""" + + DATAGEN = "datagen" + + +class CreateInputSystemByPackSampleTypedDict(TypedDict): + sample: str + r"""Data Generator File Name""" + events_per_sec: float + r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" + + +class CreateInputSystemByPackSample(BaseModel): + sample: str + r"""Data Generator File Name""" + + events_per_sec: Annotated[float, pydantic.Field(alias="eventsPerSec")] + r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" + + +class CreateInputSystemByPackInputDatagenTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputDatagenType + r"""Connector type identifier.""" + samples: List[CreateInputSystemByPackSampleTypedDict] + r"""Datagens""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputDatagen(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputDatagenType + r"""Connector type identifier.""" + + samples: List[CreateInputSystemByPackSample] + r"""Datagens""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputDatadogAgentType(str, Enum): + r"""Source type identifier.""" + + DATADOG_AGENT = "datadog_agent" + + +class CreateInputSystemByPackSamplingRuleTypedDict(TypedDict): + service: str + r"""Datadog service name""" + environment: str + r"""Datadog environment name (example: prod, staging)""" + rate: float + r"""Sampling rate for this service/environment combination (0.0–1.0)""" + + +class CreateInputSystemByPackSamplingRule(BaseModel): + service: str + r"""Datadog service name""" + + environment: str + r"""Datadog environment name (example: prod, staging)""" + + rate: float + r"""Sampling rate for this service/environment combination (0.0–1.0)""" + + +class CreateInputSystemByPackInputDatadogAgentProxyModeTypedDict(TypedDict): + enabled: bool + r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" + reject_unauthorized: NotRequired[bool] + r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + + +class CreateInputSystemByPackInputDatadogAgentProxyMode(BaseModel): + enabled: bool + r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["rejectUnauthorized"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputDatadogAgentTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputDatadogAgentType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + extract_metrics: NotRequired[bool] + r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + sampling_rate: NotRequired[float] + r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + sampling_rules: NotRequired[List[CreateInputSystemByPackSamplingRuleTypedDict]] + r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + proxy_mode: NotRequired[CreateInputSystemByPackInputDatadogAgentProxyModeTypedDict] + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputSystemByPackInputDatadogAgent(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputDatadogAgentType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + extract_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="extractMetrics") + ] = None + r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + + sampling_rate: Annotated[Optional[float], pydantic.Field(alias="samplingRate")] = ( + None + ) + r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + + sampling_rules: Annotated[ + Optional[List[CreateInputSystemByPackSamplingRule]], + pydantic.Field(alias="samplingRules"), + ] = None + r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + proxy_mode: Annotated[ + Optional[CreateInputSystemByPackInputDatadogAgentProxyMode], + pydantic.Field(alias="proxyMode"), + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "extractMetrics", + "samplingRate", + "samplingRules", + "metadata", + "proxyMode", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCrowdstrikeType(str, Enum): + r"""Connector type identifier.""" + + CROWDSTRIKE = "crowdstrike" + + +class CreateInputSystemByPackInputCrowdstrikeTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputCrowdstrikeType + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + +class CreateInputSystemByPackInputCrowdstrike(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputCrowdstrikeType + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "checkpointing", + "pollTimeout", + "encoding", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsType(str, Enum): + r"""Connector type identifier.""" + + WINDOWS_METRICS = "windows_metrics" + + +class CreateInputSystemByPackInputWindowsMetricsSystemMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for system metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputWindowsMetricsSystemTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsSystemMode] + r"""Select the level of details for system metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all system information""" + + +class CreateInputSystemByPackInputWindowsMetricsSystem(BaseModel): + mode: Optional[CreateInputSystemByPackInputWindowsMetricsSystemMode] = None + r"""Select the level of details for system metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all system information""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputWindowsMetricsSystemMode( + value + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsCPUMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for CPU metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputWindowsMetricsCPUTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsCPUMode] + r"""Select the level of details for CPU metrics""" + per_cpu: NotRequired[bool] + r"""Generate metrics for each CPU""" + detail: NotRequired[bool] + r"""Generate metrics for all CPU states""" + time: NotRequired[bool] + r"""Generate raw, monotonic CPU time counters""" + + +class CreateInputSystemByPackInputWindowsMetricsCPU(BaseModel): + mode: Optional[CreateInputSystemByPackInputWindowsMetricsCPUMode] = None + r"""Select the level of details for CPU metrics""" + + per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None + r"""Generate metrics for each CPU""" + + detail: Optional[bool] = None + r"""Generate metrics for all CPU states""" + + time: Optional[bool] = None + r"""Generate raw, monotonic CPU time counters""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputWindowsMetricsCPUMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perCpu", "detail", "time"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsMemoryMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for memory metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputWindowsMetricsMemoryTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsMemoryMode] + r"""Select the level of details for memory metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all memory states""" + + +class CreateInputSystemByPackInputWindowsMetricsMemory(BaseModel): + mode: Optional[CreateInputSystemByPackInputWindowsMetricsMemoryMode] = None + r"""Select the level of details for memory metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all memory states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputWindowsMetricsMemoryMode( + value + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsNetworkMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for network metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputWindowsMetricsNetworkTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsNetworkMode] + r"""Select the level of details for network metrics""" + detail: NotRequired[bool] + r"""Generate full network metrics""" + protocols: NotRequired[bool] + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + devices: NotRequired[List[str]] + r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + per_interface: NotRequired[bool] + r"""Generate separate metrics for each interface""" + + +class CreateInputSystemByPackInputWindowsMetricsNetwork(BaseModel): + mode: Optional[CreateInputSystemByPackInputWindowsMetricsNetworkMode] = None + r"""Select the level of details for network metrics""" + + detail: Optional[bool] = None + r"""Generate full network metrics""" + + protocols: Optional[bool] = None + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + + devices: Optional[List[str]] = None + r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + + per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + None + ) + r"""Generate separate metrics for each interface""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputWindowsMetricsNetworkMode( + value + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["mode", "detail", "protocols", "devices", "perInterface"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsDiskMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for disk metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputWindowsMetricsDiskTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsDiskMode] + r"""Select the level of details for disk metrics""" + per_volume: NotRequired[bool] + r"""Generate separate metrics for each volume""" + detail: NotRequired[bool] + r"""Generate full disk metrics""" + volumes: NotRequired[List[str]] + r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" + + +class CreateInputSystemByPackInputWindowsMetricsDisk(BaseModel): + mode: Optional[CreateInputSystemByPackInputWindowsMetricsDiskMode] = None + r"""Select the level of details for disk metrics""" + + per_volume: Annotated[Optional[bool], pydantic.Field(alias="perVolume")] = None + r"""Generate separate metrics for each volume""" + + detail: Optional[bool] = None + r"""Generate full disk metrics""" + + volumes: Optional[List[str]] = None + r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputWindowsMetricsDiskMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perVolume", "detail", "volumes"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsCustomTypedDict(TypedDict): + system: NotRequired[CreateInputSystemByPackInputWindowsMetricsSystemTypedDict] + cpu: NotRequired[CreateInputSystemByPackInputWindowsMetricsCPUTypedDict] + memory: NotRequired[CreateInputSystemByPackInputWindowsMetricsMemoryTypedDict] + network: NotRequired[CreateInputSystemByPackInputWindowsMetricsNetworkTypedDict] + disk: NotRequired[CreateInputSystemByPackInputWindowsMetricsDiskTypedDict] + + +class CreateInputSystemByPackInputWindowsMetricsCustom(BaseModel): + system: Optional[CreateInputSystemByPackInputWindowsMetricsSystem] = None + + cpu: Optional[CreateInputSystemByPackInputWindowsMetricsCPU] = None + + memory: Optional[CreateInputSystemByPackInputWindowsMetricsMemory] = None + + network: Optional[CreateInputSystemByPackInputWindowsMetricsNetwork] = None + + disk: Optional[CreateInputSystemByPackInputWindowsMetricsDisk] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["system", "cpu", "memory", "network", "disk"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsHostTypedDict(TypedDict): + mode: NotRequired[ModeOptionsHost] + r"""Select level of detail for host metrics""" + custom: NotRequired[CreateInputSystemByPackInputWindowsMetricsCustomTypedDict] + + +class CreateInputSystemByPackInputWindowsMetricsHost(BaseModel): + mode: Optional[ModeOptionsHost] = None + r"""Select level of detail for host metrics""" + + custom: Optional[CreateInputSystemByPackInputWindowsMetricsCustom] = None + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptionsHost(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "custom"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + + +class CreateInputSystemByPackInputWindowsMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputWindowsMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputWindowsMetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + host: NotRequired[CreateInputSystemByPackInputWindowsMetricsHostTypedDict] + process: NotRequired[ProcessTypeTypedDict] + gpu: NotRequired[GpuTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[ + CreateInputSystemByPackInputWindowsMetricsPersistenceTypedDict + ] + r"""persistence""" + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputWindowsMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputWindowsMetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + + host: Optional[CreateInputSystemByPackInputWindowsMetricsHost] = None + + process: Optional[ProcessType] = None + + gpu: Optional[GpuType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[CreateInputSystemByPackInputWindowsMetricsPersistence] = None + r"""persistence""" + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "host", + "process", + "gpu", + "metadata", + "persistence", + "disableNativeModule", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputKubeEventsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_EVENTS = "kube_events" + + +class CreateInputSystemByPackInputKubeEventsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputKubeEventsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] + r"""Filtering on event fields""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputKubeEvents(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputKubeEventsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + rules: Optional[List[RuleConfInputKubeMetrics]] = None + r"""Filtering on event fields""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "rules", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputKubeLogsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_LOGS = "kube_logs" + + +class CreateInputSystemByPackInputKubeLogsRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class CreateInputSystemByPackInputKubeLogsRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputKubeLogsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputKubeLogsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + rules: NotRequired[List[CreateInputSystemByPackInputKubeLogsRuleTypedDict]] + r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + timestamps: NotRequired[bool] + r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + line_buffer_limit: NotRequired[float] + r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + lb_disable_assembly: NotRequired[bool] + r"""Internal flag to disable LB worker payload reassembly.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[DiskSpoolingTypeTypedDict] + r"""Disk Spooling""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputKubeLogs(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputKubeLogsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + + rules: Optional[List[CreateInputSystemByPackInputKubeLogsRule]] = None + r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + + timestamps: Optional[bool] = None + r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + + line_buffer_limit: Annotated[ + Optional[float], pydantic.Field(alias="lineBufferLimit") + ] = None + r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + + lb_disable_assembly: Annotated[ + Optional[bool], pydantic.Field(alias="__LBDisableAssembly") + ] = None + r"""Internal flag to disable LB worker payload reassembly.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[DiskSpoolingType] = None + r"""Disk Spooling""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "rules", + "timestamps", + "lineBufferLimit", + "__LBDisableAssembly", + "metadata", + "persistence", + "breakerRulesets", + "staleChannelFlushMs", + "enableLoadBalancing", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputKubeMetricsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_METRICS = "kube_metrics" + + +class CreateInputSystemByPackInputKubeMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics on disk for Cribl Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + + +class CreateInputSystemByPackInputKubeMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics on disk for Cribl Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputKubeMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputKubeMetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + scrape_kubelet: NotRequired[bool] + r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + scrape_cadvisor: NotRequired[bool] + r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] + r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[ + CreateInputSystemByPackInputKubeMetricsPersistenceTypedDict + ] + r"""persistence""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputKubeMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputKubeMetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + + scrape_kubelet: Annotated[Optional[bool], pydantic.Field(alias="scrapeKubelet")] = ( + None + ) + r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + + scrape_cadvisor: Annotated[ + Optional[bool], pydantic.Field(alias="scrapeCadvisor") + ] = None + r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + + rules: Optional[List[RuleConfInputKubeMetrics]] = None + r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[CreateInputSystemByPackInputKubeMetricsPersistence] = None + r"""persistence""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "scrapeKubelet", + "scrapeCadvisor", + "rules", + "metadata", + "persistence", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemStateType(str, Enum): + r"""Connector type identifier.""" + + SYSTEM_STATE = "system_state" + + +class CreateInputSystemByPackHostsFileTypedDict(TypedDict): + r"""Creates events based on entries collected from the hosts file""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackHostsFile(BaseModel): + r"""Creates events based on entries collected from the hosts file""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInterfacesTypedDict(TypedDict): + r"""Creates events for each of the host’s network interfaces""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackInterfaces(BaseModel): + r"""Creates events for each of the host’s network interfaces""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackDisksAndFileSystemsTypedDict(TypedDict): + r"""Creates events for physical disks, partitions, and file systems""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackDisksAndFileSystems(BaseModel): + r"""Creates events for physical disks, partitions, and file systems""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackHostInfoTypedDict(TypedDict): + r"""Creates events based on the host system’s current state""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackHostInfo(BaseModel): + r"""Creates events based on the host system’s current state""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackRoutesTypedDict(TypedDict): + r"""Creates events based on entries collected from the host’s network routes""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackRoutes(BaseModel): + r"""Creates events based on entries collected from the host’s network routes""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackDNSTypedDict(TypedDict): + r"""Creates events for DNS resolvers and search entries""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackDNS(BaseModel): + r"""Creates events for DNS resolvers and search entries""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackUsersAndGroupsTypedDict(TypedDict): + r"""Creates events for local users and groups""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackUsersAndGroups(BaseModel): + r"""Creates events for local users and groups""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackFirewallTypedDict(TypedDict): + r"""Creates events for Firewall rules entries""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackFirewall(BaseModel): + r"""Creates events for Firewall rules entries""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackServicesTypedDict(TypedDict): + r"""Creates events from the list of services""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackServices(BaseModel): + r"""Creates events from the list of services""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackListeningPortsTypedDict(TypedDict): + r"""Creates events from list of listening ports""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackListeningPorts(BaseModel): + r"""Creates events from list of listening ports""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackLoggedInUsersTypedDict(TypedDict): + r"""Creates events from list of logged-in users""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackLoggedInUsers(BaseModel): + r"""Creates events from list of logged-in users""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackCollectorsTypedDict(TypedDict): + hostsfile: NotRequired[CreateInputSystemByPackHostsFileTypedDict] + r"""Creates events based on entries collected from the hosts file""" + interfaces: NotRequired[CreateInputSystemByPackInterfacesTypedDict] + r"""Creates events for each of the host’s network interfaces""" + disk: NotRequired[CreateInputSystemByPackDisksAndFileSystemsTypedDict] + r"""Creates events for physical disks, partitions, and file systems""" + metadata: NotRequired[CreateInputSystemByPackHostInfoTypedDict] + r"""Creates events based on the host system’s current state""" + routes: NotRequired[CreateInputSystemByPackRoutesTypedDict] + r"""Creates events based on entries collected from the host’s network routes""" + dns: NotRequired[CreateInputSystemByPackDNSTypedDict] + r"""Creates events for DNS resolvers and search entries""" + user: NotRequired[CreateInputSystemByPackUsersAndGroupsTypedDict] + r"""Creates events for local users and groups""" + firewall: NotRequired[CreateInputSystemByPackFirewallTypedDict] + r"""Creates events for Firewall rules entries""" + services: NotRequired[CreateInputSystemByPackServicesTypedDict] + r"""Creates events from the list of services""" + ports: NotRequired[CreateInputSystemByPackListeningPortsTypedDict] + r"""Creates events from list of listening ports""" + login_users: NotRequired[CreateInputSystemByPackLoggedInUsersTypedDict] + r"""Creates events from list of logged-in users""" + + +class CreateInputSystemByPackCollectors(BaseModel): + hostsfile: Optional[CreateInputSystemByPackHostsFile] = None + r"""Creates events based on entries collected from the hosts file""" + + interfaces: Optional[CreateInputSystemByPackInterfaces] = None + r"""Creates events for each of the host’s network interfaces""" + + disk: Optional[CreateInputSystemByPackDisksAndFileSystems] = None + r"""Creates events for physical disks, partitions, and file systems""" + + metadata: Optional[CreateInputSystemByPackHostInfo] = None + r"""Creates events based on the host system’s current state""" + + routes: Optional[CreateInputSystemByPackRoutes] = None + r"""Creates events based on entries collected from the host’s network routes""" + + dns: Optional[CreateInputSystemByPackDNS] = None + r"""Creates events for DNS resolvers and search entries""" + + user: Optional[CreateInputSystemByPackUsersAndGroups] = None + r"""Creates events for local users and groups""" + + firewall: Optional[CreateInputSystemByPackFirewall] = None + r"""Creates events for Firewall rules entries""" + + services: Optional[CreateInputSystemByPackServices] = None + r"""Creates events from the list of services""" + + ports: Optional[CreateInputSystemByPackListeningPorts] = None + r"""Creates events from list of listening ports""" + + login_users: Annotated[ + Optional[CreateInputSystemByPackLoggedInUsers], + pydantic.Field(alias="loginUsers"), + ] = None + r"""Creates events from list of logged-in users""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "hostsfile", + "interfaces", + "disk", + "metadata", + "routes", + "dns", + "user", + "firewall", + "services", + "ports", + "loginUsers", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemStatePersistenceTypedDict(TypedDict): + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" + + +class CreateInputSystemByPackInputSystemStatePersistence(BaseModel): + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemStateTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputSystemStateType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + collectors: NotRequired[CreateInputSystemByPackCollectorsTypedDict] + persistence: NotRequired[ + CreateInputSystemByPackInputSystemStatePersistenceTypedDict + ] + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + disable_native_last_log_module: NotRequired[bool] + r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputSystemState(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputSystemStateType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + collectors: Optional[CreateInputSystemByPackCollectors] = None + + persistence: Optional[CreateInputSystemByPackInputSystemStatePersistence] = None + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + + disable_native_last_log_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeLastLogModule") + ] = None + r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "metadata", + "collectors", + "persistence", + "disableNativeModule", + "disableNativeLastLogModule", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsType(str, Enum): + r"""Connector type identifier.""" + + SYSTEM_METRICS = "system_metrics" + + +class CreateInputSystemByPackInputSystemMetricsSystemMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for system metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputSystemMetricsSystemTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputSystemMetricsSystemMode] + r"""Select the level of detail for system metrics""" + processes: NotRequired[bool] + r"""Generate metrics for the numbers of processes in various states""" + + +class CreateInputSystemByPackInputSystemMetricsSystem(BaseModel): + mode: Optional[CreateInputSystemByPackInputSystemMetricsSystemMode] = None + r"""Select the level of detail for system metrics""" + + processes: Optional[bool] = None + r"""Generate metrics for the numbers of processes in various states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputSystemMetricsSystemMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "processes"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsCPUMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for CPU metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputSystemMetricsCPUTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputSystemMetricsCPUMode] + r"""Select the level of detail for CPU metrics""" + per_cpu: NotRequired[bool] + r"""Generate metrics for each CPU""" + detail: NotRequired[bool] + r"""Generate metrics for all CPU states""" + time: NotRequired[bool] + r"""Generate raw, monotonic CPU time counters""" + + +class CreateInputSystemByPackInputSystemMetricsCPU(BaseModel): + mode: Optional[CreateInputSystemByPackInputSystemMetricsCPUMode] = None + r"""Select the level of detail for CPU metrics""" + + per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None + r"""Generate metrics for each CPU""" + + detail: Optional[bool] = None + r"""Generate metrics for all CPU states""" + + time: Optional[bool] = None + r"""Generate raw, monotonic CPU time counters""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputSystemMetricsCPUMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perCpu", "detail", "time"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsMemoryMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for memory metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputSystemMetricsMemoryTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputSystemMetricsMemoryMode] + r"""Select the level of detail for memory metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all memory states""" + + +class CreateInputSystemByPackInputSystemMetricsMemory(BaseModel): + mode: Optional[CreateInputSystemByPackInputSystemMetricsMemoryMode] = None + r"""Select the level of detail for memory metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all memory states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputSystemMetricsMemoryMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsNetworkMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for network metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputSystemMetricsNetworkTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputSystemMetricsNetworkMode] + r"""Select the level of detail for network metrics""" + detail: NotRequired[bool] + r"""Generate full network metrics""" + protocols: NotRequired[bool] + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + devices: NotRequired[List[str]] + r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" + per_interface: NotRequired[bool] + r"""Generate separate metrics for each interface""" + + +class CreateInputSystemByPackInputSystemMetricsNetwork(BaseModel): + mode: Optional[CreateInputSystemByPackInputSystemMetricsNetworkMode] = None + r"""Select the level of detail for network metrics""" + + detail: Optional[bool] = None + r"""Generate full network metrics""" + + protocols: Optional[bool] = None + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + + devices: Optional[List[str]] = None + r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" + + per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + None + ) + r"""Generate separate metrics for each interface""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputSystemMetricsNetworkMode( + value + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["mode", "detail", "protocols", "devices", "perInterface"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsDiskMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for disk metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputSystemMetricsDiskTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackInputSystemMetricsDiskMode] + r"""Select the level of detail for disk metrics""" + detail: NotRequired[bool] + r"""Generate full disk metrics""" + inodes: NotRequired[bool] + r"""Generate filesystem inode metrics""" + devices: NotRequired[List[str]] + r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" + mountpoints: NotRequired[List[str]] + r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" + fstypes: NotRequired[List[str]] + r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" + per_device: NotRequired[bool] + r"""Generate separate metrics for each device""" + + +class CreateInputSystemByPackInputSystemMetricsDisk(BaseModel): + mode: Optional[CreateInputSystemByPackInputSystemMetricsDiskMode] = None + r"""Select the level of detail for disk metrics""" + + detail: Optional[bool] = None + r"""Generate full disk metrics""" + + inodes: Optional[bool] = None + r"""Generate filesystem inode metrics""" + + devices: Optional[List[str]] = None + r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" + + mountpoints: Optional[List[str]] = None + r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" + + fstypes: Optional[List[str]] = None + r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" + + per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None + r"""Generate separate metrics for each device""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputSystemMetricsDiskMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "mode", + "detail", + "inodes", + "devices", + "mountpoints", + "fstypes", + "perDevice", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsCustomTypedDict(TypedDict): + system: NotRequired[CreateInputSystemByPackInputSystemMetricsSystemTypedDict] + cpu: NotRequired[CreateInputSystemByPackInputSystemMetricsCPUTypedDict] + memory: NotRequired[CreateInputSystemByPackInputSystemMetricsMemoryTypedDict] + network: NotRequired[CreateInputSystemByPackInputSystemMetricsNetworkTypedDict] + disk: NotRequired[CreateInputSystemByPackInputSystemMetricsDiskTypedDict] + + +class CreateInputSystemByPackInputSystemMetricsCustom(BaseModel): + system: Optional[CreateInputSystemByPackInputSystemMetricsSystem] = None + + cpu: Optional[CreateInputSystemByPackInputSystemMetricsCPU] = None + + memory: Optional[CreateInputSystemByPackInputSystemMetricsMemory] = None + + network: Optional[CreateInputSystemByPackInputSystemMetricsNetwork] = None + + disk: Optional[CreateInputSystemByPackInputSystemMetricsDisk] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["system", "cpu", "memory", "network", "disk"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsHostTypedDict(TypedDict): + mode: NotRequired[ModeOptionsHost] + r"""Select level of detail for host metrics""" + custom: NotRequired[CreateInputSystemByPackInputSystemMetricsCustomTypedDict] + + +class CreateInputSystemByPackInputSystemMetricsHost(BaseModel): + mode: Optional[ModeOptionsHost] = None + r"""Select level of detail for host metrics""" + + custom: Optional[CreateInputSystemByPackInputSystemMetricsCustom] = None + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptionsHost(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "custom"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackContainerMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for container metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class CreateInputSystemByPackInputSystemMetricsFilterTypedDict(TypedDict): + expr: str + r"""Expression""" + + +class CreateInputSystemByPackInputSystemMetricsFilter(BaseModel): + expr: str + r"""Expression""" + + +class CreateInputSystemByPackContainerTypedDict(TypedDict): + mode: NotRequired[CreateInputSystemByPackContainerMode] + r"""Select the level of detail for container metrics""" + docker_socket: NotRequired[List[str]] + r"""Full paths for Docker's UNIX-domain socket""" + docker_timeout: NotRequired[float] + r"""Timeout, in seconds, for the Docker API""" + filters: NotRequired[List[CreateInputSystemByPackInputSystemMetricsFilterTypedDict]] + r"""Containers matching any of these will be included. All are included if no filters are added.""" + all_containers: NotRequired[bool] + r"""Include stopped and paused containers""" + per_device: NotRequired[bool] + r"""Generate separate metrics for each device""" + detail: NotRequired[bool] + r"""Generate full container metrics""" + + +class CreateInputSystemByPackContainer(BaseModel): + mode: Optional[CreateInputSystemByPackContainerMode] = None + r"""Select the level of detail for container metrics""" + + docker_socket: Annotated[ + Optional[List[str]], pydantic.Field(alias="dockerSocket") + ] = None + r"""Full paths for Docker's UNIX-domain socket""" + + docker_timeout: Annotated[ + Optional[float], pydantic.Field(alias="dockerTimeout") + ] = None + r"""Timeout, in seconds, for the Docker API""" + + filters: Optional[List[CreateInputSystemByPackInputSystemMetricsFilter]] = None + r"""Containers matching any of these will be included. All are included if no filters are added.""" + + all_containers: Annotated[Optional[bool], pydantic.Field(alias="allContainers")] = ( + None + ) + r"""Include stopped and paused containers""" + + per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None + r"""Generate separate metrics for each device""" + + detail: Optional[bool] = None + r"""Generate full container metrics""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackContainerMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "mode", + "dockerSocket", + "dockerTimeout", + "filters", + "allContainers", + "perDevice", + "detail", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" + + +class CreateInputSystemByPackInputSystemMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputSystemMetricsTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputSystemMetricsType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + host: NotRequired[CreateInputSystemByPackInputSystemMetricsHostTypedDict] + process: NotRequired[ProcessTypeTypedDict] + container: NotRequired[CreateInputSystemByPackContainerTypedDict] + gpu: NotRequired[GpuTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[ + CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict + ] + r"""persistence""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputSystemMetrics(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputSystemMetricsType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + + host: Optional[CreateInputSystemByPackInputSystemMetricsHost] = None + + process: Optional[ProcessType] = None + + container: Optional[CreateInputSystemByPackContainer] = None + + gpu: Optional[GpuType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[CreateInputSystemByPackInputSystemMetricsPersistence] = None + r"""persistence""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "host", + "process", + "container", + "gpu", + "metadata", + "persistence", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputTcpjsonTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsTcpjson + r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputSystemByPackInputTcpjson(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsTcpjson + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to establish a connection""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "enableLoadBalancing", + "authType", + "description", + "authToken", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCriblLakeHTTPType(str, Enum): + r"""Source type identifier.""" + + CRIBL_LAKE_HTTP = "cribl_lake_http" + + +class CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""When enabled, the token value is available on events as __hecToken""" + default_dataset: NotRequired[str] + allowed_indexes_at_token: NotRequired[List[str]] + + +class CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata( + BaseModel +): + enabled: Optional[bool] = None + r"""When enabled, the token value is available on events as __hecToken""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""Elasticsearch""" + default_dataset: NotRequired[str] + + +class CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata( + BaseModel +): + enabled: Optional[bool] = None + r"""Elasticsearch""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict( + TypedDict +): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Token""" + description: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + splunk_hec_metadata: NotRequired[ + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict + ] + + +class CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint( + BaseModel +): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Token""" + + description: Optional[str] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + splunk_hec_metadata: Annotated[ + Optional[ + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata + ], + pydantic.Field(alias="splunkHecMetadata"), + ] = None + + elasticsearch_metadata: Annotated[ + Optional[ + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata + ], + pydantic.Field(alias="elasticsearchMetadata"), + ] = None + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "tokenSecret", + "token", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""When enabled, the token value is available on events as __hecToken""" + default_dataset: NotRequired[str] + allowed_indexes_at_token: NotRequired[List[str]] + + +class CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata( + BaseModel +): + enabled: Optional[bool] = None + r"""When enabled, the token value is available on events as __hecToken""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""Elasticsearch""" + default_dataset: NotRequired[str] + + +class CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata( + BaseModel +): + enabled: Optional[bool] = None + r"""Elasticsearch""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict( + TypedDict +): + token: str + r"""Token""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + splunk_hec_metadata: NotRequired[ + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict + ] + + +class CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType( + BaseModel +): + token: str + r"""Token""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + splunk_hec_metadata: Annotated[ + Optional[ + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata + ], + pydantic.Field(alias="splunkHecMetadata"), + ] = None + + elasticsearch_metadata: Annotated[ + Optional[ + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata + ], + pydantic.Field(alias="elasticsearchMetadata"), + ] = None + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "tokenSecret", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExtTypedDict = TypeAliasType( + "CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExtTypedDict", + Union[ + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt = TypeAliasType( + "CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt", + Union[ + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + ], +) + + +class CreateInputSystemByPackInputCriblLakeHTTPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputCriblLakeHTTPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + cribl_api: NotRequired[str] + r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" + elastic_api: NotRequired[str] + r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" + splunk_hec_api: NotRequired[str] + r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" + splunk_hec_acks: NotRequired[bool] + r"""Enable Splunk HEC acknowledgements""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_tokens_ext: NotRequired[ + List[CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExtTypedDict] + ] + r"""Auth tokens""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_cribl_api: NotRequired[str] + r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" + template_elastic_api: NotRequired[str] + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + template_splunk_hec_api: NotRequired[str] + r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" + + +class CreateInputSystemByPackInputCriblLakeHTTP(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputCriblLakeHTTPType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + cribl_api: Annotated[Optional[str], pydantic.Field(alias="criblAPI")] = None + r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" + + elastic_api: Annotated[Optional[str], pydantic.Field(alias="elasticAPI")] = None + r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" + + splunk_hec_api: Annotated[Optional[str], pydantic.Field(alias="splunkHecAPI")] = ( + None + ) + r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" + + splunk_hec_acks: Annotated[ + Optional[bool], pydantic.Field(alias="splunkHecAcks") + ] = None + r"""Enable Splunk HEC acknowledgements""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_tokens_ext: Annotated[ + Optional[List[CreateInputSystemByPackInputCriblLakeHTTPAuthTokensExt]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Auth tokens""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + template_cribl_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_criblAPI") + ] = None + r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" + + template_elastic_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticAPI") + ] = None + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + + template_splunk_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_splunkHecAPI") + ] = None + r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "criblAPI", + "elasticAPI", + "splunkHecAPI", + "splunkHecAcks", + "metadata", + "authTokensExt", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + "__template_criblAPI", + "__template_elasticAPI", + "__template_splunkHecAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCriblHTTPType(str, Enum): + r"""Source type identifier.""" + + CRIBL_HTTP = "cribl_http" + + +class CreateInputSystemByPackInputCriblHTTPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputCriblHTTPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputSystemByPackInputCriblHTTP(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputCriblHTTPType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + ] = None + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCriblTCPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsCribltcp + r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + +class CreateInputSystemByPackInputCriblTCP(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsCribltcp + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + ] = None + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "enableLoadBalancing", + "authTokens", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputCriblType(str, Enum): + r"""Connector type identifier.""" + + CRIBL = "cribl" + + +class CreateInputSystemByPackInputCriblTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputCriblType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + filter_: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputCribl(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputCriblType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "filter", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputGooglePubsubTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsGooglepubsub + r"""Connector type identifier.""" + topic_name: str + r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" + subscription_name: str + r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + monitor_subscription: NotRequired[bool] + r"""Use when the subscription is not created by this Source and topic is not known""" + create_topic: NotRequired[bool] + r"""Create topic if it does not exist""" + create_subscription: NotRequired[bool] + r"""Create subscription if it does not exist""" + region: NotRequired[str] + r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + max_backlog: NotRequired[float] + r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" + concurrency: NotRequired[float] + r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" + request_timeout: NotRequired[float] + r"""Pull request timeout, in milliseconds""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + ordered_delivery: NotRequired[bool] + r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_name: NotRequired[str] + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + template_subscription_name: NotRequired[str] + r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + +class CreateInputSystemByPackInputGooglePubsub(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsGooglepubsub + r"""Connector type identifier.""" + + topic_name: Annotated[str, pydantic.Field(alias="topicName")] + r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" + + subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] + r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + monitor_subscription: Annotated[ + Optional[bool], pydantic.Field(alias="monitorSubscription") + ] = None + r"""Use when the subscription is not created by this Source and topic is not known""" + + create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None + r"""Create topic if it does not exist""" + + create_subscription: Annotated[ + Optional[bool], pydantic.Field(alias="createSubscription") + ] = None + r"""Create subscription if it does not exist""" + + region: Optional[str] = None + r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + + google_auth_method: Annotated[ + Optional[GoogleAuthenticationMethodOptions], + pydantic.Field(alias="googleAuthMethod"), + ] = None + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + secret: Optional[str] = None + r"""Select or create a stored text secret""" + + max_backlog: Annotated[Optional[float], pydantic.Field(alias="maxBacklog")] = None + r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" + + concurrency: Optional[float] = None + r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Pull request timeout, in milliseconds""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + ordered_delivery: Annotated[ + Optional[bool], pydantic.Field(alias="orderedDelivery") + ] = None + r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_topic_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicName") + ] = None + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + + template_subscription_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_subscriptionName") + ] = None + r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): + if isinstance(value, str): + try: + return models.GoogleAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "monitorSubscription", + "createTopic", + "createSubscription", + "region", + "googleAuthMethod", + "serviceAccountCredentials", + "secret", + "maxBacklog", + "concurrency", + "requestTimeout", + "metadata", + "autoParse", + "description", + "orderedDelivery", + "__template_environment", + "__template_streamtags", + "__template_topicName", + "__template_subscriptionName", + "__template_region", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputFirehoseType(str, Enum): + r"""Source type identifier.""" + + FIREHOSE = "firehose" + + +class CreateInputSystemByPackInputFirehoseTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputFirehoseType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + +class CreateInputSystemByPackInputFirehose(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputFirehoseType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputExecType(str, Enum): + r"""Connector type identifier.""" + + EXEC = "exec" + + +class CreateInputSystemByPackScheduleType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + + INTERVAL = "interval" + CRON_SCHEDULE = "cronSchedule" + + +class CreateInputSystemByPackInputExecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputExecType + r"""Connector type identifier.""" + command: str + r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" + disabled: NotRequired[bool] + r"""Disabled""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + script: NotRequired[str] + r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" + retries: NotRequired[float] + r"""Maximum number of retry attempts in the event that the command fails""" + schedule_type: NotRequired[CreateInputSystemByPackScheduleType] + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + interval: NotRequired[float] + r"""Interval between command executions in seconds.""" + cron_schedule: NotRequired[str] + r"""Cron schedule to execute the command on.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputExec(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputExecType + r"""Connector type identifier.""" + + command: str + r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" + + disabled: Optional[bool] = None + r"""Disabled""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + script: Optional[str] = None + r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" + + retries: Optional[float] = None + r"""Maximum number of retry attempts in the event that the command fails""" + + schedule_type: Annotated[ + Optional[CreateInputSystemByPackScheduleType], + pydantic.Field(alias="scheduleType"), + ] = None + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + interval: Optional[float] = None + r"""Interval between command executions in seconds.""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Cron schedule to execute the command on.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @field_serializer("schedule_type") + def serialize_schedule_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackScheduleType(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "script", + "retries", + "scheduleType", + "breakerRulesets", + "staleChannelFlushMs", + "metadata", + "autoParse", + "description", + "interval", + "cronSchedule", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputEventhubAmqpType(str, Enum): + r"""Connector type identifier.""" + + EVENTHUB_AMQP = "eventhub_amqp" + + +class CreateInputSystemByPackAuthenticationMechanism( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication mechanism""" + + # Connection String + CONNECTION_STRING = "connection-string" + # OAuth Bearer + OAUTH_BEARER = "oauth-bearer" + + +class CreateInputSystemByPackCertificateTypedDict(TypedDict): + certificate_name: str + r"""The certificate you registered as credentials for your app in the Azure portal""" + cert_path: str + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + priv_key_path: str + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + + +class CreateInputSystemByPackCertificate(BaseModel): + certificate_name: Annotated[str, pydantic.Field(alias="certificateName")] + r"""The certificate you registered as credentials for your app in the Azure portal""" + + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["passphrase"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackAuthTypedDict(TypedDict): + mechanism: CreateInputSystemByPackAuthenticationMechanism + r"""Authentication mechanism""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] + r"""Authentication method""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CreateInputSystemByPackCertificateTypedDict] + oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] + r"""Endpoint used to acquire authentication tokens from Azure""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory""" + fully_qualified_namespace: NotRequired[str] + r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" + template_oauth_endpoint: NotRequired[str] + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_fully_qualified_namespace: NotRequired[str] + r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" + + +class CreateInputSystemByPackAuth(BaseModel): + mechanism: CreateInputSystemByPackAuthenticationMechanism + r"""Authentication mechanism""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + client_secret_auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuth], + pydantic.Field(alias="clientSecretAuthType"), + ] = None + r"""Authentication method""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CreateInputSystemByPackCertificate] = None + + oauth_endpoint: Annotated[ + Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], + pydantic.Field(alias="oauthEndpoint"), + ] = None + r"""Endpoint used to acquire authentication tokens from Azure""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory""" + + fully_qualified_namespace: Annotated[ + Optional[str], pydantic.Field(alias="fullyQualifiedNamespace") + ] = None + r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" + + template_oauth_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_oauthEndpoint") + ] = None + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_fully_qualified_namespace: Annotated[ + Optional[str], pydantic.Field(alias="__template_fullyQualifiedNamespace") + ] = None + r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" + + @field_serializer("mechanism") + def serialize_mechanism(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackAuthenticationMechanism(value) + except ValueError: + return value + return value + + @field_serializer("client_secret_auth_type") + def serialize_client_secret_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuth(value) + except ValueError: + return value + return value + + @field_serializer("oauth_endpoint") + def serialize_oauth_endpoint(self, value): + if isinstance(value, str): + try: + return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "textSecret", + "clientSecretAuthType", + "clientTextSecret", + "certificate", + "oauthEndpoint", + "clientId", + "tenantId", + "fullyQualifiedNamespace", + "__template_oauthEndpoint", + "__template_clientId", + "__template_tenantId", + "__template_fullyQualifiedNamespace", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackAzureBlobStorageTypedDict(TypedDict): + r"""Azure Blob Storage""" + + container_name: str + r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] + r"""Authentication method""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + +class CreateInputSystemByPackAzureBlobStorage(BaseModel): + r"""Azure Blob Storage""" + + container_name: Annotated[str, pydantic.Field(alias="containerName")] + r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") + ] = None + r"""The name of your Azure storage account""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" + + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") + ] = None + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") + ] = None + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackCheckpointingTypedDict(TypedDict): + blob_store: CreateInputSystemByPackAzureBlobStorageTypedDict + r"""Azure Blob Storage""" + + +class CreateInputSystemByPackCheckpointing(BaseModel): + blob_store: Annotated[ + CreateInputSystemByPackAzureBlobStorage, pydantic.Field(alias="blobStore") + ] + r"""Azure Blob Storage""" + + +class CreateInputSystemByPackInputEventhubAmqpTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputEventhubAmqpType + r"""Connector type identifier.""" + consumer_group: str + r"""The consumer group this instance belongs to. Default is '$Default'.""" + checkpointing: CreateInputSystemByPackCheckpointingTypedDict + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + event_hub_name: NotRequired[str] + r"""The name of the Event Hub to consume from""" + auth: NotRequired[CreateInputSystemByPackAuthTypedDict] + from_beginning: NotRequired[bool] + r"""Start reading from earliest available data; relevant only during initial subscription""" + max_batch_size: NotRequired[int] + r"""Maximum number of events in each batch delivered to the consumer""" + max_wait_time_in_seconds: NotRequired[int] + r"""Maximum time to wait for a batch of events before delivering a partial batch""" + prefetch_count: NotRequired[int] + r"""Number of events to prefetch from the service for processing""" + max_retries: NotRequired[int] + r"""Maximum number of retries per operation""" + initial_backoff: NotRequired[int] + r"""Initial delay before the first retry, in milliseconds""" + max_backoff: NotRequired[int] + r"""Maximum delay between retries, in milliseconds""" + timeout_in_ms: NotRequired[int] + r"""Maximum time to wait for a request to complete""" + connection_initial_backoff: NotRequired[int] + r"""Initial delay before the first reconnection attempt, in milliseconds""" + connection_max_backoff: NotRequired[int] + r"""Maximum delay between reconnection attempts, in milliseconds""" + connection_timeout_in_ms: NotRequired[int] + r"""Maximum time to wait for a connection to complete""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputEventhubAmqp(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputEventhubAmqpType + r"""Connector type identifier.""" + + consumer_group: Annotated[str, pydantic.Field(alias="consumerGroup")] + r"""The consumer group this instance belongs to. Default is '$Default'.""" + + checkpointing: CreateInputSystemByPackCheckpointing + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + event_hub_name: Annotated[Optional[str], pydantic.Field(alias="eventHubName")] = ( + None + ) + r"""The name of the Event Hub to consume from""" + + auth: Optional[CreateInputSystemByPackAuth] = None + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Start reading from earliest available data; relevant only during initial subscription""" + + max_batch_size: Annotated[Optional[int], pydantic.Field(alias="maxBatchSize")] = ( + None + ) + r"""Maximum number of events in each batch delivered to the consumer""" + + max_wait_time_in_seconds: Annotated[ + Optional[int], pydantic.Field(alias="maxWaitTimeInSeconds") + ] = None + r"""Maximum time to wait for a batch of events before delivering a partial batch""" + + prefetch_count: Annotated[Optional[int], pydantic.Field(alias="prefetchCount")] = ( + None + ) + r"""Number of events to prefetch from the service for processing""" + + max_retries: Annotated[Optional[int], pydantic.Field(alias="maxRetries")] = None + r"""Maximum number of retries per operation""" + + initial_backoff: Annotated[ + Optional[int], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial delay before the first retry, in milliseconds""" + + max_backoff: Annotated[Optional[int], pydantic.Field(alias="maxBackoff")] = None + r"""Maximum delay between retries, in milliseconds""" + + timeout_in_ms: Annotated[Optional[int], pydantic.Field(alias="timeoutInMs")] = None + r"""Maximum time to wait for a request to complete""" + + connection_initial_backoff: Annotated[ + Optional[int], pydantic.Field(alias="connectionInitialBackoff") + ] = None + r"""Initial delay before the first reconnection attempt, in milliseconds""" + + connection_max_backoff: Annotated[ + Optional[int], pydantic.Field(alias="connectionMaxBackoff") + ] = None + r"""Maximum delay between reconnection attempts, in milliseconds""" + + connection_timeout_in_ms: Annotated[ + Optional[int], pydantic.Field(alias="connectionTimeoutInMs") + ] = None + r"""Maximum time to wait for a connection to complete""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "eventHubName", + "auth", + "fromBeginning", + "maxBatchSize", + "maxWaitTimeInSeconds", + "prefetchCount", + "maxRetries", + "initialBackoff", + "maxBackoff", + "timeoutInMs", + "connectionInitialBackoff", + "connectionMaxBackoff", + "connectionTimeoutInMs", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputEventhubType(str, Enum): + r"""Connector type identifier.""" + + EVENTHUB = "eventhub" + + +class CreateInputSystemByPackInputEventhubTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputEventhubType + r"""Connector type identifier.""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + topics: List[str] + r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + group_id: NotRequired[str] + r"""The consumer group this instance belongs to. Default is 'Cribl'.""" + from_beginning: NotRequired[bool] + r"""Start reading from earliest available data; relevant only during initial subscription""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeUseTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeTypedDict] + r"""TLS settings (client side)""" + session_timeout: NotRequired[float] + r""" + Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + rebalance_timeout: NotRequired[float] + r""" + Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + heartbeat_interval: NotRequired[float] + r""" + Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + auto_commit_interval: NotRequired[float] + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + auto_commit_threshold: NotRequired[float] + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + max_bytes_per_partition: NotRequired[float] + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + max_bytes: NotRequired[float] + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + max_socket_errors: NotRequired[float] + r"""Maximum number of network errors before the consumer re-creates a socket""" + minimize_duplicates: NotRequired[bool] + r"""Minimize duplicate events by starting only one consumer for each topic partition""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topics: NotRequired[str] + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + template_group_id: NotRequired[str] + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + +class CreateInputSystemByPackInputEventhub(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputEventhubType + r"""Connector type identifier.""" + + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + + topics: List[str] + r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""The consumer group this instance belongs to. Default is 'Cribl'.""" + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Start reading from earliest available data; relevant only during initial subscription""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" + + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationTypeUse] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideType] = None + r"""TLS settings (client side)""" + + session_timeout: Annotated[ + Optional[float], pydantic.Field(alias="sessionTimeout") + ] = None + r""" + Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + rebalance_timeout: Annotated[ + Optional[float], pydantic.Field(alias="rebalanceTimeout") + ] = None + r""" + Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + heartbeat_interval: Annotated[ + Optional[float], pydantic.Field(alias="heartbeatInterval") + ] = None + r""" + Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + auto_commit_interval: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitInterval") + ] = None + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + auto_commit_threshold: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitThreshold") + ] = None + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + max_bytes_per_partition: Annotated[ + Optional[float], pydantic.Field(alias="maxBytesPerPartition") + ] = None + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + + max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + + max_socket_errors: Annotated[ + Optional[float], pydantic.Field(alias="maxSocketErrors") + ] = None + r"""Maximum number of network errors before the consumer re-creates a socket""" + + minimize_duplicates: Annotated[ + Optional[bool], pydantic.Field(alias="minimizeDuplicates") + ] = None + r"""Minimize duplicate events by starting only one consumer for each topic partition""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") + ] = None + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + + template_topics: Annotated[ + Optional[str], pydantic.Field(alias="__template_topics") + ] = None + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + + template_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_groupId") + ] = None + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "groupId", + "fromBeginning", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", + "sessionTimeout", + "rebalanceTimeout", + "heartbeatInterval", + "autoCommitInterval", + "autoCommitThreshold", + "maxBytesPerPartition", + "maxBytes", + "maxSocketErrors", + "minimizeDuplicates", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "__template_brokers", + "__template_topics", + "__template_groupId", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputMicrosoftGraphType(str, Enum): + r"""Connector type identifier.""" + + MICROSOFT_GRAPH = "microsoft_graph" + + +class CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + OAUTH = "oauth" + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + # Microsoft 365 Enterprise + ENTERPRISE_GCC = "enterprise_gcc" + # Microsoft 365 GCC + GCC = "gcc" + # Microsoft 365 GCC High + GCC_HIGH = "gcc_high" + # Microsoft 365 DoD + DOD = "dod" + # Microsoft 365 China (21Vianet) + CHINA = "china" + + +class CreateInputSystemByPackInputMicrosoftGraphTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputMicrosoftGraphType + r"""Connector type identifier.""" + url: str + r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + start_date: NotRequired[str] + r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + end_date: NotRequired[str] + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + disable_time_filter: NotRequired[bool] + r"""Disables time filtering of events when a date range is specified.""" + max_pages: NotRequired[int] + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + auth_type: NotRequired[ + CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod + ] + r"""Select authentication method.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + reschedule_dropped_tasks: NotRequired[bool] + r"""Reschedule tasks that failed with non-fatal errors""" + max_task_reschedule: NotRequired[float] + r"""Maximum number of times a task can be rescheduled""" + log_level: NotRequired[LogLevelOptionsDebugError] + r"""Log Level (verbosity) for collection runtime behavior.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""client_secret to pass in the OAuth request parameter.""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter.""" + resource: NotRequired[str] + r"""Resource to pass in the OAuth request parameter.""" + plan_type: NotRequired[CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + text_secret: NotRequired[str] + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + cert_options: NotRequired[CertOptionsTypeTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_resource: NotRequired[str] + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + +class CreateInputSystemByPackInputMicrosoftGraph(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputMicrosoftGraphType + r"""Connector type identifier.""" + + url: str + r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" + + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None + r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + + end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + + disable_time_filter: Annotated[ + Optional[bool], pydantic.Field(alias="disableTimeFilter") + ] = None + r"""Disables time filtering of events when a date range is specified.""" + + max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + + auth_type: Annotated[ + Optional[CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + reschedule_dropped_tasks: Annotated[ + Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") + ] = None + r"""Reschedule tasks that failed with non-fatal errors""" + + max_task_reschedule: Annotated[ + Optional[float], pydantic.Field(alias="maxTaskReschedule") + ] = None + r"""Maximum number of times a task can be rescheduled""" + + log_level: Annotated[ + Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") + ] = None + r"""Log Level (verbosity) for collection runtime behavior.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""client_secret to pass in the OAuth request parameter.""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter.""" + + resource: Optional[str] = None + r"""Resource to pass in the OAuth request parameter.""" + + plan_type: Annotated[ + Optional[CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan], + pydantic.Field(alias="planType"), + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + + cert_options: Annotated[ + Optional[CertOptionsType], pydantic.Field(alias="certOptions") + ] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_resource: Annotated[ + Optional[str], pydantic.Field(alias="__template_resource") + ] = None + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsDebugError(value) + except ValueError: + return value + return value + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return ( + models.CreateInputSystemByPackInputMicrosoftGraphSubscriptionPlan( + value + ) + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "startDate", + "endDate", + "timeout", + "disableTimeFilter", + "maxPages", + "authType", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "rescheduleDroppedTasks", + "maxTaskReschedule", + "logLevel", + "retryRules", + "breakerRulesets", + "staleChannelFlushMs", + "description", + "clientSecret", + "tenantId", + "clientId", + "resource", + "planType", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_url", + "__template_tenantId", + "__template_clientId", + "__template_resource", + "__template_planType", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputOffice365MsgTraceType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_MSG_TRACE = "office365_msg_trace" + + +class CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + MANUAL = "manual" + SECRET = "secret" + OAUTH = "oauth" + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class CreateInputSystemByPackInputOffice365MsgTraceTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputOffice365MsgTraceType + r"""Connector type identifier.""" + url: str + r"""URL to use when retrieving report data.""" + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + start_date: NotRequired[str] + r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + end_date: NotRequired[str] + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + disable_time_filter: NotRequired[bool] + r"""Disables time filtering of events when a date range is specified.""" + auth_type: NotRequired[ + CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod + ] + r"""Select authentication method.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + reschedule_dropped_tasks: NotRequired[bool] + r"""Reschedule tasks that failed with non-fatal errors""" + max_task_reschedule: NotRequired[float] + r"""Maximum number of times a task can be rescheduled""" + log_level: NotRequired[LogLevelOptionsDebugError] + r"""Log Level (verbosity) for collection runtime behavior.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username to run Message Trace API call.""" + password: NotRequired[str] + r"""Password to run Message Trace API call.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials.""" + client_secret: NotRequired[str] + r"""client_secret to pass in the OAuth request parameter.""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter.""" + resource: NotRequired[str] + r"""Resource to pass in the OAuth request parameter.""" + plan_type: NotRequired[SubscriptionPlanOptions] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + text_secret: NotRequired[str] + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + cert_options: NotRequired[CertOptionsTypeTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_resource: NotRequired[str] + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + +class CreateInputSystemByPackInputOffice365MsgTrace(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputOffice365MsgTraceType + r"""Connector type identifier.""" + + url: str + r"""URL to use when retrieving report data.""" + + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None + r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + + end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + + disable_time_filter: Annotated[ + Optional[bool], pydantic.Field(alias="disableTimeFilter") + ] = None + r"""Disables time filtering of events when a date range is specified.""" + + auth_type: Annotated[ + Optional[CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + reschedule_dropped_tasks: Annotated[ + Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") + ] = None + r"""Reschedule tasks that failed with non-fatal errors""" + + max_task_reschedule: Annotated[ + Optional[float], pydantic.Field(alias="maxTaskReschedule") + ] = None + r"""Maximum number of times a task can be rescheduled""" + + log_level: Annotated[ + Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") + ] = None + r"""Log Level (verbosity) for collection runtime behavior.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username to run Message Trace API call.""" + + password: Optional[str] = None + r"""Password to run Message Trace API call.""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""client_secret to pass in the OAuth request parameter.""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter.""" + + resource: Optional[str] = None + r"""Resource to pass in the OAuth request parameter.""" + + plan_type: Annotated[ + Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + + cert_options: Annotated[ + Optional[CertOptionsType], pydantic.Field(alias="certOptions") + ] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_resource: Annotated[ + Optional[str], pydantic.Field(alias="__template_resource") + ] = None + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsDebugError(value) + except ValueError: + return value + return value + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "startDate", + "endDate", + "timeout", + "disableTimeFilter", + "authType", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "rescheduleDroppedTasks", + "maxTaskReschedule", + "logLevel", + "retryRules", + "description", + "username", + "password", + "credentialsSecret", + "clientSecret", + "tenantId", + "clientId", + "resource", + "planType", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_url", + "__template_tenantId", + "__template_clientId", + "__template_resource", + "__template_planType", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputOffice365ServiceType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_SERVICE = "office365_service" + + +class CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict(TypedDict): + content_type: NotRequired[str] + r"""Microsoft 365 Services API Content Type""" + description: NotRequired[str] + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + interval: NotRequired[float] + r"""Interval""" + log_level: NotRequired[LogLevelOptionsContentConfigItems] + r"""Collector runtime Log Level""" + enabled: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackInputOffice365ServiceContentConfig(BaseModel): + content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None + r"""Microsoft 365 Services API Content Type""" + + description: Optional[str] = None + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + + interval: Optional[float] = None + r"""Interval""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime Log Level""" + + enabled: Optional[bool] = None + r"""Enabled""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["contentType", "description", "interval", "logLevel", "enabled"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputOffice365ServiceTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputOffice365ServiceType + r"""Connector type identifier.""" + tenant_id: str + r"""Microsoft 365 Azure Tenant ID""" + app_id: str + r"""Microsoft 365 Azure Application ID""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + plan_type: NotRequired[SubscriptionPlanOptions] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, use 0 to disable""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + content_config: NotRequired[ + List[CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict] + ] + r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""Microsoft 365 Azure client secret""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_app_id: NotRequired[str] + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + +class CreateInputSystemByPackInputOffice365Service(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputOffice365ServiceType + r"""Connector type identifier.""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Microsoft 365 Azure Tenant ID""" + + app_id: Annotated[str, pydantic.Field(alias="appId")] + r"""Microsoft 365 Azure Application ID""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + plan_type: Annotated[ + Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, use 0 to disable""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + content_config: Annotated[ + Optional[List[CreateInputSystemByPackInputOffice365ServiceContentConfig]], + pydantic.Field(alias="contentConfig"), + ] = None + r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), + ] = None + r"""Enter client secret directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""Microsoft 365 Azure client secret""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_app_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_appId") + ] = None + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") + ] = None + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "planType", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "contentConfig", + "retryRules", + "authType", + "description", + "clientSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_planType", + "__template_tenantId", + "__template_appId", + "__template_clientSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputOffice365MgmtType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_MGMT = "office365_mgmt" + + +class CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict(TypedDict): + content_type: NotRequired[str] + r"""Microsoft 365 Management Activity API Content Type""" + description: NotRequired[str] + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + interval: NotRequired[float] + r"""Interval""" + log_level: NotRequired[LogLevelOptionsContentConfigItems] + r"""Collector runtime Log Level""" + enabled: NotRequired[bool] + r"""Enabled""" + + +class CreateInputSystemByPackInputOffice365MgmtContentConfig(BaseModel): + content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None + r"""Microsoft 365 Management Activity API Content Type""" + + description: Optional[str] = None + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + + interval: Optional[float] = None + r"""Interval""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime Log Level""" + + enabled: Optional[bool] = None + r"""Enabled""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["contentType", "description", "interval", "logLevel", "enabled"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputOffice365MgmtTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputOffice365MgmtType + r"""Connector type identifier.""" + plan_type: SubscriptionPlanOptions + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + tenant_id: str + r"""Microsoft 365 Azure Tenant ID""" + app_id: str + r"""Microsoft 365 Azure Application ID""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, use 0 to disable""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + publisher_identifier: NotRequired[str] + r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" + content_config: NotRequired[ + List[CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict] + ] + r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" + ingestion_lag: NotRequired[float] + r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""Microsoft 365 Azure client secret""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_app_id: NotRequired[str] + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + template_publisher_identifier: NotRequired[str] + r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + +class CreateInputSystemByPackInputOffice365Mgmt(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputOffice365MgmtType + r"""Connector type identifier.""" + + plan_type: Annotated[SubscriptionPlanOptions, pydantic.Field(alias="planType")] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Microsoft 365 Azure Tenant ID""" + + app_id: Annotated[str, pydantic.Field(alias="appId")] + r"""Microsoft 365 Azure Application ID""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, use 0 to disable""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + publisher_identifier: Annotated[ + Optional[str], pydantic.Field(alias="publisherIdentifier") + ] = None + r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" + + content_config: Annotated[ + Optional[List[CreateInputSystemByPackInputOffice365MgmtContentConfig]], + pydantic.Field(alias="contentConfig"), + ] = None + r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" + + ingestion_lag: Annotated[Optional[float], pydantic.Field(alias="ingestionLag")] = ( + None + ) + r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), + ] = None + r"""Enter client secret directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""Microsoft 365 Azure client secret""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_app_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_appId") + ] = None + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + + template_publisher_identifier: Annotated[ + Optional[str], pydantic.Field(alias="__template_publisherIdentifier") + ] = None + r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" + + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") + ] = None + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "publisherIdentifier", + "contentConfig", + "ingestionLag", + "retryRules", + "authType", + "description", + "clientSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_planType", + "__template_tenantId", + "__template_appId", + "__template_publisherIdentifier", + "__template_clientSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputEdgePrometheusType(str, Enum): + r"""Connector type identifier.""" + + EDGE_PROMETHEUS = "edge_prometheus" + + +class CreateInputSystemByPackInputEdgePrometheusDiscoveryType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + # Static + STATIC = "static" + # DNS + DNS = "dns" + # AWS EC2 + EC2 = "ec2" + # Kubernetes Node + K8S_NODE = "k8s-node" + # Kubernetes Pods + K8S_PODS = "k8s-pods" + # Kubernetes Service Monitor (v4.18+) + K8S_SERVICE_MONITOR = "k8s-service-monitor" + # HTTP SD + HTTP_SD = "http_sd" + + +class CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter credentials directly, or select a stored secret""" + + MANUAL = "manual" + SECRET = "secret" + KUBERNETES = "kubernetes" + + +class CreateInputSystemByPackTargetTypedDict(TypedDict): + host: str + r"""Name of host from which to pull metrics.""" + protocol: NotRequired[ProtocolOptionsTargetsItems] + r"""Protocol to use when collecting metrics""" + port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets.""" + path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + + +class CreateInputSystemByPackTarget(BaseModel): + host: str + r"""Name of host from which to pull metrics.""" + + protocol: Optional[ProtocolOptionsTargetsItems] = None + r"""Protocol to use when collecting metrics""" + + port: Optional[float] = None + r"""The port number in the metrics URL for discovered targets.""" + + path: Optional[str] = None + r"""Path to use when collecting metrics from discovered targets""" + + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptionsTargetsItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["protocol", "port", "path"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackPodFilterTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class CreateInputSystemByPackPodFilter(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputEdgePrometheusTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputEdgePrometheusType + r"""Connector type identifier.""" + discovery_type: CreateInputSystemByPackInputEdgePrometheusDiscoveryType + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + interval: float + r"""How often in seconds to scrape targets for metrics.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + dimension_list: NotRequired[List[str]] + r"""Other dimensions to include in events""" + field_per_metric: NotRequired[bool] + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + timeout: NotRequired[float] + r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" + persistence: NotRequired[DiskSpoolingTypeTypedDict] + r"""Disk Spooling""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_type: NotRequired[ + CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod + ] + r"""Enter credentials directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + targets: NotRequired[List[CreateInputSystemByPackTargetTypedDict]] + r"""Targets""" + record_type: NotRequired[RecordTypeOptions] + r"""DNS record type to resolve""" + scrape_port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets.""" + name_list: NotRequired[List[str]] + r"""List of DNS names to resolve""" + scrape_protocol: NotRequired[ProtocolOptionsTargetsItems] + r"""Protocol to use when collecting metrics""" + scrape_path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + use_public_ip: NotRequired[bool] + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] + r"""Filter to apply when searching for EC2 instances""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the EC2 is located""" + endpoint: NotRequired[str] + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access EC2""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + service_monitor_namespace: NotRequired[str] + r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" + scrape_protocol_expr: NotRequired[str] + r"""Protocol to use when collecting metrics""" + scrape_port_expr: NotRequired[str] + r"""The port number in the metrics URL for discovered targets.""" + scrape_path_expr: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + pod_filter: NotRequired[List[CreateInputSystemByPackPodFilterTypedDict]] + r""" + Add rules to decide which pods to discover for metrics. + Pods are searched if no rules are given or of all the rules' + expressions evaluate to true. + + """ + http_discovery_url: NotRequired[str] + r"""URL to fetch target groups from (must be http or https)""" + http_discovery_headers: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Extra headers to send with the discovery request""" + http_discovery_reject_unauthorized: NotRequired[bool] + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + max_response_body_size: NotRequired[str] + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + username: NotRequired[str] + r"""Username for Prometheus Basic authentication""" + password: NotRequired[str] + r"""Password for Prometheus Basic authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_dimension_list: NotRequired[str] + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + template_name_list: NotRequired[str] + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + +class CreateInputSystemByPackInputEdgePrometheus(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputEdgePrometheusType + r"""Connector type identifier.""" + + discovery_type: Annotated[ + CreateInputSystemByPackInputEdgePrometheusDiscoveryType, + pydantic.Field(alias="discoveryType"), + ] + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + interval: float + r"""How often in seconds to scrape targets for metrics.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + dimension_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="dimensionList") + ] = None + r"""Other dimensions to include in events""" + + field_per_metric: Annotated[ + Optional[bool], pydantic.Field(alias="fieldPerMetric") + ] = None + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + + timeout: Optional[float] = None + r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" + + persistence: Optional[DiskSpoolingType] = None + r"""Disk Spooling""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_type: Annotated[ + Optional[CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter credentials directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + targets: Optional[List[CreateInputSystemByPackTarget]] = None + r"""Targets""" + + record_type: Annotated[ + Optional[RecordTypeOptions], pydantic.Field(alias="recordType") + ] = None + r"""DNS record type to resolve""" + + scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None + r"""The port number in the metrics URL for discovered targets.""" + + name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None + r"""List of DNS names to resolve""" + + scrape_protocol: Annotated[ + Optional[ProtocolOptionsTargetsItems], pydantic.Field(alias="scrapeProtocol") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None + r"""Path to use when collecting metrics from discovered targets""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + + search_filter: Annotated[ + Optional[List[SearchFilterConfInputPrometheus]], + pydantic.Field(alias="searchFilter"), + ] = None + r"""Filter to apply when searching for EC2 instances""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""Region where the EC2 is located""" + + endpoint: Optional[str] = None + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access EC2""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + service_monitor_namespace: Annotated[ + Optional[str], pydantic.Field(alias="serviceMonitorNamespace") + ] = None + r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" + + scrape_protocol_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapeProtocolExpr") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_port_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapePortExpr") + ] = None + r"""The port number in the metrics URL for discovered targets.""" + + scrape_path_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapePathExpr") + ] = None + r"""Path to use when collecting metrics from discovered targets""" + + pod_filter: Annotated[ + Optional[List[CreateInputSystemByPackPodFilter]], + pydantic.Field(alias="podFilter"), + ] = None + r""" + Add rules to decide which pods to discover for metrics. + Pods are searched if no rules are given or of all the rules' + expressions evaluate to true. + + """ + + http_discovery_url: Annotated[ + Optional[str], pydantic.Field(alias="httpDiscoveryUrl") + ] = None + r"""URL to fetch target groups from (must be http or https)""" + + http_discovery_headers: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="httpDiscoveryHeaders"), + ] = None + r"""Extra headers to send with the discovery request""" + + http_discovery_reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") + ] = None + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + + max_response_body_size: Annotated[ + Optional[str], pydantic.Field(alias="maxResponseBodySize") + ] = None + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + + username: Optional[str] = None + r"""Username for Prometheus Basic authentication""" + + password: Optional[str] = None + r"""Password for Prometheus Basic authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_dimension_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_dimensionList") + ] = None + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + + template_name_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_nameList") + ] = None + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + @field_serializer("discovery_type") + def serialize_discovery_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputEdgePrometheusDiscoveryType( + value + ) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("record_type") + def serialize_record_type(self, value): + if isinstance(value, str): + try: + return models.RecordTypeOptions(value) + except ValueError: + return value + return value + + @field_serializer("scrape_protocol") + def serialize_scrape_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptionsTargetsItems(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "dimensionList", + "fieldPerMetric", + "timeout", + "persistence", + "metadata", + "authType", + "description", + "targets", + "recordType", + "scrapePort", + "nameList", + "scrapeProtocol", + "scrapePath", + "awsAuthenticationMethod", + "awsApiKey", + "awsSecret", + "usePublicIp", + "searchFilter", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "serviceMonitorNamespace", + "scrapeProtocolExpr", + "scrapePortExpr", + "scrapePathExpr", + "podFilter", + "httpDiscoveryUrl", + "httpDiscoveryHeaders", + "httpDiscoveryRejectUnauthorized", + "maxResponseBodySize", + "username", + "password", + "credentialsSecret", + "__template_environment", + "__template_streamtags", + "__template_dimensionList", + "__template_nameList", + "__template_awsApiKey", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputPrometheusDiscoveryType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + # Static + STATIC = "static" + # DNS + DNS = "dns" + # AWS EC2 + EC2 = "ec2" + # HTTP SD + HTTP_SD = "http_sd" + + +class CreateInputSystemByPackMetricsProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Protocol to use when collecting metrics""" + + HTTP = "http" + HTTPS = "https" + + +class CreateInputSystemByPackInputPrometheusTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsPrometheus + r"""Connector type identifier.""" + interval: float + r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" + log_level: LogLevelOptions + r"""Collector runtime log level""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + dimension_list: NotRequired[List[str]] + r"""Other dimensions to include in events""" + field_per_metric: NotRequired[bool] + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + discovery_type: NotRequired[CreateInputSystemByPackInputPrometheusDiscoveryType] + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + timeout: NotRequired[float] + r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_type: NotRequired[AuthenticationMethodOptionsSasl] + r"""Enter credentials directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + target_list: NotRequired[List[str]] + r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" + record_type: NotRequired[RecordTypeOptions] + r"""DNS record type to resolve""" + scrape_port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets""" + name_list: NotRequired[List[str]] + r"""List of DNS names to resolve""" + scrape_protocol: NotRequired[CreateInputSystemByPackMetricsProtocol] + r"""Protocol to use when collecting metrics""" + scrape_path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + use_public_ip: NotRequired[bool] + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] + r"""Filter to apply when searching for EC2 instances""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the EC2 is located""" + endpoint: NotRequired[str] + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access EC2""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + http_discovery_url: NotRequired[str] + r"""URL to fetch target groups from (must be http or https)""" + http_discovery_headers: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Extra headers to send with the discovery request""" + http_discovery_reject_unauthorized: NotRequired[bool] + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + max_response_body_size: NotRequired[str] + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + username: NotRequired[str] + r"""Username for Prometheus Basic authentication""" + password: NotRequired[str] + r"""Password for Prometheus Basic authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_dimension_list: NotRequired[str] + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + template_discovery_type: NotRequired[str] + r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" + template_log_level: NotRequired[str] + r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" + template_target_list: NotRequired[str] + r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" + template_name_list: NotRequired[str] + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + template_password: NotRequired[str] + r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" + + +class CreateInputSystemByPackInputPrometheus(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsPrometheus + r"""Connector type identifier.""" + + interval: float + r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" + + log_level: Annotated[LogLevelOptions, pydantic.Field(alias="logLevel")] + r"""Collector runtime log level""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + dimension_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="dimensionList") + ] = None + r"""Other dimensions to include in events""" + + field_per_metric: Annotated[ + Optional[bool], pydantic.Field(alias="fieldPerMetric") + ] = None + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + + discovery_type: Annotated[ + Optional[CreateInputSystemByPackInputPrometheusDiscoveryType], + pydantic.Field(alias="discoveryType"), + ] = None + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + timeout: Optional[float] = None + r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsSasl], pydantic.Field(alias="authType") + ] = None + r"""Enter credentials directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + target_list: Annotated[Optional[List[str]], pydantic.Field(alias="targetList")] = ( + None + ) + r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" + + record_type: Annotated[ + Optional[RecordTypeOptions], pydantic.Field(alias="recordType") + ] = None + r"""DNS record type to resolve""" + + scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None + r"""The port number in the metrics URL for discovered targets""" + + name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None + r"""List of DNS names to resolve""" + + scrape_protocol: Annotated[ + Optional[CreateInputSystemByPackMetricsProtocol], + pydantic.Field(alias="scrapeProtocol"), + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None + r"""Path to use when collecting metrics from discovered targets""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + + search_filter: Annotated[ + Optional[List[SearchFilterConfInputPrometheus]], + pydantic.Field(alias="searchFilter"), + ] = None + r"""Filter to apply when searching for EC2 instances""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""Region where the EC2 is located""" + + endpoint: Optional[str] = None + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access EC2""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + http_discovery_url: Annotated[ + Optional[str], pydantic.Field(alias="httpDiscoveryUrl") + ] = None + r"""URL to fetch target groups from (must be http or https)""" + + http_discovery_headers: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="httpDiscoveryHeaders"), + ] = None + r"""Extra headers to send with the discovery request""" + + http_discovery_reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") + ] = None + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + + max_response_body_size: Annotated[ + Optional[str], pydantic.Field(alias="maxResponseBodySize") + ] = None + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + + username: Optional[str] = None + r"""Username for Prometheus Basic authentication""" + + password: Optional[str] = None + r"""Password for Prometheus Basic authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_dimension_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_dimensionList") + ] = None + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + + template_discovery_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_discoveryType") + ] = None + r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" + + template_log_level: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLevel") + ] = None + r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" + + template_target_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_targetList") + ] = None + r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" + + template_name_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_nameList") + ] = None + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") + ] = None + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + template_password: Annotated[ + Optional[str], pydantic.Field(alias="__template_password") + ] = None + r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" + + @field_serializer("discovery_type") + def serialize_discovery_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputPrometheusDiscoveryType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsSasl(value) + except ValueError: + return value + return value + + @field_serializer("record_type") + def serialize_record_type(self, value): + if isinstance(value, str): + try: + return models.RecordTypeOptions(value) + except ValueError: + return value + return value + + @field_serializer("scrape_protocol") + def serialize_scrape_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackMetricsProtocol(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "dimensionList", + "fieldPerMetric", + "discoveryType", + "rejectUnauthorized", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "authType", + "description", + "targetList", + "recordType", + "scrapePort", + "nameList", + "scrapeProtocol", + "scrapePath", + "awsAuthenticationMethod", + "awsApiKey", + "awsSecret", + "usePublicIp", + "searchFilter", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "httpDiscoveryUrl", + "httpDiscoveryHeaders", + "httpDiscoveryRejectUnauthorized", + "maxResponseBodySize", + "username", + "password", + "credentialsSecret", + "__template_environment", + "__template_streamtags", + "__template_dimensionList", + "__template_discoveryType", + "__template_logLevel", + "__template_targetList", + "__template_nameList", + "__template_awsApiKey", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_username", + "__template_password", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputPrometheusRwType(str, Enum): + r"""Source type identifier.""" + + PROMETHEUS_RW = "prometheus_rw" + + +class CreateInputSystemByPackInputPrometheusRwTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputPrometheusRwType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + prometheus_api: str + r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + +class CreateInputSystemByPackInputPrometheusRw(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputPrometheusRwType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] + r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") + ] = None + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "authType", + "metadata", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_username", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputLokiType(str, Enum): + r"""Source type identifier.""" + + LOKI = "loki" + + +class CreateInputSystemByPackInputLokiTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputLokiType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + loki_api: str + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + +class CreateInputSystemByPackInputLoki(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputLokiType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "authType", + "metadata", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_lokiAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputGrafanaType2(str, Enum): + r"""Source type identifier.""" + + GRAFANA = "grafana" + + +class CreateInputSystemByPackPrometheusAuth2TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputSystemByPackPrometheusAuth2(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackLokiAuth2TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputSystemByPackLokiAuth2(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputGrafanaGrafana2TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputGrafanaType2 + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + loki_api: str + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + prometheus_api: NotRequired[str] + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + prometheus_auth: NotRequired[CreateInputSystemByPackPrometheusAuth2TypedDict] + loki_auth: NotRequired[CreateInputSystemByPackLokiAuth2TypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + +class CreateInputSystemByPackInputGrafanaGrafana2(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputGrafanaType2 + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + prometheus_api: Annotated[Optional[str], pydantic.Field(alias="prometheusAPI")] = ( + None + ) + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + + prometheus_auth: Annotated[ + Optional[CreateInputSystemByPackPrometheusAuth2], + pydantic.Field(alias="prometheusAuth"), + ] = None + + loki_auth: Annotated[ + Optional[CreateInputSystemByPackLokiAuth2], pydantic.Field(alias="lokiAuth") + ] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "prometheusAPI", + "prometheusAuth", + "lokiAuth", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_lokiAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputGrafanaType1(str, Enum): + r"""Source type identifier.""" + + GRAFANA = "grafana" + + +class CreateInputSystemByPackPrometheusAuth1TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputSystemByPackPrometheusAuth1(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackLokiAuth1TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateInputSystemByPackLokiAuth1(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputGrafanaGrafana1TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputGrafanaType1 + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + prometheus_api: str + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + loki_api: NotRequired[str] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + prometheus_auth: NotRequired[CreateInputSystemByPackPrometheusAuth1TypedDict] + loki_auth: NotRequired[CreateInputSystemByPackLokiAuth1TypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + +class CreateInputSystemByPackInputGrafanaGrafana1(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputGrafanaType1 + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + loki_api: Annotated[Optional[str], pydantic.Field(alias="lokiAPI")] = None + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + + prometheus_auth: Annotated[ + Optional[CreateInputSystemByPackPrometheusAuth1], + pydantic.Field(alias="prometheusAuth"), + ] = None + + loki_auth: Annotated[ + Optional[CreateInputSystemByPackLokiAuth1], pydantic.Field(alias="lokiAuth") + ] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "lokiAPI", + "prometheusAuth", + "lokiAuth", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_lokiAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateInputSystemByPackInputGrafanaUnionTypedDict = TypeAliasType( + "CreateInputSystemByPackInputGrafanaUnionTypedDict", + Union[ + CreateInputSystemByPackInputGrafanaGrafana1TypedDict, + CreateInputSystemByPackInputGrafanaGrafana2TypedDict, + ], +) + + +CreateInputSystemByPackInputGrafanaUnion = TypeAliasType( + "CreateInputSystemByPackInputGrafanaUnion", + Union[ + CreateInputSystemByPackInputGrafanaGrafana1, + CreateInputSystemByPackInputGrafanaGrafana2, + ], +) + + +class CreateInputSystemByPackInputConfluentCloudTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsConfluentcloud + r"""Connector type identifier.""" + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" + topics: List[str] + r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + group_id: NotRequired[str] + r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" + from_beginning: NotRequired[bool] + r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" + kafka_schema_registry: NotRequired[KafkaSchemaRegistryAuthenticationTypeTypedDict] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + session_timeout: NotRequired[float] + r""" + Timeout used to detect client failures when using Kafka's group-management facilities. + If the client sends no heartbeats to the broker before the timeout expires, + the broker will remove the client from the group and initiate a rebalance. + Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. + See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. + """ + rebalance_timeout: NotRequired[float] + r""" + Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. + """ + heartbeat_interval: NotRequired[float] + r""" + Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. + """ + auto_commit_interval: NotRequired[float] + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + auto_commit_threshold: NotRequired[float] + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + max_bytes_per_partition: NotRequired[float] + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + max_bytes: NotRequired[float] + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + max_socket_errors: NotRequired[float] + r"""Maximum number of network errors before the consumer re-creates a socket""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topics: NotRequired[str] + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + template_group_id: NotRequired[str] + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + +class CreateInputSystemByPackInputConfluentCloud(BaseModel): + id: str + r"""Unique ID for this input""" + + type: TypeOptionsConfluentcloud + r"""Connector type identifier.""" + + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" + + topics: List[str] + r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" + + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationType], + pydantic.Field(alias="kafkaSchemaRegistry"), + ] = None + r"""Kafka Schema Registry Authentication""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" + + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + session_timeout: Annotated[ + Optional[float], pydantic.Field(alias="sessionTimeout") + ] = None + r""" + Timeout used to detect client failures when using Kafka's group-management facilities. + If the client sends no heartbeats to the broker before the timeout expires, + the broker will remove the client from the group and initiate a rebalance. + Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. + See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. + """ + + rebalance_timeout: Annotated[ + Optional[float], pydantic.Field(alias="rebalanceTimeout") + ] = None + r""" + Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. + """ + + heartbeat_interval: Annotated[ + Optional[float], pydantic.Field(alias="heartbeatInterval") + ] = None + r""" + Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. + """ + + auto_commit_interval: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitInterval") + ] = None + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + auto_commit_threshold: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitThreshold") + ] = None + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + max_bytes_per_partition: Annotated[ + Optional[float], pydantic.Field(alias="maxBytesPerPartition") + ] = None + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + + max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + + max_socket_errors: Annotated[ + Optional[float], pydantic.Field(alias="maxSocketErrors") + ] = None + r"""Maximum number of network errors before the consumer re-creates a socket""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") + ] = None + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + + template_topics: Annotated[ + Optional[str], pydantic.Field(alias="__template_topics") + ] = None + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + + template_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_groupId") + ] = None + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "groupId", + "fromBeginning", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "sessionTimeout", + "rebalanceTimeout", + "heartbeatInterval", + "autoCommitInterval", + "autoCommitThreshold", + "maxBytesPerPartition", + "maxBytes", + "maxSocketErrors", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "__template_brokers", + "__template_topics", + "__template_groupId", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputElasticType(str, Enum): + r"""Source type identifier.""" + + ELASTIC = "elastic" + + +try: + CreateInputSystemByPackSNMPv3Authentication.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSnmp.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputS3Inventory.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputS3.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCriblmetrics.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputKinesis.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputHTTPRawInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputHTTPRawAuthTokensExt.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputHTTPRaw.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackSample.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputDatagen.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputDatadogAgentProxyMode.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputDatadogAgent.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCrowdstrike.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputWindowsMetricsCPU.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputWindowsMetricsNetwork.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputWindowsMetricsDisk.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputWindowsMetricsPersistence.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputWindowsMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputKubeEvents.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputKubeLogsRule.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputKubeLogs.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputKubeMetricsPersistence.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputKubeMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackCollectors.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSystemStatePersistence.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSystemState.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSystemMetricsCPU.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSystemMetricsNetwork.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSystemMetricsDisk.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackContainer.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSystemMetricsPersistence.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputSystemMetrics.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputTcpjson.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintSplunkHecMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputHTTPAuthTypeSecretConstraintElasticsearchMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCriblLakeHTTP.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCriblHTTP.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCriblTCP.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputCribl.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputGooglePubsub.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputFirehose.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputExec.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackCertificate.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackAuth.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackAzureBlobStorage.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackCheckpointing.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputEventhubAmqp.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputEventhub.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputMicrosoftGraph.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputOffice365MsgTrace.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputOffice365ServiceContentConfig.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputOffice365Service.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputOffice365MgmtContentConfig.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputOffice365Mgmt.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackPodFilter.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputEdgePrometheus.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputPrometheus.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputPrometheusRw.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputLoki.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackPrometheusAuth2.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackLokiAuth2.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputGrafanaGrafana2.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackPrometheusAuth1.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackLokiAuth1.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputGrafanaGrafana1.model_rebuild() +except NameError: + pass +try: + CreateInputSystemByPackInputConfluentCloud.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/createinputsystembypack_request.py b/src/cribl_control_plane/models/createinputsystembypack_request.py index 9fd49ba8a..60cf7031c 100644 --- a/src/cribl_control_plane/models/createinputsystembypack_request.py +++ b/src/cribl_control_plane/models/createinputsystembypack_request.py @@ -2,48 +2,32 @@ from __future__ import annotations from .authenticationmethodoptions import AuthenticationMethodOptions -from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) -from .authenticationmethodoptionsmanualsecret import ( - AuthenticationMethodOptionsManualSecret, +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, ) from .authenticationmethodoptionss3collectorconf import ( AuthenticationMethodOptionsS3CollectorConf, ) -from .authenticationmethodoptionssasl import AuthenticationMethodOptionsSasl from .authenticationtype import AuthenticationType, AuthenticationTypeTypedDict -from .authenticationtypeoptionslokiauth import AuthenticationTypeOptionsLokiAuth -from .authenticationtypeoptionsprometheusauth import ( - AuthenticationTypeOptionsPrometheusAuth, -) -from .authenticationtypeuse import AuthenticationTypeUse, AuthenticationTypeUseTypedDict -from .authtokenconfinputcribltcp import ( - AuthTokenConfInputCriblTCP, - AuthTokenConfInputCriblTCPTypedDict, -) -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, -) from .certificatetype import CertificateType, CertificateTypeTypedDict -from .certoptionstype import CertOptionsType, CertOptionsTypeTypedDict from .connectionconfinputcollection import ( ConnectionConfInputCollection, ConnectionConfInputCollectionTypedDict, ) -from .createinputsystembypack_inputkubemetrics import ( - CreateInputSystemByPackInputAnthropicCompliance, - CreateInputSystemByPackInputAnthropicComplianceTypedDict, - CreateInputSystemByPackInputAppleUnifiedLogs, - CreateInputSystemByPackInputAppleUnifiedLogsTypedDict, - CreateInputSystemByPackInputAppscope, - CreateInputSystemByPackInputAppscopeTypedDict, - CreateInputSystemByPackInputBedrockS3, - CreateInputSystemByPackInputBedrockS3TypedDict, - CreateInputSystemByPackInputCloudflareHec, - CreateInputSystemByPackInputCloudflareHecTypedDict, +from .createinputsystembypack_inputelastic_type import ( + CreateInputSystemByPackInputConfluentCloud, + CreateInputSystemByPackInputConfluentCloudTypedDict, + CreateInputSystemByPackInputCribl, + CreateInputSystemByPackInputCriblHTTP, + CreateInputSystemByPackInputCriblHTTPTypedDict, + CreateInputSystemByPackInputCriblLakeHTTP, + CreateInputSystemByPackInputCriblLakeHTTPTypedDict, + CreateInputSystemByPackInputCriblTCP, + CreateInputSystemByPackInputCriblTCPTypedDict, + CreateInputSystemByPackInputCriblTypedDict, CreateInputSystemByPackInputCriblmetrics, CreateInputSystemByPackInputCriblmetricsTypedDict, CreateInputSystemByPackInputCrowdstrike, @@ -52,12 +36,23 @@ CreateInputSystemByPackInputDatadogAgentTypedDict, CreateInputSystemByPackInputDatagen, CreateInputSystemByPackInputDatagenTypedDict, - CreateInputSystemByPackInputFile, - CreateInputSystemByPackInputFileTypedDict, + CreateInputSystemByPackInputEdgePrometheus, + CreateInputSystemByPackInputEdgePrometheusTypedDict, + CreateInputSystemByPackInputElasticType, + CreateInputSystemByPackInputEventhub, + CreateInputSystemByPackInputEventhubAmqp, + CreateInputSystemByPackInputEventhubAmqpTypedDict, + CreateInputSystemByPackInputEventhubTypedDict, + CreateInputSystemByPackInputExec, + CreateInputSystemByPackInputExecTypedDict, + CreateInputSystemByPackInputFirehose, + CreateInputSystemByPackInputFirehoseTypedDict, + CreateInputSystemByPackInputGooglePubsub, + CreateInputSystemByPackInputGooglePubsubTypedDict, + CreateInputSystemByPackInputGrafanaUnion, + CreateInputSystemByPackInputGrafanaUnionTypedDict, CreateInputSystemByPackInputHTTPRaw, CreateInputSystemByPackInputHTTPRawTypedDict, - CreateInputSystemByPackInputJournalFiles, - CreateInputSystemByPackInputJournalFilesTypedDict, CreateInputSystemByPackInputKinesis, CreateInputSystemByPackInputKinesisTypedDict, CreateInputSystemByPackInputKubeEvents, @@ -66,8 +61,72 @@ CreateInputSystemByPackInputKubeLogsTypedDict, CreateInputSystemByPackInputKubeMetrics, CreateInputSystemByPackInputKubeMetricsTypedDict, + CreateInputSystemByPackInputLoki, + CreateInputSystemByPackInputLokiTypedDict, CreateInputSystemByPackInputMetrics, CreateInputSystemByPackInputMetricsTypedDict, + CreateInputSystemByPackInputMicrosoftGraph, + CreateInputSystemByPackInputMicrosoftGraphTypedDict, + CreateInputSystemByPackInputOffice365Mgmt, + CreateInputSystemByPackInputOffice365MgmtTypedDict, + CreateInputSystemByPackInputOffice365MsgTrace, + CreateInputSystemByPackInputOffice365MsgTraceTypedDict, + CreateInputSystemByPackInputOffice365Service, + CreateInputSystemByPackInputOffice365ServiceTypedDict, + CreateInputSystemByPackInputPrometheus, + CreateInputSystemByPackInputPrometheusRw, + CreateInputSystemByPackInputPrometheusRwTypedDict, + CreateInputSystemByPackInputPrometheusTypedDict, + CreateInputSystemByPackInputS3, + CreateInputSystemByPackInputS3Inventory, + CreateInputSystemByPackInputS3InventoryTypedDict, + CreateInputSystemByPackInputS3TypedDict, + CreateInputSystemByPackInputSnmp, + CreateInputSystemByPackInputSnmpTypedDict, + CreateInputSystemByPackInputSystemMetrics, + CreateInputSystemByPackInputSystemMetricsTypedDict, + CreateInputSystemByPackInputSystemState, + CreateInputSystemByPackInputSystemStateTypedDict, + CreateInputSystemByPackInputTcpjson, + CreateInputSystemByPackInputTcpjsonTypedDict, + CreateInputSystemByPackInputWindowsMetrics, + CreateInputSystemByPackInputWindowsMetricsTypedDict, +) +from .createinputsystembypack_v3user import ( + CreateInputSystemByPackInputAkamaiHec, + CreateInputSystemByPackInputAkamaiHecTypedDict, + CreateInputSystemByPackInputAnthropicCompliance, + CreateInputSystemByPackInputAnthropicComplianceTypedDict, + CreateInputSystemByPackInputAnthropicEnterpriseAnalytics, + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsTypedDict, + CreateInputSystemByPackInputAppleUnifiedLogs, + CreateInputSystemByPackInputAppleUnifiedLogsTypedDict, + CreateInputSystemByPackInputAppscope, + CreateInputSystemByPackInputAppscopeTypedDict, + CreateInputSystemByPackInputAquaSecurityHec, + CreateInputSystemByPackInputAquaSecurityHecTypedDict, + CreateInputSystemByPackInputBedrockS3, + CreateInputSystemByPackInputBedrockS3TypedDict, + CreateInputSystemByPackInputBeyondtrustHec, + CreateInputSystemByPackInputBeyondtrustHecTypedDict, + CreateInputSystemByPackInputCloudflareHec, + CreateInputSystemByPackInputCloudflareHecTypedDict, + CreateInputSystemByPackInputExtrahopRevealx360, + CreateInputSystemByPackInputExtrahopRevealx360TypedDict, + CreateInputSystemByPackInputF5BigIP, + CreateInputSystemByPackInputF5BigIPTypedDict, + CreateInputSystemByPackInputFile, + CreateInputSystemByPackInputFileTypedDict, + CreateInputSystemByPackInputGigamonHec, + CreateInputSystemByPackInputGigamonHecTypedDict, + CreateInputSystemByPackInputHashicorpHcpVaultDedicated, + CreateInputSystemByPackInputHashicorpHcpVaultDedicatedTypedDict, + CreateInputSystemByPackInputJournalFiles, + CreateInputSystemByPackInputJournalFilesTypedDict, + CreateInputSystemByPackInputMicrosoftCopilot, + CreateInputSystemByPackInputMicrosoftCopilotTypedDict, + CreateInputSystemByPackInputMimecastHec, + CreateInputSystemByPackInputMimecastHecTypedDict, CreateInputSystemByPackInputModelDrivenTelemetry, CreateInputSystemByPackInputModelDrivenTelemetryTypedDict, CreateInputSystemByPackInputNetflow, @@ -80,18 +139,18 @@ CreateInputSystemByPackInputOpenaiComplianceLogs, CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict, CreateInputSystemByPackInputOpenaiTypedDict, + CreateInputSystemByPackInputPingIdentityPingone, + CreateInputSystemByPackInputPingIdentityPingoneTypedDict, + CreateInputSystemByPackInputProofpointPod, + CreateInputSystemByPackInputProofpointPodTypedDict, CreateInputSystemByPackInputRawUDP, CreateInputSystemByPackInputRawUDPTypedDict, - CreateInputSystemByPackInputS3, - CreateInputSystemByPackInputS3Inventory, - CreateInputSystemByPackInputS3InventoryTypedDict, - CreateInputSystemByPackInputS3TypedDict, + CreateInputSystemByPackInputSailpointHec, + CreateInputSystemByPackInputSailpointHecTypedDict, CreateInputSystemByPackInputSecurityLake, CreateInputSystemByPackInputSecurityLakeTypedDict, CreateInputSystemByPackInputServicenowTable, CreateInputSystemByPackInputServicenowTableTypedDict, - CreateInputSystemByPackInputSnmp, - CreateInputSystemByPackInputSnmpTypedDict, CreateInputSystemByPackInputSqs, CreateInputSystemByPackInputSqsTypedDict, CreateInputSystemByPackInputSysdigHec, @@ -100,14 +159,18 @@ CreateInputSystemByPackInputSyslogUnionTypedDict, CreateInputSystemByPackInputTCP, CreateInputSystemByPackInputTCPTypedDict, + CreateInputSystemByPackInputTrellixHec, + CreateInputSystemByPackInputTrellixHecTypedDict, + CreateInputSystemByPackInputTrendMicroVisionOne, + CreateInputSystemByPackInputTrendMicroVisionOneTypedDict, CreateInputSystemByPackInputUpwindHec, CreateInputSystemByPackInputUpwindHecTypedDict, + CreateInputSystemByPackInputVectraAiHec, + CreateInputSystemByPackInputVectraAiHecTypedDict, CreateInputSystemByPackInputWef, CreateInputSystemByPackInputWefTypedDict, CreateInputSystemByPackInputWinEventLogs, CreateInputSystemByPackInputWinEventLogsTypedDict, - CreateInputSystemByPackInputWindowsMetrics, - CreateInputSystemByPackInputWindowsMetricsTypedDict, CreateInputSystemByPackInputWiz, CreateInputSystemByPackInputWizTypedDict, CreateInputSystemByPackInputWizWebhook, @@ -115,55 +178,22 @@ CreateInputSystemByPackInputZscalerHec, CreateInputSystemByPackInputZscalerHecTypedDict, ) -from .datacompressionformatoptionspersistence import ( - DataCompressionFormatOptionsPersistence, -) -from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict from .extrahttpheaderconfinputelastic import ( ExtraHTTPHeaderConfInputElastic, ExtraHTTPHeaderConfInputElasticTypedDict, ) -from .googleauthenticationmethodoptions import GoogleAuthenticationMethodOptions -from .gputype import GpuType, GpuTypeTypedDict from .kafkaschemaregistryauthenticationtype import ( KafkaSchemaRegistryAuthenticationType, KafkaSchemaRegistryAuthenticationTypeTypedDict, ) -from .logleveloptions import LogLevelOptions -from .logleveloptionscontentconfigitems import LogLevelOptionsContentConfigItems -from .logleveloptionsdebugerror import LogLevelOptionsDebugError from .metadataconfinputcollection import ( MetadataConfInputCollection, MetadataConfInputCollectionTypedDict, ) -from .microsoftentraidauthenticationendpointoptionssasl import ( - MicrosoftEntraIDAuthenticationEndpointOptionsSasl, -) -from .modeoptionshost import ModeOptionsHost from .outputmodeoptionssplunkcollectorconf import OutputModeOptionsSplunkCollectorConf from .pqtype import PqType, PqTypeTypedDict from .preprocesstype import PreprocessType, PreprocessTypeTypedDict -from .processtype import ProcessType, ProcessTypeTypedDict -from .protocoloptionstargetsitems import ProtocolOptionsTargetsItems -from .recordtypeoptions import RecordTypeOptions -from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( - RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, - RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, -) from .retryrulestype import RetryRulesType, RetryRulesTypeTypedDict -from .retryrulestypecodesenableheader import ( - RetryRulesTypeCodesEnableHeader, - RetryRulesTypeCodesEnableHeaderTypedDict, -) -from .searchfilterconfinputprometheus import ( - SearchFilterConfInputPrometheus, - SearchFilterConfInputPrometheusTypedDict, -) -from .subscriptionplanoptions import SubscriptionPlanOptions -from .tlssettingsclientsidetype import ( - TLSSettingsClientSideType, - TLSSettingsClientSideTypeTypedDict, -) from .tlssettingsclientsidetypecapathcertpath import ( TLSSettingsClientSideTypeCaPathCertPath, TLSSettingsClientSideTypeCaPathCertPathTypedDict, @@ -174,13 +204,8 @@ ) from .typeoptions import TypeOptions from .typeoptionsazureblob import TypeOptionsAzureblob -from .typeoptionsconfluentcloud import TypeOptionsConfluentcloud -from .typeoptionscribltcp import TypeOptionsCribltcp -from .typeoptionsgooglepubsub import TypeOptionsGooglepubsub from .typeoptionsmsk import TypeOptionsMsk -from .typeoptionsprometheus import TypeOptionsPrometheus from .typeoptionssplunk import TypeOptionsSplunk -from .typeoptionstcpjson import TypeOptionsTcpjson from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from cribl_control_plane.utils import ( @@ -196,178 +221,133 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict -class CreateInputSystemByPackInputSystemStateType(str, Enum): - r"""Connector type identifier.""" - - SYSTEM_STATE = "system_state" - - -class CreateInputSystemByPackHostsFileTypedDict(TypedDict): - r"""Creates events based on entries collected from the hosts file""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackHostsFile(BaseModel): - r"""Creates events based on entries collected from the hosts file""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInterfacesTypedDict(TypedDict): - r"""Creates events for each of the host’s network interfaces""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackInterfaces(BaseModel): - r"""Creates events for each of the host’s network interfaces""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackDisksAndFileSystemsTypedDict(TypedDict): - r"""Creates events for physical disks, partitions, and file systems""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackDisksAndFileSystems(BaseModel): - r"""Creates events for physical disks, partitions, and file systems""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackHostInfoTypedDict(TypedDict): - r"""Creates events based on the host system’s current state""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackHostInfo(BaseModel): - r"""Creates events based on the host system’s current state""" +class CreateInputSystemByPackInputElasticAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" - enable: Optional[bool] = None - r"""Enabled""" + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Auth Tokens + AUTH_TOKENS = "authTokens" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateInputSystemByPackAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The API version to use for communicating with the server""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + # 6.8.4 + SIX_DOT_8_DOT_4 = "6.8.4" + # 8.3.2 + EIGHT_DOT_3_DOT_2 = "8.3.2" + # Custom + CUSTOM = "custom" - return m +class CreateInputSystemByPackInputElasticAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter credentials directly, or select a stored secret""" -class CreateInputSystemByPackRoutesTypedDict(TypedDict): - r"""Creates events based on entries collected from the host’s network routes""" + NONE = "none" + MANUAL = "manual" + SECRET = "secret" - enable: NotRequired[bool] - r"""Enabled""" +class CreateInputSystemByPackInputElasticProxyModeTypedDict(TypedDict): + enabled: bool + r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" + auth_type: NotRequired[CreateInputSystemByPackInputElasticAuthenticationMethod] + r"""Enter credentials directly, or select a stored secret""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + url: NotRequired[str] + r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + remove_headers: NotRequired[List[str]] + r"""List of headers to remove from the request to proxy""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateInputSystemByPackRoutes(BaseModel): - r"""Creates events based on entries collected from the host’s network routes""" - enable: Optional[bool] = None - r"""Enabled""" +class CreateInputSystemByPackInputElasticProxyMode(BaseModel): + enabled: bool + r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} + auth_type: Annotated[ + Optional[CreateInputSystemByPackInputElasticAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter credentials directly, or select a stored secret""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + username: Optional[str] = None + r"""Username""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + password: Optional[str] = None + r"""Password""" - return m + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + url: Optional[str] = None + r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" -class CreateInputSystemByPackDNSTypedDict(TypedDict): - r"""Creates events for DNS resolvers and search entries""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - enable: NotRequired[bool] - r"""Enabled""" + remove_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="removeHeaders") + ] = None + r"""List of headers to remove from the request to proxy""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" -class CreateInputSystemByPackDNS(BaseModel): - r"""Creates events for DNS resolvers and search entries""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - enable: Optional[bool] = None - r"""Enabled""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputElasticAuthenticationMethod( + value + ) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["enable"]) + optional_fields = set( + [ + "authType", + "username", + "password", + "credentialsSecret", + "url", + "rejectUnauthorized", + "removeHeaders", + "timeoutSec", + "__template_url", + ] + ) serialized = handler(self) m = {} @@ -382,323 +362,17 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackUsersAndGroupsTypedDict(TypedDict): - r"""Creates events for local users and groups""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackUsersAndGroups(BaseModel): - r"""Creates events for local users and groups""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackFirewallTypedDict(TypedDict): - r"""Creates events for Firewall rules entries""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackFirewall(BaseModel): - r"""Creates events for Firewall rules entries""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackServicesTypedDict(TypedDict): - r"""Creates events from the list of services""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackServices(BaseModel): - r"""Creates events from the list of services""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackListeningPortsTypedDict(TypedDict): - r"""Creates events from list of listening ports""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackListeningPorts(BaseModel): - r"""Creates events from list of listening ports""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackLoggedInUsersTypedDict(TypedDict): - r"""Creates events from list of logged-in users""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackLoggedInUsers(BaseModel): - r"""Creates events from list of logged-in users""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackCollectorsTypedDict(TypedDict): - hostsfile: NotRequired[CreateInputSystemByPackHostsFileTypedDict] - r"""Creates events based on entries collected from the hosts file""" - interfaces: NotRequired[CreateInputSystemByPackInterfacesTypedDict] - r"""Creates events for each of the host’s network interfaces""" - disk: NotRequired[CreateInputSystemByPackDisksAndFileSystemsTypedDict] - r"""Creates events for physical disks, partitions, and file systems""" - metadata: NotRequired[CreateInputSystemByPackHostInfoTypedDict] - r"""Creates events based on the host system’s current state""" - routes: NotRequired[CreateInputSystemByPackRoutesTypedDict] - r"""Creates events based on entries collected from the host’s network routes""" - dns: NotRequired[CreateInputSystemByPackDNSTypedDict] - r"""Creates events for DNS resolvers and search entries""" - user: NotRequired[CreateInputSystemByPackUsersAndGroupsTypedDict] - r"""Creates events for local users and groups""" - firewall: NotRequired[CreateInputSystemByPackFirewallTypedDict] - r"""Creates events for Firewall rules entries""" - services: NotRequired[CreateInputSystemByPackServicesTypedDict] - r"""Creates events from the list of services""" - ports: NotRequired[CreateInputSystemByPackListeningPortsTypedDict] - r"""Creates events from list of listening ports""" - login_users: NotRequired[CreateInputSystemByPackLoggedInUsersTypedDict] - r"""Creates events from list of logged-in users""" - - -class CreateInputSystemByPackCollectors(BaseModel): - hostsfile: Optional[CreateInputSystemByPackHostsFile] = None - r"""Creates events based on entries collected from the hosts file""" - - interfaces: Optional[CreateInputSystemByPackInterfaces] = None - r"""Creates events for each of the host’s network interfaces""" - - disk: Optional[CreateInputSystemByPackDisksAndFileSystems] = None - r"""Creates events for physical disks, partitions, and file systems""" - - metadata: Optional[CreateInputSystemByPackHostInfo] = None - r"""Creates events based on the host system’s current state""" - - routes: Optional[CreateInputSystemByPackRoutes] = None - r"""Creates events based on entries collected from the host’s network routes""" - - dns: Optional[CreateInputSystemByPackDNS] = None - r"""Creates events for DNS resolvers and search entries""" - - user: Optional[CreateInputSystemByPackUsersAndGroups] = None - r"""Creates events for local users and groups""" - - firewall: Optional[CreateInputSystemByPackFirewall] = None - r"""Creates events for Firewall rules entries""" - - services: Optional[CreateInputSystemByPackServices] = None - r"""Creates events from the list of services""" - - ports: Optional[CreateInputSystemByPackListeningPorts] = None - r"""Creates events from list of listening ports""" - - login_users: Annotated[ - Optional[CreateInputSystemByPackLoggedInUsers], - pydantic.Field(alias="loginUsers"), - ] = None - r"""Creates events from list of logged-in users""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "hostsfile", - "interfaces", - "disk", - "metadata", - "routes", - "dns", - "user", - "firewall", - "services", - "ports", - "loginUsers", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemStatePersistenceTypedDict(TypedDict): - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" - - -class CreateInputSystemByPackInputSystemStatePersistence(BaseModel): - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemStateTypedDict(TypedDict): +class CreateInputSystemByPackInputElasticTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputSystemStateType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputElasticType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + elastic_api: str + r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -714,8164 +388,191 @@ class CreateInputSystemByPackInputSystemStateTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[CreateInputSystemByPackInputElasticAuthenticationType] + r"""Authentication type""" + api_version: NotRequired[CreateInputSystemByPackAPIVersion] + r"""The API version to use for communicating with the server""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - collectors: NotRequired[CreateInputSystemByPackCollectorsTypedDict] - persistence: NotRequired[ - CreateInputSystemByPackInputSystemStatePersistenceTypedDict - ] - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" - disable_native_last_log_module: NotRequired[bool] - r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + proxy_mode: NotRequired[CreateInputSystemByPackInputElasticProxyModeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + auth_tokens: NotRequired[List[str]] + r"""Bearer tokens to include in the authorization header""" + custom_api_version: NotRequired[str] + r"""Custom version information to respond to requests""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_elastic_api: NotRequired[str] + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" -class CreateInputSystemByPackInputSystemState(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputSystemStateType - r"""Connector type identifier.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - interval: Optional[float] = None - r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - collectors: Optional[CreateInputSystemByPackCollectors] = None - - persistence: Optional[CreateInputSystemByPackInputSystemStatePersistence] = None - - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") - ] = None - r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" - - disable_native_last_log_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeLastLogModule") - ] = None - r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "interval", - "metadata", - "collectors", - "persistence", - "disableNativeModule", - "disableNativeLastLogModule", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsType(str, Enum): - r"""Connector type identifier.""" - - SYSTEM_METRICS = "system_metrics" - - -class CreateInputSystemByPackInputSystemMetricsSystemMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for system metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputSystemByPackInputSystemMetricsSystemTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputSystemMetricsSystemMode] - r"""Select the level of detail for system metrics""" - processes: NotRequired[bool] - r"""Generate metrics for the numbers of processes in various states""" - - -class CreateInputSystemByPackInputSystemMetricsSystem(BaseModel): - mode: Optional[CreateInputSystemByPackInputSystemMetricsSystemMode] = None - r"""Select the level of detail for system metrics""" - - processes: Optional[bool] = None - r"""Generate metrics for the numbers of processes in various states""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputSystemMetricsSystemMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "processes"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsCPUMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for CPU metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputSystemByPackInputSystemMetricsCPUTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputSystemMetricsCPUMode] - r"""Select the level of detail for CPU metrics""" - per_cpu: NotRequired[bool] - r"""Generate metrics for each CPU""" - detail: NotRequired[bool] - r"""Generate metrics for all CPU states""" - time: NotRequired[bool] - r"""Generate raw, monotonic CPU time counters""" - - -class CreateInputSystemByPackInputSystemMetricsCPU(BaseModel): - mode: Optional[CreateInputSystemByPackInputSystemMetricsCPUMode] = None - r"""Select the level of detail for CPU metrics""" - - per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None - r"""Generate metrics for each CPU""" - - detail: Optional[bool] = None - r"""Generate metrics for all CPU states""" - - time: Optional[bool] = None - r"""Generate raw, monotonic CPU time counters""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputSystemMetricsCPUMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perCpu", "detail", "time"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsMemoryMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for memory metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputSystemByPackInputSystemMetricsMemoryTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputSystemMetricsMemoryMode] - r"""Select the level of detail for memory metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all memory states""" - - -class CreateInputSystemByPackInputSystemMetricsMemory(BaseModel): - mode: Optional[CreateInputSystemByPackInputSystemMetricsMemoryMode] = None - r"""Select the level of detail for memory metrics""" - - detail: Optional[bool] = None - r"""Generate metrics for all memory states""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputSystemMetricsMemoryMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsNetworkMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for network metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputSystemByPackInputSystemMetricsNetworkTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputSystemMetricsNetworkMode] - r"""Select the level of detail for network metrics""" - detail: NotRequired[bool] - r"""Generate full network metrics""" - protocols: NotRequired[bool] - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - devices: NotRequired[List[str]] - r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" - per_interface: NotRequired[bool] - r"""Generate separate metrics for each interface""" - - -class CreateInputSystemByPackInputSystemMetricsNetwork(BaseModel): - mode: Optional[CreateInputSystemByPackInputSystemMetricsNetworkMode] = None - r"""Select the level of detail for network metrics""" - - detail: Optional[bool] = None - r"""Generate full network metrics""" - - protocols: Optional[bool] = None - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - - devices: Optional[List[str]] = None - r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" - - per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( - None - ) - r"""Generate separate metrics for each interface""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputSystemMetricsNetworkMode( - value - ) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["mode", "detail", "protocols", "devices", "perInterface"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsDiskMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for disk metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputSystemByPackInputSystemMetricsDiskTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputSystemMetricsDiskMode] - r"""Select the level of detail for disk metrics""" - detail: NotRequired[bool] - r"""Generate full disk metrics""" - inodes: NotRequired[bool] - r"""Generate filesystem inode metrics""" - devices: NotRequired[List[str]] - r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" - mountpoints: NotRequired[List[str]] - r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" - fstypes: NotRequired[List[str]] - r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" - per_device: NotRequired[bool] - r"""Generate separate metrics for each device""" - - -class CreateInputSystemByPackInputSystemMetricsDisk(BaseModel): - mode: Optional[CreateInputSystemByPackInputSystemMetricsDiskMode] = None - r"""Select the level of detail for disk metrics""" - - detail: Optional[bool] = None - r"""Generate full disk metrics""" - - inodes: Optional[bool] = None - r"""Generate filesystem inode metrics""" - - devices: Optional[List[str]] = None - r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" - - mountpoints: Optional[List[str]] = None - r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" - - fstypes: Optional[List[str]] = None - r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" - - per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None - r"""Generate separate metrics for each device""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputSystemMetricsDiskMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mode", - "detail", - "inodes", - "devices", - "mountpoints", - "fstypes", - "perDevice", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsCustomTypedDict(TypedDict): - system: NotRequired[CreateInputSystemByPackInputSystemMetricsSystemTypedDict] - cpu: NotRequired[CreateInputSystemByPackInputSystemMetricsCPUTypedDict] - memory: NotRequired[CreateInputSystemByPackInputSystemMetricsMemoryTypedDict] - network: NotRequired[CreateInputSystemByPackInputSystemMetricsNetworkTypedDict] - disk: NotRequired[CreateInputSystemByPackInputSystemMetricsDiskTypedDict] - - -class CreateInputSystemByPackInputSystemMetricsCustom(BaseModel): - system: Optional[CreateInputSystemByPackInputSystemMetricsSystem] = None - - cpu: Optional[CreateInputSystemByPackInputSystemMetricsCPU] = None - - memory: Optional[CreateInputSystemByPackInputSystemMetricsMemory] = None - - network: Optional[CreateInputSystemByPackInputSystemMetricsNetwork] = None - - disk: Optional[CreateInputSystemByPackInputSystemMetricsDisk] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["system", "cpu", "memory", "network", "disk"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsHostTypedDict(TypedDict): - mode: NotRequired[ModeOptionsHost] - r"""Select level of detail for host metrics""" - custom: NotRequired[CreateInputSystemByPackInputSystemMetricsCustomTypedDict] - - -class CreateInputSystemByPackInputSystemMetricsHost(BaseModel): - mode: Optional[ModeOptionsHost] = None - r"""Select level of detail for host metrics""" - - custom: Optional[CreateInputSystemByPackInputSystemMetricsCustom] = None - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptionsHost(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "custom"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackContainerMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for container metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputSystemByPackInputSystemMetricsFilterTypedDict(TypedDict): - expr: str - r"""Expression""" - - -class CreateInputSystemByPackInputSystemMetricsFilter(BaseModel): - expr: str - r"""Expression""" - - -class CreateInputSystemByPackContainerTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackContainerMode] - r"""Select the level of detail for container metrics""" - docker_socket: NotRequired[List[str]] - r"""Full paths for Docker's UNIX-domain socket""" - docker_timeout: NotRequired[float] - r"""Timeout, in seconds, for the Docker API""" - filters: NotRequired[List[CreateInputSystemByPackInputSystemMetricsFilterTypedDict]] - r"""Containers matching any of these will be included. All are included if no filters are added.""" - all_containers: NotRequired[bool] - r"""Include stopped and paused containers""" - per_device: NotRequired[bool] - r"""Generate separate metrics for each device""" - detail: NotRequired[bool] - r"""Generate full container metrics""" - - -class CreateInputSystemByPackContainer(BaseModel): - mode: Optional[CreateInputSystemByPackContainerMode] = None - r"""Select the level of detail for container metrics""" - - docker_socket: Annotated[ - Optional[List[str]], pydantic.Field(alias="dockerSocket") - ] = None - r"""Full paths for Docker's UNIX-domain socket""" - - docker_timeout: Annotated[ - Optional[float], pydantic.Field(alias="dockerTimeout") - ] = None - r"""Timeout, in seconds, for the Docker API""" - - filters: Optional[List[CreateInputSystemByPackInputSystemMetricsFilter]] = None - r"""Containers matching any of these will be included. All are included if no filters are added.""" - - all_containers: Annotated[Optional[bool], pydantic.Field(alias="allContainers")] = ( - None - ) - r"""Include stopped and paused containers""" - - per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None - r"""Generate separate metrics for each device""" - - detail: Optional[bool] = None - r"""Generate full container metrics""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackContainerMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mode", - "dockerSocket", - "dockerTimeout", - "filters", - "allContainers", - "perDevice", - "detail", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" - - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" - - -class CreateInputSystemByPackInputSystemMetricsPersistence(BaseModel): - r"""persistence""" - - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputSystemMetricsTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputSystemMetricsType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - host: NotRequired[CreateInputSystemByPackInputSystemMetricsHostTypedDict] - process: NotRequired[ProcessTypeTypedDict] - container: NotRequired[CreateInputSystemByPackContainerTypedDict] - gpu: NotRequired[GpuTypeTypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - persistence: NotRequired[ - CreateInputSystemByPackInputSystemMetricsPersistenceTypedDict - ] - r"""persistence""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputSystemByPackInputSystemMetrics(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputSystemMetricsType - r"""Connector type identifier.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - - host: Optional[CreateInputSystemByPackInputSystemMetricsHost] = None - - process: Optional[ProcessType] = None - - container: Optional[CreateInputSystemByPackContainer] = None - - gpu: Optional[GpuType] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - persistence: Optional[CreateInputSystemByPackInputSystemMetricsPersistence] = None - r"""persistence""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "interval", - "host", - "process", - "container", - "gpu", - "metadata", - "persistence", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputTcpjsonTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsTcpjson - r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateInputSystemByPackInputTcpjson(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsTcpjson - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") - ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") - ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") - ] = None - r"""Load balance traffic across all Worker Processes""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "enableLoadBalancing", - "authType", - "description", - "authToken", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputCriblLakeHTTPType(str, Enum): - r"""Source type identifier.""" - - CRIBL_LAKE_HTTP = "cribl_lake_http" - - -class CreateInputSystemByPackSplunkHecMetadataTypedDict(TypedDict): - enabled: NotRequired[bool] - r"""When enabled, the token value is available on events as __hecToken""" - default_dataset: NotRequired[str] - allowed_indexes_at_token: NotRequired[List[str]] - - -class CreateInputSystemByPackSplunkHecMetadata(BaseModel): - enabled: Optional[bool] = None - r"""When enabled, the token value is available on events as __hecToken""" - - default_dataset: Annotated[ - Optional[str], pydantic.Field(alias="defaultDataset") - ] = None - - allowed_indexes_at_token: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackElasticsearchMetadataTypedDict(TypedDict): - enabled: NotRequired[bool] - r"""Elasticsearch""" - default_dataset: NotRequired[str] - - -class CreateInputSystemByPackElasticsearchMetadata(BaseModel): - enabled: Optional[bool] = None - r"""Elasticsearch""" - - default_dataset: Annotated[ - Optional[str], pydantic.Field(alias="defaultDataset") - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "defaultDataset"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackAuthTokensExtTypedDict(TypedDict): - token: str - r"""Token""" - description: NotRequired[str] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this token""" - splunk_hec_metadata: NotRequired[CreateInputSystemByPackSplunkHecMetadataTypedDict] - elasticsearch_metadata: NotRequired[ - CreateInputSystemByPackElasticsearchMetadataTypedDict - ] - - -class CreateInputSystemByPackAuthTokensExt(BaseModel): - token: str - r"""Token""" - - description: Optional[str] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this token""" - - splunk_hec_metadata: Annotated[ - Optional[CreateInputSystemByPackSplunkHecMetadata], - pydantic.Field(alias="splunkHecMetadata"), - ] = None - - elasticsearch_metadata: Annotated[ - Optional[CreateInputSystemByPackElasticsearchMetadata], - pydantic.Field(alias="elasticsearchMetadata"), - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["description", "metadata", "splunkHecMetadata", "elasticsearchMetadata"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputCriblLakeHTTPTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCriblLakeHTTPType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - cribl_api: NotRequired[str] - r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" - elastic_api: NotRequired[str] - r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" - splunk_hec_api: NotRequired[str] - r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" - splunk_hec_acks: NotRequired[bool] - r"""Enable Splunk HEC acknowledgements""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[CreateInputSystemByPackAuthTokensExtTypedDict]] - r"""Auth tokens""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_cribl_api: NotRequired[str] - r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" - template_elastic_api: NotRequired[str] - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - template_splunk_hec_api: NotRequired[str] - r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - - -class CreateInputSystemByPackInputCriblLakeHTTP(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputCriblLakeHTTPType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - cribl_api: Annotated[Optional[str], pydantic.Field(alias="criblAPI")] = None - r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" - - elastic_api: Annotated[Optional[str], pydantic.Field(alias="elasticAPI")] = None - r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" - - splunk_hec_api: Annotated[Optional[str], pydantic.Field(alias="splunkHecAPI")] = ( - None - ) - r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" - - splunk_hec_acks: Annotated[ - Optional[bool], pydantic.Field(alias="splunkHecAcks") - ] = None - r"""Enable Splunk HEC acknowledgements""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_tokens_ext: Annotated[ - Optional[List[CreateInputSystemByPackAuthTokensExt]], - pydantic.Field(alias="authTokensExt"), - ] = None - r"""Auth tokens""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - template_cribl_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_criblAPI") - ] = None - r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" - - template_elastic_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticAPI") - ] = None - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - - template_splunk_hec_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_splunkHecAPI") - ] = None - r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "criblAPI", - "elasticAPI", - "splunkHecAPI", - "splunkHecAcks", - "metadata", - "authTokensExt", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_criblAPI", - "__template_elasticAPI", - "__template_splunkHecAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputCriblHTTPType(str, Enum): - r"""Source type identifier.""" - - CRIBL_HTTP = "cribl_http" - - -class CreateInputSystemByPackInputCriblHTTPTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCriblHTTPType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateInputSystemByPackInputCriblHTTP(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputCriblHTTPType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputCriblTCPTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsCribltcp - r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateInputSystemByPackInputCriblTCP(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsCribltcp - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") - ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") - ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") - ] = None - r"""Load balance traffic across all Worker Processes""" - - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "enableLoadBalancing", - "authTokens", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputCriblType(str, Enum): - r"""Connector type identifier.""" - - CRIBL = "cribl" - - -class CreateInputSystemByPackInputCriblTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCriblType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - filter_: NotRequired[str] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputSystemByPackInputCribl(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputCriblType - r"""Connector type identifier.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "filter", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputGooglePubsubTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsGooglepubsub - r"""Connector type identifier.""" - topic_name: str - r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" - subscription_name: str - r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - monitor_subscription: NotRequired[bool] - r"""Use when the subscription is not created by this Source and topic is not known""" - create_topic: NotRequired[bool] - r"""Create topic if it does not exist""" - create_subscription: NotRequired[bool] - r"""Create subscription if it does not exist""" - region: NotRequired[str] - r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - max_backlog: NotRequired[float] - r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" - concurrency: NotRequired[float] - r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" - request_timeout: NotRequired[float] - r"""Pull request timeout, in milliseconds""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - ordered_delivery: NotRequired[bool] - r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: NotRequired[str] - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - template_subscription_name: NotRequired[str] - r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - -class CreateInputSystemByPackInputGooglePubsub(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsGooglepubsub - r"""Connector type identifier.""" - - topic_name: Annotated[str, pydantic.Field(alias="topicName")] - r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" - - subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] - r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - monitor_subscription: Annotated[ - Optional[bool], pydantic.Field(alias="monitorSubscription") - ] = None - r"""Use when the subscription is not created by this Source and topic is not known""" - - create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None - r"""Create topic if it does not exist""" - - create_subscription: Annotated[ - Optional[bool], pydantic.Field(alias="createSubscription") - ] = None - r"""Create subscription if it does not exist""" - - region: Optional[str] = None - r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - - google_auth_method: Annotated[ - Optional[GoogleAuthenticationMethodOptions], - pydantic.Field(alias="googleAuthMethod"), - ] = None - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") - ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - - secret: Optional[str] = None - r"""Select or create a stored text secret""" - - max_backlog: Annotated[Optional[float], pydantic.Field(alias="maxBacklog")] = None - r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" - - concurrency: Optional[float] = None - r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Pull request timeout, in milliseconds""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - ordered_delivery: Annotated[ - Optional[bool], pydantic.Field(alias="orderedDelivery") - ] = None - r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_topic_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicName") - ] = None - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - - template_subscription_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_subscriptionName") - ] = None - r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): - if isinstance(value, str): - try: - return models.GoogleAuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "monitorSubscription", - "createTopic", - "createSubscription", - "region", - "googleAuthMethod", - "serviceAccountCredentials", - "secret", - "maxBacklog", - "concurrency", - "requestTimeout", - "metadata", - "description", - "orderedDelivery", - "__template_environment", - "__template_streamtags", - "__template_topicName", - "__template_subscriptionName", - "__template_region", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputFirehoseType(str, Enum): - r"""Source type identifier.""" - - FIREHOSE = "firehose" - - -class CreateInputSystemByPackInputFirehoseTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputFirehoseType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - -class CreateInputSystemByPackInputFirehose(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputFirehoseType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputExecType(str, Enum): - r"""Connector type identifier.""" - - EXEC = "exec" - - -class CreateInputSystemByPackScheduleType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - - INTERVAL = "interval" - CRON_SCHEDULE = "cronSchedule" - - -class CreateInputSystemByPackInputExecTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputExecType - r"""Connector type identifier.""" - command: str - r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" - disabled: NotRequired[bool] - r"""Disabled""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - script: NotRequired[str] - r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" - retries: NotRequired[float] - r"""Maximum number of retry attempts in the event that the command fails""" - schedule_type: NotRequired[CreateInputSystemByPackScheduleType] - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - interval: NotRequired[float] - r"""Interval between command executions in seconds.""" - cron_schedule: NotRequired[str] - r"""Cron schedule to execute the command on.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputSystemByPackInputExec(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputExecType - r"""Connector type identifier.""" - - command: str - r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" - - disabled: Optional[bool] = None - r"""Disabled""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - script: Optional[str] = None - r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" - - retries: Optional[float] = None - r"""Maximum number of retry attempts in the event that the command fails""" - - schedule_type: Annotated[ - Optional[CreateInputSystemByPackScheduleType], - pydantic.Field(alias="scheduleType"), - ] = None - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - interval: Optional[float] = None - r"""Interval between command executions in seconds.""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Cron schedule to execute the command on.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @field_serializer("schedule_type") - def serialize_schedule_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackScheduleType(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "script", - "retries", - "scheduleType", - "breakerRulesets", - "staleChannelFlushMs", - "metadata", - "description", - "interval", - "cronSchedule", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputEventhubAmqpType(str, Enum): - r"""Connector type identifier.""" - - EVENTHUB_AMQP = "eventhub_amqp" - - -class CreateInputSystemByPackAuthenticationMechanism( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication mechanism""" - - # Connection String - CONNECTION_STRING = "connection-string" - # OAuth Bearer - OAUTH_BEARER = "oauth-bearer" - - -class CreateInputSystemByPackCertificateTypedDict(TypedDict): - certificate_name: str - r"""The certificate you registered as credentials for your app in the Azure portal""" - cert_path: str - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - priv_key_path: str - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - - -class CreateInputSystemByPackCertificate(BaseModel): - certificate_name: Annotated[str, pydantic.Field(alias="certificateName")] - r"""The certificate you registered as credentials for your app in the Azure portal""" - - cert_path: Annotated[str, pydantic.Field(alias="certPath")] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - - priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["passphrase"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackAuthTypedDict(TypedDict): - mechanism: CreateInputSystemByPackAuthenticationMechanism - r"""Authentication mechanism""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] - r"""Authentication method""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CreateInputSystemByPackCertificateTypedDict] - oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] - r"""Endpoint used to acquire authentication tokens from Azure""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory""" - fully_qualified_namespace: NotRequired[str] - r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" - template_oauth_endpoint: NotRequired[str] - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_fully_qualified_namespace: NotRequired[str] - r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" - - -class CreateInputSystemByPackAuth(BaseModel): - mechanism: CreateInputSystemByPackAuthenticationMechanism - r"""Authentication mechanism""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - client_secret_auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuth], - pydantic.Field(alias="clientSecretAuthType"), - ] = None - r"""Authentication method""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[CreateInputSystemByPackCertificate] = None - - oauth_endpoint: Annotated[ - Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], - pydantic.Field(alias="oauthEndpoint"), - ] = None - r"""Endpoint used to acquire authentication tokens from Azure""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory""" - - fully_qualified_namespace: Annotated[ - Optional[str], pydantic.Field(alias="fullyQualifiedNamespace") - ] = None - r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" - - template_oauth_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_oauthEndpoint") - ] = None - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_fully_qualified_namespace: Annotated[ - Optional[str], pydantic.Field(alias="__template_fullyQualifiedNamespace") - ] = None - r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" - - @field_serializer("mechanism") - def serialize_mechanism(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackAuthenticationMechanism(value) - except ValueError: - return value - return value - - @field_serializer("client_secret_auth_type") - def serialize_client_secret_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuth(value) - except ValueError: - return value - return value - - @field_serializer("oauth_endpoint") - def serialize_oauth_endpoint(self, value): - if isinstance(value, str): - try: - return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "textSecret", - "clientSecretAuthType", - "clientTextSecret", - "certificate", - "oauthEndpoint", - "clientId", - "tenantId", - "fullyQualifiedNamespace", - "__template_oauthEndpoint", - "__template_clientId", - "__template_tenantId", - "__template_fullyQualifiedNamespace", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method""" - - SECRET = "secret" - CLIENT_SECRET = "clientSecret" - CLIENT_CERT = "clientCert" - CLIENT_ASSERTION = "clientAssertion" - CLIENT_ASSERTION_RPC = "clientAssertion_rpc" - - -class CreateInputSystemByPackAzureBlobStorageTypedDict(TypedDict): - r"""Azure Blob Storage""" - - container_name: str - r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" - auth_type: NotRequired[CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod] - r"""Authentication method""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - storage_account_name: NotRequired[str] - r"""The name of your Azure storage account""" - tenant_id: NotRequired[str] - r"""The service principal's tenant ID""" - client_id: NotRequired[str] - r"""The service principal's client ID""" - azure_cloud: NotRequired[str] - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - endpoint_suffix: NotRequired[str] - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CertificateTypeTypedDict] - template_storage_account_name: NotRequired[str] - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_azure_cloud: NotRequired[str] - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - -class CreateInputSystemByPackAzureBlobStorage(BaseModel): - r"""Azure Blob Storage""" - - container_name: Annotated[str, pydantic.Field(alias="containerName")] - r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" - - auth_type: Annotated[ - Optional[CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Authentication method""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="storageAccountName") - ] = None - r"""The name of your Azure storage account""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""The service principal's tenant ID""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""The service principal's client ID""" - - azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - - endpoint_suffix: Annotated[ - Optional[str], pydantic.Field(alias="endpointSuffix") - ] = None - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[CertificateType] = None - - template_storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageAccountName") - ] = None - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_azure_cloud: Annotated[ - Optional[str], pydantic.Field(alias="__template_azureCloud") - ] = None - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return ( - models.CreateInputSystemByPackInputEventhubAmqpAuthenticationMethod( - value - ) - ) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "textSecret", - "storageAccountName", - "tenantId", - "clientId", - "azureCloud", - "endpointSuffix", - "clientTextSecret", - "certificate", - "__template_storageAccountName", - "__template_tenantId", - "__template_clientId", - "__template_azureCloud", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackCheckpointingTypedDict(TypedDict): - blob_store: CreateInputSystemByPackAzureBlobStorageTypedDict - r"""Azure Blob Storage""" - - -class CreateInputSystemByPackCheckpointing(BaseModel): - blob_store: Annotated[ - CreateInputSystemByPackAzureBlobStorage, pydantic.Field(alias="blobStore") - ] - r"""Azure Blob Storage""" - - -class CreateInputSystemByPackInputEventhubAmqpTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputEventhubAmqpType - r"""Connector type identifier.""" - consumer_group: str - r"""The consumer group this instance belongs to. Default is '$Default'.""" - checkpointing: CreateInputSystemByPackCheckpointingTypedDict - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - event_hub_name: NotRequired[str] - r"""The name of the Event Hub to consume from""" - auth: NotRequired[CreateInputSystemByPackAuthTypedDict] - from_beginning: NotRequired[bool] - r"""Start reading from earliest available data; relevant only during initial subscription""" - max_batch_size: NotRequired[int] - r"""Maximum number of events in each batch delivered to the consumer""" - max_wait_time_in_seconds: NotRequired[int] - r"""Maximum time to wait for a batch of events before delivering a partial batch""" - prefetch_count: NotRequired[int] - r"""Number of events to prefetch from the service for processing""" - max_retries: NotRequired[int] - r"""Maximum number of retries per operation""" - initial_backoff: NotRequired[int] - r"""Initial delay before the first retry, in milliseconds""" - max_backoff: NotRequired[int] - r"""Maximum delay between retries, in milliseconds""" - timeout_in_ms: NotRequired[int] - r"""Maximum time to wait for a request to complete""" - connection_initial_backoff: NotRequired[int] - r"""Initial delay before the first reconnection attempt, in milliseconds""" - connection_max_backoff: NotRequired[int] - r"""Maximum delay between reconnection attempts, in milliseconds""" - connection_timeout_in_ms: NotRequired[int] - r"""Maximum time to wait for a connection to complete""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputSystemByPackInputEventhubAmqp(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputEventhubAmqpType - r"""Connector type identifier.""" - - consumer_group: Annotated[str, pydantic.Field(alias="consumerGroup")] - r"""The consumer group this instance belongs to. Default is '$Default'.""" - - checkpointing: CreateInputSystemByPackCheckpointing - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - event_hub_name: Annotated[Optional[str], pydantic.Field(alias="eventHubName")] = ( - None - ) - r"""The name of the Event Hub to consume from""" - - auth: Optional[CreateInputSystemByPackAuth] = None - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Start reading from earliest available data; relevant only during initial subscription""" - - max_batch_size: Annotated[Optional[int], pydantic.Field(alias="maxBatchSize")] = ( - None - ) - r"""Maximum number of events in each batch delivered to the consumer""" - - max_wait_time_in_seconds: Annotated[ - Optional[int], pydantic.Field(alias="maxWaitTimeInSeconds") - ] = None - r"""Maximum time to wait for a batch of events before delivering a partial batch""" - - prefetch_count: Annotated[Optional[int], pydantic.Field(alias="prefetchCount")] = ( - None - ) - r"""Number of events to prefetch from the service for processing""" - - max_retries: Annotated[Optional[int], pydantic.Field(alias="maxRetries")] = None - r"""Maximum number of retries per operation""" - - initial_backoff: Annotated[ - Optional[int], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial delay before the first retry, in milliseconds""" - - max_backoff: Annotated[Optional[int], pydantic.Field(alias="maxBackoff")] = None - r"""Maximum delay between retries, in milliseconds""" - - timeout_in_ms: Annotated[Optional[int], pydantic.Field(alias="timeoutInMs")] = None - r"""Maximum time to wait for a request to complete""" - - connection_initial_backoff: Annotated[ - Optional[int], pydantic.Field(alias="connectionInitialBackoff") - ] = None - r"""Initial delay before the first reconnection attempt, in milliseconds""" - - connection_max_backoff: Annotated[ - Optional[int], pydantic.Field(alias="connectionMaxBackoff") - ] = None - r"""Maximum delay between reconnection attempts, in milliseconds""" - - connection_timeout_in_ms: Annotated[ - Optional[int], pydantic.Field(alias="connectionTimeoutInMs") - ] = None - r"""Maximum time to wait for a connection to complete""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "eventHubName", - "auth", - "fromBeginning", - "maxBatchSize", - "maxWaitTimeInSeconds", - "prefetchCount", - "maxRetries", - "initialBackoff", - "maxBackoff", - "timeoutInMs", - "connectionInitialBackoff", - "connectionMaxBackoff", - "connectionTimeoutInMs", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputEventhubType(str, Enum): - r"""Connector type identifier.""" - - EVENTHUB = "eventhub" - - -class CreateInputSystemByPackInputEventhubTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputEventhubType - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - topics: List[str] - r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - group_id: NotRequired[str] - r"""The consumer group this instance belongs to. Default is 'Cribl'.""" - from_beginning: NotRequired[bool] - r"""Start reading from earliest available data; relevant only during initial subscription""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeUseTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeTypedDict] - r"""TLS settings (client side)""" - session_timeout: NotRequired[float] - r""" - Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - rebalance_timeout: NotRequired[float] - r""" - Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - heartbeat_interval: NotRequired[float] - r""" - Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - auto_commit_interval: NotRequired[float] - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - auto_commit_threshold: NotRequired[float] - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - max_bytes_per_partition: NotRequired[float] - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - max_bytes: NotRequired[float] - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - max_socket_errors: NotRequired[float] - r"""Maximum number of network errors before the consumer re-creates a socket""" - minimize_duplicates: NotRequired[bool] - r"""Minimize duplicate events by starting only one consumer for each topic partition""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topics: NotRequired[str] - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - template_group_id: NotRequired[str] - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - -class CreateInputSystemByPackInputEventhub(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputEventhubType - r"""Connector type identifier.""" - - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - - topics: List[str] - r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None - r"""The consumer group this instance belongs to. Default is 'Cribl'.""" - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Start reading from earliest available data; relevant only during initial subscription""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Maximum time to wait for a connection to complete successfully""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" - - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") - ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - - sasl: Optional[AuthenticationTypeUse] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - - tls: Optional[TLSSettingsClientSideType] = None - r"""TLS settings (client side)""" - - session_timeout: Annotated[ - Optional[float], pydantic.Field(alias="sessionTimeout") - ] = None - r""" - Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - rebalance_timeout: Annotated[ - Optional[float], pydantic.Field(alias="rebalanceTimeout") - ] = None - r""" - Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - heartbeat_interval: Annotated[ - Optional[float], pydantic.Field(alias="heartbeatInterval") - ] = None - r""" - Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - auto_commit_interval: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitInterval") - ] = None - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - auto_commit_threshold: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitThreshold") - ] = None - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - max_bytes_per_partition: Annotated[ - Optional[float], pydantic.Field(alias="maxBytesPerPartition") - ] = None - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - - max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - - max_socket_errors: Annotated[ - Optional[float], pydantic.Field(alias="maxSocketErrors") - ] = None - r"""Maximum number of network errors before the consumer re-creates a socket""" - - minimize_duplicates: Annotated[ - Optional[bool], pydantic.Field(alias="minimizeDuplicates") - ] = None - r"""Minimize duplicate events by starting only one consumer for each topic partition""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") - ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - - template_topics: Annotated[ - Optional[str], pydantic.Field(alias="__template_topics") - ] = None - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - - template_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_groupId") - ] = None - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "groupId", - "fromBeginning", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "tls", - "sessionTimeout", - "rebalanceTimeout", - "heartbeatInterval", - "autoCommitInterval", - "autoCommitThreshold", - "maxBytesPerPartition", - "maxBytes", - "maxSocketErrors", - "minimizeDuplicates", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_brokers", - "__template_topics", - "__template_groupId", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputMicrosoftGraphType(str, Enum): - r"""Connector type identifier.""" - - MICROSOFT_GRAPH = "microsoft_graph" - - -class CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select authentication method.""" - - OAUTH = "oauth" - OAUTH_SECRET = "oauthSecret" - OAUTH_CERT = "oauthCert" - - -class CreateInputSystemByPackSubscriptionPlan(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - # Microsoft 365 Enterprise - ENTERPRISE_GCC = "enterprise_gcc" - # Microsoft 365 GCC - GCC = "gcc" - # Microsoft 365 GCC High - GCC_HIGH = "gcc_high" - # Microsoft 365 DoD - DOD = "dod" - # Microsoft 365 China (21Vianet) - CHINA = "china" - - -class CreateInputSystemByPackInputMicrosoftGraphTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputMicrosoftGraphType - r"""Connector type identifier.""" - url: str - r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - start_date: NotRequired[str] - r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - end_date: NotRequired[str] - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - disable_time_filter: NotRequired[bool] - r"""Disables time filtering of events when a date range is specified.""" - max_pages: NotRequired[int] - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - auth_type: NotRequired[ - CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod - ] - r"""Select authentication method.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - reschedule_dropped_tasks: NotRequired[bool] - r"""Reschedule tasks that failed with non-fatal errors""" - max_task_reschedule: NotRequired[float] - r"""Maximum number of times a task can be rescheduled""" - log_level: NotRequired[LogLevelOptionsDebugError] - r"""Log Level (verbosity) for collection runtime behavior.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""client_secret to pass in the OAuth request parameter.""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter.""" - resource: NotRequired[str] - r"""Resource to pass in the OAuth request parameter.""" - plan_type: NotRequired[CreateInputSystemByPackSubscriptionPlan] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - text_secret: NotRequired[str] - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - cert_options: NotRequired[CertOptionsTypeTypedDict] - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_resource: NotRequired[str] - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - -class CreateInputSystemByPackInputMicrosoftGraph(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputMicrosoftGraphType - r"""Connector type identifier.""" - - url: str - r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" - - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None - r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - - end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - - disable_time_filter: Annotated[ - Optional[bool], pydantic.Field(alias="disableTimeFilter") - ] = None - r"""Disables time filtering of events when a date range is specified.""" - - max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - - auth_type: Annotated[ - Optional[CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Select authentication method.""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - reschedule_dropped_tasks: Annotated[ - Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") - ] = None - r"""Reschedule tasks that failed with non-fatal errors""" - - max_task_reschedule: Annotated[ - Optional[float], pydantic.Field(alias="maxTaskReschedule") - ] = None - r"""Maximum number of times a task can be rescheduled""" - - log_level: Annotated[ - Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") - ] = None - r"""Log Level (verbosity) for collection runtime behavior.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""client_secret to pass in the OAuth request parameter.""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter.""" - - resource: Optional[str] = None - r"""Resource to pass in the OAuth request parameter.""" - - plan_type: Annotated[ - Optional[CreateInputSystemByPackSubscriptionPlan], - pydantic.Field(alias="planType"), - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - - cert_options: Annotated[ - Optional[CertOptionsType], pydantic.Field(alias="certOptions") - ] = None - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_resource: Annotated[ - Optional[str], pydantic.Field(alias="__template_resource") - ] = None - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputMicrosoftGraphAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsDebugError(value) - except ValueError: - return value - return value - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackSubscriptionPlan(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "startDate", - "endDate", - "timeout", - "disableTimeFilter", - "maxPages", - "authType", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "rescheduleDroppedTasks", - "maxTaskReschedule", - "logLevel", - "retryRules", - "breakerRulesets", - "staleChannelFlushMs", - "description", - "clientSecret", - "tenantId", - "clientId", - "resource", - "planType", - "textSecret", - "certOptions", - "__template_environment", - "__template_streamtags", - "__template_url", - "__template_tenantId", - "__template_clientId", - "__template_resource", - "__template_planType", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputOffice365MsgTraceType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_MSG_TRACE = "office365_msg_trace" - - -class CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select authentication method.""" - - MANUAL = "manual" - SECRET = "secret" - OAUTH = "oauth" - OAUTH_SECRET = "oauthSecret" - OAUTH_CERT = "oauthCert" - - -class CreateInputSystemByPackInputOffice365MsgTraceTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOffice365MsgTraceType - r"""Connector type identifier.""" - url: str - r"""URL to use when retrieving report data.""" - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - start_date: NotRequired[str] - r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - end_date: NotRequired[str] - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - disable_time_filter: NotRequired[bool] - r"""Disables time filtering of events when a date range is specified.""" - auth_type: NotRequired[ - CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod - ] - r"""Select authentication method.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - reschedule_dropped_tasks: NotRequired[bool] - r"""Reschedule tasks that failed with non-fatal errors""" - max_task_reschedule: NotRequired[float] - r"""Maximum number of times a task can be rescheduled""" - log_level: NotRequired[LogLevelOptionsDebugError] - r"""Log Level (verbosity) for collection runtime behavior.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username to run Message Trace API call.""" - password: NotRequired[str] - r"""Password to run Message Trace API call.""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials.""" - client_secret: NotRequired[str] - r"""client_secret to pass in the OAuth request parameter.""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter.""" - resource: NotRequired[str] - r"""Resource to pass in the OAuth request parameter.""" - plan_type: NotRequired[SubscriptionPlanOptions] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - text_secret: NotRequired[str] - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - cert_options: NotRequired[CertOptionsTypeTypedDict] - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_resource: NotRequired[str] - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - -class CreateInputSystemByPackInputOffice365MsgTrace(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputOffice365MsgTraceType - r"""Connector type identifier.""" - - url: str - r"""URL to use when retrieving report data.""" - - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None - r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - - end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - - disable_time_filter: Annotated[ - Optional[bool], pydantic.Field(alias="disableTimeFilter") - ] = None - r"""Disables time filtering of events when a date range is specified.""" - - auth_type: Annotated[ - Optional[CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Select authentication method.""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - reschedule_dropped_tasks: Annotated[ - Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") - ] = None - r"""Reschedule tasks that failed with non-fatal errors""" - - max_task_reschedule: Annotated[ - Optional[float], pydantic.Field(alias="maxTaskReschedule") - ] = None - r"""Maximum number of times a task can be rescheduled""" - - log_level: Annotated[ - Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") - ] = None - r"""Log Level (verbosity) for collection runtime behavior.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username to run Message Trace API call.""" - - password: Optional[str] = None - r"""Password to run Message Trace API call.""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""client_secret to pass in the OAuth request parameter.""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter.""" - - resource: Optional[str] = None - r"""Resource to pass in the OAuth request parameter.""" - - plan_type: Annotated[ - Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - - cert_options: Annotated[ - Optional[CertOptionsType], pydantic.Field(alias="certOptions") - ] = None - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_resource: Annotated[ - Optional[str], pydantic.Field(alias="__template_resource") - ] = None - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputOffice365MsgTraceAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsDebugError(value) - except ValueError: - return value - return value - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "startDate", - "endDate", - "timeout", - "disableTimeFilter", - "authType", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "rescheduleDroppedTasks", - "maxTaskReschedule", - "logLevel", - "retryRules", - "description", - "username", - "password", - "credentialsSecret", - "clientSecret", - "tenantId", - "clientId", - "resource", - "planType", - "textSecret", - "certOptions", - "__template_environment", - "__template_streamtags", - "__template_url", - "__template_tenantId", - "__template_clientId", - "__template_resource", - "__template_planType", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputOffice365ServiceType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_SERVICE = "office365_service" - - -class CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict(TypedDict): - content_type: NotRequired[str] - r"""Microsoft 365 Services API Content Type""" - description: NotRequired[str] - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - interval: NotRequired[float] - r"""Interval""" - log_level: NotRequired[LogLevelOptionsContentConfigItems] - r"""Collector runtime Log Level""" - enabled: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackInputOffice365ServiceContentConfig(BaseModel): - content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None - r"""Microsoft 365 Services API Content Type""" - - description: Optional[str] = None - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - - interval: Optional[float] = None - r"""Interval""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime Log Level""" - - enabled: Optional[bool] = None - r"""Enabled""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["contentType", "description", "interval", "logLevel", "enabled"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputOffice365ServiceTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOffice365ServiceType - r"""Connector type identifier.""" - tenant_id: str - r"""Microsoft 365 Azure Tenant ID""" - app_id: str - r"""Microsoft 365 Azure Application ID""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - plan_type: NotRequired[SubscriptionPlanOptions] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout, use 0 to disable""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - content_config: NotRequired[ - List[CreateInputSystemByPackInputOffice365ServiceContentConfigTypedDict] - ] - r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""Microsoft 365 Azure client secret""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_app_id: NotRequired[str] - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - -class CreateInputSystemByPackInputOffice365Service(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputOffice365ServiceType - r"""Connector type identifier.""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Microsoft 365 Azure Tenant ID""" - - app_id: Annotated[str, pydantic.Field(alias="appId")] - r"""Microsoft 365 Azure Application ID""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - plan_type: Annotated[ - Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout, use 0 to disable""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - content_config: Annotated[ - Optional[List[CreateInputSystemByPackInputOffice365ServiceContentConfig]], - pydantic.Field(alias="contentConfig"), - ] = None - r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""Microsoft 365 Azure client secret""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_app_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_appId") - ] = None - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsManualSecret(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "planType", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "contentConfig", - "retryRules", - "authType", - "description", - "clientSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_planType", - "__template_tenantId", - "__template_appId", - "__template_clientSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputOffice365MgmtType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_MGMT = "office365_mgmt" - - -class CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict(TypedDict): - content_type: NotRequired[str] - r"""Microsoft 365 Management Activity API Content Type""" - description: NotRequired[str] - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - interval: NotRequired[float] - r"""Interval""" - log_level: NotRequired[LogLevelOptionsContentConfigItems] - r"""Collector runtime Log Level""" - enabled: NotRequired[bool] - r"""Enabled""" - - -class CreateInputSystemByPackInputOffice365MgmtContentConfig(BaseModel): - content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None - r"""Microsoft 365 Management Activity API Content Type""" - - description: Optional[str] = None - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - - interval: Optional[float] = None - r"""Interval""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime Log Level""" - - enabled: Optional[bool] = None - r"""Enabled""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["contentType", "description", "interval", "logLevel", "enabled"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputOffice365MgmtTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOffice365MgmtType - r"""Connector type identifier.""" - plan_type: SubscriptionPlanOptions - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - tenant_id: str - r"""Microsoft 365 Azure Tenant ID""" - app_id: str - r"""Microsoft 365 Azure Application ID""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - timeout: NotRequired[float] - r"""HTTP request inactivity timeout, use 0 to disable""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - publisher_identifier: NotRequired[str] - r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" - content_config: NotRequired[ - List[CreateInputSystemByPackInputOffice365MgmtContentConfigTypedDict] - ] - r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" - ingestion_lag: NotRequired[float] - r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""Microsoft 365 Azure client secret""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_app_id: NotRequired[str] - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - template_publisher_identifier: NotRequired[str] - r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - -class CreateInputSystemByPackInputOffice365Mgmt(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputOffice365MgmtType - r"""Connector type identifier.""" - - plan_type: Annotated[SubscriptionPlanOptions, pydantic.Field(alias="planType")] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Microsoft 365 Azure Tenant ID""" - - app_id: Annotated[str, pydantic.Field(alias="appId")] - r"""Microsoft 365 Azure Application ID""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout, use 0 to disable""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - publisher_identifier: Annotated[ - Optional[str], pydantic.Field(alias="publisherIdentifier") - ] = None - r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" - - content_config: Annotated[ - Optional[List[CreateInputSystemByPackInputOffice365MgmtContentConfig]], - pydantic.Field(alias="contentConfig"), - ] = None - r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" - - ingestion_lag: Annotated[Optional[float], pydantic.Field(alias="ingestionLag")] = ( - None - ) - r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""Microsoft 365 Azure client secret""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_app_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_appId") - ] = None - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - - template_publisher_identifier: Annotated[ - Optional[str], pydantic.Field(alias="__template_publisherIdentifier") - ] = None - r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsManualSecret(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "publisherIdentifier", - "contentConfig", - "ingestionLag", - "retryRules", - "authType", - "description", - "clientSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_planType", - "__template_tenantId", - "__template_appId", - "__template_publisherIdentifier", - "__template_clientSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputEdgePrometheusType(str, Enum): - r"""Connector type identifier.""" - - EDGE_PROMETHEUS = "edge_prometheus" - - -class CreateInputSystemByPackInputEdgePrometheusDiscoveryType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - # Static - STATIC = "static" - # DNS - DNS = "dns" - # AWS EC2 - EC2 = "ec2" - # Kubernetes Node - K8S_NODE = "k8s-node" - # Kubernetes Pods - K8S_PODS = "k8s-pods" - # Kubernetes Service Monitor (v4.18+) - K8S_SERVICE_MONITOR = "k8s-service-monitor" - # HTTP SD - HTTP_SD = "http_sd" - - -class CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter credentials directly, or select a stored secret""" - - MANUAL = "manual" - SECRET = "secret" - KUBERNETES = "kubernetes" - - -class CreateInputSystemByPackTargetTypedDict(TypedDict): - host: str - r"""Name of host from which to pull metrics.""" - protocol: NotRequired[ProtocolOptionsTargetsItems] - r"""Protocol to use when collecting metrics""" - port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets.""" - path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - - -class CreateInputSystemByPackTarget(BaseModel): - host: str - r"""Name of host from which to pull metrics.""" - - protocol: Optional[ProtocolOptionsTargetsItems] = None - r"""Protocol to use when collecting metrics""" - - port: Optional[float] = None - r"""The port number in the metrics URL for discovered targets.""" - - path: Optional[str] = None - r"""Path to use when collecting metrics from discovered targets""" - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptionsTargetsItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["protocol", "port", "path"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackPodFilterTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" - description: NotRequired[str] - r"""Optional description of this rule's purpose""" - - -class CreateInputSystemByPackPodFilter(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" - - description: Optional[str] = None - r"""Optional description of this rule's purpose""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputEdgePrometheusTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputEdgePrometheusType - r"""Connector type identifier.""" - discovery_type: CreateInputSystemByPackInputEdgePrometheusDiscoveryType - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - interval: float - r"""How often in seconds to scrape targets for metrics.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - dimension_list: NotRequired[List[str]] - r"""Other dimensions to include in events""" - field_per_metric: NotRequired[bool] - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - timeout: NotRequired[float] - r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" - persistence: NotRequired[DiskSpoolingTypeTypedDict] - r"""Disk Spooling""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_type: NotRequired[ - CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod - ] - r"""Enter credentials directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - targets: NotRequired[List[CreateInputSystemByPackTargetTypedDict]] - r"""Targets""" - record_type: NotRequired[RecordTypeOptions] - r"""DNS record type to resolve""" - scrape_port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets.""" - name_list: NotRequired[List[str]] - r"""List of DNS names to resolve""" - scrape_protocol: NotRequired[ProtocolOptionsTargetsItems] - r"""Protocol to use when collecting metrics""" - scrape_path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - use_public_ip: NotRequired[bool] - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] - r"""Filter to apply when searching for EC2 instances""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the EC2 is located""" - endpoint: NotRequired[str] - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access EC2""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - service_monitor_namespace: NotRequired[str] - r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" - scrape_protocol_expr: NotRequired[str] - r"""Protocol to use when collecting metrics""" - scrape_port_expr: NotRequired[str] - r"""The port number in the metrics URL for discovered targets.""" - scrape_path_expr: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - pod_filter: NotRequired[List[CreateInputSystemByPackPodFilterTypedDict]] - r""" - Add rules to decide which pods to discover for metrics. - Pods are searched if no rules are given or of all the rules' - expressions evaluate to true. - - """ - http_discovery_url: NotRequired[str] - r"""URL to fetch target groups from (must be http or https)""" - http_discovery_headers: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Extra headers to send with the discovery request""" - http_discovery_reject_unauthorized: NotRequired[bool] - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - max_response_body_size: NotRequired[str] - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - username: NotRequired[str] - r"""Username for Prometheus Basic authentication""" - password: NotRequired[str] - r"""Password for Prometheus Basic authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_dimension_list: NotRequired[str] - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - template_name_list: NotRequired[str] - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - -class CreateInputSystemByPackInputEdgePrometheus(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputEdgePrometheusType - r"""Connector type identifier.""" - - discovery_type: Annotated[ - CreateInputSystemByPackInputEdgePrometheusDiscoveryType, - pydantic.Field(alias="discoveryType"), - ] - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - interval: float - r"""How often in seconds to scrape targets for metrics.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - dimension_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="dimensionList") - ] = None - r"""Other dimensions to include in events""" - - field_per_metric: Annotated[ - Optional[bool], pydantic.Field(alias="fieldPerMetric") - ] = None - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - - timeout: Optional[float] = None - r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" - - persistence: Optional[DiskSpoolingType] = None - r"""Disk Spooling""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_type: Annotated[ - Optional[CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Enter credentials directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - targets: Optional[List[CreateInputSystemByPackTarget]] = None - r"""Targets""" - - record_type: Annotated[ - Optional[RecordTypeOptions], pydantic.Field(alias="recordType") - ] = None - r"""DNS record type to resolve""" - - scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None - r"""The port number in the metrics URL for discovered targets.""" - - name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None - r"""List of DNS names to resolve""" - - scrape_protocol: Annotated[ - Optional[ProtocolOptionsTargetsItems], pydantic.Field(alias="scrapeProtocol") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None - r"""Path to use when collecting metrics from discovered targets""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - - search_filter: Annotated[ - Optional[List[SearchFilterConfInputPrometheus]], - pydantic.Field(alias="searchFilter"), - ] = None - r"""Filter to apply when searching for EC2 instances""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""Region where the EC2 is located""" - - endpoint: Optional[str] = None - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access EC2""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - service_monitor_namespace: Annotated[ - Optional[str], pydantic.Field(alias="serviceMonitorNamespace") - ] = None - r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" - - scrape_protocol_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapeProtocolExpr") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_port_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapePortExpr") - ] = None - r"""The port number in the metrics URL for discovered targets.""" - - scrape_path_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapePathExpr") - ] = None - r"""Path to use when collecting metrics from discovered targets""" - - pod_filter: Annotated[ - Optional[List[CreateInputSystemByPackPodFilter]], - pydantic.Field(alias="podFilter"), - ] = None - r""" - Add rules to decide which pods to discover for metrics. - Pods are searched if no rules are given or of all the rules' - expressions evaluate to true. - - """ - - http_discovery_url: Annotated[ - Optional[str], pydantic.Field(alias="httpDiscoveryUrl") - ] = None - r"""URL to fetch target groups from (must be http or https)""" - - http_discovery_headers: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="httpDiscoveryHeaders"), - ] = None - r"""Extra headers to send with the discovery request""" - - http_discovery_reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") - ] = None - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - - max_response_body_size: Annotated[ - Optional[str], pydantic.Field(alias="maxResponseBodySize") - ] = None - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - - username: Optional[str] = None - r"""Username for Prometheus Basic authentication""" - - password: Optional[str] = None - r"""Password for Prometheus Basic authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_dimension_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_dimensionList") - ] = None - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - - template_name_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_nameList") - ] = None - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - @field_serializer("discovery_type") - def serialize_discovery_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputEdgePrometheusDiscoveryType( - value - ) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputEdgePrometheusAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("record_type") - def serialize_record_type(self, value): - if isinstance(value, str): - try: - return models.RecordTypeOptions(value) - except ValueError: - return value - return value - - @field_serializer("scrape_protocol") - def serialize_scrape_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptionsTargetsItems(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "dimensionList", - "fieldPerMetric", - "timeout", - "persistence", - "metadata", - "authType", - "description", - "targets", - "recordType", - "scrapePort", - "nameList", - "scrapeProtocol", - "scrapePath", - "awsAuthenticationMethod", - "awsApiKey", - "awsSecret", - "usePublicIp", - "searchFilter", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "serviceMonitorNamespace", - "scrapeProtocolExpr", - "scrapePortExpr", - "scrapePathExpr", - "podFilter", - "httpDiscoveryUrl", - "httpDiscoveryHeaders", - "httpDiscoveryRejectUnauthorized", - "maxResponseBodySize", - "username", - "password", - "credentialsSecret", - "__template_environment", - "__template_streamtags", - "__template_dimensionList", - "__template_nameList", - "__template_awsApiKey", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputPrometheusDiscoveryType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - # Static - STATIC = "static" - # DNS - DNS = "dns" - # AWS EC2 - EC2 = "ec2" - # HTTP SD - HTTP_SD = "http_sd" - - -class CreateInputSystemByPackMetricsProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Protocol to use when collecting metrics""" - - HTTP = "http" - HTTPS = "https" - - -class CreateInputSystemByPackInputPrometheusTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsPrometheus - r"""Connector type identifier.""" - interval: float - r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" - log_level: LogLevelOptions - r"""Collector runtime log level""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - dimension_list: NotRequired[List[str]] - r"""Other dimensions to include in events""" - field_per_metric: NotRequired[bool] - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - discovery_type: NotRequired[CreateInputSystemByPackInputPrometheusDiscoveryType] - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - timeout: NotRequired[float] - r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_type: NotRequired[AuthenticationMethodOptionsSasl] - r"""Enter credentials directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - target_list: NotRequired[List[str]] - r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" - record_type: NotRequired[RecordTypeOptions] - r"""DNS record type to resolve""" - scrape_port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets""" - name_list: NotRequired[List[str]] - r"""List of DNS names to resolve""" - scrape_protocol: NotRequired[CreateInputSystemByPackMetricsProtocol] - r"""Protocol to use when collecting metrics""" - scrape_path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - use_public_ip: NotRequired[bool] - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] - r"""Filter to apply when searching for EC2 instances""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the EC2 is located""" - endpoint: NotRequired[str] - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access EC2""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - http_discovery_url: NotRequired[str] - r"""URL to fetch target groups from (must be http or https)""" - http_discovery_headers: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Extra headers to send with the discovery request""" - http_discovery_reject_unauthorized: NotRequired[bool] - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - max_response_body_size: NotRequired[str] - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - username: NotRequired[str] - r"""Username for Prometheus Basic authentication""" - password: NotRequired[str] - r"""Password for Prometheus Basic authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_dimension_list: NotRequired[str] - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - template_discovery_type: NotRequired[str] - r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" - template_log_level: NotRequired[str] - r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - template_target_list: NotRequired[str] - r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" - template_name_list: NotRequired[str] - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - template_password: NotRequired[str] - r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" - - -class CreateInputSystemByPackInputPrometheus(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsPrometheus - r"""Connector type identifier.""" - - interval: float - r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" - - log_level: Annotated[LogLevelOptions, pydantic.Field(alias="logLevel")] - r"""Collector runtime log level""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - dimension_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="dimensionList") - ] = None - r"""Other dimensions to include in events""" - - field_per_metric: Annotated[ - Optional[bool], pydantic.Field(alias="fieldPerMetric") - ] = None - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - - discovery_type: Annotated[ - Optional[CreateInputSystemByPackInputPrometheusDiscoveryType], - pydantic.Field(alias="discoveryType"), - ] = None - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - timeout: Optional[float] = None - r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsSasl], pydantic.Field(alias="authType") - ] = None - r"""Enter credentials directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - target_list: Annotated[Optional[List[str]], pydantic.Field(alias="targetList")] = ( - None - ) - r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" - - record_type: Annotated[ - Optional[RecordTypeOptions], pydantic.Field(alias="recordType") - ] = None - r"""DNS record type to resolve""" - - scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None - r"""The port number in the metrics URL for discovered targets""" - - name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None - r"""List of DNS names to resolve""" - - scrape_protocol: Annotated[ - Optional[CreateInputSystemByPackMetricsProtocol], - pydantic.Field(alias="scrapeProtocol"), - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None - r"""Path to use when collecting metrics from discovered targets""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - - search_filter: Annotated[ - Optional[List[SearchFilterConfInputPrometheus]], - pydantic.Field(alias="searchFilter"), - ] = None - r"""Filter to apply when searching for EC2 instances""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""Region where the EC2 is located""" - - endpoint: Optional[str] = None - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access EC2""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - http_discovery_url: Annotated[ - Optional[str], pydantic.Field(alias="httpDiscoveryUrl") - ] = None - r"""URL to fetch target groups from (must be http or https)""" - - http_discovery_headers: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="httpDiscoveryHeaders"), - ] = None - r"""Extra headers to send with the discovery request""" - - http_discovery_reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") - ] = None - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - - max_response_body_size: Annotated[ - Optional[str], pydantic.Field(alias="maxResponseBodySize") - ] = None - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - - username: Optional[str] = None - r"""Username for Prometheus Basic authentication""" - - password: Optional[str] = None - r"""Password for Prometheus Basic authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_dimension_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_dimensionList") - ] = None - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - - template_discovery_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_discoveryType") - ] = None - r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" - - template_log_level: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLevel") - ] = None - r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - - template_target_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_targetList") - ] = None - r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" - - template_name_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_nameList") - ] = None - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - template_password: Annotated[ - Optional[str], pydantic.Field(alias="__template_password") - ] = None - r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" - - @field_serializer("discovery_type") - def serialize_discovery_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputPrometheusDiscoveryType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsSasl(value) - except ValueError: - return value - return value - - @field_serializer("record_type") - def serialize_record_type(self, value): - if isinstance(value, str): - try: - return models.RecordTypeOptions(value) - except ValueError: - return value - return value - - @field_serializer("scrape_protocol") - def serialize_scrape_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackMetricsProtocol(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "dimensionList", - "fieldPerMetric", - "discoveryType", - "rejectUnauthorized", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "authType", - "description", - "targetList", - "recordType", - "scrapePort", - "nameList", - "scrapeProtocol", - "scrapePath", - "awsAuthenticationMethod", - "awsApiKey", - "awsSecret", - "usePublicIp", - "searchFilter", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "httpDiscoveryUrl", - "httpDiscoveryHeaders", - "httpDiscoveryRejectUnauthorized", - "maxResponseBodySize", - "username", - "password", - "credentialsSecret", - "__template_environment", - "__template_streamtags", - "__template_dimensionList", - "__template_discoveryType", - "__template_logLevel", - "__template_targetList", - "__template_nameList", - "__template_awsApiKey", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_username", - "__template_password", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputPrometheusRwType(str, Enum): - r"""Source type identifier.""" - - PROMETHEUS_RW = "prometheus_rw" - - -class CreateInputSystemByPackInputPrometheusRwTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputPrometheusRwType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - prometheus_api: str - r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - -class CreateInputSystemByPackInputPrometheusRw(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputPrometheusRwType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] - r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "metadata", - "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_username", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputLokiType(str, Enum): - r"""Source type identifier.""" - - LOKI = "loki" - - -class CreateInputSystemByPackInputLokiTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputLokiType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - loki_api: str - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - -class CreateInputSystemByPackInputLoki(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputLokiType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "metadata", - "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_lokiAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputGrafanaType2(str, Enum): - r"""Source type identifier.""" - - GRAFANA = "grafana" - - -class CreateInputSystemByPackPrometheusAuth2TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputSystemByPackPrometheusAuth2(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackLokiAuth2TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputSystemByPackLokiAuth2(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputGrafanaGrafana2TypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputGrafanaType2 - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - loki_api: str - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - prometheus_api: NotRequired[str] - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - prometheus_auth: NotRequired[CreateInputSystemByPackPrometheusAuth2TypedDict] - loki_auth: NotRequired[CreateInputSystemByPackLokiAuth2TypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - -class CreateInputSystemByPackInputGrafanaGrafana2(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputGrafanaType2 - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - prometheus_api: Annotated[Optional[str], pydantic.Field(alias="prometheusAPI")] = ( - None - ) - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - - prometheus_auth: Annotated[ - Optional[CreateInputSystemByPackPrometheusAuth2], - pydantic.Field(alias="prometheusAuth"), - ] = None - - loki_auth: Annotated[ - Optional[CreateInputSystemByPackLokiAuth2], pydantic.Field(alias="lokiAuth") - ] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "prometheusAPI", - "prometheusAuth", - "lokiAuth", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_lokiAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputGrafanaType1(str, Enum): - r"""Source type identifier.""" - - GRAFANA = "grafana" - - -class CreateInputSystemByPackPrometheusAuth1TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputSystemByPackPrometheusAuth1(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackLokiAuth1TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateInputSystemByPackLokiAuth1(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputGrafanaGrafana1TypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputGrafanaType1 - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - prometheus_api: str - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - loki_api: NotRequired[str] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - prometheus_auth: NotRequired[CreateInputSystemByPackPrometheusAuth1TypedDict] - loki_auth: NotRequired[CreateInputSystemByPackLokiAuth1TypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - -class CreateInputSystemByPackInputGrafanaGrafana1(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputGrafanaType1 - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - loki_api: Annotated[Optional[str], pydantic.Field(alias="lokiAPI")] = None - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - - prometheus_auth: Annotated[ - Optional[CreateInputSystemByPackPrometheusAuth1], - pydantic.Field(alias="prometheusAuth"), - ] = None - - loki_auth: Annotated[ - Optional[CreateInputSystemByPackLokiAuth1], pydantic.Field(alias="lokiAuth") - ] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "lokiAPI", - "prometheusAuth", - "lokiAuth", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_lokiAPI", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -CreateInputSystemByPackInputGrafanaUnionTypedDict = TypeAliasType( - "CreateInputSystemByPackInputGrafanaUnionTypedDict", - Union[ - CreateInputSystemByPackInputGrafanaGrafana1TypedDict, - CreateInputSystemByPackInputGrafanaGrafana2TypedDict, - ], -) - - -CreateInputSystemByPackInputGrafanaUnion = TypeAliasType( - "CreateInputSystemByPackInputGrafanaUnion", - Union[ - CreateInputSystemByPackInputGrafanaGrafana1, - CreateInputSystemByPackInputGrafanaGrafana2, - ], -) - - -class CreateInputSystemByPackInputConfluentCloudTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsConfluentcloud - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" - topics: List[str] - r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - group_id: NotRequired[str] - r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" - from_beginning: NotRequired[bool] - r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" - kafka_schema_registry: NotRequired[KafkaSchemaRegistryAuthenticationTypeTypedDict] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - session_timeout: NotRequired[float] - r""" - Timeout used to detect client failures when using Kafka's group-management facilities. - If the client sends no heartbeats to the broker before the timeout expires, - the broker will remove the client from the group and initiate a rebalance. - Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. - See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. - """ - rebalance_timeout: NotRequired[float] - r""" - Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. - """ - heartbeat_interval: NotRequired[float] - r""" - Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. - """ - auto_commit_interval: NotRequired[float] - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - auto_commit_threshold: NotRequired[float] - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - max_bytes_per_partition: NotRequired[float] - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - max_bytes: NotRequired[float] - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - max_socket_errors: NotRequired[float] - r"""Maximum number of network errors before the consumer re-creates a socket""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topics: NotRequired[str] - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - template_group_id: NotRequired[str] - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - -class CreateInputSystemByPackInputConfluentCloud(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsConfluentcloud - r"""Connector type identifier.""" - - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" - - topics: List[str] - r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None - r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" - - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationType], - pydantic.Field(alias="kafkaSchemaRegistry"), - ] = None - r"""Kafka Schema Registry Authentication""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Maximum time to wait for a connection to complete successfully""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" - - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") - ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - - session_timeout: Annotated[ - Optional[float], pydantic.Field(alias="sessionTimeout") - ] = None - r""" - Timeout used to detect client failures when using Kafka's group-management facilities. - If the client sends no heartbeats to the broker before the timeout expires, - the broker will remove the client from the group and initiate a rebalance. - Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. - See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. - """ - - rebalance_timeout: Annotated[ - Optional[float], pydantic.Field(alias="rebalanceTimeout") - ] = None - r""" - Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. - """ - - heartbeat_interval: Annotated[ - Optional[float], pydantic.Field(alias="heartbeatInterval") - ] = None - r""" - Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. - """ - - auto_commit_interval: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitInterval") - ] = None - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - auto_commit_threshold: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitThreshold") - ] = None - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - max_bytes_per_partition: Annotated[ - Optional[float], pydantic.Field(alias="maxBytesPerPartition") - ] = None - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - - max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - - max_socket_errors: Annotated[ - Optional[float], pydantic.Field(alias="maxSocketErrors") - ] = None - r"""Maximum number of network errors before the consumer re-creates a socket""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") - ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - - template_topics: Annotated[ - Optional[str], pydantic.Field(alias="__template_topics") - ] = None - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - - template_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_groupId") - ] = None - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "groupId", - "fromBeginning", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "sessionTimeout", - "rebalanceTimeout", - "heartbeatInterval", - "autoCommitInterval", - "autoCommitThreshold", - "maxBytesPerPartition", - "maxBytes", - "maxSocketErrors", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_brokers", - "__template_topics", - "__template_groupId", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateInputSystemByPackInputElastic(BaseModel): + id: str + r"""Unique ID for this input""" - return m + type: CreateInputSystemByPackInputElasticType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" -class CreateInputSystemByPackInputElasticType(str, Enum): - r"""Source type identifier.""" + port: float + r"""Port to listen on""" - ELASTIC = "elastic" + elastic_api: Annotated[str, pydantic.Field(alias="elasticAPI")] + r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" -class CreateInputSystemByPackInputElasticAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Auth Tokens - AUTH_TOKENS = "authTokens" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" -class CreateInputSystemByPackAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The API version to use for communicating with the server""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - # 6.8.4 - SIX_DOT_8_DOT_4 = "6.8.4" - # 8.3.2 - EIGHT_DOT_3_DOT_2 = "8.3.2" - # Custom - CUSTOM = "custom" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" -class CreateInputSystemByPackInputElasticAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter credentials directly, or select a stored secret""" + pq: Optional[PqType] = None - NONE = "none" - MANUAL = "manual" - SECRET = "secret" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" -class CreateInputSystemByPackInputElasticProxyModeTypedDict(TypedDict): - enabled: bool - r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" - auth_type: NotRequired[CreateInputSystemByPackInputElasticAuthenticationMethod] - r"""Enter credentials directly, or select a stored secret""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - url: NotRequired[str] - r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - remove_headers: NotRequired[List[str]] - r"""List of headers to remove from the request to proxy""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" -class CreateInputSystemByPackInputElasticProxyMode(BaseModel): - enabled: bool - r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" auth_type: Annotated[ - Optional[CreateInputSystemByPackInputElasticAuthenticationMethod], + Optional[CreateInputSystemByPackInputElasticAuthenticationType], pydantic.Field(alias="authType"), ] = None - r"""Enter credentials directly, or select a stored secret""" + r"""Authentication type""" + + api_version: Annotated[ + Optional[CreateInputSystemByPackAPIVersion], pydantic.Field(alias="apiVersion") + ] = None + r"""The API version to use for communicating with the server""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + proxy_mode: Annotated[ + Optional[CreateInputSystemByPackInputElasticProxyMode], + pydantic.Field(alias="proxyMode"), + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" username: Optional[str] = None r"""Username""" @@ -8884,51 +585,107 @@ class CreateInputSystemByPackInputElasticProxyMode(BaseModel): ] = None r"""Select or create a secret that references your credentials""" - url: Optional[str] = None - r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Bearer tokens to include in the authorization header""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + custom_api_version: Annotated[ + Optional[str], pydantic.Field(alias="customAPIVersion") ] = None - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + r"""Custom version information to respond to requests""" - remove_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="removeHeaders") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""List of headers to remove from the request to proxy""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_elastic_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticAPI") + ] = None + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackInputElasticAuthenticationMethod( + return models.CreateInputSystemByPackInputElasticAuthenticationType( value ) except ValueError: return value return value + @field_serializer("api_version") + def serialize_api_version(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackAPIVersion(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", "authType", + "apiVersion", + "extraHttpHeaders", + "metadata", + "proxyMode", + "description", "username", "password", "credentialsSecret", - "url", - "rejectUnauthorized", - "removeHeaders", - "timeoutSec", - "__template_url", + "authTokens", + "customAPIVersion", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_elasticAPI", + "__template_authTokens", ] ) serialized = handler(self) @@ -8945,17 +702,19 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputElasticTypedDict(TypedDict): +class CreateInputSystemByPackInputAzureVnetFlowLogType(str, Enum): + r"""Connector type identifier.""" + + AZURE_VNET_FLOW_LOG = "azure_vnet_flow_log" + + +class CreateInputSystemByPackInputAzureVnetFlowLogTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputElasticType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - elastic_api: str - r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" + type: CreateInputSystemByPackInputAzureVnetFlowLogType + r"""Connector type identifier.""" + queue_name: str + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8971,80 +730,68 @@ class CreateInputSystemByPackInputElasticTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[CreateInputSystemByPackInputElasticAuthenticationType] - r"""Authentication type""" - api_version: NotRequired[CreateInputSystemByPackAPIVersion] - r"""The API version to use for communicating with the server""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + visibility_timeout: NotRequired[float] + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + max_messages: NotRequired[float] + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" + max_dequeue_count: NotRequired[float] + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" + service_period_secs: NotRequired[float] + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - proxy_mode: NotRequired[CreateInputSystemByPackInputElasticProxyModeTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] + r"""Authentication method""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - auth_tokens: NotRequired[List[str]] - r"""Bearer tokens to include in the authorization header""" - custom_api_version: NotRequired[str] - r"""Custom version information to respond to requests""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_elastic_api: NotRequired[str] - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" -class CreateInputSystemByPackInputElastic(BaseModel): +class CreateInputSystemByPackInputAzureVnetFlowLog(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputElasticType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" + type: CreateInputSystemByPackInputAzureVnetFlowLogType + r"""Connector type identifier.""" - elastic_api: Annotated[str, pydantic.Field(alias="elasticAPI")] - r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -9071,112 +818,82 @@ class CreateInputSystemByPackInputElastic(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") ] = None - r"""Add request headers to events, in the __headers field""" + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + max_dequeue_count: Annotated[ + Optional[float], pydantic.Field(alias="maxDequeueCount") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + service_period_secs: Annotated[ + Optional[float], pydantic.Field(alias="servicePeriodSecs") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" auth_type: Annotated[ - Optional[CreateInputSystemByPackInputElasticAuthenticationType], + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], pydantic.Field(alias="authType"), ] = None - r"""Authentication type""" - - api_version: Annotated[ - Optional[CreateInputSystemByPackAPIVersion], pydantic.Field(alias="apiVersion") - ] = None - r"""The API version to use for communicating with the server""" + r"""Authentication method""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - proxy_mode: Annotated[ - Optional[CreateInputSystemByPackInputElasticProxyMode], - pydantic.Field(alias="proxyMode"), + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") ] = None + r"""The name of your Azure storage account""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" - username: Optional[str] = None - r"""Username""" + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" - password: Optional[str] = None - r"""Password""" + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") ] = None - r"""Select or create a secret that references your credentials""" - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Bearer tokens to include in the authorization header""" + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - custom_api_version: Annotated[ - Optional[str], pydantic.Field(alias="customAPIVersion") + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") ] = None - r"""Custom version information to respond to requests""" + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -9188,46 +905,44 @@ class CreateInputSystemByPackInputElastic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_elastic_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticAPI") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackInputElasticAuthenticationType( - value + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) ) except ValueError: return value return value - @field_serializer("api_version") - def serialize_api_version(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackAPIVersion(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -9240,35 +955,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "apiVersion", - "extraHttpHeaders", + "fileFilter", + "visibilityTimeout", + "numReceivers", + "maxMessages", + "maxDequeueCount", + "servicePeriodSecs", "metadata", - "proxyMode", + "breakerRulesets", + "staleChannelFlushMs", + "authType", "description", - "username", - "password", - "credentialsSecret", - "authTokens", - "customAPIVersion", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", - "__template_elasticAPI", - "__template_authTokens", + "__template_queueName", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", ] ) serialized = handler(self) @@ -9319,6 +1031,8 @@ class CreateInputSystemByPackInputAzureBlobTypedDict(TypedDict): r"""The duration (in seconds) which pollers should be validated and restarted if exited""" skip_on_error: NotRequired[bool] r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] @@ -9331,6 +1045,8 @@ class CreateInputSystemByPackInputAzureBlobTypedDict(TypedDict): r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" auth_type: NotRequired[AuthenticationMethodOptions] r"""Authentication method""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" connection_string: NotRequired[str] @@ -9427,6 +1143,9 @@ class CreateInputSystemByPackInputAzureBlob(BaseModel): skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -9455,6 +1174,9 @@ class CreateInputSystemByPackInputAzureBlob(BaseModel): ] = None r"""Authentication method""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -9559,12 +1281,14 @@ def serialize_model(self, handler): "maxMessages", "servicePeriodSecs", "skipOnError", + "encoding", "metadata", "breakerRulesets", "staleChannelFlushMs", "parquetChunkSizeMB", "parquetChunkDownloadTimeout", "authType", + "autoParse", "description", "connectionString", "textSecret", @@ -9608,7 +1332,7 @@ class CreateInputSystemByPackInputSplunkHecType(str, Enum): class CreateInputSystemByPackInputSplunkHecAuthTokenTypedDict(TypedDict): token: str r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" token_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -9627,7 +1351,7 @@ class CreateInputSystemByPackInputSplunkHecAuthToken(BaseModel): r"""Shared secret to be provided by any client (Authorization: )""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -9653,7 +1377,7 @@ class CreateInputSystemByPackInputSplunkHecAuthToken(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -9746,6 +1470,8 @@ class CreateInputSystemByPackInputSplunkHecTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" use_fwd_timezone: NotRequired[bool] r"""Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event""" drop_control_fields: NotRequired[bool] @@ -9895,6 +1621,9 @@ class CreateInputSystemByPackInputSplunkHec(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + use_fwd_timezone: Annotated[ Optional[bool], pydantic.Field(alias="useFwdTimezone") ] = None @@ -9982,6 +1711,7 @@ def serialize_model(self, handler): "splunkHecAcks", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "useFwdTimezone", "dropControlFields", "extractMetrics", @@ -10458,22 +2188,44 @@ def serialize_model(self, handler): class CreateInputSystemByPackInputSplunkAuthTokenTypedDict(TypedDict): - token: str + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Description""" class CreateInputSystemByPackInputSplunkAuthToken(BaseModel): - token: str + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: Optional[str] = None r"""Description""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description"]) + optional_fields = set(["authType", "tokenSecret", "token", "description"]) serialized = handler(self) m = {} @@ -10552,6 +2304,8 @@ class CreateInputSystemByPackInputSplunkTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" auth_tokens: NotRequired[List[CreateInputSystemByPackInputSplunkAuthTokenTypedDict]] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" max_s2_sversion: NotRequired[CreateInputSystemByPackMaxS2SVersion] @@ -10664,6 +2418,9 @@ class CreateInputSystemByPackInputSplunk(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + auth_tokens: Annotated[ Optional[List[CreateInputSystemByPackInputSplunkAuthToken]], pydantic.Field(alias="authTokens"), @@ -10736,52 +2493,178 @@ def serialize_max_s2_sversion(self, value): return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackCompression(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "authTokens", + "maxS2Sversion", + "description", + "useFwdTimezone", + "dropControlFields", + "extractMetrics", + "compress", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_maxS2Sversion", + "__template_compress", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputHTTPType(str, Enum): + r"""Source type identifier.""" + + HTTP = "http" + + +class CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict( + TypedDict +): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict( + TypedDict +): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackCompression(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "authTokens", - "maxS2Sversion", - "description", - "useFwdTimezone", - "dropControlFields", - "extractMetrics", - "compress", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_maxS2Sversion", - "__template_compress", - ] - ) + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) serialized = handler(self) m = {} @@ -10796,10 +2679,22 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputHTTPType(str, Enum): - r"""Source type identifier.""" +CreateInputSystemByPackInputHTTPAuthTokensExtTypedDict = TypeAliasType( + "CreateInputSystemByPackInputHTTPAuthTokensExtTypedDict", + Union[ + CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) - HTTP = "http" + +CreateInputSystemByPackInputHTTPAuthTokensExt = TypeAliasType( + "CreateInputSystemByPackInputHTTPAuthTokensExt", + Union[ + CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType, + CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint, + ], +) class CreateInputSystemByPackInputHTTPTypedDict(TypedDict): @@ -10862,7 +2757,9 @@ class CreateInputSystemByPackInputHTTPTypedDict(TypedDict): r"""Enable Splunk HEC acknowledgements""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] + auth_tokens_ext: NotRequired[ + List[CreateInputSystemByPackInputHTTPAuthTokensExtTypedDict] + ] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -11005,7 +2902,7 @@ class CreateInputSystemByPackInputHTTP(BaseModel): r"""Fields to add to events from this input""" auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], + Optional[List[CreateInputSystemByPackInputHTTPAuthTokensExt]], pydantic.Field(alias="authTokensExt"), ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -11205,6 +3102,8 @@ class CreateInputSystemByPackInputMskTypedDict(TypedDict): r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" max_socket_errors: NotRequired[float] r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] @@ -11422,6 +3321,9 @@ class CreateInputSystemByPackInputMsk(BaseModel): ] = None r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11536,6 +3438,7 @@ def serialize_model(self, handler): "maxBytesPerPartition", "maxBytes", "maxSocketErrors", + "autoParse", "description", "awsApiKey", "awsSecret", @@ -11644,6 +3547,8 @@ class CreateInputSystemByPackInputKafkaTypedDict(TypedDict): r"""Maximum number of network errors before the consumer re-creates a socket""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -11801,6 +3706,9 @@ class CreateInputSystemByPackInputKafka(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11863,6 +3771,7 @@ def serialize_model(self, handler): "maxBytes", "maxSocketErrors", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", @@ -12038,74 +3947,91 @@ def serialize_model(self, handler): CreateInputSystemByPackInputTypedDict = TypeAliasType( "CreateInputSystemByPackInputTypedDict", Union[ - CreateInputSystemByPackInputDatagenTypedDict, - CreateInputSystemByPackInputKubeEventsTypedDict, CreateInputSystemByPackInputCriblTypedDict, - CreateInputSystemByPackInputAppleUnifiedLogsTypedDict, + CreateInputSystemByPackInputKubeEventsTypedDict, + CreateInputSystemByPackInputDatagenTypedDict, CreateInputSystemByPackInputCriblmetricsTypedDict, + CreateInputSystemByPackInputAppleUnifiedLogsTypedDict, CreateInputSystemByPackInputCollectionTypedDict, CreateInputSystemByPackInputKubeMetricsTypedDict, CreateInputSystemByPackInputSystemStateTypedDict, - CreateInputSystemByPackInputSystemMetricsTypedDict, CreateInputSystemByPackInputWindowsMetricsTypedDict, + CreateInputSystemByPackInputSystemMetricsTypedDict, CreateInputSystemByPackInputJournalFilesTypedDict, + CreateInputSystemByPackInputKubeLogsTypedDict, CreateInputSystemByPackInputModelDrivenTelemetryTypedDict, CreateInputSystemByPackInputExecTypedDict, + CreateInputSystemByPackInputProofpointPodTypedDict, CreateInputSystemByPackInputRawUDPTypedDict, - CreateInputSystemByPackInputKubeLogsTypedDict, CreateInputSystemByPackInputSnmpTypedDict, CreateInputSystemByPackInputWinEventLogsTypedDict, + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsTypedDict, CreateInputSystemByPackInputMetricsTypedDict, CreateInputSystemByPackInputNetflowTypedDict, CreateInputSystemByPackInputCriblTCPTypedDict, CreateInputSystemByPackInputOpenaiTypedDict, - CreateInputSystemByPackInputEventhubAmqpTypedDict, CreateInputSystemByPackInputTcpjsonTypedDict, CreateInputSystemByPackInputOktaTypedDict, - CreateInputSystemByPackInputGooglePubsubTypedDict, + CreateInputSystemByPackInputEventhubAmqpTypedDict, CreateInputSystemByPackInputCriblHTTPTypedDict, - CreateInputSystemByPackInputTCPTypedDict, + CreateInputSystemByPackInputGooglePubsubTypedDict, CreateInputSystemByPackInputFirehoseTypedDict, + CreateInputSystemByPackInputSailpointHecTypedDict, CreateInputSystemByPackInputOffice365ServiceTypedDict, - CreateInputSystemByPackInputAnthropicComplianceTypedDict, + CreateInputSystemByPackInputTCPTypedDict, CreateInputSystemByPackInputWizTypedDict, + CreateInputSystemByPackInputAkamaiHecTypedDict, + CreateInputSystemByPackInputAnthropicComplianceTypedDict, CreateInputSystemByPackInputDatadogAgentTypedDict, + CreateInputSystemByPackInputOffice365MgmtTypedDict, CreateInputSystemByPackInputAppscopeTypedDict, - CreateInputSystemByPackInputFileTypedDict, CreateInputSystemByPackInputSplunkTypedDict, - CreateInputSystemByPackInputOffice365MgmtTypedDict, + CreateInputSystemByPackInputBeyondtrustHecTypedDict, CreateInputSystemByPackInputWefTypedDict, - CreateInputSystemByPackInputLokiTypedDict, + CreateInputSystemByPackInputAzureVnetFlowLogTypedDict, CreateInputSystemByPackInputWizWebhookTypedDict, - CreateInputSystemByPackInputUpwindHecTypedDict, + CreateInputSystemByPackInputLokiTypedDict, CreateInputSystemByPackInputSysdigHecTypedDict, + CreateInputSystemByPackInputVectraAiHecTypedDict, + CreateInputSystemByPackInputGigamonHecTypedDict, + CreateInputSystemByPackInputUpwindHecTypedDict, + CreateInputSystemByPackInputPingIdentityPingoneTypedDict, + CreateInputSystemByPackInputExtrahopRevealx360TypedDict, + CreateInputSystemByPackInputFileTypedDict, + CreateInputSystemByPackInputTrellixHecTypedDict, CreateInputSystemByPackInputPrometheusRwTypedDict, - CreateInputSystemByPackInputConfluentCloudTypedDict, - CreateInputSystemByPackInputKafkaTypedDict, + CreateInputSystemByPackInputAquaSecurityHecTypedDict, + CreateInputSystemByPackInputHashicorpHcpVaultDedicatedTypedDict, + CreateInputSystemByPackInputMimecastHecTypedDict, + CreateInputSystemByPackInputTrendMicroVisionOneTypedDict, CreateInputSystemByPackInputZscalerHecTypedDict, - CreateInputSystemByPackInputCriblLakeHTTPTypedDict, CreateInputSystemByPackInputHTTPTypedDict, - CreateInputSystemByPackInputEventhubTypedDict, - CreateInputSystemByPackInputAzureBlobTypedDict, - CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict, + CreateInputSystemByPackInputCriblLakeHTTPTypedDict, + CreateInputSystemByPackInputF5BigIPTypedDict, CreateInputSystemByPackInputCloudflareHecTypedDict, + CreateInputSystemByPackInputKafkaTypedDict, + CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict, + CreateInputSystemByPackInputConfluentCloudTypedDict, + CreateInputSystemByPackInputMicrosoftCopilotTypedDict, + CreateInputSystemByPackInputEventhubTypedDict, CreateInputSystemByPackInputElasticTypedDict, - CreateInputSystemByPackInputOpenTelemetryTypedDict, CreateInputSystemByPackInputSplunkHecTypedDict, + CreateInputSystemByPackInputAzureBlobTypedDict, + CreateInputSystemByPackInputOpenTelemetryTypedDict, CreateInputSystemByPackInputSqsTypedDict, - CreateInputSystemByPackInputKinesisTypedDict, - CreateInputSystemByPackInputOffice365MsgTraceTypedDict, CreateInputSystemByPackInputMicrosoftGraphTypedDict, + CreateInputSystemByPackInputOffice365MsgTraceTypedDict, + CreateInputSystemByPackInputKinesisTypedDict, CreateInputSystemByPackInputHTTPRawTypedDict, CreateInputSystemByPackInputSplunkSearchTypedDict, CreateInputSystemByPackInputServicenowTableTypedDict, CreateInputSystemByPackInputMskTypedDict, CreateInputSystemByPackInputEdgePrometheusTypedDict, CreateInputSystemByPackInputCrowdstrikeTypedDict, - CreateInputSystemByPackInputS3TypedDict, + CreateInputSystemByPackInputPrometheusTypedDict, CreateInputSystemByPackInputBedrockS3TypedDict, CreateInputSystemByPackInputSecurityLakeTypedDict, - CreateInputSystemByPackInputPrometheusTypedDict, + CreateInputSystemByPackInputS3TypedDict, CreateInputSystemByPackInputS3InventoryTypedDict, CreateInputSystemByPackInputGrafanaUnionTypedDict, CreateInputSystemByPackInputSyslogUnionTypedDict, @@ -12124,6 +4050,9 @@ def serialize_model(self, handler): Annotated[CreateInputSystemByPackInputSplunkSearch, Tag("splunk_search")], Annotated[CreateInputSystemByPackInputSplunkHec, Tag("splunk_hec")], Annotated[CreateInputSystemByPackInputAzureBlob, Tag("azure_blob")], + Annotated[ + CreateInputSystemByPackInputAzureVnetFlowLog, Tag("azure_vnet_flow_log") + ], Annotated[CreateInputSystemByPackInputElastic, Tag("elastic")], Annotated[CreateInputSystemByPackInputConfluentCloud, Tag("confluent_cloud")], Annotated[CreateInputSystemByPackInputGrafanaUnion, Tag("grafana")], @@ -12189,10 +4118,19 @@ def serialize_model(self, handler): Annotated[CreateInputSystemByPackInputSecurityLake, Tag("security_lake")], Annotated[CreateInputSystemByPackInputBedrockS3, Tag("bedrock_s3")], Annotated[CreateInputSystemByPackInputServicenowTable, Tag("servicenow_table")], + Annotated[CreateInputSystemByPackInputProofpointPod, Tag("proofpoint_pod")], Annotated[CreateInputSystemByPackInputZscalerHec, Tag("zscaler_hec")], Annotated[CreateInputSystemByPackInputCloudflareHec, Tag("cloudflare_hec")], Annotated[CreateInputSystemByPackInputSysdigHec, Tag("sysdig_hec")], Annotated[CreateInputSystemByPackInputUpwindHec, Tag("upwind_hec")], + Annotated[CreateInputSystemByPackInputTrellixHec, Tag("trellix_hec")], + Annotated[CreateInputSystemByPackInputSailpointHec, Tag("sailpoint_hec")], + Annotated[ + CreateInputSystemByPackInputExtrahopRevealx360, Tag("extrahop_revealx_360") + ], + Annotated[ + CreateInputSystemByPackInputAquaSecurityHec, Tag("aqua_security_hec") + ], Annotated[ CreateInputSystemByPackInputOpenaiComplianceLogs, Tag("openai_compliance_logs"), @@ -12200,7 +4138,32 @@ def serialize_model(self, handler): Annotated[ CreateInputSystemByPackInputAnthropicCompliance, Tag("anthropic_compliance") ], + Annotated[ + CreateInputSystemByPackInputAnthropicEnterpriseAnalytics, + Tag("anthropic_enterprise_analytics"), + ], + Annotated[ + CreateInputSystemByPackInputMicrosoftCopilot, Tag("microsoft_copilot") + ], Annotated[CreateInputSystemByPackInputOkta, Tag("okta")], + Annotated[CreateInputSystemByPackInputAkamaiHec, Tag("akamai_hec")], + Annotated[ + CreateInputSystemByPackInputPingIdentityPingone, + Tag("ping_identity_pingone"), + ], + Annotated[CreateInputSystemByPackInputGigamonHec, Tag("gigamon_hec")], + Annotated[CreateInputSystemByPackInputVectraAiHec, Tag("vectra_ai_hec")], + Annotated[CreateInputSystemByPackInputF5BigIP, Tag("f5_big_ip")], + Annotated[CreateInputSystemByPackInputBeyondtrustHec, Tag("beyondtrust_hec")], + Annotated[ + CreateInputSystemByPackInputHashicorpHcpVaultDedicated, + Tag("hashicorp_hcp_vault_dedicated"), + ], + Annotated[CreateInputSystemByPackInputMimecastHec, Tag("mimecast_hec")], + Annotated[ + CreateInputSystemByPackInputTrendMicroVisionOne, + Tag("trend_micro_vision_one"), + ], ], Discriminator(lambda m: get_discriminator(m, "type", "type")), ] @@ -12228,207 +4191,47 @@ class CreateInputSystemByPackRequest(BaseModel): try: - CreateInputSystemByPackCollectors.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputSystemStatePersistence.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputSystemState.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputSystemMetricsCPU.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputSystemMetricsNetwork.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputSystemMetricsDisk.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackContainer.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputSystemMetricsPersistence.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputSystemMetrics.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputTcpjson.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackSplunkHecMetadata.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackElasticsearchMetadata.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackAuthTokensExt.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputCriblLakeHTTP.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputCriblHTTP.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputCriblTCP.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputCribl.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputGooglePubsub.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputFirehose.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputExec.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackCertificate.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackAuth.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackAzureBlobStorage.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackCheckpointing.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputEventhubAmqp.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputEventhub.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputMicrosoftGraph.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputOffice365MsgTrace.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputOffice365ServiceContentConfig.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputOffice365Service.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputOffice365MgmtContentConfig.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputOffice365Mgmt.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackPodFilter.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputEdgePrometheus.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputPrometheus.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputPrometheusRw.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputLoki.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackPrometheusAuth2.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackLokiAuth2.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackInputGrafanaGrafana2.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackPrometheusAuth1.model_rebuild() + CreateInputSystemByPackInputElasticProxyMode.model_rebuild() except NameError: pass try: - CreateInputSystemByPackLokiAuth1.model_rebuild() + CreateInputSystemByPackInputElastic.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputGrafanaGrafana1.model_rebuild() + CreateInputSystemByPackInputAzureVnetFlowLog.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputConfluentCloud.model_rebuild() + CreateInputSystemByPackInputAzureBlob.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputElasticProxyMode.model_rebuild() + CreateInputSystemByPackInputSplunkHecAuthToken.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputElastic.model_rebuild() + CreateInputSystemByPackInputSplunkHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputAzureBlob.model_rebuild() + CreateInputSystemByPackInputSplunkSearch.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSplunkHecAuthToken.model_rebuild() + CreateInputSystemByPackInputSplunkAuthToken.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSplunkHec.model_rebuild() + CreateInputSystemByPackInputSplunk.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSplunkSearch.model_rebuild() + CreateInputSystemByPackInputHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSplunk.model_rebuild() + CreateInputSystemByPackInputHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() except NameError: pass try: diff --git a/src/cribl_control_plane/models/createinputsystembypack_inputkubemetrics.py b/src/cribl_control_plane/models/createinputsystembypack_v3user.py similarity index 75% rename from src/cribl_control_plane/models/createinputsystembypack_inputkubemetrics.py rename to src/cribl_control_plane/models/createinputsystembypack_v3user.py index d957ffef4..54c3581d7 100644 --- a/src/cribl_control_plane/models/createinputsystembypack_inputkubemetrics.py +++ b/src/cribl_control_plane/models/createinputsystembypack_v3user.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionsmanualsecret import ( AuthenticationMethodOptionsManualSecret, @@ -14,10 +14,6 @@ AuthTokenConfInputCloudflareHec, AuthTokenConfInputCloudflareHecTypedDict, ) -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, -) from .checkpointingtype import CheckpointingType, CheckpointingTypeTypedDict from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -26,8 +22,6 @@ from .datacompressionformatoptionspersistence import ( DataCompressionFormatOptionsPersistence, ) -from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict -from .gputype import GpuType, GpuTypeTypedDict from .logleveloptions import LogLevelOptions from .logleveloptionscontentconfigitemsdebugerror import ( LogLevelOptionsContentConfigItemsDebugError, @@ -38,7 +32,6 @@ MetadataConfInputCollectionTypedDict, ) from .minimumtlsversionoptionstls import MinimumTLSVersionOptionsTLS -from .modeoptionshost import ModeOptionsHost from .oauthheaderconfinputservicenowtable import ( OauthHeaderConfInputServicenowTable, OauthHeaderConfInputServicenowTableTypedDict, @@ -49,27 +42,26 @@ ) from .pqtype import PqType, PqTypeTypedDict from .preprocesstype import PreprocessType, PreprocessTypeTypedDict -from .processtype import ProcessType, ProcessTypeTypedDict from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, ) from .retryrulestype import RetryRulesType, RetryRulesTypeTypedDict -from .ruleconfinputkubemetrics import ( - RuleConfInputKubeMetrics, - RuleConfInputKubeMetricsTypedDict, +from .retrytypeoptionshealthcheckcollectorconfretryrules import ( + RetryTypeOptionsHealthCheckCollectorConfRetryRules, ) from .sqsauthenticationmethodoptions import SqsAuthenticationMethodOptions from .tagafterprocessingoptions import TagAfterProcessingOptions +from .tlssettingsclientsidetypecapathcertpath import ( + TLSSettingsClientSideTypeCaPathCertPath, + TLSSettingsClientSideTypeCaPathCertPathTypedDict, +) from .tlssettingsserversidetype import ( TLSSettingsServerSideType, TLSSettingsServerSideTypeTypedDict, ) -from .typeoptionskinesis import TypeOptionsKinesis from .typeoptionsnetflow import TypeOptionsNetflow -from .typeoptionss3 import TypeOptionsS3 from .typeoptionssecuritylake import TypeOptionsSecuritylake -from .typeoptionssnmp import TypeOptionsSnmp from .typeoptionssqs import TypeOptionsSqs from .typeoptionssyslog import TypeOptionsSyslog from cribl_control_plane import models, utils @@ -81,29 +73,23 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict -class CreateInputSystemByPackInputOktaType(str, Enum): - r"""Connector type identifier.""" - - OKTA = "okta" - - -class CreateInputSystemByPackInputOktaManageStateTypedDict(TypedDict): - pass - +class CreateInputSystemByPackInputTrendMicroVisionOneType(str, Enum): + r"""Source type identifier.""" -class CreateInputSystemByPackInputOktaManageState(BaseModel): - pass + TREND_MICRO_VISION_ONE = "trend_micro_vision_one" -class CreateInputSystemByPackInputOktaTypedDict(TypedDict): +class CreateInputSystemByPackInputTrendMicroVisionOneTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOktaType - r"""Connector type identifier.""" - okta_domain: str - r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" - text_secret: str - r"""Select or create a stored text secret""" + type: CreateInputSystemByPackInputTrendMicroVisionOneType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -119,52 +105,75 @@ class CreateInputSystemByPackInputOktaTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - okta_token: NotRequired[str] - r"""Your Okta API token for authentication""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - manage_state: NotRequired[CreateInputSystemByPackInputOktaManageStateTypedDict] - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_okta_domain: NotRequired[str] - r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputOkta(BaseModel): +class CreateInputSystemByPackInputTrendMicroVisionOne(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOktaType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputTrendMicroVisionOneType + r"""Source type identifier.""" - okta_domain: Annotated[str, pydantic.Field(alias="oktaDomain")] - r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored text secret""" + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -191,55 +200,87 @@ class CreateInputSystemByPackInputOkta(BaseModel): pq: Optional[PqType] = None - okta_token: Annotated[Optional[str], pydantic.Field(alias="oktaToken")] = None - r"""Your Okta API token for authentication""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackInputOktaManageState], - pydantic.Field(alias="manageState"), + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -254,10 +295,35 @@ class CreateInputSystemByPackInputOkta(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_okta_domain: Annotated[ - Optional[str], pydantic.Field(alias="__template_oktaDomain") + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -271,24 +337,33 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "oktaToken", - "cronSchedule", - "earliest", - "latest", - "manageState", - "jobTimeout", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "retryRules", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", - "__template_oktaDomain", - ] + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] ) serialized = handler(self) m = {} @@ -304,190 +379,296 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputAnthropicComplianceType(str, Enum): - r"""Connector type identifier.""" +class CreateInputSystemByPackInputMimecastHecType(str, Enum): + r"""Source type identifier.""" - ANTHROPIC_COMPLIANCE = "anthropic_compliance" + MIMECAST_HEC = "mimecast_hec" -class CreateInputSystemByPackActivitiesManageStateTypedDict(TypedDict): - pass +class CreateInputSystemByPackInputMimecastHecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputMimecastHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackActivitiesManageState(BaseModel): - pass +class CreateInputSystemByPackInputMimecastHec(BaseModel): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputMimecastHecType + r"""Source type identifier.""" -class CreateInputSystemByPackActivitiesTypedDict(TypedDict): - r"""Activities""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputSystemByPackActivitiesManageStateTypedDict] + port: float + r"""Port to listen on""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" -class CreateInputSystemByPackActivities(BaseModel): - r"""Activities""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - enabled: Optional[bool] = None - r"""Enabled""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackActivitiesManageState], - pydantic.Field(alias="manageState"), + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None + r"""Add request headers to events, in the __headers field""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - return m + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" -class CreateInputSystemByPackChatsManageStateTypedDict(TypedDict): - pass + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class CreateInputSystemByPackChatsManageState(BaseModel): - pass + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" -class CreateInputSystemByPackChatsTypedDict(TypedDict): - r"""Chats""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputSystemByPackChatsManageStateTypedDict] - - -class CreateInputSystemByPackChats(BaseModel): - r"""Chats""" - - enabled: Optional[bool] = None - r"""Enabled""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackChatsManageState], - pydantic.Field(alias="manageState"), + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -504,184 +685,296 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackProjectsManageStateTypedDict(TypedDict): - pass - +class CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType(str, Enum): + r"""Source type identifier.""" -class CreateInputSystemByPackProjectsManageState(BaseModel): - pass + HASHICORP_HCP_VAULT_DEDICATED = "hashicorp_hcp_vault_dedicated" -class CreateInputSystemByPackProjectsTypedDict(TypedDict): - r"""Projects""" +class CreateInputSystemByPackInputHashicorpHcpVaultDedicatedTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputSystemByPackProjectsManageStateTypedDict] +class CreateInputSystemByPackInputHashicorpHcpVaultDedicated(BaseModel): + id: str + r"""Unique ID for this input""" -class CreateInputSystemByPackProjects(BaseModel): - r"""Projects""" + type: CreateInputSystemByPackInputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" - enabled: Optional[bool] = None - r"""Enabled""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + port: float + r"""Port to listen on""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Select whether to send data to Routes, or directly to Destinations.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackProjectsManageState], - pydantic.Field(alias="manageState"), + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - return m + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" -class CreateInputSystemByPackChatMessagesManageStateTypedDict(TypedDict): - pass + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" -class CreateInputSystemByPackChatMessagesManageState(BaseModel): - pass + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class CreateInputSystemByPackChatMessagesTypedDict(TypedDict): - r"""Chat Messages""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputSystemByPackChatMessagesManageStateTypedDict] + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class CreateInputSystemByPackChatMessages(BaseModel): - r"""Chat Messages""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - enabled: Optional[bool] = None - r"""Enabled""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackChatMessagesManageState], - pydantic.Field(alias="manageState"), + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -698,270 +991,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackProjectDetailsManageStateTypedDict(TypedDict): - pass - - -class CreateInputSystemByPackProjectDetailsManageState(BaseModel): - pass - - -class CreateInputSystemByPackProjectDetailsTypedDict(TypedDict): - r"""Project Details""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputSystemByPackProjectDetailsManageStateTypedDict] - - -class CreateInputSystemByPackProjectDetails(BaseModel): - r"""Project Details""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" - - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" +class CreateInputSystemByPackInputBeyondtrustHecType(str, Enum): + r"""Source type identifier.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" + BEYONDTRUST_HEC = "beyondtrust_hec" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackProjectDetailsManageState], - pydantic.Field(alias="manageState"), - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackGroupsTypedDict(TypedDict): - r"""Groups""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class CreateInputSystemByPackGroups(BaseModel): - r"""Groups""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackOrganizationsTypedDict(TypedDict): - r"""Organizations""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class CreateInputSystemByPackOrganizations(BaseModel): - r"""Organizations""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackOrganizationUsersTypedDict(TypedDict): - r"""Organization Users""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class CreateInputSystemByPackOrganizationUsers(BaseModel): - r"""Organization Users""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackOrganizationRolesTypedDict(TypedDict): - r"""Organization Roles""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class CreateInputSystemByPackOrganizationRoles(BaseModel): - r"""Organization Roles""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputAnthropicComplianceTypedDict(TypedDict): +class CreateInputSystemByPackInputBeyondtrustHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputAnthropicComplianceType - r"""Connector type identifier.""" - text_secret: str - r"""Select or create a stored Anthropic API key""" + type: CreateInputSystemByPackInputBeyondtrustHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -977,60 +1023,71 @@ class CreateInputSystemByPackInputAnthropicComplianceTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - api_key: NotRequired[str] - r"""API key""" - activities: NotRequired[CreateInputSystemByPackActivitiesTypedDict] - r"""Activities""" - chats: NotRequired[CreateInputSystemByPackChatsTypedDict] - r"""Chats""" - projects: NotRequired[CreateInputSystemByPackProjectsTypedDict] - r"""Projects""" - chat_messages: NotRequired[CreateInputSystemByPackChatMessagesTypedDict] - r"""Chat Messages""" - project_details: NotRequired[CreateInputSystemByPackProjectDetailsTypedDict] - r"""Project Details""" - groups: NotRequired[CreateInputSystemByPackGroupsTypedDict] - r"""Groups""" - organizations: NotRequired[CreateInputSystemByPackOrganizationsTypedDict] - r"""Organizations""" - org_users: NotRequired[CreateInputSystemByPackOrganizationUsersTypedDict] - r"""Organization Users""" - org_roles: NotRequired[CreateInputSystemByPackOrganizationRolesTypedDict] - r"""Organization Roles""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputAnthropicCompliance(BaseModel): +class CreateInputSystemByPackInputBeyondtrustHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputAnthropicComplianceType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputBeyondtrustHecType + r"""Source type identifier.""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored Anthropic API key""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -1057,75 +1114,82 @@ class CreateInputSystemByPackInputAnthropicCompliance(BaseModel): pq: Optional[PqType] = None - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" - - activities: Optional[CreateInputSystemByPackActivities] = None - r"""Activities""" - - chats: Optional[CreateInputSystemByPackChats] = None - r"""Chats""" - - projects: Optional[CreateInputSystemByPackProjects] = None - r"""Projects""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - chat_messages: Optional[CreateInputSystemByPackChatMessages] = None - r"""Chat Messages""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - project_details: Optional[CreateInputSystemByPackProjectDetails] = None - r"""Project Details""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - groups: Optional[CreateInputSystemByPackGroups] = None - r"""Groups""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - organizations: Optional[CreateInputSystemByPackOrganizations] = None - r"""Organizations""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - org_users: Optional[CreateInputSystemByPackOrganizationUsers] = None - r"""Organization Users""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - org_roles: Optional[CreateInputSystemByPackOrganizationRoles] = None - r"""Organization Roles""" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -1140,6 +1204,31 @@ class CreateInputSystemByPackInputAnthropicCompliance(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -1152,28 +1241,30 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "apiKey", - "activities", - "chats", - "projects", - "chat_messages", - "project_details", - "groups", - "organizations", - "org_users", - "org_roles", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", - "breakerRulesets", - "staleChannelFlushMs", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "retryRules", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -1190,40 +1281,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputOpenaiComplianceLogsType(str, Enum): - r"""Connector type identifier.""" - - OPENAI_COMPLIANCE_LOGS = "openai_compliance_logs" - - -class CreateInputSystemByPackAccountType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Account type""" - - # Workspace - WORKSPACE = "workspace" - # Organization - ORGANIZATION = "organization" - - -class CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict(TypedDict): - pass - +class CreateInputSystemByPackInputF5BigIPType(str, Enum): + r"""Source type identifier.""" -class CreateInputSystemByPackInputOpenaiComplianceLogsManageState(BaseModel): - pass + F5_BIG_IP = "f5_big_ip" -class CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict(TypedDict): +class CreateInputSystemByPackInputF5BigIPTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOpenaiComplianceLogsType - r"""Connector type identifier.""" - text_secret: str - r"""Select or create a stored text secret""" - account_type: CreateInputSystemByPackAccountType - r"""Account type""" - cron_schedule: str - r"""Cron schedule""" + type: CreateInputSystemByPackInputF5BigIPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -1239,81 +1313,77 @@ class CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - api_key: NotRequired[str] - r"""API key""" - earliest: NotRequired[str] - r"""Relative to the current time. Format: [+|-]""" - latest: NotRequired[str] - r"""Relative to the current time. Format: [+|-]""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] - r"""Collector runtime log level""" - max_pages: NotRequired[float] - r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] - description: NotRequired[str] - r"""Optional description for this configuration.""" - workspace_id: NotRequired[str] - r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" - workspace_event_types: NotRequired[List[str]] - r"""One or more compliance log categories to collect""" - organization_id: NotRequired[str] - r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" - organization_event_types: NotRequired[List[str]] - r"""One or more compliance log categories to collect""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[ - CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict - ] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_workspace_id: NotRequired[str] - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_organization_id: NotRequired[str] - r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputOpenaiComplianceLogs(BaseModel): +class CreateInputSystemByPackInputF5BigIP(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOpenaiComplianceLogsType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputF5BigIPType + r"""Source type identifier.""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored text secret""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - account_type: Annotated[ - CreateInputSystemByPackAccountType, pydantic.Field(alias="accountType") - ] - r"""Account type""" + port: float + r"""Port to listen on""" - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""Cron schedule""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -1340,107 +1410,93 @@ class CreateInputSystemByPackInputOpenaiComplianceLogs(BaseModel): pq: Optional[PqType] = None - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" - - earliest: Optional[str] = None - r"""Relative to the current time. Format: [+|-]""" - - latest: Optional[str] = None - r"""Relative to the current time. Format: [+|-]""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItemsDebugError], - pydantic.Field(alias="logLevel"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Collector runtime log level""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + r"""Add request headers to events, in the __headers field""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None - r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - workspace_event_types: Annotated[ - Optional[List[str]], pydantic.Field(alias="workspaceEventTypes") + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") ] = None - r"""One or more compliance log categories to collect""" + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - organization_id: Annotated[ - Optional[str], pydantic.Field(alias="organizationId") - ] = None - r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" - organization_event_types: Annotated[ - Optional[List[str]], pydantic.Field(alias="organizationEventTypes") + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""One or more compliance log categories to collect""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackInputOpenaiComplianceLogsManageState], - pydantic.Field(alias="manageState"), - ] = None + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -1452,33 +1508,35 @@ class CreateInputSystemByPackInputOpenaiComplianceLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_workspace_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceId") + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_organization_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_organizationId") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - @field_serializer("account_type") - def serialize_account_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackAccountType(value) - except ValueError: - return value - return value + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItemsDebugError(value) - except ValueError: - return value - return value + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -1492,34 +1550,33 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "apiKey", - "earliest", - "latest", - "jobTimeout", - "logLevel", - "maxPages", - "stateTracking", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "retryRules", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", - "workspaceId", - "workspaceEventTypes", - "organizationId", - "organizationEventTypes", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", "__template_environment", "__template_streamtags", - "__template_workspaceId", - "__template_organizationId", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -1536,23 +1593,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputUpwindHecType(str, Enum): +class CreateInputSystemByPackInputVectraAiHecType(str, Enum): r"""Source type identifier.""" - UPWIND_HEC = "upwind_hec" + VECTRA_AI_HEC = "vectra_ai_hec" -class CreateInputSystemByPackInputUpwindHecTypedDict(TypedDict): +class CreateInputSystemByPackInputVectraAiHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputUpwindHecType + type: CreateInputSystemByPackInputVectraAiHecType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -1622,11 +1679,11 @@ class CreateInputSystemByPackInputUpwindHecTypedDict(TypedDict): r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputUpwindHec(BaseModel): +class CreateInputSystemByPackInputVectraAiHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputUpwindHecType + type: CreateInputSystemByPackInputVectraAiHecType r"""Source type identifier.""" host: str @@ -1636,7 +1693,7 @@ class CreateInputSystemByPackInputUpwindHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -1842,23 +1899,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputSysdigHecType(str, Enum): +class CreateInputSystemByPackInputGigamonHecType(str, Enum): r"""Source type identifier.""" - SYSDIG_HEC = "sysdig_hec" + GIGAMON_HEC = "gigamon_hec" -class CreateInputSystemByPackInputSysdigHecTypedDict(TypedDict): +class CreateInputSystemByPackInputGigamonHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputSysdigHecType + type: CreateInputSystemByPackInputGigamonHecType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -1928,11 +1985,11 @@ class CreateInputSystemByPackInputSysdigHecTypedDict(TypedDict): r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputSysdigHec(BaseModel): +class CreateInputSystemByPackInputGigamonHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputSysdigHecType + type: CreateInputSystemByPackInputGigamonHecType r"""Source type identifier.""" host: str @@ -1942,7 +1999,7 @@ class CreateInputSystemByPackInputSysdigHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -2148,145 +2205,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputCloudflareHecType(str, Enum): +class CreateInputSystemByPackInputPingIdentityPingoneType(str, Enum): r"""Source type identifier.""" - CLOUDFLARE_HEC = "cloudflare_hec" - - -class CreateInputSystemByPackTLSSettingsServerSideTypedDict(TypedDict): - r"""TLS settings (server side)""" - - disabled: NotRequired[bool] - r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - request_cert: NotRequired[bool] - r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" - common_name_regex: NotRequired[str] - r"""Regex matching allowable common names in peer certificates' subject attribute""" - certificate_name: NotRequired[str] - r"""The name of the predefined certificate""" - priv_key_path: NotRequired[str] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - cert_path: NotRequired[str] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - ca_path: NotRequired[str] - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - min_version: NotRequired[MinimumTLSVersionOptionsTLS] - r"""Minimum TLS version""" - max_version: NotRequired[MaximumTLSVersionOptionsTLS] - r"""Maximum TLS version""" - - -class CreateInputSystemByPackTLSSettingsServerSide(BaseModel): - r"""TLS settings (server side)""" - - disabled: Optional[bool] = None - r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - - request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None - r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" - - common_name_regex: Annotated[ - Optional[str], pydantic.Field(alias="commonNameRegex") - ] = None - r"""Regex matching allowable common names in peer certificates' subject attribute""" - - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") - ] = None - r"""The name of the predefined certificate""" - - priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" - - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" - - cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - - ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - - min_version: Annotated[ - Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") - ] = None - r"""Minimum TLS version""" - - max_version: Annotated[ - Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") - ] = None - r"""Maximum TLS version""" - - @field_serializer("min_version") - def serialize_min_version(self, value): - if isinstance(value, str): - try: - return models.MinimumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value - - @field_serializer("max_version") - def serialize_max_version(self, value): - if isinstance(value, str): - try: - return models.MaximumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "requestCert", - "rejectUnauthorized", - "commonNameRegex", - "certificateName", - "privKeyPath", - "passphrase", - "certPath", - "caPath", - "minVersion", - "maxVersion", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m + PING_IDENTITY_PINGONE = "ping_identity_pingone" -class CreateInputSystemByPackInputCloudflareHecTypedDict(TypedDict): +class CreateInputSystemByPackInputPingIdentityPingoneTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCloudflareHecType + type: CreateInputSystemByPackInputPingIdentityPingoneType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -2304,7 +2239,7 @@ class CreateInputSystemByPackInputCloudflareHecTypedDict(TypedDict): pq: NotRequired[PqTypeTypedDict] auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[CreateInputSystemByPackTLSSettingsServerSideTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" @@ -2336,10 +2271,6 @@ class CreateInputSystemByPackInputCloudflareHecTypedDict(TypedDict): r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" emit_token_metrics: NotRequired[bool] r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -2360,11 +2291,11 @@ class CreateInputSystemByPackInputCloudflareHecTypedDict(TypedDict): r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputCloudflareHec(BaseModel): +class CreateInputSystemByPackInputPingIdentityPingone(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCloudflareHecType + type: CreateInputSystemByPackInputPingIdentityPingoneType r"""Source type identifier.""" host: str @@ -2374,7 +2305,7 @@ class CreateInputSystemByPackInputCloudflareHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -2407,7 +2338,7 @@ class CreateInputSystemByPackInputCloudflareHec(BaseModel): ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: Optional[CreateInputSystemByPackTLSSettingsServerSide] = None + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( @@ -2483,16 +2414,6 @@ class CreateInputSystemByPackInputCloudflareHec(BaseModel): ] = None r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -2565,8 +2486,6 @@ def serialize_model(self, handler): "accessControlAllowOrigin", "accessControlAllowHeaders", "emitTokenMetrics", - "breakerRulesets", - "staleChannelFlushMs", "description", "__template_environment", "__template_streamtags", @@ -2592,102 +2511,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputZscalerHecType(str, Enum): +class CreateInputSystemByPackInputAkamaiHecType(str, Enum): r"""Source type identifier.""" - ZSCALER_HEC = "zscaler_hec" - - -class CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict(TypedDict): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - token_secret: NotRequired[str] - r"""Select or create a stored text secret""" - enabled: NotRequired[bool] - r"""Enable token""" - description: NotRequired[str] - r"""Description""" - allowed_indexes_at_token: NotRequired[List[str]] - r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this token""" - - -class CreateInputSystemByPackInputZscalerHecAuthToken(BaseModel): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None - r"""Select or create a stored text secret""" - - enabled: Optional[bool] = None - r"""Enable token""" - - description: Optional[str] = None - r"""Description""" - - allowed_indexes_at_token: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") - ] = None - r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this token""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "tokenSecret", - "enabled", - "description", - "allowedIndexesAtToken", - "metadata", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m + AKAMAI_HEC = "akamai_hec" -class CreateInputSystemByPackInputZscalerHecTypedDict(TypedDict): +class CreateInputSystemByPackInputAkamaiHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputZscalerHecType + type: CreateInputSystemByPackInputAkamaiHecType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -2703,9 +2543,7 @@ class CreateInputSystemByPackInputZscalerHecTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[ - List[CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict] - ] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" @@ -2729,18 +2567,10 @@ class CreateInputSystemByPackInputZscalerHecTypedDict(TypedDict): r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - allowed_indexes: NotRequired[List[str]] - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - access_control_allow_origin: NotRequired[List[str]] - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - access_control_allow_headers: NotRequired[List[str]] - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - emit_token_metrics: NotRequired[bool] - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" hec_acks: NotRequired[bool] - r"""Whether to enable Zscaler HEC acknowledgements""" + r"""Whether to enable HEC indexer acknowledgements""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -2753,19 +2583,13 @@ class CreateInputSystemByPackInputZscalerHecTypedDict(TypedDict): r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_hec_api: NotRequired[str] r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_allowed_indexes: NotRequired[str] - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - template_access_control_allow_origin: NotRequired[str] - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_access_control_allow_headers: NotRequired[str] - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputZscalerHec(BaseModel): +class CreateInputSystemByPackInputAkamaiHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputZscalerHecType + type: CreateInputSystemByPackInputAkamaiHecType r"""Source type identifier.""" host: str @@ -2775,7 +2599,7 @@ class CreateInputSystemByPackInputZscalerHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -2803,7 +2627,7 @@ class CreateInputSystemByPackInputZscalerHec(BaseModel): pq: Optional[PqType] = None auth_tokens: Annotated[ - Optional[List[CreateInputSystemByPackInputZscalerHecAuthToken]], + Optional[List[AuthTokenConfInputCloudflareHec]], pydantic.Field(alias="authTokens"), ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -2864,28 +2688,8 @@ class CreateInputSystemByPackInputZscalerHec(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - allowed_indexes: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexes") - ] = None - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - - access_control_allow_origin: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") - ] = None - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - - access_control_allow_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") - ] = None - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - - emit_token_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="emitTokenMetrics") - ] = None - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None - r"""Whether to enable Zscaler HEC acknowledgements""" + r"""Whether to enable HEC indexer acknowledgements""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -2915,21 +2719,6 @@ class CreateInputSystemByPackInputZscalerHec(BaseModel): ] = None r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_allowed_indexes: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedIndexes") - ] = None - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - - template_access_control_allow_origin: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") - ] = None - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - - template_access_control_allow_headers: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") - ] = None - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -2955,10 +2744,6 @@ def serialize_model(self, handler): "ipAllowlistRegex", "ipDenylistRegex", "metadata", - "allowedIndexes", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "emitTokenMetrics", "hecAcks", "description", "__template_environment", @@ -2966,9 +2751,6 @@ def serialize_model(self, handler): "__template_host", "__template_port", "__template_hecAPI", - "__template_allowedIndexes", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -2985,66 +2767,29 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputServicenowTableType(str, Enum): +class CreateInputSystemByPackInputOktaType(str, Enum): r"""Connector type identifier.""" - SERVICENOW_TABLE = "servicenow_table" - - -class CreateInputSystemByPackSortDirection(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Used only when Sort by field is set.""" - - # Ascending - ASC = "asc" - # Descending - DESC = "desc" - - -class CreateInputSystemByPackInputServicenowTableAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""ServiceNow Table API authentication method""" - - # None - NONE = "none" - # Basic - BASIC_SECRET = "basicSecret" - # OAuth - OAUTH_SECRET = "oauthSecret" - - -class CreateInputSystemByPackGrantType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""ServiceNow OAuth grant type used for token requests""" - - # Password - CLIENT_CREDENTIALS = "client_credentials" - # Client credentials - PASSWORD = "password" + OKTA = "okta" -class CreateInputSystemByPackInputServicenowTableManageStateTypedDict(TypedDict): +class CreateInputSystemByPackInputOktaManageStateTypedDict(TypedDict): pass -class CreateInputSystemByPackInputServicenowTableManageState(BaseModel): +class CreateInputSystemByPackInputOktaManageState(BaseModel): pass -class CreateInputSystemByPackInputServicenowTableTypedDict(TypedDict): +class CreateInputSystemByPackInputOktaTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputServicenowTableType + type: CreateInputSystemByPackInputOktaType r"""Connector type identifier.""" - instance: str - r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - table_name: str - r"""ServiceNow table name to collect from.""" - cron_schedule: str - r"""Cron schedule on which to run this job""" - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + okta_domain: str + r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" + text_secret: str + r"""Select or create a stored text secret""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -3060,36 +2805,21 @@ class CreateInputSystemByPackInputServicenowTableTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - fields: NotRequired[List[str]] - r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - order_by_field: NotRequired[str] - r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" - order_by_direction: NotRequired[CreateInputSystemByPackSortDirection] - r"""Used only when Sort by field is set.""" - query: NotRequired[str] - r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" - page_size: NotRequired[int] - r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" - max_pages: NotRequired[int] - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - auth_type: NotRequired[ - CreateInputSystemByPackInputServicenowTableAuthenticationType - ] - r"""ServiceNow Table API authentication method""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - log_level: NotRequired[LogLevelOptions] - r"""Collector runtime log level""" + okta_token: NotRequired[str] + r"""Your Okta API token for authentication""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + manage_state: NotRequired[CreateInputSystemByPackInputOktaManageStateTypedDict] + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" request_timeout: NotRequired[float] r"""HTTP request inactivity timeout. Use 0 to disable.""" - use_round_robin_dns: NotRequired[bool] - r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" keep_alive_time: NotRequired[float] r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" max_missed_keep_alives: NotRequired[float] r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" ttl: NotRequired[str] @@ -3101,68 +2831,26 @@ class CreateInputSystemByPackInputServicenowTableTypedDict(TypedDict): retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - oauth_grant_type: NotRequired[CreateInputSystemByPackGrantType] - r"""ServiceNow OAuth grant type used for token requests""" - username: NotRequired[str] - r"""ServiceNow username for the password grant type""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret for the ServiceNow password value""" - use_custom_o_auth_params_or_headers: NotRequired[bool] - r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - client_id: NotRequired[str] - r"""ServiceNow OAuth client ID""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret for the OAuth client secret value""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[ - CreateInputSystemByPackInputServicenowTableManageStateTypedDict - ] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_instance: NotRequired[str] - r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - template_order_by_field: NotRequired[str] - r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - template_query: NotRequired[str] - r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_okta_domain: NotRequired[str] + r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" -class CreateInputSystemByPackInputServicenowTable(BaseModel): +class CreateInputSystemByPackInputOkta(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputServicenowTableType + type: CreateInputSystemByPackInputOktaType r"""Connector type identifier.""" - instance: str - r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - - table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""ServiceNow table name to collect from.""" - - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""Cron schedule on which to run this job""" - - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + okta_domain: Annotated[str, pydantic.Field(alias="oktaDomain")] + r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -3189,68 +2877,36 @@ class CreateInputSystemByPackInputServicenowTable(BaseModel): pq: Optional[PqType] = None - fields: Optional[List[str]] = None - r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - - order_by_field: Annotated[Optional[str], pydantic.Field(alias="orderByField")] = ( - None - ) - r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" - - order_by_direction: Annotated[ - Optional[CreateInputSystemByPackSortDirection], - pydantic.Field(alias="orderByDirection"), - ] = None - r"""Used only when Sort by field is set.""" - - query: Optional[str] = None - r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" - - page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None - r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" - - max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + okta_token: Annotated[Optional[str], pydantic.Field(alias="oktaToken")] = None + r"""Your Okta API token for authentication""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - auth_type: Annotated[ - Optional[CreateInputSystemByPackInputServicenowTableAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""ServiceNow Table API authentication method""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - log_level: Annotated[ - Optional[LogLevelOptions], pydantic.Field(alias="logLevel") + manage_state: Annotated[ + Optional[CreateInputSystemByPackInputOktaManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Collector runtime log level""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None r"""HTTP request inactivity timeout. Use 0 to disable.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" - keep_alive_time: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTime") ] = None r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: Annotated[ Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None @@ -3274,63 +2930,6 @@ class CreateInputSystemByPackInputServicenowTable(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - oauth_grant_type: Annotated[ - Optional[CreateInputSystemByPackGrantType], - pydantic.Field(alias="oauthGrantType"), - ] = None - r"""ServiceNow OAuth grant type used for token requests""" - - username: Optional[str] = None - r"""ServiceNow username for the password grant type""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret for the ServiceNow password value""" - - use_custom_o_auth_params_or_headers: Annotated[ - Optional[bool], pydantic.Field(alias="useCustomOAuthParamsOrHeaders") - ] = None - r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""ServiceNow OAuth client ID""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret for the OAuth client secret value""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - - manage_state: Annotated[ - Optional[CreateInputSystemByPackInputServicenowTableManageState], - pydantic.Field(alias="manageState"), - ] = None - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -3341,68 +2940,10 @@ class CreateInputSystemByPackInputServicenowTable(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_instance: Annotated[ - Optional[str], pydantic.Field(alias="__template_instance") - ] = None - r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - - template_order_by_field: Annotated[ - Optional[str], pydantic.Field(alias="__template_orderByField") - ] = None - r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - - template_query: Annotated[ - Optional[str], pydantic.Field(alias="__template_query") - ] = None - r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") + template_okta_domain: Annotated[ + Optional[str], pydantic.Field(alias="__template_oktaDomain") ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - @field_serializer("order_by_direction") - def serialize_order_by_direction(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackSortDirection(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputServicenowTableAuthenticationType( - value - ) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("oauth_grant_type") - def serialize_oauth_grant_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackGrantType(value) - except ValueError: - return value - return value + r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -3416,45 +2957,143 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "fields", - "orderByField", - "orderByDirection", - "query", - "pageSize", - "maxPages", - "rejectUnauthorized", - "authType", - "stateTracking", - "logLevel", + "oktaToken", + "cronSchedule", + "earliest", + "latest", + "manageState", + "jobTimeout", "requestTimeout", - "useRoundRobinDns", "keepAliveTime", - "jobTimeout", "maxMissedKeepAlives", "ttl", "ignoreGroupJobsLimit", "metadata", "retryRules", "description", - "credentialsSecret", - "oauthGrantType", - "username", - "textSecret", - "useCustomOAuthParamsOrHeaders", - "oauthParams", - "oauthHeaders", - "clientId", - "clientTextSecret", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", "__template_environment", "__template_streamtags", - "__template_instance", - "__template_orderByField", - "__template_query", - "__template_username", - "__template_clientId", + "__template_oktaDomain", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputMicrosoftCopilotType(str, Enum): + r"""Connector type identifier.""" + + MICROSOFT_COPILOT = "microsoft_copilot" + + +class CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + + ENTERPRISE_GCC = "enterprise_gcc" + GCC = "gcc" + GCC_HIGH = "gcc_high" + DOD = "dod" + + +class CreateInputSystemByPackInputMicrosoftCopilotManageStateTypedDict(TypedDict): + pass + + +class CreateInputSystemByPackInputMicrosoftCopilotManageState(BaseModel): + pass + + +class CreateInputSystemByPackRetryRulesTypedDict(TypedDict): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + interval: NotRequired[float] + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + limit: NotRequired[float] + r"""The maximum number of times to retry a failed HTTP request""" + multiplier: NotRequired[float] + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + codes: NotRequired[List[float]] + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + enable_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + retry_connect_timeout: NotRequired[bool] + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + retry_connect_reset: NotRequired[bool] + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + +class CreateInputSystemByPackRetryRules(BaseModel): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + + interval: Optional[float] = None + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + + limit: Optional[float] = None + r"""The maximum number of times to retry a failed HTTP request""" + + multiplier: Optional[float] = None + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + + codes: Optional[List[float]] = None + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( + None + ) + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + + retry_connect_timeout: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectTimeout") + ] = None + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + + retry_connect_reset: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectReset") + ] = None + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + @field_serializer("type") + def serialize_type(self, value): + if isinstance(value, str): + try: + return models.RetryTypeOptionsHealthCheckCollectorConfRetryRules(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "interval", + "limit", + "multiplier", + "codes", + "enableHeader", + "retryConnectTimeout", + "retryConnectReset", ] ) serialized = handler(self) @@ -3471,19 +3110,58 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputBedrockS3Type(str, Enum): - r"""Connector type identifier.""" - - BEDROCK_S3 = "bedrock_s3" - - -class CreateInputSystemByPackInputBedrockS3TypedDict(TypedDict): +class CreateInputSystemByPackCertOptionsTypedDict(TypedDict): + priv_key_path: str + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + cert_path: str + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + certificate_name: NotRequired[str] + r"""The name of a predefined certificate""" + passphrase: NotRequired[str] + r"""Passphrase to decrypt the private key""" + + +class CreateInputSystemByPackCertOptions(BaseModel): + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The name of a predefined certificate""" + + passphrase: Optional[str] = None + r"""Passphrase to decrypt the private key""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["certificateName", "passphrase"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputMicrosoftCopilotTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputBedrockS3Type + type: CreateInputSystemByPackInputMicrosoftCopilotType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + tenant_id: str + r"""Directory (tenant) ID from Azure Active Directory""" + client_id: str + r"""Application (client) ID from the app registration""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -3499,125 +3177,79 @@ class CreateInputSystemByPackInputBedrockS3TypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + resource: NotRequired[str] + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" + auth_type: NotRequired[ + CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod + ] + r"""Select authentication method.""" + plan_type: NotRequired[CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + cron_schedule: NotRequired[str] + r"""Cron schedule for collection runs""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + page_size: NotRequired[int] + r"""Number of interactions to request per page ($top). Maximum 1000.""" + app_class_filter: NotRequired[List[str]] + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" + filter_by_license: NotRequired[bool] + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" + sku_ids: NotRequired[List[str]] + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" + manage_state: NotRequired[ + CreateInputSystemByPackInputMicrosoftCopilotManageStateTypedDict + ] + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + retry_rules: NotRequired[CreateInputSystemByPackRetryRulesTypedDict] breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + text_secret: NotRequired[str] + r"""Select or create a secret that references the client secret from your app registration""" + cert_options: NotRequired[CreateInputSystemByPackCertOptionsTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" -class CreateInputSystemByPackInputBedrockS3(BaseModel): +class CreateInputSystemByPackInputMicrosoftCopilot(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputBedrockS3Type + type: CreateInputSystemByPackInputMicrosoftCopilotType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Directory (tenant) ID from Azure Active Directory""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""Application (client) ID from the app registration""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -3636,197 +3268,110 @@ class CreateInputSystemByPackInputBedrockS3(BaseModel): pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" - - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + pq: Optional[PqType] = None - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + resource: Optional[str] = None + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + auth_type: Annotated[ + Optional[CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod], + pydantic.Field(alias="authType"), ] = None - r"""Maximum file size for each Parquet chunk""" + r"""Select authentication method.""" - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + plan_type: Annotated[ + Optional[CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan], + pydantic.Field(alias="planType"), ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" - checkpointing: Optional[CheckpointingType] = None + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Cron schedule for collection runs""" - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None + r"""Number of interactions to request per page ($top). Maximum 1000.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" + app_class_filter: Annotated[ + Optional[List[str]], pydantic.Field(alias="appClassFilter") + ] = None + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + filter_by_license: Annotated[ + Optional[bool], pydantic.Field(alias="filterByLicense") + ] = None + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + sku_ids: Annotated[Optional[List[str]], pydantic.Field(alias="skuIds")] = None + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" + + manage_state: Annotated[ + Optional[CreateInputSystemByPackInputMicrosoftCopilotManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""External ID to use when assuming role""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Choose Auto to use IAM roles""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + retry_rules: Annotated[ + Optional[CreateInputSystemByPackRetryRules], pydantic.Field(alias="retryRules") ] = None - r"""SQS secret key""" - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references the client secret from your app registration""" + + cert_options: Annotated[ + Optional[CreateInputSystemByPackCertOptions], + pydantic.Field(alias="certOptions"), ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -3838,84 +3383,227 @@ class CreateInputSystemByPackInputBedrockS3(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputMicrosoftCopilotAuthenticationMethod( + value + ) + except ValueError: + return value + return value - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return ( + models.CreateInputSystemByPackInputMicrosoftCopilotSubscriptionPlan( + value + ) + ) + except ValueError: + return value + return value - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "resource", + "authType", + "planType", + "cronSchedule", + "earliest", + "latest", + "pageSize", + "appClassFilter", + "filterByLicense", + "skuIds", + "manageState", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", + "breakerRulesets", + "staleChannelFlushMs", + "description", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_tenantId", + "__template_clientId", + "__template_planType", + ] + ) + serialized = handler(self) + m = {} - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType(str, Enum): + r"""Connector type identifier.""" + + ANTHROPIC_ENTERPRISE_ANALYTICS = "anthropic_enterprise_analytics" + + +class CreateInputSystemByPackContentType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Content type""" + + USAGE_REPORT = "Usage Report" + COST_REPORT = "Cost Report" + + +class CreateInputSystemByPackGroupBy(str, Enum, metaclass=utils.OpenEnumMeta): + MODEL = "model" + PRODUCT = "product" + CONTEXT_WINDOW = "context_window" + INFERENCE_GEO = "inference_geo" + SPEED = "speed" + RBAC_GROUP_ID = "rbac_group_id" + SLACK_CHANNEL_ID = "slack_channel_id" + TEAMS_CHANNEL_ID = "teams_channel_id" + COST_TYPE = "cost_type" + TOKEN_TYPE = "token_type" + + +class CreateInputSystemByPackBucketWidth(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + + # Daily (1d) + ONED = "1d" + # Hourly (1h) + ONEH = "1h" + # Per-minute (1m) + ONEM = "1m" + + +class CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfigTypedDict( + TypedDict +): + content_type: CreateInputSystemByPackContentType + r"""Content type""" + cron_schedule: str + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + disabled: NotRequired[bool] + r"""Enabled""" + state_tracking: NotRequired[bool] + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + state_update_expression: NotRequired[str] + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" + manage_state: NotRequired[bool] + r"""Manage state""" + group_by: NotRequired[List[CreateInputSystemByPackGroupBy]] + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" + bucket_width: NotRequired[CreateInputSystemByPackBucketWidth] + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + +class CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig(BaseModel): + content_type: Annotated[ + CreateInputSystemByPackContentType, pydantic.Field(alias="contentType") + ] + r"""Content type""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + + disabled: Optional[bool] = None + r"""Enabled""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + manage_state: Annotated[Optional[bool], pydantic.Field(alias="manageState")] = None + r"""Manage state""" + + group_by: Annotated[ + Optional[List[CreateInputSystemByPackGroupBy]], pydantic.Field(alias="groupBy") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + bucket_width: Annotated[ + Optional[CreateInputSystemByPackBucketWidth], + pydantic.Field(alias="bucketWidth"), ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @field_serializer("content_type") + def serialize_content_type(self, value): if isinstance(value, str): try: - return models.SqsAuthenticationMethodOptions(value) + return models.CreateInputSystemByPackContentType(value) except ValueError: return value return value - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): + @field_serializer("bucket_width") + def serialize_bucket_width(self, value): if isinstance(value, str): try: - return models.TagAfterProcessingOptions(value) + return models.CreateInputSystemByPackBucketWidth(value) except ValueError: return value return value @@ -3925,68 +3613,14 @@ def serialize_model(self, handler): optional_fields = set( [ "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", - "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "groupBy", + "bucketWidth", + "earliest", + "jobTimeout", ] ) serialized = handler(self) @@ -4003,13 +3637,17 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputSecurityLakeTypedDict(TypedDict): +class CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSecuritylake + type: CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + text_secret: str + r"""Select or create a stored API key with read:analytics scope""" + content_config: List[ + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfigTypedDict + ] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -4025,125 +3663,48 @@ class CreateInputSystemByPackInputSecurityLakeTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + api_key: NotRequired[str] + r"""API key""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputSystemByPackInputSecurityLake(BaseModel): +class CreateInputSystemByPackInputAnthropicEnterpriseAnalytics(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSecuritylake + type: CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored API key with read:analytics scope""" + + content_config: Annotated[ + List[CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig], + pydantic.Field(alias="contentConfig"), + ] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -4170,40 +3731,13 @@ class CreateInputSystemByPackInputSecurityLake(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -4215,304 +3749,269 @@ class CreateInputSystemByPackInputSecurityLake(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Use Assume Role credentials to access Amazon S3""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "apiKey", + "requestTimeout", + "breakerRulesets", + "staleChannelFlushMs", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + return m - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" +class CreateInputSystemByPackInputAnthropicComplianceType(str, Enum): + r"""Connector type identifier.""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + ANTHROPIC_COMPLIANCE = "anthropic_compliance" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" +class CreateInputSystemByPackActivitiesManageStateTypedDict(TypedDict): + pass - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: Optional[CheckpointingType] = None +class CreateInputSystemByPackActivitiesManageState(BaseModel): + pass - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" +class CreateInputSystemByPackActivitiesTypedDict(TypedDict): + r"""Activities""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputSystemByPackActivitiesManageStateTypedDict] - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" +class CreateInputSystemByPackActivities(BaseModel): + r"""Activities""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" + enabled: Optional[bool] = None + r"""Enabled""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Select or create a stored secret that references your access key and secret key""" + r"""Track collection progress between consecutive scheduled executions""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""SQS secret key""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") + manage_state: Annotated[ + Optional[CreateInputSystemByPackActivitiesManageState], + pydantic.Field(alias="manageState"), ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackChatsManageStateTypedDict(TypedDict): + pass + + +class CreateInputSystemByPackChatsManageState(BaseModel): + pass + + +class CreateInputSystemByPackChatsTypedDict(TypedDict): + r"""Chats""" + + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputSystemByPackChatsManageStateTypedDict] - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" +class CreateInputSystemByPackChats(BaseModel): + r"""Chats""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + enabled: Optional[bool] = None + r"""Enabled""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + manage_state: Annotated[ + Optional[CreateInputSystemByPackChatsManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", - "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", ] ) serialized = handler(self) @@ -4529,186 +4028,87 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputNetflowTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsNetflow - r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - enable_pass_through: NotRequired[bool] - r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - template_cache_minutes: NotRequired[float] - r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" - v5_enabled: NotRequired[bool] - r"""Accept messages in Netflow V5 format.""" - v9_enabled: NotRequired[bool] - r"""Accept messages in Netflow V9 format.""" - ipfix_enabled: NotRequired[bool] - r"""Accept messages in IPFIX format.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateInputSystemByPackInputNetflow(BaseModel): - id: str - r"""Unique ID for this input""" - - type: TypeOptionsNetflow - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - - port: float - r"""Port to listen on""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" +class CreateInputSystemByPackProjectsManageStateTypedDict(TypedDict): + pass - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class CreateInputSystemByPackProjectsManageState(BaseModel): + pass - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: Optional[PqType] = None +class CreateInputSystemByPackProjectsTypedDict(TypedDict): + r"""Projects""" - enable_pass_through: Annotated[ - Optional[bool], pydantic.Field(alias="enablePassThrough") - ] = None - r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputSystemByPackProjectsManageStateTypedDict] - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" +class CreateInputSystemByPackProjects(BaseModel): + r"""Projects""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") - ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enabled: Optional[bool] = None + r"""Enabled""" - template_cache_minutes: Annotated[ - Optional[float], pydantic.Field(alias="templateCacheMinutes") - ] = None - r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - v5_enabled: Annotated[Optional[bool], pydantic.Field(alias="v5Enabled")] = None - r"""Accept messages in Netflow V5 format.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - v9_enabled: Annotated[Optional[bool], pydantic.Field(alias="v9Enabled")] = None - r"""Accept messages in Netflow V9 format.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - ipfix_enabled: Annotated[Optional[bool], pydantic.Field(alias="ipfixEnabled")] = ( + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Accept messages in IPFIX format.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""Track collection progress between consecutive scheduled executions""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + manage_state: Annotated[ + Optional[CreateInputSystemByPackProjectsManageState], + pydantic.Field(alias="manageState"), + ] = None @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "enablePassThrough", - "ipAllowlistRegex", - "ipDenylistRegex", - "udpSocketRxBufSize", - "templateCacheMinutes", - "v5Enabled", - "v9Enabled", - "ipfixEnabled", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", ] ) serialized = handler(self) @@ -4725,291 +4125,184 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputWizWebhookType(str, Enum): - r"""Source type identifier.""" - - WIZ_WEBHOOK = "wiz_webhook" - - -class CreateInputSystemByPackInputWizWebhookTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWizWebhookType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - allowed_paths: NotRequired[List[str]] - r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" - allowed_methods: NotRequired[List[str]] - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_allowed_paths: NotRequired[str] - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - - -class CreateInputSystemByPackInputWizWebhook(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputWizWebhookType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" +class CreateInputSystemByPackChatMessagesManageStateTypedDict(TypedDict): + pass - port: float - r"""Port to listen on""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" +class CreateInputSystemByPackChatMessagesManageState(BaseModel): + pass - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" +class CreateInputSystemByPackChatMessagesTypedDict(TypedDict): + r"""Chat Messages""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputSystemByPackChatMessagesManageStateTypedDict] - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class CreateInputSystemByPackChatMessages(BaseModel): + r"""Chat Messages""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + enabled: Optional[bool] = None + r"""Enabled""" - pq: Optional[PqType] = None + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + r"""Track collection progress between consecutive scheduled executions""" - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") + manage_state: Annotated[ + Optional[CreateInputSystemByPackChatMessagesManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + return m - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" +class CreateInputSystemByPackProjectDetailsManageStateTypedDict(TypedDict): + pass - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" +class CreateInputSystemByPackProjectDetailsManageState(BaseModel): + pass - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" +class CreateInputSystemByPackProjectDetailsTypedDict(TypedDict): + r"""Project Details""" - allowed_paths: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedPaths") - ] = None - r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputSystemByPackProjectDetailsManageStateTypedDict] - allowed_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedMethods") - ] = None - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], - pydantic.Field(alias="authTokensExt"), - ] = None - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" +class CreateInputSystemByPackProjectDetails(BaseModel): + r"""Project Details""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + enabled: Optional[bool] = None + r"""Enabled""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + r"""Track collection progress between consecutive scheduled executions""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - template_allowed_paths: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedPaths") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputSystemByPackProjectDetailsManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "breakerRulesets", - "staleChannelFlushMs", - "metadata", - "allowedPaths", - "allowedMethods", - "authTokensExt", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_allowedPaths", + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", ] ) serialized = handler(self) @@ -5026,204 +4319,152 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputOpenaiType(str, Enum): - r"""Connector type identifier.""" +class CreateInputSystemByPackGroupsTypedDict(TypedDict): + r"""Groups""" + + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + +class CreateInputSystemByPackGroups(BaseModel): + r"""Groups""" + + enabled: Optional[bool] = None + r"""Enabled""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackOrganizationsTypedDict(TypedDict): + r"""Organizations""" - OPENAI = "openai" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" -class CreateInputSystemByPackInputOpenaiManageStateTypedDict(TypedDict): - pass +class CreateInputSystemByPackOrganizations(BaseModel): + r"""Organizations""" + enabled: Optional[bool] = None + r"""Enabled""" -class CreateInputSystemByPackInputOpenaiManageState(BaseModel): - pass + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" -class CreateInputSystemByPackPaginationType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Pagination type""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} - # None - NONE = "none" - # Response Body Attribute - RESPONSE_BODY = "response_body" - # Response Header Attribute - RESPONSE_HEADER = "response_header" - # RFC 5988 Link Header - RESPONSE_HEADER_LINK = "response_header_link" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val -class CreateInputSystemByPackInputOpenaiLogLevel( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Collector runtime log level.""" + return m - ERROR = "error" - WARN = "warn" - INFO = "info" - DEBUG = "debug" - SILLY = "silly" +class CreateInputSystemByPackOrganizationUsersTypedDict(TypedDict): + r"""Organization Users""" -class CreateInputSystemByPackInputOpenaiContentConfigTypedDict(TypedDict): - request_params: List[ - RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict - ] - r"""Query-string parameters to send with this endpoint""" - pagination_type: CreateInputSystemByPackPaginationType - r"""Pagination type""" - cron_schedule: str - r"""A cron schedule on which to run this job""" - earliest: str - r"""Relative to the current time""" - latest: str - r"""Relative to the current time""" - disabled: NotRequired[bool] + enabled: NotRequired[bool] r"""Enabled""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions.""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[CreateInputSystemByPackInputOpenaiManageStateTypedDict] - pagination_attribute: NotRequired[List[str]] - r"""Pagination attributes""" - pagination_last_page_expr: NotRequired[str] - r"""Last page expression""" - max_pages: NotRequired[float] - r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" - pagination_next_relation_attribute: NotRequired[str] - r"""Used only for RFC 5988 link-header pagination""" - pagination_cur_relation_attribute: NotRequired[str] - r"""Optional relation that represents the current page""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" job_timeout: NotRequired[str] r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: NotRequired[CreateInputSystemByPackInputOpenaiLogLevel] - r"""Collector runtime log level.""" - endpoint_metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields automatically added to events from this Content Type""" -class CreateInputSystemByPackInputOpenaiContentConfig(BaseModel): - request_params: Annotated[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret], - pydantic.Field(alias="requestParams"), - ] - r"""Query-string parameters to send with this endpoint""" +class CreateInputSystemByPackOrganizationUsers(BaseModel): + r"""Organization Users""" - pagination_type: Annotated[ - CreateInputSystemByPackPaginationType, pydantic.Field(alias="paginationType") - ] - r"""Pagination type""" + enabled: Optional[bool] = None + r"""Enabled""" - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""A cron schedule on which to run this job""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - earliest: str - r"""Relative to the current time""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - latest: str - r"""Relative to the current time""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} - disabled: Optional[bool] = None - r"""Enabled""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" + return m - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: Annotated[ - Optional[CreateInputSystemByPackInputOpenaiManageState], - pydantic.Field(alias="manageState"), - ] = None +class CreateInputSystemByPackOrganizationRolesTypedDict(TypedDict): + r"""Organization Roles""" - pagination_attribute: Annotated[ - Optional[List[str]], pydantic.Field(alias="paginationAttribute") - ] = None - r"""Pagination attributes""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - pagination_last_page_expr: Annotated[ - Optional[str], pydantic.Field(alias="paginationLastPageExpr") - ] = None - r"""Last page expression""" - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" +class CreateInputSystemByPackOrganizationRoles(BaseModel): + r"""Organization Roles""" - pagination_next_relation_attribute: Annotated[ - Optional[str], pydantic.Field(alias="paginationNextRelationAttribute") - ] = None - r"""Used only for RFC 5988 link-header pagination""" + enabled: Optional[bool] = None + r"""Enabled""" - pagination_cur_relation_attribute: Annotated[ - Optional[str], pydantic.Field(alias="paginationCurRelationAttribute") - ] = None - r"""Optional relation that represents the current page""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: Annotated[ - Optional[CreateInputSystemByPackInputOpenaiLogLevel], - pydantic.Field(alias="logLevel"), - ] = None - r"""Collector runtime log level.""" - - endpoint_metadata: Annotated[ - Optional[List[MetadataConfInputCollection]], - pydantic.Field(alias="endpointMetadata"), - ] = None - r"""Fields automatically added to events from this Content Type""" - - @field_serializer("pagination_type") - def serialize_pagination_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackPaginationType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputOpenaiLogLevel(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - "paginationAttribute", - "paginationLastPageExpr", - "maxPages", - "paginationNextRelationAttribute", - "paginationCurRelationAttribute", - "jobTimeout", - "logLevel", - "endpointMetadata", - ] - ) + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) serialized = handler(self) m = {} @@ -5238,15 +4479,13 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputOpenaiTypedDict(TypedDict): +class CreateInputSystemByPackInputAnthropicComplianceTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOpenaiType + type: CreateInputSystemByPackInputAnthropicComplianceType r"""Connector type identifier.""" - content_config: List[CreateInputSystemByPackInputOpenaiContentConfigTypedDict] - r"""Content Types""" text_secret: str - r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" + r"""Select or create a stored Anthropic API key""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -5262,14 +4501,32 @@ class CreateInputSystemByPackInputOpenaiTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - openai_organization: NotRequired[str] - r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" - openai_project: NotRequired[str] - r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" + api_key: NotRequired[str] + r"""API key""" + activities: NotRequired[CreateInputSystemByPackActivitiesTypedDict] + r"""Activities""" + chats: NotRequired[CreateInputSystemByPackChatsTypedDict] + r"""Chats""" + projects: NotRequired[CreateInputSystemByPackProjectsTypedDict] + r"""Projects""" + chat_messages: NotRequired[CreateInputSystemByPackChatMessagesTypedDict] + r"""Chat Messages""" + project_details: NotRequired[CreateInputSystemByPackProjectDetailsTypedDict] + r"""Project Details""" + groups: NotRequired[CreateInputSystemByPackGroupsTypedDict] + r"""Groups""" + organizations: NotRequired[CreateInputSystemByPackOrganizationsTypedDict] + r"""Organizations""" + org_users: NotRequired[CreateInputSystemByPackOrganizationUsersTypedDict] + r"""Organization Users""" + org_roles: NotRequired[CreateInputSystemByPackOrganizationRolesTypedDict] + r"""Organization Roles""" request_timeout: NotRequired[float] r"""HTTP request inactivity timeout. Use 0 to disable.""" - api_key: NotRequired[str] - r"""API key""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" keep_alive_time: NotRequired[float] r"""How often workers should check in with the scheduler to keep job subscription alive""" max_missed_keep_alives: NotRequired[float] @@ -5287,27 +4544,17 @@ class CreateInputSystemByPackInputOpenaiTypedDict(TypedDict): r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_openai_organization: NotRequired[str] - r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - template_openai_project: NotRequired[str] - r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" -class CreateInputSystemByPackInputOpenai(BaseModel): +class CreateInputSystemByPackInputAnthropicCompliance(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOpenaiType + type: CreateInputSystemByPackInputAnthropicComplianceType r"""Connector type identifier.""" - content_config: Annotated[ - List[CreateInputSystemByPackInputOpenaiContentConfig], - pydantic.Field(alias="contentConfig"), - ] - r"""Content Types""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" + r"""Select or create a stored Anthropic API key""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -5334,23 +4581,50 @@ class CreateInputSystemByPackInputOpenai(BaseModel): pq: Optional[PqType] = None - openai_organization: Annotated[ - Optional[str], pydantic.Field(alias="openaiOrganization") - ] = None - r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - openai_project: Annotated[Optional[str], pydantic.Field(alias="openaiProject")] = ( - None - ) - r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" + activities: Optional[CreateInputSystemByPackActivities] = None + r"""Activities""" + + chats: Optional[CreateInputSystemByPackChats] = None + r"""Chats""" + + projects: Optional[CreateInputSystemByPackProjects] = None + r"""Projects""" + + chat_messages: Optional[CreateInputSystemByPackChatMessages] = None + r"""Chat Messages""" + + project_details: Optional[CreateInputSystemByPackProjectDetails] = None + r"""Project Details""" + + groups: Optional[CreateInputSystemByPackGroups] = None + r"""Groups""" + + organizations: Optional[CreateInputSystemByPackOrganizations] = None + r"""Organizations""" + + org_users: Optional[CreateInputSystemByPackOrganizationUsers] = None + r"""Organization Users""" + + org_roles: Optional[CreateInputSystemByPackOrganizationRoles] = None + r"""Organization Roles""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None r"""HTTP request inactivity timeout. Use 0 to disable.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" keep_alive_time: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTime") @@ -5378,193 +4652,52 @@ class CreateInputSystemByPackInputOpenai(BaseModel): ] = None description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_openai_organization: Annotated[ - Optional[str], pydantic.Field(alias="__template_openaiOrganization") - ] = None - r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - - template_openai_project: Annotated[ - Optional[str], pydantic.Field(alias="__template_openaiProject") - ] = None - r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "openaiOrganization", - "openaiProject", - "requestTimeout", - "apiKey", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "retryRules", - "description", - "__template_environment", - "__template_streamtags", - "__template_openaiOrganization", - "__template_openaiProject", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputWizType(str, Enum): - r"""Connector type identifier.""" - - WIZ = "wiz" - - -class CreateInputSystemByPackInputWizManageStateTypedDict(TypedDict): - pass - - -class CreateInputSystemByPackInputWizManageState(BaseModel): - pass - - -class CreateInputSystemByPackInputWizContentConfigTypedDict(TypedDict): - content_type: str - r"""The name of the Wiz query""" - content_query: str - r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" - cron_schedule: str - r"""A cron schedule on which to run this job""" - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - content_description: NotRequired[str] - r"""Description""" - enabled: NotRequired[bool] - r"""Enable content""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[CreateInputSystemByPackInputWizManageStateTypedDict] - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" - log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] - r"""Collector runtime log level""" - max_pages: NotRequired[float] - r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" - - -class CreateInputSystemByPackInputWizContentConfig(BaseModel): - content_type: Annotated[str, pydantic.Field(alias="contentType")] - r"""The name of the Wiz query""" - - content_query: Annotated[str, pydantic.Field(alias="contentQuery")] - r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" - - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""A cron schedule on which to run this job""" - - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - - content_description: Annotated[ - Optional[str], pydantic.Field(alias="contentDescription") - ] = None - r"""Description""" - - enabled: Optional[bool] = None - r"""Enable content""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - - manage_state: Annotated[ - Optional[CreateInputSystemByPackInputWizManageState], - pydantic.Field(alias="manageState"), - ] = None - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItemsDebugError], - pydantic.Field(alias="logLevel"), - ] = None - r"""Collector runtime log level""" - - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItemsDebugError(value) - except ValueError: - return value - return value + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "contentDescription", - "enabled", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - "jobTimeout", - "logLevel", - "maxPages", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "apiKey", + "activities", + "chats", + "projects", + "chat_messages", + "project_details", + "groups", + "organizations", + "org_users", + "org_roles", + "requestTimeout", + "breakerRulesets", + "staleChannelFlushMs", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", + "description", + "__template_environment", + "__template_streamtags", ] ) serialized = handler(self) @@ -5581,19 +4714,40 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputWizTypedDict(TypedDict): +class CreateInputSystemByPackInputOpenaiComplianceLogsType(str, Enum): + r"""Connector type identifier.""" + + OPENAI_COMPLIANCE_LOGS = "openai_compliance_logs" + + +class CreateInputSystemByPackAccountType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Account type""" + + # Workspace + WORKSPACE = "workspace" + # Organization + ORGANIZATION = "organization" + + +class CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict(TypedDict): + pass + + +class CreateInputSystemByPackInputOpenaiComplianceLogsManageState(BaseModel): + pass + + +class CreateInputSystemByPackInputOpenaiComplianceLogsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWizType + type: CreateInputSystemByPackInputOpenaiComplianceLogsType r"""Connector type identifier.""" - endpoint: str - r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" - auth_url: str - r"""The authentication URL to generate an OAuth token""" - client_id: str - r"""The client ID of the Wiz application""" - content_config: List[CreateInputSystemByPackInputWizContentConfigTypedDict] - r"""Content types""" + text_secret: str + r"""Select or create a stored text secret""" + account_type: CreateInputSystemByPackAccountType + r"""Account type""" + cron_schedule: str + r"""Cron schedule""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -5609,8 +4763,20 @@ class CreateInputSystemByPackInputWizTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_audience_override: NotRequired[str] - r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + api_key: NotRequired[str] + r"""API key""" + earliest: NotRequired[str] + r"""Relative to the current time. Format: [+|-]""" + latest: NotRequired[str] + r"""Relative to the current time. Format: [+|-]""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] + r"""Collector runtime log level""" + max_pages: NotRequired[float] + r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" request_timeout: NotRequired[float] r"""HTTP request inactivity timeout. Use 0 to disable.""" keep_alive_time: NotRequired[float] @@ -5628,47 +4794,50 @@ class CreateInputSystemByPackInputWizTypedDict(TypedDict): stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" retry_rules: NotRequired[RetryRulesTypeTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""The client secret of the Wiz application""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" + workspace_id: NotRequired[str] + r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" + workspace_event_types: NotRequired[List[str]] + r"""One or more compliance log categories to collect""" + organization_id: NotRequired[str] + r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + organization_event_types: NotRequired[List[str]] + r"""One or more compliance log categories to collect""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[ + CreateInputSystemByPackInputOpenaiComplianceLogsManageStateTypedDict + ] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_auth_url: NotRequired[str] - r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_workspace_id: NotRequired[str] + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + template_organization_id: NotRequired[str] + r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" -class CreateInputSystemByPackInputWiz(BaseModel): +class CreateInputSystemByPackInputOpenaiComplianceLogs(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWizType + type: CreateInputSystemByPackInputOpenaiComplianceLogsType r"""Connector type identifier.""" - endpoint: str - r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" - - auth_url: Annotated[str, pydantic.Field(alias="authUrl")] - r"""The authentication URL to generate an OAuth token""" - - client_id: Annotated[str, pydantic.Field(alias="clientId")] - r"""The client ID of the Wiz application""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" - content_config: Annotated[ - List[CreateInputSystemByPackInputWizContentConfig], - pydantic.Field(alias="contentConfig"), + account_type: Annotated[ + CreateInputSystemByPackAccountType, pydantic.Field(alias="accountType") ] - r"""Content types""" + r"""Account type""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -5695,10 +4864,31 @@ class CreateInputSystemByPackInputWiz(BaseModel): pq: Optional[PqType] = None - auth_audience_override: Annotated[ - Optional[str], pydantic.Field(alias="authAudienceOverride") + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" + + earliest: Optional[str] = None + r"""Relative to the current time. Format: [+|-]""" + + latest: Optional[str] = None + r"""Relative to the current time. Format: [+|-]""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItemsDebugError], + pydantic.Field(alias="logLevel"), ] = None - r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + r"""Collector runtime log level""" + + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") @@ -5740,20 +4930,41 @@ class CreateInputSystemByPackInputWiz(BaseModel): Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""The client secret of the Wiz application""" + workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None + r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + workspace_event_types: Annotated[ + Optional[List[str]], pydantic.Field(alias="workspaceEventTypes") + ] = None + r"""One or more compliance log categories to collect""" + + organization_id: Annotated[ + Optional[str], pydantic.Field(alias="organizationId") + ] = None + r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + + organization_event_types: Annotated[ + Optional[List[str]], pydantic.Field(alias="organizationEventTypes") + ] = None + r"""One or more compliance log categories to collect""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputSystemByPackInputOpenaiComplianceLogsManageState], + pydantic.Field(alias="manageState"), + ] = None template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -5765,26 +4976,30 @@ class CreateInputSystemByPackInputWiz(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_workspace_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceId") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_auth_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_authUrl") + template_organization_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_organizationId") ] = None - r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" + r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + @field_serializer("account_type") + def serialize_account_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackAccountType(value) + except ValueError: + return value + return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("log_level") + def serialize_log_level(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsManualSecret(value) + return models.LogLevelOptionsContentConfigItemsDebugError(value) except ValueError: return value return value @@ -5801,7 +5016,13 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "authAudienceOverride", + "apiKey", + "earliest", + "latest", + "jobTimeout", + "logLevel", + "maxPages", + "stateTracking", "requestTimeout", "keepAliveTime", "maxMissedKeepAlives", @@ -5811,15 +5032,18 @@ def serialize_model(self, handler): "breakerRulesets", "staleChannelFlushMs", "retryRules", - "authType", "description", - "clientSecret", - "textSecret", + "workspaceId", + "workspaceEventTypes", + "organizationId", + "organizationEventTypes", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", "__template_environment", "__template_streamtags", - "__template_endpoint", - "__template_authUrl", - "__template_clientId", + "__template_workspaceId", + "__template_organizationId", ] ) serialized = handler(self) @@ -5836,52 +5060,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputJournalFilesType(str, Enum): - r"""Connector type identifier.""" - - JOURNAL_FILES = "journal_files" - - -class CreateInputSystemByPackInputJournalFilesRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" - description: NotRequired[str] - r"""Optional description of this rule's purpose""" - - -class CreateInputSystemByPackInputJournalFilesRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" - - description: Optional[str] = None - r"""Optional description of this rule's purpose""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateInputSystemByPackInputAquaSecurityHecType(str, Enum): + r"""Source type identifier.""" - return m + AQUA_SECURITY_HEC = "aqua_security_hec" -class CreateInputSystemByPackInputJournalFilesTypedDict(TypedDict): +class CreateInputSystemByPackInputAquaSecurityHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputJournalFilesType - r"""Connector type identifier.""" - path: str - r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" - journals: List[str] - r"""The full path of discovered journals are matched against this wildcard list.""" + type: CreateInputSystemByPackInputAquaSecurityHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -5897,38 +5092,75 @@ class CreateInputSystemByPackInputJournalFilesTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between scanning for journals.""" - rules: NotRequired[List[CreateInputSystemByPackInputJournalFilesRuleTypedDict]] - r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" - current_boot: NotRequired[bool] - r"""Skip log messages that are not part of the current boot session""" - max_age_dur: NotRequired[str] - r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" - suppress_missing_path_errors: NotRequired[bool] - r"""Suppress errors when search path does not exist""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputJournalFiles(BaseModel): +class CreateInputSystemByPackInputAquaSecurityHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputJournalFilesType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputAquaSecurityHecType + r"""Source type identifier.""" - path: str - r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - journals: List[str] - r"""The full path of discovered journals are matched against this wildcard list.""" + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -5955,25 +5187,85 @@ class CreateInputSystemByPackInputJournalFiles(BaseModel): pq: Optional[PqType] = None - interval: Optional[float] = None - r"""Time, in seconds, between scanning for journals.""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - rules: Optional[List[CreateInputSystemByPackInputJournalFilesRule]] = None - r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - current_boot: Annotated[Optional[bool], pydantic.Field(alias="currentBoot")] = None - r"""Skip log messages that are not part of the current boot session""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None - r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - suppress_missing_path_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Suppress errors when search path does not exist""" + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -5983,10 +5275,40 @@ class CreateInputSystemByPackInputJournalFiles(BaseModel): ] = None r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -6000,15 +5322,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "interval", - "rules", - "currentBoot", - "maxAgeDur", - "suppressMissingPathErrors", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -6025,21 +5364,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputRawUDPType(str, Enum): - r"""Connector type identifier.""" +class CreateInputSystemByPackInputExtrahopRevealx360Type(str, Enum): + r"""Source type identifier.""" - RAW_UDP = "raw_udp" + EXTRAHOP_REVEALX_360 = "extrahop_revealx_360" -class CreateInputSystemByPackInputRawUDPTypedDict(TypedDict): +class CreateInputSystemByPackInputExtrahopRevealx360TypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputRawUDPType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputExtrahopRevealx360Type + r"""Source type identifier.""" host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6055,18 +5396,40 @@ class CreateInputSystemByPackInputRawUDPTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - single_msg_udp_packets: NotRequired[bool] - r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" - ingest_raw_bytes: NotRequired[bool] - r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -6077,21 +5440,32 @@ class CreateInputSystemByPackInputRawUDPTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputRawUDP(BaseModel): +class CreateInputSystemByPackInputExtrahopRevealx360(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputRawUDPType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputExtrahopRevealx360Type + r"""Source type identifier.""" host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -6117,33 +5491,87 @@ class CreateInputSystemByPackInputRawUDP(BaseModel): pq: Optional[PqType] = None - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Maximum number of events to buffer when downstream is blocking.""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - ingest_raw_bytes: Annotated[ - Optional[bool], pydantic.Field(alias="ingestRawBytes") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" + r"""Add request headers to events, in the __headers field""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -6168,6 +5596,26 @@ class CreateInputSystemByPackInputRawUDP(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -6180,17 +5628,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "maxBufferSize", - "ipWhitelistRegex", - "singleMsgUdpPackets", - "ingestRawBytes", - "udpSocketRxBufSize", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -6207,30 +5670,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputAppleUnifiedLogsType(str, Enum): - r"""Connector type identifier.""" - - APPLE_UNIFIED_LOGS = "apple_unified_logs" - - -class CreateInputSystemByPackInputAppleUnifiedLogsReadMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" +class CreateInputSystemByPackInputSailpointHecType(str, Enum): + r"""Source type identifier.""" - # Entire log - OLDEST = "oldest" - # From last entry - NEWEST = "newest" + SAILPOINT_HEC = "sailpoint_hec" -class CreateInputSystemByPackInputAppleUnifiedLogsTypedDict(TypedDict): +class CreateInputSystemByPackInputSailpointHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputAppleUnifiedLogsType - r"""Connector type identifier.""" - predicate: str - r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" + type: CreateInputSystemByPackInputSailpointHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6246,27 +5702,61 @@ class CreateInputSystemByPackInputAppleUnifiedLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - read_mode: NotRequired[CreateInputSystemByPackInputAppleUnifiedLogsReadMode] - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" -class CreateInputSystemByPackInputAppleUnifiedLogs(BaseModel): +class CreateInputSystemByPackInputSailpointHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputAppleUnifiedLogsType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputSailpointHecType + r"""Source type identifier.""" - predicate: str - r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -6293,14 +5783,67 @@ class CreateInputSystemByPackInputAppleUnifiedLogs(BaseModel): pq: Optional[PqType] = None - read_mode: Annotated[ - Optional[CreateInputSystemByPackInputAppleUnifiedLogsReadMode], - pydantic.Field(alias="readMode"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -6315,16 +5858,20 @@ class CreateInputSystemByPackInputAppleUnifiedLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - @field_serializer("read_mode") - def serialize_read_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputAppleUnifiedLogsReadMode( - value - ) - except ValueError: - return value - return value + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -6338,11 +5885,25 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "readMode", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", ] ) serialized = handler(self) @@ -6359,39 +5920,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputWinEventLogsType(str, Enum): - r"""Connector type identifier.""" - - WIN_EVENT_LOGS = "win_event_logs" - - -class CreateInputSystemByPackInputWinEventLogsReadMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Read all stored and future event logs, or only future events""" - - # Entire log - OLDEST = "oldest" - # From last entry - NEWEST = "newest" - - -class CreateInputSystemByPackEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of individual events""" +class CreateInputSystemByPackInputTrellixHecType(str, Enum): + r"""Source type identifier.""" - # JSON - JSON = "json" - # XML - XML = "xml" + TRELLIX_HEC = "trellix_hec" -class CreateInputSystemByPackInputWinEventLogsTypedDict(TypedDict): +class CreateInputSystemByPackInputTrellixHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWinEventLogsType - r"""Connector type identifier.""" - log_names: List[str] - r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + type: CreateInputSystemByPackInputTrellixHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6407,43 +5952,75 @@ class CreateInputSystemByPackInputWinEventLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - suppress_missing_log_errors: NotRequired[bool] - r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - read_mode: NotRequired[CreateInputSystemByPackInputWinEventLogsReadMode] - r"""Read all stored and future event logs, or only future events""" - event_format: NotRequired[CreateInputSystemByPackEventFormat] - r"""Format of individual events""" - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" - interval: NotRequired[float] - r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" - batch_size: NotRequired[float] - r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - max_event_bytes: NotRequired[int] - r"""The maximum number of bytes in an event before it is flushed to the pipelines""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - disable_json_rendering: NotRequired[bool] - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" - disable_xml_rendering: NotRequired[bool] - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputWinEventLogs(BaseModel): +class CreateInputSystemByPackInputTrellixHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWinEventLogsType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputTrellixHecType + r"""Source type identifier.""" - log_names: Annotated[List[str], pydantic.Field(alias="logNames")] - r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -6470,258 +6047,169 @@ class CreateInputSystemByPackInputWinEventLogs(BaseModel): pq: Optional[PqType] = None - suppress_missing_log_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingLogErrors") - ] = None - r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - - read_mode: Annotated[ - Optional[CreateInputSystemByPackInputWinEventLogsReadMode], - pydantic.Field(alias="readMode"), - ] = None - r"""Read all stored and future event logs, or only future events""" - - event_format: Annotated[ - Optional[CreateInputSystemByPackEventFormat], - pydantic.Field(alias="eventFormat"), - ] = None - r"""Format of individual events""" - - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" - - interval: Optional[float] = None - r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" - - batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None - r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - max_event_bytes: Annotated[Optional[int], pydantic.Field(alias="maxEventBytes")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""The maximum number of bytes in an event before it is flushed to the pipelines""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - disable_json_rendering: Annotated[ - Optional[bool], pydantic.Field(alias="disableJsonRendering") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - disable_xml_rendering: Annotated[ - Optional[bool], pydantic.Field(alias="disableXmlRendering") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Add request headers to events, in the __headers field""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @field_serializer("read_mode") - def serialize_read_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputWinEventLogsReadMode(value) - except ValueError: - return value - return value - - @field_serializer("event_format") - def serialize_event_format(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackEventFormat(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "suppressMissingLogErrors", - "readMode", - "eventFormat", - "disableNativeModule", - "interval", - "batchSize", - "metadata", - "maxEventBytes", - "description", - "disableJsonRendering", - "disableXmlRendering", - "__template_environment", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputWefType(str, Enum): - r"""Connector type identifier.""" - - WEF = "wef" - + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" -class CreateInputSystemByPackInputWefAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""How to authenticate incoming client connections""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - # Client certificate - CLIENT_CERT = "clientCert" - # Kerberos - KERBEROS = "kerberos" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class CreateInputSystemByPackMTLSSettingsTypedDict(TypedDict): - r"""mTLS settings""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - priv_key_path: str - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - cert_path: str - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - ca_path: str - r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" - disabled: NotRequired[bool] - r"""Enable TLS""" - reject_unauthorized: NotRequired[bool] - r"""Required for WEF certificate authentication""" - request_cert: NotRequired[bool] - r"""Required for WEF certificate authentication""" - certificate_name: NotRequired[str] - r"""Name of the predefined certificate""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - common_name_regex: NotRequired[str] - r"""Regex matching allowable common names in peer certificates' subject attribute""" - min_version: NotRequired[MinimumTLSVersionOptionsTLS] - r"""Minimum TLS version""" - max_version: NotRequired[MaximumTLSVersionOptionsTLS] - r"""Maximum TLS version""" - ocsp_check: NotRequired[bool] - r"""Enable OCSP check of certificate""" - ocsp_check_fail_close: NotRequired[bool] - r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class CreateInputSystemByPackMTLSSettings(BaseModel): - r"""mTLS settings""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - cert_path: Annotated[str, pydantic.Field(alias="certPath")] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - ca_path: Annotated[str, pydantic.Field(alias="caPath")] - r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - disabled: Optional[bool] = None - r"""Enable TLS""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Required for WEF certificate authentication""" - - request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None - r"""Required for WEF certificate authentication""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Name of the predefined certificate""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - common_name_regex: Annotated[ - Optional[str], pydantic.Field(alias="commonNameRegex") - ] = None - r"""Regex matching allowable common names in peer certificates' subject attribute""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - min_version: Annotated[ - Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Minimum TLS version""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - max_version: Annotated[ - Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Maximum TLS version""" - - ocsp_check: Annotated[Optional[bool], pydantic.Field(alias="ocspCheck")] = None - r"""Enable OCSP check of certificate""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - ocsp_check_fail_close: Annotated[ - Optional[bool], pydantic.Field(alias="ocspCheckFailClose") + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") ] = None - r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" - - @field_serializer("min_version") - def serialize_min_version(self, value): - if isinstance(value, str): - try: - return models.MinimumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - @field_serializer("max_version") - def serialize_max_version(self, value): - if isinstance(value, str): - try: - return models.MaximumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ "disabled", - "rejectUnauthorized", - "requestCert", - "certificateName", - "passphrase", - "commonNameRegex", - "minVersion", - "maxVersion", - "ocspCheck", - "ocspCheckFailClose", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -6738,149 +6226,296 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Content format in which the endpoint should deliver events""" +class CreateInputSystemByPackInputUpwindHecType(str, Enum): + r"""Source type identifier.""" - RAW = "Raw" - RENDERED_TEXT = "RenderedText" + UPWIND_HEC = "upwind_hec" -class CreateInputSystemByPackQueryBuilderMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Query builder mode""" +class CreateInputSystemByPackInputUpwindHecTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputUpwindHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - SIMPLE = "simple" - XML = "xml" +class CreateInputSystemByPackInputUpwindHec(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputUpwindHecType + r"""Source type identifier.""" -class CreateInputSystemByPackQueryTypedDict(TypedDict): - path: str - r"""The Path attribute from the relevant XML Select element""" - query_expression: str - r"""The XPath query inside the relevant XML Select element""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" -class CreateInputSystemByPackQuery(BaseModel): - path: str - r"""The Path attribute from the relevant XML Select element""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - query_expression: Annotated[str, pydantic.Field(alias="queryExpression")] - r"""The XPath query inside the relevant XML Select element""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" -class CreateInputSystemByPackSubscriptionTypedDict(TypedDict): - subscription_name: str - r"""Subscription name""" - content_format: CreateInputSystemByPackFormat - r"""Content format in which the endpoint should deliver events""" - heartbeat_interval: float - r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" - batch_timeout: float - r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" - targets: List[str] - r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" - version: NotRequired[str] - r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" - read_existing_events: NotRequired[bool] - r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" - send_bookmarks: NotRequired[bool] - r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - compress: NotRequired[bool] - r"""Receive compressed events from the source""" - locale: NotRequired[str] - r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" - query_selector: NotRequired[CreateInputSystemByPackQueryBuilderMode] - r"""Query builder mode""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events ingested under this subscription""" - queries: NotRequired[List[CreateInputSystemByPackQueryTypedDict]] - r"""Queries""" - xml_query: NotRequired[str] - r"""The XPath query to use for selecting events""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class CreateInputSystemByPackSubscription(BaseModel): - subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] - r"""Subscription name""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - content_format: Annotated[ - CreateInputSystemByPackFormat, pydantic.Field(alias="contentFormat") - ] - r"""Content format in which the endpoint should deliver events""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - heartbeat_interval: Annotated[float, pydantic.Field(alias="heartbeatInterval")] - r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - batch_timeout: Annotated[float, pydantic.Field(alias="batchTimeout")] - r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - targets: List[str] - r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - version: Optional[str] = None - r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - read_existing_events: Annotated[ - Optional[bool], pydantic.Field(alias="readExistingEvents") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - send_bookmarks: Annotated[Optional[bool], pydantic.Field(alias="sendBookmarks")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - - compress: Optional[bool] = None - r"""Receive compressed events from the source""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - locale: Optional[str] = None - r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - query_selector: Annotated[ - Optional[CreateInputSystemByPackQueryBuilderMode], - pydantic.Field(alias="querySelector"), + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Query builder mode""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events ingested under this subscription""" - - queries: Optional[List[CreateInputSystemByPackQuery]] = None - r"""Queries""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - xml_query: Annotated[Optional[str], pydantic.Field(alias="xmlQuery")] = None - r"""The XPath query to use for selecting events""" + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - @field_serializer("content_format") - def serialize_content_format(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackFormat(value) - except ValueError: - return value - return value + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - @field_serializer("query_selector") - def serialize_query_selector(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackQueryBuilderMode(value) - except ValueError: - return value - return value + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "version", - "readExistingEvents", - "sendBookmarks", - "compress", - "locale", - "querySelector", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "queries", - "xmlQuery", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -6897,17 +6532,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputWefTypedDict(TypedDict): +class CreateInputSystemByPackInputSysdigHecType(str, Enum): + r"""Source type identifier.""" + + SYSDIG_HEC = "sysdig_hec" + + +class CreateInputSystemByPackInputSysdigHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWefType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputSysdigHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" - subscriptions: List[CreateInputSystemByPackSubscriptionTypedDict] - r"""Subscriptions to events on forwarding endpoints""" + hec_api: str + r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -6923,42 +6564,42 @@ class CreateInputSystemByPackInputWefTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_method: NotRequired[CreateInputSystemByPackInputWefAuthenticationMethod] - r"""How to authenticate incoming client connections""" - tls: NotRequired[CreateInputSystemByPackMTLSSettingsTypedDict] - r"""mTLS settings""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" max_requests_per_socket: NotRequired[int] r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" capture_headers: NotRequired[bool] - r"""Add request headers to events in the __headers field""" + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: NotRequired[float] r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" ip_allowlist_regex: NotRequired[str] r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - ca_fingerprint: NotRequired[str] - r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" - keytab: NotRequired[str] - r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" - principal: NotRequired[str] - r"""Kerberos principal used for authentication, typically in the form HTTP/@""" - allow_machine_id_mismatch: NotRequired[bool] - r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - log_fingerprint_mismatch: NotRequired[bool] - r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -6967,18 +6608,22 @@ class CreateInputSystemByPackInputWefTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_keytab: NotRequired[str] - r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" - template_principal: NotRequired[str] - r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputWef(BaseModel): +class CreateInputSystemByPackInputSysdigHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWefType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputSysdigHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -6986,8 +6631,8 @@ class CreateInputSystemByPackInputWef(BaseModel): port: float r"""Port to listen on""" - subscriptions: List[CreateInputSystemByPackSubscription] - r"""Subscriptions to events on forwarding endpoints""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -7014,14 +6659,14 @@ class CreateInputSystemByPackInputWef(BaseModel): pq: Optional[PqType] = None - auth_method: Annotated[ - Optional[CreateInputSystemByPackInputWefAuthenticationMethod], - pydantic.Field(alias="authMethod"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""How to authenticate incoming client connections""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: Optional[CreateInputSystemByPackMTLSSettings] = None - r"""mTLS settings""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None @@ -7036,23 +6681,33 @@ class CreateInputSystemByPackInputWef(BaseModel): enable_proxy_header: Annotated[ Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" capture_headers: Annotated[ Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Add request headers to events in the __headers field""" + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None @@ -7063,38 +6718,32 @@ class CreateInputSystemByPackInputWef(BaseModel): ] = None r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - ca_fingerprint: Annotated[Optional[str], pydantic.Field(alias="caFingerprint")] = ( - None - ) - r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - keytab: Optional[str] = None - r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - principal: Optional[str] = None - r"""Kerberos principal used for authentication, typically in the form HTTP/@""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - allow_machine_id_mismatch: Annotated[ - Optional[bool], pydantic.Field(alias="allowMachineIdMismatch") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None - r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" - log_fingerprint_mismatch: Annotated[ - Optional[bool], pydantic.Field(alias="logFingerprintMismatch") - ] = None - r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -7115,24 +6764,25 @@ class CreateInputSystemByPackInputWef(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_keytab: Annotated[ - Optional[str], pydantic.Field(alias="__template_keytab") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_principal: Annotated[ - Optional[str], pydantic.Field(alias="__template_principal") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - @field_serializer("auth_method") - def serialize_auth_method(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputWefAuthenticationMethod(value) - except ValueError: - return value - return value + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -7146,30 +6796,32 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "authMethod", + "authTokens", "tls", "maxActiveReq", "maxRequestsPerSocket", "enableProxyHeader", "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", "keepAliveTimeout", - "enableHealthCheck", "ipAllowlistRegex", "ipDenylistRegex", - "socketTimeout", - "caFingerprint", - "keytab", - "principal", - "allowMachineIdMismatch", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", - "logFingerprintMismatch", "__template_environment", "__template_streamtags", "__template_host", "__template_port", - "__template_keytab", - "__template_principal", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -7186,122 +6838,99 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputAppscopeType(str, Enum): - r"""Connector type identifier.""" - - APPSCOPE = "appscope" - - -class CreateInputSystemByPackAllowTypedDict(TypedDict): - procname: str - r"""Specify the name of a process or family of processes.""" - config: str - r"""Choose a config to apply to processes that match the process name and/or argument.""" - arg: NotRequired[str] - r"""Specify a string to substring-match against process command-line.""" - - -class CreateInputSystemByPackAllow(BaseModel): - procname: str - r"""Specify the name of a process or family of processes.""" - - config: str - r"""Choose a config to apply to processes that match the process name and/or argument.""" - - arg: Optional[str] = None - r"""Specify a string to substring-match against process command-line.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["arg"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputAppscopeFilterTypedDict(TypedDict): - allow: NotRequired[List[CreateInputSystemByPackAllowTypedDict]] - r"""Specify processes that AppScope should be loaded into, and the config to use.""" - transport_url: NotRequired[str] - r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" +class CreateInputSystemByPackInputCloudflareHecType(str, Enum): + r"""Source type identifier.""" + CLOUDFLARE_HEC = "cloudflare_hec" -class CreateInputSystemByPackInputAppscopeFilter(BaseModel): - allow: Optional[List[CreateInputSystemByPackAllow]] = None - r"""Specify processes that AppScope should be loaded into, and the config to use.""" - transport_url: Annotated[Optional[str], pydantic.Field(alias="transportURL")] = None - r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" +class CreateInputSystemByPackTLSSettingsServerSideTypedDict(TypedDict): + r"""TLS settings (server side)""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["allow", "transportURL"]) - serialized = handler(self) - m = {} + disabled: NotRequired[bool] + r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" + request_cert: NotRequired[bool] + r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" + ca_path: NotRequired[str] + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" + common_name_regex: NotRequired[str] + r"""Regex matching allowable common names in peer certificates' subject attribute""" + certificate_name: NotRequired[str] + r"""The name of the predefined certificate""" + priv_key_path: NotRequired[str] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + cert_path: NotRequired[str] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" + min_version: NotRequired[MinimumTLSVersionOptionsTLS] + r"""Minimum TLS version""" + max_version: NotRequired[MaximumTLSVersionOptionsTLS] + r"""Maximum TLS version""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateInputSystemByPackTLSSettingsServerSide(BaseModel): + r"""TLS settings (server side)""" - return m + disabled: Optional[bool] = None + r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" + request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None + r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" -class CreateInputSystemByPackInputAppscopePersistenceTypedDict(TypedDict): - r"""Persistence""" + ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - enable: NotRequired[bool] - r"""Spool events and metrics on disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" + common_name_regex: Annotated[ + Optional[str], pydantic.Field(alias="commonNameRegex") + ] = None + r"""Regex matching allowable common names in peer certificates' subject attribute""" -class CreateInputSystemByPackInputAppscopePersistence(BaseModel): - r"""Persistence""" + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The name of the predefined certificate""" - enable: Optional[bool] = None - r"""Spool events and metrics on disk for Cribl Edge and Search""" + priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + min_version: Annotated[ + Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") + ] = None + r"""Minimum TLS version""" - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" + max_version: Annotated[ + Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") + ] = None + r"""Maximum TLS version""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" + @field_serializer("min_version") + def serialize_min_version(self, value): + if isinstance(value, str): + try: + return models.MinimumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("max_version") + def serialize_max_version(self, value): if isinstance(value, str): try: - return models.DataCompressionFormatOptionsPersistence(value) + return models.MaximumTLSVersionOptionsTLS(value) except ValueError: return value return value @@ -7310,12 +6939,17 @@ def serialize_compress(self, value): def serialize_model(self, handler): optional_fields = set( [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", + "disabled", + "requestCert", + "caPath", + "rejectUnauthorized", + "commonNameRegex", + "certificateName", + "privKeyPath", + "passphrase", + "certPath", + "minVersion", + "maxVersion", ] ) serialized = handler(self) @@ -7332,23 +6966,17 @@ def serialize_model(self, handler): return m -CreateInputSystemByPackUNIXSocketPermissionsTypedDict = TypeAliasType( - "CreateInputSystemByPackUNIXSocketPermissionsTypedDict", Union[str, float] -) -r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - -CreateInputSystemByPackUNIXSocketPermissions = TypeAliasType( - "CreateInputSystemByPackUNIXSocketPermissions", Union[str, float] -) -r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - -class CreateInputSystemByPackInputAppscopeTypedDict(TypedDict): +class CreateInputSystemByPackInputCloudflareHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputAppscopeType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputCloudflareHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -7364,49 +6992,46 @@ class CreateInputSystemByPackInputAppscopeTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[CreateInputSystemByPackTLSSettingsServerSideTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_unix_path: NotRequired[bool] - r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" - filter_: NotRequired[CreateInputSystemByPackInputAppscopeFilterTypedDict] - persistence: NotRequired[CreateInputSystemByPackInputAppscopePersistenceTypedDict] - r"""Persistence""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: NotRequired[float] - r"""Port to listen on""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - unix_socket_path: NotRequired[str] - r"""Path to the UNIX domain socket to listen on.""" - unix_socket_perms: NotRequired[ - CreateInputSystemByPackUNIXSocketPermissionsTypedDict - ] - r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -7415,14 +7040,31 @@ class CreateInputSystemByPackInputAppscopeTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputAppscope(BaseModel): +class CreateInputSystemByPackInputCloudflareHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputAppscopeType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputCloudflareHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -7449,38 +7091,87 @@ class CreateInputSystemByPackInputAppscope(BaseModel): pq: Optional[PqType] = None - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + tls: Optional[CreateInputSystemByPackTLSSettingsServerSide] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -7492,54 +7183,9 @@ class CreateInputSystemByPackInputAppscope(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_unix_path: Annotated[ - Optional[bool], pydantic.Field(alias="enableUnixPath") - ] = None - r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" - - filter_: Annotated[ - Optional[CreateInputSystemByPackInputAppscopeFilter], - pydantic.Field(alias="filter"), - ] = None - - persistence: Optional[CreateInputSystemByPackInputAppscopePersistence] = None - r"""Persistence""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - description: Optional[str] = None r"""Optional description for this configuration.""" - host: Optional[str] = None - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: Optional[float] = None - r"""Port to listen on""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - unix_socket_path: Annotated[ - Optional[str], pydantic.Field(alias="unixSocketPath") - ] = None - r"""Path to the UNIX domain socket to listen on.""" - - unix_socket_perms: Annotated[ - Optional[CreateInputSystemByPackUNIXSocketPermissions], - pydantic.Field(alias="unixSocketPerms"), - ] = None - r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -7560,14 +7206,25 @@ class CreateInputSystemByPackInputAppscope(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -7581,31 +7238,34 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "breakerRulesets", "staleChannelFlushMs", - "enableUnixPath", - "filter", - "persistence", - "authType", "description", - "host", - "port", - "tls", - "unixSocketPath", - "unixSocketPerms", - "authToken", - "textSecret", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -7622,21 +7282,102 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputTCPType(str, Enum): - r"""Connector type identifier.""" +class CreateInputSystemByPackInputZscalerHecType(str, Enum): + r"""Source type identifier.""" - TCP = "tcp" + ZSCALER_HEC = "zscaler_hec" -class CreateInputSystemByPackInputTCPTypedDict(TypedDict): +class CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + enabled: NotRequired[bool] + r"""Enable token""" + description: NotRequired[str] + r"""Description""" + allowed_indexes_at_token: NotRequired[List[str]] + r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class CreateInputSystemByPackInputZscalerHecAuthToken(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + enabled: Optional[bool] = None + r"""Enable token""" + + description: Optional[str] = None + r"""Description""" + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "tokenSecret", + "enabled", + "description", + "allowedIndexesAtToken", + "metadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputZscalerHecTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputTCPType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputZscalerHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -7652,38 +7393,46 @@ class CreateInputSystemByPackInputTCPTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[ + List[CreateInputSystemByPackInputZscalerHecAuthTokenTypedDict] + ] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_header: NotRequired[bool] - r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + hec_acks: NotRequired[bool] + r"""Whether to enable Zscaler HEC acknowledgements""" description: NotRequired[str] r"""Optional description for this configuration.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -7692,14 +7441,22 @@ class CreateInputSystemByPackInputTCPTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" -class CreateInputSystemByPackInputTCP(BaseModel): +class CreateInputSystemByPackInputZscalerHec(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputTCPType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputZscalerHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -7707,6 +7464,9 @@ class CreateInputSystemByPackInputTCP(BaseModel): port: float r"""Port to listen on""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -7732,74 +7492,93 @@ class CreateInputSystemByPackInputTCP(BaseModel): pq: Optional[PqType] = None + auth_tokens: Annotated[ + Optional[List[CreateInputSystemByPackInputZscalerHecAuthToken]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Add request headers to events, in the __headers field""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( - None - ) - r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable Zscaler HEC acknowledgements""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -7821,14 +7600,25 @@ class CreateInputSystemByPackInputTCP(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -7842,26 +7632,33 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", + "authTokens", "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", + "maxActiveReq", + "maxRequestsPerSocket", "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "enableHeader", - "preprocess", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "hecAcks", "description", - "authToken", - "authType", - "textSecret", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", ] ) serialized = handler(self) @@ -7878,26 +7675,34 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputFileType(str, Enum): +class CreateInputSystemByPackInputProofpointPodType(str, Enum): r"""Connector type identifier.""" - FILE = "file" + PROOFPOINT_POD = "proofpoint_pod" -class CreateInputSystemByPackInputFileMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Choose how to discover files to monitor""" +class CreateInputSystemByPackFeedType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Proofpoint on Demand feed to ingest.""" - # Manual - MANUAL = "manual" - # Auto - AUTO = "auto" + # Message + MESSAGE = "message" + # Mail log + MAILLOG = "maillog" + # Audit + AUDIT = "audit" -class CreateInputSystemByPackInputFileTypedDict(TypedDict): +class CreateInputSystemByPackInputProofpointPodTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputFileType + type: CreateInputSystemByPackInputProofpointPodType r"""Connector type identifier.""" + cluster_id: str + r"""Proofpoint on Demand cluster ID.""" + feed_type: CreateInputSystemByPackFeedType + r"""Proofpoint on Demand feed to ingest.""" + text_secret: str + r"""Select or create a stored text secret""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -7910,68 +7715,51 @@ class CreateInputSystemByPackInputFileTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - mode: NotRequired[CreateInputSystemByPackInputFileMode] - r"""Choose how to discover files to monitor""" - interval: NotRequired[float] - r"""Time, in seconds, between scanning for files""" - filenames: NotRequired[List[str]] - r"""The full path of discovered files are matched against this wildcard list""" - filter_archived_files: NotRequired[bool] - r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - tail_only: NotRequired[bool] - r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" - idle_timeout: NotRequired[float] - r"""Time, in seconds, before an idle file is closed""" - min_age_dur: NotRequired[str] - r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" - max_age_dur: NotRequired[str] - r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" - check_file_mod_time: NotRequired[bool] - r"""Skip files with modification times earlier than the maximum age duration""" - force_text: NotRequired[bool] - r"""Forces files containing binary data to be streamed as text""" - hash_len: NotRequired[float] - r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - disable_stale_channel_flush: NotRequired[bool] - r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - path: NotRequired[str] - r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" - depth: NotRequired[float] - r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" - suppress_missing_path_errors: NotRequired[bool] - r"""Suppress errors when search path does not exist""" - delete_files: NotRequired[bool] - r"""Delete files after they have been collected""" - salt_hash: NotRequired[bool] - r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" - optimize_leaf_directories: NotRequired[bool] - r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" - include_unidentifiable_binary: NotRequired[bool] - r"""Stream binary files as Base64-encoded chunks""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + compress: NotRequired[bool] + r"""Compress the feed connection.""" + handshake_timeout: NotRequired[float] + r"""Maximum time to wait for the connection handshake to complete.""" + keep_alive_interval_sec: NotRequired[float] + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" + max_missed_keep_alives: NotRequired[float] + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" + max_message_size: NotRequired[str] + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" + read_buffer_size: NotRequired[str] + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_cluster_id: NotRequired[str] + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" -class CreateInputSystemByPackInputFile(BaseModel): +class CreateInputSystemByPackInputProofpointPod(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputFileType + type: CreateInputSystemByPackInputProofpointPodType r"""Connector type identifier.""" + cluster_id: Annotated[str, pydantic.Field(alias="clusterId")] + r"""Proofpoint on Demand cluster ID.""" + + feed_type: Annotated[ + CreateInputSystemByPackFeedType, pydantic.Field(alias="feedType") + ] + r"""Proofpoint on Demand feed to ingest.""" + + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -7997,91 +7785,40 @@ class CreateInputSystemByPackInputFile(BaseModel): pq: Optional[PqType] = None - mode: Optional[CreateInputSystemByPackInputFileMode] = None - r"""Choose how to discover files to monitor""" - - interval: Optional[float] = None - r"""Time, in seconds, between scanning for files""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - filenames: Optional[List[str]] = None - r"""The full path of discovered files are matched against this wildcard list""" + compress: Optional[bool] = None + r"""Compress the feed connection.""" - filter_archived_files: Annotated[ - Optional[bool], pydantic.Field(alias="filterArchivedFiles") + handshake_timeout: Annotated[ + Optional[float], pydantic.Field(alias="handshakeTimeout") ] = None - r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - - tail_only: Annotated[Optional[bool], pydantic.Field(alias="tailOnly")] = None - r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" - - idle_timeout: Annotated[Optional[float], pydantic.Field(alias="idleTimeout")] = None - r"""Time, in seconds, before an idle file is closed""" + r"""Maximum time to wait for the connection handshake to complete.""" - min_age_dur: Annotated[Optional[str], pydantic.Field(alias="minAgeDur")] = None - r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" - - max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None - r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" - - check_file_mod_time: Annotated[ - Optional[bool], pydantic.Field(alias="checkFileModTime") + keep_alive_interval_sec: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveIntervalSec") ] = None - r"""Skip files with modification times earlier than the maximum age duration""" - - force_text: Annotated[Optional[bool], pydantic.Field(alias="forceText")] = None - r"""Forces files containing binary data to be streamed as text""" - - hash_len: Annotated[Optional[float], pydantic.Field(alias="hashLen")] = None - r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" - disable_stale_channel_flush: Annotated[ - Optional[bool], pydantic.Field(alias="disableStaleChannelFlush") + max_message_size: Annotated[ + Optional[str], pydantic.Field(alias="maxMessageSize") ] = None - r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + read_buffer_size: Annotated[ + Optional[str], pydantic.Field(alias="readBufferSize") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" description: Optional[str] = None r"""Optional description for this configuration.""" - path: Optional[str] = None - r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" - - depth: Optional[float] = None - r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" - - suppress_missing_path_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") - ] = None - r"""Suppress errors when search path does not exist""" - - delete_files: Annotated[Optional[bool], pydantic.Field(alias="deleteFiles")] = None - r"""Delete files after they have been collected""" - - salt_hash: Annotated[Optional[bool], pydantic.Field(alias="saltHash")] = None - r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" - - optimize_leaf_directories: Annotated[ - Optional[bool], pydantic.Field(alias="optimizeLeafDirectories") - ] = None - r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" - - include_unidentifiable_binary: Annotated[ - Optional[bool], pydantic.Field(alias="includeUnidentifiableBinary") - ] = None - r"""Stream binary files as Base64-encoded chunks""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -8092,11 +7829,16 @@ class CreateInputSystemByPackInputFile(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - @field_serializer("mode") - def serialize_mode(self, value): + template_cluster_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clusterId") + ] = None + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" + + @field_serializer("feed_type") + def serialize_feed_type(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackInputFileMode(value) + return models.CreateInputSystemByPackFeedType(value) except ValueError: return value return value @@ -8113,31 +7855,17 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "mode", - "interval", - "filenames", - "filterArchivedFiles", - "tailOnly", - "idleTimeout", - "minAgeDur", - "maxAgeDur", - "checkFileModTime", - "forceText", - "hashLen", - "metadata", - "breakerRulesets", - "disableStaleChannelFlush", - "staleChannelFlushMs", + "tls", + "compress", + "handshakeTimeout", + "keepAliveIntervalSec", + "maxMissedKeepAlives", + "maxMessageSize", + "readBufferSize", "description", - "path", - "depth", - "suppressMissingPathErrors", - "deleteFiles", - "saltHash", - "optimizeLeafDirectories", - "includeUnidentifiableBinary", "__template_environment", "__template_streamtags", + "__template_clusterId", ] ) serialized = handler(self) @@ -8154,15 +7882,66 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputSyslogSyslog2TypedDict(TypedDict): +class CreateInputSystemByPackInputServicenowTableType(str, Enum): + r"""Connector type identifier.""" + + SERVICENOW_TABLE = "servicenow_table" + + +class CreateInputSystemByPackSortDirection(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Used only when Sort by field is set.""" + + # Ascending + ASC = "asc" + # Descending + DESC = "desc" + + +class CreateInputSystemByPackInputServicenowTableAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""ServiceNow Table API authentication method""" + + # None + NONE = "none" + # Basic + BASIC_SECRET = "basicSecret" + # OAuth + OAUTH_SECRET = "oauthSecret" + + +class CreateInputSystemByPackGrantType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""ServiceNow OAuth grant type used for token requests""" + + # Password + CLIENT_CREDENTIALS = "client_credentials" + # Client credentials + PASSWORD = "password" + + +class CreateInputSystemByPackInputServicenowTableManageStateTypedDict(TypedDict): + pass + + +class CreateInputSystemByPackInputServicenowTableManageState(BaseModel): + pass + + +class CreateInputSystemByPackInputServicenowTableTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: CreateInputSystemByPackInputServicenowTableType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - tcp_port: float - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + instance: str + r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" + table_name: str + r"""ServiceNow table name to collect from.""" + cron_schedule: str + r"""Cron schedule on which to run this job""" + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8178,74 +7957,109 @@ class CreateInputSystemByPackInputSyslogSyslog2TypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - udp_port: NotRequired[float] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - timestamp_timezone: NotRequired[str] - r"""Timezone to assign to timestamps without timezone info""" - single_msg_udp_packets: NotRequired[bool] - r"""Treat UDP packet data received as full syslog message""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - keep_fields_list: NotRequired[List[str]] - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - octet_counting: NotRequired[bool] - r"""Enable if incoming messages use octet counting per RFC 6587.""" - infer_framing: NotRequired[bool] - r"""Enable if we should infer the syslog framing of the incoming messages.""" - strictly_infer_octet_counting: NotRequired[bool] - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - allow_non_standard_app_name: NotRequired[bool] - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + fields: NotRequired[List[str]] + r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" + order_by_field: NotRequired[str] + r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" + order_by_direction: NotRequired[CreateInputSystemByPackSortDirection] + r"""Used only when Sort by field is set.""" + query: NotRequired[str] + r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + page_size: NotRequired[int] + r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" + max_pages: NotRequired[int] + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + auth_type: NotRequired[ + CreateInputSystemByPackInputServicenowTableAuthenticationType + ] + r"""ServiceNow Table API authentication method""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + log_level: NotRequired[LogLevelOptions] + r"""Collector runtime log level""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + use_round_robin_dns: NotRequired[bool] + r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: NotRequired[bool] - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + oauth_grant_type: NotRequired[CreateInputSystemByPackGrantType] + r"""ServiceNow OAuth grant type used for token requests""" + username: NotRequired[str] + r"""ServiceNow username for the password grant type""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret for the ServiceNow password value""" + use_custom_o_auth_params_or_headers: NotRequired[bool] + r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + client_id: NotRequired[str] + r"""ServiceNow OAuth client ID""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth client secret value""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[ + CreateInputSystemByPackInputServicenowTableManageStateTypedDict + ] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - template_timestamp_timezone: NotRequired[str] - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + template_instance: NotRequired[str] + r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" + template_order_by_field: NotRequired[str] + r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" + template_query: NotRequired[str] + r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" -class CreateInputSystemByPackInputSyslogSyslog2(BaseModel): +class CreateInputSystemByPackInputServicenowTable(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: CreateInputSystemByPackInputServicenowTableType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + instance: str + r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - tcp_port: Annotated[float, pydantic.Field(alias="tcpPort")] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""ServiceNow table name to collect from.""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule on which to run this job""" + + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -8272,102 +8086,147 @@ class CreateInputSystemByPackInputSyslogSyslog2(BaseModel): pq: Optional[PqType] = None - udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + fields: Optional[List[str]] = None + r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + order_by_field: Annotated[Optional[str], pydantic.Field(alias="orderByField")] = ( + None + ) + r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" + + order_by_direction: Annotated[ + Optional[CreateInputSystemByPackSortDirection], + pydantic.Field(alias="orderByDirection"), ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""Used only when Sort by field is set.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + query: Optional[str] = None + r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + + page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None + r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" + + max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="timestampTimezone") + auth_type: Annotated[ + Optional[CreateInputSystemByPackInputServicenowTableAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Timezone to assign to timestamps without timezone info""" + r"""ServiceNow Table API authentication method""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" + + log_level: Annotated[ + Optional[LogLevelOptions], pydantic.Field(alias="logLevel") ] = None - r"""Treat UDP packet data received as full syslog message""" + r"""Collector runtime log level""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_fields_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="keepFieldsList") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" - octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( - None - ) - r"""Enable if incoming messages use octet counting per RFC 6587.""" + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" - infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( - None - ) - r"""Enable if we should infer the syslog framing of the incoming messages.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - strictly_infer_octet_counting: Annotated[ - Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - allow_non_standard_app_name: Annotated[ - Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Select or create a secret that references your credentials""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + oauth_grant_type: Annotated[ + Optional[CreateInputSystemByPackGrantType], + pydantic.Field(alias="oauthGrantType"), ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""ServiceNow OAuth grant type used for token requests""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + username: Optional[str] = None + r"""ServiceNow username for the password grant type""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret for the ServiceNow password value""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + use_custom_o_auth_params_or_headers: Annotated[ + Optional[bool], pydantic.Field(alias="useCustomOAuthParamsOrHeaders") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), ] = None - r"""Load balance traffic across all Worker Processes""" + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - enable_enhanced_proxy_header_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""ServiceNow OAuth client ID""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth client secret value""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputSystemByPackInputServicenowTableManageState], + pydantic.Field(alias="manageState"), ] = None - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -8379,25 +8238,68 @@ class CreateInputSystemByPackInputSyslogSyslog2(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_instance: Annotated[ + Optional[str], pydantic.Field(alias="__template_instance") + ] = None + r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") + template_order_by_field: Annotated[ + Optional[str], pydantic.Field(alias="__template_orderByField") ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") + template_query: Annotated[ + Optional[str], pydantic.Field(alias="__template_query") + ] = None + r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - template_timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="__template_timestampTimezone") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + @field_serializer("order_by_direction") + def serialize_order_by_direction(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackSortDirection(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputServicenowTableAuthenticationType( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("oauth_grant_type") + def serialize_oauth_grant_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackGrantType(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -8411,33 +8313,45 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "udpPort", - "maxBufferSize", - "ipWhitelistRegex", - "timestampTimezone", - "singleMsgUdpPackets", - "enableProxyHeader", - "keepFieldsList", - "octetCounting", - "inferFraming", - "strictlyInferOctetCounting", - "allowNonStandardAppName", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "tls", + "fields", + "orderByField", + "orderByDirection", + "query", + "pageSize", + "maxPages", + "rejectUnauthorized", + "authType", + "stateTracking", + "logLevel", + "requestTimeout", + "useRoundRobinDns", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "udpSocketRxBufSize", - "enableLoadBalancing", + "retryRules", "description", - "enableEnhancedProxyHeaderParsing", + "credentialsSecret", + "oauthGrantType", + "username", + "textSecret", + "useCustomOAuthParamsOrHeaders", + "oauthParams", + "oauthHeaders", + "clientId", + "clientTextSecret", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", "__template_environment", "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", - "__template_timestampTimezone", + "__template_instance", + "__template_orderByField", + "__template_query", + "__template_username", + "__template_clientId", ] ) serialized = handler(self) @@ -8454,15 +8368,19 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputSyslogSyslog1TypedDict(TypedDict): +class CreateInputSystemByPackInputBedrockS3Type(str, Enum): + r"""Connector type identifier.""" + + BEDROCK_S3 = "bedrock_s3" + + +class CreateInputSystemByPackInputBedrockS3TypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: CreateInputSystemByPackInputBedrockS3Type r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - udp_port: float - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8478,74 +8396,125 @@ class CreateInputSystemByPackInputSyslogSyslog1TypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tcp_port: NotRequired[float] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - timestamp_timezone: NotRequired[str] - r"""Timezone to assign to timestamps without timezone info""" - single_msg_udp_packets: NotRequired[bool] - r"""Treat UDP packet data received as full syslog message""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - keep_fields_list: NotRequired[List[str]] - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - octet_counting: NotRequired[bool] - r"""Enable if incoming messages use octet counting per RFC 6587.""" - infer_framing: NotRequired[bool] - r"""Enable if we should infer the syslog framing of the incoming messages.""" - strictly_infer_octet_counting: NotRequired[bool] - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - allow_non_standard_app_name: NotRequired[bool] - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: NotRequired[bool] - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - template_timestamp_timezone: NotRequired[str] - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputSystemByPackInputSyslogSyslog1(BaseModel): +class CreateInputSystemByPackInputBedrockS3(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSyslog + type: CreateInputSystemByPackInputBedrockS3Type r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - - udp_port: Annotated[float, pydantic.Field(alias="udpPort")] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -8572,132 +8541,281 @@ class CreateInputSystemByPackInputSyslogSyslog1(BaseModel): pq: Optional[PqType] = None - tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Reuse connections between requests, which can improve performance""" - timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="timestampTimezone") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Timezone to assign to timestamps without timezone info""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Treat UDP packet data received as full syslog message""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - keep_fields_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="keepFieldsList") + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") ] = None - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( None ) - r"""Enable if incoming messages use octet counting per RFC 6587.""" + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( - None - ) - r"""Enable if we should infer the syslog framing of the incoming messages.""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - strictly_infer_octet_counting: Annotated[ - Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") ] = None - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - allow_non_standard_app_name: Annotated[ - Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + r"""Use Assume Role credentials to access Amazon S3""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + r"""Amazon Resource Name (ARN) of the role to assume""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""External ID to use when assuming role""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Use Assume Role credentials when accessing Amazon SQS""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""Maximum file size for each Parquet chunk""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: Optional[str] = None r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") ] = None - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="__template_timestampTimezone") + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") ] = None - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -8711,33 +8829,61 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "tcpPort", - "maxBufferSize", - "ipWhitelistRegex", - "timestampTimezone", - "singleMsgUdpPackets", - "enableProxyHeader", - "keepFieldsList", - "octetCounting", - "inferFraming", - "strictlyInferOctetCounting", - "allowNonStandardAppName", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "tls", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", "metadata", - "udpSocketRxBufSize", - "enableLoadBalancing", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "encoding", "description", - "enableEnhancedProxyHeaderParsing", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", "__template_environment", "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", - "__template_timestampTimezone", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", ] ) serialized = handler(self) @@ -8754,42 +8900,13 @@ def serialize_model(self, handler): return m -CreateInputSystemByPackInputSyslogUnionTypedDict = TypeAliasType( - "CreateInputSystemByPackInputSyslogUnionTypedDict", - Union[ - CreateInputSystemByPackInputSyslogSyslog1TypedDict, - CreateInputSystemByPackInputSyslogSyslog2TypedDict, - ], -) - - -CreateInputSystemByPackInputSyslogUnion = TypeAliasType( - "CreateInputSystemByPackInputSyslogUnion", - Union[ - CreateInputSystemByPackInputSyslogSyslog1, - CreateInputSystemByPackInputSyslogSyslog2, - ], -) - - -class CreateInputSystemByPackQueueType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The queue type used (or created)""" - - # Standard - STANDARD = "standard" - # FIFO - FIFO = "fifo" - - -class CreateInputSystemByPackInputSqsTypedDict(TypedDict): +class CreateInputSystemByPackInputSecurityLakeTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSqs + type: TypeOptionsSecuritylake r"""Connector type identifier.""" queue_name: str - r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - queue_type: CreateInputSystemByPackQueueType - r"""The queue type used (or created)""" + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -8805,54 +8922,94 @@ class CreateInputSystemByPackInputSqsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" aws_account_id: NotRequired[str] r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - create_queue: NotRequired[bool] - r"""Create queue if it does not exist""" aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] r"""AWS authentication method. Choose Auto to use IAM roles.""" aws_secret_key: NotRequired[str] r"""Secret key""" region: NotRequired[str] - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" endpoint: NotRequired[str] - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" reuse_connections: NotRequired[bool] r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SQS""" + r"""Use Assume Role credentials to access Amazon S3""" assume_role_arn: NotRequired[str] r"""Amazon Resource Name (ARN) of the role to assume""" assume_role_external_id: NotRequired[str] r"""External ID to use when assuming role""" duration_seconds: NotRequired[float] r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] poll_timeout: NotRequired[float] r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] r"""Access key""" aws_secret: NotRequired[str] r"""Select or create a stored secret that references your access key and secret key""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_queue_name: NotRequired[str] r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: NotRequired[str] - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" template_aws_account_id: NotRequired[str] r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" template_aws_secret_key: NotRequired[str] @@ -8867,22 +9024,23 @@ class CreateInputSystemByPackInputSqsTypedDict(TypedDict): r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_aws_api_key: NotRequired[str] r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputSystemByPackInputSqs(BaseModel): +class CreateInputSystemByPackInputSecurityLake(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSqs + type: TypeOptionsSecuritylake r"""Connector type identifier.""" queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - - queue_type: Annotated[ - CreateInputSystemByPackQueueType, pydantic.Field(alias="queueType") - ] - r"""The queue type used (or created)""" + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -8909,14 +9067,14 @@ class CreateInputSystemByPackInputSqs(BaseModel): pq: Optional[PqType] = None + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( None ) r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None - r"""Create queue if it does not exist""" - aws_authentication_method: Annotated[ Optional[AuthenticationMethodOptionsS3CollectorConf], pydantic.Field(alias="awsAuthenticationMethod"), @@ -8929,10 +9087,10 @@ class CreateInputSystemByPackInputSqs(BaseModel): r"""Secret key""" region: Optional[str] = None - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" endpoint: Optional[str] = None - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" reuse_connections: Annotated[ Optional[bool], pydantic.Field(alias="reuseConnections") @@ -8944,10 +9102,46 @@ class CreateInputSystemByPackInputSqs(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: Annotated[ Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Use Assume Role credentials to access SQS""" + r"""Use Assume Role credentials to access Amazon S3""" assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None @@ -8964,20 +9158,45 @@ class CreateInputSystemByPackInputSqs(BaseModel): ] = None r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -8987,10 +9206,50 @@ class CreateInputSystemByPackInputSqs(BaseModel): aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None r"""Select or create a stored secret that references your access key and secret key""" - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( None ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -9007,11 +9266,6 @@ class CreateInputSystemByPackInputSqs(BaseModel): ] = None r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueType") - ] = None - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - template_aws_account_id: Annotated[ Optional[str], pydantic.Field(alias="__template_awsAccountId") ] = None @@ -9047,20 +9301,44 @@ class CreateInputSystemByPackInputSqs(BaseModel): ] = None r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - @field_serializer("queue_type") - def serialize_queue_type(self, value): + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackQueueType(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) except ValueError: return value return value @@ -9077,30 +9355,51 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", + "fileFilter", "awsAccountId", - "createQueue", "awsAuthenticationMethod", "awsSecretKey", "region", "endpoint", "reuseConnections", "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", "enableAssumeRole", "assumeRoleArn", "assumeRoleExternalId", "durationSeconds", - "maxMessages", - "visibilityTimeout", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", "pollTimeout", + "encoding", "description", "awsApiKey", "awsSecret", - "numReceivers", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", "__template_environment", "__template_streamtags", "__template_queueName", - "__template_queueType", "__template_awsAccountId", "__template_awsSecretKey", "__template_region", @@ -9108,6 +9407,9 @@ def serialize_model(self, handler): "__template_assumeRoleArn", "__template_assumeRoleExternalId", "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", ] ) serialized = handler(self) @@ -9124,19 +9426,13 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputModelDrivenTelemetryType(str, Enum): - r"""Connector type identifier.""" - - MODEL_DRIVEN_TELEMETRY = "model_driven_telemetry" - - -class CreateInputSystemByPackInputModelDrivenTelemetryTypedDict(TypedDict): +class CreateInputSystemByPackInputNetflowTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputModelDrivenTelemetryType + type: TypeOptionsNetflow r"""Connector type identifier.""" host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" port: float r"""Port to listen on""" disabled: NotRequired[bool] @@ -9154,14 +9450,24 @@ class CreateInputSystemByPackInputModelDrivenTelemetryTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + enable_pass_through: NotRequired[bool] + r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + template_cache_minutes: NotRequired[float] + r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" + v5_enabled: NotRequired[bool] + r"""Accept messages in Netflow V5 format.""" + v9_enabled: NotRequired[bool] + r"""Accept messages in Netflow V9 format.""" + ipfix_enabled: NotRequired[bool] + r"""Accept messages in IPFIX format.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - shutdown_timeout_ms: NotRequired[float] - r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -9174,15 +9480,15 @@ class CreateInputSystemByPackInputModelDrivenTelemetryTypedDict(TypedDict): r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateInputSystemByPackInputModelDrivenTelemetry(BaseModel): +class CreateInputSystemByPackInputNetflow(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputModelDrivenTelemetryType + type: TypeOptionsNetflow r"""Connector type identifier.""" host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" port: float r"""Port to listen on""" @@ -9210,23 +9516,46 @@ class CreateInputSystemByPackInputModelDrivenTelemetry(BaseModel): connections: Optional[List[ConnectionConfInputCollection]] = None r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: Optional[PqType] = None + pq: Optional[PqType] = None + + enable_pass_through: Annotated[ + Optional[bool], pydantic.Field(alias="enablePassThrough") + ] = None + r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + template_cache_minutes: Annotated[ + Optional[float], pydantic.Field(alias="templateCacheMinutes") + ] = None + r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + v5_enabled: Annotated[Optional[bool], pydantic.Field(alias="v5Enabled")] = None + r"""Accept messages in Netflow V5 format.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + v9_enabled: Annotated[Optional[bool], pydantic.Field(alias="v9Enabled")] = None + r"""Accept messages in Netflow V9 format.""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + ipfix_enabled: Annotated[Optional[bool], pydantic.Field(alias="ipfixEnabled")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Accept messages in IPFIX format.""" - shutdown_timeout_ms: Annotated[ - Optional[float], pydantic.Field(alias="shutdownTimeoutMs") - ] = None - r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -9263,10 +9592,15 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "tls", + "enablePassThrough", + "ipAllowlistRegex", + "ipDenylistRegex", + "udpSocketRxBufSize", + "templateCacheMinutes", + "v5Enabled", + "v9Enabled", + "ipfixEnabled", "metadata", - "maxActiveCxn", - "shutdownTimeoutMs", "description", "__template_environment", "__template_streamtags", @@ -9288,141 +9622,113 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputOpenTelemetryType(str, Enum): +class CreateInputSystemByPackInputWizWebhookType(str, Enum): r"""Source type identifier.""" - OPEN_TELEMETRY = "open_telemetry" + WIZ_WEBHOOK = "wiz_webhook" -class CreateInputSystemByPackProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" +class CreateInputSystemByPackInputWizWebhookAuthTokensExt2TypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: str + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" - # gRPC - GRPC = "grpc" - # HTTP - HTTP = "http" +class CreateInputSystemByPackInputWizWebhookAuthTokensExt2(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" -class CreateInputSystemByPackOTLPVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" - # 0.10.0 - ZERO_DOT_10_DOT_0 = "0.10.0" - # 1.3.1 - ONE_DOT_3_DOT_1 = "1.3.1" + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + description: Optional[str] = None + r"""Description""" -class CreateInputSystemByPackInputOpenTelemetryAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""OpenTelemetry authentication type""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["token", "description", "metadata"]) + serialized = handler(self) + m = {} -class CreateInputSystemByPackAuthMethodsExtAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - # Token - TOKEN = "token" - # Token (secret) - TOKEN_SECRET = "tokenSecret" - # Basic - BASIC = "basic" - # Basic (credentials secret) - BASIC_SECRET = "basicSecret" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + return m -class CreateInputSystemByPackAuthMethodsExtTypedDict(TypedDict): - auth_type: CreateInputSystemByPackAuthMethodsExtAuthenticationType - r"""Authentication type""" - token: NotRequired[str] - r"""Bearer token for Authorization header""" + +class CreateInputSystemByPackInputWizWebhookAuthTokensExt1TypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" description: NotRequired[str] r"""Description""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this auth method""" - enabled: NotRequired[bool] - r"""Enable""" - token_secret: NotRequired[str] - r"""Select or create a stored text secret""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" + r"""Fields to add to events referencing this token""" -class CreateInputSystemByPackAuthMethodsExt(BaseModel): +class CreateInputSystemByPackInputWizWebhookAuthTokensExt1(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: Annotated[ - CreateInputSystemByPackAuthMethodsExtAuthenticationType, + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), - ] - r"""Authentication type""" + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - token: Optional[str] = None - r"""Bearer token for Authorization header""" + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" description: Optional[str] = None r"""Description""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this auth method""" - - enabled: Optional[bool] = None - r"""Enable""" - - token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None - r"""Select or create a stored text secret""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" + r"""Fields to add to events referencing this token""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackAuthMethodsExtAuthenticationType( - value - ) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "token", - "description", - "metadata", - "enabled", - "tokenSecret", - "username", - "password", - "credentialsSecret", - ] - ) + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) serialized = handler(self) m = {} @@ -9437,10 +9743,28 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputOpenTelemetryTypedDict(TypedDict): +CreateInputSystemByPackInputWizWebhookAuthTokensExtUnionTypedDict = TypeAliasType( + "CreateInputSystemByPackInputWizWebhookAuthTokensExtUnionTypedDict", + Union[ + CreateInputSystemByPackInputWizWebhookAuthTokensExt1TypedDict, + CreateInputSystemByPackInputWizWebhookAuthTokensExt2TypedDict, + ], +) + + +CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion = TypeAliasType( + "CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion", + Union[ + CreateInputSystemByPackInputWizWebhookAuthTokensExt1, + CreateInputSystemByPackInputWizWebhookAuthTokensExt2, + ], +) + + +class CreateInputSystemByPackInputWizWebhookTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOpenTelemetryType + type: CreateInputSystemByPackInputWizWebhookType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -9461,54 +9785,48 @@ class CreateInputSystemByPackInputOpenTelemetryTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" max_requests_per_socket: NotRequired[int] r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" socket_timeout: NotRequired[float] r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" enable_health_check: NotRequired[bool] - r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - protocol: NotRequired[CreateInputSystemByPackProtocol] - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - extract_spans: NotRequired[bool] - r"""Enable to extract each incoming span to a separate event""" - extract_metrics: NotRequired[bool] - r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - otlp_version: NotRequired[CreateInputSystemByPackOTLPVersion] - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - auth_type: NotRequired[CreateInputSystemByPackInputOpenTelemetryAuthenticationType] - r"""OpenTelemetry authentication type""" - auth_methods_ext: NotRequired[List[CreateInputSystemByPackAuthMethodsExtTypedDict]] - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + allowed_paths: NotRequired[List[str]] + r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" + allowed_methods: NotRequired[List[str]] + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + auth_tokens_ext: NotRequired[ + List[CreateInputSystemByPackInputWizWebhookAuthTokensExtUnionTypedDict] + ] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - extract_logs: NotRequired[bool] - r"""Enable to extract each incoming log record to a separate event""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -9517,17 +9835,17 @@ class CreateInputSystemByPackInputOpenTelemetryTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_protocol: NotRequired[str] - r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" - template_otlp_version: NotRequired[str] - r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_allowed_paths: NotRequired[str] + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" -class CreateInputSystemByPackInputOpenTelemetry(BaseModel): +class CreateInputSystemByPackInputWizWebhook(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputOpenTelemetryType + type: CreateInputSystemByPackInputWizWebhookType r"""Source type identifier.""" host: str @@ -9561,6 +9879,11 @@ class CreateInputSystemByPackInputOpenTelemetry(BaseModel): pq: Optional[PqType] = None + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" @@ -9574,6 +9897,21 @@ class CreateInputSystemByPackInputOpenTelemetry(BaseModel): ] = None r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None @@ -9587,84 +9925,54 @@ class CreateInputSystemByPackInputOpenTelemetry(BaseModel): keep_alive_timeout: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" enable_health_check: Annotated[ Optional[bool], pydantic.Field(alias="enableHealthCheck") ] = None - r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" ip_allowlist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - protocol: Optional[CreateInputSystemByPackProtocol] = None - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - - extract_spans: Annotated[Optional[bool], pydantic.Field(alias="extractSpans")] = ( - None - ) - r"""Enable to extract each incoming span to a separate event""" - - extract_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="extractMetrics") - ] = None - r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - - otlp_version: Annotated[ - Optional[CreateInputSystemByPackOTLPVersion], - pydantic.Field(alias="otlpVersion"), - ] = None - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - - auth_type: Annotated[ - Optional[CreateInputSystemByPackInputOpenTelemetryAuthenticationType], - pydantic.Field(alias="authType"), + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""OpenTelemetry authentication type""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - auth_methods_ext: Annotated[ - Optional[List[CreateInputSystemByPackAuthMethodsExt]], - pydantic.Field(alias="authMethodsExt"), + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" + allowed_paths: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedPaths") + ] = None + r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + allowed_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedMethods") ] = None - r"""Select or create a secret that references your credentials""" + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + auth_tokens_ext: Annotated[ + Optional[List[CreateInputSystemByPackInputWizWebhookAuthTokensExtUnion]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - extract_logs: Annotated[Optional[bool], pydantic.Field(alias="extractLogs")] = None - r"""Enable to extract each incoming log record to a separate event""" + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -9686,46 +9994,15 @@ class CreateInputSystemByPackInputOpenTelemetry(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_protocol: Annotated[ - Optional[str], pydantic.Field(alias="__template_protocol") + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") ] = None - r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_otlp_version: Annotated[ - Optional[str], pydantic.Field(alias="__template_otlpVersion") + template_allowed_paths: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedPaths") ] = None - r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackProtocol(value) - except ValueError: - return value - return value - - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackOTLPVersion(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return ( - models.CreateInputSystemByPackInputOpenTelemetryAuthenticationType( - value - ) - ) - except ValueError: - return value - return value + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -9739,188 +10016,246 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", + "authTokens", "tls", "maxActiveReq", "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", "requestTimeout", "socketTimeout", "keepAliveTimeout", "enableHealthCheck", "ipAllowlistRegex", "ipDenylistRegex", - "protocol", - "extractSpans", - "extractMetrics", - "otlpVersion", - "authType", - "authMethodsExt", + "breakerRulesets", + "staleChannelFlushMs", "metadata", - "maxActiveCxn", + "allowedPaths", + "allowedMethods", + "authTokensExt", "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "extractLogs", "__template_environment", "__template_streamtags", "__template_host", "__template_port", - "__template_protocol", - "__template_otlpVersion", + "__template_authTokens", + "__template_allowedPaths", ] ) serialized = handler(self) m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputOpenaiType(str, Enum): + r"""Connector type identifier.""" + + OPENAI = "openai" + + +class CreateInputSystemByPackInputOpenaiManageStateTypedDict(TypedDict): + pass + + +class CreateInputSystemByPackInputOpenaiManageState(BaseModel): + pass + + +class CreateInputSystemByPackPaginationType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Pagination type""" + + # None + NONE = "none" + # Response Body Attribute + RESPONSE_BODY = "response_body" + # Response Header Attribute + RESPONSE_HEADER = "response_header" + # RFC 5988 Link Header + RESPONSE_HEADER_LINK = "response_header_link" + + +class CreateInputSystemByPackInputOpenaiLogLevel( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Collector runtime log level.""" + + ERROR = "error" + WARN = "warn" + INFO = "info" + DEBUG = "debug" + SILLY = "silly" + + +class CreateInputSystemByPackInputOpenaiContentConfigTypedDict(TypedDict): + request_params: List[ + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict + ] + r"""Query-string parameters to send with this endpoint""" + pagination_type: CreateInputSystemByPackPaginationType + r"""Pagination type""" + cron_schedule: str + r"""A cron schedule on which to run this job""" + earliest: str + r"""Relative to the current time""" + latest: str + r"""Relative to the current time""" + disabled: NotRequired[bool] + r"""Enabled""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions.""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputSystemByPackInputOpenaiManageStateTypedDict] + pagination_attribute: NotRequired[List[str]] + r"""Pagination attributes""" + pagination_last_page_expr: NotRequired[str] + r"""Last page expression""" + max_pages: NotRequired[float] + r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" + pagination_next_relation_attribute: NotRequired[str] + r"""Used only for RFC 5988 link-header pagination""" + pagination_cur_relation_attribute: NotRequired[str] + r"""Optional relation that represents the current page""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + log_level: NotRequired[CreateInputSystemByPackInputOpenaiLogLevel] + r"""Collector runtime log level.""" + endpoint_metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields automatically added to events from this Content Type""" + + +class CreateInputSystemByPackInputOpenaiContentConfig(BaseModel): + request_params: Annotated[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret], + pydantic.Field(alias="requestParams"), + ] + r"""Query-string parameters to send with this endpoint""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + pagination_type: Annotated[ + CreateInputSystemByPackPaginationType, pydantic.Field(alias="paginationType") + ] + r"""Pagination type""" - return m + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""A cron schedule on which to run this job""" + earliest: str + r"""Relative to the current time""" -class CreateInputSystemByPackAuthenticationProtocol( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication protocol""" + latest: str + r"""Relative to the current time""" - # None - NONE = "none" - # MD5 - MD5 = "md5" - # SHA1 - SHA = "sha" - # SHA224 - SHA224 = "sha224" - # SHA256 - SHA256 = "sha256" - # SHA384 - SHA384 = "sha384" - # SHA512 - SHA512 = "sha512" + disabled: Optional[bool] = None + r"""Enabled""" + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions.""" -class CreateInputSystemByPackPrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Privacy protocol""" + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - # None - NONE = "none" - # DES - DES = "des" - # AES128 - AES = "aes" - # AES256b (Blumenthal) - AES256B = "aes256b" - # AES256r (Reeder) - AES256R = "aes256r" + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: Annotated[ + Optional[CreateInputSystemByPackInputOpenaiManageState], + pydantic.Field(alias="manageState"), + ] = None -class CreateInputSystemByPackV3UserTypedDict(TypedDict): - name: str - r"""V3 name""" - auth_protocol: NotRequired[CreateInputSystemByPackAuthenticationProtocol] - r"""Authentication protocol""" - auth_key: NotRequired[str] - r"""V3 authentication key""" - priv_protocol: NotRequired[CreateInputSystemByPackPrivacyProtocol] - r"""Privacy protocol""" - priv_key: NotRequired[str] - r"""V3 privacy key""" + pagination_attribute: Annotated[ + Optional[List[str]], pydantic.Field(alias="paginationAttribute") + ] = None + r"""Pagination attributes""" + pagination_last_page_expr: Annotated[ + Optional[str], pydantic.Field(alias="paginationLastPageExpr") + ] = None + r"""Last page expression""" -class CreateInputSystemByPackV3User(BaseModel): - name: str - r"""V3 name""" + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" - auth_protocol: Annotated[ - Optional[CreateInputSystemByPackAuthenticationProtocol], - pydantic.Field(alias="authProtocol"), + pagination_next_relation_attribute: Annotated[ + Optional[str], pydantic.Field(alias="paginationNextRelationAttribute") ] = None - r"""Authentication protocol""" + r"""Used only for RFC 5988 link-header pagination""" - auth_key: Annotated[Optional[str], pydantic.Field(alias="authKey")] = None - r"""V3 authentication key""" + pagination_cur_relation_attribute: Annotated[ + Optional[str], pydantic.Field(alias="paginationCurRelationAttribute") + ] = None + r"""Optional relation that represents the current page""" - priv_protocol: Annotated[ - Optional[CreateInputSystemByPackPrivacyProtocol], - pydantic.Field(alias="privProtocol"), + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + log_level: Annotated[ + Optional[CreateInputSystemByPackInputOpenaiLogLevel], + pydantic.Field(alias="logLevel"), ] = None - r"""Privacy protocol""" + r"""Collector runtime log level.""" - priv_key: Annotated[Optional[str], pydantic.Field(alias="privKey")] = None - r"""V3 privacy key""" + endpoint_metadata: Annotated[ + Optional[List[MetadataConfInputCollection]], + pydantic.Field(alias="endpointMetadata"), + ] = None + r"""Fields automatically added to events from this Content Type""" - @field_serializer("auth_protocol") - def serialize_auth_protocol(self, value): + @field_serializer("pagination_type") + def serialize_pagination_type(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackAuthenticationProtocol(value) + return models.CreateInputSystemByPackPaginationType(value) except ValueError: return value return value - @field_serializer("priv_protocol") - def serialize_priv_protocol(self, value): + @field_serializer("log_level") + def serialize_log_level(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackPrivacyProtocol(value) + return models.CreateInputSystemByPackInputOpenaiLogLevel(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["authProtocol", "authKey", "privProtocol", "privKey"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackSNMPv3AuthenticationTypedDict(TypedDict): - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" - - v3_auth_enabled: bool - r"""Enabled""" - allow_unmatched_trap: NotRequired[bool] - r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" - v3_users: NotRequired[List[CreateInputSystemByPackV3UserTypedDict]] - r"""User credentials for receiving v3 traps""" - - -class CreateInputSystemByPackSNMPv3Authentication(BaseModel): - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" - - v3_auth_enabled: Annotated[bool, pydantic.Field(alias="v3AuthEnabled")] - r"""Enabled""" - - allow_unmatched_trap: Annotated[ - Optional[bool], pydantic.Field(alias="allowUnmatchedTrap") - ] = None - r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" - - v3_users: Annotated[ - Optional[List[CreateInputSystemByPackV3User]], pydantic.Field(alias="v3Users") - ] = None - r"""User credentials for receiving v3 traps""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["allowUnmatchedTrap", "v3Users"]) + optional_fields = set( + [ + "disabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "paginationAttribute", + "paginationLastPageExpr", + "maxPages", + "paginationNextRelationAttribute", + "paginationCurRelationAttribute", + "jobTimeout", + "logLevel", + "endpointMetadata", + ] + ) serialized = handler(self) m = {} @@ -9935,15 +10270,15 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputSnmpTypedDict(TypedDict): +class CreateInputSystemByPackInputOpenaiTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: TypeOptionsSnmp + type: CreateInputSystemByPackInputOpenaiType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - port: float - r"""UDP port to receive SNMP traps on. Defaults to 162.""" + content_config: List[CreateInputSystemByPackInputOpenaiContentConfigTypedDict] + r"""Content Types""" + text_secret: str + r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -9959,44 +10294,52 @@ class CreateInputSystemByPackInputSnmpTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - snmp_v3_auth: NotRequired[CreateInputSystemByPackSNMPv3AuthenticationTypedDict] - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" + openai_organization: NotRequired[str] + r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" + openai_project: NotRequired[str] + r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + api_key: NotRequired[str] + r"""API key""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - varbinds_with_types: NotRequired[bool] - r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" - best_effort_parsing: NotRequired[bool] - r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_openai_organization: NotRequired[str] + r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" + template_openai_project: NotRequired[str] + r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" -class CreateInputSystemByPackInputSnmp(BaseModel): +class CreateInputSystemByPackInputOpenai(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsSnmp + type: CreateInputSystemByPackInputOpenaiType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + content_config: Annotated[ + List[CreateInputSystemByPackInputOpenaiContentConfig], + pydantic.Field(alias="contentConfig"), + ] + r"""Content Types""" - port: float - r"""UDP port to receive SNMP traps on. Defaults to 162.""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -10023,39 +10366,48 @@ class CreateInputSystemByPackInputSnmp(BaseModel): pq: Optional[PqType] = None - snmp_v3_auth: Annotated[ - Optional[CreateInputSystemByPackSNMPv3Authentication], - pydantic.Field(alias="snmpV3Auth"), + openai_organization: Annotated[ + Optional[str], pydantic.Field(alias="openaiOrganization") ] = None - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + openai_project: Annotated[Optional[str], pydantic.Field(alias="openaiProject")] = ( + None + ) + r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Maximum number of events to buffer when downstream is blocking.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" + + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - varbinds_with_types: Annotated[ - Optional[bool], pydantic.Field(alias="varbindsWithTypes") - ] = None - r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - best_effort_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="bestEffortParsing") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -10070,15 +10422,15 @@ class CreateInputSystemByPackInputSnmp(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_openai_organization: Annotated[ + Optional[str], pydantic.Field(alias="__template_openaiOrganization") + ] = None + r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_openai_project: Annotated[ + Optional[str], pydantic.Field(alias="__template_openaiProject") + ] = None + r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -10092,18 +10444,21 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "snmpV3Auth", - "maxBufferSize", - "ipWhitelistRegex", + "openaiOrganization", + "openaiProject", + "requestTimeout", + "apiKey", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "udpSocketRxBufSize", - "varbindsWithTypes", - "bestEffortParsing", + "retryRules", "description", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", + "__template_openaiOrganization", + "__template_openaiProject", ] ) serialized = handler(self) @@ -10120,19 +10475,157 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputS3InventoryType(str, Enum): +class CreateInputSystemByPackInputWizType(str, Enum): r"""Connector type identifier.""" - S3_INVENTORY = "s3_inventory" + WIZ = "wiz" + + +class CreateInputSystemByPackInputWizManageStateTypedDict(TypedDict): + pass + + +class CreateInputSystemByPackInputWizManageState(BaseModel): + pass + + +class CreateInputSystemByPackInputWizContentConfigTypedDict(TypedDict): + content_type: str + r"""The name of the Wiz query""" + content_query: str + r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" + cron_schedule: str + r"""A cron schedule on which to run this job""" + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + content_description: NotRequired[str] + r"""Description""" + enabled: NotRequired[bool] + r"""Enable content""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[CreateInputSystemByPackInputWizManageStateTypedDict] + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" + log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] + r"""Collector runtime log level""" + max_pages: NotRequired[float] + r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" + + +class CreateInputSystemByPackInputWizContentConfig(BaseModel): + content_type: Annotated[str, pydantic.Field(alias="contentType")] + r"""The name of the Wiz query""" + + content_query: Annotated[str, pydantic.Field(alias="contentQuery")] + r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""A cron schedule on which to run this job""" + + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + + content_description: Annotated[ + Optional[str], pydantic.Field(alias="contentDescription") + ] = None + r"""Description""" + + enabled: Optional[bool] = None + r"""Enable content""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[CreateInputSystemByPackInputWizManageState], + pydantic.Field(alias="manageState"), + ] = None + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItemsDebugError], + pydantic.Field(alias="logLevel"), + ] = None + r"""Collector runtime log level""" + + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItemsDebugError(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "contentDescription", + "enabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "jobTimeout", + "logLevel", + "maxPages", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m -class CreateInputSystemByPackInputS3InventoryTypedDict(TypedDict): +class CreateInputSystemByPackInputWizTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputS3InventoryType + type: CreateInputSystemByPackInputWizType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + endpoint: str + r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" + auth_url: str + r"""The authentication URL to generate an OAuth token""" + client_id: str + r"""The client ID of the Wiz application""" + content_config: List[CreateInputSystemByPackInputWizContentConfigTypedDict] + r"""Content types""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -10148,129 +10641,66 @@ class CreateInputSystemByPackInputS3InventoryTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + auth_audience_override: NotRequired[str] + r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - checksum_suffix: NotRequired[str] - r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ - max_manifest_size_kb: NotRequired[int] - r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" - validate_inventory_files: NotRequired[bool] - r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + client_secret: NotRequired[str] + r"""The client secret of the Wiz application""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_endpoint: NotRequired[str] r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + template_auth_url: NotRequired[str] + r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" -class CreateInputSystemByPackInputS3Inventory(BaseModel): +class CreateInputSystemByPackInputWiz(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputS3InventoryType + type: CreateInputSystemByPackInputWizType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + endpoint: str + r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" + + auth_url: Annotated[str, pydantic.Field(alias="authUrl")] + r"""The authentication URL to generate an OAuth token""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""The client ID of the Wiz application""" + + content_config: Annotated[ + List[CreateInputSystemByPackInputWizContentConfig], + pydantic.Field(alias="contentConfig"), + ] + r"""Content types""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -10297,201 +10727,65 @@ class CreateInputSystemByPackInputS3Inventory(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + auth_audience_override: Annotated[ + Optional[str], pydantic.Field(alias="authAudienceOverride") ] = None - r"""Use Assume Role credentials to access Amazon S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""External ID to use when assuming role""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Use the same settings for S3 and SQS""" - - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" - - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - - checkpointing: Optional[CheckpointingType] = None - - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - - checksum_suffix: Annotated[ - Optional[str], pydantic.Field(alias="checksumSuffix") - ] = None - r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ - - max_manifest_size_kb: Annotated[ - Optional[int], pydantic.Field(alias="maxManifestSizeKB") - ] = None - r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" - - validate_inventory_files: Annotated[ - Optional[bool], pydantic.Field(alias="validateInventoryFiles") - ] = None - r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" - - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" + r"""Fields to add to events from this input""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""SQS secret key""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + r"""Enter client secret directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""The client secret of the Wiz application""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -10503,84 +10797,26 @@ class CreateInputSystemByPackInputS3Inventory(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: Annotated[ Optional[str], pydantic.Field(alias="__template_endpoint") ] = None r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + template_auth_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_authUrl") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.TagAfterProcessingOptions(value) + return models.AuthenticationMethodOptionsManualSecret(value) except ValueError: return value return value @@ -10597,63 +10833,25 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", + "authAudienceOverride", + "requestTimeout", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", "breakerRulesets", "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "checksumSuffix", - "maxManifestSizeKB", - "validateInventoryFiles", + "retryRules", + "authType", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", + "clientSecret", + "textSecret", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "__template_authUrl", + "__template_clientId", ] ) serialized = handler(self) @@ -10670,148 +10868,101 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputS3TypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsS3 +class CreateInputSystemByPackInputJournalFilesType(str, Enum): r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + JOURNAL_FILES = "journal_files" + + +class CreateInputSystemByPackInputJournalFilesRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class CreateInputSystemByPackInputJournalFilesRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputJournalFilesTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputJournalFilesType + r"""Connector type identifier.""" + path: str + r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + journals: List[str] + r"""The full path of discovered journals are matched against this wildcard list.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between scanning for journals.""" + rules: NotRequired[List[CreateInputSystemByPackInputJournalFilesRuleTypedDict]] + r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" + current_boot: NotRequired[bool] + r"""Skip log messages that are not part of the current boot session""" + max_age_dur: NotRequired[str] + r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" + suppress_missing_path_errors: NotRequired[bool] + r"""Suppress errors when search path does not exist""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - tag_after_processing: NotRequired[bool] - r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" -class CreateInputSystemByPackInputS3(BaseModel): +class CreateInputSystemByPackInputJournalFiles(BaseModel): id: str r"""Unique ID for this input""" - type: TypeOptionsS3 + type: CreateInputSystemByPackInputJournalFilesType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + path: str + r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + + journals: List[str] + r"""The full path of discovered journals are matched against this wildcard list.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -10838,341 +10989,252 @@ class CreateInputSystemByPackInputS3(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + interval: Optional[float] = None + r"""Time, in seconds, between scanning for journals.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + rules: Optional[List[CreateInputSystemByPackInputJournalFilesRule]] = None + r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + current_boot: Annotated[Optional[bool], pydantic.Field(alias="currentBoot")] = None + r"""Skip log messages that are not part of the current boot session""" - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None + r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + suppress_missing_path_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") ] = None - r"""Use Assume Role credentials to access Amazon S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""Suppress errors when search path does not exist""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Use the same credential settings for S3 and SQS""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Use the same settings for S3 and SQS""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "interval", + "rules", + "currentBoot", + "maxAgeDur", + "suppressMissingPathErrors", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + return m - checkpointing: Optional[CheckpointingType] = None - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" +class CreateInputSystemByPackInputRawUDPType(str, Enum): + r"""Connector type identifier.""" - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + RAW_UDP = "raw_udp" - tag_after_processing: Annotated[ - Optional[bool], pydantic.Field(alias="tagAfterProcessing") - ] = None - r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" - description: Optional[str] = None +class CreateInputSystemByPackInputRawUDPTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputRawUDPType + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""Port to listen on""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + single_msg_udp_packets: NotRequired[bool] + r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" + ingest_raw_bytes: NotRequired[bool] + r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" +class CreateInputSystemByPackInputRawUDP(BaseModel): + id: str + r"""Unique ID for this input""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" + type: CreateInputSystemByPackInputRawUDPType + r"""Connector type identifier.""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + port: float + r"""Port to listen on""" - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( None ) - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" + r"""Select whether to send data to Routes, or directly to Destinations.""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + pq: Optional[PqType] = None - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + r"""Maximum number of events to buffer when downstream is blocking.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Regex matching IP addresses that are allowed to send data""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + ingest_raw_bytes: Annotated[ + Optional[bool], pydantic.Field(alias="ingestRawBytes") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "maxBufferSize", + "ipWhitelistRegex", + "singleMsgUdpPackets", + "ingestRawBytes", + "udpSocketRxBufSize", "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", - "tagAfterProcessing", + "autoParse", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "processedTagKey", - "processedTagValue", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -11189,19 +11251,30 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputMetricsType(str, Enum): +class CreateInputSystemByPackInputAppleUnifiedLogsType(str, Enum): r"""Connector type identifier.""" - METRICS = "metrics" + APPLE_UNIFIED_LOGS = "apple_unified_logs" + + +class CreateInputSystemByPackInputAppleUnifiedLogsReadMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + + # Entire log + OLDEST = "oldest" + # From last entry + NEWEST = "newest" -class CreateInputSystemByPackInputMetricsTypedDict(TypedDict): +class CreateInputSystemByPackInputAppleUnifiedLogsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputMetricsType + type: CreateInputSystemByPackInputAppleUnifiedLogsType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + predicate: str + r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -11217,45 +11290,27 @@ class CreateInputSystemByPackInputMetricsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - udp_port: NotRequired[float] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - tcp_port: NotRequired[float] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + read_mode: NotRequired[CreateInputSystemByPackInputAppleUnifiedLogsReadMode] + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" -class CreateInputSystemByPackInputMetrics(BaseModel): +class CreateInputSystemByPackInputAppleUnifiedLogs(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputMetricsType + type: CreateInputSystemByPackInputAppleUnifiedLogsType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + predicate: str + r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -11282,38 +11337,15 @@ class CreateInputSystemByPackInputMetrics(BaseModel): pq: Optional[PqType] = None - udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - - tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") - ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to send data""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + read_mode: Annotated[ + Optional[CreateInputSystemByPackInputAppleUnifiedLogsReadMode], + pydantic.Field(alias="readMode"), ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") - ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11327,20 +11359,16 @@ class CreateInputSystemByPackInputMetrics(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") - ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") - ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + @field_serializer("read_mode") + def serialize_read_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputAppleUnifiedLogsReadMode( + value + ) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -11354,20 +11382,11 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "udpPort", - "tcpPort", - "maxBufferSize", - "ipWhitelistRegex", - "enableProxyHeader", - "tls", + "readMode", "metadata", - "udpSocketRxBufSize", "description", "__template_environment", "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", ] ) serialized = handler(self) @@ -11384,17 +11403,39 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputCriblmetricsType(str, Enum): +class CreateInputSystemByPackInputWinEventLogsType(str, Enum): r"""Connector type identifier.""" - CRIBLMETRICS = "criblmetrics" + WIN_EVENT_LOGS = "win_event_logs" + + +class CreateInputSystemByPackInputWinEventLogsReadMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Read all stored and future event logs, or only future events""" + + # Entire log + OLDEST = "oldest" + # From last entry + NEWEST = "newest" + + +class CreateInputSystemByPackEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of individual events""" + # JSON + JSON = "json" + # XML + XML = "xml" -class CreateInputSystemByPackInputCriblmetricsTypedDict(TypedDict): + +class CreateInputSystemByPackInputWinEventLogsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCriblmetricsType + type: CreateInputSystemByPackInputWinEventLogsType r"""Connector type identifier.""" + log_names: List[str] + r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -11410,27 +11451,46 @@ class CreateInputSystemByPackInputCriblmetricsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - prefix: NotRequired[str] - r"""A prefix that is applied to the metrics provided by Cribl Stream""" - full_fidelity: NotRequired[bool] - r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + suppress_missing_log_errors: NotRequired[bool] + r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" + read_mode: NotRequired[CreateInputSystemByPackInputWinEventLogsReadMode] + r"""Read all stored and future event logs, or only future events""" + event_format: NotRequired[CreateInputSystemByPackEventFormat] + r"""Format of individual events""" + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" + interval: NotRequired[float] + r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + batch_size: NotRequired[float] + r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + max_event_bytes: NotRequired[int] + r"""The maximum number of bytes in an event before it is flushed to the pipelines""" description: NotRequired[str] r"""Optional description for this configuration.""" + disable_json_rendering: NotRequired[bool] + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + include_empty_json_fields: NotRequired[bool] + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" + disable_xml_rendering: NotRequired[bool] + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class CreateInputSystemByPackInputCriblmetrics(BaseModel): +class CreateInputSystemByPackInputWinEventLogs(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCriblmetricsType + type: CreateInputSystemByPackInputWinEventLogsType r"""Connector type identifier.""" + log_names: Annotated[List[str], pydantic.Field(alias="logNames")] + r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -11456,20 +11516,60 @@ class CreateInputSystemByPackInputCriblmetrics(BaseModel): pq: Optional[PqType] = None - prefix: Optional[str] = None - r"""A prefix that is applied to the metrics provided by Cribl Stream""" + suppress_missing_log_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingLogErrors") + ] = None + r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - full_fidelity: Annotated[Optional[bool], pydantic.Field(alias="fullFidelity")] = ( - None - ) - r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + read_mode: Annotated[ + Optional[CreateInputSystemByPackInputWinEventLogsReadMode], + pydantic.Field(alias="readMode"), + ] = None + r"""Read all stored and future event logs, or only future events""" + + event_format: Annotated[ + Optional[CreateInputSystemByPackEventFormat], + pydantic.Field(alias="eventFormat"), + ] = None + r"""Format of individual events""" + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" + + interval: Optional[float] = None + r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + + batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None + r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + max_event_bytes: Annotated[Optional[int], pydantic.Field(alias="maxEventBytes")] = ( + None + ) + r"""The maximum number of bytes in an event before it is flushed to the pipelines""" + description: Optional[str] = None r"""Optional description for this configuration.""" + disable_json_rendering: Annotated[ + Optional[bool], pydantic.Field(alias="disableJsonRendering") + ] = None + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + + include_empty_json_fields: Annotated[ + Optional[bool], pydantic.Field(alias="includeEmptyJsonFields") + ] = None + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" + + disable_xml_rendering: Annotated[ + Optional[bool], pydantic.Field(alias="disableXmlRendering") + ] = None + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -11480,6 +11580,24 @@ class CreateInputSystemByPackInputCriblmetrics(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + @field_serializer("read_mode") + def serialize_read_mode(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputWinEventLogsReadMode(value) + except ValueError: + return value + return value + + @field_serializer("event_format") + def serialize_event_format(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackEventFormat(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -11492,10 +11610,18 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "prefix", - "fullFidelity", + "suppressMissingLogErrors", + "readMode", + "eventFormat", + "disableNativeModule", + "interval", + "batchSize", "metadata", + "maxEventBytes", "description", + "disableJsonRendering", + "includeEmptyJsonFields", + "disableXmlRendering", "__template_environment", "__template_streamtags", ] @@ -11514,360 +11640,284 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackShardIteratorStart( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Location at which to start reading a shard for the first time""" - - # Earliest record - TRIM_HORIZON = "TRIM_HORIZON" - # Latest record - LATEST = "LATEST" - - -class CreateInputSystemByPackRecordDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" +class CreateInputSystemByPackInputWefType(str, Enum): + r"""Connector type identifier.""" - # Cribl - CRIBL = "cribl" - # Newline JSON - NDJSON = "ndjson" - # Cloudwatch Logs - CLOUDWATCH = "cloudwatch" - # Event per line - LINE = "line" + WEF = "wef" -class CreateInputSystemByPackShardLoadBalancing( +class CreateInputSystemByPackInputWefAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + r"""How to authenticate incoming client connections""" - # Consistent Hashing - CONSISTENT_HASHING = "ConsistentHashing" - # Round Robin - ROUND_ROBIN = "RoundRobin" + # Client certificate + CLIENT_CERT = "clientCert" + # Kerberos + KERBEROS = "kerberos" + # Negotiate (SPNEGO) + NEGOTIATE = "negotiate" -class CreateInputSystemByPackInputKinesisTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: TypeOptionsKinesis - r"""Connector type identifier.""" - stream_name: str - r"""Kinesis Data Stream to read data from""" - region: str - r"""Region where the Kinesis stream is located""" +class CreateInputSystemByPackMTLSSettingsTypedDict(TypedDict): + r"""mTLS settings""" + + priv_key_path: str + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + cert_path: str + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + ca_path: str + r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - service_interval: NotRequired[float] - r"""Time interval in minutes between consecutive service calls""" - shard_expr: NotRequired[str] - r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" - shard_iterator_type: NotRequired[CreateInputSystemByPackShardIteratorStart] - r"""Location at which to start reading a shard for the first time""" - payload_format: NotRequired[CreateInputSystemByPackRecordDataFormat] - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" - get_records_limit: NotRequired[float] - r"""Maximum number of records per getRecords call""" - get_records_limit_total: NotRequired[float] - r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" - load_balancing_algorithm: NotRequired[CreateInputSystemByPackShardLoadBalancing] - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + r"""Enable TLS""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Kinesis stream""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - verify_kpl_check_sums: NotRequired[bool] - r"""Verify Kinesis Producer Library (KPL) event checksums""" - avoid_duplicates: NotRequired[bool] - r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - template_shard_iterator_type: NotRequired[str] - r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" - template_payload_format: NotRequired[str] - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Required for WEF certificate authentication""" + request_cert: NotRequired[bool] + r"""Required for WEF certificate authentication""" + certificate_name: NotRequired[str] + r"""Name of the predefined certificate""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + common_name_regex: NotRequired[str] + r"""Regex matching allowable common names in peer certificates' subject attribute""" + min_version: NotRequired[MinimumTLSVersionOptionsTLS] + r"""Minimum TLS version""" + max_version: NotRequired[MaximumTLSVersionOptionsTLS] + r"""Maximum TLS version""" + ocsp_check: NotRequired[bool] + r"""Enable OCSP check of certificate""" + ocsp_check_fail_close: NotRequired[bool] + r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" -class CreateInputSystemByPackInputKinesis(BaseModel): - id: str - r"""Unique ID for this input""" +class CreateInputSystemByPackMTLSSettings(BaseModel): + r"""mTLS settings""" - type: TypeOptionsKinesis - r"""Connector type identifier.""" + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - stream_name: Annotated[str, pydantic.Field(alias="streamName")] - r"""Kinesis Data Stream to read data from""" + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - region: str - r"""Region where the Kinesis stream is located""" + ca_path: Annotated[str, pydantic.Field(alias="caPath")] + r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" + r"""Enable TLS""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Required for WEF certificate authentication""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None + r"""Required for WEF certificate authentication""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""Name of the predefined certificate""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + common_name_regex: Annotated[ + Optional[str], pydantic.Field(alias="commonNameRegex") + ] = None + r"""Regex matching allowable common names in peer certificates' subject attribute""" - pq: Optional[PqType] = None + min_version: Annotated[ + Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") + ] = None + r"""Minimum TLS version""" - service_interval: Annotated[ - Optional[float], pydantic.Field(alias="serviceInterval") + max_version: Annotated[ + Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") ] = None - r"""Time interval in minutes between consecutive service calls""" + r"""Maximum TLS version""" - shard_expr: Annotated[Optional[str], pydantic.Field(alias="shardExpr")] = None - r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + ocsp_check: Annotated[Optional[bool], pydantic.Field(alias="ocspCheck")] = None + r"""Enable OCSP check of certificate""" - shard_iterator_type: Annotated[ - Optional[CreateInputSystemByPackShardIteratorStart], - pydantic.Field(alias="shardIteratorType"), + ocsp_check_fail_close: Annotated[ + Optional[bool], pydantic.Field(alias="ocspCheckFailClose") ] = None - r"""Location at which to start reading a shard for the first time""" + r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" - payload_format: Annotated[ - Optional[CreateInputSystemByPackRecordDataFormat], - pydantic.Field(alias="payloadFormat"), - ] = None - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + @field_serializer("min_version") + def serialize_min_version(self, value): + if isinstance(value, str): + try: + return models.MinimumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value - get_records_limit: Annotated[ - Optional[float], pydantic.Field(alias="getRecordsLimit") - ] = None - r"""Maximum number of records per getRecords call""" + @field_serializer("max_version") + def serialize_max_version(self, value): + if isinstance(value, str): + try: + return models.MaximumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value - get_records_limit_total: Annotated[ - Optional[float], pydantic.Field(alias="getRecordsLimitTotal") - ] = None - r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "rejectUnauthorized", + "requestCert", + "certificateName", + "passphrase", + "commonNameRegex", + "minVersion", + "maxVersion", + "ocspCheck", + "ocspCheckFailClose", + ] + ) + serialized = handler(self) + m = {} - load_balancing_algorithm: Annotated[ - Optional[CreateInputSystemByPackShardLoadBalancing], - pydantic.Field(alias="loadBalancingAlgorithm"), - ] = None - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + return m - endpoint: Optional[str] = None - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" +class CreateInputSystemByPackFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Content format in which the endpoint should deliver events""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + RAW = "Raw" + RENDERED_TEXT = "RenderedText" + + +class CreateInputSystemByPackQueryBuilderMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Query builder mode""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Kinesis stream""" + SIMPLE = "simple" + XML = "xml" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" +class CreateInputSystemByPackQueryTypedDict(TypedDict): + path: str + r"""The Path attribute from the relevant XML Select element""" + query_expression: str + r"""The XPath query inside the relevant XML Select element""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - verify_kpl_check_sums: Annotated[ - Optional[bool], pydantic.Field(alias="verifyKPLCheckSums") - ] = None - r"""Verify Kinesis Producer Library (KPL) event checksums""" +class CreateInputSystemByPackQuery(BaseModel): + path: str + r"""The Path attribute from the relevant XML Select element""" - avoid_duplicates: Annotated[ - Optional[bool], pydantic.Field(alias="avoidDuplicates") - ] = None - r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + query_expression: Annotated[str, pydantic.Field(alias="queryExpression")] + r"""The XPath query inside the relevant XML Select element""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - description: Optional[str] = None - r"""Optional description for this configuration.""" +class CreateInputSystemByPackSubscriptionTypedDict(TypedDict): + subscription_name: str + r"""Subscription name""" + content_format: CreateInputSystemByPackFormat + r"""Content format in which the endpoint should deliver events""" + heartbeat_interval: float + r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" + batch_timeout: float + r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" + targets: List[str] + r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" + version: NotRequired[str] + r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" + read_existing_events: NotRequired[bool] + r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" + send_bookmarks: NotRequired[bool] + r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" + compress: NotRequired[bool] + r"""Receive compressed events from the source""" + locale: NotRequired[str] + r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" + query_selector: NotRequired[CreateInputSystemByPackQueryBuilderMode] + r"""Query builder mode""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events ingested under this subscription""" + queries: NotRequired[List[CreateInputSystemByPackQueryTypedDict]] + r"""Queries""" + xml_query: NotRequired[str] + r"""The XPath query to use for selecting events""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" +class CreateInputSystemByPackSubscription(BaseModel): + subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] + r"""Subscription name""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + content_format: Annotated[ + CreateInputSystemByPackFormat, pydantic.Field(alias="contentFormat") + ] + r"""Content format in which the endpoint should deliver events""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + heartbeat_interval: Annotated[float, pydantic.Field(alias="heartbeatInterval")] + r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") - ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + batch_timeout: Annotated[float, pydantic.Field(alias="batchTimeout")] + r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" - template_shard_iterator_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_shardIteratorType") - ] = None - r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + targets: List[str] + r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" - template_payload_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadFormat") - ] = None - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + version: Optional[str] = None + r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + read_existing_events: Annotated[ + Optional[bool], pydantic.Field(alias="readExistingEvents") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + send_bookmarks: Annotated[Optional[bool], pydantic.Field(alias="sendBookmarks")] = ( + None + ) + r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + compress: Optional[bool] = None + r"""Receive compressed events from the source""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + locale: Optional[str] = None + r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + query_selector: Annotated[ + Optional[CreateInputSystemByPackQueryBuilderMode], + pydantic.Field(alias="querySelector"), ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Query builder mode""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events ingested under this subscription""" - @field_serializer("shard_iterator_type") - def serialize_shard_iterator_type(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackShardIteratorStart(value) - except ValueError: - return value - return value + queries: Optional[List[CreateInputSystemByPackQuery]] = None + r"""Queries""" - @field_serializer("payload_format") - def serialize_payload_format(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackRecordDataFormat(value) - except ValueError: - return value - return value + xml_query: Annotated[Optional[str], pydantic.Field(alias="xmlQuery")] = None + r"""The XPath query to use for selecting events""" - @field_serializer("load_balancing_algorithm") - def serialize_load_balancing_algorithm(self, value): + @field_serializer("content_format") + def serialize_content_format(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackShardLoadBalancing(value) + return models.CreateInputSystemByPackFormat(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("query_selector") + def serialize_query_selector(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.CreateInputSystemByPackQueryBuilderMode(value) except ValueError: return value return value @@ -11876,47 +11926,15 @@ def serialize_aws_authentication_method(self, value): def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "serviceInterval", - "shardExpr", - "shardIteratorType", - "payloadFormat", - "getRecordsLimit", - "getRecordsLimitTotal", - "loadBalancingAlgorithm", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "verifyKPLCheckSums", - "avoidDuplicates", + "version", + "readExistingEvents", + "sendBookmarks", + "compress", + "locale", + "querySelector", "metadata", - "description", - "awsApiKey", - "awsSecret", - "__template_environment", - "__template_streamtags", - "__template_streamName", - "__template_shardIteratorType", - "__template_payloadFormat", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", + "queries", + "xmlQuery", ] ) serialized = handler(self) @@ -11933,21 +11951,17 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputHTTPRawType(str, Enum): - r"""Source type identifier.""" - - HTTP_RAW = "http_raw" - - -class CreateInputSystemByPackInputHTTPRawTypedDict(TypedDict): +class CreateInputSystemByPackInputWefTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputHTTPRawType - r"""Source type identifier.""" + type: CreateInputSystemByPackInputWefType + r"""Connector type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + subscriptions: List[CreateInputSystemByPackSubscriptionTypedDict] + r"""Subscriptions to events on forwarding endpoints""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -11963,24 +11977,18 @@ class CreateInputSystemByPackInputHTTPRawTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + auth_method: NotRequired[CreateInputSystemByPackInputWefAuthenticationMethod] + r"""How to authenticate incoming client connections""" + tls: NotRequired[CreateInputSystemByPackMTLSSettingsTypedDict] + r"""mTLS settings""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" max_requests_per_socket: NotRequired[int] r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""Add request headers to events in the __headers field""" keep_alive_timeout: NotRequired[float] r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" enable_health_check: NotRequired[bool] @@ -11989,32 +11997,22 @@ class CreateInputSystemByPackInputHTTPRawTypedDict(TypedDict): r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + ca_fingerprint: NotRequired[str] + r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" + keytab: NotRequired[str] + r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" + principal: NotRequired[str] + r"""Kerberos principal used for authentication, typically in the form HTTP/@""" + allow_machine_id_mismatch: NotRequired[bool] + r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - allowed_paths: NotRequired[List[str]] - r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" - allowed_methods: NotRequired[List[str]] - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - access_control_allow_origin: NotRequired[List[str]] - r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" - access_control_allow_headers: NotRequired[List[str]] - r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" - access_control_allow_methods: NotRequired[List[str]] - r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" - access_control_expose_headers: NotRequired[List[str]] - r"""Headers the browser is allowed to access from the response""" - access_control_allow_credentials: NotRequired[bool] - r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" - access_control_max_age: NotRequired[float] - r"""How long browsers should cache the preflight response""" description: NotRequired[str] r"""Optional description for this configuration.""" + log_fingerprint_mismatch: NotRequired[bool] + r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -12023,22 +12021,18 @@ class CreateInputSystemByPackInputHTTPRawTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_allowed_paths: NotRequired[str] - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - template_access_control_allow_origin: NotRequired[str] - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_access_control_allow_headers: NotRequired[str] - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + template_keytab: NotRequired[str] + r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" + template_principal: NotRequired[str] + r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" -class CreateInputSystemByPackInputHTTPRaw(BaseModel): +class CreateInputSystemByPackInputWef(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputHTTPRawType - r"""Source type identifier.""" + type: CreateInputSystemByPackInputWefType + r"""Connector type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -12046,6 +12040,9 @@ class CreateInputSystemByPackInputHTTPRaw(BaseModel): port: float r"""Port to listen on""" + subscriptions: List[CreateInputSystemByPackSubscription] + r"""Subscriptions to events on forwarding endpoints""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -12071,13 +12068,14 @@ class CreateInputSystemByPackInputHTTPRaw(BaseModel): pq: Optional[PqType] = None - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + auth_method: Annotated[ + Optional[CreateInputSystemByPackInputWefAuthenticationMethod], + pydantic.Field(alias="authMethod"), + ] = None + r"""How to authenticate incoming client connections""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + tls: Optional[CreateInputSystemByPackMTLSSettings] = None + r"""mTLS settings""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None @@ -12092,27 +12090,12 @@ class CreateInputSystemByPackInputHTTPRaw(BaseModel): enable_proxy_header: Annotated[ Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" capture_headers: Annotated[ Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Add request headers to events, in the __headers field""" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""Add request headers to events in the __headers field""" keep_alive_timeout: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTimeout") @@ -12134,68 +12117,38 @@ class CreateInputSystemByPackInputHTTPRaw(BaseModel): ] = None r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - allowed_paths: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedPaths") - ] = None - r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" - - allowed_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedMethods") - ] = None - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - - auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], - pydantic.Field(alias="authTokensExt"), - ] = None - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - access_control_allow_origin: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - access_control_allow_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") - ] = None - r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + ca_fingerprint: Annotated[Optional[str], pydantic.Field(alias="caFingerprint")] = ( + None + ) + r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" - access_control_allow_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowMethods") - ] = None - r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + keytab: Optional[str] = None + r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" - access_control_expose_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlExposeHeaders") - ] = None - r"""Headers the browser is allowed to access from the response""" + principal: Optional[str] = None + r"""Kerberos principal used for authentication, typically in the form HTTP/@""" - access_control_allow_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="accessControlAllowCredentials") + allow_machine_id_mismatch: Annotated[ + Optional[bool], pydantic.Field(alias="allowMachineIdMismatch") ] = None - r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" - access_control_max_age: Annotated[ - Optional[float], pydantic.Field(alias="accessControlMaxAge") - ] = None - r"""How long browsers should cache the preflight response""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" description: Optional[str] = None r"""Optional description for this configuration.""" + log_fingerprint_mismatch: Annotated[ + Optional[bool], pydantic.Field(alias="logFingerprintMismatch") + ] = None + r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -12216,191 +12169,24 @@ class CreateInputSystemByPackInputHTTPRaw(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - template_allowed_paths: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedPaths") - ] = None - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - - template_access_control_allow_origin: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") - ] = None - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - - template_access_control_allow_headers: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") - ] = None - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "breakerRulesets", - "staleChannelFlushMs", - "metadata", - "allowedPaths", - "allowedMethods", - "authTokensExt", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "accessControlAllowMethods", - "accessControlExposeHeaders", - "accessControlAllowCredentials", - "accessControlMaxAge", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_allowedPaths", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateInputSystemByPackInputDatagenType(str, Enum): - r"""Connector type identifier.""" - - DATAGEN = "datagen" - - -class CreateInputSystemByPackSampleTypedDict(TypedDict): - sample: str - r"""Data Generator File Name""" - events_per_sec: float - r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" - - -class CreateInputSystemByPackSample(BaseModel): - sample: str - r"""Data Generator File Name""" - - events_per_sec: Annotated[float, pydantic.Field(alias="eventsPerSec")] - r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" - - -class CreateInputSystemByPackInputDatagenTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputDatagenType - r"""Connector type identifier.""" - samples: List[CreateInputSystemByPackSampleTypedDict] - r"""Datagens""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateInputSystemByPackInputDatagen(BaseModel): - id: str - r"""Unique ID for this input""" - - type: CreateInputSystemByPackInputDatagenType - r"""Connector type identifier.""" - - samples: List[CreateInputSystemByPackSample] - r"""Datagens""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + template_keytab: Annotated[ + Optional[str], pydantic.Field(alias="__template_keytab") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_principal: Annotated[ + Optional[str], pydantic.Field(alias="__template_principal") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" + + @field_serializer("auth_method") + def serialize_auth_method(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackInputWefAuthenticationMethod(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -12414,10 +12200,30 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", + "authMethod", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "socketTimeout", + "caFingerprint", + "keytab", + "principal", + "allowMachineIdMismatch", "metadata", "description", + "logFingerprintMismatch", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_keytab", + "__template_principal", ] ) serialized = handler(self) @@ -12434,51 +12240,138 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputDatadogAgentType(str, Enum): - r"""Source type identifier.""" +class CreateInputSystemByPackInputAppscopeType(str, Enum): + r"""Connector type identifier.""" + + APPSCOPE = "appscope" - DATADOG_AGENT = "datadog_agent" +class CreateInputSystemByPackAllowTypedDict(TypedDict): + procname: str + r"""Specify the name of a process or family of processes.""" + config: str + r"""Choose a config to apply to processes that match the process name and/or argument.""" + arg: NotRequired[str] + r"""Specify a string to substring-match against process command-line.""" -class CreateInputSystemByPackSamplingRuleTypedDict(TypedDict): - service: str - r"""Datadog service name""" - environment: str - r"""Datadog environment name (example: prod, staging)""" - rate: float - r"""Sampling rate for this service/environment combination (0.0–1.0)""" +class CreateInputSystemByPackAllow(BaseModel): + procname: str + r"""Specify the name of a process or family of processes.""" -class CreateInputSystemByPackSamplingRule(BaseModel): - service: str - r"""Datadog service name""" + config: str + r"""Choose a config to apply to processes that match the process name and/or argument.""" - environment: str - r"""Datadog environment name (example: prod, staging)""" + arg: Optional[str] = None + r"""Specify a string to substring-match against process command-line.""" - rate: float - r"""Sampling rate for this service/environment combination (0.0–1.0)""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["arg"]) + serialized = handler(self) + m = {} + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) -class CreateInputSystemByPackInputDatadogAgentProxyModeTypedDict(TypedDict): - enabled: bool - r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" - reject_unauthorized: NotRequired[bool] - r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + return m -class CreateInputSystemByPackInputDatadogAgentProxyMode(BaseModel): - enabled: bool - r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" +class CreateInputSystemByPackInputAppscopeFilterTypedDict(TypedDict): + allow: NotRequired[List[CreateInputSystemByPackAllowTypedDict]] + r"""Specify processes that AppScope should be loaded into, and the config to use.""" + transport_url: NotRequired[str] + r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" + + +class CreateInputSystemByPackInputAppscopeFilter(BaseModel): + allow: Optional[List[CreateInputSystemByPackAllow]] = None + r"""Specify processes that AppScope should be loaded into, and the config to use.""" + + transport_url: Annotated[Optional[str], pydantic.Field(alias="transportURL")] = None + r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["allow", "transportURL"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateInputSystemByPackInputAppscopePersistenceTypedDict(TypedDict): + r"""Persistence""" + + enable: NotRequired[bool] + r"""Spool events and metrics on disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" + + +class CreateInputSystemByPackInputAppscopePersistence(BaseModel): + r"""Persistence""" + + enable: Optional[bool] = None + r"""Spool events and metrics on disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["rejectUnauthorized"]) + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) serialized = handler(self) m = {} @@ -12493,15 +12386,23 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputDatadogAgentTypedDict(TypedDict): +CreateInputSystemByPackUNIXSocketPermissionsTypedDict = TypeAliasType( + "CreateInputSystemByPackUNIXSocketPermissionsTypedDict", Union[str, float] +) +r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + + +CreateInputSystemByPackUNIXSocketPermissions = TypeAliasType( + "CreateInputSystemByPackUNIXSocketPermissions", Union[str, float] +) +r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + + +class CreateInputSystemByPackInputAppscopeTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputDatadogAgentType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" + type: CreateInputSystemByPackInputAppscopeType + r"""Connector type identifier.""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -12517,41 +12418,49 @@ class CreateInputSystemByPackInputDatadogAgentTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - extract_metrics: NotRequired[bool] - r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" - sampling_rate: NotRequired[float] - r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" - sampling_rules: NotRequired[List[CreateInputSystemByPackSamplingRuleTypedDict]] - r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - proxy_mode: NotRequired[CreateInputSystemByPackInputDatadogAgentProxyModeTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + enable_unix_path: NotRequired[bool] + r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" + filter_: NotRequired[CreateInputSystemByPackInputAppscopeFilterTypedDict] + persistence: NotRequired[CreateInputSystemByPackInputAppscopePersistenceTypedDict] + r"""Persistence""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" + host: NotRequired[str] + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: NotRequired[float] + r"""Port to listen on""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + unix_socket_path: NotRequired[str] + r"""Path to the UNIX domain socket to listen on.""" + unix_socket_perms: NotRequired[ + CreateInputSystemByPackUNIXSocketPermissionsTypedDict + ] + r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -12562,18 +12471,12 @@ class CreateInputSystemByPackInputDatadogAgentTypedDict(TypedDict): r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateInputSystemByPackInputDatadogAgent(BaseModel): +class CreateInputSystemByPackInputAppscope(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputDatadogAgentType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" + type: CreateInputSystemByPackInputAppscopeType + r"""Connector type identifier.""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -12600,90 +12503,96 @@ class CreateInputSystemByPackInputDatadogAgent(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( None ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" enable_proxy_header: Annotated[ Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + enable_unix_path: Annotated[ + Optional[bool], pydantic.Field(alias="enableUnixPath") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + filter_: Annotated[ + Optional[CreateInputSystemByPackInputAppscopeFilter], + pydantic.Field(alias="filter"), ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + persistence: Optional[CreateInputSystemByPackInputAppscopePersistence] = None + r"""Persistence""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - extract_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="extractMetrics") - ] = None - r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + host: Optional[str] = None + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - sampling_rate: Annotated[Optional[float], pydantic.Field(alias="samplingRate")] = ( - None - ) - r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + port: Optional[float] = None + r"""Port to listen on""" - sampling_rules: Annotated[ - Optional[List[CreateInputSystemByPackSamplingRule]], - pydantic.Field(alias="samplingRules"), - ] = None - r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + unix_socket_path: Annotated[ + Optional[str], pydantic.Field(alias="unixSocketPath") + ] = None + r"""Path to the UNIX domain socket to listen on.""" - proxy_mode: Annotated[ - Optional[CreateInputSystemByPackInputDatadogAgentProxyMode], - pydantic.Field(alias="proxyMode"), + unix_socket_perms: Annotated[ + Optional[CreateInputSystemByPackUNIXSocketPermissions], + pydantic.Field(alias="unixSocketPerms"), ] = None + r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -12705,6 +12614,15 @@ class CreateInputSystemByPackInputDatadogAgent(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -12717,24 +12635,27 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", "enableProxyHeader", - "captureHeaders", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "extractMetrics", - "samplingRate", - "samplingRules", "metadata", - "proxyMode", + "breakerRulesets", + "staleChannelFlushMs", + "enableUnixPath", + "filter", + "persistence", + "authType", "description", + "host", + "port", + "tls", + "unixSocketPath", + "unixSocketPerms", + "authToken", + "textSecret", "__template_environment", "__template_streamtags", "__template_host", @@ -12755,19 +12676,21 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputCrowdstrikeType(str, Enum): +class CreateInputSystemByPackInputTCPType(str, Enum): r"""Connector type identifier.""" - CROWDSTRIKE = "crowdstrike" + TCP = "tcp" -class CreateInputSystemByPackInputCrowdstrikeTypedDict(TypedDict): +class CreateInputSystemByPackInputTCPTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCrowdstrikeType + type: CreateInputSystemByPackInputTCPType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -12783,121 +12706,62 @@ class CreateInputSystemByPackInputCrowdstrikeTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + enable_header: NotRequired[bool] + r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" preprocess: NotRequired[PreprocessTypeTypedDict] r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateInputSystemByPackInputCrowdstrike(BaseModel): +class CreateInputSystemByPackInputTCP(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputCrowdstrikeType + type: CreateInputSystemByPackInputTCPType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -12924,40 +12788,41 @@ class CreateInputSystemByPackInputCrowdstrike(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Regex matching IP addresses that are allowed to establish a connection""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( None ) - r"""Secret key""" + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -12969,134 +12834,31 @@ class CreateInputSystemByPackInputCrowdstrike(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( None ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" - - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" - - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" + r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" preprocess: Optional[PreprocessType] = None r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - checkpointing: Optional[CheckpointingType] = None - - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" - - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" - - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -13108,84 +12870,21 @@ class CreateInputSystemByPackInputCrowdstrike(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") - ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") - ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.TagAfterProcessingOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -13202,59 +12901,27 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", "breakerRulesets", "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", + "autoParse", + "enableHeader", "preprocess", - "metadata", - "checkpointing", - "pollTimeout", - "encoding", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", + "authToken", + "authType", + "textSecret", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -13268,58 +12935,301 @@ def serialize_model(self, handler): if val is not None or k not in optional_fields: m[k] = val - return m + return m + + +class CreateInputSystemByPackInputFileType(str, Enum): + r"""Connector type identifier.""" + + FILE = "file" + + +class CreateInputSystemByPackInputFileMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Choose how to discover files to monitor""" + + # Manual + MANUAL = "manual" + # Auto + AUTO = "auto" + + +class CreateInputSystemByPackInputFileTypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: CreateInputSystemByPackInputFileType + r"""Connector type identifier.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + mode: NotRequired[CreateInputSystemByPackInputFileMode] + r"""Choose how to discover files to monitor""" + interval: NotRequired[float] + r"""Time, in seconds, between scanning for files""" + filenames: NotRequired[List[str]] + r"""The full path of discovered files are matched against this wildcard list""" + filter_archived_files: NotRequired[bool] + r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" + tail_only: NotRequired[bool] + r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" + idle_timeout: NotRequired[float] + r"""Time, in seconds, before an idle file is closed""" + min_age_dur: NotRequired[str] + r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" + max_age_dur: NotRequired[str] + r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" + check_file_mod_time: NotRequired[bool] + r"""Skip files with modification times earlier than the maximum age duration""" + force_text: NotRequired[bool] + r"""Forces files containing binary data to be streamed as text""" + hash_len: NotRequired[float] + r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + disable_stale_channel_flush: NotRequired[bool] + r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + path: NotRequired[str] + r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" + depth: NotRequired[float] + r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" + suppress_missing_path_errors: NotRequired[bool] + r"""Suppress errors when search path does not exist""" + delete_files: NotRequired[bool] + r"""Delete files after they have been collected""" + salt_hash: NotRequired[bool] + r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" + optimize_leaf_directories: NotRequired[bool] + r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" + enable_discovery_throttle: NotRequired[bool] + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" + discovery_throttle_cpu_percent: NotRequired[float] + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" + include_unidentifiable_binary: NotRequired[bool] + r"""Stream binary files as Base64-encoded chunks""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateInputSystemByPackInputFile(BaseModel): + id: str + r"""Unique ID for this input""" + + type: CreateInputSystemByPackInputFileType + r"""Connector type identifier.""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + mode: Optional[CreateInputSystemByPackInputFileMode] = None + r"""Choose how to discover files to monitor""" + + interval: Optional[float] = None + r"""Time, in seconds, between scanning for files""" + + filenames: Optional[List[str]] = None + r"""The full path of discovered files are matched against this wildcard list""" + + filter_archived_files: Annotated[ + Optional[bool], pydantic.Field(alias="filterArchivedFiles") + ] = None + r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" + + tail_only: Annotated[Optional[bool], pydantic.Field(alias="tailOnly")] = None + r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" + + idle_timeout: Annotated[Optional[float], pydantic.Field(alias="idleTimeout")] = None + r"""Time, in seconds, before an idle file is closed""" + + min_age_dur: Annotated[Optional[str], pydantic.Field(alias="minAgeDur")] = None + r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" + + max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None + r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" + + check_file_mod_time: Annotated[ + Optional[bool], pydantic.Field(alias="checkFileModTime") + ] = None + r"""Skip files with modification times earlier than the maximum age duration""" + + force_text: Annotated[Optional[bool], pydantic.Field(alias="forceText")] = None + r"""Forces files containing binary data to be streamed as text""" + + hash_len: Annotated[Optional[float], pydantic.Field(alias="hashLen")] = None + r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + disable_stale_channel_flush: Annotated[ + Optional[bool], pydantic.Field(alias="disableStaleChannelFlush") + ] = None + r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None + r"""Optional description for this configuration.""" -class CreateInputSystemByPackInputWindowsMetricsType(str, Enum): - r"""Connector type identifier.""" + path: Optional[str] = None + r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" - WINDOWS_METRICS = "windows_metrics" + depth: Optional[float] = None + r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" + suppress_missing_path_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + ] = None + r"""Suppress errors when search path does not exist""" -class CreateInputSystemByPackInputWindowsMetricsSystemMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for system metrics""" + delete_files: Annotated[Optional[bool], pydantic.Field(alias="deleteFiles")] = None + r"""Delete files after they have been collected""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + salt_hash: Annotated[Optional[bool], pydantic.Field(alias="saltHash")] = None + r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" + + optimize_leaf_directories: Annotated[ + Optional[bool], pydantic.Field(alias="optimizeLeafDirectories") + ] = None + r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" + enable_discovery_throttle: Annotated[ + Optional[bool], pydantic.Field(alias="enableDiscoveryThrottle") + ] = None + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" -class CreateInputSystemByPackInputWindowsMetricsSystemTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsSystemMode] - r"""Select the level of details for system metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all system information""" + discovery_throttle_cpu_percent: Annotated[ + Optional[float], pydantic.Field(alias="discoveryThrottleCpuPercent") + ] = None + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" + include_unidentifiable_binary: Annotated[ + Optional[bool], pydantic.Field(alias="includeUnidentifiableBinary") + ] = None + r"""Stream binary files as Base64-encoded chunks""" -class CreateInputSystemByPackInputWindowsMetricsSystem(BaseModel): - mode: Optional[CreateInputSystemByPackInputWindowsMetricsSystemMode] = None - r"""Select the level of details for system metrics""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - detail: Optional[bool] = None - r"""Generate metrics for all system information""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @field_serializer("mode") def serialize_mode(self, value): if isinstance(value, str): try: - return models.CreateInputSystemByPackInputWindowsMetricsSystemMode( - value - ) + return models.CreateInputSystemByPackInputFileMode(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) + optional_fields = set( + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "mode", + "interval", + "filenames", + "filterArchivedFiles", + "tailOnly", + "idleTimeout", + "minAgeDur", + "maxAgeDur", + "checkFileModTime", + "forceText", + "hashLen", + "enableLoadBalancing", + "metadata", + "breakerRulesets", + "disableStaleChannelFlush", + "staleChannelFlushMs", + "autoParse", + "description", + "path", + "depth", + "suppressMissingPathErrors", + "deleteFiles", + "saltHash", + "optimizeLeafDirectories", + "enableDiscoveryThrottle", + "discoveryThrottleCpuPercent", + "includeUnidentifiableBinary", + "__template_environment", + "__template_streamtags", + ] + ) serialized = handler(self) m = {} @@ -13334,189 +13244,297 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputWindowsMetricsCPUMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for CPU metrics""" +class CreateInputSystemByPackInputSyslogSyslog2TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsSyslog + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + tcp_port: float + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + udp_port: NotRequired[float] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + timestamp_timezone: NotRequired[str] + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: NotRequired[bool] + r"""Treat UDP packet data received as full syslog message""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: NotRequired[List[str]] + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + octet_counting: NotRequired[bool] + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: NotRequired[bool] + r"""Enable if we should infer the syslog framing of the incoming messages.""" + strictly_infer_octet_counting: NotRequired[bool] + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + allow_non_standard_app_name: NotRequired[bool] + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: NotRequired[bool] + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + template_timestamp_timezone: NotRequired[str] + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" +class CreateInputSystemByPackInputSyslogSyslog2(BaseModel): + id: str + r"""Unique ID for this input""" -class CreateInputSystemByPackInputWindowsMetricsCPUTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsCPUMode] - r"""Select the level of details for CPU metrics""" - per_cpu: NotRequired[bool] - r"""Generate metrics for each CPU""" - detail: NotRequired[bool] - r"""Generate metrics for all CPU states""" - time: NotRequired[bool] - r"""Generate raw, monotonic CPU time counters""" + type: TypeOptionsSyslog + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" -class CreateInputSystemByPackInputWindowsMetricsCPU(BaseModel): - mode: Optional[CreateInputSystemByPackInputWindowsMetricsCPUMode] = None - r"""Select the level of details for CPU metrics""" + tcp_port: Annotated[float, pydantic.Field(alias="tcpPort")] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None - r"""Generate metrics for each CPU""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - detail: Optional[bool] = None - r"""Generate metrics for all CPU states""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - time: Optional[bool] = None - r"""Generate raw, monotonic CPU time counters""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputWindowsMetricsCPUMode(value) - except ValueError: - return value - return value + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perCpu", "detail", "time"]) - serialized = handler(self) - m = {} + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - return m + pq: Optional[PqType] = None + + udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" -class CreateInputSystemByPackInputWindowsMetricsMemoryMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for memory metrics""" + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="timestampTimezone") + ] = None + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + ] = None + r"""Treat UDP packet data received as full syslog message""" -class CreateInputSystemByPackInputWindowsMetricsMemoryTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsMemoryMode] - r"""Select the level of details for memory metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all memory states""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="keepFieldsList") + ] = None + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" -class CreateInputSystemByPackInputWindowsMetricsMemory(BaseModel): - mode: Optional[CreateInputSystemByPackInputWindowsMetricsMemoryMode] = None - r"""Select the level of details for memory metrics""" + octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + None + ) + r"""Enable if incoming messages use octet counting per RFC 6587.""" - detail: Optional[bool] = None - r"""Generate metrics for all memory states""" + infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( + None + ) + r"""Enable if we should infer the syslog framing of the incoming messages.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputWindowsMetricsMemoryMode( - value - ) - except ValueError: - return value - return value + strictly_infer_octet_counting: Annotated[ + Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + ] = None + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) - serialized = handler(self) - m = {} + allow_non_standard_app_name: Annotated[ + Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ] = None + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - return m + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" -class CreateInputSystemByPackInputWindowsMetricsNetworkMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for network metrics""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" -class CreateInputSystemByPackInputWindowsMetricsNetworkTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsNetworkMode] - r"""Select the level of details for network metrics""" - detail: NotRequired[bool] - r"""Generate full network metrics""" - protocols: NotRequired[bool] - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - devices: NotRequired[List[str]] - r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" - per_interface: NotRequired[bool] - r"""Generate separate metrics for each interface""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" -class CreateInputSystemByPackInputWindowsMetricsNetwork(BaseModel): - mode: Optional[CreateInputSystemByPackInputWindowsMetricsNetworkMode] = None - r"""Select the level of details for network metrics""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - detail: Optional[bool] = None - r"""Generate full network metrics""" + enable_enhanced_proxy_header_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + ] = None + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" - protocols: Optional[bool] = None - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - devices: Optional[List[str]] = None - r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Generate separate metrics for each interface""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputWindowsMetricsNetworkMode( - value - ) - except ValueError: - return value - return value + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + + template_timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="__template_timestampTimezone") + ] = None + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( - ["mode", "detail", "protocols", "devices", "perInterface"] + [ + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "udpPort", + "maxBufferSize", + "ipWhitelistRegex", + "timestampTimezone", + "singleMsgUdpPackets", + "enableProxyHeader", + "keepFieldsList", + "octetCounting", + "inferFraming", + "strictlyInferOctetCounting", + "allowNonStandardAppName", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "tls", + "metadata", + "udpSocketRxBufSize", + "enableLoadBalancing", + "autoParse", + "description", + "enableEnhancedProxyHeaderParsing", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + "__template_timestampTimezone", + ] ) serialized = handler(self) m = {} @@ -13532,202 +13550,296 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputWindowsMetricsDiskMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for disk metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class CreateInputSystemByPackInputWindowsMetricsDiskTypedDict(TypedDict): - mode: NotRequired[CreateInputSystemByPackInputWindowsMetricsDiskMode] - r"""Select the level of details for disk metrics""" - per_volume: NotRequired[bool] - r"""Generate separate metrics for each volume""" - detail: NotRequired[bool] - r"""Generate full disk metrics""" - volumes: NotRequired[List[str]] - r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" - - -class CreateInputSystemByPackInputWindowsMetricsDisk(BaseModel): - mode: Optional[CreateInputSystemByPackInputWindowsMetricsDiskMode] = None - r"""Select the level of details for disk metrics""" - - per_volume: Annotated[Optional[bool], pydantic.Field(alias="perVolume")] = None - r"""Generate separate metrics for each volume""" +class CreateInputSystemByPackInputSyslogSyslog1TypedDict(TypedDict): + id: str + r"""Unique ID for this input""" + type: TypeOptionsSyslog + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + udp_port: float + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tcp_port: NotRequired[float] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + timestamp_timezone: NotRequired[str] + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: NotRequired[bool] + r"""Treat UDP packet data received as full syslog message""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: NotRequired[List[str]] + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + octet_counting: NotRequired[bool] + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: NotRequired[bool] + r"""Enable if we should infer the syslog framing of the incoming messages.""" + strictly_infer_octet_counting: NotRequired[bool] + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + allow_non_standard_app_name: NotRequired[bool] + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: NotRequired[bool] + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + template_timestamp_timezone: NotRequired[str] + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" - detail: Optional[bool] = None - r"""Generate full disk metrics""" - volumes: Optional[List[str]] = None - r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" +class CreateInputSystemByPackInputSyslogSyslog1(BaseModel): + id: str + r"""Unique ID for this input""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.CreateInputSystemByPackInputWindowsMetricsDiskMode(value) - except ValueError: - return value - return value + type: TypeOptionsSyslog + r"""Connector type identifier.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perVolume", "detail", "volumes"]) - serialized = handler(self) - m = {} + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + udp_port: Annotated[float, pydantic.Field(alias="udpPort")] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - return m + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" -class CreateInputSystemByPackInputWindowsMetricsCustomTypedDict(TypedDict): - system: NotRequired[CreateInputSystemByPackInputWindowsMetricsSystemTypedDict] - cpu: NotRequired[CreateInputSystemByPackInputWindowsMetricsCPUTypedDict] - memory: NotRequired[CreateInputSystemByPackInputWindowsMetricsMemoryTypedDict] - network: NotRequired[CreateInputSystemByPackInputWindowsMetricsNetworkTypedDict] - disk: NotRequired[CreateInputSystemByPackInputWindowsMetricsDiskTypedDict] + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" -class CreateInputSystemByPackInputWindowsMetricsCustom(BaseModel): - system: Optional[CreateInputSystemByPackInputWindowsMetricsSystem] = None + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - cpu: Optional[CreateInputSystemByPackInputWindowsMetricsCPU] = None + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - memory: Optional[CreateInputSystemByPackInputWindowsMetricsMemory] = None + pq: Optional[PqType] = None - network: Optional[CreateInputSystemByPackInputWindowsMetricsNetwork] = None + tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - disk: Optional[CreateInputSystemByPackInputWindowsMetricsDisk] = None + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["system", "cpu", "memory", "network", "disk"]) - serialized = handler(self) - m = {} + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="timestampTimezone") + ] = None + r"""Timezone to assign to timestamps without timezone info""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + ] = None + r"""Treat UDP packet data received as full syslog message""" - return m + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="keepFieldsList") + ] = None + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" -class CreateInputSystemByPackInputWindowsMetricsHostTypedDict(TypedDict): - mode: NotRequired[ModeOptionsHost] - r"""Select level of detail for host metrics""" - custom: NotRequired[CreateInputSystemByPackInputWindowsMetricsCustomTypedDict] + octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + None + ) + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( + None + ) + r"""Enable if we should infer the syslog framing of the incoming messages.""" -class CreateInputSystemByPackInputWindowsMetricsHost(BaseModel): - mode: Optional[ModeOptionsHost] = None - r"""Select level of detail for host metrics""" + strictly_infer_octet_counting: Annotated[ + Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + ] = None + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - custom: Optional[CreateInputSystemByPackInputWindowsMetricsCustom] = None + allow_non_standard_app_name: Annotated[ + Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ] = None + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptionsHost(value) - except ValueError: - return value - return value + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "custom"]) - serialized = handler(self) - m = {} + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - return m + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" -class CreateInputSystemByPackInputWindowsMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" -class CreateInputSystemByPackInputWindowsMetricsPersistence(BaseModel): - r"""persistence""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" + enable_enhanced_proxy_header_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + ] = None + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value + template_timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="__template_timestampTimezone") + ] = None + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tcpPort", + "maxBufferSize", + "ipWhitelistRegex", + "timestampTimezone", + "singleMsgUdpPackets", + "enableProxyHeader", + "keepFieldsList", + "octetCounting", + "inferFraming", + "strictlyInferOctetCounting", + "allowNonStandardAppName", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "tls", + "metadata", + "udpSocketRxBufSize", + "enableLoadBalancing", + "autoParse", + "description", + "enableEnhancedProxyHeaderParsing", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + "__template_timestampTimezone", ] ) serialized = handler(self) @@ -13744,11 +13856,42 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputWindowsMetricsTypedDict(TypedDict): +CreateInputSystemByPackInputSyslogUnionTypedDict = TypeAliasType( + "CreateInputSystemByPackInputSyslogUnionTypedDict", + Union[ + CreateInputSystemByPackInputSyslogSyslog1TypedDict, + CreateInputSystemByPackInputSyslogSyslog2TypedDict, + ], +) + + +CreateInputSystemByPackInputSyslogUnion = TypeAliasType( + "CreateInputSystemByPackInputSyslogUnion", + Union[ + CreateInputSystemByPackInputSyslogSyslog1, + CreateInputSystemByPackInputSyslogSyslog2, + ], +) + + +class CreateInputSystemByPackQueueType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The queue type used (or created)""" + + # Standard + STANDARD = "standard" + # FIFO + FIFO = "fifo" + + +class CreateInputSystemByPackInputSqsTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWindowsMetricsType + type: TypeOptionsSqs r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + queue_type: CreateInputSystemByPackQueueType + r"""The queue type used (or created)""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -13764,34 +13907,87 @@ class CreateInputSystemByPackInputWindowsMetricsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - host: NotRequired[CreateInputSystemByPackInputWindowsMetricsHostTypedDict] - process: NotRequired[ProcessTypeTypedDict] - gpu: NotRequired[GpuTypeTypedDict] + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + create_queue: NotRequired[bool] + r"""Create queue if it does not exist""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SQS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - persistence: NotRequired[ - CreateInputSystemByPackInputWindowsMetricsPersistenceTypedDict - ] - r"""persistence""" - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_queue_type: NotRequired[str] + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateInputSystemByPackInputWindowsMetrics(BaseModel): +class CreateInputSystemByPackInputSqs(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputWindowsMetricsType + type: TypeOptionsSqs r"""Connector type identifier.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + queue_type: Annotated[ + CreateInputSystemByPackQueueType, pydantic.Field(alias="queueType") + ] + r"""The queue type used (or created)""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -13817,29 +14013,92 @@ class CreateInputSystemByPackInputWindowsMetrics(BaseModel): pq: Optional[PqType] = None - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None + r"""Create queue if it does not exist""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SQS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" - host: Optional[CreateInputSystemByPackInputWindowsMetricsHost] = None + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - process: Optional[ProcessType] = None + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - gpu: Optional[GpuType] = None + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - persistence: Optional[CreateInputSystemByPackInputWindowsMetricsPersistence] = None - r"""persistence""" + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") - ] = None - r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: Optional[str] = None r"""Optional description for this configuration.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -13850,6 +14109,69 @@ class CreateInputSystemByPackInputWindowsMetrics(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_queue_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueType") + ] = None + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("queue_type") + def serialize_queue_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackQueueType(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -13862,16 +14184,38 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "interval", - "host", - "process", - "gpu", + "awsAccountId", + "createQueue", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxMessages", + "visibilityTimeout", "metadata", - "persistence", - "disableNativeModule", + "pollTimeout", + "autoParse", "description", + "awsApiKey", + "awsSecret", + "numReceivers", "__template_environment", "__template_streamtags", + "__template_queueName", + "__template_queueType", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -13888,17 +14232,21 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputKubeEventsType(str, Enum): +class CreateInputSystemByPackInputModelDrivenTelemetryType(str, Enum): r"""Connector type identifier.""" - KUBE_EVENTS = "kube_events" + MODEL_DRIVEN_TELEMETRY = "model_driven_telemetry" -class CreateInputSystemByPackInputKubeEventsTypedDict(TypedDict): +class CreateInputSystemByPackInputModelDrivenTelemetryTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputKubeEventsType + type: CreateInputSystemByPackInputModelDrivenTelemetryType r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -13914,25 +14262,43 @@ class CreateInputSystemByPackInputKubeEventsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] - r"""Filtering on event fields""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" + shutdown_timeout_ms: NotRequired[float] + r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateInputSystemByPackInputKubeEvents(BaseModel): +class CreateInputSystemByPackInputModelDrivenTelemetry(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputKubeEventsType + type: CreateInputSystemByPackInputModelDrivenTelemetryType r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -13958,12 +14324,32 @@ class CreateInputSystemByPackInputKubeEvents(BaseModel): pq: Optional[PqType] = None - rules: Optional[List[RuleConfInputKubeMetrics]] = None - r"""Filtering on event fields""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") + ] = None + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") + ] = None + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" + + shutdown_timeout_ms: Annotated[ + Optional[float], pydantic.Field(alias="shutdownTimeoutMs") + ] = None + r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -13977,6 +14363,16 @@ class CreateInputSystemByPackInputKubeEvents(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -13989,11 +14385,17 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "rules", + "tls", "metadata", + "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", + "shutdownTimeoutMs", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -14010,29 +14412,167 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputKubeLogsType(str, Enum): - r"""Connector type identifier.""" +class CreateInputSystemByPackInputOpenTelemetryType(str, Enum): + r"""Source type identifier.""" + + OPEN_TELEMETRY = "open_telemetry" - KUBE_LOGS = "kube_logs" +class CreateInputSystemByPackProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" -class CreateInputSystemByPackInputKubeLogsRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + # gRPC + GRPC = "grpc" + # HTTP + HTTP = "http" + + +class CreateInputSystemByPackOTLPVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" + + # 0.10.0 + ZERO_DOT_10_DOT_0 = "0.10.0" + # 1.3.1 + ONE_DOT_3_DOT_1 = "1.3.1" + + +class CreateInputSystemByPackInputOpenTelemetryAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""OpenTelemetry authentication type""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + + +class CreateInputSystemByPackAuthMethodsExtAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" + + # Token + TOKEN = "token" + # Token (secret) + TOKEN_SECRET = "tokenSecret" + # Basic + BASIC = "basic" + # Basic (credentials secret) + BASIC_SECRET = "basicSecret" + # OAuth + OAUTH = "oauth" + + +class CreateInputSystemByPackAuthMethodsExtTypedDict(TypedDict): + auth_type: CreateInputSystemByPackAuthMethodsExtAuthenticationType + r"""Authentication type""" + token: NotRequired[str] + r"""Bearer token for Authorization header""" description: NotRequired[str] - r"""Optional description of this rule's purpose""" + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this auth method""" + enabled: NotRequired[bool] + r"""Enable""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + issuer: NotRequired[str] + r"""Expected token issuer (iss claim)""" + jwks_uri: NotRequired[str] + r"""URL of the JWKS endpoint used to fetch signing keys""" + audience: NotRequired[str] + r"""Expected token audience (aud claim)""" + scopes: NotRequired[List[str]] + r"""Scopes the token must grant (optional)""" -class CreateInputSystemByPackInputKubeLogsRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" +class CreateInputSystemByPackAuthMethodsExt(BaseModel): + auth_type: Annotated[ + CreateInputSystemByPackAuthMethodsExtAuthenticationType, + pydantic.Field(alias="authType"), + ] + r"""Authentication type""" + + token: Optional[str] = None + r"""Bearer token for Authorization header""" description: Optional[str] = None - r"""Optional description of this rule's purpose""" + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this auth method""" + + enabled: Optional[bool] = None + r"""Enable""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + issuer: Optional[str] = None + r"""Expected token issuer (iss claim)""" + + jwks_uri: Annotated[Optional[str], pydantic.Field(alias="jwksUri")] = None + r"""URL of the JWKS endpoint used to fetch signing keys""" + + audience: Optional[str] = None + r"""Expected token audience (aud claim)""" + + scopes: Optional[List[str]] = None + r"""Scopes the token must grant (optional)""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackAuthMethodsExtAuthenticationType( + value + ) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description"]) + optional_fields = set( + [ + "token", + "description", + "metadata", + "enabled", + "tokenSecret", + "username", + "password", + "credentialsSecret", + "issuer", + "jwksUri", + "audience", + "scopes", + ] + ) serialized = handler(self) m = {} @@ -14047,11 +14587,15 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputKubeLogsTypedDict(TypedDict): +class CreateInputSystemByPackInputOpenTelemetryTypedDict(TypedDict): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputKubeLogsType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputOpenTelemetryType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" pipeline: NotRequired[str] @@ -14067,40 +14611,84 @@ class CreateInputSystemByPackInputKubeLogsTypedDict(TypedDict): connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" - rules: NotRequired[List[CreateInputSystemByPackInputKubeLogsRuleTypedDict]] - r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" - timestamps: NotRequired[bool] - r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" - line_buffer_limit: NotRequired[float] - r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" - lb_disable_assembly: NotRequired[bool] - r"""Internal flag to disable LB worker payload reassembly.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + enable_health_check: NotRequired[bool] + r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + protocol: NotRequired[CreateInputSystemByPackProtocol] + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" + extract_spans: NotRequired[bool] + r"""Enable to extract each incoming span to a separate event""" + extract_metrics: NotRequired[bool] + r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" + otlp_version: NotRequired[CreateInputSystemByPackOTLPVersion] + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" + auth_type: NotRequired[CreateInputSystemByPackInputOpenTelemetryAuthenticationType] + r"""OpenTelemetry authentication type""" + auth_methods_ext: NotRequired[List[CreateInputSystemByPackAuthMethodsExtTypedDict]] + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - persistence: NotRequired[DiskSpoolingTypeTypedDict] - r"""Disk Spooling""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + extract_logs: NotRequired[bool] + r"""Enable to extract each incoming log record to a separate event""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_protocol: NotRequired[str] + r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + template_otlp_version: NotRequired[str] + r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" -class CreateInputSystemByPackInputKubeLogs(BaseModel): +class CreateInputSystemByPackInputOpenTelemetry(BaseModel): id: str r"""Unique ID for this input""" - type: CreateInputSystemByPackInputKubeLogsType - r"""Connector type identifier.""" + type: CreateInputSystemByPackInputOpenTelemetryType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" disabled: Optional[bool] = None r"""If true, the Source is disabled and will not collect data.""" @@ -14113,63 +14701,135 @@ class CreateInputSystemByPackInputKubeLogs(BaseModel): ) r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - pq: Optional[PqType] = None + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - interval: Optional[float] = None - r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + protocol: Optional[CreateInputSystemByPackProtocol] = None + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" + + extract_spans: Annotated[Optional[bool], pydantic.Field(alias="extractSpans")] = ( + None + ) + r"""Enable to extract each incoming span to a separate event""" - rules: Optional[List[CreateInputSystemByPackInputKubeLogsRule]] = None - r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + extract_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="extractMetrics") + ] = None + r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - timestamps: Optional[bool] = None - r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + otlp_version: Annotated[ + Optional[CreateInputSystemByPackOTLPVersion], + pydantic.Field(alias="otlpVersion"), + ] = None + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - line_buffer_limit: Annotated[ - Optional[float], pydantic.Field(alias="lineBufferLimit") + auth_type: Annotated[ + Optional[CreateInputSystemByPackInputOpenTelemetryAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + r"""OpenTelemetry authentication type""" - lb_disable_assembly: Annotated[ - Optional[bool], pydantic.Field(alias="__LBDisableAssembly") + auth_methods_ext: Annotated[ + Optional[List[CreateInputSystemByPackAuthMethodsExt]], + pydantic.Field(alias="authMethodsExt"), ] = None - r"""Internal flag to disable LB worker payload reassembly.""" + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - persistence: Optional[DiskSpoolingType] = None - r"""Disk Spooling""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: Optional[str] = None r"""Optional description for this configuration.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + extract_logs: Annotated[Optional[bool], pydantic.Field(alias="extractLogs")] = None + r"""Enable to extract each incoming log record to a separate event""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -14180,6 +14840,57 @@ class CreateInputSystemByPackInputKubeLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_protocol: Annotated[ + Optional[str], pydantic.Field(alias="__template_protocol") + ] = None + r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + + template_otlp_version: Annotated[ + Optional[str], pydantic.Field(alias="__template_otlpVersion") + ] = None + r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" + + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackProtocol(value) + except ValueError: + return value + return value + + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackOTLPVersion(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return ( + models.CreateInputSystemByPackInputOpenTelemetryAuthenticationType( + value + ) + ) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -14192,19 +14903,38 @@ def serialize_model(self, handler): "streamtags", "connections", "pq", - "interval", - "rules", - "timestamps", - "lineBufferLimit", - "__LBDisableAssembly", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "protocol", + "extractSpans", + "extractMetrics", + "otlpVersion", + "authType", + "authMethodsExt", "metadata", - "persistence", - "breakerRulesets", - "staleChannelFlushMs", - "enableLoadBalancing", + "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "extractLogs", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_protocol", + "__template_otlpVersion", ] ) serialized = handler(self) @@ -14221,215 +14951,175 @@ def serialize_model(self, handler): return m -class CreateInputSystemByPackInputKubeMetricsType(str, Enum): - r"""Connector type identifier.""" - - KUBE_METRICS = "kube_metrics" - - -class CreateInputSystemByPackInputKubeMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" - - enable: NotRequired[bool] - r"""Spool metrics on disk for Cribl Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - - -class CreateInputSystemByPackInputKubeMetricsPersistence(BaseModel): - r"""persistence""" - - enable: Optional[bool] = None - r"""Spool metrics on disk for Cribl Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} +class CreateInputSystemByPackAuthenticationProtocol( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication protocol""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + # None + NONE = "none" + # MD5 + MD5 = "md5" + # SHA1 + SHA = "sha" + # SHA224 + SHA224 = "sha224" + # SHA256 + SHA256 = "sha256" + # SHA384 + SHA384 = "sha384" + # SHA512 + SHA512 = "sha512" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - return m +class CreateInputSystemByPackV3AuthenticationKeyType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" -class CreateInputSystemByPackInputKubeMetricsTypedDict(TypedDict): - id: str - r"""Unique ID for this input""" - type: CreateInputSystemByPackInputKubeMetricsType - r"""Connector type identifier.""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" - scrape_kubelet: NotRequired[bool] - r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" - scrape_cadvisor: NotRequired[bool] - r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" - rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] - r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - persistence: NotRequired[ - CreateInputSystemByPackInputKubeMetricsPersistenceTypedDict - ] - r"""persistence""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" +class CreateInputSystemByPackPrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Privacy protocol""" -class CreateInputSystemByPackInputKubeMetrics(BaseModel): - id: str - r"""Unique ID for this input""" + # None + NONE = "none" + # DES + DES = "des" + # AES128 + AES = "aes" + # AES256b (Blumenthal) + AES256B = "aes256b" + # AES256r (Reeder) + AES256R = "aes256r" - type: CreateInputSystemByPackInputKubeMetricsType - r"""Connector type identifier.""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" +class CreateInputSystemByPackV3PrivacyKeyType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" +class CreateInputSystemByPackV3UserTypedDict(TypedDict): + name: str + r"""V3 name""" + auth_protocol: NotRequired[CreateInputSystemByPackAuthenticationProtocol] + r"""Authentication protocol""" + auth_key_type: NotRequired[CreateInputSystemByPackV3AuthenticationKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + auth_key: NotRequired[str] + r"""V3 authentication key""" + auth_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" + priv_protocol: NotRequired[CreateInputSystemByPackPrivacyProtocol] + r"""Privacy protocol""" + priv_key_type: NotRequired[CreateInputSystemByPackV3PrivacyKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + priv_key: NotRequired[str] + r"""V3 privacy key""" + priv_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class CreateInputSystemByPackV3User(BaseModel): + name: str + r"""V3 name""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + auth_protocol: Annotated[ + Optional[CreateInputSystemByPackAuthenticationProtocol], + pydantic.Field(alias="authProtocol"), + ] = None + r"""Authentication protocol""" - pq: Optional[PqType] = None + auth_key_type: Annotated[ + Optional[CreateInputSystemByPackV3AuthenticationKeyType], + pydantic.Field(alias="authKeyType"), + ] = None + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + auth_key: Annotated[Optional[str], pydantic.Field(alias="authKey")] = None + r"""V3 authentication key""" - scrape_kubelet: Annotated[Optional[bool], pydantic.Field(alias="scrapeKubelet")] = ( + auth_key_secret: Annotated[Optional[str], pydantic.Field(alias="authKeySecret")] = ( None ) - r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + r"""Select or create a stored text secret""" - scrape_cadvisor: Annotated[ - Optional[bool], pydantic.Field(alias="scrapeCadvisor") + priv_protocol: Annotated[ + Optional[CreateInputSystemByPackPrivacyProtocol], + pydantic.Field(alias="privProtocol"), ] = None - r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + r"""Privacy protocol""" - rules: Optional[List[RuleConfInputKubeMetrics]] = None - r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + priv_key_type: Annotated[ + Optional[CreateInputSystemByPackV3PrivacyKeyType], + pydantic.Field(alias="privKeyType"), + ] = None + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + priv_key: Annotated[Optional[str], pydantic.Field(alias="privKey")] = None + r"""V3 privacy key""" - persistence: Optional[CreateInputSystemByPackInputKubeMetricsPersistence] = None - r"""persistence""" + priv_key_secret: Annotated[Optional[str], pydantic.Field(alias="privKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + @field_serializer("auth_protocol") + def serialize_auth_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackAuthenticationProtocol(value) + except ValueError: + return value + return value - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + @field_serializer("auth_key_type") + def serialize_auth_key_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackV3AuthenticationKeyType(value) + except ValueError: + return value + return value - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + @field_serializer("priv_protocol") + def serialize_priv_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackPrivacyProtocol(value) + except ValueError: + return value + return value + + @field_serializer("priv_key_type") + def serialize_priv_key_type(self, value): + if isinstance(value, str): + try: + return models.CreateInputSystemByPackV3PrivacyKeyType(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "connections", - "pq", - "interval", - "scrapeKubelet", - "scrapeCadvisor", - "rules", - "metadata", - "persistence", - "description", - "__template_environment", - "__template_streamtags", + "authProtocol", + "authKeyType", + "authKey", + "authKeySecret", + "privProtocol", + "privKeyType", + "privKey", + "privKeySecret", ] ) serialized = handler(self) @@ -14447,286 +15137,278 @@ def serialize_model(self, handler): try: - CreateInputSystemByPackInputOkta.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackActivities.model_rebuild() -except NameError: - pass -try: - CreateInputSystemByPackChats.model_rebuild() + CreateInputSystemByPackInputTrendMicroVisionOne.model_rebuild() except NameError: pass try: - CreateInputSystemByPackProjects.model_rebuild() + CreateInputSystemByPackInputMimecastHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackChatMessages.model_rebuild() + CreateInputSystemByPackInputHashicorpHcpVaultDedicated.model_rebuild() except NameError: pass try: - CreateInputSystemByPackProjectDetails.model_rebuild() + CreateInputSystemByPackInputBeyondtrustHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackGroups.model_rebuild() + CreateInputSystemByPackInputF5BigIP.model_rebuild() except NameError: pass try: - CreateInputSystemByPackOrganizations.model_rebuild() + CreateInputSystemByPackInputVectraAiHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackOrganizationUsers.model_rebuild() + CreateInputSystemByPackInputGigamonHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackOrganizationRoles.model_rebuild() + CreateInputSystemByPackInputPingIdentityPingone.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputAnthropicCompliance.model_rebuild() + CreateInputSystemByPackInputAkamaiHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputOpenaiComplianceLogs.model_rebuild() + CreateInputSystemByPackInputOkta.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputUpwindHec.model_rebuild() + CreateInputSystemByPackRetryRules.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSysdigHec.model_rebuild() + CreateInputSystemByPackCertOptions.model_rebuild() except NameError: pass try: - CreateInputSystemByPackTLSSettingsServerSide.model_rebuild() + CreateInputSystemByPackInputMicrosoftCopilot.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputCloudflareHec.model_rebuild() + CreateInputSystemByPackInputAnthropicEnterpriseAnalyticsContentConfig.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputZscalerHecAuthToken.model_rebuild() + CreateInputSystemByPackInputAnthropicEnterpriseAnalytics.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputZscalerHec.model_rebuild() + CreateInputSystemByPackActivities.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputServicenowTable.model_rebuild() + CreateInputSystemByPackChats.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputBedrockS3.model_rebuild() + CreateInputSystemByPackProjects.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSecurityLake.model_rebuild() + CreateInputSystemByPackChatMessages.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputNetflow.model_rebuild() + CreateInputSystemByPackProjectDetails.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWizWebhook.model_rebuild() + CreateInputSystemByPackGroups.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputOpenaiContentConfig.model_rebuild() + CreateInputSystemByPackOrganizations.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputOpenai.model_rebuild() + CreateInputSystemByPackOrganizationUsers.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWizContentConfig.model_rebuild() + CreateInputSystemByPackOrganizationRoles.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWiz.model_rebuild() + CreateInputSystemByPackInputAnthropicCompliance.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputJournalFilesRule.model_rebuild() + CreateInputSystemByPackInputOpenaiComplianceLogs.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputJournalFiles.model_rebuild() + CreateInputSystemByPackInputAquaSecurityHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputRawUDP.model_rebuild() + CreateInputSystemByPackInputExtrahopRevealx360.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputAppleUnifiedLogs.model_rebuild() + CreateInputSystemByPackInputSailpointHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWinEventLogs.model_rebuild() + CreateInputSystemByPackInputTrellixHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackMTLSSettings.model_rebuild() + CreateInputSystemByPackInputUpwindHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackQuery.model_rebuild() + CreateInputSystemByPackInputSysdigHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackSubscription.model_rebuild() + CreateInputSystemByPackTLSSettingsServerSide.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWef.model_rebuild() + CreateInputSystemByPackInputCloudflareHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputAppscopeFilter.model_rebuild() + CreateInputSystemByPackInputZscalerHecAuthToken.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputAppscopePersistence.model_rebuild() + CreateInputSystemByPackInputZscalerHec.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputAppscope.model_rebuild() + CreateInputSystemByPackInputProofpointPod.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputTCP.model_rebuild() + CreateInputSystemByPackInputServicenowTable.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputFile.model_rebuild() + CreateInputSystemByPackInputBedrockS3.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSyslogSyslog2.model_rebuild() + CreateInputSystemByPackInputSecurityLake.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSyslogSyslog1.model_rebuild() + CreateInputSystemByPackInputNetflow.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSqs.model_rebuild() + CreateInputSystemByPackInputWizWebhookAuthTokensExt2.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputModelDrivenTelemetry.model_rebuild() + CreateInputSystemByPackInputWizWebhookAuthTokensExt1.model_rebuild() except NameError: pass try: - CreateInputSystemByPackAuthMethodsExt.model_rebuild() + CreateInputSystemByPackInputWizWebhook.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputOpenTelemetry.model_rebuild() + CreateInputSystemByPackInputOpenaiContentConfig.model_rebuild() except NameError: pass try: - CreateInputSystemByPackV3User.model_rebuild() + CreateInputSystemByPackInputOpenai.model_rebuild() except NameError: pass try: - CreateInputSystemByPackSNMPv3Authentication.model_rebuild() + CreateInputSystemByPackInputWizContentConfig.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputSnmp.model_rebuild() + CreateInputSystemByPackInputWiz.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputS3Inventory.model_rebuild() + CreateInputSystemByPackInputJournalFilesRule.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputS3.model_rebuild() + CreateInputSystemByPackInputJournalFiles.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputMetrics.model_rebuild() + CreateInputSystemByPackInputRawUDP.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputCriblmetrics.model_rebuild() + CreateInputSystemByPackInputAppleUnifiedLogs.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputKinesis.model_rebuild() + CreateInputSystemByPackInputWinEventLogs.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputHTTPRaw.model_rebuild() + CreateInputSystemByPackMTLSSettings.model_rebuild() except NameError: pass try: - CreateInputSystemByPackSample.model_rebuild() + CreateInputSystemByPackQuery.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputDatagen.model_rebuild() + CreateInputSystemByPackSubscription.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputDatadogAgentProxyMode.model_rebuild() + CreateInputSystemByPackInputWef.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputDatadogAgent.model_rebuild() + CreateInputSystemByPackInputAppscopeFilter.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputCrowdstrike.model_rebuild() + CreateInputSystemByPackInputAppscopePersistence.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWindowsMetricsCPU.model_rebuild() + CreateInputSystemByPackInputAppscope.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWindowsMetricsNetwork.model_rebuild() + CreateInputSystemByPackInputTCP.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWindowsMetricsDisk.model_rebuild() + CreateInputSystemByPackInputFile.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWindowsMetricsPersistence.model_rebuild() + CreateInputSystemByPackInputSyslogSyslog2.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputWindowsMetrics.model_rebuild() + CreateInputSystemByPackInputSyslogSyslog1.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputKubeEvents.model_rebuild() + CreateInputSystemByPackInputSqs.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputKubeLogsRule.model_rebuild() + CreateInputSystemByPackInputModelDrivenTelemetry.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputKubeLogs.model_rebuild() + CreateInputSystemByPackAuthMethodsExt.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputKubeMetricsPersistence.model_rebuild() + CreateInputSystemByPackInputOpenTelemetry.model_rebuild() except NameError: pass try: - CreateInputSystemByPackInputKubeMetrics.model_rebuild() + CreateInputSystemByPackV3User.model_rebuild() except NameError: pass diff --git a/src/cribl_control_plane/models/createoutput_output.py b/src/cribl_control_plane/models/createoutput_output.py index 534623077..e5c22a9b2 100644 --- a/src/cribl_control_plane/models/createoutput_output.py +++ b/src/cribl_control_plane/models/createoutput_output.py @@ -1,7 +1,99 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .createoutput_outputdefault_type import ( +from .backpressurebehavioroptions import BackpressureBehaviorOptions +from .compressionoptionspq import CompressionOptionsPq +from .createoutput_outputsns_pqcontrols import ( + CreateOutputOutputAlibabaCloudS3, + CreateOutputOutputAlibabaCloudS3TypedDict, + CreateOutputOutputAlphasocS3, + CreateOutputOutputAlphasocS3TypedDict, + CreateOutputOutputAmazonManagedPrometheus, + CreateOutputOutputAmazonManagedPrometheusTypedDict, + CreateOutputOutputChronicle, + CreateOutputOutputChronicleTypedDict, + CreateOutputOutputClickHouse, + CreateOutputOutputClickHouseTypedDict, + CreateOutputOutputCloudflareR2, + CreateOutputOutputCloudflareR2TypedDict, + CreateOutputOutputCloudianS3, + CreateOutputOutputCloudianS3TypedDict, + CreateOutputOutputCriblHTTP, + CreateOutputOutputCriblHTTPTypedDict, + CreateOutputOutputCriblLake, + CreateOutputOutputCriblLakeTypedDict, + CreateOutputOutputCriblSearchEngine, + CreateOutputOutputCriblSearchEngineTypedDict, + CreateOutputOutputCriblTCP, + CreateOutputOutputCriblTCPTypedDict, + CreateOutputOutputCrowdstrikeNextGenSiem, + CreateOutputOutputCrowdstrikeNextGenSiemTypedDict, + CreateOutputOutputCustomerMetricsStorage, + CreateOutputOutputCustomerMetricsStorageTypedDict, + CreateOutputOutputDatabricks, + CreateOutputOutputDatabricksTypedDict, + CreateOutputOutputDatabricksZerobus, + CreateOutputOutputDatabricksZerobusTypedDict, + CreateOutputOutputDatadog, + CreateOutputOutputDatadogTypedDict, + CreateOutputOutputDataset, + CreateOutputOutputDatasetTypedDict, + CreateOutputOutputDellS3, + CreateOutputOutputDellS3TypedDict, + CreateOutputOutputDiskSpool, + CreateOutputOutputDiskSpoolTypedDict, + CreateOutputOutputDlS3, + CreateOutputOutputDlS3TypedDict, + CreateOutputOutputDynatraceHTTP, + CreateOutputOutputDynatraceHTTPTypedDict, + CreateOutputOutputDynatraceOtlp, + CreateOutputOutputDynatraceOtlpTypedDict, + CreateOutputOutputGrafanaCloudUnion, + CreateOutputOutputGrafanaCloudUnionTypedDict, + CreateOutputOutputHumioHec, + CreateOutputOutputHumioHecTypedDict, + CreateOutputOutputIbmCloudS3, + CreateOutputOutputIbmCloudS3TypedDict, + CreateOutputOutputLocalSearchStorage, + CreateOutputOutputLocalSearchStorageTypedDict, + CreateOutputOutputLoki, + CreateOutputOutputLokiTypedDict, + CreateOutputOutputMicrosoftFabric, + CreateOutputOutputMicrosoftFabricTypedDict, + CreateOutputOutputNetflow, + CreateOutputOutputNetflowTypedDict, + CreateOutputOutputNutanixObjects, + CreateOutputOutputNutanixObjectsTypedDict, + CreateOutputOutputOpenTelemetry, + CreateOutputOutputOpenTelemetryTypedDict, + CreateOutputOutputPrometheus, + CreateOutputOutputPrometheusTypedDict, + CreateOutputOutputRing, + CreateOutputOutputRingTypedDict, + CreateOutputOutputScalityS3, + CreateOutputOutputScalityS3TypedDict, + CreateOutputOutputSecurityLake, + CreateOutputOutputSecurityLakeTypedDict, + CreateOutputOutputSentinelOneAiSiem, + CreateOutputOutputSentinelOneAiSiemTypedDict, + CreateOutputOutputServiceNow, + CreateOutputOutputServiceNowTypedDict, + CreateOutputOutputSnmp, + CreateOutputOutputSnmpTypedDict, + CreateOutputOutputSnowflakeStreaming, + CreateOutputOutputSnowflakeStreamingTypedDict, + CreateOutputOutputSqs, + CreateOutputOutputSqsTypedDict, + CreateOutputOutputStorjS3, + CreateOutputOutputStorjS3TypedDict, + CreateOutputOutputSumoLogic, + CreateOutputOutputSumoLogicTypedDict, + CreateOutputOutputTraversalOtlp, + CreateOutputOutputTraversalOtlpTypedDict, + CreateOutputOutputXsiam, + CreateOutputOutputXsiamTypedDict, +) +from .createoutput_outputwebhook_format_2 import ( CreateOutputOutputAzureBlob, CreateOutputOutputAzureBlobTypedDict, CreateOutputOutputAzureDataExplorer, @@ -14,7 +106,6 @@ CreateOutputOutputCloudwatchTypedDict, CreateOutputOutputConfluentCloud, CreateOutputOutputConfluentCloudTypedDict, - CreateOutputOutputDefaultType, CreateOutputOutputDevnull, CreateOutputOutputDevnullTypedDict, CreateOutputOutputElastic, @@ -37,6 +128,8 @@ CreateOutputOutputGoogleCloudStorageTypedDict, CreateOutputOutputGooglePubsub, CreateOutputOutputGooglePubsubTypedDict, + CreateOutputOutputGraphite, + CreateOutputOutputGraphiteTypedDict, CreateOutputOutputHoneycomb, CreateOutputOutputHoneycombTypedDict, CreateOutputOutputInfluxdb, @@ -53,12 +146,16 @@ CreateOutputOutputNewrelicEvents, CreateOutputOutputNewrelicEventsTypedDict, CreateOutputOutputNewrelicTypedDict, + CreateOutputOutputRouter, + CreateOutputOutputRouterTypedDict, CreateOutputOutputS3, CreateOutputOutputS3TypedDict, CreateOutputOutputSentinel, CreateOutputOutputSentinelTypedDict, CreateOutputOutputSignalfx, CreateOutputOutputSignalfxTypedDict, + CreateOutputOutputSns, + CreateOutputOutputSnsTypedDict, CreateOutputOutputSplunk, CreateOutputOutputSplunkHec, CreateOutputOutputSplunkHecTypedDict, @@ -75,109 +172,1603 @@ CreateOutputOutputTcpjsonTypedDict, CreateOutputOutputWavefront, CreateOutputOutputWavefrontTypedDict, - CreateOutputOutputWebhookUnion, - CreateOutputOutputWebhookUnionTypedDict, + CreateOutputOutputWebhookFormat2, + CreateOutputOutputWebhookType2, CreateOutputOutputWizHec, CreateOutputOutputWizHecTypedDict, ) -from .createoutput_outputstatsdext_type import ( - CreateOutputOutputAlibabaCloudS3, - CreateOutputOutputAlibabaCloudS3TypedDict, - CreateOutputOutputAlphasocS3, - CreateOutputOutputAlphasocS3TypedDict, - CreateOutputOutputAmazonManagedPrometheus, - CreateOutputOutputAmazonManagedPrometheusTypedDict, - CreateOutputOutputChronicle, - CreateOutputOutputChronicleTypedDict, - CreateOutputOutputClickHouse, - CreateOutputOutputClickHouseTypedDict, - CreateOutputOutputCloudflareR2, - CreateOutputOutputCloudflareR2TypedDict, - CreateOutputOutputCloudianS3, - CreateOutputOutputCloudianS3TypedDict, - CreateOutputOutputCriblHTTP, - CreateOutputOutputCriblHTTPTypedDict, - CreateOutputOutputCriblLake, - CreateOutputOutputCriblLakeTypedDict, - CreateOutputOutputCriblSearchEngine, - CreateOutputOutputCriblSearchEngineTypedDict, - CreateOutputOutputCriblTCP, - CreateOutputOutputCriblTCPTypedDict, - CreateOutputOutputCrowdstrikeNextGenSiem, - CreateOutputOutputCrowdstrikeNextGenSiemTypedDict, - CreateOutputOutputCustomerMetricsStorage, - CreateOutputOutputCustomerMetricsStorageTypedDict, - CreateOutputOutputDatabricks, - CreateOutputOutputDatabricksTypedDict, - CreateOutputOutputDatadog, - CreateOutputOutputDatadogTypedDict, - CreateOutputOutputDataset, - CreateOutputOutputDatasetTypedDict, - CreateOutputOutputDellS3, - CreateOutputOutputDellS3TypedDict, - CreateOutputOutputDiskSpool, - CreateOutputOutputDiskSpoolTypedDict, - CreateOutputOutputDlS3, - CreateOutputOutputDlS3TypedDict, - CreateOutputOutputDynatraceHTTP, - CreateOutputOutputDynatraceHTTPTypedDict, - CreateOutputOutputDynatraceOtlp, - CreateOutputOutputDynatraceOtlpTypedDict, - CreateOutputOutputGrafanaCloudUnion, - CreateOutputOutputGrafanaCloudUnionTypedDict, - CreateOutputOutputGraphite, - CreateOutputOutputGraphiteTypedDict, - CreateOutputOutputHumioHec, - CreateOutputOutputHumioHecTypedDict, - CreateOutputOutputIbmCloudS3, - CreateOutputOutputIbmCloudS3TypedDict, - CreateOutputOutputLocalSearchStorage, - CreateOutputOutputLocalSearchStorageTypedDict, - CreateOutputOutputLoki, - CreateOutputOutputLokiTypedDict, - CreateOutputOutputMicrosoftFabric, - CreateOutputOutputMicrosoftFabricTypedDict, - CreateOutputOutputNetflow, - CreateOutputOutputNetflowTypedDict, - CreateOutputOutputNutanixObjects, - CreateOutputOutputNutanixObjectsTypedDict, - CreateOutputOutputOpenTelemetry, - CreateOutputOutputOpenTelemetryTypedDict, - CreateOutputOutputPrometheus, - CreateOutputOutputPrometheusTypedDict, - CreateOutputOutputRing, - CreateOutputOutputRingTypedDict, - CreateOutputOutputRouter, - CreateOutputOutputRouterTypedDict, - CreateOutputOutputScalityS3, - CreateOutputOutputScalityS3TypedDict, - CreateOutputOutputSecurityLake, - CreateOutputOutputSecurityLakeTypedDict, - CreateOutputOutputSentinelOneAiSiem, - CreateOutputOutputSentinelOneAiSiemTypedDict, - CreateOutputOutputServiceNow, - CreateOutputOutputServiceNowTypedDict, - CreateOutputOutputSnmp, - CreateOutputOutputSnmpTypedDict, - CreateOutputOutputSnowflakeStreaming, - CreateOutputOutputSnowflakeStreamingTypedDict, - CreateOutputOutputSns, - CreateOutputOutputSnsTypedDict, - CreateOutputOutputSqs, - CreateOutputOutputSqsTypedDict, - CreateOutputOutputStorjS3, - CreateOutputOutputStorjS3TypedDict, - CreateOutputOutputSumoLogic, - CreateOutputOutputSumoLogicTypedDict, - CreateOutputOutputXsiam, - CreateOutputOutputXsiamTypedDict, +from .extrahttpheaderconfinputelastic import ( + ExtraHTTPHeaderConfInputElastic, + ExtraHTTPHeaderConfInputElasticTypedDict, +) +from .failedrequestloggingmodeoptions import FailedRequestLoggingModeOptions +from .methodoptions import MethodOptions +from .modeoptions import ModeOptions +from .oauthheaderconfinputservicenowtable import ( + OauthHeaderConfInputServicenowTable, + OauthHeaderConfInputServicenowTableTypedDict, +) +from .oauthparamconfinputservicenowtable import ( + OauthParamConfInputServicenowTable, + OauthParamConfInputServicenowTableTypedDict, +) +from .queuefullbehavioroptions import QueueFullBehaviorOptions +from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( + RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, +) +from .responseretrysettingconfoutputwebhook import ( + ResponseRetrySettingConfOutputWebhook, + ResponseRetrySettingConfOutputWebhookTypedDict, +) +from .timeoutretrysettingstype import ( + TimeoutRetrySettingsType, + TimeoutRetrySettingsTypeTypedDict, +) +from .tlssettingsclientsidetypecapathcertpathextended import ( + TLSSettingsClientSideTypeCaPathCertPathExtended, + TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict, +) +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, Nullable, UNSET_SENTINEL +from cribl_control_plane.utils import get_discriminator +from enum import Enum +import pydantic +from pydantic import Discriminator, Tag, field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class CreateOutputOutputWebhookAuthenticationType2( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method to use for the HTTP request""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth + OAUTH = "oauth" + + +class CreateOutputOutputWebhookPqControls2TypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputWebhookPqControls2(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputWebhookURL2TypedDict(TypedDict): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputOutputWebhookURL2(BaseModel): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputWebhookWebhook2TypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputWebhookType2 + r"""Connector type identifier.""" + urls: List[CreateOutputOutputWebhookURL2TypedDict] + r"""Webhook URLs""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + format_: NotRequired[CreateOutputOutputWebhookFormat2] + r"""How to format events before sending out""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[CreateOutputOutputWebhookAuthenticationType2] + r"""Authentication method to use for the HTTP request""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_source_expression: NotRequired[str] + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + custom_drop_when_null: NotRequired[bool] + r"""Whether to drop events when the source expression evaluates to null""" + custom_event_delimiter: NotRequired[str] + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + custom_content_type: NotRequired[str] + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + custom_payload_expression: NotRequired[str] + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + advanced_content_type: NotRequired[str] + r"""HTTP content-type header value""" + format_event_code: NotRequired[str] + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + format_payload_code: NotRequired[str] + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputWebhookPqControls2TypedDict] + r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + secret: NotRequired[str] + r"""Secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + url: NotRequired[str] + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_refresh_url: NotRequired[str] + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputOutputWebhookWebhook2(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputOutputWebhookType2 + r"""Connector type identifier.""" + + urls: List[CreateOutputOutputWebhookURL2] + r"""Webhook URLs""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + format_: Annotated[ + Optional[CreateOutputOutputWebhookFormat2], pydantic.Field(alias="format") + ] = None + r"""How to format events before sending out""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[CreateOutputOutputWebhookAuthenticationType2], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method to use for the HTTP request""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_source_expression: Annotated[ + Optional[str], pydantic.Field(alias="customSourceExpression") + ] = None + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + + custom_drop_when_null: Annotated[ + Optional[bool], pydantic.Field(alias="customDropWhenNull") + ] = None + r"""Whether to drop events when the source expression evaluates to null""" + + custom_event_delimiter: Annotated[ + Optional[str], pydantic.Field(alias="customEventDelimiter") + ] = None + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + + custom_content_type: Annotated[ + Optional[str], pydantic.Field(alias="customContentType") + ] = None + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + + custom_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="customPayloadExpression") + ] = None + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + + advanced_content_type: Annotated[ + Optional[str], pydantic.Field(alias="advancedContentType") + ] = None + r"""HTTP content-type header value""" + + format_event_code: Annotated[ + Optional[str], pydantic.Field(alias="formatEventCode") + ] = None + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + format_payload_code: Annotated[ + Optional[str], pydantic.Field(alias="formatPayloadCode") + ] = None + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[CreateOutputOutputWebhookPqControls2], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + secret: Optional[str] = None + r"""Secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + url: Optional[str] = None + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + + template_refresh_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_refreshUrl") + ] = None + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputWebhookFormat2(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputWebhookAuthenticationType2(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "method", + "format", + "keepAlive", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "tls", + "totalMemoryLimitKB", + "loadBalanced", + "description", + "customSourceExpression", + "customDropWhenNull", + "customEventDelimiter", + "customContentType", + "customPayloadExpression", + "advancedContentType", + "formatEventCode", + "formatPayloadCode", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "secret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "url", + "excludeSelf", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "__template_streamtags", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "__template_loginUrl", + "__template_secret", + "__template_refreshUrl", + "__template_url", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputWebhookType1(str, Enum): + r"""Connector type identifier.""" + + WEBHOOK = "webhook" + + +class CreateOutputOutputWebhookFormat1(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How to format events before sending out""" + + # NDJSON (Newline Delimited JSON) + NDJSON = "ndjson" + # JSON Array + JSON_ARRAY = "json_array" + # Custom + CUSTOM = "custom" + # Advanced + ADVANCED = "advanced" + + +class CreateOutputOutputWebhookAuthenticationType1( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method to use for the HTTP request""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth + OAUTH = "oauth" + + +class CreateOutputOutputWebhookPqControls1TypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputWebhookPqControls1(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputWebhookURL1TypedDict(TypedDict): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputOutputWebhookURL1(BaseModel): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputWebhookWebhook1TypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputWebhookType1 + r"""Connector type identifier.""" + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + format_: NotRequired[CreateOutputOutputWebhookFormat1] + r"""How to format events before sending out""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[CreateOutputOutputWebhookAuthenticationType1] + r"""Authentication method to use for the HTTP request""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_source_expression: NotRequired[str] + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + custom_drop_when_null: NotRequired[bool] + r"""Whether to drop events when the source expression evaluates to null""" + custom_event_delimiter: NotRequired[str] + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + custom_content_type: NotRequired[str] + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + custom_payload_expression: NotRequired[str] + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + advanced_content_type: NotRequired[str] + r"""HTTP content-type header value""" + format_event_code: NotRequired[str] + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + format_payload_code: NotRequired[str] + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputWebhookPqControls1TypedDict] + r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + secret: NotRequired[str] + r"""Secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputOutputWebhookURL1TypedDict]] + r"""Webhook URLs""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_refresh_url: NotRequired[str] + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputOutputWebhookWebhook1(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputOutputWebhookType1 + r"""Connector type identifier.""" + + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + format_: Annotated[ + Optional[CreateOutputOutputWebhookFormat1], pydantic.Field(alias="format") + ] = None + r"""How to format events before sending out""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[CreateOutputOutputWebhookAuthenticationType1], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method to use for the HTTP request""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_source_expression: Annotated[ + Optional[str], pydantic.Field(alias="customSourceExpression") + ] = None + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + + custom_drop_when_null: Annotated[ + Optional[bool], pydantic.Field(alias="customDropWhenNull") + ] = None + r"""Whether to drop events when the source expression evaluates to null""" + + custom_event_delimiter: Annotated[ + Optional[str], pydantic.Field(alias="customEventDelimiter") + ] = None + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + + custom_content_type: Annotated[ + Optional[str], pydantic.Field(alias="customContentType") + ] = None + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + + custom_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="customPayloadExpression") + ] = None + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + + advanced_content_type: Annotated[ + Optional[str], pydantic.Field(alias="advancedContentType") + ] = None + r"""HTTP content-type header value""" + + format_event_code: Annotated[ + Optional[str], pydantic.Field(alias="formatEventCode") + ] = None + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + format_payload_code: Annotated[ + Optional[str], pydantic.Field(alias="formatPayloadCode") + ] = None + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[CreateOutputOutputWebhookPqControls1], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + secret: Optional[str] = None + r"""Secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[CreateOutputOutputWebhookURL1]] = None + r"""Webhook URLs""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + + template_refresh_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_refreshUrl") + ] = None + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputWebhookFormat1(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputWebhookAuthenticationType1(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "method", + "format", + "keepAlive", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "tls", + "totalMemoryLimitKB", + "loadBalanced", + "description", + "customSourceExpression", + "customDropWhenNull", + "customEventDelimiter", + "customContentType", + "customPayloadExpression", + "advancedContentType", + "formatEventCode", + "formatPayloadCode", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "secret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "__template_streamtags", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "__template_loginUrl", + "__template_secret", + "__template_refreshUrl", + "__template_url", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateOutputOutputWebhookUnionTypedDict = TypeAliasType( + "CreateOutputOutputWebhookUnionTypedDict", + Union[ + CreateOutputOutputWebhookWebhook1TypedDict, + CreateOutputOutputWebhookWebhook2TypedDict, + ], +) + + +CreateOutputOutputWebhookUnion = TypeAliasType( + "CreateOutputOutputWebhookUnion", + Union[CreateOutputOutputWebhookWebhook1, CreateOutputOutputWebhookWebhook2], ) -from cribl_control_plane.types import BaseModel, Nullable, UNSET_SENTINEL -from cribl_control_plane.utils import get_discriminator -import pydantic -from pydantic import Discriminator, Tag, model_serializer -from typing import List, Optional, Union -from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class CreateOutputOutputDefaultType(str, Enum): + r"""Connector type identifier.""" + + DEFAULT = "default" class CreateOutputOutputDefaultTypedDict(TypedDict): @@ -268,78 +1859,80 @@ def serialize_model(self, handler): CreateOutputOutputDevnullTypedDict, CreateOutputOutputDefaultTypedDict, CreateOutputOutputRouterTypedDict, - CreateOutputOutputNetflowTypedDict, CreateOutputOutputSnmpTypedDict, + CreateOutputOutputNetflowTypedDict, CreateOutputOutputDiskSpoolTypedDict, CreateOutputOutputRingTypedDict, - CreateOutputOutputStatsdExtTypedDict, - CreateOutputOutputStatsdTypedDict, CreateOutputOutputGraphiteTypedDict, + CreateOutputOutputStatsdTypedDict, + CreateOutputOutputStatsdExtTypedDict, + CreateOutputOutputDatabricksZerobusTypedDict, CreateOutputOutputGoogleBigqueryTypedDict, CreateOutputOutputGooglePubsubTypedDict, CreateOutputOutputCriblTCPTypedDict, - CreateOutputOutputAzureEventhubTypedDict, CreateOutputOutputWavefrontTypedDict, - CreateOutputOutputSignalfxTypedDict, CreateOutputOutputGoogleCloudObservabilityTypedDict, - CreateOutputOutputMicrosoftFabricTypedDict, + CreateOutputOutputSignalfxTypedDict, CreateOutputOutputHoneycombTypedDict, - CreateOutputOutputExabeamTypedDict, + CreateOutputOutputAzureEventhubTypedDict, + CreateOutputOutputMicrosoftFabricTypedDict, CreateOutputOutputTcpjsonTypedDict, CreateOutputOutputSplunkTypedDict, - CreateOutputOutputSumoLogicTypedDict, - CreateOutputOutputCrowdstrikeNextGenSiemTypedDict, CreateOutputOutputHumioHecTypedDict, + CreateOutputOutputCrowdstrikeNextGenSiemTypedDict, + CreateOutputOutputSumoLogicTypedDict, CreateOutputOutputSnsTypedDict, CreateOutputOutputKafkaTypedDict, CreateOutputOutputElasticCloudTypedDict, - CreateOutputOutputCloudwatchTypedDict, - CreateOutputOutputSyslogTypedDict, - CreateOutputOutputAzureLogsTypedDict, CreateOutputOutputConfluentCloudTypedDict, CreateOutputOutputSplunkLbTypedDict, - CreateOutputOutputWizHecTypedDict, - CreateOutputOutputNewrelicEventsTypedDict, + CreateOutputOutputSyslogTypedDict, + CreateOutputOutputAzureLogsTypedDict, + CreateOutputOutputCloudwatchTypedDict, CreateOutputOutputKinesisTypedDict, - CreateOutputOutputCriblSearchEngineTypedDict, + CreateOutputOutputExabeamTypedDict, + CreateOutputOutputNewrelicEventsTypedDict, CreateOutputOutputNewrelicTypedDict, CreateOutputOutputCriblHTTPTypedDict, - CreateOutputOutputXsiamTypedDict, - CreateOutputOutputDatasetTypedDict, CreateOutputOutputLokiTypedDict, + CreateOutputOutputDatasetTypedDict, + CreateOutputOutputWizHecTypedDict, + CreateOutputOutputXsiamTypedDict, CreateOutputOutputDynatraceHTTPTypedDict, - CreateOutputOutputSplunkHecTypedDict, + CreateOutputOutputCriblSearchEngineTypedDict, CreateOutputOutputFilesystemTypedDict, + CreateOutputOutputSplunkHecTypedDict, CreateOutputOutputSqsTypedDict, - CreateOutputOutputCriblLakeTypedDict, CreateOutputOutputDynatraceOtlpTypedDict, CreateOutputOutputSnowflakeStreamingTypedDict, CreateOutputOutputServiceNowTypedDict, + CreateOutputOutputAmazonManagedPrometheusTypedDict, CreateOutputOutputDatadogTypedDict, CreateOutputOutputInfluxdbTypedDict, - CreateOutputOutputAmazonManagedPrometheusTypedDict, + CreateOutputOutputCriblLakeTypedDict, CreateOutputOutputGoogleChronicleTypedDict, CreateOutputOutputElasticTypedDict, CreateOutputOutputSentinelOneAiSiemTypedDict, + CreateOutputOutputClickHouseTypedDict, CreateOutputOutputCustomerMetricsStorageTypedDict, CreateOutputOutputChronicleTypedDict, - CreateOutputOutputClickHouseTypedDict, CreateOutputOutputLocalSearchStorageTypedDict, CreateOutputOutputPrometheusTypedDict, + CreateOutputOutputTraversalOtlpTypedDict, CreateOutputOutputDatabricksTypedDict, CreateOutputOutputAlphasocS3TypedDict, CreateOutputOutputMskTypedDict, - CreateOutputOutputStorjS3TypedDict, CreateOutputOutputIbmCloudS3TypedDict, + CreateOutputOutputStorjS3TypedDict, CreateOutputOutputNutanixObjectsTypedDict, CreateOutputOutputScalityS3TypedDict, CreateOutputOutputOpenTelemetryTypedDict, CreateOutputOutputDellS3TypedDict, CreateOutputOutputCloudflareR2TypedDict, - CreateOutputOutputSentinelTypedDict, CreateOutputOutputAlibabaCloudS3TypedDict, CreateOutputOutputGoogleCloudStorageTypedDict, CreateOutputOutputAzureBlobTypedDict, + CreateOutputOutputSentinelTypedDict, CreateOutputOutputCloudianS3TypedDict, CreateOutputOutputMinioTypedDict, CreateOutputOutputSecurityLakeTypedDict, @@ -347,8 +1940,8 @@ def serialize_model(self, handler): CreateOutputOutputDlS3TypedDict, CreateOutputOutputS3TypedDict, CreateOutputOutputAzureDataExplorerTypedDict, - CreateOutputOutputWebhookUnionTypedDict, CreateOutputOutputGrafanaCloudUnionTypedDict, + CreateOutputOutputWebhookUnionTypedDict, ], ) r"""Output object.""" @@ -435,6 +2028,7 @@ def serialize_model(self, handler): Annotated[CreateOutputOutputNetflow, Tag("netflow")], Annotated[CreateOutputOutputDynatraceHTTP, Tag("dynatrace_http")], Annotated[CreateOutputOutputDynatraceOtlp, Tag("dynatrace_otlp")], + Annotated[CreateOutputOutputTraversalOtlp, Tag("traversal_otlp")], Annotated[CreateOutputOutputSentinelOneAiSiem, Tag("sentinel_one_ai_siem")], Annotated[CreateOutputOutputChronicle, Tag("chronicle")], Annotated[CreateOutputOutputDatabricks, Tag("databricks")], @@ -449,12 +2043,29 @@ def serialize_model(self, handler): Annotated[CreateOutputOutputScalityS3, Tag("scality_s3")], Annotated[CreateOutputOutputAlibabaCloudS3, Tag("alibaba_cloud_s3")], Annotated[CreateOutputOutputIbmCloudS3, Tag("ibm_cloud_s3")], + Annotated[CreateOutputOutputDatabricksZerobus, Tag("databricks_zerobus")], ], Discriminator(lambda m: get_discriminator(m, "type", "type")), ] r"""Output object.""" +try: + CreateOutputOutputWebhookURL2.model_rebuild() +except NameError: + pass +try: + CreateOutputOutputWebhookWebhook2.model_rebuild() +except NameError: + pass +try: + CreateOutputOutputWebhookURL1.model_rebuild() +except NameError: + pass +try: + CreateOutputOutputWebhookWebhook1.model_rebuild() +except NameError: + pass try: CreateOutputOutputDefault.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/createoutput_outputstatsdext_type.py b/src/cribl_control_plane/models/createoutput_outputsns_pqcontrols.py similarity index 97% rename from src/cribl_control_plane/models/createoutput_outputstatsdext_type.py rename to src/cribl_control_plane/models/createoutput_outputsns_pqcontrols.py index 111f48c41..6bb136926 100644 --- a/src/cribl_control_plane/models/createoutput_outputstatsdext_type.py +++ b/src/cribl_control_plane/models/createoutput_outputsns_pqcontrols.py @@ -4,8 +4,8 @@ from .acknowledgmentsoptions import AcknowledgmentsOptions from .authenticationmethodoptionsapi import AuthenticationMethodOptionsAPI from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionsautosecret import AuthenticationMethodOptionsAutoSecret from .authenticationmethodoptionss3collectorconf import ( @@ -42,7 +42,6 @@ ) from .dataformatoptions import DataFormatOptions from .datapageversionoptions import DataPageVersionOptions -from .destinationprotocoloptions import DestinationProtocolOptions from .diskspaceprotectionoptions import DiskSpaceProtectionOptions from .extrahttpheaderconfinputelastic import ( ExtraHTTPHeaderConfInputElastic, @@ -143,6 +142,323 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict +class CreateOutputOutputDatabricksZerobusType(str, Enum): + r"""Connector type identifier.""" + + DATABRICKS_ZEROBUS = "databricks_zerobus" + + +class CreateOutputOutputDatabricksZerobusPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputDatabricksZerobusPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputDatabricksZerobusTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputDatabricksZerobusType + r"""Connector type identifier.""" + workspace_url: str + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" + workspace_id: str + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" + zerobus_endpoint: str + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + client_id: str + r"""OAuth client ID of the service principal authorized to write to the target table""" + client_text_secret: str + r"""OAuth client secret of the service principal""" + table_name: str + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + max_batch_size_kb: NotRequired[int] + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" + max_batch_records: NotRequired[int] + r"""Maximum number of records to include in a single ingest batch""" + max_buffered_kb: NotRequired[int] + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" + max_inflight_batches: NotRequired[int] + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" + flush_period_sec: NotRequired[int] + r"""Maximum time, in seconds, to hold a batch before sending it""" + ack_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" + connection_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputDatabricksZerobusPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + +class CreateOutputOutputDatabricksZerobus(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputOutputDatabricksZerobusType + r"""Connector type identifier.""" + + workspace_url: Annotated[str, pydantic.Field(alias="workspaceUrl")] + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" + + workspace_id: Annotated[str, pydantic.Field(alias="workspaceId")] + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" + + zerobus_endpoint: Annotated[str, pydantic.Field(alias="zerobusEndpoint")] + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""OAuth client ID of the service principal authorized to write to the target table""" + + client_text_secret: Annotated[str, pydantic.Field(alias="clientTextSecret")] + r"""OAuth client secret of the service principal""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + max_batch_size_kb: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchSizeKB") + ] = None + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" + + max_batch_records: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchRecords") + ] = None + r"""Maximum number of records to include in a single ingest batch""" + + max_buffered_kb: Annotated[Optional[int], pydantic.Field(alias="maxBufferedKB")] = ( + None + ) + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" + + max_inflight_batches: Annotated[ + Optional[int], pydantic.Field(alias="maxInflightBatches") + ] = None + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" + + flush_period_sec: Annotated[ + Optional[int], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time, in seconds, to hold a batch before sending it""" + + ack_timeout_sec: Annotated[Optional[int], pydantic.Field(alias="ackTimeoutSec")] = ( + None + ) + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" + + connection_timeout_sec: Annotated[ + Optional[int], pydantic.Field(alias="connectionTimeoutSec") + ] = None + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[CreateOutputOutputDatabricksZerobusPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "maxBatchSizeKB", + "maxBatchRecords", + "maxBufferedKB", + "maxInflightBatches", + "flushPeriodSec", + "ackTimeoutSec", + "connectionTimeoutSec", + "onBackpressure", + "description", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_onBackpressure", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + class CreateOutputOutputIbmCloudS3Type(str, Enum): r"""Connector type identifier.""" @@ -7952,7 +8268,7 @@ class CreateOutputOutputSentinelOneAiSiemTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -8113,7 +8429,7 @@ class CreateOutputOutputSentinelOneAiSiem(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -8295,7 +8611,7 @@ def serialize_failed_request_logging_mode(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -8427,51 +8743,42 @@ def serialize_model(self, handler): return m -class CreateOutputOutputDynatraceOtlpType(str, Enum): +class CreateOutputOutputTraversalOtlpType(str, Enum): r"""Connector type identifier.""" - DYNATRACE_OTLP = "dynatrace_otlp" + TRAVERSAL_OTLP = "traversal_otlp" -class CreateOutputOutputDynatraceOtlpProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select a transport option for Dynatrace""" - - # HTTP - HTTP = "http" - - -class CreateOutputEndpointType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the type of Dynatrace endpoint configured""" +class CreateOutputOutputTraversalOtlpAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" - # SaaS - SAAS = "saas" - # ActiveGate - AG = "ag" + # None + NONE = "none" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth (text secret) + OAUTH_SECRET = "oauthSecret" -class CreateOutputOutputDynatraceOtlpPqControlsTypedDict(TypedDict): +class CreateOutputOutputTraversalOtlpPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputDynatraceOtlpPqControls(BaseModel): +class CreateOutputOutputTraversalOtlpPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): +class CreateOutputOutputTraversalOtlpTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDynatraceOtlpType + type: CreateOutputOutputTraversalOtlpType r"""Connector type identifier.""" - protocol: CreateOutputOutputDynatraceOtlpProtocol - r"""Select a transport option for Dynatrace""" endpoint: str - r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - otlp_version: OtlpVersionOptions - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - endpoint_type: CreateOutputEndpointType - r"""Select the type of Dynatrace endpoint configured""" - token_secret: str - r"""Select or create a stored text secret""" + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -8480,16 +8787,16 @@ class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + auth_type: NotRequired[CreateOutputOutputTraversalOtlpAuthenticationType] + r"""Authentication type""" + protocol: NotRequired[ProtocolOptions] + r"""Select a transport option for OpenTelemetry""" preserve_native_any_value: NotRequired[bool] r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" compress: NotRequired[CompressionOptionsDeflateGzip] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" http_compress: NotRequired[CompressionOptionsMessages] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: NotRequired[str] - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_metrics_endpoint_override: NotRequired[str] - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" http_logs_endpoint_override: NotRequired[str] r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] @@ -8501,7 +8808,7 @@ class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" + r"""Maximum size, in KB, of the request body""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] @@ -8516,12 +8823,30 @@ class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): r"""How often the sender should ping the peer to keep the connection open""" keep_alive: NotRequired[bool] r"""Disable to close the connection immediately after sending the outgoing request""" - auth_token_name: NotRequired[str] - r"""Api-Token name""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -8540,6 +8865,8 @@ class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -8562,7 +8889,7 @@ class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputDynatraceOtlpPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputTraversalOtlpPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -8570,31 +8897,19 @@ class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" -class CreateOutputOutputDynatraceOtlp(BaseModel): +class CreateOutputOutputTraversalOtlp(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDynatraceOtlpType + type: CreateOutputOutputTraversalOtlpType r"""Connector type identifier.""" - protocol: CreateOutputOutputDynatraceOtlpProtocol - r"""Select a transport option for Dynatrace""" - endpoint: str - r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - - otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - - endpoint_type: Annotated[ - CreateOutputEndpointType, pydantic.Field(alias="endpointType") - ] - r"""Select the type of Dynatrace endpoint configured""" - - token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] - r"""Select or create a stored text secret""" + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -8610,6 +8925,15 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + auth_type: Annotated[ + Optional[CreateOutputOutputTraversalOtlpAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + + protocol: Optional[ProtocolOptions] = None + r"""Select a transport option for OpenTelemetry""" + preserve_native_any_value: Annotated[ Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") ] = None @@ -8623,16 +8947,6 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): ] = None r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") - ] = None - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - - http_metrics_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") - ] = None - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: Annotated[ Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") ] = None @@ -8657,7 +8971,7 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" + r"""Maximum size, in KB, of the request body""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -8691,11 +9005,6 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None r"""Disable to close the connection immediately after sending the outgoing request""" - auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( - None - ) - r"""Api-Token name""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None @@ -8704,6 +9013,54 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -8743,6 +9100,9 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -8793,7 +9153,7 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputDynatraceOtlpPqControls], + Optional[CreateOutputOutputTraversalOtlpPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -8813,20 +9173,25 @@ class CreateOutputOutputDynatraceOtlp(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputDynatraceOtlpProtocol(value) + return models.CreateOutputOutputTraversalOtlpAuthenticationType(value) except ValueError: return value return value - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.OtlpVersionOptions(value) + return models.ProtocolOptions(value) except ValueError: return value return value @@ -8858,15 +9223,6 @@ def serialize_failed_request_logging_mode(self, value): return value return value - @field_serializer("endpoint_type") - def serialize_endpoint_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputEndpointType(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -8911,11 +9267,11 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "authType", + "protocol", "preserveNativeAnyValue", "compress", "httpCompress", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", "httpLogsEndpointOverride", "metadata", "dynamicHeadersEnabled", @@ -8929,9 +9285,18 @@ def serialize_model(self, handler): "connectionTimeout", "keepAliveTime", "keepAlive", - "authTokenName", "onBackpressure", "description", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "oauthTextSecret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", "rejectUnauthorized", "useRoundRobinDns", "extraHttpHeaders", @@ -8939,6 +9304,7 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", + "tls", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -8954,6 +9320,7 @@ def serialize_model(self, handler): "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_loginUrl", ] ) serialized = handler(self) @@ -8970,71 +9337,51 @@ def serialize_model(self, handler): return m -class CreateOutputOutputDynatraceHTTPType(str, Enum): +class CreateOutputOutputDynatraceOtlpType(str, Enum): r"""Connector type identifier.""" - DYNATRACE_HTTP = "dynatrace_http" - - -class CreateOutputOutputDynatraceHTTPAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" - - # Auth token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" + DYNATRACE_OTLP = "dynatrace_otlp" -class CreateOutputOutputDynatraceHTTPFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" +class CreateOutputOutputDynatraceOtlpProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select a transport option for Dynatrace""" - # JSON - JSON_ARRAY = "json_array" - # Plaintext - PLAINTEXT = "plaintext" + # HTTP + HTTP = "http" -class CreateOutputOutputDynatraceHTTPEndpoint(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Endpoint""" +class CreateOutputEndpointType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the type of Dynatrace endpoint configured""" - # Cloud - CLOUD = "cloud" + # SaaS + SAAS = "saas" # ActiveGate - ACTIVE_GATE = "activeGate" - # Manual - MANUAL = "manual" - + AG = "ag" -class CreateOutputTelemetryType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Telemetry type""" - # Logs - LOGS = "logs" - # Metrics - METRICS = "metrics" +class CreateOutputOutputDynatraceOtlpPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" -class CreateOutputOutputDynatraceHTTPPqControlsTypedDict(TypedDict): +class CreateOutputOutputDynatraceOtlpPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputDynatraceHTTPPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputDynatraceHTTPTypedDict(TypedDict): +class CreateOutputOutputDynatraceOtlpTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDynatraceHTTPType + type: CreateOutputOutputDynatraceOtlpType r"""Connector type identifier.""" - format_: CreateOutputOutputDynatraceHTTPFormat - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - endpoint: CreateOutputOutputDynatraceHTTPEndpoint - r"""Endpoint""" - telemetry_type: CreateOutputTelemetryType - r"""Telemetry type""" + protocol: CreateOutputOutputDynatraceOtlpProtocol + r"""Select a transport option for Dynatrace""" + endpoint: str + r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + otlp_version: OtlpVersionOptions + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + endpoint_type: CreateOutputEndpointType + r"""Select the type of Dynatrace endpoint configured""" + token_secret: str + r"""Select or create a stored text secret""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9043,35 +9390,57 @@ class CreateOutputOutputDynatraceHTTPTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_traces_endpoint_override: NotRequired[str] + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_metrics_endpoint_override: NotRequired[str] + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + auth_token_name: NotRequired[str] + r"""Api-Token name""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" response_retry_settings: NotRequired[ @@ -9081,14 +9450,6 @@ class CreateOutputOutputDynatraceHTTPTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputOutputDynatraceHTTPAuthenticationType] - r"""Authentication type""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9111,47 +9472,39 @@ class CreateOutputOutputDynatraceHTTPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputDynatraceHTTPPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputDynatraceOtlpPqControlsTypedDict] r"""Persistent queue controls.""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - environment_id: NotRequired[str] - r"""ID of the environment to send to""" - active_gate_domain: NotRequired[str] - r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" - url: NotRequired[str] - r"""URL to send events to. Can be overwritten by an event's __url field.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputDynatraceHTTP(BaseModel): +class CreateOutputOutputDynatraceOtlp(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDynatraceHTTPType + type: CreateOutputOutputDynatraceOtlpType r"""Connector type identifier.""" - format_: Annotated[ - CreateOutputOutputDynatraceHTTPFormat, pydantic.Field(alias="format") - ] - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" + protocol: CreateOutputOutputDynatraceOtlpProtocol + r"""Select a transport option for Dynatrace""" - endpoint: CreateOutputOutputDynatraceHTTPEndpoint - r"""Endpoint""" + endpoint: str + r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - telemetry_type: Annotated[ - CreateOutputTelemetryType, pydantic.Field(alias="telemetryType") + otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + endpoint_type: Annotated[ + CreateOutputEndpointType, pydantic.Field(alias="endpointType") ] - r"""Telemetry type""" + r"""Select the type of Dynatrace endpoint configured""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9167,35 +9520,54 @@ class CreateOutputOutputDynatraceHTTP(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + ] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + http_traces_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") ] = None - r"""Maximum size, in KB, of the request body""" + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + http_metrics_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + ] = None + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Batch event data upon dynamic metadata (whether presented or not)""" + + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") + ] = None + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -9210,22 +9582,56 @@ class CreateOutputOutputDynatraceHTTP(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( + None + ) + r"""Api-Token name""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Headers to add to all events""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") @@ -9247,34 +9653,15 @@ class CreateOutputOutputDynatraceHTTP(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - auth_type: Annotated[ - Optional[CreateOutputOutputDynatraceHTTPAuthenticationType], - pydantic.Field(alias="authType"), + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Authentication type""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" @@ -9316,30 +9703,11 @@ class CreateOutputOutputDynatraceHTTP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputDynatraceHTTPPqControls], + Optional[CreateOutputOutputDynatraceOtlpPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - environment_id: Annotated[Optional[str], pydantic.Field(alias="environmentId")] = ( - None - ) - r"""ID of the environment to send to""" - - active_gate_domain: Annotated[ - Optional[str], pydantic.Field(alias="activeGateDomain") - ] = None - r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" - - url: Optional[str] = None - r"""URL to send events to. Can be overwritten by an event's __url field.""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -9355,70 +9723,65 @@ class CreateOutputOutputDynatraceHTTP(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @field_serializer("method") - def serialize_method(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.CreateOutputOutputDynatraceOtlpProtocol(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OtlpVersionOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptionsDeflateGzip(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("http_compress") + def serialize_http_compress(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputDynatraceHTTPAuthenticationType(value) + return models.CompressionOptionsMessages(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputDynatraceHTTPFormat(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("endpoint") - def serialize_endpoint(self, value): + @field_serializer("endpoint_type") + def serialize_endpoint_type(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputDynatraceHTTPEndpoint(value) + return models.CreateOutputEndpointType(value) except ValueError: return value return value - @field_serializer("telemetry_type") - def serialize_telemetry_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputTelemetryType(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -9458,27 +9821,34 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "keepAlive", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "authTokenName", + "onBackpressure", + "description", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "totalMemoryLimitKB", - "description", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9491,15 +9861,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "token", - "textSecret", - "environmentId", - "activeGateDomain", - "url", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", ] ) serialized = handler(self) @@ -9516,58 +9880,71 @@ def serialize_model(self, handler): return m -class CreateOutputOutputNetflowHostTypedDict(TypedDict): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 2055""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" +class CreateOutputOutputDynatraceHTTPType(str, Enum): + r"""Connector type identifier.""" + DYNATRACE_HTTP = "dynatrace_http" -class CreateOutputOutputNetflowHost(BaseModel): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 2055""" +class CreateOutputOutputDynatraceHTTPAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + # Auth token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["__template_host", "__template_port"]) - serialized = handler(self) - m = {} +class CreateOutputOutputDynatraceHTTPFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + # JSON + JSON_ARRAY = "json_array" + # Plaintext + PLAINTEXT = "plaintext" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - return m +class CreateOutputOutputDynatraceHTTPEndpoint(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Endpoint""" + + # Cloud + CLOUD = "cloud" + # ActiveGate + ACTIVE_GATE = "activeGate" + # Manual + MANUAL = "manual" -class CreateOutputOutputNetflowTypedDict(TypedDict): +class CreateOutputTelemetryType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Telemetry type""" + + # Logs + LOGS = "logs" + # Metrics + METRICS = "metrics" + + +class CreateOutputOutputDynatraceHTTPPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputDynatraceHTTPPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputDynatraceHTTPTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsNetflow + type: CreateOutputOutputDynatraceHTTPType r"""Connector type identifier.""" - hosts: List[CreateOutputOutputNetflowHostTypedDict] - r"""One or more NetFlow Destinations to forward events to""" + format_: CreateOutputOutputDynatraceHTTPFormat + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" + endpoint: CreateOutputOutputDynatraceHTTPEndpoint + r"""Endpoint""" + telemetry_type: CreateOutputTelemetryType + r"""Telemetry type""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9576,216 +9953,52 @@ class CreateOutputOutputNetflowTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[CreateOutputOutputDynatraceHTTPAuthenticationType] + r"""Authentication type""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_record_size: NotRequired[float] - r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateOutputOutputNetflow(BaseModel): - id: str - r"""Unique ID for this output""" - - type: TypeOptionsNetflow - r"""Connector type identifier.""" - - hosts: List[CreateOutputOutputNetflowHost] - r"""One or more NetFlow Destinations to forward events to""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") - ] = None - r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") - ] = None - r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "dnsResolvePeriodSec", - "enableIpSpoofing", - "description", - "maxRecordSize", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputXsiamType(str, Enum): - r"""Connector type identifier.""" - - XSIAM = "xsiam" - - -class CreateOutputOutputXsiamAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter a token directly, or provide a secret referencing a token""" - - TOKEN = "token" - SECRET = "secret" - - -class CreateOutputOutputXsiamURLTypedDict(TypedDict): - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - -class CreateOutputOutputXsiamURL(BaseModel): - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputXsiamPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputXsiamPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputXsiamTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputXsiamType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[CreateOutputOutputXsiamAuthenticationMethod] - r"""Enter a token directly, or provide a secret referencing a token""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - throttle_rate_req_per_sec: NotRequired[int] - r"""Maximum number of requests to limit to per second""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputOutputXsiamURLTypedDict]] - r"""XSIAM Endpoints""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - token: NotRequired[str] - r"""XSIAM authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9808,8 +10021,18 @@ class CreateOutputOutputXsiamTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputXsiamPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputDynatraceHTTPPqControlsTypedDict] r"""Persistent queue controls.""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + environment_id: NotRequired[str] + r"""ID of the environment to send to""" + active_gate_domain: NotRequired[str] + r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" + url: NotRequired[str] + r"""URL to send events to. Can be overwritten by an event's __url field.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] @@ -9820,13 +10043,26 @@ class CreateOutputOutputXsiamTypedDict(TypedDict): r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputXsiam(BaseModel): +class CreateOutputOutputDynatraceHTTP(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputXsiamType + type: CreateOutputOutputDynatraceHTTPType r"""Connector type identifier.""" + format_: Annotated[ + CreateOutputOutputDynatraceHTTPFormat, pydantic.Field(alias="format") + ] + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" + + endpoint: CreateOutputOutputDynatraceHTTPEndpoint + r"""Endpoint""" + + telemetry_type: Annotated[ + CreateOutputTelemetryType, pydantic.Field(alias="telemetryType") + ] + r"""Telemetry type""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9841,10 +10077,11 @@ class CreateOutputOutputXsiam(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -9887,7 +10124,12 @@ class CreateOutputOutputXsiam(BaseModel): Optional[List[ExtraHTTPHeaderConfInputElastic]], pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Headers to add to all events""" + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], @@ -9900,12 +10142,6 @@ class CreateOutputOutputXsiam(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - auth_type: Annotated[ - Optional[CreateOutputOutputXsiamAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Enter a token directly, or provide a secret referencing a token""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -9921,16 +10157,17 @@ class CreateOutputOutputXsiam(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - throttle_rate_req_per_sec: Annotated[ - Optional[int], pydantic.Field(alias="throttleRateReqPerSec") - ] = None - r"""Maximum number of requests to limit to per second""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[CreateOutputOutputDynatraceHTTPAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + total_memory_limit_kb: Annotated[ Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None @@ -9939,36 +10176,6 @@ class CreateOutputOutputXsiam(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[CreateOutputOutputXsiamURL]] = None - r"""XSIAM Endpoints""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" - - token: Optional[str] = None - r"""XSIAM authentication token""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -10019,10 +10226,30 @@ class CreateOutputOutputXsiam(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputXsiamPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputDynatraceHTTPPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + environment_id: Annotated[Optional[str], pydantic.Field(alias="environmentId")] = ( + None + ) + r"""ID of the environment to send to""" + + active_gate_domain: Annotated[ + Optional[str], pydantic.Field(alias="activeGateDomain") + ] = None + r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" + + url: Optional[str] = None + r"""URL to send events to. Can be overwritten by an event's __url field.""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -10043,6 +10270,15 @@ class CreateOutputOutputXsiam(BaseModel): ) r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -10052,20 +10288,47 @@ def serialize_failed_request_logging_mode(self, value): return value return value + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputXsiamAuthenticationMethod(value) + return models.CreateOutputOutputDynatraceHTTPAuthenticationType(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputOutputDynatraceHTTPFormat(value) + except ValueError: + return value + return value + + @field_serializer("endpoint") + def serialize_endpoint(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputDynatraceHTTPEndpoint(value) + except ValueError: + return value + return value + + @field_serializer("telemetry_type") + def serialize_telemetry_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputTelemetryType(value) except ValueError: return value return value @@ -10105,7 +10368,8 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", + "method", + "keepAlive", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -10115,24 +10379,16 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "throttleRateReqPerSec", "onBackpressure", + "authType", "totalMemoryLimitKB", "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "token", - "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10145,6 +10401,11 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "token", + "textSecret", + "environmentId", + "activeGateDomain", + "url", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", @@ -10165,80 +10426,37 @@ def serialize_model(self, handler): return m -class CreateOutputOutputLocalSearchStorageType(str, Enum): - r"""Connector type identifier.""" - - LOCAL_SEARCH_STORAGE = "local_search_storage" - - -class CreateOutputOutputLocalSearchStorageFormat( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Data format to use when sending data. Defaults to JSON Compact.""" - - # JSONCompactEachRowWithNames - JSON_COMPACT_EACH_ROW_WITH_NAMES = "json-compact-each-row-with-names" - # JSONEachRow - JSON_EACH_ROW = "json-each-row" - - -class CreateOutputMappingType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How event fields are mapped to columns.""" - - # Automatic - AUTOMATIC = "automatic" - # Custom - CUSTOM = "custom" - - -class CreateOutputStatsDestinationTypedDict(TypedDict): - url: NotRequired[str] - database: NotRequired[str] - table_name: NotRequired[str] - auth_type: NotRequired[str] - username: NotRequired[str] - sql_username: NotRequired[str] - password: NotRequired[str] - wait_for_async_inserts: NotRequired[bool] - concurrency: NotRequired[float] - - -class CreateOutputStatsDestination(BaseModel): - url: Optional[str] = None - - database: Optional[str] = None - - table_name: Annotated[Optional[str], pydantic.Field(alias="tableName")] = None - - auth_type: Annotated[Optional[str], pydantic.Field(alias="authType")] = None +class CreateOutputOutputNetflowHostTypedDict(TypedDict): + host: str + r"""Destination host""" + port: float + r"""Destination port, default is 2055""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - username: Optional[str] = None - sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None +class CreateOutputOutputNetflowHost(BaseModel): + host: str + r"""Destination host""" - password: Optional[str] = None + port: float + r"""Destination port, default is 2055""" - wait_for_async_inserts: Annotated[ - Optional[bool], pydantic.Field(alias="waitForAsyncInserts") - ] = None + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - concurrency: Optional[float] = None + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "url", - "database", - "tableName", - "authType", - "username", - "sqlUsername", - "password", - "waitForAsyncInserts", - "concurrency", - ] - ) + optional_fields = set(["__template_host", "__template_port"]) serialized = handler(self) m = {} @@ -10253,30 +10471,95 @@ def serialize_model(self, handler): return m -class CreateOutputColumnMappingTypedDict(TypedDict): - column_name: str - r"""Name of the column that will store field value""" - column_value_expression: str - r"""JavaScript expression to compute value to be inserted into the table""" - column_type: NotRequired[str] - r"""Type of the column in the database""" - +class CreateOutputOutputNetflowTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: TypeOptionsNetflow + r"""Connector type identifier.""" + hosts: List[CreateOutputOutputNetflowHostTypedDict] + r"""One or more NetFlow Destinations to forward events to""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + max_record_size: NotRequired[float] + r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class CreateOutputColumnMapping(BaseModel): - column_name: Annotated[str, pydantic.Field(alias="columnName")] - r"""Name of the column that will store field value""" - column_value_expression: Annotated[ - str, pydantic.Field(alias="columnValueExpression") - ] - r"""JavaScript expression to compute value to be inserted into the table""" +class CreateOutputOutputNetflow(BaseModel): + id: str + r"""Unique ID for this output""" - column_type: Annotated[Optional[str], pydantic.Field(alias="columnType")] = None - r"""Type of the column in the database""" + type: TypeOptionsNetflow + r"""Connector type identifier.""" + + hosts: List[CreateOutputOutputNetflowHost] + r"""One or more NetFlow Destinations to forward events to""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" + + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") + ] = None + r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") + ] = None + r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["columnType"]) + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "dnsResolvePeriodSec", + "enableIpSpoofing", + "description", + "maxRecordSize", + "__template_streamtags", + ] + ) serialized = handler(self) m = {} @@ -10291,25 +10574,60 @@ def serialize_model(self, handler): return m -class CreateOutputOutputLocalSearchStoragePqControlsTypedDict(TypedDict): +class CreateOutputOutputXsiamType(str, Enum): + r"""Connector type identifier.""" + + XSIAM = "xsiam" + + +class CreateOutputOutputXsiamAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter a token directly, or provide a secret referencing a token""" + + TOKEN = "token" + SECRET = "secret" + + +class CreateOutputOutputXsiamURLTypedDict(TypedDict): + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + +class CreateOutputOutputXsiamURL(BaseModel): + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputXsiamPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputLocalSearchStoragePqControls(BaseModel): +class CreateOutputOutputXsiamPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputLocalSearchStorageTypedDict(TypedDict): +class CreateOutputOutputXsiamTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputLocalSearchStorageType + type: CreateOutputOutputXsiamType r"""Connector type identifier.""" - url: str - r"""URL of the database instance. Example: http://localhost:8123/""" - database: str - r"""Database""" - table_name: str - r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10318,16 +10636,8 @@ class CreateOutputOutputLocalSearchStorageTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationTypeOptions] - r"""Authentication type""" - format_: NotRequired[CreateOutputOutputLocalSearchStorageFormat] - r"""Data format to use when sending data. Defaults to JSON Compact.""" - mapping_type: NotRequired[CreateOutputMappingType] - r"""How event fields are mapped to columns.""" - async_inserts: NotRequired[bool] - r"""Collect data into batches for later processing. Disable to write to a table immediately.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -10349,12 +10659,12 @@ class CreateOutputOutputLocalSearchStorageTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" + auth_type: NotRequired[CreateOutputOutputXsiamAuthenticationMethod] + r"""Enter a token directly, or provide a secret referencing a token""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -10362,31 +10672,30 @@ class CreateOutputOutputLocalSearchStorageTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - workload: NotRequired[str] - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - dump_format_errors_to_disk: NotRequired[bool] - r"""Log the most recent event that fails to match the table schema""" + throttle_rate_req_per_sec: NotRequired[int] + r"""Maximum number of requests to limit to per second""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - stats_destination: NotRequired[CreateOutputStatsDestinationTypedDict] + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - sql_username: NotRequired[str] - r"""Username for certificate authentication""" - wait_for_async_inserts: NotRequired[bool] - r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - exclude_mapping_fields: NotRequired[List[str]] - r"""Fields to exclude from sending""" - describe_table: NotRequired[str] - r"""Retrieves the table schema and populates the Column Mapping table""" - column_mappings: NotRequired[List[CreateOutputColumnMappingTypedDict]] - r"""Column Mapping""" + url: NotRequired[str] + r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputOutputXsiamURLTypedDict]] + r"""XSIAM Endpoints""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""XSIAM authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -10409,38 +10718,25 @@ class CreateOutputOutputLocalSearchStorageTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputLocalSearchStoragePqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputXsiamPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_table_name: NotRequired[str] - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputLocalSearchStorage(BaseModel): +class CreateOutputOutputXsiam(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputLocalSearchStorageType + type: CreateOutputOutputXsiamType r"""Connector type identifier.""" - url: str - r"""URL of the database instance. Example: http://localhost:8123/""" - - database: str - r"""Database""" - - table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -10455,29 +10751,10 @@ class CreateOutputOutputLocalSearchStorage(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") - ] = None - r"""Authentication type""" - - format_: Annotated[ - Optional[CreateOutputOutputLocalSearchStorageFormat], - pydantic.Field(alias="format"), - ] = None - r"""Data format to use when sending data. Defaults to JSON Compact.""" - - mapping_type: Annotated[ - Optional[CreateOutputMappingType], pydantic.Field(alias="mappingType") - ] = None - r"""How event fields are mapped to columns.""" - - async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Collect data into batches for later processing. Disable to write to a table immediately.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -10522,11 +10799,6 @@ class CreateOutputOutputLocalSearchStorage(BaseModel): ] = None r"""Headers to add to all events""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -10538,6 +10810,12 @@ class CreateOutputOutputLocalSearchStorage(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" + auth_type: Annotated[ + Optional[CreateOutputOutputXsiamAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter a token directly, or provide a secret referencing a token""" + response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -10553,60 +10831,53 @@ class CreateOutputOutputLocalSearchStorage(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - workload: Optional[str] = None - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - - dump_format_errors_to_disk: Annotated[ - Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") + throttle_rate_req_per_sec: Annotated[ + Optional[int], pydantic.Field(alias="throttleRateReqPerSec") ] = None - r"""Log the most recent event that fails to match the table schema""" + r"""Maximum number of requests to limit to per second""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - stats_destination: Annotated[ - Optional[CreateOutputStatsDestination], pydantic.Field(alias="statsDestination") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: Optional[str] = None r"""Optional description for this configuration.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" + url: Optional[str] = None + r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Select or create a secret that references your credentials""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None - r"""Username for certificate authentication""" + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - wait_for_async_inserts: Annotated[ - Optional[bool], pydantic.Field(alias="waitForAsyncInserts") + urls: Optional[List[CreateOutputOutputXsiamURL]] = None + r"""XSIAM Endpoints""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - exclude_mapping_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeMappingFields") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Fields to exclude from sending""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( - None - ) - r"""Retrieves the table schema and populates the Column Mapping table""" + token: Optional[str] = None + r"""XSIAM authentication token""" - column_mappings: Annotated[ - Optional[List[CreateOutputColumnMapping]], - pydantic.Field(alias="columnMappings"), - ] = None - r"""Column Mapping""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -10658,8 +10929,7 @@ class CreateOutputOutputLocalSearchStorage(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputLocalSearchStoragePqControls], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputXsiamPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -10668,21 +10938,6 @@ class CreateOutputOutputLocalSearchStorage(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") - ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - - template_table_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_tableName") - ] = None - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -10693,38 +10948,25 @@ class CreateOutputOutputLocalSearchStorage(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptions(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputLocalSearchStorageFormat(value) - except ValueError: - return value - return value + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - @field_serializer("mapping_type") - def serialize_mapping_type(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CreateOutputMappingType(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CreateOutputOutputXsiamAuthenticationMethod(value) except ValueError: return value return value @@ -10773,11 +11015,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "format", - "mappingType", - "asyncInserts", - "tls", + "loadBalanced", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -10787,25 +11025,24 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "workload", - "dumpFormatErrorsToDisk", + "throttleRateReqPerSec", "onBackpressure", - "statsDestination", + "totalMemoryLimitKB", "description", - "username", - "password", - "credentialsSecret", - "sqlUsername", - "waitForAsyncInserts", - "excludeMappingFields", - "describeTable", - "columnMappings", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10819,11 +11056,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_url", - "__template_database", - "__template_tableName", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_url", ] ) serialized = handler(self) @@ -10840,31 +11075,151 @@ def serialize_model(self, handler): return m -class CreateOutputOutputCustomerMetricsStorageType(str, Enum): +class CreateOutputOutputLocalSearchStorageType(str, Enum): r"""Connector type identifier.""" - CUSTOMER_METRICS_STORAGE = "customer_metrics_storage" + LOCAL_SEARCH_STORAGE = "local_search_storage" -class CreateOutputOutputCustomerMetricsStoragePqControlsTypedDict(TypedDict): +class CreateOutputOutputLocalSearchStorageFormat( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Data format to use when sending data. Defaults to JSON Compact.""" + + # JSONCompactEachRowWithNames + JSON_COMPACT_EACH_ROW_WITH_NAMES = "json-compact-each-row-with-names" + # JSONEachRow + JSON_EACH_ROW = "json-each-row" + + +class CreateOutputMappingType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How event fields are mapped to columns.""" + + # Automatic + AUTOMATIC = "automatic" + # Custom + CUSTOM = "custom" + + +class CreateOutputStatsDestinationTypedDict(TypedDict): + url: NotRequired[str] + database: NotRequired[str] + table_name: NotRequired[str] + auth_type: NotRequired[str] + username: NotRequired[str] + sql_username: NotRequired[str] + password: NotRequired[str] + wait_for_async_inserts: NotRequired[bool] + concurrency: NotRequired[float] + + +class CreateOutputStatsDestination(BaseModel): + url: Optional[str] = None + + database: Optional[str] = None + + table_name: Annotated[Optional[str], pydantic.Field(alias="tableName")] = None + + auth_type: Annotated[Optional[str], pydantic.Field(alias="authType")] = None + + username: Optional[str] = None + + sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + + password: Optional[str] = None + + wait_for_async_inserts: Annotated[ + Optional[bool], pydantic.Field(alias="waitForAsyncInserts") + ] = None + + concurrency: Optional[float] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "url", + "database", + "tableName", + "authType", + "username", + "sqlUsername", + "password", + "waitForAsyncInserts", + "concurrency", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputColumnMappingTypedDict(TypedDict): + column_name: str + r"""Name of the column that will store field value""" + column_value_expression: str + r"""JavaScript expression to compute value to be inserted into the table""" + column_type: NotRequired[str] + r"""Type of the column in the database""" + + +class CreateOutputColumnMapping(BaseModel): + column_name: Annotated[str, pydantic.Field(alias="columnName")] + r"""Name of the column that will store field value""" + + column_value_expression: Annotated[ + str, pydantic.Field(alias="columnValueExpression") + ] + r"""JavaScript expression to compute value to be inserted into the table""" + + column_type: Annotated[Optional[str], pydantic.Field(alias="columnType")] = None + r"""Type of the column in the database""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["columnType"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputLocalSearchStoragePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputCustomerMetricsStoragePqControls(BaseModel): +class CreateOutputOutputLocalSearchStoragePqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputCustomerMetricsStorageTypedDict(TypedDict): +class CreateOutputOutputLocalSearchStorageTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCustomerMetricsStorageType + type: CreateOutputOutputLocalSearchStorageType r"""Connector type identifier.""" url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + r"""URL of the database instance. Example: http://localhost:8123/""" database: str - r"""ClickHouse database""" + r"""Database""" table_name: str - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10875,12 +11230,12 @@ class CreateOutputOutputCustomerMetricsStorageTypedDict(TypedDict): r"""Metadata tags used for categorization and filtering.""" auth_type: NotRequired[AuthenticationTypeOptions] r"""Authentication type""" - format_: NotRequired[FormatOptions] - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - mapping_type: NotRequired[MappingTypeOptions] - r"""How event fields are mapped to ClickHouse columns""" + format_: NotRequired[CreateOutputOutputLocalSearchStorageFormat] + r"""Data format to use when sending data. Defaults to JSON Compact.""" + mapping_type: NotRequired[CreateOutputMappingType] + r"""How event fields are mapped to columns.""" async_inserts: NotRequired[bool] - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + r"""Collect data into batches for later processing. Disable to write to a table immediately.""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" concurrency: NotRequired[float] @@ -10923,6 +11278,7 @@ class CreateOutputOutputCustomerMetricsStorageTypedDict(TypedDict): r"""Log the most recent event that fails to match the table schema""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + stats_destination: NotRequired[CreateOutputStatsDestinationTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" username: NotRequired[str] @@ -10934,12 +11290,12 @@ class CreateOutputOutputCustomerMetricsStorageTypedDict(TypedDict): sql_username: NotRequired[str] r"""Username for certificate authentication""" wait_for_async_inserts: NotRequired[bool] - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" exclude_mapping_fields: NotRequired[List[str]] - r"""Fields to exclude from sending to ClickHouse""" + r"""Fields to exclude from sending""" describe_table: NotRequired[str] - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] + r"""Retrieves the table schema and populates the Column Mapping table""" + column_mappings: NotRequired[List[CreateOutputColumnMappingTypedDict]] r"""Column Mapping""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" @@ -10963,9 +11319,7 @@ class CreateOutputOutputCustomerMetricsStorageTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputOutputCustomerMetricsStoragePqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputOutputLocalSearchStoragePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -10981,21 +11335,21 @@ class CreateOutputOutputCustomerMetricsStorageTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputCustomerMetricsStorage(BaseModel): +class CreateOutputOutputLocalSearchStorage(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCustomerMetricsStorageType + type: CreateOutputOutputLocalSearchStorageType r"""Connector type identifier.""" url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + r"""URL of the database instance. Example: http://localhost:8123/""" database: str - r"""ClickHouse database""" + r"""Database""" table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -11016,18 +11370,21 @@ class CreateOutputOutputCustomerMetricsStorage(BaseModel): ] = None r"""Authentication type""" - format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + format_: Annotated[ + Optional[CreateOutputOutputLocalSearchStorageFormat], + pydantic.Field(alias="format"), + ] = None + r"""Data format to use when sending data. Defaults to JSON Compact.""" mapping_type: Annotated[ - Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") + Optional[CreateOutputMappingType], pydantic.Field(alias="mappingType") ] = None - r"""How event fields are mapped to ClickHouse columns""" + r"""How event fields are mapped to columns.""" async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( None ) - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + r"""Collect data into batches for later processing. Disable to write to a table immediately.""" tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None r"""TLS settings (client side)""" @@ -11119,6 +11476,10 @@ class CreateOutputOutputCustomerMetricsStorage(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" + stats_destination: Annotated[ + Optional[CreateOutputStatsDestination], pydantic.Field(alias="statsDestination") + ] = None + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11139,20 +11500,20 @@ class CreateOutputOutputCustomerMetricsStorage(BaseModel): wait_for_async_inserts: Annotated[ Optional[bool], pydantic.Field(alias="waitForAsyncInserts") ] = None - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" exclude_mapping_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="excludeMappingFields") ] = None - r"""Fields to exclude from sending to ClickHouse""" + r"""Fields to exclude from sending""" describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( None ) - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" + r"""Retrieves the table schema and populates the Column Mapping table""" column_mappings: Annotated[ - Optional[List[ColumnMappingConfOutputClickHouse]], + Optional[List[CreateOutputColumnMapping]], pydantic.Field(alias="columnMappings"), ] = None r"""Column Mapping""" @@ -11207,7 +11568,7 @@ class CreateOutputOutputCustomerMetricsStorage(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputCustomerMetricsStoragePqControls], + Optional[CreateOutputOutputLocalSearchStoragePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -11255,7 +11616,7 @@ def serialize_auth_type(self, value): def serialize_format_(self, value): if isinstance(value, str): try: - return models.FormatOptions(value) + return models.CreateOutputOutputLocalSearchStorageFormat(value) except ValueError: return value return value @@ -11264,7 +11625,7 @@ def serialize_format_(self, value): def serialize_mapping_type(self, value): if isinstance(value, str): try: - return models.MappingTypeOptions(value) + return models.CreateOutputMappingType(value) except ValueError: return value return value @@ -11345,6 +11706,7 @@ def serialize_model(self, handler): "workload", "dumpFormatErrorsToDisk", "onBackpressure", + "statsDestination", "description", "username", "password", @@ -11388,24 +11750,24 @@ def serialize_model(self, handler): return m -class CreateOutputOutputClickHouseType(str, Enum): +class CreateOutputOutputCustomerMetricsStorageType(str, Enum): r"""Connector type identifier.""" - CLICK_HOUSE = "click_house" + CUSTOMER_METRICS_STORAGE = "customer_metrics_storage" -class CreateOutputOutputClickHousePqControlsTypedDict(TypedDict): +class CreateOutputOutputCustomerMetricsStoragePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputClickHousePqControls(BaseModel): +class CreateOutputOutputCustomerMetricsStoragePqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputClickHouseTypedDict(TypedDict): +class CreateOutputOutputCustomerMetricsStorageTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputClickHouseType + type: CreateOutputOutputCustomerMetricsStorageType r"""Connector type identifier.""" url: str r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" @@ -11511,7 +11873,9 @@ class CreateOutputOutputClickHouseTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputClickHousePqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputOutputCustomerMetricsStoragePqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -11527,11 +11891,11 @@ class CreateOutputOutputClickHouseTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputClickHouse(BaseModel): +class CreateOutputOutputCustomerMetricsStorage(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputClickHouseType + type: CreateOutputOutputCustomerMetricsStorageType r"""Connector type identifier.""" url: str @@ -11753,7 +12117,7 @@ class CreateOutputOutputClickHouse(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputClickHousePqControls], + Optional[CreateOutputOutputCustomerMetricsStoragePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -11934,17 +12298,31 @@ def serialize_model(self, handler): return m -class CreateOutputOutputDiskSpoolType(str, Enum): +class CreateOutputOutputClickHouseType(str, Enum): r"""Connector type identifier.""" - DISK_SPOOL = "disk_spool" + CLICK_HOUSE = "click_house" -class CreateOutputOutputDiskSpoolTypedDict(TypedDict): +class CreateOutputOutputClickHousePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputClickHousePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputClickHouseTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDiskSpoolType + type: CreateOutputOutputClickHouseType r"""Connector type identifier.""" + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + database: str + r"""ClickHouse database""" + table_name: str + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -11953,29 +12331,128 @@ class CreateOutputOutputDiskSpoolTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - time_window: NotRequired[str] - r"""Time period for grouping spooled events. Default is 10m.""" - max_data_size: NotRequired[str] - r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" - compress: NotRequired[CompressionOptionsPersistence] - r"""Data compression format. Default is gzip.""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" + auth_type: NotRequired[AuthenticationTypeOptions] + r"""Authentication type""" + format_: NotRequired[FormatOptions] + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + mapping_type: NotRequired[MappingTypeOptions] + r"""How event fields are mapped to ClickHouse columns""" + async_inserts: NotRequired[bool] + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + workload: NotRequired[str] + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" + dump_format_errors_to_disk: NotRequired[bool] + r"""Log the most recent event that fails to match the table schema""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + sql_username: NotRequired[str] + r"""Username for certificate authentication""" + wait_for_async_inserts: NotRequired[bool] + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + exclude_mapping_fields: NotRequired[List[str]] + r"""Fields to exclude from sending to ClickHouse""" + describe_table: NotRequired[str] + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" + column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] + r"""Column Mapping""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputClickHousePqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_table_name: NotRequired[str] + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputDiskSpool(BaseModel): +class CreateOutputOutputClickHouse(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDiskSpoolType + type: CreateOutputOutputClickHouseType r"""Connector type identifier.""" + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + + database: str + r"""ClickHouse database""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -11990,495 +12467,305 @@ class CreateOutputOutputDiskSpool(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time period for grouping spooled events. Default is 10m.""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" + auth_type: Annotated[ + Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") + ] = None + r"""Authentication type""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - compress: Optional[CompressionOptionsPersistence] = None - r"""Data compression format. Default is gzip.""" + mapping_type: Annotated[ + Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") + ] = None + r"""How event fields are mapped to ClickHouse columns""" - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( None ) - r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPersistence(value) - except ValueError: - return value - return value + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "partitionExpr", - "description", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - return m + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" -class CreateOutputOutputCriblLakeType(str, Enum): - r"""Connector type identifier.""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - CRIBL_LAKE = "cribl_lake" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" -class CreateOutputOutputCriblLakeFormat(str, Enum, metaclass=utils.OpenEnumMeta): - JSON = "json" - PARQUET = "parquet" - RAW = "raw" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" -class CreateOutputOutputCriblLakeTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputCriblLakeType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - storage_location_id: NotRequired[str] - r"""Storage location that contains the target Lake dataset.""" - dest_path: NotRequired[str] - r"""Lake dataset to send the data to.""" - format_: NotRequired[CreateOutputOutputCriblLakeFormat] - dynamic_dataset: NotRequired[bool] - max_closing_files_to_backpressure: NotRequired[float] - max_concurrent_file_parts: NotRequired[float] - description: NotRequired[str] - r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None -class CreateOutputOutputCriblLake(BaseModel): - id: str - r"""Unique ID for this output""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - type: CreateOutputOutputCriblLakeType - r"""Connector type identifier.""" + workload: Optional[str] = None + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + dump_format_errors_to_disk: Annotated[ + Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") + ] = None + r"""Log the most recent event that fails to match the table schema""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""How to handle events when all receivers are exerting backpressure""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + username: Optional[str] = None + r"""Username""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + password: Optional[str] = None + r"""Password""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") ] = None - r"""Add the Output ID value to staging location""" + r"""Select or create a secret that references your credentials""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + r"""Username for certificate authentication""" + + wait_for_async_inserts: Annotated[ + Optional[bool], pydantic.Field(alias="waitForAsyncInserts") ] = None - r"""Remove empty staging directories after moving files""" + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + exclude_mapping_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeMappingFields") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""Fields to exclude from sending to ClickHouse""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( None ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" - - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None - r"""Buffer size used to write to a file""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - storage_location_id: Annotated[ - Optional[str], pydantic.Field(alias="storageLocationId") - ] = None - r"""Storage location that contains the target Lake dataset.""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Lake dataset to send the data to.""" - - format_: Annotated[ - Optional[CreateOutputOutputCriblLakeFormat], pydantic.Field(alias="format") - ] = None - - dynamic_dataset: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicDataset") - ] = None - - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + column_mappings: Annotated[ + Optional[List[ColumnMappingConfOutputClickHouse]], + pydantic.Field(alias="columnMappings"), ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Column Mapping""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Determines which data types are supported and how they are represented""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + r"""Codec to use to compress the persisted data""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_controls: Annotated[ + Optional[CreateOutputOutputClickHousePqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""Persistent queue controls.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + template_table_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_tableName") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.AuthenticationTypeOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.FormatOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("mapping_type") + def serialize_mapping_type(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputCriblLakeFormat(value) + return models.MappingTypeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): - if isinstance(value, str): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -12491,54 +12778,56 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "stagePath", - "addIdToStagePath", - "removeEmptyDirs", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "storageLocationId", - "destPath", + "authType", "format", - "dynamicDataset", - "maxClosingFilesToBackpressure", - "maxConcurrentFileParts", - "description", + "mappingType", + "asyncInserts", + "tls", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "workload", + "dumpFormatErrorsToDisk", + "onBackpressure", + "description", + "username", + "password", + "credentialsSecret", + "sqlUsername", + "waitForAsyncInserts", + "excludeMappingFields", + "describeTable", + "columnMappings", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_baseFileName", - "__template_fileNameSuffix", + "__template_url", + "__template_database", + "__template_tableName", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_destPath", - "__template_compress", - "__template_parquetSchema", ] ) serialized = handler(self) @@ -12555,194 +12844,55 @@ def serialize_model(self, handler): return m -class CreateOutputOutputSecurityLakeTypedDict(TypedDict): +class CreateOutputOutputDiskSpoolType(str, Enum): + r"""Connector type identifier.""" + + DISK_SPOOL = "disk_spool" + + +class CreateOutputOutputDiskSpoolTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSecuritylake + type: CreateOutputOutputDiskSpoolType r"""Connector type identifier.""" - assume_role_arn: str - r"""Amazon Resource Name (ARN) of the role to assume""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - region: str - r"""Region where the Amazon Security Lake is located.""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - account_id: str - r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" - custom_source: str - r"""Name of the custom source configured in Amazon Security Lake""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - endpoint: NotRequired[str] - r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access S3""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + time_window: NotRequired[str] + r"""Time period for grouping spooled events. Default is 10m.""" + max_data_size: NotRequired[str] + r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + compress: NotRequired[CompressionOptionsPersistence] + r"""Data compression format. Default is gzip.""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_account_id: NotRequired[str] - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - template_custom_source: NotRequired[str] - r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputOutputSecurityLake(BaseModel): +class CreateOutputOutputDiskSpool(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSecuritylake + type: CreateOutputOutputDiskSpoolType r"""Connector type identifier.""" - assume_role_arn: Annotated[str, pydantic.Field(alias="assumeRoleArn")] - r"""Amazon Resource Name (ARN) of the role to assume""" - - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - - region: str - r"""Region where the Amazon Security Lake is located.""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - - account_id: Annotated[str, pydantic.Field(alias="accountId")] - r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" - - custom_source: Annotated[str, pydantic.Field(alias="customSource")] - r"""Name of the custom source configured in Amazon Security Lake""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -12750,156 +12900,340 @@ class CreateOutputOutputSecurityLake(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - endpoint: Optional[str] = None - r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time period for grouping spooled events. Default is 10m.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access S3""" + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + compress: Optional[CompressionOptionsPersistence] = None + r"""Data compression format. Default is gzip.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPersistence(value) + except ValueError: + return value + return value - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") - ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "partitionExpr", + "description", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" + return m - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" +class CreateOutputOutputCriblLakeType(str, Enum): + r"""Connector type identifier.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + CRIBL_LAKE = "cribl_lake" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" +class CreateOutputOutputCriblLakeFormat(str, Enum, metaclass=utils.OpenEnumMeta): + JSON = "json" + PARQUET = "parquet" + RAW = "raw" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None +class CreateOutputOutputCriblLakeTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputCriblLakeType + r"""Connector type identifier.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] r"""Buffer size used to write to a file""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None + deadletter_enabled: NotRequired[bool] r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None + force_close_on_shutdown: NotRequired[bool] r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" - - storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") - ] = None - r"""Storage class to select for uploaded objects""" - - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), - ] = None - r"""Server-side encryption to use for uploaded objects""" - - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - - automatic_schema: Annotated[ + storage_location_id: NotRequired[str] + r"""Storage location that contains the target Lake dataset.""" + dest_path: NotRequired[str] + r"""Lake dataset to send the data to.""" + format_: NotRequired[CreateOutputOutputCriblLakeFormat] + dynamic_dataset: NotRequired[bool] + max_closing_files_to_backpressure: NotRequired[float] + max_concurrent_file_parts: NotRequired[float] + freshness_grace_period_sec: NotRequired[float] + description: NotRequired[str] + r"""Optional description for this configuration.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + +class CreateOutputOutputCriblLake(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputOutputCriblLakeType + r"""Connector type identifier.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + storage_location_id: Annotated[ + Optional[str], pydantic.Field(alias="storageLocationId") + ] = None + r"""Storage location that contains the target Lake dataset.""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Lake dataset to send the data to.""" + + format_: Annotated[ + Optional[CreateOutputOutputCriblLakeFormat], pydantic.Field(alias="format") + ] = None + + dynamic_dataset: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicDataset") + ] = None + + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + ] = None + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + + freshness_grace_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="freshnessGracePeriodSec") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" + + automatic_schema: Annotated[ Optional[bool], pydantic.Field(alias="automaticSchema") ] = None r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: Annotated[ Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None @@ -12946,15 +13280,6 @@ class CreateOutputOutputSecurityLake(BaseModel): ] = None r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - empty_dir_cleanup_sec: Annotated[ Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None @@ -12965,11 +13290,6 @@ class CreateOutputOutputSecurityLake(BaseModel): ] = None r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - deadletter_path: Annotated[ Optional[str], pydantic.Field(alias="deadletterPath") ] = None @@ -12985,95 +13305,36 @@ class CreateOutputOutputSecurityLake(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_base_file_name: Annotated[ Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") - ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") - ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - - template_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_accountId") - ] = None - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - - template_custom_source: Annotated[ - Optional[str], pydantic.Field(alias="__template_customSource") - ] = None - r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: Annotated[ Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -13092,29 +13353,29 @@ def serialize_on_disk_full_backpressure(self, value): return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.ObjectACLOptions(value) + return models.CreateOutputOutputCriblLakeFormat(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.StorageClassOptions(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value @@ -13145,19 +13406,11 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "endpoint", - "enableAssumeRole", - "assumeRoleExternalId", - "durationSeconds", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", + "stagePath", "addIdToStagePath", "removeEmptyDirs", "baseFileName", + "fileNameSuffix", "maxFileSizeMB", "maxFileOpenTimeSec", "maxFileIdleTimeSec", @@ -13170,12 +13423,18 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", - "kmsKeyId", + "storageLocationId", + "destPath", + "format", + "dynamicDataset", + "maxClosingFilesToBackpressure", + "maxConcurrentFileParts", + "freshnessGracePeriodSec", + "description", + "compress", + "compressionLevel", "automaticSchema", + "parquetSchema", "parquetVersion", "parquetDataPageVersion", "parquetRowGroupLength", @@ -13185,30 +13444,16 @@ def serialize_model(self, handler): "enableStatistics", "enableWritePageIndex", "enablePageChecksum", - "description", - "awsApiKey", - "awsSecret", "emptyDirCleanupSec", "directoryBatchSize", - "parquetSchema", "deadletterPath", "maxRetryNum", "__template_streamtags", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_bucket", - "__template_region", "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", - "__template_accountId", - "__template_customSource", - "__template_awsApiKey", + "__template_destPath", + "__template_compress", "__template_parquetSchema", ] ) @@ -13226,35 +13471,35 @@ def serialize_model(self, handler): return m -class CreateOutputOutputDlS3Type(str, Enum): - r"""Connector type identifier.""" - - DL_S3 = "dl_s3" - - -class CreateOutputOutputDlS3TypedDict(TypedDict): +class CreateOutputOutputSecurityLakeTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDlS3Type + type: TypeOptionsSecuritylake r"""Connector type identifier.""" + assume_role_arn: str + r"""Amazon Resource Name (ARN) of the role to assume""" bucket: str r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + region: str + r"""Region where the Amazon Security Lake is located.""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + account_id: str + r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" + custom_source: str + r"""Name of the custom source configured in Amazon Security Lake""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" enable_assume_role: NotRequired[bool] r"""Use Assume Role credentials to access S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" assume_role_external_id: NotRequired[str] r"""External ID to use when assuming role""" duration_seconds: NotRequired[float] @@ -13265,10 +13510,6 @@ class CreateOutputOutputDlS3TypedDict(TypedDict): r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the S3 bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" verify_permissions: NotRequired[bool] @@ -13279,12 +13520,8 @@ class CreateOutputOutputDlS3TypedDict(TypedDict): r"""Add the Output ID value to staging location""" remove_empty_dirs: NotRequired[bool] r"""Remove empty staging directories after moving files""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" base_file_name: NotRequired[str] r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" max_file_size_mb: NotRequired[float] r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" max_file_open_time_sec: NotRequired[float] @@ -13309,7 +13546,7 @@ class CreateOutputOutputDlS3TypedDict(TypedDict): orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + r"""Secret key""" object_acl: NotRequired[ObjectACLOptions] r"""Object ACL to assign to uploaded objects""" storage_class: NotRequired[StorageClassOptions] @@ -13318,22 +13555,8 @@ class CreateOutputOutputDlS3TypedDict(TypedDict): r"""Server-side encryption to use for uploaded objects""" kms_key_id: NotRequired[str] r"""ID or ARN of the KMS customer-managed key to use for encryption""" - partitioning_fields: NotRequired[List[str]] - r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" automatic_schema: NotRequired[bool] r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" parquet_version: NotRequired[ParquetVersionOptions] r"""Determines which data types are supported and how they are represented""" parquet_data_page_version: NotRequired[DataPageVersionOptions] @@ -13352,10 +13575,18 @@ class CreateOutputOutputDlS3TypedDict(TypedDict): r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" enable_page_checksum: NotRequired[bool] r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" empty_dir_cleanup_sec: NotRequired[float] r"""How frequently, in seconds, to clean up empty directories""" directory_batch_size: NotRequired[float] r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" deadletter_path: NotRequired[str] r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] @@ -13372,14 +13603,8 @@ class CreateOutputOutputDlS3TypedDict(TypedDict): r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_base_file_name: NotRequired[str] r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_aws_secret_key: NotRequired[str] @@ -13392,36 +13617,48 @@ class CreateOutputOutputDlS3TypedDict(TypedDict): r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" template_kms_key_id: NotRequired[str] r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_partitioning_fields: NotRequired[str] - r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + template_account_id: NotRequired[str] + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + template_custom_source: NotRequired[str] + r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" template_aws_api_key: NotRequired[str] r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputOutputDlS3(BaseModel): +class CreateOutputOutputSecurityLake(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDlS3Type + type: TypeOptionsSecuritylake r"""Connector type identifier.""" + assume_role_arn: Annotated[str, pydantic.Field(alias="assumeRoleArn")] + r"""Amazon Resource Name (ARN) of the role to assume""" + bucket: str r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + region: str + r"""Region where the Amazon Security Lake is located.""" + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + account_id: Annotated[str, pydantic.Field(alias="accountId")] + r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" + + custom_source: Annotated[str, pydantic.Field(alias="customSource")] + r"""Name of the custom source configured in Amazon Security Lake""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -13430,18 +13667,13 @@ class CreateOutputOutputDlS3(BaseModel): r"""Metadata tags used for categorization and filtering.""" endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" enable_assume_role: Annotated[ Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None r"""Use Assume Role credentials to access S3""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: Annotated[ Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None @@ -13468,12 +13700,6 @@ class CreateOutputOutputDlS3(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: Optional[str] = None - r"""Region where the S3 bucket is located""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: Annotated[ Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None @@ -13499,21 +13725,11 @@ class CreateOutputOutputDlS3(BaseModel): ] = None r"""Remove empty staging directories after moving files""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( None ) r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: Annotated[ Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None @@ -13574,7 +13790,7 @@ class CreateOutputOutputDlS3(BaseModel): aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( None ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + r"""Secret key""" object_acl: Annotated[ Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") @@ -13595,38 +13811,11 @@ class CreateOutputOutputDlS3(BaseModel): kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None r"""ID or ARN of the KMS customer-managed key to use for encryption""" - partitioning_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="partitioningFields") - ] = None - r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - automatic_schema: Annotated[ Optional[bool], pydantic.Field(alias="automaticSchema") ] = None r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: Annotated[ Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None @@ -13673,16 +13862,30 @@ class CreateOutputOutputDlS3(BaseModel): ] = None r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" + + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + deadletter_path: Annotated[ Optional[str], pydantic.Field(alias="deadletterPath") ] = None @@ -13723,26 +13926,11 @@ class CreateOutputOutputDlS3(BaseModel): ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: Annotated[ Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None @@ -13773,21 +13961,21 @@ class CreateOutputOutputDlS3(BaseModel): ] = None r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_partitioning_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitioningFields") + template_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_accountId") ] = None - r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + + template_custom_source: Annotated[ + Optional[str], pydantic.Field(alias="__template_customSource") + ] = None + r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" template_aws_api_key: Annotated[ Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: Annotated[ Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None @@ -13802,15 +13990,6 @@ def serialize_aws_authentication_method(self, value): return value return value - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -13856,24 +14035,6 @@ def serialize_server_side_encryption(self, value): return value return value - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value - @field_serializer("parquet_version") def serialize_parquet_version(self, value): if isinstance(value, str): @@ -13902,22 +14063,17 @@ def serialize_model(self, handler): "streamtags", "endpoint", "enableAssumeRole", - "assumeRoleArn", "assumeRoleExternalId", "durationSeconds", "awsAuthenticationMethod", "reuseConnections", "rejectUnauthorized", - "region", - "destPath", "maxConcurrentFileParts", "verifyPermissions", "maxClosingFilesToBackpressure", "addIdToStagePath", "removeEmptyDirs", - "format", "baseFileName", - "fileNameSuffix", "maxFileSizeMB", "maxFileOpenTimeSec", "maxFileIdleTimeSec", @@ -13935,14 +14091,7 @@ def serialize_model(self, handler): "storageClass", "serverSideEncryption", "kmsKeyId", - "partitioningFields", - "description", - "awsApiKey", - "awsSecret", - "compress", - "compressionLevel", "automaticSchema", - "parquetSchema", "parquetVersion", "parquetDataPageVersion", "parquetRowGroupLength", @@ -13952,8 +14101,12 @@ def serialize_model(self, handler): "enableStatistics", "enableWritePageIndex", "enablePageChecksum", + "description", + "awsApiKey", + "awsSecret", "emptyDirCleanupSec", "directoryBatchSize", + "parquetSchema", "deadletterPath", "maxRetryNum", "__template_streamtags", @@ -13962,19 +14115,16 @@ def serialize_model(self, handler): "__template_assumeRoleExternalId", "__template_bucket", "__template_region", - "__template_destPath", - "__template_format", "__template_baseFileName", - "__template_fileNameSuffix", "__template_onBackpressure", "__template_awsSecretKey", "__template_objectACL", "__template_storageClass", "__template_serverSideEncryption", "__template_kmsKeyId", - "__template_partitioningFields", + "__template_accountId", + "__template_customSource", "__template_awsApiKey", - "__template_compress", "__template_parquetSchema", ] ) @@ -13992,31 +14142,21 @@ def serialize_model(self, handler): return m -class CreateOutputOutputCrowdstrikeNextGenSiemType(str, Enum): +class CreateOutputOutputDlS3Type(str, Enum): r"""Connector type identifier.""" - CROWDSTRIKE_NEXT_GEN_SIEM = "crowdstrike_next_gen_siem" - - -class CreateOutputOutputCrowdstrikeNextGenSiemPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputCrowdstrikeNextGenSiemPqControls(BaseModel): - r"""Persistent queue controls.""" + DL_S3 = "dl_s3" -class CreateOutputOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): +class CreateOutputOutputDlS3TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCrowdstrikeNextGenSiemType + type: CreateOutputOutputDlS3Type r"""Connector type identifier.""" - url: str - r"""URL provided from a CrowdStrike data connector. - Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector - """ - format_: RequestFormatOptions - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -14025,289 +14165,555 @@ class CreateOutputOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the S3 bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + partitioning_fields: NotRequired[List[str]] + r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""Next-Gen SIEM authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputOutputCrowdstrikeNextGenSiemPqControlsTypedDict - ] - r"""Persistent queue controls.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_partitioning_fields: NotRequired[str] + r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + +class CreateOutputOutputDlS3(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputOutputDlS3Type + r"""Connector type identifier.""" + + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + region: Optional[str] = None + r"""Region where the S3 bucket is located""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") + ] = None + r"""Disable if you can access files within the bucket but not the bucket itself""" + + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + ] = None + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" -class CreateOutputOutputCrowdstrikeNextGenSiem(BaseModel): - id: str - r"""Unique ID for this output""" + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - type: CreateOutputOutputCrowdstrikeNextGenSiemType - r"""Connector type identifier.""" + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - url: str - r"""URL provided from a CrowdStrike data connector. - Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector - """ + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""How to handle events when all receivers are exerting backpressure""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Maximum size, in KB, of the request body""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Object ACL to assign to uploaded objects""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + ] = None + r"""Storage class to select for uploaded objects""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Server-side encryption to use for uploaded objects""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + partitioning_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="partitioningFields") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Compression level to apply before moving files to final destination""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Headers to add to all events""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Determines which data types are supported and how they are represented""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""List of headers that are safe to log in plain text""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") + ] = None + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - token: Optional[str] = None - r"""Next-Gen SIEM authentication token""" + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") + ] = None + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") + ] = None + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Codec to use to compress the persisted data""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - pq_controls: Annotated[ - Optional[CreateOutputOutputCrowdstrikeNextGenSiemPqControls], - pydantic.Field(alias="pqControls"), + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") ] = None - r"""Persistent queue controls.""" + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_partitioning_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitioningFields") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -14316,52 +14722,88 @@ def serialize_failed_request_logging_mode(self, value): def serialize_format_(self, value): if isinstance(value, str): try: - return models.RequestFormatOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.StorageClassOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ServerSideEncryptionForUploadedObjectsOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -14374,42 +14816,82 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "endpoint", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", + "partitioningFields", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_bucket", + "__template_region", + "__template_destPath", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", + "__template_partitioningFields", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -14426,27 +14908,29 @@ def serialize_model(self, handler): return m -class CreateOutputOutputHumioHecType(str, Enum): +class CreateOutputOutputCrowdstrikeNextGenSiemType(str, Enum): r"""Connector type identifier.""" - HUMIO_HEC = "humio_hec" + CROWDSTRIKE_NEXT_GEN_SIEM = "crowdstrike_next_gen_siem" -class CreateOutputOutputHumioHecPqControlsTypedDict(TypedDict): +class CreateOutputOutputCrowdstrikeNextGenSiemPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputHumioHecPqControls(BaseModel): +class CreateOutputOutputCrowdstrikeNextGenSiemPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputHumioHecTypedDict(TypedDict): +class CreateOutputOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputHumioHecType + type: CreateOutputOutputCrowdstrikeNextGenSiemType r"""Connector type identifier.""" url: str - r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + r"""URL provided from a CrowdStrike data connector. + Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector + """ format_: RequestFormatOptions r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" pipeline: NotRequired[str] @@ -14484,7 +14968,7 @@ class CreateOutputOutputHumioHecTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -14498,7 +14982,7 @@ class CreateOutputOutputHumioHecTypedDict(TypedDict): description: NotRequired[str] r"""Optional description for this configuration.""" token: NotRequired[str] - r"""CrowdStrike Falcon LogScale authentication token""" + r"""Next-Gen SIEM authentication token""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] @@ -14523,7 +15007,9 @@ class CreateOutputOutputHumioHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputHumioHecPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputOutputCrowdstrikeNextGenSiemPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -14535,15 +15021,17 @@ class CreateOutputOutputHumioHecTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputHumioHec(BaseModel): +class CreateOutputOutputCrowdstrikeNextGenSiem(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputHumioHecType + type: CreateOutputOutputCrowdstrikeNextGenSiemType r"""Connector type identifier.""" url: str - r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + r"""URL provided from a CrowdStrike data connector. + Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector + """ format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" @@ -14622,7 +15110,7 @@ class CreateOutputOutputHumioHec(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -14651,7 +15139,7 @@ class CreateOutputOutputHumioHec(BaseModel): r"""Optional description for this configuration.""" token: Optional[str] = None - r"""CrowdStrike Falcon LogScale authentication token""" + r"""Next-Gen SIEM authentication token""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -14706,7 +15194,7 @@ class CreateOutputOutputHumioHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputHumioHecPqControls], + Optional[CreateOutputOutputCrowdstrikeNextGenSiemPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -14753,7 +15241,7 @@ def serialize_format_(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -14854,25 +15342,29 @@ def serialize_model(self, handler): return m -class CreateOutputOutputCriblSearchEngineType(str, Enum): +class CreateOutputOutputHumioHecType(str, Enum): r"""Connector type identifier.""" - CRIBL_SEARCH_ENGINE = "cribl_search_engine" + HUMIO_HEC = "humio_hec" -class CreateOutputOutputCriblSearchEnginePqControlsTypedDict(TypedDict): +class CreateOutputOutputHumioHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputCriblSearchEnginePqControls(BaseModel): +class CreateOutputOutputHumioHecPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputCriblSearchEngineTypedDict(TypedDict): +class CreateOutputOutputHumioHecTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCriblSearchEngineType + type: CreateOutputOutputHumioHecType r"""Connector type identifier.""" + url: str + r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + format_: RequestFormatOptions + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -14881,22 +15373,14 @@ class CreateOutputOutputCriblSearchEngineTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - exclude_fields: NotRequired[List[str]] - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -14910,12 +15394,14 @@ class CreateOutputOutputCriblSearchEngineTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -14923,24 +15409,14 @@ class CreateOutputOutputCriblSearchEngineTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] - r"""Cribl Worker endpoints""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""CrowdStrike Falcon LogScale authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -14963,25 +15439,31 @@ class CreateOutputOutputCriblSearchEngineTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputCriblSearchEnginePqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputHumioHecPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputCriblSearchEngine(BaseModel): +class CreateOutputOutputHumioHec(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCriblSearchEngineType + type: CreateOutputOutputHumioHecType r"""Connector type identifier.""" + url: str + r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + + format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -14996,27 +15478,6 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") - ] = None - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") - ] = None - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - - compression: Optional[CompressionOptionsGzipNone] = None - r"""Codec to use to compress the data before sending""" - concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -15030,6 +15491,9 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): ] = None r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -15057,6 +15521,11 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -15068,10 +15537,11 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], @@ -15088,42 +15558,19 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: Annotated[ - Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[URLConfOutputCriblHTTP]] = None - r"""Cribl Worker endpoints""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + token: Optional[str] = None + r"""CrowdStrike Falcon LogScale authentication token""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -15175,7 +15622,7 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputCriblSearchEnginePqControls], + Optional[CreateOutputOutputHumioHecPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -15185,6 +15632,11 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -15195,25 +15647,29 @@ class CreateOutputOutputCriblSearchEngine(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipNone(value) + return models.RequestFormatOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -15262,34 +15718,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "tls", - "tokenTTLMinutes", - "excludeFields", - "compression", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", + "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "throttleRatePerSec", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "authTokens", "onBackpressure", - "useRoundRobinDns", "description", - "url", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -15303,9 +15751,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", ] ) serialized = handler(self) @@ -15322,24 +15770,35 @@ def serialize_model(self, handler): return m -class CreateOutputOutputCriblHTTPType(str, Enum): +class CreateOutputOutputCriblSearchEngineType(str, Enum): r"""Connector type identifier.""" - CRIBL_HTTP = "cribl_http" + CRIBL_SEARCH_ENGINE = "cribl_search_engine" -class CreateOutputOutputCriblHTTPPqControlsTypedDict(TypedDict): +class CreateOutputSendAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + + # Logs + LOGS = "logs" + # Metrics + METRICS = "metrics" + # Logs and Metrics + BOTH = "both" + + +class CreateOutputOutputCriblSearchEnginePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputCriblHTTPPqControls(BaseModel): +class CreateOutputOutputCriblSearchEnginePqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputCriblHTTPTypedDict(TypedDict): +class CreateOutputOutputCriblSearchEngineTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCriblHTTPType + type: CreateOutputOutputCriblSearchEngineType r"""Connector type identifier.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -15392,15 +15851,17 @@ class CreateOutputOutputCriblHTTPTypedDict(TypedDict): response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + send_as: NotRequired[CreateOutputSendAs] + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" description: NotRequired[str] r"""Optional description for this configuration.""" url: NotRequired[str] r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] @@ -15431,7 +15892,7 @@ class CreateOutputOutputCriblHTTPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputCriblHTTPPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputCriblSearchEnginePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -15443,11 +15904,11 @@ class CreateOutputOutputCriblHTTPTypedDict(TypedDict): r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputCriblHTTP(BaseModel): +class CreateOutputOutputCriblSearchEngine(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCriblHTTPType + type: CreateOutputOutputCriblSearchEngineType r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -15559,24 +16020,29 @@ class CreateOutputOutputCriblHTTP(BaseModel): auth_tokens: Annotated[ Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + send_as: Annotated[Optional[CreateOutputSendAs], pydantic.Field(alias="sendAs")] = ( + None + ) + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + description: Optional[str] = None r"""Optional description for this configuration.""" url: Optional[str] = None r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" @@ -15643,7 +16109,7 @@ class CreateOutputOutputCriblHTTP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputCriblHTTPPqControls], + Optional[CreateOutputOutputCriblSearchEnginePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -15695,6 +16161,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("send_as") + def serialize_send_as(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSendAs(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -15751,9 +16226,10 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "authTokens", "onBackpressure", + "sendAs", + "useRoundRobinDns", "description", "url", - "useRoundRobinDns", "excludeSelf", "urls", "dnsResolvePeriodSec", @@ -15790,18 +16266,24 @@ def serialize_model(self, handler): return m -class CreateOutputOutputCriblTCPPqControlsTypedDict(TypedDict): +class CreateOutputOutputCriblHTTPType(str, Enum): + r"""Connector type identifier.""" + + CRIBL_HTTP = "cribl_http" + + +class CreateOutputOutputCriblHTTPPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputCriblTCPPqControls(BaseModel): +class CreateOutputOutputCriblHTTPPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputCriblTCPTypedDict(TypedDict): +class CreateOutputOutputCriblHTTPTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsCribltcp + type: CreateOutputOutputCriblHTTPType r"""Connector type identifier.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -15812,43 +16294,65 @@ class CreateOutputOutputCriblTCPTypedDict(TypedDict): streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" load_balanced: NotRequired[bool] - r"""Use load-balanced destinations""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" exclude_fields: NotRequired[List[str]] r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" + url: NotRequired[str] + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" + urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] + r"""Cribl Worker endpoints""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15871,23 +16375,23 @@ class CreateOutputOutputCriblTCPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputCriblTCPPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputCriblHTTPPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputCriblTCP(BaseModel): +class CreateOutputOutputCriblHTTP(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsCribltcp + type: CreateOutputOutputCriblHTTPType r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -15907,48 +16411,99 @@ class CreateOutputOutputCriblTCP(BaseModel): load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Use load-balanced destinations""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") + ] = None + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" + + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") + ] = None + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" compression: Optional[CompressionOptionsGzipNone] = None r"""Codec to use to compress the data before sending""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" throttle_rate_per_sec: Annotated[ Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") ] = None - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -15958,17 +16513,19 @@ class CreateOutputOutputCriblTCP(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - host: Optional[str] = None - r"""The hostname of the receiver""" + url: Optional[str] = None + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - port: Optional[float] = None - r"""The port to connect to on the provided host""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" + urls: Optional[List[URLConfOutputCriblHTTP]] = None + r"""Cribl Worker endpoints""" dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") @@ -15980,11 +16537,6 @@ class CreateOutputOutputCriblTCP(BaseModel): ] = None r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") - ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -16035,7 +16587,7 @@ class CreateOutputOutputCriblTCP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputCriblTCPPqControls], + Optional[CreateOutputOutputCriblHTTPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -16045,20 +16597,20 @@ class CreateOutputOutputCriblTCP(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" @field_serializer("compression") def serialize_compression(self, value): @@ -16069,6 +16621,15 @@ def serialize_compression(self, value): return value return value + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -16114,24 +16675,33 @@ def serialize_model(self, handler): "environment", "streamtags", "loadBalanced", - "compression", - "logFailedRequests", - "throttleRatePerSec", "tls", - "connectionTimeout", - "writeTimeout", "tokenTTLMinutes", - "authTokens", "excludeFields", + "compression", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "throttleRatePerSec", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "authTokens", "onBackpressure", "description", - "host", - "port", + "url", + "useRoundRobinDns", "excludeSelf", - "hosts", + "urls", "dnsResolvePeriodSec", "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16145,9 +16715,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_host", - "__template_port", + "__template_url", ] ) serialized = handler(self) @@ -16164,54 +16734,18 @@ def serialize_model(self, handler): return m -class CreateOutputOutputDatasetType(str, Enum): - r"""Connector type identifier.""" - - DATASET = "dataset" - - -class CreateOutputOutputDatasetSeverity(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - - # 0 - finest - FINEST = "finest" - # 1 - finer - FINER = "finer" - # 2 - fine - FINE = "fine" - # 3 - info - INFO = "info" - # 4 - warning - WARNING = "warning" - # 5 - error - ERROR = "error" - # 6 - fatal - FATAL = "fatal" - - -class CreateOutputDataSetSite(str, Enum, metaclass=utils.OpenEnumMeta): - r"""DataSet site to which events should be sent""" - - # US - US = "us" - # Europe - EU = "eu" - # Custom - CUSTOM = "custom" - - -class CreateOutputOutputDatasetPqControlsTypedDict(TypedDict): +class CreateOutputOutputCriblTCPPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputDatasetPqControls(BaseModel): +class CreateOutputOutputCriblTCPPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputDatasetTypedDict(TypedDict): +class CreateOutputOutputCriblTCPTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDatasetType + type: TypeOptionsCribltcp r"""Connector type identifier.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -16221,61 +16755,44 @@ class CreateOutputOutputDatasetTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - message_field: NotRequired[str] - r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" + load_balanced: NotRequired[bool] + r"""Use load-balanced destinations""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + token_ttl_minutes: NotRequired[float] + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" exclude_fields: NotRequired[List[str]] - r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - server_host_field: NotRequired[str] - r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - timestamp_field: NotRequired[str] - r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - default_severity: NotRequired[CreateOutputOutputDatasetSeverity] - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - site: NotRequired[CreateOutputDataSetSite] - r"""DataSet site to which events should be sent""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16298,27 +16815,23 @@ class CreateOutputOutputDatasetTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputDatasetPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputCriblTCPPqControlsTypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""A 'Log Write Access' API key for the DataSet account""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: NotRequired[str] - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputOutputDataset(BaseModel): +class CreateOutputOutputCriblTCP(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDatasetType + type: TypeOptionsCribltcp r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -16335,126 +16848,86 @@ class CreateOutputOutputDataset(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None - r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" - - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") - ] = None - r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - - server_host_field: Annotated[ - Optional[str], pydantic.Field(alias="serverHostField") - ] = None - r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - - timestamp_field: Annotated[ - Optional[str], pydantic.Field(alias="timestampField") - ] = None - r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - - default_severity: Annotated[ - Optional[CreateOutputOutputDatasetSeverity], - pydantic.Field(alias="defaultSeverity"), - ] = None - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - site: Optional[CreateOutputDataSetSite] = None - r"""DataSet site to which events should be sent""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Use load-balanced destinations""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + compression: Optional[CompressionOptionsGzipNone] = None + r"""Codec to use to compress the data before sending""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Use to troubleshoot issues with sending data""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Headers to add to all events""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + host: Optional[str] = None + r"""The hostname of the receiver""" + + port: Optional[float] = None + r"""The port to connect to on the provided host""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") + ] = None + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16506,60 +16979,36 @@ class CreateOutputOutputDataset(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputDatasetPqControls], + Optional[CreateOutputOutputCriblTCPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""A 'Log Write Access' API key for the DataSet account""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_customUrl") - ] = None - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - - @field_serializer("default_severity") - def serialize_default_severity(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputDatasetSeverity(value) - except ValueError: - return value - return value + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - @field_serializer("site") - def serialize_site(self, value): - if isinstance(value, str): - try: - return models.CreateOutputDataSetSite(value) - except ValueError: - return value - return value + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("compression") + def serialize_compression(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CompressionOptionsGzipNone(value) except ValueError: return value return value @@ -16573,15 +17022,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -16617,32 +17057,25 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "messageField", + "loadBalanced", + "compression", + "logFailedRequests", + "throttleRatePerSec", + "tls", + "connectionTimeout", + "writeTimeout", + "tokenTTLMinutes", + "authTokens", "excludeFields", - "serverHostField", - "timestampField", - "defaultSeverity", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "site", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", "onBackpressure", - "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16655,12 +17088,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_customUrl", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -16677,33 +17108,55 @@ def serialize_model(self, handler): return m -class CreateOutputOutputServiceNowType(str, Enum): +class CreateOutputOutputDatasetType(str, Enum): r"""Connector type identifier.""" - SERVICE_NOW = "service_now" + DATASET = "dataset" -class CreateOutputOutputServiceNowPqControlsTypedDict(TypedDict): +class CreateOutputOutputDatasetSeverity(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" + + # 0 - finest + FINEST = "finest" + # 1 - finer + FINER = "finer" + # 2 - fine + FINE = "fine" + # 3 - info + INFO = "info" + # 4 - warning + WARNING = "warning" + # 5 - error + ERROR = "error" + # 6 - fatal + FATAL = "fatal" + + +class CreateOutputDataSetSite(str, Enum, metaclass=utils.OpenEnumMeta): + r"""DataSet site to which events should be sent""" + + # US + US = "us" + # Europe + EU = "eu" + # Custom + CUSTOM = "custom" + + +class CreateOutputOutputDatasetPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputServiceNowPqControls(BaseModel): +class CreateOutputOutputDatasetPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputServiceNowTypedDict(TypedDict): +class CreateOutputOutputDatasetTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputServiceNowType + type: CreateOutputOutputDatasetType r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - token_secret: str - r"""Select or create a stored text secret""" - otlp_version: OtlpVersionOptions - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - protocol: ProtocolOptions - r"""Select a transport option for OpenTelemetry""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -16712,68 +17165,61 @@ class CreateOutputOutputServiceNowTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_token_name: NotRequired[str] - r"""Auth token name""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - compress: NotRequired[CompressionOptionsDeflateGzip] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_compress: NotRequired[CompressionOptionsMessages] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: NotRequired[str] - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_metrics_endpoint_override: NotRequired[str] - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: NotRequired[str] - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + message_field: NotRequired[str] + r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" + exclude_fields: NotRequired[List[str]] + r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" + server_host_field: NotRequired[str] + r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" + timestamp_field: NotRequired[str] + r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" + default_severity: NotRequired[CreateOutputOutputDatasetSeverity] + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + site: NotRequired[CreateOutputDataSetSite] + r"""DataSet site to which events should be sent""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] - r"""TLS settings (client side)""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16796,35 +17242,29 @@ class CreateOutputOutputServiceNowTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputServiceNowPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputDatasetPqControlsTypedDict] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""A 'Log Write Access' API key for the DataSet account""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_custom_url: NotRequired[str] + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" -class CreateOutputOutputServiceNow(BaseModel): +class CreateOutputOutputDataset(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputServiceNowType + type: CreateOutputOutputDatasetType r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - - token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] - r"""Select or create a stored text secret""" - - otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - - protocol: ProtocolOptions - r"""Select a transport option for OpenTelemetry""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -16839,59 +17279,71 @@ class CreateOutputOutputServiceNow(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( - None - ) - r"""Auth token name""" + message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None + r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + server_host_field: Annotated[ + Optional[str], pydantic.Field(alias="serverHostField") ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - compress: Optional[CompressionOptionsDeflateGzip] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + timestamp_field: Annotated[ + Optional[str], pydantic.Field(alias="timestampField") + ] = None + r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - http_compress: Annotated[ - Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + default_severity: Annotated[ + Optional[CreateOutputOutputDatasetSeverity], + pydantic.Field(alias="defaultSeverity"), ] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - http_traces_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - http_metrics_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + site: Optional[CreateOutputDataSetSite] = None + r"""DataSet site to which events should be sent""" - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + r"""Maximum size, in KB, of the request body""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -16906,74 +17358,47 @@ class CreateOutputOutputServiceNow(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often the sender should ping the peer to keep the connection open""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Headers to add to all events""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None r"""List of headers that are safe to log in plain text""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""How to handle events when all receivers are exerting backpressure""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") ] = None + r"""Enter API key directly, or select a stored secret""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - tls: Optional[TLSSettingsClientSideTypeExtended] = None - r"""TLS settings (client side)""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17025,11 +17450,17 @@ class CreateOutputOutputServiceNow(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputServiceNowPqControls], + Optional[CreateOutputOutputDatasetPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""A 'Log Write Access' API key for the DataSet account""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -17045,38 +17476,25 @@ class CreateOutputOutputServiceNow(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.OtlpVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptions(value) - except ValueError: - return value - return value + template_custom_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_customUrl") + ] = None + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("default_severity") + def serialize_default_severity(self, value): if isinstance(value, str): try: - return models.CompressionOptionsDeflateGzip(value) + return models.CreateOutputOutputDatasetSeverity(value) except ValueError: return value return value - @field_serializer("http_compress") - def serialize_http_compress(self, value): + @field_serializer("site") + def serialize_site(self, value): if isinstance(value, str): try: - return models.CompressionOptionsMessages(value) + return models.CreateOutputDataSetSite(value) except ValueError: return value return value @@ -17099,6 +17517,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -17134,35 +17561,32 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authTokenName", + "messageField", + "excludeFields", + "serverHostField", + "timestampField", + "defaultSeverity", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "site", + "concurrency", "maxPayloadSizeKB", - "preserveNativeAnyValue", + "maxPayloadEvents", "compress", - "httpCompress", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", - "httpLogsEndpointOverride", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", - "concurrency", + "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "keepAlive", + "safeHeaders", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "rejectUnauthorized", - "useRoundRobinDns", - "extraHttpHeaders", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "tls", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17175,9 +17599,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_customUrl", ] ) serialized = handler(self) @@ -17194,57 +17621,33 @@ def serialize_model(self, handler): return m -class CreateOutputOutputOpenTelemetryType(str, Enum): +class CreateOutputOutputServiceNowType(str, Enum): r"""Connector type identifier.""" - OPEN_TELEMETRY = "open_telemetry" - - -class CreateOutputOutputOpenTelemetryOTLPVersion( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - - # 0.10.0 - ZERO_DOT_10_DOT_0 = "0.10.0" - # 1.3.1 - ONE_DOT_3_DOT_1 = "1.3.1" - - -class CreateOutputOutputOpenTelemetryAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth (text secret) - OAUTH_SECRET = "oauthSecret" + SERVICE_NOW = "service_now" -class CreateOutputOutputOpenTelemetryPqControlsTypedDict(TypedDict): +class CreateOutputOutputServiceNowPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputOpenTelemetryPqControls(BaseModel): +class CreateOutputOutputServiceNowPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputOpenTelemetryTypedDict(TypedDict): +class CreateOutputOutputServiceNowTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputOpenTelemetryType + type: CreateOutputOutputServiceNowType r"""Connector type identifier.""" endpoint: str - r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" + r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + token_secret: str + r"""Select or create a stored text secret""" + otlp_version: OtlpVersionOptions + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + protocol: ProtocolOptions + r"""Select a transport option for OpenTelemetry""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -17253,18 +17656,16 @@ class CreateOutputOutputOpenTelemetryTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[ProtocolOptions] - r"""Select a transport option for OpenTelemetry""" - otlp_version: NotRequired[CreateOutputOutputOpenTelemetryOTLPVersion] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + auth_token_name: NotRequired[str] + r"""Auth token name""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" preserve_native_any_value: NotRequired[bool] r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" compress: NotRequired[CompressionOptionsDeflateGzip] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" http_compress: NotRequired[CompressionOptionsMessages] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - auth_type: NotRequired[CreateOutputOutputOpenTelemetryAuthenticationType] - r"""Authentication type""" http_traces_endpoint_override: NotRequired[str] r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" http_metrics_endpoint_override: NotRequired[str] @@ -17279,8 +17680,6 @@ class CreateOutputOutputOpenTelemetryTypedDict(TypedDict): r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] @@ -17299,32 +17698,6 @@ class CreateOutputOutputOpenTelemetryTypedDict(TypedDict): r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" - oauth_text_secret: NotRequired[str] - r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -17367,7 +17740,7 @@ class CreateOutputOutputOpenTelemetryTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputOpenTelemetryPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputServiceNowPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -17375,19 +17748,26 @@ class CreateOutputOutputOpenTelemetryTypedDict(TypedDict): r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" -class CreateOutputOutputOpenTelemetry(BaseModel): +class CreateOutputOutputServiceNow(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputOpenTelemetryType + type: CreateOutputOutputServiceNowType r"""Connector type identifier.""" endpoint: str - r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" + r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" + + otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + protocol: ProtocolOptions + r"""Select a transport option for OpenTelemetry""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -17403,14 +17783,15 @@ class CreateOutputOutputOpenTelemetry(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[ProtocolOptions] = None - r"""Select a transport option for OpenTelemetry""" + auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( + None + ) + r"""Auth token name""" - otlp_version: Annotated[ - Optional[CreateOutputOutputOpenTelemetryOTLPVersion], - pydantic.Field(alias="otlpVersion"), + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + r"""Maximum size, in KB, of the request body""" preserve_native_any_value: Annotated[ Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") @@ -17425,12 +17806,6 @@ class CreateOutputOutputOpenTelemetry(BaseModel): ] = None r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - auth_type: Annotated[ - Optional[CreateOutputOutputOpenTelemetryAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""Authentication type""" - http_traces_endpoint_override: Annotated[ Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") ] = None @@ -17462,11 +17837,6 @@ class CreateOutputOutputOpenTelemetry(BaseModel): concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -17507,63 +17877,6 @@ class CreateOutputOutputOpenTelemetry(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - - oauth_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="oauthTextSecret") - ] = None - r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" - - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -17656,7 +17969,7 @@ class CreateOutputOutputOpenTelemetry(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputOpenTelemetryPqControls], + Optional[CreateOutputOutputServiceNowPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -17676,25 +17989,20 @@ class CreateOutputOutputOpenTelemetry(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - @field_serializer("protocol") - def serialize_protocol(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.ProtocolOptions(value) + return models.OtlpVersionOptions(value) except ValueError: return value return value - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputOpenTelemetryOTLPVersion(value) + return models.ProtocolOptions(value) except ValueError: return value return value @@ -17717,277 +18025,47 @@ def serialize_http_compress(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputOpenTelemetryAuthenticationType(value) - except ValueError: - return value - return value - @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPq(value) - except ValueError: - return value - return value - - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "protocol", - "otlpVersion", - "preserveNativeAnyValue", - "compress", - "httpCompress", - "authType", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", - "httpLogsEndpointOverride", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", - "concurrency", - "maxPayloadSizeKB", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "keepAlive", - "onBackpressure", - "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", - "oauthTextSecret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "rejectUnauthorized", - "useRoundRobinDns", - "extraHttpHeaders", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "tls", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "__template_streamtags", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - "__template_loginUrl", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputRingType(str, Enum): - r"""Connector type identifier.""" - - RING = "ring" - - -class CreateOutputOutputRingDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of the output data.""" - - JSON = "json" - RAW = "raw" - - -class CreateOutputOutputRingTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputRingType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - format_: NotRequired[CreateOutputOutputRingDataFormat] - r"""Format of the output data.""" - partition_expr: NotRequired[str] - r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - -class CreateOutputOutputRing(BaseModel): - id: str - r"""Unique ID for this output""" - - type: CreateOutputOutputRingType - r"""Connector type identifier.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - format_: Annotated[ - Optional[CreateOutputOutputRingDataFormat], pydantic.Field(alias="format") - ] = None - r"""Format of the output data.""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputRingDataFormat(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.DataCompressionFormatOptionsPersistence(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -18000,15 +18078,49 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "format", - "partitionExpr", - "maxDataSize", - "maxDataTime", + "authTokenName", + "maxPayloadSizeKB", + "preserveNativeAnyValue", "compress", - "destPath", + "httpCompress", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", + "concurrency", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", "onBackpressure", "description", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "tls", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", ] ) @@ -18026,10 +18138,27 @@ def serialize_model(self, handler): return m -class CreateOutputOutputPrometheusAuthenticationType( +class CreateOutputOutputOpenTelemetryType(str, Enum): + r"""Connector type identifier.""" + + OPEN_TELEMETRY = "open_telemetry" + + +class CreateOutputOutputOpenTelemetryOTLPVersion( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Remote Write authentication type""" + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + # 0.10.0 + ZERO_DOT_10_DOT_0 = "0.10.0" + # 1.3.1 + ONE_DOT_3_DOT_1 = "1.3.1" + + +class CreateOutputOutputOpenTelemetryAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" # None NONE = "none" @@ -18041,62 +18170,114 @@ class CreateOutputOutputPrometheusAuthenticationType( TOKEN = "token" # Token (text secret) TEXT_SECRET = "textSecret" - # AWS Signature v4 - AWS_SIGV4 = "aws_sigv4" + # OAuth (text secret) + OAUTH_SECRET = "oauthSecret" -class CreateOutputOutputPrometheusPqControlsTypedDict(TypedDict): +class CreateOutputOutputOpenTelemetryPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputPrometheusPqControls(BaseModel): +class CreateOutputOutputOpenTelemetryPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputPrometheusTypedDict(TypedDict): +class CreateOutputOutputOpenTelemetryTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsPrometheus + type: CreateOutputOutputOpenTelemetryType r"""Connector type identifier.""" - url: str - r"""The endpoint to send metrics to""" + endpoint: str + r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - send_metadata: NotRequired[bool] - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - use_prometheus_histogram_bucket_suffix: NotRequired[bool] - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" + protocol: NotRequired[ProtocolOptions] + r"""Select a transport option for OpenTelemetry""" + otlp_version: NotRequired[CreateOutputOutputOpenTelemetryOTLPVersion] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + auth_type: NotRequired[CreateOutputOutputOpenTelemetryAuthenticationType] + r"""Authentication type""" + http_traces_endpoint_override: NotRequired[str] + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_metrics_endpoint_override: NotRequired[str] + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" response_retry_settings: NotRequired[ @@ -18106,14 +18287,8 @@ class CreateOutputOutputPrometheusTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputOutputPrometheusAuthenticationType] - r"""Remote Write authentication type""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - metrics_flush_period_sec: NotRequired[float] - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -18136,61 +18311,27 @@ class CreateOutputOutputPrometheusTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputPrometheusPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputOpenTelemetryPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - region: NotRequired[str] - r"""AWS region used to sign Remote Write requests""" - aws_service: NotRequired[str] - r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Prometheus""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_aws_service: NotRequired[str] - r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" -class CreateOutputOutputPrometheus(BaseModel): +class CreateOutputOutputOpenTelemetry(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsPrometheus + type: CreateOutputOutputOpenTelemetryType r"""Connector type identifier.""" - url: str - r"""The endpoint to send metrics to""" + endpoint: str + r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -18198,7 +18339,7 @@ class CreateOutputOutputPrometheus(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -18206,20 +18347,61 @@ class CreateOutputOutputPrometheus(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") + protocol: Optional[ProtocolOptions] = None + r"""Select a transport option for OpenTelemetry""" + + otlp_version: Annotated[ + Optional[CreateOutputOutputOpenTelemetryOTLPVersion], + pydantic.Field(alias="otlpVersion"), ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( - None - ) - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - use_prometheus_histogram_bucket_suffix: Annotated[ - Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") ] = None - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + auth_type: Annotated[ + Optional[CreateOutputOutputOpenTelemetryAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + + http_traces_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") + ] = None + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + http_metrics_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") + ] = None + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + ] = None + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + ] = None + r"""Batch event data upon dynamic metadata (whether presented or not)""" + + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") + ] = None + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -18229,19 +18411,6 @@ class CreateOutputOutputPrometheus(BaseModel): ] = None r"""Maximum size, in KB, of the request body""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -18255,22 +18424,108 @@ class CreateOutputOutputPrometheus(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Headers to add to all events""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") @@ -18292,24 +18547,8 @@ class CreateOutputOutputPrometheus(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - auth_type: Annotated[ - Optional[CreateOutputOutputPrometheusAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - metrics_flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") - ] = None - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18345,89 +18584,32 @@ class CreateOutputOutputPrometheus(BaseModel): pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[CreateOutputOutputPrometheusPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsAutoSecret], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - region: Optional[str] = None - r"""AWS region used to sign Remote Write requests""" - - aws_service: Annotated[Optional[str], pydantic.Field(alias="awsService")] = None - r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Use Assume Role credentials to access Prometheus""" + r"""Codec to use to compress the persisted data""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""External ID to use when assuming role""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + pq_controls: Annotated[ + Optional[CreateOutputOutputOpenTelemetryPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Persistent queue controls.""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -18438,40 +18620,43 @@ class CreateOutputOutputPrometheus(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_aws_service: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsService") + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") ] = None - r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptions(value) + except ValueError: + return value + return value - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputOpenTelemetryOTLPVersion(value) + except ValueError: + return value + return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CompressionOptionsDeflateGzip(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("http_compress") + def serialize_http_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptionsMessages(value) except ValueError: return value return value @@ -18480,7 +18665,25 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputPrometheusAuthenticationType(value) + return models.CreateOutputOutputOpenTelemetryAuthenticationType(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -18512,15 +18715,6 @@ def serialize_pq_on_backpressure(self, value): return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAutoSecret(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -18529,27 +18723,50 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "metricRenameExpr", - "sendMetadata", - "usePrometheusHistogramBucketSuffix", + "protocol", + "otlpVersion", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "authType", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "onBackpressure", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "oauthTextSecret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "description", - "metricsFlushPeriodSec", + "tls", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -18562,27 +18779,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "awsAuthenticationMethod", - "awsSecret", - "region", - "awsService", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", "__template_streamtags", - "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_region", - "__template_awsService", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_loginUrl", ] ) serialized = handler(self) @@ -18599,165 +18799,68 @@ def serialize_model(self, handler): return m -class CreateOutputOutputAmazonManagedPrometheusType(str, Enum): +class CreateOutputOutputRingType(str, Enum): r"""Connector type identifier.""" - AMAZON_MANAGED_PROMETHEUS = "amazon_managed_prometheus" - + RING = "ring" -class CreateOutputOutputAmazonManagedPrometheusPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputOutputRingDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of the output data.""" -class CreateOutputOutputAmazonManagedPrometheusPqControls(BaseModel): - r"""Persistent queue controls.""" + JSON = "json" + RAW = "raw" -class CreateOutputOutputAmazonManagedPrometheusTypedDict(TypedDict): +class CreateOutputOutputRingTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputAmazonManagedPrometheusType + type: CreateOutputOutputRingType r"""Connector type identifier.""" - url: str - r"""The Amazon Managed Service for Prometheus remote_write endpoint""" - aws_authentication_method: AuthenticationMethodOptionsAutoSecret - r"""AWS authentication method. Choose Auto to use IAM roles.""" - region: str - r"""Region where the AMSP is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access AMSP""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - send_metadata: NotRequired[bool] - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - use_prometheus_histogram_bucket_suffix: NotRequired[bool] - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + format_: NotRequired[CreateOutputOutputRingDataFormat] + r"""Format of the output data.""" + partition_expr: NotRequired[str] + r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - metrics_flush_period_sec: NotRequired[float] - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputOutputAmazonManagedPrometheusPqControlsTypedDict - ] - r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputAmazonManagedPrometheus(BaseModel): +class CreateOutputOutputRing(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputAmazonManagedPrometheusType + type: CreateOutputOutputRingType r"""Connector type identifier.""" - url: str - r"""The Amazon Managed Service for Prometheus remote_write endpoint""" - - aws_authentication_method: Annotated[ - AuthenticationMethodOptionsAutoSecret, - pydantic.Field(alias="awsAuthenticationMethod"), - ] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - region: str - r"""Region where the AMSP is located""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -18765,242 +18868,61 @@ class CreateOutputOutputAmazonManagedPrometheus(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access AMSP""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") + format_: Annotated[ + Optional[CreateOutputOutputRingDataFormat], pydantic.Field(alias="format") ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + r"""Format of the output data.""" - send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( None ) - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - - use_prometheus_histogram_bucket_suffix: Annotated[ - Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") - ] = None - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - metrics_flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") - ] = None - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[CreateOutputOutputAmazonManagedPrometheusPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""How to handle events when all receivers are exerting backpressure""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAutoSecret(value) + return models.CreateOutputOutputRingDataFormat(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataCompressionFormatOptionsPersistence(value) except ValueError: return value return value @@ -19009,34 +18931,7 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPq(value) - except ValueError: - return value - return value - - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value @@ -19049,51 +18944,15 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsSecretKey", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "metricRenameExpr", - "sendMetadata", - "usePrometheusHistogramBucketSuffix", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "format", + "partitionExpr", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", "onBackpressure", "description", - "awsSecret", - "metricsFlushPeriodSec", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", "__template_streamtags", - "__template_url", - "__template_awsSecretKey", - "__template_region", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_failedRequestLoggingMode", "__template_onBackpressure", ] ) @@ -19111,53 +18970,60 @@ def serialize_model(self, handler): return m -class CreateOutputOutputLokiType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputOutputPrometheusAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Remote Write authentication type""" - LOKI = "loki" + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # AWS Signature v4 + AWS_SIGV4 = "aws_sigv4" -class CreateOutputOutputLokiPqControlsTypedDict(TypedDict): +class CreateOutputOutputPrometheusPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputLokiPqControls(BaseModel): +class CreateOutputOutputPrometheusPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputLokiTypedDict(TypedDict): +class CreateOutputOutputPrometheusTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputLokiType + type: TypeOptionsPrometheus r"""Connector type identifier.""" url: str - r"""The endpoint to send logs to""" + r"""The endpoint to send metrics to""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - message: NotRequired[str] - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - message_format: NotRequired[MessageFormatOptions] - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - labels: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - auth_type: NotRequired[ - AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret - ] - r"""Authentication type""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + send_metadata: NotRequired[bool] + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + use_prometheus_histogram_bucket_suffix: NotRequired[bool] + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -19168,7 +19034,7 @@ class CreateOutputOutputLokiTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -19184,26 +19050,14 @@ class CreateOutputOutputLokiTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_dynamic_headers: NotRequired[bool] - r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[CreateOutputOutputPrometheusAuthenticationType] + r"""Remote Write authentication type""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - username: NotRequired[str] - r"""Username for authentication""" - password: NotRequired[str] - r"""Password (API key in Grafana Cloud domain) for authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" + metrics_flush_period_sec: NotRequired[float] + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -19226,25 +19080,61 @@ class CreateOutputOutputLokiTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputLokiPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputPrometheusPqControlsTypedDict] r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + region: NotRequired[str] + r"""AWS region used to sign Remote Write requests""" + aws_service: NotRequired[str] + r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Prometheus""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_aws_service: NotRequired[str] + r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" -class CreateOutputOutputLoki(BaseModel): +class CreateOutputOutputPrometheus(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputLokiType + type: TypeOptionsPrometheus r"""Connector type identifier.""" url: str - r"""The endpoint to send logs to""" + r"""The endpoint to send metrics to""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -19252,45 +19142,41 @@ class CreateOutputOutputLoki(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - message: Optional[str] = None - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - - message_format: Annotated[ - Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") - ] = None - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - labels: Optional[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") ] = None - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret], - pydantic.Field(alias="authType"), + send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + None + ) + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + + use_prometheus_histogram_bucket_suffix: Annotated[ + Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") ] = None - r"""Authentication type""" + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -19311,7 +19197,7 @@ class CreateOutputOutputLoki(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -19350,43 +19236,24 @@ class CreateOutputOutputLoki(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_dynamic_headers: Annotated[ - Optional[bool], pydantic.Field(alias="enableDynamicHeaders") - ] = None - r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + auth_type: Annotated[ + Optional[CreateOutputOutputPrometheusAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Remote Write authentication type""" description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - username: Optional[str] = None - r"""Username for authentication""" - - password: Optional[str] = None - r"""Password (API key in Grafana Cloud domain) for authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + metrics_flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") ] = None - r"""Select or create a secret that references your credentials""" + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19438,15 +19305,73 @@ class CreateOutputOutputLoki(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputLokiPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputPrometheusPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsAutoSecret], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + region: Optional[str] = None + r"""AWS region used to sign Remote Write requests""" + + aws_service: Annotated[Optional[str], pydantic.Field(alias="awsService")] = None + r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Prometheus""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -19457,25 +19382,25 @@ class CreateOutputOutputLoki(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("message_format") - def serialize_message_format(self, value): - if isinstance(value, str): - try: - return models.MessageFormatOptions(value) - except ValueError: - return value - return value + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret( - value - ) - except ValueError: - return value - return value + template_aws_service: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsService") + ] = None + r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): @@ -19495,6 +19420,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputPrometheusAuthenticationType(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -19522,6 +19456,15 @@ def serialize_pq_on_backpressure(self, value): return value return value + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAutoSecret(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -19530,10 +19473,9 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "message", - "messageFormat", - "labels", - "authType", + "metricRenameExpr", + "sendMetadata", + "usePrometheusHistogramBucketSuffix", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -19548,16 +19490,10 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "enableDynamicHeaders", "onBackpressure", - "totalMemoryLimitKB", + "authType", "description", - "compress", - "token", - "textSecret", - "username", - "password", - "credentialsSecret", + "metricsFlushPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -19570,9 +19506,27 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "awsAuthenticationMethod", + "awsSecret", + "region", + "awsService", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "__template_streamtags", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_region", + "__template_awsService", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", ] ) serialized = handler(self) @@ -19589,68 +19543,74 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGrafanaCloudType2(str, Enum): +class CreateOutputOutputAmazonManagedPrometheusType(str, Enum): r"""Connector type identifier.""" - GRAFANA_CLOUD = "grafana_cloud" + AMAZON_MANAGED_PROMETHEUS = "amazon_managed_prometheus" -class CreateOutputOutputGrafanaCloudPqControls2TypedDict(TypedDict): +class CreateOutputOutputAmazonManagedPrometheusPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputGrafanaCloudPqControls2(BaseModel): +class CreateOutputOutputAmazonManagedPrometheusPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): +class CreateOutputOutputAmazonManagedPrometheusTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGrafanaCloudType2 + type: CreateOutputOutputAmazonManagedPrometheusType r"""Connector type identifier.""" - prometheus_url: str - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + url: str + r"""The Amazon Managed Service for Prometheus remote_write endpoint""" + aws_authentication_method: AuthenticationMethodOptionsAutoSecret + r"""AWS authentication method. Choose Auto to use IAM roles.""" + region: str + r"""Region where the AMSP is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - loki_url: NotRequired[str] - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" - message: NotRequired[str] - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - message_format: NotRequired[MessageFormatOptions] - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - labels: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] - loki_auth: NotRequired[PrometheusAuthTypeTypedDict] - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), that value will take precedence. """ + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access AMSP""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + send_metadata: NotRequired[bool] + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + use_prometheus_histogram_bucket_suffix: NotRequired[bool] + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" use_round_robin_dns: NotRequired[bool] r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] @@ -19668,8 +19628,10 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[bool] - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + metrics_flush_period_sec: NotRequired[float] + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -19692,29 +19654,46 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputGrafanaCloudPqControls2TypedDict] + pq_controls: NotRequired[ + CreateOutputOutputAmazonManagedPrometheusPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: NotRequired[str] - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - template_prometheus_url: NotRequired[str] - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): +class CreateOutputOutputAmazonManagedPrometheus(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGrafanaCloudType2 + type: CreateOutputOutputAmazonManagedPrometheusType r"""Connector type identifier.""" - prometheus_url: Annotated[str, pydantic.Field(alias="prometheusUrl")] - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + url: str + r"""The Amazon Managed Service for Prometheus remote_write endpoint""" + + aws_authentication_method: Annotated[ + AuthenticationMethodOptionsAutoSecret, + pydantic.Field(alias="awsAuthenticationMethod"), + ] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + region: str + r"""Region where the AMSP is located""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -19722,7 +19701,7 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -19730,55 +19709,66 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - loki_url: Annotated[Optional[str], pydantic.Field(alias="lokiUrl")] = None - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - message: Optional[str] = None - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - message_format: Annotated[ - Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + r"""Use Assume Role credentials to access AMSP""" - labels: Optional[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" metric_rename_expr: Annotated[ Optional[str], pydantic.Field(alias="metricRenameExpr") ] = None r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") - ] = None + send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + None + ) + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - loki_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") + use_prometheus_histogram_bucket_suffix: Annotated[ + Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") ] = None + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -19791,13 +19781,13 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Headers to add to all events""" + r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") @@ -19838,8 +19828,13 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + metrics_flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") + ] = None + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19891,7 +19886,7 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputGrafanaCloudPqControls2], + Optional[CreateOutputOutputAmazonManagedPrometheusPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -19901,15 +19896,30 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiUrl") + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_prometheus_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusUrl") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -19921,11 +19931,11 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("message_format") - def serialize_message_format(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.MessageFormatOptions(value) + return models.AuthenticationMethodOptionsAutoSecret(value) except ValueError: return value return value @@ -19983,17 +19993,18 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "lokiUrl", - "message", - "messageFormat", - "labels", + "awsSecretKey", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "metricRenameExpr", - "prometheusAuth", - "lokiAuth", + "sendMetadata", + "usePrometheusHistogramBucketSuffix", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", @@ -20006,7 +20017,8 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "description", - "compress", + "awsSecret", + "metricsFlushPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -20020,8 +20032,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_lokiUrl", - "__template_prometheusUrl", + "__template_url", + "__template_awsSecretKey", + "__template_region", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_failedRequestLoggingMode", "__template_onBackpressure", ] @@ -20040,37 +20055,35 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGrafanaCloudType1(str, Enum): +class CreateOutputOutputLokiType(str, Enum): r"""Connector type identifier.""" - GRAFANA_CLOUD = "grafana_cloud" + LOKI = "loki" -class CreateOutputOutputGrafanaCloudPqControls1TypedDict(TypedDict): +class CreateOutputOutputLokiPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputGrafanaCloudPqControls1(BaseModel): +class CreateOutputOutputLokiPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): +class CreateOutputOutputLokiTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGrafanaCloudType1 + type: CreateOutputOutputLokiType r"""Connector type identifier.""" - loki_url: str - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + url: str + r"""The endpoint to send logs to""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - prometheus_url: NotRequired[str] - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" message: NotRequired[str] r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" message_format: NotRequired[MessageFormatOptions] @@ -20079,16 +20092,16 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] ] r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] - loki_auth: NotRequired[PrometheusAuthTypeTypedDict] + auth_type: NotRequired[ + AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret + ] + r"""Authentication type""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -20099,7 +20112,7 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -20115,12 +20128,26 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + enable_dynamic_headers: NotRequired[bool] + r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" compress: NotRequired[bool] - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + r"""Compress the payload body before sending""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + username: NotRequired[str] + r"""Username for authentication""" + password: NotRequired[str] + r"""Password (API key in Grafana Cloud domain) for authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -20143,29 +20170,25 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputGrafanaCloudPqControls1TypedDict] + pq_controls: NotRequired[CreateOutputOutputLokiPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: NotRequired[str] - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - template_prometheus_url: NotRequired[str] - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): +class CreateOutputOutputLoki(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGrafanaCloudType1 + type: CreateOutputOutputLokiType r"""Connector type identifier.""" - loki_url: Annotated[str, pydantic.Field(alias="lokiUrl")] - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + url: str + r"""The endpoint to send logs to""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -20173,7 +20196,7 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -20181,11 +20204,6 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - prometheus_url: Annotated[Optional[str], pydantic.Field(alias="prometheusUrl")] = ( - None - ) - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" - message: Optional[str] = None r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" @@ -20199,31 +20217,24 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") - ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - - prometheus_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") - ] = None - - loki_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret], + pydantic.Field(alias="authType"), ] = None + r"""Authentication type""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -20244,7 +20255,7 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -20283,16 +20294,43 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + enable_dynamic_headers: Annotated[ + Optional[bool], pydantic.Field(alias="enableDynamicHeaders") + ] = None + r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" + on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" compress: Optional[bool] = None - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + r"""Compress the payload body before sending""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + username: Optional[str] = None + r"""Username for authentication""" + + password: Optional[str] = None + r"""Password (API key in Grafana Cloud domain) for authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -20344,8 +20382,7 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputGrafanaCloudPqControls1], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputLokiPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -20354,16 +20391,6 @@ class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiUrl") - ] = None - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - - template_prometheus_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusUrl") - ] = None - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -20383,6 +20410,17 @@ def serialize_message_format(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret( + value + ) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -20436,13 +20474,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "prometheusUrl", "message", "messageFormat", "labels", - "metricRenameExpr", - "prometheusAuth", - "lokiAuth", + "authType", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -20457,9 +20492,16 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", + "enableDynamicHeaders", "onBackpressure", + "totalMemoryLimitKB", "description", "compress", + "token", + "textSecret", + "username", + "password", + "credentialsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -20473,8 +20515,6 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_lokiUrl", - "__template_prometheusUrl", "__template_failedRequestLoggingMode", "__template_onBackpressure", ] @@ -20493,130 +20533,55 @@ def serialize_model(self, handler): return m -CreateOutputOutputGrafanaCloudUnionTypedDict = TypeAliasType( - "CreateOutputOutputGrafanaCloudUnionTypedDict", - Union[ - CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict, - CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict, - ], -) - - -CreateOutputOutputGrafanaCloudUnion = TypeAliasType( - "CreateOutputOutputGrafanaCloudUnion", - Union[ - CreateOutputOutputGrafanaCloudGrafanaCloud1, - CreateOutputOutputGrafanaCloudGrafanaCloud2, - ], -) - - -class CreateOutputOutputDatadogType(str, Enum): +class CreateOutputOutputGrafanaCloudType2(str, Enum): r"""Connector type identifier.""" - DATADOG = "datadog" - - -class CreateOutputSendLogsAs(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The content type to use when sending logs""" - - # text/plain - TEXT = "text" - # application/json - JSON = "json" - - -class CreateOutputOutputDatadogSeverity(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - - # emergency - EMERGENCY = "emergency" - # alert - ALERT = "alert" - # critical - CRITICAL = "critical" - # error - ERROR = "error" - # warning - WARNING = "warning" - # notice - NOTICE = "notice" - # info - INFO = "info" - # debug - DEBUG = "debug" - - -class CreateOutputDatadogSite(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Datadog site to which events should be sent""" - - # US - US = "us" - # US3 - US3 = "us3" - # US5 - US5 = "us5" - # Europe - EU = "eu" - # US1-FED - FED1 = "fed1" - # AP1 - AP1 = "ap1" - # Custom - CUSTOM = "custom" + GRAFANA_CLOUD = "grafana_cloud" -class CreateOutputOutputDatadogPqControlsTypedDict(TypedDict): +class CreateOutputOutputGrafanaCloudPqControls2TypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputDatadogPqControls(BaseModel): +class CreateOutputOutputGrafanaCloudPqControls2(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputDatadogTypedDict(TypedDict): +class CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDatadogType + type: CreateOutputOutputGrafanaCloudType2 r"""Connector type identifier.""" + prometheus_url: str + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - content_type: NotRequired[CreateOutputSendLogsAs] - r"""The content type to use when sending logs""" + loki_url: NotRequired[str] + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" message: NotRequired[str] r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - source: NotRequired[str] - r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" - host: NotRequired[str] - r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" - service: NotRequired[str] - r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" - tags: NotRequired[List[str]] - r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" - batch_by_tags: NotRequired[bool] - r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" - allow_api_key_from_events: NotRequired[bool] - r"""Allow API key to be set from the event's '__agent_api_key' field""" - severity: NotRequired[CreateOutputOutputDatadogSeverity] - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - site: NotRequired[CreateOutputDatadogSite] - r"""Datadog site to which events should be sent""" - send_counters_as_count: NotRequired[bool] - r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" + message_format: NotRequired[MessageFormatOptions] + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + labels: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] + loki_auth: NotRequired[PrometheusAuthTypeTypedDict] concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -20627,7 +20592,7 @@ class CreateOutputOutputDatadogTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -20645,13 +20610,10 @@ class CreateOutputOutputDatadogTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + compress: NotRequired[bool] + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -20674,36 +20636,37 @@ class CreateOutputOutputDatadogTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputDatadogPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputGrafanaCloudPqControls2TypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""Organization's API key in Datadog""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_tags: NotRequired[str] - r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_loki_url: NotRequired[str] + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + template_prometheus_url: NotRequired[str] + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputDatadog(BaseModel): +class CreateOutputOutputGrafanaCloudGrafanaCloud2(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputDatadogType + type: CreateOutputOutputGrafanaCloudType2 r"""Connector type identifier.""" + prometheus_url: Annotated[str, pydantic.Field(alias="prometheusUrl")] + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -20711,60 +20674,47 @@ class CreateOutputOutputDatadog(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - content_type: Annotated[ - Optional[CreateOutputSendLogsAs], pydantic.Field(alias="contentType") - ] = None - r"""The content type to use when sending logs""" + loki_url: Annotated[Optional[str], pydantic.Field(alias="lokiUrl")] = None + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" message: Optional[str] = None r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - source: Optional[str] = None - r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" - - host: Optional[str] = None - r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" - - service: Optional[str] = None - r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" - - tags: Optional[List[str]] = None - r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" - - batch_by_tags: Annotated[Optional[bool], pydantic.Field(alias="batchByTags")] = None - r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + message_format: Annotated[ + Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + ] = None + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - allow_api_key_from_events: Annotated[ - Optional[bool], pydantic.Field(alias="allowApiKeyFromEvents") + labels: Optional[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] ] = None - r"""Allow API key to be set from the event's '__agent_api_key' field""" + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - severity: Optional[CreateOutputOutputDatadogSeverity] = None - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") + ] = None + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - site: Optional[CreateOutputDatadogSite] = None - r"""Datadog site to which events should be sent""" + prometheus_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") + ] = None - send_counters_as_count: Annotated[ - Optional[bool], pydantic.Field(alias="sendCountersAsCount") + loki_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") ] = None - r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -20785,7 +20735,7 @@ class CreateOutputOutputDatadog(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -20829,20 +20779,11 @@ class CreateOutputOutputDatadog(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + compress: Optional[bool] = None + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -20894,26 +20835,25 @@ class CreateOutputOutputDatadog(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputDatadogPqControls], + Optional[CreateOutputOutputGrafanaCloudPqControls2], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""Organization's API key in Datadog""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_tags: Annotated[Optional[str], pydantic.Field(alias="__template_tags")] = ( - None - ) - r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_loki_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiUrl") + ] = None + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + + template_prometheus_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusUrl") + ] = None + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -20925,29 +20865,11 @@ class CreateOutputOutputDatadog(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("content_type") - def serialize_content_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSendLogsAs(value) - except ValueError: - return value - return value - - @field_serializer("severity") - def serialize_severity(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputDatadogSeverity(value) - except ValueError: - return value - return value - - @field_serializer("site") - def serialize_site(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.CreateOutputDatadogSite(value) + return models.MessageFormatOptions(value) except ValueError: return value return value @@ -20970,15 +20892,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -21014,21 +20927,16 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "contentType", + "lokiUrl", "message", - "source", - "host", - "service", - "tags", - "batchByTags", - "allowApiKeyFromEvents", - "severity", - "site", - "sendCountersAsCount", + "messageFormat", + "labels", + "metricRenameExpr", + "prometheusAuth", + "lokiAuth", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", - "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", @@ -21041,10 +20949,8 @@ def serialize_model(self, handler): "timeoutRetrySettings", "responseHonorRetryAfterHeader", "onBackpressure", - "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "compress", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -21057,10 +20963,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", - "__template_tags", + "__template_lokiUrl", + "__template_prometheusUrl", "__template_failedRequestLoggingMode", "__template_onBackpressure", ] @@ -21079,58 +20984,55 @@ def serialize_model(self, handler): return m -class CreateOutputOutputSumoLogicType(str, Enum): +class CreateOutputOutputGrafanaCloudType1(str, Enum): r"""Connector type identifier.""" - SUMO_LOGIC = "sumo_logic" - - -class CreateOutputOutputSumoLogicDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Preserve the raw event format instead of JSONifying it""" - - # JSON - JSON = "json" - # Raw - RAW = "raw" + GRAFANA_CLOUD = "grafana_cloud" -class CreateOutputOutputSumoLogicPqControlsTypedDict(TypedDict): +class CreateOutputOutputGrafanaCloudPqControls1TypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSumoLogicPqControls(BaseModel): +class CreateOutputOutputGrafanaCloudPqControls1(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSumoLogicTypedDict(TypedDict): +class CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSumoLogicType + type: CreateOutputOutputGrafanaCloudType1 r"""Connector type identifier.""" - url: str - r"""Sumo Logic HTTP collector URL to which events should be sent""" + loki_url: str + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - custom_source: NotRequired[str] - r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" - custom_category: NotRequired[str] - r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - format_: NotRequired[CreateOutputOutputSumoLogicDataFormat] - r"""Preserve the raw event format instead of JSONifying it""" + prometheus_url: NotRequired[str] + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + message: NotRequired[str] + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + message_format: NotRequired[MessageFormatOptions] + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + labels: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] + loki_auth: NotRequired[PrometheusAuthTypeTypedDict] concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -21141,7 +21043,7 @@ class CreateOutputOutputSumoLogicTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -21159,10 +21061,10 @@ class CreateOutputOutputSumoLogicTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + compress: NotRequired[bool] + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -21185,27 +21087,29 @@ class CreateOutputOutputSumoLogicTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSumoLogicPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputGrafanaCloudPqControls1TypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_loki_url: NotRequired[str] + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + template_prometheus_url: NotRequired[str] + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputSumoLogic(BaseModel): +class CreateOutputOutputGrafanaCloudGrafanaCloud1(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSumoLogicType + type: CreateOutputOutputGrafanaCloudType1 r"""Connector type identifier.""" - url: str - r"""Sumo Logic HTTP collector URL to which events should be sent""" + loki_url: Annotated[str, pydantic.Field(alias="lokiUrl")] + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -21213,42 +21117,57 @@ class CreateOutputOutputSumoLogic(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + prometheus_url: Annotated[Optional[str], pydantic.Field(alias="prometheusUrl")] = ( + None + ) + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + + message: Optional[str] = None + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + message_format: Annotated[ + Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + ] = None + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + labels: Optional[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + ] = None + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - custom_source: Annotated[Optional[str], pydantic.Field(alias="customSource")] = None - r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") + ] = None + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - custom_category: Annotated[ - Optional[str], pydantic.Field(alias="customCategory") + prometheus_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") ] = None - r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - format_: Annotated[ - Optional[CreateOutputOutputSumoLogicDataFormat], pydantic.Field(alias="format") + loki_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") ] = None - r"""Preserve the raw event format instead of JSONifying it""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -21269,7 +21188,7 @@ class CreateOutputOutputSumoLogic(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -21313,14 +21232,12 @@ class CreateOutputOutputSumoLogic(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -21371,7 +21288,7 @@ class CreateOutputOutputSumoLogic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSumoLogicPqControls], + Optional[CreateOutputOutputGrafanaCloudPqControls1], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -21381,10 +21298,15 @@ class CreateOutputOutputSumoLogic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_loki_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiUrl") + ] = None + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + + template_prometheus_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusUrl") + ] = None + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -21396,11 +21318,11 @@ class CreateOutputOutputSumoLogic(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputSumoLogicDataFormat(value) + return models.MessageFormatOptions(value) except ValueError: return value return value @@ -21443,192 +21365,12 @@ def serialize_pq_compress(self, value): @field_serializer("pq_on_backpressure") def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "customSource", - "customCategory", - "format", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "onBackpressure", - "totalMemoryLimitKB", - "description", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputSnmpHostTypedDict(TypedDict): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 162""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateOutputOutputSnmpHost(BaseModel): - host: str - r"""Destination host""" - - port: float - r"""Destination port, default is 162""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["__template_host", "__template_port"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputSnmpTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: TypeOptionsSnmp - r"""Connector type identifier.""" - hosts: List[CreateOutputOutputSnmpHostTypedDict] - r"""One or more SNMP destinations to forward traps to""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - max_record_size: NotRequired[float] - r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateOutputOutputSnmp(BaseModel): - id: str - r"""Unique ID for this output""" - - type: TypeOptionsSnmp - r"""Connector type identifier.""" - - hosts: List[CreateOutputOutputSnmpHost] - r"""One or more SNMP destinations to forward traps to""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" - - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") - ] = None - r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") - ] = None - r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -21638,11 +21380,47 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "dnsResolvePeriodSec", - "enableIpSpoofing", + "prometheusUrl", + "message", + "messageFormat", + "labels", + "metricRenameExpr", + "prometheusAuth", + "lokiAuth", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "maxRecordSize", + "compress", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", + "__template_lokiUrl", + "__template_prometheusUrl", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", ] ) serialized = handler(self) @@ -21659,32 +21437,92 @@ def serialize_model(self, handler): return m -class CreateOutputQueueType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The queue type used (or created). Defaults to Standard.""" +CreateOutputOutputGrafanaCloudUnionTypedDict = TypeAliasType( + "CreateOutputOutputGrafanaCloudUnionTypedDict", + Union[ + CreateOutputOutputGrafanaCloudGrafanaCloud1TypedDict, + CreateOutputOutputGrafanaCloudGrafanaCloud2TypedDict, + ], +) - # Standard - STANDARD = "standard" - # FIFO - FIFO = "fifo" + +CreateOutputOutputGrafanaCloudUnion = TypeAliasType( + "CreateOutputOutputGrafanaCloudUnion", + Union[ + CreateOutputOutputGrafanaCloudGrafanaCloud1, + CreateOutputOutputGrafanaCloudGrafanaCloud2, + ], +) -class CreateOutputOutputSqsPqControlsTypedDict(TypedDict): +class CreateOutputOutputDatadogType(str, Enum): + r"""Connector type identifier.""" + + DATADOG = "datadog" + + +class CreateOutputSendLogsAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The content type to use when sending logs""" + + # text/plain + TEXT = "text" + # application/json + JSON = "json" + + +class CreateOutputOutputDatadogSeverity(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + + # emergency + EMERGENCY = "emergency" + # alert + ALERT = "alert" + # critical + CRITICAL = "critical" + # error + ERROR = "error" + # warning + WARNING = "warning" + # notice + NOTICE = "notice" + # info + INFO = "info" + # debug + DEBUG = "debug" + + +class CreateOutputDatadogSite(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Datadog site to which events should be sent""" + + # US + US = "us" + # US3 + US3 = "us3" + # US5 + US5 = "us5" + # Europe + EU = "eu" + # US1-FED + FED1 = "fed1" + # AP1 + AP1 = "ap1" + # Custom + CUSTOM = "custom" + + +class CreateOutputOutputDatadogPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSqsPqControls(BaseModel): +class CreateOutputOutputDatadogPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSqsTypedDict(TypedDict): +class CreateOutputOutputDatadogTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSqs + type: CreateOutputOutputDatadogType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - queue_type: CreateOutputQueueType - r"""The queue type used (or created). Defaults to Standard.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -21693,48 +21531,71 @@ class CreateOutputOutputSqsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - message_group_id: NotRequired[str] - r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" - create_queue: NotRequired[bool] - r"""Create queue if it does not exist.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + content_type: NotRequired[CreateOutputSendLogsAs] + r"""The content type to use when sending logs""" + message: NotRequired[str] + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + source: NotRequired[str] + r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" + host: NotRequired[str] + r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" + service: NotRequired[str] + r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" + tags: NotRequired[List[str]] + r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" + batch_by_tags: NotRequired[bool] + r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + allow_api_key_from_events: NotRequired[bool] + r"""Allow API key to be set from the event's '__agent_api_key' field""" + severity: NotRequired[CreateOutputOutputDatadogSeverity] + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + site: NotRequired[CreateOutputDatadogSite] + r"""Datadog site to which events should be sent""" + send_counters_as_count: NotRequired[bool] + r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SQS""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking.""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -21754,50 +21615,32 @@ class CreateOutputOutputSqsTypedDict(TypedDict): pq_compress: NotRequired[CompressionOptionsPq] r"""Codec to use to compress the persisted data""" pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSqsPqControlsTypedDict] - r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: NotRequired[str] - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_message_group_id: NotRequired[str] - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputDatadogPqControlsTypedDict] + r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""Organization's API key in Datadog""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_tags: NotRequired[str] + r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputSqs(BaseModel): +class CreateOutputOutputDatadog(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSqs + type: CreateOutputOutputDatadogType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - - queue_type: Annotated[CreateOutputQueueType, pydantic.Field(alias="queueType")] - r"""The queue type used (or created). Defaults to Standard.""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -21812,99 +21655,138 @@ class CreateOutputOutputSqs(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="messageGroupId") + content_type: Annotated[ + Optional[CreateOutputSendLogsAs], pydantic.Field(alias="contentType") ] = None - r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" + r"""The content type to use when sending logs""" - create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None - r"""Create queue if it does not exist.""" + message: Optional[str] = None + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + source: Optional[str] = None + r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" + + host: Optional[str] = None + r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" + + service: Optional[str] = None + r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" + + tags: Optional[List[str]] = None + r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" + + batch_by_tags: Annotated[Optional[bool], pydantic.Field(alias="batchByTags")] = None + r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + + allow_api_key_from_events: Annotated[ + Optional[bool], pydantic.Field(alias="allowApiKeyFromEvents") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Allow API key to be set from the event's '__agent_api_key' field""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + severity: Optional[CreateOutputOutputDatadogSeverity] = None + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - region: Optional[str] = None - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + site: Optional[CreateOutputDatadogSite] = None + r"""Datadog site to which events should be sent""" - endpoint: Optional[str] = None - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + send_counters_as_count: Annotated[ + Optional[bool], pydantic.Field(alias="sendCountersAsCount") + ] = None + r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Use Assume Role credentials to access SQS""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""External ID to use when assuming role""" + r"""Headers to add to all events""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + r"""List of headers that are safe to log in plain text""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The maximum number of in-progress API requests before backpressure is applied.""" + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + ] = None + r"""Enter API key directly, or select a stored secret""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -21956,84 +21838,69 @@ class CreateOutputOutputSqs(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSqsPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputDatadogPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""Organization's API key in Datadog""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_queue_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueType") - ] = None - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - - template_message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageGroupId") - ] = None - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_tags: Annotated[Optional[str], pydantic.Field(alias="__template_tags")] = ( + None + ) + r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + @field_serializer("content_type") + def serialize_content_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSendLogsAs(value) + except ValueError: + return value + return value + + @field_serializer("severity") + def serialize_severity(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputDatadogSeverity(value) + except ValueError: + return value + return value - @field_serializer("queue_type") - def serialize_queue_type(self, value): + @field_serializer("site") + def serialize_site(self, value): if isinstance(value, str): try: - return models.CreateOutputQueueType(value) + return models.CreateOutputDatadogSite(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -22047,6 +21914,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -22082,27 +21958,37 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAccountId", - "messageGroupId", - "createQueue", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", + "contentType", + "message", + "source", + "host", + "service", + "tags", + "batchByTags", + "allowApiKeyFromEvents", + "severity", + "site", + "sendCountersAsCount", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "maxQueueSize", - "maxRecordSizeKB", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "maxInProgress", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "awsApiKey", - "awsSecret", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -22115,18 +22001,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_queueName", - "__template_queueType", - "__template_awsAccountId", - "__template_messageGroupId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_tags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -22143,29 +22023,36 @@ def serialize_model(self, handler): return m -class CreateOutputOutputSnsType(str, Enum): +class CreateOutputOutputSumoLogicType(str, Enum): r"""Connector type identifier.""" - SNS = "sns" + SUMO_LOGIC = "sumo_logic" -class CreateOutputOutputSnsPqControlsTypedDict(TypedDict): +class CreateOutputOutputSumoLogicDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Preserve the raw event format instead of JSONifying it""" + + # JSON + JSON = "json" + # Raw + RAW = "raw" + + +class CreateOutputOutputSumoLogicPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSnsPqControls(BaseModel): +class CreateOutputOutputSumoLogicPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSnsTypedDict(TypedDict): +class CreateOutputOutputSumoLogicTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSnsType + type: CreateOutputOutputSumoLogicType r"""Connector type identifier.""" - topic_arn: str - r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - message_group_id: str - r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + url: str + r"""Sumo Logic HTTP collector URL to which events should be sent""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -22174,36 +22061,52 @@ class CreateOutputOutputSnsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - max_retries: NotRequired[float] - r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the SNS is located""" - endpoint: NotRequired[str] - r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + custom_source: NotRequired[str] + r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" + custom_category: NotRequired[str] + r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" + format_: NotRequired[CreateOutputOutputSumoLogicDataFormat] + r"""Preserve the raw event format instead of JSONifying it""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SNS""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -22226,42 +22129,27 @@ class CreateOutputOutputSnsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSnsPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputSumoLogicPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_arn: NotRequired[str] - r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" - template_message_group_id: NotRequired[str] - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputSns(BaseModel): +class CreateOutputOutputSumoLogic(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSnsType + type: CreateOutputOutputSumoLogicType r"""Connector type identifier.""" - topic_arn: Annotated[str, pydantic.Field(alias="topicArn")] - r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - - message_group_id: Annotated[str, pydantic.Field(alias="messageGroupId")] - r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + url: str + r"""Sumo Logic HTTP collector URL to which events should be sent""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -22277,70 +22165,106 @@ class CreateOutputOutputSns(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" + custom_source: Annotated[Optional[str], pydantic.Field(alias="customSource")] = None + r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + custom_category: Annotated[ + Optional[str], pydantic.Field(alias="customCategory") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + format_: Annotated[ + Optional[CreateOutputOutputSumoLogicDataFormat], pydantic.Field(alias="format") + ] = None + r"""Preserve the raw event format instead of JSONifying it""" - region: Optional[str] = None - r"""Region where the SNS is located""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - endpoint: Optional[str] = None - r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Use Assume Role credentials to access SNS""" + r"""List of headers that are safe to log in plain text""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""External ID to use when assuming role""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -22391,7 +22315,8 @@ class CreateOutputOutputSns(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSnsPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputSumoLogicPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -22400,56 +22325,35 @@ class CreateOutputOutputSns(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicArn") - ] = None - r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" - - template_message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageGroupId") - ] = None - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputSumoLogicDataFormat(value) + except ValueError: + return value + return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -22498,21 +22402,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "maxRetries", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", + "customSource", + "customCategory", + "format", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", + "totalMemoryLimitKB", "description", - "awsApiKey", - "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -22526,15 +22436,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topicArn", - "__template_messageGroupId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_url", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -22551,39 +22455,37 @@ def serialize_model(self, handler): return m -class CreateOutputOutputRouterType(str, Enum): - r"""Connector type identifier.""" - - ROUTER = "router" - - -class CreateOutputRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression to select events to send to output""" - output: str - r"""Output to send matching events to""" - description: NotRequired[str] - r"""Description of this rule's purpose""" - final: NotRequired[bool] - r"""Flag to control whether to stop the event from being checked against other rules""" +class CreateOutputOutputSnmpHostTypedDict(TypedDict): + host: str + r"""Destination host""" + port: float + r"""Destination port, default is 162""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression to select events to send to output""" +class CreateOutputOutputSnmpHost(BaseModel): + host: str + r"""Destination host""" - output: str - r"""Output to send matching events to""" + port: float + r"""Destination port, default is 162""" - description: Optional[str] = None - r"""Description of this rule's purpose""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - final: Optional[bool] = None - r"""Flag to control whether to stop the event from being checked against other rules""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description", "final"]) + optional_fields = set(["__template_host", "__template_port"]) serialized = handler(self) m = {} @@ -22598,13 +22500,13 @@ def serialize_model(self, handler): return m -class CreateOutputOutputRouterTypedDict(TypedDict): +class CreateOutputOutputSnmpTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputRouterType + type: TypeOptionsSnmp r"""Connector type identifier.""" - rules: List[CreateOutputRuleTypedDict] - r"""Event routing rules""" + hosts: List[CreateOutputOutputSnmpHostTypedDict] + r"""One or more SNMP destinations to forward traps to""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -22613,21 +22515,27 @@ class CreateOutputOutputRouterTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" description: NotRequired[str] r"""Optional description for this configuration.""" + max_record_size: NotRequired[float] + r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class CreateOutputOutputRouter(BaseModel): +class CreateOutputOutputSnmp(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputRouterType + type: TypeOptionsSnmp r"""Connector type identifier.""" - rules: List[CreateOutputRule] - r"""Event routing rules""" + hosts: List[CreateOutputOutputSnmpHost] + r"""One or more SNMP destinations to forward traps to""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -22643,9 +22551,24 @@ class CreateOutputOutputRouter(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" + + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") + ] = None + r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + description: Optional[str] = None r"""Optional description for this configuration.""" + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") + ] = None + r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -22659,7 +22582,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "dnsResolvePeriodSec", + "enableIpSpoofing", "description", + "maxRecordSize", "__template_streamtags", ] ) @@ -22677,31 +22603,32 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGraphiteType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputQueueType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The queue type used (or created). Defaults to Standard.""" - GRAPHITE = "graphite" + # Standard + STANDARD = "standard" + # FIFO + FIFO = "fifo" -class CreateOutputOutputGraphitePqControlsTypedDict(TypedDict): +class CreateOutputOutputSqsPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputGraphitePqControls(BaseModel): +class CreateOutputOutputSqsPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputGraphiteTypedDict(TypedDict): +class CreateOutputOutputSqsTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGraphiteType + type: TypeOptionsSqs r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + queue_type: CreateOutputQueueType + r"""The queue type used (or created). Defaults to Standard.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -22710,22 +22637,48 @@ class CreateOutputOutputGraphiteTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + message_group_id: NotRequired[str] + r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" + create_queue: NotRequired[bool] + r"""Create queue if it does not exist.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SQS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -22748,29 +22701,46 @@ class CreateOutputOutputGraphiteTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputGraphitePqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputSqsPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_queue_type: NotRequired[str] + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_message_group_id: NotRequired[str] + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputGraphite(BaseModel): +class CreateOutputOutputSqs(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGraphiteType + type: TypeOptionsSqs r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - - host: str - r"""The hostname of the destination.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - port: float - r"""Destination port.""" + queue_type: Annotated[CreateOutputQueueType, pydantic.Field(alias="queueType")] + r"""The queue type used (or created). Defaults to Standard.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -22786,42 +22756,100 @@ class CreateOutputOutputGraphite(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - mtu: Optional[float] = None - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="messageGroupId") ] = None - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None + r"""Create queue if it does not exist.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + region: Optional[str] = None + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Reuse connections between requests, which can improve performance""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SQS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking.""" + + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") + ] = None + r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") + ] = None + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -22872,8 +22900,7 @@ class CreateOutputOutputGraphite(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputGraphitePqControls], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputSqsPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -22882,16 +22909,75 @@ class CreateOutputOutputGraphite(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_queue_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueType") + ] = None + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageGroupId") + ] = None + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("queue_type") + def serialize_queue_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputQueueType(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.DestinationProtocolOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -22940,14 +23026,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "mtu", + "awsAccountId", + "messageGroupId", + "createQueue", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxQueueSize", + "maxRecordSizeKB", "flushPeriodSec", - "dnsResolvePeriodSec", - "description", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "maxInProgress", "onBackpressure", + "description", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -22961,7 +23060,17 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_queueName", + "__template_queueType", + "__template_awsAccountId", + "__template_messageGroupId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -22978,12 +23087,24 @@ def serialize_model(self, handler): return m -class CreateOutputOutputStatsdExtType(str, Enum): +class CreateOutputOutputSnsType(str, Enum): r"""Connector type identifier.""" - STATSD_EXT = "statsd_ext" + SNS = "sns" + + +class CreateOutputOutputSnsPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputSnsPqControls(BaseModel): + r"""Persistent queue controls.""" +try: + CreateOutputOutputDatabricksZerobus.model_rebuild() +except NameError: + pass try: CreateOutputOutputIbmCloudS3.model_rebuild() except NameError: @@ -23052,6 +23173,10 @@ class CreateOutputOutputStatsdExtType(str, Enum): CreateOutputOutputSentinelOneAiSiem.model_rebuild() except NameError: pass +try: + CreateOutputOutputTraversalOtlp.model_rebuild() +except NameError: + pass try: CreateOutputOutputDynatraceOtlp.model_rebuild() except NameError: @@ -23184,19 +23309,3 @@ class CreateOutputOutputStatsdExtType(str, Enum): CreateOutputOutputSqs.model_rebuild() except NameError: pass -try: - CreateOutputOutputSns.model_rebuild() -except NameError: - pass -try: - CreateOutputRule.model_rebuild() -except NameError: - pass -try: - CreateOutputOutputRouter.model_rebuild() -except NameError: - pass -try: - CreateOutputOutputGraphite.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/createoutput_outputdefault_type.py b/src/cribl_control_plane/models/createoutput_outputwebhook_format_2.py similarity index 94% rename from src/cribl_control_plane/models/createoutput_outputdefault_type.py rename to src/cribl_control_plane/models/createoutput_outputwebhook_format_2.py index 2fa1c7d41..3134b354a 100644 --- a/src/cribl_control_plane/models/createoutput_outputdefault_type.py +++ b/src/cribl_control_plane/models/createoutput_outputwebhook_format_2.py @@ -5,8 +5,8 @@ from .acknowledgmentsoptionsallleader import AcknowledgmentsOptionsAllLeader from .authenticationmethodoptions import AuthenticationMethodOptions from .authenticationmethodoptionsapi import AuthenticationMethodOptionsAPI -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionss3collectorconf import ( AuthenticationMethodOptionsS3CollectorConf, @@ -26,7 +26,11 @@ from .compressionoptionsgzipnone import CompressionOptionsGzipNone from .compressionoptionshttp import CompressionOptionsHTTP from .compressionoptionspq import CompressionOptionsPq -from .createoutput_outputstatsdext_type import CreateOutputOutputStatsdExtType +from .createoutput_outputsns_pqcontrols import ( + CreateOutputOutputSnsPqControls, + CreateOutputOutputSnsPqControlsTypedDict, + CreateOutputOutputSnsType, +) from .dataformatoptions import DataFormatOptions from .datapageversionoptions import DataPageVersionOptions from .destinationprotocoloptions import DestinationProtocolOptions @@ -51,20 +55,11 @@ LogLabelConfOutputGoogleCloudLoggingTypedDict, ) from .maxs2sversionoptions import MaxS2SVersionOptions -from .methodoptions import MethodOptions from .microsoftentraidauthenticationendpointoptionssasl import ( MicrosoftEntraIDAuthenticationEndpointOptionsSasl, ) from .modeoptions import ModeOptions from .nestedfieldserializationoptions import NestedFieldSerializationOptions -from .oauthheaderconfinputservicenowtable import ( - OauthHeaderConfInputServicenowTable, - OauthHeaderConfInputServicenowTableTypedDict, -) -from .oauthparamconfinputservicenowtable import ( - OauthParamConfInputServicenowTable, - OauthParamConfInputServicenowTableTypedDict, -) from .objectacloptions import ObjectACLOptions from .objectacloptionsauthenticatedreadbucketownerfullcontrol import ( ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol, @@ -137,29 +132,19 @@ from enum import Enum import pydantic from pydantic import field_serializer, model_serializer -from typing import List, Optional, Union -from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict - - -class CreateOutputOutputStatsdExtPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict -class CreateOutputOutputStatsdExtPqControls(BaseModel): - r"""Persistent queue controls.""" - -class CreateOutputOutputStatsdExtTypedDict(TypedDict): +class CreateOutputOutputSnsTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputStatsdExtType + type: CreateOutputOutputSnsType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + topic_arn: str + r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" + message_group_id: str + r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -168,22 +153,36 @@ class CreateOutputOutputStatsdExtTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + max_retries: NotRequired[float] + r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the SNS is located""" + endpoint: NotRequired[str] + r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SNS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -206,29 +205,42 @@ class CreateOutputOutputStatsdExtTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputStatsdExtPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputSnsPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_arn: NotRequired[str] + r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" + template_message_group_id: NotRequired[str] + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputStatsdExt(BaseModel): +class CreateOutputOutputSns(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputStatsdExtType + type: CreateOutputOutputSnsType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - - host: str - r"""The hostname of the destination.""" + topic_arn: Annotated[str, pydantic.Field(alias="topicArn")] + r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - port: float - r"""Destination port.""" + message_group_id: Annotated[str, pydantic.Field(alias="messageGroupId")] + r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -244,42 +256,70 @@ class CreateOutputOutputStatsdExt(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - mtu: Optional[float] = None - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + region: Optional[str] = None + r"""Region where the SNS is located""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + endpoint: Optional[str] = None + r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Reuse connections between requests, which can improve performance""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SNS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -330,8 +370,7 @@ class CreateOutputOutputStatsdExt(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputStatsdExtPqControls], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputSnsPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -340,16 +379,56 @@ class CreateOutputOutputStatsdExt(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicArn") + ] = None + r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" + + template_message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageGroupId") + ] = None + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.DestinationProtocolOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -398,14 +477,21 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "mtu", - "flushPeriodSec", - "dnsResolvePeriodSec", - "description", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "maxRetries", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "onBackpressure", + "description", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -419,7 +505,15 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_topicArn", + "__template_messageGroupId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -436,31 +530,60 @@ def serialize_model(self, handler): return m -class CreateOutputOutputStatsdType(str, Enum): +class CreateOutputOutputRouterType(str, Enum): r"""Connector type identifier.""" - STATSD = "statsd" + ROUTER = "router" -class CreateOutputOutputStatsdPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression to select events to send to output""" + output: str + r"""Output to send matching events to""" + description: NotRequired[str] + r"""Description of this rule's purpose""" + final: NotRequired[bool] + r"""Flag to control whether to stop the event from being checked against other rules""" -class CreateOutputOutputStatsdPqControls(BaseModel): - r"""Persistent queue controls.""" +class CreateOutputRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression to select events to send to output""" + output: str + r"""Output to send matching events to""" -class CreateOutputOutputStatsdTypedDict(TypedDict): + description: Optional[str] = None + r"""Description of this rule's purpose""" + + final: Optional[bool] = None + r"""Flag to control whether to stop the event from being checked against other rules""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description", "final"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputRouterTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputStatsdType + type: CreateOutputOutputRouterType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + rules: List[CreateOutputRuleTypedDict] + r"""Event routing rules""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -469,20 +592,125 @@ class CreateOutputOutputStatsdTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + report_branch_metrics: NotRequired[bool] + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" description: NotRequired[str] r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateOutputOutputRouter(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputOutputRouterType + r"""Connector type identifier.""" + + rules: List[CreateOutputRule] + r"""Event routing rules""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + report_branch_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="reportBranchMetrics") + ] = None + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "reportBranchMetrics", + "description", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputGraphiteType(str, Enum): + r"""Connector type identifier.""" + + GRAPHITE = "graphite" + + +class CreateOutputOutputGraphitePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputGraphitePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputGraphiteTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputGraphiteType + r"""Connector type identifier.""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + flush_period_sec: NotRequired[float] + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" pq_strict_ordering: NotRequired[bool] @@ -507,7 +735,7 @@ class CreateOutputOutputStatsdTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputStatsdPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputGraphitePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -515,11 +743,11 @@ class CreateOutputOutputStatsdTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputStatsd(BaseModel): +class CreateOutputOutputGraphite(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputStatsdType + type: CreateOutputOutputGraphiteType r"""Connector type identifier.""" protocol: DestinationProtocolOptions @@ -631,7 +859,8 @@ class CreateOutputOutputStatsd(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputStatsdPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputGraphitePqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -736,23 +965,31 @@ def serialize_model(self, handler): return m -class CreateOutputOutputMinioType(str, Enum): +class CreateOutputOutputStatsdExtType(str, Enum): r"""Connector type identifier.""" - MINIO = "minio" + STATSD_EXT = "statsd_ext" -class CreateOutputOutputMinioTypedDict(TypedDict): +class CreateOutputOutputStatsdExtPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputStatsdExtPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputStatsdExtTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputMinioType + type: CreateOutputOutputStatsdExtType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""MinIO service url (e.g. http://minioHost:9000)""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -761,156 +998,67 @@ class CreateOutputOutputMinioTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the MinIO bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ - ServerSideEncryptionForUploadedObjectsOptionsAes256 - ] - r"""Server-side encryption to use for uploaded objects""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + flush_period_sec: NotRequired[float] + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputStatsdExtPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputMinio(BaseModel): +class CreateOutputOutputStatsdExt(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputMinioType + type: CreateOutputOutputStatsdExtType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + host: str + r"""The hostname of the destination.""" - endpoint: str - r"""MinIO service url (e.g. http://minioHost:9000)""" + port: float + r"""Destination port.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -926,339 +1074,112 @@ class CreateOutputOutputMinio(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - region: Optional[str] = None - r"""Region where the MinIO bucket is located""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + mtu: Optional[float] = None + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Add the Output ID value to staging location""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( None ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""How to handle events when all receivers are exerting backpressure""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Buffer size used to write to a file""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None + r"""Codec to use to compress the persisted data""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Object ACL to assign to uploaded objects""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - storage_class: Annotated[ - Optional[StorageClassOptionsReducedredundancyStandard], - pydantic.Field(alias="storageClass"), + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Storage class to select for uploaded objects""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], - pydantic.Field(alias="serverSideEncryption"), + pq_controls: Annotated[ + Optional[CreateOutputOutputStatsdExtPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Server-side encryption to use for uploaded objects""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + r"""Persistent queue controls.""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" - - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") - ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.DataFormatOptions(value) + return models.DestinationProtocolOptions(value) except ValueError: return value return value @@ -1267,79 +1188,34 @@ def serialize_format_(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("object_acl") - def serialize_object_acl(self, value): - if isinstance(value, str): - try: - return models.ObjectACLOptions(value) - except ValueError: - return value - return value - - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptionsReducedredundancyStandard(value) - except ValueError: - return value - return value - - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): - if isinstance(value, str): - try: - return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -1352,72 +1228,28 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "region", - "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", + "mtu", + "flushPeriodSec", + "dnsResolvePeriodSec", + "description", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", - "description", - "awsApiKey", - "awsSecret", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_bucket", - "__template_region", - "__template_destPath", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_awsApiKey", - "__template_compress", - "__template_parquetSchema", ] ) serialized = handler(self) @@ -1434,31 +1266,31 @@ def serialize_model(self, handler): return m -class CreateOutputOutputCloudwatchType(str, Enum): +class CreateOutputOutputStatsdType(str, Enum): r"""Connector type identifier.""" - CLOUDWATCH = "cloudwatch" + STATSD = "statsd" -class CreateOutputOutputCloudwatchPqControlsTypedDict(TypedDict): +class CreateOutputOutputStatsdPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputCloudwatchPqControls(BaseModel): +class CreateOutputOutputStatsdPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputCloudwatchTypedDict(TypedDict): +class CreateOutputOutputStatsdTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCloudwatchType + type: CreateOutputOutputStatsdType r"""Connector type identifier.""" - log_group_name: str - r"""CloudWatch log group to associate events with""" - log_stream_name: str - r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" - region: str - r"""Region where the CloudWatchLogs is located""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -1467,38 +1299,22 @@ class CreateOutputOutputCloudwatchTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access CloudWatchLogs""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -1521,45 +1337,29 @@ class CreateOutputOutputCloudwatchTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputCloudwatchPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputStatsdPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_group_name: NotRequired[str] - r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" - template_log_stream_name: NotRequired[str] - r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputCloudwatch(BaseModel): +class CreateOutputOutputStatsd(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputCloudwatchType + type: CreateOutputOutputStatsdType r"""Connector type identifier.""" - log_group_name: Annotated[str, pydantic.Field(alias="logGroupName")] - r"""CloudWatch log group to associate events with""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" - log_stream_name: Annotated[str, pydantic.Field(alias="logStreamName")] - r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + host: str + r"""The hostname of the destination.""" - region: str - r"""Region where the CloudWatchLogs is located""" + port: float + r"""Destination port.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -1575,79 +1375,42 @@ class CreateOutputOutputCloudwatch(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - endpoint: Optional[str] = None - r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + mtu: Optional[float] = None + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Use Assume Role credentials to access CloudWatchLogs""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""External ID to use when assuming role""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( None ) - r"""Maximum number of queued batches before blocking""" - - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") - ] = None - r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -1698,8 +1461,7 @@ class CreateOutputOutputCloudwatch(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputCloudwatchPqControls], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputStatsdPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -1708,59 +1470,19 @@ class CreateOutputOutputCloudwatch(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_group_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_logGroupName") - ] = None - r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" - - template_log_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_logStreamName") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.DestinationProtocolOptions(value) + except ValueError: + return value + return value @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): @@ -1806,22 +1528,14 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "maxQueueSize", - "maxRecordSizeKB", + "mtu", "flushPeriodSec", - "onBackpressure", + "dnsResolvePeriodSec", "description", - "awsApiKey", - "awsSecret", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "onBackpressure", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -1835,15 +1549,7 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_logGroupName", - "__template_logStreamName", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -1860,61 +1566,23 @@ def serialize_model(self, handler): return m -class CreateOutputOutputInfluxdbType(str, Enum): +class CreateOutputOutputMinioType(str, Enum): r"""Connector type identifier.""" - INFLUXDB = "influxdb" - - -class CreateOutputTimestampPrecision(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - - # Nanoseconds - NS = "ns" - # Microseconds - U = "u" - # Milliseconds - MS = "ms" - # Seconds - S = "s" - # Minutes - M = "m" - # Hours - H = "h" - - -class CreateOutputOutputInfluxdbAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""InfluxDB authentication type""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - - -class CreateOutputOutputInfluxdbPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputInfluxdbPqControls(BaseModel): - r"""Persistent queue controls.""" + MINIO = "minio" -class CreateOutputOutputInfluxdbTypedDict(TypedDict): +class CreateOutputOutputMinioTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputInfluxdbType + type: CreateOutputOutputMinioType r"""Connector type identifier.""" - url: str - r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + bucket: str + r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""MinIO service url (e.g. http://minioHost:9000)""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -1923,117 +1591,156 @@ class CreateOutputOutputInfluxdbTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - use_v2_api: NotRequired[bool] - r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - timestamp_precision: NotRequired[CreateOutputTimestampPrecision] - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - dynamic_value_field_name: NotRequired[bool] - r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" - value_field_name: NotRequired[str] - r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the MinIO bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputOutputInfluxdbAuthenticationType] - r"""InfluxDB authentication type""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ + ServerSideEncryptionForUploadedObjectsOptionsAes256 + ] + r"""Server-side encryption to use for uploaded objects""" description: NotRequired[str] r"""Optional description for this configuration.""" - database: NotRequired[str] - r"""Database to write to.""" - bucket: NotRequired[str] - r"""Bucket to write to.""" - org: NotRequired[str] - r"""Organization ID for this bucket.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputInfluxdbPqControlsTypedDict] - r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputOutputInfluxdb(BaseModel): +class CreateOutputOutputMinio(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputInfluxdbType + type: CreateOutputOutputMinioType r"""Connector type identifier.""" - url: str - r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + bucket: str + r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + endpoint: str + r"""MinIO service url (e.g. http://minioHost:9000)""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -2049,238 +1756,339 @@ class CreateOutputOutputInfluxdb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - use_v2_api: Annotated[Optional[bool], pydantic.Field(alias="useV2API")] = None - r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - - timestamp_precision: Annotated[ - Optional[CreateOutputTimestampPrecision], - pydantic.Field(alias="timestampPrecision"), + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - dynamic_value_field_name: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicValueFieldName") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" + r"""Reuse connections between requests, which can improve performance""" - value_field_name: Annotated[ - Optional[str], pydantic.Field(alias="valueFieldName") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + region: Optional[str] = None + r"""Region where the MinIO bucket is located""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Add the Output ID value to staging location""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""Headers to add to all events""" + r"""Remove empty staging directories after moving files""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Buffer size used to write to a file""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[CreateOutputOutputInfluxdbAuthenticationType], - pydantic.Field(alias="authType"), + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""InfluxDB authentication type""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - database: Optional[str] = None - r"""Database to write to.""" + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - bucket: Optional[str] = None - r"""Bucket to write to.""" + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None - org: Optional[str] = None - r"""Organization ID for this bucket.""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Object ACL to assign to uploaded objects""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + storage_class: Annotated[ + Optional[StorageClassOptionsReducedredundancyStandard], + pydantic.Field(alias="storageClass"), ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Storage class to select for uploaded objects""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Compression level to apply before moving files to final destination""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Determines which data types are supported and how they are represented""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") + ] = None + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""Codec to use to compress the persisted data""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_controls: Annotated[ - Optional[CreateOutputOutputInfluxdbPqControls], - pydantic.Field(alias="pqControls"), + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""Persistent queue controls.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - username: Optional[str] = None - r"""Username""" + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") + ] = None + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - password: Optional[str] = None - r"""Password""" + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") + ] = None + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Select or create a secret that references your credentials""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") + ] = None + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - @field_serializer("timestamp_precision") - def serialize_timestamp_precision(self, value): + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + ] = None + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.CreateOutputTimestampPrecision(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -2289,103 +2097,157 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputInfluxdbAuthenticationType(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.StorageClassOptionsReducedredundancyStandard(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) except ValueError: return value return value - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", "systemFields", "environment", "streamtags", - "useV2API", - "timestampPrecision", - "dynamicValueFieldName", - "valueFieldName", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", - "authType", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", "description", - "database", - "bucket", - "org", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - "__template_database", "__template_bucket", + "__template_region", + "__template_destPath", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", + "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -2402,29 +2264,31 @@ def serialize_model(self, handler): return m -class CreateOutputOutputNewrelicEventsType(str, Enum): +class CreateOutputOutputCloudwatchType(str, Enum): r"""Connector type identifier.""" - NEWRELIC_EVENTS = "newrelic_events" + CLOUDWATCH = "cloudwatch" -class CreateOutputOutputNewrelicEventsPqControlsTypedDict(TypedDict): +class CreateOutputOutputCloudwatchPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputNewrelicEventsPqControls(BaseModel): +class CreateOutputOutputCloudwatchPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputNewrelicEventsTypedDict(TypedDict): +class CreateOutputOutputCloudwatchTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputNewrelicEventsType + type: CreateOutputOutputCloudwatchType r"""Connector type identifier.""" - account_id: str - r"""New Relic account ID""" - event_type: str - r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" + log_group_name: str + r"""CloudWatch log group to associate events with""" + log_stream_name: str + r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + region: str + r"""Region where the CloudWatchLogs is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -2433,49 +2297,38 @@ class CreateOutputOutputNewrelicEventsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - region: NotRequired[RegionOptions] - r"""Which New Relic region endpoint to use.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access CloudWatchLogs""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -2498,40 +2351,45 @@ class CreateOutputOutputNewrelicEventsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputNewrelicEventsPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputCloudwatchPqControlsTypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_log_group_name: NotRequired[str] + r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" + template_log_stream_name: NotRequired[str] + r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_account_id: NotRequired[str] - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - template_event_type: NotRequired[str] - r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: NotRequired[str] - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputNewrelicEvents(BaseModel): +class CreateOutputOutputCloudwatch(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputNewrelicEventsType + type: CreateOutputOutputCloudwatchType r"""Connector type identifier.""" - account_id: Annotated[str, pydantic.Field(alias="accountId")] - r"""New Relic account ID""" + log_group_name: Annotated[str, pydantic.Field(alias="logGroupName")] + r"""CloudWatch log group to associate events with""" - event_type: Annotated[str, pydantic.Field(alias="eventType")] - r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" + log_stream_name: Annotated[str, pydantic.Field(alias="logStreamName")] + r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + + region: str + r"""Region where the CloudWatchLogs is located""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -2547,97 +2405,78 @@ class CreateOutputOutputNewrelicEvents(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - region: Optional[RegionOptions] = None - r"""Which New Relic region endpoint to use.""" + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + endpoint: Optional[str] = None + r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Headers to add to all events""" + r"""Use Assume Role credentials to access CloudWatchLogs""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""External ID to use when assuming role""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None + r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -2689,66 +2528,66 @@ class CreateOutputOutputNewrelicEvents(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputNewrelicEventsPqControls], + Optional[CreateOutputOutputCloudwatchPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_log_group_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_logGroupName") + ] = None + r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" + + template_log_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_logStreamName") + ] = None + r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: Annotated[ Optional[str], pydantic.Field(alias="__template_region") ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_accountId") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_event_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_eventType") + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") ] = None - r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_customUrl") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - - @field_serializer("region") - def serialize_region(self, value): - if isinstance(value, str): - try: - return models.RegionOptions(value) - except ValueError: - return value - return value + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -2762,15 +2601,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -2806,26 +2636,22 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "region", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxQueueSize", + "maxRecordSizeKB", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", "onBackpressure", - "authType", "description", - "customUrl", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -2838,15 +2664,16 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", + "__template_logGroupName", + "__template_logStreamName", + "__template_awsSecretKey", "__template_region", - "__template_accountId", - "__template_eventType", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", - "__template_customUrl", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -2863,58 +2690,61 @@ def serialize_model(self, handler): return m -class CreateOutputOutputNewrelicType(str, Enum): +class CreateOutputOutputInfluxdbType(str, Enum): r"""Connector type identifier.""" - NEWRELIC = "newrelic" - - -class CreateOutputFieldName(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Name of the metadata field.""" - - SERVICE = "service" - HOSTNAME = "hostname" - TIMESTAMP = "timestamp" - AUDIT_ID = "auditId" - + INFLUXDB = "influxdb" -class CreateOutputMetadatumTypedDict(TypedDict): - name: CreateOutputFieldName - r"""Name of the metadata field.""" - value: str - r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" +class CreateOutputTimestampPrecision(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" -class CreateOutputMetadatum(BaseModel): - name: CreateOutputFieldName - r"""Name of the metadata field.""" + # Nanoseconds + NS = "ns" + # Microseconds + U = "u" + # Milliseconds + MS = "ms" + # Seconds + S = "s" + # Minutes + M = "m" + # Hours + H = "h" - value: str - r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - @field_serializer("name") - def serialize_name(self, value): - if isinstance(value, str): - try: - return models.CreateOutputFieldName(value) - except ValueError: - return value - return value +class CreateOutputOutputInfluxdbAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""InfluxDB authentication type""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" -class CreateOutputOutputNewrelicPqControlsTypedDict(TypedDict): +class CreateOutputOutputInfluxdbPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputNewrelicPqControls(BaseModel): +class CreateOutputOutputInfluxdbPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputNewrelicTypedDict(TypedDict): +class CreateOutputOutputInfluxdbTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputNewrelicType + type: CreateOutputOutputInfluxdbType r"""Connector type identifier.""" + url: str + r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -2923,14 +2753,14 @@ class CreateOutputOutputNewrelicTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - region: NotRequired[RegionOptions] - r"""Which New Relic region endpoint to use.""" - log_type: NotRequired[str] - r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" - message_field: NotRequired[str] - r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" - metadata: NotRequired[List[CreateOutputMetadatumTypedDict]] - r"""Fields to add to events from this input""" + use_v2_api: NotRequired[bool] + r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" + timestamp_precision: NotRequired[CreateOutputTimestampPrecision] + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" + dynamic_value_field_name: NotRequired[bool] + r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" + value_field_name: NotRequired[str] + r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -2967,13 +2797,16 @@ class CreateOutputOutputNewrelicTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[CreateOutputOutputInfluxdbAuthenticationType] + r"""InfluxDB authentication type""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + database: NotRequired[str] + r"""Database to write to.""" + bucket: NotRequired[str] + r"""Bucket to write to.""" + org: NotRequired[str] + r"""Organization ID for this bucket.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -2996,33 +2829,42 @@ class CreateOutputOutputNewrelicTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputNewrelicPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputInfluxdbPqControlsTypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_log_type: NotRequired[str] - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" - template_message_field: NotRequired[str] - r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" -class CreateOutputOutputNewrelic(BaseModel): +class CreateOutputOutputInfluxdb(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputNewrelicType + type: CreateOutputOutputInfluxdbType r"""Connector type identifier.""" + url: str + r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -3037,17 +2879,24 @@ class CreateOutputOutputNewrelic(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - region: Optional[RegionOptions] = None - r"""Which New Relic region endpoint to use.""" + use_v2_api: Annotated[Optional[bool], pydantic.Field(alias="useV2API")] = None + r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None - r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + timestamp_precision: Annotated[ + Optional[CreateOutputTimestampPrecision], + pydantic.Field(alias="timestampPrecision"), + ] = None + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None - r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + dynamic_value_field_name: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicValueFieldName") + ] = None + r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" - metadata: Optional[List[CreateOutputMetadatum]] = None - r"""Fields to add to events from this input""" + value_field_name: Annotated[ + Optional[str], pydantic.Field(alias="valueFieldName") + ] = None + r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -3129,19 +2978,22 @@ class CreateOutputOutputNewrelic(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + Optional[CreateOutputOutputInfluxdbAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""InfluxDB authentication type""" description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + database: Optional[str] = None + r"""Database to write to.""" + + bucket: Optional[str] = None + r"""Bucket to write to.""" + + org: Optional[str] = None + r"""Organization ID for this bucket.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -3193,13 +3045,24 @@ class CreateOutputOutputNewrelic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputNewrelicPqControls], + Optional[CreateOutputOutputInfluxdbPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -3209,20 +3072,10 @@ class CreateOutputOutputNewrelic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_log_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_logType") - ] = None - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" - - template_message_field: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageField") - ] = None - r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -3234,11 +3087,21 @@ class CreateOutputOutputNewrelic(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("region") - def serialize_region(self, value): + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") + ] = None + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + + @field_serializer("timestamp_precision") + def serialize_timestamp_precision(self, value): if isinstance(value, str): try: - return models.RegionOptions(value) + return models.CreateOutputTimestampPrecision(value) except ValueError: return value return value @@ -3265,7 +3128,7 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAPI(value) + return models.CreateOutputOutputInfluxdbAuthenticationType(value) except ValueError: return value return value @@ -3305,10 +3168,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "region", - "logType", - "messageField", - "metadata", + "useV2API", + "timestampPrecision", + "dynamicValueFieldName", + "valueFieldName", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -3326,9 +3189,10 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "database", + "bucket", + "org", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -3341,14 +3205,17 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", + "username", + "password", + "token", + "credentialsSecret", "textSecret", "__template_streamtags", - "__template_region", - "__template_logType", - "__template_messageField", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_database", + "__template_bucket", ] ) serialized = handler(self) @@ -3365,29 +3232,29 @@ def serialize_model(self, handler): return m -class CreateOutputOutputElasticCloudType(str, Enum): +class CreateOutputOutputNewrelicEventsType(str, Enum): r"""Connector type identifier.""" - ELASTIC_CLOUD = "elastic_cloud" + NEWRELIC_EVENTS = "newrelic_events" -class CreateOutputOutputElasticCloudPqControlsTypedDict(TypedDict): +class CreateOutputOutputNewrelicEventsPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputElasticCloudPqControls(BaseModel): +class CreateOutputOutputNewrelicEventsPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputElasticCloudTypedDict(TypedDict): +class CreateOutputOutputNewrelicEventsTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputElasticCloudType + type: CreateOutputOutputNewrelicEventsType r"""Connector type identifier.""" - url: str - r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" - index: str - r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" + account_id: str + r"""New Relic account ID""" + event_type: str + r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -3396,6 +3263,8 @@ class CreateOutputOutputElasticCloudTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + region: NotRequired[RegionOptions] + r"""Which New Relic region endpoint to use.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -3417,17 +3286,12 @@ class CreateOutputOutputElasticCloudTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] - r"""Extra parameters to use in HTTP requests""" - auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] - elastic_pipeline: NotRequired[str] - r"""Optional Elastic Cloud Destination pipeline""" - include_doc_id: NotRequired[bool] - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -3437,8 +3301,11 @@ class CreateOutputOutputElasticCloudTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -3461,34 +3328,40 @@ class CreateOutputOutputElasticCloudTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputElasticCloudPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputNewrelicEventsPqControlsTypedDict] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_index: NotRequired[str] - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_account_id: NotRequired[str] + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + template_event_type: NotRequired[str] + r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: NotRequired[str] - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_custom_url: NotRequired[str] + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" -class CreateOutputOutputElasticCloud(BaseModel): +class CreateOutputOutputNewrelicEvents(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputElasticCloudType + type: CreateOutputOutputNewrelicEventsType r"""Connector type identifier.""" - url: str - r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" + account_id: Annotated[str, pydantic.Field(alias="accountId")] + r"""New Relic account ID""" - index: str - r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" + event_type: Annotated[str, pydantic.Field(alias="eventType")] + r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -3504,6 +3377,9 @@ class CreateOutputOutputElasticCloud(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + region: Optional[RegionOptions] = None + r"""Which New Relic region endpoint to use.""" + concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -3547,6 +3423,11 @@ class CreateOutputOutputElasticCloud(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -3558,23 +3439,6 @@ class CreateOutputOutputElasticCloud(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - extra_params: Annotated[ - Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") - ] = None - r"""Extra parameters to use in HTTP requests""" - - auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - - elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="elasticPipeline") - ] = None - r"""Optional Elastic Cloud Destination pipeline""" - - include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( - None - ) - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -3595,9 +3459,16 @@ class CreateOutputOutputElasticCloud(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + ] = None + r"""Enter API key directly, or select a stored secret""" + description: Optional[str] = None r"""Optional description for this configuration.""" + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -3648,41 +3519,61 @@ class CreateOutputOutputElasticCloud(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputElasticCloudPqControls], + Optional[CreateOutputOutputNewrelicEventsPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_index: Annotated[ - Optional[str], pydantic.Field(alias="__template_index") + template_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_accountId") ] = None - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + + template_event_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_eventType") + ] = None + r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticPipeline") - ] = None - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_custom_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_customUrl") + ] = None + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + + @field_serializer("region") + def serialize_region(self, value): + if isinstance(value, str): + try: + return models.RegionOptions(value) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -3701,6 +3592,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -3736,6 +3636,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "region", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -3745,17 +3646,16 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "extraParams", - "auth", - "elasticPipeline", - "includeDocId", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", "onBackpressure", + "authType", "description", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -3768,12 +3668,15 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_url", - "__template_index", + "__template_region", + "__template_accountId", + "__template_eventType", "__template_failedRequestLoggingMode", - "__template_elasticPipeline", "__template_onBackpressure", + "__template_customUrl", ] ) serialized = handler(self) @@ -3790,85 +3693,58 @@ def serialize_model(self, handler): return m -class CreateOutputOutputElasticType(str, Enum): +class CreateOutputOutputNewrelicType(str, Enum): r"""Connector type identifier.""" - ELASTIC = "elastic" - - -class CreateOutputElasticVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - - # Auto - AUTO = "auto" - # 6.x - SIX = "6" - # 7.x - SEVEN = "7" - - -class CreateOutputWriteAction(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - - # Index - INDEX = "index" - # Create - CREATE = "create" - + NEWRELIC = "newrelic" -class CreateOutputOutputElasticURLTypedDict(TypedDict): - url: str - r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" +class CreateOutputFieldName(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Name of the metadata field.""" -class CreateOutputOutputElasticURL(BaseModel): - url: str - r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + SERVICE = "service" + HOSTNAME = "hostname" + TIMESTAMP = "timestamp" + AUDIT_ID = "auditId" - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" +class CreateOutputMetadatumTypedDict(TypedDict): + name: CreateOutputFieldName + r"""Name of the metadata field.""" + value: str + r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateOutputMetadatum(BaseModel): + name: CreateOutputFieldName + r"""Name of the metadata field.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + value: str + r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - return m + @field_serializer("name") + def serialize_name(self, value): + if isinstance(value, str): + try: + return models.CreateOutputFieldName(value) + except ValueError: + return value + return value -class CreateOutputOutputElasticPqControlsTypedDict(TypedDict): +class CreateOutputOutputNewrelicPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputElasticPqControls(BaseModel): +class CreateOutputOutputNewrelicPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputElasticTypedDict(TypedDict): +class CreateOutputOutputNewrelicTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputElasticType + type: CreateOutputOutputNewrelicType r"""Connector type identifier.""" - index: str - r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -3877,10 +3753,14 @@ class CreateOutputOutputElasticTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - doc_type: NotRequired[str] - r"""Document type to use for events. Can be overwritten by an event's __type field.""" + region: NotRequired[RegionOptions] + r"""Which New Relic region endpoint to use.""" + log_type: NotRequired[str] + r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + message_field: NotRequired[str] + r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + metadata: NotRequired[List[CreateOutputMetadatumTypedDict]] + r"""Fields to add to events from this input""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -3902,6 +3782,8 @@ class CreateOutputOutputElasticTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] @@ -3913,35 +3795,15 @@ class CreateOutputOutputElasticTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] - r"""Extra parameters""" - auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] - elastic_version: NotRequired[CreateOutputElasticVersion] - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - elastic_pipeline: NotRequired[str] - r"""Optional Elasticsearch destination pipeline""" - include_doc_id: NotRequired[bool] - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - write_action: NotRequired[CreateOutputWriteAction] - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - retry_partial_errors: NotRequired[bool] - r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputOutputElasticURLTypedDict]] - r"""Bulk API URLs""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -3964,34 +3826,33 @@ class CreateOutputOutputElasticTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputElasticPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputNewrelicPqControlsTypedDict] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_index: NotRequired[str] - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_doc_type: NotRequired[str] - r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_log_type: NotRequired[str] + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + template_message_field: NotRequired[str] + r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: NotRequired[str] - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputElastic(BaseModel): +class CreateOutputOutputNewrelic(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputElasticType + type: CreateOutputOutputNewrelicType r"""Connector type identifier.""" - index: str - r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -4006,13 +3867,17 @@ class CreateOutputOutputElastic(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + region: Optional[RegionOptions] = None + r"""Which New Relic region endpoint to use.""" - doc_type: Annotated[Optional[str], pydantic.Field(alias="docType")] = None - r"""Document type to use for events. Can be overwritten by an event's __type field.""" + log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None + r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + + message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None + r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + + metadata: Optional[List[CreateOutputMetadatum]] = None + r"""Fields to add to events from this input""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -4057,6 +3922,11 @@ class CreateOutputOutputElastic(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -4083,69 +3953,25 @@ class CreateOutputOutputElastic(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - extra_params: Annotated[ - Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") - ] = None - r"""Extra parameters""" - - auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - - elastic_version: Annotated[ - Optional[CreateOutputElasticVersion], pydantic.Field(alias="elasticVersion") - ] = None - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - - elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="elasticPipeline") - ] = None - r"""Optional Elasticsearch destination pipeline""" - - include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( - None - ) - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - - write_action: Annotated[ - Optional[CreateOutputWriteAction], pydantic.Field(alias="writeAction") - ] = None - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - - retry_partial_errors: Annotated[ - Optional[bool], pydantic.Field(alias="retryPartialErrors") - ] = None - r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - url: Optional[str] = None - r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[CreateOutputOutputElasticURL]] = None - r"""Bulk API URLs""" + r"""Enter API key directly, or select a stored secret""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -4197,78 +4023,79 @@ class CreateOutputOutputElastic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputElasticPqControls], + Optional[CreateOutputOutputNewrelicPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_index: Annotated[ - Optional[str], pydantic.Field(alias="__template_index") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_doc_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_docType") + template_log_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_logType") ] = None - r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + + template_message_field: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageField") + ] = None + r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticPipeline") - ] = None - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("region") + def serialize_region(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.RegionOptions(value) except ValueError: return value return value - @field_serializer("elastic_version") - def serialize_elastic_version(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CreateOutputElasticVersion(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("write_action") - def serialize_write_action(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputWriteAction(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.AuthenticationMethodOptionsAPI(value) except ValueError: return value return value @@ -4308,8 +4135,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "docType", + "region", + "logType", + "messageField", + "metadata", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -4319,26 +4148,17 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "extraParams", - "auth", - "elasticVersion", - "elasticPipeline", - "includeDocId", - "writeAction", - "retryPartialErrors", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -4351,13 +4171,14 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_index", - "__template_docType", + "__template_region", + "__template_logType", + "__template_messageField", "__template_failedRequestLoggingMode", - "__template_elasticPipeline", "__template_onBackpressure", - "__template_url", ] ) serialized = handler(self) @@ -4374,27 +4195,29 @@ def serialize_model(self, handler): return m -class CreateOutputOutputMskPqControlsTypedDict(TypedDict): +class CreateOutputOutputElasticCloudType(str, Enum): + r"""Connector type identifier.""" + + ELASTIC_CLOUD = "elastic_cloud" + + +class CreateOutputOutputElasticCloudPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputMskPqControls(BaseModel): +class CreateOutputOutputElasticCloudPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputMskTypedDict(TypedDict): +class CreateOutputOutputElasticCloudTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsMsk + type: CreateOutputOutputElasticCloudType r"""Connector type identifier.""" - brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" - aws_authentication_method: AuthenticationMethodOptionsS3CollectorConf - r"""AWS authentication method. Choose Auto to use IAM roles.""" - region: str - r"""Region where the MSK cluster is located""" + url: str + r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" + index: str + r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -4403,68 +4226,49 @@ class CreateOutputOutputMskTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - ack: NotRequired[AcknowledgmentsOptionsAllLeader] - r"""Control the number of required acknowledgments.""" - format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] - r"""Format to use to serialize events before writing to Kafka.""" - compression: NotRequired[CompressionOptionsGzipLz4] - r"""Codec to use to compress the data before sending to Kafka""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - flush_event_count: NotRequired[float] - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - kafka_schema_registry: NotRequired[ - KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] + r"""Extra parameters to use in HTTP requests""" + auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] + elastic_pipeline: NotRequired[str] + r"""Optional Elastic Cloud Destination pipeline""" + include_doc_id: NotRequired[bool] + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] ] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access MSK""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - protobuf_library_id: NotRequired[str] - r"""Select a set of Protobuf definitions for the events you want to send""" - protobuf_encoding_id: NotRequired[str] - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -4487,53 +4291,34 @@ class CreateOutputOutputMskTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputMskPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputElasticCloudPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compression: NotRequired[str] - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_index: NotRequired[str] + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_elastic_pipeline: NotRequired[str] + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputMsk(BaseModel): +class CreateOutputOutputElasticCloud(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsMsk + type: CreateOutputOutputElasticCloudType r"""Connector type identifier.""" - brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" - - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" - - aws_authentication_method: Annotated[ - AuthenticationMethodOptionsS3CollectorConf, - pydantic.Field(alias="awsAuthenticationMethod"), - ] - r"""AWS authentication method. Choose Auto to use IAM roles.""" + url: str + r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" - region: str - r"""Region where the MSK cluster is located""" + index: str + r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -4549,139 +4334,102 @@ class CreateOutputOutputMsk(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - ack: Optional[AcknowledgmentsOptionsAllLeader] = None - r"""Control the number of required acknowledgments.""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - format_: Annotated[ - Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Format to use to serialize events before writing to Kafka.""" + r"""Maximum size, in KB, of the request body""" - compression: Optional[CompressionOptionsGzipLz4] = None - r"""Codec to use to compress the data before sending to Kafka""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], - pydantic.Field(alias="kafkaSchemaRegistry"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Kafka Schema Registry Authentication""" + r"""Headers to add to all events""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + r"""List of headers that are safe to log in plain text""" - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + extra_params: Annotated[ + Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + r"""Extra parameters to use in HTTP requests""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="elasticPipeline") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""Optional Elastic Cloud Destination pipeline""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( None ) - r"""Secret key""" + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - endpoint: Optional[str] = None - r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Use Assume Role credentials to access MSK""" + r"""How to handle events when all receivers are exerting backpressure""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - protobuf_library_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufLibraryId") - ] = None - r"""Select a set of Protobuf definitions for the events you want to send""" - - protobuf_encoding_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufEncodingId") - ] = None - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" @@ -4730,7 +4478,8 @@ class CreateOutputOutputMsk(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputMskPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputElasticCloudPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -4739,88 +4488,36 @@ class CreateOutputOutputMsk(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") - ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_compression: Annotated[ - Optional[str], pydantic.Field(alias="__template_compression") - ] = None - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_index: Annotated[ + Optional[str], pydantic.Field(alias="__template_index") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticPipeline") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - @field_serializer("ack") - def serialize_ack(self, value): - if isinstance(value, str): - try: - return models.AcknowledgmentsOptionsAllLeader(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.RecordDataFormatOptionsJSONProtobuf(value) - except ValueError: - return value - return value - - @field_serializer("compression") - def serialize_compression(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsGzipLz4(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -4869,36 +4566,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "ack", - "format", - "compression", - "maxRecordSizeKB", - "flushEventCount", - "flushPeriodSec", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "awsSecretKey", - "endpoint", - "reuseConnections", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "tls", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "extraParams", + "auth", + "elasticPipeline", + "includeDocId", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", "description", - "awsApiKey", - "awsSecret", - "protobufLibraryId", - "protobufEncodingId", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -4912,16 +4599,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topic", - "__template_format", - "__template_compression", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_url", + "__template_index", + "__template_failedRequestLoggingMode", + "__template_elasticPipeline", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -4938,23 +4620,85 @@ def serialize_model(self, handler): return m -class CreateOutputOutputConfluentCloudPqControlsTypedDict(TypedDict): +class CreateOutputOutputElasticType(str, Enum): + r"""Connector type identifier.""" + + ELASTIC = "elastic" + + +class CreateOutputElasticVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" + + # Auto + AUTO = "auto" + # 6.x + SIX = "6" + # 7.x + SEVEN = "7" + + +class CreateOutputWriteAction(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + + # Index + INDEX = "index" + # Create + CREATE = "create" + + +class CreateOutputOutputElasticURLTypedDict(TypedDict): + url: str + r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputOutputElasticURL(BaseModel): + url: str + r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputElasticPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputConfluentCloudPqControls(BaseModel): +class CreateOutputOutputElasticPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputConfluentCloudTypedDict(TypedDict): +class CreateOutputOutputElasticTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsConfluentcloud + type: CreateOutputOutputElasticType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + index: str + r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -4963,50 +4707,71 @@ class CreateOutputOutputConfluentCloudTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - ack: NotRequired[AcknowledgmentsOptionsAllLeader] - r"""Control the number of required acknowledgments.""" - format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] - r"""Format to use to serialize events before writing to Kafka.""" - compression: NotRequired[CompressionOptionsGzipLz4] - r"""Codec to use to compress the data before sending to Kafka""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - flush_event_count: NotRequired[float] - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + doc_type: NotRequired[str] + r"""Document type to use for events. Can be overwritten by an event's __type field.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - kafka_schema_registry: NotRequired[ - KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] ] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] + r"""Extra parameters""" + auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] + elastic_version: NotRequired[CreateOutputElasticVersion] + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" + elastic_pipeline: NotRequired[str] + r"""Optional Elasticsearch destination pipeline""" + include_doc_id: NotRequired[bool] + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" + write_action: NotRequired[CreateOutputWriteAction] + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + retry_partial_errors: NotRequired[bool] + r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - protobuf_library_id: NotRequired[str] - r"""Select a set of Protobuf definitions for the events you want to send""" - protobuf_encoding_id: NotRequired[str] - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + url: NotRequired[str] + r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputOutputElasticURLTypedDict]] + r"""Bulk API URLs""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -5029,34 +4794,33 @@ class CreateOutputOutputConfluentCloudTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputConfluentCloudPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputElasticPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compression: NotRequired[str] - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + template_index: NotRequired[str] + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_doc_type: NotRequired[str] + r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_elastic_pipeline: NotRequired[str] + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputConfluentCloud(BaseModel): +class CreateOutputOutputElastic(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsConfluentcloud + type: CreateOutputOutputElasticType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" - - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + index: str + r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -5072,77 +4836,114 @@ class CreateOutputOutputConfluentCloud(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - ack: Optional[AcknowledgmentsOptionsAllLeader] = None - r"""Control the number of required acknowledgments.""" + doc_type: Annotated[Optional[str], pydantic.Field(alias="docType")] = None + r"""Document type to use for events. Can be overwritten by an event's __type field.""" - format_: Annotated[ - Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Format to use to serialize events before writing to Kafka.""" + r"""Maximum size, in KB, of the request body""" - compression: Optional[CompressionOptionsGzipLz4] = None - r"""Codec to use to compress the data before sending to Kafka""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], - pydantic.Field(alias="kafkaSchemaRegistry"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Kafka Schema Registry Authentication""" + r"""Headers to add to all events""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum time to wait for Kafka to respond to a request""" + r"""List of headers that are safe to log in plain text""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + extra_params: Annotated[ + Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") + ] = None + r"""Extra parameters""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") + auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None + + elastic_version: Annotated[ + Optional[CreateOutputElasticVersion], pydantic.Field(alias="elasticVersion") ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="elasticPipeline") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""Optional Elasticsearch destination pipeline""" - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( + None + ) + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" + + write_action: Annotated[ + Optional[CreateOutputWriteAction], pydantic.Field(alias="writeAction") + ] = None + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + + retry_partial_errors: Annotated[ + Optional[bool], pydantic.Field(alias="retryPartialErrors") + ] = None + r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -5152,15 +4953,29 @@ class CreateOutputOutputConfluentCloud(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - protobuf_library_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufLibraryId") + url: Optional[str] = None + r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Select a set of Protobuf definitions for the events you want to send""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - protobuf_encoding_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufEncodingId") + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[CreateOutputOutputElasticURL]] = None + r"""Bulk API URLs""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -5212,7 +5027,7 @@ class CreateOutputOutputConfluentCloud(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputConfluentCloudPqControls], + Optional[CreateOutputOutputElasticPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -5222,54 +5037,59 @@ class CreateOutputOutputConfluentCloud(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") + template_index: Annotated[ + Optional[str], pydantic.Field(alias="__template_index") ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") + template_doc_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_docType") ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_compression: Annotated[ - Optional[str], pydantic.Field(alias="__template_compression") + template_elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticPipeline") ] = None - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("ack") - def serialize_ack(self, value): + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AcknowledgmentsOptionsAllLeader(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("elastic_version") + def serialize_elastic_version(self, value): if isinstance(value, str): try: - return models.RecordDataFormatOptionsJSONProtobuf(value) + return models.CreateOutputElasticVersion(value) except ValueError: return value return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("write_action") + def serialize_write_action(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipLz4(value) + return models.CreateOutputWriteAction(value) except ValueError: return value return value @@ -5318,27 +5138,37 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "tls", - "ack", - "format", - "compression", - "maxRecordSizeKB", - "flushEventCount", + "loadBalanced", + "docType", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "extraParams", + "auth", + "elasticVersion", + "elasticPipeline", + "includeDocId", + "writeAction", + "retryPartialErrors", "onBackpressure", "description", - "protobufLibraryId", - "protobufEncodingId", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -5352,11 +5182,12 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_brokers", - "__template_topic", - "__template_format", - "__template_compression", + "__template_index", + "__template_docType", + "__template_failedRequestLoggingMode", + "__template_elasticPipeline", "__template_onBackpressure", + "__template_url", ] ) serialized = handler(self) @@ -5373,23 +5204,27 @@ def serialize_model(self, handler): return m -class CreateOutputOutputKafkaPqControlsTypedDict(TypedDict): +class CreateOutputOutputMskPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputKafkaPqControls(BaseModel): +class CreateOutputOutputMskPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputKafkaTypedDict(TypedDict): +class CreateOutputOutputMskTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptions + type: TypeOptionsMsk r"""Connector type identifier.""" brokers: List[str] r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + aws_authentication_method: AuthenticationMethodOptionsS3CollectorConf + r"""AWS authentication method. Choose Auto to use IAM roles.""" + region: str + r"""Region where the MSK cluster is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -5430,14 +5265,32 @@ class CreateOutputOutputKafkaTypedDict(TypedDict): r"""Maximum time to wait for Kafka to respond to an authentication request""" reauthentication_threshold: NotRequired[float] r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access MSK""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" protobuf_library_id: NotRequired[str] r"""Select a set of Protobuf definitions for the events you want to send""" protobuf_encoding_id: NotRequired[str] @@ -5464,7 +5317,7 @@ class CreateOutputOutputKafkaTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputKafkaPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputMskPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -5474,15 +5327,27 @@ class CreateOutputOutputKafkaTypedDict(TypedDict): r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_compression: NotRequired[str] r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputKafka(BaseModel): +class CreateOutputOutputMsk(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptions + type: TypeOptionsMsk r"""Connector type identifier.""" brokers: List[str] @@ -5491,6 +5356,15 @@ class CreateOutputOutputKafka(BaseModel): topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + aws_authentication_method: Annotated[ + AuthenticationMethodOptionsS3CollectorConf, + pydantic.Field(alias="awsAuthenticationMethod"), + ] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + region: str + r"""Region where the MSK cluster is located""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -5571,8 +5445,43 @@ class CreateOutputOutputKafka(BaseModel): ] = None r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + endpoint: Optional[str] = None + r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access MSK""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None r"""TLS settings (client side)""" @@ -5585,6 +5494,12 @@ class CreateOutputOutputKafka(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + protobuf_library_id: Annotated[ Optional[str], pydantic.Field(alias="protobufLibraryId") ] = None @@ -5645,7 +5560,7 @@ class CreateOutputOutputKafka(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputKafkaPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputMskPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -5669,22 +5584,52 @@ class CreateOutputOutputKafka(BaseModel): ] = None r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - @field_serializer("ack") - def serialize_ack(self, value): - if isinstance(value, str): - try: - return models.AcknowledgmentsOptionsAllLeader(value) - except ValueError: - return value - return value + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - @field_serializer("format_") - def serialize_format_(self, value): + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("ack") + def serialize_ack(self, value): + if isinstance(value, str): + try: + return models.AcknowledgmentsOptionsAllLeader(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: return models.RecordDataFormatOptionsJSONProtobuf(value) @@ -5701,6 +5646,15 @@ def serialize_compression(self, value): return value return value + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -5760,10 +5714,19 @@ def serialize_model(self, handler): "backoffRate", "authenticationTimeout", "reauthenticationThreshold", - "sasl", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "tls", "onBackpressure", "description", + "awsApiKey", + "awsSecret", "protobufLibraryId", "protobufEncodingId", "pqStrictOrdering", @@ -5782,7 +5745,13 @@ def serialize_model(self, handler): "__template_topic", "__template_format", "__template_compression", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -5799,29 +5768,23 @@ def serialize_model(self, handler): return m -class CreateOutputOutputExabeamType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputOutputConfluentCloudPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - EXABEAM = "exabeam" + +class CreateOutputOutputConfluentCloudPqControls(BaseModel): + r"""Persistent queue controls.""" -class CreateOutputOutputExabeamTypedDict(TypedDict): +class CreateOutputOutputConfluentCloudTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputExabeamType + type: TypeOptionsConfluentcloud r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" - region: str - r"""Region where the bucket is located""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Google Cloud Storage service endpoint""" - collector_instance_id: str - r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 - - """ + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -5830,94 +5793,100 @@ class CreateOutputOutputExabeamTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsArchiveColdline] - r"""Storage class to select for uploaded objects""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + ack: NotRequired[AcknowledgmentsOptionsAllLeader] + r"""Control the number of required acknowledgments.""" + format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] + r"""Format to use to serialize events before writing to Kafka.""" + compression: NotRequired[CompressionOptionsGzipLz4] + r"""Codec to use to compress the data before sending to Kafka""" + max_record_size_kb: NotRequired[float] + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + flush_event_count: NotRequired[float] + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + flush_period_sec: NotRequired[float] + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + kafka_schema_registry: NotRequired[ + KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + ] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - encoded_configuration: NotRequired[str] - r"""Enter an encoded string containing Exabeam configurations""" - site_name: NotRequired[str] - r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" - site_id: NotRequired[str] - r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" - timezone_offset: NotRequired[str] - r"""Timezone offset""" - aws_api_key: NotRequired[str] - r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - aws_secret_key: NotRequired[str] - r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" description: NotRequired[str] r"""Optional description for this configuration.""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + protobuf_library_id: NotRequired[str] + r"""Select a set of Protobuf definitions for the events you want to send""" + protobuf_encoding_id: NotRequired[str] + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputConfluentCloudPqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_compression: NotRequired[str] + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputExabeam(BaseModel): +class CreateOutputOutputConfluentCloud(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputExabeamType + type: TypeOptionsConfluentcloud r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" - - region: str - r"""Region where the bucket is located""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - - endpoint: str - r"""Google Cloud Storage service endpoint""" - - collector_instance_id: Annotated[str, pydantic.Field(alias="collectorInstanceId")] - r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" - """ + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -5933,175 +5902,204 @@ class CreateOutputOutputExabeam(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - object_acl: Annotated[ - Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], - pydantic.Field(alias="objectACL"), - ] = None - r"""Object ACL to assign to uploaded objects""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - storage_class: Annotated[ - Optional[StorageClassOptionsArchiveColdline], - pydantic.Field(alias="storageClass"), - ] = None - r"""Storage class to select for uploaded objects""" + ack: Optional[AcknowledgmentsOptionsAllLeader] = None + r"""Control the number of required acknowledgments.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + format_: Annotated[ + Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Format to use to serialize events before writing to Kafka.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + compression: Optional[CompressionOptionsGzipLz4] = None + r"""Codec to use to compress the data before sending to Kafka""" + + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") ] = None - r"""Add the Output ID value to staging location""" + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Remove empty staging directories after moving files""" + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], + pydantic.Field(alias="kafkaSchemaRegistry"), ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Kafka Schema Registry Authentication""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""Maximum time to wait for a connection to complete successfully""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""Maximum time to wait for Kafka to respond to an authentication request""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None + r"""How to handle events when all receivers are exerting backpressure""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + protobuf_library_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufLibraryId") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Select a set of Protobuf definitions for the events you want to send""" - encoded_configuration: Annotated[ - Optional[str], pydantic.Field(alias="encodedConfiguration") + protobuf_encoding_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufEncodingId") ] = None - r"""Enter an encoded string containing Exabeam configurations""" + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" - site_name: Annotated[Optional[str], pydantic.Field(alias="siteName")] = None - r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - site_id: Annotated[Optional[str], pydantic.Field(alias="siteId")] = None - r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - timezone_offset: Annotated[ - Optional[str], pydantic.Field(alias="timezoneOffset") + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Timezone offset""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Codec to use to compress the persisted data""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + pq_controls: Annotated[ + Optional[CreateOutputOutputConfluentCloudPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + template_compression: Annotated[ + Optional[str], pydantic.Field(alias="__template_compression") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( - value - ) + return models.AcknowledgmentsOptionsAllLeader(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.StorageClassOptionsArchiveColdline(value) + return models.RecordDataFormatOptionsJSONProtobuf(value) + except ValueError: + return value + return value + + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsGzipLz4(value) except ValueError: return value return value @@ -6110,16 +6108,34 @@ def serialize_storage_class(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -6132,37 +6148,44 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "objectACL", - "storageClass", - "reuseConnections", - "rejectUnauthorized", - "addIdToStagePath", - "removeEmptyDirs", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "retrySettings", - "orphans", - "maxFileSizeMB", - "encodedConfiguration", - "siteName", - "siteId", - "timezoneOffset", - "awsApiKey", - "awsSecretKey", + "tls", + "ack", + "format", + "compression", + "maxRecordSizeKB", + "flushEventCount", + "flushPeriodSec", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "onBackpressure", "description", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "protobufLibraryId", + "protobufEncodingId", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_region", - "__template_endpoint", - "__template_objectACL", - "__template_storageClass", + "__template_brokers", + "__template_topic", + "__template_format", + "__template_compression", "__template_onBackpressure", ] ) @@ -6180,21 +6203,23 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGooglePubsubPqControlsTypedDict(TypedDict): +class CreateOutputOutputKafkaPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputGooglePubsubPqControls(BaseModel): +class CreateOutputOutputKafkaPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputGooglePubsubTypedDict(TypedDict): +class CreateOutputOutputKafkaTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsGooglepubsub + type: TypeOptions r"""Connector type identifier.""" - topic_name: str - r"""ID of the topic to send events to.""" + brokers: List[str] + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -6203,34 +6228,50 @@ class CreateOutputOutputGooglePubsubTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - create_topic: NotRequired[bool] - r"""If enabled, create topic if it does not exist.""" - ordered_delivery: NotRequired[bool] - r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" - region: NotRequired[str] - r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - batch_size: NotRequired[float] - r"""The maximum number of items the Google API should batch before it sends them to the topic.""" - batch_timeout: NotRequired[float] - r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking.""" + ack: NotRequired[AcknowledgmentsOptionsAllLeader] + r"""Control the number of required acknowledgments.""" + format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] + r"""Format to use to serialize events before writing to Kafka.""" + compression: NotRequired[CompressionOptionsGzipLz4] + r"""Codec to use to compress the data before sending to Kafka""" max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of batches to send.""" - flush_period: NotRequired[float] - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + flush_event_count: NotRequired[float] + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + flush_period_sec: NotRequired[float] + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + kafka_schema_registry: NotRequired[ + KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + ] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + protobuf_library_id: NotRequired[str] + r"""Select a set of Protobuf definitions for the events you want to send""" + protobuf_encoding_id: NotRequired[str] + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -6253,27 +6294,32 @@ class CreateOutputOutputGooglePubsubTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputGooglePubsubPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputKafkaPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: NotRequired[str] - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_compression: NotRequired[str] + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputGooglePubsub(BaseModel): +class CreateOutputOutputKafka(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsGooglepubsub + type: TypeOptions r"""Connector type identifier.""" - topic_name: Annotated[str, pydantic.Field(alias="topicName")] - r"""ID of the topic to send events to.""" + brokers: List[str] + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" + + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -6289,56 +6335,77 @@ class CreateOutputOutputGooglePubsub(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None - r"""If enabled, create topic if it does not exist.""" + ack: Optional[AcknowledgmentsOptionsAllLeader] = None + r"""Control the number of required acknowledgments.""" - ordered_delivery: Annotated[ - Optional[bool], pydantic.Field(alias="orderedDelivery") + format_: Annotated[ + Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") ] = None - r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" + r"""Format to use to serialize events before writing to Kafka.""" - region: Optional[str] = None - r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + compression: Optional[CompressionOptionsGzipLz4] = None + r"""Codec to use to compress the data before sending to Kafka""" - google_auth_method: Annotated[ - Optional[GoogleAuthenticationMethodOptions], - pydantic.Field(alias="googleAuthMethod"), + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" - secret: Optional[str] = None - r"""Select or create a stored text secret""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None - r"""The maximum number of items the Google API should batch before it sends them to the topic.""" + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], + pydantic.Field(alias="kafkaSchemaRegistry"), + ] = None + r"""Kafka Schema Registry Authentication""" - batch_timeout: Annotated[Optional[float], pydantic.Field(alias="batchTimeout")] = ( - None - ) - r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""Maximum size (KB) of batches to send.""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -6348,6 +6415,16 @@ class CreateOutputOutputGooglePubsub(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + protobuf_library_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufLibraryId") + ] = None + r"""Select a set of Protobuf definitions for the events you want to send""" + + protobuf_encoding_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufEncodingId") + ] = None + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -6398,8 +6475,7 @@ class CreateOutputOutputGooglePubsub(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputGooglePubsubPqControls], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputKafkaPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -6408,26 +6484,49 @@ class CreateOutputOutputGooglePubsub(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicName") - ] = None - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") + ] = None + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_compression: Annotated[ + Optional[str], pydantic.Field(alias="__template_compression") + ] = None + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.GoogleAuthenticationMethodOptions(value) + return models.AcknowledgmentsOptionsAllLeader(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.RecordDataFormatOptionsJSONProtobuf(value) + except ValueError: + return value + return value + + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsGzipLz4(value) except ValueError: return value return value @@ -6476,20 +6575,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "createTopic", - "orderedDelivery", - "region", - "googleAuthMethod", - "serviceAccountCredentials", - "secret", - "batchSize", - "batchTimeout", - "maxQueueSize", + "ack", + "format", + "compression", "maxRecordSizeKB", - "flushPeriod", - "maxInProgress", + "flushEventCount", + "flushPeriodSec", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", "onBackpressure", "description", + "protobufLibraryId", + "protobufEncodingId", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -6503,8 +6609,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topicName", - "__template_region", + "__template_topic", + "__template_format", + "__template_compression", "__template_onBackpressure", ] ) @@ -6522,64 +6629,40 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGoogleCloudObservabilityType(str, Enum): +class CreateOutputOutputExabeamType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CLOUD_OBSERVABILITY = "google_cloud_observability" - - -class CreateOutputOutputGoogleCloudObservabilityProtocol( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Discriminator value.""" - - GRPC = "grpc" - - -class CreateOutputOutputGoogleCloudObservabilityOtlpVersion( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Discriminator value.""" - - ONE_DOT_3_DOT_1 = "1.3.1" - - -class CreateOutputOutputGoogleCloudObservabilityEndpoint( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - - TELEMETRY_GOOGLEAPIS_COM_443 = "telemetry.googleapis.com:443" + EXABEAM = "exabeam" -class CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod( +class CreateOutputOutputExabeamAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + r"""Authentication method""" - # Auto - AUTO = "auto" + # Manual + MANUAL = "manual" # Secret SECRET = "secret" -class CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputGoogleCloudObservabilityPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputGoogleCloudObservabilityTypedDict(TypedDict): +class CreateOutputOutputExabeamTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleCloudObservabilityType + type: CreateOutputOutputExabeamType r"""Connector type identifier.""" - google_auth_method: ( - CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod - ) - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + bucket: str + r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" + region: str + r"""Region where the bucket is located""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Google Cloud Storage service endpoint""" + collector_instance_id: str + r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + + """ pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -6588,92 +6671,108 @@ class CreateOutputOutputGoogleCloudObservabilityTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[CreateOutputOutputGoogleCloudObservabilityProtocol] - r"""Discriminator value.""" - otlp_version: NotRequired[CreateOutputOutputGoogleCloudObservabilityOtlpVersion] - r"""Discriminator value.""" - endpoint: NotRequired[CreateOutputOutputGoogleCloudObservabilityEndpoint] - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] - r"""TLS settings (client side)""" - max_payload_events: NotRequired[float] - r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsArchiveColdline] + r"""Storage class to select for uploaded objects""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + encoded_configuration: NotRequired[str] + r"""Enter an encoded string containing Exabeam configurations""" + aws_authentication_method: NotRequired[ + CreateOutputOutputExabeamAuthenticationMethod + ] + r"""Authentication method""" + site_name: NotRequired[str] + r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" + site_id: NotRequired[str] + r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" + timezone_offset: NotRequired[str] + r"""Timezone offset""" + hostname: NotRequired[str] + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" + forwarder: NotRequired[str] + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" + origin: NotRequired[str] + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" + logtags: NotRequired[str] + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" + aws_api_key: NotRequired[str] + r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + aws_secret_key: NotRequired[str] + r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" description: NotRequired[str] r"""Optional description for this configuration.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict - ] - r"""Persistent queue controls.""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputGoogleCloudObservability(BaseModel): +class CreateOutputOutputExabeam(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleCloudObservabilityType + type: CreateOutputOutputExabeamType r"""Connector type identifier.""" - google_auth_method: Annotated[ - CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod, - pydantic.Field(alias="googleAuthMethod"), - ] - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + bucket: str + r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" + + region: str + r"""Region where the bucket is located""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + endpoint: str + r"""Google Cloud Storage service endpoint""" + + collector_instance_id: Annotated[str, pydantic.Field(alias="collectorInstanceId")] + r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + + """ pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -6689,207 +6788,196 @@ class CreateOutputOutputGoogleCloudObservability(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[CreateOutputOutputGoogleCloudObservabilityProtocol] = None - r"""Discriminator value.""" - - otlp_version: Annotated[ - Optional[CreateOutputOutputGoogleCloudObservabilityOtlpVersion], - pydantic.Field(alias="otlpVersion"), + object_acl: Annotated[ + Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], + pydantic.Field(alias="objectACL"), ] = None - r"""Discriminator value.""" + r"""Object ACL to assign to uploaded objects""" - endpoint: Optional[CreateOutputOutputGoogleCloudObservabilityEndpoint] = None - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + storage_class: Annotated[ + Optional[StorageClassOptionsArchiveColdline], + pydantic.Field(alias="storageClass"), + ] = None + r"""Storage class to select for uploaded objects""" - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + r"""Reuse connections between requests, which can improve performance""" - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + r"""Add the Output ID value to staging location""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + r"""Remove empty staging directories after moving files""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""How to handle events when all receivers are exerting backpressure""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often the sender should ping the peer to keep the connection open""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - tls: Optional[TLSSettingsClientSideTypeExtended] = None - r"""TLS settings (client side)""" + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + encoded_configuration: Annotated[ + Optional[str], pydantic.Field(alias="encodedConfiguration") ] = None - r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" + r"""Enter an encoded string containing Exabeam configurations""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + aws_authentication_method: Annotated[ + Optional[CreateOutputOutputExabeamAuthenticationMethod], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Authentication method""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + site_name: Annotated[Optional[str], pydantic.Field(alias="siteName")] = None + r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" - secret: Optional[str] = None - r"""Select or create a stored text secret""" + site_id: Annotated[Optional[str], pydantic.Field(alias="siteId")] = None + r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + timezone_offset: Annotated[ + Optional[str], pydantic.Field(alias="timezoneOffset") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Timezone offset""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + hostname: Optional[str] = None + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + forwarder: Optional[str] = None + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + origin: Optional[str] = None + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + logtags: Optional[str] = None + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""Codec to use to compress the persisted data""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - pq_controls: Annotated[ - Optional[CreateOutputOutputGoogleCloudObservabilityPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputGoogleCloudObservabilityProtocol(value) + return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( + value + ) except ValueError: return value return value - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputGoogleCloudObservabilityOtlpVersion( - value - ) - except ValueError: - return value - return value - - @field_serializer("endpoint") - def serialize_endpoint(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputGoogleCloudObservabilityEndpoint(value) - except ValueError: - return value - return value - - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) + return models.StorageClassOptionsArchiveColdline(value) except ValueError: return value return value @@ -6898,34 +6986,25 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.CreateOutputOutputExabeamAuthenticationMethod(value) except ValueError: return value return value @@ -6938,40 +7017,43 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "otlpVersion", - "endpoint", - "preserveNativeAnyValue", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", - "concurrency", - "maxPayloadSizeKB", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "tls", - "maxPayloadEvents", + "objectACL", + "storageClass", + "reuseConnections", + "rejectUnauthorized", + "addIdToStagePath", + "removeEmptyDirs", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "retrySettings", + "orphans", + "maxFileSizeMB", + "encodedConfiguration", + "awsAuthenticationMethod", + "siteName", + "siteId", + "timezoneOffset", + "hostname", + "forwarder", + "origin", + "logtags", + "awsApiKey", + "awsSecretKey", "description", - "secret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", + "awsSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_region", + "__template_endpoint", + "__template_objectACL", + "__template_storageClass", "__template_onBackpressure", ] ) @@ -6989,53 +7071,21 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGoogleCloudLoggingType(str, Enum): - r"""Connector type identifier.""" - - GOOGLE_CLOUD_LOGGING = "google_cloud_logging" - - -class CreateOutputLogLocationType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Log location type""" - - # Project - PROJECT = "project" - # Organization - ORGANIZATION = "organization" - # Billing Account - BILLING_ACCOUNT = "billingAccount" - # Folder - FOLDER = "folder" - - -class CreateOutputPayloadFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format to use when sending payload. Defaults to Text.""" - - # Text - TEXT = "text" - # JSON - JSON = "json" - - -class CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict(TypedDict): +class CreateOutputOutputGooglePubsubPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputGoogleCloudLoggingPqControls(BaseModel): +class CreateOutputOutputGooglePubsubPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputGoogleCloudLoggingTypedDict(TypedDict): +class CreateOutputOutputGooglePubsubTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleCloudLoggingType + type: TypeOptionsGooglepubsub r"""Connector type identifier.""" - log_location_type: CreateOutputLogLocationType - r"""Log location type""" - log_name_expression: str - r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" - log_location_expression: str - r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + topic_name: str + r"""ID of the topic to send events to.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -7044,106 +7094,34 @@ class CreateOutputOutputGoogleCloudLoggingTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - sanitize_log_names: NotRequired[bool] - r"""Validate and correct log name""" - payload_format: NotRequired[CreateOutputPayloadFormat] - r"""Format to use when sending payload. Defaults to Text.""" - log_labels: NotRequired[List[LogLabelConfOutputGoogleCloudLoggingTypedDict]] - r"""Labels to apply to the log entry""" - resource_type_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - resource_type_labels: NotRequired[ - List[LogLabelConfOutputGoogleCloudLoggingTypedDict] - ] - r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" - severity_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" - insert_id_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the insert ID field.""" + create_topic: NotRequired[bool] + r"""If enabled, create topic if it does not exist.""" + ordered_delivery: NotRequired[bool] + r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" + region: NotRequired[str] + r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" service_account_credentials: NotRequired[str] r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" secret: NotRequired[str] r"""Select or create a stored text secret""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body.""" - max_payload_events: NotRequired[float] - r"""Max number of events to include in the request body. Default is 0 (unlimited).""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" - throttle_rate_req_per_sec: NotRequired[int] - r"""Maximum number of requests to limit to per second.""" - request_method_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - request_url_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - request_size_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - status_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - response_size_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - user_agent_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - remote_ip_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - server_ip_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - referer_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - latency_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_lookup_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_hit_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_validated_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_fill_bytes_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - protocol_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - id_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - producer_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - first_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - last_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - file_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - line_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - function_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - uid_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - index_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - total_splits_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - trace_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - span_id_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - trace_sampled_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - payload_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" + batch_size: NotRequired[float] + r"""The maximum number of items the Google API should batch before it sends them to the topic.""" + batch_timeout: NotRequired[float] + r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of batches to send.""" + flush_period: NotRequired[float] + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -7166,55 +7144,27 @@ class CreateOutputOutputGoogleCloudLoggingTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputGooglePubsubPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_location_type: NotRequired[str] - r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" - template_log_name_expression: NotRequired[str] - r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" - template_payload_format: NotRequired[str] - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - template_resource_type_expression: NotRequired[str] - r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" - template_severity_expression: NotRequired[str] - r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" - template_insert_id_expression: NotRequired[str] - r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" - template_trace_expression: NotRequired[str] - r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" - template_span_id_expression: NotRequired[str] - r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" - template_trace_sampled_expression: NotRequired[str] - r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" + template_topic_name: NotRequired[str] + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_log_location_expression: NotRequired[str] - r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - template_payload_expression: NotRequired[str] - r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" -class CreateOutputOutputGoogleCloudLogging(BaseModel): +class CreateOutputOutputGooglePubsub(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleCloudLoggingType + type: TypeOptionsGooglepubsub r"""Connector type identifier.""" - log_location_type: Annotated[ - CreateOutputLogLocationType, pydantic.Field(alias="logLocationType") - ] - r"""Log location type""" - - log_name_expression: Annotated[str, pydantic.Field(alias="logNameExpression")] - r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" - - log_location_expression: Annotated[ - str, pydantic.Field(alias="logLocationExpression") - ] - r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + topic_name: Annotated[str, pydantic.Field(alias="topicName")] + r"""ID of the topic to send events to.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -7230,42 +7180,16 @@ class CreateOutputOutputGoogleCloudLogging(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - sanitize_log_names: Annotated[ - Optional[bool], pydantic.Field(alias="sanitizeLogNames") - ] = None - r"""Validate and correct log name""" - - payload_format: Annotated[ - Optional[CreateOutputPayloadFormat], pydantic.Field(alias="payloadFormat") - ] = None - r"""Format to use when sending payload. Defaults to Text.""" - - log_labels: Annotated[ - Optional[List[LogLabelConfOutputGoogleCloudLogging]], - pydantic.Field(alias="logLabels"), - ] = None - r"""Labels to apply to the log entry""" - - resource_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="resourceTypeExpression") - ] = None - r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - - resource_type_labels: Annotated[ - Optional[List[LogLabelConfOutputGoogleCloudLogging]], - pydantic.Field(alias="resourceTypeLabels"), - ] = None - r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" + create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None + r"""If enabled, create topic if it does not exist.""" - severity_expression: Annotated[ - Optional[str], pydantic.Field(alias="severityExpression") + ordered_delivery: Annotated[ + Optional[bool], pydantic.Field(alias="orderedDelivery") ] = None - r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" + r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" - insert_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="insertIdExpression") - ] = None - r"""JavaScript expression to compute the value of the insert ID field.""" + region: Optional[str] = None + r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" google_auth_method: Annotated[ Optional[GoogleAuthenticationMethodOptions], @@ -7281,330 +7205,114 @@ class CreateOutputOutputGoogleCloudLogging(BaseModel): secret: Optional[str] = None r"""Select or create a stored text secret""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body.""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Max number of events to include in the request body. Default is 0 (unlimited).""" + batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None + r"""The maximum number of items the Google API should batch before it sends them to the topic.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + batch_timeout: Annotated[Optional[float], pydantic.Field(alias="batchTimeout")] = ( + None + ) + r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking.""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking.""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Maximum size (KB) of batches to send.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" + flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - throttle_rate_req_per_sec: Annotated[ - Optional[int], pydantic.Field(alias="throttleRateReqPerSec") + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") ] = None - r"""Maximum number of requests to limit to per second.""" + r"""The maximum number of in-progress API requests before backpressure is applied.""" - request_method_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestMethodExpression") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""How to handle events when all receivers are exerting backpressure""" - request_url_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestUrlExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - request_size_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestSizeExpression") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - status_expression: Annotated[ - Optional[str], pydantic.Field(alias="statusExpression") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - response_size_expression: Annotated[ - Optional[str], pydantic.Field(alias="responseSizeExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - user_agent_expression: Annotated[ - Optional[str], pydantic.Field(alias="userAgentExpression") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - remote_ip_expression: Annotated[ - Optional[str], pydantic.Field(alias="remoteIpExpression") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - server_ip_expression: Annotated[ - Optional[str], pydantic.Field(alias="serverIpExpression") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - referer_expression: Annotated[ - Optional[str], pydantic.Field(alias="refererExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - latency_expression: Annotated[ - Optional[str], pydantic.Field(alias="latencyExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - cache_lookup_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheLookupExpression") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Codec to use to compress the persisted data""" - cache_hit_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheHitExpression") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - cache_validated_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheValidatedExpression") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - cache_fill_bytes_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheFillBytesExpression") + pq_controls: Annotated[ + Optional[CreateOutputOutputGooglePubsubPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Persistent queue controls.""" - protocol_expression: Annotated[ - Optional[str], pydantic.Field(alias="protocolExpression") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - id_expression: Annotated[Optional[str], pydantic.Field(alias="idExpression")] = None - r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - producer_expression: Annotated[ - Optional[str], pydantic.Field(alias="producerExpression") + template_topic_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicName") ] = None - r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - first_expression: Annotated[ - Optional[str], pydantic.Field(alias="firstExpression") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - last_expression: Annotated[ - Optional[str], pydantic.Field(alias="lastExpression") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - - file_expression: Annotated[ - Optional[str], pydantic.Field(alias="fileExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - line_expression: Annotated[ - Optional[str], pydantic.Field(alias="lineExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - function_expression: Annotated[ - Optional[str], pydantic.Field(alias="functionExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - uid_expression: Annotated[Optional[str], pydantic.Field(alias="uidExpression")] = ( - None - ) - r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - index_expression: Annotated[ - Optional[str], pydantic.Field(alias="indexExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - total_splits_expression: Annotated[ - Optional[str], pydantic.Field(alias="totalSplitsExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - trace_expression: Annotated[ - Optional[str], pydantic.Field(alias="traceExpression") - ] = None - r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - - span_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="spanIdExpression") - ] = None - r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - - trace_sampled_expression: Annotated[ - Optional[str], pydantic.Field(alias="traceSampledExpression") - ] = None - r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="payloadExpression") - ] = None - r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[CreateOutputOutputGoogleCloudLoggingPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_log_location_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLocationType") - ] = None - r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" - - template_log_name_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_logNameExpression") - ] = None - r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" - - template_payload_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadFormat") - ] = None - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - - template_resource_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_resourceTypeExpression") - ] = None - r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" - - template_severity_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_severityExpression") - ] = None - r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" - - template_insert_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_insertIdExpression") - ] = None - r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" - - template_trace_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_traceExpression") - ] = None - r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" - - template_span_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_spanIdExpression") - ] = None - r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" - - template_trace_sampled_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_traceSampledExpression") - ] = None - r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_log_location_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLocationExpression") - ] = None - r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - - template_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadExpression") - ] = None - r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" - - @field_serializer("log_location_type") - def serialize_log_location_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputLogLocationType(value) - except ValueError: - return value - return value - - @field_serializer("payload_format") - def serialize_payload_format(self, value): - if isinstance(value, str): - try: - return models.CreateOutputPayloadFormat(value) - except ValueError: - return value - return value + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" @field_serializer("google_auth_method") def serialize_google_auth_method(self, value): @@ -7659,55 +7367,20 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "sanitizeLogNames", - "payloadFormat", - "logLabels", - "resourceTypeExpression", - "resourceTypeLabels", - "severityExpression", - "insertIdExpression", + "createTopic", + "orderedDelivery", + "region", "googleAuthMethod", "serviceAccountCredentials", "secret", - "maxPayloadSizeKB", - "maxPayloadEvents", - "flushPeriodSec", - "concurrency", - "connectionTimeout", - "timeoutSec", - "throttleRateReqPerSec", - "requestMethodExpression", - "requestUrlExpression", - "requestSizeExpression", - "statusExpression", - "responseSizeExpression", - "userAgentExpression", - "remoteIpExpression", - "serverIpExpression", - "refererExpression", - "latencyExpression", - "cacheLookupExpression", - "cacheHitExpression", - "cacheValidatedExpression", - "cacheFillBytesExpression", - "protocolExpression", - "idExpression", - "producerExpression", - "firstExpression", - "lastExpression", - "fileExpression", - "lineExpression", - "functionExpression", - "uidExpression", - "indexExpression", - "totalSplitsExpression", - "traceExpression", - "spanIdExpression", - "traceSampledExpression", + "batchSize", + "batchTimeout", + "maxQueueSize", + "maxRecordSizeKB", + "flushPeriod", + "maxInProgress", "onBackpressure", - "totalMemoryLimitKB", "description", - "payloadExpression", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -7721,18 +7394,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_logLocationType", - "__template_logNameExpression", - "__template_payloadFormat", - "__template_resourceTypeExpression", - "__template_severityExpression", - "__template_insertIdExpression", - "__template_traceExpression", - "__template_spanIdExpression", - "__template_traceSampledExpression", + "__template_topicName", + "__template_region", "__template_onBackpressure", - "__template_logLocationExpression", - "__template_payloadExpression", ] ) serialized = handler(self) @@ -7749,38 +7413,64 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGoogleCloudStorageType(str, Enum): +class CreateOutputOutputGoogleCloudObservabilityType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CLOUD_STORAGE = "google_cloud_storage" + GOOGLE_CLOUD_OBSERVABILITY = "google_cloud_observability" -class CreateOutputOutputGoogleCloudStorageAuthenticationMethod( +class CreateOutputOutputGoogleCloudObservabilityProtocol( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Authentication method""" + r"""Discriminator value.""" - # auto + GRPC = "grpc" + + +class CreateOutputOutputGoogleCloudObservabilityOtlpVersion( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Discriminator value.""" + + ONE_DOT_3_DOT_1 = "1.3.1" + + +class CreateOutputOutputGoogleCloudObservabilityEndpoint( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + + TELEMETRY_GOOGLEAPIS_COM_443 = "telemetry.googleapis.com:443" + + +class CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + + # Auto AUTO = "auto" - # manual - MANUAL = "manual" - # Secret Key pair + # Secret SECRET = "secret" -class CreateOutputOutputGoogleCloudStorageTypedDict(TypedDict): +class CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputGoogleCloudObservabilityPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputGoogleCloudObservabilityTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleCloudStorageType + type: CreateOutputOutputGoogleCloudObservabilityType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - region: str - r"""Region where the bucket is located""" - endpoint: str - r"""Google Cloud Storage service endpoint""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + google_auth_method: ( + CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod + ) + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -7789,151 +7479,92 @@ class CreateOutputOutputGoogleCloudStorageTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[ - CreateOutputOutputGoogleCloudStorageAuthenticationMethod - ] - r"""Authentication method""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsArchiveColdline] - r"""Storage class to select for uploaded objects""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + protocol: NotRequired[CreateOutputOutputGoogleCloudObservabilityProtocol] + r"""Discriminator value.""" + otlp_version: NotRequired[CreateOutputOutputGoogleCloudObservabilityOtlpVersion] + r"""Discriminator value.""" + endpoint: NotRequired[CreateOutputOutputGoogleCloudObservabilityEndpoint] + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" + max_payload_events: NotRequired[float] + r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - aws_api_key: NotRequired[str] - r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - aws_secret_key: NotRequired[str] - r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + CreateOutputOutputGoogleCloudObservabilityPqControlsTypedDict + ] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" -class CreateOutputOutputGoogleCloudStorage(BaseModel): +class CreateOutputOutputGoogleCloudObservability(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleCloudStorageType + type: CreateOutputOutputGoogleCloudObservabilityType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - - region: str - r"""Region where the bucket is located""" - - endpoint: str - r"""Google Cloud Storage service endpoint""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + google_auth_method: Annotated[ + CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod, + pydantic.Field(alias="googleAuthMethod"), + ] + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -7949,397 +7580,243 @@ class CreateOutputOutputGoogleCloudStorage(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[CreateOutputOutputGoogleCloudStorageAuthenticationMethod], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""Authentication method""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") - ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + protocol: Optional[CreateOutputOutputGoogleCloudObservabilityProtocol] = None + r"""Discriminator value.""" - object_acl: Annotated[ - Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], - pydantic.Field(alias="objectACL"), + otlp_version: Annotated[ + Optional[CreateOutputOutputGoogleCloudObservabilityOtlpVersion], + pydantic.Field(alias="otlpVersion"), ] = None - r"""Object ACL to assign to uploaded objects""" + r"""Discriminator value.""" - storage_class: Annotated[ - Optional[StorageClassOptionsArchiveColdline], - pydantic.Field(alias="storageClass"), - ] = None - r"""Storage class to select for uploaded objects""" + endpoint: Optional[CreateOutputOutputGoogleCloudObservabilityEndpoint] = None + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""Add the Output ID value to staging location""" + r"""Batch event data upon dynamic metadata (whether presented or not)""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Buffer size used to write to a file""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""How often the sender should ping the peer to keep the connection open""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Determines which data types are supported and how they are represented""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + r"""Codec to use to compress the persisted data""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + pq_controls: Annotated[ + Optional[CreateOutputOutputGoogleCloudObservabilityPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""Persistent queue controls.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputGoogleCloudStorageAuthenticationMethod( - value - ) + return models.CreateOutputOutputGoogleCloudObservabilityProtocol(value) except ValueError: return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( + return models.CreateOutputOutputGoogleCloudObservabilityOtlpVersion( value ) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptionsArchiveColdline(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("endpoint") + def serialize_endpoint(self, value): if isinstance(value, str): try: - return models.DataFormatOptions(value) + return models.CreateOutputOutputGoogleCloudObservabilityEndpoint(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.CreateOutputOutputGoogleCloudObservabilityGoogleAuthenticationMethod( + value + ) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -8352,68 +7829,41 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "destPath", - "verifyPermissions", - "objectACL", - "storageClass", - "reuseConnections", - "rejectUnauthorized", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", + "protocol", + "otlpVersion", + "endpoint", + "preserveNativeAnyValue", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", + "concurrency", + "maxPayloadSizeKB", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "tls", + "maxPayloadEvents", "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "awsApiKey", - "awsSecretKey", - "awsSecret", + "secret", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_bucket", - "__template_region", - "__template_endpoint", - "__template_destPath", - "__template_objectACL", - "__template_storageClass", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", - "__template_awsApiKey", - "__template_awsSecretKey", ] ) serialized = handler(self) @@ -8430,98 +7880,53 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGoogleChronicleType(str, Enum): +class CreateOutputOutputGoogleCloudLoggingType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CHRONICLE = "google_chronicle" + GOOGLE_CLOUD_LOGGING = "google_cloud_logging" -class CreateOutputAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""API version""" - - # V1 - V1 = "v1" - # V2 - V2 = "v2" - - -class CreateOutputOutputGoogleChronicleAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method""" - - # API key - MANUAL = "manual" - # API key secret - SECRET = "secret" - # Service account credentials - SERVICE_ACCOUNT = "serviceAccount" - # Service account credentials secret - SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" - - -class CreateOutputSendEventsAs(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Send events as""" - - # Unstructured - UNSTRUCTURED = "unstructured" - # UDM - UDM = "udm" - - -class CreateOutputExtraLogTypeTypedDict(TypedDict): - log_type: str - r"""Log Type""" - description: NotRequired[str] - r"""Description""" - - -class CreateOutputExtraLogType(BaseModel): - log_type: Annotated[str, pydantic.Field(alias="logType")] - r"""Log Type""" - - description: Optional[str] = None - r"""Description""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateOutputLogLocationType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Log location type""" - return m + # Project + PROJECT = "project" + # Organization + ORGANIZATION = "organization" + # Billing Account + BILLING_ACCOUNT = "billingAccount" + # Folder + FOLDER = "folder" -class CreateOutputUDMType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" +class CreateOutputPayloadFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format to use when sending payload. Defaults to Text.""" - ENTITIES = "entities" - LOGS = "logs" + # Text + TEXT = "text" + # JSON + JSON = "json" -class CreateOutputOutputGoogleChroniclePqControlsTypedDict(TypedDict): +class CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputGoogleChroniclePqControls(BaseModel): +class CreateOutputOutputGoogleCloudLoggingPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputGoogleChronicleTypedDict(TypedDict): +class CreateOutputOutputGoogleCloudLoggingTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleChronicleType + type: CreateOutputOutputGoogleCloudLoggingType r"""Connector type identifier.""" - log_format_type: CreateOutputSendEventsAs - r"""Send events as""" + log_location_type: CreateOutputLogLocationType + r"""Log location type""" + log_name_expression: str + r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + log_location_expression: str + r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -8530,76 +7935,106 @@ class CreateOutputOutputGoogleChronicleTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - api_version: NotRequired[CreateOutputAPIVersion] - r"""API version""" - authentication_method: NotRequired[ - CreateOutputOutputGoogleChronicleAuthenticationMethod - ] - r"""Authentication method""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] + sanitize_log_names: NotRequired[bool] + r"""Validate and correct log name""" + payload_format: NotRequired[CreateOutputPayloadFormat] + r"""Format to use when sending payload. Defaults to Text.""" + log_labels: NotRequired[List[LogLabelConfOutputGoogleCloudLoggingTypedDict]] + r"""Labels to apply to the log entry""" + resource_type_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" + resource_type_labels: NotRequired[ + List[LogLabelConfOutputGoogleCloudLoggingTypedDict] ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - region: NotRequired[str] - r"""Regional endpoint to send events to""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" + severity_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" + insert_id_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the insert ID field.""" + google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Max number of events to include in the request body. Default is 0 (unlimited).""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" + throttle_rate_req_per_sec: NotRequired[int] + r"""Maximum number of requests to limit to per second.""" + request_method_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + request_url_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + request_size_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + status_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + response_size_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + user_agent_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + remote_ip_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + server_ip_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + referer_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + latency_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_lookup_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_hit_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_validated_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_fill_bytes_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + protocol_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + id_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + producer_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + first_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + last_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + file_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + line_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + function_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + uid_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + index_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + total_splits_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + trace_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + span_id_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + trace_sampled_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" total_memory_limit_kb: NotRequired[float] r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - extra_log_types: NotRequired[List[CreateOutputExtraLogTypeTypedDict]] - r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" - log_type: NotRequired[str] - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" - log_text_field: NotRequired[str] - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" - customer_id: NotRequired[str] - r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" - namespace: NotRequired[str] - r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" - custom_labels: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""Custom labels to be added to every batch""" - udm_type: NotRequired[CreateOutputUDMType] - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" - api_key: NotRequired[str] - r"""Organization's API key in Google SecOps""" - api_key_secret: NotRequired[str] - r"""Select or create a stored text secret""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - service_account_credentials_secret: NotRequired[str] - r"""Select or create a stored text secret""" + payload_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -8622,33 +8057,55 @@ class CreateOutputOutputGoogleChronicleTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputGoogleChroniclePqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputGoogleCloudLoggingPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_api_version: NotRequired[str] - r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] + template_log_location_type: NotRequired[str] + r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" + template_log_name_expression: NotRequired[str] + r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" + template_payload_format: NotRequired[str] + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + template_resource_type_expression: NotRequired[str] + r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" + template_severity_expression: NotRequired[str] + r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" + template_insert_id_expression: NotRequired[str] + r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" + template_trace_expression: NotRequired[str] + r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" + template_span_id_expression: NotRequired[str] + r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" + template_trace_sampled_expression: NotRequired[str] + r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" + template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_customer_id: NotRequired[str] - r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + template_log_location_expression: NotRequired[str] + r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" + template_payload_expression: NotRequired[str] + r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" -class CreateOutputOutputGoogleChronicle(BaseModel): +class CreateOutputOutputGoogleCloudLogging(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleChronicleType + type: CreateOutputOutputGoogleCloudLoggingType r"""Connector type identifier.""" - log_format_type: Annotated[ - CreateOutputSendEventsAs, pydantic.Field(alias="logFormatType") + log_location_type: Annotated[ + CreateOutputLogLocationType, pydantic.Field(alias="logLocationType") ] - r"""Send events as""" + r"""Log location type""" + + log_name_expression: Annotated[str, pydantic.Field(alias="logNameExpression")] + r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + + log_location_expression: Annotated[ + str, pydantic.Field(alias="logLocationExpression") + ] + r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -8664,162 +8121,251 @@ class CreateOutputOutputGoogleChronicle(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - api_version: Annotated[ - Optional[CreateOutputAPIVersion], pydantic.Field(alias="apiVersion") + sanitize_log_names: Annotated[ + Optional[bool], pydantic.Field(alias="sanitizeLogNames") ] = None - r"""API version""" + r"""Validate and correct log name""" - authentication_method: Annotated[ - Optional[CreateOutputOutputGoogleChronicleAuthenticationMethod], - pydantic.Field(alias="authenticationMethod"), + payload_format: Annotated[ + Optional[CreateOutputPayloadFormat], pydantic.Field(alias="payloadFormat") ] = None - r"""Authentication method""" + r"""Format to use when sending payload. Defaults to Text.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + log_labels: Annotated[ + Optional[List[LogLabelConfOutputGoogleCloudLogging]], + pydantic.Field(alias="logLabels"), ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Labels to apply to the log entry""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + resource_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="resourceTypeExpression") ] = None + r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + resource_type_labels: Annotated[ + Optional[List[LogLabelConfOutputGoogleCloudLogging]], + pydantic.Field(alias="resourceTypeLabels"), ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" - region: Optional[str] = None - r"""Regional endpoint to send events to""" + severity_expression: Annotated[ + Optional[str], pydantic.Field(alias="severityExpression") + ] = None + r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + insert_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="insertIdExpression") + ] = None + r"""JavaScript expression to compute the value of the insert ID field.""" + + google_auth_method: Annotated[ + Optional[GoogleAuthenticationMethodOptions], + pydantic.Field(alias="googleAuthMethod"), + ] = None + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + secret: Optional[str] = None + r"""Select or create a stored text secret""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Max number of events to include in the request body. Default is 0 (unlimited).""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + throttle_rate_req_per_sec: Annotated[ + Optional[int], pydantic.Field(alias="throttleRateReqPerSec") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of requests to limit to per second.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + request_method_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestMethodExpression") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + request_url_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestUrlExpression") ] = None - r"""Headers to add to all events""" + r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + request_size_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestSizeExpression") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + status_expression: Annotated[ + Optional[str], pydantic.Field(alias="statusExpression") ] = None - r"""List of headers that are safe to log in plain text""" + r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + response_size_expression: Annotated[ + Optional[str], pydantic.Field(alias="responseSizeExpression") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" + r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + user_agent_expression: Annotated[ + Optional[str], pydantic.Field(alias="userAgentExpression") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + remote_ip_expression: Annotated[ + Optional[str], pydantic.Field(alias="remoteIpExpression") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - extra_log_types: Annotated[ - Optional[List[CreateOutputExtraLogType]], pydantic.Field(alias="extraLogTypes") + server_ip_expression: Annotated[ + Optional[str], pydantic.Field(alias="serverIpExpression") ] = None - r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + referer_expression: Annotated[ + Optional[str], pydantic.Field(alias="refererExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( - None - ) - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + latency_expression: Annotated[ + Optional[str], pydantic.Field(alias="latencyExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - customer_id: Annotated[Optional[str], pydantic.Field(alias="customerId")] = None - r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + cache_lookup_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheLookupExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - namespace: Optional[str] = None - r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + cache_hit_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheHitExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - custom_labels: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="customLabels"), + cache_validated_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheValidatedExpression") ] = None - r"""Custom labels to be added to every batch""" + r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - udm_type: Annotated[ - Optional[CreateOutputUDMType], pydantic.Field(alias="udmType") + cache_fill_bytes_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheFillBytesExpression") ] = None - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""Organization's API key in Google SecOps""" + protocol_expression: Annotated[ + Optional[str], pydantic.Field(alias="protocolExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - api_key_secret: Annotated[Optional[str], pydantic.Field(alias="apiKeySecret")] = ( - None - ) - r"""Select or create a stored text secret""" + id_expression: Annotated[Optional[str], pydantic.Field(alias="idExpression")] = None + r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + producer_expression: Annotated[ + Optional[str], pydantic.Field(alias="producerExpression") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - service_account_credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") + first_expression: Annotated[ + Optional[str], pydantic.Field(alias="firstExpression") ] = None - r"""Select or create a stored text secret""" + r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + last_expression: Annotated[ + Optional[str], pydantic.Field(alias="lastExpression") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + file_expression: Annotated[ + Optional[str], pydantic.Field(alias="fileExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + + line_expression: Annotated[ + Optional[str], pydantic.Field(alias="lineExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + + function_expression: Annotated[ + Optional[str], pydantic.Field(alias="functionExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + + uid_expression: Annotated[Optional[str], pydantic.Field(alias="uidExpression")] = ( + None + ) + r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + + index_expression: Annotated[ + Optional[str], pydantic.Field(alias="indexExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + + total_splits_expression: Annotated[ + Optional[str], pydantic.Field(alias="totalSplitsExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + + trace_expression: Annotated[ + Optional[str], pydantic.Field(alias="traceExpression") + ] = None + r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + + span_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="spanIdExpression") + ] = None + r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + + trace_sampled_expression: Annotated[ + Optional[str], pydantic.Field(alias="traceSampledExpression") + ] = None + r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="payloadExpression") + ] = None + r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" @@ -8863,7 +8409,7 @@ class CreateOutputOutputGoogleChronicle(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputGoogleChroniclePqControls], + Optional[CreateOutputOutputGoogleCloudLoggingPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -8873,65 +8419,89 @@ class CreateOutputOutputGoogleChronicle(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_api_version: Annotated[ - Optional[str], pydantic.Field(alias="__template_apiVersion") + template_log_location_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLocationType") ] = None - r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" + r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_log_name_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_logNameExpression") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_payload_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadFormat") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + + template_resource_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_resourceTypeExpression") + ] = None + r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" + + template_severity_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_severityExpression") + ] = None + r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" + + template_insert_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_insertIdExpression") + ] = None + r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" + + template_trace_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_traceExpression") + ] = None + r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" + + template_span_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_spanIdExpression") + ] = None + r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" + + template_trace_sampled_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_traceSampledExpression") + ] = None + r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_customer_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_customerId") + template_log_location_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLocationExpression") ] = None - r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - @field_serializer("api_version") - def serialize_api_version(self, value): - if isinstance(value, str): - try: - return models.CreateOutputAPIVersion(value) - except ValueError: - return value - return value + template_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadExpression") + ] = None + r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" - @field_serializer("authentication_method") - def serialize_authentication_method(self, value): + @field_serializer("log_location_type") + def serialize_log_location_type(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputGoogleChronicleAuthenticationMethod( - value - ) + return models.CreateOutputLogLocationType(value) except ValueError: return value return value - @field_serializer("log_format_type") - def serialize_log_format_type(self, value): + @field_serializer("payload_format") + def serialize_payload_format(self, value): if isinstance(value, str): try: - return models.CreateOutputSendEventsAs(value) + return models.CreateOutputPayloadFormat(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.GoogleAuthenticationMethodOptions(value) except ValueError: return value return value @@ -8945,15 +8515,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("udm_type") - def serialize_udm_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputUDMType(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -8989,38 +8550,55 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "apiVersion", - "authenticationMethod", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "region", - "concurrency", + "sanitizeLogNames", + "payloadFormat", + "logLabels", + "resourceTypeExpression", + "resourceTypeLabels", + "severityExpression", + "insertIdExpression", + "googleAuthMethod", + "serviceAccountCredentials", + "secret", "maxPayloadSizeKB", "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "useRoundRobinDns", + "concurrency", + "connectionTimeout", + "timeoutSec", + "throttleRateReqPerSec", + "requestMethodExpression", + "requestUrlExpression", + "requestSizeExpression", + "statusExpression", + "responseSizeExpression", + "userAgentExpression", + "remoteIpExpression", + "serverIpExpression", + "refererExpression", + "latencyExpression", + "cacheLookupExpression", + "cacheHitExpression", + "cacheValidatedExpression", + "cacheFillBytesExpression", + "protocolExpression", + "idExpression", + "producerExpression", + "firstExpression", + "lastExpression", + "fileExpression", + "lineExpression", + "functionExpression", + "uidExpression", + "indexExpression", + "totalSplitsExpression", + "traceExpression", + "spanIdExpression", + "traceSampledExpression", "onBackpressure", "totalMemoryLimitKB", "description", - "extraLogTypes", - "logType", - "logTextField", - "customerId", - "namespace", - "customLabels", - "udmType", - "apiKey", - "apiKeySecret", - "serviceAccountCredentials", - "serviceAccountCredentialsSecret", + "payloadExpression", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9034,11 +8612,18 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_apiVersion", - "__template_region", - "__template_failedRequestLoggingMode", + "__template_logLocationType", + "__template_logNameExpression", + "__template_payloadFormat", + "__template_resourceTypeExpression", + "__template_severityExpression", + "__template_insertIdExpression", + "__template_traceExpression", + "__template_spanIdExpression", + "__template_traceSampledExpression", "__template_onBackpressure", - "__template_customerId", + "__template_logLocationExpression", + "__template_payloadExpression", ] ) serialized = handler(self) @@ -9055,44 +8640,38 @@ def serialize_model(self, handler): return m -class CreateOutputOutputGoogleBigqueryType(str, Enum): +class CreateOutputOutputGoogleCloudStorageType(str, Enum): r"""Connector type identifier.""" - GOOGLE_BIGQUERY = "google_bigquery" + GOOGLE_CLOUD_STORAGE = "google_cloud_storage" -class CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod( +class CreateOutputOutputGoogleCloudStorageAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + r"""Authentication method""" - # Auto + # auto AUTO = "auto" - # Secret + # manual + MANUAL = "manual" + # Secret Key pair SECRET = "secret" -class CreateOutputOutputGoogleBigqueryPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputGoogleBigqueryPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputGoogleBigqueryTypedDict(TypedDict): +class CreateOutputOutputGoogleCloudStorageTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleBigqueryType + type: CreateOutputOutputGoogleCloudStorageType r"""Connector type identifier.""" - project_id: str - r"""Google Cloud project ID that contains the BigQuery dataset""" - dataset_id: str - r"""BigQuery dataset ID""" - table_id: str - r"""BigQuery table ID""" - google_auth_method: CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + bucket: str + r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" + region: str + r"""Region where the bucket is located""" + endpoint: str + r"""Google Cloud Storage service endpoint""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9101,81 +8680,151 @@ class CreateOutputOutputGoogleBigqueryTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - timestamp_column: NotRequired[str] - r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - flush_period: NotRequired[float] - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied""" - max_send_retries: NotRequired[float] - r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + aws_authentication_method: NotRequired[ + CreateOutputOutputGoogleCloudStorageAuthenticationMethod + ] + r"""Authentication method""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsArchiveColdline] + r"""Storage class to select for uploaded objects""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputGoogleBigqueryPqControlsTypedDict] - r"""Persistent queue controls.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_api_key: NotRequired[str] + r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + aws_secret_key: NotRequired[str] + r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_project_id: NotRequired[str] - r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" - template_dataset_id: NotRequired[str] - r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" - template_table_id: NotRequired[str] - r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" -class CreateOutputOutputGoogleBigquery(BaseModel): +class CreateOutputOutputGoogleCloudStorage(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputGoogleBigqueryType + type: CreateOutputOutputGoogleCloudStorageType r"""Connector type identifier.""" - project_id: Annotated[str, pydantic.Field(alias="projectId")] - r"""Google Cloud project ID that contains the BigQuery dataset""" + bucket: str + r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - dataset_id: Annotated[str, pydantic.Field(alias="datasetId")] - r"""BigQuery dataset ID""" + region: str + r"""Region where the bucket is located""" - table_id: Annotated[str, pydantic.Field(alias="tableId")] - r"""BigQuery table ID""" + endpoint: str + r"""Google Cloud Storage service endpoint""" - google_auth_method: Annotated[ - CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod, - pydantic.Field(alias="googleAuthMethod"), - ] - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9191,170 +8840,397 @@ class CreateOutputOutputGoogleBigquery(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - timestamp_column: Annotated[ - Optional[str], pydantic.Field(alias="timestampColumn") + aws_authentication_method: Annotated[ + Optional[CreateOutputOutputGoogleCloudStorageAuthenticationMethod], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - - secret: Optional[str] = None - r"""Select or create a stored text secret""" - - flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + r"""Authentication method""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + object_acl: Annotated[ + Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], + pydantic.Field(alias="objectACL"), ] = None - r"""The maximum number of in-progress API requests before backpressure is applied""" + r"""Object ACL to assign to uploaded objects""" - max_send_retries: Annotated[ - Optional[float], pydantic.Field(alias="maxSendRetries") + storage_class: Annotated[ + Optional[StorageClassOptionsArchiveColdline], + pydantic.Field(alias="storageClass"), ] = None - r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" + r"""Storage class to select for uploaded objects""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + description: Optional[str] = None r"""Optional description for this configuration.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Compression level to apply before moving files to final destination""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Determines which data types are supported and how they are represented""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""Codec to use to compress the persisted data""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_controls: Annotated[ - Optional[CreateOutputOutputGoogleBigqueryPqControls], - pydantic.Field(alias="pqControls"), + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Persistent queue controls.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" + + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") + ] = None + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_project_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_projectId") + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") ] = None - r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_dataset_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_datasetId") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_table_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tableId") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): - if isinstance(value, str): - try: - return ( - models.CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod( - value - ) - ) - except ValueError: - return value - return value + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.CreateOutputOutputGoogleCloudStorageAuthenticationMethod( + value + ) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( + value + ) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.StorageClassOptionsArchiveColdline(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.DataFormatOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptionsBlockDrop(value) + except ValueError: + return value + return value + + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): + if isinstance(value, str): + try: + return models.DiskSpaceProtectionOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -9367,32 +9243,68 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "timestampColumn", - "secret", - "flushPeriod", - "maxQueueSize", - "maxRecordSizeKB", - "maxInProgress", - "maxSendRetries", + "awsAuthenticationMethod", + "destPath", + "verifyPermissions", + "objectACL", + "storageClass", + "reuseConnections", + "rejectUnauthorized", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", "description", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", + "awsApiKey", + "awsSecretKey", + "awsSecret", "__template_streamtags", - "__template_projectId", - "__template_datasetId", - "__template_tableId", + "__template_bucket", + "__template_region", + "__template_endpoint", + "__template_destPath", + "__template_objectACL", + "__template_storageClass", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_compress", + "__template_parquetSchema", + "__template_awsApiKey", + "__template_awsSecretKey", ] ) serialized = handler(self) @@ -9409,71 +9321,176 @@ def serialize_model(self, handler): return m -class CreateOutputOutputAzureEventhubType(str, Enum): +class CreateOutputOutputGoogleChronicleType(str, Enum): r"""Connector type identifier.""" - AZURE_EVENTHUB = "azure_eventhub" + GOOGLE_CHRONICLE = "google_chronicle" -class CreateOutputOutputAzureEventhubPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""API version""" + # V1 + V1 = "v1" + # V2 + V2 = "v2" -class CreateOutputOutputAzureEventhubPqControls(BaseModel): - r"""Persistent queue controls.""" +class CreateOutputOutputGoogleChronicleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method""" -class CreateOutputOutputAzureEventhubTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputAzureEventhubType - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - topic: str - r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - ack: NotRequired[AcknowledgmentsOptions] - r"""Control the number of required acknowledgments""" - format_: NotRequired[RecordDataFormatOptions] - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - flush_event_count: NotRequired[float] - r"""Maximum number of events in a batch before forcing a flush""" + # API key + MANUAL = "manual" + # API key secret + SECRET = "secret" + # Service account credentials + SERVICE_ACCOUNT = "serviceAccount" + # Service account credentials secret + SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" + + +class CreateOutputSendEventsAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Send events as""" + + # Unstructured + UNSTRUCTURED = "unstructured" + # UDM + UDM = "udm" + + +class CreateOutputExtraLogTypeTypedDict(TypedDict): + log_type: str + r"""Log Type""" + description: NotRequired[str] + r"""Description""" + + +class CreateOutputExtraLogType(BaseModel): + log_type: Annotated[str, pydantic.Field(alias="logType")] + r"""Log Type""" + + description: Optional[str] = None + r"""Description""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputUDMType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + + ENTITIES = "entities" + LOGS = "logs" + + +class CreateOutputOutputGoogleChroniclePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputGoogleChroniclePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputGoogleChronicleTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputGoogleChronicleType + r"""Connector type identifier.""" + log_format_type: CreateOutputSendEventsAs + r"""Send events as""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + api_version: NotRequired[CreateOutputAPIVersion] + r"""API version""" + authentication_method: NotRequired[ + CreateOutputOutputGoogleChronicleAuthenticationMethod + ] + r"""Authentication method""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + region: NotRequired[str] + r"""Regional endpoint to send events to""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeUseTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeTypedDict] - r"""TLS settings (client side)""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + extra_log_types: NotRequired[List[CreateOutputExtraLogTypeTypedDict]] + r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + log_type: NotRequired[str] + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + log_text_field: NotRequired[str] + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + customer_id: NotRequired[str] + r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + namespace: NotRequired[str] + r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + custom_labels: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""Custom labels to be added to every batch""" + udm_type: NotRequired[CreateOutputUDMType] + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + api_key: NotRequired[str] + r"""Organization's API key in Google SecOps""" + api_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + service_account_credentials_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9496,32 +9513,33 @@ class CreateOutputOutputAzureEventhubTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputAzureEventhubPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputGoogleChroniclePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_api_version: NotRequired[str] + r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_customer_id: NotRequired[str] + r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" -class CreateOutputOutputAzureEventhub(BaseModel): +class CreateOutputOutputGoogleChronicle(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputAzureEventhubType + type: CreateOutputOutputGoogleChronicleType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - - topic: str - r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" + log_format_type: Annotated[ + CreateOutputSendEventsAs, pydantic.Field(alias="logFormatType") + ] + r"""Send events as""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9537,77 +9555,155 @@ class CreateOutputOutputAzureEventhub(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - ack: Optional[AcknowledgmentsOptions] = None - r"""Control the number of required acknowledgments""" - - format_: Annotated[ - Optional[RecordDataFormatOptions], pydantic.Field(alias="format") + api_version: Annotated[ + Optional[CreateOutputAPIVersion], pydantic.Field(alias="apiVersion") ] = None - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" + r"""API version""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + authentication_method: Annotated[ + Optional[CreateOutputOutputGoogleChronicleAuthenticationMethod], + pydantic.Field(alias="authenticationMethod"), ] = None - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" + r"""Authentication method""" - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Maximum number of events in a batch before forcing a flush""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" + region: Optional[str] = None + r"""Regional endpoint to send events to""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - sasl: Optional[AuthenticationTypeUse] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - tls: Optional[TLSSettingsClientSideType] = None - r"""TLS settings (client side)""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" + extra_log_types: Annotated[ + Optional[List[CreateOutputExtraLogType]], pydantic.Field(alias="extraLogTypes") + ] = None + r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + + log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + + log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( + None + ) + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + + customer_id: Annotated[Optional[str], pydantic.Field(alias="customerId")] = None + r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + + namespace: Optional[str] = None + r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + + custom_labels: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="customLabels"), + ] = None + r"""Custom labels to be added to every batch""" + + udm_type: Annotated[ + Optional[CreateOutputUDMType], pydantic.Field(alias="udmType") + ] = None + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""Organization's API key in Google SecOps""" + + api_key_secret: Annotated[Optional[str], pydantic.Field(alias="apiKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + service_account_credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") + ] = None + r"""Select or create a stored text secret""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -9658,7 +9754,7 @@ class CreateOutputOutputAzureEventhub(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputAzureEventhubPqControls], + Optional[CreateOutputOutputGoogleChroniclePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -9668,40 +9764,65 @@ class CreateOutputOutputAzureEventhub(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") + template_api_version: Annotated[ + Optional[str], pydantic.Field(alias="__template_apiVersion") ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("ack") - def serialize_ack(self, value): + template_customer_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_customerId") + ] = None + r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + + @field_serializer("api_version") + def serialize_api_version(self, value): if isinstance(value, str): try: - return models.AcknowledgmentsOptions(value) + return models.CreateOutputAPIVersion(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("authentication_method") + def serialize_authentication_method(self, value): if isinstance(value, str): try: - return models.RecordDataFormatOptions(value) + return models.CreateOutputOutputGoogleChronicleAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_format_type") + def serialize_log_format_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSendEventsAs(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -9715,6 +9836,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("udm_type") + def serialize_udm_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputUDMType(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -9750,23 +9880,38 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "ack", - "format", - "maxRecordSizeKB", - "flushEventCount", + "apiVersion", + "authenticationMethod", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "region", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "tls", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "useRoundRobinDns", "onBackpressure", + "totalMemoryLimitKB", "description", + "extraLogTypes", + "logType", + "logTextField", + "customerId", + "namespace", + "customLabels", + "udmType", + "apiKey", + "apiKeySecret", + "serviceAccountCredentials", + "serviceAccountCredentialsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9780,10 +9925,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_brokers", - "__template_topic", - "__template_format", + "__template_apiVersion", + "__template_region", + "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_customerId", ] ) serialized = handler(self) @@ -9800,27 +9946,44 @@ def serialize_model(self, handler): return m -class CreateOutputOutputHoneycombType(str, Enum): +class CreateOutputOutputGoogleBigqueryType(str, Enum): r"""Connector type identifier.""" - HONEYCOMB = "honeycomb" + GOOGLE_BIGQUERY = "google_bigquery" -class CreateOutputOutputHoneycombPqControlsTypedDict(TypedDict): +class CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + + # Auto + AUTO = "auto" + # Secret + SECRET = "secret" + + +class CreateOutputOutputGoogleBigqueryPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputHoneycombPqControls(BaseModel): +class CreateOutputOutputGoogleBigqueryPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputHoneycombTypedDict(TypedDict): +class CreateOutputOutputGoogleBigqueryTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputHoneycombType + type: CreateOutputOutputGoogleBigqueryType r"""Connector type identifier.""" - dataset: str - r"""Name of the dataset to send events to – e.g., observability""" + project_id: str + r"""Google Cloud project ID that contains the BigQuery dataset""" + dataset_id: str + r"""BigQuery dataset ID""" + table_id: str + r"""BigQuery table ID""" + google_auth_method: CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9829,44 +9992,22 @@ class CreateOutputOutputHoneycombTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + timestamp_column: NotRequired[str] + r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + flush_period: NotRequired[float] + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied""" + max_send_retries: NotRequired[float] + r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] @@ -9891,29 +10032,41 @@ class CreateOutputOutputHoneycombTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputHoneycombPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputGoogleBigqueryPqControlsTypedDict] r"""Persistent queue controls.""" - team: NotRequired[str] - r"""Team API key where the dataset belongs""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_project_id: NotRequired[str] + r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + template_dataset_id: NotRequired[str] + r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + template_table_id: NotRequired[str] + r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputHoneycomb(BaseModel): +class CreateOutputOutputGoogleBigquery(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputHoneycombType + type: CreateOutputOutputGoogleBigqueryType r"""Connector type identifier.""" - dataset: str - r"""Name of the dataset to send events to – e.g., observability""" + project_id: Annotated[str, pydantic.Field(alias="projectId")] + r"""Google Cloud project ID that contains the BigQuery dataset""" + + dataset_id: Annotated[str, pydantic.Field(alias="datasetId")] + r"""BigQuery dataset ID""" + + table_id: Annotated[str, pydantic.Field(alias="tableId")] + r"""BigQuery table ID""" + + google_auth_method: Annotated[ + CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod, + pydantic.Field(alias="googleAuthMethod"), + ] + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9929,90 +10082,42 @@ class CreateOutputOutputHoneycomb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + timestamp_column: Annotated[ + Optional[str], pydantic.Field(alias="timestampColumn") ] = None - r"""Headers to add to all events""" + r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") ] = None + r"""The maximum number of in-progress API requests before backpressure is applied""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_send_retries: Annotated[ + Optional[float], pydantic.Field(alias="maxSendRetries") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -10066,37 +10171,45 @@ class CreateOutputOutputHoneycomb(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputHoneycombPqControls], + Optional[CreateOutputOutputGoogleBigqueryPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - team: Optional[str] = None - r"""Team API key where the dataset belongs""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_project_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_projectId") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + + template_dataset_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_datasetId") + ] = None + r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + + template_table_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tableId") + ] = None + r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return ( + models.CreateOutputOutputGoogleBigqueryGoogleAuthenticationMethod( + value + ) + ) except ValueError: return value return value @@ -10110,15 +10223,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -10154,23 +10258,14 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "timestampColumn", + "secret", + "flushPeriod", + "maxQueueSize", + "maxRecordSizeKB", + "maxInProgress", + "maxSendRetries", "onBackpressure", - "authType", "description", "pqStrictOrdering", "pqRatePerSec", @@ -10184,10 +10279,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "team", - "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_projectId", + "__template_datasetId", + "__template_tableId", "__template_onBackpressure", ] ) @@ -10205,32 +10300,29 @@ def serialize_model(self, handler): return m -class CreateOutputCompression(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Compression type to use for records""" +class CreateOutputOutputAzureEventhubType(str, Enum): + r"""Connector type identifier.""" - # None - NONE = "none" - # Gzip - GZIP = "gzip" + AZURE_EVENTHUB = "azure_eventhub" -class CreateOutputOutputKinesisPqControlsTypedDict(TypedDict): +class CreateOutputOutputAzureEventhubPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputKinesisPqControls(BaseModel): +class CreateOutputOutputAzureEventhubPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputKinesisTypedDict(TypedDict): +class CreateOutputOutputAzureEventhubTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsKinesis + type: CreateOutputOutputAzureEventhubType r"""Connector type identifier.""" - stream_name: str - r"""Kinesis stream name to send events to.""" - region: str - r"""Region where the Kinesis stream is located""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + topic: str + r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10239,46 +10331,40 @@ class CreateOutputOutputKinesisTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Kinesis stream""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing put requests before blocking.""" + ack: NotRequired[AcknowledgmentsOptions] + r"""Control the number of required acknowledgments""" + format_: NotRequired[RecordDataFormatOptions] + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" + flush_event_count: NotRequired[float] + r"""Maximum number of events in a batch before forcing a flush""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - compression: NotRequired[CreateOutputCompression] - r"""Compression type to use for records""" - use_list_shards: NotRequired[bool] - r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" - as_ndjson: NotRequired[bool] - r"""Batch events into a single record as NDJSON""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeUseTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeTypedDict] + r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - max_events_per_flush: NotRequired[float] - r"""Maximum number of records to send in a single request""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -10301,40 +10387,32 @@ class CreateOutputOutputKinesisTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputKinesisPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputAzureEventhubPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputKinesis(BaseModel): +class CreateOutputOutputAzureEventhub(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsKinesis + type: CreateOutputOutputAzureEventhubType r"""Connector type identifier.""" - stream_name: Annotated[str, pydantic.Field(alias="streamName")] - r"""Kinesis stream name to send events to.""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - region: str - r"""Region where the Kinesis stream is located""" + topic: str + r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -10350,73 +10428,68 @@ class CreateOutputOutputKinesis(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + ack: Optional[AcknowledgmentsOptions] = None + r"""Control the number of required acknowledgments""" + + format_: Annotated[ + Optional[RecordDataFormatOptions], pydantic.Field(alias="format") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") + ] = None + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - endpoint: Optional[str] = None - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") + ] = None + r"""Maximum number of events in a batch before forcing a flush""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Maximum time to wait for a connection to complete successfully""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Use Assume Role credentials to access Kinesis stream""" + r"""Maximum time to wait for Kafka to respond to a request""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing put requests before blocking.""" + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None - r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" + r"""Maximum time to wait for Kafka to respond to an authentication request""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - - compression: Optional[CreateOutputCompression] = None - r"""Compression type to use for records""" + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - use_list_shards: Annotated[ - Optional[bool], pydantic.Field(alias="useListShards") - ] = None - r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" + sasl: Optional[AuthenticationTypeUse] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - as_ndjson: Annotated[Optional[bool], pydantic.Field(alias="asNdjson")] = None - r"""Batch events into a single record as NDJSON""" + tls: Optional[TLSSettingsClientSideType] = None + r"""TLS settings (client side)""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -10426,17 +10499,6 @@ class CreateOutputOutputKinesis(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - max_events_per_flush: Annotated[ - Optional[float], pydantic.Field(alias="maxEventsPerFlush") - ] = None - r"""Maximum number of records to send in a single request""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -10487,7 +10549,7 @@ class CreateOutputOutputKinesis(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputKinesisPqControls], + Optional[CreateOutputOutputAzureEventhubPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -10497,60 +10559,40 @@ class CreateOutputOutputKinesis(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") - ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.AcknowledgmentsOptions(value) except ValueError: return value return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.CreateOutputCompression(value) + return models.RecordDataFormatOptions(value) except ValueError: return value return value @@ -10599,26 +10641,23 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "concurrency", + "ack", + "format", "maxRecordSizeKB", + "flushEventCount", "flushPeriodSec", - "compression", - "useListShards", - "asNdjson", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", "onBackpressure", "description", - "awsApiKey", - "awsSecret", - "maxEventsPerFlush", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10632,14 +10671,10 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_streamName", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_brokers", + "__template_topic", + "__template_format", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -10656,36 +10691,27 @@ def serialize_model(self, handler): return m -class CreateOutputOutputAzureLogsType(str, Enum): +class CreateOutputOutputHoneycombType(str, Enum): r"""Connector type identifier.""" - AZURE_LOGS = "azure_logs" - - -class CreateOutputOutputAzureLogsAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter workspace ID and workspace key directly, or select a stored secret""" - - MANUAL = "manual" - SECRET = "secret" + HONEYCOMB = "honeycomb" -class CreateOutputOutputAzureLogsPqControlsTypedDict(TypedDict): +class CreateOutputOutputHoneycombPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputAzureLogsPqControls(BaseModel): +class CreateOutputOutputHoneycombPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputAzureLogsTypedDict(TypedDict): +class CreateOutputOutputHoneycombTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputAzureLogsType + type: CreateOutputOutputHoneycombType r"""Connector type identifier.""" - log_type: str - r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + dataset: str + r"""Name of the dataset to send events to – e.g., observability""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10694,8 +10720,6 @@ class CreateOutputOutputAzureLogsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - resource_id: NotRequired[str] - r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -10703,6 +10727,7 @@ class CreateOutputOutputAzureLogsTypedDict(TypedDict): max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -10722,8 +10747,6 @@ class CreateOutputOutputAzureLogsTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - api_url: NotRequired[str] - r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -10733,8 +10756,8 @@ class CreateOutputOutputAzureLogsTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputOutputAzureLogsAuthenticationMethod] - r"""Enter workspace ID and workspace key directly, or select a stored secret""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] @@ -10759,35 +10782,29 @@ class CreateOutputOutputAzureLogsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputAzureLogsPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputHoneycombPqControlsTypedDict] r"""Persistent queue controls.""" - workspace_id: NotRequired[str] - r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" - workspace_key: NotRequired[str] - r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" - keypair_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + team: NotRequired[str] + r"""Team API key where the dataset belongs""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_workspace_id: NotRequired[str] - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_workspace_key: NotRequired[str] - r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" -class CreateOutputOutputAzureLogs(BaseModel): +class CreateOutputOutputHoneycomb(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputAzureLogsType + type: CreateOutputOutputHoneycombType r"""Connector type identifier.""" - log_type: Annotated[str, pydantic.Field(alias="logType")] - r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + dataset: str + r"""Name of the dataset to send events to – e.g., observability""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -10803,9 +10820,6 @@ class CreateOutputOutputAzureLogs(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - resource_id: Annotated[Optional[str], pydantic.Field(alias="resourceId")] = None - r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" - concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -10820,6 +10834,7 @@ class CreateOutputOutputAzureLogs(BaseModel): r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: Optional[bool] = None + r"""Compress the payload body before sending""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -10864,9 +10879,6 @@ class CreateOutputOutputAzureLogs(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - api_url: Annotated[Optional[str], pydantic.Field(alias="apiUrl")] = None - r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -10888,10 +10900,9 @@ class CreateOutputOutputAzureLogs(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[CreateOutputOutputAzureLogsAuthenticationMethod], - pydantic.Field(alias="authType"), + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") ] = None - r"""Enter workspace ID and workspace key directly, or select a stored secret""" + r"""Enter API key directly, or select a stored secret""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -10946,21 +10957,16 @@ class CreateOutputOutputAzureLogs(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputAzureLogsPqControls], + Optional[CreateOutputOutputHoneycombPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None - r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" - - workspace_key: Annotated[Optional[str], pydantic.Field(alias="workspaceKey")] = None - r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" + team: Optional[str] = None + r"""Team API key where the dataset belongs""" - keypair_secret: Annotated[Optional[str], pydantic.Field(alias="keypairSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") @@ -10977,16 +10983,6 @@ class CreateOutputOutputAzureLogs(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_workspace_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceId") - ] = None - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - - template_workspace_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceKey") - ] = None - r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" - @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -11009,7 +11005,7 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputAzureLogsAuthenticationMethod(value) + return models.AuthenticationMethodOptionsAPI(value) except ValueError: return value return value @@ -11049,7 +11045,6 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "resourceId", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -11062,7 +11057,6 @@ def serialize_model(self, handler): "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "apiUrl", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", @@ -11081,14 +11075,11 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "workspaceId", - "workspaceKey", - "keypairSecret", + "team", + "textSecret", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_workspaceId", - "__template_workspaceKey", ] ) serialized = handler(self) @@ -11105,189 +11096,32 @@ def serialize_model(self, handler): return m -class CreateOutputOutputAzureDataExplorerType(str, Enum): - r"""Connector type identifier.""" - - AZURE_DATA_EXPLORER = "azure_data_explorer" - - -class CreateOutputIngestionMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Ingestion mode""" - - # Batching - BATCHING = "batching" - # Streaming - STREAMING = "streaming" - - -class CreateOutputOutputAzureDataExplorerAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""The type of OAuth 2.0 client credentials grant flow to use""" - - # Client secret - CLIENT_SECRET = "clientSecret" - # Client secret (text secret) - CLIENT_TEXT_SECRET = "clientTextSecret" - # Certificate - CERTIFICATE = "certificate" - - -class CreateOutputCertificateTypedDict(TypedDict): - certificate_name: NotRequired[str] - r"""The certificate you registered as credentials for your app in the Azure portal""" - - -class CreateOutputCertificate(BaseModel): - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") - ] = None - r"""The certificate you registered as credentials for your app in the Azure portal""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["certificateName"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputPrefixOptional(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Prefix (optional)""" - - # drop-by - DROP_BY = "dropBy" - # ingest-by - INGEST_BY = "ingestBy" - - -class CreateOutputExtentTagTypedDict(TypedDict): - value: str - r"""Value""" - prefix: NotRequired[CreateOutputPrefixOptional] - r"""Prefix (optional)""" - - -class CreateOutputExtentTag(BaseModel): - value: str - r"""Value""" - - prefix: Optional[CreateOutputPrefixOptional] = None - r"""Prefix (optional)""" - - @field_serializer("prefix") - def serialize_prefix(self, value): - if isinstance(value, str): - try: - return models.CreateOutputPrefixOptional(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["prefix"]) - serialized = handler(self) - m = {} +class CreateOutputCompression(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Compression type to use for records""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + # None + NONE = "none" + # Gzip + GZIP = "gzip" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - return m +class CreateOutputOutputKinesisPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" -class CreateOutputIngestIfNotExistTypedDict(TypedDict): - value: str - r"""Value""" +class CreateOutputOutputKinesisPqControls(BaseModel): + r"""Persistent queue controls.""" -class CreateOutputIngestIfNotExist(BaseModel): - value: str - r"""Value""" - - -class CreateOutputReportLevel(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" - - # FailuresOnly - FAILURES_ONLY = "failuresOnly" - # DoNotReport - DO_NOT_REPORT = "doNotReport" - # FailuresAndSuccesses - FAILURES_AND_SUCCESSES = "failuresAndSuccesses" - - -class CreateOutputReportMethod(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Target of the ingestion status reporting. Defaults to Queue.""" - - # Queue - QUEUE = "queue" - # Table - TABLE = "table" - # QueueAndTable - QUEUE_AND_TABLE = "queueAndTable" - - -class CreateOutputAdditionalPropertyTypedDict(TypedDict): - key: str - r"""Key""" - value: str - r"""Value""" - - -class CreateOutputAdditionalProperty(BaseModel): - key: str - r"""Key""" - - value: str - r"""Value""" - - -class CreateOutputOutputAzureDataExplorerPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputAzureDataExplorerPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputAzureDataExplorerTypedDict(TypedDict): +class CreateOutputOutputKinesisTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputAzureDataExplorerType + type: TypeOptionsKinesis r"""Connector type identifier.""" - cluster_url: str - r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - database: str - r"""Name of the database containing the table where data will be ingested""" - table: str - r"""Name of the table to ingest data into""" - oauth_endpoint: MicrosoftEntraIDAuthenticationEndpointOptionsSasl - r"""Endpoint used to acquire authentication tokens from Azure""" - tenant_id: str - r"""Directory ID (tenant identifier) in Azure Active Directory""" - client_id: str - r"""client_id to pass in the OAuth request parameter""" - scope: str - r"""Scope to pass in the OAuth request parameter""" - oauth_type: CreateOutputOutputAzureDataExplorerAuthenticationMethod - r"""The type of OAuth 2.0 client credentials grant flow to use""" - compress: CompressionOptionsHTTP - r"""Data compression format to apply to HTTP content before it is delivered""" + stream_name: str + r"""Kinesis stream name to send events to.""" + region: str + r"""Region where the Kinesis stream is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -11296,128 +11130,46 @@ class CreateOutputOutputAzureDataExplorerTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - validate_database_settings: NotRequired[bool] - r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" - ingest_mode: NotRequired[CreateOutputIngestionMode] - r"""Ingestion mode""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""The client secret that you generated for your app in the Azure portal""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CreateOutputCertificateTypedDict] - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - is_mapping_obj: NotRequired[bool] - r"""Send a JSON mapping object instead of specifying an existing named data mapping""" - mapping_obj: NotRequired[str] - r"""Enter a JSON object that defines your desired data mapping""" - mapping_ref: NotRequired[str] - r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" - ingest_url: NotRequired[str] - r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - flush_immediately: NotRequired[bool] - r"""Bypass the data management service's aggregation mechanism""" - retain_blob_on_success: NotRequired[bool] - r"""Prevent blob deletion after ingestion is complete""" - extent_tags: NotRequired[List[CreateOutputExtentTagTypedDict]] - r"""Strings or tags associated with the extent (ingested data shard)""" - ingest_if_not_exists: NotRequired[List[CreateOutputIngestIfNotExistTypedDict]] - r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" - report_level: NotRequired[CreateOutputReportLevel] - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" - report_method: NotRequired[CreateOutputReportMethod] - r"""Target of the ingestion status reporting. Defaults to Queue.""" - additional_properties: NotRequired[List[CreateOutputAdditionalPropertyTypedDict]] - r"""Optionally, enter additional configuration properties to send to the ingestion service""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Kinesis stream""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of ongoing put requests before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + compression: NotRequired[CreateOutputCompression] + r"""Compression type to use for records""" + use_list_shards: NotRequired[bool] + r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" + as_ndjson: NotRequired[bool] + r"""Batch events into a single record as NDJSON""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + max_events_per_flush: NotRequired[float] + r"""Maximum number of records to send in a single request""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -11440,81 +11192,40 @@ class CreateOutputOutputAzureDataExplorerTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputAzureDataExplorerPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputKinesisPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_cluster_url: NotRequired[str] - r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_table: NotRequired[str] - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - template_oauth_endpoint: NotRequired[str] - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_scope: NotRequired[str] - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_mapping_ref: NotRequired[str] - r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" - template_ingest_url: NotRequired[str] - r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputOutputAzureDataExplorer(BaseModel): +class CreateOutputOutputKinesis(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputAzureDataExplorerType + type: TypeOptionsKinesis r"""Connector type identifier.""" - cluster_url: Annotated[str, pydantic.Field(alias="clusterUrl")] - r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - - database: str - r"""Name of the database containing the table where data will be ingested""" - - table: str - r"""Name of the table to ingest data into""" - - oauth_endpoint: Annotated[ - MicrosoftEntraIDAuthenticationEndpointOptionsSasl, - pydantic.Field(alias="oauthEndpoint"), - ] - r"""Endpoint used to acquire authentication tokens from Azure""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Directory ID (tenant identifier) in Azure Active Directory""" - - client_id: Annotated[str, pydantic.Field(alias="clientId")] - r"""client_id to pass in the OAuth request parameter""" - - scope: str - r"""Scope to pass in the OAuth request parameter""" - - oauth_type: Annotated[ - CreateOutputOutputAzureDataExplorerAuthenticationMethod, - pydantic.Field(alias="oauthType"), - ] - r"""The type of OAuth 2.0 client credentials grant flow to use""" + stream_name: Annotated[str, pydantic.Field(alias="streamName")] + r"""Kinesis stream name to send events to.""" - compress: CompressionOptionsHTTP - r"""Data compression format to apply to HTTP content before it is delivered""" + region: str + r"""Region where the Kinesis stream is located""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -11530,304 +11241,569 @@ class CreateOutputOutputAzureDataExplorer(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - validate_database_settings: Annotated[ - Optional[bool], pydantic.Field(alias="validateDatabaseSettings") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - ingest_mode: Annotated[ - Optional[CreateOutputIngestionMode], pydantic.Field(alias="ingestMode") - ] = None - r"""Ingestion mode""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + endpoint: Optional[str] = None + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""The client secret that you generated for your app in the Azure portal""" + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - certificate: Optional[CreateOutputCertificate] = None + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Kinesis stream""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Format of the output data""" + r"""Amazon Resource Name (ARN) of the role to assume""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""External ID to use when assuming role""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing put requests before blocking.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Determines which data types are supported and how they are represented""" + r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + compression: Optional[CreateOutputCompression] = None + r"""Compression type to use for records""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + use_list_shards: Annotated[ + Optional[bool], pydantic.Field(alias="useListShards") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + as_ndjson: Annotated[Optional[bool], pydantic.Field(alias="asNdjson")] = None + r"""Batch events into a single record as NDJSON""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + r"""How to handle events when all receivers are exerting backpressure""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + max_events_per_flush: Annotated[ + Optional[float], pydantic.Field(alias="maxEventsPerFlush") ] = None - r"""Remove empty staging directories after moving files""" + r"""Maximum number of records to send in a single request""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - is_mapping_obj: Annotated[Optional[bool], pydantic.Field(alias="isMappingObj")] = ( - None - ) - r"""Send a JSON mapping object instead of specifying an existing named data mapping""" + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - mapping_obj: Annotated[Optional[str], pydantic.Field(alias="mappingObj")] = None - r"""Enter a JSON object that defines your desired data mapping""" + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - mapping_ref: Annotated[Optional[str], pydantic.Field(alias="mappingRef")] = None - r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - ingest_url: Annotated[Optional[str], pydantic.Field(alias="ingestUrl")] = None - r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + r"""Codec to use to compress the persisted data""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + pq_controls: Annotated[ + Optional[CreateOutputOutputKinesisPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Persistent queue controls.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") ] = None - r"""Maximum number of parts to upload in parallel per file""" + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Add the Output ID value to staging location""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - flush_immediately: Annotated[ - Optional[bool], pydantic.Field(alias="flushImmediately") + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") ] = None - r"""Bypass the data management service's aggregation mechanism""" + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - retain_blob_on_success: Annotated[ - Optional[bool], pydantic.Field(alias="retainBlobOnSuccess") + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") ] = None - r"""Prevent blob deletion after ingestion is complete""" + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - extent_tags: Annotated[ - Optional[List[CreateOutputExtentTag]], pydantic.Field(alias="extentTags") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Strings or tags associated with the extent (ingested data shard)""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - ingest_if_not_exists: Annotated[ - Optional[List[CreateOutputIngestIfNotExist]], - pydantic.Field(alias="ingestIfNotExists"), + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - report_level: Annotated[ - Optional[CreateOutputReportLevel], pydantic.Field(alias="reportLevel") - ] = None - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value - report_method: Annotated[ - Optional[CreateOutputReportMethod], pydantic.Field(alias="reportMethod") - ] = None - r"""Target of the ingestion status reporting. Defaults to Queue.""" + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CreateOutputCompression(value) + except ValueError: + return value + return value - additional_properties: Annotated[ - Optional[List[CreateOutputAdditionalProperty]], - pydantic.Field(alias="additionalProperties"), - ] = None - r"""Optionally, enter additional configuration properties to send to the ingestion service""" + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "concurrency", + "maxRecordSizeKB", + "flushPeriodSec", + "compression", + "useListShards", + "asNdjson", + "onBackpressure", + "description", + "awsApiKey", + "awsSecret", + "maxEventsPerFlush", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_streamName", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_onBackpressure", + "__template_awsApiKey", + ] + ) + serialized = handler(self) + m = {} - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + return m - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ +class CreateOutputOutputAzureLogsType(str, Enum): + r"""Connector type identifier.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + AZURE_LOGS = "azure_logs" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" +class CreateOutputOutputAzureLogsAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter workspace ID and workspace key directly, or select a stored secret""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + MANUAL = "manual" + SECRET = "secret" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" +class CreateOutputOutputAzureLogsPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputAzureLogsPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputAzureLogsTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputAzureLogsType + r"""Connector type identifier.""" + log_type: str + r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + resource_id: NotRequired[str] + r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + api_url: NotRequired[str] + r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[CreateOutputOutputAzureLogsAuthenticationMethod] + r"""Enter workspace ID and workspace key directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputAzureLogsPqControlsTypedDict] + r"""Persistent queue controls.""" + workspace_id: NotRequired[str] + r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" + workspace_key: NotRequired[str] + r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" + keypair_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_workspace_id: NotRequired[str] + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + template_workspace_key: NotRequired[str] + r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" + + +class CreateOutputOutputAzureLogs(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputOutputAzureLogsType + r"""Connector type identifier.""" + + log_type: Annotated[str, pydantic.Field(alias="logType")] + r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + resource_id: Annotated[Optional[str], pydantic.Field(alias="resourceId")] = None + r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + api_url: Annotated[Optional[str], pydantic.Field(alias="apiUrl")] = None + r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[CreateOutputOutputAzureLogsAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter workspace ID and workspace key directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" pq_max_backpressure_sec: Annotated[ Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") @@ -11861,161 +11837,52 @@ class CreateOutputOutputAzureDataExplorer(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputAzureDataExplorerPqControls], + Optional[CreateOutputOutputAzureLogsPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None + r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" + + workspace_key: Annotated[Optional[str], pydantic.Field(alias="workspaceKey")] = None + r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" + + keypair_secret: Annotated[Optional[str], pydantic.Field(alias="keypairSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_cluster_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_clusterUrl") - ] = None - r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" - - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") - ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - - template_table: Annotated[ - Optional[str], pydantic.Field(alias="__template_table") - ] = None - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - - template_oauth_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_oauthEndpoint") - ] = None - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_scope: Annotated[ - Optional[str], pydantic.Field(alias="__template_scope") - ] = None - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - template_mapping_ref: Annotated[ - Optional[str], pydantic.Field(alias="__template_mappingRef") - ] = None - r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" - - template_ingest_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_ingestUrl") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_workspace_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceId") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - @field_serializer("ingest_mode") - def serialize_ingest_mode(self, value): - if isinstance(value, str): - try: - return models.CreateOutputIngestionMode(value) - except ValueError: - return value - return value - - @field_serializer("oauth_endpoint") - def serialize_oauth_endpoint(self, value): - if isinstance(value, str): - try: - return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) - except ValueError: - return value - return value - - @field_serializer("oauth_type") - def serialize_oauth_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputAzureDataExplorerAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): - if isinstance(value, str): - try: - return models.ParquetVersionOptions(value) - except ValueError: - return value - return value + template_workspace_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceKey") + ] = None + r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -12029,29 +11896,11 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("report_level") - def serialize_report_level(self, value): - if isinstance(value, str): - try: - return models.CreateOutputReportLevel(value) - except ValueError: - return value - return value - - @field_serializer("report_method") - def serialize_report_method(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputReportMethod(value) + return models.CreateOutputOutputAzureLogsAuthenticationMethod(value) except ValueError: return value return value @@ -12091,66 +11940,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "validateDatabaseSettings", - "ingestMode", - "description", - "clientSecret", - "textSecret", - "certificate", - "format", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "removeEmptyDirs", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterEnabled", - "deadletterPath", - "maxRetryNum", - "isMappingObj", - "mappingObj", - "mappingRef", - "ingestUrl", - "onBackpressure", - "stagePath", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "maxConcurrentFileParts", - "onDiskFullBackpressure", - "addIdToStagePath", - "retrySettings", - "orphans", - "timeoutSec", - "flushImmediately", - "retainBlobOnSuccess", - "extentTags", - "ingestIfNotExists", - "reportLevel", - "reportMethod", - "additionalProperties", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "resourceId", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "rejectUnauthorized", + "extraHttpHeaders", "useRoundRobinDns", - "keepAlive", + "failedRequestLoggingMode", + "safeHeaders", + "apiUrl", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "description", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -12163,22 +11972,14 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "workspaceId", + "workspaceKey", + "keypairSecret", "__template_streamtags", - "__template_clusterUrl", - "__template_database", - "__template_table", - "__template_oauthEndpoint", - "__template_tenantId", - "__template_clientId", - "__template_scope", - "__template_clientSecret", - "__template_format", - "__template_compress", - "__template_parquetSchema", - "__template_mappingRef", - "__template_ingestUrl", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_fileNameSuffix", + "__template_workspaceId", + "__template_workspaceKey", ] ) serialized = handler(self) @@ -12195,30 +11996,189 @@ def serialize_model(self, handler): return m -class CreateOutputBlobAccessTier(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Blob access tier""" +class CreateOutputOutputAzureDataExplorerType(str, Enum): + r"""Connector type identifier.""" - # Default account access tier - INFERRED = "Inferred" - # Hot tier - HOT = "Hot" - # Cool tier - COOL = "Cool" - # Cold tier - COLD = "Cold" - # Archive tier - ARCHIVE = "Archive" + AZURE_DATA_EXPLORER = "azure_data_explorer" -class CreateOutputOutputAzureBlobTypedDict(TypedDict): +class CreateOutputIngestionMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Ingestion mode""" + + # Batching + BATCHING = "batching" + # Streaming + STREAMING = "streaming" + + +class CreateOutputOutputAzureDataExplorerAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""The type of OAuth 2.0 client credentials grant flow to use""" + + # Client secret + CLIENT_SECRET = "clientSecret" + # Client secret (text secret) + CLIENT_TEXT_SECRET = "clientTextSecret" + # Certificate + CERTIFICATE = "certificate" + + +class CreateOutputCertificateTypedDict(TypedDict): + certificate_name: NotRequired[str] + r"""The certificate you registered as credentials for your app in the Azure portal""" + + +class CreateOutputCertificate(BaseModel): + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The certificate you registered as credentials for your app in the Azure portal""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["certificateName"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputPrefixOptional(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Prefix (optional)""" + + # drop-by + DROP_BY = "dropBy" + # ingest-by + INGEST_BY = "ingestBy" + + +class CreateOutputExtentTagTypedDict(TypedDict): + value: str + r"""Value""" + prefix: NotRequired[CreateOutputPrefixOptional] + r"""Prefix (optional)""" + + +class CreateOutputExtentTag(BaseModel): + value: str + r"""Value""" + + prefix: Optional[CreateOutputPrefixOptional] = None + r"""Prefix (optional)""" + + @field_serializer("prefix") + def serialize_prefix(self, value): + if isinstance(value, str): + try: + return models.CreateOutputPrefixOptional(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["prefix"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputIngestIfNotExistTypedDict(TypedDict): + value: str + r"""Value""" + + +class CreateOutputIngestIfNotExist(BaseModel): + value: str + r"""Value""" + + +class CreateOutputReportLevel(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + + # FailuresOnly + FAILURES_ONLY = "failuresOnly" + # DoNotReport + DO_NOT_REPORT = "doNotReport" + # FailuresAndSuccesses + FAILURES_AND_SUCCESSES = "failuresAndSuccesses" + + +class CreateOutputReportMethod(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Target of the ingestion status reporting. Defaults to Queue.""" + + # Queue + QUEUE = "queue" + # Table + TABLE = "table" + # QueueAndTable + QUEUE_AND_TABLE = "queueAndTable" + + +class CreateOutputAdditionalPropertyTypedDict(TypedDict): + key: str + r"""Key""" + value: str + r"""Value""" + + +class CreateOutputAdditionalProperty(BaseModel): + key: str + r"""Key""" + + value: str + r"""Value""" + + +class CreateOutputOutputAzureDataExplorerPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputAzureDataExplorerPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputAzureDataExplorerTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsAzureblob + type: CreateOutputOutputAzureDataExplorerType r"""Connector type identifier.""" - container_name: str - r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - stage_path: str - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + cluster_url: str + r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" + database: str + r"""Name of the database containing the table where data will be ingested""" + table: str + r"""Name of the table to ingest data into""" + oauth_endpoint: MicrosoftEntraIDAuthenticationEndpointOptionsSasl + r"""Endpoint used to acquire authentication tokens from Azure""" + tenant_id: str + r"""Directory ID (tenant identifier) in Azure Active Directory""" + client_id: str + r"""client_id to pass in the OAuth request parameter""" + scope: str + r"""Scope to pass in the OAuth request parameter""" + oauth_type: CreateOutputOutputAzureDataExplorerAuthenticationMethod + r"""The type of OAuth 2.0 client credentials grant flow to use""" + compress: CompressionOptionsHTTP + r"""Data compression format to apply to HTTP content before it is delivered""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -12227,55 +12187,19 @@ class CreateOutputOutputAzureBlobTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - create_container: NotRequired[bool] - r"""Create the configured container in Azure Blob Storage if it does not already exist""" - dest_path: NotRequired[str] - r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - auth_type: NotRequired[AuthenticationMethodOptions] - r"""Authentication method""" - storage_class: NotRequired[CreateOutputBlobAccessTier] - r"""Blob access tier""" + validate_database_settings: NotRequired[bool] + r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" + ingest_mode: NotRequired[CreateOutputIngestionMode] + r"""Ingestion mode""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" + client_secret: NotRequired[str] + r"""The client secret that you generated for your app in the Azure portal""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CreateOutputCertificateTypedDict] + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" compression_level: NotRequired[CompressionLevelOptions] r"""Compression level to apply before moving files to final destination""" automatic_schema: NotRequired[bool] @@ -12300,75 +12224,188 @@ class CreateOutputOutputAzureBlobTypedDict(TypedDict): r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" enable_page_checksum: NotRequired[bool] r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" empty_dir_cleanup_sec: NotRequired[float] r"""How frequently, in seconds, to clean up empty directories""" directory_batch_size: NotRequired[float] r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" deadletter_path: NotRequired[str] r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - connection_string: NotRequired[str] - r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - storage_account_name: NotRequired[str] - r"""The name of your Azure storage account""" - tenant_id: NotRequired[str] - r"""The service principal's tenant ID""" - client_id: NotRequired[str] - r"""The service principal's client ID""" - azure_cloud: NotRequired[str] - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - endpoint_suffix: NotRequired[str] - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CertificateTypeTypedDict] + is_mapping_obj: NotRequired[bool] + r"""Send a JSON mapping object instead of specifying an existing named data mapping""" + mapping_obj: NotRequired[str] + r"""Enter a JSON object that defines your desired data mapping""" + mapping_ref: NotRequired[str] + r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" + ingest_url: NotRequired[str] + r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + flush_immediately: NotRequired[bool] + r"""Bypass the data management service's aggregation mechanism""" + retain_blob_on_success: NotRequired[bool] + r"""Prevent blob deletion after ingestion is complete""" + extent_tags: NotRequired[List[CreateOutputExtentTagTypedDict]] + r"""Strings or tags associated with the extent (ingested data shard)""" + ingest_if_not_exists: NotRequired[List[CreateOutputIngestIfNotExistTypedDict]] + r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" + report_level: NotRequired[CreateOutputReportLevel] + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + report_method: NotRequired[CreateOutputReportMethod] + r"""Target of the ingestion status reporting. Defaults to Queue.""" + additional_properties: NotRequired[List[CreateOutputAdditionalPropertyTypedDict]] + r"""Optionally, enter additional configuration properties to send to the ingestion service""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputOutputAzureDataExplorerPqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_container_name: NotRequired[str] - r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_cluster_url: NotRequired[str] + r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_table: NotRequired[str] + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" + template_oauth_endpoint: NotRequired[str] + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_scope: NotRequired[str] + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" template_format: NotRequired[str] r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_connection_string: NotRequired[str] - r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" - template_storage_account_name: NotRequired[str] - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_azure_cloud: NotRequired[str] - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + template_mapping_ref: NotRequired[str] + r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" + template_ingest_url: NotRequired[str] + r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" -class CreateOutputOutputAzureBlob(BaseModel): +class CreateOutputOutputAzureDataExplorer(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsAzureblob + type: CreateOutputOutputAzureDataExplorerType r"""Connector type identifier.""" - container_name: Annotated[str, pydantic.Field(alias="containerName")] - r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" + cluster_url: Annotated[str, pydantic.Field(alias="clusterUrl")] + r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + database: str + r"""Name of the database containing the table where data will be ingested""" + + table: str + r"""Name of the table to ingest data into""" + + oauth_endpoint: Annotated[ + MicrosoftEntraIDAuthenticationEndpointOptionsSasl, + pydantic.Field(alias="oauthEndpoint"), + ] + r"""Endpoint used to acquire authentication tokens from Azure""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Directory ID (tenant identifier) in Azure Active Directory""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""client_id to pass in the OAuth request parameter""" + + scope: str + r"""Scope to pass in the OAuth request parameter""" + + oauth_type: Annotated[ + CreateOutputOutputAzureDataExplorerAuthenticationMethod, + pydantic.Field(alias="oauthType"), + ] + r"""The type of OAuth 2.0 client credentials grant flow to use""" + + compress: CompressionOptionsHTTP + r"""Data compression format to apply to HTTP content before it is delivered""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -12384,141 +12421,51 @@ class CreateOutputOutputAzureBlob(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - create_container: Annotated[ - Optional[bool], pydantic.Field(alias="createContainer") + validate_database_settings: Annotated[ + Optional[bool], pydantic.Field(alias="validateDatabaseSettings") ] = None - r"""Create the configured container in Azure Blob Storage if it does not already exist""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" + r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + ingest_mode: Annotated[ + Optional[CreateOutputIngestionMode], pydantic.Field(alias="ingestMode") ] = None - r"""Add the Output ID value to staging location""" + r"""Ingestion mode""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""The client secret that you generated for your app in the Azure portal""" - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CreateOutputCertificate] = None format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( None ) r"""Format of the output data""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" + + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") + ] = None + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( None ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" - - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None - r"""Buffer size used to write to a file""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptions], pydantic.Field(alias="authType") - ] = None - r"""Authentication method""" - - storage_class: Annotated[ - Optional[CreateOutputBlobAccessTier], pydantic.Field(alias="storageClass") - ] = None - r"""Blob access tier""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" + r"""Determines which data types are supported and how they are represented""" parquet_data_page_version: Annotated[ Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") @@ -12561,6 +12508,11 @@ class CreateOutputOutputAzureBlob(BaseModel): ] = None r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + empty_dir_cleanup_sec: Annotated[ Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None @@ -12571,6 +12523,11 @@ class CreateOutputOutputAzureBlob(BaseModel): ] = None r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + deadletter_path: Annotated[ Optional[str], pydantic.Field(alias="deadletterPath") ] = None @@ -12581,156 +12538,339 @@ class CreateOutputOutputAzureBlob(BaseModel): ) r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - connection_string: Annotated[ - Optional[str], pydantic.Field(alias="connectionString") - ] = None - r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" + is_mapping_obj: Annotated[Optional[bool], pydantic.Field(alias="isMappingObj")] = ( + None + ) + r"""Send a JSON mapping object instead of specifying an existing named data mapping""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + mapping_obj: Annotated[Optional[str], pydantic.Field(alias="mappingObj")] = None + r"""Enter a JSON object that defines your desired data mapping""" - storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="storageAccountName") - ] = None - r"""The name of your Azure storage account""" + mapping_ref: Annotated[Optional[str], pydantic.Field(alias="mappingRef")] = None + r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""The service principal's tenant ID""" + ingest_url: Annotated[Optional[str], pydantic.Field(alias="ingestUrl")] = None + r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""The service principal's client ID""" + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" - azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - endpoint_suffix: Annotated[ - Optional[str], pydantic.Field(alias="endpointSuffix") + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Select or create a stored text secret""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - certificate: Optional[CertificateType] = None + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - template_container_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_containerName") + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" + r"""Maximum number of parts to upload in parallel per file""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + r"""Add the Output ID value to staging location""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + flush_immediately: Annotated[ + Optional[bool], pydantic.Field(alias="flushImmediately") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Bypass the data management service's aggregation mechanism""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + retain_blob_on_success: Annotated[ + Optional[bool], pydantic.Field(alias="retainBlobOnSuccess") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Prevent blob deletion after ingestion is complete""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + extent_tags: Annotated[ + Optional[List[CreateOutputExtentTag]], pydantic.Field(alias="extentTags") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Strings or tags associated with the extent (ingested data shard)""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") + ingest_if_not_exists: Annotated[ + Optional[List[CreateOutputIngestIfNotExist]], + pydantic.Field(alias="ingestIfNotExists"), ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") + report_level: Annotated[ + Optional[CreateOutputReportLevel], pydantic.Field(alias="reportLevel") ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" - template_connection_string: Annotated[ - Optional[str], pydantic.Field(alias="__template_connectionString") + report_method: Annotated[ + Optional[CreateOutputReportMethod], pydantic.Field(alias="reportMethod") ] = None - r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" + r"""Target of the ingestion status reporting. Defaults to Queue.""" - template_storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageAccountName") + additional_properties: Annotated[ + Optional[List[CreateOutputAdditionalProperty]], + pydantic.Field(alias="additionalProperties"), ] = None - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + r"""Optionally, enter additional configuration properties to send to the ingestion service""" - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_azure_cloud: Annotated[ - Optional[str], pydantic.Field(alias="__template_azureCloud") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[CreateOutputOutputAzureDataExplorerPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_cluster_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_clusterUrl") + ] = None + r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" + + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") + ] = None + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + + template_table: Annotated[ + Optional[str], pydantic.Field(alias="__template_table") + ] = None + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" + + template_oauth_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_oauthEndpoint") + ] = None + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_scope: Annotated[ + Optional[str], pydantic.Field(alias="__template_scope") + ] = None + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") + ] = None + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + template_mapping_ref: Annotated[ + Optional[str], pydantic.Field(alias="__template_mappingRef") + ] = None + r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" + + template_ingest_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_ingestUrl") + ] = None + r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + + @field_serializer("ingest_mode") + def serialize_ingest_mode(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.CreateOutputIngestionMode(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("oauth_endpoint") + def serialize_oauth_endpoint(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("oauth_type") + def serialize_oauth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptions(value) + return models.CreateOutputOutputAzureDataExplorerAuthenticationMethod( + value + ) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.CreateOutputBlobAccessTier(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -12771,79 +12911,165 @@ def serialize_parquet_data_page_version(self, value): return value return value - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "createContainer", - "destPath", - "addIdToStagePath", - "maxConcurrentFileParts", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "authType", - "storageClass", - "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "connectionString", - "textSecret", - "storageAccountName", - "tenantId", - "clientId", - "azureCloud", - "endpointSuffix", - "clientTextSecret", + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): + if isinstance(value, str): + try: + return models.DiskSpaceProtectionOptions(value) + except ValueError: + return value + return value + + @field_serializer("report_level") + def serialize_report_level(self, value): + if isinstance(value, str): + try: + return models.CreateOutputReportLevel(value) + except ValueError: + return value + return value + + @field_serializer("report_method") + def serialize_report_method(self, value): + if isinstance(value, str): + try: + return models.CreateOutputReportMethod(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "validateDatabaseSettings", + "ingestMode", + "description", + "clientSecret", + "textSecret", "certificate", + "format", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "removeEmptyDirs", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterEnabled", + "deadletterPath", + "maxRetryNum", + "isMappingObj", + "mappingObj", + "mappingRef", + "ingestUrl", + "onBackpressure", + "stagePath", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "maxConcurrentFileParts", + "onDiskFullBackpressure", + "addIdToStagePath", + "retrySettings", + "orphans", + "timeoutSec", + "flushImmediately", + "retainBlobOnSuccess", + "extentTags", + "ingestIfNotExists", + "reportLevel", + "reportMethod", + "additionalProperties", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "maxConnectionReuseSec", + "flushPeriodSec", + "rejectUnauthorized", + "useRoundRobinDns", + "keepAlive", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_containerName", - "__template_destPath", - "__template_partitionExpr", + "__template_clusterUrl", + "__template_database", + "__template_table", + "__template_oauthEndpoint", + "__template_tenantId", + "__template_clientId", + "__template_scope", + "__template_clientSecret", "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", - "__template_onBackpressure", "__template_compress", "__template_parquetSchema", - "__template_connectionString", - "__template_storageAccountName", - "__template_tenantId", - "__template_clientId", - "__template_azureCloud", + "__template_mappingRef", + "__template_ingestUrl", + "__template_onBackpressure", + "__template_fileNameSuffix", ] ) serialized = handler(self) @@ -12860,15 +13086,30 @@ def serialize_model(self, handler): return m -class CreateOutputOutputS3TypedDict(TypedDict): +class CreateOutputBlobAccessTier(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Blob access tier""" + + # Default account access tier + INFERRED = "Inferred" + # Hot tier + HOT = "Hot" + # Cool tier + COOL = "Cool" + # Cold tier + COLD = "Cold" + # Archive tier + ARCHIVE = "Archive" + + +class CreateOutputOutputAzureBlobTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsS3 + type: TypeOptionsAzureblob r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + container_name: str + r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -12877,34 +13118,14 @@ class CreateOutputOutputS3TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the S3 bucket is located""" + create_container: NotRequired[bool] + r"""Create the configured container in Azure Blob Storage if it does not already exist""" dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" add_id_to_stage_path: NotRequired[bool] r"""Add the Output ID value to staging location""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file""" remove_empty_dirs: NotRequired[bool] r"""Remove empty staging directories after moving files""" partition_expr: NotRequired[str] @@ -12938,22 +13159,12 @@ class CreateOutputOutputS3TypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" + auth_type: NotRequired[AuthenticationMethodOptions] + r"""Authentication method""" + storage_class: NotRequired[CreateOutputBlobAccessTier] + r"""Blob access tier""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" compress: NotRequired[CompressionOptionsHTTP] r"""Data compression format to apply to HTTP content before it is delivered""" compression_level: NotRequired[CompressionLevelOptions] @@ -12988,19 +13199,28 @@ class CreateOutputOutputS3TypedDict(TypedDict): r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] + connection_string: NotRequired[str] + r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_container_name: NotRequired[str] + r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" + template_dest_path: NotRequired[str] r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" template_partition_expr: NotRequired[str] r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" @@ -13012,36 +13232,34 @@ class CreateOutputOutputS3TypedDict(TypedDict): r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + template_connection_string: NotRequired[str] + r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" -class CreateOutputOutputS3(BaseModel): +class CreateOutputOutputAzureBlob(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsS3 + type: TypeOptionsAzureblob r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + container_name: Annotated[str, pydantic.Field(alias="containerName")] + r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -13057,71 +13275,24 @@ class CreateOutputOutputS3(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + create_container: Annotated[ + Optional[bool], pydantic.Field(alias="createContainer") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - region: Optional[str] = None - r"""Region where the S3 bucket is located""" + r"""Create the configured container in Azure Blob Storage if it does not already exist""" dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") - ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" - - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" add_id_to_stage_path: Annotated[ Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None r"""Add the Output ID value to staging location""" + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file""" + remove_empty_dirs: Annotated[ Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None @@ -13204,39 +13375,19 @@ class CreateOutputOutputS3(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + auth_type: Annotated[ + Optional[AuthenticationMethodOptions], pydantic.Field(alias="authType") ] = None - r"""Object ACL to assign to uploaded objects""" + r"""Authentication method""" storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") - ] = None - r"""Storage class to select for uploaded objects""" - - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), + Optional[CreateOutputBlobAccessTier], pydantic.Field(alias="storageClass") ] = None - r"""Server-side encryption to use for uploaded objects""" - - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" + r"""Blob access tier""" description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - compress: Optional[CompressionOptionsHTTP] = None r"""Data compression format to apply to HTTP content before it is delivered""" @@ -13321,35 +13472,49 @@ class CreateOutputOutputS3(BaseModel): ) r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + connection_string: Annotated[ + Optional[str], pydantic.Field(alias="connectionString") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""The name of your Azure storage account""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" + + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Select or create a stored text secret""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + certificate: Optional[CertificateType] = None + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_container_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_containerName") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" template_dest_path: Annotated[ Optional[str], pydantic.Field(alias="__template_destPath") @@ -13381,54 +13546,40 @@ class CreateOutputOutputS3(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + template_connection_string: Annotated[ + Optional[str], pydantic.Field(alias="__template_connectionString") ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" @field_serializer("format_") def serialize_format_(self, value): @@ -13457,11 +13608,11 @@ def serialize_on_disk_full_backpressure(self, value): return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.ObjectACLOptions(value) + return models.AuthenticationMethodOptions(value) except ValueError: return value return value @@ -13470,16 +13621,7 @@ def serialize_object_acl(self, value): def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.StorageClassOptions(value) - except ValueError: - return value - return value - - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): - if isinstance(value, str): - try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) + return models.CreateOutputBlobAccessTier(value) except ValueError: return value return value @@ -13528,20 +13670,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "endpoint", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "region", + "createContainer", "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", "addIdToStagePath", + "maxConcurrentFileParts", "removeEmptyDirs", "partitionExpr", "format", @@ -13559,14 +13691,9 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "awsSecretKey", - "objectACL", + "authType", "storageClass", - "serverSideEncryption", - "kmsKeyId", "description", - "awsApiKey", - "awsSecret", "compress", "compressionLevel", "automaticSchema", @@ -13584,26 +13711,30 @@ def serialize_model(self, handler): "directoryBatchSize", "deadletterPath", "maxRetryNum", + "connectionString", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", "__template_streamtags", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_bucket", - "__template_region", + "__template_containerName", "__template_destPath", "__template_partitionExpr", "__template_format", "__template_baseFileName", "__template_fileNameSuffix", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", - "__template_awsApiKey", "__template_compress", "__template_parquetSchema", + "__template_connectionString", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", ] ) serialized = handler(self) @@ -13620,19 +13751,15 @@ def serialize_model(self, handler): return m -class CreateOutputOutputFilesystemType(str, Enum): - r"""Connector type identifier.""" - - FILESYSTEM = "filesystem" - - -class CreateOutputOutputFilesystemTypedDict(TypedDict): +class CreateOutputOutputS3TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputFilesystemType + type: TypeOptionsS3 r"""Connector type identifier.""" - dest_path: str - r"""Final destination for the output files""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -13641,8 +13768,32 @@ class CreateOutputOutputFilesystemTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the S3 bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" add_id_to_stage_path: NotRequired[bool] r"""Add the Output ID value to staging location""" remove_empty_dirs: NotRequired[bool] @@ -13678,8 +13829,22 @@ class CreateOutputOutputFilesystemTypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" compress: NotRequired[CompressionOptionsHTTP] r"""Data compression format to apply to HTTP content before it is delivered""" compression_level: NotRequired[CompressionLevelOptions] @@ -13716,6 +13881,18 @@ class CreateOutputOutputFilesystemTypedDict(TypedDict): r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" template_partition_expr: NotRequired[str] r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" template_format: NotRequired[str] @@ -13726,21 +13903,36 @@ class CreateOutputOutputFilesystemTypedDict(TypedDict): r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputOutputFilesystem(BaseModel): +class CreateOutputOutputS3(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputFilesystemType + type: TypeOptionsS3 r"""Connector type identifier.""" - dest_path: Annotated[str, pydantic.Field(alias="destPath")] - r"""Final destination for the output files""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -13756,8 +13948,65 @@ class CreateOutputOutputFilesystem(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + region: Optional[str] = None + r"""Region where the S3 bucket is located""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") + ] = None + r"""Disable if you can access files within the bucket but not the bucket itself""" + + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + ] = None + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" add_id_to_stage_path: Annotated[ Optional[bool], pydantic.Field(alias="addIdToStagePath") @@ -13846,572 +14095,237 @@ class CreateOutputOutputFilesystem(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" - - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): - if isinstance(value, str): - try: - return models.ParquetVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): - if isinstance(value, str): - try: - return models.DataPageVersionOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "stagePath", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "__template_streamtags", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", - "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputSignalfxType(str, Enum): - r"""Connector type identifier.""" - - SIGNALFX = "signalfx" - - -class CreateOutputOutputSignalfxPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputSignalfxPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputSignalfxTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputSignalfxType - r"""Connector type identifier.""" - realm: str - r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSignalfxPqControlsTypedDict] - r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + ] = None + r"""Object ACL to assign to uploaded objects""" -class CreateOutputOutputSignalfx(BaseModel): - id: str - r"""Unique ID for this output""" + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + ] = None + r"""Storage class to select for uploaded objects""" - type: CreateOutputOutputSignalfxType - r"""Connector type identifier.""" + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" - realm: str - r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Compression level to apply before moving files to final destination""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Determines which data types are supported and how they are represented""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""Headers to add to all events""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""List of headers that are safe to log in plain text""" + r"""How frequently, in seconds, to clean up empty directories""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - token: Optional[str] = None - r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Codec to use to compress the persisted data""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - pq_controls: Annotated[ - Optional[CreateOutputOutputSignalfxPqControls], - pydantic.Field(alias="pqControls"), + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") ] = None - r"""Persistent queue controls.""" + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -14420,34 +14334,79 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.StorageClassOptions(value) + except ValueError: + return value + return value + + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): + if isinstance(value, str): + try: + return models.ServerSideEncryptionForUploadedObjectsOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -14460,41 +14419,82 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "endpoint", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_bucket", + "__template_region", + "__template_destPath", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -14509,122 +14509,129 @@ def serialize_model(self, handler): m[k] = val return m - - -class CreateOutputOutputWavefrontType(str, Enum): - r"""Connector type identifier.""" - - WAVEFRONT = "wavefront" - - -class CreateOutputOutputWavefrontPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputWavefrontPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputWavefrontTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputWavefrontType - r"""Connector type identifier.""" - domain: str - r"""WaveFront domain name, e.g. \"longboard\" """ - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + + +class CreateOutputOutputFilesystemType(str, Enum): + r"""Connector type identifier.""" + + FILESYSTEM = "filesystem" + + +class CreateOutputOutputFilesystemTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputFilesystemType + r"""Connector type identifier.""" + dest_path: str + r"""Final destination for the output files""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputWavefrontPqControlsTypedDict] - r"""Persistent queue controls.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputOutputWavefront(BaseModel): +class CreateOutputOutputFilesystem(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputWavefrontType + type: CreateOutputOutputFilesystemType r"""Connector type identifier.""" - domain: str - r"""WaveFront domain name, e.g. \"longboard\" """ + dest_path: Annotated[str, pydantic.Field(alias="destPath")] + r"""Final destination for the output files""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -14640,220 +14647,282 @@ class CreateOutputOutputWavefront(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Add the Output ID value to staging location""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Remove empty staging directories after moving files""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Headers to add to all events""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Buffer size used to write to a file""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""List of headers that are safe to log in plain text""" + r"""How to handle events when all receivers are exerting backpressure""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" description: Optional[str] = None r"""Optional description for this configuration.""" - token: Optional[str] = None - r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Determines which data types are supported and how they are represented""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), + ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""Codec to use to compress the persisted data""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_controls: Annotated[ - Optional[CreateOutputOutputWavefrontPqControls], - pydantic.Field(alias="pqControls"), + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Persistent queue controls.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.DataFormatOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -14866,41 +14935,51 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "stagePath", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -14917,19 +14996,27 @@ def serialize_model(self, handler): return m -class CreateOutputOutputTcpjsonPqControlsTypedDict(TypedDict): +class CreateOutputOutputSignalfxType(str, Enum): + r"""Connector type identifier.""" + + SIGNALFX = "signalfx" + + +class CreateOutputOutputSignalfxPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputTcpjsonPqControls(BaseModel): +class CreateOutputOutputSignalfxPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputTcpjsonTypedDict(TypedDict): +class CreateOutputOutputSignalfxTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsTcpjson + type: CreateOutputOutputSignalfxType r"""Connector type identifier.""" + realm: str + r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -14938,44 +15025,50 @@ class CreateOutputOutputTcpjsonTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Use load-balanced destinations""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - send_header: NotRequired[bool] - r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + token: NotRequired[str] + r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -14998,29 +15091,26 @@ class CreateOutputOutputTcpjsonTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputTcpjsonPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputSignalfxPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Optional authentication token to include as part of the connection header""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputOutputTcpjson(BaseModel): +class CreateOutputOutputSignalfx(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsTcpjson + type: CreateOutputOutputSignalfxType r"""Connector type identifier.""" + realm: str + r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -15035,85 +15125,99 @@ class CreateOutputOutputTcpjson(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Use load-balanced destinations""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - compression: Optional[CompressionOptionsGzipNone] = None - r"""Codec to use to compress the data before sending""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Maximum size, in KB, of the request body""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - - send_header: Annotated[Optional[bool], pydantic.Field(alias="sendHeader")] = None - r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""Headers to add to all events""" - host: Optional[str] = None - r"""The hostname of the receiver""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - port: Optional[float] = None - r"""The port to connect to on the provided host""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + token: Optional[str] = None + r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -15165,42 +15269,40 @@ class CreateOutputOutputTcpjson(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputTcpjsonPqControls], + Optional[CreateOutputOutputSignalfxPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Optional authentication token to include as part of the connection header""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipNone(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -15214,15 +15316,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -15258,25 +15351,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "compression", - "logFailedRequests", - "throttleRatePerSec", - "tls", - "connectionTimeout", - "writeTimeout", - "tokenTTLMinutes", - "sendHeader", - "onBackpressure", "authType", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "host", - "port", - "excludeSelf", - "hosts", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -15289,12 +15383,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_host", - "__template_port", ] ) serialized = handler(self) @@ -15311,33 +15402,27 @@ def serialize_model(self, handler): return m -class CreateOutputOutputWizHecType(str, Enum): +class CreateOutputOutputWavefrontType(str, Enum): r"""Connector type identifier.""" - WIZ_HEC = "wiz_hec" + WAVEFRONT = "wavefront" -class CreateOutputOutputWizHecPqControlsTypedDict(TypedDict): +class CreateOutputOutputWavefrontPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputWizHecPqControls(BaseModel): +class CreateOutputOutputWavefrontPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputWizHecTypedDict(TypedDict): +class CreateOutputOutputWavefrontTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputWizHecType + type: CreateOutputOutputWavefrontType r"""Connector type identifier.""" - wiz_connector_id: str - r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" - wiz_environment: str - r"""Your Wiz deployment environment""" - data_center: str - r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - wiz_sourcetype: str - r"""Wiz Defend Source type""" + domain: str + r"""WaveFront domain name, e.g. \"longboard\" """ pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -15346,8 +15431,8 @@ class CreateOutputOutputWizHecTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -15369,12 +15454,12 @@ class CreateOutputOutputWizHecTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -15387,7 +15472,7 @@ class CreateOutputOutputWizHecTypedDict(TypedDict): description: NotRequired[str] r"""Optional description for this configuration.""" token: NotRequired[str] - r"""Wiz Defend Auth token""" + r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] @@ -15412,40 +15497,25 @@ class CreateOutputOutputWizHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputWizHecPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputWavefrontPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_wiz_environment: NotRequired[str] - r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" - template_data_center: NotRequired[str] - r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" - template_wiz_sourcetype: NotRequired[str] - r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputOutputWizHec(BaseModel): +class CreateOutputOutputWavefront(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputWizHecType + type: CreateOutputOutputWavefrontType r"""Connector type identifier.""" - wiz_connector_id: str - r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" - - wiz_environment: str - r"""Your Wiz deployment environment""" - - data_center: str - r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - - wiz_sourcetype: str - r"""Wiz Defend Source type""" + domain: str + r"""WaveFront domain name, e.g. \"longboard\" """ pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -15461,8 +15531,11 @@ class CreateOutputOutputWizHec(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -15507,6 +15580,11 @@ class CreateOutputOutputWizHec(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -15518,12 +15596,6 @@ class CreateOutputOutputWizHec(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -15548,7 +15620,7 @@ class CreateOutputOutputWizHec(BaseModel): r"""Optional description for this configuration.""" token: Optional[str] = None - r"""Wiz Defend Auth token""" + r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -15603,7 +15675,8 @@ class CreateOutputOutputWizHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputWizHecPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputWavefrontPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -15617,40 +15690,25 @@ class CreateOutputOutputWizHec(BaseModel): ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_wiz_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_wiz_environment") - ] = None - r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" - - template_data_center: Annotated[ - Optional[str], pydantic.Field(alias="__template_data_center") - ] = None - r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" - - template_wiz_sourcetype: Annotated[ - Optional[str], pydantic.Field(alias="__template_wiz_sourcetype") - ] = None - r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -15699,7 +15757,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "tls", + "authType", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -15709,9 +15767,9 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", @@ -15733,9 +15791,6 @@ def serialize_model(self, handler): "pqControls", "__template_streamtags", "__template_failedRequestLoggingMode", - "__template_wiz_environment", - "__template_data_center", - "__template_wiz_sourcetype", "__template_onBackpressure", ] ) @@ -15753,135 +15808,65 @@ def serialize_model(self, handler): return m -class CreateOutputOutputSplunkHecType(str, Enum): - r"""Connector type identifier.""" - - SPLUNK_HEC = "splunk_hec" - - -class CreateOutputOutputSplunkHecURLTypedDict(TypedDict): - url: str - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - -class CreateOutputOutputSplunkHecURL(BaseModel): - url: str - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputSplunkHecPqControlsTypedDict(TypedDict): +class CreateOutputOutputTcpjsonPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSplunkHecPqControls(BaseModel): +class CreateOutputOutputTcpjsonPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSplunkHecTypedDict(TypedDict): +class CreateOutputOutputTcpjsonTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSplunkHecType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - next_queue: NotRequired[str] - r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" - tcp_routing: NotRequired[str] - r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" + type: TypeOptionsTcpjson + r"""Connector type identifier.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + load_balanced: NotRequired[bool] + r"""Use load-balanced destinations""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + token_ttl_minutes: NotRequired[float] + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" + send_header: NotRequired[bool] + r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputOutputSplunkHecURLTypedDict]] - r"""Splunk HEC Endpoints""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" - token: NotRequired[str] - r"""Splunk HEC authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15904,23 +15889,27 @@ class CreateOutputOutputSplunkHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSplunkHecPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputTcpjsonPqControlsTypedDict] r"""Persistent queue controls.""" + auth_token: NotRequired[str] + r"""Optional authentication token to include as part of the connection header""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputOutputSplunkHec(BaseModel): +class CreateOutputOutputTcpjson(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSplunkHecType + type: TypeOptionsTcpjson r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -15940,118 +15929,67 @@ class CreateOutputOutputSplunkHec(BaseModel): load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Use load-balanced destinations""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + compression: Optional[CompressionOptionsGzipNone] = None + r"""Codec to use to compress the data before sending""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Use to troubleshoot issues with sending data""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + send_header: Annotated[Optional[bool], pydantic.Field(alias="sendHeader")] = None + r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" - enable_multi_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="enableMultiMetrics") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" + r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - next_queue: Annotated[Optional[str], pydantic.Field(alias="nextQueue")] = None - r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" - - tcp_routing: Annotated[Optional[str], pydantic.Field(alias="tcpRouting")] = None - r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + host: Optional[str] = None + r"""The hostname of the receiver""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + port: Optional[float] = None + r"""The port to connect to on the provided host""" exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: Optional[List[CreateOutputOutputSplunkHecURL]] = None - r"""Splunk HEC Endpoints""" + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") @@ -16063,11 +16001,10 @@ class CreateOutputOutputSplunkHec(BaseModel): ] = None r"""How far back in time to keep traffic stats for load balancing purposes""" - token: Optional[str] = None - r"""Splunk HEC authentication token""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") + ] = None + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16119,54 +16056,60 @@ class CreateOutputOutputSplunkHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSplunkHecPqControls], + Optional[CreateOutputOutputTcpjsonPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Optional authentication token to include as part of the connection header""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @field_serializer("compression") + def serialize_compression(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CompressionOptionsGzipNone(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -16207,35 +16150,24 @@ def serialize_model(self, handler): "environment", "streamtags", "loadBalanced", + "compression", + "logFailedRequests", + "throttleRatePerSec", "tls", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "enableMultiMetrics", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "nextQueue", - "tcpRouting", + "connectionTimeout", + "writeTimeout", + "tokenTTLMinutes", + "sendHeader", "onBackpressure", + "authType", "description", - "url", - "useRoundRobinDns", + "host", + "port", "excludeSelf", - "urls", + "hosts", "dnsResolvePeriodSec", "loadBalanceStatsPeriodSec", - "token", - "textSecret", + "maxConcurrentSenders", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16248,10 +16180,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "authToken", + "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -16268,158 +16202,53 @@ def serialize_model(self, handler): return m -class CreateOutputOutputSplunkLbType(str, Enum): +class CreateOutputOutputWizHecType(str, Enum): r"""Connector type identifier.""" - SPLUNK_LB = "splunk_lb" - - -class CreateOutputAuthTokenTypedDict(TypedDict): - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateOutputAuthToken(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["authType", "authToken", "textSecret"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputIndexerDiscoveryConfigsTypedDict(TypedDict): - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - - site: str - r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" - master_uri: str - r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" - refresh_interval_sec: float - r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" - reject_unauthorized: NotRequired[bool] - r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" - auth_tokens: NotRequired[List[CreateOutputAuthTokenTypedDict]] - r"""Tokens required to authenticate to cluster manager for indexer discovery""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateOutputIndexerDiscoveryConfigs(BaseModel): - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - - site: str - r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" - - master_uri: Annotated[str, pydantic.Field(alias="masterUri")] - r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" - - refresh_interval_sec: Annotated[float, pydantic.Field(alias="refreshIntervalSec")] - r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" - - auth_tokens: Annotated[ - Optional[List[CreateOutputAuthToken]], pydantic.Field(alias="authTokens") - ] = None - r"""Tokens required to authenticate to cluster manager for indexer discovery""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + WIZ_HEC = "wiz_hec" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value +class CreateOutputWizDefendSourceType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["rejectUnauthorized", "authTokens", "authType", "authToken", "textSecret"] - ) - serialized = handler(self) - m = {} + AWS_CLOUDTRAIL = "AWS_CLOUDTRAIL" + AWS_EKS_AUDIT_LOGS = "AWS_EKS_AUDIT_LOGS" + AWS_RESOLVER_QUERY_LOGS = "AWS_RESOLVER_QUERY_LOGS" + AZURE_ACTIVITY_LOGS = "AZURE_ACTIVITY_LOGS" + GCP_AUDIT_LOGS = "GCP_AUDIT_LOGS" + GITHUB_AUDIT_LOGS = "GITHUB_AUDIT_LOGS" + OCI_AUDIT_LOGS = "OCI_AUDIT_LOGS" + AWS_VPC_FLOW_LOGS = "AWS_VPC_FLOW_LOGS" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateOutputEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The format of the VPC Flow Log events""" - return m + JSON = "json" + CSV_ROW = "csv_row" -class CreateOutputOutputSplunkLbPqControlsTypedDict(TypedDict): +class CreateOutputOutputWizHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSplunkLbPqControls(BaseModel): +class CreateOutputOutputWizHecPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSplunkLbTypedDict(TypedDict): +class CreateOutputOutputWizHecTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSplunkLbType + type: CreateOutputOutputWizHecType r"""Connector type identifier.""" - hosts: List[HostConfOutputSyslogTypedDict] - r"""Set of Splunk indexers to load-balance data to.""" + wiz_connector_id: str + r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" + wiz_environment: str + r"""Your Wiz deployment environment""" + data_center: str + r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" + wiz_sourcetype: CreateOutputWizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -16428,48 +16257,54 @@ class CreateOutputOutputSplunkLbTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - nested_fields: NotRequired[NestedFieldSerializationOptions] - r"""How to serialize nested fields into index-time fields""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" - enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - enable_ack: NotRequired[bool] - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - max_s2_sversion: NotRequired[MaxS2SVersionOptions] - r"""The highest S2S protocol version to advertise during handshake""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - indexer_discovery: NotRequired[bool] - r"""Automatically discover indexers in indexer clustering environment.""" - sender_unhealthy_time_allowance: NotRequired[float] - r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_failed_health_checks: NotRequired[float] - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - compress: NotRequired[CompressionOptions] - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" - indexer_discovery_configs: NotRequired[CreateOutputIndexerDiscoveryConfigsTypedDict] - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + token: NotRequired[str] + r"""Wiz Defend Auth token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + wiz_vpc_event_format: NotRequired[CreateOutputEventFormat] + r"""The format of the VPC Flow Log events""" + wiz_vpc_flow_log_format: NotRequired[str] + r"""The format string for VPC Flow Log fields""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16492,33 +16327,40 @@ class CreateOutputOutputSplunkLbTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSplunkLbPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputWizHecPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_nested_fields: NotRequired[str] - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_max_s2_sversion: NotRequired[str] - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_wiz_environment: NotRequired[str] + r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" + template_data_center: NotRequired[str] + r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" + template_wiz_sourcetype: NotRequired[str] + r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" -class CreateOutputOutputSplunkLb(BaseModel): +class CreateOutputOutputWizHec(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSplunkLbType + type: CreateOutputOutputWizHecType r"""Connector type identifier.""" - hosts: List[HostConfOutputSyslog] - r"""Set of Splunk indexers to load-balance data to.""" + wiz_connector_id: str + r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" + + wiz_environment: str + r"""Your Wiz deployment environment""" + + data_center: str + r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" + + wiz_sourcetype: CreateOutputWizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -16534,102 +16376,103 @@ class CreateOutputOutputSplunkLb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + r"""Maximum size, in KB, of the request body""" - nested_fields: Annotated[ - Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""How to serialize nested fields into index-time fields""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") - ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - enable_multi_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="enableMultiMetrics") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - max_s2_sversion: Annotated[ - Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""The highest S2S protocol version to advertise during handshake""" + r"""List of headers that are safe to log in plain text""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - indexer_discovery: Annotated[ - Optional[bool], pydantic.Field(alias="indexerDiscovery") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Automatically discover indexers in indexer clustering environment.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - sender_unhealthy_time_allowance: Annotated[ - Optional[float], pydantic.Field(alias="senderUnhealthyTimeAllowance") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - max_failed_health_checks: Annotated[ - Optional[float], pydantic.Field(alias="maxFailedHealthChecks") - ] = None - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + token: Optional[str] = None + r"""Wiz Defend Auth token""" - compress: Optional[CompressionOptions] = None - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - indexer_discovery_configs: Annotated[ - Optional[CreateOutputIndexerDiscoveryConfigs], - pydantic.Field(alias="indexerDiscoveryConfigs"), - ] = None - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + wiz_vpc_event_format: Optional[CreateOutputEventFormat] = None + r"""The format of the VPC Flow Log events""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + wiz_vpc_flow_log_format: Optional[str] = None + r"""The format string for VPC Flow Log fields""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16681,83 +16524,81 @@ class CreateOutputOutputSplunkLb(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSplunkLbPqControls], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputWizHecPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_nested_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_nestedFields") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_max_s2_sversion: Annotated[ - Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + template_wiz_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_wiz_environment") ] = None - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" + + template_data_center: Annotated[ + Optional[str], pydantic.Field(alias="__template_data_center") + ] = None + r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" + + template_wiz_sourcetype: Annotated[ + Optional[str], pydantic.Field(alias="__template_wiz_sourcetype") + ] = None + r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - @field_serializer("nested_fields") - def serialize_nested_fields(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.NestedFieldSerializationOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.MaxS2SVersionOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("wiz_sourcetype") + def serialize_wiz_sourcetype(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputWizDefendSourceType(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("wiz_vpc_event_format") + def serialize_wiz_vpc_event_format(self, value): if isinstance(value, str): try: - return models.CompressionOptions(value) + return models.CreateOutputEventFormat(value) except ValueError: return value return value @@ -16797,27 +16638,28 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", - "nestedFields", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", "tls", - "enableMultiMetrics", - "enableACK", - "logFailedRequests", - "maxS2Sversion", - "onBackpressure", - "indexerDiscovery", - "senderUnhealthyTimeAllowance", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", "authType", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "maxFailedHealthChecks", - "compress", - "indexerDiscoveryConfigs", - "excludeSelf", + "token", + "textSecret", + "wiz_vpc_event_format", + "wiz_vpc_flow_log_format", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16830,13 +16672,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", - "__template_nestedFields", - "__template_maxS2Sversion", + "__template_failedRequestLoggingMode", + "__template_wiz_environment", + "__template_data_center", + "__template_wiz_sourcetype", "__template_onBackpressure", - "__template_compress", ] ) serialized = handler(self) @@ -16853,23 +16694,63 @@ def serialize_model(self, handler): return m -class CreateOutputOutputSplunkPqControlsTypedDict(TypedDict): +class CreateOutputOutputSplunkHecType(str, Enum): + r"""Connector type identifier.""" + + SPLUNK_HEC = "splunk_hec" + + +class CreateOutputOutputSplunkHecURLTypedDict(TypedDict): + url: str + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputOutputSplunkHecURL(BaseModel): + url: str + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputSplunkHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSplunkPqControls(BaseModel): +class CreateOutputOutputSplunkHecPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSplunkTypedDict(TypedDict): +class CreateOutputOutputSplunkHecTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSplunk + type: CreateOutputOutputSplunkHecType r"""Connector type identifier.""" - host: str - r"""The hostname of the receiver""" - port: float - r"""The port to connect to on the provided host""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -16878,34 +16759,70 @@ class CreateOutputOutputSplunkTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - nested_fields: NotRequired[NestedFieldSerializationOptions] - r"""How to serialize nested fields into index-time fields""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - enable_ack: NotRequired[bool] - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - max_s2_sversion: NotRequired[MaxS2SVersionOptions] - r"""The highest S2S protocol version to advertise during handshake""" + r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + next_queue: NotRequired[str] + r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" + tcp_routing: NotRequired[str] + r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_failed_health_checks: NotRequired[float] - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - compress: NotRequired[CompressionOptions] - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + url: NotRequired[str] + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputOutputSplunkHecURLTypedDict]] + r"""Splunk HEC Endpoints""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""Splunk HEC authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16928,41 +16845,25 @@ class CreateOutputOutputSplunkTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSplunkPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputSplunkHecPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_nested_fields: NotRequired[str] - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_max_s2_sversion: NotRequired[str] - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputSplunk(BaseModel): +class CreateOutputOutputSplunkHec(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSplunk + type: CreateOutputOutputSplunkHecType r"""Connector type identifier.""" - host: str - r"""The hostname of the receiver""" - - port: float - r"""The port to connect to on the provided host""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -16977,68 +16878,137 @@ class CreateOutputOutputSplunk(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - nested_fields: Annotated[ - Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""How to serialize nested fields into index-time fields""" + r"""Maximum size, in KB, of the request body""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" enable_multi_metrics: Annotated[ Optional[bool], pydantic.Field(alias="enableMultiMetrics") ] = None - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" - enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_s2_sversion: Annotated[ - Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The highest S2S protocol version to advertise during handshake""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + next_queue: Annotated[Optional[str], pydantic.Field(alias="nextQueue")] = None + r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" + + tcp_routing: Annotated[Optional[str], pydantic.Field(alias="tcpRouting")] = None + r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + url: Optional[str] = None + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[CreateOutputOutputSplunkHecURL]] = None + r"""Splunk HEC Endpoints""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - max_failed_health_checks: Annotated[ - Optional[float], pydantic.Field(alias="maxFailedHealthChecks") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - compress: Optional[CompressionOptions] = None - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + token: Optional[str] = None + r"""Splunk HEC authentication token""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17090,65 +17060,45 @@ class CreateOutputOutputSplunk(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSplunkPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputSplunkHecPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_nested_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_nestedFields") - ] = None - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - - template_max_s2_sversion: Annotated[ - Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - @field_serializer("nested_fields") - def serialize_nested_fields(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.NestedFieldSerializationOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.MaxS2SVersionOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -17162,24 +17112,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptions(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -17215,20 +17147,36 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "nestedFields", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "loadBalanced", "tls", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", "enableMultiMetrics", - "enableACK", - "logFailedRequests", - "maxS2Sversion", - "onBackpressure", "authType", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "nextQueue", + "tcpRouting", + "onBackpressure", "description", - "maxFailedHealthChecks", - "compress", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17241,15 +17189,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", - "__template_host", - "__template_port", - "__template_nestedFields", - "__template_maxS2Sversion", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_compress", + "__template_url", ] ) serialized = handler(self) @@ -17266,116 +17209,158 @@ def serialize_model(self, handler): return m -class CreateOutputOutputSyslogProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The network protocol to use for sending out syslog messages""" +class CreateOutputOutputSplunkLbType(str, Enum): + r"""Connector type identifier.""" - # TCP - TCP = "tcp" - # UDP - UDP = "udp" + SPLUNK_LB = "splunk_lb" -class CreateOutputFacility(int, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" +class CreateOutputAuthTokenTypedDict(TypedDict): + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" - # kern - KERN = 0 - # user - USER = 1 - # mail - MAIL = 2 - # daemon - DAEMON = 3 - # auth - AUTH = 4 - # syslog - SYSLOG = 5 - # lpr - LPR = 6 - # news - NEWS = 7 - # uucp - UUCP = 8 - # cron - CRON = 9 - # authpriv - AUTHPRIV = 10 - # ftp - FTP = 11 - # ntp - NTP = 12 - # security - SECURITY = 13 - # console - CONSOLE = 14 - # solaris-cron - SOLARIS_CRON = 15 - # local0 - LOCAL0 = 16 - # local1 - LOCAL1 = 17 - # local2 - LOCAL2 = 18 - # local3 - LOCAL3 = 19 - # local4 - LOCAL4 = 20 - # local5 - LOCAL5 = 21 + +class CreateOutputAuthToken(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "authToken", "textSecret"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputIndexerDiscoveryConfigsTypedDict(TypedDict): + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + site: str + r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" + master_uri: str + r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" + refresh_interval_sec: float + r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" + reject_unauthorized: NotRequired[bool] + r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" + auth_tokens: NotRequired[List[CreateOutputAuthTokenTypedDict]] + r"""Tokens required to authenticate to cluster manager for indexer discovery""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" -class CreateOutputOutputSyslogSeverity(int, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" +class CreateOutputIndexerDiscoveryConfigs(BaseModel): + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - # emergency - EMERGENCY = 0 - # alert - ALERT = 1 - # critical - CRITICAL = 2 - # error - ERROR = 3 - # warning - WARNING = 4 - # notice - NOTICE = 5 - # info - INFO = 6 - # debug - DEBUG = 7 + site: str + r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" + master_uri: Annotated[str, pydantic.Field(alias="masterUri")] + r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" -class CreateOutputMessageFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The syslog message format depending on the receiver's support""" + refresh_interval_sec: Annotated[float, pydantic.Field(alias="refreshIntervalSec")] + r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" - # RFC3164 - RFC3164 = "rfc3164" - # RFC5424 - RFC5424 = "rfc5424" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" + auth_tokens: Annotated[ + Optional[List[CreateOutputAuthToken]], pydantic.Field(alias="authTokens") + ] = None + r"""Tokens required to authenticate to cluster manager for indexer discovery""" -class CreateOutputTimestampFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Timestamp format to use when serializing event's time field""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - # Syslog - SYSLOG = "syslog" - # ISO8601 - ISO8601 = "iso8601" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" -class CreateOutputOutputSyslogPqControlsTypedDict(TypedDict): + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["rejectUnauthorized", "authTokens", "authType", "authToken", "textSecret"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputOutputSplunkLbPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSyslogPqControls(BaseModel): +class CreateOutputOutputSplunkLbPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSyslogTypedDict(TypedDict): +class CreateOutputOutputSplunkLbTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSyslog + type: CreateOutputOutputSplunkLbType r"""Connector type identifier.""" + hosts: List[HostConfOutputSyslogTypedDict] + r"""Set of Splunk indexers to load-balance data to.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -17384,56 +17369,48 @@ class CreateOutputOutputSyslogTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[CreateOutputOutputSyslogProtocol] - r"""The network protocol to use for sending out syslog messages""" - facility: NotRequired[CreateOutputFacility] - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - severity: NotRequired[CreateOutputOutputSyslogSeverity] - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - app_name: NotRequired[str] - r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - message_format: NotRequired[CreateOutputMessageFormat] - r"""The syslog message format depending on the receiver's support""" - timestamp_format: NotRequired[CreateOutputTimestampFormat] - r"""Timestamp format to use when serializing event's time field""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - octet_count_framing: NotRequired[bool] - r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - load_balanced: NotRequired[bool] - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" max_concurrent_senders: NotRequired[float] r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + nested_fields: NotRequired[NestedFieldSerializationOptions] + r"""How to serialize nested fields into index-time fields""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" connection_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" write_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" + enable_multi_metrics: NotRequired[bool] + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + enable_ack: NotRequired[bool] + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + max_s2_sversion: NotRequired[MaxS2SVersionOptions] + r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - max_record_size: NotRequired[float] - r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" - udp_dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + indexer_discovery: NotRequired[bool] + r"""Automatically discover indexers in indexer clustering environment.""" + sender_unhealthy_time_allowance: NotRequired[float] + r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + max_failed_health_checks: NotRequired[float] + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + compress: NotRequired[CompressionOptions] + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + indexer_discovery_configs: NotRequired[CreateOutputIndexerDiscoveryConfigsTypedDict] + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -17456,25 +17433,34 @@ class CreateOutputOutputSyslogTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSyslogPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputSplunkLbPqControlsTypedDict] r"""Persistent queue controls.""" + auth_token: NotRequired[str] + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_nested_fields: NotRequired[str] + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + template_max_s2_sversion: NotRequired[str] + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" -class CreateOutputOutputSyslog(BaseModel): +class CreateOutputOutputSplunkLb(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSyslog + type: CreateOutputOutputSplunkLbType r"""Connector type identifier.""" + hosts: List[HostConfOutputSyslog] + r"""Set of Splunk indexers to load-balance data to.""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -17489,63 +17475,6 @@ class CreateOutputOutputSyslog(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[CreateOutputOutputSyslogProtocol] = None - r"""The network protocol to use for sending out syslog messages""" - - facility: Optional[CreateOutputFacility] = None - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - - severity: Optional[CreateOutputOutputSyslogSeverity] = None - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - - app_name: Annotated[Optional[str], pydantic.Field(alias="appName")] = None - r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - - message_format: Annotated[ - Optional[CreateOutputMessageFormat], pydantic.Field(alias="messageFormat") - ] = None - r"""The syslog message format depending on the receiver's support""" - - timestamp_format: Annotated[ - Optional[CreateOutputTimestampFormat], pydantic.Field(alias="timestampFormat") - ] = None - r"""Timestamp format to use when serializing event's time field""" - - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") - ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - - octet_count_framing: Annotated[ - Optional[bool], pydantic.Field(alias="octetCountFraming") - ] = None - r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") - ] = None - r"""Use to troubleshoot issues with sending data""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - - host: Optional[str] = None - r"""The hostname of the receiver""" - - port: Optional[float] = None - r"""The port to connect to on the provided host""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" - dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None @@ -17561,6 +17490,16 @@ class CreateOutputOutputSyslog(BaseModel): ] = None r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + nested_fields: Annotated[ + Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + ] = None + r"""How to serialize nested fields into index-time fields""" + + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") + ] = None + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: Annotated[ Optional[float], pydantic.Field(alias="connectionTimeout") ] = None @@ -17571,28 +17510,67 @@ class CreateOutputOutputSyslog(BaseModel): ) r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + enable_multi_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="enableMultiMetrics") + ] = None + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + + enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") + ] = None + r"""Use to troubleshoot issues with sending data""" + + max_s2_sversion: Annotated[ + Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + ] = None + r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") + indexer_discovery: Annotated[ + Optional[bool], pydantic.Field(alias="indexerDiscovery") ] = None - r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" + r"""Automatically discover indexers in indexer clustering environment.""" - udp_dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="udpDnsResolvePeriodSec") + sender_unhealthy_time_allowance: Annotated[ + Optional[float], pydantic.Field(alias="senderUnhealthyTimeAllowance") ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" + r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + max_failed_health_checks: Annotated[ + Optional[float], pydantic.Field(alias="maxFailedHealthChecks") + ] = None + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + + compress: Optional[CompressionOptions] = None + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + + indexer_discovery_configs: Annotated[ + Optional[CreateOutputIndexerDiscoveryConfigs], + pydantic.Field(alias="indexerDiscoveryConfigs"), + ] = None + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17644,80 +17622,83 @@ class CreateOutputOutputSyslog(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSyslogPqControls], pydantic.Field(alias="pqControls") + Optional[CreateOutputOutputSplunkLbPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_nested_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_nestedFields") + ] = None + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_max_s2_sversion: Annotated[ + Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + ] = None + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateOutputOutputSyslogProtocol(value) - except ValueError: - return value - return value + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - @field_serializer("facility") - def serialize_facility(self, value): + @field_serializer("nested_fields") + def serialize_nested_fields(self, value): if isinstance(value, str): try: - return models.CreateOutputFacility(value) + return models.NestedFieldSerializationOptions(value) except ValueError: return value return value - @field_serializer("severity") - def serialize_severity(self, value): + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputSyslogSeverity(value) + return models.MaxS2SVersionOptions(value) except ValueError: return value return value - @field_serializer("message_format") - def serialize_message_format(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputMessageFormat(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("timestamp_format") - def serialize_timestamp_format(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputTimestampFormat(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptions(value) except ValueError: return value return value @@ -17757,31 +17738,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "facility", - "severity", - "appName", - "messageFormat", - "timestampFormat", - "throttleRatePerSec", - "octetCountFraming", - "logFailedRequests", - "description", - "loadBalanced", - "host", - "port", - "excludeSelf", - "hosts", "dnsResolvePeriodSec", "loadBalanceStatsPeriodSec", "maxConcurrentSenders", + "nestedFields", + "throttleRatePerSec", "connectionTimeout", "writeTimeout", "tls", + "enableMultiMetrics", + "enableACK", + "logFailedRequests", + "maxS2Sversion", "onBackpressure", - "maxRecordSize", - "udpDnsResolvePeriodSec", - "enableIpSpoofing", + "indexerDiscovery", + "senderUnhealthyTimeAllowance", + "authType", + "description", + "maxFailedHealthChecks", + "compress", + "indexerDiscoveryConfigs", + "excludeSelf", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17794,149 +17771,46 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_onBackpressure", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputDevnullType(str, Enum): - r"""Connector type identifier.""" - - DEVNULL = "devnull" - - -class CreateOutputOutputDevnullTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputDevnullType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateOutputOutputDevnull(BaseModel): - id: str - r"""Unique ID for this output""" - - type: CreateOutputOutputDevnullType - r"""Connector type identifier.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputOutputSentinelType(str, Enum): - r"""Connector type identifier.""" - - SENTINEL = "sentinel" - - -class CreateOutputAuthType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Discriminator value.""" - - OAUTH = "oauth" - - -class CreateOutputEndpointConfiguration(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Enter the data collection endpoint URL or the individual ID""" + "authToken", + "textSecret", + "__template_streamtags", + "__template_nestedFields", + "__template_maxS2Sversion", + "__template_onBackpressure", + "__template_compress", + ] + ) + serialized = handler(self) + m = {} - # URL - URL = "url" - # ID - ID = "ID" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val -class CreateOutputOutputSentinelFormat(str, Enum, metaclass=utils.OpenEnumMeta): - NDJSON = "ndjson" - JSON_ARRAY = "json_array" - CUSTOM = "custom" - ADVANCED = "advanced" + return m -class CreateOutputOutputSentinelPqControlsTypedDict(TypedDict): +class CreateOutputOutputSplunkPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputOutputSentinelPqControls(BaseModel): +class CreateOutputOutputSplunkPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputOutputSentinelTypedDict(TypedDict): +class CreateOutputOutputSplunkTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputSentinelType + type: TypeOptionsSplunk r"""Connector type identifier.""" - login_url: str - r"""URL for OAuth""" - secret: str - r"""Secret parameter value to pass in request body""" - client_id: str - r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" - endpoint_url_configuration: CreateOutputEndpointConfiguration - r"""Enter the data collection endpoint URL or the individual ID""" + host: str + r"""The hostname of the receiver""" + port: float + r"""The port to connect to on the provided host""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -17945,79 +17819,34 @@ class CreateOutputOutputSentinelTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + nested_fields: NotRequired[NestedFieldSerializationOptions] + r"""How to serialize nested fields into index-time fields""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + enable_multi_metrics: NotRequired[bool] + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + enable_ack: NotRequired[bool] + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + max_s2_sversion: NotRequired[MaxS2SVersionOptions] + r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputAuthType] - r"""Discriminator value.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - scope: NotRequired[str] - r"""Scope to pass in the OAuth request""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - format_: NotRequired[CreateOutputOutputSentinelFormat] - custom_source_expression: NotRequired[str] - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" - custom_drop_when_null: NotRequired[bool] - r"""Whether to drop events when the source expression evaluates to null""" - custom_event_delimiter: NotRequired[str] - r"""Delimiter string to insert between individual events. Defaults to newline character.""" - custom_content_type: NotRequired[str] - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" - custom_payload_expression: NotRequired[str] - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" - advanced_content_type: NotRequired[str] - r"""HTTP content-type header value""" - format_event_code: NotRequired[str] - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" - format_payload_code: NotRequired[str] - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + max_failed_health_checks: NotRequired[float] + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + compress: NotRequired[CompressionOptions] + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -18040,238 +17869,117 @@ class CreateOutputOutputSentinelTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputSentinelPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputOutputSplunkPqControlsTypedDict] r"""Persistent queue controls.""" - url: NotRequired[str] - r"""URL to send events to. Can be overwritten by an event's __url field.""" - dcr_id: NotRequired[str] - r"""Immutable ID for the Data Collection Rule (DCR)""" - dce_endpoint: NotRequired[str] - r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" - stream_name: NotRequired[str] - r"""The name of the stream (Sentinel table) in which to store the events""" + auth_token: NotRequired[str] + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_nested_fields: NotRequired[str] + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + template_max_s2_sversion: NotRequired[str] + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: NotRequired[str] - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" - template_scope: NotRequired[str] - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_dcr_id: NotRequired[str] - r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" - template_dce_endpoint: NotRequired[str] - r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - - -class CreateOutputOutputSentinel(BaseModel): - id: str - r"""Unique ID for this output""" - - type: CreateOutputOutputSentinelType - r"""Connector type identifier.""" - - login_url: Annotated[str, pydantic.Field(alias="loginUrl")] - r"""URL for OAuth""" - - secret: str - r"""Secret parameter value to pass in request body""" - - client_id: str - r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" - - endpoint_url_configuration: Annotated[ - CreateOutputEndpointConfiguration, - pydantic.Field(alias="endpointURLConfiguration"), - ] - r"""Enter the data collection endpoint URL or the individual ID""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" +class CreateOutputOutputSplunk(BaseModel): + id: str + r"""Unique ID for this output""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + type: TypeOptionsSplunk + r"""Connector type identifier.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + host: str + r"""The hostname of the receiver""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + port: float + r"""The port to connect to on the provided host""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - auth_type: Annotated[ - Optional[CreateOutputAuthType], pydantic.Field(alias="authType") - ] = None - r"""Discriminator value.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") + nested_fields: Annotated[ + Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + r"""How to serialize nested fields into index-time fields""" - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - - scope: Optional[str] = None - r"""Scope to pass in the OAuth request""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - format_: Annotated[ - Optional[CreateOutputOutputSentinelFormat], pydantic.Field(alias="format") + enable_multi_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="enableMultiMetrics") ] = None + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - custom_source_expression: Annotated[ - Optional[str], pydantic.Field(alias="customSourceExpression") - ] = None - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - custom_drop_when_null: Annotated[ - Optional[bool], pydantic.Field(alias="customDropWhenNull") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Whether to drop events when the source expression evaluates to null""" + r"""Use to troubleshoot issues with sending data""" - custom_event_delimiter: Annotated[ - Optional[str], pydantic.Field(alias="customEventDelimiter") + max_s2_sversion: Annotated[ + Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") ] = None - r"""Delimiter string to insert between individual events. Defaults to newline character.""" + r"""The highest S2S protocol version to advertise during handshake""" - custom_content_type: Annotated[ - Optional[str], pydantic.Field(alias="customContentType") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + r"""How to handle events when all receivers are exerting backpressure""" - custom_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="customPayloadExpression") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - advanced_content_type: Annotated[ - Optional[str], pydantic.Field(alias="advancedContentType") - ] = None - r"""HTTP content-type header value""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - format_event_code: Annotated[ - Optional[str], pydantic.Field(alias="formatEventCode") + max_failed_health_checks: Annotated[ + Optional[float], pydantic.Field(alias="maxFailedHealthChecks") ] = None - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - format_payload_code: Annotated[ - Optional[str], pydantic.Field(alias="formatPayloadCode") - ] = None - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + compress: Optional[CompressionOptions] = None + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18323,124 +18031,92 @@ class CreateOutputOutputSentinel(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputSentinelPqControls], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputSplunkPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" - url: Optional[str] = None - r"""URL to send events to. Can be overwritten by an event's __url field.""" - - dcr_id: Annotated[Optional[str], pydantic.Field(alias="dcrID")] = None - r"""Immutable ID for the Data Collection Rule (DCR)""" - - dce_endpoint: Annotated[Optional[str], pydantic.Field(alias="dceEndpoint")] = None - r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - stream_name: Annotated[Optional[str], pydantic.Field(alias="streamName")] = None - r"""The name of the stream (Sentinel table) in which to store the events""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - - template_refresh_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_refreshUrl") - ] = None - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_client_id") - ] = None - r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" - - template_scope: Annotated[ - Optional[str], pydantic.Field(alias="__template_scope") - ] = None - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_dcr_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_dcrID") + template_nested_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_nestedFields") ] = None - r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_dce_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_dceEndpoint") + template_max_s2_sversion: Annotated[ + Optional[str], pydantic.Field(alias="__template_maxS2Sversion") ] = None - r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + @field_serializer("nested_fields") + def serialize_nested_fields(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.NestedFieldSerializationOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.MaxS2SVersionOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputAuthType(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("endpoint_url_configuration") - def serialize_endpoint_url_configuration(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputEndpointConfiguration(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputSentinelFormat(value) + return models.CompressionOptions(value) except ValueError: return value return value @@ -18480,40 +18156,20 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "keepAlive", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "nestedFields", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "tls", + "enableMultiMetrics", + "enableACK", + "logFailedRequests", + "maxS2Sversion", "onBackpressure", "authType", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "scope", - "totalMemoryLimitKB", "description", - "format", - "customSourceExpression", - "customDropWhenNull", - "customEventDelimiter", - "customContentType", - "customPayloadExpression", - "advancedContentType", - "formatEventCode", - "formatPayloadCode", + "maxFailedHealthChecks", + "compress", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -18526,22 +18182,15 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "url", - "dcrID", - "dceEndpoint", - "streamName", + "authToken", + "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_host", + "__template_port", + "__template_nestedFields", + "__template_maxS2Sversion", "__template_onBackpressure", - "__template_loginUrl", - "__template_secret", - "__template_refreshUrl", - "__template_client_id", - "__template_scope", - "__template_url", - "__template_dcrID", - "__template_dceEndpoint", - "__template_streamName", + "__template_compress", ] ) serialized = handler(self) @@ -18558,173 +18207,174 @@ def serialize_model(self, handler): return m -class CreateOutputOutputWebhookType2(str, Enum): - r"""Connector type identifier.""" - - WEBHOOK = "webhook" - - -class CreateOutputOutputWebhookFormat2(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How to format events before sending out""" - - # NDJSON (Newline Delimited JSON) - NDJSON = "ndjson" - # JSON Array - JSON_ARRAY = "json_array" - # Custom - CUSTOM = "custom" - # Advanced - ADVANCED = "advanced" - - -class CreateOutputOutputWebhookAuthenticationType2( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method to use for the HTTP request""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth - OAUTH = "oauth" - - -class CreateOutputOutputWebhookPqControls2TypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputOutputWebhookPqControls2(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputOutputWebhookURL2TypedDict(TypedDict): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - -class CreateOutputOutputWebhookURL2(BaseModel): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" +class CreateOutputOutputSyslogProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The network protocol to use for sending out syslog messages""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + # TCP + TCP = "tcp" + # UDP + UDP = "udp" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateOutputFacility(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + # kern + KERN = 0 + # user + USER = 1 + # mail + MAIL = 2 + # daemon + DAEMON = 3 + # auth + AUTH = 4 + # syslog + SYSLOG = 5 + # lpr + LPR = 6 + # news + NEWS = 7 + # uucp + UUCP = 8 + # cron + CRON = 9 + # authpriv + AUTHPRIV = 10 + # ftp + FTP = 11 + # ntp + NTP = 12 + # security + SECURITY = 13 + # console + CONSOLE = 14 + # solaris-cron + SOLARIS_CRON = 15 + # local0 + LOCAL0 = 16 + # local1 + LOCAL1 = 17 + # local2 + LOCAL2 = 18 + # local3 + LOCAL3 = 19 + # local4 + LOCAL4 = 20 + # local5 + LOCAL5 = 21 - return m +class CreateOutputOutputSyslogSeverity(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" -class CreateOutputOutputWebhookWebhook2TypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputOutputWebhookType2 - r"""Connector type identifier.""" - urls: List[CreateOutputOutputWebhookURL2TypedDict] - r"""Webhook URLs""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - format_: NotRequired[CreateOutputOutputWebhookFormat2] - r"""How to format events before sending out""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputOutputWebhookAuthenticationType2] - r"""Authentication method to use for the HTTP request""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + # emergency + EMERGENCY = 0 + # alert + ALERT = 1 + # critical + CRITICAL = 2 + # error + ERROR = 3 + # warning + WARNING = 4 + # notice + NOTICE = 5 + # info + INFO = 6 + # debug + DEBUG = 7 + + +class CreateOutputMessageFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The syslog message format depending on the receiver's support""" + + # RFC3164 + RFC3164 = "rfc3164" + # RFC5424 + RFC5424 = "rfc5424" + + +class CreateOutputTimestampFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Timestamp format to use when serializing event's time field""" + + # Syslog + SYSLOG = "syslog" + # ISO8601 + ISO8601 = "iso8601" + + +class CreateOutputOutputSyslogPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputSyslogPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputSyslogTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: TypeOptionsSyslog + r"""Connector type identifier.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + protocol: NotRequired[CreateOutputOutputSyslogProtocol] + r"""The network protocol to use for sending out syslog messages""" + facility: NotRequired[CreateOutputFacility] + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" + severity: NotRequired[CreateOutputOutputSyslogSeverity] + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" + app_name: NotRequired[str] + r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" + message_format: NotRequired[CreateOutputMessageFormat] + r"""The syslog message format depending on the receiver's support""" + timestamp_format: NotRequired[CreateOutputTimestampFormat] + r"""Timestamp format to use when serializing event's time field""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + octet_count_framing: NotRequired[bool] + r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_source_expression: NotRequired[str] - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" - custom_drop_when_null: NotRequired[bool] - r"""Whether to drop events when the source expression evaluates to null""" - custom_event_delimiter: NotRequired[str] - r"""Delimiter string to insert between individual events. Defaults to newline character.""" - custom_content_type: NotRequired[str] - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" - custom_payload_expression: NotRequired[str] - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" - advanced_content_type: NotRequired[str] - r"""HTTP content-type header value""" - format_event_code: NotRequired[str] - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" - format_payload_code: NotRequired[str] - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + load_balanced: NotRequired[bool] + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + max_record_size: NotRequired[float] + r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" + udp_dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -18747,78 +18397,25 @@ class CreateOutputOutputWebhookWebhook2TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputWebhookPqControls2TypedDict] + pq_controls: NotRequired[CreateOutputOutputSyslogPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" - secret: NotRequired[str] - r"""Secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - url: NotRequired[str] - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: NotRequired[str] - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputOutputWebhookWebhook2(BaseModel): +class CreateOutputOutputSyslog(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputWebhookType2 + type: TypeOptionsSyslog r"""Connector type identifier.""" - urls: List[CreateOutputOutputWebhookURL2] - r"""Webhook URLs""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -18833,157 +18430,110 @@ class CreateOutputOutputWebhookWebhook2(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" - - format_: Annotated[ - Optional[CreateOutputOutputWebhookFormat2], pydantic.Field(alias="format") - ] = None - r"""How to format events before sending out""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + protocol: Optional[CreateOutputOutputSyslogProtocol] = None + r"""The network protocol to use for sending out syslog messages""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + facility: Optional[CreateOutputFacility] = None + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + severity: Optional[CreateOutputOutputSyslogSeverity] = None + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None + app_name: Annotated[Optional[str], pydantic.Field(alias="appName")] = None + r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + message_format: Annotated[ + Optional[CreateOutputMessageFormat], pydantic.Field(alias="messageFormat") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""The syslog message format depending on the receiver's support""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + timestamp_format: Annotated[ + Optional[CreateOutputTimestampFormat], pydantic.Field(alias="timestampFormat") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Timestamp format to use when serializing event's time field""" - auth_type: Annotated[ - Optional[CreateOutputOutputWebhookAuthenticationType2], - pydantic.Field(alias="authType"), + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Authentication method to use for the HTTP request""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + octet_count_framing: Annotated[ + Optional[bool], pydantic.Field(alias="octetCountFraming") + ] = None + r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Use to troubleshoot issues with sending data""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + host: Optional[str] = None + r"""The hostname of the receiver""" - custom_source_expression: Annotated[ - Optional[str], pydantic.Field(alias="customSourceExpression") + port: Optional[float] = None + r"""The port to connect to on the provided host""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - custom_drop_when_null: Annotated[ - Optional[bool], pydantic.Field(alias="customDropWhenNull") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Whether to drop events when the source expression evaluates to null""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - custom_event_delimiter: Annotated[ - Optional[str], pydantic.Field(alias="customEventDelimiter") + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") ] = None - r"""Delimiter string to insert between individual events. Defaults to newline character.""" + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - custom_content_type: Annotated[ - Optional[str], pydantic.Field(alias="customContentType") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - custom_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="customPayloadExpression") + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + r"""How to handle events when all receivers are exerting backpressure""" - advanced_content_type: Annotated[ - Optional[str], pydantic.Field(alias="advancedContentType") + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") ] = None - r"""HTTP content-type header value""" + r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" - format_event_code: Annotated[ - Optional[str], pydantic.Field(alias="formatEventCode") + udp_dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="udpDnsResolvePeriodSec") ] = None - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" - format_payload_code: Annotated[ - Optional[str], pydantic.Field(alias="formatPayloadCode") + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") ] = None - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19035,177 +18585,80 @@ class CreateOutputOutputWebhookWebhook2(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputWebhookPqControls2], - pydantic.Field(alias="pqControls"), + Optional[CreateOutputOutputSyslogPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - - secret: Optional[str] = None - r"""Secret parameter value to pass in request body""" - - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") - ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") - ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), - ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - - url: Optional[str] = None - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - - template_refresh_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_refreshUrl") - ] = None - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateOutputOutputSyslogProtocol(value) + except ValueError: + return value + return value - @field_serializer("method") - def serialize_method(self, value): + @field_serializer("facility") + def serialize_facility(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.CreateOutputFacility(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("severity") + def serialize_severity(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputWebhookFormat2(value) + return models.CreateOutputOutputSyslogSeverity(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CreateOutputMessageFormat(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("timestamp_format") + def serialize_timestamp_format(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputTimestampFormat(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputWebhookAuthenticationType2(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -19245,38 +18698,31 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "format", - "keepAlive", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", + "protocol", + "facility", + "severity", + "appName", + "messageFormat", + "timestampFormat", + "throttleRatePerSec", + "octetCountFraming", + "logFailedRequests", + "description", + "loadBalanced", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", + "connectionTimeout", + "writeTimeout", "tls", - "totalMemoryLimitKB", - "loadBalanced", - "description", - "customSourceExpression", - "customDropWhenNull", - "customEventDelimiter", - "customContentType", - "customPayloadExpression", - "advancedContentType", - "formatEventCode", - "formatPayloadCode", + "onBackpressure", + "maxRecordSize", + "udpDnsResolvePeriodSec", + "enableIpSpoofing", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -19289,34 +18735,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", - "secret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "url", - "excludeSelf", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_host", + "__template_port", "__template_onBackpressure", - "__template_loginUrl", - "__template_secret", - "__template_refreshUrl", - "__template_url", ] ) serialized = handler(self) @@ -19333,76 +18755,66 @@ def serialize_model(self, handler): return m -class CreateOutputOutputWebhookType1(str, Enum): +class CreateOutputOutputDevnullType(str, Enum): r"""Connector type identifier.""" - WEBHOOK = "webhook" - - -class CreateOutputOutputWebhookFormat1(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How to format events before sending out""" - - # NDJSON (Newline Delimited JSON) - NDJSON = "ndjson" - # JSON Array - JSON_ARRAY = "json_array" - # Custom - CUSTOM = "custom" - # Advanced - ADVANCED = "advanced" - - -class CreateOutputOutputWebhookAuthenticationType1( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method to use for the HTTP request""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth - OAUTH = "oauth" + DEVNULL = "devnull" -class CreateOutputOutputWebhookPqControls1TypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputOutputDevnullTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputDevnullType + r"""Connector type identifier.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class CreateOutputOutputWebhookPqControls1(BaseModel): - r"""Persistent queue controls.""" +class CreateOutputOutputDevnull(BaseModel): + id: str + r"""Unique ID for this output""" + type: CreateOutputOutputDevnullType + r"""Connector type identifier.""" -class CreateOutputOutputWebhookURL1TypedDict(TypedDict): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" -class CreateOutputOutputWebhookURL1(BaseModel): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "__template_streamtags", + ] + ) serialized = handler(self) m = {} @@ -19417,13 +18829,60 @@ def serialize_model(self, handler): return m -class CreateOutputOutputWebhookWebhook1TypedDict(TypedDict): +class CreateOutputOutputSentinelType(str, Enum): + r"""Connector type identifier.""" + + SENTINEL = "sentinel" + + +class CreateOutputAuthType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Discriminator value.""" + + OAUTH = "oauth" + + +class CreateOutputOAuthSecretSource(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Enter the OAuth secret directly, or select a stored text secret""" + + INLINE = "inline" + SECRET = "secret" + + +class CreateOutputEndpointConfiguration(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Enter the data collection endpoint URL or the individual ID""" + + # URL + URL = "url" + # ID + ID = "ID" + + +class CreateOutputOutputSentinelFormat(str, Enum, metaclass=utils.OpenEnumMeta): + NDJSON = "ndjson" + JSON_ARRAY = "json_array" + CUSTOM = "custom" + ADVANCED = "advanced" + + +class CreateOutputOutputSentinelPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputOutputSentinelPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputOutputSentinelTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputOutputWebhookType1 + type: CreateOutputOutputSentinelType r"""Connector type identifier.""" - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + login_url: str + r"""URL for OAuth""" + client_id: str + r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" + endpoint_url_configuration: CreateOutputEndpointConfiguration + r"""Enter the data collection endpoint URL or the individual ID""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -19432,16 +18891,12 @@ class CreateOutputOutputWebhookWebhook1TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - format_: NotRequired[CreateOutputOutputWebhookFormat1] - r"""How to format events before sending out""" keep_alive: NotRequired[bool] r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: NotRequired[bool] @@ -19474,16 +18929,27 @@ class CreateOutputOutputWebhookWebhook1TypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputOutputWebhookAuthenticationType1] - r"""Authentication method to use for the HTTP request""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + auth_type: NotRequired[CreateOutputAuthType] + r"""Discriminator value.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + oauth_secret_source: NotRequired[CreateOutputOAuthSecretSource] + r"""Enter the OAuth secret directly, or select a stored text secret""" + scope: NotRequired[str] + r"""Scope to pass in the OAuth request""" total_memory_limit_kb: NotRequired[float] r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" description: NotRequired[str] r"""Optional description for this configuration.""" + format_: NotRequired[CreateOutputOutputSentinelFormat] custom_source_expression: NotRequired[str] r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" custom_drop_when_null: NotRequired[bool] @@ -19522,52 +18988,20 @@ class CreateOutputOutputWebhookWebhook1TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputOutputWebhookPqControls1TypedDict] + pq_controls: NotRequired[CreateOutputOutputSentinelPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" secret: NotRequired[str] r"""Secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputOutputWebhookURL1TypedDict]] - r"""Webhook URLs""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret value""" + url: NotRequired[str] + r"""URL to send events to. Can be overwritten by an event's __url field.""" + dcr_id: NotRequired[str] + r"""Immutable ID for the Data Collection Rule (DCR)""" + dce_endpoint: NotRequired[str] + r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" + stream_name: NotRequired[str] + r"""The name of the stream (Sentinel table) in which to store the events""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] @@ -19576,23 +19010,42 @@ class CreateOutputOutputWebhookWebhook1TypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_login_url: NotRequired[str] r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_refresh_url: NotRequired[str] r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" + template_scope: NotRequired[str] + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_url: NotRequired[str] r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_dcr_id: NotRequired[str] + r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + template_dce_endpoint: NotRequired[str] + r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" -class CreateOutputOutputWebhookWebhook1(BaseModel): +class CreateOutputOutputSentinel(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputOutputWebhookType1 + type: CreateOutputOutputSentinelType r"""Connector type identifier.""" - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + login_url: Annotated[str, pydantic.Field(alias="loginUrl")] + r"""URL for OAuth""" + + client_id: str + r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" + + endpoint_url_configuration: Annotated[ + CreateOutputEndpointConfiguration, + pydantic.Field(alias="endpointURLConfiguration"), + ] + r"""Enter the data collection endpoint URL or the individual ID""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -19608,14 +19061,6 @@ class CreateOutputOutputWebhookWebhook1(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" - - format_: Annotated[ - Optional[CreateOutputOutputWebhookFormat1], pydantic.Field(alias="format") - ] = None - r"""How to format events before sending out""" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None r"""Disable to close the connection immediately after sending the outgoing request""" @@ -19625,7 +19070,7 @@ class CreateOutputOutputWebhookWebhook1(BaseModel): max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") @@ -19699,27 +19144,50 @@ class CreateOutputOutputWebhookWebhook1(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[CreateOutputOutputWebhookAuthenticationType1], - pydantic.Field(alias="authType"), + Optional[CreateOutputAuthType], pydantic.Field(alias="authType") ] = None - r"""Authentication method to use for the HTTP request""" + r"""Discriminator value.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + oauth_secret_source: Annotated[ + Optional[CreateOutputOAuthSecretSource], + pydantic.Field(alias="oauthSecretSource"), + ] = None + r"""Enter the OAuth secret directly, or select a stored text secret""" + + scope: Optional[str] = None + r"""Scope to pass in the OAuth request""" total_memory_limit_kb: Annotated[ Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - description: Optional[str] = None r"""Optional description for this configuration.""" + format_: Annotated[ + Optional[CreateOutputOutputSentinelFormat], pydantic.Field(alias="format") + ] = None + custom_source_expression: Annotated[ Optional[str], pydantic.Field(alias="customSourceExpression") ] = None @@ -19810,100 +19278,30 @@ class CreateOutputOutputWebhookWebhook1(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputOutputWebhookPqControls1], + Optional[CreateOutputOutputSentinelPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - secret: Optional[str] = None r"""Secret parameter value to pass in request body""" - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") - ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") - ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + r"""Select or create a stored text secret for the OAuth secret value""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + url: Optional[str] = None + r"""URL to send events to. Can be overwritten by an event's __url field.""" - urls: Optional[List[CreateOutputOutputWebhookURL1]] = None - r"""Webhook URLs""" + dcr_id: Annotated[Optional[str], pydantic.Field(alias="dcrID")] = None + r"""Immutable ID for the Data Collection Rule (DCR)""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + dce_endpoint: Annotated[Optional[str], pydantic.Field(alias="dceEndpoint")] = None + r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + stream_name: Annotated[Optional[str], pydantic.Field(alias="streamName")] = None + r"""The name of the stream (Sentinel table) in which to store the events""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") @@ -19925,62 +19323,96 @@ class CreateOutputOutputWebhookWebhook1(BaseModel): ] = None r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: Annotated[ Optional[str], pydantic.Field(alias="__template_refreshUrl") ] = None r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_client_id") + ] = None + r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" + + template_scope: Annotated[ + Optional[str], pydantic.Field(alias="__template_scope") + ] = None + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - @field_serializer("method") - def serialize_method(self, value): + template_dcr_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_dcrID") + ] = None + r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + + template_dce_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_dceEndpoint") + ] = None + r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") + ] = None + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputWebhookFormat1(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CreateOutputAuthType(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("oauth_secret_source") + def serialize_oauth_secret_source(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputOAuthSecretSource(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("endpoint_url_configuration") + def serialize_endpoint_url_configuration(self, value): + if isinstance(value, str): + try: + return models.CreateOutputEndpointConfiguration(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.CreateOutputOutputWebhookAuthenticationType1(value) + return models.CreateOutputOutputSentinelFormat(value) except ValueError: return value return value @@ -20020,8 +19452,6 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "format", "keepAlive", "concurrency", "maxPayloadSizeKB", @@ -20040,10 +19470,15 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "authType", - "tls", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "oauthSecretSource", + "scope", "totalMemoryLimitKB", - "loadBalanced", "description", + "format", "customSourceExpression", "customDropWhenNull", "customEventDelimiter", @@ -20064,34 +19499,24 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", "secret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "oauthTextSecret", + "url", + "dcrID", + "dceEndpoint", + "streamName", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", "__template_loginUrl", - "__template_secret", "__template_refreshUrl", + "__template_client_id", + "__template_scope", + "__template_secret", "__template_url", + "__template_dcrID", + "__template_dceEndpoint", + "__template_streamName", ] ) serialized = handler(self) @@ -20108,27 +19533,41 @@ def serialize_model(self, handler): return m -CreateOutputOutputWebhookUnionTypedDict = TypeAliasType( - "CreateOutputOutputWebhookUnionTypedDict", - Union[ - CreateOutputOutputWebhookWebhook1TypedDict, - CreateOutputOutputWebhookWebhook2TypedDict, - ], -) - +class CreateOutputOutputWebhookType2(str, Enum): + r"""Connector type identifier.""" -CreateOutputOutputWebhookUnion = TypeAliasType( - "CreateOutputOutputWebhookUnion", - Union[CreateOutputOutputWebhookWebhook1, CreateOutputOutputWebhookWebhook2], -) + WEBHOOK = "webhook" -class CreateOutputOutputDefaultType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputOutputWebhookFormat2(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How to format events before sending out""" - DEFAULT = "default" + # NDJSON (Newline Delimited JSON) + NDJSON = "ndjson" + # JSON Array + JSON_ARRAY = "json_array" + # Custom + CUSTOM = "custom" + # Advanced + ADVANCED = "advanced" +try: + CreateOutputOutputSns.model_rebuild() +except NameError: + pass +try: + CreateOutputRule.model_rebuild() +except NameError: + pass +try: + CreateOutputOutputRouter.model_rebuild() +except NameError: + pass +try: + CreateOutputOutputGraphite.model_rebuild() +except NameError: + pass try: CreateOutputOutputStatsdExt.model_rebuild() except NameError: @@ -20301,19 +19740,3 @@ class CreateOutputOutputDefaultType(str, Enum): CreateOutputOutputSentinel.model_rebuild() except NameError: pass -try: - CreateOutputOutputWebhookURL2.model_rebuild() -except NameError: - pass -try: - CreateOutputOutputWebhookWebhook2.model_rebuild() -except NameError: - pass -try: - CreateOutputOutputWebhookURL1.model_rebuild() -except NameError: - pass -try: - CreateOutputOutputWebhookWebhook1.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/createoutputsystembypack_outputstatsdext_type.py b/src/cribl_control_plane/models/createoutputsystembypack_outputsns_pqcontrols.py similarity index 97% rename from src/cribl_control_plane/models/createoutputsystembypack_outputstatsdext_type.py rename to src/cribl_control_plane/models/createoutputsystembypack_outputsns_pqcontrols.py index eaaabce4e..2f8a2326c 100644 --- a/src/cribl_control_plane/models/createoutputsystembypack_outputstatsdext_type.py +++ b/src/cribl_control_plane/models/createoutputsystembypack_outputsns_pqcontrols.py @@ -4,8 +4,8 @@ from .acknowledgmentsoptions import AcknowledgmentsOptions from .authenticationmethodoptionsapi import AuthenticationMethodOptionsAPI from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionsautosecret import AuthenticationMethodOptionsAutoSecret from .authenticationmethodoptionss3collectorconf import ( @@ -42,7 +42,6 @@ ) from .dataformatoptions import DataFormatOptions from .datapageversionoptions import DataPageVersionOptions -from .destinationprotocoloptions import DestinationProtocolOptions from .diskspaceprotectionoptions import DiskSpaceProtectionOptions from .extrahttpheaderconfinputelastic import ( ExtraHTTPHeaderConfInputElastic, @@ -143,6 +142,325 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict +class CreateOutputSystemByPackOutputDatabricksZerobusType(str, Enum): + r"""Connector type identifier.""" + + DATABRICKS_ZEROBUS = "databricks_zerobus" + + +class CreateOutputSystemByPackOutputDatabricksZerobusPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputDatabricksZerobusPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputDatabricksZerobusTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputDatabricksZerobusType + r"""Connector type identifier.""" + workspace_url: str + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" + workspace_id: str + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" + zerobus_endpoint: str + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + client_id: str + r"""OAuth client ID of the service principal authorized to write to the target table""" + client_text_secret: str + r"""OAuth client secret of the service principal""" + table_name: str + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + max_batch_size_kb: NotRequired[int] + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" + max_batch_records: NotRequired[int] + r"""Maximum number of records to include in a single ingest batch""" + max_buffered_kb: NotRequired[int] + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" + max_inflight_batches: NotRequired[int] + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" + flush_period_sec: NotRequired[int] + r"""Maximum time, in seconds, to hold a batch before sending it""" + ack_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" + connection_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputDatabricksZerobusPqControlsTypedDict + ] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + +class CreateOutputSystemByPackOutputDatabricksZerobus(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputSystemByPackOutputDatabricksZerobusType + r"""Connector type identifier.""" + + workspace_url: Annotated[str, pydantic.Field(alias="workspaceUrl")] + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" + + workspace_id: Annotated[str, pydantic.Field(alias="workspaceId")] + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" + + zerobus_endpoint: Annotated[str, pydantic.Field(alias="zerobusEndpoint")] + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""OAuth client ID of the service principal authorized to write to the target table""" + + client_text_secret: Annotated[str, pydantic.Field(alias="clientTextSecret")] + r"""OAuth client secret of the service principal""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + max_batch_size_kb: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchSizeKB") + ] = None + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" + + max_batch_records: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchRecords") + ] = None + r"""Maximum number of records to include in a single ingest batch""" + + max_buffered_kb: Annotated[Optional[int], pydantic.Field(alias="maxBufferedKB")] = ( + None + ) + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" + + max_inflight_batches: Annotated[ + Optional[int], pydantic.Field(alias="maxInflightBatches") + ] = None + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" + + flush_period_sec: Annotated[ + Optional[int], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time, in seconds, to hold a batch before sending it""" + + ack_timeout_sec: Annotated[Optional[int], pydantic.Field(alias="ackTimeoutSec")] = ( + None + ) + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" + + connection_timeout_sec: Annotated[ + Optional[int], pydantic.Field(alias="connectionTimeoutSec") + ] = None + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputDatabricksZerobusPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "maxBatchSizeKB", + "maxBatchRecords", + "maxBufferedKB", + "maxInflightBatches", + "flushPeriodSec", + "ackTimeoutSec", + "connectionTimeoutSec", + "onBackpressure", + "description", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_onBackpressure", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + class CreateOutputSystemByPackOutputIbmCloudS3Type(str, Enum): r"""Connector type identifier.""" @@ -7965,7 +8283,7 @@ class CreateOutputSystemByPackOutputSentinelOneAiSiemTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -8128,7 +8446,7 @@ class CreateOutputSystemByPackOutputSentinelOneAiSiem(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -8310,7 +8628,7 @@ def serialize_failed_request_logging_mode(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -8442,53 +8760,42 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputDynatraceOtlpType(str, Enum): +class CreateOutputSystemByPackOutputTraversalOtlpType(str, Enum): r"""Connector type identifier.""" - DYNATRACE_OTLP = "dynatrace_otlp" + TRAVERSAL_OTLP = "traversal_otlp" -class CreateOutputSystemByPackOutputDynatraceOtlpProtocol( +class CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Select a transport option for Dynatrace""" - - # HTTP - HTTP = "http" - - -class CreateOutputSystemByPackEndpointType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the type of Dynatrace endpoint configured""" + r"""Authentication type""" - # SaaS - SAAS = "saas" - # ActiveGate - AG = "ag" + # None + NONE = "none" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth (text secret) + OAUTH_SECRET = "oauthSecret" -class CreateOutputSystemByPackOutputDynatraceOtlpPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputTraversalOtlpPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputDynatraceOtlpPqControls(BaseModel): +class CreateOutputSystemByPackOutputTraversalOtlpPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): +class CreateOutputSystemByPackOutputTraversalOtlpTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDynatraceOtlpType + type: CreateOutputSystemByPackOutputTraversalOtlpType r"""Connector type identifier.""" - protocol: CreateOutputSystemByPackOutputDynatraceOtlpProtocol - r"""Select a transport option for Dynatrace""" endpoint: str - r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - otlp_version: OtlpVersionOptions - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - endpoint_type: CreateOutputSystemByPackEndpointType - r"""Select the type of Dynatrace endpoint configured""" - token_secret: str - r"""Select or create a stored text secret""" + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -8497,16 +8804,18 @@ class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + auth_type: NotRequired[ + CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType + ] + r"""Authentication type""" + protocol: NotRequired[ProtocolOptions] + r"""Select a transport option for OpenTelemetry""" preserve_native_any_value: NotRequired[bool] r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" compress: NotRequired[CompressionOptionsDeflateGzip] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" http_compress: NotRequired[CompressionOptionsMessages] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: NotRequired[str] - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_metrics_endpoint_override: NotRequired[str] - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" http_logs_endpoint_override: NotRequired[str] r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] @@ -8518,7 +8827,7 @@ class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" + r"""Maximum size, in KB, of the request body""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] @@ -8533,12 +8842,30 @@ class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): r"""How often the sender should ping the peer to keep the connection open""" keep_alive: NotRequired[bool] r"""Disable to close the connection immediately after sending the outgoing request""" - auth_token_name: NotRequired[str] - r"""Api-Token name""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -8557,6 +8884,8 @@ class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -8580,7 +8909,7 @@ class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputDynatraceOtlpPqControlsTypedDict + CreateOutputSystemByPackOutputTraversalOtlpPqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] @@ -8589,31 +8918,19 @@ class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" -class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): +class CreateOutputSystemByPackOutputTraversalOtlp(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDynatraceOtlpType + type: CreateOutputSystemByPackOutputTraversalOtlpType r"""Connector type identifier.""" - protocol: CreateOutputSystemByPackOutputDynatraceOtlpProtocol - r"""Select a transport option for Dynatrace""" - endpoint: str - r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - - otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - - endpoint_type: Annotated[ - CreateOutputSystemByPackEndpointType, pydantic.Field(alias="endpointType") - ] - r"""Select the type of Dynatrace endpoint configured""" - - token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] - r"""Select or create a stored text secret""" + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -8629,6 +8946,15 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + + protocol: Optional[ProtocolOptions] = None + r"""Select a transport option for OpenTelemetry""" + preserve_native_any_value: Annotated[ Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") ] = None @@ -8642,16 +8968,6 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): ] = None r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") - ] = None - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - - http_metrics_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") - ] = None - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: Annotated[ Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") ] = None @@ -8676,7 +8992,7 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" + r"""Maximum size, in KB, of the request body""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -8710,11 +9026,6 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None r"""Disable to close the connection immediately after sending the outgoing request""" - auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( - None - ) - r"""Api-Token name""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None @@ -8723,6 +9034,54 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -8762,6 +9121,9 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -8812,7 +9174,7 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputDynatraceOtlpPqControls], + Optional[CreateOutputSystemByPackOutputTraversalOtlpPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -8832,20 +9194,27 @@ class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputDynatraceOtlpProtocol(value) + return models.CreateOutputSystemByPackOutputTraversalOtlpAuthenticationType( + value + ) except ValueError: return value return value - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.OtlpVersionOptions(value) + return models.ProtocolOptions(value) except ValueError: return value return value @@ -8877,15 +9246,6 @@ def serialize_failed_request_logging_mode(self, value): return value return value - @field_serializer("endpoint_type") - def serialize_endpoint_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackEndpointType(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -8930,11 +9290,11 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "authType", + "protocol", "preserveNativeAnyValue", "compress", "httpCompress", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", "httpLogsEndpointOverride", "metadata", "dynamicHeadersEnabled", @@ -8948,9 +9308,18 @@ def serialize_model(self, handler): "connectionTimeout", "keepAliveTime", "keepAlive", - "authTokenName", "onBackpressure", "description", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "oauthTextSecret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", "rejectUnauthorized", "useRoundRobinDns", "extraHttpHeaders", @@ -8958,6 +9327,7 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", + "tls", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -8973,6 +9343,7 @@ def serialize_model(self, handler): "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_loginUrl", ] ) serialized = handler(self) @@ -8989,75 +9360,53 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputDynatraceHTTPType(str, Enum): +class CreateOutputSystemByPackOutputDynatraceOtlpType(str, Enum): r"""Connector type identifier.""" - DYNATRACE_HTTP = "dynatrace_http" + DYNATRACE_OTLP = "dynatrace_otlp" -class CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType( +class CreateOutputSystemByPackOutputDynatraceOtlpProtocol( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Authentication type""" + r"""Select a transport option for Dynatrace""" - # Auth token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" + # HTTP + HTTP = "http" -class CreateOutputSystemByPackOutputDynatraceHTTPFormat( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" +class CreateOutputSystemByPackEndpointType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the type of Dynatrace endpoint configured""" - # JSON - JSON_ARRAY = "json_array" - # Plaintext - PLAINTEXT = "plaintext" + # SaaS + SAAS = "saas" + # ActiveGate + AG = "ag" -class CreateOutputSystemByPackOutputDynatraceHTTPEndpoint( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Endpoint""" +class CreateOutputSystemByPackOutputDynatraceOtlpPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - # Cloud - CLOUD = "cloud" - # ActiveGate - ACTIVE_GATE = "activeGate" - # Manual - MANUAL = "manual" +class CreateOutputSystemByPackOutputDynatraceOtlpPqControls(BaseModel): + r"""Persistent queue controls.""" -class CreateOutputSystemByPackTelemetryType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Telemetry type""" - # Logs - LOGS = "logs" - # Metrics - METRICS = "metrics" - - -class CreateOutputSystemByPackOutputDynatraceHTTPPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputDynatraceHTTPPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputDynatraceHTTPTypedDict(TypedDict): +class CreateOutputSystemByPackOutputDynatraceOtlpTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDynatraceHTTPType + type: CreateOutputSystemByPackOutputDynatraceOtlpType r"""Connector type identifier.""" - format_: CreateOutputSystemByPackOutputDynatraceHTTPFormat - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - endpoint: CreateOutputSystemByPackOutputDynatraceHTTPEndpoint - r"""Endpoint""" - telemetry_type: CreateOutputSystemByPackTelemetryType - r"""Telemetry type""" + protocol: CreateOutputSystemByPackOutputDynatraceOtlpProtocol + r"""Select a transport option for Dynatrace""" + endpoint: str + r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + otlp_version: OtlpVersionOptions + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + endpoint_type: CreateOutputSystemByPackEndpointType + r"""Select the type of Dynatrace endpoint configured""" + token_secret: str + r"""Select or create a stored text secret""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9066,35 +9415,57 @@ class CreateOutputSystemByPackOutputDynatraceHTTPTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_traces_endpoint_override: NotRequired[str] + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_metrics_endpoint_override: NotRequired[str] + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + auth_token_name: NotRequired[str] + r"""Api-Token name""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" response_retry_settings: NotRequired[ @@ -9104,16 +9475,6 @@ class CreateOutputSystemByPackOutputDynatraceHTTPTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[ - CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType - ] - r"""Authentication type""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9137,49 +9498,40 @@ class CreateOutputSystemByPackOutputDynatraceHTTPTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputDynatraceHTTPPqControlsTypedDict + CreateOutputSystemByPackOutputDynatraceOtlpPqControlsTypedDict ] r"""Persistent queue controls.""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - environment_id: NotRequired[str] - r"""ID of the environment to send to""" - active_gate_domain: NotRequired[str] - r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" - url: NotRequired[str] - r"""URL to send events to. Can be overwritten by an event's __url field.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputDynatraceHTTP(BaseModel): +class CreateOutputSystemByPackOutputDynatraceOtlp(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDynatraceHTTPType + type: CreateOutputSystemByPackOutputDynatraceOtlpType r"""Connector type identifier.""" - format_: Annotated[ - CreateOutputSystemByPackOutputDynatraceHTTPFormat, - pydantic.Field(alias="format"), - ] - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" + protocol: CreateOutputSystemByPackOutputDynatraceOtlpProtocol + r"""Select a transport option for Dynatrace""" - endpoint: CreateOutputSystemByPackOutputDynatraceHTTPEndpoint - r"""Endpoint""" + endpoint: str + r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - telemetry_type: Annotated[ - CreateOutputSystemByPackTelemetryType, pydantic.Field(alias="telemetryType") + otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + endpoint_type: Annotated[ + CreateOutputSystemByPackEndpointType, pydantic.Field(alias="endpointType") ] - r"""Telemetry type""" + r"""Select the type of Dynatrace endpoint configured""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9195,35 +9547,54 @@ class CreateOutputSystemByPackOutputDynatraceHTTP(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + ] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + http_traces_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") ] = None - r"""Maximum size, in KB, of the request body""" + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + http_metrics_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + ] = None + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Batch event data upon dynamic metadata (whether presented or not)""" + + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") + ] = None + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -9238,22 +9609,56 @@ class CreateOutputSystemByPackOutputDynatraceHTTP(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( + None + ) + r"""Api-Token name""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Headers to add to all events""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") @@ -9275,27 +9680,8 @@ class CreateOutputSystemByPackOutputDynatraceHTTP(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""Authentication type""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" @@ -9344,30 +9730,11 @@ class CreateOutputSystemByPackOutputDynatraceHTTP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputDynatraceHTTPPqControls], + Optional[CreateOutputSystemByPackOutputDynatraceOtlpPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - environment_id: Annotated[Optional[str], pydantic.Field(alias="environmentId")] = ( - None - ) - r"""ID of the environment to send to""" - - active_gate_domain: Annotated[ - Optional[str], pydantic.Field(alias="activeGateDomain") - ] = None - r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" - - url: Optional[str] = None - r"""URL to send events to. Can be overwritten by an event's __url field.""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -9383,72 +9750,65 @@ class CreateOutputSystemByPackOutputDynatraceHTTP(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @field_serializer("method") - def serialize_method(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.CreateOutputSystemByPackOutputDynatraceOtlpProtocol(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OtlpVersionOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptionsDeflateGzip(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("http_compress") + def serialize_http_compress(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType( - value - ) + return models.CompressionOptionsMessages(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputDynatraceHTTPFormat(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("endpoint") - def serialize_endpoint(self, value): + @field_serializer("endpoint_type") + def serialize_endpoint_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputDynatraceHTTPEndpoint(value) + return models.CreateOutputSystemByPackEndpointType(value) except ValueError: return value return value - @field_serializer("telemetry_type") - def serialize_telemetry_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackTelemetryType(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -9488,27 +9848,34 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "keepAlive", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "authTokenName", + "onBackpressure", + "description", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "totalMemoryLimitKB", - "description", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9521,15 +9888,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "token", - "textSecret", - "environmentId", - "activeGateDomain", - "url", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", ] ) serialized = handler(self) @@ -9546,58 +9907,75 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputNetflowHostTypedDict(TypedDict): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 2055""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" +class CreateOutputSystemByPackOutputDynatraceHTTPType(str, Enum): + r"""Connector type identifier.""" + DYNATRACE_HTTP = "dynatrace_http" -class CreateOutputSystemByPackOutputNetflowHost(BaseModel): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 2055""" +class CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + # Auth token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["__template_host", "__template_port"]) - serialized = handler(self) - m = {} +class CreateOutputSystemByPackOutputDynatraceHTTPFormat( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + # JSON + JSON_ARRAY = "json_array" + # Plaintext + PLAINTEXT = "plaintext" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - return m +class CreateOutputSystemByPackOutputDynatraceHTTPEndpoint( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Endpoint""" + + # Cloud + CLOUD = "cloud" + # ActiveGate + ACTIVE_GATE = "activeGate" + # Manual + MANUAL = "manual" -class CreateOutputSystemByPackOutputNetflowTypedDict(TypedDict): +class CreateOutputSystemByPackTelemetryType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Telemetry type""" + + # Logs + LOGS = "logs" + # Metrics + METRICS = "metrics" + + +class CreateOutputSystemByPackOutputDynatraceHTTPPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputDynatraceHTTPPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputDynatraceHTTPTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsNetflow + type: CreateOutputSystemByPackOutputDynatraceHTTPType r"""Connector type identifier.""" - hosts: List[CreateOutputSystemByPackOutputNetflowHostTypedDict] - r"""One or more NetFlow Destinations to forward events to""" + format_: CreateOutputSystemByPackOutputDynatraceHTTPFormat + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" + endpoint: CreateOutputSystemByPackOutputDynatraceHTTPEndpoint + r"""Endpoint""" + telemetry_type: CreateOutputSystemByPackTelemetryType + r"""Telemetry type""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9606,158 +9984,10 @@ class CreateOutputSystemByPackOutputNetflowTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - max_record_size: NotRequired[float] - r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateOutputSystemByPackOutputNetflow(BaseModel): - id: str - r"""Unique ID for this output""" - - type: TypeOptionsNetflow - r"""Connector type identifier.""" - - hosts: List[CreateOutputSystemByPackOutputNetflowHost] - r"""One or more NetFlow Destinations to forward events to""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") - ] = None - r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") - ] = None - r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "dnsResolvePeriodSec", - "enableIpSpoofing", - "description", - "maxRecordSize", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputXsiamType(str, Enum): - r"""Connector type identifier.""" - - XSIAM = "xsiam" - - -class CreateOutputSystemByPackOutputXsiamAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter a token directly, or provide a secret referencing a token""" - - TOKEN = "token" - SECRET = "secret" - - -class CreateOutputSystemByPackOutputXsiamURLTypedDict(TypedDict): - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - -class CreateOutputSystemByPackOutputXsiamURL(BaseModel): - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputXsiamPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputXsiamPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputXsiamTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputXsiamType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -9778,13 +10008,13 @@ class CreateOutputSystemByPackOutputXsiamTypedDict(TypedDict): flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[CreateOutputSystemByPackOutputXsiamAuthenticationMethod] - r"""Enter a token directly, or provide a secret referencing a token""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -9792,30 +10022,16 @@ class CreateOutputSystemByPackOutputXsiamTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - throttle_rate_req_per_sec: NotRequired[int] - r"""Maximum number of requests to limit to per second""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[ + CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType + ] + r"""Authentication type""" total_memory_limit_kb: NotRequired[float] r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputSystemByPackOutputXsiamURLTypedDict]] - r"""XSIAM Endpoints""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - token: NotRequired[str] - r"""XSIAM authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9838,8 +10054,20 @@ class CreateOutputSystemByPackOutputXsiamTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputXsiamPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputDynatraceHTTPPqControlsTypedDict + ] r"""Persistent queue controls.""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + environment_id: NotRequired[str] + r"""ID of the environment to send to""" + active_gate_domain: NotRequired[str] + r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" + url: NotRequired[str] + r"""URL to send events to. Can be overwritten by an event's __url field.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] @@ -9850,13 +10078,27 @@ class CreateOutputSystemByPackOutputXsiamTypedDict(TypedDict): r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputXsiam(BaseModel): +class CreateOutputSystemByPackOutputDynatraceHTTP(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputXsiamType + type: CreateOutputSystemByPackOutputDynatraceHTTPType r"""Connector type identifier.""" + format_: Annotated[ + CreateOutputSystemByPackOutputDynatraceHTTPFormat, + pydantic.Field(alias="format"), + ] + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" + + endpoint: CreateOutputSystemByPackOutputDynatraceHTTPEndpoint + r"""Endpoint""" + + telemetry_type: Annotated[ + CreateOutputSystemByPackTelemetryType, pydantic.Field(alias="telemetryType") + ] + r"""Telemetry type""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9871,10 +10113,11 @@ class CreateOutputSystemByPackOutputXsiam(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -9917,7 +10160,12 @@ class CreateOutputSystemByPackOutputXsiam(BaseModel): Optional[List[ExtraHTTPHeaderConfInputElastic]], pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Headers to add to all events""" + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], @@ -9930,12 +10178,6 @@ class CreateOutputSystemByPackOutputXsiam(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputXsiamAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Enter a token directly, or provide a secret referencing a token""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -9951,16 +10193,17 @@ class CreateOutputSystemByPackOutputXsiam(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - throttle_rate_req_per_sec: Annotated[ - Optional[int], pydantic.Field(alias="throttleRateReqPerSec") - ] = None - r"""Maximum number of requests to limit to per second""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + total_memory_limit_kb: Annotated[ Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None @@ -9969,36 +10212,6 @@ class CreateOutputSystemByPackOutputXsiam(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[CreateOutputSystemByPackOutputXsiamURL]] = None - r"""XSIAM Endpoints""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" - - token: Optional[str] = None - r"""XSIAM authentication token""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -10049,23 +10262,42 @@ class CreateOutputSystemByPackOutputXsiam(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputXsiamPqControls], + Optional[CreateOutputSystemByPackOutputDynatraceHTTPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + environment_id: Annotated[Optional[str], pydantic.Field(alias="environmentId")] = ( + None + ) + r"""ID of the environment to send to""" + + active_gate_domain: Annotated[ + Optional[str], pydantic.Field(alias="activeGateDomain") + ] = None + r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" + + url: Optional[str] = None + r"""URL to send events to. Can be overwritten by an event's __url field.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" @@ -10074,6 +10306,15 @@ class CreateOutputSystemByPackOutputXsiam(BaseModel): ) r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -10083,22 +10324,49 @@ def serialize_failed_request_logging_mode(self, value): return value return value + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputXsiamAuthenticationMethod( + return models.CreateOutputSystemByPackOutputDynatraceHTTPAuthenticationType( value ) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputSystemByPackOutputDynatraceHTTPFormat(value) + except ValueError: + return value + return value + + @field_serializer("endpoint") + def serialize_endpoint(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputDynatraceHTTPEndpoint(value) + except ValueError: + return value + return value + + @field_serializer("telemetry_type") + def serialize_telemetry_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackTelemetryType(value) except ValueError: return value return value @@ -10138,7 +10406,8 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", + "method", + "keepAlive", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -10148,24 +10417,16 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "throttleRateReqPerSec", "onBackpressure", + "authType", "totalMemoryLimitKB", "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "token", - "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10178,6 +10439,11 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "token", + "textSecret", + "environmentId", + "activeGateDomain", + "url", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", @@ -10198,78 +10464,138 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputLocalSearchStorageType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputSystemByPackOutputNetflowHostTypedDict(TypedDict): + host: str + r"""Destination host""" + port: float + r"""Destination port, default is 2055""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - LOCAL_SEARCH_STORAGE = "local_search_storage" +class CreateOutputSystemByPackOutputNetflowHost(BaseModel): + host: str + r"""Destination host""" -class CreateOutputSystemByPackOutputLocalSearchStorageFormat( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Data format to use when sending data. Defaults to JSON Compact.""" + port: float + r"""Destination port, default is 2055""" - # JSONCompactEachRowWithNames - JSON_COMPACT_EACH_ROW_WITH_NAMES = "json-compact-each-row-with-names" - # JSONEachRow - JSON_EACH_ROW = "json-each-row" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputSystemByPackMappingType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How event fields are mapped to columns.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["__template_host", "__template_port"]) + serialized = handler(self) + m = {} - # Automatic - AUTOMATIC = "automatic" - # Custom - CUSTOM = "custom" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val -class CreateOutputSystemByPackStatsDestinationTypedDict(TypedDict): - url: NotRequired[str] - database: NotRequired[str] - table_name: NotRequired[str] - auth_type: NotRequired[str] - username: NotRequired[str] - sql_username: NotRequired[str] - password: NotRequired[str] - wait_for_async_inserts: NotRequired[bool] - concurrency: NotRequired[float] + return m -class CreateOutputSystemByPackStatsDestination(BaseModel): - url: Optional[str] = None +class CreateOutputSystemByPackOutputNetflowTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: TypeOptionsNetflow + r"""Connector type identifier.""" + hosts: List[CreateOutputSystemByPackOutputNetflowHostTypedDict] + r"""One or more NetFlow Destinations to forward events to""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + max_record_size: NotRequired[float] + r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - database: Optional[str] = None - table_name: Annotated[Optional[str], pydantic.Field(alias="tableName")] = None +class CreateOutputSystemByPackOutputNetflow(BaseModel): + id: str + r"""Unique ID for this output""" - auth_type: Annotated[Optional[str], pydantic.Field(alias="authType")] = None + type: TypeOptionsNetflow + r"""Connector type identifier.""" - username: Optional[str] = None + hosts: List[CreateOutputSystemByPackOutputNetflowHost] + r"""One or more NetFlow Destinations to forward events to""" - sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - password: Optional[str] = None + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - wait_for_async_inserts: Annotated[ - Optional[bool], pydantic.Field(alias="waitForAsyncInserts") + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - concurrency: Optional[float] = None + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") + ] = None + r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") + ] = None + r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "url", - "database", - "tableName", - "authType", - "username", - "sqlUsername", - "password", - "waitForAsyncInserts", - "concurrency", + "pipeline", + "systemFields", + "environment", + "streamtags", + "dnsResolvePeriodSec", + "enableIpSpoofing", + "description", + "maxRecordSize", + "__template_streamtags", ] ) serialized = handler(self) @@ -10286,30 +10612,33 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackColumnMappingTypedDict(TypedDict): - column_name: str - r"""Name of the column that will store field value""" - column_value_expression: str - r"""JavaScript expression to compute value to be inserted into the table""" - column_type: NotRequired[str] - r"""Type of the column in the database""" +class CreateOutputSystemByPackOutputXsiamType(str, Enum): + r"""Connector type identifier.""" + XSIAM = "xsiam" -class CreateOutputSystemByPackColumnMapping(BaseModel): - column_name: Annotated[str, pydantic.Field(alias="columnName")] - r"""Name of the column that will store field value""" - column_value_expression: Annotated[ - str, pydantic.Field(alias="columnValueExpression") - ] - r"""JavaScript expression to compute value to be inserted into the table""" +class CreateOutputSystemByPackOutputXsiamAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter a token directly, or provide a secret referencing a token""" - column_type: Annotated[Optional[str], pydantic.Field(alias="columnType")] = None - r"""Type of the column in the database""" + TOKEN = "token" + SECRET = "secret" + + +class CreateOutputSystemByPackOutputXsiamURLTypedDict(TypedDict): + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + +class CreateOutputSystemByPackOutputXsiamURL(BaseModel): + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["columnType"]) + optional_fields = set(["weight"]) serialized = handler(self) m = {} @@ -10324,25 +10653,19 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputLocalSearchStoragePqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputXsiamPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputLocalSearchStoragePqControls(BaseModel): +class CreateOutputSystemByPackOutputXsiamPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputLocalSearchStorageTypedDict(TypedDict): +class CreateOutputSystemByPackOutputXsiamTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputLocalSearchStorageType + type: CreateOutputSystemByPackOutputXsiamType r"""Connector type identifier.""" - url: str - r"""URL of the database instance. Example: http://localhost:8123/""" - database: str - r"""Database""" - table_name: str - r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10351,16 +10674,8 @@ class CreateOutputSystemByPackOutputLocalSearchStorageTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationTypeOptions] - r"""Authentication type""" - format_: NotRequired[CreateOutputSystemByPackOutputLocalSearchStorageFormat] - r"""Data format to use when sending data. Defaults to JSON Compact.""" - mapping_type: NotRequired[CreateOutputSystemByPackMappingType] - r"""How event fields are mapped to columns.""" - async_inserts: NotRequired[bool] - r"""Collect data into batches for later processing. Disable to write to a table immediately.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -10382,12 +10697,12 @@ class CreateOutputSystemByPackOutputLocalSearchStorageTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" + auth_type: NotRequired[CreateOutputSystemByPackOutputXsiamAuthenticationMethod] + r"""Enter a token directly, or provide a secret referencing a token""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -10395,31 +10710,30 @@ class CreateOutputSystemByPackOutputLocalSearchStorageTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - workload: NotRequired[str] - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - dump_format_errors_to_disk: NotRequired[bool] - r"""Log the most recent event that fails to match the table schema""" + throttle_rate_req_per_sec: NotRequired[int] + r"""Maximum number of requests to limit to per second""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - stats_destination: NotRequired[CreateOutputSystemByPackStatsDestinationTypedDict] + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - sql_username: NotRequired[str] - r"""Username for certificate authentication""" - wait_for_async_inserts: NotRequired[bool] - r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - exclude_mapping_fields: NotRequired[List[str]] - r"""Fields to exclude from sending""" - describe_table: NotRequired[str] - r"""Retrieves the table schema and populates the Column Mapping table""" - column_mappings: NotRequired[List[CreateOutputSystemByPackColumnMappingTypedDict]] - r"""Column Mapping""" + url: NotRequired[str] + r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputSystemByPackOutputXsiamURLTypedDict]] + r"""XSIAM Endpoints""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""XSIAM authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -10442,40 +10756,25 @@ class CreateOutputSystemByPackOutputLocalSearchStorageTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputLocalSearchStoragePqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputSystemByPackOutputXsiamPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_table_name: NotRequired[str] - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): +class CreateOutputSystemByPackOutputXsiam(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputLocalSearchStorageType + type: CreateOutputSystemByPackOutputXsiamType r"""Connector type identifier.""" - url: str - r"""URL of the database instance. Example: http://localhost:8123/""" - - database: str - r"""Database""" - - table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -10490,30 +10789,10 @@ class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") - ] = None - r"""Authentication type""" - - format_: Annotated[ - Optional[CreateOutputSystemByPackOutputLocalSearchStorageFormat], - pydantic.Field(alias="format"), - ] = None - r"""Data format to use when sending data. Defaults to JSON Compact.""" - - mapping_type: Annotated[ - Optional[CreateOutputSystemByPackMappingType], - pydantic.Field(alias="mappingType"), - ] = None - r"""How event fields are mapped to columns.""" - - async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Collect data into batches for later processing. Disable to write to a table immediately.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -10558,11 +10837,6 @@ class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): ] = None r"""Headers to add to all events""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -10574,6 +10848,12 @@ class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputXsiamAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter a token directly, or provide a secret referencing a token""" + response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -10589,61 +10869,53 @@ class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - workload: Optional[str] = None - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - - dump_format_errors_to_disk: Annotated[ - Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") + throttle_rate_req_per_sec: Annotated[ + Optional[int], pydantic.Field(alias="throttleRateReqPerSec") ] = None - r"""Log the most recent event that fails to match the table schema""" + r"""Maximum number of requests to limit to per second""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - stats_destination: Annotated[ - Optional[CreateOutputSystemByPackStatsDestination], - pydantic.Field(alias="statsDestination"), + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: Optional[str] = None r"""Optional description for this configuration.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" + url: Optional[str] = None + r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Select or create a secret that references your credentials""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None - r"""Username for certificate authentication""" + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - wait_for_async_inserts: Annotated[ - Optional[bool], pydantic.Field(alias="waitForAsyncInserts") + urls: Optional[List[CreateOutputSystemByPackOutputXsiamURL]] = None + r"""XSIAM Endpoints""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - exclude_mapping_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeMappingFields") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Fields to exclude from sending""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( - None - ) - r"""Retrieves the table schema and populates the Column Mapping table""" + token: Optional[str] = None + r"""XSIAM authentication token""" - column_mappings: Annotated[ - Optional[List[CreateOutputSystemByPackColumnMapping]], - pydantic.Field(alias="columnMappings"), - ] = None - r"""Column Mapping""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -10695,7 +10967,7 @@ class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputLocalSearchStoragePqControls], + Optional[CreateOutputSystemByPackOutputXsiamPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -10705,21 +10977,6 @@ class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") - ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - - template_table_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_tableName") - ] = None - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -10730,49 +10987,36 @@ class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationTypeOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputLocalSearchStorageFormat( + return models.CreateOutputSystemByPackOutputXsiamAuthenticationMethod( value ) except ValueError: return value return value - @field_serializer("mapping_type") - def serialize_mapping_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackMappingType(value) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -10812,11 +11056,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "format", - "mappingType", - "asyncInserts", - "tls", + "loadBalanced", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -10826,25 +11066,24 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "workload", - "dumpFormatErrorsToDisk", + "throttleRateReqPerSec", "onBackpressure", - "statsDestination", + "totalMemoryLimitKB", "description", - "username", - "password", - "credentialsSecret", - "sqlUsername", - "waitForAsyncInserts", - "excludeMappingFields", - "describeTable", - "columnMappings", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10858,11 +11097,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_url", - "__template_database", - "__template_tableName", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_url", ] ) serialized = handler(self) @@ -10879,33 +11116,151 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputCustomerMetricsStorageType(str, Enum): +class CreateOutputSystemByPackOutputLocalSearchStorageType(str, Enum): r"""Connector type identifier.""" - CUSTOMER_METRICS_STORAGE = "customer_metrics_storage" + LOCAL_SEARCH_STORAGE = "local_search_storage" -class CreateOutputSystemByPackOutputCustomerMetricsStoragePqControlsTypedDict( - TypedDict +class CreateOutputSystemByPackOutputLocalSearchStorageFormat( + str, Enum, metaclass=utils.OpenEnumMeta ): + r"""Data format to use when sending data. Defaults to JSON Compact.""" + + # JSONCompactEachRowWithNames + JSON_COMPACT_EACH_ROW_WITH_NAMES = "json-compact-each-row-with-names" + # JSONEachRow + JSON_EACH_ROW = "json-each-row" + + +class CreateOutputSystemByPackMappingType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How event fields are mapped to columns.""" + + # Automatic + AUTOMATIC = "automatic" + # Custom + CUSTOM = "custom" + + +class CreateOutputSystemByPackStatsDestinationTypedDict(TypedDict): + url: NotRequired[str] + database: NotRequired[str] + table_name: NotRequired[str] + auth_type: NotRequired[str] + username: NotRequired[str] + sql_username: NotRequired[str] + password: NotRequired[str] + wait_for_async_inserts: NotRequired[bool] + concurrency: NotRequired[float] + + +class CreateOutputSystemByPackStatsDestination(BaseModel): + url: Optional[str] = None + + database: Optional[str] = None + + table_name: Annotated[Optional[str], pydantic.Field(alias="tableName")] = None + + auth_type: Annotated[Optional[str], pydantic.Field(alias="authType")] = None + + username: Optional[str] = None + + sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + + password: Optional[str] = None + + wait_for_async_inserts: Annotated[ + Optional[bool], pydantic.Field(alias="waitForAsyncInserts") + ] = None + + concurrency: Optional[float] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "url", + "database", + "tableName", + "authType", + "username", + "sqlUsername", + "password", + "waitForAsyncInserts", + "concurrency", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackColumnMappingTypedDict(TypedDict): + column_name: str + r"""Name of the column that will store field value""" + column_value_expression: str + r"""JavaScript expression to compute value to be inserted into the table""" + column_type: NotRequired[str] + r"""Type of the column in the database""" + + +class CreateOutputSystemByPackColumnMapping(BaseModel): + column_name: Annotated[str, pydantic.Field(alias="columnName")] + r"""Name of the column that will store field value""" + + column_value_expression: Annotated[ + str, pydantic.Field(alias="columnValueExpression") + ] + r"""JavaScript expression to compute value to be inserted into the table""" + + column_type: Annotated[Optional[str], pydantic.Field(alias="columnType")] = None + r"""Type of the column in the database""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["columnType"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputLocalSearchStoragePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCustomerMetricsStoragePqControls(BaseModel): +class CreateOutputSystemByPackOutputLocalSearchStoragePqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict(TypedDict): +class CreateOutputSystemByPackOutputLocalSearchStorageTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCustomerMetricsStorageType + type: CreateOutputSystemByPackOutputLocalSearchStorageType r"""Connector type identifier.""" url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + r"""URL of the database instance. Example: http://localhost:8123/""" database: str - r"""ClickHouse database""" + r"""Database""" table_name: str - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10916,12 +11271,12 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict(TypedDict): r"""Metadata tags used for categorization and filtering.""" auth_type: NotRequired[AuthenticationTypeOptions] r"""Authentication type""" - format_: NotRequired[FormatOptions] - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - mapping_type: NotRequired[MappingTypeOptions] - r"""How event fields are mapped to ClickHouse columns""" + format_: NotRequired[CreateOutputSystemByPackOutputLocalSearchStorageFormat] + r"""Data format to use when sending data. Defaults to JSON Compact.""" + mapping_type: NotRequired[CreateOutputSystemByPackMappingType] + r"""How event fields are mapped to columns.""" async_inserts: NotRequired[bool] - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + r"""Collect data into batches for later processing. Disable to write to a table immediately.""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" concurrency: NotRequired[float] @@ -10964,6 +11319,7 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict(TypedDict): r"""Log the most recent event that fails to match the table schema""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + stats_destination: NotRequired[CreateOutputSystemByPackStatsDestinationTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" username: NotRequired[str] @@ -10975,12 +11331,12 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict(TypedDict): sql_username: NotRequired[str] r"""Username for certificate authentication""" wait_for_async_inserts: NotRequired[bool] - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" exclude_mapping_fields: NotRequired[List[str]] - r"""Fields to exclude from sending to ClickHouse""" + r"""Fields to exclude from sending""" describe_table: NotRequired[str] - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] + r"""Retrieves the table schema and populates the Column Mapping table""" + column_mappings: NotRequired[List[CreateOutputSystemByPackColumnMappingTypedDict]] r"""Column Mapping""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" @@ -11005,7 +11361,7 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputCustomerMetricsStoragePqControlsTypedDict + CreateOutputSystemByPackOutputLocalSearchStoragePqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] @@ -11022,21 +11378,21 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputCustomerMetricsStorage(BaseModel): +class CreateOutputSystemByPackOutputLocalSearchStorage(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCustomerMetricsStorageType + type: CreateOutputSystemByPackOutputLocalSearchStorageType r"""Connector type identifier.""" url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + r"""URL of the database instance. Example: http://localhost:8123/""" database: str - r"""ClickHouse database""" + r"""Database""" table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -11057,18 +11413,22 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorage(BaseModel): ] = None r"""Authentication type""" - format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + format_: Annotated[ + Optional[CreateOutputSystemByPackOutputLocalSearchStorageFormat], + pydantic.Field(alias="format"), + ] = None + r"""Data format to use when sending data. Defaults to JSON Compact.""" mapping_type: Annotated[ - Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") + Optional[CreateOutputSystemByPackMappingType], + pydantic.Field(alias="mappingType"), ] = None - r"""How event fields are mapped to ClickHouse columns""" + r"""How event fields are mapped to columns.""" async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( None ) - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + r"""Collect data into batches for later processing. Disable to write to a table immediately.""" tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None r"""TLS settings (client side)""" @@ -11160,6 +11520,11 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorage(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" + stats_destination: Annotated[ + Optional[CreateOutputSystemByPackStatsDestination], + pydantic.Field(alias="statsDestination"), + ] = None + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11180,20 +11545,20 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorage(BaseModel): wait_for_async_inserts: Annotated[ Optional[bool], pydantic.Field(alias="waitForAsyncInserts") ] = None - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" exclude_mapping_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="excludeMappingFields") ] = None - r"""Fields to exclude from sending to ClickHouse""" + r"""Fields to exclude from sending""" describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( None ) - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" + r"""Retrieves the table schema and populates the Column Mapping table""" column_mappings: Annotated[ - Optional[List[ColumnMappingConfOutputClickHouse]], + Optional[List[CreateOutputSystemByPackColumnMapping]], pydantic.Field(alias="columnMappings"), ] = None r"""Column Mapping""" @@ -11248,7 +11613,7 @@ class CreateOutputSystemByPackOutputCustomerMetricsStorage(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputCustomerMetricsStoragePqControls], + Optional[CreateOutputSystemByPackOutputLocalSearchStoragePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -11296,7 +11661,9 @@ def serialize_auth_type(self, value): def serialize_format_(self, value): if isinstance(value, str): try: - return models.FormatOptions(value) + return models.CreateOutputSystemByPackOutputLocalSearchStorageFormat( + value + ) except ValueError: return value return value @@ -11305,7 +11672,7 @@ def serialize_format_(self, value): def serialize_mapping_type(self, value): if isinstance(value, str): try: - return models.MappingTypeOptions(value) + return models.CreateOutputSystemByPackMappingType(value) except ValueError: return value return value @@ -11386,6 +11753,7 @@ def serialize_model(self, handler): "workload", "dumpFormatErrorsToDisk", "onBackpressure", + "statsDestination", "description", "username", "password", @@ -11429,24 +11797,26 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputClickHouseType(str, Enum): +class CreateOutputSystemByPackOutputCustomerMetricsStorageType(str, Enum): r"""Connector type identifier.""" - CLICK_HOUSE = "click_house" + CUSTOMER_METRICS_STORAGE = "customer_metrics_storage" -class CreateOutputSystemByPackOutputClickHousePqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCustomerMetricsStoragePqControlsTypedDict( + TypedDict +): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputClickHousePqControls(BaseModel): +class CreateOutputSystemByPackOutputCustomerMetricsStoragePqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputClickHouseTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputClickHouseType + type: CreateOutputSystemByPackOutputCustomerMetricsStorageType r"""Connector type identifier.""" url: str r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" @@ -11553,7 +11923,7 @@ class CreateOutputSystemByPackOutputClickHouseTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputClickHousePqControlsTypedDict + CreateOutputSystemByPackOutputCustomerMetricsStoragePqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] @@ -11570,11 +11940,11 @@ class CreateOutputSystemByPackOutputClickHouseTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputClickHouse(BaseModel): +class CreateOutputSystemByPackOutputCustomerMetricsStorage(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputClickHouseType + type: CreateOutputSystemByPackOutputCustomerMetricsStorageType r"""Connector type identifier.""" url: str @@ -11796,7 +12166,7 @@ class CreateOutputSystemByPackOutputClickHouse(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputClickHousePqControls], + Optional[CreateOutputSystemByPackOutputCustomerMetricsStoragePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -11977,17 +12347,31 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputDiskSpoolType(str, Enum): +class CreateOutputSystemByPackOutputClickHouseType(str, Enum): r"""Connector type identifier.""" - DISK_SPOOL = "disk_spool" + CLICK_HOUSE = "click_house" -class CreateOutputSystemByPackOutputDiskSpoolTypedDict(TypedDict): +class CreateOutputSystemByPackOutputClickHousePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputClickHousePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputClickHouseTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDiskSpoolType + type: CreateOutputSystemByPackOutputClickHouseType r"""Connector type identifier.""" + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + database: str + r"""ClickHouse database""" + table_name: str + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -11996,29 +12380,130 @@ class CreateOutputSystemByPackOutputDiskSpoolTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - time_window: NotRequired[str] - r"""Time period for grouping spooled events. Default is 10m.""" - max_data_size: NotRequired[str] - r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" - compress: NotRequired[CompressionOptionsPersistence] - r"""Data compression format. Default is gzip.""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" + auth_type: NotRequired[AuthenticationTypeOptions] + r"""Authentication type""" + format_: NotRequired[FormatOptions] + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + mapping_type: NotRequired[MappingTypeOptions] + r"""How event fields are mapped to ClickHouse columns""" + async_inserts: NotRequired[bool] + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + workload: NotRequired[str] + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" + dump_format_errors_to_disk: NotRequired[bool] + r"""Log the most recent event that fails to match the table schema""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + sql_username: NotRequired[str] + r"""Username for certificate authentication""" + wait_for_async_inserts: NotRequired[bool] + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + exclude_mapping_fields: NotRequired[List[str]] + r"""Fields to exclude from sending to ClickHouse""" + describe_table: NotRequired[str] + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" + column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] + r"""Column Mapping""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputClickHousePqControlsTypedDict + ] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_table_name: NotRequired[str] + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputDiskSpool(BaseModel): +class CreateOutputSystemByPackOutputClickHouse(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDiskSpoolType + type: CreateOutputSystemByPackOutputClickHouseType r"""Connector type identifier.""" + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + + database: str + r"""ClickHouse database""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -12033,498 +12518,305 @@ class CreateOutputSystemByPackOutputDiskSpool(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time period for grouping spooled events. Default is 10m.""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" + auth_type: Annotated[ + Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") + ] = None + r"""Authentication type""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - compress: Optional[CompressionOptionsPersistence] = None - r"""Data compression format. Default is gzip.""" + mapping_type: Annotated[ + Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") + ] = None + r"""How event fields are mapped to ClickHouse columns""" - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( None ) - r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPersistence(value) - except ValueError: - return value - return value + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "partitionExpr", - "description", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - return m + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" -class CreateOutputSystemByPackOutputCriblLakeType(str, Enum): - r"""Connector type identifier.""" - - CRIBL_LAKE = "cribl_lake" - - -class CreateOutputSystemByPackOutputCriblLakeFormat( - str, Enum, metaclass=utils.OpenEnumMeta -): - JSON = "json" - PARQUET = "parquet" - RAW = "raw" - + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" -class CreateOutputSystemByPackOutputCriblLakeTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCriblLakeType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - storage_location_id: NotRequired[str] - r"""Storage location that contains the target Lake dataset.""" - dest_path: NotRequired[str] - r"""Lake dataset to send the data to.""" - format_: NotRequired[CreateOutputSystemByPackOutputCriblLakeFormat] - dynamic_dataset: NotRequired[bool] - max_closing_files_to_backpressure: NotRequired[float] - max_concurrent_file_parts: NotRequired[float] - description: NotRequired[str] - r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" -class CreateOutputSystemByPackOutputCriblLake(BaseModel): - id: str - r"""Unique ID for this output""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - type: CreateOutputSystemByPackOutputCriblLakeType - r"""Connector type identifier.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + workload: Optional[str] = None + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + dump_format_errors_to_disk: Annotated[ + Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") ] = None - r"""Add the Output ID value to staging location""" + r"""Log the most recent event that fails to match the table schema""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Remove empty staging directories after moving files""" + r"""How to handle events when all receivers are exerting backpressure""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + username: Optional[str] = None + r"""Username""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + password: Optional[str] = None + r"""Password""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Select or create a secret that references your credentials""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + r"""Username for certificate authentication""" + + wait_for_async_inserts: Annotated[ + Optional[bool], pydantic.Field(alias="waitForAsyncInserts") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + exclude_mapping_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeMappingFields") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""Fields to exclude from sending to ClickHouse""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( None ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + column_mappings: Annotated[ + Optional[List[ColumnMappingConfOutputClickHouse]], + pydantic.Field(alias="columnMappings"), ] = None - r"""Buffer size used to write to a file""" + r"""Column Mapping""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - storage_location_id: Annotated[ - Optional[str], pydantic.Field(alias="storageLocationId") - ] = None - r"""Storage location that contains the target Lake dataset.""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Lake dataset to send the data to.""" - - format_: Annotated[ - Optional[CreateOutputSystemByPackOutputCriblLakeFormat], - pydantic.Field(alias="format"), - ] = None - - dynamic_dataset: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicDataset") - ] = None - - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + r"""Codec to use to compress the persisted data""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputClickHousePqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""Persistent queue controls.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + template_table_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_tableName") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptions(value) + except ValueError: + return value + return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.FormatOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("mapping_type") + def serialize_mapping_type(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.MappingTypeOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputCriblLakeFormat(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -12537,54 +12829,56 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "stagePath", - "addIdToStagePath", - "removeEmptyDirs", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "storageLocationId", - "destPath", + "authType", "format", - "dynamicDataset", - "maxClosingFilesToBackpressure", - "maxConcurrentFileParts", - "description", + "mappingType", + "asyncInserts", + "tls", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "workload", + "dumpFormatErrorsToDisk", + "onBackpressure", + "description", + "username", + "password", + "credentialsSecret", + "sqlUsername", + "waitForAsyncInserts", + "excludeMappingFields", + "describeTable", + "columnMappings", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_baseFileName", - "__template_fileNameSuffix", + "__template_url", + "__template_database", + "__template_tableName", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_destPath", - "__template_compress", - "__template_parquetSchema", ] ) serialized = handler(self) @@ -12601,57 +12895,164 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSecurityLakeTypedDict(TypedDict): +class CreateOutputSystemByPackOutputDiskSpoolType(str, Enum): + r"""Connector type identifier.""" + + DISK_SPOOL = "disk_spool" + + +class CreateOutputSystemByPackOutputDiskSpoolTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSecuritylake + type: CreateOutputSystemByPackOutputDiskSpoolType r"""Connector type identifier.""" - assume_role_arn: str - r"""Amazon Resource Name (ARN) of the role to assume""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - region: str - r"""Region where the Amazon Security Lake is located.""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - account_id: str - r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" - custom_source: str - r"""Name of the custom source configured in Amazon Security Lake""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - endpoint: NotRequired[str] - r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access S3""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + time_window: NotRequired[str] + r"""Time period for grouping spooled events. Default is 10m.""" + max_data_size: NotRequired[str] + r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + compress: NotRequired[CompressionOptionsPersistence] + r"""Data compression format. Default is gzip.""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateOutputSystemByPackOutputDiskSpool(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputSystemByPackOutputDiskSpoolType + r"""Connector type identifier.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time period for grouping spooled events. Default is 10m.""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + + compress: Optional[CompressionOptionsPersistence] = None + r"""Data compression format. Default is gzip.""" + + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "partitionExpr", + "description", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputCriblLakeType(str, Enum): + r"""Connector type identifier.""" + + CRIBL_LAKE = "cribl_lake" + + +class CreateOutputSystemByPackOutputCriblLakeFormat( + str, Enum, metaclass=utils.OpenEnumMeta +): + JSON = "json" + PARQUET = "parquet" + RAW = "raw" + + +class CreateOutputSystemByPackOutputCriblLakeTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputCriblLakeType + r"""Connector type identifier.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" add_id_to_stage_path: NotRequired[bool] r"""Add the Output ID value to staging location""" remove_empty_dirs: NotRequired[bool] r"""Remove empty staging directories after moving files""" base_file_name: NotRequired[str] r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" max_file_size_mb: NotRequired[float] r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" max_file_open_time_sec: NotRequired[float] @@ -12675,18 +13076,25 @@ class CreateOutputSystemByPackOutputSecurityLakeTypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" + storage_location_id: NotRequired[str] + r"""Storage location that contains the target Lake dataset.""" + dest_path: NotRequired[str] + r"""Lake dataset to send the data to.""" + format_: NotRequired[CreateOutputSystemByPackOutputCriblLakeFormat] + dynamic_dataset: NotRequired[bool] + max_closing_files_to_backpressure: NotRequired[float] + max_concurrent_file_parts: NotRequired[float] + freshness_grace_period_sec: NotRequired[float] + description: NotRequired[str] + r"""Optional description for this configuration.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" automatic_schema: NotRequired[bool] r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" parquet_version: NotRequired[ParquetVersionOptions] r"""Determines which data types are supported and how they are represented""" parquet_data_page_version: NotRequired[DataPageVersionOptions] @@ -12705,90 +13113,44 @@ class CreateOutputSystemByPackOutputSecurityLakeTypedDict(TypedDict): r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" enable_page_checksum: NotRequired[bool] r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" empty_dir_cleanup_sec: NotRequired[float] r"""How frequently, in seconds, to clean up empty directories""" directory_batch_size: NotRequired[float] r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" deadletter_path: NotRequired[str] r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_base_file_name: NotRequired[str] r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_account_id: NotRequired[str] - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - template_custom_source: NotRequired[str] - r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputSystemByPackOutputSecurityLake(BaseModel): +class CreateOutputSystemByPackOutputCriblLake(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSecuritylake + type: CreateOutputSystemByPackOutputCriblLakeType r"""Connector type identifier.""" - assume_role_arn: Annotated[str, pydantic.Field(alias="assumeRoleArn")] - r"""Amazon Resource Name (ARN) of the role to assume""" - - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - - region: str - r"""Region where the Amazon Security Lake is located.""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - - account_id: Annotated[str, pydantic.Field(alias="accountId")] - r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" - - custom_source: Annotated[str, pydantic.Field(alias="customSource")] - r"""Name of the custom source configured in Amazon Security Lake""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -12796,54 +13158,8 @@ class CreateOutputSystemByPackOutputSecurityLake(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - endpoint: Optional[str] = None - r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access S3""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") - ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" - - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" add_id_to_stage_path: Annotated[ Optional[bool], pydantic.Field(alias="addIdToStagePath") @@ -12860,6 +13176,11 @@ class CreateOutputSystemByPackOutputSecurityLake(BaseModel): ) r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: Annotated[ Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None @@ -12917,35 +13238,56 @@ class CreateOutputSystemByPackOutputSecurityLake(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + storage_location_id: Annotated[ + Optional[str], pydantic.Field(alias="storageLocationId") + ] = None + r"""Storage location that contains the target Lake dataset.""" - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Lake dataset to send the data to.""" + + format_: Annotated[ + Optional[CreateOutputSystemByPackOutputCriblLakeFormat], + pydantic.Field(alias="format"), ] = None - r"""Object ACL to assign to uploaded objects""" - storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + dynamic_dataset: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicDataset") ] = None - r"""Storage class to select for uploaded objects""" - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") ] = None - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + + freshness_grace_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="freshnessGracePeriodSec") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" automatic_schema: Annotated[ Optional[bool], pydantic.Field(alias="automaticSchema") ] = None r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: Annotated[ Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None @@ -12992,15 +13334,6 @@ class CreateOutputSystemByPackOutputSecurityLake(BaseModel): ] = None r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - empty_dir_cleanup_sec: Annotated[ Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None @@ -13011,11 +13344,6 @@ class CreateOutputSystemByPackOutputSecurityLake(BaseModel): ] = None r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - deadletter_path: Annotated[ Optional[str], pydantic.Field(alias="deadletterPath") ] = None @@ -13031,97 +13359,38 @@ class CreateOutputSystemByPackOutputSecurityLake(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_base_file_name: Annotated[ Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") - ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") - ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - - template_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_accountId") - ] = None - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - - template_custom_source: Annotated[ - Optional[str], pydantic.Field(alias="__template_customSource") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: Annotated[ Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: return models.BackpressureBehaviorOptionsBlockDrop(value) @@ -13138,29 +13407,29 @@ def serialize_on_disk_full_backpressure(self, value): return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.ObjectACLOptions(value) + return models.CreateOutputSystemByPackOutputCriblLakeFormat(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.StorageClassOptions(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value @@ -13191,19 +13460,11 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "endpoint", - "enableAssumeRole", - "assumeRoleExternalId", - "durationSeconds", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", + "stagePath", "addIdToStagePath", "removeEmptyDirs", "baseFileName", + "fileNameSuffix", "maxFileSizeMB", "maxFileOpenTimeSec", "maxFileIdleTimeSec", @@ -13216,12 +13477,18 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", - "kmsKeyId", + "storageLocationId", + "destPath", + "format", + "dynamicDataset", + "maxClosingFilesToBackpressure", + "maxConcurrentFileParts", + "freshnessGracePeriodSec", + "description", + "compress", + "compressionLevel", "automaticSchema", + "parquetSchema", "parquetVersion", "parquetDataPageVersion", "parquetRowGroupLength", @@ -13231,30 +13498,16 @@ def serialize_model(self, handler): "enableStatistics", "enableWritePageIndex", "enablePageChecksum", - "description", - "awsApiKey", - "awsSecret", "emptyDirCleanupSec", "directoryBatchSize", - "parquetSchema", "deadletterPath", "maxRetryNum", "__template_streamtags", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_bucket", - "__template_region", "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", - "__template_accountId", - "__template_customSource", - "__template_awsApiKey", + "__template_destPath", + "__template_compress", "__template_parquetSchema", ] ) @@ -13272,35 +13525,35 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputDlS3Type(str, Enum): - r"""Connector type identifier.""" - - DL_S3 = "dl_s3" - - -class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): +class CreateOutputSystemByPackOutputSecurityLakeTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDlS3Type + type: TypeOptionsSecuritylake r"""Connector type identifier.""" + assume_role_arn: str + r"""Amazon Resource Name (ARN) of the role to assume""" bucket: str r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + region: str + r"""Region where the Amazon Security Lake is located.""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + account_id: str + r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" + custom_source: str + r"""Name of the custom source configured in Amazon Security Lake""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" enable_assume_role: NotRequired[bool] r"""Use Assume Role credentials to access S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" assume_role_external_id: NotRequired[str] r"""External ID to use when assuming role""" duration_seconds: NotRequired[float] @@ -13311,10 +13564,6 @@ class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the S3 bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" verify_permissions: NotRequired[bool] @@ -13325,12 +13574,8 @@ class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): r"""Add the Output ID value to staging location""" remove_empty_dirs: NotRequired[bool] r"""Remove empty staging directories after moving files""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" base_file_name: NotRequired[str] r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" max_file_size_mb: NotRequired[float] r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" max_file_open_time_sec: NotRequired[float] @@ -13355,7 +13600,7 @@ class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + r"""Secret key""" object_acl: NotRequired[ObjectACLOptions] r"""Object ACL to assign to uploaded objects""" storage_class: NotRequired[StorageClassOptions] @@ -13364,22 +13609,8 @@ class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): r"""Server-side encryption to use for uploaded objects""" kms_key_id: NotRequired[str] r"""ID or ARN of the KMS customer-managed key to use for encryption""" - partitioning_fields: NotRequired[List[str]] - r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" automatic_schema: NotRequired[bool] r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" parquet_version: NotRequired[ParquetVersionOptions] r"""Determines which data types are supported and how they are represented""" parquet_data_page_version: NotRequired[DataPageVersionOptions] @@ -13398,10 +13629,18 @@ class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" enable_page_checksum: NotRequired[bool] r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" empty_dir_cleanup_sec: NotRequired[float] r"""How frequently, in seconds, to clean up empty directories""" directory_batch_size: NotRequired[float] r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" deadletter_path: NotRequired[str] r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] @@ -13418,14 +13657,8 @@ class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_base_file_name: NotRequired[str] r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_aws_secret_key: NotRequired[str] @@ -13438,36 +13671,48 @@ class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" template_kms_key_id: NotRequired[str] r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_partitioning_fields: NotRequired[str] - r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + template_account_id: NotRequired[str] + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + template_custom_source: NotRequired[str] + r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" template_aws_api_key: NotRequired[str] r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputSystemByPackOutputDlS3(BaseModel): +class CreateOutputSystemByPackOutputSecurityLake(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDlS3Type + type: TypeOptionsSecuritylake r"""Connector type identifier.""" + assume_role_arn: Annotated[str, pydantic.Field(alias="assumeRoleArn")] + r"""Amazon Resource Name (ARN) of the role to assume""" + bucket: str r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + region: str + r"""Region where the Amazon Security Lake is located.""" + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + account_id: Annotated[str, pydantic.Field(alias="accountId")] + r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" + + custom_source: Annotated[str, pydantic.Field(alias="customSource")] + r"""Name of the custom source configured in Amazon Security Lake""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -13476,18 +13721,13 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): r"""Metadata tags used for categorization and filtering.""" endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" enable_assume_role: Annotated[ Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None r"""Use Assume Role credentials to access S3""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: Annotated[ Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None @@ -13514,12 +13754,6 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: Optional[str] = None - r"""Region where the S3 bucket is located""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: Annotated[ Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None @@ -13545,21 +13779,11 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): ] = None r"""Remove empty staging directories after moving files""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( None ) r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: Annotated[ Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None @@ -13620,7 +13844,7 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( None ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + r"""Secret key""" object_acl: Annotated[ Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") @@ -13641,38 +13865,11 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None r"""ID or ARN of the KMS customer-managed key to use for encryption""" - partitioning_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="partitioningFields") - ] = None - r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - automatic_schema: Annotated[ Optional[bool], pydantic.Field(alias="automaticSchema") ] = None r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: Annotated[ Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None @@ -13719,6 +13916,15 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): ] = None r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + empty_dir_cleanup_sec: Annotated[ Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None @@ -13729,6 +13935,11 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): ] = None r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + deadletter_path: Annotated[ Optional[str], pydantic.Field(alias="deadletterPath") ] = None @@ -13769,26 +13980,11 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: Annotated[ Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None @@ -13819,21 +14015,21 @@ class CreateOutputSystemByPackOutputDlS3(BaseModel): ] = None r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_partitioning_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitioningFields") + template_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_accountId") ] = None - r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + + template_custom_source: Annotated[ + Optional[str], pydantic.Field(alias="__template_customSource") + ] = None + r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" template_aws_api_key: Annotated[ Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: Annotated[ Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None @@ -13848,15 +14044,6 @@ def serialize_aws_authentication_method(self, value): return value return value - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -13902,24 +14089,6 @@ def serialize_server_side_encryption(self, value): return value return value - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value - @field_serializer("parquet_version") def serialize_parquet_version(self, value): if isinstance(value, str): @@ -13948,22 +14117,17 @@ def serialize_model(self, handler): "streamtags", "endpoint", "enableAssumeRole", - "assumeRoleArn", "assumeRoleExternalId", "durationSeconds", "awsAuthenticationMethod", "reuseConnections", "rejectUnauthorized", - "region", - "destPath", "maxConcurrentFileParts", "verifyPermissions", "maxClosingFilesToBackpressure", "addIdToStagePath", "removeEmptyDirs", - "format", "baseFileName", - "fileNameSuffix", "maxFileSizeMB", "maxFileOpenTimeSec", "maxFileIdleTimeSec", @@ -13981,14 +14145,7 @@ def serialize_model(self, handler): "storageClass", "serverSideEncryption", "kmsKeyId", - "partitioningFields", - "description", - "awsApiKey", - "awsSecret", - "compress", - "compressionLevel", "automaticSchema", - "parquetSchema", "parquetVersion", "parquetDataPageVersion", "parquetRowGroupLength", @@ -13998,8 +14155,12 @@ def serialize_model(self, handler): "enableStatistics", "enableWritePageIndex", "enablePageChecksum", + "description", + "awsApiKey", + "awsSecret", "emptyDirCleanupSec", "directoryBatchSize", + "parquetSchema", "deadletterPath", "maxRetryNum", "__template_streamtags", @@ -14008,19 +14169,16 @@ def serialize_model(self, handler): "__template_assumeRoleExternalId", "__template_bucket", "__template_region", - "__template_destPath", - "__template_format", "__template_baseFileName", - "__template_fileNameSuffix", "__template_onBackpressure", "__template_awsSecretKey", "__template_objectACL", "__template_storageClass", "__template_serverSideEncryption", "__template_kmsKeyId", - "__template_partitioningFields", + "__template_accountId", + "__template_customSource", "__template_awsApiKey", - "__template_compress", "__template_parquetSchema", ] ) @@ -14038,33 +14196,21 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType(str, Enum): +class CreateOutputSystemByPackOutputDlS3Type(str, Enum): r"""Connector type identifier.""" - CROWDSTRIKE_NEXT_GEN_SIEM = "crowdstrike_next_gen_siem" - - -class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControlsTypedDict( - TypedDict -): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControls(BaseModel): - r"""Persistent queue controls.""" + DL_S3 = "dl_s3" -class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): +class CreateOutputSystemByPackOutputDlS3TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType + type: CreateOutputSystemByPackOutputDlS3Type r"""Connector type identifier.""" - url: str - r"""URL provided from a CrowdStrike data connector. - Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector - """ - format_: RequestFormatOptions - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -14073,100 +14219,171 @@ class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the S3 bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + partitioning_fields: NotRequired[List[str]] + r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""Next-Gen SIEM authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControlsTypedDict - ] - r"""Persistent queue controls.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_partitioning_fields: NotRequired[str] + r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiem(BaseModel): +class CreateOutputSystemByPackOutputDlS3(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType + type: CreateOutputSystemByPackOutputDlS3Type r"""Connector type identifier.""" - url: str - r"""URL provided from a CrowdStrike data connector. - Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector - """ + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -14182,180 +14399,375 @@ class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiem(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Use Assume Role credentials to access S3""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""External ID to use when assuming role""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Headers to add to all events""" + r"""Reuse connections between requests, which can improve performance""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + region: Optional[str] = None + r"""Region where the S3 bucket is located""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") ] = None + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Add the Output ID value to staging location""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""Remove empty staging directories after moving files""" - token: Optional[str] = None - r"""Next-Gen SIEM authentication token""" + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""Codec to use to compress the persisted data""" + r"""How to handle events when all receivers are exerting backpressure""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControls], - pydantic.Field(alias="pqControls"), + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") ] = None - r"""Persistent queue controls.""" + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Object ACL to assign to uploaded objects""" + + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + ] = None + r"""Storage class to select for uploaded objects""" + + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" + + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + + partitioning_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="partitioningFields") + ] = None + r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" + + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") + ] = None + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + ] = None + r"""Determines which data types are supported and how they are represented""" + + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") + ] = None + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), + ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") + ] = None + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") + ] = None + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" + + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") + ] = None + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") + ] = None + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + ] = None + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") + ] = None + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + + template_partitioning_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitioningFields") + ] = None + r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -14364,100 +14776,176 @@ def serialize_failed_request_logging_mode(self, value): def serialize_format_(self, value): if isinstance(value, str): try: - return models.RequestFormatOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.StorageClassOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ServerSideEncryptionForUploadedObjectsOptions(value) except ValueError: return value return value - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "endpoint", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", + "partitioningFields", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_bucket", + "__template_region", + "__template_destPath", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", + "__template_partitioningFields", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -14474,27 +14962,31 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputHumioHecType(str, Enum): +class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType(str, Enum): r"""Connector type identifier.""" - HUMIO_HEC = "humio_hec" + CROWDSTRIKE_NEXT_GEN_SIEM = "crowdstrike_next_gen_siem" -class CreateOutputSystemByPackOutputHumioHecPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControlsTypedDict( + TypedDict +): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputHumioHecPqControls(BaseModel): +class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputHumioHecTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputHumioHecType + type: CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType r"""Connector type identifier.""" url: str - r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + r"""URL provided from a CrowdStrike data connector. + Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector + """ format_: RequestFormatOptions r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" pipeline: NotRequired[str] @@ -14532,7 +15024,7 @@ class CreateOutputSystemByPackOutputHumioHecTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -14546,7 +15038,7 @@ class CreateOutputSystemByPackOutputHumioHecTypedDict(TypedDict): description: NotRequired[str] r"""Optional description for this configuration.""" token: NotRequired[str] - r"""CrowdStrike Falcon LogScale authentication token""" + r"""Next-Gen SIEM authentication token""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] @@ -14571,7 +15063,9 @@ class CreateOutputSystemByPackOutputHumioHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputHumioHecPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -14583,15 +15077,17 @@ class CreateOutputSystemByPackOutputHumioHecTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputHumioHec(BaseModel): +class CreateOutputSystemByPackOutputCrowdstrikeNextGenSiem(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputHumioHecType + type: CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemType r"""Connector type identifier.""" url: str - r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + r"""URL provided from a CrowdStrike data connector. + Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector + """ format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" @@ -14670,7 +15166,7 @@ class CreateOutputSystemByPackOutputHumioHec(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -14699,7 +15195,7 @@ class CreateOutputSystemByPackOutputHumioHec(BaseModel): r"""Optional description for this configuration.""" token: Optional[str] = None - r"""CrowdStrike Falcon LogScale authentication token""" + r"""Next-Gen SIEM authentication token""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -14754,7 +15250,7 @@ class CreateOutputSystemByPackOutputHumioHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputHumioHecPqControls], + Optional[CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -14801,7 +15297,7 @@ def serialize_format_(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -14902,25 +15398,29 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputCriblSearchEngineType(str, Enum): +class CreateOutputSystemByPackOutputHumioHecType(str, Enum): r"""Connector type identifier.""" - CRIBL_SEARCH_ENGINE = "cribl_search_engine" + HUMIO_HEC = "humio_hec" -class CreateOutputSystemByPackOutputCriblSearchEnginePqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputHumioHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCriblSearchEnginePqControls(BaseModel): +class CreateOutputSystemByPackOutputHumioHecPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCriblSearchEngineTypedDict(TypedDict): +class CreateOutputSystemByPackOutputHumioHecTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCriblSearchEngineType + type: CreateOutputSystemByPackOutputHumioHecType r"""Connector type identifier.""" + url: str + r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + format_: RequestFormatOptions + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -14929,22 +15429,14 @@ class CreateOutputSystemByPackOutputCriblSearchEngineTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - exclude_fields: NotRequired[List[str]] - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -14958,12 +15450,14 @@ class CreateOutputSystemByPackOutputCriblSearchEngineTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -14971,24 +15465,14 @@ class CreateOutputSystemByPackOutputCriblSearchEngineTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] - r"""Cribl Worker endpoints""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""CrowdStrike Falcon LogScale authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15011,27 +15495,31 @@ class CreateOutputSystemByPackOutputCriblSearchEngineTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputCriblSearchEnginePqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputSystemByPackOutputHumioHecPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): +class CreateOutputSystemByPackOutputHumioHec(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCriblSearchEngineType + type: CreateOutputSystemByPackOutputHumioHecType r"""Connector type identifier.""" + url: str + r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + + format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -15046,29 +15534,8 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") - ] = None - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") - ] = None - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - - compression: Optional[CompressionOptionsGzipNone] = None - r"""Codec to use to compress the data before sending""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") @@ -15080,6 +15547,9 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): ] = None r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -15107,6 +15577,11 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -15118,10 +15593,11 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], @@ -15138,42 +15614,19 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: Annotated[ - Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[URLConfOutputCriblHTTP]] = None - r"""Cribl Worker endpoints""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + token: Optional[str] = None + r"""CrowdStrike Falcon LogScale authentication token""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -15225,7 +15678,7 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputCriblSearchEnginePqControls], + Optional[CreateOutputSystemByPackOutputHumioHecPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -15235,6 +15688,11 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -15245,25 +15703,29 @@ class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipNone(value) + return models.RequestFormatOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -15312,34 +15774,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "tls", - "tokenTTLMinutes", - "excludeFields", - "compression", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", + "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "throttleRatePerSec", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "authTokens", "onBackpressure", - "useRoundRobinDns", "description", - "url", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -15353,9 +15807,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", ] ) serialized = handler(self) @@ -15372,24 +15826,35 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputCriblHTTPType(str, Enum): +class CreateOutputSystemByPackOutputCriblSearchEngineType(str, Enum): r"""Connector type identifier.""" - CRIBL_HTTP = "cribl_http" + CRIBL_SEARCH_ENGINE = "cribl_search_engine" -class CreateOutputSystemByPackOutputCriblHTTPPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackSendAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + + # Logs + LOGS = "logs" + # Metrics + METRICS = "metrics" + # Logs and Metrics + BOTH = "both" + + +class CreateOutputSystemByPackOutputCriblSearchEnginePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCriblHTTPPqControls(BaseModel): +class CreateOutputSystemByPackOutputCriblSearchEnginePqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCriblHTTPTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCriblSearchEngineTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCriblHTTPType + type: CreateOutputSystemByPackOutputCriblSearchEngineType r"""Connector type identifier.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -15442,15 +15907,17 @@ class CreateOutputSystemByPackOutputCriblHTTPTypedDict(TypedDict): response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + send_as: NotRequired[CreateOutputSystemByPackSendAs] + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" description: NotRequired[str] r"""Optional description for this configuration.""" url: NotRequired[str] r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] @@ -15481,7 +15948,9 @@ class CreateOutputSystemByPackOutputCriblHTTPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputCriblHTTPPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputCriblSearchEnginePqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -15493,11 +15962,11 @@ class CreateOutputSystemByPackOutputCriblHTTPTypedDict(TypedDict): r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputCriblHTTP(BaseModel): +class CreateOutputSystemByPackOutputCriblSearchEngine(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCriblHTTPType + type: CreateOutputSystemByPackOutputCriblSearchEngineType r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -15609,24 +16078,29 @@ class CreateOutputSystemByPackOutputCriblHTTP(BaseModel): auth_tokens: Annotated[ Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - url: Optional[str] = None - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" + send_as: Annotated[ + Optional[CreateOutputSystemByPackSendAs], pydantic.Field(alias="sendAs") + ] = None + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + url: Optional[str] = None + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" @@ -15693,7 +16167,7 @@ class CreateOutputSystemByPackOutputCriblHTTP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputCriblHTTPPqControls], + Optional[CreateOutputSystemByPackOutputCriblSearchEnginePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -15745,6 +16219,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("send_as") + def serialize_send_as(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackSendAs(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -15801,9 +16284,10 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "authTokens", "onBackpressure", + "sendAs", + "useRoundRobinDns", "description", "url", - "useRoundRobinDns", "excludeSelf", "urls", "dnsResolvePeriodSec", @@ -15840,18 +16324,24 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputCriblTCPPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCriblHTTPType(str, Enum): + r"""Connector type identifier.""" + + CRIBL_HTTP = "cribl_http" + + +class CreateOutputSystemByPackOutputCriblHTTPPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCriblTCPPqControls(BaseModel): +class CreateOutputSystemByPackOutputCriblHTTPPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCriblTCPTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCriblHTTPTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsCribltcp + type: CreateOutputSystemByPackOutputCriblHTTPType r"""Connector type identifier.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -15862,43 +16352,65 @@ class CreateOutputSystemByPackOutputCriblTCPTypedDict(TypedDict): streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" load_balanced: NotRequired[bool] - r"""Use load-balanced destinations""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" exclude_fields: NotRequired[List[str]] r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" + url: NotRequired[str] + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" + urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] + r"""Cribl Worker endpoints""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15921,23 +16433,23 @@ class CreateOutputSystemByPackOutputCriblTCPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputCriblTCPPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputCriblHTTPPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputCriblTCP(BaseModel): +class CreateOutputSystemByPackOutputCriblHTTP(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsCribltcp + type: CreateOutputSystemByPackOutputCriblHTTPType r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -15957,48 +16469,99 @@ class CreateOutputSystemByPackOutputCriblTCP(BaseModel): load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Use load-balanced destinations""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") + ] = None + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" + + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") + ] = None + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" compression: Optional[CompressionOptionsGzipNone] = None r"""Codec to use to compress the data before sending""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" throttle_rate_per_sec: Annotated[ Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") ] = None - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -16008,17 +16571,19 @@ class CreateOutputSystemByPackOutputCriblTCP(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - host: Optional[str] = None - r"""The hostname of the receiver""" + url: Optional[str] = None + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - port: Optional[float] = None - r"""The port to connect to on the provided host""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" + urls: Optional[List[URLConfOutputCriblHTTP]] = None + r"""Cribl Worker endpoints""" dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") @@ -16030,11 +16595,6 @@ class CreateOutputSystemByPackOutputCriblTCP(BaseModel): ] = None r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") - ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -16085,7 +16645,7 @@ class CreateOutputSystemByPackOutputCriblTCP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputCriblTCPPqControls], + Optional[CreateOutputSystemByPackOutputCriblHTTPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -16095,20 +16655,20 @@ class CreateOutputSystemByPackOutputCriblTCP(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" @field_serializer("compression") def serialize_compression(self, value): @@ -16119,6 +16679,15 @@ def serialize_compression(self, value): return value return value + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -16164,24 +16733,33 @@ def serialize_model(self, handler): "environment", "streamtags", "loadBalanced", - "compression", - "logFailedRequests", - "throttleRatePerSec", "tls", - "connectionTimeout", - "writeTimeout", "tokenTTLMinutes", - "authTokens", "excludeFields", + "compression", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "throttleRatePerSec", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "authTokens", "onBackpressure", "description", - "host", - "port", + "url", + "useRoundRobinDns", "excludeSelf", - "hosts", + "urls", "dnsResolvePeriodSec", "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16195,9 +16773,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_host", - "__template_port", + "__template_url", ] ) serialized = handler(self) @@ -16214,56 +16792,18 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputDatasetType(str, Enum): - r"""Connector type identifier.""" - - DATASET = "dataset" - - -class CreateOutputSystemByPackOutputDatasetSeverity( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - - # 0 - finest - FINEST = "finest" - # 1 - finer - FINER = "finer" - # 2 - fine - FINE = "fine" - # 3 - info - INFO = "info" - # 4 - warning - WARNING = "warning" - # 5 - error - ERROR = "error" - # 6 - fatal - FATAL = "fatal" - - -class CreateOutputSystemByPackDataSetSite(str, Enum, metaclass=utils.OpenEnumMeta): - r"""DataSet site to which events should be sent""" - - # US - US = "us" - # Europe - EU = "eu" - # Custom - CUSTOM = "custom" - - -class CreateOutputSystemByPackOutputDatasetPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCriblTCPPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputDatasetPqControls(BaseModel): +class CreateOutputSystemByPackOutputCriblTCPPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputDatasetTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCriblTCPTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDatasetType + type: TypeOptionsCribltcp r"""Connector type identifier.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -16273,61 +16813,44 @@ class CreateOutputSystemByPackOutputDatasetTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - message_field: NotRequired[str] - r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" + load_balanced: NotRequired[bool] + r"""Use load-balanced destinations""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + token_ttl_minutes: NotRequired[float] + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" exclude_fields: NotRequired[List[str]] - r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - server_host_field: NotRequired[str] - r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - timestamp_field: NotRequired[str] - r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - default_severity: NotRequired[CreateOutputSystemByPackOutputDatasetSeverity] - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - site: NotRequired[CreateOutputSystemByPackDataSetSite] - r"""DataSet site to which events should be sent""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16350,27 +16873,23 @@ class CreateOutputSystemByPackOutputDatasetTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputDatasetPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputCriblTCPPqControlsTypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""A 'Log Write Access' API key for the DataSet account""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: NotRequired[str] - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputSystemByPackOutputDataset(BaseModel): +class CreateOutputSystemByPackOutputCriblTCP(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDatasetType + type: TypeOptionsCribltcp r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -16387,126 +16906,86 @@ class CreateOutputSystemByPackOutputDataset(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None - r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" - - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") - ] = None - r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - - server_host_field: Annotated[ - Optional[str], pydantic.Field(alias="serverHostField") - ] = None - r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Use load-balanced destinations""" - timestamp_field: Annotated[ - Optional[str], pydantic.Field(alias="timestampField") - ] = None - r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" + compression: Optional[CompressionOptionsGzipNone] = None + r"""Codec to use to compress the data before sending""" - default_severity: Annotated[ - Optional[CreateOutputSystemByPackOutputDatasetSeverity], - pydantic.Field(alias="defaultSeverity"), + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" + r"""Use to troubleshoot issues with sending data""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - site: Optional[CreateOutputSystemByPackDataSetSite] = None - r"""DataSet site to which events should be sent""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") ] = None - r"""Maximum size, in KB, of the request body""" + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""How to handle events when all receivers are exerting backpressure""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + host: Optional[str] = None + r"""The hostname of the receiver""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + port: Optional[float] = None + r"""The port to connect to on the provided host""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Enter API key directly, or select a stored secret""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16558,66 +17037,42 @@ class CreateOutputSystemByPackOutputDataset(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputDatasetPqControls], + Optional[CreateOutputSystemByPackOutputCriblTCPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""A 'Log Write Access' API key for the DataSet account""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_customUrl") - ] = None - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - @field_serializer("default_severity") - def serialize_default_severity(self, value): + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + @field_serializer("compression") + def serialize_compression(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputDatasetSeverity(value) + return models.CompressionOptionsGzipNone(value) except ValueError: return value return value - @field_serializer("site") - def serialize_site(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackDataSetSite(value) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: return models.BackpressureBehaviorOptions(value) @@ -16625,15 +17080,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -16669,32 +17115,25 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "messageField", + "loadBalanced", + "compression", + "logFailedRequests", + "throttleRatePerSec", + "tls", + "connectionTimeout", + "writeTimeout", + "tokenTTLMinutes", + "authTokens", "excludeFields", - "serverHostField", - "timestampField", - "defaultSeverity", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "site", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", "onBackpressure", - "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16707,12 +17146,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_customUrl", + "__template_host", + "__template_port", ] ) serialized = handler(self) @@ -16729,33 +17166,57 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputServiceNowType(str, Enum): +class CreateOutputSystemByPackOutputDatasetType(str, Enum): r"""Connector type identifier.""" - SERVICE_NOW = "service_now" + DATASET = "dataset" -class CreateOutputSystemByPackOutputServiceNowPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputDatasetSeverity( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" + + # 0 - finest + FINEST = "finest" + # 1 - finer + FINER = "finer" + # 2 - fine + FINE = "fine" + # 3 - info + INFO = "info" + # 4 - warning + WARNING = "warning" + # 5 - error + ERROR = "error" + # 6 - fatal + FATAL = "fatal" + + +class CreateOutputSystemByPackDataSetSite(str, Enum, metaclass=utils.OpenEnumMeta): + r"""DataSet site to which events should be sent""" + + # US + US = "us" + # Europe + EU = "eu" + # Custom + CUSTOM = "custom" + + +class CreateOutputSystemByPackOutputDatasetPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputServiceNowPqControls(BaseModel): +class CreateOutputSystemByPackOutputDatasetPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputServiceNowTypedDict(TypedDict): +class CreateOutputSystemByPackOutputDatasetTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputServiceNowType + type: CreateOutputSystemByPackOutputDatasetType r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - token_secret: str - r"""Select or create a stored text secret""" - otlp_version: OtlpVersionOptions - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - protocol: ProtocolOptions - r"""Select a transport option for OpenTelemetry""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -16764,68 +17225,61 @@ class CreateOutputSystemByPackOutputServiceNowTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_token_name: NotRequired[str] - r"""Auth token name""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - compress: NotRequired[CompressionOptionsDeflateGzip] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_compress: NotRequired[CompressionOptionsMessages] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: NotRequired[str] - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_metrics_endpoint_override: NotRequired[str] - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: NotRequired[str] - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + message_field: NotRequired[str] + r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" + exclude_fields: NotRequired[List[str]] + r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" + server_host_field: NotRequired[str] + r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" + timestamp_field: NotRequired[str] + r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" + default_severity: NotRequired[CreateOutputSystemByPackOutputDatasetSeverity] + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + site: NotRequired[CreateOutputSystemByPackDataSetSite] + r"""DataSet site to which events should be sent""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] - r"""TLS settings (client side)""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16848,37 +17302,29 @@ class CreateOutputSystemByPackOutputServiceNowTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputServiceNowPqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputSystemByPackOutputDatasetPqControlsTypedDict] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""A 'Log Write Access' API key for the DataSet account""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_custom_url: NotRequired[str] + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" -class CreateOutputSystemByPackOutputServiceNow(BaseModel): +class CreateOutputSystemByPackOutputDataset(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputServiceNowType + type: CreateOutputSystemByPackOutputDatasetType r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - - token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] - r"""Select or create a stored text secret""" - - otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - - protocol: ProtocolOptions - r"""Select a transport option for OpenTelemetry""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -16893,59 +17339,71 @@ class CreateOutputSystemByPackOutputServiceNow(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( - None - ) - r"""Auth token name""" + message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None + r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + server_host_field: Annotated[ + Optional[str], pydantic.Field(alias="serverHostField") ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - compress: Optional[CompressionOptionsDeflateGzip] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + timestamp_field: Annotated[ + Optional[str], pydantic.Field(alias="timestampField") + ] = None + r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - http_compress: Annotated[ - Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + default_severity: Annotated[ + Optional[CreateOutputSystemByPackOutputDatasetSeverity], + pydantic.Field(alias="defaultSeverity"), ] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - http_traces_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - http_metrics_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + site: Optional[CreateOutputSystemByPackDataSetSite] = None + r"""DataSet site to which events should be sent""" - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + r"""Maximum size, in KB, of the request body""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -16960,74 +17418,47 @@ class CreateOutputSystemByPackOutputServiceNow(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often the sender should ping the peer to keep the connection open""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Headers to add to all events""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None r"""List of headers that are safe to log in plain text""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""How to handle events when all receivers are exerting backpressure""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") ] = None + r"""Enter API key directly, or select a stored secret""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - tls: Optional[TLSSettingsClientSideTypeExtended] = None - r"""TLS settings (client side)""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17079,11 +17510,17 @@ class CreateOutputSystemByPackOutputServiceNow(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputServiceNowPqControls], + Optional[CreateOutputSystemByPackOutputDatasetPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""A 'Log Write Access' API key for the DataSet account""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -17099,38 +17536,25 @@ class CreateOutputSystemByPackOutputServiceNow(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.OtlpVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptions(value) - except ValueError: - return value - return value + template_custom_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_customUrl") + ] = None + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("default_severity") + def serialize_default_severity(self, value): if isinstance(value, str): try: - return models.CompressionOptionsDeflateGzip(value) + return models.CreateOutputSystemByPackOutputDatasetSeverity(value) except ValueError: return value return value - @field_serializer("http_compress") - def serialize_http_compress(self, value): + @field_serializer("site") + def serialize_site(self, value): if isinstance(value, str): try: - return models.CompressionOptionsMessages(value) + return models.CreateOutputSystemByPackDataSetSite(value) except ValueError: return value return value @@ -17153,6 +17577,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -17188,35 +17621,32 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authTokenName", + "messageField", + "excludeFields", + "serverHostField", + "timestampField", + "defaultSeverity", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "site", + "concurrency", "maxPayloadSizeKB", - "preserveNativeAnyValue", + "maxPayloadEvents", "compress", - "httpCompress", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", - "httpLogsEndpointOverride", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", - "concurrency", + "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "keepAlive", + "safeHeaders", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "rejectUnauthorized", - "useRoundRobinDns", - "extraHttpHeaders", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "tls", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17229,9 +17659,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_customUrl", ] ) serialized = handler(self) @@ -17248,57 +17681,33 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputOpenTelemetryType(str, Enum): +class CreateOutputSystemByPackOutputServiceNowType(str, Enum): r"""Connector type identifier.""" - OPEN_TELEMETRY = "open_telemetry" - + SERVICE_NOW = "service_now" -class CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - # 0.10.0 - ZERO_DOT_10_DOT_0 = "0.10.0" - # 1.3.1 - ONE_DOT_3_DOT_1 = "1.3.1" +class CreateOutputSystemByPackOutputServiceNowPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" +class CreateOutputSystemByPackOutputServiceNowPqControls(BaseModel): + r"""Persistent queue controls.""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth (text secret) - OAUTH_SECRET = "oauthSecret" - -class CreateOutputSystemByPackOutputOpenTelemetryPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputOpenTelemetryPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputOpenTelemetryTypedDict(TypedDict): +class CreateOutputSystemByPackOutputServiceNowTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputOpenTelemetryType + type: CreateOutputSystemByPackOutputServiceNowType r"""Connector type identifier.""" endpoint: str - r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" + r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + token_secret: str + r"""Select or create a stored text secret""" + otlp_version: OtlpVersionOptions + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + protocol: ProtocolOptions + r"""Select a transport option for OpenTelemetry""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -17307,20 +17716,16 @@ class CreateOutputSystemByPackOutputOpenTelemetryTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[ProtocolOptions] - r"""Select a transport option for OpenTelemetry""" - otlp_version: NotRequired[CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + auth_token_name: NotRequired[str] + r"""Auth token name""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" preserve_native_any_value: NotRequired[bool] r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" compress: NotRequired[CompressionOptionsDeflateGzip] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" http_compress: NotRequired[CompressionOptionsMessages] r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - auth_type: NotRequired[ - CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType - ] - r"""Authentication type""" http_traces_endpoint_override: NotRequired[str] r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" http_metrics_endpoint_override: NotRequired[str] @@ -17335,8 +17740,6 @@ class CreateOutputSystemByPackOutputOpenTelemetryTypedDict(TypedDict): r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] @@ -17355,32 +17758,6 @@ class CreateOutputSystemByPackOutputOpenTelemetryTypedDict(TypedDict): r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" - oauth_text_secret: NotRequired[str] - r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -17424,7 +17801,7 @@ class CreateOutputSystemByPackOutputOpenTelemetryTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputOpenTelemetryPqControlsTypedDict + CreateOutputSystemByPackOutputServiceNowPqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] @@ -17433,19 +17810,26 @@ class CreateOutputSystemByPackOutputOpenTelemetryTypedDict(TypedDict): r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" -class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): +class CreateOutputSystemByPackOutputServiceNow(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputOpenTelemetryType + type: CreateOutputSystemByPackOutputServiceNowType r"""Connector type identifier.""" endpoint: str - r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" + r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" + + otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + protocol: ProtocolOptions + r"""Select a transport option for OpenTelemetry""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -17461,14 +17845,15 @@ class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[ProtocolOptions] = None - r"""Select a transport option for OpenTelemetry""" + auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( + None + ) + r"""Auth token name""" - otlp_version: Annotated[ - Optional[CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion], - pydantic.Field(alias="otlpVersion"), + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + r"""Maximum size, in KB, of the request body""" preserve_native_any_value: Annotated[ Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") @@ -17483,12 +17868,6 @@ class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): ] = None r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""Authentication type""" - http_traces_endpoint_override: Annotated[ Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") ] = None @@ -17520,11 +17899,6 @@ class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -17565,63 +17939,6 @@ class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - - oauth_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="oauthTextSecret") - ] = None - r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" - - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -17714,7 +18031,7 @@ class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputOpenTelemetryPqControls], + Optional[CreateOutputSystemByPackOutputServiceNowPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -17734,27 +18051,20 @@ class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - @field_serializer("protocol") - def serialize_protocol(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.ProtocolOptions(value) + return models.OtlpVersionOptions(value) except ValueError: return value return value - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion( - value - ) + return models.ProtocolOptions(value) except ValueError: return value return value @@ -17777,17 +18087,6 @@ def serialize_http_compress(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType( - value - ) - except ValueError: - return value - return value - @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -17841,12 +18140,11 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "otlpVersion", + "authTokenName", + "maxPayloadSizeKB", "preserveNativeAnyValue", "compress", "httpCompress", - "authType", "httpTracesEndpointOverride", "httpMetricsEndpointOverride", "httpLogsEndpointOverride", @@ -17854,7 +18152,6 @@ def serialize_model(self, handler): "dynamicHeadersEnabled", "dynamicHeadersField", "concurrency", - "maxPayloadSizeKB", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", @@ -17864,19 +18161,6 @@ def serialize_model(self, handler): "keepAlive", "onBackpressure", "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", - "oauthTextSecret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", "rejectUnauthorized", "useRoundRobinDns", "extraHttpHeaders", @@ -17900,7 +18184,6 @@ def serialize_model(self, handler): "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_loginUrl", ] ) serialized = handler(self) @@ -17917,26 +18200,57 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputRingType(str, Enum): +class CreateOutputSystemByPackOutputOpenTelemetryType(str, Enum): r"""Connector type identifier.""" - RING = "ring" + OPEN_TELEMETRY = "open_telemetry" -class CreateOutputSystemByPackOutputRingDataFormat( +class CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Format of the output data.""" + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - JSON = "json" - RAW = "raw" + # 0.10.0 + ZERO_DOT_10_DOT_0 = "0.10.0" + # 1.3.1 + ONE_DOT_3_DOT_1 = "1.3.1" -class CreateOutputSystemByPackOutputRingTypedDict(TypedDict): +class CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth (text secret) + OAUTH_SECRET = "oauthSecret" + + +class CreateOutputSystemByPackOutputOpenTelemetryPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputOpenTelemetryPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputOpenTelemetryTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputRingType + type: CreateOutputSystemByPackOutputOpenTelemetryType r"""Connector type identifier.""" + endpoint: str + r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -17945,35 +18259,146 @@ class CreateOutputSystemByPackOutputRingTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - format_: NotRequired[CreateOutputSystemByPackOutputRingDataFormat] - r"""Format of the output data.""" - partition_expr: NotRequired[str] - r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + protocol: NotRequired[ProtocolOptions] + r"""Select a transport option for OpenTelemetry""" + otlp_version: NotRequired[CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + auth_type: NotRequired[ + CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType + ] + r"""Authentication type""" + http_traces_endpoint_override: NotRequired[str] + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_metrics_endpoint_override: NotRequired[str] + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputOpenTelemetryPqControlsTypedDict + ] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" -class CreateOutputSystemByPackOutputRing(BaseModel): +class CreateOutputSystemByPackOutputOpenTelemetry(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputRingType + type: CreateOutputSystemByPackOutputOpenTelemetryType r"""Connector type identifier.""" + endpoint: str + r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -17988,318 +18413,166 @@ class CreateOutputSystemByPackOutputRing(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - format_: Annotated[ - Optional[CreateOutputSystemByPackOutputRingDataFormat], - pydantic.Field(alias="format"), + protocol: Optional[ProtocolOptions] = None + r"""Select a transport option for OpenTelemetry""" + + otlp_version: Annotated[ + Optional[CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion], + pydantic.Field(alias="otlpVersion"), ] = None - r"""Format of the output data.""" + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + ] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + http_traces_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") + ] = None + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + http_metrics_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + ] = None + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Batch event data upon dynamic metadata (whether presented or not)""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputRingDataFormat(value) - except ValueError: - return value - return value + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "format", - "partitionExpr", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - "onBackpressure", - "description", - "__template_streamtags", - "__template_onBackpressure", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputPrometheusAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Remote Write authentication type""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # AWS Signature v4 - AWS_SIGV4 = "aws_sigv4" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" -class CreateOutputSystemByPackOutputPrometheusPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" -class CreateOutputSystemByPackOutputPrometheusPqControls(BaseModel): - r"""Persistent queue controls.""" + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" -class CreateOutputSystemByPackOutputPrometheusTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: TypeOptionsPrometheus - r"""Connector type identifier.""" - url: str - r"""The endpoint to send metrics to""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - send_metadata: NotRequired[bool] - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - use_prometheus_histogram_bucket_suffix: NotRequired[bool] - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputSystemByPackOutputPrometheusAuthenticationType] - r"""Remote Write authentication type""" - description: NotRequired[str] + + description: Optional[str] = None r"""Optional description for this configuration.""" - metrics_flush_period_sec: NotRequired[float] - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputPrometheusPqControlsTypedDict - ] - r"""Persistent queue controls.""" - username: NotRequired[str] + + username: Optional[str] = None r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - region: NotRequired[str] - r"""AWS region used to sign Remote Write requests""" - aws_service: NotRequired[str] - r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Prometheus""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_aws_service: NotRequired[str] - r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + password: Optional[str] = None + r"""Password""" -class CreateOutputSystemByPackOutputPrometheus(BaseModel): - id: str - r"""Unique ID for this output""" + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" - type: TypeOptionsPrometheus - r"""Connector type identifier.""" + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" - url: str - r"""The endpoint to send metrics to""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + r"""Secret parameter name to pass in request body""" - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" - send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( - None - ) - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - use_prometheus_histogram_bucket_suffix: Annotated[ - Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") ] = None - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), ] = None - r"""Maximum size, in KB, of the request body""" + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -18309,18 +18582,10 @@ class CreateOutputSystemByPackOutputPrometheus(BaseModel): that value will take precedence. """ - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -18328,17 +18593,6 @@ class CreateOutputSystemByPackOutputPrometheus(BaseModel): ] = None r"""Headers to add to all events""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None @@ -18359,24 +18613,8 @@ class CreateOutputSystemByPackOutputPrometheus(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputPrometheusAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - metrics_flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") - ] = None - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18428,73 +18666,16 @@ class CreateOutputSystemByPackOutputPrometheus(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputPrometheusPqControls], + Optional[CreateOutputSystemByPackOutputOpenTelemetryPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsAutoSecret], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - region: Optional[str] = None - r"""AWS region used to sign Remote Write requests""" - - aws_service: Annotated[Optional[str], pydantic.Field(alias="awsService")] = None - r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Prometheus""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -18503,42 +18684,47 @@ class CreateOutputSystemByPackOutputPrometheus(BaseModel): template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_aws_service: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsService") - ] = None - r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptions(value) + except ValueError: + return value + return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CreateOutputSystemByPackOutputOpenTelemetryOTLPVersion( + value + ) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptionsDeflateGzip(value) + except ValueError: + return value + return value + + @field_serializer("http_compress") + def serialize_http_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsMessages(value) except ValueError: return value return value @@ -18547,15 +18733,31 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return ( - models.CreateOutputSystemByPackOutputPrometheusAuthenticationType( - value - ) + return models.CreateOutputSystemByPackOutputOpenTelemetryAuthenticationType( + value ) except ValueError: return value return value + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -18583,15 +18785,6 @@ def serialize_pq_on_backpressure(self, value): return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAutoSecret(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -18600,27 +18793,50 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "metricRenameExpr", - "sendMetadata", - "usePrometheusHistogramBucketSuffix", + "protocol", + "otlpVersion", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "authType", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "onBackpressure", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "oauthTextSecret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "description", - "metricsFlushPeriodSec", + "tls", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -18633,27 +18849,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "awsAuthenticationMethod", - "awsSecret", - "region", - "awsService", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", "__template_streamtags", - "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_region", - "__template_awsService", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_loginUrl", ] ) serialized = handler(self) @@ -18670,167 +18869,70 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputAmazonManagedPrometheusType(str, Enum): +class CreateOutputSystemByPackOutputRingType(str, Enum): r"""Connector type identifier.""" - AMAZON_MANAGED_PROMETHEUS = "amazon_managed_prometheus" + RING = "ring" -class CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControlsTypedDict( - TypedDict +class CreateOutputSystemByPackOutputRingDataFormat( + str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Persistent queue controls.""" - + r"""Format of the output data.""" -class CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControls(BaseModel): - r"""Persistent queue controls.""" + JSON = "json" + RAW = "raw" -class CreateOutputSystemByPackOutputAmazonManagedPrometheusTypedDict(TypedDict): +class CreateOutputSystemByPackOutputRingTypedDict(TypedDict): id: str - r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAmazonManagedPrometheusType - r"""Connector type identifier.""" - url: str - r"""The Amazon Managed Service for Prometheus remote_write endpoint""" - aws_authentication_method: AuthenticationMethodOptionsAutoSecret - r"""AWS authentication method. Choose Auto to use IAM roles.""" - region: str - r"""Region where the AMSP is located""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access AMSP""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - send_metadata: NotRequired[bool] - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - use_prometheus_histogram_bucket_suffix: NotRequired[bool] - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - metrics_flush_period_sec: NotRequired[float] - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControlsTypedDict - ] - r"""Persistent queue controls.""" + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputRingType + r"""Connector type identifier.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + format_: NotRequired[CreateOutputSystemByPackOutputRingDataFormat] + r"""Format of the output data.""" + partition_expr: NotRequired[str] + r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputAmazonManagedPrometheus(BaseModel): +class CreateOutputSystemByPackOutputRing(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAmazonManagedPrometheusType + type: CreateOutputSystemByPackOutputRingType r"""Connector type identifier.""" - url: str - r"""The Amazon Managed Service for Prometheus remote_write endpoint""" - - aws_authentication_method: Annotated[ - AuthenticationMethodOptionsAutoSecret, - pydantic.Field(alias="awsAuthenticationMethod"), - ] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - region: str - r"""Region where the AMSP is located""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -18838,242 +18940,62 @@ class CreateOutputSystemByPackOutputAmazonManagedPrometheus(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access AMSP""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") + format_: Annotated[ + Optional[CreateOutputSystemByPackOutputRingDataFormat], + pydantic.Field(alias="format"), ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + r"""Format of the output data.""" - send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( None ) - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - - use_prometheus_histogram_bucket_suffix: Annotated[ - Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") - ] = None - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - metrics_flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") - ] = None - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" + r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""How to handle events when all receivers are exerting backpressure""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAutoSecret(value) + return models.CreateOutputSystemByPackOutputRingDataFormat(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataCompressionFormatOptionsPersistence(value) except ValueError: return value return value @@ -19082,34 +19004,7 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPq(value) - except ValueError: - return value - return value - - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value @@ -19122,51 +19017,15 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsSecretKey", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "metricRenameExpr", - "sendMetadata", - "usePrometheusHistogramBucketSuffix", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "format", + "partitionExpr", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", "onBackpressure", "description", - "awsSecret", - "metricsFlushPeriodSec", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", "__template_streamtags", - "__template_url", - "__template_awsSecretKey", - "__template_region", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_failedRequestLoggingMode", "__template_onBackpressure", ] ) @@ -19184,53 +19043,60 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputLokiType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputSystemByPackOutputPrometheusAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Remote Write authentication type""" - LOKI = "loki" + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # AWS Signature v4 + AWS_SIGV4 = "aws_sigv4" -class CreateOutputSystemByPackOutputLokiPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputPrometheusPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputLokiPqControls(BaseModel): +class CreateOutputSystemByPackOutputPrometheusPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputLokiTypedDict(TypedDict): +class CreateOutputSystemByPackOutputPrometheusTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputLokiType + type: TypeOptionsPrometheus r"""Connector type identifier.""" url: str - r"""The endpoint to send logs to""" + r"""The endpoint to send metrics to""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - message: NotRequired[str] - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - message_format: NotRequired[MessageFormatOptions] - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - labels: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - auth_type: NotRequired[ - AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret - ] - r"""Authentication type""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + send_metadata: NotRequired[bool] + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + use_prometheus_histogram_bucket_suffix: NotRequired[bool] + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -19241,7 +19107,7 @@ class CreateOutputSystemByPackOutputLokiTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -19257,26 +19123,14 @@ class CreateOutputSystemByPackOutputLokiTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_dynamic_headers: NotRequired[bool] - r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[CreateOutputSystemByPackOutputPrometheusAuthenticationType] + r"""Remote Write authentication type""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - username: NotRequired[str] - r"""Username for authentication""" - password: NotRequired[str] - r"""Password (API key in Grafana Cloud domain) for authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" + metrics_flush_period_sec: NotRequired[float] + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -19299,25 +19153,63 @@ class CreateOutputSystemByPackOutputLokiTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputLokiPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputPrometheusPqControlsTypedDict + ] r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + region: NotRequired[str] + r"""AWS region used to sign Remote Write requests""" + aws_service: NotRequired[str] + r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Prometheus""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_aws_service: NotRequired[str] + r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" -class CreateOutputSystemByPackOutputLoki(BaseModel): +class CreateOutputSystemByPackOutputPrometheus(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputLokiType + type: TypeOptionsPrometheus r"""Connector type identifier.""" url: str - r"""The endpoint to send logs to""" + r"""The endpoint to send metrics to""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -19325,7 +19217,7 @@ class CreateOutputSystemByPackOutputLoki(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -19333,37 +19225,33 @@ class CreateOutputSystemByPackOutputLoki(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - message: Optional[str] = None - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - - message_format: Annotated[ - Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") ] = None - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - labels: Optional[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] - ] = None - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + None + ) + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret], - pydantic.Field(alias="authType"), + use_prometheus_histogram_bucket_suffix: Annotated[ + Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") ] = None - r"""Authentication type""" + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -19384,7 +19272,7 @@ class CreateOutputSystemByPackOutputLoki(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -19423,43 +19311,24 @@ class CreateOutputSystemByPackOutputLoki(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_dynamic_headers: Annotated[ - Optional[bool], pydantic.Field(alias="enableDynamicHeaders") - ] = None - r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputPrometheusAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Remote Write authentication type""" description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - username: Optional[str] = None - r"""Username for authentication""" - - password: Optional[str] = None - r"""Password (API key in Grafana Cloud domain) for authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + metrics_flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") ] = None - r"""Select or create a secret that references your credentials""" + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19511,16 +19380,73 @@ class CreateOutputSystemByPackOutputLoki(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputLokiPqControls], + Optional[CreateOutputSystemByPackOutputPrometheusPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsAutoSecret], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + region: Optional[str] = None + r"""AWS region used to sign Remote Write requests""" + + aws_service: Annotated[Optional[str], pydantic.Field(alias="awsService")] = None + r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Prometheus""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -19531,25 +19457,25 @@ class CreateOutputSystemByPackOutputLoki(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("message_format") - def serialize_message_format(self, value): - if isinstance(value, str): - try: - return models.MessageFormatOptions(value) - except ValueError: - return value - return value + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret( - value - ) - except ValueError: - return value - return value + template_aws_service: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsService") + ] = None + r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): @@ -19569,6 +19495,19 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return ( + models.CreateOutputSystemByPackOutputPrometheusAuthenticationType( + value + ) + ) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -19596,6 +19535,15 @@ def serialize_pq_on_backpressure(self, value): return value return value + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAutoSecret(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -19604,10 +19552,9 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "message", - "messageFormat", - "labels", - "authType", + "metricRenameExpr", + "sendMetadata", + "usePrometheusHistogramBucketSuffix", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -19622,16 +19569,10 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "enableDynamicHeaders", "onBackpressure", - "totalMemoryLimitKB", + "authType", "description", - "compress", - "token", - "textSecret", - "username", - "password", - "credentialsSecret", + "metricsFlushPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -19644,9 +19585,27 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "awsAuthenticationMethod", + "awsSecret", + "region", + "awsService", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "__template_streamtags", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_region", + "__template_awsService", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", ] ) serialized = handler(self) @@ -19663,68 +19622,76 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGrafanaCloudType2(str, Enum): +class CreateOutputSystemByPackOutputAmazonManagedPrometheusType(str, Enum): r"""Connector type identifier.""" - GRAFANA_CLOUD = "grafana_cloud" + AMAZON_MANAGED_PROMETHEUS = "amazon_managed_prometheus" -class CreateOutputSystemByPackOutputGrafanaCloudPqControls2TypedDict(TypedDict): +class CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControlsTypedDict( + TypedDict +): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGrafanaCloudPqControls2(BaseModel): +class CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): +class CreateOutputSystemByPackOutputAmazonManagedPrometheusTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGrafanaCloudType2 + type: CreateOutputSystemByPackOutputAmazonManagedPrometheusType r"""Connector type identifier.""" - prometheus_url: str - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + url: str + r"""The Amazon Managed Service for Prometheus remote_write endpoint""" + aws_authentication_method: AuthenticationMethodOptionsAutoSecret + r"""AWS authentication method. Choose Auto to use IAM roles.""" + region: str + r"""Region where the AMSP is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - loki_url: NotRequired[str] - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" - message: NotRequired[str] - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - message_format: NotRequired[MessageFormatOptions] - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - labels: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access AMSP""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" metric_rename_expr: NotRequired[str] r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] - loki_auth: NotRequired[PrometheusAuthTypeTypedDict] + send_metadata: NotRequired[bool] + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + use_prometheus_histogram_bucket_suffix: NotRequired[bool] + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" use_round_robin_dns: NotRequired[bool] r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] @@ -19742,8 +19709,10 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[bool] - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + metrics_flush_period_sec: NotRequired[float] + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -19767,30 +19736,45 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputGrafanaCloudPqControls2TypedDict + CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: NotRequired[str] - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - template_prometheus_url: NotRequired[str] - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): +class CreateOutputSystemByPackOutputAmazonManagedPrometheus(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGrafanaCloudType2 + type: CreateOutputSystemByPackOutputAmazonManagedPrometheusType r"""Connector type identifier.""" - prometheus_url: Annotated[str, pydantic.Field(alias="prometheusUrl")] - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + url: str + r"""The Amazon Managed Service for Prometheus remote_write endpoint""" + + aws_authentication_method: Annotated[ + AuthenticationMethodOptionsAutoSecret, + pydantic.Field(alias="awsAuthenticationMethod"), + ] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + region: str + r"""Region where the AMSP is located""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -19798,7 +19782,7 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -19806,55 +19790,66 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - loki_url: Annotated[Optional[str], pydantic.Field(alias="lokiUrl")] = None - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - message: Optional[str] = None - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - message_format: Annotated[ - Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + r"""Use Assume Role credentials to access AMSP""" - labels: Optional[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" metric_rename_expr: Annotated[ Optional[str], pydantic.Field(alias="metricRenameExpr") ] = None r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") - ] = None + send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + None + ) + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - loki_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") + use_prometheus_histogram_bucket_suffix: Annotated[ + Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") ] = None + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -19867,13 +19862,13 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Headers to add to all events""" + r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") @@ -19914,8 +19909,13 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + metrics_flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") + ] = None + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19967,7 +19967,7 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGrafanaCloudPqControls2], + Optional[CreateOutputSystemByPackOutputAmazonManagedPrometheusPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -19977,15 +19977,30 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiUrl") + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_prometheus_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusUrl") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -19997,11 +20012,11 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("message_format") - def serialize_message_format(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.MessageFormatOptions(value) + return models.AuthenticationMethodOptionsAutoSecret(value) except ValueError: return value return value @@ -20059,17 +20074,18 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "lokiUrl", - "message", - "messageFormat", - "labels", + "awsSecretKey", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "metricRenameExpr", - "prometheusAuth", - "lokiAuth", + "sendMetadata", + "usePrometheusHistogramBucketSuffix", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", @@ -20082,7 +20098,8 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "description", - "compress", + "awsSecret", + "metricsFlushPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -20096,8 +20113,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_lokiUrl", - "__template_prometheusUrl", + "__template_url", + "__template_awsSecretKey", + "__template_region", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_failedRequestLoggingMode", "__template_onBackpressure", ] @@ -20116,37 +20136,35 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGrafanaCloudType1(str, Enum): +class CreateOutputSystemByPackOutputLokiType(str, Enum): r"""Connector type identifier.""" - GRAFANA_CLOUD = "grafana_cloud" + LOKI = "loki" -class CreateOutputSystemByPackOutputGrafanaCloudPqControls1TypedDict(TypedDict): +class CreateOutputSystemByPackOutputLokiPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGrafanaCloudPqControls1(BaseModel): +class CreateOutputSystemByPackOutputLokiPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): +class CreateOutputSystemByPackOutputLokiTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGrafanaCloudType1 + type: CreateOutputSystemByPackOutputLokiType r"""Connector type identifier.""" - loki_url: str - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + url: str + r"""The endpoint to send logs to""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - prometheus_url: NotRequired[str] - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" message: NotRequired[str] r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" message_format: NotRequired[MessageFormatOptions] @@ -20155,16 +20173,16 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] ] r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] - loki_auth: NotRequired[PrometheusAuthTypeTypedDict] + auth_type: NotRequired[ + AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret + ] + r"""Authentication type""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -20175,7 +20193,7 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -20191,12 +20209,26 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + enable_dynamic_headers: NotRequired[bool] + r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" compress: NotRequired[bool] - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + r"""Compress the payload body before sending""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + username: NotRequired[str] + r"""Username for authentication""" + password: NotRequired[str] + r"""Password (API key in Grafana Cloud domain) for authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -20219,31 +20251,25 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputGrafanaCloudPqControls1TypedDict - ] - r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: NotRequired[str] - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - template_prometheus_url: NotRequired[str] - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" + pq_controls: NotRequired[CreateOutputSystemByPackOutputLokiPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): +class CreateOutputSystemByPackOutputLoki(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGrafanaCloudType1 + type: CreateOutputSystemByPackOutputLokiType r"""Connector type identifier.""" - loki_url: Annotated[str, pydantic.Field(alias="lokiUrl")] - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + url: str + r"""The endpoint to send logs to""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -20251,7 +20277,7 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -20259,11 +20285,6 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - prometheus_url: Annotated[Optional[str], pydantic.Field(alias="prometheusUrl")] = ( - None - ) - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" - message: Optional[str] = None r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" @@ -20277,31 +20298,24 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") - ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - - prometheus_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") - ] = None - - loki_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret], + pydantic.Field(alias="authType"), ] = None + r"""Authentication type""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -20322,7 +20336,7 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -20361,16 +20375,43 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + enable_dynamic_headers: Annotated[ + Optional[bool], pydantic.Field(alias="enableDynamicHeaders") + ] = None + r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" + on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" compress: Optional[bool] = None - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + r"""Compress the payload body before sending""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + username: Optional[str] = None + r"""Username for authentication""" + + password: Optional[str] = None + r"""Password (API key in Grafana Cloud domain) for authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -20422,7 +20463,7 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGrafanaCloudPqControls1], + Optional[CreateOutputSystemByPackOutputLokiPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -20432,16 +20473,6 @@ class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiUrl") - ] = None - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - - template_prometheus_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusUrl") - ] = None - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -20461,6 +20492,17 @@ def serialize_message_format(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret( + value + ) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -20514,13 +20556,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "prometheusUrl", "message", "messageFormat", "labels", - "metricRenameExpr", - "prometheusAuth", - "lokiAuth", + "authType", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -20535,9 +20574,16 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", + "enableDynamicHeaders", "onBackpressure", + "totalMemoryLimitKB", "description", "compress", + "token", + "textSecret", + "username", + "password", + "credentialsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -20551,8 +20597,6 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_lokiUrl", - "__template_prometheusUrl", "__template_failedRequestLoggingMode", "__template_onBackpressure", ] @@ -20571,132 +20615,55 @@ def serialize_model(self, handler): return m -CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict = TypeAliasType( - "CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict", - Union[ - CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict, - CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict, - ], -) - - -CreateOutputSystemByPackOutputGrafanaCloudUnion = TypeAliasType( - "CreateOutputSystemByPackOutputGrafanaCloudUnion", - Union[ - CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1, - CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2, - ], -) - - -class CreateOutputSystemByPackOutputDatadogType(str, Enum): +class CreateOutputSystemByPackOutputGrafanaCloudType2(str, Enum): r"""Connector type identifier.""" - DATADOG = "datadog" - - -class CreateOutputSystemByPackSendLogsAs(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The content type to use when sending logs""" - - # text/plain - TEXT = "text" - # application/json - JSON = "json" - - -class CreateOutputSystemByPackOutputDatadogSeverity( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - - # emergency - EMERGENCY = "emergency" - # alert - ALERT = "alert" - # critical - CRITICAL = "critical" - # error - ERROR = "error" - # warning - WARNING = "warning" - # notice - NOTICE = "notice" - # info - INFO = "info" - # debug - DEBUG = "debug" - - -class CreateOutputSystemByPackDatadogSite(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Datadog site to which events should be sent""" - - # US - US = "us" - # US3 - US3 = "us3" - # US5 - US5 = "us5" - # Europe - EU = "eu" - # US1-FED - FED1 = "fed1" - # AP1 - AP1 = "ap1" - # Custom - CUSTOM = "custom" + GRAFANA_CLOUD = "grafana_cloud" -class CreateOutputSystemByPackOutputDatadogPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGrafanaCloudPqControls2TypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputDatadogPqControls(BaseModel): +class CreateOutputSystemByPackOutputGrafanaCloudPqControls2(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputDatadogTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDatadogType + type: CreateOutputSystemByPackOutputGrafanaCloudType2 r"""Connector type identifier.""" + prometheus_url: str + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - content_type: NotRequired[CreateOutputSystemByPackSendLogsAs] - r"""The content type to use when sending logs""" + loki_url: NotRequired[str] + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" message: NotRequired[str] r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - source: NotRequired[str] - r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" - host: NotRequired[str] - r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" - service: NotRequired[str] - r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" - tags: NotRequired[List[str]] - r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" - batch_by_tags: NotRequired[bool] - r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" - allow_api_key_from_events: NotRequired[bool] - r"""Allow API key to be set from the event's '__agent_api_key' field""" - severity: NotRequired[CreateOutputSystemByPackOutputDatadogSeverity] - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - site: NotRequired[CreateOutputSystemByPackDatadogSite] - r"""Datadog site to which events should be sent""" - send_counters_as_count: NotRequired[bool] - r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" + message_format: NotRequired[MessageFormatOptions] + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + labels: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] + loki_auth: NotRequired[PrometheusAuthTypeTypedDict] concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -20707,7 +20674,7 @@ class CreateOutputSystemByPackOutputDatadogTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -20725,13 +20692,10 @@ class CreateOutputSystemByPackOutputDatadogTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + compress: NotRequired[bool] + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -20754,36 +20718,39 @@ class CreateOutputSystemByPackOutputDatadogTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputDatadogPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputGrafanaCloudPqControls2TypedDict + ] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""Organization's API key in Datadog""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_tags: NotRequired[str] - r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_loki_url: NotRequired[str] + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + template_prometheus_url: NotRequired[str] + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputDatadog(BaseModel): +class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDatadogType + type: CreateOutputSystemByPackOutputGrafanaCloudType2 r"""Connector type identifier.""" + prometheus_url: Annotated[str, pydantic.Field(alias="prometheusUrl")] + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -20791,61 +20758,47 @@ class CreateOutputSystemByPackOutputDatadog(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - content_type: Annotated[ - Optional[CreateOutputSystemByPackSendLogsAs], - pydantic.Field(alias="contentType"), - ] = None - r"""The content type to use when sending logs""" + loki_url: Annotated[Optional[str], pydantic.Field(alias="lokiUrl")] = None + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" message: Optional[str] = None r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - source: Optional[str] = None - r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" - - host: Optional[str] = None - r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" - - service: Optional[str] = None - r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" - - tags: Optional[List[str]] = None - r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" - - batch_by_tags: Annotated[Optional[bool], pydantic.Field(alias="batchByTags")] = None - r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + message_format: Annotated[ + Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + ] = None + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - allow_api_key_from_events: Annotated[ - Optional[bool], pydantic.Field(alias="allowApiKeyFromEvents") + labels: Optional[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] ] = None - r"""Allow API key to be set from the event's '__agent_api_key' field""" + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - severity: Optional[CreateOutputSystemByPackOutputDatadogSeverity] = None - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") + ] = None + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - site: Optional[CreateOutputSystemByPackDatadogSite] = None - r"""Datadog site to which events should be sent""" + prometheus_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") + ] = None - send_counters_as_count: Annotated[ - Optional[bool], pydantic.Field(alias="sendCountersAsCount") + loki_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") ] = None - r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -20866,7 +20819,7 @@ class CreateOutputSystemByPackOutputDatadog(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -20910,20 +20863,11 @@ class CreateOutputSystemByPackOutputDatadog(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + compress: Optional[bool] = None + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -20975,26 +20919,25 @@ class CreateOutputSystemByPackOutputDatadog(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputDatadogPqControls], + Optional[CreateOutputSystemByPackOutputGrafanaCloudPqControls2], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""Organization's API key in Datadog""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_tags: Annotated[Optional[str], pydantic.Field(alias="__template_tags")] = ( - None - ) - r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_loki_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiUrl") + ] = None + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + + template_prometheus_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusUrl") + ] = None + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -21006,29 +20949,11 @@ class CreateOutputSystemByPackOutputDatadog(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("content_type") - def serialize_content_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackSendLogsAs(value) - except ValueError: - return value - return value - - @field_serializer("severity") - def serialize_severity(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputDatadogSeverity(value) - except ValueError: - return value - return value - - @field_serializer("site") - def serialize_site(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackDatadogSite(value) + return models.MessageFormatOptions(value) except ValueError: return value return value @@ -21051,15 +20976,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -21095,21 +21011,16 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "contentType", + "lokiUrl", "message", - "source", - "host", - "service", - "tags", - "batchByTags", - "allowApiKeyFromEvents", - "severity", - "site", - "sendCountersAsCount", + "messageFormat", + "labels", + "metricRenameExpr", + "prometheusAuth", + "lokiAuth", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", - "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", @@ -21122,10 +21033,8 @@ def serialize_model(self, handler): "timeoutRetrySettings", "responseHonorRetryAfterHeader", "onBackpressure", - "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "compress", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -21138,10 +21047,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", - "__template_tags", + "__template_lokiUrl", + "__template_prometheusUrl", "__template_failedRequestLoggingMode", "__template_onBackpressure", ] @@ -21160,60 +21068,55 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSumoLogicType(str, Enum): +class CreateOutputSystemByPackOutputGrafanaCloudType1(str, Enum): r"""Connector type identifier.""" - SUMO_LOGIC = "sumo_logic" - - -class CreateOutputSystemByPackOutputSumoLogicDataFormat( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Preserve the raw event format instead of JSONifying it""" - - # JSON - JSON = "json" - # Raw - RAW = "raw" + GRAFANA_CLOUD = "grafana_cloud" -class CreateOutputSystemByPackOutputSumoLogicPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGrafanaCloudPqControls1TypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSumoLogicPqControls(BaseModel): +class CreateOutputSystemByPackOutputGrafanaCloudPqControls1(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSumoLogicTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSumoLogicType + type: CreateOutputSystemByPackOutputGrafanaCloudType1 r"""Connector type identifier.""" - url: str - r"""Sumo Logic HTTP collector URL to which events should be sent""" + loki_url: str + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - custom_source: NotRequired[str] - r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" - custom_category: NotRequired[str] - r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - format_: NotRequired[CreateOutputSystemByPackOutputSumoLogicDataFormat] - r"""Preserve the raw event format instead of JSONifying it""" + prometheus_url: NotRequired[str] + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + message: NotRequired[str] + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + message_format: NotRequired[MessageFormatOptions] + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + labels: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] + loki_auth: NotRequired[PrometheusAuthTypeTypedDict] concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -21224,7 +21127,7 @@ class CreateOutputSystemByPackOutputSumoLogicTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -21242,10 +21145,10 @@ class CreateOutputSystemByPackOutputSumoLogicTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + compress: NotRequired[bool] + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -21268,27 +21171,31 @@ class CreateOutputSystemByPackOutputSumoLogicTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSumoLogicPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputGrafanaCloudPqControls1TypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_loki_url: NotRequired[str] + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + template_prometheus_url: NotRequired[str] + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputSumoLogic(BaseModel): +class CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSumoLogicType + type: CreateOutputSystemByPackOutputGrafanaCloudType1 r"""Connector type identifier.""" - url: str - r"""Sumo Logic HTTP collector URL to which events should be sent""" + loki_url: Annotated[str, pydantic.Field(alias="lokiUrl")] + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -21296,43 +21203,57 @@ class CreateOutputSystemByPackOutputSumoLogic(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + prometheus_url: Annotated[Optional[str], pydantic.Field(alias="prometheusUrl")] = ( + None + ) + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + + message: Optional[str] = None + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + message_format: Annotated[ + Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + ] = None + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + labels: Optional[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + ] = None + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - custom_source: Annotated[Optional[str], pydantic.Field(alias="customSource")] = None - r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") + ] = None + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - custom_category: Annotated[ - Optional[str], pydantic.Field(alias="customCategory") + prometheus_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") ] = None - r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - format_: Annotated[ - Optional[CreateOutputSystemByPackOutputSumoLogicDataFormat], - pydantic.Field(alias="format"), + loki_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") ] = None - r"""Preserve the raw event format instead of JSONifying it""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -21353,7 +21274,7 @@ class CreateOutputSystemByPackOutputSumoLogic(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -21397,14 +21318,12 @@ class CreateOutputSystemByPackOutputSumoLogic(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -21455,7 +21374,7 @@ class CreateOutputSystemByPackOutputSumoLogic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSumoLogicPqControls], + Optional[CreateOutputSystemByPackOutputGrafanaCloudPqControls1], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -21465,10 +21384,15 @@ class CreateOutputSystemByPackOutputSumoLogic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_loki_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiUrl") + ] = None + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + + template_prometheus_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusUrl") + ] = None + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -21480,11 +21404,11 @@ class CreateOutputSystemByPackOutputSumoLogic(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputSumoLogicDataFormat(value) + return models.MessageFormatOptions(value) except ValueError: return value return value @@ -21526,193 +21450,13 @@ def serialize_pq_compress(self, value): return value @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "customSource", - "customCategory", - "format", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "onBackpressure", - "totalMemoryLimitKB", - "description", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputSnmpHostTypedDict(TypedDict): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 162""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class CreateOutputSystemByPackOutputSnmpHost(BaseModel): - host: str - r"""Destination host""" - - port: float - r"""Destination port, default is 162""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["__template_host", "__template_port"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputSnmpTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: TypeOptionsSnmp - r"""Connector type identifier.""" - hosts: List[CreateOutputSystemByPackOutputSnmpHostTypedDict] - r"""One or more SNMP destinations to forward traps to""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - max_record_size: NotRequired[float] - r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateOutputSystemByPackOutputSnmp(BaseModel): - id: str - r"""Unique ID for this output""" - - type: TypeOptionsSnmp - r"""Connector type identifier.""" - - hosts: List[CreateOutputSystemByPackOutputSnmpHost] - r"""One or more SNMP destinations to forward traps to""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" - - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") - ] = None - r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") - ] = None - r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -21722,11 +21466,47 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "dnsResolvePeriodSec", - "enableIpSpoofing", + "prometheusUrl", + "message", + "messageFormat", + "labels", + "metricRenameExpr", + "prometheusAuth", + "lokiAuth", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "maxRecordSize", + "compress", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", + "__template_lokiUrl", + "__template_prometheusUrl", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", ] ) serialized = handler(self) @@ -21743,32 +21523,94 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackQueueType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The queue type used (or created). Defaults to Standard.""" +CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict = TypeAliasType( + "CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict", + Union[ + CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1TypedDict, + CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2TypedDict, + ], +) - # Standard - STANDARD = "standard" - # FIFO - FIFO = "fifo" + +CreateOutputSystemByPackOutputGrafanaCloudUnion = TypeAliasType( + "CreateOutputSystemByPackOutputGrafanaCloudUnion", + Union[ + CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud1, + CreateOutputSystemByPackOutputGrafanaCloudGrafanaCloud2, + ], +) -class CreateOutputSystemByPackOutputSqsPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputDatadogType(str, Enum): + r"""Connector type identifier.""" + + DATADOG = "datadog" + + +class CreateOutputSystemByPackSendLogsAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The content type to use when sending logs""" + + # text/plain + TEXT = "text" + # application/json + JSON = "json" + + +class CreateOutputSystemByPackOutputDatadogSeverity( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + + # emergency + EMERGENCY = "emergency" + # alert + ALERT = "alert" + # critical + CRITICAL = "critical" + # error + ERROR = "error" + # warning + WARNING = "warning" + # notice + NOTICE = "notice" + # info + INFO = "info" + # debug + DEBUG = "debug" + + +class CreateOutputSystemByPackDatadogSite(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Datadog site to which events should be sent""" + + # US + US = "us" + # US3 + US3 = "us3" + # US5 + US5 = "us5" + # Europe + EU = "eu" + # US1-FED + FED1 = "fed1" + # AP1 + AP1 = "ap1" + # Custom + CUSTOM = "custom" + + +class CreateOutputSystemByPackOutputDatadogPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSqsPqControls(BaseModel): +class CreateOutputSystemByPackOutputDatadogPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSqsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputDatadogTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSqs + type: CreateOutputSystemByPackOutputDatadogType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - queue_type: CreateOutputSystemByPackQueueType - r"""The queue type used (or created). Defaults to Standard.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -21777,48 +21619,71 @@ class CreateOutputSystemByPackOutputSqsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - message_group_id: NotRequired[str] - r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" - create_queue: NotRequired[bool] - r"""Create queue if it does not exist.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + content_type: NotRequired[CreateOutputSystemByPackSendLogsAs] + r"""The content type to use when sending logs""" + message: NotRequired[str] + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + source: NotRequired[str] + r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" + host: NotRequired[str] + r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" + service: NotRequired[str] + r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" + tags: NotRequired[List[str]] + r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" + batch_by_tags: NotRequired[bool] + r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + allow_api_key_from_events: NotRequired[bool] + r"""Allow API key to be set from the event's '__agent_api_key' field""" + severity: NotRequired[CreateOutputSystemByPackOutputDatadogSeverity] + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + site: NotRequired[CreateOutputSystemByPackDatadogSite] + r"""Datadog site to which events should be sent""" + send_counters_as_count: NotRequired[bool] + r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SQS""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking.""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -21841,49 +21706,29 @@ class CreateOutputSystemByPackOutputSqsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSqsPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputDatadogPqControlsTypedDict] r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: NotRequired[str] - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_message_group_id: NotRequired[str] - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + api_key: NotRequired[str] + r"""Organization's API key in Datadog""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_tags: NotRequired[str] + r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputSqs(BaseModel): +class CreateOutputSystemByPackOutputDatadog(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSqs + type: CreateOutputSystemByPackOutputDatadogType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - - queue_type: Annotated[ - CreateOutputSystemByPackQueueType, pydantic.Field(alias="queueType") - ] - r"""The queue type used (or created). Defaults to Standard.""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -21898,99 +21743,139 @@ class CreateOutputSystemByPackOutputSqs(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="messageGroupId") + content_type: Annotated[ + Optional[CreateOutputSystemByPackSendLogsAs], + pydantic.Field(alias="contentType"), ] = None - r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" + r"""The content type to use when sending logs""" - create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None - r"""Create queue if it does not exist.""" + message: Optional[str] = None + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + source: Optional[str] = None + r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" + + host: Optional[str] = None + r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" + + service: Optional[str] = None + r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" + + tags: Optional[List[str]] = None + r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" + + batch_by_tags: Annotated[Optional[bool], pydantic.Field(alias="batchByTags")] = None + r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + + allow_api_key_from_events: Annotated[ + Optional[bool], pydantic.Field(alias="allowApiKeyFromEvents") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Allow API key to be set from the event's '__agent_api_key' field""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + severity: Optional[CreateOutputSystemByPackOutputDatadogSeverity] = None + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - region: Optional[str] = None - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + site: Optional[CreateOutputSystemByPackDatadogSite] = None + r"""Datadog site to which events should be sent""" - endpoint: Optional[str] = None - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + send_counters_as_count: Annotated[ + Optional[bool], pydantic.Field(alias="sendCountersAsCount") + ] = None + r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Use Assume Role credentials to access SQS""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""External ID to use when assuming role""" + r"""Headers to add to all events""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + r"""List of headers that are safe to log in plain text""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The maximum number of in-progress API requests before backpressure is applied.""" + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + ] = None + r"""Enter API key directly, or select a stored secret""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -22042,85 +21927,69 @@ class CreateOutputSystemByPackOutputSqs(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSqsPqControls], + Optional[CreateOutputSystemByPackOutputDatadogPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""Organization's API key in Datadog""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_queue_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueType") - ] = None - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - - template_message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageGroupId") - ] = None - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_tags: Annotated[Optional[str], pydantic.Field(alias="__template_tags")] = ( + None + ) + r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + @field_serializer("content_type") + def serialize_content_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackSendLogsAs(value) + except ValueError: + return value + return value + + @field_serializer("severity") + def serialize_severity(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputDatadogSeverity(value) + except ValueError: + return value + return value - @field_serializer("queue_type") - def serialize_queue_type(self, value): + @field_serializer("site") + def serialize_site(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackQueueType(value) + return models.CreateOutputSystemByPackDatadogSite(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -22134,6 +22003,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -22169,27 +22047,37 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAccountId", - "messageGroupId", - "createQueue", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", + "contentType", + "message", + "source", + "host", + "service", + "tags", + "batchByTags", + "allowApiKeyFromEvents", + "severity", + "site", + "sendCountersAsCount", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "maxQueueSize", - "maxRecordSizeKB", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "maxInProgress", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "awsApiKey", - "awsSecret", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -22202,18 +22090,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_queueName", - "__template_queueType", - "__template_awsAccountId", - "__template_messageGroupId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_tags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -22230,29 +22112,38 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSnsType(str, Enum): +class CreateOutputSystemByPackOutputSumoLogicType(str, Enum): r"""Connector type identifier.""" - SNS = "sns" + SUMO_LOGIC = "sumo_logic" -class CreateOutputSystemByPackOutputSnsPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSumoLogicDataFormat( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Preserve the raw event format instead of JSONifying it""" + + # JSON + JSON = "json" + # Raw + RAW = "raw" + + +class CreateOutputSystemByPackOutputSumoLogicPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSnsPqControls(BaseModel): +class CreateOutputSystemByPackOutputSumoLogicPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSnsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSumoLogicTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSnsType + type: CreateOutputSystemByPackOutputSumoLogicType r"""Connector type identifier.""" - topic_arn: str - r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - message_group_id: str - r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + url: str + r"""Sumo Logic HTTP collector URL to which events should be sent""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -22261,36 +22152,52 @@ class CreateOutputSystemByPackOutputSnsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - max_retries: NotRequired[float] - r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the SNS is located""" - endpoint: NotRequired[str] - r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + custom_source: NotRequired[str] + r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" + custom_category: NotRequired[str] + r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" + format_: NotRequired[CreateOutputSystemByPackOutputSumoLogicDataFormat] + r"""Preserve the raw event format instead of JSONifying it""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SNS""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -22313,42 +22220,27 @@ class CreateOutputSystemByPackOutputSnsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSnsPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSumoLogicPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_arn: NotRequired[str] - r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" - template_message_group_id: NotRequired[str] - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputSns(BaseModel): +class CreateOutputSystemByPackOutputSumoLogic(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSnsType + type: CreateOutputSystemByPackOutputSumoLogicType r"""Connector type identifier.""" - topic_arn: Annotated[str, pydantic.Field(alias="topicArn")] - r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - - message_group_id: Annotated[str, pydantic.Field(alias="messageGroupId")] - r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + url: str + r"""Sumo Logic HTTP collector URL to which events should be sent""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -22364,70 +22256,107 @@ class CreateOutputSystemByPackOutputSns(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" + custom_source: Annotated[Optional[str], pydantic.Field(alias="customSource")] = None + r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + custom_category: Annotated[ + Optional[str], pydantic.Field(alias="customCategory") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + format_: Annotated[ + Optional[CreateOutputSystemByPackOutputSumoLogicDataFormat], + pydantic.Field(alias="format"), + ] = None + r"""Preserve the raw event format instead of JSONifying it""" - region: Optional[str] = None - r"""Region where the SNS is located""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - endpoint: Optional[str] = None - r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Use Assume Role credentials to access SNS""" + r"""List of headers that are safe to log in plain text""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""External ID to use when assuming role""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -22478,7 +22407,7 @@ class CreateOutputSystemByPackOutputSns(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSnsPqControls], + Optional[CreateOutputSystemByPackOutputSumoLogicPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -22488,56 +22417,35 @@ class CreateOutputSystemByPackOutputSns(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicArn") - ] = None - r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" - - template_message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageGroupId") - ] = None - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputSumoLogicDataFormat(value) + except ValueError: + return value + return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -22586,21 +22494,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "maxRetries", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", + "customSource", + "customCategory", + "format", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", + "totalMemoryLimitKB", "description", - "awsApiKey", - "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -22614,15 +22528,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topicArn", - "__template_messageGroupId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_url", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -22639,39 +22547,37 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputRouterType(str, Enum): - r"""Connector type identifier.""" - - ROUTER = "router" - - -class CreateOutputSystemByPackRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression to select events to send to output""" - output: str - r"""Output to send matching events to""" - description: NotRequired[str] - r"""Description of this rule's purpose""" - final: NotRequired[bool] - r"""Flag to control whether to stop the event from being checked against other rules""" +class CreateOutputSystemByPackOutputSnmpHostTypedDict(TypedDict): + host: str + r"""Destination host""" + port: float + r"""Destination port, default is 162""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputSystemByPackRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression to select events to send to output""" +class CreateOutputSystemByPackOutputSnmpHost(BaseModel): + host: str + r"""Destination host""" - output: str - r"""Output to send matching events to""" + port: float + r"""Destination port, default is 162""" - description: Optional[str] = None - r"""Description of this rule's purpose""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - final: Optional[bool] = None - r"""Flag to control whether to stop the event from being checked against other rules""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description", "final"]) + optional_fields = set(["__template_host", "__template_port"]) serialized = handler(self) m = {} @@ -22686,13 +22592,13 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputRouterTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSnmpTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputRouterType + type: TypeOptionsSnmp r"""Connector type identifier.""" - rules: List[CreateOutputSystemByPackRuleTypedDict] - r"""Event routing rules""" + hosts: List[CreateOutputSystemByPackOutputSnmpHostTypedDict] + r"""One or more SNMP destinations to forward traps to""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -22701,21 +22607,27 @@ class CreateOutputSystemByPackOutputRouterTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" description: NotRequired[str] r"""Optional description for this configuration.""" + max_record_size: NotRequired[float] + r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class CreateOutputSystemByPackOutputRouter(BaseModel): +class CreateOutputSystemByPackOutputSnmp(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputRouterType + type: TypeOptionsSnmp r"""Connector type identifier.""" - rules: List[CreateOutputSystemByPackRule] - r"""Event routing rules""" + hosts: List[CreateOutputSystemByPackOutputSnmpHost] + r"""One or more SNMP destinations to forward traps to""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -22731,9 +22643,24 @@ class CreateOutputSystemByPackOutputRouter(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" + + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") + ] = None + r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + description: Optional[str] = None r"""Optional description for this configuration.""" + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") + ] = None + r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -22747,7 +22674,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "dnsResolvePeriodSec", + "enableIpSpoofing", "description", + "maxRecordSize", "__template_streamtags", ] ) @@ -22765,31 +22695,32 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGraphiteType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputSystemByPackQueueType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The queue type used (or created). Defaults to Standard.""" - GRAPHITE = "graphite" + # Standard + STANDARD = "standard" + # FIFO + FIFO = "fifo" -class CreateOutputSystemByPackOutputGraphitePqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSqsPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGraphitePqControls(BaseModel): +class CreateOutputSystemByPackOutputSqsPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGraphiteTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSqsTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGraphiteType + type: TypeOptionsSqs r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + queue_type: CreateOutputSystemByPackQueueType + r"""The queue type used (or created). Defaults to Standard.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -22798,22 +22729,48 @@ class CreateOutputSystemByPackOutputGraphiteTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + message_group_id: NotRequired[str] + r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" + create_queue: NotRequired[bool] + r"""Create queue if it does not exist.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SQS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -22836,29 +22793,48 @@ class CreateOutputSystemByPackOutputGraphiteTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputGraphitePqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSqsPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_queue_type: NotRequired[str] + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_message_group_id: NotRequired[str] + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputGraphite(BaseModel): +class CreateOutputSystemByPackOutputSqs(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGraphiteType + type: TypeOptionsSqs r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - - host: str - r"""The hostname of the destination.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - port: float - r"""Destination port.""" + queue_type: Annotated[ + CreateOutputSystemByPackQueueType, pydantic.Field(alias="queueType") + ] + r"""The queue type used (or created). Defaults to Standard.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -22874,42 +22850,100 @@ class CreateOutputSystemByPackOutputGraphite(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - mtu: Optional[float] = None - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="messageGroupId") ] = None - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None + r"""Create queue if it does not exist.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + region: Optional[str] = None + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Reuse connections between requests, which can improve performance""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SQS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking.""" + + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") + ] = None + r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") + ] = None + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -22960,7 +22994,7 @@ class CreateOutputSystemByPackOutputGraphite(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGraphitePqControls], + Optional[CreateOutputSystemByPackOutputSqsPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -22970,16 +23004,75 @@ class CreateOutputSystemByPackOutputGraphite(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_queue_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueType") + ] = None + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageGroupId") + ] = None + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("queue_type") + def serialize_queue_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackQueueType(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.DestinationProtocolOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -23028,14 +23121,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "mtu", + "awsAccountId", + "messageGroupId", + "createQueue", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxQueueSize", + "maxRecordSizeKB", "flushPeriodSec", - "dnsResolvePeriodSec", - "description", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "maxInProgress", "onBackpressure", + "description", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -23049,7 +23155,17 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_queueName", + "__template_queueType", + "__template_awsAccountId", + "__template_messageGroupId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -23066,12 +23182,24 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputStatsdExtType(str, Enum): +class CreateOutputSystemByPackOutputSnsType(str, Enum): r"""Connector type identifier.""" - STATSD_EXT = "statsd_ext" + SNS = "sns" + + +class CreateOutputSystemByPackOutputSnsPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputSnsPqControls(BaseModel): + r"""Persistent queue controls.""" +try: + CreateOutputSystemByPackOutputDatabricksZerobus.model_rebuild() +except NameError: + pass try: CreateOutputSystemByPackOutputIbmCloudS3.model_rebuild() except NameError: @@ -23140,6 +23268,10 @@ class CreateOutputSystemByPackOutputStatsdExtType(str, Enum): CreateOutputSystemByPackOutputSentinelOneAiSiem.model_rebuild() except NameError: pass +try: + CreateOutputSystemByPackOutputTraversalOtlp.model_rebuild() +except NameError: + pass try: CreateOutputSystemByPackOutputDynatraceOtlp.model_rebuild() except NameError: @@ -23272,19 +23404,3 @@ class CreateOutputSystemByPackOutputStatsdExtType(str, Enum): CreateOutputSystemByPackOutputSqs.model_rebuild() except NameError: pass -try: - CreateOutputSystemByPackOutputSns.model_rebuild() -except NameError: - pass -try: - CreateOutputSystemByPackRule.model_rebuild() -except NameError: - pass -try: - CreateOutputSystemByPackOutputRouter.model_rebuild() -except NameError: - pass -try: - CreateOutputSystemByPackOutputGraphite.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/createoutputsystembypack_outputdefault_type.py b/src/cribl_control_plane/models/createoutputsystembypack_outputwebhook_format_2.py similarity index 94% rename from src/cribl_control_plane/models/createoutputsystembypack_outputdefault_type.py rename to src/cribl_control_plane/models/createoutputsystembypack_outputwebhook_format_2.py index 46419fa10..92032a8ac 100644 --- a/src/cribl_control_plane/models/createoutputsystembypack_outputdefault_type.py +++ b/src/cribl_control_plane/models/createoutputsystembypack_outputwebhook_format_2.py @@ -5,8 +5,8 @@ from .acknowledgmentsoptionsallleader import AcknowledgmentsOptionsAllLeader from .authenticationmethodoptions import AuthenticationMethodOptions from .authenticationmethodoptionsapi import AuthenticationMethodOptionsAPI -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionss3collectorconf import ( AuthenticationMethodOptionsS3CollectorConf, @@ -26,8 +26,10 @@ from .compressionoptionsgzipnone import CompressionOptionsGzipNone from .compressionoptionshttp import CompressionOptionsHTTP from .compressionoptionspq import CompressionOptionsPq -from .createoutputsystembypack_outputstatsdext_type import ( - CreateOutputSystemByPackOutputStatsdExtType, +from .createoutputsystembypack_outputsns_pqcontrols import ( + CreateOutputSystemByPackOutputSnsPqControls, + CreateOutputSystemByPackOutputSnsPqControlsTypedDict, + CreateOutputSystemByPackOutputSnsType, ) from .dataformatoptions import DataFormatOptions from .datapageversionoptions import DataPageVersionOptions @@ -53,20 +55,11 @@ LogLabelConfOutputGoogleCloudLoggingTypedDict, ) from .maxs2sversionoptions import MaxS2SVersionOptions -from .methodoptions import MethodOptions from .microsoftentraidauthenticationendpointoptionssasl import ( MicrosoftEntraIDAuthenticationEndpointOptionsSasl, ) from .modeoptions import ModeOptions from .nestedfieldserializationoptions import NestedFieldSerializationOptions -from .oauthheaderconfinputservicenowtable import ( - OauthHeaderConfInputServicenowTable, - OauthHeaderConfInputServicenowTableTypedDict, -) -from .oauthparamconfinputservicenowtable import ( - OauthParamConfInputServicenowTable, - OauthParamConfInputServicenowTableTypedDict, -) from .objectacloptions import ObjectACLOptions from .objectacloptionsauthenticatedreadbucketownerfullcontrol import ( ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol, @@ -139,29 +132,19 @@ from enum import Enum import pydantic from pydantic import field_serializer, model_serializer -from typing import List, Optional, Union -from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict - - -class CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputStatsdExtPqControls(BaseModel): - r"""Persistent queue controls.""" +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict -class CreateOutputSystemByPackOutputStatsdExtTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSnsTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputStatsdExtType + type: CreateOutputSystemByPackOutputSnsType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + topic_arn: str + r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" + message_group_id: str + r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -170,22 +153,36 @@ class CreateOutputSystemByPackOutputStatsdExtTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + max_retries: NotRequired[float] + r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the SNS is located""" + endpoint: NotRequired[str] + r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SNS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -208,29 +205,42 @@ class CreateOutputSystemByPackOutputStatsdExtTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSnsPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_arn: NotRequired[str] + r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" + template_message_group_id: NotRequired[str] + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputStatsdExt(BaseModel): +class CreateOutputSystemByPackOutputSns(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputStatsdExtType + type: CreateOutputSystemByPackOutputSnsType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - - host: str - r"""The hostname of the destination.""" + topic_arn: Annotated[str, pydantic.Field(alias="topicArn")] + r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - port: float - r"""Destination port.""" + message_group_id: Annotated[str, pydantic.Field(alias="messageGroupId")] + r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -246,42 +256,70 @@ class CreateOutputSystemByPackOutputStatsdExt(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - mtu: Optional[float] = None - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + region: Optional[str] = None + r"""Region where the SNS is located""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + endpoint: Optional[str] = None + r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Reuse connections between requests, which can improve performance""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SNS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -332,7 +370,7 @@ class CreateOutputSystemByPackOutputStatsdExt(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputStatsdExtPqControls], + Optional[CreateOutputSystemByPackOutputSnsPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -342,16 +380,56 @@ class CreateOutputSystemByPackOutputStatsdExt(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicArn") + ] = None + r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" + + template_message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageGroupId") + ] = None + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.DestinationProtocolOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -400,14 +478,21 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "mtu", - "flushPeriodSec", - "dnsResolvePeriodSec", - "description", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "maxRetries", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "onBackpressure", + "description", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -421,7 +506,15 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_topicArn", + "__template_messageGroupId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -438,31 +531,60 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputStatsdType(str, Enum): +class CreateOutputSystemByPackOutputRouterType(str, Enum): r"""Connector type identifier.""" - STATSD = "statsd" + ROUTER = "router" -class CreateOutputSystemByPackOutputStatsdPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputSystemByPackRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression to select events to send to output""" + output: str + r"""Output to send matching events to""" + description: NotRequired[str] + r"""Description of this rule's purpose""" + final: NotRequired[bool] + r"""Flag to control whether to stop the event from being checked against other rules""" -class CreateOutputSystemByPackOutputStatsdPqControls(BaseModel): - r"""Persistent queue controls.""" +class CreateOutputSystemByPackRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression to select events to send to output""" + output: str + r"""Output to send matching events to""" -class CreateOutputSystemByPackOutputStatsdTypedDict(TypedDict): + description: Optional[str] = None + r"""Description of this rule's purpose""" + + final: Optional[bool] = None + r"""Flag to control whether to stop the event from being checked against other rules""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description", "final"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputRouterTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputStatsdType + type: CreateOutputSystemByPackOutputRouterType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + rules: List[CreateOutputSystemByPackRuleTypedDict] + r"""Event routing rules""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -471,22 +593,127 @@ class CreateOutputSystemByPackOutputStatsdTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + report_branch_metrics: NotRequired[bool] + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" description: NotRequired[str] r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class CreateOutputSystemByPackOutputRouter(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputSystemByPackOutputRouterType + r"""Connector type identifier.""" + + rules: List[CreateOutputSystemByPackRule] + r"""Event routing rules""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + report_branch_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="reportBranchMetrics") + ] = None + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "reportBranchMetrics", + "description", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputGraphiteType(str, Enum): + r"""Connector type identifier.""" + + GRAPHITE = "graphite" + + +class CreateOutputSystemByPackOutputGraphitePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputGraphitePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputGraphiteTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputGraphiteType + r"""Connector type identifier.""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + flush_period_sec: NotRequired[float] + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -509,7 +736,7 @@ class CreateOutputSystemByPackOutputStatsdTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputStatsdPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputGraphitePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -517,11 +744,11 @@ class CreateOutputSystemByPackOutputStatsdTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputStatsd(BaseModel): +class CreateOutputSystemByPackOutputGraphite(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputStatsdType + type: CreateOutputSystemByPackOutputGraphiteType r"""Connector type identifier.""" protocol: DestinationProtocolOptions @@ -633,7 +860,7 @@ class CreateOutputSystemByPackOutputStatsd(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputStatsdPqControls], + Optional[CreateOutputSystemByPackOutputGraphitePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -739,23 +966,31 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputMinioType(str, Enum): +class CreateOutputSystemByPackOutputStatsdExtType(str, Enum): r"""Connector type identifier.""" - MINIO = "minio" + STATSD_EXT = "statsd_ext" -class CreateOutputSystemByPackOutputMinioTypedDict(TypedDict): +class CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputStatsdExtPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputStatsdExtTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputMinioType + type: CreateOutputSystemByPackOutputStatsdExtType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""MinIO service url (e.g. http://minioHost:9000)""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -764,156 +999,67 @@ class CreateOutputSystemByPackOutputMinioTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the MinIO bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ - ServerSideEncryptionForUploadedObjectsOptionsAes256 - ] - r"""Server-side encryption to use for uploaded objects""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + flush_period_sec: NotRequired[float] + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputSystemByPackOutputStatsdExtPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputMinio(BaseModel): +class CreateOutputSystemByPackOutputStatsdExt(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputMinioType + type: CreateOutputSystemByPackOutputStatsdExtType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + host: str + r"""The hostname of the destination.""" - endpoint: str - r"""MinIO service url (e.g. http://minioHost:9000)""" + port: float + r"""Destination port.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -929,339 +1075,112 @@ class CreateOutputSystemByPackOutputMinio(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - region: Optional[str] = None - r"""Region where the MinIO bucket is located""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + mtu: Optional[float] = None + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Add the Output ID value to staging location""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( None ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""How to handle events when all receivers are exerting backpressure""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Buffer size used to write to a file""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None + r"""Codec to use to compress the persisted data""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Object ACL to assign to uploaded objects""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - storage_class: Annotated[ - Optional[StorageClassOptionsReducedredundancyStandard], - pydantic.Field(alias="storageClass"), + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Storage class to select for uploaded objects""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], - pydantic.Field(alias="serverSideEncryption"), + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputStatsdExtPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Server-side encryption to use for uploaded objects""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + r"""Persistent queue controls.""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" - - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") - ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.DataFormatOptions(value) + return models.DestinationProtocolOptions(value) except ValueError: return value return value @@ -1270,79 +1189,34 @@ def serialize_format_(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("object_acl") - def serialize_object_acl(self, value): - if isinstance(value, str): - try: - return models.ObjectACLOptions(value) - except ValueError: - return value - return value - - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptionsReducedredundancyStandard(value) - except ValueError: - return value - return value - - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): - if isinstance(value, str): - try: - return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -1355,72 +1229,28 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "region", - "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", + "mtu", + "flushPeriodSec", + "dnsResolvePeriodSec", "description", - "awsApiKey", - "awsSecret", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "onBackpressure", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_bucket", - "__template_region", - "__template_destPath", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_awsApiKey", - "__template_compress", - "__template_parquetSchema", ] ) serialized = handler(self) @@ -1437,31 +1267,31 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputCloudwatchType(str, Enum): +class CreateOutputSystemByPackOutputStatsdType(str, Enum): r"""Connector type identifier.""" - CLOUDWATCH = "cloudwatch" + STATSD = "statsd" -class CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputStatsdPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCloudwatchPqControls(BaseModel): +class CreateOutputSystemByPackOutputStatsdPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputCloudwatchTypedDict(TypedDict): +class CreateOutputSystemByPackOutputStatsdTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCloudwatchType + type: CreateOutputSystemByPackOutputStatsdType r"""Connector type identifier.""" - log_group_name: str - r"""CloudWatch log group to associate events with""" - log_stream_name: str - r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" - region: str - r"""Region where the CloudWatchLogs is located""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -1470,38 +1300,22 @@ class CreateOutputSystemByPackOutputCloudwatchTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access CloudWatchLogs""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -1524,47 +1338,29 @@ class CreateOutputSystemByPackOutputCloudwatchTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputSystemByPackOutputStatsdPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_group_name: NotRequired[str] - r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" - template_log_stream_name: NotRequired[str] - r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputCloudwatch(BaseModel): +class CreateOutputSystemByPackOutputStatsd(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputCloudwatchType + type: CreateOutputSystemByPackOutputStatsdType r"""Connector type identifier.""" - log_group_name: Annotated[str, pydantic.Field(alias="logGroupName")] - r"""CloudWatch log group to associate events with""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" - log_stream_name: Annotated[str, pydantic.Field(alias="logStreamName")] - r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + host: str + r"""The hostname of the destination.""" - region: str - r"""Region where the CloudWatchLogs is located""" + port: float + r"""Destination port.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -1580,79 +1376,42 @@ class CreateOutputSystemByPackOutputCloudwatch(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - endpoint: Optional[str] = None - r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + mtu: Optional[float] = None + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Use Assume Role credentials to access CloudWatchLogs""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""External ID to use when assuming role""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( None ) - r"""Maximum number of queued batches before blocking""" - - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") - ] = None - r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -1703,7 +1462,7 @@ class CreateOutputSystemByPackOutputCloudwatch(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputCloudwatchPqControls], + Optional[CreateOutputSystemByPackOutputStatsdPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -1713,59 +1472,19 @@ class CreateOutputSystemByPackOutputCloudwatch(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_group_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_logGroupName") - ] = None - r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" - - template_log_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_logStreamName") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.DestinationProtocolOptions(value) + except ValueError: + return value + return value @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): @@ -1811,22 +1530,14 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "maxQueueSize", - "maxRecordSizeKB", + "mtu", "flushPeriodSec", - "onBackpressure", + "dnsResolvePeriodSec", "description", - "awsApiKey", - "awsSecret", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "onBackpressure", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -1840,15 +1551,7 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_logGroupName", - "__template_logStreamName", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -1865,63 +1568,23 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputInfluxdbType(str, Enum): +class CreateOutputSystemByPackOutputMinioType(str, Enum): r"""Connector type identifier.""" - INFLUXDB = "influxdb" - - -class CreateOutputSystemByPackTimestampPrecision( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - - # Nanoseconds - NS = "ns" - # Microseconds - U = "u" - # Milliseconds - MS = "ms" - # Seconds - S = "s" - # Minutes - M = "m" - # Hours - H = "h" - - -class CreateOutputSystemByPackOutputInfluxdbAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""InfluxDB authentication type""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - - -class CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputInfluxdbPqControls(BaseModel): - r"""Persistent queue controls.""" + MINIO = "minio" -class CreateOutputSystemByPackOutputInfluxdbTypedDict(TypedDict): +class CreateOutputSystemByPackOutputMinioTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputInfluxdbType + type: CreateOutputSystemByPackOutputMinioType r"""Connector type identifier.""" - url: str - r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + bucket: str + r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""MinIO service url (e.g. http://minioHost:9000)""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -1930,117 +1593,156 @@ class CreateOutputSystemByPackOutputInfluxdbTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - use_v2_api: NotRequired[bool] - r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - timestamp_precision: NotRequired[CreateOutputSystemByPackTimestampPrecision] - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - dynamic_value_field_name: NotRequired[bool] - r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" - value_field_name: NotRequired[str] - r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the MinIO bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputSystemByPackOutputInfluxdbAuthenticationType] - r"""InfluxDB authentication type""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ + ServerSideEncryptionForUploadedObjectsOptionsAes256 + ] + r"""Server-side encryption to use for uploaded objects""" description: NotRequired[str] r"""Optional description for this configuration.""" - database: NotRequired[str] - r"""Database to write to.""" - bucket: NotRequired[str] - r"""Bucket to write to.""" - org: NotRequired[str] - r"""Organization ID for this bucket.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict] - r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputSystemByPackOutputInfluxdb(BaseModel): +class CreateOutputSystemByPackOutputMinio(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputInfluxdbType + type: CreateOutputSystemByPackOutputMinioType r"""Connector type identifier.""" - url: str - r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + bucket: str + r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + endpoint: str + r"""MinIO service url (e.g. http://minioHost:9000)""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -2056,238 +1758,339 @@ class CreateOutputSystemByPackOutputInfluxdb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - use_v2_api: Annotated[Optional[bool], pydantic.Field(alias="useV2API")] = None - r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - - timestamp_precision: Annotated[ - Optional[CreateOutputSystemByPackTimestampPrecision], - pydantic.Field(alias="timestampPrecision"), + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - dynamic_value_field_name: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicValueFieldName") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" + r"""Reuse connections between requests, which can improve performance""" - value_field_name: Annotated[ - Optional[str], pydantic.Field(alias="valueFieldName") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + region: Optional[str] = None + r"""Region where the MinIO bucket is located""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Add the Output ID value to staging location""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""Headers to add to all events""" + r"""Remove empty staging directories after moving files""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Buffer size used to write to a file""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputInfluxdbAuthenticationType], - pydantic.Field(alias="authType"), + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""InfluxDB authentication type""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - database: Optional[str] = None - r"""Database to write to.""" + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - bucket: Optional[str] = None - r"""Bucket to write to.""" + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None - org: Optional[str] = None - r"""Organization ID for this bucket.""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Object ACL to assign to uploaded objects""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + storage_class: Annotated[ + Optional[StorageClassOptionsReducedredundancyStandard], + pydantic.Field(alias="storageClass"), ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Storage class to select for uploaded objects""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Compression level to apply before moving files to final destination""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Determines which data types are supported and how they are represented""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") + ] = None + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""Codec to use to compress the persisted data""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputInfluxdbPqControls], - pydantic.Field(alias="pqControls"), + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""Persistent queue controls.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - username: Optional[str] = None - r"""Username""" + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") + ] = None + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - password: Optional[str] = None - r"""Password""" + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") + ] = None + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Select or create a secret that references your credentials""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") + ] = None + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - @field_serializer("timestamp_precision") - def serialize_timestamp_precision(self, value): + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + ] = None + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackTimestampPrecision(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -2296,45 +2099,79 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputInfluxdbAuthenticationType( - value - ) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.StorageClassOptionsReducedredundancyStandard(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -2347,54 +2184,72 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "useV2API", - "timestampPrecision", - "dynamicValueFieldName", - "valueFieldName", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", - "authType", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", "description", - "database", - "bucket", - "org", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - "__template_database", "__template_bucket", + "__template_region", + "__template_destPath", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", + "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -2411,29 +2266,31 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputNewrelicEventsType(str, Enum): +class CreateOutputSystemByPackOutputCloudwatchType(str, Enum): r"""Connector type identifier.""" - NEWRELIC_EVENTS = "newrelic_events" + CLOUDWATCH = "cloudwatch" -class CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputNewrelicEventsPqControls(BaseModel): +class CreateOutputSystemByPackOutputCloudwatchPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputNewrelicEventsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputCloudwatchTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputNewrelicEventsType + type: CreateOutputSystemByPackOutputCloudwatchType r"""Connector type identifier.""" - account_id: str - r"""New Relic account ID""" - event_type: str - r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" + log_group_name: str + r"""CloudWatch log group to associate events with""" + log_stream_name: str + r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + region: str + r"""Region where the CloudWatchLogs is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -2442,49 +2299,38 @@ class CreateOutputSystemByPackOutputNewrelicEventsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - region: NotRequired[RegionOptions] - r"""Which New Relic region endpoint to use.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access CloudWatchLogs""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -2508,41 +2354,46 @@ class CreateOutputSystemByPackOutputNewrelicEventsTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict + CreateOutputSystemByPackOutputCloudwatchPqControlsTypedDict ] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_log_group_name: NotRequired[str] + r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" + template_log_stream_name: NotRequired[str] + r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_account_id: NotRequired[str] - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - template_event_type: NotRequired[str] - r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: NotRequired[str] - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputNewrelicEvents(BaseModel): +class CreateOutputSystemByPackOutputCloudwatch(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputNewrelicEventsType + type: CreateOutputSystemByPackOutputCloudwatchType r"""Connector type identifier.""" - account_id: Annotated[str, pydantic.Field(alias="accountId")] - r"""New Relic account ID""" + log_group_name: Annotated[str, pydantic.Field(alias="logGroupName")] + r"""CloudWatch log group to associate events with""" - event_type: Annotated[str, pydantic.Field(alias="eventType")] - r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" + log_stream_name: Annotated[str, pydantic.Field(alias="logStreamName")] + r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + + region: str + r"""Region where the CloudWatchLogs is located""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -2558,97 +2409,78 @@ class CreateOutputSystemByPackOutputNewrelicEvents(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - region: Optional[RegionOptions] = None - r"""Which New Relic region endpoint to use.""" + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + endpoint: Optional[str] = None + r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Headers to add to all events""" + r"""Use Assume Role credentials to access CloudWatchLogs""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""External ID to use when assuming role""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None + r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -2700,66 +2532,66 @@ class CreateOutputSystemByPackOutputNewrelicEvents(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputNewrelicEventsPqControls], + Optional[CreateOutputSystemByPackOutputCloudwatchPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_log_group_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_logGroupName") + ] = None + r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" + + template_log_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_logStreamName") + ] = None + r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: Annotated[ Optional[str], pydantic.Field(alias="__template_region") ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_accountId") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_event_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_eventType") + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") ] = None - r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_customUrl") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - - @field_serializer("region") - def serialize_region(self, value): - if isinstance(value, str): - try: - return models.RegionOptions(value) - except ValueError: - return value - return value + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -2773,15 +2605,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -2817,26 +2640,22 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "region", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxQueueSize", + "maxRecordSizeKB", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", "onBackpressure", - "authType", "description", - "customUrl", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -2849,15 +2668,16 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", + "__template_logGroupName", + "__template_logStreamName", + "__template_awsSecretKey", "__template_region", - "__template_accountId", - "__template_eventType", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", - "__template_customUrl", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -2874,58 +2694,63 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputNewrelicType(str, Enum): +class CreateOutputSystemByPackOutputInfluxdbType(str, Enum): r"""Connector type identifier.""" - NEWRELIC = "newrelic" + INFLUXDB = "influxdb" -class CreateOutputSystemByPackFieldName(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Name of the metadata field.""" +class CreateOutputSystemByPackTimestampPrecision( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - SERVICE = "service" - HOSTNAME = "hostname" - TIMESTAMP = "timestamp" - AUDIT_ID = "auditId" + # Nanoseconds + NS = "ns" + # Microseconds + U = "u" + # Milliseconds + MS = "ms" + # Seconds + S = "s" + # Minutes + M = "m" + # Hours + H = "h" -class CreateOutputSystemByPackMetadatumTypedDict(TypedDict): - name: CreateOutputSystemByPackFieldName - r"""Name of the metadata field.""" - value: str - r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - - -class CreateOutputSystemByPackMetadatum(BaseModel): - name: CreateOutputSystemByPackFieldName - r"""Name of the metadata field.""" - - value: str - r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" +class CreateOutputSystemByPackOutputInfluxdbAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""InfluxDB authentication type""" - @field_serializer("name") - def serialize_name(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackFieldName(value) - except ValueError: - return value - return value + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" -class CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputNewrelicPqControls(BaseModel): +class CreateOutputSystemByPackOutputInfluxdbPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputNewrelicTypedDict(TypedDict): +class CreateOutputSystemByPackOutputInfluxdbTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputNewrelicType + type: CreateOutputSystemByPackOutputInfluxdbType r"""Connector type identifier.""" + url: str + r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -2934,14 +2759,14 @@ class CreateOutputSystemByPackOutputNewrelicTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - region: NotRequired[RegionOptions] - r"""Which New Relic region endpoint to use.""" - log_type: NotRequired[str] - r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" - message_field: NotRequired[str] - r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" - metadata: NotRequired[List[CreateOutputSystemByPackMetadatumTypedDict]] - r"""Fields to add to events from this input""" + use_v2_api: NotRequired[bool] + r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" + timestamp_precision: NotRequired[CreateOutputSystemByPackTimestampPrecision] + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" + dynamic_value_field_name: NotRequired[bool] + r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" + value_field_name: NotRequired[str] + r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -2978,13 +2803,16 @@ class CreateOutputSystemByPackOutputNewrelicTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[CreateOutputSystemByPackOutputInfluxdbAuthenticationType] + r"""InfluxDB authentication type""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + database: NotRequired[str] + r"""Database to write to.""" + bucket: NotRequired[str] + r"""Bucket to write to.""" + org: NotRequired[str] + r"""Organization ID for this bucket.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -3007,33 +2835,42 @@ class CreateOutputSystemByPackOutputNewrelicTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputInfluxdbPqControlsTypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_log_type: NotRequired[str] - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" - template_message_field: NotRequired[str] - r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" -class CreateOutputSystemByPackOutputNewrelic(BaseModel): +class CreateOutputSystemByPackOutputInfluxdb(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputNewrelicType + type: CreateOutputSystemByPackOutputInfluxdbType r"""Connector type identifier.""" + url: str + r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -3048,17 +2885,24 @@ class CreateOutputSystemByPackOutputNewrelic(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - region: Optional[RegionOptions] = None - r"""Which New Relic region endpoint to use.""" + use_v2_api: Annotated[Optional[bool], pydantic.Field(alias="useV2API")] = None + r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None - r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + timestamp_precision: Annotated[ + Optional[CreateOutputSystemByPackTimestampPrecision], + pydantic.Field(alias="timestampPrecision"), + ] = None + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None - r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + dynamic_value_field_name: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicValueFieldName") + ] = None + r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" - metadata: Optional[List[CreateOutputSystemByPackMetadatum]] = None - r"""Fields to add to events from this input""" + value_field_name: Annotated[ + Optional[str], pydantic.Field(alias="valueFieldName") + ] = None + r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -3140,19 +2984,22 @@ class CreateOutputSystemByPackOutputNewrelic(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + Optional[CreateOutputSystemByPackOutputInfluxdbAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""InfluxDB authentication type""" description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + database: Optional[str] = None + r"""Database to write to.""" + + bucket: Optional[str] = None + r"""Bucket to write to.""" + + org: Optional[str] = None + r"""Organization ID for this bucket.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -3204,13 +3051,24 @@ class CreateOutputSystemByPackOutputNewrelic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputNewrelicPqControls], + Optional[CreateOutputSystemByPackOutputInfluxdbPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -3220,20 +3078,10 @@ class CreateOutputSystemByPackOutputNewrelic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_log_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_logType") - ] = None - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" - - template_message_field: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageField") - ] = None - r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -3245,11 +3093,21 @@ class CreateOutputSystemByPackOutputNewrelic(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("region") - def serialize_region(self, value): + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") + ] = None + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + + @field_serializer("timestamp_precision") + def serialize_timestamp_precision(self, value): if isinstance(value, str): try: - return models.RegionOptions(value) + return models.CreateOutputSystemByPackTimestampPrecision(value) except ValueError: return value return value @@ -3276,7 +3134,9 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAPI(value) + return models.CreateOutputSystemByPackOutputInfluxdbAuthenticationType( + value + ) except ValueError: return value return value @@ -3316,10 +3176,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "region", - "logType", - "messageField", - "metadata", + "useV2API", + "timestampPrecision", + "dynamicValueFieldName", + "valueFieldName", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -3337,9 +3197,10 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "database", + "bucket", + "org", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -3352,14 +3213,17 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", + "username", + "password", + "token", + "credentialsSecret", "textSecret", "__template_streamtags", - "__template_region", - "__template_logType", - "__template_messageField", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_database", + "__template_bucket", ] ) serialized = handler(self) @@ -3376,29 +3240,29 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputElasticCloudType(str, Enum): +class CreateOutputSystemByPackOutputNewrelicEventsType(str, Enum): r"""Connector type identifier.""" - ELASTIC_CLOUD = "elastic_cloud" + NEWRELIC_EVENTS = "newrelic_events" -class CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputElasticCloudPqControls(BaseModel): +class CreateOutputSystemByPackOutputNewrelicEventsPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputElasticCloudTypedDict(TypedDict): +class CreateOutputSystemByPackOutputNewrelicEventsTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputElasticCloudType + type: CreateOutputSystemByPackOutputNewrelicEventsType r"""Connector type identifier.""" - url: str - r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" - index: str - r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" + account_id: str + r"""New Relic account ID""" + event_type: str + r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -3407,6 +3271,8 @@ class CreateOutputSystemByPackOutputElasticCloudTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + region: NotRequired[RegionOptions] + r"""Which New Relic region endpoint to use.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -3428,17 +3294,12 @@ class CreateOutputSystemByPackOutputElasticCloudTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] - r"""Extra parameters to use in HTTP requests""" - auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] - elastic_pipeline: NotRequired[str] - r"""Optional Elastic Cloud Destination pipeline""" - include_doc_id: NotRequired[bool] - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -3448,8 +3309,11 @@ class CreateOutputSystemByPackOutputElasticCloudTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -3473,35 +3337,41 @@ class CreateOutputSystemByPackOutputElasticCloudTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict + CreateOutputSystemByPackOutputNewrelicEventsPqControlsTypedDict ] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_index: NotRequired[str] - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_account_id: NotRequired[str] + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + template_event_type: NotRequired[str] + r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: NotRequired[str] - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_custom_url: NotRequired[str] + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" -class CreateOutputSystemByPackOutputElasticCloud(BaseModel): +class CreateOutputSystemByPackOutputNewrelicEvents(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputElasticCloudType + type: CreateOutputSystemByPackOutputNewrelicEventsType r"""Connector type identifier.""" - url: str - r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" + account_id: Annotated[str, pydantic.Field(alias="accountId")] + r"""New Relic account ID""" - index: str - r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" + event_type: Annotated[str, pydantic.Field(alias="eventType")] + r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -3517,6 +3387,9 @@ class CreateOutputSystemByPackOutputElasticCloud(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + region: Optional[RegionOptions] = None + r"""Which New Relic region endpoint to use.""" + concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -3560,6 +3433,11 @@ class CreateOutputSystemByPackOutputElasticCloud(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -3571,23 +3449,6 @@ class CreateOutputSystemByPackOutputElasticCloud(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - extra_params: Annotated[ - Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") - ] = None - r"""Extra parameters to use in HTTP requests""" - - auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - - elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="elasticPipeline") - ] = None - r"""Optional Elastic Cloud Destination pipeline""" - - include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( - None - ) - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -3608,9 +3469,16 @@ class CreateOutputSystemByPackOutputElasticCloud(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + ] = None + r"""Enter API key directly, or select a stored secret""" + description: Optional[str] = None r"""Optional description for this configuration.""" + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -3661,41 +3529,61 @@ class CreateOutputSystemByPackOutputElasticCloud(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputElasticCloudPqControls], + Optional[CreateOutputSystemByPackOutputNewrelicEventsPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_index: Annotated[ - Optional[str], pydantic.Field(alias="__template_index") + template_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_accountId") ] = None - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + + template_event_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_eventType") + ] = None + r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticPipeline") - ] = None - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_custom_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_customUrl") + ] = None + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + + @field_serializer("region") + def serialize_region(self, value): + if isinstance(value, str): + try: + return models.RegionOptions(value) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -3714,6 +3602,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -3749,6 +3646,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "region", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -3758,17 +3656,16 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "extraParams", - "auth", - "elasticPipeline", - "includeDocId", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", "onBackpressure", + "authType", "description", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -3781,12 +3678,15 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_url", - "__template_index", + "__template_region", + "__template_accountId", + "__template_eventType", "__template_failedRequestLoggingMode", - "__template_elasticPipeline", "__template_onBackpressure", + "__template_customUrl", ] ) serialized = handler(self) @@ -3803,85 +3703,58 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputElasticType(str, Enum): +class CreateOutputSystemByPackOutputNewrelicType(str, Enum): r"""Connector type identifier.""" - ELASTIC = "elastic" - - -class CreateOutputSystemByPackElasticVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - - # Auto - AUTO = "auto" - # 6.x - SIX = "6" - # 7.x - SEVEN = "7" - - -class CreateOutputSystemByPackWriteAction(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - - # Index - INDEX = "index" - # Create - CREATE = "create" - + NEWRELIC = "newrelic" -class CreateOutputSystemByPackOutputElasticURLTypedDict(TypedDict): - url: str - r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" +class CreateOutputSystemByPackFieldName(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Name of the metadata field.""" -class CreateOutputSystemByPackOutputElasticURL(BaseModel): - url: str - r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + SERVICE = "service" + HOSTNAME = "hostname" + TIMESTAMP = "timestamp" + AUDIT_ID = "auditId" - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" +class CreateOutputSystemByPackMetadatumTypedDict(TypedDict): + name: CreateOutputSystemByPackFieldName + r"""Name of the metadata field.""" + value: str + r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateOutputSystemByPackMetadatum(BaseModel): + name: CreateOutputSystemByPackFieldName + r"""Name of the metadata field.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + value: str + r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - return m + @field_serializer("name") + def serialize_name(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackFieldName(value) + except ValueError: + return value + return value -class CreateOutputSystemByPackOutputElasticPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputElasticPqControls(BaseModel): +class CreateOutputSystemByPackOutputNewrelicPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputElasticTypedDict(TypedDict): +class CreateOutputSystemByPackOutputNewrelicTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputElasticType + type: CreateOutputSystemByPackOutputNewrelicType r"""Connector type identifier.""" - index: str - r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -3890,10 +3763,14 @@ class CreateOutputSystemByPackOutputElasticTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - doc_type: NotRequired[str] - r"""Document type to use for events. Can be overwritten by an event's __type field.""" + region: NotRequired[RegionOptions] + r"""Which New Relic region endpoint to use.""" + log_type: NotRequired[str] + r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + message_field: NotRequired[str] + r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + metadata: NotRequired[List[CreateOutputSystemByPackMetadatumTypedDict]] + r"""Fields to add to events from this input""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -3915,6 +3792,8 @@ class CreateOutputSystemByPackOutputElasticTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] @@ -3926,35 +3805,15 @@ class CreateOutputSystemByPackOutputElasticTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] - r"""Extra parameters""" - auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] - elastic_version: NotRequired[CreateOutputSystemByPackElasticVersion] - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - elastic_pipeline: NotRequired[str] - r"""Optional Elasticsearch destination pipeline""" - include_doc_id: NotRequired[bool] - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - write_action: NotRequired[CreateOutputSystemByPackWriteAction] - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - retry_partial_errors: NotRequired[bool] - r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputSystemByPackOutputElasticURLTypedDict]] - r"""Bulk API URLs""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -3977,34 +3836,33 @@ class CreateOutputSystemByPackOutputElasticTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputElasticPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputNewrelicPqControlsTypedDict] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_index: NotRequired[str] - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_doc_type: NotRequired[str] - r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_log_type: NotRequired[str] + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + template_message_field: NotRequired[str] + r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: NotRequired[str] - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputElastic(BaseModel): +class CreateOutputSystemByPackOutputNewrelic(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputElasticType + type: CreateOutputSystemByPackOutputNewrelicType r"""Connector type identifier.""" - index: str - r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -4019,13 +3877,17 @@ class CreateOutputSystemByPackOutputElastic(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + region: Optional[RegionOptions] = None + r"""Which New Relic region endpoint to use.""" - doc_type: Annotated[Optional[str], pydantic.Field(alias="docType")] = None - r"""Document type to use for events. Can be overwritten by an event's __type field.""" + log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None + r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + + message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None + r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + + metadata: Optional[List[CreateOutputSystemByPackMetadatum]] = None + r"""Fields to add to events from this input""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -4070,6 +3932,11 @@ class CreateOutputSystemByPackOutputElastic(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -4096,71 +3963,25 @@ class CreateOutputSystemByPackOutputElastic(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - extra_params: Annotated[ - Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") - ] = None - r"""Extra parameters""" - - auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - - elastic_version: Annotated[ - Optional[CreateOutputSystemByPackElasticVersion], - pydantic.Field(alias="elasticVersion"), - ] = None - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - - elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="elasticPipeline") - ] = None - r"""Optional Elasticsearch destination pipeline""" - - include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( - None - ) - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - - write_action: Annotated[ - Optional[CreateOutputSystemByPackWriteAction], - pydantic.Field(alias="writeAction"), - ] = None - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - - retry_partial_errors: Annotated[ - Optional[bool], pydantic.Field(alias="retryPartialErrors") - ] = None - r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - url: Optional[str] = None - r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[CreateOutputSystemByPackOutputElasticURL]] = None - r"""Bulk API URLs""" + r"""Enter API key directly, or select a stored secret""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -4212,78 +4033,79 @@ class CreateOutputSystemByPackOutputElastic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputElasticPqControls], + Optional[CreateOutputSystemByPackOutputNewrelicPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_index: Annotated[ - Optional[str], pydantic.Field(alias="__template_index") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_doc_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_docType") + template_log_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_logType") ] = None - r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + + template_message_field: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageField") + ] = None + r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticPipeline") - ] = None - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("region") + def serialize_region(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.RegionOptions(value) except ValueError: return value return value - @field_serializer("elastic_version") - def serialize_elastic_version(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackElasticVersion(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("write_action") - def serialize_write_action(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackWriteAction(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.AuthenticationMethodOptionsAPI(value) except ValueError: return value return value @@ -4323,8 +4145,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "docType", + "region", + "logType", + "messageField", + "metadata", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -4334,26 +4158,17 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "extraParams", - "auth", - "elasticVersion", - "elasticPipeline", - "includeDocId", - "writeAction", - "retryPartialErrors", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -4366,13 +4181,14 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_index", - "__template_docType", + "__template_region", + "__template_logType", + "__template_messageField", "__template_failedRequestLoggingMode", - "__template_elasticPipeline", "__template_onBackpressure", - "__template_url", ] ) serialized = handler(self) @@ -4389,27 +4205,29 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputMskPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputElasticCloudType(str, Enum): + r"""Connector type identifier.""" + + ELASTIC_CLOUD = "elastic_cloud" + + +class CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputMskPqControls(BaseModel): +class CreateOutputSystemByPackOutputElasticCloudPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputMskTypedDict(TypedDict): +class CreateOutputSystemByPackOutputElasticCloudTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsMsk + type: CreateOutputSystemByPackOutputElasticCloudType r"""Connector type identifier.""" - brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" - aws_authentication_method: AuthenticationMethodOptionsS3CollectorConf - r"""AWS authentication method. Choose Auto to use IAM roles.""" - region: str - r"""Region where the MSK cluster is located""" + url: str + r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" + index: str + r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -4418,68 +4236,49 @@ class CreateOutputSystemByPackOutputMskTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - ack: NotRequired[AcknowledgmentsOptionsAllLeader] - r"""Control the number of required acknowledgments.""" - format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] - r"""Format to use to serialize events before writing to Kafka.""" - compression: NotRequired[CompressionOptionsGzipLz4] - r"""Codec to use to compress the data before sending to Kafka""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - flush_event_count: NotRequired[float] - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - kafka_schema_registry: NotRequired[ - KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] + r"""Extra parameters to use in HTTP requests""" + auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] + elastic_pipeline: NotRequired[str] + r"""Optional Elastic Cloud Destination pipeline""" + include_doc_id: NotRequired[bool] + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] ] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access MSK""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - protobuf_library_id: NotRequired[str] - r"""Select a set of Protobuf definitions for the events you want to send""" - protobuf_encoding_id: NotRequired[str] - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -4502,53 +4301,36 @@ class CreateOutputSystemByPackOutputMskTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputMskPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputElasticCloudPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compression: NotRequired[str] - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_index: NotRequired[str] + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_elastic_pipeline: NotRequired[str] + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputMsk(BaseModel): +class CreateOutputSystemByPackOutputElasticCloud(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsMsk + type: CreateOutputSystemByPackOutputElasticCloudType r"""Connector type identifier.""" - brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" - - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" - - aws_authentication_method: Annotated[ - AuthenticationMethodOptionsS3CollectorConf, - pydantic.Field(alias="awsAuthenticationMethod"), - ] - r"""AWS authentication method. Choose Auto to use IAM roles.""" + url: str + r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" - region: str - r"""Region where the MSK cluster is located""" + index: str + r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -4564,137 +4346,100 @@ class CreateOutputSystemByPackOutputMsk(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - ack: Optional[AcknowledgmentsOptionsAllLeader] = None - r"""Control the number of required acknowledgments.""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - format_: Annotated[ - Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Format to use to serialize events before writing to Kafka.""" + r"""Maximum size, in KB, of the request body""" - compression: Optional[CompressionOptionsGzipLz4] = None - r"""Codec to use to compress the data before sending to Kafka""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], - pydantic.Field(alias="kafkaSchemaRegistry"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Kafka Schema Registry Authentication""" + r"""Headers to add to all events""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + r"""List of headers that are safe to log in plain text""" - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + extra_params: Annotated[ + Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + r"""Extra parameters to use in HTTP requests""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="elasticPipeline") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""Optional Elastic Cloud Destination pipeline""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( None ) - r"""Secret key""" + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - endpoint: Optional[str] = None - r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Use Assume Role credentials to access MSK""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - protobuf_library_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufLibraryId") - ] = None - r"""Select a set of Protobuf definitions for the events you want to send""" - - protobuf_encoding_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufEncodingId") - ] = None - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -4745,7 +4490,7 @@ class CreateOutputSystemByPackOutputMsk(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputMskPqControls], + Optional[CreateOutputSystemByPackOutputElasticCloudPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -4755,88 +4500,36 @@ class CreateOutputSystemByPackOutputMsk(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") - ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_compression: Annotated[ - Optional[str], pydantic.Field(alias="__template_compression") - ] = None - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_index: Annotated[ + Optional[str], pydantic.Field(alias="__template_index") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticPipeline") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - @field_serializer("ack") - def serialize_ack(self, value): - if isinstance(value, str): - try: - return models.AcknowledgmentsOptionsAllLeader(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.RecordDataFormatOptionsJSONProtobuf(value) - except ValueError: - return value - return value - - @field_serializer("compression") - def serialize_compression(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsGzipLz4(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -4885,36 +4578,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "ack", - "format", - "compression", - "maxRecordSizeKB", - "flushEventCount", - "flushPeriodSec", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "awsSecretKey", - "endpoint", - "reuseConnections", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "tls", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "extraParams", + "auth", + "elasticPipeline", + "includeDocId", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", "description", - "awsApiKey", - "awsSecret", - "protobufLibraryId", - "protobufEncodingId", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -4928,16 +4611,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topic", - "__template_format", - "__template_compression", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_url", + "__template_index", + "__template_failedRequestLoggingMode", + "__template_elasticPipeline", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -4954,23 +4632,85 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputElasticType(str, Enum): + r"""Connector type identifier.""" + + ELASTIC = "elastic" + + +class CreateOutputSystemByPackElasticVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" + + # Auto + AUTO = "auto" + # 6.x + SIX = "6" + # 7.x + SEVEN = "7" + + +class CreateOutputSystemByPackWriteAction(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + + # Index + INDEX = "index" + # Create + CREATE = "create" + + +class CreateOutputSystemByPackOutputElasticURLTypedDict(TypedDict): + url: str + r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputSystemByPackOutputElasticURL(BaseModel): + url: str + r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputElasticPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputConfluentCloudPqControls(BaseModel): +class CreateOutputSystemByPackOutputElasticPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputConfluentCloudTypedDict(TypedDict): +class CreateOutputSystemByPackOutputElasticTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsConfluentcloud + type: CreateOutputSystemByPackOutputElasticType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + index: str + r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -4979,50 +4719,71 @@ class CreateOutputSystemByPackOutputConfluentCloudTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - ack: NotRequired[AcknowledgmentsOptionsAllLeader] - r"""Control the number of required acknowledgments.""" - format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] - r"""Format to use to serialize events before writing to Kafka.""" - compression: NotRequired[CompressionOptionsGzipLz4] - r"""Codec to use to compress the data before sending to Kafka""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - flush_event_count: NotRequired[float] - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + doc_type: NotRequired[str] + r"""Document type to use for events. Can be overwritten by an event's __type field.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - kafka_schema_registry: NotRequired[ - KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] ] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] + r"""Extra parameters""" + auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] + elastic_version: NotRequired[CreateOutputSystemByPackElasticVersion] + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" + elastic_pipeline: NotRequired[str] + r"""Optional Elasticsearch destination pipeline""" + include_doc_id: NotRequired[bool] + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" + write_action: NotRequired[CreateOutputSystemByPackWriteAction] + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + retry_partial_errors: NotRequired[bool] + r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - protobuf_library_id: NotRequired[str] - r"""Select a set of Protobuf definitions for the events you want to send""" - protobuf_encoding_id: NotRequired[str] - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + url: NotRequired[str] + r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputSystemByPackOutputElasticURLTypedDict]] + r"""Bulk API URLs""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -5045,36 +4806,33 @@ class CreateOutputSystemByPackOutputConfluentCloudTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputSystemByPackOutputElasticPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compression: NotRequired[str] - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + template_index: NotRequired[str] + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_doc_type: NotRequired[str] + r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_elastic_pipeline: NotRequired[str] + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputConfluentCloud(BaseModel): +class CreateOutputSystemByPackOutputElastic(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsConfluentcloud + type: CreateOutputSystemByPackOutputElasticType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" - - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + index: str + r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -5090,77 +4848,116 @@ class CreateOutputSystemByPackOutputConfluentCloud(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - ack: Optional[AcknowledgmentsOptionsAllLeader] = None - r"""Control the number of required acknowledgments.""" + doc_type: Annotated[Optional[str], pydantic.Field(alias="docType")] = None + r"""Document type to use for events. Can be overwritten by an event's __type field.""" - format_: Annotated[ - Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Format to use to serialize events before writing to Kafka.""" + r"""Maximum size, in KB, of the request body""" - compression: Optional[CompressionOptionsGzipLz4] = None - r"""Codec to use to compress the data before sending to Kafka""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], - pydantic.Field(alias="kafkaSchemaRegistry"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Kafka Schema Registry Authentication""" + r"""Headers to add to all events""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum time to wait for Kafka to respond to a request""" + r"""List of headers that are safe to log in plain text""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + extra_params: Annotated[ + Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") + ] = None + r"""Extra parameters""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") + auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None + + elastic_version: Annotated[ + Optional[CreateOutputSystemByPackElasticVersion], + pydantic.Field(alias="elasticVersion"), ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="elasticPipeline") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""Optional Elasticsearch destination pipeline""" - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( + None + ) + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" + + write_action: Annotated[ + Optional[CreateOutputSystemByPackWriteAction], + pydantic.Field(alias="writeAction"), + ] = None + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + + retry_partial_errors: Annotated[ + Optional[bool], pydantic.Field(alias="retryPartialErrors") + ] = None + r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -5170,15 +4967,29 @@ class CreateOutputSystemByPackOutputConfluentCloud(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - protobuf_library_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufLibraryId") + url: Optional[str] = None + r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Select a set of Protobuf definitions for the events you want to send""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - protobuf_encoding_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufEncodingId") + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[CreateOutputSystemByPackOutputElasticURL]] = None + r"""Bulk API URLs""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -5230,7 +5041,7 @@ class CreateOutputSystemByPackOutputConfluentCloud(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputConfluentCloudPqControls], + Optional[CreateOutputSystemByPackOutputElasticPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -5240,54 +5051,59 @@ class CreateOutputSystemByPackOutputConfluentCloud(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") + template_index: Annotated[ + Optional[str], pydantic.Field(alias="__template_index") ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") + template_doc_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_docType") ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_compression: Annotated[ - Optional[str], pydantic.Field(alias="__template_compression") + template_elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticPipeline") ] = None - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("ack") - def serialize_ack(self, value): + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AcknowledgmentsOptionsAllLeader(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("elastic_version") + def serialize_elastic_version(self, value): if isinstance(value, str): try: - return models.RecordDataFormatOptionsJSONProtobuf(value) + return models.CreateOutputSystemByPackElasticVersion(value) except ValueError: return value return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("write_action") + def serialize_write_action(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipLz4(value) + return models.CreateOutputSystemByPackWriteAction(value) except ValueError: return value return value @@ -5336,27 +5152,37 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "tls", - "ack", - "format", - "compression", - "maxRecordSizeKB", - "flushEventCount", + "loadBalanced", + "docType", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "extraParams", + "auth", + "elasticVersion", + "elasticPipeline", + "includeDocId", + "writeAction", + "retryPartialErrors", "onBackpressure", "description", - "protobufLibraryId", - "protobufEncodingId", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -5370,11 +5196,12 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_brokers", - "__template_topic", - "__template_format", - "__template_compression", + "__template_index", + "__template_docType", + "__template_failedRequestLoggingMode", + "__template_elasticPipeline", "__template_onBackpressure", + "__template_url", ] ) serialized = handler(self) @@ -5391,23 +5218,27 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputKafkaPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputMskPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputKafkaPqControls(BaseModel): +class CreateOutputSystemByPackOutputMskPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputKafkaTypedDict(TypedDict): +class CreateOutputSystemByPackOutputMskTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptions + type: TypeOptionsMsk r"""Connector type identifier.""" brokers: List[str] r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + aws_authentication_method: AuthenticationMethodOptionsS3CollectorConf + r"""AWS authentication method. Choose Auto to use IAM roles.""" + region: str + r"""Region where the MSK cluster is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -5448,14 +5279,32 @@ class CreateOutputSystemByPackOutputKafkaTypedDict(TypedDict): r"""Maximum time to wait for Kafka to respond to an authentication request""" reauthentication_threshold: NotRequired[float] r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access MSK""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" protobuf_library_id: NotRequired[str] r"""Select a set of Protobuf definitions for the events you want to send""" protobuf_encoding_id: NotRequired[str] @@ -5482,7 +5331,7 @@ class CreateOutputSystemByPackOutputKafkaTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputKafkaPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputMskPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -5492,15 +5341,27 @@ class CreateOutputSystemByPackOutputKafkaTypedDict(TypedDict): r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_compression: NotRequired[str] r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputKafka(BaseModel): +class CreateOutputSystemByPackOutputMsk(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptions + type: TypeOptionsMsk r"""Connector type identifier.""" brokers: List[str] @@ -5509,6 +5370,15 @@ class CreateOutputSystemByPackOutputKafka(BaseModel): topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + aws_authentication_method: Annotated[ + AuthenticationMethodOptionsS3CollectorConf, + pydantic.Field(alias="awsAuthenticationMethod"), + ] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + region: str + r"""Region where the MSK cluster is located""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -5589,8 +5459,43 @@ class CreateOutputSystemByPackOutputKafka(BaseModel): ] = None r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + endpoint: Optional[str] = None + r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access MSK""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None r"""TLS settings (client side)""" @@ -5603,6 +5508,12 @@ class CreateOutputSystemByPackOutputKafka(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + protobuf_library_id: Annotated[ Optional[str], pydantic.Field(alias="protobufLibraryId") ] = None @@ -5663,7 +5574,7 @@ class CreateOutputSystemByPackOutputKafka(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputKafkaPqControls], + Optional[CreateOutputSystemByPackOutputMskPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -5688,21 +5599,51 @@ class CreateOutputSystemByPackOutputKafka(BaseModel): ] = None r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - @field_serializer("ack") - def serialize_ack(self, value): - if isinstance(value, str): - try: - return models.AcknowledgmentsOptionsAllLeader(value) - except ValueError: - return value - return value + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - @field_serializer("format_") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + @field_serializer("ack") + def serialize_ack(self, value): + if isinstance(value, str): + try: + return models.AcknowledgmentsOptionsAllLeader(value) + except ValueError: + return value + return value + + @field_serializer("format_") def serialize_format_(self, value): if isinstance(value, str): try: @@ -5720,6 +5661,15 @@ def serialize_compression(self, value): return value return value + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -5779,10 +5729,19 @@ def serialize_model(self, handler): "backoffRate", "authenticationTimeout", "reauthenticationThreshold", - "sasl", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "tls", "onBackpressure", "description", + "awsApiKey", + "awsSecret", "protobufLibraryId", "protobufEncodingId", "pqStrictOrdering", @@ -5801,7 +5760,13 @@ def serialize_model(self, handler): "__template_topic", "__template_format", "__template_compression", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", ] ) serialized = handler(self) @@ -5818,29 +5783,23 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputExabeamType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - EXABEAM = "exabeam" + +class CreateOutputSystemByPackOutputConfluentCloudPqControls(BaseModel): + r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputExabeamTypedDict(TypedDict): +class CreateOutputSystemByPackOutputConfluentCloudTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputExabeamType + type: TypeOptionsConfluentcloud r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" - region: str - r"""Region where the bucket is located""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Google Cloud Storage service endpoint""" - collector_instance_id: str - r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 - - """ + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -5849,94 +5808,102 @@ class CreateOutputSystemByPackOutputExabeamTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsArchiveColdline] - r"""Storage class to select for uploaded objects""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + ack: NotRequired[AcknowledgmentsOptionsAllLeader] + r"""Control the number of required acknowledgments.""" + format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] + r"""Format to use to serialize events before writing to Kafka.""" + compression: NotRequired[CompressionOptionsGzipLz4] + r"""Codec to use to compress the data before sending to Kafka""" + max_record_size_kb: NotRequired[float] + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + flush_event_count: NotRequired[float] + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + flush_period_sec: NotRequired[float] + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + kafka_schema_registry: NotRequired[ + KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + ] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - encoded_configuration: NotRequired[str] - r"""Enter an encoded string containing Exabeam configurations""" - site_name: NotRequired[str] - r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" - site_id: NotRequired[str] - r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" - timezone_offset: NotRequired[str] - r"""Timezone offset""" - aws_api_key: NotRequired[str] - r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - aws_secret_key: NotRequired[str] - r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" description: NotRequired[str] r"""Optional description for this configuration.""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + protobuf_library_id: NotRequired[str] + r"""Select a set of Protobuf definitions for the events you want to send""" + protobuf_encoding_id: NotRequired[str] + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputConfluentCloudPqControlsTypedDict + ] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_compression: NotRequired[str] + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputExabeam(BaseModel): +class CreateOutputSystemByPackOutputConfluentCloud(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputExabeamType + type: TypeOptionsConfluentcloud r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" - - region: str - r"""Region where the bucket is located""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - - endpoint: str - r"""Google Cloud Storage service endpoint""" - - collector_instance_id: Annotated[str, pydantic.Field(alias="collectorInstanceId")] - r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" - """ + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -5952,175 +5919,204 @@ class CreateOutputSystemByPackOutputExabeam(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - object_acl: Annotated[ - Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], - pydantic.Field(alias="objectACL"), + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + ack: Optional[AcknowledgmentsOptionsAllLeader] = None + r"""Control the number of required acknowledgments.""" + + format_: Annotated[ + Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") ] = None - r"""Object ACL to assign to uploaded objects""" + r"""Format to use to serialize events before writing to Kafka.""" - storage_class: Annotated[ - Optional[StorageClassOptionsArchiveColdline], - pydantic.Field(alias="storageClass"), + compression: Optional[CompressionOptionsGzipLz4] = None + r"""Codec to use to compress the data before sending to Kafka""" + + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Storage class to select for uploaded objects""" + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], + pydantic.Field(alias="kafkaSchemaRegistry"), ] = None - r"""Add the Output ID value to staging location""" + r"""Kafka Schema Registry Authentication""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Remove empty staging directories after moving files""" + r"""Maximum time to wait for a connection to complete successfully""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Maximum time to wait for Kafka to respond to a request""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Maximum time to wait for Kafka to respond to an authentication request""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""How to handle events when all receivers are exerting backpressure""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + protobuf_library_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufLibraryId") ] = None + r"""Select a set of Protobuf definitions for the events you want to send""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + protobuf_encoding_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufEncodingId") + ] = None + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - encoded_configuration: Annotated[ - Optional[str], pydantic.Field(alias="encodedConfiguration") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Enter an encoded string containing Exabeam configurations""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - site_name: Annotated[Optional[str], pydantic.Field(alias="siteName")] = None - r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - site_id: Annotated[Optional[str], pydantic.Field(alias="siteId")] = None - r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - timezone_offset: Annotated[ - Optional[str], pydantic.Field(alias="timezoneOffset") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Timezone offset""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Codec to use to compress the persisted data""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputConfluentCloudPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + template_compression: Annotated[ + Optional[str], pydantic.Field(alias="__template_compression") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( - value - ) + return models.AcknowledgmentsOptionsAllLeader(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.StorageClassOptionsArchiveColdline(value) + return models.RecordDataFormatOptionsJSONProtobuf(value) + except ValueError: + return value + return value + + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsGzipLz4(value) except ValueError: return value return value @@ -6129,16 +6125,34 @@ def serialize_storage_class(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -6151,37 +6165,44 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "objectACL", - "storageClass", - "reuseConnections", - "rejectUnauthorized", - "addIdToStagePath", - "removeEmptyDirs", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "retrySettings", - "orphans", - "maxFileSizeMB", - "encodedConfiguration", - "siteName", - "siteId", - "timezoneOffset", - "awsApiKey", - "awsSecretKey", + "tls", + "ack", + "format", + "compression", + "maxRecordSizeKB", + "flushEventCount", + "flushPeriodSec", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "onBackpressure", "description", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "protobufLibraryId", + "protobufEncodingId", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_region", - "__template_endpoint", - "__template_objectACL", - "__template_storageClass", + "__template_brokers", + "__template_topic", + "__template_format", + "__template_compression", "__template_onBackpressure", ] ) @@ -6199,21 +6220,23 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputKafkaPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGooglePubsubPqControls(BaseModel): +class CreateOutputSystemByPackOutputKafkaPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGooglePubsubTypedDict(TypedDict): +class CreateOutputSystemByPackOutputKafkaTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsGooglepubsub + type: TypeOptions r"""Connector type identifier.""" - topic_name: str - r"""ID of the topic to send events to.""" + brokers: List[str] + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -6222,34 +6245,50 @@ class CreateOutputSystemByPackOutputGooglePubsubTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - create_topic: NotRequired[bool] - r"""If enabled, create topic if it does not exist.""" - ordered_delivery: NotRequired[bool] - r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" - region: NotRequired[str] - r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - batch_size: NotRequired[float] - r"""The maximum number of items the Google API should batch before it sends them to the topic.""" - batch_timeout: NotRequired[float] - r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking.""" + ack: NotRequired[AcknowledgmentsOptionsAllLeader] + r"""Control the number of required acknowledgments.""" + format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] + r"""Format to use to serialize events before writing to Kafka.""" + compression: NotRequired[CompressionOptionsGzipLz4] + r"""Codec to use to compress the data before sending to Kafka""" max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of batches to send.""" - flush_period: NotRequired[float] - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + flush_event_count: NotRequired[float] + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + flush_period_sec: NotRequired[float] + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + kafka_schema_registry: NotRequired[ + KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + ] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + protobuf_library_id: NotRequired[str] + r"""Select a set of Protobuf definitions for the events you want to send""" + protobuf_encoding_id: NotRequired[str] + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -6272,29 +6311,32 @@ class CreateOutputSystemByPackOutputGooglePubsubTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputSystemByPackOutputKafkaPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: NotRequired[str] - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_compression: NotRequired[str] + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputGooglePubsub(BaseModel): +class CreateOutputSystemByPackOutputKafka(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsGooglepubsub + type: TypeOptions r"""Connector type identifier.""" - topic_name: Annotated[str, pydantic.Field(alias="topicName")] - r"""ID of the topic to send events to.""" + brokers: List[str] + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" + + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -6310,56 +6352,77 @@ class CreateOutputSystemByPackOutputGooglePubsub(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None - r"""If enabled, create topic if it does not exist.""" + ack: Optional[AcknowledgmentsOptionsAllLeader] = None + r"""Control the number of required acknowledgments.""" - ordered_delivery: Annotated[ - Optional[bool], pydantic.Field(alias="orderedDelivery") + format_: Annotated[ + Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") ] = None - r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" + r"""Format to use to serialize events before writing to Kafka.""" - region: Optional[str] = None - r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + compression: Optional[CompressionOptionsGzipLz4] = None + r"""Codec to use to compress the data before sending to Kafka""" - google_auth_method: Annotated[ - Optional[GoogleAuthenticationMethodOptions], - pydantic.Field(alias="googleAuthMethod"), + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" - secret: Optional[str] = None - r"""Select or create a stored text secret""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None - r"""The maximum number of items the Google API should batch before it sends them to the topic.""" + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], + pydantic.Field(alias="kafkaSchemaRegistry"), + ] = None + r"""Kafka Schema Registry Authentication""" - batch_timeout: Annotated[Optional[float], pydantic.Field(alias="batchTimeout")] = ( - None - ) - r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""Maximum size (KB) of batches to send.""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -6369,6 +6432,16 @@ class CreateOutputSystemByPackOutputGooglePubsub(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + protobuf_library_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufLibraryId") + ] = None + r"""Select a set of Protobuf definitions for the events you want to send""" + + protobuf_encoding_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufEncodingId") + ] = None + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -6419,7 +6492,7 @@ class CreateOutputSystemByPackOutputGooglePubsub(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGooglePubsubPqControls], + Optional[CreateOutputSystemByPackOutputKafkaPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -6429,26 +6502,49 @@ class CreateOutputSystemByPackOutputGooglePubsub(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicName") + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") ] = None - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_compression: Annotated[ + Optional[str], pydantic.Field(alias="__template_compression") + ] = None + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.GoogleAuthenticationMethodOptions(value) + return models.AcknowledgmentsOptionsAllLeader(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.RecordDataFormatOptionsJSONProtobuf(value) + except ValueError: + return value + return value + + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsGzipLz4(value) except ValueError: return value return value @@ -6497,20 +6593,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "createTopic", - "orderedDelivery", - "region", - "googleAuthMethod", - "serviceAccountCredentials", - "secret", - "batchSize", - "batchTimeout", - "maxQueueSize", + "ack", + "format", + "compression", "maxRecordSizeKB", - "flushPeriod", - "maxInProgress", + "flushEventCount", + "flushPeriodSec", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", "onBackpressure", "description", + "protobufLibraryId", + "protobufEncodingId", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -6524,8 +6627,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topicName", - "__template_region", + "__template_topic", + "__template_format", + "__template_compression", "__template_onBackpressure", ] ) @@ -6543,66 +6647,40 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGoogleCloudObservabilityType(str, Enum): +class CreateOutputSystemByPackOutputExabeamType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CLOUD_OBSERVABILITY = "google_cloud_observability" - - -class CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Discriminator value.""" - - GRPC = "grpc" - - -class CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Discriminator value.""" - - ONE_DOT_3_DOT_1 = "1.3.1" - - -class CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - - TELEMETRY_GOOGLEAPIS_COM_443 = "telemetry.googleapis.com:443" + EXABEAM = "exabeam" -class CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod( +class CreateOutputSystemByPackOutputExabeamAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + r"""Authentication method""" - # Auto - AUTO = "auto" + # Manual + MANUAL = "manual" # Secret SECRET = "secret" -class CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict( - TypedDict -): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict(TypedDict): +class CreateOutputSystemByPackOutputExabeamTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleCloudObservabilityType + type: CreateOutputSystemByPackOutputExabeamType r"""Connector type identifier.""" - google_auth_method: ( - CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod - ) - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + bucket: str + r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" + region: str + r"""Region where the bucket is located""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Google Cloud Storage service endpoint""" + collector_instance_id: str + r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + + """ pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -6611,98 +6689,108 @@ class CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict(TypedDict) r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[ - CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol - ] - r"""Discriminator value.""" - otlp_version: NotRequired[ - CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion - ] - r"""Discriminator value.""" - endpoint: NotRequired[ - CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint - ] - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] - r"""TLS settings (client side)""" - max_payload_events: NotRequired[float] - r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsArchiveColdline] + r"""Storage class to select for uploaded objects""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + encoded_configuration: NotRequired[str] + r"""Enter an encoded string containing Exabeam configurations""" + aws_authentication_method: NotRequired[ + CreateOutputSystemByPackOutputExabeamAuthenticationMethod + ] + r"""Authentication method""" + site_name: NotRequired[str] + r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" + site_id: NotRequired[str] + r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" + timezone_offset: NotRequired[str] + r"""Timezone offset""" + hostname: NotRequired[str] + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" + forwarder: NotRequired[str] + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" + origin: NotRequired[str] + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" + logtags: NotRequired[str] + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" + aws_api_key: NotRequired[str] + r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + aws_secret_key: NotRequired[str] + r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" description: NotRequired[str] r"""Optional description for this configuration.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict - ] - r"""Persistent queue controls.""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputGoogleCloudObservability(BaseModel): +class CreateOutputSystemByPackOutputExabeam(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleCloudObservabilityType + type: CreateOutputSystemByPackOutputExabeamType r"""Connector type identifier.""" - google_auth_method: Annotated[ - CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod, - pydantic.Field(alias="googleAuthMethod"), - ] - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + bucket: str + r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" + + region: str + r"""Region where the bucket is located""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + endpoint: str + r"""Google Cloud Storage service endpoint""" + + collector_instance_id: Annotated[str, pydantic.Field(alias="collectorInstanceId")] + r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + + """ pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -6718,215 +6806,196 @@ class CreateOutputSystemByPackOutputGoogleCloudObservability(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[ - CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol + object_acl: Annotated[ + Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], + pydantic.Field(alias="objectACL"), ] = None - r"""Discriminator value.""" + r"""Object ACL to assign to uploaded objects""" - otlp_version: Annotated[ - Optional[CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion], - pydantic.Field(alias="otlpVersion"), + storage_class: Annotated[ + Optional[StorageClassOptionsArchiveColdline], + pydantic.Field(alias="storageClass"), ] = None - r"""Discriminator value.""" + r"""Storage class to select for uploaded objects""" - endpoint: Optional[ - CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + r"""Reuse connections between requests, which can improve performance""" - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + r"""Add the Output ID value to staging location""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + r"""Remove empty staging directories after moving files""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""How to handle events when all receivers are exerting backpressure""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often the sender should ping the peer to keep the connection open""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - tls: Optional[TLSSettingsClientSideTypeExtended] = None - r"""TLS settings (client side)""" + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + encoded_configuration: Annotated[ + Optional[str], pydantic.Field(alias="encodedConfiguration") ] = None - r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" + r"""Enter an encoded string containing Exabeam configurations""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + aws_authentication_method: Annotated[ + Optional[CreateOutputSystemByPackOutputExabeamAuthenticationMethod], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Authentication method""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + site_name: Annotated[Optional[str], pydantic.Field(alias="siteName")] = None + r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" - secret: Optional[str] = None - r"""Select or create a stored text secret""" + site_id: Annotated[Optional[str], pydantic.Field(alias="siteId")] = None + r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + timezone_offset: Annotated[ + Optional[str], pydantic.Field(alias="timezoneOffset") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Timezone offset""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + hostname: Optional[str] = None + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + forwarder: Optional[str] = None + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + origin: Optional[str] = None + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + logtags: Optional[str] = None + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""Codec to use to compress the persisted data""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol( + return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( value ) except ValueError: return value return value - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion( - value - ) - except ValueError: - return value - return value - - @field_serializer("endpoint") - def serialize_endpoint(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint( - value - ) - except ValueError: - return value - return value - - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) + return models.StorageClassOptionsArchiveColdline(value) except ValueError: return value return value @@ -6935,34 +7004,27 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.CreateOutputSystemByPackOutputExabeamAuthenticationMethod( + value + ) except ValueError: return value return value @@ -6975,40 +7037,43 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "otlpVersion", - "endpoint", - "preserveNativeAnyValue", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", - "concurrency", - "maxPayloadSizeKB", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "tls", - "maxPayloadEvents", + "objectACL", + "storageClass", + "reuseConnections", + "rejectUnauthorized", + "addIdToStagePath", + "removeEmptyDirs", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "retrySettings", + "orphans", + "maxFileSizeMB", + "encodedConfiguration", + "awsAuthenticationMethod", + "siteName", + "siteId", + "timezoneOffset", + "hostname", + "forwarder", + "origin", + "logtags", + "awsApiKey", + "awsSecretKey", "description", - "secret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", + "awsSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_region", + "__template_endpoint", + "__template_objectACL", + "__template_storageClass", "__template_onBackpressure", ] ) @@ -7026,53 +7091,21 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGoogleCloudLoggingType(str, Enum): - r"""Connector type identifier.""" - - GOOGLE_CLOUD_LOGGING = "google_cloud_logging" - - -class CreateOutputSystemByPackLogLocationType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Log location type""" - - # Project - PROJECT = "project" - # Organization - ORGANIZATION = "organization" - # Billing Account - BILLING_ACCOUNT = "billingAccount" - # Folder - FOLDER = "folder" - - -class CreateOutputSystemByPackPayloadFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format to use when sending payload. Defaults to Text.""" - - # Text - TEXT = "text" - # JSON - JSON = "json" - - -class CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls(BaseModel): +class CreateOutputSystemByPackOutputGooglePubsubPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGooglePubsubTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleCloudLoggingType + type: TypeOptionsGooglepubsub r"""Connector type identifier.""" - log_location_type: CreateOutputSystemByPackLogLocationType - r"""Log location type""" - log_name_expression: str - r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" - log_location_expression: str - r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + topic_name: str + r"""ID of the topic to send events to.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -7081,106 +7114,34 @@ class CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - sanitize_log_names: NotRequired[bool] - r"""Validate and correct log name""" - payload_format: NotRequired[CreateOutputSystemByPackPayloadFormat] - r"""Format to use when sending payload. Defaults to Text.""" - log_labels: NotRequired[List[LogLabelConfOutputGoogleCloudLoggingTypedDict]] - r"""Labels to apply to the log entry""" - resource_type_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - resource_type_labels: NotRequired[ - List[LogLabelConfOutputGoogleCloudLoggingTypedDict] - ] - r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" - severity_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" - insert_id_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the insert ID field.""" + create_topic: NotRequired[bool] + r"""If enabled, create topic if it does not exist.""" + ordered_delivery: NotRequired[bool] + r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" + region: NotRequired[str] + r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" service_account_credentials: NotRequired[str] r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" secret: NotRequired[str] r"""Select or create a stored text secret""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body.""" - max_payload_events: NotRequired[float] - r"""Max number of events to include in the request body. Default is 0 (unlimited).""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" - throttle_rate_req_per_sec: NotRequired[int] - r"""Maximum number of requests to limit to per second.""" - request_method_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - request_url_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - request_size_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - status_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - response_size_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - user_agent_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - remote_ip_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - server_ip_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - referer_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - latency_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_lookup_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_hit_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_validated_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_fill_bytes_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - protocol_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - id_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - producer_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - first_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - last_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - file_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - line_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - function_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - uid_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - index_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - total_splits_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - trace_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - span_id_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - trace_sampled_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - payload_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" + batch_size: NotRequired[float] + r"""The maximum number of items the Google API should batch before it sends them to the topic.""" + batch_timeout: NotRequired[float] + r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of batches to send.""" + flush_period: NotRequired[float] + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -7204,56 +7165,28 @@ class CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict + CreateOutputSystemByPackOutputGooglePubsubPqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_location_type: NotRequired[str] - r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" - template_log_name_expression: NotRequired[str] - r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" - template_payload_format: NotRequired[str] - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - template_resource_type_expression: NotRequired[str] - r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" - template_severity_expression: NotRequired[str] - r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" - template_insert_id_expression: NotRequired[str] - r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" - template_trace_expression: NotRequired[str] - r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" - template_span_id_expression: NotRequired[str] - r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" - template_trace_sampled_expression: NotRequired[str] - r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" + template_topic_name: NotRequired[str] + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_log_location_expression: NotRequired[str] - r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - template_payload_expression: NotRequired[str] - r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" -class CreateOutputSystemByPackOutputGoogleCloudLogging(BaseModel): +class CreateOutputSystemByPackOutputGooglePubsub(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleCloudLoggingType + type: TypeOptionsGooglepubsub r"""Connector type identifier.""" - log_location_type: Annotated[ - CreateOutputSystemByPackLogLocationType, pydantic.Field(alias="logLocationType") - ] - r"""Log location type""" - - log_name_expression: Annotated[str, pydantic.Field(alias="logNameExpression")] - r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" - - log_location_expression: Annotated[ - str, pydantic.Field(alias="logLocationExpression") - ] - r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + topic_name: Annotated[str, pydantic.Field(alias="topicName")] + r"""ID of the topic to send events to.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -7269,43 +7202,16 @@ class CreateOutputSystemByPackOutputGoogleCloudLogging(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - sanitize_log_names: Annotated[ - Optional[bool], pydantic.Field(alias="sanitizeLogNames") - ] = None - r"""Validate and correct log name""" - - payload_format: Annotated[ - Optional[CreateOutputSystemByPackPayloadFormat], - pydantic.Field(alias="payloadFormat"), - ] = None - r"""Format to use when sending payload. Defaults to Text.""" - - log_labels: Annotated[ - Optional[List[LogLabelConfOutputGoogleCloudLogging]], - pydantic.Field(alias="logLabels"), - ] = None - r"""Labels to apply to the log entry""" - - resource_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="resourceTypeExpression") - ] = None - r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - - resource_type_labels: Annotated[ - Optional[List[LogLabelConfOutputGoogleCloudLogging]], - pydantic.Field(alias="resourceTypeLabels"), - ] = None - r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" + create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None + r"""If enabled, create topic if it does not exist.""" - severity_expression: Annotated[ - Optional[str], pydantic.Field(alias="severityExpression") + ordered_delivery: Annotated[ + Optional[bool], pydantic.Field(alias="orderedDelivery") ] = None - r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" + r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" - insert_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="insertIdExpression") - ] = None - r"""JavaScript expression to compute the value of the insert ID field.""" + region: Optional[str] = None + r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" google_auth_method: Annotated[ Optional[GoogleAuthenticationMethodOptions], @@ -7321,331 +7227,115 @@ class CreateOutputSystemByPackOutputGoogleCloudLogging(BaseModel): secret: Optional[str] = None r"""Select or create a stored text secret""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body.""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Max number of events to include in the request body. Default is 0 (unlimited).""" + batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None + r"""The maximum number of items the Google API should batch before it sends them to the topic.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + batch_timeout: Annotated[Optional[float], pydantic.Field(alias="batchTimeout")] = ( + None + ) + r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking.""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking.""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Maximum size (KB) of batches to send.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" + flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - throttle_rate_req_per_sec: Annotated[ - Optional[int], pydantic.Field(alias="throttleRateReqPerSec") + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") ] = None - r"""Maximum number of requests to limit to per second.""" + r"""The maximum number of in-progress API requests before backpressure is applied.""" - request_method_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestMethodExpression") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""How to handle events when all receivers are exerting backpressure""" - request_url_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestUrlExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - request_size_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestSizeExpression") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - status_expression: Annotated[ - Optional[str], pydantic.Field(alias="statusExpression") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - response_size_expression: Annotated[ - Optional[str], pydantic.Field(alias="responseSizeExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - user_agent_expression: Annotated[ - Optional[str], pydantic.Field(alias="userAgentExpression") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - remote_ip_expression: Annotated[ - Optional[str], pydantic.Field(alias="remoteIpExpression") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - server_ip_expression: Annotated[ - Optional[str], pydantic.Field(alias="serverIpExpression") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - referer_expression: Annotated[ - Optional[str], pydantic.Field(alias="refererExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - latency_expression: Annotated[ - Optional[str], pydantic.Field(alias="latencyExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - cache_lookup_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheLookupExpression") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Codec to use to compress the persisted data""" - cache_hit_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheHitExpression") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - cache_validated_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheValidatedExpression") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - cache_fill_bytes_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheFillBytesExpression") + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputGooglePubsubPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + r"""Persistent queue controls.""" - protocol_expression: Annotated[ - Optional[str], pydantic.Field(alias="protocolExpression") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - id_expression: Annotated[Optional[str], pydantic.Field(alias="idExpression")] = None - r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - producer_expression: Annotated[ - Optional[str], pydantic.Field(alias="producerExpression") + template_topic_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicName") ] = None - r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - first_expression: Annotated[ - Optional[str], pydantic.Field(alias="firstExpression") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - last_expression: Annotated[ - Optional[str], pydantic.Field(alias="lastExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - - file_expression: Annotated[ - Optional[str], pydantic.Field(alias="fileExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - line_expression: Annotated[ - Optional[str], pydantic.Field(alias="lineExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - function_expression: Annotated[ - Optional[str], pydantic.Field(alias="functionExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - uid_expression: Annotated[Optional[str], pydantic.Field(alias="uidExpression")] = ( - None - ) - r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - index_expression: Annotated[ - Optional[str], pydantic.Field(alias="indexExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - total_splits_expression: Annotated[ - Optional[str], pydantic.Field(alias="totalSplitsExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - trace_expression: Annotated[ - Optional[str], pydantic.Field(alias="traceExpression") - ] = None - r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - - span_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="spanIdExpression") - ] = None - r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - - trace_sampled_expression: Annotated[ - Optional[str], pydantic.Field(alias="traceSampledExpression") - ] = None - r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="payloadExpression") - ] = None - r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_log_location_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLocationType") - ] = None - r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" - - template_log_name_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_logNameExpression") - ] = None - r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" - - template_payload_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadFormat") - ] = None - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - - template_resource_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_resourceTypeExpression") - ] = None - r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" - - template_severity_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_severityExpression") - ] = None - r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" - - template_insert_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_insertIdExpression") - ] = None - r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" - - template_trace_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_traceExpression") - ] = None - r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" - - template_span_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_spanIdExpression") - ] = None - r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" - - template_trace_sampled_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_traceSampledExpression") - ] = None - r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_log_location_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLocationExpression") - ] = None - r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - - template_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadExpression") - ] = None - r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" - - @field_serializer("log_location_type") - def serialize_log_location_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackLogLocationType(value) - except ValueError: - return value - return value - - @field_serializer("payload_format") - def serialize_payload_format(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackPayloadFormat(value) - except ValueError: - return value - return value - @field_serializer("google_auth_method") def serialize_google_auth_method(self, value): if isinstance(value, str): @@ -7699,55 +7389,20 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "sanitizeLogNames", - "payloadFormat", - "logLabels", - "resourceTypeExpression", - "resourceTypeLabels", - "severityExpression", - "insertIdExpression", + "createTopic", + "orderedDelivery", + "region", "googleAuthMethod", "serviceAccountCredentials", "secret", - "maxPayloadSizeKB", - "maxPayloadEvents", - "flushPeriodSec", - "concurrency", - "connectionTimeout", - "timeoutSec", - "throttleRateReqPerSec", - "requestMethodExpression", - "requestUrlExpression", - "requestSizeExpression", - "statusExpression", - "responseSizeExpression", - "userAgentExpression", - "remoteIpExpression", - "serverIpExpression", - "refererExpression", - "latencyExpression", - "cacheLookupExpression", - "cacheHitExpression", - "cacheValidatedExpression", - "cacheFillBytesExpression", - "protocolExpression", - "idExpression", - "producerExpression", - "firstExpression", - "lastExpression", - "fileExpression", - "lineExpression", - "functionExpression", - "uidExpression", - "indexExpression", - "totalSplitsExpression", - "traceExpression", - "spanIdExpression", - "traceSampledExpression", + "batchSize", + "batchTimeout", + "maxQueueSize", + "maxRecordSizeKB", + "flushPeriod", + "maxInProgress", "onBackpressure", - "totalMemoryLimitKB", "description", - "payloadExpression", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -7761,18 +7416,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_logLocationType", - "__template_logNameExpression", - "__template_payloadFormat", - "__template_resourceTypeExpression", - "__template_severityExpression", - "__template_insertIdExpression", - "__template_traceExpression", - "__template_spanIdExpression", - "__template_traceSampledExpression", + "__template_topicName", + "__template_region", "__template_onBackpressure", - "__template_logLocationExpression", - "__template_payloadExpression", ] ) serialized = handler(self) @@ -7789,38 +7435,66 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGoogleCloudStorageType(str, Enum): +class CreateOutputSystemByPackOutputGoogleCloudObservabilityType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CLOUD_STORAGE = "google_cloud_storage" + GOOGLE_CLOUD_OBSERVABILITY = "google_cloud_observability" -class CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod( +class CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Authentication method""" + r"""Discriminator value.""" - # auto + GRPC = "grpc" + + +class CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Discriminator value.""" + + ONE_DOT_3_DOT_1 = "1.3.1" + + +class CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + + TELEMETRY_GOOGLEAPIS_COM_443 = "telemetry.googleapis.com:443" + + +class CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + + # Auto AUTO = "auto" - # manual - MANUAL = "manual" - # Secret Key pair + # Secret SECRET = "secret" -class CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict( + TypedDict +): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleCloudStorageType + type: CreateOutputSystemByPackOutputGoogleCloudObservabilityType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - region: str - r"""Region where the bucket is located""" - endpoint: str - r"""Google Cloud Storage service endpoint""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + google_auth_method: ( + CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod + ) + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -7829,151 +7503,98 @@ class CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[ - CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod + protocol: NotRequired[ + CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol ] - r"""Authentication method""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsArchiveColdline] - r"""Storage class to select for uploaded objects""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + r"""Discriminator value.""" + otlp_version: NotRequired[ + CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion + ] + r"""Discriminator value.""" + endpoint: NotRequired[ + CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint + ] + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" + max_payload_events: NotRequired[float] + r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - aws_api_key: NotRequired[str] - r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - aws_secret_key: NotRequired[str] - r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControlsTypedDict + ] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" -class CreateOutputSystemByPackOutputGoogleCloudStorage(BaseModel): +class CreateOutputSystemByPackOutputGoogleCloudObservability(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleCloudStorageType + type: CreateOutputSystemByPackOutputGoogleCloudObservabilityType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - - region: str - r"""Region where the bucket is located""" - - endpoint: str - r"""Google Cloud Storage service endpoint""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + google_auth_method: Annotated[ + CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod, + pydantic.Field(alias="googleAuthMethod"), + ] + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -7989,397 +7610,251 @@ class CreateOutputSystemByPackOutputGoogleCloudStorage(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""Authentication method""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") + protocol: Optional[ + CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + r"""Discriminator value.""" - object_acl: Annotated[ - Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], - pydantic.Field(alias="objectACL"), + otlp_version: Annotated[ + Optional[CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion], + pydantic.Field(alias="otlpVersion"), ] = None - r"""Object ACL to assign to uploaded objects""" + r"""Discriminator value.""" - storage_class: Annotated[ - Optional[StorageClassOptionsArchiveColdline], - pydantic.Field(alias="storageClass"), + endpoint: Optional[ + CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint ] = None - r"""Storage class to select for uploaded objects""" + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""Add the Output ID value to staging location""" + r"""Batch event data upon dynamic metadata (whether presented or not)""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Buffer size used to write to a file""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""How often the sender should ping the peer to keep the connection open""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Determines which data types are supported and how they are represented""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + r"""Codec to use to compress the persisted data""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputGoogleCloudObservabilityPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + r"""Persistent queue controls.""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""How frequently, in seconds, to clean up empty directories""" - - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod( + return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityProtocol( value ) except ValueError: return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( + return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityOtlpVersion( value ) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptionsArchiveColdline(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("endpoint") + def serialize_endpoint(self, value): if isinstance(value, str): try: - return models.DataFormatOptions(value) + return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityEndpoint( + value + ) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.CreateOutputSystemByPackOutputGoogleCloudObservabilityGoogleAuthenticationMethod( + value + ) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -8392,68 +7867,41 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "destPath", - "verifyPermissions", - "objectACL", - "storageClass", - "reuseConnections", - "rejectUnauthorized", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", + "protocol", + "otlpVersion", + "endpoint", + "preserveNativeAnyValue", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", + "concurrency", + "maxPayloadSizeKB", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "tls", + "maxPayloadEvents", "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "awsApiKey", - "awsSecretKey", - "awsSecret", + "secret", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_bucket", - "__template_region", - "__template_endpoint", - "__template_destPath", - "__template_objectACL", - "__template_storageClass", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", - "__template_awsApiKey", - "__template_awsSecretKey", ] ) serialized = handler(self) @@ -8470,98 +7918,53 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGoogleChronicleType(str, Enum): +class CreateOutputSystemByPackOutputGoogleCloudLoggingType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CHRONICLE = "google_chronicle" - - -class CreateOutputSystemByPackAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""API version""" - - # V1 - V1 = "v1" - # V2 - V2 = "v2" - - -class CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method""" - - # API key - MANUAL = "manual" - # API key secret - SECRET = "secret" - # Service account credentials - SERVICE_ACCOUNT = "serviceAccount" - # Service account credentials secret - SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" - - -class CreateOutputSystemByPackSendEventsAs(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Send events as""" - - # Unstructured - UNSTRUCTURED = "unstructured" - # UDM - UDM = "udm" - - -class CreateOutputSystemByPackExtraLogTypeTypedDict(TypedDict): - log_type: str - r"""Log Type""" - description: NotRequired[str] - r"""Description""" - - -class CreateOutputSystemByPackExtraLogType(BaseModel): - log_type: Annotated[str, pydantic.Field(alias="logType")] - r"""Log Type""" - - description: Optional[str] = None - r"""Description""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} + GOOGLE_CLOUD_LOGGING = "google_cloud_logging" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateOutputSystemByPackLogLocationType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Log location type""" - return m + # Project + PROJECT = "project" + # Organization + ORGANIZATION = "organization" + # Billing Account + BILLING_ACCOUNT = "billingAccount" + # Folder + FOLDER = "folder" -class CreateOutputSystemByPackUDMType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" +class CreateOutputSystemByPackPayloadFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format to use when sending payload. Defaults to Text.""" - ENTITIES = "entities" - LOGS = "logs" + # Text + TEXT = "text" + # JSON + JSON = "json" -class CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGoogleChroniclePqControls(BaseModel): +class CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputGoogleChronicleTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleChronicleType + type: CreateOutputSystemByPackOutputGoogleCloudLoggingType r"""Connector type identifier.""" - log_format_type: CreateOutputSystemByPackSendEventsAs - r"""Send events as""" + log_location_type: CreateOutputSystemByPackLogLocationType + r"""Log location type""" + log_name_expression: str + r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + log_location_expression: str + r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -8570,76 +7973,106 @@ class CreateOutputSystemByPackOutputGoogleChronicleTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - api_version: NotRequired[CreateOutputSystemByPackAPIVersion] - r"""API version""" - authentication_method: NotRequired[ - CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod - ] - r"""Authentication method""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] + sanitize_log_names: NotRequired[bool] + r"""Validate and correct log name""" + payload_format: NotRequired[CreateOutputSystemByPackPayloadFormat] + r"""Format to use when sending payload. Defaults to Text.""" + log_labels: NotRequired[List[LogLabelConfOutputGoogleCloudLoggingTypedDict]] + r"""Labels to apply to the log entry""" + resource_type_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" + resource_type_labels: NotRequired[ + List[LogLabelConfOutputGoogleCloudLoggingTypedDict] ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - region: NotRequired[str] - r"""Regional endpoint to send events to""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" + severity_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" + insert_id_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the insert ID field.""" + google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Max number of events to include in the request body. Default is 0 (unlimited).""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" + throttle_rate_req_per_sec: NotRequired[int] + r"""Maximum number of requests to limit to per second.""" + request_method_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + request_url_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + request_size_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + status_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + response_size_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + user_agent_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + remote_ip_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + server_ip_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + referer_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + latency_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_lookup_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_hit_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_validated_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_fill_bytes_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + protocol_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + id_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + producer_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + first_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + last_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + file_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + line_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + function_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + uid_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + index_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + total_splits_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + trace_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + span_id_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + trace_sampled_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" total_memory_limit_kb: NotRequired[float] r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - extra_log_types: NotRequired[List[CreateOutputSystemByPackExtraLogTypeTypedDict]] - r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" - log_type: NotRequired[str] - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" - log_text_field: NotRequired[str] - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" - customer_id: NotRequired[str] - r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" - namespace: NotRequired[str] - r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" - custom_labels: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""Custom labels to be added to every batch""" - udm_type: NotRequired[CreateOutputSystemByPackUDMType] - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" - api_key: NotRequired[str] - r"""Organization's API key in Google SecOps""" - api_key_secret: NotRequired[str] - r"""Select or create a stored text secret""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - service_account_credentials_secret: NotRequired[str] - r"""Select or create a stored text secret""" + payload_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -8663,34 +8096,56 @@ class CreateOutputSystemByPackOutputGoogleChronicleTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict + CreateOutputSystemByPackOutputGoogleCloudLoggingPqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_api_version: NotRequired[str] - r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_log_location_type: NotRequired[str] + r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" + template_log_name_expression: NotRequired[str] + r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" + template_payload_format: NotRequired[str] + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + template_resource_type_expression: NotRequired[str] + r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" + template_severity_expression: NotRequired[str] + r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" + template_insert_id_expression: NotRequired[str] + r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" + template_trace_expression: NotRequired[str] + r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" + template_span_id_expression: NotRequired[str] + r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" + template_trace_sampled_expression: NotRequired[str] + r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_customer_id: NotRequired[str] - r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + template_log_location_expression: NotRequired[str] + r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" + template_payload_expression: NotRequired[str] + r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" -class CreateOutputSystemByPackOutputGoogleChronicle(BaseModel): +class CreateOutputSystemByPackOutputGoogleCloudLogging(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleChronicleType + type: CreateOutputSystemByPackOutputGoogleCloudLoggingType r"""Connector type identifier.""" - log_format_type: Annotated[ - CreateOutputSystemByPackSendEventsAs, pydantic.Field(alias="logFormatType") + log_location_type: Annotated[ + CreateOutputSystemByPackLogLocationType, pydantic.Field(alias="logLocationType") ] - r"""Send events as""" + r"""Log location type""" + + log_name_expression: Annotated[str, pydantic.Field(alias="logNameExpression")] + r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + + log_location_expression: Annotated[ + str, pydantic.Field(alias="logLocationExpression") + ] + r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -8706,155 +8161,244 @@ class CreateOutputSystemByPackOutputGoogleChronicle(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - api_version: Annotated[ - Optional[CreateOutputSystemByPackAPIVersion], pydantic.Field(alias="apiVersion") + sanitize_log_names: Annotated[ + Optional[bool], pydantic.Field(alias="sanitizeLogNames") ] = None - r"""API version""" + r"""Validate and correct log name""" - authentication_method: Annotated[ - Optional[CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod], - pydantic.Field(alias="authenticationMethod"), + payload_format: Annotated[ + Optional[CreateOutputSystemByPackPayloadFormat], + pydantic.Field(alias="payloadFormat"), ] = None - r"""Authentication method""" + r"""Format to use when sending payload. Defaults to Text.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + log_labels: Annotated[ + Optional[List[LogLabelConfOutputGoogleCloudLogging]], + pydantic.Field(alias="logLabels"), ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Labels to apply to the log entry""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + resource_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="resourceTypeExpression") ] = None + r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + resource_type_labels: Annotated[ + Optional[List[LogLabelConfOutputGoogleCloudLogging]], + pydantic.Field(alias="resourceTypeLabels"), ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" - region: Optional[str] = None - r"""Regional endpoint to send events to""" + severity_expression: Annotated[ + Optional[str], pydantic.Field(alias="severityExpression") + ] = None + r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + insert_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="insertIdExpression") + ] = None + r"""JavaScript expression to compute the value of the insert ID field.""" + + google_auth_method: Annotated[ + Optional[GoogleAuthenticationMethodOptions], + pydantic.Field(alias="googleAuthMethod"), + ] = None + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + secret: Optional[str] = None + r"""Select or create a stored text secret""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Max number of events to include in the request body. Default is 0 (unlimited).""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + throttle_rate_req_per_sec: Annotated[ + Optional[int], pydantic.Field(alias="throttleRateReqPerSec") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of requests to limit to per second.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + request_method_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestMethodExpression") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + request_url_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestUrlExpression") ] = None - r"""Headers to add to all events""" + r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + request_size_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestSizeExpression") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + status_expression: Annotated[ + Optional[str], pydantic.Field(alias="statusExpression") ] = None - r"""List of headers that are safe to log in plain text""" + r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + response_size_expression: Annotated[ + Optional[str], pydantic.Field(alias="responseSizeExpression") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" + r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + user_agent_expression: Annotated[ + Optional[str], pydantic.Field(alias="userAgentExpression") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + remote_ip_expression: Annotated[ + Optional[str], pydantic.Field(alias="remoteIpExpression") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + server_ip_expression: Annotated[ + Optional[str], pydantic.Field(alias="serverIpExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - extra_log_types: Annotated[ - Optional[List[CreateOutputSystemByPackExtraLogType]], - pydantic.Field(alias="extraLogTypes"), + referer_expression: Annotated[ + Optional[str], pydantic.Field(alias="refererExpression") ] = None - r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + latency_expression: Annotated[ + Optional[str], pydantic.Field(alias="latencyExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( - None - ) - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + cache_lookup_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheLookupExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - customer_id: Annotated[Optional[str], pydantic.Field(alias="customerId")] = None - r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + cache_hit_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheHitExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - namespace: Optional[str] = None - r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + cache_validated_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheValidatedExpression") + ] = None + r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - custom_labels: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="customLabels"), + cache_fill_bytes_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheFillBytesExpression") ] = None - r"""Custom labels to be added to every batch""" + r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - udm_type: Annotated[ - Optional[CreateOutputSystemByPackUDMType], pydantic.Field(alias="udmType") + protocol_expression: Annotated[ + Optional[str], pydantic.Field(alias="protocolExpression") ] = None - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""Organization's API key in Google SecOps""" + id_expression: Annotated[Optional[str], pydantic.Field(alias="idExpression")] = None + r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - api_key_secret: Annotated[Optional[str], pydantic.Field(alias="apiKeySecret")] = ( - None - ) - r"""Select or create a stored text secret""" + producer_expression: Annotated[ + Optional[str], pydantic.Field(alias="producerExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + first_expression: Annotated[ + Optional[str], pydantic.Field(alias="firstExpression") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - service_account_credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") + last_expression: Annotated[ + Optional[str], pydantic.Field(alias="lastExpression") ] = None - r"""Select or create a stored text secret""" + r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + + file_expression: Annotated[ + Optional[str], pydantic.Field(alias="fileExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + + line_expression: Annotated[ + Optional[str], pydantic.Field(alias="lineExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + + function_expression: Annotated[ + Optional[str], pydantic.Field(alias="functionExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + + uid_expression: Annotated[Optional[str], pydantic.Field(alias="uidExpression")] = ( + None + ) + r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + + index_expression: Annotated[ + Optional[str], pydantic.Field(alias="indexExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + + total_splits_expression: Annotated[ + Optional[str], pydantic.Field(alias="totalSplitsExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + + trace_expression: Annotated[ + Optional[str], pydantic.Field(alias="traceExpression") + ] = None + r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + + span_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="spanIdExpression") + ] = None + r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + + trace_sampled_expression: Annotated[ + Optional[str], pydantic.Field(alias="traceSampledExpression") + ] = None + r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="payloadExpression") + ] = None + r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -8906,7 +8450,7 @@ class CreateOutputSystemByPackOutputGoogleChronicle(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGoogleChroniclePqControls], + Optional[CreateOutputSystemByPackOutputGoogleCloudLoggingPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -8916,65 +8460,89 @@ class CreateOutputSystemByPackOutputGoogleChronicle(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_api_version: Annotated[ - Optional[str], pydantic.Field(alias="__template_apiVersion") + template_log_location_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLocationType") ] = None - r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" + r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_log_name_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_logNameExpression") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_payload_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadFormat") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + + template_resource_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_resourceTypeExpression") + ] = None + r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" + + template_severity_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_severityExpression") + ] = None + r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" + + template_insert_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_insertIdExpression") + ] = None + r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" + + template_trace_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_traceExpression") + ] = None + r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" + + template_span_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_spanIdExpression") + ] = None + r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" + + template_trace_sampled_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_traceSampledExpression") + ] = None + r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_customer_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_customerId") + template_log_location_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLocationExpression") ] = None - r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - @field_serializer("api_version") - def serialize_api_version(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackAPIVersion(value) - except ValueError: - return value - return value + template_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadExpression") + ] = None + r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" - @field_serializer("authentication_method") - def serialize_authentication_method(self, value): + @field_serializer("log_location_type") + def serialize_log_location_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod( - value - ) + return models.CreateOutputSystemByPackLogLocationType(value) except ValueError: return value return value - @field_serializer("log_format_type") - def serialize_log_format_type(self, value): + @field_serializer("payload_format") + def serialize_payload_format(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackSendEventsAs(value) + return models.CreateOutputSystemByPackPayloadFormat(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.GoogleAuthenticationMethodOptions(value) except ValueError: return value return value @@ -8988,15 +8556,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("udm_type") - def serialize_udm_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackUDMType(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -9032,38 +8591,55 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "apiVersion", - "authenticationMethod", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "region", - "concurrency", + "sanitizeLogNames", + "payloadFormat", + "logLabels", + "resourceTypeExpression", + "resourceTypeLabels", + "severityExpression", + "insertIdExpression", + "googleAuthMethod", + "serviceAccountCredentials", + "secret", "maxPayloadSizeKB", "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "useRoundRobinDns", + "concurrency", + "connectionTimeout", + "timeoutSec", + "throttleRateReqPerSec", + "requestMethodExpression", + "requestUrlExpression", + "requestSizeExpression", + "statusExpression", + "responseSizeExpression", + "userAgentExpression", + "remoteIpExpression", + "serverIpExpression", + "refererExpression", + "latencyExpression", + "cacheLookupExpression", + "cacheHitExpression", + "cacheValidatedExpression", + "cacheFillBytesExpression", + "protocolExpression", + "idExpression", + "producerExpression", + "firstExpression", + "lastExpression", + "fileExpression", + "lineExpression", + "functionExpression", + "uidExpression", + "indexExpression", + "totalSplitsExpression", + "traceExpression", + "spanIdExpression", + "traceSampledExpression", "onBackpressure", "totalMemoryLimitKB", "description", - "extraLogTypes", - "logType", - "logTextField", - "customerId", - "namespace", - "customLabels", - "udmType", - "apiKey", - "apiKeySecret", - "serviceAccountCredentials", - "serviceAccountCredentialsSecret", + "payloadExpression", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9077,11 +8653,18 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_apiVersion", - "__template_region", - "__template_failedRequestLoggingMode", + "__template_logLocationType", + "__template_logNameExpression", + "__template_payloadFormat", + "__template_resourceTypeExpression", + "__template_severityExpression", + "__template_insertIdExpression", + "__template_traceExpression", + "__template_spanIdExpression", + "__template_traceSampledExpression", "__template_onBackpressure", - "__template_customerId", + "__template_logLocationExpression", + "__template_payloadExpression", ] ) serialized = handler(self) @@ -9098,46 +8681,38 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputGoogleBigqueryType(str, Enum): +class CreateOutputSystemByPackOutputGoogleCloudStorageType(str, Enum): r"""Connector type identifier.""" - GOOGLE_BIGQUERY = "google_bigquery" + GOOGLE_CLOUD_STORAGE = "google_cloud_storage" -class CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod( +class CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + r"""Authentication method""" - # Auto + # auto AUTO = "auto" - # Secret - SECRET = "secret" - - -class CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputGoogleBigqueryPqControls(BaseModel): - r"""Persistent queue controls.""" + # manual + MANUAL = "manual" + # Secret Key pair + SECRET = "secret" -class CreateOutputSystemByPackOutputGoogleBigqueryTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleBigqueryType + type: CreateOutputSystemByPackOutputGoogleCloudStorageType r"""Connector type identifier.""" - project_id: str - r"""Google Cloud project ID that contains the BigQuery dataset""" - dataset_id: str - r"""BigQuery dataset ID""" - table_id: str - r"""BigQuery table ID""" - google_auth_method: ( - CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod - ) - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + bucket: str + r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" + region: str + r"""Region where the bucket is located""" + endpoint: str + r"""Google Cloud Storage service endpoint""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9146,83 +8721,151 @@ class CreateOutputSystemByPackOutputGoogleBigqueryTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - timestamp_column: NotRequired[str] - r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - flush_period: NotRequired[float] - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied""" - max_send_retries: NotRequired[float] - r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + aws_authentication_method: NotRequired[ + CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod + ] + r"""Authentication method""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsArchiveColdline] + r"""Storage class to select for uploaded objects""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict - ] - r"""Persistent queue controls.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_api_key: NotRequired[str] + r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + aws_secret_key: NotRequired[str] + r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_project_id: NotRequired[str] - r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" - template_dataset_id: NotRequired[str] - r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" - template_table_id: NotRequired[str] - r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" -class CreateOutputSystemByPackOutputGoogleBigquery(BaseModel): +class CreateOutputSystemByPackOutputGoogleCloudStorage(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputGoogleBigqueryType + type: CreateOutputSystemByPackOutputGoogleCloudStorageType r"""Connector type identifier.""" - project_id: Annotated[str, pydantic.Field(alias="projectId")] - r"""Google Cloud project ID that contains the BigQuery dataset""" + bucket: str + r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - dataset_id: Annotated[str, pydantic.Field(alias="datasetId")] - r"""BigQuery dataset ID""" + region: str + r"""Region where the bucket is located""" - table_id: Annotated[str, pydantic.Field(alias="tableId")] - r"""BigQuery table ID""" + endpoint: str + r"""Google Cloud Storage service endpoint""" - google_auth_method: Annotated[ - CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod, - pydantic.Field(alias="googleAuthMethod"), - ] - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9238,168 +8881,397 @@ class CreateOutputSystemByPackOutputGoogleBigquery(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - timestamp_column: Annotated[ - Optional[str], pydantic.Field(alias="timestampColumn") + aws_authentication_method: Annotated[ + Optional[CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - - secret: Optional[str] = None - r"""Select or create a stored text secret""" - - flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + r"""Authentication method""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + object_acl: Annotated[ + Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], + pydantic.Field(alias="objectACL"), ] = None - r"""The maximum number of in-progress API requests before backpressure is applied""" + r"""Object ACL to assign to uploaded objects""" - max_send_retries: Annotated[ - Optional[float], pydantic.Field(alias="maxSendRetries") + storage_class: Annotated[ + Optional[StorageClassOptionsArchiveColdline], + pydantic.Field(alias="storageClass"), ] = None - r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" + r"""Storage class to select for uploaded objects""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + description: Optional[str] = None r"""Optional description for this configuration.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Compression level to apply before moving files to final destination""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Determines which data types are supported and how they are represented""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""Codec to use to compress the persisted data""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputGoogleBigqueryPqControls], - pydantic.Field(alias="pqControls"), + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Persistent queue controls.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" + + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") + ] = None + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_project_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_projectId") + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") ] = None - r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_dataset_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_datasetId") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_table_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tableId") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod( - value - ) - except ValueError: - return value - return value + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.CreateOutputSystemByPackOutputGoogleCloudStorageAuthenticationMethod( + value + ) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( + value + ) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.StorageClassOptionsArchiveColdline(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.DataFormatOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptionsBlockDrop(value) + except ValueError: + return value + return value + + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): + if isinstance(value, str): + try: + return models.DiskSpaceProtectionOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -9412,32 +9284,68 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "timestampColumn", - "secret", - "flushPeriod", - "maxQueueSize", - "maxRecordSizeKB", - "maxInProgress", - "maxSendRetries", + "awsAuthenticationMethod", + "destPath", + "verifyPermissions", + "objectACL", + "storageClass", + "reuseConnections", + "rejectUnauthorized", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", "description", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", + "awsApiKey", + "awsSecretKey", + "awsSecret", "__template_streamtags", - "__template_projectId", - "__template_datasetId", - "__template_tableId", + "__template_bucket", + "__template_region", + "__template_endpoint", + "__template_destPath", + "__template_objectACL", + "__template_storageClass", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_compress", + "__template_parquetSchema", + "__template_awsApiKey", + "__template_awsSecretKey", ] ) serialized = handler(self) @@ -9454,71 +9362,176 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputAzureEventhubType(str, Enum): +class CreateOutputSystemByPackOutputGoogleChronicleType(str, Enum): r"""Connector type identifier.""" - AZURE_EVENTHUB = "azure_eventhub" + GOOGLE_CHRONICLE = "google_chronicle" -class CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputSystemByPackAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""API version""" + # V1 + V1 = "v1" + # V2 + V2 = "v2" -class CreateOutputSystemByPackOutputAzureEventhubPqControls(BaseModel): - r"""Persistent queue controls.""" +class CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method""" -class CreateOutputSystemByPackOutputAzureEventhubTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAzureEventhubType - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - topic: str - r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - ack: NotRequired[AcknowledgmentsOptions] - r"""Control the number of required acknowledgments""" - format_: NotRequired[RecordDataFormatOptions] - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - flush_event_count: NotRequired[float] - r"""Maximum number of events in a batch before forcing a flush""" + # API key + MANUAL = "manual" + # API key secret + SECRET = "secret" + # Service account credentials + SERVICE_ACCOUNT = "serviceAccount" + # Service account credentials secret + SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" + + +class CreateOutputSystemByPackSendEventsAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Send events as""" + + # Unstructured + UNSTRUCTURED = "unstructured" + # UDM + UDM = "udm" + + +class CreateOutputSystemByPackExtraLogTypeTypedDict(TypedDict): + log_type: str + r"""Log Type""" + description: NotRequired[str] + r"""Description""" + + +class CreateOutputSystemByPackExtraLogType(BaseModel): + log_type: Annotated[str, pydantic.Field(alias="logType")] + r"""Log Type""" + + description: Optional[str] = None + r"""Description""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackUDMType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + + ENTITIES = "entities" + LOGS = "logs" + + +class CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputGoogleChroniclePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputGoogleChronicleTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputGoogleChronicleType + r"""Connector type identifier.""" + log_format_type: CreateOutputSystemByPackSendEventsAs + r"""Send events as""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + api_version: NotRequired[CreateOutputSystemByPackAPIVersion] + r"""API version""" + authentication_method: NotRequired[ + CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod + ] + r"""Authentication method""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + region: NotRequired[str] + r"""Regional endpoint to send events to""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeUseTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeTypedDict] - r"""TLS settings (client side)""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + extra_log_types: NotRequired[List[CreateOutputSystemByPackExtraLogTypeTypedDict]] + r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + log_type: NotRequired[str] + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + log_text_field: NotRequired[str] + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + customer_id: NotRequired[str] + r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + namespace: NotRequired[str] + r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + custom_labels: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""Custom labels to be added to every batch""" + udm_type: NotRequired[CreateOutputSystemByPackUDMType] + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + api_key: NotRequired[str] + r"""Organization's API key in Google SecOps""" + api_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + service_account_credentials_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9542,33 +9555,34 @@ class CreateOutputSystemByPackOutputAzureEventhubTypedDict(TypedDict): pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[ - CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict + CreateOutputSystemByPackOutputGoogleChroniclePqControlsTypedDict ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_api_version: NotRequired[str] + r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_customer_id: NotRequired[str] + r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" -class CreateOutputSystemByPackOutputAzureEventhub(BaseModel): +class CreateOutputSystemByPackOutputGoogleChronicle(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAzureEventhubType + type: CreateOutputSystemByPackOutputGoogleChronicleType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - - topic: str - r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" + log_format_type: Annotated[ + CreateOutputSystemByPackSendEventsAs, pydantic.Field(alias="logFormatType") + ] + r"""Send events as""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9584,77 +9598,156 @@ class CreateOutputSystemByPackOutputAzureEventhub(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - ack: Optional[AcknowledgmentsOptions] = None - r"""Control the number of required acknowledgments""" - - format_: Annotated[ - Optional[RecordDataFormatOptions], pydantic.Field(alias="format") + api_version: Annotated[ + Optional[CreateOutputSystemByPackAPIVersion], pydantic.Field(alias="apiVersion") ] = None - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" + r"""API version""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + authentication_method: Annotated[ + Optional[CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod], + pydantic.Field(alias="authenticationMethod"), ] = None - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" + r"""Authentication method""" - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Maximum number of events in a batch before forcing a flush""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" + region: Optional[str] = None + r"""Regional endpoint to send events to""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - sasl: Optional[AuthenticationTypeUse] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - tls: Optional[TLSSettingsClientSideType] = None - r"""TLS settings (client side)""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" + extra_log_types: Annotated[ + Optional[List[CreateOutputSystemByPackExtraLogType]], + pydantic.Field(alias="extraLogTypes"), + ] = None + r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + + log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + + log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( + None + ) + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + + customer_id: Annotated[Optional[str], pydantic.Field(alias="customerId")] = None + r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + + namespace: Optional[str] = None + r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + + custom_labels: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="customLabels"), + ] = None + r"""Custom labels to be added to every batch""" + + udm_type: Annotated[ + Optional[CreateOutputSystemByPackUDMType], pydantic.Field(alias="udmType") + ] = None + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""Organization's API key in Google SecOps""" + + api_key_secret: Annotated[Optional[str], pydantic.Field(alias="apiKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + service_account_credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") + ] = None + r"""Select or create a stored text secret""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -9705,7 +9798,7 @@ class CreateOutputSystemByPackOutputAzureEventhub(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputAzureEventhubPqControls], + Optional[CreateOutputSystemByPackOutputGoogleChroniclePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -9715,40 +9808,65 @@ class CreateOutputSystemByPackOutputAzureEventhub(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") + template_api_version: Annotated[ + Optional[str], pydantic.Field(alias="__template_apiVersion") ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("ack") - def serialize_ack(self, value): + template_customer_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_customerId") + ] = None + r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + + @field_serializer("api_version") + def serialize_api_version(self, value): if isinstance(value, str): try: - return models.AcknowledgmentsOptions(value) + return models.CreateOutputSystemByPackAPIVersion(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("authentication_method") + def serialize_authentication_method(self, value): if isinstance(value, str): try: - return models.RecordDataFormatOptions(value) + return models.CreateOutputSystemByPackOutputGoogleChronicleAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_format_type") + def serialize_log_format_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackSendEventsAs(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -9762,6 +9880,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("udm_type") + def serialize_udm_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackUDMType(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -9797,23 +9924,38 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "ack", - "format", - "maxRecordSizeKB", - "flushEventCount", + "apiVersion", + "authenticationMethod", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "region", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "tls", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "useRoundRobinDns", "onBackpressure", + "totalMemoryLimitKB", "description", + "extraLogTypes", + "logType", + "logTextField", + "customerId", + "namespace", + "customLabels", + "udmType", + "apiKey", + "apiKeySecret", + "serviceAccountCredentials", + "serviceAccountCredentialsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9827,10 +9969,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_brokers", - "__template_topic", - "__template_format", + "__template_apiVersion", + "__template_region", + "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_customerId", ] ) serialized = handler(self) @@ -9847,27 +9990,46 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputHoneycombType(str, Enum): +class CreateOutputSystemByPackOutputGoogleBigqueryType(str, Enum): r"""Connector type identifier.""" - HONEYCOMB = "honeycomb" + GOOGLE_BIGQUERY = "google_bigquery" -class CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + + # Auto + AUTO = "auto" + # Secret + SECRET = "secret" + + +class CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputHoneycombPqControls(BaseModel): +class CreateOutputSystemByPackOutputGoogleBigqueryPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputHoneycombTypedDict(TypedDict): +class CreateOutputSystemByPackOutputGoogleBigqueryTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputHoneycombType + type: CreateOutputSystemByPackOutputGoogleBigqueryType r"""Connector type identifier.""" - dataset: str - r"""Name of the dataset to send events to – e.g., observability""" + project_id: str + r"""Google Cloud project ID that contains the BigQuery dataset""" + dataset_id: str + r"""BigQuery dataset ID""" + table_id: str + r"""BigQuery table ID""" + google_auth_method: ( + CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod + ) + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -9876,44 +10038,22 @@ class CreateOutputSystemByPackOutputHoneycombTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + timestamp_column: NotRequired[str] + r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + flush_period: NotRequired[float] + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied""" + max_send_retries: NotRequired[float] + r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] @@ -9938,29 +10078,43 @@ class CreateOutputSystemByPackOutputHoneycombTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputGoogleBigqueryPqControlsTypedDict + ] r"""Persistent queue controls.""" - team: NotRequired[str] - r"""Team API key where the dataset belongs""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_project_id: NotRequired[str] + r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + template_dataset_id: NotRequired[str] + r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + template_table_id: NotRequired[str] + r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputHoneycomb(BaseModel): +class CreateOutputSystemByPackOutputGoogleBigquery(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputHoneycombType + type: CreateOutputSystemByPackOutputGoogleBigqueryType r"""Connector type identifier.""" - dataset: str - r"""Name of the dataset to send events to – e.g., observability""" + project_id: Annotated[str, pydantic.Field(alias="projectId")] + r"""Google Cloud project ID that contains the BigQuery dataset""" + + dataset_id: Annotated[str, pydantic.Field(alias="datasetId")] + r"""BigQuery dataset ID""" + + table_id: Annotated[str, pydantic.Field(alias="tableId")] + r"""BigQuery table ID""" + + google_auth_method: Annotated[ + CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod, + pydantic.Field(alias="googleAuthMethod"), + ] + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -9976,90 +10130,42 @@ class CreateOutputSystemByPackOutputHoneycomb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + timestamp_column: Annotated[ + Optional[str], pydantic.Field(alias="timestampColumn") ] = None - r"""Headers to add to all events""" + r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") ] = None + r"""The maximum number of in-progress API requests before backpressure is applied""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_send_retries: Annotated[ + Optional[float], pydantic.Field(alias="maxSendRetries") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -10113,37 +10219,43 @@ class CreateOutputSystemByPackOutputHoneycomb(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputHoneycombPqControls], + Optional[CreateOutputSystemByPackOutputGoogleBigqueryPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - team: Optional[str] = None - r"""Team API key where the dataset belongs""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_project_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_projectId") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + + template_dataset_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_datasetId") + ] = None + r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + + template_table_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tableId") + ] = None + r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CreateOutputSystemByPackOutputGoogleBigqueryGoogleAuthenticationMethod( + value + ) except ValueError: return value return value @@ -10157,15 +10269,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -10201,23 +10304,14 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "timestampColumn", + "secret", + "flushPeriod", + "maxQueueSize", + "maxRecordSizeKB", + "maxInProgress", + "maxSendRetries", "onBackpressure", - "authType", "description", "pqStrictOrdering", "pqRatePerSec", @@ -10231,10 +10325,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "team", - "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_projectId", + "__template_datasetId", + "__template_tableId", "__template_onBackpressure", ] ) @@ -10252,32 +10346,29 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackCompression(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Compression type to use for records""" +class CreateOutputSystemByPackOutputAzureEventhubType(str, Enum): + r"""Connector type identifier.""" - # None - NONE = "none" - # Gzip - GZIP = "gzip" + AZURE_EVENTHUB = "azure_eventhub" -class CreateOutputSystemByPackOutputKinesisPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputKinesisPqControls(BaseModel): +class CreateOutputSystemByPackOutputAzureEventhubPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputKinesisTypedDict(TypedDict): +class CreateOutputSystemByPackOutputAzureEventhubTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsKinesis + type: CreateOutputSystemByPackOutputAzureEventhubType r"""Connector type identifier.""" - stream_name: str - r"""Kinesis stream name to send events to.""" - region: str - r"""Region where the Kinesis stream is located""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + topic: str + r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10286,46 +10377,40 @@ class CreateOutputSystemByPackOutputKinesisTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Kinesis stream""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing put requests before blocking.""" + ack: NotRequired[AcknowledgmentsOptions] + r"""Control the number of required acknowledgments""" + format_: NotRequired[RecordDataFormatOptions] + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" + flush_event_count: NotRequired[float] + r"""Maximum number of events in a batch before forcing a flush""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - compression: NotRequired[CreateOutputSystemByPackCompression] - r"""Compression type to use for records""" - use_list_shards: NotRequired[bool] - r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" - as_ndjson: NotRequired[bool] - r"""Batch events into a single record as NDJSON""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeUseTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeTypedDict] + r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - max_events_per_flush: NotRequired[float] - r"""Maximum number of records to send in a single request""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -10348,40 +10433,34 @@ class CreateOutputSystemByPackOutputKinesisTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputKinesisPqControlsTypedDict] + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputAzureEventhubPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputKinesis(BaseModel): +class CreateOutputSystemByPackOutputAzureEventhub(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsKinesis + type: CreateOutputSystemByPackOutputAzureEventhubType r"""Connector type identifier.""" - stream_name: Annotated[str, pydantic.Field(alias="streamName")] - r"""Kinesis stream name to send events to.""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - region: str - r"""Region where the Kinesis stream is located""" + topic: str + r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -10397,73 +10476,68 @@ class CreateOutputSystemByPackOutputKinesis(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + ack: Optional[AcknowledgmentsOptions] = None + r"""Control the number of required acknowledgments""" + + format_: Annotated[ + Optional[RecordDataFormatOptions], pydantic.Field(alias="format") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") + ] = None + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - endpoint: Optional[str] = None - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") + ] = None + r"""Maximum number of events in a batch before forcing a flush""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Maximum time to wait for a connection to complete successfully""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Use Assume Role credentials to access Kinesis stream""" + r"""Maximum time to wait for Kafka to respond to a request""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing put requests before blocking.""" + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None - r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" + r"""Maximum time to wait for Kafka to respond to an authentication request""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - - compression: Optional[CreateOutputSystemByPackCompression] = None - r"""Compression type to use for records""" + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - use_list_shards: Annotated[ - Optional[bool], pydantic.Field(alias="useListShards") - ] = None - r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" + sasl: Optional[AuthenticationTypeUse] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - as_ndjson: Annotated[Optional[bool], pydantic.Field(alias="asNdjson")] = None - r"""Batch events into a single record as NDJSON""" + tls: Optional[TLSSettingsClientSideType] = None + r"""TLS settings (client side)""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -10473,17 +10547,6 @@ class CreateOutputSystemByPackOutputKinesis(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - max_events_per_flush: Annotated[ - Optional[float], pydantic.Field(alias="maxEventsPerFlush") - ] = None - r"""Maximum number of records to send in a single request""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -10534,7 +10597,7 @@ class CreateOutputSystemByPackOutputKinesis(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputKinesisPqControls], + Optional[CreateOutputSystemByPackOutputAzureEventhubPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -10544,60 +10607,40 @@ class CreateOutputSystemByPackOutputKinesis(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") - ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.AcknowledgmentsOptions(value) except ValueError: return value return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackCompression(value) + return models.RecordDataFormatOptions(value) except ValueError: return value return value @@ -10646,26 +10689,23 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "concurrency", + "ack", + "format", "maxRecordSizeKB", + "flushEventCount", "flushPeriodSec", - "compression", - "useListShards", - "asNdjson", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", "onBackpressure", "description", - "awsApiKey", - "awsSecret", - "maxEventsPerFlush", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10679,14 +10719,10 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_streamName", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_brokers", + "__template_topic", + "__template_format", "__template_onBackpressure", - "__template_awsApiKey", ] ) serialized = handler(self) @@ -10703,36 +10739,27 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputAzureLogsType(str, Enum): +class CreateOutputSystemByPackOutputHoneycombType(str, Enum): r"""Connector type identifier.""" - AZURE_LOGS = "azure_logs" - - -class CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter workspace ID and workspace key directly, or select a stored secret""" - - MANUAL = "manual" - SECRET = "secret" + HONEYCOMB = "honeycomb" -class CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputAzureLogsPqControls(BaseModel): +class CreateOutputSystemByPackOutputHoneycombPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputAzureLogsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputHoneycombTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAzureLogsType + type: CreateOutputSystemByPackOutputHoneycombType r"""Connector type identifier.""" - log_type: str - r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + dataset: str + r"""Name of the dataset to send events to – e.g., observability""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -10741,8 +10768,6 @@ class CreateOutputSystemByPackOutputAzureLogsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - resource_id: NotRequired[str] - r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -10750,6 +10775,7 @@ class CreateOutputSystemByPackOutputAzureLogsTypedDict(TypedDict): max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -10769,8 +10795,6 @@ class CreateOutputSystemByPackOutputAzureLogsTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - api_url: NotRequired[str] - r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -10780,8 +10804,8 @@ class CreateOutputSystemByPackOutputAzureLogsTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod] - r"""Enter workspace ID and workspace key directly, or select a stored secret""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] @@ -10806,35 +10830,29 @@ class CreateOutputSystemByPackOutputAzureLogsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputHoneycombPqControlsTypedDict] r"""Persistent queue controls.""" - workspace_id: NotRequired[str] - r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" - workspace_key: NotRequired[str] - r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" - keypair_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + team: NotRequired[str] + r"""Team API key where the dataset belongs""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_workspace_id: NotRequired[str] - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_workspace_key: NotRequired[str] - r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" -class CreateOutputSystemByPackOutputAzureLogs(BaseModel): +class CreateOutputSystemByPackOutputHoneycomb(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAzureLogsType + type: CreateOutputSystemByPackOutputHoneycombType r"""Connector type identifier.""" - log_type: Annotated[str, pydantic.Field(alias="logType")] - r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + dataset: str + r"""Name of the dataset to send events to – e.g., observability""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -10850,9 +10868,6 @@ class CreateOutputSystemByPackOutputAzureLogs(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - resource_id: Annotated[Optional[str], pydantic.Field(alias="resourceId")] = None - r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" - concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -10867,6 +10882,7 @@ class CreateOutputSystemByPackOutputAzureLogs(BaseModel): r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: Optional[bool] = None + r"""Compress the payload body before sending""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -10911,9 +10927,6 @@ class CreateOutputSystemByPackOutputAzureLogs(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - api_url: Annotated[Optional[str], pydantic.Field(alias="apiUrl")] = None - r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -10935,10 +10948,9 @@ class CreateOutputSystemByPackOutputAzureLogs(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod], - pydantic.Field(alias="authType"), + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") ] = None - r"""Enter workspace ID and workspace key directly, or select a stored secret""" + r"""Enter API key directly, or select a stored secret""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -10993,21 +11005,16 @@ class CreateOutputSystemByPackOutputAzureLogs(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputAzureLogsPqControls], + Optional[CreateOutputSystemByPackOutputHoneycombPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None - r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" - - workspace_key: Annotated[Optional[str], pydantic.Field(alias="workspaceKey")] = None - r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" + team: Optional[str] = None + r"""Team API key where the dataset belongs""" - keypair_secret: Annotated[Optional[str], pydantic.Field(alias="keypairSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") @@ -11024,16 +11031,6 @@ class CreateOutputSystemByPackOutputAzureLogs(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_workspace_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceId") - ] = None - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - - template_workspace_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceKey") - ] = None - r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" - @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -11056,11 +11053,7 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return ( - models.CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod( - value - ) - ) + return models.AuthenticationMethodOptionsAPI(value) except ValueError: return value return value @@ -11100,7 +11093,6 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "resourceId", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -11113,7 +11105,6 @@ def serialize_model(self, handler): "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "apiUrl", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", @@ -11132,14 +11123,11 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "workspaceId", - "workspaceKey", - "keypairSecret", + "team", + "textSecret", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_workspaceId", - "__template_workspaceKey", ] ) serialized = handler(self) @@ -11156,189 +11144,32 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputAzureDataExplorerType(str, Enum): - r"""Connector type identifier.""" - - AZURE_DATA_EXPLORER = "azure_data_explorer" - - -class CreateOutputSystemByPackIngestionMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Ingestion mode""" - - # Batching - BATCHING = "batching" - # Streaming - STREAMING = "streaming" - - -class CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""The type of OAuth 2.0 client credentials grant flow to use""" - - # Client secret - CLIENT_SECRET = "clientSecret" - # Client secret (text secret) - CLIENT_TEXT_SECRET = "clientTextSecret" - # Certificate - CERTIFICATE = "certificate" - - -class CreateOutputSystemByPackCertificateTypedDict(TypedDict): - certificate_name: NotRequired[str] - r"""The certificate you registered as credentials for your app in the Azure portal""" - - -class CreateOutputSystemByPackCertificate(BaseModel): - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") - ] = None - r"""The certificate you registered as credentials for your app in the Azure portal""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["certificateName"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackPrefixOptional(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Prefix (optional)""" - - # drop-by - DROP_BY = "dropBy" - # ingest-by - INGEST_BY = "ingestBy" - - -class CreateOutputSystemByPackExtentTagTypedDict(TypedDict): - value: str - r"""Value""" - prefix: NotRequired[CreateOutputSystemByPackPrefixOptional] - r"""Prefix (optional)""" - - -class CreateOutputSystemByPackExtentTag(BaseModel): - value: str - r"""Value""" +class CreateOutputSystemByPackCompression(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Compression type to use for records""" - prefix: Optional[CreateOutputSystemByPackPrefixOptional] = None - r"""Prefix (optional)""" + # None + NONE = "none" + # Gzip + GZIP = "gzip" - @field_serializer("prefix") - def serialize_prefix(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackPrefixOptional(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["prefix"]) - serialized = handler(self) - m = {} +class CreateOutputSystemByPackOutputKinesisPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class CreateOutputSystemByPackOutputKinesisPqControls(BaseModel): + r"""Persistent queue controls.""" - return m - -class CreateOutputSystemByPackIngestIfNotExistTypedDict(TypedDict): - value: str - r"""Value""" - - -class CreateOutputSystemByPackIngestIfNotExist(BaseModel): - value: str - r"""Value""" - - -class CreateOutputSystemByPackReportLevel(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" - - # FailuresOnly - FAILURES_ONLY = "failuresOnly" - # DoNotReport - DO_NOT_REPORT = "doNotReport" - # FailuresAndSuccesses - FAILURES_AND_SUCCESSES = "failuresAndSuccesses" - - -class CreateOutputSystemByPackReportMethod(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Target of the ingestion status reporting. Defaults to Queue.""" - - # Queue - QUEUE = "queue" - # Table - TABLE = "table" - # QueueAndTable - QUEUE_AND_TABLE = "queueAndTable" - - -class CreateOutputSystemByPackAdditionalPropertyTypedDict(TypedDict): - key: str - r"""Key""" - value: str - r"""Value""" - - -class CreateOutputSystemByPackAdditionalProperty(BaseModel): - key: str - r"""Key""" - - value: str - r"""Value""" - - -class CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputAzureDataExplorerPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputAzureDataExplorerTypedDict(TypedDict): +class CreateOutputSystemByPackOutputKinesisTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAzureDataExplorerType + type: TypeOptionsKinesis r"""Connector type identifier.""" - cluster_url: str - r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - database: str - r"""Name of the database containing the table where data will be ingested""" - table: str - r"""Name of the table to ingest data into""" - oauth_endpoint: MicrosoftEntraIDAuthenticationEndpointOptionsSasl - r"""Endpoint used to acquire authentication tokens from Azure""" - tenant_id: str - r"""Directory ID (tenant identifier) in Azure Active Directory""" - client_id: str - r"""client_id to pass in the OAuth request parameter""" - scope: str - r"""Scope to pass in the OAuth request parameter""" - oauth_type: CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod - r"""The type of OAuth 2.0 client credentials grant flow to use""" - compress: CompressionOptionsHTTP - r"""Data compression format to apply to HTTP content before it is delivered""" + stream_name: str + r"""Kinesis stream name to send events to.""" + region: str + r"""Region where the Kinesis stream is located""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -11347,132 +11178,46 @@ class CreateOutputSystemByPackOutputAzureDataExplorerTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - validate_database_settings: NotRequired[bool] - r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" - ingest_mode: NotRequired[CreateOutputSystemByPackIngestionMode] - r"""Ingestion mode""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""The client secret that you generated for your app in the Azure portal""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CreateOutputSystemByPackCertificateTypedDict] - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - is_mapping_obj: NotRequired[bool] - r"""Send a JSON mapping object instead of specifying an existing named data mapping""" - mapping_obj: NotRequired[str] - r"""Enter a JSON object that defines your desired data mapping""" - mapping_ref: NotRequired[str] - r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" - ingest_url: NotRequired[str] - r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - flush_immediately: NotRequired[bool] - r"""Bypass the data management service's aggregation mechanism""" - retain_blob_on_success: NotRequired[bool] - r"""Prevent blob deletion after ingestion is complete""" - extent_tags: NotRequired[List[CreateOutputSystemByPackExtentTagTypedDict]] - r"""Strings or tags associated with the extent (ingested data shard)""" - ingest_if_not_exists: NotRequired[ - List[CreateOutputSystemByPackIngestIfNotExistTypedDict] - ] - r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" - report_level: NotRequired[CreateOutputSystemByPackReportLevel] - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" - report_method: NotRequired[CreateOutputSystemByPackReportMethod] - r"""Target of the ingestion status reporting. Defaults to Queue.""" - additional_properties: NotRequired[ - List[CreateOutputSystemByPackAdditionalPropertyTypedDict] - ] - r"""Optionally, enter additional configuration properties to send to the ingestion service""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Kinesis stream""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of ongoing put requests before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + compression: NotRequired[CreateOutputSystemByPackCompression] + r"""Compression type to use for records""" + use_list_shards: NotRequired[bool] + r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" + as_ndjson: NotRequired[bool] + r"""Batch events into a single record as NDJSON""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + max_events_per_flush: NotRequired[float] + r"""Maximum number of records to send in a single request""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -11495,83 +11240,40 @@ class CreateOutputSystemByPackOutputAzureDataExplorerTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict - ] + pq_controls: NotRequired[CreateOutputSystemByPackOutputKinesisPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_cluster_url: NotRequired[str] - r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_table: NotRequired[str] - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - template_oauth_endpoint: NotRequired[str] - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_scope: NotRequired[str] - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_mapping_ref: NotRequired[str] - r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" - template_ingest_url: NotRequired[str] - r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" -class CreateOutputSystemByPackOutputAzureDataExplorer(BaseModel): +class CreateOutputSystemByPackOutputKinesis(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputAzureDataExplorerType + type: TypeOptionsKinesis r"""Connector type identifier.""" - cluster_url: Annotated[str, pydantic.Field(alias="clusterUrl")] - r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - - database: str - r"""Name of the database containing the table where data will be ingested""" - - table: str - r"""Name of the table to ingest data into""" - - oauth_endpoint: Annotated[ - MicrosoftEntraIDAuthenticationEndpointOptionsSasl, - pydantic.Field(alias="oauthEndpoint"), - ] - r"""Endpoint used to acquire authentication tokens from Azure""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Directory ID (tenant identifier) in Azure Active Directory""" - - client_id: Annotated[str, pydantic.Field(alias="clientId")] - r"""client_id to pass in the OAuth request parameter""" - - scope: str - r"""Scope to pass in the OAuth request parameter""" - - oauth_type: Annotated[ - CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod, - pydantic.Field(alias="oauthType"), - ] - r"""The type of OAuth 2.0 client credentials grant flow to use""" + stream_name: Annotated[str, pydantic.Field(alias="streamName")] + r"""Kinesis stream name to send events to.""" - compress: CompressionOptionsHTTP - r"""Data compression format to apply to HTTP content before it is delivered""" + region: str + r"""Region where the Kinesis stream is located""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -11587,290 +11289,551 @@ class CreateOutputSystemByPackOutputAzureDataExplorer(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - validate_database_settings: Annotated[ - Optional[bool], pydantic.Field(alias="validateDatabaseSettings") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - ingest_mode: Annotated[ - Optional[CreateOutputSystemByPackIngestionMode], - pydantic.Field(alias="ingestMode"), - ] = None - r"""Ingestion mode""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + endpoint: Optional[str] = None + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""The client secret that you generated for your app in the Azure portal""" + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - certificate: Optional[CreateOutputSystemByPackCertificate] = None + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Kinesis stream""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Format of the output data""" + r"""Amazon Resource Name (ARN) of the role to assume""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""External ID to use when assuming role""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing put requests before blocking.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Determines which data types are supported and how they are represented""" + r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + compression: Optional[CreateOutputSystemByPackCompression] = None + r"""Compression type to use for records""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + use_list_shards: Annotated[ + Optional[bool], pydantic.Field(alias="useListShards") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + as_ndjson: Annotated[Optional[bool], pydantic.Field(alias="asNdjson")] = None + r"""Batch events into a single record as NDJSON""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + r"""How to handle events when all receivers are exerting backpressure""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + max_events_per_flush: Annotated[ + Optional[float], pydantic.Field(alias="maxEventsPerFlush") ] = None - r"""Remove empty staging directories after moving files""" + r"""Maximum number of records to send in a single request""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - is_mapping_obj: Annotated[Optional[bool], pydantic.Field(alias="isMappingObj")] = ( - None - ) - r"""Send a JSON mapping object instead of specifying an existing named data mapping""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - mapping_obj: Annotated[Optional[str], pydantic.Field(alias="mappingObj")] = None - r"""Enter a JSON object that defines your desired data mapping""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - mapping_ref: Annotated[Optional[str], pydantic.Field(alias="mappingRef")] = None - r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" - ingest_url: Annotated[Optional[str], pydantic.Field(alias="ingestUrl")] = None - r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputKinesisPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") ] = None - r"""Maximum number of parts to upload in parallel per file""" + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Add the Output ID value to staging location""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackCompression(value) + except ValueError: + return value + return value - flush_immediately: Annotated[ - Optional[bool], pydantic.Field(alias="flushImmediately") - ] = None - r"""Bypass the data management service's aggregation mechanism""" + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value - retain_blob_on_success: Annotated[ - Optional[bool], pydantic.Field(alias="retainBlobOnSuccess") - ] = None - r"""Prevent blob deletion after ingestion is complete""" + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value - extent_tags: Annotated[ - Optional[List[CreateOutputSystemByPackExtentTag]], - pydantic.Field(alias="extentTags"), - ] = None - r"""Strings or tags associated with the extent (ingested data shard)""" + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value - ingest_if_not_exists: Annotated[ - Optional[List[CreateOutputSystemByPackIngestIfNotExist]], - pydantic.Field(alias="ingestIfNotExists"), - ] = None - r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value - report_level: Annotated[ - Optional[CreateOutputSystemByPackReportLevel], - pydantic.Field(alias="reportLevel"), - ] = None - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "concurrency", + "maxRecordSizeKB", + "flushPeriodSec", + "compression", + "useListShards", + "asNdjson", + "onBackpressure", + "description", + "awsApiKey", + "awsSecret", + "maxEventsPerFlush", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_streamName", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_onBackpressure", + "__template_awsApiKey", + ] + ) + serialized = handler(self) + m = {} - report_method: Annotated[ - Optional[CreateOutputSystemByPackReportMethod], - pydantic.Field(alias="reportMethod"), - ] = None - r"""Target of the ingestion status reporting. Defaults to Queue.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - additional_properties: Annotated[ - Optional[List[CreateOutputSystemByPackAdditionalProperty]], - pydantic.Field(alias="additionalProperties"), - ] = None - r"""Optionally, enter additional configuration properties to send to the ingestion service""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + return m - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" +class CreateOutputSystemByPackOutputAzureLogsType(str, Enum): + r"""Connector type identifier.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + AZURE_LOGS = "azure_logs" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" +class CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter workspace ID and workspace key directly, or select a stored secret""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + MANUAL = "manual" + SECRET = "secret" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ +class CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputAzureLogsPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputAzureLogsTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputAzureLogsType + r"""Connector type identifier.""" + log_type: str + r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + resource_id: NotRequired[str] + r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + api_url: NotRequired[str] + r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod] + r"""Enter workspace ID and workspace key directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputSystemByPackOutputAzureLogsPqControlsTypedDict] + r"""Persistent queue controls.""" + workspace_id: NotRequired[str] + r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" + workspace_key: NotRequired[str] + r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" + keypair_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_workspace_id: NotRequired[str] + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + template_workspace_key: NotRequired[str] + r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" + + +class CreateOutputSystemByPackOutputAzureLogs(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputSystemByPackOutputAzureLogsType + r"""Connector type identifier.""" + + log_type: Annotated[str, pydantic.Field(alias="logType")] + r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + resource_id: Annotated[Optional[str], pydantic.Field(alias="resourceId")] = None + r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + api_url: Annotated[Optional[str], pydantic.Field(alias="apiUrl")] = None + r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter workspace ID and workspace key directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -11922,161 +11885,52 @@ class CreateOutputSystemByPackOutputAzureDataExplorer(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputAzureDataExplorerPqControls], + Optional[CreateOutputSystemByPackOutputAzureLogsPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None + r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" + + workspace_key: Annotated[Optional[str], pydantic.Field(alias="workspaceKey")] = None + r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" + + keypair_secret: Annotated[Optional[str], pydantic.Field(alias="keypairSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_cluster_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_clusterUrl") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_table: Annotated[ - Optional[str], pydantic.Field(alias="__template_table") + template_workspace_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceId") ] = None - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_oauth_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_oauthEndpoint") + template_workspace_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceKey") ] = None - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_scope: Annotated[ - Optional[str], pydantic.Field(alias="__template_scope") - ] = None - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - template_mapping_ref: Annotated[ - Optional[str], pydantic.Field(alias="__template_mappingRef") - ] = None - r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" - - template_ingest_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_ingestUrl") - ] = None - r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - @field_serializer("ingest_mode") - def serialize_ingest_mode(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackIngestionMode(value) - except ValueError: - return value - return value - - @field_serializer("oauth_endpoint") - def serialize_oauth_endpoint(self, value): - if isinstance(value, str): - try: - return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) - except ValueError: - return value - return value - - @field_serializer("oauth_type") - def serialize_oauth_type(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): - if isinstance(value, str): - try: - return models.ParquetVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -12090,29 +11944,15 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("report_level") - def serialize_report_level(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackReportLevel(value) - except ValueError: - return value - return value - - @field_serializer("report_method") - def serialize_report_method(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackReportMethod(value) + return ( + models.CreateOutputSystemByPackOutputAzureLogsAuthenticationMethod( + value + ) + ) except ValueError: return value return value @@ -12152,66 +11992,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "validateDatabaseSettings", - "ingestMode", - "description", - "clientSecret", - "textSecret", - "certificate", - "format", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "removeEmptyDirs", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterEnabled", - "deadletterPath", - "maxRetryNum", - "isMappingObj", - "mappingObj", - "mappingRef", - "ingestUrl", - "onBackpressure", - "stagePath", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "maxConcurrentFileParts", - "onDiskFullBackpressure", - "addIdToStagePath", - "retrySettings", - "orphans", - "timeoutSec", - "flushImmediately", - "retainBlobOnSuccess", - "extentTags", - "ingestIfNotExists", - "reportLevel", - "reportMethod", - "additionalProperties", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "resourceId", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "rejectUnauthorized", + "extraHttpHeaders", "useRoundRobinDns", - "keepAlive", + "failedRequestLoggingMode", + "safeHeaders", + "apiUrl", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "description", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -12224,22 +12024,14 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "workspaceId", + "workspaceKey", + "keypairSecret", "__template_streamtags", - "__template_clusterUrl", - "__template_database", - "__template_table", - "__template_oauthEndpoint", - "__template_tenantId", - "__template_clientId", - "__template_scope", - "__template_clientSecret", - "__template_format", - "__template_compress", - "__template_parquetSchema", - "__template_mappingRef", - "__template_ingestUrl", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_fileNameSuffix", + "__template_workspaceId", + "__template_workspaceKey", ] ) serialized = handler(self) @@ -12256,30 +12048,189 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackBlobAccessTier(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Blob access tier""" +class CreateOutputSystemByPackOutputAzureDataExplorerType(str, Enum): + r"""Connector type identifier.""" - # Default account access tier - INFERRED = "Inferred" - # Hot tier - HOT = "Hot" - # Cool tier - COOL = "Cool" - # Cold tier - COLD = "Cold" - # Archive tier - ARCHIVE = "Archive" + AZURE_DATA_EXPLORER = "azure_data_explorer" -class CreateOutputSystemByPackOutputAzureBlobTypedDict(TypedDict): +class CreateOutputSystemByPackIngestionMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Ingestion mode""" + + # Batching + BATCHING = "batching" + # Streaming + STREAMING = "streaming" + + +class CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""The type of OAuth 2.0 client credentials grant flow to use""" + + # Client secret + CLIENT_SECRET = "clientSecret" + # Client secret (text secret) + CLIENT_TEXT_SECRET = "clientTextSecret" + # Certificate + CERTIFICATE = "certificate" + + +class CreateOutputSystemByPackCertificateTypedDict(TypedDict): + certificate_name: NotRequired[str] + r"""The certificate you registered as credentials for your app in the Azure portal""" + + +class CreateOutputSystemByPackCertificate(BaseModel): + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The certificate you registered as credentials for your app in the Azure portal""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["certificateName"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackPrefixOptional(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Prefix (optional)""" + + # drop-by + DROP_BY = "dropBy" + # ingest-by + INGEST_BY = "ingestBy" + + +class CreateOutputSystemByPackExtentTagTypedDict(TypedDict): + value: str + r"""Value""" + prefix: NotRequired[CreateOutputSystemByPackPrefixOptional] + r"""Prefix (optional)""" + + +class CreateOutputSystemByPackExtentTag(BaseModel): + value: str + r"""Value""" + + prefix: Optional[CreateOutputSystemByPackPrefixOptional] = None + r"""Prefix (optional)""" + + @field_serializer("prefix") + def serialize_prefix(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackPrefixOptional(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["prefix"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackIngestIfNotExistTypedDict(TypedDict): + value: str + r"""Value""" + + +class CreateOutputSystemByPackIngestIfNotExist(BaseModel): + value: str + r"""Value""" + + +class CreateOutputSystemByPackReportLevel(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + + # FailuresOnly + FAILURES_ONLY = "failuresOnly" + # DoNotReport + DO_NOT_REPORT = "doNotReport" + # FailuresAndSuccesses + FAILURES_AND_SUCCESSES = "failuresAndSuccesses" + + +class CreateOutputSystemByPackReportMethod(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Target of the ingestion status reporting. Defaults to Queue.""" + + # Queue + QUEUE = "queue" + # Table + TABLE = "table" + # QueueAndTable + QUEUE_AND_TABLE = "queueAndTable" + + +class CreateOutputSystemByPackAdditionalPropertyTypedDict(TypedDict): + key: str + r"""Key""" + value: str + r"""Value""" + + +class CreateOutputSystemByPackAdditionalProperty(BaseModel): + key: str + r"""Key""" + + value: str + r"""Value""" + + +class CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputAzureDataExplorerPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputAzureDataExplorerTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsAzureblob + type: CreateOutputSystemByPackOutputAzureDataExplorerType r"""Connector type identifier.""" - container_name: str - r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - stage_path: str - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + cluster_url: str + r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" + database: str + r"""Name of the database containing the table where data will be ingested""" + table: str + r"""Name of the table to ingest data into""" + oauth_endpoint: MicrosoftEntraIDAuthenticationEndpointOptionsSasl + r"""Endpoint used to acquire authentication tokens from Azure""" + tenant_id: str + r"""Directory ID (tenant identifier) in Azure Active Directory""" + client_id: str + r"""client_id to pass in the OAuth request parameter""" + scope: str + r"""Scope to pass in the OAuth request parameter""" + oauth_type: CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod + r"""The type of OAuth 2.0 client credentials grant flow to use""" + compress: CompressionOptionsHTTP + r"""Data compression format to apply to HTTP content before it is delivered""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -12288,55 +12239,19 @@ class CreateOutputSystemByPackOutputAzureBlobTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - create_container: NotRequired[bool] - r"""Create the configured container in Azure Blob Storage if it does not already exist""" - dest_path: NotRequired[str] - r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - auth_type: NotRequired[AuthenticationMethodOptions] - r"""Authentication method""" - storage_class: NotRequired[CreateOutputSystemByPackBlobAccessTier] - r"""Blob access tier""" + validate_database_settings: NotRequired[bool] + r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" + ingest_mode: NotRequired[CreateOutputSystemByPackIngestionMode] + r"""Ingestion mode""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" + client_secret: NotRequired[str] + r"""The client secret that you generated for your app in the Azure portal""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CreateOutputSystemByPackCertificateTypedDict] + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" compression_level: NotRequired[CompressionLevelOptions] r"""Compression level to apply before moving files to final destination""" automatic_schema: NotRequired[bool] @@ -12361,620 +12276,30 @@ class CreateOutputSystemByPackOutputAzureBlobTypedDict(TypedDict): r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" enable_page_checksum: NotRequired[bool] r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" empty_dir_cleanup_sec: NotRequired[float] r"""How frequently, in seconds, to clean up empty directories""" directory_batch_size: NotRequired[float] r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" deadletter_path: NotRequired[str] r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - connection_string: NotRequired[str] - r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - storage_account_name: NotRequired[str] - r"""The name of your Azure storage account""" - tenant_id: NotRequired[str] - r"""The service principal's tenant ID""" - client_id: NotRequired[str] - r"""The service principal's client ID""" - azure_cloud: NotRequired[str] - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - endpoint_suffix: NotRequired[str] - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CertificateTypeTypedDict] - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_container_name: NotRequired[str] - r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_connection_string: NotRequired[str] - r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" - template_storage_account_name: NotRequired[str] - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_azure_cloud: NotRequired[str] - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - -class CreateOutputSystemByPackOutputAzureBlob(BaseModel): - id: str - r"""Unique ID for this output""" - - type: TypeOptionsAzureblob - r"""Connector type identifier.""" - - container_name: Annotated[str, pydantic.Field(alias="containerName")] - r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - create_container: Annotated[ - Optional[bool], pydantic.Field(alias="createContainer") - ] = None - r"""Create the configured container in Azure Blob Storage if it does not already exist""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file""" - - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" - - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None - r"""Buffer size used to write to a file""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptions], pydantic.Field(alias="authType") - ] = None - r"""Authentication method""" - - storage_class: Annotated[ - Optional[CreateOutputSystemByPackBlobAccessTier], - pydantic.Field(alias="storageClass"), - ] = None - r"""Blob access tier""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" - - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - connection_string: Annotated[ - Optional[str], pydantic.Field(alias="connectionString") - ] = None - r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="storageAccountName") - ] = None - r"""The name of your Azure storage account""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""The service principal's tenant ID""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""The service principal's client ID""" - - azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - - endpoint_suffix: Annotated[ - Optional[str], pydantic.Field(alias="endpointSuffix") - ] = None - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[CertificateType] = None - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_container_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_containerName") - ] = None - r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - template_connection_string: Annotated[ - Optional[str], pydantic.Field(alias="__template_connectionString") - ] = None - r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" - - template_storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageAccountName") - ] = None - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_azure_cloud: Annotated[ - Optional[str], pydantic.Field(alias="__template_azureCloud") - ] = None - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackBlobAccessTier(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): - if isinstance(value, str): - try: - return models.ParquetVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): - if isinstance(value, str): - try: - return models.DataPageVersionOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "createContainer", - "destPath", - "addIdToStagePath", - "maxConcurrentFileParts", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "authType", - "storageClass", - "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "connectionString", - "textSecret", - "storageAccountName", - "tenantId", - "clientId", - "azureCloud", - "endpointSuffix", - "clientTextSecret", - "certificate", - "__template_streamtags", - "__template_containerName", - "__template_destPath", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", - "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", - "__template_connectionString", - "__template_storageAccountName", - "__template_tenantId", - "__template_clientId", - "__template_azureCloud", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputS3TypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: TypeOptionsS3 - r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the S3 bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" + is_mapping_obj: NotRequired[bool] + r"""Send a JSON mapping object instead of specifying an existing named data mapping""" + mapping_obj: NotRequired[str] + r"""Enter a JSON object that defines your desired data mapping""" + mapping_ref: NotRequired[str] + r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" + ingest_url: NotRequired[str] + r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" file_name_suffix: NotRequired[str] r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" max_file_size_mb: NotRequired[float] @@ -12985,322 +12310,201 @@ class CreateOutputSystemByPackOutputS3TypedDict(TypedDict): r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" max_open_files: NotRequired[float] r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file""" on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + flush_immediately: NotRequired[bool] + r"""Bypass the data management service's aggregation mechanism""" + retain_blob_on_success: NotRequired[bool] + r"""Prevent blob deletion after ingestion is complete""" + extent_tags: NotRequired[List[CreateOutputSystemByPackExtentTagTypedDict]] + r"""Strings or tags associated with the extent (ingested data shard)""" + ingest_if_not_exists: NotRequired[ + List[CreateOutputSystemByPackIngestIfNotExistTypedDict] + ] + r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" + report_level: NotRequired[CreateOutputSystemByPackReportLevel] + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + report_method: NotRequired[CreateOutputSystemByPackReportMethod] + r"""Target of the ingestion status reporting. Defaults to Queue.""" + additional_properties: NotRequired[ + List[CreateOutputSystemByPackAdditionalPropertyTypedDict] + ] + r"""Optionally, enter additional configuration properties to send to the ingestion service""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + CreateOutputSystemByPackOutputAzureDataExplorerPqControlsTypedDict + ] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_cluster_url: NotRequired[str] + r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_table: NotRequired[str] + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" + template_oauth_endpoint: NotRequired[str] + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_scope: NotRequired[str] + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" template_format: NotRequired[str] r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + template_mapping_ref: NotRequired[str] + r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" + template_ingest_url: NotRequired[str] + r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" -class CreateOutputSystemByPackOutputS3(BaseModel): +class CreateOutputSystemByPackOutputAzureDataExplorer(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsS3 + type: CreateOutputSystemByPackOutputAzureDataExplorerType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - region: Optional[str] = None - r"""Region where the S3 bucket is located""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") - ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" - - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" - - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + cluster_url: Annotated[str, pydantic.Field(alias="clusterUrl")] + r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + database: str + r"""Name of the database containing the table where data will be ingested""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + table: str + r"""Name of the table to ingest data into""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + oauth_endpoint: Annotated[ + MicrosoftEntraIDAuthenticationEndpointOptionsSasl, + pydantic.Field(alias="oauthEndpoint"), + ] + r"""Endpoint used to acquire authentication tokens from Azure""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Directory ID (tenant identifier) in Azure Active Directory""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None - r"""Buffer size used to write to a file""" + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""client_id to pass in the OAuth request parameter""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" + scope: str + r"""Scope to pass in the OAuth request parameter""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + oauth_type: Annotated[ + CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod, + pydantic.Field(alias="oauthType"), + ] + r"""The type of OAuth 2.0 client credentials grant flow to use""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + compress: CompressionOptionsHTTP + r"""Data compression format to apply to HTTP content before it is delivered""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + validate_database_settings: Annotated[ + Optional[bool], pydantic.Field(alias="validateDatabaseSettings") ] = None - r"""Storage class to select for uploaded objects""" + r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), + ingest_mode: Annotated[ + Optional[CreateOutputSystemByPackIngestionMode], + pydantic.Field(alias="ingestMode"), ] = None - r"""Server-side encryption to use for uploaded objects""" - - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" + r"""Ingestion mode""" description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""The client secret that you generated for your app in the Azure portal""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + certificate: Optional[CreateOutputSystemByPackCertificate] = None + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" compression_level: Annotated[ Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") @@ -13363,6 +12567,11 @@ class CreateOutputSystemByPackOutputS3(BaseModel): ] = None r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + empty_dir_cleanup_sec: Annotated[ Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None @@ -13373,6 +12582,11 @@ class CreateOutputSystemByPackOutputS3(BaseModel): ] = None r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + deadletter_path: Annotated[ Optional[str], pydantic.Field(alias="deadletterPath") ] = None @@ -13383,95 +12597,277 @@ class CreateOutputSystemByPackOutputS3(BaseModel): ) r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + is_mapping_obj: Annotated[Optional[bool], pydantic.Field(alias="isMappingObj")] = ( + None + ) + r"""Send a JSON mapping object instead of specifying an existing named data mapping""" + + mapping_obj: Annotated[Optional[str], pydantic.Field(alias="mappingObj")] = None + r"""Enter a JSON object that defines your desired data mapping""" + + mapping_ref: Annotated[Optional[str], pydantic.Field(alias="mappingRef")] = None + r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" + + ingest_url: Annotated[Optional[str], pydantic.Field(alias="ingestUrl")] = None + r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""How to handle events when all receivers are exerting backpressure""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + flush_immediately: Annotated[ + Optional[bool], pydantic.Field(alias="flushImmediately") + ] = None + r"""Bypass the data management service's aggregation mechanism""" + + retain_blob_on_success: Annotated[ + Optional[bool], pydantic.Field(alias="retainBlobOnSuccess") + ] = None + r"""Prevent blob deletion after ingestion is complete""" + + extent_tags: Annotated[ + Optional[List[CreateOutputSystemByPackExtentTag]], + pydantic.Field(alias="extentTags"), + ] = None + r"""Strings or tags associated with the extent (ingested data shard)""" + + ingest_if_not_exists: Annotated[ + Optional[List[CreateOutputSystemByPackIngestIfNotExist]], + pydantic.Field(alias="ingestIfNotExists"), + ] = None + r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" + + report_level: Annotated[ + Optional[CreateOutputSystemByPackReportLevel], + pydantic.Field(alias="reportLevel"), + ] = None + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + + report_method: Annotated[ + Optional[CreateOutputSystemByPackReportMethod], + pydantic.Field(alias="reportMethod"), + ] = None + r"""Target of the ingestion status reporting. Defaults to Queue.""" + + additional_properties: Annotated[ + Optional[List[CreateOutputSystemByPackAdditionalProperty]], + pydantic.Field(alias="additionalProperties"), + ] = None + r"""Optionally, enter additional configuration properties to send to the ingestion service""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""Codec to use to compress the persisted data""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputAzureDataExplorerPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + r"""Persistent queue controls.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + template_cluster_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_clusterUrl") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_table: Annotated[ + Optional[str], pydantic.Field(alias="__template_table") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + template_oauth_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_oauthEndpoint") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + template_scope: Annotated[ + Optional[str], pydantic.Field(alias="__template_scope") ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_compress: Annotated[ Optional[str], pydantic.Field(alias="__template_compress") @@ -13483,11 +12879,51 @@ class CreateOutputSystemByPackOutputS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + template_mapping_ref: Annotated[ + Optional[str], pydantic.Field(alias="__template_mappingRef") + ] = None + r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" + + template_ingest_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_ingestUrl") + ] = None + r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + + @field_serializer("ingest_mode") + def serialize_ingest_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.CreateOutputSystemByPackIngestionMode(value) + except ValueError: + return value + return value + + @field_serializer("oauth_endpoint") + def serialize_oauth_endpoint(self, value): + if isinstance(value, str): + try: + return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) + except ValueError: + return value + return value + + @field_serializer("oauth_type") + def serialize_oauth_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputAzureDataExplorerAuthenticationMethod( + value + ) except ValueError: return value return value @@ -13501,83 +12937,101 @@ def serialize_format_(self, value): return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.ObjectACLOptions(value) + return models.ParquetVersionOptions(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): if isinstance(value, str): try: - return models.StorageClassOptions(value) + return models.DataPageVersionOptions(value) except ValueError: return value return value - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("report_level") + def serialize_report_level(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.CreateOutputSystemByPackReportLevel(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("report_method") + def serialize_report_method(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CreateOutputSystemByPackReportMethod(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -13590,46 +13044,13 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "endpoint", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "region", - "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", - "kmsKeyId", + "validateDatabaseSettings", + "ingestMode", "description", - "awsApiKey", - "awsSecret", - "compress", + "clientSecret", + "textSecret", + "certificate", + "format", "compressionLevel", "automaticSchema", "parquetSchema", @@ -13642,30 +13063,75 @@ def serialize_model(self, handler): "enableStatistics", "enableWritePageIndex", "enablePageChecksum", + "removeEmptyDirs", "emptyDirCleanupSec", "directoryBatchSize", + "deadletterEnabled", "deadletterPath", "maxRetryNum", + "isMappingObj", + "mappingObj", + "mappingRef", + "ingestUrl", + "onBackpressure", + "stagePath", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "maxConcurrentFileParts", + "onDiskFullBackpressure", + "addIdToStagePath", + "retrySettings", + "orphans", + "timeoutSec", + "flushImmediately", + "retainBlobOnSuccess", + "extentTags", + "ingestIfNotExists", + "reportLevel", + "reportMethod", + "additionalProperties", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "maxConnectionReuseSec", + "flushPeriodSec", + "rejectUnauthorized", + "useRoundRobinDns", + "keepAlive", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_bucket", - "__template_region", - "__template_destPath", - "__template_partitionExpr", + "__template_clusterUrl", + "__template_database", + "__template_table", + "__template_oauthEndpoint", + "__template_tenantId", + "__template_clientId", + "__template_scope", + "__template_clientSecret", "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", - "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", - "__template_awsApiKey", "__template_compress", "__template_parquetSchema", + "__template_mappingRef", + "__template_ingestUrl", + "__template_onBackpressure", + "__template_fileNameSuffix", ] ) serialized = handler(self) @@ -13682,19 +13148,30 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputFilesystemType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputSystemByPackBlobAccessTier(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Blob access tier""" - FILESYSTEM = "filesystem" + # Default account access tier + INFERRED = "Inferred" + # Hot tier + HOT = "Hot" + # Cool tier + COOL = "Cool" + # Cold tier + COLD = "Cold" + # Archive tier + ARCHIVE = "Archive" -class CreateOutputSystemByPackOutputFilesystemTypedDict(TypedDict): +class CreateOutputSystemByPackOutputAzureBlobTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputFilesystemType + type: TypeOptionsAzureblob r"""Connector type identifier.""" - dest_path: str - r"""Final destination for the output files""" + container_name: str + r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" + stage_path: str + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -13703,10 +13180,14 @@ class CreateOutputSystemByPackOutputFilesystemTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + create_container: NotRequired[bool] + r"""Create the configured container in Azure Blob Storage if it does not already exist""" + dest_path: NotRequired[str] + r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" add_id_to_stage_path: NotRequired[bool] r"""Add the Output ID value to staging location""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file""" remove_empty_dirs: NotRequired[bool] r"""Remove empty staging directories after moving files""" partition_expr: NotRequired[str] @@ -13740,6 +13221,10 @@ class CreateOutputSystemByPackOutputFilesystemTypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" + auth_type: NotRequired[AuthenticationMethodOptions] + r"""Authentication method""" + storage_class: NotRequired[CreateOutputSystemByPackBlobAccessTier] + r"""Blob access tier""" description: NotRequired[str] r"""Optional description for this configuration.""" compress: NotRequired[CompressionOptionsHTTP] @@ -13776,8 +13261,29 @@ class CreateOutputSystemByPackOutputFilesystemTypedDict(TypedDict): r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + connection_string: NotRequired[str] + r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_container_name: NotRequired[str] + r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" template_partition_expr: NotRequired[str] r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" template_format: NotRequired[str] @@ -13792,17 +13298,30 @@ class CreateOutputSystemByPackOutputFilesystemTypedDict(TypedDict): r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + template_connection_string: NotRequired[str] + r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" -class CreateOutputSystemByPackOutputFilesystem(BaseModel): +class CreateOutputSystemByPackOutputAzureBlob(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputFilesystemType + type: TypeOptionsAzureblob r"""Connector type identifier.""" - dest_path: Annotated[str, pydantic.Field(alias="destPath")] - r"""Final destination for the output files""" + container_name: Annotated[str, pydantic.Field(alias="containerName")] + r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -13818,14 +13337,24 @@ class CreateOutputSystemByPackOutputFilesystem(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + create_container: Annotated[ + Optional[bool], pydantic.Field(alias="createContainer") + ] = None + r"""Create the configured container in Azure Blob Storage if it does not already exist""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" add_id_to_stage_path: Annotated[ Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None r"""Add the Output ID value to staging location""" + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file""" + remove_empty_dirs: Annotated[ Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None @@ -13908,6 +13437,17 @@ class CreateOutputSystemByPackOutputFilesystem(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptions], pydantic.Field(alias="authType") + ] = None + r"""Authentication method""" + + storage_class: Annotated[ + Optional[CreateOutputSystemByPackBlobAccessTier], + pydantic.Field(alias="storageClass"), + ] = None + r"""Blob access tier""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -13995,11 +13535,55 @@ class CreateOutputSystemByPackOutputFilesystem(BaseModel): ) r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + connection_string: Annotated[ + Optional[str], pydantic.Field(alias="connectionString") + ] = None + r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") + ] = None + r"""The name of your Azure storage account""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" + + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") + ] = None + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_container_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_containerName") + ] = None + r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" + + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") + ] = None + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: Annotated[ Optional[str], pydantic.Field(alias="__template_partitionExpr") ] = None @@ -14035,6 +13619,31 @@ class CreateOutputSystemByPackOutputFilesystem(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + template_connection_string: Annotated[ + Optional[str], pydantic.Field(alias="__template_connectionString") + ] = None + r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") + ] = None + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + @field_serializer("format_") def serialize_format_(self, value): if isinstance(value, str): @@ -14057,7 +13666,25 @@ def serialize_on_backpressure(self, value): def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.DiskSpaceProtectionOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("storage_class") + def serialize_storage_class(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackBlobAccessTier(value) except ValueError: return value return value @@ -14106,8 +13733,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "stagePath", + "createContainer", + "destPath", "addIdToStagePath", + "maxConcurrentFileParts", "removeEmptyDirs", "partitionExpr", "format", @@ -14125,6 +13754,8 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", + "authType", + "storageClass", "description", "compress", "compressionLevel", @@ -14143,7 +13774,18 @@ def serialize_model(self, handler): "directoryBatchSize", "deadletterPath", "maxRetryNum", + "connectionString", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", "__template_streamtags", + "__template_containerName", + "__template_destPath", "__template_partitionExpr", "__template_format", "__template_baseFileName", @@ -14151,6 +13793,11 @@ def serialize_model(self, handler): "__template_onBackpressure", "__template_compress", "__template_parquetSchema", + "__template_connectionString", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", ] ) serialized = handler(self) @@ -14167,27 +13814,15 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSignalfxType(str, Enum): - r"""Connector type identifier.""" - - SIGNALFX = "signalfx" - - -class CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputSignalfxPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputSignalfxTypedDict(TypedDict): +class CreateOutputSystemByPackOutputS3TypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSignalfxType + type: TypeOptionsS3 r"""Connector type identifier.""" - realm: str - r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -14196,91 +13831,171 @@ class CreateOutputSystemByPackOutputSignalfxTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the S3 bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict] - r"""Persistent queue controls.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputSystemByPackOutputSignalfx(BaseModel): +class CreateOutputSystemByPackOutputS3(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSignalfxType + type: TypeOptionsS3 r"""Connector type identifier.""" - realm: str - r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -14296,184 +14011,384 @@ class CreateOutputSystemByPackOutputSignalfx(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Use Assume Role credentials to access S3""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Maximum size, in KB, of the request body""" + r"""External ID to use when assuming role""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + region: Optional[str] = None + r"""Region where the S3 bucket is located""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") ] = None - r"""Headers to add to all events""" + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + ] = None + r"""Object ACL to assign to uploaded objects""" + + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + ] = None + r"""Storage class to select for uploaded objects""" + + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" + + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" + + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") + ] = None + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + ] = None + r"""Determines which data types are supported and how they are represented""" + + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") + ] = None + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), + ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""List of headers that are safe to log in plain text""" + r"""How frequently, in seconds, to clean up empty directories""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - token: Optional[str] = None - r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Codec to use to compress the persisted data""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSignalfxPqControls], - pydantic.Field(alias="pqControls"), + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") ] = None - r"""Persistent queue controls.""" + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -14482,34 +14397,79 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.StorageClassOptions(value) + except ValueError: + return value + return value + + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): + if isinstance(value, str): + try: + return models.ServerSideEncryptionForUploadedObjectsOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -14522,41 +14482,82 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "endpoint", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "awsAuthenticationMethod", + "reuseConnections", + "rejectUnauthorized", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_bucket", + "__template_region", + "__template_destPath", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -14573,27 +14574,19 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputWavefrontType(str, Enum): +class CreateOutputSystemByPackOutputFilesystemType(str, Enum): r"""Connector type identifier.""" - WAVEFRONT = "wavefront" - - -class CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class CreateOutputSystemByPackOutputWavefrontPqControls(BaseModel): - r"""Persistent queue controls.""" + FILESYSTEM = "filesystem" -class CreateOutputSystemByPackOutputWavefrontTypedDict(TypedDict): +class CreateOutputSystemByPackOutputFilesystemTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWavefrontType + type: CreateOutputSystemByPackOutputFilesystemType r"""Connector type identifier.""" - domain: str - r"""WaveFront domain name, e.g. \"longboard\" """ + dest_path: str + r"""Final destination for the output files""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -14602,92 +14595,107 @@ class CreateOutputSystemByPackOutputWavefrontTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict] - r"""Persistent queue controls.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" -class CreateOutputSystemByPackOutputWavefront(BaseModel): +class CreateOutputSystemByPackOutputFilesystem(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWavefrontType + type: CreateOutputSystemByPackOutputFilesystemType r"""Connector type identifier.""" - domain: str - r"""WaveFront domain name, e.g. \"longboard\" """ - + dest_path: Annotated[str, pydantic.Field(alias="destPath")] + r"""Final destination for the output files""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -14702,220 +14710,282 @@ class CreateOutputSystemByPackOutputWavefront(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Add the Output ID value to staging location""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Remove empty staging directories after moving files""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Headers to add to all events""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Buffer size used to write to a file""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""List of headers that are safe to log in plain text""" + r"""How to handle events when all receivers are exerting backpressure""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" description: Optional[str] = None r"""Optional description for this configuration.""" - token: Optional[str] = None - r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Determines which data types are supported and how they are represented""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), + ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""Codec to use to compress the persisted data""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputWavefrontPqControls], - pydantic.Field(alias="pqControls"), + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Persistent queue controls.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.DataFormatOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ParquetVersionOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -14928,41 +14998,51 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "stagePath", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_compress", + "__template_parquetSchema", ] ) serialized = handler(self) @@ -14979,19 +15059,27 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSignalfxType(str, Enum): + r"""Connector type identifier.""" + + SIGNALFX = "signalfx" + + +class CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputTcpjsonPqControls(BaseModel): +class CreateOutputSystemByPackOutputSignalfxPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputTcpjsonTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSignalfxTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsTcpjson + type: CreateOutputSystemByPackOutputSignalfxType r"""Connector type identifier.""" + realm: str + r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -15000,44 +15088,50 @@ class CreateOutputSystemByPackOutputTcpjsonTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Use load-balanced destinations""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - send_header: NotRequired[bool] - r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + token: NotRequired[str] + r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15060,29 +15154,26 @@ class CreateOutputSystemByPackOutputTcpjsonTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSignalfxPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Optional authentication token to include as part of the connection header""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputSystemByPackOutputTcpjson(BaseModel): +class CreateOutputSystemByPackOutputSignalfx(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsTcpjson + type: CreateOutputSystemByPackOutputSignalfxType r"""Connector type identifier.""" + realm: str + r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -15097,85 +15188,99 @@ class CreateOutputSystemByPackOutputTcpjson(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Use load-balanced destinations""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - compression: Optional[CompressionOptionsGzipNone] = None - r"""Codec to use to compress the data before sending""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Headers to add to all events""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""List of headers that are safe to log in plain text""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - send_header: Annotated[Optional[bool], pydantic.Field(alias="sendHeader")] = None - r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - description: Optional[str] = None r"""Optional description for this configuration.""" - host: Optional[str] = None - r"""The hostname of the receiver""" - - port: Optional[float] = None - r"""The port to connect to on the provided host""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + token: Optional[str] = None + r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") - ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -15227,60 +15332,49 @@ class CreateOutputSystemByPackOutputTcpjson(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputTcpjsonPqControls], + Optional[CreateOutputSystemByPackOutputSignalfxPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Optional authentication token to include as part of the connection header""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipNone(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -15320,25 +15414,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "compression", - "logFailedRequests", - "throttleRatePerSec", - "tls", - "connectionTimeout", - "writeTimeout", - "tokenTTLMinutes", - "sendHeader", - "onBackpressure", "authType", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "host", - "port", - "excludeSelf", - "hosts", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -15351,12 +15446,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_host", - "__template_port", ] ) serialized = handler(self) @@ -15373,33 +15465,27 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputWizHecType(str, Enum): +class CreateOutputSystemByPackOutputWavefrontType(str, Enum): r"""Connector type identifier.""" - WIZ_HEC = "wiz_hec" + WAVEFRONT = "wavefront" -class CreateOutputSystemByPackOutputWizHecPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputWizHecPqControls(BaseModel): +class CreateOutputSystemByPackOutputWavefrontPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputWizHecTypedDict(TypedDict): +class CreateOutputSystemByPackOutputWavefrontTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWizHecType + type: CreateOutputSystemByPackOutputWavefrontType r"""Connector type identifier.""" - wiz_connector_id: str - r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" - wiz_environment: str - r"""Your Wiz deployment environment""" - data_center: str - r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - wiz_sourcetype: str - r"""Wiz Defend Source type""" + domain: str + r"""WaveFront domain name, e.g. \"longboard\" """ pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -15408,8 +15494,8 @@ class CreateOutputSystemByPackOutputWizHecTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -15431,12 +15517,12 @@ class CreateOutputSystemByPackOutputWizHecTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -15449,7 +15535,7 @@ class CreateOutputSystemByPackOutputWizHecTypedDict(TypedDict): description: NotRequired[str] r"""Optional description for this configuration.""" token: NotRequired[str] - r"""Wiz Defend Auth token""" + r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] @@ -15474,40 +15560,25 @@ class CreateOutputSystemByPackOutputWizHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputWizHecPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputWavefrontPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_wiz_environment: NotRequired[str] - r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" - template_data_center: NotRequired[str] - r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" - template_wiz_sourcetype: NotRequired[str] - r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" -class CreateOutputSystemByPackOutputWizHec(BaseModel): +class CreateOutputSystemByPackOutputWavefront(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWizHecType + type: CreateOutputSystemByPackOutputWavefrontType r"""Connector type identifier.""" - wiz_connector_id: str - r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" - - wiz_environment: str - r"""Your Wiz deployment environment""" - - data_center: str - r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - - wiz_sourcetype: str - r"""Wiz Defend Source type""" + domain: str + r"""WaveFront domain name, e.g. \"longboard\" """ pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -15523,8 +15594,11 @@ class CreateOutputSystemByPackOutputWizHec(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -15569,6 +15643,11 @@ class CreateOutputSystemByPackOutputWizHec(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -15580,12 +15659,6 @@ class CreateOutputSystemByPackOutputWizHec(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -15610,7 +15683,7 @@ class CreateOutputSystemByPackOutputWizHec(BaseModel): r"""Optional description for this configuration.""" token: Optional[str] = None - r"""Wiz Defend Auth token""" + r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -15665,7 +15738,7 @@ class CreateOutputSystemByPackOutputWizHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputWizHecPqControls], + Optional[CreateOutputSystemByPackOutputWavefrontPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -15680,40 +15753,25 @@ class CreateOutputSystemByPackOutputWizHec(BaseModel): ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_wiz_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_wiz_environment") - ] = None - r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" - - template_data_center: Annotated[ - Optional[str], pydantic.Field(alias="__template_data_center") - ] = None - r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" - - template_wiz_sourcetype: Annotated[ - Optional[str], pydantic.Field(alias="__template_wiz_sourcetype") - ] = None - r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -15762,7 +15820,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "tls", + "authType", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -15772,9 +15830,9 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", @@ -15796,9 +15854,6 @@ def serialize_model(self, handler): "pqControls", "__template_streamtags", "__template_failedRequestLoggingMode", - "__template_wiz_environment", - "__template_data_center", - "__template_wiz_sourcetype", "__template_onBackpressure", ] ) @@ -15816,62 +15871,18 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSplunkHecType(str, Enum): - r"""Connector type identifier.""" - - SPLUNK_HEC = "splunk_hec" - - -class CreateOutputSystemByPackOutputSplunkHecURLTypedDict(TypedDict): - url: str - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - -class CreateOutputSystemByPackOutputSplunkHecURL(BaseModel): - url: str - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSplunkHecPqControls(BaseModel): +class CreateOutputSystemByPackOutputTcpjsonPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSplunkHecTypedDict(TypedDict): +class CreateOutputSystemByPackOutputTcpjsonTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSplunkHecType + type: TypeOptionsTcpjson r"""Connector type identifier.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -15882,69 +15893,43 @@ class CreateOutputSystemByPackOutputSplunkHecTypedDict(TypedDict): streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""Use load-balanced destinations""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - next_queue: NotRequired[str] - r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" - tcp_routing: NotRequired[str] - r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + token_ttl_minutes: NotRequired[float] + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" + send_header: NotRequired[bool] + r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputSystemByPackOutputSplunkHecURLTypedDict]] - r"""Splunk HEC Endpoints""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" - token: NotRequired[str] - r"""Splunk HEC authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15967,23 +15952,27 @@ class CreateOutputSystemByPackOutputSplunkHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputTcpjsonPqControlsTypedDict] r"""Persistent queue controls.""" + auth_token: NotRequired[str] + r"""Optional authentication token to include as part of the connection header""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class CreateOutputSystemByPackOutputSplunkHec(BaseModel): +class CreateOutputSystemByPackOutputTcpjson(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSplunkHecType + type: TypeOptionsTcpjson r"""Connector type identifier.""" pipeline: Optional[str] = None @@ -16003,118 +15992,67 @@ class CreateOutputSystemByPackOutputSplunkHec(BaseModel): load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + r"""Use load-balanced destinations""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + compression: Optional[CompressionOptionsGzipNone] = None + r"""Codec to use to compress the data before sending""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Use to troubleshoot issues with sending data""" - enable_multi_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="enableMultiMetrics") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - next_queue: Annotated[Optional[str], pydantic.Field(alias="nextQueue")] = None - r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - tcp_routing: Annotated[Optional[str], pydantic.Field(alias="tcpRouting")] = None - r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" + send_header: Annotated[Optional[bool], pydantic.Field(alias="sendHeader")] = None + r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + host: Optional[str] = None + r"""The hostname of the receiver""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + port: Optional[float] = None + r"""The port to connect to on the provided host""" exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: Optional[List[CreateOutputSystemByPackOutputSplunkHecURL]] = None - r"""Splunk HEC Endpoints""" + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") @@ -16126,11 +16064,10 @@ class CreateOutputSystemByPackOutputSplunkHec(BaseModel): ] = None r"""How far back in time to keep traffic stats for load balancing purposes""" - token: Optional[str] = None - r"""Splunk HEC authentication token""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") + ] = None + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16182,270 +16119,87 @@ class CreateOutputSystemByPackOutputSplunkHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSplunkHecPqControls], + Optional[CreateOutputSystemByPackOutputTcpjsonPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPq(value) - except ValueError: - return value - return value - - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "loadBalanced", - "tls", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "enableMultiMetrics", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "nextQueue", - "tcpRouting", - "onBackpressure", - "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "__template_streamtags", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - "__template_url", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputSplunkLbType(str, Enum): - r"""Connector type identifier.""" - - SPLUNK_LB = "splunk_lb" - - -class CreateOutputSystemByPackAuthTokenTypedDict(TypedDict): - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateOutputSystemByPackAuthToken(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + r"""Optional authentication token to include as part of the connection header""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["authType", "authToken", "textSecret"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict(TypedDict): - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - - site: str - r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" - master_uri: str - r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" - refresh_interval_sec: float - r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" - reject_unauthorized: NotRequired[bool] - r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" - auth_tokens: NotRequired[List[CreateOutputSystemByPackAuthTokenTypedDict]] - r"""Tokens required to authenticate to cluster manager for indexer discovery""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class CreateOutputSystemByPackIndexerDiscoveryConfigs(BaseModel): - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - - site: str - r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" - - master_uri: Annotated[str, pydantic.Field(alias="masterUri")] - r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" - - refresh_interval_sec: Annotated[float, pydantic.Field(alias="refreshIntervalSec")] - r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - auth_tokens: Annotated[ - Optional[List[CreateOutputSystemByPackAuthToken]], - pydantic.Field(alias="authTokens"), + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Tokens required to authenticate to cluster manager for indexer discovery""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsGzipNone(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -16453,7 +16207,49 @@ def serialize_auth_type(self, value): @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( - ["rejectUnauthorized", "authTokens", "authType", "authToken", "textSecret"] + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "loadBalanced", + "compression", + "logFailedRequests", + "throttleRatePerSec", + "tls", + "connectionTimeout", + "writeTimeout", + "tokenTTLMinutes", + "sendHeader", + "onBackpressure", + "authType", + "description", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "authToken", + "textSecret", + "__template_streamtags", + "__template_onBackpressure", + "__template_host", + "__template_port", + ] ) serialized = handler(self) m = {} @@ -16469,21 +16265,55 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputWizHecType(str, Enum): + r"""Connector type identifier.""" + + WIZ_HEC = "wiz_hec" + + +class CreateOutputSystemByPackWizDefendSourceType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" + + AWS_CLOUDTRAIL = "AWS_CLOUDTRAIL" + AWS_EKS_AUDIT_LOGS = "AWS_EKS_AUDIT_LOGS" + AWS_RESOLVER_QUERY_LOGS = "AWS_RESOLVER_QUERY_LOGS" + AZURE_ACTIVITY_LOGS = "AZURE_ACTIVITY_LOGS" + GCP_AUDIT_LOGS = "GCP_AUDIT_LOGS" + GITHUB_AUDIT_LOGS = "GITHUB_AUDIT_LOGS" + OCI_AUDIT_LOGS = "OCI_AUDIT_LOGS" + AWS_VPC_FLOW_LOGS = "AWS_VPC_FLOW_LOGS" + + +class CreateOutputSystemByPackEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The format of the VPC Flow Log events""" + + JSON = "json" + CSV_ROW = "csv_row" + + +class CreateOutputSystemByPackOutputWizHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSplunkLbPqControls(BaseModel): +class CreateOutputSystemByPackOutputWizHecPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSplunkLbTypedDict(TypedDict): +class CreateOutputSystemByPackOutputWizHecTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSplunkLbType + type: CreateOutputSystemByPackOutputWizHecType r"""Connector type identifier.""" - hosts: List[HostConfOutputSyslogTypedDict] - r"""Set of Splunk indexers to load-balance data to.""" + wiz_connector_id: str + r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" + wiz_environment: str + r"""Your Wiz deployment environment""" + data_center: str + r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" + wiz_sourcetype: CreateOutputSystemByPackWizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -16492,50 +16322,54 @@ class CreateOutputSystemByPackOutputSplunkLbTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - nested_fields: NotRequired[NestedFieldSerializationOptions] - r"""How to serialize nested fields into index-time fields""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" - enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - enable_ack: NotRequired[bool] - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - max_s2_sversion: NotRequired[MaxS2SVersionOptions] - r"""The highest S2S protocol version to advertise during handshake""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - indexer_discovery: NotRequired[bool] - r"""Automatically discover indexers in indexer clustering environment.""" - sender_unhealthy_time_allowance: NotRequired[float] - r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_failed_health_checks: NotRequired[float] - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - compress: NotRequired[CompressionOptions] - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" - indexer_discovery_configs: NotRequired[ - CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict - ] - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + token: NotRequired[str] + r"""Wiz Defend Auth token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + wiz_vpc_event_format: NotRequired[CreateOutputSystemByPackEventFormat] + r"""The format of the VPC Flow Log events""" + wiz_vpc_flow_log_format: NotRequired[str] + r"""The format string for VPC Flow Log fields""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16558,33 +16392,40 @@ class CreateOutputSystemByPackOutputSplunkLbTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputWizHecPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_nested_fields: NotRequired[str] - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_max_s2_sversion: NotRequired[str] - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_wiz_environment: NotRequired[str] + r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" + template_data_center: NotRequired[str] + r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" + template_wiz_sourcetype: NotRequired[str] + r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" -class CreateOutputSystemByPackOutputSplunkLb(BaseModel): +class CreateOutputSystemByPackOutputWizHec(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSplunkLbType + type: CreateOutputSystemByPackOutputWizHecType r"""Connector type identifier.""" - hosts: List[HostConfOutputSyslog] - r"""Set of Splunk indexers to load-balance data to.""" + wiz_connector_id: str + r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" + + wiz_environment: str + r"""Your Wiz deployment environment""" + + data_center: str + r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" + + wiz_sourcetype: CreateOutputSystemByPackWizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -16600,102 +16441,103 @@ class CreateOutputSystemByPackOutputSplunkLb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + r"""Maximum size, in KB, of the request body""" - nested_fields: Annotated[ - Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""How to serialize nested fields into index-time fields""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") - ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - enable_multi_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="enableMultiMetrics") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - max_s2_sversion: Annotated[ - Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""The highest S2S protocol version to advertise during handshake""" + r"""List of headers that are safe to log in plain text""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - indexer_discovery: Annotated[ - Optional[bool], pydantic.Field(alias="indexerDiscovery") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Automatically discover indexers in indexer clustering environment.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - sender_unhealthy_time_allowance: Annotated[ - Optional[float], pydantic.Field(alias="senderUnhealthyTimeAllowance") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - max_failed_health_checks: Annotated[ - Optional[float], pydantic.Field(alias="maxFailedHealthChecks") - ] = None - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + token: Optional[str] = None + r"""Wiz Defend Auth token""" - compress: Optional[CompressionOptions] = None - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - indexer_discovery_configs: Annotated[ - Optional[CreateOutputSystemByPackIndexerDiscoveryConfigs], - pydantic.Field(alias="indexerDiscoveryConfigs"), - ] = None - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + wiz_vpc_event_format: Optional[CreateOutputSystemByPackEventFormat] = None + r"""The format of the VPC Flow Log events""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + wiz_vpc_flow_log_format: Optional[str] = None + r"""The format string for VPC Flow Log fields""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16747,83 +16589,82 @@ class CreateOutputSystemByPackOutputSplunkLb(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSplunkLbPqControls], + Optional[CreateOutputSystemByPackOutputWizHecPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_nested_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_nestedFields") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_max_s2_sversion: Annotated[ - Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + template_wiz_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_wiz_environment") ] = None - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" + + template_data_center: Annotated[ + Optional[str], pydantic.Field(alias="__template_data_center") + ] = None + r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" + + template_wiz_sourcetype: Annotated[ + Optional[str], pydantic.Field(alias="__template_wiz_sourcetype") + ] = None + r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - @field_serializer("nested_fields") - def serialize_nested_fields(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.NestedFieldSerializationOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.MaxS2SVersionOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("wiz_sourcetype") + def serialize_wiz_sourcetype(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputSystemByPackWizDefendSourceType(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("wiz_vpc_event_format") + def serialize_wiz_vpc_event_format(self, value): if isinstance(value, str): try: - return models.CompressionOptions(value) + return models.CreateOutputSystemByPackEventFormat(value) except ValueError: return value return value @@ -16863,27 +16704,28 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", - "nestedFields", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", "tls", - "enableMultiMetrics", - "enableACK", - "logFailedRequests", - "maxS2Sversion", - "onBackpressure", - "indexerDiscovery", - "senderUnhealthyTimeAllowance", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", "authType", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "maxFailedHealthChecks", - "compress", - "indexerDiscoveryConfigs", - "excludeSelf", + "token", + "textSecret", + "wiz_vpc_event_format", + "wiz_vpc_flow_log_format", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16896,13 +16738,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", - "__template_nestedFields", - "__template_maxS2Sversion", + "__template_failedRequestLoggingMode", + "__template_wiz_environment", + "__template_data_center", + "__template_wiz_sourcetype", "__template_onBackpressure", - "__template_compress", ] ) serialized = handler(self) @@ -16919,23 +16760,63 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSplunkPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSplunkHecType(str, Enum): + r"""Connector type identifier.""" + + SPLUNK_HEC = "splunk_hec" + + +class CreateOutputSystemByPackOutputSplunkHecURLTypedDict(TypedDict): + url: str + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputSystemByPackOutputSplunkHecURL(BaseModel): + url: str + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSplunkPqControls(BaseModel): +class CreateOutputSystemByPackOutputSplunkHecPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSplunkTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSplunkHecTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSplunk + type: CreateOutputSystemByPackOutputSplunkHecType r"""Connector type identifier.""" - host: str - r"""The hostname of the receiver""" - port: float - r"""The port to connect to on the provided host""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -16944,34 +16825,70 @@ class CreateOutputSystemByPackOutputSplunkTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - nested_fields: NotRequired[NestedFieldSerializationOptions] - r"""How to serialize nested fields into index-time fields""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - enable_ack: NotRequired[bool] - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - max_s2_sversion: NotRequired[MaxS2SVersionOptions] - r"""The highest S2S protocol version to advertise during handshake""" + r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + next_queue: NotRequired[str] + r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" + tcp_routing: NotRequired[str] + r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_failed_health_checks: NotRequired[float] - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - compress: NotRequired[CompressionOptions] - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + url: NotRequired[str] + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputSystemByPackOutputSplunkHecURLTypedDict]] + r"""Splunk HEC Endpoints""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""Splunk HEC authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16994,41 +16911,25 @@ class CreateOutputSystemByPackOutputSplunkTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSplunkPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSplunkHecPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_nested_fields: NotRequired[str] - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_max_s2_sversion: NotRequired[str] - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputSplunk(BaseModel): +class CreateOutputSystemByPackOutputSplunkHec(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSplunk + type: CreateOutputSystemByPackOutputSplunkHecType r"""Connector type identifier.""" - host: str - r"""The hostname of the receiver""" - - port: float - r"""The port to connect to on the provided host""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -17043,68 +16944,137 @@ class CreateOutputSystemByPackOutputSplunk(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - nested_fields: Annotated[ - Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""How to serialize nested fields into index-time fields""" + r"""Maximum size, in KB, of the request body""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" enable_multi_metrics: Annotated[ Optional[bool], pydantic.Field(alias="enableMultiMetrics") ] = None - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" - enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_s2_sversion: Annotated[ - Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The highest S2S protocol version to advertise during handshake""" + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + next_queue: Annotated[Optional[str], pydantic.Field(alias="nextQueue")] = None + r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" + + tcp_routing: Annotated[Optional[str], pydantic.Field(alias="tcpRouting")] = None + r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + description: Optional[str] = None + r"""Optional description for this configuration.""" + + url: Optional[str] = None + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[CreateOutputSystemByPackOutputSplunkHecURL]] = None + r"""Splunk HEC Endpoints""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - max_failed_health_checks: Annotated[ - Optional[float], pydantic.Field(alias="maxFailedHealthChecks") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - compress: Optional[CompressionOptions] = None - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + token: Optional[str] = None + r"""Splunk HEC authentication token""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17156,66 +17126,45 @@ class CreateOutputSystemByPackOutputSplunk(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSplunkPqControls], + Optional[CreateOutputSystemByPackOutputSplunkHecPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_nested_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_nestedFields") - ] = None - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - - template_max_s2_sversion: Annotated[ - Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - @field_serializer("nested_fields") - def serialize_nested_fields(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.NestedFieldSerializationOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.MaxS2SVersionOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -17229,24 +17178,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptions(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -17282,20 +17213,36 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "nestedFields", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "loadBalanced", "tls", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", "enableMultiMetrics", - "enableACK", - "logFailedRequests", - "maxS2Sversion", - "onBackpressure", "authType", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "nextQueue", + "tcpRouting", + "onBackpressure", "description", - "maxFailedHealthChecks", - "compress", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17308,15 +17255,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", - "__template_host", - "__template_port", - "__template_nestedFields", - "__template_maxS2Sversion", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_compress", + "__template_url", ] ) serialized = handler(self) @@ -17333,120 +17275,159 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputSyslogProtocol( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""The network protocol to use for sending out syslog messages""" +class CreateOutputSystemByPackOutputSplunkLbType(str, Enum): + r"""Connector type identifier.""" - # TCP - TCP = "tcp" - # UDP - UDP = "udp" + SPLUNK_LB = "splunk_lb" -class CreateOutputSystemByPackFacility(int, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" +class CreateOutputSystemByPackAuthTokenTypedDict(TypedDict): + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" - # kern - KERN = 0 - # user - USER = 1 - # mail - MAIL = 2 - # daemon - DAEMON = 3 - # auth - AUTH = 4 - # syslog - SYSLOG = 5 - # lpr - LPR = 6 - # news - NEWS = 7 - # uucp - UUCP = 8 - # cron - CRON = 9 - # authpriv - AUTHPRIV = 10 - # ftp - FTP = 11 - # ntp - NTP = 12 - # security - SECURITY = 13 - # console - CONSOLE = 14 - # solaris-cron - SOLARIS_CRON = 15 - # local0 - LOCAL0 = 16 - # local1 - LOCAL1 = 17 - # local2 - LOCAL2 = 18 - # local3 - LOCAL3 = 19 - # local4 - LOCAL4 = 20 - # local5 - LOCAL5 = 21 +class CreateOutputSystemByPackAuthToken(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "authToken", "textSecret"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict(TypedDict): + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + site: str + r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" + master_uri: str + r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" + refresh_interval_sec: float + r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" + reject_unauthorized: NotRequired[bool] + r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" + auth_tokens: NotRequired[List[CreateOutputSystemByPackAuthTokenTypedDict]] + r"""Tokens required to authenticate to cluster manager for indexer discovery""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class CreateOutputSystemByPackIndexerDiscoveryConfigs(BaseModel): + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + site: str + r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" + + master_uri: Annotated[str, pydantic.Field(alias="masterUri")] + r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" + + refresh_interval_sec: Annotated[float, pydantic.Field(alias="refreshIntervalSec")] + r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" -class CreateOutputSystemByPackOutputSyslogSeverity( - int, Enum, metaclass=utils.OpenEnumMeta -): - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" - # emergency - EMERGENCY = 0 - # alert - ALERT = 1 - # critical - CRITICAL = 2 - # error - ERROR = 3 - # warning - WARNING = 4 - # notice - NOTICE = 5 - # info - INFO = 6 - # debug - DEBUG = 7 + auth_tokens: Annotated[ + Optional[List[CreateOutputSystemByPackAuthToken]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Tokens required to authenticate to cluster manager for indexer discovery""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" -class CreateOutputSystemByPackMessageFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The syslog message format depending on the receiver's support""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - # RFC3164 - RFC3164 = "rfc3164" - # RFC5424 - RFC5424 = "rfc5424" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value -class CreateOutputSystemByPackTimestampFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Timestamp format to use when serializing event's time field""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["rejectUnauthorized", "authTokens", "authType", "authToken", "textSecret"] + ) + serialized = handler(self) + m = {} - # Syslog - SYSLOG = "syslog" - # ISO8601 - ISO8601 = "iso8601" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m -class CreateOutputSystemByPackOutputSyslogPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSyslogPqControls(BaseModel): +class CreateOutputSystemByPackOutputSplunkLbPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSyslogTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSplunkLbTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: TypeOptionsSyslog + type: CreateOutputSystemByPackOutputSplunkLbType r"""Connector type identifier.""" + hosts: List[HostConfOutputSyslogTypedDict] + r"""Set of Splunk indexers to load-balance data to.""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -17455,56 +17436,50 @@ class CreateOutputSystemByPackOutputSyslogTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[CreateOutputSystemByPackOutputSyslogProtocol] - r"""The network protocol to use for sending out syslog messages""" - facility: NotRequired[CreateOutputSystemByPackFacility] - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - severity: NotRequired[CreateOutputSystemByPackOutputSyslogSeverity] - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - app_name: NotRequired[str] - r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - message_format: NotRequired[CreateOutputSystemByPackMessageFormat] - r"""The syslog message format depending on the receiver's support""" - timestamp_format: NotRequired[CreateOutputSystemByPackTimestampFormat] - r"""Timestamp format to use when serializing event's time field""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - octet_count_framing: NotRequired[bool] - r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - load_balanced: NotRequired[bool] - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" max_concurrent_senders: NotRequired[float] r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + nested_fields: NotRequired[NestedFieldSerializationOptions] + r"""How to serialize nested fields into index-time fields""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" connection_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" write_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" + enable_multi_metrics: NotRequired[bool] + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + enable_ack: NotRequired[bool] + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + max_s2_sversion: NotRequired[MaxS2SVersionOptions] + r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - max_record_size: NotRequired[float] - r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" - udp_dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + indexer_discovery: NotRequired[bool] + r"""Automatically discover indexers in indexer clustering environment.""" + sender_unhealthy_time_allowance: NotRequired[float] + r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + max_failed_health_checks: NotRequired[float] + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + compress: NotRequired[CompressionOptions] + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + indexer_discovery_configs: NotRequired[ + CreateOutputSystemByPackIndexerDiscoveryConfigsTypedDict + ] + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -17527,25 +17502,34 @@ class CreateOutputSystemByPackOutputSyslogTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSyslogPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSplunkLbPqControlsTypedDict] r"""Persistent queue controls.""" + auth_token: NotRequired[str] + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_nested_fields: NotRequired[str] + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + template_max_s2_sversion: NotRequired[str] + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" -class CreateOutputSystemByPackOutputSyslog(BaseModel): +class CreateOutputSystemByPackOutputSplunkLb(BaseModel): id: str r"""Unique ID for this output""" - type: TypeOptionsSyslog + type: CreateOutputSystemByPackOutputSplunkLbType r"""Connector type identifier.""" + hosts: List[HostConfOutputSyslog] + r"""Set of Splunk indexers to load-balance data to.""" + pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -17560,65 +17544,6 @@ class CreateOutputSystemByPackOutputSyslog(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[CreateOutputSystemByPackOutputSyslogProtocol] = None - r"""The network protocol to use for sending out syslog messages""" - - facility: Optional[CreateOutputSystemByPackFacility] = None - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - - severity: Optional[CreateOutputSystemByPackOutputSyslogSeverity] = None - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - - app_name: Annotated[Optional[str], pydantic.Field(alias="appName")] = None - r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - - message_format: Annotated[ - Optional[CreateOutputSystemByPackMessageFormat], - pydantic.Field(alias="messageFormat"), - ] = None - r"""The syslog message format depending on the receiver's support""" - - timestamp_format: Annotated[ - Optional[CreateOutputSystemByPackTimestampFormat], - pydantic.Field(alias="timestampFormat"), - ] = None - r"""Timestamp format to use when serializing event's time field""" - - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") - ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - - octet_count_framing: Annotated[ - Optional[bool], pydantic.Field(alias="octetCountFraming") - ] = None - r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") - ] = None - r"""Use to troubleshoot issues with sending data""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - - host: Optional[str] = None - r"""The hostname of the receiver""" - - port: Optional[float] = None - r"""The port to connect to on the provided host""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" - dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None @@ -17634,6 +17559,16 @@ class CreateOutputSystemByPackOutputSyslog(BaseModel): ] = None r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + nested_fields: Annotated[ + Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + ] = None + r"""How to serialize nested fields into index-time fields""" + + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") + ] = None + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: Annotated[ Optional[float], pydantic.Field(alias="connectionTimeout") ] = None @@ -17647,25 +17582,64 @@ class CreateOutputSystemByPackOutputSyslog(BaseModel): tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None r"""TLS settings (client side)""" + enable_multi_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="enableMultiMetrics") + ] = None + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + + enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") + ] = None + r"""Use to troubleshoot issues with sending data""" + + max_s2_sversion: Annotated[ + Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + ] = None + r"""The highest S2S protocol version to advertise during handshake""" + on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") + indexer_discovery: Annotated[ + Optional[bool], pydantic.Field(alias="indexerDiscovery") ] = None - r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" + r"""Automatically discover indexers in indexer clustering environment.""" - udp_dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="udpDnsResolvePeriodSec") + sender_unhealthy_time_allowance: Annotated[ + Optional[float], pydantic.Field(alias="senderUnhealthyTimeAllowance") ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" + r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + max_failed_health_checks: Annotated[ + Optional[float], pydantic.Field(alias="maxFailedHealthChecks") + ] = None + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + + compress: Optional[CompressionOptions] = None + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + + indexer_discovery_configs: Annotated[ + Optional[CreateOutputSystemByPackIndexerDiscoveryConfigs], + pydantic.Field(alias="indexerDiscoveryConfigs"), + ] = None + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17717,81 +17691,83 @@ class CreateOutputSystemByPackOutputSyslog(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSyslogPqControls], + Optional[CreateOutputSystemByPackOutputSplunkLbPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_nested_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_nestedFields") + ] = None + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_max_s2_sversion: Annotated[ + Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + ] = None + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.CreateOutputSystemByPackOutputSyslogProtocol(value) - except ValueError: - return value - return value + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - @field_serializer("facility") - def serialize_facility(self, value): + @field_serializer("nested_fields") + def serialize_nested_fields(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackFacility(value) + return models.NestedFieldSerializationOptions(value) except ValueError: return value return value - @field_serializer("severity") - def serialize_severity(self, value): + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputSyslogSeverity(value) + return models.MaxS2SVersionOptions(value) except ValueError: return value return value - @field_serializer("message_format") - def serialize_message_format(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackMessageFormat(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("timestamp_format") - def serialize_timestamp_format(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackTimestampFormat(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptions(value) except ValueError: return value return value @@ -17831,31 +17807,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "facility", - "severity", - "appName", - "messageFormat", - "timestampFormat", - "throttleRatePerSec", - "octetCountFraming", - "logFailedRequests", - "description", - "loadBalanced", - "host", - "port", - "excludeSelf", - "hosts", "dnsResolvePeriodSec", "loadBalanceStatsPeriodSec", "maxConcurrentSenders", + "nestedFields", + "throttleRatePerSec", "connectionTimeout", "writeTimeout", "tls", + "enableMultiMetrics", + "enableACK", + "logFailedRequests", + "maxS2Sversion", "onBackpressure", - "maxRecordSize", - "udpDnsResolvePeriodSec", - "enableIpSpoofing", + "indexerDiscovery", + "senderUnhealthyTimeAllowance", + "authType", + "description", + "maxFailedHealthChecks", + "compress", + "indexerDiscoveryConfigs", + "excludeSelf", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17868,10 +17840,13 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "authToken", + "textSecret", "__template_streamtags", - "__template_host", - "__template_port", + "__template_nestedFields", + "__template_maxS2Sversion", "__template_onBackpressure", + "__template_compress", ] ) serialized = handler(self) @@ -17888,133 +17863,23 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputDevnullType(str, Enum): - r"""Connector type identifier.""" - - DEVNULL = "devnull" - - -class CreateOutputSystemByPackOutputDevnullTypedDict(TypedDict): - id: str - r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputDevnullType - r"""Connector type identifier.""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - -class CreateOutputSystemByPackOutputDevnull(BaseModel): - id: str - r"""Unique ID for this output""" - - type: CreateOutputSystemByPackOutputDevnullType - r"""Connector type identifier.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "__template_streamtags", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class CreateOutputSystemByPackOutputSentinelType(str, Enum): - r"""Connector type identifier.""" - - SENTINEL = "sentinel" - - -class CreateOutputSystemByPackAuthType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Discriminator value.""" - - OAUTH = "oauth" - - -class CreateOutputSystemByPackEndpointConfiguration( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter the data collection endpoint URL or the individual ID""" - - # URL - URL = "url" - # ID - ID = "ID" - - -class CreateOutputSystemByPackOutputSentinelFormat( - str, Enum, metaclass=utils.OpenEnumMeta -): - NDJSON = "ndjson" - JSON_ARRAY = "json_array" - CUSTOM = "custom" - ADVANCED = "advanced" - - -class CreateOutputSystemByPackOutputSentinelPqControlsTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSplunkPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSentinelPqControls(BaseModel): +class CreateOutputSystemByPackOutputSplunkPqControls(BaseModel): r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputSentinelTypedDict(TypedDict): +class CreateOutputSystemByPackOutputSplunkTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSentinelType + type: TypeOptionsSplunk r"""Connector type identifier.""" - login_url: str - r"""URL for OAuth""" - secret: str - r"""Secret parameter value to pass in request body""" - client_id: str - r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" - endpoint_url_configuration: CreateOutputSystemByPackEndpointConfiguration - r"""Enter the data collection endpoint URL or the individual ID""" + host: str + r"""The hostname of the receiver""" + port: float + r"""The port to connect to on the provided host""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -18023,79 +17888,34 @@ class CreateOutputSystemByPackOutputSentinelTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + nested_fields: NotRequired[NestedFieldSerializationOptions] + r"""How to serialize nested fields into index-time fields""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + enable_multi_metrics: NotRequired[bool] + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + enable_ack: NotRequired[bool] + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + max_s2_sversion: NotRequired[MaxS2SVersionOptions] + r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputSystemByPackAuthType] - r"""Discriminator value.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - scope: NotRequired[str] - r"""Scope to pass in the OAuth request""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - format_: NotRequired[CreateOutputSystemByPackOutputSentinelFormat] - custom_source_expression: NotRequired[str] - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" - custom_drop_when_null: NotRequired[bool] - r"""Whether to drop events when the source expression evaluates to null""" - custom_event_delimiter: NotRequired[str] - r"""Delimiter string to insert between individual events. Defaults to newline character.""" - custom_content_type: NotRequired[str] - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" - custom_payload_expression: NotRequired[str] - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" - advanced_content_type: NotRequired[str] - r"""HTTP content-type header value""" - format_event_code: NotRequired[str] - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" - format_payload_code: NotRequired[str] - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + max_failed_health_checks: NotRequired[float] + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + compress: NotRequired[CompressionOptions] + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -18118,239 +17938,117 @@ class CreateOutputSystemByPackOutputSentinelTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputSentinelPqControlsTypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSplunkPqControlsTypedDict] r"""Persistent queue controls.""" - url: NotRequired[str] - r"""URL to send events to. Can be overwritten by an event's __url field.""" - dcr_id: NotRequired[str] - r"""Immutable ID for the Data Collection Rule (DCR)""" - dce_endpoint: NotRequired[str] - r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" - stream_name: NotRequired[str] - r"""The name of the stream (Sentinel table) in which to store the events""" + auth_token: NotRequired[str] + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_nested_fields: NotRequired[str] + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + template_max_s2_sversion: NotRequired[str] + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: NotRequired[str] - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" - template_scope: NotRequired[str] - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_dcr_id: NotRequired[str] - r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" - template_dce_endpoint: NotRequired[str] - r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" -class CreateOutputSystemByPackOutputSentinel(BaseModel): +class CreateOutputSystemByPackOutputSplunk(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputSentinelType - r"""Connector type identifier.""" - - login_url: Annotated[str, pydantic.Field(alias="loginUrl")] - r"""URL for OAuth""" - - secret: str - r"""Secret parameter value to pass in request body""" - - client_id: str - r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" - - endpoint_url_configuration: Annotated[ - CreateOutputSystemByPackEndpointConfiguration, - pydantic.Field(alias="endpointURLConfiguration"), - ] - r"""Enter the data collection endpoint URL or the individual ID""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + type: TypeOptionsSplunk + r"""Connector type identifier.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" + host: str + r"""The hostname of the receiver""" - auth_type: Annotated[ - Optional[CreateOutputSystemByPackAuthType], pydantic.Field(alias="authType") - ] = None - r"""Discriminator value.""" + port: float + r"""The port to connect to on the provided host""" - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") - ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + nested_fields: Annotated[ + Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + r"""How to serialize nested fields into index-time fields""" - scope: Optional[str] = None - r"""Scope to pass in the OAuth request""" + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") + ] = None + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - format_: Annotated[ - Optional[CreateOutputSystemByPackOutputSentinelFormat], - pydantic.Field(alias="format"), - ] = None + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - custom_source_expression: Annotated[ - Optional[str], pydantic.Field(alias="customSourceExpression") + enable_multi_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="enableMultiMetrics") ] = None - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - custom_drop_when_null: Annotated[ - Optional[bool], pydantic.Field(alias="customDropWhenNull") - ] = None - r"""Whether to drop events when the source expression evaluates to null""" + enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - custom_event_delimiter: Annotated[ - Optional[str], pydantic.Field(alias="customEventDelimiter") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Delimiter string to insert between individual events. Defaults to newline character.""" + r"""Use to troubleshoot issues with sending data""" - custom_content_type: Annotated[ - Optional[str], pydantic.Field(alias="customContentType") + max_s2_sversion: Annotated[ + Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") ] = None - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + r"""The highest S2S protocol version to advertise during handshake""" - custom_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="customPayloadExpression") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + r"""How to handle events when all receivers are exerting backpressure""" - advanced_content_type: Annotated[ - Optional[str], pydantic.Field(alias="advancedContentType") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""HTTP content-type header value""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - format_event_code: Annotated[ - Optional[str], pydantic.Field(alias="formatEventCode") - ] = None - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - format_payload_code: Annotated[ - Optional[str], pydantic.Field(alias="formatPayloadCode") + max_failed_health_checks: Annotated[ + Optional[float], pydantic.Field(alias="maxFailedHealthChecks") ] = None - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + + compress: Optional[CompressionOptions] = None + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18402,124 +18100,93 @@ class CreateOutputSystemByPackOutputSentinel(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputSentinelPqControls], + Optional[CreateOutputSystemByPackOutputSplunkPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - url: Optional[str] = None - r"""URL to send events to. Can be overwritten by an event's __url field.""" - - dcr_id: Annotated[Optional[str], pydantic.Field(alias="dcrID")] = None - r"""Immutable ID for the Data Collection Rule (DCR)""" - - dce_endpoint: Annotated[Optional[str], pydantic.Field(alias="dceEndpoint")] = None - r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - stream_name: Annotated[Optional[str], pydantic.Field(alias="streamName")] = None - r"""The name of the stream (Sentinel table) in which to store the events""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - - template_refresh_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_refreshUrl") - ] = None - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_client_id") - ] = None - r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" - - template_scope: Annotated[ - Optional[str], pydantic.Field(alias="__template_scope") - ] = None - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_dcr_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_dcrID") + template_nested_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_nestedFields") ] = None - r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_dce_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_dceEndpoint") + template_max_s2_sversion: Annotated[ + Optional[str], pydantic.Field(alias="__template_maxS2Sversion") ] = None - r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + @field_serializer("nested_fields") + def serialize_nested_fields(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.NestedFieldSerializationOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.MaxS2SVersionOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackAuthType(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("endpoint_url_configuration") - def serialize_endpoint_url_configuration(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackEndpointConfiguration(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputSentinelFormat(value) + return models.CompressionOptions(value) except ValueError: return value return value @@ -18548,51 +18215,31 @@ def serialize_pq_on_backpressure(self, value): try: return models.QueueFullBehaviorOptions(value) except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "pipeline", - "systemFields", - "environment", - "streamtags", - "keepAlive", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "nestedFields", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "tls", + "enableMultiMetrics", + "enableACK", + "logFailedRequests", + "maxS2Sversion", "onBackpressure", "authType", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "scope", - "totalMemoryLimitKB", "description", - "format", - "customSourceExpression", - "customDropWhenNull", - "customEventDelimiter", - "customContentType", - "customPayloadExpression", - "advancedContentType", - "formatEventCode", - "formatPayloadCode", + "maxFailedHealthChecks", + "compress", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -18605,22 +18252,15 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "url", - "dcrID", - "dceEndpoint", - "streamName", + "authToken", + "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_host", + "__template_port", + "__template_nestedFields", + "__template_maxS2Sversion", "__template_onBackpressure", - "__template_loginUrl", - "__template_secret", - "__template_refreshUrl", - "__template_client_id", - "__template_scope", - "__template_url", - "__template_dcrID", - "__template_dceEndpoint", - "__template_streamName", + "__template_compress", ] ) serialized = handler(self) @@ -18637,175 +18277,178 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputWebhookType2(str, Enum): - r"""Connector type identifier.""" - - WEBHOOK = "webhook" - - -class CreateOutputSystemByPackOutputWebhookFormat2( +class CreateOutputSystemByPackOutputSyslogProtocol( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""How to format events before sending out""" - - # NDJSON (Newline Delimited JSON) - NDJSON = "ndjson" - # JSON Array - JSON_ARRAY = "json_array" - # Custom - CUSTOM = "custom" - # Advanced - ADVANCED = "advanced" + r"""The network protocol to use for sending out syslog messages""" + # TCP + TCP = "tcp" + # UDP + UDP = "udp" -class CreateOutputSystemByPackOutputWebhookAuthenticationType2( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method to use for the HTTP request""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth - OAUTH = "oauth" +class CreateOutputSystemByPackFacility(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" + # kern + KERN = 0 + # user + USER = 1 + # mail + MAIL = 2 + # daemon + DAEMON = 3 + # auth + AUTH = 4 + # syslog + SYSLOG = 5 + # lpr + LPR = 6 + # news + NEWS = 7 + # uucp + UUCP = 8 + # cron + CRON = 9 + # authpriv + AUTHPRIV = 10 + # ftp + FTP = 11 + # ntp + NTP = 12 + # security + SECURITY = 13 + # console + CONSOLE = 14 + # solaris-cron + SOLARIS_CRON = 15 + # local0 + LOCAL0 = 16 + # local1 + LOCAL1 = 17 + # local2 + LOCAL2 = 18 + # local3 + LOCAL3 = 19 + # local4 + LOCAL4 = 20 + # local5 + LOCAL5 = 21 -class CreateOutputSystemByPackOutputWebhookPqControls2TypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputSystemByPackOutputSyslogSeverity( + int, Enum, metaclass=utils.OpenEnumMeta +): + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" -class CreateOutputSystemByPackOutputWebhookPqControls2(BaseModel): - r"""Persistent queue controls.""" + # emergency + EMERGENCY = 0 + # alert + ALERT = 1 + # critical + CRITICAL = 2 + # error + ERROR = 3 + # warning + WARNING = 4 + # notice + NOTICE = 5 + # info + INFO = 6 + # debug + DEBUG = 7 -class CreateOutputSystemByPackOutputWebhookURL2TypedDict(TypedDict): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" +class CreateOutputSystemByPackMessageFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The syslog message format depending on the receiver's support""" + # RFC3164 + RFC3164 = "rfc3164" + # RFC5424 + RFC5424 = "rfc5424" -class CreateOutputSystemByPackOutputWebhookURL2(BaseModel): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" +class CreateOutputSystemByPackTimestampFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Timestamp format to use when serializing event's time field""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + # Syslog + SYSLOG = "syslog" + # ISO8601 + ISO8601 = "iso8601" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class CreateOutputSystemByPackOutputSyslogPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - return m +class CreateOutputSystemByPackOutputSyslogPqControls(BaseModel): + r"""Persistent queue controls.""" -class CreateOutputSystemByPackOutputWebhookWebhook2TypedDict(TypedDict): +class CreateOutputSystemByPackOutputSyslogTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWebhookType2 + type: TypeOptionsSyslog r"""Connector type identifier.""" - urls: List[CreateOutputSystemByPackOutputWebhookURL2TypedDict] - r"""Webhook URLs""" pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - format_: NotRequired[CreateOutputSystemByPackOutputWebhookFormat2] - r"""How to format events before sending out""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputSystemByPackOutputWebhookAuthenticationType2] - r"""Authentication method to use for the HTTP request""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + protocol: NotRequired[CreateOutputSystemByPackOutputSyslogProtocol] + r"""The network protocol to use for sending out syslog messages""" + facility: NotRequired[CreateOutputSystemByPackFacility] + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" + severity: NotRequired[CreateOutputSystemByPackOutputSyslogSeverity] + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" + app_name: NotRequired[str] + r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" + message_format: NotRequired[CreateOutputSystemByPackMessageFormat] + r"""The syslog message format depending on the receiver's support""" + timestamp_format: NotRequired[CreateOutputSystemByPackTimestampFormat] + r"""Timestamp format to use when serializing event's time field""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + octet_count_framing: NotRequired[bool] + r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_source_expression: NotRequired[str] - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" - custom_drop_when_null: NotRequired[bool] - r"""Whether to drop events when the source expression evaluates to null""" - custom_event_delimiter: NotRequired[str] - r"""Delimiter string to insert between individual events. Defaults to newline character.""" - custom_content_type: NotRequired[str] - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" - custom_payload_expression: NotRequired[str] - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" - advanced_content_type: NotRequired[str] - r"""HTTP content-type header value""" - format_event_code: NotRequired[str] - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" - format_payload_code: NotRequired[str] - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + load_balanced: NotRequired[bool] + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + max_record_size: NotRequired[float] + r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" + udp_dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -18828,78 +18471,25 @@ class CreateOutputSystemByPackOutputWebhookWebhook2TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputWebhookPqControls2TypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSyslogPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" - secret: NotRequired[str] - r"""Secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - url: NotRequired[str] - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: NotRequired[str] - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class CreateOutputSystemByPackOutputWebhookWebhook2(BaseModel): +class CreateOutputSystemByPackOutputSyslog(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWebhookType2 + type: TypeOptionsSyslog r"""Connector type identifier.""" - urls: List[CreateOutputSystemByPackOutputWebhookURL2] - r"""Webhook URLs""" - pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -18914,158 +18504,112 @@ class CreateOutputSystemByPackOutputWebhookWebhook2(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" - - format_: Annotated[ - Optional[CreateOutputSystemByPackOutputWebhookFormat2], - pydantic.Field(alias="format"), - ] = None - r"""How to format events before sending out""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + protocol: Optional[CreateOutputSystemByPackOutputSyslogProtocol] = None + r"""The network protocol to use for sending out syslog messages""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + facility: Optional[CreateOutputSystemByPackFacility] = None + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + severity: Optional[CreateOutputSystemByPackOutputSyslogSeverity] = None + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + app_name: Annotated[Optional[str], pydantic.Field(alias="appName")] = None + r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + message_format: Annotated[ + Optional[CreateOutputSystemByPackMessageFormat], + pydantic.Field(alias="messageFormat"), ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""The syslog message format depending on the receiver's support""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + timestamp_format: Annotated[ + Optional[CreateOutputSystemByPackTimestampFormat], + pydantic.Field(alias="timestampFormat"), ] = None + r"""Timestamp format to use when serializing event's time field""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + octet_count_framing: Annotated[ + Optional[bool], pydantic.Field(alias="octetCountFraming") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputWebhookAuthenticationType2], - pydantic.Field(alias="authType"), + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Authentication method to use for the HTTP request""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + r"""Use to troubleshoot issues with sending data""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + host: Optional[str] = None + r"""The hostname of the receiver""" - custom_source_expression: Annotated[ - Optional[str], pydantic.Field(alias="customSourceExpression") + port: Optional[float] = None + r"""The port to connect to on the provided host""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - custom_drop_when_null: Annotated[ - Optional[bool], pydantic.Field(alias="customDropWhenNull") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Whether to drop events when the source expression evaluates to null""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - custom_event_delimiter: Annotated[ - Optional[str], pydantic.Field(alias="customEventDelimiter") + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") ] = None - r"""Delimiter string to insert between individual events. Defaults to newline character.""" + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - custom_content_type: Annotated[ - Optional[str], pydantic.Field(alias="customContentType") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - custom_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="customPayloadExpression") + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + r"""How to handle events when all receivers are exerting backpressure""" - advanced_content_type: Annotated[ - Optional[str], pydantic.Field(alias="advancedContentType") + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") ] = None - r"""HTTP content-type header value""" + r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" - format_event_code: Annotated[ - Optional[str], pydantic.Field(alias="formatEventCode") + udp_dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="udpDnsResolvePeriodSec") ] = None - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" - format_payload_code: Annotated[ - Optional[str], pydantic.Field(alias="formatPayloadCode") + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") ] = None - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19117,179 +18661,81 @@ class CreateOutputSystemByPackOutputWebhookWebhook2(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputWebhookPqControls2], + Optional[CreateOutputSystemByPackOutputSyslogPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - - secret: Optional[str] = None - r"""Secret parameter value to pass in request body""" - - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") - ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") - ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), - ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - - url: Optional[str] = None - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - - template_refresh_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_refreshUrl") - ] = None - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputSyslogProtocol(value) + except ValueError: + return value + return value - @field_serializer("method") - def serialize_method(self, value): + @field_serializer("facility") + def serialize_facility(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.CreateOutputSystemByPackFacility(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("severity") + def serialize_severity(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputWebhookFormat2(value) + return models.CreateOutputSystemByPackOutputSyslogSeverity(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CreateOutputSystemByPackMessageFormat(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("timestamp_format") + def serialize_timestamp_format(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputSystemByPackTimestampFormat(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputWebhookAuthenticationType2( - value - ) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -19329,78 +18775,47 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "format", - "keepAlive", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "tls", - "totalMemoryLimitKB", - "loadBalanced", + "protocol", + "facility", + "severity", + "appName", + "messageFormat", + "timestampFormat", + "throttleRatePerSec", + "octetCountFraming", + "logFailedRequests", "description", - "customSourceExpression", - "customDropWhenNull", - "customEventDelimiter", - "customContentType", - "customPayloadExpression", - "advancedContentType", - "formatEventCode", - "formatPayloadCode", + "loadBalanced", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", + "connectionTimeout", + "writeTimeout", + "tls", + "onBackpressure", + "maxRecordSize", + "udpDnsResolvePeriodSec", + "enableIpSpoofing", "pqStrictOrdering", "pqRatePerSec", "pqMode", "pqMaxBufferSize", "pqMaxBackpressureSec", "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", - "secret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "url", - "excludeSelf", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_host", + "__template_port", "__template_onBackpressure", - "__template_loginUrl", - "__template_secret", - "__template_refreshUrl", - "__template_url", ] ) serialized = handler(self) @@ -19417,78 +18832,66 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputWebhookType1(str, Enum): +class CreateOutputSystemByPackOutputDevnullType(str, Enum): r"""Connector type identifier.""" - WEBHOOK = "webhook" - - -class CreateOutputSystemByPackOutputWebhookFormat1( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""How to format events before sending out""" - - # NDJSON (Newline Delimited JSON) - NDJSON = "ndjson" - # JSON Array - JSON_ARRAY = "json_array" - # Custom - CUSTOM = "custom" - # Advanced - ADVANCED = "advanced" - - -class CreateOutputSystemByPackOutputWebhookAuthenticationType1( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method to use for the HTTP request""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth - OAUTH = "oauth" + DEVNULL = "devnull" -class CreateOutputSystemByPackOutputWebhookPqControls1TypedDict(TypedDict): - r"""Persistent queue controls.""" +class CreateOutputSystemByPackOutputDevnullTypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputDevnullType + r"""Connector type identifier.""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class CreateOutputSystemByPackOutputWebhookPqControls1(BaseModel): - r"""Persistent queue controls.""" +class CreateOutputSystemByPackOutputDevnull(BaseModel): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputDevnullType + r"""Connector type identifier.""" -class CreateOutputSystemByPackOutputWebhookURL1TypedDict(TypedDict): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" -class CreateOutputSystemByPackOutputWebhookURL1(BaseModel): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "__template_streamtags", + ] + ) serialized = handler(self) m = {} @@ -19503,13 +18906,66 @@ def serialize_model(self, handler): return m -class CreateOutputSystemByPackOutputWebhookWebhook1TypedDict(TypedDict): +class CreateOutputSystemByPackOutputSentinelType(str, Enum): + r"""Connector type identifier.""" + + SENTINEL = "sentinel" + + +class CreateOutputSystemByPackAuthType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Discriminator value.""" + + OAUTH = "oauth" + + +class CreateOutputSystemByPackOAuthSecretSource( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter the OAuth secret directly, or select a stored text secret""" + + INLINE = "inline" + SECRET = "secret" + + +class CreateOutputSystemByPackEndpointConfiguration( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter the data collection endpoint URL or the individual ID""" + + # URL + URL = "url" + # ID + ID = "ID" + + +class CreateOutputSystemByPackOutputSentinelFormat( + str, Enum, metaclass=utils.OpenEnumMeta +): + NDJSON = "ndjson" + JSON_ARRAY = "json_array" + CUSTOM = "custom" + ADVANCED = "advanced" + + +class CreateOutputSystemByPackOutputSentinelPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputSentinelPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputSentinelTypedDict(TypedDict): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWebhookType1 + type: CreateOutputSystemByPackOutputSentinelType r"""Connector type identifier.""" - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + login_url: str + r"""URL for OAuth""" + client_id: str + r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" + endpoint_url_configuration: CreateOutputSystemByPackEndpointConfiguration + r"""Enter the data collection endpoint URL or the individual ID""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] @@ -19518,16 +18974,12 @@ class CreateOutputSystemByPackOutputWebhookWebhook1TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - format_: NotRequired[CreateOutputSystemByPackOutputWebhookFormat1] - r"""How to format events before sending out""" keep_alive: NotRequired[bool] r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: NotRequired[bool] @@ -19560,16 +19012,27 @@ class CreateOutputSystemByPackOutputWebhookWebhook1TypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[CreateOutputSystemByPackOutputWebhookAuthenticationType1] - r"""Authentication method to use for the HTTP request""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + auth_type: NotRequired[CreateOutputSystemByPackAuthType] + r"""Discriminator value.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + oauth_secret_source: NotRequired[CreateOutputSystemByPackOAuthSecretSource] + r"""Enter the OAuth secret directly, or select a stored text secret""" + scope: NotRequired[str] + r"""Scope to pass in the OAuth request""" total_memory_limit_kb: NotRequired[float] r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" description: NotRequired[str] r"""Optional description for this configuration.""" + format_: NotRequired[CreateOutputSystemByPackOutputSentinelFormat] custom_source_expression: NotRequired[str] r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" custom_drop_when_null: NotRequired[bool] @@ -19608,52 +19071,20 @@ class CreateOutputSystemByPackOutputWebhookWebhook1TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[CreateOutputSystemByPackOutputWebhookPqControls1TypedDict] + pq_controls: NotRequired[CreateOutputSystemByPackOutputSentinelPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" secret: NotRequired[str] r"""Secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[CreateOutputSystemByPackOutputWebhookURL1TypedDict]] - r"""Webhook URLs""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret value""" + url: NotRequired[str] + r"""URL to send events to. Can be overwritten by an event's __url field.""" + dcr_id: NotRequired[str] + r"""Immutable ID for the Data Collection Rule (DCR)""" + dce_endpoint: NotRequired[str] + r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" + stream_name: NotRequired[str] + r"""The name of the stream (Sentinel table) in which to store the events""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] @@ -19662,23 +19093,42 @@ class CreateOutputSystemByPackOutputWebhookWebhook1TypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_login_url: NotRequired[str] r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_refresh_url: NotRequired[str] r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" + template_scope: NotRequired[str] + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_url: NotRequired[str] r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_dcr_id: NotRequired[str] + r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + template_dce_endpoint: NotRequired[str] + r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" -class CreateOutputSystemByPackOutputWebhookWebhook1(BaseModel): +class CreateOutputSystemByPackOutputSentinel(BaseModel): id: str r"""Unique ID for this output""" - type: CreateOutputSystemByPackOutputWebhookType1 + type: CreateOutputSystemByPackOutputSentinelType r"""Connector type identifier.""" - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + login_url: Annotated[str, pydantic.Field(alias="loginUrl")] + r"""URL for OAuth""" + + client_id: str + r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" + + endpoint_url_configuration: Annotated[ + CreateOutputSystemByPackEndpointConfiguration, + pydantic.Field(alias="endpointURLConfiguration"), + ] + r"""Enter the data collection endpoint URL or the individual ID""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -19688,20 +19138,11 @@ class CreateOutputSystemByPackOutputWebhookWebhook1(BaseModel): ] = None r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" - - format_: Annotated[ - Optional[CreateOutputSystemByPackOutputWebhookFormat1], - pydantic.Field(alias="format"), - ] = None - r"""How to format events before sending out""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None r"""Disable to close the connection immediately after sending the outgoing request""" @@ -19712,7 +19153,7 @@ class CreateOutputSystemByPackOutputWebhookWebhook1(BaseModel): max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") @@ -19786,27 +19227,51 @@ class CreateOutputSystemByPackOutputWebhookWebhook1(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[CreateOutputSystemByPackOutputWebhookAuthenticationType1], - pydantic.Field(alias="authType"), + Optional[CreateOutputSystemByPackAuthType], pydantic.Field(alias="authType") ] = None - r"""Authentication method to use for the HTTP request""" + r"""Discriminator value.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + oauth_secret_source: Annotated[ + Optional[CreateOutputSystemByPackOAuthSecretSource], + pydantic.Field(alias="oauthSecretSource"), + ] = None + r"""Enter the OAuth secret directly, or select a stored text secret""" + + scope: Optional[str] = None + r"""Scope to pass in the OAuth request""" total_memory_limit_kb: Annotated[ Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - description: Optional[str] = None r"""Optional description for this configuration.""" + format_: Annotated[ + Optional[CreateOutputSystemByPackOutputSentinelFormat], + pydantic.Field(alias="format"), + ] = None + custom_source_expression: Annotated[ Optional[str], pydantic.Field(alias="customSourceExpression") ] = None @@ -19897,100 +19362,30 @@ class CreateOutputSystemByPackOutputWebhookWebhook1(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[CreateOutputSystemByPackOutputWebhookPqControls1], + Optional[CreateOutputSystemByPackOutputSentinelPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - secret: Optional[str] = None r"""Secret parameter value to pass in request body""" - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") - ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") - ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + r"""Select or create a stored text secret for the OAuth secret value""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + url: Optional[str] = None + r"""URL to send events to. Can be overwritten by an event's __url field.""" - urls: Optional[List[CreateOutputSystemByPackOutputWebhookURL1]] = None - r"""Webhook URLs""" + dcr_id: Annotated[Optional[str], pydantic.Field(alias="dcrID")] = None + r"""Immutable ID for the Data Collection Rule (DCR)""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + dce_endpoint: Annotated[Optional[str], pydantic.Field(alias="dceEndpoint")] = None + r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + stream_name: Annotated[Optional[str], pydantic.Field(alias="streamName")] = None + r"""The name of the stream (Sentinel table) in which to store the events""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") @@ -20012,64 +19407,96 @@ class CreateOutputSystemByPackOutputWebhookWebhook1(BaseModel): ] = None r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: Annotated[ Optional[str], pydantic.Field(alias="__template_refreshUrl") ] = None r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_client_id") + ] = None + r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" + + template_scope: Annotated[ + Optional[str], pydantic.Field(alias="__template_scope") + ] = None + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - @field_serializer("method") - def serialize_method(self, value): + template_dcr_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_dcrID") + ] = None + r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + + template_dce_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_dceEndpoint") + ] = None + r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") + ] = None + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputWebhookFormat1(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CreateOutputSystemByPackAuthType(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("oauth_secret_source") + def serialize_oauth_secret_source(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CreateOutputSystemByPackOAuthSecretSource(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("endpoint_url_configuration") + def serialize_endpoint_url_configuration(self, value): if isinstance(value, str): try: - return models.CreateOutputSystemByPackOutputWebhookAuthenticationType1( - value - ) + return models.CreateOutputSystemByPackEndpointConfiguration(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputSentinelFormat(value) except ValueError: return value return value @@ -20109,8 +19536,6 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "format", "keepAlive", "concurrency", "maxPayloadSizeKB", @@ -20129,10 +19554,15 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "authType", - "tls", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "oauthSecretSource", + "scope", "totalMemoryLimitKB", - "loadBalanced", "description", + "format", "customSourceExpression", "customDropWhenNull", "customEventDelimiter", @@ -20153,34 +19583,24 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", "secret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "oauthTextSecret", + "url", + "dcrID", + "dceEndpoint", + "streamName", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", "__template_loginUrl", - "__template_secret", "__template_refreshUrl", + "__template_client_id", + "__template_scope", + "__template_secret", "__template_url", + "__template_dcrID", + "__template_dceEndpoint", + "__template_streamName", ] ) serialized = handler(self) @@ -20197,30 +19617,43 @@ def serialize_model(self, handler): return m -CreateOutputSystemByPackOutputWebhookUnionTypedDict = TypeAliasType( - "CreateOutputSystemByPackOutputWebhookUnionTypedDict", - Union[ - CreateOutputSystemByPackOutputWebhookWebhook1TypedDict, - CreateOutputSystemByPackOutputWebhookWebhook2TypedDict, - ], -) - +class CreateOutputSystemByPackOutputWebhookType2(str, Enum): + r"""Connector type identifier.""" -CreateOutputSystemByPackOutputWebhookUnion = TypeAliasType( - "CreateOutputSystemByPackOutputWebhookUnion", - Union[ - CreateOutputSystemByPackOutputWebhookWebhook1, - CreateOutputSystemByPackOutputWebhookWebhook2, - ], -) + WEBHOOK = "webhook" -class CreateOutputSystemByPackOutputDefaultType(str, Enum): - r"""Connector type identifier.""" +class CreateOutputSystemByPackOutputWebhookFormat2( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""How to format events before sending out""" - DEFAULT = "default" + # NDJSON (Newline Delimited JSON) + NDJSON = "ndjson" + # JSON Array + JSON_ARRAY = "json_array" + # Custom + CUSTOM = "custom" + # Advanced + ADVANCED = "advanced" +try: + CreateOutputSystemByPackOutputSns.model_rebuild() +except NameError: + pass +try: + CreateOutputSystemByPackRule.model_rebuild() +except NameError: + pass +try: + CreateOutputSystemByPackOutputRouter.model_rebuild() +except NameError: + pass +try: + CreateOutputSystemByPackOutputGraphite.model_rebuild() +except NameError: + pass try: CreateOutputSystemByPackOutputStatsdExt.model_rebuild() except NameError: @@ -20393,19 +19826,3 @@ class CreateOutputSystemByPackOutputDefaultType(str, Enum): CreateOutputSystemByPackOutputSentinel.model_rebuild() except NameError: pass -try: - CreateOutputSystemByPackOutputWebhookURL2.model_rebuild() -except NameError: - pass -try: - CreateOutputSystemByPackOutputWebhookWebhook2.model_rebuild() -except NameError: - pass -try: - CreateOutputSystemByPackOutputWebhookURL1.model_rebuild() -except NameError: - pass -try: - CreateOutputSystemByPackOutputWebhookWebhook1.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/createoutputsystembypack_request.py b/src/cribl_control_plane/models/createoutputsystembypack_request.py index daacdc41e..4a3a93c3e 100644 --- a/src/cribl_control_plane/models/createoutputsystembypack_request.py +++ b/src/cribl_control_plane/models/createoutputsystembypack_request.py @@ -1,86 +1,9 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .createoutputsystembypack_outputdefault_type import ( - CreateOutputSystemByPackOutputAzureBlob, - CreateOutputSystemByPackOutputAzureBlobTypedDict, - CreateOutputSystemByPackOutputAzureDataExplorer, - CreateOutputSystemByPackOutputAzureDataExplorerTypedDict, - CreateOutputSystemByPackOutputAzureEventhub, - CreateOutputSystemByPackOutputAzureEventhubTypedDict, - CreateOutputSystemByPackOutputAzureLogs, - CreateOutputSystemByPackOutputAzureLogsTypedDict, - CreateOutputSystemByPackOutputCloudwatch, - CreateOutputSystemByPackOutputCloudwatchTypedDict, - CreateOutputSystemByPackOutputConfluentCloud, - CreateOutputSystemByPackOutputConfluentCloudTypedDict, - CreateOutputSystemByPackOutputDefaultType, - CreateOutputSystemByPackOutputDevnull, - CreateOutputSystemByPackOutputDevnullTypedDict, - CreateOutputSystemByPackOutputElastic, - CreateOutputSystemByPackOutputElasticCloud, - CreateOutputSystemByPackOutputElasticCloudTypedDict, - CreateOutputSystemByPackOutputElasticTypedDict, - CreateOutputSystemByPackOutputExabeam, - CreateOutputSystemByPackOutputExabeamTypedDict, - CreateOutputSystemByPackOutputFilesystem, - CreateOutputSystemByPackOutputFilesystemTypedDict, - CreateOutputSystemByPackOutputGoogleBigquery, - CreateOutputSystemByPackOutputGoogleBigqueryTypedDict, - CreateOutputSystemByPackOutputGoogleChronicle, - CreateOutputSystemByPackOutputGoogleChronicleTypedDict, - CreateOutputSystemByPackOutputGoogleCloudLogging, - CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict, - CreateOutputSystemByPackOutputGoogleCloudObservability, - CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict, - CreateOutputSystemByPackOutputGoogleCloudStorage, - CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict, - CreateOutputSystemByPackOutputGooglePubsub, - CreateOutputSystemByPackOutputGooglePubsubTypedDict, - CreateOutputSystemByPackOutputHoneycomb, - CreateOutputSystemByPackOutputHoneycombTypedDict, - CreateOutputSystemByPackOutputInfluxdb, - CreateOutputSystemByPackOutputInfluxdbTypedDict, - CreateOutputSystemByPackOutputKafka, - CreateOutputSystemByPackOutputKafkaTypedDict, - CreateOutputSystemByPackOutputKinesis, - CreateOutputSystemByPackOutputKinesisTypedDict, - CreateOutputSystemByPackOutputMinio, - CreateOutputSystemByPackOutputMinioTypedDict, - CreateOutputSystemByPackOutputMsk, - CreateOutputSystemByPackOutputMskTypedDict, - CreateOutputSystemByPackOutputNewrelic, - CreateOutputSystemByPackOutputNewrelicEvents, - CreateOutputSystemByPackOutputNewrelicEventsTypedDict, - CreateOutputSystemByPackOutputNewrelicTypedDict, - CreateOutputSystemByPackOutputS3, - CreateOutputSystemByPackOutputS3TypedDict, - CreateOutputSystemByPackOutputSentinel, - CreateOutputSystemByPackOutputSentinelTypedDict, - CreateOutputSystemByPackOutputSignalfx, - CreateOutputSystemByPackOutputSignalfxTypedDict, - CreateOutputSystemByPackOutputSplunk, - CreateOutputSystemByPackOutputSplunkHec, - CreateOutputSystemByPackOutputSplunkHecTypedDict, - CreateOutputSystemByPackOutputSplunkLb, - CreateOutputSystemByPackOutputSplunkLbTypedDict, - CreateOutputSystemByPackOutputSplunkTypedDict, - CreateOutputSystemByPackOutputStatsd, - CreateOutputSystemByPackOutputStatsdExt, - CreateOutputSystemByPackOutputStatsdExtTypedDict, - CreateOutputSystemByPackOutputStatsdTypedDict, - CreateOutputSystemByPackOutputSyslog, - CreateOutputSystemByPackOutputSyslogTypedDict, - CreateOutputSystemByPackOutputTcpjson, - CreateOutputSystemByPackOutputTcpjsonTypedDict, - CreateOutputSystemByPackOutputWavefront, - CreateOutputSystemByPackOutputWavefrontTypedDict, - CreateOutputSystemByPackOutputWebhookUnion, - CreateOutputSystemByPackOutputWebhookUnionTypedDict, - CreateOutputSystemByPackOutputWizHec, - CreateOutputSystemByPackOutputWizHecTypedDict, -) -from .createoutputsystembypack_outputstatsdext_type import ( +from .backpressurebehavioroptions import BackpressureBehaviorOptions +from .compressionoptionspq import CompressionOptionsPq +from .createoutputsystembypack_outputsns_pqcontrols import ( CreateOutputSystemByPackOutputAlibabaCloudS3, CreateOutputSystemByPackOutputAlibabaCloudS3TypedDict, CreateOutputSystemByPackOutputAlphasocS3, @@ -109,6 +32,8 @@ CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict, CreateOutputSystemByPackOutputDatabricks, CreateOutputSystemByPackOutputDatabricksTypedDict, + CreateOutputSystemByPackOutputDatabricksZerobus, + CreateOutputSystemByPackOutputDatabricksZerobusTypedDict, CreateOutputSystemByPackOutputDatadog, CreateOutputSystemByPackOutputDatadogTypedDict, CreateOutputSystemByPackOutputDataset, @@ -125,8 +50,6 @@ CreateOutputSystemByPackOutputDynatraceOtlpTypedDict, CreateOutputSystemByPackOutputGrafanaCloudUnion, CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict, - CreateOutputSystemByPackOutputGraphite, - CreateOutputSystemByPackOutputGraphiteTypedDict, CreateOutputSystemByPackOutputHumioHec, CreateOutputSystemByPackOutputHumioHecTypedDict, CreateOutputSystemByPackOutputIbmCloudS3, @@ -147,8 +70,6 @@ CreateOutputSystemByPackOutputPrometheusTypedDict, CreateOutputSystemByPackOutputRing, CreateOutputSystemByPackOutputRingTypedDict, - CreateOutputSystemByPackOutputRouter, - CreateOutputSystemByPackOutputRouterTypedDict, CreateOutputSystemByPackOutputScalityS3, CreateOutputSystemByPackOutputScalityS3TypedDict, CreateOutputSystemByPackOutputSecurityLake, @@ -161,28 +82,1709 @@ CreateOutputSystemByPackOutputSnmpTypedDict, CreateOutputSystemByPackOutputSnowflakeStreaming, CreateOutputSystemByPackOutputSnowflakeStreamingTypedDict, - CreateOutputSystemByPackOutputSns, - CreateOutputSystemByPackOutputSnsTypedDict, CreateOutputSystemByPackOutputSqs, CreateOutputSystemByPackOutputSqsTypedDict, CreateOutputSystemByPackOutputStorjS3, CreateOutputSystemByPackOutputStorjS3TypedDict, CreateOutputSystemByPackOutputSumoLogic, CreateOutputSystemByPackOutputSumoLogicTypedDict, + CreateOutputSystemByPackOutputTraversalOtlp, + CreateOutputSystemByPackOutputTraversalOtlpTypedDict, CreateOutputSystemByPackOutputXsiam, CreateOutputSystemByPackOutputXsiamTypedDict, ) -from cribl_control_plane.types import BaseModel, Nullable, UNSET_SENTINEL -from cribl_control_plane.utils import ( - FieldMetadata, - PathParamMetadata, - RequestMetadata, - get_discriminator, +from .createoutputsystembypack_outputwebhook_format_2 import ( + CreateOutputSystemByPackOutputAzureBlob, + CreateOutputSystemByPackOutputAzureBlobTypedDict, + CreateOutputSystemByPackOutputAzureDataExplorer, + CreateOutputSystemByPackOutputAzureDataExplorerTypedDict, + CreateOutputSystemByPackOutputAzureEventhub, + CreateOutputSystemByPackOutputAzureEventhubTypedDict, + CreateOutputSystemByPackOutputAzureLogs, + CreateOutputSystemByPackOutputAzureLogsTypedDict, + CreateOutputSystemByPackOutputCloudwatch, + CreateOutputSystemByPackOutputCloudwatchTypedDict, + CreateOutputSystemByPackOutputConfluentCloud, + CreateOutputSystemByPackOutputConfluentCloudTypedDict, + CreateOutputSystemByPackOutputDevnull, + CreateOutputSystemByPackOutputDevnullTypedDict, + CreateOutputSystemByPackOutputElastic, + CreateOutputSystemByPackOutputElasticCloud, + CreateOutputSystemByPackOutputElasticCloudTypedDict, + CreateOutputSystemByPackOutputElasticTypedDict, + CreateOutputSystemByPackOutputExabeam, + CreateOutputSystemByPackOutputExabeamTypedDict, + CreateOutputSystemByPackOutputFilesystem, + CreateOutputSystemByPackOutputFilesystemTypedDict, + CreateOutputSystemByPackOutputGoogleBigquery, + CreateOutputSystemByPackOutputGoogleBigqueryTypedDict, + CreateOutputSystemByPackOutputGoogleChronicle, + CreateOutputSystemByPackOutputGoogleChronicleTypedDict, + CreateOutputSystemByPackOutputGoogleCloudLogging, + CreateOutputSystemByPackOutputGoogleCloudLoggingTypedDict, + CreateOutputSystemByPackOutputGoogleCloudObservability, + CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict, + CreateOutputSystemByPackOutputGoogleCloudStorage, + CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict, + CreateOutputSystemByPackOutputGooglePubsub, + CreateOutputSystemByPackOutputGooglePubsubTypedDict, + CreateOutputSystemByPackOutputGraphite, + CreateOutputSystemByPackOutputGraphiteTypedDict, + CreateOutputSystemByPackOutputHoneycomb, + CreateOutputSystemByPackOutputHoneycombTypedDict, + CreateOutputSystemByPackOutputInfluxdb, + CreateOutputSystemByPackOutputInfluxdbTypedDict, + CreateOutputSystemByPackOutputKafka, + CreateOutputSystemByPackOutputKafkaTypedDict, + CreateOutputSystemByPackOutputKinesis, + CreateOutputSystemByPackOutputKinesisTypedDict, + CreateOutputSystemByPackOutputMinio, + CreateOutputSystemByPackOutputMinioTypedDict, + CreateOutputSystemByPackOutputMsk, + CreateOutputSystemByPackOutputMskTypedDict, + CreateOutputSystemByPackOutputNewrelic, + CreateOutputSystemByPackOutputNewrelicEvents, + CreateOutputSystemByPackOutputNewrelicEventsTypedDict, + CreateOutputSystemByPackOutputNewrelicTypedDict, + CreateOutputSystemByPackOutputRouter, + CreateOutputSystemByPackOutputRouterTypedDict, + CreateOutputSystemByPackOutputS3, + CreateOutputSystemByPackOutputS3TypedDict, + CreateOutputSystemByPackOutputSentinel, + CreateOutputSystemByPackOutputSentinelTypedDict, + CreateOutputSystemByPackOutputSignalfx, + CreateOutputSystemByPackOutputSignalfxTypedDict, + CreateOutputSystemByPackOutputSns, + CreateOutputSystemByPackOutputSnsTypedDict, + CreateOutputSystemByPackOutputSplunk, + CreateOutputSystemByPackOutputSplunkHec, + CreateOutputSystemByPackOutputSplunkHecTypedDict, + CreateOutputSystemByPackOutputSplunkLb, + CreateOutputSystemByPackOutputSplunkLbTypedDict, + CreateOutputSystemByPackOutputSplunkTypedDict, + CreateOutputSystemByPackOutputStatsd, + CreateOutputSystemByPackOutputStatsdExt, + CreateOutputSystemByPackOutputStatsdExtTypedDict, + CreateOutputSystemByPackOutputStatsdTypedDict, + CreateOutputSystemByPackOutputSyslog, + CreateOutputSystemByPackOutputSyslogTypedDict, + CreateOutputSystemByPackOutputTcpjson, + CreateOutputSystemByPackOutputTcpjsonTypedDict, + CreateOutputSystemByPackOutputWavefront, + CreateOutputSystemByPackOutputWavefrontTypedDict, + CreateOutputSystemByPackOutputWebhookFormat2, + CreateOutputSystemByPackOutputWebhookType2, + CreateOutputSystemByPackOutputWizHec, + CreateOutputSystemByPackOutputWizHecTypedDict, +) +from .extrahttpheaderconfinputelastic import ( + ExtraHTTPHeaderConfInputElastic, + ExtraHTTPHeaderConfInputElasticTypedDict, +) +from .failedrequestloggingmodeoptions import FailedRequestLoggingModeOptions +from .methodoptions import MethodOptions +from .modeoptions import ModeOptions +from .oauthheaderconfinputservicenowtable import ( + OauthHeaderConfInputServicenowTable, + OauthHeaderConfInputServicenowTableTypedDict, +) +from .oauthparamconfinputservicenowtable import ( + OauthParamConfInputServicenowTable, + OauthParamConfInputServicenowTableTypedDict, +) +from .queuefullbehavioroptions import QueueFullBehaviorOptions +from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( + RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, +) +from .responseretrysettingconfoutputwebhook import ( + ResponseRetrySettingConfOutputWebhook, + ResponseRetrySettingConfOutputWebhookTypedDict, +) +from .timeoutretrysettingstype import ( + TimeoutRetrySettingsType, + TimeoutRetrySettingsTypeTypedDict, +) +from .tlssettingsclientsidetypecapathcertpathextended import ( + TLSSettingsClientSideTypeCaPathCertPathExtended, + TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict, +) +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, Nullable, UNSET_SENTINEL +from cribl_control_plane.utils import ( + FieldMetadata, + PathParamMetadata, + RequestMetadata, + get_discriminator, +) +from enum import Enum +import pydantic +from pydantic import Discriminator, Tag, field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class CreateOutputSystemByPackOutputWebhookAuthenticationType2( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method to use for the HTTP request""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth + OAUTH = "oauth" + + +class CreateOutputSystemByPackOutputWebhookPqControls2TypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputWebhookPqControls2(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputWebhookURL2TypedDict(TypedDict): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputSystemByPackOutputWebhookURL2(BaseModel): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputWebhookWebhook2TypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputWebhookType2 + r"""Connector type identifier.""" + urls: List[CreateOutputSystemByPackOutputWebhookURL2TypedDict] + r"""Webhook URLs""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + format_: NotRequired[CreateOutputSystemByPackOutputWebhookFormat2] + r"""How to format events before sending out""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[CreateOutputSystemByPackOutputWebhookAuthenticationType2] + r"""Authentication method to use for the HTTP request""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_source_expression: NotRequired[str] + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + custom_drop_when_null: NotRequired[bool] + r"""Whether to drop events when the source expression evaluates to null""" + custom_event_delimiter: NotRequired[str] + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + custom_content_type: NotRequired[str] + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + custom_payload_expression: NotRequired[str] + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + advanced_content_type: NotRequired[str] + r"""HTTP content-type header value""" + format_event_code: NotRequired[str] + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + format_payload_code: NotRequired[str] + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputSystemByPackOutputWebhookPqControls2TypedDict] + r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + secret: NotRequired[str] + r"""Secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + url: NotRequired[str] + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_refresh_url: NotRequired[str] + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputSystemByPackOutputWebhookWebhook2(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputSystemByPackOutputWebhookType2 + r"""Connector type identifier.""" + + urls: List[CreateOutputSystemByPackOutputWebhookURL2] + r"""Webhook URLs""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + format_: Annotated[ + Optional[CreateOutputSystemByPackOutputWebhookFormat2], + pydantic.Field(alias="format"), + ] = None + r"""How to format events before sending out""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputWebhookAuthenticationType2], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method to use for the HTTP request""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_source_expression: Annotated[ + Optional[str], pydantic.Field(alias="customSourceExpression") + ] = None + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + + custom_drop_when_null: Annotated[ + Optional[bool], pydantic.Field(alias="customDropWhenNull") + ] = None + r"""Whether to drop events when the source expression evaluates to null""" + + custom_event_delimiter: Annotated[ + Optional[str], pydantic.Field(alias="customEventDelimiter") + ] = None + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + + custom_content_type: Annotated[ + Optional[str], pydantic.Field(alias="customContentType") + ] = None + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + + custom_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="customPayloadExpression") + ] = None + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + + advanced_content_type: Annotated[ + Optional[str], pydantic.Field(alias="advancedContentType") + ] = None + r"""HTTP content-type header value""" + + format_event_code: Annotated[ + Optional[str], pydantic.Field(alias="formatEventCode") + ] = None + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + format_payload_code: Annotated[ + Optional[str], pydantic.Field(alias="formatPayloadCode") + ] = None + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputWebhookPqControls2], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + secret: Optional[str] = None + r"""Secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + url: Optional[str] = None + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + + template_refresh_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_refreshUrl") + ] = None + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputWebhookFormat2(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputWebhookAuthenticationType2( + value + ) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "method", + "format", + "keepAlive", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "tls", + "totalMemoryLimitKB", + "loadBalanced", + "description", + "customSourceExpression", + "customDropWhenNull", + "customEventDelimiter", + "customContentType", + "customPayloadExpression", + "advancedContentType", + "formatEventCode", + "formatPayloadCode", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "secret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "url", + "excludeSelf", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "__template_streamtags", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "__template_loginUrl", + "__template_secret", + "__template_refreshUrl", + "__template_url", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputWebhookType1(str, Enum): + r"""Connector type identifier.""" + + WEBHOOK = "webhook" + + +class CreateOutputSystemByPackOutputWebhookFormat1( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""How to format events before sending out""" + + # NDJSON (Newline Delimited JSON) + NDJSON = "ndjson" + # JSON Array + JSON_ARRAY = "json_array" + # Custom + CUSTOM = "custom" + # Advanced + ADVANCED = "advanced" + + +class CreateOutputSystemByPackOutputWebhookAuthenticationType1( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method to use for the HTTP request""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth + OAUTH = "oauth" + + +class CreateOutputSystemByPackOutputWebhookPqControls1TypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputWebhookPqControls1(BaseModel): + r"""Persistent queue controls.""" + + +class CreateOutputSystemByPackOutputWebhookURL1TypedDict(TypedDict): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputSystemByPackOutputWebhookURL1(BaseModel): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CreateOutputSystemByPackOutputWebhookWebhook1TypedDict(TypedDict): + id: str + r"""Unique ID for this output""" + type: CreateOutputSystemByPackOutputWebhookType1 + r"""Connector type identifier.""" + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + format_: NotRequired[CreateOutputSystemByPackOutputWebhookFormat1] + r"""How to format events before sending out""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[CreateOutputSystemByPackOutputWebhookAuthenticationType1] + r"""Authentication method to use for the HTTP request""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_source_expression: NotRequired[str] + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + custom_drop_when_null: NotRequired[bool] + r"""Whether to drop events when the source expression evaluates to null""" + custom_event_delimiter: NotRequired[str] + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + custom_content_type: NotRequired[str] + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + custom_payload_expression: NotRequired[str] + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + advanced_content_type: NotRequired[str] + r"""HTTP content-type header value""" + format_event_code: NotRequired[str] + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + format_payload_code: NotRequired[str] + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[CreateOutputSystemByPackOutputWebhookPqControls1TypedDict] + r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + secret: NotRequired[str] + r"""Secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[CreateOutputSystemByPackOutputWebhookURL1TypedDict]] + r"""Webhook URLs""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_refresh_url: NotRequired[str] + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class CreateOutputSystemByPackOutputWebhookWebhook1(BaseModel): + id: str + r"""Unique ID for this output""" + + type: CreateOutputSystemByPackOutputWebhookType1 + r"""Connector type identifier.""" + + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + format_: Annotated[ + Optional[CreateOutputSystemByPackOutputWebhookFormat1], + pydantic.Field(alias="format"), + ] = None + r"""How to format events before sending out""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[CreateOutputSystemByPackOutputWebhookAuthenticationType1], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method to use for the HTTP request""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_source_expression: Annotated[ + Optional[str], pydantic.Field(alias="customSourceExpression") + ] = None + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + + custom_drop_when_null: Annotated[ + Optional[bool], pydantic.Field(alias="customDropWhenNull") + ] = None + r"""Whether to drop events when the source expression evaluates to null""" + + custom_event_delimiter: Annotated[ + Optional[str], pydantic.Field(alias="customEventDelimiter") + ] = None + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + + custom_content_type: Annotated[ + Optional[str], pydantic.Field(alias="customContentType") + ] = None + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + + custom_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="customPayloadExpression") + ] = None + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + + advanced_content_type: Annotated[ + Optional[str], pydantic.Field(alias="advancedContentType") + ] = None + r"""HTTP content-type header value""" + + format_event_code: Annotated[ + Optional[str], pydantic.Field(alias="formatEventCode") + ] = None + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + format_payload_code: Annotated[ + Optional[str], pydantic.Field(alias="formatPayloadCode") + ] = None + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[CreateOutputSystemByPackOutputWebhookPqControls1], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + secret: Optional[str] = None + r"""Secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[CreateOutputSystemByPackOutputWebhookURL1]] = None + r"""Webhook URLs""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + + template_refresh_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_refreshUrl") + ] = None + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputWebhookFormat1(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.CreateOutputSystemByPackOutputWebhookAuthenticationType1( + value + ) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "pipeline", + "systemFields", + "environment", + "streamtags", + "method", + "format", + "keepAlive", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "tls", + "totalMemoryLimitKB", + "loadBalanced", + "description", + "customSourceExpression", + "customDropWhenNull", + "customEventDelimiter", + "customContentType", + "customPayloadExpression", + "advancedContentType", + "formatEventCode", + "formatPayloadCode", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "secret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "__template_streamtags", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "__template_loginUrl", + "__template_secret", + "__template_refreshUrl", + "__template_url", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +CreateOutputSystemByPackOutputWebhookUnionTypedDict = TypeAliasType( + "CreateOutputSystemByPackOutputWebhookUnionTypedDict", + Union[ + CreateOutputSystemByPackOutputWebhookWebhook1TypedDict, + CreateOutputSystemByPackOutputWebhookWebhook2TypedDict, + ], +) + + +CreateOutputSystemByPackOutputWebhookUnion = TypeAliasType( + "CreateOutputSystemByPackOutputWebhookUnion", + Union[ + CreateOutputSystemByPackOutputWebhookWebhook1, + CreateOutputSystemByPackOutputWebhookWebhook2, + ], ) -import pydantic -from pydantic import Discriminator, Tag, model_serializer -from typing import List, Optional, Union -from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class CreateOutputSystemByPackOutputDefaultType(str, Enum): + r"""Connector type identifier.""" + + DEFAULT = "default" class CreateOutputSystemByPackOutputDefaultTypedDict(TypedDict): @@ -273,78 +1875,80 @@ def serialize_model(self, handler): CreateOutputSystemByPackOutputDevnullTypedDict, CreateOutputSystemByPackOutputDefaultTypedDict, CreateOutputSystemByPackOutputRouterTypedDict, - CreateOutputSystemByPackOutputNetflowTypedDict, CreateOutputSystemByPackOutputSnmpTypedDict, + CreateOutputSystemByPackOutputNetflowTypedDict, CreateOutputSystemByPackOutputDiskSpoolTypedDict, CreateOutputSystemByPackOutputRingTypedDict, - CreateOutputSystemByPackOutputStatsdExtTypedDict, - CreateOutputSystemByPackOutputStatsdTypedDict, CreateOutputSystemByPackOutputGraphiteTypedDict, + CreateOutputSystemByPackOutputStatsdTypedDict, + CreateOutputSystemByPackOutputStatsdExtTypedDict, + CreateOutputSystemByPackOutputDatabricksZerobusTypedDict, CreateOutputSystemByPackOutputGoogleBigqueryTypedDict, CreateOutputSystemByPackOutputGooglePubsubTypedDict, CreateOutputSystemByPackOutputCriblTCPTypedDict, - CreateOutputSystemByPackOutputAzureEventhubTypedDict, CreateOutputSystemByPackOutputWavefrontTypedDict, - CreateOutputSystemByPackOutputSignalfxTypedDict, CreateOutputSystemByPackOutputGoogleCloudObservabilityTypedDict, - CreateOutputSystemByPackOutputMicrosoftFabricTypedDict, + CreateOutputSystemByPackOutputSignalfxTypedDict, CreateOutputSystemByPackOutputHoneycombTypedDict, - CreateOutputSystemByPackOutputExabeamTypedDict, + CreateOutputSystemByPackOutputAzureEventhubTypedDict, + CreateOutputSystemByPackOutputMicrosoftFabricTypedDict, CreateOutputSystemByPackOutputTcpjsonTypedDict, CreateOutputSystemByPackOutputSplunkTypedDict, - CreateOutputSystemByPackOutputSumoLogicTypedDict, - CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemTypedDict, CreateOutputSystemByPackOutputHumioHecTypedDict, + CreateOutputSystemByPackOutputCrowdstrikeNextGenSiemTypedDict, + CreateOutputSystemByPackOutputSumoLogicTypedDict, CreateOutputSystemByPackOutputSnsTypedDict, CreateOutputSystemByPackOutputKafkaTypedDict, CreateOutputSystemByPackOutputElasticCloudTypedDict, - CreateOutputSystemByPackOutputCloudwatchTypedDict, - CreateOutputSystemByPackOutputSyslogTypedDict, - CreateOutputSystemByPackOutputAzureLogsTypedDict, CreateOutputSystemByPackOutputConfluentCloudTypedDict, CreateOutputSystemByPackOutputSplunkLbTypedDict, - CreateOutputSystemByPackOutputWizHecTypedDict, - CreateOutputSystemByPackOutputNewrelicEventsTypedDict, + CreateOutputSystemByPackOutputSyslogTypedDict, + CreateOutputSystemByPackOutputAzureLogsTypedDict, + CreateOutputSystemByPackOutputCloudwatchTypedDict, CreateOutputSystemByPackOutputKinesisTypedDict, - CreateOutputSystemByPackOutputCriblSearchEngineTypedDict, + CreateOutputSystemByPackOutputExabeamTypedDict, + CreateOutputSystemByPackOutputNewrelicEventsTypedDict, CreateOutputSystemByPackOutputNewrelicTypedDict, CreateOutputSystemByPackOutputCriblHTTPTypedDict, - CreateOutputSystemByPackOutputXsiamTypedDict, - CreateOutputSystemByPackOutputDatasetTypedDict, CreateOutputSystemByPackOutputLokiTypedDict, + CreateOutputSystemByPackOutputDatasetTypedDict, + CreateOutputSystemByPackOutputWizHecTypedDict, + CreateOutputSystemByPackOutputXsiamTypedDict, CreateOutputSystemByPackOutputDynatraceHTTPTypedDict, - CreateOutputSystemByPackOutputSplunkHecTypedDict, + CreateOutputSystemByPackOutputCriblSearchEngineTypedDict, CreateOutputSystemByPackOutputFilesystemTypedDict, + CreateOutputSystemByPackOutputSplunkHecTypedDict, CreateOutputSystemByPackOutputSqsTypedDict, - CreateOutputSystemByPackOutputCriblLakeTypedDict, CreateOutputSystemByPackOutputDynatraceOtlpTypedDict, CreateOutputSystemByPackOutputSnowflakeStreamingTypedDict, CreateOutputSystemByPackOutputServiceNowTypedDict, + CreateOutputSystemByPackOutputAmazonManagedPrometheusTypedDict, CreateOutputSystemByPackOutputDatadogTypedDict, CreateOutputSystemByPackOutputInfluxdbTypedDict, - CreateOutputSystemByPackOutputAmazonManagedPrometheusTypedDict, + CreateOutputSystemByPackOutputCriblLakeTypedDict, CreateOutputSystemByPackOutputGoogleChronicleTypedDict, CreateOutputSystemByPackOutputElasticTypedDict, CreateOutputSystemByPackOutputSentinelOneAiSiemTypedDict, + CreateOutputSystemByPackOutputClickHouseTypedDict, CreateOutputSystemByPackOutputCustomerMetricsStorageTypedDict, CreateOutputSystemByPackOutputChronicleTypedDict, - CreateOutputSystemByPackOutputClickHouseTypedDict, CreateOutputSystemByPackOutputLocalSearchStorageTypedDict, CreateOutputSystemByPackOutputPrometheusTypedDict, + CreateOutputSystemByPackOutputTraversalOtlpTypedDict, CreateOutputSystemByPackOutputDatabricksTypedDict, CreateOutputSystemByPackOutputAlphasocS3TypedDict, CreateOutputSystemByPackOutputMskTypedDict, - CreateOutputSystemByPackOutputStorjS3TypedDict, CreateOutputSystemByPackOutputIbmCloudS3TypedDict, + CreateOutputSystemByPackOutputStorjS3TypedDict, CreateOutputSystemByPackOutputNutanixObjectsTypedDict, CreateOutputSystemByPackOutputScalityS3TypedDict, CreateOutputSystemByPackOutputOpenTelemetryTypedDict, CreateOutputSystemByPackOutputDellS3TypedDict, CreateOutputSystemByPackOutputCloudflareR2TypedDict, - CreateOutputSystemByPackOutputSentinelTypedDict, CreateOutputSystemByPackOutputAlibabaCloudS3TypedDict, CreateOutputSystemByPackOutputGoogleCloudStorageTypedDict, CreateOutputSystemByPackOutputAzureBlobTypedDict, + CreateOutputSystemByPackOutputSentinelTypedDict, CreateOutputSystemByPackOutputCloudianS3TypedDict, CreateOutputSystemByPackOutputMinioTypedDict, CreateOutputSystemByPackOutputSecurityLakeTypedDict, @@ -352,8 +1956,8 @@ def serialize_model(self, handler): CreateOutputSystemByPackOutputDlS3TypedDict, CreateOutputSystemByPackOutputS3TypedDict, CreateOutputSystemByPackOutputAzureDataExplorerTypedDict, - CreateOutputSystemByPackOutputWebhookUnionTypedDict, CreateOutputSystemByPackOutputGrafanaCloudUnionTypedDict, + CreateOutputSystemByPackOutputWebhookUnionTypedDict, ], ) r"""Output object.""" @@ -460,6 +2064,7 @@ def serialize_model(self, handler): Annotated[CreateOutputSystemByPackOutputNetflow, Tag("netflow")], Annotated[CreateOutputSystemByPackOutputDynatraceHTTP, Tag("dynatrace_http")], Annotated[CreateOutputSystemByPackOutputDynatraceOtlp, Tag("dynatrace_otlp")], + Annotated[CreateOutputSystemByPackOutputTraversalOtlp, Tag("traversal_otlp")], Annotated[ CreateOutputSystemByPackOutputSentinelOneAiSiem, Tag("sentinel_one_ai_siem") ], @@ -482,6 +2087,9 @@ def serialize_model(self, handler): CreateOutputSystemByPackOutputAlibabaCloudS3, Tag("alibaba_cloud_s3") ], Annotated[CreateOutputSystemByPackOutputIbmCloudS3, Tag("ibm_cloud_s3")], + Annotated[ + CreateOutputSystemByPackOutputDatabricksZerobus, Tag("databricks_zerobus") + ], ], Discriminator(lambda m: get_discriminator(m, "type", "type")), ] @@ -508,6 +2116,22 @@ class CreateOutputSystemByPackRequest(BaseModel): r"""Output object.""" +try: + CreateOutputSystemByPackOutputWebhookURL2.model_rebuild() +except NameError: + pass +try: + CreateOutputSystemByPackOutputWebhookWebhook2.model_rebuild() +except NameError: + pass +try: + CreateOutputSystemByPackOutputWebhookURL1.model_rebuild() +except NameError: + pass +try: + CreateOutputSystemByPackOutputWebhookWebhook1.model_rebuild() +except NameError: + pass try: CreateOutputSystemByPackOutputDefault.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/cribllakedataset.py b/src/cribl_control_plane/models/cribllakedataset.py index beb2ce4dc..4c8ec8d7c 100644 --- a/src/cribl_control_plane/models/cribllakedataset.py +++ b/src/cribl_control_plane/models/cribllakedataset.py @@ -22,6 +22,8 @@ class CriblLakeDatasetTypedDict(TypedDict): r"""Unique identifier for the Dataset.""" accelerated_fields: NotRequired[List[str]] r"""Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance.""" + allow_record_erasure: NotRequired[bool] + r"""If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled.""" bucket_name: NotRequired[str] r"""Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId.""" cache_connection: NotRequired[CacheConnectionTypedDict] @@ -34,6 +36,8 @@ class CriblLakeDatasetTypedDict(TypedDict): http_da_used: NotRequired[bool] r"""If true, the Dataset is used by Direct Access HTTP. Otherwise, false.""" metrics: NotRequired[LakeDatasetMetricsTypedDict] + provider_path: NotRequired[str] + r"""Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets).""" retention_period_in_days: NotRequired[int] r"""Dataset retention period, in days.""" search_config: NotRequired[LakeDatasetSearchConfigTypedDict] @@ -54,6 +58,11 @@ class CriblLakeDataset(BaseModel): ] = None r"""Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance.""" + allow_record_erasure: Annotated[ + Optional[bool], pydantic.Field(alias="allowRecordErasure") + ] = None + r"""If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled.""" + bucket_name: Annotated[Optional[str], pydantic.Field(alias="bucketName")] = None r"""Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId.""" @@ -79,6 +88,9 @@ class CriblLakeDataset(BaseModel): metrics: Optional[LakeDatasetMetrics] = None + provider_path: Annotated[Optional[str], pydantic.Field(alias="providerPath")] = None + r"""Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets).""" + retention_period_in_days: Annotated[ Optional[int], pydantic.Field(alias="retentionPeriodInDays") ] = None @@ -125,6 +137,7 @@ def serialize_model(self, handler): optional_fields = set( [ "acceleratedFields", + "allowRecordErasure", "bucketName", "cacheConnection", "deletionStartedAt", @@ -132,6 +145,7 @@ def serialize_model(self, handler): "format", "httpDAUsed", "metrics", + "providerPath", "retentionPeriodInDays", "searchConfig", "storageClass", diff --git a/src/cribl_control_plane/models/cribllakedatasetupdate.py b/src/cribl_control_plane/models/cribllakedatasetupdate.py index 8e59cee86..c52fa93bf 100644 --- a/src/cribl_control_plane/models/cribllakedatasetupdate.py +++ b/src/cribl_control_plane/models/cribllakedatasetupdate.py @@ -20,6 +20,8 @@ class CriblLakeDatasetUpdateTypedDict(TypedDict): accelerated_fields: NotRequired[List[str]] r"""Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance.""" + allow_record_erasure: NotRequired[bool] + r"""If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled.""" bucket_name: NotRequired[str] r"""Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId.""" cache_connection: NotRequired[CacheConnectionTypedDict] @@ -34,6 +36,8 @@ class CriblLakeDatasetUpdateTypedDict(TypedDict): id: NotRequired[str] r"""Unique identifier for the Dataset. Optional; the path parameter id is authoritative.""" metrics: NotRequired[LakeDatasetMetricsTypedDict] + provider_path: NotRequired[str] + r"""Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets).""" retention_period_in_days: NotRequired[int] r"""Dataset retention period, in days.""" search_config: NotRequired[LakeDatasetSearchConfigTypedDict] @@ -51,6 +55,11 @@ class CriblLakeDatasetUpdate(BaseModel): ] = None r"""Accelerated fields for the Dataset. Data is partitioned by these fields in storage to improve query performance.""" + allow_record_erasure: Annotated[ + Optional[bool], pydantic.Field(alias="allowRecordErasure") + ] = None + r"""If true, the Dataset is opted in to Lake Record Erasure. Off by default; only settable when the feature-lake-record-erasure flag is enabled.""" + bucket_name: Annotated[Optional[str], pydantic.Field(alias="bucketName")] = None r"""Name of the legacy Cribl Lake bucket that backs the Dataset. Mutually exclusive with storageLocationId.""" @@ -79,6 +88,9 @@ class CriblLakeDatasetUpdate(BaseModel): metrics: Optional[LakeDatasetMetrics] = None + provider_path: Annotated[Optional[str], pydantic.Field(alias="providerPath")] = None + r"""Storage path within the provider (for example an S3 prefix or Azure container). Independent of id for catalog-backed Datasets so name reuse after delete cannot collide with lingering object-storage data. When omitted, id is the storage path (legacy YAML Datasets).""" + retention_period_in_days: Annotated[ Optional[int], pydantic.Field(alias="retentionPeriodInDays") ] = None @@ -125,6 +137,7 @@ def serialize_model(self, handler): optional_fields = set( [ "acceleratedFields", + "allowRecordErasure", "bucketName", "cacheConnection", "deletionStartedAt", @@ -133,6 +146,7 @@ def serialize_model(self, handler): "httpDAUsed", "id", "metrics", + "providerPath", "retentionPeriodInDays", "searchConfig", "storageClass", diff --git a/src/cribl_control_plane/models/databaseconnectionconfig.py b/src/cribl_control_plane/models/databaseconnectionconfig.py index aa9bf4699..3d1ded2d9 100644 --- a/src/cribl_control_plane/models/databaseconnectionconfig.py +++ b/src/cribl_control_plane/models/databaseconnectionconfig.py @@ -25,12 +25,22 @@ class DatabaseConnectionConfigTypedDict(TypedDict): r"""Database connection string with embedded credentials or server information.""" connection_timeout: NotRequired[int] r"""Maximum time (in milliseconds) to wait when establishing the database connection.""" + credentials_secret: NotRequired[str] + r"""Name of the stored credentials secret containing username and password for SQL Server configObj authentication.""" creds_secrets: NotRequired[str] r"""Name of the stored credentials secret containing username and password. Used with Oracle connections.""" + database: NotRequired[str] + r"""Database to connect to instead of the server default.""" + host: NotRequired[str] + r"""Hostname of the server to connect to.""" + log_on_mechanism: NotRequired[str] + r"""Log On Mechanism for databases that support multiple, like Teradata.""" password: NotRequired[str] r"""Database password for authentication. Used with Oracle connections.""" request_timeout: NotRequired[int] r"""Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only.""" + sslmode: NotRequired[str] + r"""HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior.""" tags: NotRequired[str] r"""Comma-separated list of tags for categorizing and filtering Database Connections.""" text_secret: NotRequired[str] @@ -67,9 +77,25 @@ class DatabaseConnectionConfig(BaseModel): ] = None r"""Maximum time (in milliseconds) to wait when establishing the database connection.""" + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Name of the stored credentials secret containing username and password for SQL Server configObj authentication.""" + creds_secrets: Annotated[Optional[str], pydantic.Field(alias="credsSecrets")] = None r"""Name of the stored credentials secret containing username and password. Used with Oracle connections.""" + database: Optional[str] = None + r"""Database to connect to instead of the server default.""" + + host: Optional[str] = None + r"""Hostname of the server to connect to.""" + + log_on_mechanism: Annotated[ + Optional[str], pydantic.Field(alias="logOnMechanism") + ] = None + r"""Log On Mechanism for databases that support multiple, like Teradata.""" + password: Optional[str] = None r"""Database password for authentication. Used with Oracle connections.""" @@ -78,6 +104,9 @@ class DatabaseConnectionConfig(BaseModel): ] = None r"""Maximum time (in milliseconds) to wait for a database query to complete. Applies to SQL Server connections only.""" + sslmode: Optional[str] = None + r"""HTTPS/TLS connection mode for Teradata. Controls certificate verification behavior.""" + tags: Optional[str] = None r"""Comma-separated list of tags for categorizing and filtering Database Connections.""" @@ -115,9 +144,14 @@ def serialize_model(self, handler): "configObj", "connectionString", "connectionTimeout", + "credentialsSecret", "credsSecrets", + "database", + "host", + "logOnMechanism", "password", "requestTimeout", + "sslmode", "tags", "textSecret", "tls", diff --git a/src/cribl_control_plane/models/databaseconnectiontype.py b/src/cribl_control_plane/models/databaseconnectiontype.py index f0d98aebf..6da36ca99 100644 --- a/src/cribl_control_plane/models/databaseconnectiontype.py +++ b/src/cribl_control_plane/models/databaseconnectiontype.py @@ -10,3 +10,4 @@ class DatabaseConnectionType(str, Enum, metaclass=utils.OpenEnumMeta): ORACLE = "oracle" POSTGRES = "postgres" SQLSERVER = "sqlserver" + TERADATA = "teradata" diff --git a/src/cribl_control_plane/models/destinationtype.py b/src/cribl_control_plane/models/destinationtype.py index e2cf28eb7..f9544a7a1 100644 --- a/src/cribl_control_plane/models/destinationtype.py +++ b/src/cribl_control_plane/models/destinationtype.py @@ -90,3 +90,5 @@ class DestinationType(str, Enum, metaclass=utils.OpenEnumMeta): ALIBABA_CLOUD_S3 = "alibaba_cloud_s3" SNOWFLAKE_STREAMING = "snowflake_streaming" IBM_CLOUD_S3 = "ibm_cloud_s3" + DATABRICKS_ZEROBUS = "databricks_zerobus" + TRAVERSAL_OTLP = "traversal_otlp" diff --git a/src/cribl_control_plane/models/emailrecipient.py b/src/cribl_control_plane/models/emailrecipient.py new file mode 100644 index 000000000..5e5677dc7 --- /dev/null +++ b/src/cribl_control_plane/models/emailrecipient.py @@ -0,0 +1,43 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from pydantic import model_serializer +from typing import Optional +from typing_extensions import NotRequired, TypedDict + + +class EmailRecipientTypedDict(TypedDict): + to: str + r"""Recipients' email addresses.""" + bcc: NotRequired[str] + r"""Bcc: Recipients' email addresses.""" + cc: NotRequired[str] + r"""Cc: Recipients' email addresses.""" + + +class EmailRecipient(BaseModel): + to: str + r"""Recipients' email addresses.""" + + bcc: Optional[str] = None + r"""Bcc: Recipients' email addresses.""" + + cc: Optional[str] = None + r"""Cc: Recipients' email addresses.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["bcc", "cc"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m diff --git a/src/cribl_control_plane/models/executorspecificsettingstyperunnablejobexecutorexecutor.py b/src/cribl_control_plane/models/executorspecificsettingstyperunnablejobexecutorexecutor.py deleted file mode 100644 index 1d9a68255..000000000 --- a/src/cribl_control_plane/models/executorspecificsettingstyperunnablejobexecutorexecutor.py +++ /dev/null @@ -1,13 +0,0 @@ -"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" - -from __future__ import annotations -from cribl_control_plane.types import BaseModel -from typing_extensions import TypedDict - - -class ExecutorSpecificSettingsTypeRunnableJobExecutorExecutorTypedDict(TypedDict): - r"""Executor-type-specific settings object. Shape varies by executor type.""" - - -class ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor(BaseModel): - r"""Executor-type-specific settings object. Shape varies by executor type.""" diff --git a/src/cribl_control_plane/models/executortyperunnablejobexecutor.py b/src/cribl_control_plane/models/executortyperunnablejobexecutor.py index 5b0229772..900c77313 100644 --- a/src/cribl_control_plane/models/executortyperunnablejobexecutor.py +++ b/src/cribl_control_plane/models/executortyperunnablejobexecutor.py @@ -1,14 +1,10 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .executorspecificsettingstyperunnablejobexecutorexecutor import ( - ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor, - ExecutorSpecificSettingsTypeRunnableJobExecutorExecutorTypedDict, -) from cribl_control_plane.types import BaseModel, UNSET_SENTINEL import pydantic from pydantic import model_serializer -from typing import Optional +from typing import Any, Dict, Optional from typing_extensions import Annotated, NotRequired, TypedDict @@ -19,7 +15,7 @@ class ExecutorTypeRunnableJobExecutorTypedDict(TypedDict): r"""The type of executor to run""" store_task_results: NotRequired[bool] r"""Determines whether or not to write task results to disk""" - conf: NotRequired[ExecutorSpecificSettingsTypeRunnableJobExecutorExecutorTypedDict] + conf: NotRequired[Dict[str, Any]] r"""Executor-type-specific settings object. Shape varies by executor type.""" @@ -34,7 +30,7 @@ class ExecutorTypeRunnableJobExecutor(BaseModel): ] = None r"""Determines whether or not to write task results to disk""" - conf: Optional[ExecutorSpecificSettingsTypeRunnableJobExecutorExecutor] = None + conf: Optional[Dict[str, Any]] = None r"""Executor-type-specific settings object. Shape varies by executor type.""" @model_serializer(mode="wrap") diff --git a/src/cribl_control_plane/models/functionconfschemadetectionrules.py b/src/cribl_control_plane/models/functionconfschemadetectionrules.py new file mode 100644 index 000000000..221300099 --- /dev/null +++ b/src/cribl_control_plane/models/functionconfschemadetectionrules.py @@ -0,0 +1,275 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class FunctionConfSchemaDetectionRulesSeverity(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Severity level to assign to the Detection Rule.""" + + SEVERITY_ID_ONE = 1 + SEVERITY_ID_TWO = 2 + SEVERITY_ID_THREE = 3 + SEVERITY_ID_FOUR = 4 + SEVERITY_ID_FIVE = 5 + + +class Confidence(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Confidence level to assign to the Detection Rule.""" + + CONFIDENCE_ID_ONE = 1 + CONFIDENCE_ID_TWO = 2 + CONFIDENCE_ID_THREE = 3 + + +class Impact(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Impact level to assign to the Detection Rule.""" + + IMPACT_ID_ONE = 1 + IMPACT_ID_TWO = 2 + IMPACT_ID_THREE = 3 + IMPACT_ID_FOUR = 4 + + +class FieldOverrideTypedDict(TypedDict): + id: str + r"""Unique identifier for the Detection Rule to override.""" + severity_id: NotRequired[FunctionConfSchemaDetectionRulesSeverity] + r"""Severity level to assign to the Detection Rule.""" + confidence_id: NotRequired[Confidence] + r"""Confidence level to assign to the Detection Rule.""" + impact_id: NotRequired[Impact] + r"""Impact level to assign to the Detection Rule.""" + is_alert: NotRequired[bool] + r"""If true, the Detection Rule creates an alert. Otherwise, false.""" + message: NotRequired[str] + r"""Replacement alert message for the Detection Rule.""" + + +class FieldOverride(BaseModel): + id: str + r"""Unique identifier for the Detection Rule to override.""" + + severity_id: Annotated[ + Optional[FunctionConfSchemaDetectionRulesSeverity], + pydantic.Field(alias="severityId"), + ] = None + r"""Severity level to assign to the Detection Rule.""" + + confidence_id: Annotated[ + Optional[Confidence], pydantic.Field(alias="confidenceId") + ] = None + r"""Confidence level to assign to the Detection Rule.""" + + impact_id: Annotated[Optional[Impact], pydantic.Field(alias="impactId")] = None + r"""Impact level to assign to the Detection Rule.""" + + is_alert: Annotated[Optional[bool], pydantic.Field(alias="isAlert")] = None + r"""If true, the Detection Rule creates an alert. Otherwise, false.""" + + message: Optional[str] = None + r"""Replacement alert message for the Detection Rule.""" + + @field_serializer("severity_id") + def serialize_severity_id(self, value): + if isinstance(value, str): + try: + return models.FunctionConfSchemaDetectionRulesSeverity(value) + except ValueError: + return value + return value + + @field_serializer("confidence_id") + def serialize_confidence_id(self, value): + if isinstance(value, str): + try: + return models.Confidence(value) + except ValueError: + return value + return value + + @field_serializer("impact_id") + def serialize_impact_id(self, value): + if isinstance(value, str): + try: + return models.Impact(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["severityId", "confidenceId", "impactId", "isAlert", "message"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InlineRuleTypedDict(TypedDict): + id: str + r"""Unique identifier for the Detection Rule.""" + name: str + r"""Display name for the Detection Rule.""" + condition: str + r"""Expression that determines whether the Detection Rule matches an event.""" + severity_id: NotRequired[int] + r"""Severity level for the Detection Rule.""" + confidence_id: NotRequired[int] + r"""Confidence level for the Detection Rule.""" + is_alert: NotRequired[bool] + r"""If true, the Detection Rule creates an alert. Otherwise, false.""" + message: NotRequired[str] + r"""Alert message emitted when the Detection Rule matches.""" + tags: NotRequired[List[str]] + r"""Tags for filtering and grouping detection rules.""" + + +class InlineRule(BaseModel): + id: str + r"""Unique identifier for the Detection Rule.""" + + name: str + r"""Display name for the Detection Rule.""" + + condition: str + r"""Expression that determines whether the Detection Rule matches an event.""" + + severity_id: Annotated[Optional[int], pydantic.Field(alias="severityId")] = None + r"""Severity level for the Detection Rule.""" + + confidence_id: Annotated[Optional[int], pydantic.Field(alias="confidenceId")] = None + r"""Confidence level for the Detection Rule.""" + + is_alert: Annotated[Optional[bool], pydantic.Field(alias="isAlert")] = None + r"""If true, the Detection Rule creates an alert. Otherwise, false.""" + + message: Optional[str] = None + r"""Alert message emitted when the Detection Rule matches.""" + + tags: Optional[List[str]] = None + r"""Tags for filtering and grouping detection rules.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["severityId", "confidenceId", "isAlert", "message", "tags"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class LocalOverridesTypedDict(TypedDict): + r"""Instance-level tuning applied after the rule set is merged. Managed by Cribl Security; not intended for direct editing.""" + + disabled: NotRequired[List[str]] + r"""Rule IDs to silence entirely.""" + field_overrides: NotRequired[List[FieldOverrideTypedDict]] + r"""Patch scalar fields of a rule without copying its full definition.""" + inline_rules: NotRequired[List[InlineRuleTypedDict]] + r"""Full rule definitions authored here rather than delivered with the corpus.""" + + +class LocalOverrides(BaseModel): + r"""Instance-level tuning applied after the rule set is merged. Managed by Cribl Security; not intended for direct editing.""" + + disabled: Optional[List[str]] = None + r"""Rule IDs to silence entirely.""" + + field_overrides: Annotated[ + Optional[List[FieldOverride]], pydantic.Field(alias="fieldOverrides") + ] = None + r"""Patch scalar fields of a rule without copying its full definition.""" + + inline_rules: Annotated[ + Optional[List[InlineRule]], pydantic.Field(alias="inlineRules") + ] = None + r"""Full rule definitions authored here rather than delivered with the corpus.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["disabled", "fieldOverrides", "inlineRules"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class FunctionConfSchemaDetectionRulesTypedDict(TypedDict): + local_overrides: NotRequired[LocalOverridesTypedDict] + r"""Instance-level tuning applied after the rule set is merged. Managed by Cribl Security; not intended for direct editing.""" + + +class FunctionConfSchemaDetectionRules(BaseModel): + local_overrides: Annotated[ + Optional[LocalOverrides], pydantic.Field(alias="localOverrides") + ] = None + r"""Instance-level tuning applied after the rule set is merged. Managed by Cribl Security; not intended for direct editing.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["localOverrides"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + FieldOverride.model_rebuild() +except NameError: + pass +try: + InlineRule.model_rebuild() +except NameError: + pass +try: + LocalOverrides.model_rebuild() +except NameError: + pass +try: + FunctionConfSchemaDetectionRules.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/functionconfschemalakehouseenginemetricsnormalizer.py b/src/cribl_control_plane/models/functionconfschemalakehouseenginemetricsnormalizer.py new file mode 100644 index 000000000..dffa5fe7a --- /dev/null +++ b/src/cribl_control_plane/models/functionconfschemalakehouseenginemetricsnormalizer.py @@ -0,0 +1,13 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel +from typing_extensions import TypedDict + + +class FunctionConfSchemaLakehouseEngineMetricsNormalizerTypedDict(TypedDict): + pass + + +class FunctionConfSchemaLakehouseEngineMetricsNormalizer(BaseModel): + pass diff --git a/src/cribl_control_plane/models/functionconfschemametricstimerangegate.py b/src/cribl_control_plane/models/functionconfschemametricstimerangegate.py new file mode 100644 index 000000000..b5e54b68a --- /dev/null +++ b/src/cribl_control_plane/models/functionconfschemametricstimerangegate.py @@ -0,0 +1,13 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel +from typing_extensions import TypedDict + + +class FunctionConfSchemaMetricsTimeRangeGateTypedDict(TypedDict): + pass + + +class FunctionConfSchemaMetricsTimeRangeGate(BaseModel): + pass diff --git a/src/cribl_control_plane/models/functionconfschemanotificationpolicies.py b/src/cribl_control_plane/models/functionconfschemanotificationpolicies.py index 8246b13a6..46bcfcd57 100644 --- a/src/cribl_control_plane/models/functionconfschemanotificationpolicies.py +++ b/src/cribl_control_plane/models/functionconfschemanotificationpolicies.py @@ -1,10 +1,6 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .templatetargetpairconffunctionconfschemanotificationpolicies import ( - TemplateTargetPairConfFunctionConfSchemaNotificationPolicies, - TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict, -) from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum @@ -60,11 +56,26 @@ def serialize_operator(self, value): return value +class FunctionConfSchemaNotificationPoliciesTemplateTargetPairTypedDict(TypedDict): + template_id: str + r"""ID of the notification template to use""" + target_id: str + r"""ID of the notification target (output)""" + + +class FunctionConfSchemaNotificationPoliciesTemplateTargetPair(BaseModel): + template_id: Annotated[str, pydantic.Field(alias="templateId")] + r"""ID of the notification template to use""" + + target_id: Annotated[str, pydantic.Field(alias="targetId")] + r"""ID of the notification target (output)""" + + class PolicyTypedDict(TypedDict): id: str r"""Unique identifier for this policy""" template_target_pairs: List[ - TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict + FunctionConfSchemaNotificationPoliciesTemplateTargetPairTypedDict ] r"""List of targets to route to and the templates to use""" order: int @@ -86,7 +97,7 @@ class Policy(BaseModel): r"""Unique identifier for this policy""" template_target_pairs: Annotated[ - List[TemplateTargetPairConfFunctionConfSchemaNotificationPolicies], + List[FunctionConfSchemaNotificationPoliciesTemplateTargetPair], pydantic.Field(alias="templateTargetPairs"), ] r"""List of targets to route to and the templates to use""" @@ -156,6 +167,10 @@ def serialize_model(self, handler): return m +try: + FunctionConfSchemaNotificationPoliciesTemplateTargetPair.model_rebuild() +except NameError: + pass try: Policy.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/functiondetectionrules.py b/src/cribl_control_plane/models/functiondetectionrules.py new file mode 100644 index 000000000..dcb99f9fb --- /dev/null +++ b/src/cribl_control_plane/models/functiondetectionrules.py @@ -0,0 +1,125 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import Any, Dict, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class FunctionDetectionRulesID(str, Enum): + r"""Identifier of the Function. Always detection_rules""" + + DETECTION_RULES = "detection_rules" + + +class FunctionDetectionRulesTypedDict(TypedDict): + filename: str + r"""Path to the JavaScript file that implements the Function.""" + group: str + r"""Category group the Function belongs to.""" + id: FunctionDetectionRulesID + r"""Identifier of the Function. Always detection_rules""" + load_time: float + r"""Time the Function module was loaded, in milliseconds since the Unix epoch.""" + mod_time: float + r"""Time the Function module was last modified, in milliseconds since the Unix epoch.""" + name: str + r"""Display name of the Function.""" + uischema: Dict[str, Any] + r"""UI Schema that controls how the Function's configuration form is rendered.""" + version: str + r"""Version string of the Function.""" + async_timeout: NotRequired[float] + r"""Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out.""" + cribl_version: NotRequired[str] + r"""Minimum Cribl version required by the Function, if applicable.""" + disabled: NotRequired[bool] + r"""If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false.""" + handle_signals: NotRequired[bool] + r"""If true, the Function handles stream signals such as flush and close. Otherwise, false.""" + sync: NotRequired[bool] + r"""If true, the Function executes synchronously. Otherwise, false.""" + schema_: NotRequired[Dict[str, Any]] + r"""JSON Schema document that describes the Function configuration.""" + + +class FunctionDetectionRules(BaseModel): + filename: Annotated[str, pydantic.Field(alias="__filename")] + r"""Path to the JavaScript file that implements the Function.""" + + group: str + r"""Category group the Function belongs to.""" + + id: FunctionDetectionRulesID + r"""Identifier of the Function. Always detection_rules""" + + load_time: Annotated[float, pydantic.Field(alias="loadTime")] + r"""Time the Function module was loaded, in milliseconds since the Unix epoch.""" + + mod_time: Annotated[float, pydantic.Field(alias="modTime")] + r"""Time the Function module was last modified, in milliseconds since the Unix epoch.""" + + name: str + r"""Display name of the Function.""" + + uischema: Dict[str, Any] + r"""UI Schema that controls how the Function's configuration form is rendered.""" + + version: str + r"""Version string of the Function.""" + + async_timeout: Annotated[Optional[float], pydantic.Field(alias="asyncTimeout")] = ( + None + ) + r"""Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out.""" + + cribl_version: Optional[str] = None + r"""Minimum Cribl version required by the Function, if applicable.""" + + disabled: Optional[bool] = None + r"""If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false.""" + + handle_signals: Annotated[Optional[bool], pydantic.Field(alias="handleSignals")] = ( + None + ) + r"""If true, the Function handles stream signals such as flush and close. Otherwise, false.""" + + sync: Optional[bool] = None + r"""If true, the Function executes synchronously. Otherwise, false.""" + + schema_: Annotated[Optional[Dict[str, Any]], pydantic.Field(alias="schema")] = None + r"""JSON Schema document that describes the Function configuration.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "asyncTimeout", + "cribl_version", + "disabled", + "handleSignals", + "sync", + "schema", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + FunctionDetectionRules.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/functionlakehouseenginemetricsnormalizer.py b/src/cribl_control_plane/models/functionlakehouseenginemetricsnormalizer.py new file mode 100644 index 000000000..4d3c73225 --- /dev/null +++ b/src/cribl_control_plane/models/functionlakehouseenginemetricsnormalizer.py @@ -0,0 +1,125 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import Any, Dict, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class FunctionLakehouseEngineMetricsNormalizerID(str, Enum): + r"""Identifier of the Function. Always lakehouse_engine_metrics_normalizer""" + + LAKEHOUSE_ENGINE_METRICS_NORMALIZER = "lakehouse_engine_metrics_normalizer" + + +class FunctionLakehouseEngineMetricsNormalizerTypedDict(TypedDict): + filename: str + r"""Path to the JavaScript file that implements the Function.""" + group: str + r"""Category group the Function belongs to.""" + id: FunctionLakehouseEngineMetricsNormalizerID + r"""Identifier of the Function. Always lakehouse_engine_metrics_normalizer""" + load_time: float + r"""Time the Function module was loaded, in milliseconds since the Unix epoch.""" + mod_time: float + r"""Time the Function module was last modified, in milliseconds since the Unix epoch.""" + name: str + r"""Display name of the Function.""" + uischema: Dict[str, Any] + r"""UI Schema that controls how the Function's configuration form is rendered.""" + version: str + r"""Version string of the Function.""" + async_timeout: NotRequired[float] + r"""Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out.""" + cribl_version: NotRequired[str] + r"""Minimum Cribl version required by the Function, if applicable.""" + disabled: NotRequired[bool] + r"""If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false.""" + handle_signals: NotRequired[bool] + r"""If true, the Function handles stream signals such as flush and close. Otherwise, false.""" + sync: NotRequired[bool] + r"""If true, the Function executes synchronously. Otherwise, false.""" + schema_: NotRequired[Dict[str, Any]] + r"""JSON Schema document that describes the Function configuration.""" + + +class FunctionLakehouseEngineMetricsNormalizer(BaseModel): + filename: Annotated[str, pydantic.Field(alias="__filename")] + r"""Path to the JavaScript file that implements the Function.""" + + group: str + r"""Category group the Function belongs to.""" + + id: FunctionLakehouseEngineMetricsNormalizerID + r"""Identifier of the Function. Always lakehouse_engine_metrics_normalizer""" + + load_time: Annotated[float, pydantic.Field(alias="loadTime")] + r"""Time the Function module was loaded, in milliseconds since the Unix epoch.""" + + mod_time: Annotated[float, pydantic.Field(alias="modTime")] + r"""Time the Function module was last modified, in milliseconds since the Unix epoch.""" + + name: str + r"""Display name of the Function.""" + + uischema: Dict[str, Any] + r"""UI Schema that controls how the Function's configuration form is rendered.""" + + version: str + r"""Version string of the Function.""" + + async_timeout: Annotated[Optional[float], pydantic.Field(alias="asyncTimeout")] = ( + None + ) + r"""Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out.""" + + cribl_version: Optional[str] = None + r"""Minimum Cribl version required by the Function, if applicable.""" + + disabled: Optional[bool] = None + r"""If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false.""" + + handle_signals: Annotated[Optional[bool], pydantic.Field(alias="handleSignals")] = ( + None + ) + r"""If true, the Function handles stream signals such as flush and close. Otherwise, false.""" + + sync: Optional[bool] = None + r"""If true, the Function executes synchronously. Otherwise, false.""" + + schema_: Annotated[Optional[Dict[str, Any]], pydantic.Field(alias="schema")] = None + r"""JSON Schema document that describes the Function configuration.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "asyncTimeout", + "cribl_version", + "disabled", + "handleSignals", + "sync", + "schema", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + FunctionLakehouseEngineMetricsNormalizer.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/functionmetricstimerangegate.py b/src/cribl_control_plane/models/functionmetricstimerangegate.py new file mode 100644 index 000000000..fc44e272c --- /dev/null +++ b/src/cribl_control_plane/models/functionmetricstimerangegate.py @@ -0,0 +1,125 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import Any, Dict, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class FunctionMetricsTimeRangeGateID(str, Enum): + r"""Identifier of the Function. Always metrics_time_range_gate""" + + METRICS_TIME_RANGE_GATE = "metrics_time_range_gate" + + +class FunctionMetricsTimeRangeGateTypedDict(TypedDict): + filename: str + r"""Path to the JavaScript file that implements the Function.""" + group: str + r"""Category group the Function belongs to.""" + id: FunctionMetricsTimeRangeGateID + r"""Identifier of the Function. Always metrics_time_range_gate""" + load_time: float + r"""Time the Function module was loaded, in milliseconds since the Unix epoch.""" + mod_time: float + r"""Time the Function module was last modified, in milliseconds since the Unix epoch.""" + name: str + r"""Display name of the Function.""" + uischema: Dict[str, Any] + r"""UI Schema that controls how the Function's configuration form is rendered.""" + version: str + r"""Version string of the Function.""" + async_timeout: NotRequired[float] + r"""Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out.""" + cribl_version: NotRequired[str] + r"""Minimum Cribl version required by the Function, if applicable.""" + disabled: NotRequired[bool] + r"""If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false.""" + handle_signals: NotRequired[bool] + r"""If true, the Function handles stream signals such as flush and close. Otherwise, false.""" + sync: NotRequired[bool] + r"""If true, the Function executes synchronously. Otherwise, false.""" + schema_: NotRequired[Dict[str, Any]] + r"""JSON Schema document that describes the Function configuration.""" + + +class FunctionMetricsTimeRangeGate(BaseModel): + filename: Annotated[str, pydantic.Field(alias="__filename")] + r"""Path to the JavaScript file that implements the Function.""" + + group: str + r"""Category group the Function belongs to.""" + + id: FunctionMetricsTimeRangeGateID + r"""Identifier of the Function. Always metrics_time_range_gate""" + + load_time: Annotated[float, pydantic.Field(alias="loadTime")] + r"""Time the Function module was loaded, in milliseconds since the Unix epoch.""" + + mod_time: Annotated[float, pydantic.Field(alias="modTime")] + r"""Time the Function module was last modified, in milliseconds since the Unix epoch.""" + + name: str + r"""Display name of the Function.""" + + uischema: Dict[str, Any] + r"""UI Schema that controls how the Function's configuration form is rendered.""" + + version: str + r"""Version string of the Function.""" + + async_timeout: Annotated[Optional[float], pydantic.Field(alias="asyncTimeout")] = ( + None + ) + r"""Maximum time, in milliseconds, that the Function is allowed to run asynchronously before timing out.""" + + cribl_version: Optional[str] = None + r"""Minimum Cribl version required by the Function, if applicable.""" + + disabled: Optional[bool] = None + r"""If true, the Function is disabled and will not execute in a Pipeline. Otherwise, false.""" + + handle_signals: Annotated[Optional[bool], pydantic.Field(alias="handleSignals")] = ( + None + ) + r"""If true, the Function handles stream signals such as flush and close. Otherwise, false.""" + + sync: Optional[bool] = None + r"""If true, the Function executes synchronously. Otherwise, false.""" + + schema_: Annotated[Optional[Dict[str, Any]], pydantic.Field(alias="schema")] = None + r"""JSON Schema document that describes the Function configuration.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "asyncTimeout", + "cribl_version", + "disabled", + "handleSignals", + "sync", + "schema", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + FunctionMetricsTimeRangeGate.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/functionresponse.py b/src/cribl_control_plane/models/functionresponse.py index 17ddfd425..47b0ee1c6 100644 --- a/src/cribl_control_plane/models/functionresponse.py +++ b/src/cribl_control_plane/models/functionresponse.py @@ -12,6 +12,10 @@ from .functionclone import FunctionClone, FunctionCloneTypedDict from .functioncode import FunctionCode, FunctionCodeTypedDict from .functioncomment import FunctionComment, FunctionCommentTypedDict +from .functiondetectionrules import ( + FunctionDetectionRules, + FunctionDetectionRulesTypedDict, +) from .functiondistinct import FunctionDistinct, FunctionDistinctTypedDict from .functiondnslookup import FunctionDNSLookup, FunctionDNSLookupTypedDict from .functiondrop import FunctionDrop, FunctionDropTypedDict @@ -36,6 +40,10 @@ from .functionjoin import FunctionJoin, FunctionJoinTypedDict from .functionjsonunroll import FunctionJSONUnroll, FunctionJSONUnrollTypedDict from .functionlakeexport import FunctionLakeExport, FunctionLakeExportTypedDict +from .functionlakehouseenginemetricsnormalizer import ( + FunctionLakehouseEngineMetricsNormalizer, + FunctionLakehouseEngineMetricsNormalizerTypedDict, +) from .functionlimit import FunctionLimit, FunctionLimitTypedDict from .functionlocalsearchdatatypeparser import ( FunctionLocalSearchDatatypeParser, @@ -60,6 +68,10 @@ from .functionlookup import FunctionLookup, FunctionLookupTypedDict from .functionmask import FunctionMask, FunctionMaskTypedDict from .functionmetricsexport import FunctionMetricsExport, FunctionMetricsExportTypedDict +from .functionmetricstimerangegate import ( + FunctionMetricsTimeRangeGate, + FunctionMetricsTimeRangeGateTypedDict, +) from .functionmvexpand import FunctionMvExpand, FunctionMvExpandTypedDict from .functionmvpull import FunctionMvPull, FunctionMvPullTypedDict from .functionnotificationpolicies import ( @@ -129,6 +141,7 @@ FunctionCloneTypedDict, FunctionCodeTypedDict, FunctionCommentTypedDict, + FunctionDetectionRulesTypedDict, FunctionDistinctTypedDict, FunctionDNSLookupTypedDict, FunctionDropTypedDict, @@ -147,6 +160,7 @@ FunctionJoinTypedDict, FunctionJSONUnrollTypedDict, FunctionLakeExportTypedDict, + FunctionLakehouseEngineMetricsNormalizerTypedDict, FunctionLimitTypedDict, FunctionLocalSearchDatatypeParserTypedDict, FunctionLocalSearchRulesetRunnerTypedDict, @@ -156,6 +170,7 @@ FunctionLookupTypedDict, FunctionMaskTypedDict, FunctionMetricsExportTypedDict, + FunctionMetricsTimeRangeGateTypedDict, FunctionMvExpandTypedDict, FunctionMvPullTypedDict, FunctionNotificationPoliciesTypedDict, @@ -213,6 +228,7 @@ class UnknownFunctionResponse(BaseModel): "clone": FunctionClone, "code": FunctionCode, "comment": FunctionComment, + "detection_rules": FunctionDetectionRules, "distinct": FunctionDistinct, "dns_lookup": FunctionDNSLookup, "drop": FunctionDrop, @@ -231,6 +247,7 @@ class UnknownFunctionResponse(BaseModel): "join": FunctionJoin, "json_unroll": FunctionJSONUnroll, "lake_export": FunctionLakeExport, + "lakehouse_engine_metrics_normalizer": FunctionLakehouseEngineMetricsNormalizer, "limit": FunctionLimit, "local_search_datatype_parser": FunctionLocalSearchDatatypeParser, "local_search_ruleset_runner": FunctionLocalSearchRulesetRunner, @@ -240,6 +257,7 @@ class UnknownFunctionResponse(BaseModel): "lookup": FunctionLookup, "mask": FunctionMask, "metrics_export": FunctionMetricsExport, + "metrics_time_range_gate": FunctionMetricsTimeRangeGate, "mv_expand": FunctionMvExpand, "mv_pull": FunctionMvPull, "notification_policies": FunctionNotificationPolicies, @@ -287,6 +305,7 @@ class UnknownFunctionResponse(BaseModel): FunctionClone, FunctionCode, FunctionComment, + FunctionDetectionRules, FunctionDistinct, FunctionDNSLookup, FunctionDrop, @@ -305,6 +324,7 @@ class UnknownFunctionResponse(BaseModel): FunctionJoin, FunctionJSONUnroll, FunctionLakeExport, + FunctionLakehouseEngineMetricsNormalizer, FunctionLimit, FunctionLocalSearchDatatypeParser, FunctionLocalSearchRulesetRunner, @@ -314,6 +334,7 @@ class UnknownFunctionResponse(BaseModel): FunctionLookup, FunctionMask, FunctionMetricsExport, + FunctionMetricsTimeRangeGate, FunctionMvExpand, FunctionMvPull, FunctionNotificationPolicies, diff --git a/src/cribl_control_plane/models/getcribllakedatasetbylakeidop.py b/src/cribl_control_plane/models/getcribllakedatasetbylakeidop.py index 744978da1..a0198cdb8 100644 --- a/src/cribl_control_plane/models/getcribllakedatasetbylakeidop.py +++ b/src/cribl_control_plane/models/getcribllakedatasetbylakeidop.py @@ -45,9 +45,21 @@ class GetCriblLakeDatasetByLakeIDRequestTypedDict(TypedDict): include_metrics: NotRequired[bool] r"""Set to true to include storage metrics for each Lake Dataset. Otherwise, false (default). Requires a Cribl Lake metrics license.""" offset: NotRequired[int] - r"""Pagination offset""" + r"""Starting point for catalog-backed pagination. Requires limit.""" limit: NotRequired[int] - r"""Maximum number of items to return""" + r"""Page size for catalog-backed pagination. Requires offset.""" + order_by: NotRequired[str] + r"""Catalog sort field when paginating: name, createdAt, updatedAt, providerPath, type, or retentionPeriodInDays. Defaults to name.""" + order_dir: NotRequired[str] + r"""Sort direction when paginating: asc or desc. Defaults to asc.""" + name: NotRequired[str] + r"""Exact dataset name match (catalog path, with pagination).""" + name_contains: NotRequired[str] + r"""Case-insensitive substring match on dataset name (catalog path, with pagination).""" + provider_path_contains: NotRequired[str] + r"""Case-insensitive substring match on provider path (catalog path, with pagination).""" + description_contains: NotRequired[str] + r"""Case-insensitive substring match on description (catalog path, with pagination).""" class GetCriblLakeDatasetByLakeIDRequest(BaseModel): @@ -118,13 +130,54 @@ class GetCriblLakeDatasetByLakeIDRequest(BaseModel): Optional[int], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), ] = None - r"""Pagination offset""" + r"""Starting point for catalog-backed pagination. Requires limit.""" limit: Annotated[ Optional[int], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), ] = None - r"""Maximum number of items to return""" + r"""Page size for catalog-backed pagination. Requires offset.""" + + order_by: Annotated[ + Optional[str], + pydantic.Field(alias="orderBy"), + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Catalog sort field when paginating: name, createdAt, updatedAt, providerPath, type, or retentionPeriodInDays. Defaults to name.""" + + order_dir: Annotated[ + Optional[str], + pydantic.Field(alias="orderDir"), + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Sort direction when paginating: asc or desc. Defaults to asc.""" + + name: Annotated[ + Optional[str], + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Exact dataset name match (catalog path, with pagination).""" + + name_contains: Annotated[ + Optional[str], + pydantic.Field(alias="nameContains"), + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Case-insensitive substring match on dataset name (catalog path, with pagination).""" + + provider_path_contains: Annotated[ + Optional[str], + pydantic.Field(alias="providerPathContains"), + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Case-insensitive substring match on provider path (catalog path, with pagination).""" + + description_contains: Annotated[ + Optional[str], + pydantic.Field(alias="descriptionContains"), + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Case-insensitive substring match on description (catalog path, with pagination).""" @field_serializer("format_") def serialize_format_(self, value): @@ -149,6 +202,12 @@ def serialize_model(self, handler): "includeMetrics", "offset", "limit", + "orderBy", + "orderDir", + "name", + "nameContains", + "providerPathContains", + "descriptionContains", ] ) serialized = handler(self) diff --git a/src/cribl_control_plane/models/listinputop.py b/src/cribl_control_plane/models/getinputop.py similarity index 88% rename from src/cribl_control_plane/models/listinputop.py rename to src/cribl_control_plane/models/getinputop.py index 0b275e9ac..0904ec94d 100644 --- a/src/cribl_control_plane/models/listinputop.py +++ b/src/cribl_control_plane/models/getinputop.py @@ -12,7 +12,7 @@ from typing_extensions import Annotated, NotRequired, TypedDict -class ListInputRequestTypedDict(TypedDict): +class GetInputRequestTypedDict(TypedDict): type: NotRequired[List[str]] r"""Type of Source to include in the results. Each request can include only one type parameter; multiple parameters per request are not supported.""" offset: NotRequired[int] @@ -21,7 +21,7 @@ class ListInputRequestTypedDict(TypedDict): r"""Maximum number of items to return""" -class ListInputRequest(BaseModel): +class GetInputRequest(BaseModel): type: Annotated[ Optional[List[str]], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), @@ -57,14 +57,14 @@ def serialize_model(self, handler): return m -class ListInputResponseTypedDict(TypedDict): +class GetInputResponseTypedDict(TypedDict): result: PaginatedInputResponseTypedDict -class ListInputResponse(BaseModel): +class GetInputResponse(BaseModel): next: Union[ - Callable[[], Optional[ListInputResponse]], - Callable[[], Awaitable[Optional[ListInputResponse]]], + Callable[[], Optional[GetInputResponse]], + Callable[[], Awaitable[Optional[GetInputResponse]]], ] result: PaginatedInputResponse diff --git a/src/cribl_control_plane/models/listoutputop.py b/src/cribl_control_plane/models/getoutputop.py similarity index 89% rename from src/cribl_control_plane/models/listoutputop.py rename to src/cribl_control_plane/models/getoutputop.py index 14b933f4a..952190149 100644 --- a/src/cribl_control_plane/models/listoutputop.py +++ b/src/cribl_control_plane/models/getoutputop.py @@ -14,7 +14,7 @@ from typing_extensions import Annotated, NotRequired, TypedDict -class ListOutputRequestTypedDict(TypedDict): +class GetOutputRequestTypedDict(TypedDict): type: NotRequired[DestinationType] r"""Type of Destination to include in the results. Each request can include only one type parameter; multiple parameters per request are not supported.""" offset: NotRequired[int] @@ -23,7 +23,7 @@ class ListOutputRequestTypedDict(TypedDict): r"""Maximum number of items to return""" -class ListOutputRequest(BaseModel): +class GetOutputRequest(BaseModel): type: Annotated[ Optional[DestinationType], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), @@ -68,14 +68,14 @@ def serialize_model(self, handler): return m -class ListOutputResponseTypedDict(TypedDict): +class GetOutputResponseTypedDict(TypedDict): result: PaginatedOutputResponseTypedDict -class ListOutputResponse(BaseModel): +class GetOutputResponse(BaseModel): next: Union[ - Callable[[], Optional[ListOutputResponse]], - Callable[[], Awaitable[Optional[ListOutputResponse]]], + Callable[[], Optional[GetOutputResponse]], + Callable[[], Awaitable[Optional[GetOutputResponse]]], ] result: PaginatedOutputResponse diff --git a/src/cribl_control_plane/models/getpipelinesbypackop.py b/src/cribl_control_plane/models/getpipelinesbypackop.py index 5fc14e7e5..669ace8cc 100644 --- a/src/cribl_control_plane/models/getpipelinesbypackop.py +++ b/src/cribl_control_plane/models/getpipelinesbypackop.py @@ -17,9 +17,9 @@ class GetPipelinesByPackRequestTypedDict(TypedDict): pack: str r"""The id of the Pack.""" offset: NotRequired[int] - r"""Pagination offset""" + r"""Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches.""" limit: NotRequired[int] - r"""Maximum number of items to return""" + r"""Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches.""" class GetPipelinesByPackRequest(BaseModel): @@ -32,13 +32,13 @@ class GetPipelinesByPackRequest(BaseModel): Optional[int], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), ] = None - r"""Pagination offset""" + r"""Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches.""" limit: Annotated[ Optional[int], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), ] = None - r"""Maximum number of items to return""" + r"""Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches.""" @model_serializer(mode="wrap") def serialize_model(self, handler): diff --git a/src/cribl_control_plane/models/getpipelinesop.py b/src/cribl_control_plane/models/getpipelinesop.py index 43a854857..e12676009 100644 --- a/src/cribl_control_plane/models/getpipelinesop.py +++ b/src/cribl_control_plane/models/getpipelinesop.py @@ -11,9 +11,9 @@ class GetPipelinesRequestTypedDict(TypedDict): offset: NotRequired[int] - r"""Pagination offset""" + r"""Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches.""" limit: NotRequired[int] - r"""Maximum number of items to return""" + r"""Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches.""" class GetPipelinesRequest(BaseModel): @@ -21,13 +21,13 @@ class GetPipelinesRequest(BaseModel): Optional[int], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), ] = None - r"""Pagination offset""" + r"""Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches.""" limit: Annotated[ Optional[int], FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), ] = None - r"""Maximum number of items to return""" + r"""Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches.""" @model_serializer(mode="wrap") def serialize_model(self, handler): diff --git a/src/cribl_control_plane/models/getproductsgroupsaclbyproductandidop.py b/src/cribl_control_plane/models/getproductsgroupsaclbyproductandidop.py index 0cb9593bb..9b0955860 100644 --- a/src/cribl_control_plane/models/getproductsgroupsaclbyproductandidop.py +++ b/src/cribl_control_plane/models/getproductsgroupsaclbyproductandidop.py @@ -17,7 +17,7 @@ class GetProductsGroupsACLByProductAndIDRequestTypedDict(TypedDict): product: ProductsCore - r"""Name of the Cribl product to get the Worker Groups or Edge Fleets for.""" + r"""Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet.""" id: str r"""The id of the Worker Group, Outpost Group, or Edge Fleet to get the ACL for.""" type: NotRequired[RbacResource] @@ -29,7 +29,7 @@ class GetProductsGroupsACLByProductAndIDRequest(BaseModel): ProductsCore, FieldMetadata(path=PathParamMetadata(style="simple", explode=False)), ] - r"""Name of the Cribl product to get the Worker Groups or Edge Fleets for.""" + r"""Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet.""" id: Annotated[ str, FieldMetadata(path=PathParamMetadata(style="simple", explode=False)) diff --git a/src/cribl_control_plane/models/getproductsgroupsaclteamsbyproductandidop.py b/src/cribl_control_plane/models/getproductsgroupsaclteamsbyproductandidop.py index faa79d553..17f5f19ff 100644 --- a/src/cribl_control_plane/models/getproductsgroupsaclteamsbyproductandidop.py +++ b/src/cribl_control_plane/models/getproductsgroupsaclteamsbyproductandidop.py @@ -19,7 +19,7 @@ class GetProductsGroupsACLTeamsByProductAndIDRequestTypedDict(TypedDict): product: ProductsCore r"""Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet.""" id: str - r"""The id of the Worker Group, Outpost Group, or Edge Fleet to get the team ACL for.""" + r"""The id of the Worker Group, Outpost Group, or Edge Fleet to get the Team ACL for.""" type: NotRequired[RbacResource] r"""Filter for limiting the response to ACL entries for the specified RBAC resource type.""" @@ -34,7 +34,7 @@ class GetProductsGroupsACLTeamsByProductAndIDRequest(BaseModel): id: Annotated[ str, FieldMetadata(path=PathParamMetadata(style="simple", explode=False)) ] - r"""The id of the Worker Group, Outpost Group, or Edge Fleet to get the team ACL for.""" + r"""The id of the Worker Group, Outpost Group, or Edge Fleet to get the Team ACL for.""" type: Annotated[ Optional[RbacResource], diff --git a/src/cribl_control_plane/models/getroutesbypackop.py b/src/cribl_control_plane/models/getroutesbypackop.py index 066f0e60e..566176d8a 100644 --- a/src/cribl_control_plane/models/getroutesbypackop.py +++ b/src/cribl_control_plane/models/getroutesbypackop.py @@ -1,14 +1,25 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from cribl_control_plane.types import BaseModel -from cribl_control_plane.utils import FieldMetadata, PathParamMetadata -from typing_extensions import Annotated, TypedDict +from .paginatedroutes import PaginatedRoutes, PaginatedRoutesTypedDict +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from cribl_control_plane.utils import ( + FieldMetadata, + PathParamMetadata, + QueryParamMetadata, +) +from pydantic import model_serializer +from typing import Awaitable, Callable, Optional, Union +from typing_extensions import Annotated, NotRequired, TypedDict class GetRoutesByPackRequestTypedDict(TypedDict): pack: str r"""The id of the Pack.""" + offset: NotRequired[int] + r"""Pagination offset""" + limit: NotRequired[int] + r"""Maximum number of items to return""" class GetRoutesByPackRequest(BaseModel): @@ -16,3 +27,44 @@ class GetRoutesByPackRequest(BaseModel): str, FieldMetadata(path=PathParamMetadata(style="simple", explode=False)) ] r"""The id of the Pack.""" + + offset: Annotated[ + Optional[int], + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Pagination offset""" + + limit: Annotated[ + Optional[int], + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Maximum number of items to return""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["offset", "limit"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class GetRoutesByPackResponseTypedDict(TypedDict): + result: PaginatedRoutesTypedDict + + +class GetRoutesByPackResponse(BaseModel): + next: Union[ + Callable[[], Optional[GetRoutesByPackResponse]], + Callable[[], Awaitable[Optional[GetRoutesByPackResponse]]], + ] + + result: PaginatedRoutes diff --git a/src/cribl_control_plane/models/getroutesop.py b/src/cribl_control_plane/models/getroutesop.py new file mode 100644 index 000000000..fb75399dc --- /dev/null +++ b/src/cribl_control_plane/models/getroutesop.py @@ -0,0 +1,59 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .paginatedroutes import PaginatedRoutes, PaginatedRoutesTypedDict +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from cribl_control_plane.utils import FieldMetadata, QueryParamMetadata +from pydantic import model_serializer +from typing import Awaitable, Callable, Optional, Union +from typing_extensions import Annotated, NotRequired, TypedDict + + +class GetRoutesRequestTypedDict(TypedDict): + offset: NotRequired[int] + r"""Pagination offset""" + limit: NotRequired[int] + r"""Maximum number of items to return""" + + +class GetRoutesRequest(BaseModel): + offset: Annotated[ + Optional[int], + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Pagination offset""" + + limit: Annotated[ + Optional[int], + FieldMetadata(query=QueryParamMetadata(style="form", explode=True)), + ] = None + r"""Maximum number of items to return""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["offset", "limit"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class GetRoutesResponseTypedDict(TypedDict): + result: PaginatedRoutesTypedDict + + +class GetRoutesResponse(BaseModel): + next: Union[ + Callable[[], Optional[GetRoutesResponse]], + Callable[[], Awaitable[Optional[GetRoutesResponse]]], + ] + + result: PaginatedRoutes diff --git a/src/cribl_control_plane/models/groupcreaterequest.py b/src/cribl_control_plane/models/groupcreaterequest.py index 6c1245a2a..2bf3245f7 100644 --- a/src/cribl_control_plane/models/groupcreaterequest.py +++ b/src/cribl_control_plane/models/groupcreaterequest.py @@ -17,6 +17,10 @@ class GroupCreateRequestTypedDict(TypedDict): id: str r"""Unique identifier.""" + src_group: NotRequired[str] + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + src_overridden: NotRequired[bool] + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" cloud: NotRequired[ConfigGroupCloudTypedDict] collectors_ha_enabled: NotRequired[bool] r"""Keeps Collector jobs running if the Leader Node fails. Applies only to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups. to Stream Worker Groups. Always true for Cribl.Cloud groups; defaults to false for on-prem groups.""" @@ -58,6 +62,14 @@ class GroupCreateRequest(BaseModel): id: str r"""Unique identifier.""" + src_group: Annotated[Optional[str], pydantic.Field(alias="__srcGroup")] = None + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + + src_overridden: Annotated[ + Optional[bool], pydantic.Field(alias="__srcOverridden") + ] = None + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" + cloud: Optional[ConfigGroupCloud] = None collectors_ha_enabled: Annotated[ @@ -160,6 +172,8 @@ def serialize_type(self, value): def serialize_model(self, handler): optional_fields = set( [ + "__srcGroup", + "__srcOverridden", "cloud", "collectorsHaEnabled", "description", diff --git a/src/cribl_control_plane/models/hbcriblinfo.py b/src/cribl_control_plane/models/hbcriblinfo.py index c6dde4bb9..6b3963b57 100644 --- a/src/cribl_control_plane/models/hbcriblinfo.py +++ b/src/cribl_control_plane/models/hbcriblinfo.py @@ -96,9 +96,11 @@ def serialize_model(self, handler): class DistMode(str, Enum, metaclass=utils.OpenEnumMeta): r"""Distributed deployment mode for the instance.""" + DEDICATED_ORG_LEADER = "dedicated-org-leader" EDGE = "edge" MANAGED_EDGE = "managed-edge" MASTER = "master" + ORG_LEADER = "org-leader" OUTPOST = "outpost" SEARCH_SUPERVISOR = "search-supervisor" SINGLE = "single" @@ -116,6 +118,8 @@ class HBCriblInfoTypedDict(TypedDict): r"""Unique instance identifier for the Cribl node.""" start_time: int r"""Timestamp (in Unix time) when the Cribl server process started, in milliseconds.""" + auto_lookup_versions: NotRequired[Dict[str, Dict[str, str]]] + r"""Objects that map Lookup files to deployment versions.""" deployment_id: NotRequired[str] r"""Unique identifier for the deployment assigned for the node.""" disable_sni_routing: NotRequired[bool] @@ -156,6 +160,11 @@ class HBCriblInfo(BaseModel): start_time: Annotated[int, pydantic.Field(alias="startTime")] r"""Timestamp (in Unix time) when the Cribl server process started, in milliseconds.""" + auto_lookup_versions: Annotated[ + Optional[Dict[str, Dict[str, str]]], pydantic.Field(alias="autoLookupVersions") + ] = None + r"""Objects that map Lookup files to deployment versions.""" + deployment_id: Annotated[Optional[str], pydantic.Field(alias="deploymentId")] = None r"""Unique identifier for the deployment assigned for the node.""" @@ -208,6 +217,7 @@ def serialize_dist_mode(self, value): def serialize_model(self, handler): optional_fields = set( [ + "autoLookupVersions", "deploymentId", "disableSNIRouting", "edgeNodes", diff --git a/src/cribl_control_plane/models/input.py b/src/cribl_control_plane/models/input.py index 1407aff42..dc487fcc0 100644 --- a/src/cribl_control_plane/models/input.py +++ b/src/cribl_control_plane/models/input.py @@ -1,17 +1,34 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations +from .inputakamaihec_input import InputAkamaiHecInput, InputAkamaiHecInputTypedDict from .inputanthropiccompliance_input import ( InputAnthropicComplianceInput, InputAnthropicComplianceInputTypedDict, ) +from .inputanthropicenterpriseanalytics_input import ( + InputAnthropicEnterpriseAnalyticsInput, + InputAnthropicEnterpriseAnalyticsInputTypedDict, +) from .inputappleunifiedlogs_input import ( InputAppleUnifiedLogsInput, InputAppleUnifiedLogsInputTypedDict, ) from .inputappscope_input import InputAppscopeInput, InputAppscopeInputTypedDict +from .inputaquasecurityhec_input import ( + InputAquaSecurityHecInput, + InputAquaSecurityHecInputTypedDict, +) from .inputazureblob_input import InputAzureBlobInput, InputAzureBlobInputTypedDict +from .inputazurevnetflowlog_input import ( + InputAzureVnetFlowLogInput, + InputAzureVnetFlowLogInputTypedDict, +) from .inputbedrocks3_input import InputBedrockS3Input, InputBedrockS3InputTypedDict +from .inputbeyondtrusthec_input import ( + InputBeyondtrustHecInput, + InputBeyondtrustHecInputTypedDict, +) from .inputcloudflarehec_input import ( InputCloudflareHecInput, InputCloudflareHecInputTypedDict, @@ -52,8 +69,14 @@ InputEventhubAmqpInputTypedDict, ) from .inputexec_input import InputExecInput, InputExecInputTypedDict +from .inputextrahoprevealx360_input import ( + InputExtrahopRevealx360Input, + InputExtrahopRevealx360InputTypedDict, +) +from .inputf5bigip_input import InputF5BigIPInput, InputF5BigIPInputTypedDict from .inputfile_input import InputFileInput, InputFileInputTypedDict from .inputfirehose_input import InputFirehoseInput, InputFirehoseInputTypedDict +from .inputgigamonhec_input import InputGigamonHecInput, InputGigamonHecInputTypedDict from .inputgooglepubsub_input import ( InputGooglePubsubInput, InputGooglePubsubInputTypedDict, @@ -62,6 +85,10 @@ InputGrafanaInputUnion, InputGrafanaInputUnionTypedDict, ) +from .inputhashicorphcpvaultdedicated_input import ( + InputHashicorpHcpVaultDedicatedInput, + InputHashicorpHcpVaultDedicatedInputTypedDict, +) from .inputhttp_input import InputHTTPInput, InputHTTPInputTypedDict from .inputhttpraw_input import InputHTTPRawInput, InputHTTPRawInputTypedDict from .inputjournalfiles_input import ( @@ -78,10 +105,18 @@ ) from .inputloki_input import InputLokiInput, InputLokiInputTypedDict from .inputmetrics_input import InputMetricsInput, InputMetricsInputTypedDict +from .inputmicrosoftcopilot_input import ( + InputMicrosoftCopilotInput, + InputMicrosoftCopilotInputTypedDict, +) from .inputmicrosoftgraph_input import ( InputMicrosoftGraphInput, InputMicrosoftGraphInputTypedDict, ) +from .inputmimecasthec_input import ( + InputMimecastHecInput, + InputMimecastHecInputTypedDict, +) from .inputmodeldriventelemetry_input import ( InputModelDrivenTelemetryInput, InputModelDrivenTelemetryInputTypedDict, @@ -110,17 +145,29 @@ InputOpenTelemetryInput, InputOpenTelemetryInputTypedDict, ) +from .inputpingidentitypingone_input import ( + InputPingIdentityPingoneInput, + InputPingIdentityPingoneInputTypedDict, +) from .inputprometheus_input import InputPrometheusInput, InputPrometheusInputTypedDict from .inputprometheusrw_input import ( InputPrometheusRwInput, InputPrometheusRwInputTypedDict, ) +from .inputproofpointpod_input import ( + InputProofpointPodInput, + InputProofpointPodInputTypedDict, +) from .inputrawudp_input import InputRawUDPInput, InputRawUDPInputTypedDict from .inputs3_input import InputS3Input, InputS3InputTypedDict from .inputs3inventory_input import ( InputS3InventoryInput, InputS3InventoryInputTypedDict, ) +from .inputsailpointhec_input import ( + InputSailpointHecInput, + InputSailpointHecInputTypedDict, +) from .inputsecuritylake_input import ( InputSecurityLakeInput, InputSecurityLakeInputTypedDict, @@ -152,7 +199,16 @@ ) from .inputtcp_input import InputTCPInput, InputTCPInputTypedDict from .inputtcpjson_input import InputTcpjsonInput, InputTcpjsonInputTypedDict +from .inputtrellixhec_input import InputTrellixHecInput, InputTrellixHecInputTypedDict +from .inputtrendmicrovisionone_input import ( + InputTrendMicroVisionOneInput, + InputTrendMicroVisionOneInputTypedDict, +) from .inputupwindhec_input import InputUpwindHecInput, InputUpwindHecInputTypedDict +from .inputvectraaihec_input import ( + InputVectraAiHecInput, + InputVectraAiHecInputTypedDict, +) from .inputwef_input import InputWefInput, InputWefInputTypedDict from .inputwindowsmetrics_input import ( InputWindowsMetricsInput, @@ -174,74 +230,91 @@ InputTypedDict = TypeAliasType( "InputTypedDict", Union[ - InputDatagenInputTypedDict, - InputKubeEventsInputTypedDict, InputCriblInputTypedDict, - InputAppleUnifiedLogsInputTypedDict, + InputKubeEventsInputTypedDict, + InputDatagenInputTypedDict, InputCriblmetricsInputTypedDict, + InputAppleUnifiedLogsInputTypedDict, InputCollectionInputTypedDict, InputKubeMetricsInputTypedDict, InputSystemStateInputTypedDict, - InputSystemMetricsInputTypedDict, InputWindowsMetricsInputTypedDict, + InputSystemMetricsInputTypedDict, InputJournalFilesInputTypedDict, + InputKubeLogsInputTypedDict, InputModelDrivenTelemetryInputTypedDict, InputExecInputTypedDict, + InputProofpointPodInputTypedDict, InputRawUDPInputTypedDict, - InputKubeLogsInputTypedDict, InputSnmpInputTypedDict, InputWinEventLogsInputTypedDict, + InputAnthropicEnterpriseAnalyticsInputTypedDict, InputMetricsInputTypedDict, InputNetflowInputTypedDict, InputCriblTCPInputTypedDict, InputOpenaiInputTypedDict, - InputEventhubAmqpInputTypedDict, InputTcpjsonInputTypedDict, InputOktaInputTypedDict, - InputGooglePubsubInputTypedDict, + InputEventhubAmqpInputTypedDict, InputCriblHTTPInputTypedDict, - InputTCPInputTypedDict, + InputGooglePubsubInputTypedDict, InputFirehoseInputTypedDict, + InputSailpointHecInputTypedDict, InputOffice365ServiceInputTypedDict, - InputAnthropicComplianceInputTypedDict, + InputTCPInputTypedDict, InputWizInputTypedDict, + InputAkamaiHecInputTypedDict, + InputAnthropicComplianceInputTypedDict, InputDatadogAgentInputTypedDict, + InputOffice365MgmtInputTypedDict, InputAppscopeInputTypedDict, - InputFileInputTypedDict, InputSplunkInputTypedDict, - InputOffice365MgmtInputTypedDict, + InputBeyondtrustHecInputTypedDict, InputWefInputTypedDict, - InputLokiInputTypedDict, + InputAzureVnetFlowLogInputTypedDict, InputWizWebhookInputTypedDict, - InputUpwindHecInputTypedDict, + InputLokiInputTypedDict, InputSysdigHecInputTypedDict, + InputVectraAiHecInputTypedDict, + InputGigamonHecInputTypedDict, + InputUpwindHecInputTypedDict, + InputPingIdentityPingoneInputTypedDict, + InputExtrahopRevealx360InputTypedDict, + InputFileInputTypedDict, + InputTrellixHecInputTypedDict, InputPrometheusRwInputTypedDict, - InputConfluentCloudInputTypedDict, - InputKafkaInputTypedDict, + InputAquaSecurityHecInputTypedDict, + InputHashicorpHcpVaultDedicatedInputTypedDict, + InputMimecastHecInputTypedDict, + InputTrendMicroVisionOneInputTypedDict, InputZscalerHecInputTypedDict, - InputCriblLakeHTTPInputTypedDict, InputHTTPInputTypedDict, - InputEventhubInputTypedDict, - InputAzureBlobInputTypedDict, - InputOpenaiComplianceLogsInputTypedDict, + InputCriblLakeHTTPInputTypedDict, + InputF5BigIPInputTypedDict, InputCloudflareHecInputTypedDict, + InputKafkaInputTypedDict, + InputOpenaiComplianceLogsInputTypedDict, + InputConfluentCloudInputTypedDict, + InputMicrosoftCopilotInputTypedDict, + InputEventhubInputTypedDict, InputElasticInputTypedDict, - InputOpenTelemetryInputTypedDict, InputSplunkHecInputTypedDict, + InputAzureBlobInputTypedDict, + InputOpenTelemetryInputTypedDict, InputSqsInputTypedDict, - InputKinesisInputTypedDict, - InputOffice365MsgTraceInputTypedDict, InputMicrosoftGraphInputTypedDict, + InputOffice365MsgTraceInputTypedDict, + InputKinesisInputTypedDict, InputHTTPRawInputTypedDict, InputSplunkSearchInputTypedDict, InputServicenowTableInputTypedDict, InputMskInputTypedDict, InputEdgePrometheusInputTypedDict, InputCrowdstrikeInputTypedDict, - InputS3InputTypedDict, + InputPrometheusInputTypedDict, InputBedrockS3InputTypedDict, InputSecurityLakeInputTypedDict, - InputPrometheusInputTypedDict, + InputS3InputTypedDict, InputS3InventoryInputTypedDict, InputGrafanaInputUnionTypedDict, InputSyslogInputUnionTypedDict, @@ -259,6 +332,7 @@ Annotated[InputSplunkSearchInput, Tag("splunk_search")], Annotated[InputSplunkHecInput, Tag("splunk_hec")], Annotated[InputAzureBlobInput, Tag("azure_blob")], + Annotated[InputAzureVnetFlowLogInput, Tag("azure_vnet_flow_log")], Annotated[InputElasticInput, Tag("elastic")], Annotated[InputConfluentCloudInput, Tag("confluent_cloud")], Annotated[InputGrafanaInputUnion, Tag("grafana")], @@ -315,13 +389,34 @@ Annotated[InputSecurityLakeInput, Tag("security_lake")], Annotated[InputBedrockS3Input, Tag("bedrock_s3")], Annotated[InputServicenowTableInput, Tag("servicenow_table")], + Annotated[InputProofpointPodInput, Tag("proofpoint_pod")], Annotated[InputZscalerHecInput, Tag("zscaler_hec")], Annotated[InputCloudflareHecInput, Tag("cloudflare_hec")], Annotated[InputSysdigHecInput, Tag("sysdig_hec")], Annotated[InputUpwindHecInput, Tag("upwind_hec")], + Annotated[InputTrellixHecInput, Tag("trellix_hec")], + Annotated[InputSailpointHecInput, Tag("sailpoint_hec")], + Annotated[InputExtrahopRevealx360Input, Tag("extrahop_revealx_360")], + Annotated[InputAquaSecurityHecInput, Tag("aqua_security_hec")], Annotated[InputOpenaiComplianceLogsInput, Tag("openai_compliance_logs")], Annotated[InputAnthropicComplianceInput, Tag("anthropic_compliance")], + Annotated[ + InputAnthropicEnterpriseAnalyticsInput, + Tag("anthropic_enterprise_analytics"), + ], + Annotated[InputMicrosoftCopilotInput, Tag("microsoft_copilot")], Annotated[InputOktaInput, Tag("okta")], + Annotated[InputAkamaiHecInput, Tag("akamai_hec")], + Annotated[InputPingIdentityPingoneInput, Tag("ping_identity_pingone")], + Annotated[InputGigamonHecInput, Tag("gigamon_hec")], + Annotated[InputVectraAiHecInput, Tag("vectra_ai_hec")], + Annotated[InputF5BigIPInput, Tag("f5_big_ip")], + Annotated[InputBeyondtrustHecInput, Tag("beyondtrust_hec")], + Annotated[ + InputHashicorpHcpVaultDedicatedInput, Tag("hashicorp_hcp_vault_dedicated") + ], + Annotated[InputMimecastHecInput, Tag("mimecast_hec")], + Annotated[InputTrendMicroVisionOneInput, Tag("trend_micro_vision_one")], ], Discriminator(lambda m: get_discriminator(m, "type", "type")), ] diff --git a/src/cribl_control_plane/models/inputakamaihec_input.py b/src/cribl_control_plane/models/inputakamaihec_input.py new file mode 100644 index 000000000..afae9a124 --- /dev/null +++ b/src/cribl_control_plane/models/inputakamaihec_input.py @@ -0,0 +1,289 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputAkamaiHecType(str, Enum): + r"""Source type identifier.""" + + AKAMAI_HEC = "akamai_hec" + + +class InputAkamaiHecInputTypedDict(TypedDict): + type: InputAkamaiHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + +class InputAkamaiHecInput(BaseModel): + type: InputAkamaiHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "hecAcks", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputAkamaiHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputanthropiccompliance_input.py b/src/cribl_control_plane/models/inputanthropiccompliance_input.py index e8e2b7c18..d5338902e 100644 --- a/src/cribl_control_plane/models/inputanthropiccompliance_input.py +++ b/src/cribl_control_plane/models/inputanthropiccompliance_input.py @@ -49,9 +49,9 @@ class ActivitiesTypedDict(TypedDict): state_tracking: NotRequired[bool] r"""Track collection progress between consecutive scheduled executions""" state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: NotRequired[ActivitiesManageStateTypedDict] @@ -81,12 +81,12 @@ class Activities(BaseModel): state_update_expression: Annotated[ Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: Annotated[ Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: Annotated[ Optional[ActivitiesManageState], pydantic.Field(alias="manageState") @@ -145,9 +145,9 @@ class ChatsTypedDict(TypedDict): state_tracking: NotRequired[bool] r"""Track collection progress between consecutive scheduled executions""" state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: NotRequired[ChatsManageStateTypedDict] @@ -177,12 +177,12 @@ class Chats(BaseModel): state_update_expression: Annotated[ Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: Annotated[ Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: Annotated[ Optional[ChatsManageState], pydantic.Field(alias="manageState") @@ -241,9 +241,9 @@ class ProjectsTypedDict(TypedDict): state_tracking: NotRequired[bool] r"""Track collection progress between consecutive scheduled executions""" state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: NotRequired[ProjectsManageStateTypedDict] @@ -273,12 +273,12 @@ class Projects(BaseModel): state_update_expression: Annotated[ Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: Annotated[ Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: Annotated[ Optional[ProjectsManageState], pydantic.Field(alias="manageState") @@ -337,9 +337,9 @@ class ChatMessagesTypedDict(TypedDict): state_tracking: NotRequired[bool] r"""Track collection progress between consecutive scheduled executions""" state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: NotRequired[ChatMessagesManageStateTypedDict] @@ -369,12 +369,12 @@ class ChatMessages(BaseModel): state_update_expression: Annotated[ Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: Annotated[ Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: Annotated[ Optional[ChatMessagesManageState], pydantic.Field(alias="manageState") @@ -433,9 +433,9 @@ class ProjectDetailsTypedDict(TypedDict): state_tracking: NotRequired[bool] r"""Track collection progress between consecutive scheduled executions""" state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: NotRequired[ProjectDetailsManageStateTypedDict] @@ -465,12 +465,12 @@ class ProjectDetails(BaseModel): state_update_expression: Annotated[ Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: Annotated[ Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: Annotated[ Optional[ProjectDetailsManageState], pydantic.Field(alias="manageState") diff --git a/src/cribl_control_plane/models/inputanthropicenterpriseanalytics_input.py b/src/cribl_control_plane/models/inputanthropicenterpriseanalytics_input.py new file mode 100644 index 000000000..7d18a1e89 --- /dev/null +++ b/src/cribl_control_plane/models/inputanthropicenterpriseanalytics_input.py @@ -0,0 +1,371 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .retryrulestype import RetryRulesType, RetryRulesTypeTypedDict +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputAnthropicEnterpriseAnalyticsType(str, Enum): + r"""Connector type identifier.""" + + ANTHROPIC_ENTERPRISE_ANALYTICS = "anthropic_enterprise_analytics" + + +class ContentType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Content type""" + + USAGE_REPORT = "Usage Report" + COST_REPORT = "Cost Report" + + +class GroupBy(str, Enum, metaclass=utils.OpenEnumMeta): + MODEL = "model" + PRODUCT = "product" + CONTEXT_WINDOW = "context_window" + INFERENCE_GEO = "inference_geo" + SPEED = "speed" + RBAC_GROUP_ID = "rbac_group_id" + SLACK_CHANNEL_ID = "slack_channel_id" + TEAMS_CHANNEL_ID = "teams_channel_id" + COST_TYPE = "cost_type" + TOKEN_TYPE = "token_type" + + +class BucketWidth(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + + # Daily (1d) + ONED = "1d" + # Hourly (1h) + ONEH = "1h" + # Per-minute (1m) + ONEM = "1m" + + +class InputAnthropicEnterpriseAnalyticsContentConfigTypedDict(TypedDict): + content_type: ContentType + r"""Content type""" + cron_schedule: str + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + disabled: NotRequired[bool] + r"""Enabled""" + state_tracking: NotRequired[bool] + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + state_update_expression: NotRequired[str] + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" + manage_state: NotRequired[bool] + r"""Manage state""" + group_by: NotRequired[List[GroupBy]] + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" + bucket_width: NotRequired[BucketWidth] + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + +class InputAnthropicEnterpriseAnalyticsContentConfig(BaseModel): + content_type: Annotated[ContentType, pydantic.Field(alias="contentType")] + r"""Content type""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + + disabled: Optional[bool] = None + r"""Enabled""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" + + manage_state: Annotated[Optional[bool], pydantic.Field(alias="manageState")] = None + r"""Manage state""" + + group_by: Annotated[Optional[List[GroupBy]], pydantic.Field(alias="groupBy")] = None + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" + + bucket_width: Annotated[ + Optional[BucketWidth], pydantic.Field(alias="bucketWidth") + ] = None + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @field_serializer("content_type") + def serialize_content_type(self, value): + if isinstance(value, str): + try: + return models.ContentType(value) + except ValueError: + return value + return value + + @field_serializer("bucket_width") + def serialize_bucket_width(self, value): + if isinstance(value, str): + try: + return models.BucketWidth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "groupBy", + "bucketWidth", + "earliest", + "jobTimeout", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputAnthropicEnterpriseAnalyticsInputTypedDict(TypedDict): + type: InputAnthropicEnterpriseAnalyticsType + r"""Connector type identifier.""" + text_secret: str + r"""Select or create a stored API key with read:analytics scope""" + content_config: List[InputAnthropicEnterpriseAnalyticsContentConfigTypedDict] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + api_key: NotRequired[str] + r"""API key""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + +class InputAnthropicEnterpriseAnalyticsInput(BaseModel): + type: InputAnthropicEnterpriseAnalyticsType + r"""Connector type identifier.""" + + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored API key with read:analytics scope""" + + content_config: Annotated[ + List[InputAnthropicEnterpriseAnalyticsContentConfig], + pydantic.Field(alias="contentConfig"), + ] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""HTTP request inactivity timeout. Use 0 to disable.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "apiKey", + "requestTimeout", + "breakerRulesets", + "staleChannelFlushMs", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", + "description", + "__template_environment", + "__template_streamtags", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputAnthropicEnterpriseAnalyticsContentConfig.model_rebuild() +except NameError: + pass +try: + InputAnthropicEnterpriseAnalyticsInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputappscope_input.py b/src/cribl_control_plane/models/inputappscope_input.py index 1b1e06520..6bee9c3e2 100644 --- a/src/cribl_control_plane/models/inputappscope_input.py +++ b/src/cribl_control_plane/models/inputappscope_input.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -228,7 +228,7 @@ class InputAppscopeInputTypedDict(TypedDict): filter_: NotRequired[InputAppscopeFilterTypedDict] persistence: NotRequired[InputAppscopePersistenceTypedDict] r"""Persistence""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -344,7 +344,7 @@ class InputAppscopeInput(BaseModel): r"""Persistence""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -401,7 +401,7 @@ class InputAppscopeInput(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/inputaquasecurityhec_input.py b/src/cribl_control_plane/models/inputaquasecurityhec_input.py new file mode 100644 index 000000000..a6ff14494 --- /dev/null +++ b/src/cribl_control_plane/models/inputaquasecurityhec_input.py @@ -0,0 +1,337 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputAquaSecurityHecType(str, Enum): + r"""Source type identifier.""" + + AQUA_SECURITY_HEC = "aqua_security_hec" + + +class InputAquaSecurityHecInputTypedDict(TypedDict): + type: InputAquaSecurityHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputAquaSecurityHecInput(BaseModel): + type: InputAquaSecurityHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputAquaSecurityHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputazureblob_input.py b/src/cribl_control_plane/models/inputazureblob_input.py index 06c5dfedc..53f463a71 100644 --- a/src/cribl_control_plane/models/inputazureblob_input.py +++ b/src/cribl_control_plane/models/inputazureblob_input.py @@ -55,6 +55,8 @@ class InputAzureBlobInputTypedDict(TypedDict): r"""The duration (in seconds) which pollers should be validated and restarted if exited""" skip_on_error: NotRequired[bool] r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] @@ -67,6 +69,8 @@ class InputAzureBlobInputTypedDict(TypedDict): r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" auth_type: NotRequired[AuthenticationMethodOptions] r"""Authentication method""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" connection_string: NotRequired[str] @@ -163,6 +167,9 @@ class InputAzureBlobInput(BaseModel): skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -191,6 +198,9 @@ class InputAzureBlobInput(BaseModel): ] = None r"""Authentication method""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -296,12 +306,14 @@ def serialize_model(self, handler): "maxMessages", "servicePeriodSecs", "skipOnError", + "encoding", "metadata", "breakerRulesets", "staleChannelFlushMs", "parquetChunkSizeMB", "parquetChunkDownloadTimeout", "authType", + "autoParse", "description", "connectionString", "textSecret", diff --git a/src/cribl_control_plane/models/inputazurevnetflowlog_input.py b/src/cribl_control_plane/models/inputazurevnetflowlog_input.py new file mode 100644 index 000000000..b824a2a36 --- /dev/null +++ b/src/cribl_control_plane/models/inputazurevnetflowlog_input.py @@ -0,0 +1,325 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, +) +from .certificatetype import CertificateType, CertificateTypeTypedDict +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from cribl_control_plane import models +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputAzureVnetFlowLogType(str, Enum): + r"""Connector type identifier.""" + + AZURE_VNET_FLOW_LOG = "azure_vnet_flow_log" + + +class InputAzureVnetFlowLogInputTypedDict(TypedDict): + type: InputAzureVnetFlowLogType + r"""Connector type identifier.""" + queue_name: str + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + visibility_timeout: NotRequired[float] + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + max_messages: NotRequired[float] + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" + max_dequeue_count: NotRequired[float] + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" + service_period_secs: NotRequired[float] + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] + r"""Authentication method""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + +class InputAzureVnetFlowLogInput(BaseModel): + type: InputAzureVnetFlowLogType + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" + + max_dequeue_count: Annotated[ + Optional[float], pydantic.Field(alias="maxDequeueCount") + ] = None + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" + + service_period_secs: Annotated[ + Optional[float], pydantic.Field(alias="servicePeriodSecs") + ] = None + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") + ] = None + r"""The name of your Azure storage account""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" + + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") + ] = None + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") + ] = None + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "fileFilter", + "visibilityTimeout", + "numReceivers", + "maxMessages", + "maxDequeueCount", + "servicePeriodSecs", + "metadata", + "breakerRulesets", + "staleChannelFlushMs", + "authType", + "description", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputAzureVnetFlowLogInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputbeyondtrusthec_input.py b/src/cribl_control_plane/models/inputbeyondtrusthec_input.py new file mode 100644 index 000000000..d7b784a2f --- /dev/null +++ b/src/cribl_control_plane/models/inputbeyondtrusthec_input.py @@ -0,0 +1,323 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputBeyondtrustHecType(str, Enum): + r"""Source type identifier.""" + + BEYONDTRUST_HEC = "beyondtrust_hec" + + +class InputBeyondtrustHecInputTypedDict(TypedDict): + type: InputBeyondtrustHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputBeyondtrustHecInput(BaseModel): + type: InputBeyondtrustHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputBeyondtrustHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputcloudflarehec_input.py b/src/cribl_control_plane/models/inputcloudflarehec_input.py index 33f0a9aeb..62449c81d 100644 --- a/src/cribl_control_plane/models/inputcloudflarehec_input.py +++ b/src/cribl_control_plane/models/inputcloudflarehec_input.py @@ -38,6 +38,8 @@ class TLSSettingsServerSideTypedDict(TypedDict): r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" request_cert: NotRequired[bool] r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" + ca_path: NotRequired[str] + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" common_name_regex: NotRequired[str] @@ -50,8 +52,6 @@ class TLSSettingsServerSideTypedDict(TypedDict): r"""Passphrase to use to decrypt private key""" cert_path: NotRequired[str] r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - ca_path: NotRequired[str] - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" min_version: NotRequired[MinimumTLSVersionOptionsTLS] r"""Minimum TLS version""" max_version: NotRequired[MaximumTLSVersionOptionsTLS] @@ -67,6 +67,9 @@ class TLSSettingsServerSide(BaseModel): request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" + ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -91,9 +94,6 @@ class TLSSettingsServerSide(BaseModel): cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - min_version: Annotated[ Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") ] = None @@ -128,13 +128,13 @@ def serialize_model(self, handler): [ "disabled", "requestCert", + "caPath", "rejectUnauthorized", "commonNameRegex", "certificateName", "privKeyPath", "passphrase", "certPath", - "caPath", "minVersion", "maxVersion", ] diff --git a/src/cribl_control_plane/models/inputconfluentcloud_input.py b/src/cribl_control_plane/models/inputconfluentcloud_input.py index 19d7af3e6..328d7c933 100644 --- a/src/cribl_control_plane/models/inputconfluentcloud_input.py +++ b/src/cribl_control_plane/models/inputconfluentcloud_input.py @@ -105,6 +105,8 @@ class InputConfluentCloudInputTypedDict(TypedDict): r"""Maximum number of network errors before the consumer re-creates a socket""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -262,6 +264,9 @@ class InputConfluentCloudInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -325,6 +330,7 @@ def serialize_model(self, handler): "maxBytes", "maxSocketErrors", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputcribllakehttp_input.py b/src/cribl_control_plane/models/inputcribllakehttp_input.py index 80262095e..4e7a5d83d 100644 --- a/src/cribl_control_plane/models/inputcribllakehttp_input.py +++ b/src/cribl_control_plane/models/inputcribllakehttp_input.py @@ -1,6 +1,9 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, +) from .connectionconfinputcollection import ( ConnectionConfInputCollection, ConnectionConfInputCollectionTypedDict, @@ -14,12 +17,13 @@ TLSSettingsServerSideType, TLSSettingsServerSideTypeTypedDict, ) +from cribl_control_plane import models from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum import pydantic -from pydantic import model_serializer -from typing import List, Optional -from typing_extensions import Annotated, NotRequired, TypedDict +from pydantic import field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict class InputCriblLakeHTTPType(str, Enum): @@ -28,14 +32,14 @@ class InputCriblLakeHTTPType(str, Enum): CRIBL_LAKE_HTTP = "cribl_lake_http" -class SplunkHecMetadataTypedDict(TypedDict): +class InputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict(TypedDict): enabled: NotRequired[bool] r"""When enabled, the token value is available on events as __hecToken""" default_dataset: NotRequired[str] allowed_indexes_at_token: NotRequired[List[str]] -class SplunkHecMetadata(BaseModel): +class InputHTTPAuthTypeSecretConstraintSplunkHecMetadata(BaseModel): enabled: Optional[bool] = None r"""When enabled, the token value is available on events as __hecToken""" @@ -64,13 +68,13 @@ def serialize_model(self, handler): return m -class ElasticsearchMetadataTypedDict(TypedDict): +class InputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict(TypedDict): enabled: NotRequired[bool] r"""Elasticsearch""" default_dataset: NotRequired[str] -class ElasticsearchMetadata(BaseModel): +class InputHTTPAuthTypeSecretConstraintElasticsearchMetadata(BaseModel): enabled: Optional[bool] = None r"""Elasticsearch""" @@ -95,37 +99,219 @@ def serialize_model(self, handler): return m -class AuthTokensExtTypedDict(TypedDict): +class InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Token""" + description: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + splunk_hec_metadata: NotRequired[ + InputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + InputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict + ] + + +class InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Token""" + + description: Optional[str] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + splunk_hec_metadata: Annotated[ + Optional[InputHTTPAuthTypeSecretConstraintSplunkHecMetadata], + pydantic.Field(alias="splunkHecMetadata"), + ] = None + + elasticsearch_metadata: Annotated[ + Optional[InputHTTPAuthTypeSecretConstraintElasticsearchMetadata], + pydantic.Field(alias="elasticsearchMetadata"), + ] = None + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "tokenSecret", + "token", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict(TypedDict): + enabled: NotRequired[bool] + r"""When enabled, the token value is available on events as __hecToken""" + default_dataset: NotRequired[str] + allowed_indexes_at_token: NotRequired[List[str]] + + +class InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata(BaseModel): + enabled: Optional[bool] = None + r"""When enabled, the token value is available on events as __hecToken""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict(TypedDict): + enabled: NotRequired[bool] + r"""Elasticsearch""" + default_dataset: NotRequired[str] + + +class InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata(BaseModel): + enabled: Optional[bool] = None + r"""Elasticsearch""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict(TypedDict): token: str r"""Token""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" description: NotRequired[str] metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events referencing this token""" - splunk_hec_metadata: NotRequired[SplunkHecMetadataTypedDict] - elasticsearch_metadata: NotRequired[ElasticsearchMetadataTypedDict] + splunk_hec_metadata: NotRequired[ + InputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + InputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict + ] -class AuthTokensExt(BaseModel): +class InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType(BaseModel): token: str r"""Token""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + description: Optional[str] = None metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events referencing this token""" splunk_hec_metadata: Annotated[ - Optional[SplunkHecMetadata], pydantic.Field(alias="splunkHecMetadata") + Optional[InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata], + pydantic.Field(alias="splunkHecMetadata"), ] = None elasticsearch_metadata: Annotated[ - Optional[ElasticsearchMetadata], pydantic.Field(alias="elasticsearchMetadata") + Optional[InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata], + pydantic.Field(alias="elasticsearchMetadata"), ] = None + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( - ["description", "metadata", "splunkHecMetadata", "elasticsearchMetadata"] + [ + "authType", + "tokenSecret", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] ) serialized = handler(self) m = {} @@ -141,6 +327,24 @@ def serialize_model(self, handler): return m +InputCriblLakeHTTPAuthTokensExtTypedDict = TypeAliasType( + "InputCriblLakeHTTPAuthTokensExtTypedDict", + Union[ + InputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +InputCriblLakeHTTPAuthTokensExt = TypeAliasType( + "InputCriblLakeHTTPAuthTokensExt", + Union[ + InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + ], +) + + class InputCriblLakeHTTPInputTypedDict(TypedDict): type: InputCriblLakeHTTPType r"""Source type identifier.""" @@ -201,7 +405,7 @@ class InputCriblLakeHTTPInputTypedDict(TypedDict): r"""Enable Splunk HEC acknowledgements""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[AuthTokensExtTypedDict]] + auth_tokens_ext: NotRequired[List[InputCriblLakeHTTPAuthTokensExtTypedDict]] r"""Auth tokens""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -344,7 +548,8 @@ class InputCriblLakeHTTPInput(BaseModel): r"""Fields to add to events from this input""" auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExt]], pydantic.Field(alias="authTokensExt") + Optional[List[InputCriblLakeHTTPAuthTokensExt]], + pydantic.Field(alias="authTokensExt"), ] = None r"""Auth tokens""" @@ -449,15 +654,27 @@ def serialize_model(self, handler): try: - SplunkHecMetadata.model_rebuild() + InputHTTPAuthTypeSecretConstraintSplunkHecMetadata.model_rebuild() +except NameError: + pass +try: + InputHTTPAuthTypeSecretConstraintElasticsearchMetadata.model_rebuild() +except NameError: + pass +try: + InputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + InputHTTPAuthTokensExtItemsTypeSplunkHecMetadata.model_rebuild() except NameError: pass try: - ElasticsearchMetadata.model_rebuild() + InputHTTPAuthTokensExtItemsTypeElasticsearchMetadata.model_rebuild() except NameError: pass try: - AuthTokensExt.model_rebuild() + InputCriblLakeHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() except NameError: pass try: diff --git a/src/cribl_control_plane/models/inputeventhub_input.py b/src/cribl_control_plane/models/inputeventhub_input.py index c42e79329..6f83975be 100644 --- a/src/cribl_control_plane/models/inputeventhub_input.py +++ b/src/cribl_control_plane/models/inputeventhub_input.py @@ -103,6 +103,8 @@ class InputEventhubInputTypedDict(TypedDict): r"""Minimize duplicate events by starting only one consumer for each topic partition""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -255,6 +257,9 @@ class InputEventhubInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -318,6 +323,7 @@ def serialize_model(self, handler): "maxSocketErrors", "minimizeDuplicates", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputeventhubamqp_input.py b/src/cribl_control_plane/models/inputeventhubamqp_input.py index 08b927600..f58d48ae5 100644 --- a/src/cribl_control_plane/models/inputeventhubamqp_input.py +++ b/src/cribl_control_plane/models/inputeventhubamqp_input.py @@ -2,6 +2,9 @@ from __future__ import annotations from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, +) from .certificatetype import CertificateType, CertificateTypeTypedDict from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -224,22 +227,12 @@ def serialize_model(self, handler): return m -class InputEventhubAmqpAuthenticationMethod(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Authentication method""" - - SECRET = "secret" - CLIENT_SECRET = "clientSecret" - CLIENT_CERT = "clientCert" - CLIENT_ASSERTION = "clientAssertion" - CLIENT_ASSERTION_RPC = "clientAssertion_rpc" - - class AzureBlobStorageTypedDict(TypedDict): r"""Azure Blob Storage""" container_name: str r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" - auth_type: NotRequired[InputEventhubAmqpAuthenticationMethod] + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] r"""Authentication method""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -273,7 +266,7 @@ class AzureBlobStorage(BaseModel): r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" auth_type: Annotated[ - Optional[InputEventhubAmqpAuthenticationMethod], + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], pydantic.Field(alias="authType"), ] = None r"""Authentication method""" @@ -331,7 +324,11 @@ class AzureBlobStorage(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.InputEventhubAmqpAuthenticationMethod(value) + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) + ) except ValueError: return value return value @@ -429,6 +426,8 @@ class InputEventhubAmqpInputTypedDict(TypedDict): r"""Maximum time to wait for a connection to complete""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -533,6 +532,9 @@ class InputEventhubAmqpInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -573,6 +575,7 @@ def serialize_model(self, handler): "connectionMaxBackoff", "connectionTimeoutInMs", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputexec_input.py b/src/cribl_control_plane/models/inputexec_input.py index 93b4dec55..8a5f4cf16 100644 --- a/src/cribl_control_plane/models/inputexec_input.py +++ b/src/cribl_control_plane/models/inputexec_input.py @@ -66,6 +66,8 @@ class InputExecInputTypedDict(TypedDict): r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" interval: NotRequired[float] @@ -137,6 +139,9 @@ class InputExecInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -184,6 +189,7 @@ def serialize_model(self, handler): "breakerRulesets", "staleChannelFlushMs", "metadata", + "autoParse", "description", "interval", "cronSchedule", diff --git a/src/cribl_control_plane/models/inputextrahoprevealx360_input.py b/src/cribl_control_plane/models/inputextrahoprevealx360_input.py new file mode 100644 index 000000000..ac50a7e30 --- /dev/null +++ b/src/cribl_control_plane/models/inputextrahoprevealx360_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputExtrahopRevealx360Type(str, Enum): + r"""Source type identifier.""" + + EXTRAHOP_REVEALX_360 = "extrahop_revealx_360" + + +class InputExtrahopRevealx360InputTypedDict(TypedDict): + type: InputExtrahopRevealx360Type + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputExtrahopRevealx360Input(BaseModel): + type: InputExtrahopRevealx360Type + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputExtrahopRevealx360Input.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputf5bigip_input.py b/src/cribl_control_plane/models/inputf5bigip_input.py new file mode 100644 index 000000000..6f252efbb --- /dev/null +++ b/src/cribl_control_plane/models/inputf5bigip_input.py @@ -0,0 +1,345 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputF5BigIPType(str, Enum): + r"""Source type identifier.""" + + F5_BIG_IP = "f5_big_ip" + + +class InputF5BigIPInputTypedDict(TypedDict): + type: InputF5BigIPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputF5BigIPInput(BaseModel): + type: InputF5BigIPType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputF5BigIPInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputfile_input.py b/src/cribl_control_plane/models/inputfile_input.py index 78f426661..73ab35c65 100644 --- a/src/cribl_control_plane/models/inputfile_input.py +++ b/src/cribl_control_plane/models/inputfile_input.py @@ -76,6 +76,8 @@ class InputFileInputTypedDict(TypedDict): r"""Forces files containing binary data to be streamed as text""" hash_len: NotRequired[float] r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] @@ -84,6 +86,8 @@ class InputFileInputTypedDict(TypedDict): r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" path: NotRequired[str] @@ -98,6 +102,10 @@ class InputFileInputTypedDict(TypedDict): r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" optimize_leaf_directories: NotRequired[bool] r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" + enable_discovery_throttle: NotRequired[bool] + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" + discovery_throttle_cpu_percent: NotRequired[float] + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" include_unidentifiable_binary: NotRequired[bool] r"""Stream binary files as Base64-encoded chunks""" template_environment: NotRequired[str] @@ -175,6 +183,11 @@ class InputFileInput(BaseModel): hash_len: Annotated[Optional[float], pydantic.Field(alias="hashLen")] = None r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -193,6 +206,9 @@ class InputFileInput(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -218,6 +234,16 @@ class InputFileInput(BaseModel): ] = None r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" + enable_discovery_throttle: Annotated[ + Optional[bool], pydantic.Field(alias="enableDiscoveryThrottle") + ] = None + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" + + discovery_throttle_cpu_percent: Annotated[ + Optional[float], pydantic.Field(alias="discoveryThrottleCpuPercent") + ] = None + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" + include_unidentifiable_binary: Annotated[ Optional[bool], pydantic.Field(alias="includeUnidentifiableBinary") ] = None @@ -266,10 +292,12 @@ def serialize_model(self, handler): "checkFileModTime", "forceText", "hashLen", + "enableLoadBalancing", "metadata", "breakerRulesets", "disableStaleChannelFlush", "staleChannelFlushMs", + "autoParse", "description", "path", "depth", @@ -277,6 +305,8 @@ def serialize_model(self, handler): "deleteFiles", "saltHash", "optimizeLeafDirectories", + "enableDiscoveryThrottle", + "discoveryThrottleCpuPercent", "includeUnidentifiableBinary", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputgigamonhec_input.py b/src/cribl_control_plane/models/inputgigamonhec_input.py new file mode 100644 index 000000000..7004a6d1f --- /dev/null +++ b/src/cribl_control_plane/models/inputgigamonhec_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputGigamonHecType(str, Enum): + r"""Source type identifier.""" + + GIGAMON_HEC = "gigamon_hec" + + +class InputGigamonHecInputTypedDict(TypedDict): + type: InputGigamonHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputGigamonHecInput(BaseModel): + type: InputGigamonHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputGigamonHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputgooglepubsub_input.py b/src/cribl_control_plane/models/inputgooglepubsub_input.py index 3726d90da..3dc9abeff 100644 --- a/src/cribl_control_plane/models/inputgooglepubsub_input.py +++ b/src/cribl_control_plane/models/inputgooglepubsub_input.py @@ -66,6 +66,8 @@ class InputGooglePubsubInputTypedDict(TypedDict): r"""Pull request timeout, in milliseconds""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" ordered_delivery: NotRequired[bool] @@ -164,6 +166,9 @@ class InputGooglePubsubInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -230,6 +235,7 @@ def serialize_model(self, handler): "concurrency", "requestTimeout", "metadata", + "autoParse", "description", "orderedDelivery", "__template_environment", diff --git a/src/cribl_control_plane/models/inputhashicorphcpvaultdedicated_input.py b/src/cribl_control_plane/models/inputhashicorphcpvaultdedicated_input.py new file mode 100644 index 000000000..a973d5f44 --- /dev/null +++ b/src/cribl_control_plane/models/inputhashicorphcpvaultdedicated_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputHashicorpHcpVaultDedicatedType(str, Enum): + r"""Source type identifier.""" + + HASHICORP_HCP_VAULT_DEDICATED = "hashicorp_hcp_vault_dedicated" + + +class InputHashicorpHcpVaultDedicatedInputTypedDict(TypedDict): + type: InputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputHashicorpHcpVaultDedicatedInput(BaseModel): + type: InputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputHashicorpHcpVaultDedicatedInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputhttp_input.py b/src/cribl_control_plane/models/inputhttp_input.py index ef9bfbaa8..6c7e2d62e 100644 --- a/src/cribl_control_plane/models/inputhttp_input.py +++ b/src/cribl_control_plane/models/inputhttp_input.py @@ -1,9 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -18,12 +17,13 @@ TLSSettingsServerSideType, TLSSettingsServerSideTypeTypedDict, ) +from cribl_control_plane import models from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum import pydantic -from pydantic import model_serializer -from typing import List, Optional -from typing_extensions import Annotated, NotRequired, TypedDict +from pydantic import field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict class InputHTTPType(str, Enum): @@ -32,6 +32,139 @@ class InputHTTPType(str, Enum): HTTP = "http" +class InputHTTPInputHTTPAuthTypeSecretConstraintTypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputHTTPInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputHTTPInputHTTPAuthTokensExtItemsType(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +InputHTTPAuthTokensExtTypedDict = TypeAliasType( + "InputHTTPAuthTokensExtTypedDict", + Union[ + InputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +InputHTTPAuthTokensExt = TypeAliasType( + "InputHTTPAuthTokensExt", + Union[ + InputHTTPInputHTTPAuthTokensExtItemsType, + InputHTTPInputHTTPAuthTypeSecretConstraint, + ], +) + + class InputHTTPInputTypedDict(TypedDict): type: InputHTTPType r"""Source type identifier.""" @@ -92,7 +225,7 @@ class InputHTTPInputTypedDict(TypedDict): r"""Enable Splunk HEC acknowledgements""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] + auth_tokens_ext: NotRequired[List[InputHTTPAuthTokensExtTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -235,8 +368,7 @@ class InputHTTPInput(BaseModel): r"""Fields to add to events from this input""" auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], - pydantic.Field(alias="authTokensExt"), + Optional[List[InputHTTPAuthTokensExt]], pydantic.Field(alias="authTokensExt") ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -340,6 +472,14 @@ def serialize_model(self, handler): return m +try: + InputHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + InputHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() +except NameError: + pass try: InputHTTPInput.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/inputhttpraw_input.py b/src/cribl_control_plane/models/inputhttpraw_input.py index 70fe4ead4..889a414f9 100644 --- a/src/cribl_control_plane/models/inputhttpraw_input.py +++ b/src/cribl_control_plane/models/inputhttpraw_input.py @@ -1,9 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -18,12 +17,13 @@ TLSSettingsServerSideType, TLSSettingsServerSideTypeTypedDict, ) +from cribl_control_plane import models from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum import pydantic -from pydantic import model_serializer -from typing import List, Optional -from typing_extensions import Annotated, NotRequired, TypedDict +from pydantic import field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict class InputHTTPRawType(str, Enum): @@ -32,6 +32,136 @@ class InputHTTPRawType(str, Enum): HTTP_RAW = "http_raw" +class InputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputHTTPRawInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputHTTPRawAuthTokensExtTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputHTTPRawAuthTokensExt(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +InputHTTPRawAuthTokensExtUnionTypedDict = TypeAliasType( + "InputHTTPRawAuthTokensExtUnionTypedDict", + Union[ + InputHTTPRawAuthTokensExtTypedDict, + InputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +InputHTTPRawAuthTokensExtUnion = TypeAliasType( + "InputHTTPRawAuthTokensExtUnion", + Union[InputHTTPRawAuthTokensExt, InputHTTPRawInputHTTPAuthTypeSecretConstraint], +) + + class InputHTTPRawInputTypedDict(TypedDict): type: InputHTTPRawType r"""Source type identifier.""" @@ -86,13 +216,15 @@ class InputHTTPRawInputTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" allowed_paths: NotRequired[List[str]] r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" allowed_methods: NotRequired[List[str]] r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] + auth_tokens_ext: NotRequired[List[InputHTTPRawAuthTokensExtUnionTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" access_control_allow_origin: NotRequired[List[str]] r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" @@ -237,6 +369,9 @@ class InputHTTPRawInput(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -251,7 +386,7 @@ class InputHTTPRawInput(BaseModel): r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], + Optional[List[InputHTTPRawAuthTokensExtUnion]], pydantic.Field(alias="authTokensExt"), ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -357,6 +492,7 @@ def serialize_model(self, handler): "ipDenylistRegex", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "metadata", "allowedPaths", "allowedMethods", @@ -392,6 +528,14 @@ def serialize_model(self, handler): return m +try: + InputHTTPRawInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + InputHTTPRawAuthTokensExt.model_rebuild() +except NameError: + pass try: InputHTTPRawInput.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/inputjournalfiles_input.py b/src/cribl_control_plane/models/inputjournalfiles_input.py index ef59721c0..f10a3acb8 100644 --- a/src/cribl_control_plane/models/inputjournalfiles_input.py +++ b/src/cribl_control_plane/models/inputjournalfiles_input.py @@ -91,6 +91,8 @@ class InputJournalFilesInputTypedDict(TypedDict): r"""Suppress errors when search path does not exist""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -157,6 +159,9 @@ class InputJournalFilesInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -189,6 +194,7 @@ def serialize_model(self, handler): "maxAgeDur", "suppressMissingPathErrors", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputkafka_input.py b/src/cribl_control_plane/models/inputkafka_input.py index 3af32a9af..1fb0621f1 100644 --- a/src/cribl_control_plane/models/inputkafka_input.py +++ b/src/cribl_control_plane/models/inputkafka_input.py @@ -105,6 +105,8 @@ class InputKafkaInputTypedDict(TypedDict): r"""Maximum number of network errors before the consumer re-creates a socket""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -262,6 +264,9 @@ class InputKafkaInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -325,6 +330,7 @@ def serialize_model(self, handler): "maxBytes", "maxSocketErrors", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputkinesis_input.py b/src/cribl_control_plane/models/inputkinesis_input.py index 60b96a535..a49f28e34 100644 --- a/src/cribl_control_plane/models/inputkinesis_input.py +++ b/src/cribl_control_plane/models/inputkinesis_input.py @@ -116,6 +116,8 @@ class InputKinesisInputTypedDict(TypedDict): r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] @@ -274,6 +276,9 @@ class InputKinesisInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -406,6 +411,7 @@ def serialize_model(self, handler): "verifyKPLCheckSums", "avoidDuplicates", "metadata", + "autoParse", "description", "awsApiKey", "awsSecret", diff --git a/src/cribl_control_plane/models/inputmicrosoftcopilot_input.py b/src/cribl_control_plane/models/inputmicrosoftcopilot_input.py new file mode 100644 index 000000000..bce4ad86d --- /dev/null +++ b/src/cribl_control_plane/models/inputmicrosoftcopilot_input.py @@ -0,0 +1,512 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .retrytypeoptionshealthcheckcollectorconfretryrules import ( + RetryTypeOptionsHealthCheckCollectorConfRetryRules, +) +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputMicrosoftCopilotType(str, Enum): + r"""Connector type identifier.""" + + MICROSOFT_COPILOT = "microsoft_copilot" + + +class InputMicrosoftCopilotAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class InputMicrosoftCopilotSubscriptionPlan(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + + ENTERPRISE_GCC = "enterprise_gcc" + GCC = "gcc" + GCC_HIGH = "gcc_high" + DOD = "dod" + + +class InputMicrosoftCopilotManageStateTypedDict(TypedDict): + pass + + +class InputMicrosoftCopilotManageState(BaseModel): + pass + + +class InputMicrosoftCopilotRetryRulesTypedDict(TypedDict): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + interval: NotRequired[float] + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + limit: NotRequired[float] + r"""The maximum number of times to retry a failed HTTP request""" + multiplier: NotRequired[float] + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + codes: NotRequired[List[float]] + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + enable_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + retry_connect_timeout: NotRequired[bool] + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + retry_connect_reset: NotRequired[bool] + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + +class InputMicrosoftCopilotRetryRules(BaseModel): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + + interval: Optional[float] = None + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + + limit: Optional[float] = None + r"""The maximum number of times to retry a failed HTTP request""" + + multiplier: Optional[float] = None + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + + codes: Optional[List[float]] = None + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( + None + ) + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + + retry_connect_timeout: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectTimeout") + ] = None + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + + retry_connect_reset: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectReset") + ] = None + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + @field_serializer("type") + def serialize_type(self, value): + if isinstance(value, str): + try: + return models.RetryTypeOptionsHealthCheckCollectorConfRetryRules(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "interval", + "limit", + "multiplier", + "codes", + "enableHeader", + "retryConnectTimeout", + "retryConnectReset", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class CertOptionsTypedDict(TypedDict): + priv_key_path: str + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + cert_path: str + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + certificate_name: NotRequired[str] + r"""The name of a predefined certificate""" + passphrase: NotRequired[str] + r"""Passphrase to decrypt the private key""" + + +class CertOptions(BaseModel): + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The name of a predefined certificate""" + + passphrase: Optional[str] = None + r"""Passphrase to decrypt the private key""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["certificateName", "passphrase"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputMicrosoftCopilotInputTypedDict(TypedDict): + type: InputMicrosoftCopilotType + r"""Connector type identifier.""" + tenant_id: str + r"""Directory (tenant) ID from Azure Active Directory""" + client_id: str + r"""Application (client) ID from the app registration""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + resource: NotRequired[str] + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" + auth_type: NotRequired[InputMicrosoftCopilotAuthenticationMethod] + r"""Select authentication method.""" + plan_type: NotRequired[InputMicrosoftCopilotSubscriptionPlan] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + cron_schedule: NotRequired[str] + r"""Cron schedule for collection runs""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + page_size: NotRequired[int] + r"""Number of interactions to request per page ($top). Maximum 1000.""" + app_class_filter: NotRequired[List[str]] + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" + filter_by_license: NotRequired[bool] + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" + sku_ids: NotRequired[List[str]] + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" + manage_state: NotRequired[InputMicrosoftCopilotManageStateTypedDict] + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + retry_rules: NotRequired[InputMicrosoftCopilotRetryRulesTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + text_secret: NotRequired[str] + r"""Select or create a secret that references the client secret from your app registration""" + cert_options: NotRequired[CertOptionsTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + +class InputMicrosoftCopilotInput(BaseModel): + type: InputMicrosoftCopilotType + r"""Connector type identifier.""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Directory (tenant) ID from Azure Active Directory""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""Application (client) ID from the app registration""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + resource: Optional[str] = None + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" + + auth_type: Annotated[ + Optional[InputMicrosoftCopilotAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" + + plan_type: Annotated[ + Optional[InputMicrosoftCopilotSubscriptionPlan], + pydantic.Field(alias="planType"), + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Cron schedule for collection runs""" + + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" + + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" + + page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None + r"""Number of interactions to request per page ($top). Maximum 1000.""" + + app_class_filter: Annotated[ + Optional[List[str]], pydantic.Field(alias="appClassFilter") + ] = None + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" + + filter_by_license: Annotated[ + Optional[bool], pydantic.Field(alias="filterByLicense") + ] = None + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" + + sku_ids: Annotated[Optional[List[str]], pydantic.Field(alias="skuIds")] = None + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" + + manage_state: Annotated[ + Optional[InputMicrosoftCopilotManageState], pydantic.Field(alias="manageState") + ] = None + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + retry_rules: Annotated[ + Optional[InputMicrosoftCopilotRetryRules], pydantic.Field(alias="retryRules") + ] = None + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references the client secret from your app registration""" + + cert_options: Annotated[ + Optional[CertOptions], pydantic.Field(alias="certOptions") + ] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputMicrosoftCopilotAuthenticationMethod(value) + except ValueError: + return value + return value + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.InputMicrosoftCopilotSubscriptionPlan(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "resource", + "authType", + "planType", + "cronSchedule", + "earliest", + "latest", + "pageSize", + "appClassFilter", + "filterByLicense", + "skuIds", + "manageState", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", + "breakerRulesets", + "staleChannelFlushMs", + "description", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_tenantId", + "__template_clientId", + "__template_planType", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputMicrosoftCopilotRetryRules.model_rebuild() +except NameError: + pass +try: + CertOptions.model_rebuild() +except NameError: + pass +try: + InputMicrosoftCopilotInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputmicrosoftgraph_input.py b/src/cribl_control_plane/models/inputmicrosoftgraph_input.py index f3fb1e6a2..a012b3fb4 100644 --- a/src/cribl_control_plane/models/inputmicrosoftgraph_input.py +++ b/src/cribl_control_plane/models/inputmicrosoftgraph_input.py @@ -39,7 +39,7 @@ class InputMicrosoftGraphAuthenticationMethod(str, Enum, metaclass=utils.OpenEnu OAUTH_CERT = "oauthCert" -class SubscriptionPlan(str, Enum, metaclass=utils.OpenEnumMeta): +class InputMicrosoftGraphSubscriptionPlan(str, Enum, metaclass=utils.OpenEnumMeta): r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" # Microsoft 365 Enterprise @@ -123,7 +123,7 @@ class InputMicrosoftGraphInputTypedDict(TypedDict): r"""client_id to pass in the OAuth request parameter.""" resource: NotRequired[str] r"""Resource to pass in the OAuth request parameter.""" - plan_type: NotRequired[SubscriptionPlan] + plan_type: NotRequired[InputMicrosoftGraphSubscriptionPlan] r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" text_secret: NotRequired[str] r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" @@ -274,7 +274,7 @@ class InputMicrosoftGraphInput(BaseModel): r"""Resource to pass in the OAuth request parameter.""" plan_type: Annotated[ - Optional[SubscriptionPlan], pydantic.Field(alias="planType") + Optional[InputMicrosoftGraphSubscriptionPlan], pydantic.Field(alias="planType") ] = None r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" @@ -342,7 +342,7 @@ def serialize_log_level(self, value): def serialize_plan_type(self, value): if isinstance(value, str): try: - return models.SubscriptionPlan(value) + return models.InputMicrosoftGraphSubscriptionPlan(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/inputmimecasthec_input.py b/src/cribl_control_plane/models/inputmimecasthec_input.py new file mode 100644 index 000000000..6a24b335f --- /dev/null +++ b/src/cribl_control_plane/models/inputmimecasthec_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputMimecastHecType(str, Enum): + r"""Source type identifier.""" + + MIMECAST_HEC = "mimecast_hec" + + +class InputMimecastHecInputTypedDict(TypedDict): + type: InputMimecastHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputMimecastHecInput(BaseModel): + type: InputMimecastHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputMimecastHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputmodeldriventelemetry_input.py b/src/cribl_control_plane/models/inputmodeldriventelemetry_input.py index 79d007ac0..9aa0a49e3 100644 --- a/src/cribl_control_plane/models/inputmodeldriventelemetry_input.py +++ b/src/cribl_control_plane/models/inputmodeldriventelemetry_input.py @@ -58,6 +58,10 @@ class InputModelDrivenTelemetryInputTypedDict(TypedDict): r"""Fields to add to events from this input""" max_active_cxn: NotRequired[float] r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" shutdown_timeout_ms: NotRequired[float] r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" description: NotRequired[str] @@ -121,6 +125,16 @@ class InputModelDrivenTelemetryInput(BaseModel): ) r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") + ] = None + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") + ] = None + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" + shutdown_timeout_ms: Annotated[ Optional[float], pydantic.Field(alias="shutdownTimeoutMs") ] = None @@ -165,6 +179,8 @@ def serialize_model(self, handler): "tls", "metadata", "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", "shutdownTimeoutMs", "description", "__template_environment", diff --git a/src/cribl_control_plane/models/inputmsk_input.py b/src/cribl_control_plane/models/inputmsk_input.py index 5bc832227..c0bd37e8f 100644 --- a/src/cribl_control_plane/models/inputmsk_input.py +++ b/src/cribl_control_plane/models/inputmsk_input.py @@ -126,6 +126,8 @@ class InputMskInputTypedDict(TypedDict): r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" max_socket_errors: NotRequired[float] r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] @@ -343,6 +345,9 @@ class InputMskInput(BaseModel): ] = None r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -458,6 +463,7 @@ def serialize_model(self, handler): "maxBytesPerPartition", "maxBytes", "maxSocketErrors", + "autoParse", "description", "awsApiKey", "awsSecret", diff --git a/src/cribl_control_plane/models/inputopenai_input.py b/src/cribl_control_plane/models/inputopenai_input.py index 25092c294..fe62b2585 100644 --- a/src/cribl_control_plane/models/inputopenai_input.py +++ b/src/cribl_control_plane/models/inputopenai_input.py @@ -79,9 +79,9 @@ class ContentConfigInputTypedDict(TypedDict): state_tracking: NotRequired[bool] r"""Track collection progress between consecutive scheduled executions.""" state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: NotRequired[InputOpenaiManageStateTypedDict] pagination_attribute: NotRequired[List[str]] r"""Pagination attributes""" @@ -131,12 +131,12 @@ class ContentConfigInput(BaseModel): state_update_expression: Annotated[ Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" state_merge_expression: Annotated[ Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" manage_state: Annotated[ Optional[InputOpenaiManageState], pydantic.Field(alias="manageState") diff --git a/src/cribl_control_plane/models/inputopentelemetry_input.py b/src/cribl_control_plane/models/inputopentelemetry_input.py index 9771e01c4..f7a358c82 100644 --- a/src/cribl_control_plane/models/inputopentelemetry_input.py +++ b/src/cribl_control_plane/models/inputopentelemetry_input.py @@ -73,6 +73,8 @@ class AuthMethodsExtAuthenticationType(str, Enum, metaclass=utils.OpenEnumMeta): BASIC = "basic" # Basic (credentials secret) BASIC_SECRET = "basicSecret" + # OAuth + OAUTH = "oauth" class AuthMethodsExtTypedDict(TypedDict): @@ -94,6 +96,14 @@ class AuthMethodsExtTypedDict(TypedDict): r"""Password""" credentials_secret: NotRequired[str] r"""Select or create a secret that references your credentials""" + issuer: NotRequired[str] + r"""Expected token issuer (iss claim)""" + jwks_uri: NotRequired[str] + r"""URL of the JWKS endpoint used to fetch signing keys""" + audience: NotRequired[str] + r"""Expected token audience (aud claim)""" + scopes: NotRequired[List[str]] + r"""Scopes the token must grant (optional)""" class AuthMethodsExt(BaseModel): @@ -128,6 +138,18 @@ class AuthMethodsExt(BaseModel): ] = None r"""Select or create a secret that references your credentials""" + issuer: Optional[str] = None + r"""Expected token issuer (iss claim)""" + + jwks_uri: Annotated[Optional[str], pydantic.Field(alias="jwksUri")] = None + r"""URL of the JWKS endpoint used to fetch signing keys""" + + audience: Optional[str] = None + r"""Expected token audience (aud claim)""" + + scopes: Optional[List[str]] = None + r"""Scopes the token must grant (optional)""" + @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): @@ -149,6 +171,10 @@ def serialize_model(self, handler): "username", "password", "credentialsSecret", + "issuer", + "jwksUri", + "audience", + "scopes", ] ) serialized = handler(self) @@ -218,11 +244,15 @@ class InputOpenTelemetryInputTypedDict(TypedDict): auth_type: NotRequired[InputOpenTelemetryAuthenticationType] r"""OpenTelemetry authentication type""" auth_methods_ext: NotRequired[List[AuthMethodsExtTypedDict]] - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: NotRequired[str] r"""Optional description for this configuration.""" username: NotRequired[str] @@ -358,7 +388,7 @@ class InputOpenTelemetryInput(BaseModel): auth_methods_ext: Annotated[ Optional[List[AuthMethodsExt]], pydantic.Field(alias="authMethodsExt") ] = None - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -366,7 +396,17 @@ class InputOpenTelemetryInput(BaseModel): max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" + + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") + ] = None + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" + + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") + ] = None + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -478,6 +518,8 @@ def serialize_model(self, handler): "authMethodsExt", "metadata", "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", "description", "username", "password", diff --git a/src/cribl_control_plane/models/inputpingidentitypingone_input.py b/src/cribl_control_plane/models/inputpingidentitypingone_input.py new file mode 100644 index 000000000..e8a99906a --- /dev/null +++ b/src/cribl_control_plane/models/inputpingidentitypingone_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputPingIdentityPingoneType(str, Enum): + r"""Source type identifier.""" + + PING_IDENTITY_PINGONE = "ping_identity_pingone" + + +class InputPingIdentityPingoneInputTypedDict(TypedDict): + type: InputPingIdentityPingoneType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputPingIdentityPingoneInput(BaseModel): + type: InputPingIdentityPingoneType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputPingIdentityPingoneInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputproofpointpod_input.py b/src/cribl_control_plane/models/inputproofpointpod_input.py new file mode 100644 index 000000000..d72a9b186 --- /dev/null +++ b/src/cribl_control_plane/models/inputproofpointpod_input.py @@ -0,0 +1,231 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsclientsidetypecapathcertpath import ( + TLSSettingsClientSideTypeCaPathCertPath, + TLSSettingsClientSideTypeCaPathCertPathTypedDict, +) +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputProofpointPodType(str, Enum): + r"""Connector type identifier.""" + + PROOFPOINT_POD = "proofpoint_pod" + + +class FeedType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Proofpoint on Demand feed to ingest.""" + + # Message + MESSAGE = "message" + # Mail log + MAILLOG = "maillog" + # Audit + AUDIT = "audit" + + +class InputProofpointPodInputTypedDict(TypedDict): + type: InputProofpointPodType + r"""Connector type identifier.""" + cluster_id: str + r"""Proofpoint on Demand cluster ID.""" + feed_type: FeedType + r"""Proofpoint on Demand feed to ingest.""" + text_secret: str + r"""Select or create a stored text secret""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + compress: NotRequired[bool] + r"""Compress the feed connection.""" + handshake_timeout: NotRequired[float] + r"""Maximum time to wait for the connection handshake to complete.""" + keep_alive_interval_sec: NotRequired[float] + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" + max_missed_keep_alives: NotRequired[float] + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" + max_message_size: NotRequired[str] + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" + read_buffer_size: NotRequired[str] + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_cluster_id: NotRequired[str] + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" + + +class InputProofpointPodInput(BaseModel): + type: InputProofpointPodType + r"""Connector type identifier.""" + + cluster_id: Annotated[str, pydantic.Field(alias="clusterId")] + r"""Proofpoint on Demand cluster ID.""" + + feed_type: Annotated[FeedType, pydantic.Field(alias="feedType")] + r"""Proofpoint on Demand feed to ingest.""" + + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + compress: Optional[bool] = None + r"""Compress the feed connection.""" + + handshake_timeout: Annotated[ + Optional[float], pydantic.Field(alias="handshakeTimeout") + ] = None + r"""Maximum time to wait for the connection handshake to complete.""" + + keep_alive_interval_sec: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveIntervalSec") + ] = None + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" + + max_message_size: Annotated[ + Optional[str], pydantic.Field(alias="maxMessageSize") + ] = None + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" + + read_buffer_size: Annotated[ + Optional[str], pydantic.Field(alias="readBufferSize") + ] = None + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_cluster_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clusterId") + ] = None + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" + + @field_serializer("feed_type") + def serialize_feed_type(self, value): + if isinstance(value, str): + try: + return models.FeedType(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "tls", + "compress", + "handshakeTimeout", + "keepAliveIntervalSec", + "maxMissedKeepAlives", + "maxMessageSize", + "readBufferSize", + "description", + "__template_environment", + "__template_streamtags", + "__template_clusterId", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputProofpointPodInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.py b/src/cribl_control_plane/models/inputprovenancetypeoptional.py similarity index 56% rename from src/cribl_control_plane/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.py rename to src/cribl_control_plane/models/inputprovenancetypeoptional.py index 19dee6ddf..bc465193c 100644 --- a/src/cribl_control_plane/models/inputcollectionorigindatasourcediscoverywithdestinationarnconstraint.py +++ b/src/cribl_control_plane/models/inputprovenancetypeoptional.py @@ -1,40 +1,39 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from cribl_control_plane import models, utils +from .originoptionscriblsourceprovenance import OriginOptionsCriblSourceProvenance +from .templatefamilyoptionscriblsourceprovenance import ( + TemplateFamilyOptionsCriblSourceProvenance, +) +from cribl_control_plane import models from cribl_control_plane.types import BaseModel, UNSET_SENTINEL -from enum import Enum import pydantic from pydantic import field_serializer, model_serializer from typing import Optional from typing_extensions import Annotated, NotRequired, TypedDict -class Origin(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Feature that created the Source.""" - - DATA_SOURCE_DISCOVERY = "data_source_discovery" - - -class InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict( - TypedDict -): +class InputProvenanceTypeOptionalTypedDict(TypedDict): r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - origin: NotRequired[Origin] + origin: NotRequired[OriginOptionsCriblSourceProvenance] r"""Feature that created the Source.""" destination_arn: NotRequired[str] r"""ARN of the S3 bucket or Firehose delivery stream configured as the Source.""" source_arn: NotRequired[str] r"""ARN of the AWS resource that produces the logs.""" + source_service: NotRequired[str] + r"""Resolved DSD source-service offering, when known.""" account_id: NotRequired[str] r"""Cloud tenant or scope id the Source was configured for (for example an AWS account id, GCP project or folder id, or Azure subscription or resource group id).""" + template_family: NotRequired[TemplateFamilyOptionsCriblSourceProvenance] + r"""Infrastructure-as-code family that provisioned the AWS resources (absent means cloudformation).""" -class InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint(BaseModel): +class InputProvenanceTypeOptional(BaseModel): r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - origin: Optional[Origin] = None + origin: Optional[OriginOptionsCriblSourceProvenance] = None r"""Feature that created the Source.""" destination_arn: Annotated[ @@ -45,21 +44,50 @@ class InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint(BaseM source_arn: Annotated[Optional[str], pydantic.Field(alias="sourceArn")] = None r"""ARN of the AWS resource that produces the logs.""" + source_service: Annotated[Optional[str], pydantic.Field(alias="sourceService")] = ( + None + ) + r"""Resolved DSD source-service offering, when known.""" + account_id: Annotated[Optional[str], pydantic.Field(alias="accountId")] = None r"""Cloud tenant or scope id the Source was configured for (for example an AWS account id, GCP project or folder id, or Azure subscription or resource group id).""" + template_family: Annotated[ + Optional[TemplateFamilyOptionsCriblSourceProvenance], + pydantic.Field(alias="templateFamily"), + ] = None + r"""Infrastructure-as-code family that provisioned the AWS resources (absent means cloudformation).""" + @field_serializer("origin") def serialize_origin(self, value): if isinstance(value, str): try: - return models.Origin(value) + return models.OriginOptionsCriblSourceProvenance(value) + except ValueError: + return value + return value + + @field_serializer("template_family") + def serialize_template_family(self, value): + if isinstance(value, str): + try: + return models.TemplateFamilyOptionsCriblSourceProvenance(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["origin", "destinationArn", "sourceArn", "accountId"]) + optional_fields = set( + [ + "origin", + "destinationArn", + "sourceArn", + "sourceService", + "accountId", + "templateFamily", + ] + ) serialized = handler(self) m = {} @@ -75,6 +103,6 @@ def serialize_model(self, handler): try: - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint.model_rebuild() + InputProvenanceTypeOptional.model_rebuild() except NameError: pass diff --git a/src/cribl_control_plane/models/inputrawudp_input.py b/src/cribl_control_plane/models/inputrawudp_input.py index fb1bfd870..78e125837 100644 --- a/src/cribl_control_plane/models/inputrawudp_input.py +++ b/src/cribl_control_plane/models/inputrawudp_input.py @@ -60,6 +60,8 @@ class InputRawUDPInputTypedDict(TypedDict): r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -138,6 +140,9 @@ class InputRawUDPInput(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -180,6 +185,7 @@ def serialize_model(self, handler): "ingestRawBytes", "udpSocketRxBufSize", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputresponse.py b/src/cribl_control_plane/models/inputresponse.py index 8845c60e6..405c1e886 100644 --- a/src/cribl_control_plane/models/inputresponse.py +++ b/src/cribl_control_plane/models/inputresponse.py @@ -2,62 +2,40 @@ from __future__ import annotations from .authenticationmethodoptions import AuthenticationMethodOptions -from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) -from .authenticationmethodoptionsmanualsecret import ( - AuthenticationMethodOptionsManualSecret, +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, ) from .authenticationmethodoptionss3collectorconf import ( AuthenticationMethodOptionsS3CollectorConf, ) -from .authenticationmethodoptionssasl import AuthenticationMethodOptionsSasl from .authenticationtype import AuthenticationType, AuthenticationTypeTypedDict -from .authenticationtypeoptionslokiauth import AuthenticationTypeOptionsLokiAuth -from .authenticationtypeoptionsprometheusauth import ( - AuthenticationTypeOptionsPrometheusAuth, -) -from .authenticationtypeuse import AuthenticationTypeUse, AuthenticationTypeUseTypedDict -from .authtokenconfinputcribltcp import ( - AuthTokenConfInputCriblTCP, - AuthTokenConfInputCriblTCPTypedDict, -) -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, -) from .certificatetype import CertificateType, CertificateTypeTypedDict -from .certoptionstype import CertOptionsType, CertOptionsTypeTypedDict from .connectionconfinputcollection import ( ConnectionConfInputCollection, ConnectionConfInputCollectionTypedDict, ) -from .datacompressionformatoptionspersistence import ( - DataCompressionFormatOptionsPersistence, -) -from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict from .extrahttpheaderconfinputelastic import ( ExtraHTTPHeaderConfInputElastic, ExtraHTTPHeaderConfInputElasticTypedDict, ) -from .googleauthenticationmethodoptions import GoogleAuthenticationMethodOptions -from .gputype import GpuType, GpuTypeTypedDict -from .inputcollectionorigindatasourcediscoverywithdestinationarnconstraint import ( - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint, - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict, +from .inputprovenancetypeoptional import ( + InputProvenanceTypeOptional, + InputProvenanceTypeOptionalTypedDict, ) -from .inputresponse_inputkubemetrics import ( - InputResponseInputAnthropicCompliance, - InputResponseInputAnthropicComplianceTypedDict, - InputResponseInputAppleUnifiedLogs, - InputResponseInputAppleUnifiedLogsTypedDict, - InputResponseInputAppscope, - InputResponseInputAppscopeTypedDict, - InputResponseInputBedrockS3, - InputResponseInputBedrockS3TypedDict, - InputResponseInputCloudflareHec, - InputResponseInputCloudflareHecTypedDict, +from .inputresponse_inputelastic_type import ( + InputResponseInputConfluentCloud, + InputResponseInputConfluentCloudTypedDict, + InputResponseInputCribl, + InputResponseInputCriblHTTP, + InputResponseInputCriblHTTPTypedDict, + InputResponseInputCriblLakeHTTP, + InputResponseInputCriblLakeHTTPTypedDict, + InputResponseInputCriblTCP, + InputResponseInputCriblTCPTypedDict, + InputResponseInputCriblTypedDict, InputResponseInputCriblmetrics, InputResponseInputCriblmetricsTypedDict, InputResponseInputCrowdstrike, @@ -66,12 +44,23 @@ InputResponseInputDatadogAgentTypedDict, InputResponseInputDatagen, InputResponseInputDatagenTypedDict, - InputResponseInputFile, - InputResponseInputFileTypedDict, + InputResponseInputEdgePrometheus, + InputResponseInputEdgePrometheusTypedDict, + InputResponseInputElasticType, + InputResponseInputEventhub, + InputResponseInputEventhubAmqp, + InputResponseInputEventhubAmqpTypedDict, + InputResponseInputEventhubTypedDict, + InputResponseInputExec, + InputResponseInputExecTypedDict, + InputResponseInputFirehose, + InputResponseInputFirehoseTypedDict, + InputResponseInputGooglePubsub, + InputResponseInputGooglePubsubTypedDict, + InputResponseInputGrafanaUnion, + InputResponseInputGrafanaUnionTypedDict, InputResponseInputHTTPRaw, InputResponseInputHTTPRawTypedDict, - InputResponseInputJournalFiles, - InputResponseInputJournalFilesTypedDict, InputResponseInputKinesis, InputResponseInputKinesisTypedDict, InputResponseInputKubeEvents, @@ -80,8 +69,72 @@ InputResponseInputKubeLogsTypedDict, InputResponseInputKubeMetrics, InputResponseInputKubeMetricsTypedDict, + InputResponseInputLoki, + InputResponseInputLokiTypedDict, InputResponseInputMetrics, InputResponseInputMetricsTypedDict, + InputResponseInputMicrosoftGraph, + InputResponseInputMicrosoftGraphTypedDict, + InputResponseInputOffice365Mgmt, + InputResponseInputOffice365MgmtTypedDict, + InputResponseInputOffice365MsgTrace, + InputResponseInputOffice365MsgTraceTypedDict, + InputResponseInputOffice365Service, + InputResponseInputOffice365ServiceTypedDict, + InputResponseInputPrometheus, + InputResponseInputPrometheusRw, + InputResponseInputPrometheusRwTypedDict, + InputResponseInputPrometheusTypedDict, + InputResponseInputS3, + InputResponseInputS3Inventory, + InputResponseInputS3InventoryTypedDict, + InputResponseInputS3TypedDict, + InputResponseInputSnmp, + InputResponseInputSnmpTypedDict, + InputResponseInputSystemMetrics, + InputResponseInputSystemMetricsTypedDict, + InputResponseInputSystemState, + InputResponseInputSystemStateTypedDict, + InputResponseInputTcpjson, + InputResponseInputTcpjsonTypedDict, + InputResponseInputWindowsMetrics, + InputResponseInputWindowsMetricsTypedDict, +) +from .inputresponse_v3user import ( + InputResponseInputAkamaiHec, + InputResponseInputAkamaiHecTypedDict, + InputResponseInputAnthropicCompliance, + InputResponseInputAnthropicComplianceTypedDict, + InputResponseInputAnthropicEnterpriseAnalytics, + InputResponseInputAnthropicEnterpriseAnalyticsTypedDict, + InputResponseInputAppleUnifiedLogs, + InputResponseInputAppleUnifiedLogsTypedDict, + InputResponseInputAppscope, + InputResponseInputAppscopeTypedDict, + InputResponseInputAquaSecurityHec, + InputResponseInputAquaSecurityHecTypedDict, + InputResponseInputBedrockS3, + InputResponseInputBedrockS3TypedDict, + InputResponseInputBeyondtrustHec, + InputResponseInputBeyondtrustHecTypedDict, + InputResponseInputCloudflareHec, + InputResponseInputCloudflareHecTypedDict, + InputResponseInputExtrahopRevealx360, + InputResponseInputExtrahopRevealx360TypedDict, + InputResponseInputF5BigIP, + InputResponseInputF5BigIPTypedDict, + InputResponseInputFile, + InputResponseInputFileTypedDict, + InputResponseInputGigamonHec, + InputResponseInputGigamonHecTypedDict, + InputResponseInputHashicorpHcpVaultDedicated, + InputResponseInputHashicorpHcpVaultDedicatedTypedDict, + InputResponseInputJournalFiles, + InputResponseInputJournalFilesTypedDict, + InputResponseInputMicrosoftCopilot, + InputResponseInputMicrosoftCopilotTypedDict, + InputResponseInputMimecastHec, + InputResponseInputMimecastHecTypedDict, InputResponseInputModelDrivenTelemetry, InputResponseInputModelDrivenTelemetryTypedDict, InputResponseInputNetflow, @@ -94,18 +147,18 @@ InputResponseInputOpenaiComplianceLogs, InputResponseInputOpenaiComplianceLogsTypedDict, InputResponseInputOpenaiTypedDict, + InputResponseInputPingIdentityPingone, + InputResponseInputPingIdentityPingoneTypedDict, + InputResponseInputProofpointPod, + InputResponseInputProofpointPodTypedDict, InputResponseInputRawUDP, InputResponseInputRawUDPTypedDict, - InputResponseInputS3, - InputResponseInputS3Inventory, - InputResponseInputS3InventoryTypedDict, - InputResponseInputS3TypedDict, + InputResponseInputSailpointHec, + InputResponseInputSailpointHecTypedDict, InputResponseInputSecurityLake, InputResponseInputSecurityLakeTypedDict, InputResponseInputServicenowTable, InputResponseInputServicenowTableTypedDict, - InputResponseInputSnmp, - InputResponseInputSnmpTypedDict, InputResponseInputSqs, InputResponseInputSqsTypedDict, InputResponseInputSysdigHec, @@ -114,14 +167,18 @@ InputResponseInputSyslogUnionTypedDict, InputResponseInputTCP, InputResponseInputTCPTypedDict, + InputResponseInputTrellixHec, + InputResponseInputTrellixHecTypedDict, + InputResponseInputTrendMicroVisionOne, + InputResponseInputTrendMicroVisionOneTypedDict, InputResponseInputUpwindHec, InputResponseInputUpwindHecTypedDict, + InputResponseInputVectraAiHec, + InputResponseInputVectraAiHecTypedDict, InputResponseInputWef, InputResponseInputWefTypedDict, InputResponseInputWinEventLogs, InputResponseInputWinEventLogsTypedDict, - InputResponseInputWindowsMetrics, - InputResponseInputWindowsMetricsTypedDict, InputResponseInputWiz, InputResponseInputWizTypedDict, InputResponseInputWizWebhook, @@ -133,43 +190,16 @@ KafkaSchemaRegistryAuthenticationType, KafkaSchemaRegistryAuthenticationTypeTypedDict, ) -from .logleveloptions import LogLevelOptions -from .logleveloptionscontentconfigitems import LogLevelOptionsContentConfigItems -from .logleveloptionsdebugerror import LogLevelOptionsDebugError from .metadataconfinputcollection import ( MetadataConfInputCollection, MetadataConfInputCollectionTypedDict, ) -from .microsoftentraidauthenticationendpointoptionssasl import ( - MicrosoftEntraIDAuthenticationEndpointOptionsSasl, -) -from .modeoptionshost import ModeOptionsHost -from .notification_union import NotificationUnion, NotificationUnionTypedDict +from .notification import Notification, NotificationTypedDict from .outputmodeoptionssplunkcollectorconf import OutputModeOptionsSplunkCollectorConf from .pqtype import PqType, PqTypeTypedDict from .preprocesstype import PreprocessType, PreprocessTypeTypedDict -from .processtype import ProcessType, ProcessTypeTypedDict -from .protocoloptionstargetsitems import ProtocolOptionsTargetsItems -from .recordtypeoptions import RecordTypeOptions -from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( - RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, - RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, -) from .retryrulestype import RetryRulesType, RetryRulesTypeTypedDict -from .retryrulestypecodesenableheader import ( - RetryRulesTypeCodesEnableHeader, - RetryRulesTypeCodesEnableHeaderTypedDict, -) -from .searchfilterconfinputprometheus import ( - SearchFilterConfInputPrometheus, - SearchFilterConfInputPrometheusTypedDict, -) from .statustype import StatusType, StatusTypeTypedDict -from .subscriptionplanoptions import SubscriptionPlanOptions -from .tlssettingsclientsidetype import ( - TLSSettingsClientSideType, - TLSSettingsClientSideTypeTypedDict, -) from .tlssettingsclientsidetypecapathcertpath import ( TLSSettingsClientSideTypeCaPathCertPath, TLSSettingsClientSideTypeCaPathCertPathTypedDict, @@ -180,13 +210,8 @@ ) from .typeoptions import TypeOptions from .typeoptionsazureblob import TypeOptionsAzureblob -from .typeoptionsconfluentcloud import TypeOptionsConfluentcloud -from .typeoptionscribltcp import TypeOptionsCribltcp -from .typeoptionsgooglepubsub import TypeOptionsGooglepubsub from .typeoptionsmsk import TypeOptionsMsk -from .typeoptionsprometheus import TypeOptionsPrometheus from .typeoptionssplunk import TypeOptionsSplunk -from .typeoptionstcpjson import TypeOptionsTcpjson from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from cribl_control_plane.utils import validate_const @@ -200,178 +225,131 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict -class InputResponseInputSystemStateType(str, Enum): - r"""Connector type identifier.""" - - SYSTEM_STATE = "system_state" - - -class InputResponseHostsFileTypedDict(TypedDict): - r"""Creates events based on entries collected from the hosts file""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseHostsFile(BaseModel): - r"""Creates events based on entries collected from the hosts file""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInterfacesTypedDict(TypedDict): - r"""Creates events for each of the host’s network interfaces""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseInterfaces(BaseModel): - r"""Creates events for each of the host’s network interfaces""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseDisksAndFileSystemsTypedDict(TypedDict): - r"""Creates events for physical disks, partitions, and file systems""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseDisksAndFileSystems(BaseModel): - r"""Creates events for physical disks, partitions, and file systems""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseHostInfoTypedDict(TypedDict): - r"""Creates events based on the host system’s current state""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseHostInfo(BaseModel): - r"""Creates events based on the host system’s current state""" +class InputResponseInputElasticAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" - enable: Optional[bool] = None - r"""Enabled""" + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Auth Tokens + AUTH_TOKENS = "authTokens" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class InputResponseAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The API version to use for communicating with the server""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + # 6.8.4 + SIX_DOT_8_DOT_4 = "6.8.4" + # 8.3.2 + EIGHT_DOT_3_DOT_2 = "8.3.2" + # Custom + CUSTOM = "custom" - return m +class InputResponseInputElasticAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter credentials directly, or select a stored secret""" -class InputResponseRoutesTypedDict(TypedDict): - r"""Creates events based on entries collected from the host’s network routes""" + NONE = "none" + MANUAL = "manual" + SECRET = "secret" - enable: NotRequired[bool] - r"""Enabled""" +class InputResponseInputElasticProxyModeTypedDict(TypedDict): + enabled: bool + r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" + auth_type: NotRequired[InputResponseInputElasticAuthenticationMethod] + r"""Enter credentials directly, or select a stored secret""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + url: NotRequired[str] + r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + remove_headers: NotRequired[List[str]] + r"""List of headers to remove from the request to proxy""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" -class InputResponseRoutes(BaseModel): - r"""Creates events based on entries collected from the host’s network routes""" - enable: Optional[bool] = None - r"""Enabled""" +class InputResponseInputElasticProxyMode(BaseModel): + enabled: bool + r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} + auth_type: Annotated[ + Optional[InputResponseInputElasticAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter credentials directly, or select a stored secret""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + username: Optional[str] = None + r"""Username""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + password: Optional[str] = None + r"""Password""" - return m + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + url: Optional[str] = None + r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" -class InputResponseDNSTypedDict(TypedDict): - r"""Creates events for DNS resolvers and search entries""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - enable: NotRequired[bool] - r"""Enabled""" + remove_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="removeHeaders") + ] = None + r"""List of headers to remove from the request to proxy""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" -class InputResponseDNS(BaseModel): - r"""Creates events for DNS resolvers and search entries""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - enable: Optional[bool] = None - r"""Enabled""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputElasticAuthenticationMethod(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["enable"]) + optional_fields = set( + [ + "authType", + "username", + "password", + "credentialsSecret", + "url", + "rejectUnauthorized", + "removeHeaders", + "timeoutSec", + "__template_url", + ] + ) serialized = handler(self) m = {} @@ -386,320 +364,15 @@ def serialize_model(self, handler): return m -class InputResponseUsersAndGroupsTypedDict(TypedDict): - r"""Creates events for local users and groups""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseUsersAndGroups(BaseModel): - r"""Creates events for local users and groups""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseFirewallTypedDict(TypedDict): - r"""Creates events for Firewall rules entries""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseFirewall(BaseModel): - r"""Creates events for Firewall rules entries""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseServicesTypedDict(TypedDict): - r"""Creates events from the list of services""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseServices(BaseModel): - r"""Creates events from the list of services""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseListeningPortsTypedDict(TypedDict): - r"""Creates events from list of listening ports""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseListeningPorts(BaseModel): - r"""Creates events from list of listening ports""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseLoggedInUsersTypedDict(TypedDict): - r"""Creates events from list of logged-in users""" - - enable: NotRequired[bool] - r"""Enabled""" - - -class InputResponseLoggedInUsers(BaseModel): - r"""Creates events from list of logged-in users""" - - enable: Optional[bool] = None - r"""Enabled""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enable"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseCollectorsTypedDict(TypedDict): - hostsfile: NotRequired[InputResponseHostsFileTypedDict] - r"""Creates events based on entries collected from the hosts file""" - interfaces: NotRequired[InputResponseInterfacesTypedDict] - r"""Creates events for each of the host’s network interfaces""" - disk: NotRequired[InputResponseDisksAndFileSystemsTypedDict] - r"""Creates events for physical disks, partitions, and file systems""" - metadata: NotRequired[InputResponseHostInfoTypedDict] - r"""Creates events based on the host system’s current state""" - routes: NotRequired[InputResponseRoutesTypedDict] - r"""Creates events based on entries collected from the host’s network routes""" - dns: NotRequired[InputResponseDNSTypedDict] - r"""Creates events for DNS resolvers and search entries""" - user: NotRequired[InputResponseUsersAndGroupsTypedDict] - r"""Creates events for local users and groups""" - firewall: NotRequired[InputResponseFirewallTypedDict] - r"""Creates events for Firewall rules entries""" - services: NotRequired[InputResponseServicesTypedDict] - r"""Creates events from the list of services""" - ports: NotRequired[InputResponseListeningPortsTypedDict] - r"""Creates events from list of listening ports""" - login_users: NotRequired[InputResponseLoggedInUsersTypedDict] - r"""Creates events from list of logged-in users""" - - -class InputResponseCollectors(BaseModel): - hostsfile: Optional[InputResponseHostsFile] = None - r"""Creates events based on entries collected from the hosts file""" - - interfaces: Optional[InputResponseInterfaces] = None - r"""Creates events for each of the host’s network interfaces""" - - disk: Optional[InputResponseDisksAndFileSystems] = None - r"""Creates events for physical disks, partitions, and file systems""" - - metadata: Optional[InputResponseHostInfo] = None - r"""Creates events based on the host system’s current state""" - - routes: Optional[InputResponseRoutes] = None - r"""Creates events based on entries collected from the host’s network routes""" - - dns: Optional[InputResponseDNS] = None - r"""Creates events for DNS resolvers and search entries""" - - user: Optional[InputResponseUsersAndGroups] = None - r"""Creates events for local users and groups""" - - firewall: Optional[InputResponseFirewall] = None - r"""Creates events for Firewall rules entries""" - - services: Optional[InputResponseServices] = None - r"""Creates events from the list of services""" - - ports: Optional[InputResponseListeningPorts] = None - r"""Creates events from list of listening ports""" - - login_users: Annotated[ - Optional[InputResponseLoggedInUsers], pydantic.Field(alias="loginUsers") - ] = None - r"""Creates events from list of logged-in users""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "hostsfile", - "interfaces", - "disk", - "metadata", - "routes", - "dns", - "user", - "firewall", - "services", - "ports", - "loginUsers", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemStatePersistenceTypedDict(TypedDict): - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" - - -class InputResponseInputSystemStatePersistence(BaseModel): - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemStateTypedDict(TypedDict): - type: InputResponseInputSystemStateType - r"""Connector type identifier.""" +class InputResponseInputElasticTypedDict(TypedDict): + type: InputResponseInputElasticType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + elastic_api: str + r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -714,38 +387,87 @@ class InputResponseInputSystemStateTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[InputResponseInputElasticAuthenticationType] + r"""Authentication type""" + api_version: NotRequired[InputResponseAPIVersion] + r"""The API version to use for communicating with the server""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - collectors: NotRequired[InputResponseCollectorsTypedDict] - persistence: NotRequired[InputResponseInputSystemStatePersistenceTypedDict] - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" - disable_native_last_log_module: NotRequired[bool] - r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + proxy_mode: NotRequired[InputResponseInputElasticProxyModeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + auth_tokens: NotRequired[List[str]] + r"""Bearer tokens to include in the authorization header""" + custom_api_version: NotRequired[str] + r"""Custom version information to respond to requests""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_elastic_api: NotRequired[str] + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputSystemState(BaseModel): - type: InputResponseInputSystemStateType - r"""Connector type identifier.""" +class InputResponseInputElastic(BaseModel): + type: InputResponseInputElasticType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + elastic_api: Annotated[str, pydantic.Field(alias="elasticAPI")] + r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -764,8683 +486,112 @@ class InputResponseInputSystemState(BaseModel): environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - interval: Optional[float] = None - r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - collectors: Optional[InputResponseCollectors] = None - - persistence: Optional[InputResponseInputSystemStatePersistence] = None - - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") - ] = None - r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" - - disable_native_last_log_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeLastLogModule") - ] = None - r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "interval", - "metadata", - "collectors", - "persistence", - "disableNativeModule", - "disableNativeLastLogModule", - "description", - "__template_environment", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsType(str, Enum): - r"""Connector type identifier.""" - - SYSTEM_METRICS = "system_metrics" - - -class InputResponseInputSystemMetricsSystemMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for system metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class InputResponseInputSystemMetricsSystemTypedDict(TypedDict): - mode: NotRequired[InputResponseInputSystemMetricsSystemMode] - r"""Select the level of detail for system metrics""" - processes: NotRequired[bool] - r"""Generate metrics for the numbers of processes in various states""" - - -class InputResponseInputSystemMetricsSystem(BaseModel): - mode: Optional[InputResponseInputSystemMetricsSystemMode] = None - r"""Select the level of detail for system metrics""" - - processes: Optional[bool] = None - r"""Generate metrics for the numbers of processes in various states""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputSystemMetricsSystemMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "processes"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for CPU metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class InputResponseInputSystemMetricsCPUTypedDict(TypedDict): - mode: NotRequired[InputResponseInputSystemMetricsCPUMode] - r"""Select the level of detail for CPU metrics""" - per_cpu: NotRequired[bool] - r"""Generate metrics for each CPU""" - detail: NotRequired[bool] - r"""Generate metrics for all CPU states""" - time: NotRequired[bool] - r"""Generate raw, monotonic CPU time counters""" - - -class InputResponseInputSystemMetricsCPU(BaseModel): - mode: Optional[InputResponseInputSystemMetricsCPUMode] = None - r"""Select the level of detail for CPU metrics""" - - per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None - r"""Generate metrics for each CPU""" - - detail: Optional[bool] = None - r"""Generate metrics for all CPU states""" - - time: Optional[bool] = None - r"""Generate raw, monotonic CPU time counters""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputSystemMetricsCPUMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perCpu", "detail", "time"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsMemoryMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for memory metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class InputResponseInputSystemMetricsMemoryTypedDict(TypedDict): - mode: NotRequired[InputResponseInputSystemMetricsMemoryMode] - r"""Select the level of detail for memory metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all memory states""" - - -class InputResponseInputSystemMetricsMemory(BaseModel): - mode: Optional[InputResponseInputSystemMetricsMemoryMode] = None - r"""Select the level of detail for memory metrics""" - - detail: Optional[bool] = None - r"""Generate metrics for all memory states""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputSystemMetricsMemoryMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsNetworkMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of detail for network metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class InputResponseInputSystemMetricsNetworkTypedDict(TypedDict): - mode: NotRequired[InputResponseInputSystemMetricsNetworkMode] - r"""Select the level of detail for network metrics""" - detail: NotRequired[bool] - r"""Generate full network metrics""" - protocols: NotRequired[bool] - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - devices: NotRequired[List[str]] - r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" - per_interface: NotRequired[bool] - r"""Generate separate metrics for each interface""" - - -class InputResponseInputSystemMetricsNetwork(BaseModel): - mode: Optional[InputResponseInputSystemMetricsNetworkMode] = None - r"""Select the level of detail for network metrics""" - - detail: Optional[bool] = None - r"""Generate full network metrics""" - - protocols: Optional[bool] = None - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - - devices: Optional[List[str]] = None - r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" - - per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( - None - ) - r"""Generate separate metrics for each interface""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputSystemMetricsNetworkMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["mode", "detail", "protocols", "devices", "perInterface"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for disk metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class InputResponseInputSystemMetricsDiskTypedDict(TypedDict): - mode: NotRequired[InputResponseInputSystemMetricsDiskMode] - r"""Select the level of detail for disk metrics""" - detail: NotRequired[bool] - r"""Generate full disk metrics""" - inodes: NotRequired[bool] - r"""Generate filesystem inode metrics""" - devices: NotRequired[List[str]] - r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" - mountpoints: NotRequired[List[str]] - r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" - fstypes: NotRequired[List[str]] - r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" - per_device: NotRequired[bool] - r"""Generate separate metrics for each device""" - - -class InputResponseInputSystemMetricsDisk(BaseModel): - mode: Optional[InputResponseInputSystemMetricsDiskMode] = None - r"""Select the level of detail for disk metrics""" - - detail: Optional[bool] = None - r"""Generate full disk metrics""" - - inodes: Optional[bool] = None - r"""Generate filesystem inode metrics""" - - devices: Optional[List[str]] = None - r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" - - mountpoints: Optional[List[str]] = None - r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" - - fstypes: Optional[List[str]] = None - r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" - - per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None - r"""Generate separate metrics for each device""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputSystemMetricsDiskMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mode", - "detail", - "inodes", - "devices", - "mountpoints", - "fstypes", - "perDevice", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsCustomTypedDict(TypedDict): - system: NotRequired[InputResponseInputSystemMetricsSystemTypedDict] - cpu: NotRequired[InputResponseInputSystemMetricsCPUTypedDict] - memory: NotRequired[InputResponseInputSystemMetricsMemoryTypedDict] - network: NotRequired[InputResponseInputSystemMetricsNetworkTypedDict] - disk: NotRequired[InputResponseInputSystemMetricsDiskTypedDict] - - -class InputResponseInputSystemMetricsCustom(BaseModel): - system: Optional[InputResponseInputSystemMetricsSystem] = None - - cpu: Optional[InputResponseInputSystemMetricsCPU] = None - - memory: Optional[InputResponseInputSystemMetricsMemory] = None - - network: Optional[InputResponseInputSystemMetricsNetwork] = None - - disk: Optional[InputResponseInputSystemMetricsDisk] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["system", "cpu", "memory", "network", "disk"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsHostTypedDict(TypedDict): - mode: NotRequired[ModeOptionsHost] - r"""Select level of detail for host metrics""" - custom: NotRequired[InputResponseInputSystemMetricsCustomTypedDict] - - -class InputResponseInputSystemMetricsHost(BaseModel): - mode: Optional[ModeOptionsHost] = None - r"""Select level of detail for host metrics""" - - custom: Optional[InputResponseInputSystemMetricsCustom] = None - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptionsHost(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "custom"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseContainerMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of detail for container metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class InputResponseInputSystemMetricsFilterTypedDict(TypedDict): - expr: str - r"""Expression""" - - -class InputResponseInputSystemMetricsFilter(BaseModel): - expr: str - r"""Expression""" - - -class InputResponseContainerTypedDict(TypedDict): - mode: NotRequired[InputResponseContainerMode] - r"""Select the level of detail for container metrics""" - docker_socket: NotRequired[List[str]] - r"""Full paths for Docker's UNIX-domain socket""" - docker_timeout: NotRequired[float] - r"""Timeout, in seconds, for the Docker API""" - filters: NotRequired[List[InputResponseInputSystemMetricsFilterTypedDict]] - r"""Containers matching any of these will be included. All are included if no filters are added.""" - all_containers: NotRequired[bool] - r"""Include stopped and paused containers""" - per_device: NotRequired[bool] - r"""Generate separate metrics for each device""" - detail: NotRequired[bool] - r"""Generate full container metrics""" - - -class InputResponseContainer(BaseModel): - mode: Optional[InputResponseContainerMode] = None - r"""Select the level of detail for container metrics""" - - docker_socket: Annotated[ - Optional[List[str]], pydantic.Field(alias="dockerSocket") - ] = None - r"""Full paths for Docker's UNIX-domain socket""" - - docker_timeout: Annotated[ - Optional[float], pydantic.Field(alias="dockerTimeout") - ] = None - r"""Timeout, in seconds, for the Docker API""" - - filters: Optional[List[InputResponseInputSystemMetricsFilter]] = None - r"""Containers matching any of these will be included. All are included if no filters are added.""" - - all_containers: Annotated[Optional[bool], pydantic.Field(alias="allContainers")] = ( - None - ) - r"""Include stopped and paused containers""" - - per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None - r"""Generate separate metrics for each device""" - - detail: Optional[bool] = None - r"""Generate full container metrics""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseContainerMode(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mode", - "dockerSocket", - "dockerTimeout", - "filters", - "allContainers", - "perDevice", - "detail", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" - - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" - - -class InputResponseInputSystemMetricsPersistence(BaseModel): - r"""persistence""" - - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputSystemMetricsTypedDict(TypedDict): - type: InputResponseInputSystemMetricsType - r"""Connector type identifier.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - host: NotRequired[InputResponseInputSystemMetricsHostTypedDict] - process: NotRequired[ProcessTypeTypedDict] - container: NotRequired[InputResponseContainerTypedDict] - gpu: NotRequired[GpuTypeTypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - persistence: NotRequired[InputResponseInputSystemMetricsPersistenceTypedDict] - r"""persistence""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputSystemMetrics(BaseModel): - type: InputResponseInputSystemMetricsType - r"""Connector type identifier.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - - host: Optional[InputResponseInputSystemMetricsHost] = None - - process: Optional[ProcessType] = None - - container: Optional[InputResponseContainer] = None - - gpu: Optional[GpuType] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - persistence: Optional[InputResponseInputSystemMetricsPersistence] = None - r"""persistence""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "interval", - "host", - "process", - "container", - "gpu", - "metadata", - "persistence", - "description", - "__template_environment", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputTcpjsonTypedDict(TypedDict): - type: TypeOptionsTcpjson - r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputTcpjson(BaseModel): - type: TypeOptionsTcpjson - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") - ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") - ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") - ] = None - r"""Load balance traffic across all Worker Processes""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "enableLoadBalancing", - "authType", - "description", - "authToken", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputCriblLakeHTTPType(str, Enum): - r"""Source type identifier.""" - - CRIBL_LAKE_HTTP = "cribl_lake_http" - - -class InputResponseSplunkHecMetadataTypedDict(TypedDict): - enabled: NotRequired[bool] - r"""When enabled, the token value is available on events as __hecToken""" - default_dataset: NotRequired[str] - allowed_indexes_at_token: NotRequired[List[str]] - - -class InputResponseSplunkHecMetadata(BaseModel): - enabled: Optional[bool] = None - r"""When enabled, the token value is available on events as __hecToken""" - - default_dataset: Annotated[ - Optional[str], pydantic.Field(alias="defaultDataset") - ] = None - - allowed_indexes_at_token: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseElasticsearchMetadataTypedDict(TypedDict): - enabled: NotRequired[bool] - r"""Elasticsearch""" - default_dataset: NotRequired[str] - - -class InputResponseElasticsearchMetadata(BaseModel): - enabled: Optional[bool] = None - r"""Elasticsearch""" - - default_dataset: Annotated[ - Optional[str], pydantic.Field(alias="defaultDataset") - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "defaultDataset"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseAuthTokensExtTypedDict(TypedDict): - token: str - r"""Token""" - description: NotRequired[str] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this token""" - splunk_hec_metadata: NotRequired[InputResponseSplunkHecMetadataTypedDict] - elasticsearch_metadata: NotRequired[InputResponseElasticsearchMetadataTypedDict] - - -class InputResponseAuthTokensExt(BaseModel): - token: str - r"""Token""" - - description: Optional[str] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this token""" - - splunk_hec_metadata: Annotated[ - Optional[InputResponseSplunkHecMetadata], - pydantic.Field(alias="splunkHecMetadata"), - ] = None - - elasticsearch_metadata: Annotated[ - Optional[InputResponseElasticsearchMetadata], - pydantic.Field(alias="elasticsearchMetadata"), - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["description", "metadata", "splunkHecMetadata", "elasticsearchMetadata"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputCriblLakeHTTPTypedDict(TypedDict): - type: InputResponseInputCriblLakeHTTPType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - cribl_api: NotRequired[str] - r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" - elastic_api: NotRequired[str] - r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" - splunk_hec_api: NotRequired[str] - r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" - splunk_hec_acks: NotRequired[bool] - r"""Enable Splunk HEC acknowledgements""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[InputResponseAuthTokensExtTypedDict]] - r"""Auth tokens""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_cribl_api: NotRequired[str] - r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" - template_elastic_api: NotRequired[str] - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - template_splunk_hec_api: NotRequired[str] - r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputCriblLakeHTTP(BaseModel): - type: InputResponseInputCriblLakeHTTPType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - cribl_api: Annotated[Optional[str], pydantic.Field(alias="criblAPI")] = None - r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" - - elastic_api: Annotated[Optional[str], pydantic.Field(alias="elasticAPI")] = None - r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" - - splunk_hec_api: Annotated[Optional[str], pydantic.Field(alias="splunkHecAPI")] = ( - None - ) - r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" - - splunk_hec_acks: Annotated[ - Optional[bool], pydantic.Field(alias="splunkHecAcks") - ] = None - r"""Enable Splunk HEC acknowledgements""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_tokens_ext: Annotated[ - Optional[List[InputResponseAuthTokensExt]], - pydantic.Field(alias="authTokensExt"), - ] = None - r"""Auth tokens""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - template_cribl_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_criblAPI") - ] = None - r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" - - template_elastic_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticAPI") - ] = None - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - - template_splunk_hec_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_splunkHecAPI") - ] = None - r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "criblAPI", - "elasticAPI", - "splunkHecAPI", - "splunkHecAcks", - "metadata", - "authTokensExt", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_criblAPI", - "__template_elasticAPI", - "__template_splunkHecAPI", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputCriblHTTPType(str, Enum): - r"""Source type identifier.""" - - CRIBL_HTTP = "cribl_http" - - -class InputResponseInputCriblHTTPTypedDict(TypedDict): - type: InputResponseInputCriblHTTPType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputCriblHTTP(BaseModel): - type: InputResponseInputCriblHTTPType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputCriblTCPTypedDict(TypedDict): - type: TypeOptionsCribltcp - r"""Connector type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputCriblTCP(BaseModel): - type: TypeOptionsCribltcp - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") - ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") - ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") - ] = None - r"""Load balance traffic across all Worker Processes""" - - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "enableLoadBalancing", - "authTokens", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputCriblType(str, Enum): - r"""Connector type identifier.""" - - CRIBL = "cribl" - - -class InputResponseInputCriblTypedDict(TypedDict): - type: InputResponseInputCriblType - r"""Connector type identifier.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - filter_: NotRequired[str] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputCribl(BaseModel): - type: InputResponseInputCriblType - r"""Connector type identifier.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "filter", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputGooglePubsubTypedDict(TypedDict): - type: TypeOptionsGooglepubsub - r"""Connector type identifier.""" - topic_name: str - r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" - subscription_name: str - r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - monitor_subscription: NotRequired[bool] - r"""Use when the subscription is not created by this Source and topic is not known""" - create_topic: NotRequired[bool] - r"""Create topic if it does not exist""" - create_subscription: NotRequired[bool] - r"""Create subscription if it does not exist""" - region: NotRequired[str] - r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - max_backlog: NotRequired[float] - r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" - concurrency: NotRequired[float] - r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" - request_timeout: NotRequired[float] - r"""Pull request timeout, in milliseconds""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - ordered_delivery: NotRequired[bool] - r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: NotRequired[str] - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - template_subscription_name: NotRequired[str] - r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputGooglePubsub(BaseModel): - type: TypeOptionsGooglepubsub - r"""Connector type identifier.""" - - topic_name: Annotated[str, pydantic.Field(alias="topicName")] - r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" - - subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] - r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - monitor_subscription: Annotated[ - Optional[bool], pydantic.Field(alias="monitorSubscription") - ] = None - r"""Use when the subscription is not created by this Source and topic is not known""" - - create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None - r"""Create topic if it does not exist""" - - create_subscription: Annotated[ - Optional[bool], pydantic.Field(alias="createSubscription") - ] = None - r"""Create subscription if it does not exist""" - - region: Optional[str] = None - r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - - google_auth_method: Annotated[ - Optional[GoogleAuthenticationMethodOptions], - pydantic.Field(alias="googleAuthMethod"), - ] = None - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") - ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - - secret: Optional[str] = None - r"""Select or create a stored text secret""" - - max_backlog: Annotated[Optional[float], pydantic.Field(alias="maxBacklog")] = None - r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" - - concurrency: Optional[float] = None - r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Pull request timeout, in milliseconds""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - ordered_delivery: Annotated[ - Optional[bool], pydantic.Field(alias="orderedDelivery") - ] = None - r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_topic_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicName") - ] = None - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - - template_subscription_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_subscriptionName") - ] = None - r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): - if isinstance(value, str): - try: - return models.GoogleAuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "monitorSubscription", - "createTopic", - "createSubscription", - "region", - "googleAuthMethod", - "serviceAccountCredentials", - "secret", - "maxBacklog", - "concurrency", - "requestTimeout", - "metadata", - "description", - "orderedDelivery", - "__template_environment", - "__template_streamtags", - "__template_topicName", - "__template_subscriptionName", - "__template_region", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputFirehoseType(str, Enum): - r"""Source type identifier.""" - - FIREHOSE = "firehose" - - -class InputResponseInputFirehoseTypedDict(TypedDict): - type: InputResponseInputFirehoseType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputFirehose(BaseModel): - type: InputResponseInputFirehoseType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputExecType(str, Enum): - r"""Connector type identifier.""" - - EXEC = "exec" - - -class InputResponseScheduleType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - - INTERVAL = "interval" - CRON_SCHEDULE = "cronSchedule" - - -class InputResponseInputExecTypedDict(TypedDict): - type: InputResponseInputExecType - r"""Connector type identifier.""" - command: str - r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""Disabled""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - script: NotRequired[str] - r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" - retries: NotRequired[float] - r"""Maximum number of retry attempts in the event that the command fails""" - schedule_type: NotRequired[InputResponseScheduleType] - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - interval: NotRequired[float] - r"""Interval between command executions in seconds.""" - cron_schedule: NotRequired[str] - r"""Cron schedule to execute the command on.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputExec(BaseModel): - type: InputResponseInputExecType - r"""Connector type identifier.""" - - command: str - r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""Disabled""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - script: Optional[str] = None - r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" - - retries: Optional[float] = None - r"""Maximum number of retry attempts in the event that the command fails""" - - schedule_type: Annotated[ - Optional[InputResponseScheduleType], pydantic.Field(alias="scheduleType") - ] = None - r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - interval: Optional[float] = None - r"""Interval between command executions in seconds.""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Cron schedule to execute the command on.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("schedule_type") - def serialize_schedule_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseScheduleType(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "script", - "retries", - "scheduleType", - "breakerRulesets", - "staleChannelFlushMs", - "metadata", - "description", - "interval", - "cronSchedule", - "__template_environment", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputEventhubAmqpType(str, Enum): - r"""Connector type identifier.""" - - EVENTHUB_AMQP = "eventhub_amqp" - - -class InputResponseAuthenticationMechanism(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Authentication mechanism""" - - # Connection String - CONNECTION_STRING = "connection-string" - # OAuth Bearer - OAUTH_BEARER = "oauth-bearer" - - -class InputResponseCertificateTypedDict(TypedDict): - certificate_name: str - r"""The certificate you registered as credentials for your app in the Azure portal""" - cert_path: str - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - priv_key_path: str - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - - -class InputResponseCertificate(BaseModel): - certificate_name: Annotated[str, pydantic.Field(alias="certificateName")] - r"""The certificate you registered as credentials for your app in the Azure portal""" - - cert_path: Annotated[str, pydantic.Field(alias="certPath")] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - - priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["passphrase"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseAuthTypedDict(TypedDict): - mechanism: InputResponseAuthenticationMechanism - r"""Authentication mechanism""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] - r"""Authentication method""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[InputResponseCertificateTypedDict] - oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] - r"""Endpoint used to acquire authentication tokens from Azure""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory""" - fully_qualified_namespace: NotRequired[str] - r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" - template_oauth_endpoint: NotRequired[str] - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_fully_qualified_namespace: NotRequired[str] - r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" - - -class InputResponseAuth(BaseModel): - mechanism: InputResponseAuthenticationMechanism - r"""Authentication mechanism""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - client_secret_auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuth], - pydantic.Field(alias="clientSecretAuthType"), - ] = None - r"""Authentication method""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[InputResponseCertificate] = None - - oauth_endpoint: Annotated[ - Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], - pydantic.Field(alias="oauthEndpoint"), - ] = None - r"""Endpoint used to acquire authentication tokens from Azure""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory""" - - fully_qualified_namespace: Annotated[ - Optional[str], pydantic.Field(alias="fullyQualifiedNamespace") - ] = None - r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" - - template_oauth_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_oauthEndpoint") - ] = None - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_fully_qualified_namespace: Annotated[ - Optional[str], pydantic.Field(alias="__template_fullyQualifiedNamespace") - ] = None - r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" - - @field_serializer("mechanism") - def serialize_mechanism(self, value): - if isinstance(value, str): - try: - return models.InputResponseAuthenticationMechanism(value) - except ValueError: - return value - return value - - @field_serializer("client_secret_auth_type") - def serialize_client_secret_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuth(value) - except ValueError: - return value - return value - - @field_serializer("oauth_endpoint") - def serialize_oauth_endpoint(self, value): - if isinstance(value, str): - try: - return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "textSecret", - "clientSecretAuthType", - "clientTextSecret", - "certificate", - "oauthEndpoint", - "clientId", - "tenantId", - "fullyQualifiedNamespace", - "__template_oauthEndpoint", - "__template_clientId", - "__template_tenantId", - "__template_fullyQualifiedNamespace", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputEventhubAmqpAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method""" - - SECRET = "secret" - CLIENT_SECRET = "clientSecret" - CLIENT_CERT = "clientCert" - CLIENT_ASSERTION = "clientAssertion" - CLIENT_ASSERTION_RPC = "clientAssertion_rpc" - - -class InputResponseAzureBlobStorageTypedDict(TypedDict): - r"""Azure Blob Storage""" - - container_name: str - r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" - auth_type: NotRequired[InputResponseInputEventhubAmqpAuthenticationMethod] - r"""Authentication method""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - storage_account_name: NotRequired[str] - r"""The name of your Azure storage account""" - tenant_id: NotRequired[str] - r"""The service principal's tenant ID""" - client_id: NotRequired[str] - r"""The service principal's client ID""" - azure_cloud: NotRequired[str] - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - endpoint_suffix: NotRequired[str] - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CertificateTypeTypedDict] - template_storage_account_name: NotRequired[str] - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_azure_cloud: NotRequired[str] - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - -class InputResponseAzureBlobStorage(BaseModel): - r"""Azure Blob Storage""" - - container_name: Annotated[str, pydantic.Field(alias="containerName")] - r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" - - auth_type: Annotated[ - Optional[InputResponseInputEventhubAmqpAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Authentication method""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="storageAccountName") - ] = None - r"""The name of your Azure storage account""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""The service principal's tenant ID""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""The service principal's client ID""" - - azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - - endpoint_suffix: Annotated[ - Optional[str], pydantic.Field(alias="endpointSuffix") - ] = None - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[CertificateType] = None - - template_storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageAccountName") - ] = None - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_azure_cloud: Annotated[ - Optional[str], pydantic.Field(alias="__template_azureCloud") - ] = None - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputEventhubAmqpAuthenticationMethod(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "textSecret", - "storageAccountName", - "tenantId", - "clientId", - "azureCloud", - "endpointSuffix", - "clientTextSecret", - "certificate", - "__template_storageAccountName", - "__template_tenantId", - "__template_clientId", - "__template_azureCloud", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseCheckpointingTypedDict(TypedDict): - blob_store: InputResponseAzureBlobStorageTypedDict - r"""Azure Blob Storage""" - - -class InputResponseCheckpointing(BaseModel): - blob_store: Annotated[ - InputResponseAzureBlobStorage, pydantic.Field(alias="blobStore") - ] - r"""Azure Blob Storage""" - - -class InputResponseInputEventhubAmqpTypedDict(TypedDict): - type: InputResponseInputEventhubAmqpType - r"""Connector type identifier.""" - consumer_group: str - r"""The consumer group this instance belongs to. Default is '$Default'.""" - checkpointing: InputResponseCheckpointingTypedDict - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - event_hub_name: NotRequired[str] - r"""The name of the Event Hub to consume from""" - auth: NotRequired[InputResponseAuthTypedDict] - from_beginning: NotRequired[bool] - r"""Start reading from earliest available data; relevant only during initial subscription""" - max_batch_size: NotRequired[int] - r"""Maximum number of events in each batch delivered to the consumer""" - max_wait_time_in_seconds: NotRequired[int] - r"""Maximum time to wait for a batch of events before delivering a partial batch""" - prefetch_count: NotRequired[int] - r"""Number of events to prefetch from the service for processing""" - max_retries: NotRequired[int] - r"""Maximum number of retries per operation""" - initial_backoff: NotRequired[int] - r"""Initial delay before the first retry, in milliseconds""" - max_backoff: NotRequired[int] - r"""Maximum delay between retries, in milliseconds""" - timeout_in_ms: NotRequired[int] - r"""Maximum time to wait for a request to complete""" - connection_initial_backoff: NotRequired[int] - r"""Initial delay before the first reconnection attempt, in milliseconds""" - connection_max_backoff: NotRequired[int] - r"""Maximum delay between reconnection attempts, in milliseconds""" - connection_timeout_in_ms: NotRequired[int] - r"""Maximum time to wait for a connection to complete""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputEventhubAmqp(BaseModel): - type: InputResponseInputEventhubAmqpType - r"""Connector type identifier.""" - - consumer_group: Annotated[str, pydantic.Field(alias="consumerGroup")] - r"""The consumer group this instance belongs to. Default is '$Default'.""" - - checkpointing: InputResponseCheckpointing - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - event_hub_name: Annotated[Optional[str], pydantic.Field(alias="eventHubName")] = ( - None - ) - r"""The name of the Event Hub to consume from""" - - auth: Optional[InputResponseAuth] = None - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Start reading from earliest available data; relevant only during initial subscription""" - - max_batch_size: Annotated[Optional[int], pydantic.Field(alias="maxBatchSize")] = ( - None - ) - r"""Maximum number of events in each batch delivered to the consumer""" - - max_wait_time_in_seconds: Annotated[ - Optional[int], pydantic.Field(alias="maxWaitTimeInSeconds") - ] = None - r"""Maximum time to wait for a batch of events before delivering a partial batch""" - - prefetch_count: Annotated[Optional[int], pydantic.Field(alias="prefetchCount")] = ( - None - ) - r"""Number of events to prefetch from the service for processing""" - - max_retries: Annotated[Optional[int], pydantic.Field(alias="maxRetries")] = None - r"""Maximum number of retries per operation""" - - initial_backoff: Annotated[ - Optional[int], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial delay before the first retry, in milliseconds""" - - max_backoff: Annotated[Optional[int], pydantic.Field(alias="maxBackoff")] = None - r"""Maximum delay between retries, in milliseconds""" - - timeout_in_ms: Annotated[Optional[int], pydantic.Field(alias="timeoutInMs")] = None - r"""Maximum time to wait for a request to complete""" - - connection_initial_backoff: Annotated[ - Optional[int], pydantic.Field(alias="connectionInitialBackoff") - ] = None - r"""Initial delay before the first reconnection attempt, in milliseconds""" - - connection_max_backoff: Annotated[ - Optional[int], pydantic.Field(alias="connectionMaxBackoff") - ] = None - r"""Maximum delay between reconnection attempts, in milliseconds""" - - connection_timeout_in_ms: Annotated[ - Optional[int], pydantic.Field(alias="connectionTimeoutInMs") - ] = None - r"""Maximum time to wait for a connection to complete""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "eventHubName", - "auth", - "fromBeginning", - "maxBatchSize", - "maxWaitTimeInSeconds", - "prefetchCount", - "maxRetries", - "initialBackoff", - "maxBackoff", - "timeoutInMs", - "connectionInitialBackoff", - "connectionMaxBackoff", - "connectionTimeoutInMs", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputEventhubType(str, Enum): - r"""Connector type identifier.""" - - EVENTHUB = "eventhub" - - -class InputResponseInputEventhubTypedDict(TypedDict): - type: InputResponseInputEventhubType - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - topics: List[str] - r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - group_id: NotRequired[str] - r"""The consumer group this instance belongs to. Default is 'Cribl'.""" - from_beginning: NotRequired[bool] - r"""Start reading from earliest available data; relevant only during initial subscription""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeUseTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeTypedDict] - r"""TLS settings (client side)""" - session_timeout: NotRequired[float] - r""" - Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - rebalance_timeout: NotRequired[float] - r""" - Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - heartbeat_interval: NotRequired[float] - r""" - Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - auto_commit_interval: NotRequired[float] - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - auto_commit_threshold: NotRequired[float] - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - max_bytes_per_partition: NotRequired[float] - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - max_bytes: NotRequired[float] - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - max_socket_errors: NotRequired[float] - r"""Maximum number of network errors before the consumer re-creates a socket""" - minimize_duplicates: NotRequired[bool] - r"""Minimize duplicate events by starting only one consumer for each topic partition""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topics: NotRequired[str] - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - template_group_id: NotRequired[str] - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputEventhub(BaseModel): - type: InputResponseInputEventhubType - r"""Connector type identifier.""" - - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - - topics: List[str] - r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None - r"""The consumer group this instance belongs to. Default is 'Cribl'.""" - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Start reading from earliest available data; relevant only during initial subscription""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Maximum time to wait for a connection to complete successfully""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" - - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") - ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - - sasl: Optional[AuthenticationTypeUse] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - - tls: Optional[TLSSettingsClientSideType] = None - r"""TLS settings (client side)""" - - session_timeout: Annotated[ - Optional[float], pydantic.Field(alias="sessionTimeout") - ] = None - r""" - Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - rebalance_timeout: Annotated[ - Optional[float], pydantic.Field(alias="rebalanceTimeout") - ] = None - r""" - Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - heartbeat_interval: Annotated[ - Optional[float], pydantic.Field(alias="heartbeatInterval") - ] = None - r""" - Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). - """ - - auto_commit_interval: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitInterval") - ] = None - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - auto_commit_threshold: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitThreshold") - ] = None - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - max_bytes_per_partition: Annotated[ - Optional[float], pydantic.Field(alias="maxBytesPerPartition") - ] = None - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - - max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - - max_socket_errors: Annotated[ - Optional[float], pydantic.Field(alias="maxSocketErrors") - ] = None - r"""Maximum number of network errors before the consumer re-creates a socket""" - - minimize_duplicates: Annotated[ - Optional[bool], pydantic.Field(alias="minimizeDuplicates") - ] = None - r"""Minimize duplicate events by starting only one consumer for each topic partition""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") - ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - - template_topics: Annotated[ - Optional[str], pydantic.Field(alias="__template_topics") - ] = None - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - - template_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_groupId") - ] = None - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "groupId", - "fromBeginning", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "tls", - "sessionTimeout", - "rebalanceTimeout", - "heartbeatInterval", - "autoCommitInterval", - "autoCommitThreshold", - "maxBytesPerPartition", - "maxBytes", - "maxSocketErrors", - "minimizeDuplicates", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_brokers", - "__template_topics", - "__template_groupId", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputMicrosoftGraphType(str, Enum): - r"""Connector type identifier.""" - - MICROSOFT_GRAPH = "microsoft_graph" - - -class InputResponseInputMicrosoftGraphAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select authentication method.""" - - OAUTH = "oauth" - OAUTH_SECRET = "oauthSecret" - OAUTH_CERT = "oauthCert" - - -class InputResponseSubscriptionPlan(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - # Microsoft 365 Enterprise - ENTERPRISE_GCC = "enterprise_gcc" - # Microsoft 365 GCC - GCC = "gcc" - # Microsoft 365 GCC High - GCC_HIGH = "gcc_high" - # Microsoft 365 DoD - DOD = "dod" - # Microsoft 365 China (21Vianet) - CHINA = "china" - - -class InputResponseInputMicrosoftGraphTypedDict(TypedDict): - type: InputResponseInputMicrosoftGraphType - r"""Connector type identifier.""" - url: str - r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - start_date: NotRequired[str] - r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - end_date: NotRequired[str] - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - disable_time_filter: NotRequired[bool] - r"""Disables time filtering of events when a date range is specified.""" - max_pages: NotRequired[int] - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - auth_type: NotRequired[InputResponseInputMicrosoftGraphAuthenticationMethod] - r"""Select authentication method.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - reschedule_dropped_tasks: NotRequired[bool] - r"""Reschedule tasks that failed with non-fatal errors""" - max_task_reschedule: NotRequired[float] - r"""Maximum number of times a task can be rescheduled""" - log_level: NotRequired[LogLevelOptionsDebugError] - r"""Log Level (verbosity) for collection runtime behavior.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""client_secret to pass in the OAuth request parameter.""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter.""" - resource: NotRequired[str] - r"""Resource to pass in the OAuth request parameter.""" - plan_type: NotRequired[InputResponseSubscriptionPlan] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - text_secret: NotRequired[str] - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - cert_options: NotRequired[CertOptionsTypeTypedDict] - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_resource: NotRequired[str] - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputMicrosoftGraph(BaseModel): - type: InputResponseInputMicrosoftGraphType - r"""Connector type identifier.""" - - url: str - r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" - - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None - r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - - end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - - disable_time_filter: Annotated[ - Optional[bool], pydantic.Field(alias="disableTimeFilter") - ] = None - r"""Disables time filtering of events when a date range is specified.""" - - max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - - auth_type: Annotated[ - Optional[InputResponseInputMicrosoftGraphAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Select authentication method.""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - reschedule_dropped_tasks: Annotated[ - Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") - ] = None - r"""Reschedule tasks that failed with non-fatal errors""" - - max_task_reschedule: Annotated[ - Optional[float], pydantic.Field(alias="maxTaskReschedule") - ] = None - r"""Maximum number of times a task can be rescheduled""" - - log_level: Annotated[ - Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") - ] = None - r"""Log Level (verbosity) for collection runtime behavior.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""client_secret to pass in the OAuth request parameter.""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter.""" - - resource: Optional[str] = None - r"""Resource to pass in the OAuth request parameter.""" - - plan_type: Annotated[ - Optional[InputResponseSubscriptionPlan], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - - cert_options: Annotated[ - Optional[CertOptionsType], pydantic.Field(alias="certOptions") - ] = None - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_resource: Annotated[ - Optional[str], pydantic.Field(alias="__template_resource") - ] = None - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputMicrosoftGraphAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsDebugError(value) - except ValueError: - return value - return value - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseSubscriptionPlan(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "startDate", - "endDate", - "timeout", - "disableTimeFilter", - "maxPages", - "authType", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "rescheduleDroppedTasks", - "maxTaskReschedule", - "logLevel", - "retryRules", - "breakerRulesets", - "staleChannelFlushMs", - "description", - "clientSecret", - "tenantId", - "clientId", - "resource", - "planType", - "textSecret", - "certOptions", - "__template_environment", - "__template_streamtags", - "__template_url", - "__template_tenantId", - "__template_clientId", - "__template_resource", - "__template_planType", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputOffice365MsgTraceType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_MSG_TRACE = "office365_msg_trace" - - -class InputResponseInputOffice365MsgTraceAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select authentication method.""" - - MANUAL = "manual" - SECRET = "secret" - OAUTH = "oauth" - OAUTH_SECRET = "oauthSecret" - OAUTH_CERT = "oauthCert" - - -class InputResponseInputOffice365MsgTraceTypedDict(TypedDict): - type: InputResponseInputOffice365MsgTraceType - r"""Connector type identifier.""" - url: str - r"""URL to use when retrieving report data.""" - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - start_date: NotRequired[str] - r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - end_date: NotRequired[str] - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - disable_time_filter: NotRequired[bool] - r"""Disables time filtering of events when a date range is specified.""" - auth_type: NotRequired[InputResponseInputOffice365MsgTraceAuthenticationMethod] - r"""Select authentication method.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - reschedule_dropped_tasks: NotRequired[bool] - r"""Reschedule tasks that failed with non-fatal errors""" - max_task_reschedule: NotRequired[float] - r"""Maximum number of times a task can be rescheduled""" - log_level: NotRequired[LogLevelOptionsDebugError] - r"""Log Level (verbosity) for collection runtime behavior.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username to run Message Trace API call.""" - password: NotRequired[str] - r"""Password to run Message Trace API call.""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials.""" - client_secret: NotRequired[str] - r"""client_secret to pass in the OAuth request parameter.""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter.""" - resource: NotRequired[str] - r"""Resource to pass in the OAuth request parameter.""" - plan_type: NotRequired[SubscriptionPlanOptions] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - text_secret: NotRequired[str] - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - cert_options: NotRequired[CertOptionsTypeTypedDict] - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_resource: NotRequired[str] - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputOffice365MsgTrace(BaseModel): - type: InputResponseInputOffice365MsgTraceType - r"""Connector type identifier.""" - - url: str - r"""URL to use when retrieving report data.""" - - interval: int - r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None - r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" - - end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None - r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" - - disable_time_filter: Annotated[ - Optional[bool], pydantic.Field(alias="disableTimeFilter") - ] = None - r"""Disables time filtering of events when a date range is specified.""" - - auth_type: Annotated[ - Optional[InputResponseInputOffice365MsgTraceAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Select authentication method.""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - reschedule_dropped_tasks: Annotated[ - Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") - ] = None - r"""Reschedule tasks that failed with non-fatal errors""" - - max_task_reschedule: Annotated[ - Optional[float], pydantic.Field(alias="maxTaskReschedule") - ] = None - r"""Maximum number of times a task can be rescheduled""" - - log_level: Annotated[ - Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") - ] = None - r"""Log Level (verbosity) for collection runtime behavior.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username to run Message Trace API call.""" - - password: Optional[str] = None - r"""Password to run Message Trace API call.""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""client_secret to pass in the OAuth request parameter.""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter.""" - - resource: Optional[str] = None - r"""Resource to pass in the OAuth request parameter.""" - - plan_type: Annotated[ - Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" - - cert_options: Annotated[ - Optional[CertOptionsType], pydantic.Field(alias="certOptions") - ] = None - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_resource: Annotated[ - Optional[str], pydantic.Field(alias="__template_resource") - ] = None - r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputOffice365MsgTraceAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsDebugError(value) - except ValueError: - return value - return value - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "startDate", - "endDate", - "timeout", - "disableTimeFilter", - "authType", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "rescheduleDroppedTasks", - "maxTaskReschedule", - "logLevel", - "retryRules", - "description", - "username", - "password", - "credentialsSecret", - "clientSecret", - "tenantId", - "clientId", - "resource", - "planType", - "textSecret", - "certOptions", - "__template_environment", - "__template_streamtags", - "__template_url", - "__template_tenantId", - "__template_clientId", - "__template_resource", - "__template_planType", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputOffice365ServiceType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_SERVICE = "office365_service" - - -class InputResponseInputOffice365ServiceContentConfigTypedDict(TypedDict): - content_type: NotRequired[str] - r"""Microsoft 365 Services API Content Type""" - description: NotRequired[str] - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - interval: NotRequired[float] - r"""Interval""" - log_level: NotRequired[LogLevelOptionsContentConfigItems] - r"""Collector runtime Log Level""" - enabled: NotRequired[bool] - r"""Enabled""" - - -class InputResponseInputOffice365ServiceContentConfig(BaseModel): - content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None - r"""Microsoft 365 Services API Content Type""" - - description: Optional[str] = None - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - - interval: Optional[float] = None - r"""Interval""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime Log Level""" - - enabled: Optional[bool] = None - r"""Enabled""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["contentType", "description", "interval", "logLevel", "enabled"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputOffice365ServiceTypedDict(TypedDict): - type: InputResponseInputOffice365ServiceType - r"""Connector type identifier.""" - tenant_id: str - r"""Microsoft 365 Azure Tenant ID""" - app_id: str - r"""Microsoft 365 Azure Application ID""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - plan_type: NotRequired[SubscriptionPlanOptions] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - timeout: NotRequired[float] - r"""HTTP request inactivity timeout, use 0 to disable""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - content_config: NotRequired[ - List[InputResponseInputOffice365ServiceContentConfigTypedDict] - ] - r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""Microsoft 365 Azure client secret""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_app_id: NotRequired[str] - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputOffice365Service(BaseModel): - type: InputResponseInputOffice365ServiceType - r"""Connector type identifier.""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Microsoft 365 Azure Tenant ID""" - - app_id: Annotated[str, pydantic.Field(alias="appId")] - r"""Microsoft 365 Azure Application ID""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - plan_type: Annotated[ - Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") - ] = None - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout, use 0 to disable""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - content_config: Annotated[ - Optional[List[InputResponseInputOffice365ServiceContentConfig]], - pydantic.Field(alias="contentConfig"), - ] = None - r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""Microsoft 365 Azure client secret""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_app_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_appId") - ] = None - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsManualSecret(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "planType", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "contentConfig", - "retryRules", - "authType", - "description", - "clientSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_planType", - "__template_tenantId", - "__template_appId", - "__template_clientSecret", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputOffice365MgmtType(str, Enum): - r"""Connector type identifier.""" - - OFFICE365_MGMT = "office365_mgmt" - - -class InputResponseInputOffice365MgmtContentConfigTypedDict(TypedDict): - content_type: NotRequired[str] - r"""Microsoft 365 Management Activity API Content Type""" - description: NotRequired[str] - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - interval: NotRequired[float] - r"""Interval""" - log_level: NotRequired[LogLevelOptionsContentConfigItems] - r"""Collector runtime Log Level""" - enabled: NotRequired[bool] - r"""Enabled""" - - -class InputResponseInputOffice365MgmtContentConfig(BaseModel): - content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None - r"""Microsoft 365 Management Activity API Content Type""" - - description: Optional[str] = None - r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" - - interval: Optional[float] = None - r"""Interval""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime Log Level""" - - enabled: Optional[bool] = None - r"""Enabled""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - ["contentType", "description", "interval", "logLevel", "enabled"] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputOffice365MgmtTypedDict(TypedDict): - type: InputResponseInputOffice365MgmtType - r"""Connector type identifier.""" - plan_type: SubscriptionPlanOptions - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - tenant_id: str - r"""Microsoft 365 Azure Tenant ID""" - app_id: str - r"""Microsoft 365 Azure Application ID""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - timeout: NotRequired[float] - r"""HTTP request inactivity timeout, use 0 to disable""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - publisher_identifier: NotRequired[str] - r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" - content_config: NotRequired[ - List[InputResponseInputOffice365MgmtContentConfigTypedDict] - ] - r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" - ingestion_lag: NotRequired[float] - r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" - retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""Microsoft 365 Azure client secret""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_plan_type: NotRequired[str] - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_app_id: NotRequired[str] - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - template_publisher_identifier: NotRequired[str] - r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputOffice365Mgmt(BaseModel): - type: InputResponseInputOffice365MgmtType - r"""Connector type identifier.""" - - plan_type: Annotated[SubscriptionPlanOptions, pydantic.Field(alias="planType")] - r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Microsoft 365 Azure Tenant ID""" - - app_id: Annotated[str, pydantic.Field(alias="appId")] - r"""Microsoft 365 Azure Application ID""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - timeout: Optional[float] = None - r"""HTTP request inactivity timeout, use 0 to disable""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - publisher_identifier: Annotated[ - Optional[str], pydantic.Field(alias="publisherIdentifier") - ] = None - r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" - - content_config: Annotated[ - Optional[List[InputResponseInputOffice365MgmtContentConfig]], - pydantic.Field(alias="contentConfig"), - ] = None - r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" - - ingestion_lag: Annotated[Optional[float], pydantic.Field(alias="ingestionLag")] = ( - None - ) - r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" - - retry_rules: Annotated[ - Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") - ] = None - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""Microsoft 365 Azure client secret""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_plan_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_planType") - ] = None - r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_app_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_appId") - ] = None - r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" - - template_publisher_identifier: Annotated[ - Optional[str], pydantic.Field(alias="__template_publisherIdentifier") - ] = None - r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("plan_type") - def serialize_plan_type(self, value): - if isinstance(value, str): - try: - return models.SubscriptionPlanOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsManualSecret(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "publisherIdentifier", - "contentConfig", - "ingestionLag", - "retryRules", - "authType", - "description", - "clientSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_planType", - "__template_tenantId", - "__template_appId", - "__template_publisherIdentifier", - "__template_clientSecret", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputEdgePrometheusType(str, Enum): - r"""Connector type identifier.""" - - EDGE_PROMETHEUS = "edge_prometheus" - - -class InputResponseInputEdgePrometheusDiscoveryType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - # Static - STATIC = "static" - # DNS - DNS = "dns" - # AWS EC2 - EC2 = "ec2" - # Kubernetes Node - K8S_NODE = "k8s-node" - # Kubernetes Pods - K8S_PODS = "k8s-pods" - # Kubernetes Service Monitor (v4.18+) - K8S_SERVICE_MONITOR = "k8s-service-monitor" - # HTTP SD - HTTP_SD = "http_sd" - - -class InputResponseInputEdgePrometheusAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter credentials directly, or select a stored secret""" - - MANUAL = "manual" - SECRET = "secret" - KUBERNETES = "kubernetes" - - -class InputResponseTargetTypedDict(TypedDict): - host: str - r"""Name of host from which to pull metrics.""" - protocol: NotRequired[ProtocolOptionsTargetsItems] - r"""Protocol to use when collecting metrics""" - port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets.""" - path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - - -class InputResponseTarget(BaseModel): - host: str - r"""Name of host from which to pull metrics.""" - - protocol: Optional[ProtocolOptionsTargetsItems] = None - r"""Protocol to use when collecting metrics""" - - port: Optional[float] = None - r"""The port number in the metrics URL for discovered targets.""" - - path: Optional[str] = None - r"""Path to use when collecting metrics from discovered targets""" - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptionsTargetsItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["protocol", "port", "path"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponsePodFilterTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" - description: NotRequired[str] - r"""Optional description of this rule's purpose""" - - -class InputResponsePodFilter(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" - - description: Optional[str] = None - r"""Optional description of this rule's purpose""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputEdgePrometheusTypedDict(TypedDict): - type: InputResponseInputEdgePrometheusType - r"""Connector type identifier.""" - discovery_type: InputResponseInputEdgePrometheusDiscoveryType - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - interval: float - r"""How often in seconds to scrape targets for metrics.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - dimension_list: NotRequired[List[str]] - r"""Other dimensions to include in events""" - field_per_metric: NotRequired[bool] - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - timeout: NotRequired[float] - r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" - persistence: NotRequired[DiskSpoolingTypeTypedDict] - r"""Disk Spooling""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_type: NotRequired[InputResponseInputEdgePrometheusAuthenticationMethod] - r"""Enter credentials directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - targets: NotRequired[List[InputResponseTargetTypedDict]] - r"""Targets""" - record_type: NotRequired[RecordTypeOptions] - r"""DNS record type to resolve""" - scrape_port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets.""" - name_list: NotRequired[List[str]] - r"""List of DNS names to resolve""" - scrape_protocol: NotRequired[ProtocolOptionsTargetsItems] - r"""Protocol to use when collecting metrics""" - scrape_path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - use_public_ip: NotRequired[bool] - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] - r"""Filter to apply when searching for EC2 instances""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the EC2 is located""" - endpoint: NotRequired[str] - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access EC2""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - service_monitor_namespace: NotRequired[str] - r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" - scrape_protocol_expr: NotRequired[str] - r"""Protocol to use when collecting metrics""" - scrape_port_expr: NotRequired[str] - r"""The port number in the metrics URL for discovered targets.""" - scrape_path_expr: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - pod_filter: NotRequired[List[InputResponsePodFilterTypedDict]] - r""" - Add rules to decide which pods to discover for metrics. - Pods are searched if no rules are given or of all the rules' - expressions evaluate to true. - - """ - http_discovery_url: NotRequired[str] - r"""URL to fetch target groups from (must be http or https)""" - http_discovery_headers: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Extra headers to send with the discovery request""" - http_discovery_reject_unauthorized: NotRequired[bool] - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - max_response_body_size: NotRequired[str] - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - username: NotRequired[str] - r"""Username for Prometheus Basic authentication""" - password: NotRequired[str] - r"""Password for Prometheus Basic authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_dimension_list: NotRequired[str] - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - template_name_list: NotRequired[str] - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputEdgePrometheus(BaseModel): - type: InputResponseInputEdgePrometheusType - r"""Connector type identifier.""" - - discovery_type: Annotated[ - InputResponseInputEdgePrometheusDiscoveryType, - pydantic.Field(alias="discoveryType"), - ] - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - interval: float - r"""How often in seconds to scrape targets for metrics.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - dimension_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="dimensionList") - ] = None - r"""Other dimensions to include in events""" - - field_per_metric: Annotated[ - Optional[bool], pydantic.Field(alias="fieldPerMetric") - ] = None - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - - timeout: Optional[float] = None - r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" - - persistence: Optional[DiskSpoolingType] = None - r"""Disk Spooling""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_type: Annotated[ - Optional[InputResponseInputEdgePrometheusAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Enter credentials directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - targets: Optional[List[InputResponseTarget]] = None - r"""Targets""" - - record_type: Annotated[ - Optional[RecordTypeOptions], pydantic.Field(alias="recordType") - ] = None - r"""DNS record type to resolve""" - - scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None - r"""The port number in the metrics URL for discovered targets.""" - - name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None - r"""List of DNS names to resolve""" - - scrape_protocol: Annotated[ - Optional[ProtocolOptionsTargetsItems], pydantic.Field(alias="scrapeProtocol") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None - r"""Path to use when collecting metrics from discovered targets""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - - search_filter: Annotated[ - Optional[List[SearchFilterConfInputPrometheus]], - pydantic.Field(alias="searchFilter"), - ] = None - r"""Filter to apply when searching for EC2 instances""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""Region where the EC2 is located""" - - endpoint: Optional[str] = None - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access EC2""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - service_monitor_namespace: Annotated[ - Optional[str], pydantic.Field(alias="serviceMonitorNamespace") - ] = None - r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" - - scrape_protocol_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapeProtocolExpr") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_port_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapePortExpr") - ] = None - r"""The port number in the metrics URL for discovered targets.""" - - scrape_path_expr: Annotated[ - Optional[str], pydantic.Field(alias="scrapePathExpr") - ] = None - r"""Path to use when collecting metrics from discovered targets""" - - pod_filter: Annotated[ - Optional[List[InputResponsePodFilter]], pydantic.Field(alias="podFilter") - ] = None - r""" - Add rules to decide which pods to discover for metrics. - Pods are searched if no rules are given or of all the rules' - expressions evaluate to true. - - """ - - http_discovery_url: Annotated[ - Optional[str], pydantic.Field(alias="httpDiscoveryUrl") - ] = None - r"""URL to fetch target groups from (must be http or https)""" - - http_discovery_headers: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="httpDiscoveryHeaders"), - ] = None - r"""Extra headers to send with the discovery request""" - - http_discovery_reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") - ] = None - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - - max_response_body_size: Annotated[ - Optional[str], pydantic.Field(alias="maxResponseBodySize") - ] = None - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - - username: Optional[str] = None - r"""Username for Prometheus Basic authentication""" - - password: Optional[str] = None - r"""Password for Prometheus Basic authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_dimension_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_dimensionList") - ] = None - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - - template_name_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_nameList") - ] = None - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("discovery_type") - def serialize_discovery_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputEdgePrometheusDiscoveryType(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputEdgePrometheusAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("record_type") - def serialize_record_type(self, value): - if isinstance(value, str): - try: - return models.RecordTypeOptions(value) - except ValueError: - return value - return value - - @field_serializer("scrape_protocol") - def serialize_scrape_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptionsTargetsItems(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "dimensionList", - "fieldPerMetric", - "timeout", - "persistence", - "metadata", - "authType", - "description", - "targets", - "recordType", - "scrapePort", - "nameList", - "scrapeProtocol", - "scrapePath", - "awsAuthenticationMethod", - "awsApiKey", - "awsSecret", - "usePublicIp", - "searchFilter", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "serviceMonitorNamespace", - "scrapeProtocolExpr", - "scrapePortExpr", - "scrapePathExpr", - "podFilter", - "httpDiscoveryUrl", - "httpDiscoveryHeaders", - "httpDiscoveryRejectUnauthorized", - "maxResponseBodySize", - "username", - "password", - "credentialsSecret", - "__template_environment", - "__template_streamtags", - "__template_dimensionList", - "__template_nameList", - "__template_awsApiKey", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputPrometheusDiscoveryType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - # Static - STATIC = "static" - # DNS - DNS = "dns" - # AWS EC2 - EC2 = "ec2" - # HTTP SD - HTTP_SD = "http_sd" - - -class InputResponseMetricsProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Protocol to use when collecting metrics""" - - HTTP = "http" - HTTPS = "https" - - -class InputResponseInputPrometheusTypedDict(TypedDict): - type: TypeOptionsPrometheus - r"""Connector type identifier.""" - interval: float - r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" - log_level: LogLevelOptions - r"""Collector runtime log level""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - dimension_list: NotRequired[List[str]] - r"""Other dimensions to include in events""" - field_per_metric: NotRequired[bool] - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - discovery_type: NotRequired[InputResponseInputPrometheusDiscoveryType] - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - timeout: NotRequired[float] - r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - auth_type: NotRequired[AuthenticationMethodOptionsSasl] - r"""Enter credentials directly, or select a stored secret""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - target_list: NotRequired[List[str]] - r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" - record_type: NotRequired[RecordTypeOptions] - r"""DNS record type to resolve""" - scrape_port: NotRequired[float] - r"""The port number in the metrics URL for discovered targets""" - name_list: NotRequired[List[str]] - r"""List of DNS names to resolve""" - scrape_protocol: NotRequired[InputResponseMetricsProtocol] - r"""Protocol to use when collecting metrics""" - scrape_path: NotRequired[str] - r"""Path to use when collecting metrics from discovered targets""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - use_public_ip: NotRequired[bool] - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] - r"""Filter to apply when searching for EC2 instances""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the EC2 is located""" - endpoint: NotRequired[str] - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access EC2""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - http_discovery_url: NotRequired[str] - r"""URL to fetch target groups from (must be http or https)""" - http_discovery_headers: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Extra headers to send with the discovery request""" - http_discovery_reject_unauthorized: NotRequired[bool] - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - max_response_body_size: NotRequired[str] - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - username: NotRequired[str] - r"""Username for Prometheus Basic authentication""" - password: NotRequired[str] - r"""Password for Prometheus Basic authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_dimension_list: NotRequired[str] - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - template_discovery_type: NotRequired[str] - r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" - template_log_level: NotRequired[str] - r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - template_target_list: NotRequired[str] - r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" - template_name_list: NotRequired[str] - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - template_password: NotRequired[str] - r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputPrometheus(BaseModel): - type: TypeOptionsPrometheus - r"""Connector type identifier.""" - - interval: float - r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" - - log_level: Annotated[LogLevelOptions, pydantic.Field(alias="logLevel")] - r"""Collector runtime log level""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - dimension_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="dimensionList") - ] = None - r"""Other dimensions to include in events""" - - field_per_metric: Annotated[ - Optional[bool], pydantic.Field(alias="fieldPerMetric") - ] = None - r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" - - discovery_type: Annotated[ - Optional[InputResponseInputPrometheusDiscoveryType], - pydantic.Field(alias="discoveryType"), - ] = None - r"""Target discovery mechanism. Use static to manually enter a list of targets.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - timeout: Optional[float] = None - r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") - ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") - ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsSasl], pydantic.Field(alias="authType") - ] = None - r"""Enter credentials directly, or select a stored secret""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - target_list: Annotated[Optional[List[str]], pydantic.Field(alias="targetList")] = ( - None - ) - r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" - - record_type: Annotated[ - Optional[RecordTypeOptions], pydantic.Field(alias="recordType") - ] = None - r"""DNS record type to resolve""" - - scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None - r"""The port number in the metrics URL for discovered targets""" - - name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None - r"""List of DNS names to resolve""" - - scrape_protocol: Annotated[ - Optional[InputResponseMetricsProtocol], pydantic.Field(alias="scrapeProtocol") - ] = None - r"""Protocol to use when collecting metrics""" - - scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None - r"""Path to use when collecting metrics from discovered targets""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None - r"""Use public IP address for discovered targets. Disable to use the private IP address.""" - - search_filter: Annotated[ - Optional[List[SearchFilterConfInputPrometheus]], - pydantic.Field(alias="searchFilter"), - ] = None - r"""Filter to apply when searching for EC2 instances""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""Region where the EC2 is located""" - - endpoint: Optional[str] = None - r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access EC2""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - http_discovery_url: Annotated[ - Optional[str], pydantic.Field(alias="httpDiscoveryUrl") - ] = None - r"""URL to fetch target groups from (must be http or https)""" - - http_discovery_headers: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="httpDiscoveryHeaders"), - ] = None - r"""Extra headers to send with the discovery request""" - - http_discovery_reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") - ] = None - r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" - - max_response_body_size: Annotated[ - Optional[str], pydantic.Field(alias="maxResponseBodySize") - ] = None - r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" - - username: Optional[str] = None - r"""Username for Prometheus Basic authentication""" - - password: Optional[str] = None - r"""Password for Prometheus Basic authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_dimension_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_dimensionList") - ] = None - r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" - - template_discovery_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_discoveryType") - ] = None - r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" - - template_log_level: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLevel") - ] = None - r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - - template_target_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_targetList") - ] = None - r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" - - template_name_list: Annotated[ - Optional[str], pydantic.Field(alias="__template_nameList") - ] = None - r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - template_password: Annotated[ - Optional[str], pydantic.Field(alias="__template_password") - ] = None - r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("discovery_type") - def serialize_discovery_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputPrometheusDiscoveryType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsSasl(value) - except ValueError: - return value - return value - - @field_serializer("record_type") - def serialize_record_type(self, value): - if isinstance(value, str): - try: - return models.RecordTypeOptions(value) - except ValueError: - return value - return value - - @field_serializer("scrape_protocol") - def serialize_scrape_protocol(self, value): - if isinstance(value, str): - try: - return models.InputResponseMetricsProtocol(value) - except ValueError: - return value - return value - - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "dimensionList", - "fieldPerMetric", - "discoveryType", - "rejectUnauthorized", - "timeout", - "keepAliveTime", - "jobTimeout", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "authType", - "description", - "targetList", - "recordType", - "scrapePort", - "nameList", - "scrapeProtocol", - "scrapePath", - "awsAuthenticationMethod", - "awsApiKey", - "awsSecret", - "usePublicIp", - "searchFilter", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "httpDiscoveryUrl", - "httpDiscoveryHeaders", - "httpDiscoveryRejectUnauthorized", - "maxResponseBodySize", - "username", - "password", - "credentialsSecret", - "__template_environment", - "__template_streamtags", - "__template_dimensionList", - "__template_discoveryType", - "__template_logLevel", - "__template_targetList", - "__template_nameList", - "__template_awsApiKey", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_username", - "__template_password", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputPrometheusRwType(str, Enum): - r"""Source type identifier.""" - - PROMETHEUS_RW = "prometheus_rw" - - -class InputResponseInputPrometheusRwTypedDict(TypedDict): - type: InputResponseInputPrometheusRwType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - prometheus_api: str - r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputPrometheusRw(BaseModel): - type: InputResponseInputPrometheusRwType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] - r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "metadata", - "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_username", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputLokiType(str, Enum): - r"""Source type identifier.""" - - LOKI = "loki" - - -class InputResponseInputLokiTypedDict(TypedDict): - type: InputResponseInputLokiType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - loki_api: str - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputLoki(BaseModel): - type: InputResponseInputLokiType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "metadata", - "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_lokiAPI", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputGrafanaType2(str, Enum): - r"""Source type identifier.""" - - GRAFANA = "grafana" - - -class InputResponsePrometheusAuth2TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class InputResponsePrometheusAuth2(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseLokiAuth2TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class InputResponseLokiAuth2(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputGrafanaGrafana2TypedDict(TypedDict): - type: InputResponseInputGrafanaType2 - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - loki_api: str - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - prometheus_api: NotRequired[str] - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - prometheus_auth: NotRequired[InputResponsePrometheusAuth2TypedDict] - loki_auth: NotRequired[InputResponseLokiAuth2TypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputGrafanaGrafana2(BaseModel): - type: InputResponseInputGrafanaType2 - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - prometheus_api: Annotated[Optional[str], pydantic.Field(alias="prometheusAPI")] = ( - None - ) - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - - prometheus_auth: Annotated[ - Optional[InputResponsePrometheusAuth2], pydantic.Field(alias="prometheusAuth") - ] = None - - loki_auth: Annotated[ - Optional[InputResponseLokiAuth2], pydantic.Field(alias="lokiAuth") - ] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "prometheusAPI", - "prometheusAuth", - "lokiAuth", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_lokiAPI", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputGrafanaType1(str, Enum): - r"""Source type identifier.""" - - GRAFANA = "grafana" - - -class InputResponsePrometheusAuth1TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] - r"""Remote Write authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class InputResponsePrometheusAuth1(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuth], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseLokiAuth1TypedDict(TypedDict): - auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] - r"""Loki logs authentication type""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class InputResponseLokiAuth1(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") - ] = None - r"""Loki logs authentication type""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsLokiAuth(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputGrafanaGrafana1TypedDict(TypedDict): - type: InputResponseInputGrafanaType1 - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - prometheus_api: str - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - loki_api: NotRequired[str] - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - prometheus_auth: NotRequired[InputResponsePrometheusAuth1TypedDict] - loki_auth: NotRequired[InputResponseLokiAuth1TypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_prometheus_api: NotRequired[str] - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - template_loki_api: NotRequired[str] - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputGrafanaGrafana1(BaseModel): - type: InputResponseInputGrafanaType1 - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" - - prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] - r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" - - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - - loki_api: Annotated[Optional[str], pydantic.Field(alias="lokiAPI")] = None - r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" - - prometheus_auth: Annotated[ - Optional[InputResponsePrometheusAuth1], pydantic.Field(alias="prometheusAuth") - ] = None - - loki_auth: Annotated[ - Optional[InputResponseLokiAuth1], pydantic.Field(alias="lokiAuth") - ] = None - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_prometheus_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusAPI") - ] = None - r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" - - template_loki_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiAPI") - ] = None - r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "lokiAPI", - "prometheusAuth", - "lokiAuth", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_prometheusAPI", - "__template_lokiAPI", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -InputResponseInputGrafanaUnionTypedDict = TypeAliasType( - "InputResponseInputGrafanaUnionTypedDict", - Union[ - InputResponseInputGrafanaGrafana1TypedDict, - InputResponseInputGrafanaGrafana2TypedDict, - ], -) - - -InputResponseInputGrafanaUnion = TypeAliasType( - "InputResponseInputGrafanaUnion", - Union[InputResponseInputGrafanaGrafana1, InputResponseInputGrafanaGrafana2], -) - - -class InputResponseInputConfluentCloudTypedDict(TypedDict): - type: TypeOptionsConfluentcloud - r"""Connector type identifier.""" - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" - topics: List[str] - r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - group_id: NotRequired[str] - r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" - from_beginning: NotRequired[bool] - r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" - kafka_schema_registry: NotRequired[KafkaSchemaRegistryAuthenticationTypeTypedDict] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - session_timeout: NotRequired[float] - r""" - Timeout used to detect client failures when using Kafka's group-management facilities. - If the client sends no heartbeats to the broker before the timeout expires, - the broker will remove the client from the group and initiate a rebalance. - Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. - See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. - """ - rebalance_timeout: NotRequired[float] - r""" - Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. - """ - heartbeat_interval: NotRequired[float] - r""" - Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. - """ - auto_commit_interval: NotRequired[float] - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - auto_commit_threshold: NotRequired[float] - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - max_bytes_per_partition: NotRequired[float] - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - max_bytes: NotRequired[float] - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - max_socket_errors: NotRequired[float] - r"""Maximum number of network errors before the consumer re-creates a socket""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topics: NotRequired[str] - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - template_group_id: NotRequired[str] - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputConfluentCloud(BaseModel): - type: TypeOptionsConfluentcloud - r"""Connector type identifier.""" - - brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" - - topics: List[str] - r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None - r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" - - from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( - None - ) - r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" - - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationType], - pydantic.Field(alias="kafkaSchemaRegistry"), - ] = None - r"""Kafka Schema Registry Authentication""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Maximum time to wait for a connection to complete successfully""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" - - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") - ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" - - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") - ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - - session_timeout: Annotated[ - Optional[float], pydantic.Field(alias="sessionTimeout") - ] = None - r""" - Timeout used to detect client failures when using Kafka's group-management facilities. - If the client sends no heartbeats to the broker before the timeout expires, - the broker will remove the client from the group and initiate a rebalance. - Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. - See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. - """ - - rebalance_timeout: Annotated[ - Optional[float], pydantic.Field(alias="rebalanceTimeout") - ] = None - r""" - Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. - """ - - heartbeat_interval: Annotated[ - Optional[float], pydantic.Field(alias="heartbeatInterval") - ] = None - r""" - Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. - """ - - auto_commit_interval: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitInterval") - ] = None - r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - auto_commit_threshold: Annotated[ - Optional[float], pydantic.Field(alias="autoCommitThreshold") - ] = None - r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" - - max_bytes_per_partition: Annotated[ - Optional[float], pydantic.Field(alias="maxBytesPerPartition") - ] = None - r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" - - max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None - r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" - - max_socket_errors: Annotated[ - Optional[float], pydantic.Field(alias="maxSocketErrors") - ] = None - r"""Maximum number of network errors before the consumer re-creates a socket""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") - ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - - template_topics: Annotated[ - Optional[str], pydantic.Field(alias="__template_topics") - ] = None - r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" - - template_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_groupId") - ] = None - r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "groupId", - "fromBeginning", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "sessionTimeout", - "rebalanceTimeout", - "heartbeatInterval", - "autoCommitInterval", - "autoCommitThreshold", - "maxBytesPerPartition", - "maxBytes", - "maxSocketErrors", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_brokers", - "__template_topics", - "__template_groupId", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - return m + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" -class InputResponseInputElasticType(str, Enum): - r"""Source type identifier.""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - ELASTIC = "elastic" + pq: Optional[PqType] = None + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" -class InputResponseInputElasticAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Auth Tokens - AUTH_TOKENS = "authTokens" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" -class InputResponseAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The API version to use for communicating with the server""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - # 6.8.4 - SIX_DOT_8_DOT_4 = "6.8.4" - # 8.3.2 - EIGHT_DOT_3_DOT_2 = "8.3.2" - # Custom - CUSTOM = "custom" + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" -class InputResponseInputElasticAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter credentials directly, or select a stored secret""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - NONE = "none" - MANUAL = "manual" - SECRET = "secret" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class InputResponseInputElasticProxyModeTypedDict(TypedDict): - enabled: bool - r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" - auth_type: NotRequired[InputResponseInputElasticAuthenticationMethod] - r"""Enter credentials directly, or select a stored secret""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - url: NotRequired[str] - r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - remove_headers: NotRequired[List[str]] - r"""List of headers to remove from the request to proxy""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" -class InputResponseInputElasticProxyMode(BaseModel): - enabled: bool - r"""Enable proxying of non-bulk API requests to an external Elastic server. Enable this only if you understand the implications. See [Cribl Docs](https://docs.cribl.io/stream/sources-elastic/#proxy-mode) for more details.""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" auth_type: Annotated[ - Optional[InputResponseInputElasticAuthenticationMethod], + Optional[InputResponseInputElasticAuthenticationType], pydantic.Field(alias="authType"), ] = None - r"""Enter credentials directly, or select a stored secret""" + r"""Authentication type""" + + api_version: Annotated[ + Optional[InputResponseAPIVersion], pydantic.Field(alias="apiVersion") + ] = None + r"""The API version to use for communicating with the server""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + proxy_mode: Annotated[ + Optional[InputResponseInputElasticProxyMode], pydantic.Field(alias="proxyMode") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" username: Optional[str] = None r"""Username""" @@ -9453,32 +604,66 @@ class InputResponseInputElasticProxyMode(BaseModel): ] = None r"""Select or create a secret that references your credentials""" - url: Optional[str] = None - r"""URL of the Elastic server to proxy non-bulk requests to, such as http://elastic:9200""" + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Bearer tokens to include in the authorization header""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + custom_api_version: Annotated[ + Optional[str], pydantic.Field(alias="customAPIVersion") ] = None - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + r"""Custom version information to respond to requests""" - remove_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="removeHeaders") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""List of headers to remove from the request to proxy""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a proxy request to complete before canceling it""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_elastic_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticAPI") + ] = None + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.InputResponseInputElasticAuthenticationMethod(value) + return models.InputResponseInputElasticAuthenticationType(value) + except ValueError: + return value + return value + + @field_serializer("api_version") + def serialize_api_version(self, value): + if isinstance(value, str): + try: + return models.InputResponseAPIVersion(value) except ValueError: return value return value @@ -9487,15 +672,48 @@ def serialize_auth_type(self, value): def serialize_model(self, handler): optional_fields = set( [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", "authType", + "apiVersion", + "extraHttpHeaders", + "metadata", + "proxyMode", + "description", "username", "password", "credentialsSecret", - "url", - "rejectUnauthorized", - "removeHeaders", - "timeoutSec", - "__template_url", + "authTokens", + "customAPIVersion", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_elasticAPI", + "__template_authTokens", + "notifications", + "status", ] ) serialized = handler(self) @@ -9512,15 +730,17 @@ def serialize_model(self, handler): return m -class InputResponseInputElasticTypedDict(TypedDict): - type: InputResponseInputElasticType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - elastic_api: str - r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" +class InputResponseInputAzureVnetFlowLogType(str, Enum): + r"""Connector type identifier.""" + + AZURE_VNET_FLOW_LOG = "azure_vnet_flow_log" + + +class InputResponseInputAzureVnetFlowLogTypedDict(TypedDict): + type: InputResponseInputAzureVnetFlowLogType + r"""Connector type identifier.""" + queue_name: str + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -9535,89 +755,74 @@ class InputResponseInputElasticTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - auth_type: NotRequired[InputResponseInputElasticAuthenticationType] - r"""Authentication type""" - api_version: NotRequired[InputResponseAPIVersion] - r"""The API version to use for communicating with the server""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + visibility_timeout: NotRequired[float] + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + max_messages: NotRequired[float] + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" + max_dequeue_count: NotRequired[float] + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" + service_period_secs: NotRequired[float] + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - proxy_mode: NotRequired[InputResponseInputElasticProxyModeTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] + r"""Authentication method""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - auth_tokens: NotRequired[List[str]] - r"""Bearer tokens to include in the authorization header""" - custom_api_version: NotRequired[str] - r"""Custom version information to respond to requests""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_elastic_api: NotRequired[str] - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputElastic(BaseModel): - type: InputResponseInputElasticType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" +class InputResponseInputAzureVnetFlowLog(BaseModel): + type: InputResponseInputAzureVnetFlowLogType + r"""Connector type identifier.""" - elastic_api: Annotated[str, pydantic.Field(alias="elasticAPI")] - r"""Absolute path on which to listen for Elasticsearch API requests. Defaults to /. _bulk will be appended automatically. For example, /myPath becomes /myPath/_bulk. Requests can then be made to either /myPath/_bulk or /myPath//_bulk. Other entries are faked as success.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The storage account queue name blob notifications will be read from. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myQueue-${C.vars.myVar}`""" id: Optional[str] = None r"""Unique ID for this input""" @@ -9643,7 +848,7 @@ class InputResponseInputElastic(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -9653,116 +858,82 @@ class InputResponseInputElastic(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" - - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( - None - ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") - ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") - ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" + r"""The duration (in seconds) that the received messages are hidden from subsequent retrieve requests after being retrieved by a ReceiveMessage request.""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages to return in a poll request. Azure storage queues never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 32.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + max_dequeue_count: Annotated[ + Optional[float], pydantic.Field(alias="maxDequeueCount") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""Number of times a non-matching message can be dequeued before it is permanently deleted. At the default of 1, non-matching messages are deleted immediately (same as standard Azure Blob source behavior). Set higher to leave messages in the queue for other consumers.""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + service_period_secs: Annotated[ + Optional[float], pydantic.Field(alias="servicePeriodSecs") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + r"""The duration (in seconds) which pollers should be validated and restarted if exited""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" auth_type: Annotated[ - Optional[InputResponseInputElasticAuthenticationType], + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], pydantic.Field(alias="authType"), ] = None - r"""Authentication type""" - - api_version: Annotated[ - Optional[InputResponseAPIVersion], pydantic.Field(alias="apiVersion") - ] = None - r"""The API version to use for communicating with the server""" + r"""Authentication method""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - proxy_mode: Annotated[ - Optional[InputResponseInputElasticProxyMode], pydantic.Field(alias="proxyMode") + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") ] = None + r"""The name of your Azure storage account""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" - username: Optional[str] = None - r"""Username""" + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" - password: Optional[str] = None - r"""Password""" + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") ] = None - r"""Select or create a secret that references your credentials""" - - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Bearer tokens to include in the authorization header""" + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - custom_api_version: Annotated[ - Optional[str], pydantic.Field(alias="customAPIVersion") + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") ] = None - r"""Custom version information to respond to requests""" + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -9774,27 +945,32 @@ class InputResponseInputElastic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_elastic_api: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticAPI") + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -9804,16 +980,11 @@ class InputResponseInputElastic(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.InputResponseInputElasticAuthenticationType(value) - except ValueError: - return value - return value - - @field_serializer("api_version") - def serialize_api_version(self, value): - if isinstance(value, str): - try: - return models.InputResponseAPIVersion(value) + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) + ) except ValueError: return value return value @@ -9832,36 +1003,32 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "authType", - "apiVersion", - "extraHttpHeaders", + "fileFilter", + "visibilityTimeout", + "numReceivers", + "maxMessages", + "maxDequeueCount", + "servicePeriodSecs", "metadata", - "proxyMode", + "breakerRulesets", + "staleChannelFlushMs", + "authType", "description", - "username", - "password", - "credentialsSecret", - "authTokens", - "customAPIVersion", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", "__template_environment", "__template_streamtags", - "__template_host", - "__template_port", - "__template_elasticAPI", - "__template_authTokens", + "__template_queueName", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", "notifications", "status", ] @@ -9899,9 +1066,7 @@ class InputResponseInputAzureBlobTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -9918,6 +1083,8 @@ class InputResponseInputAzureBlobTypedDict(TypedDict): r"""The duration (in seconds) which pollers should be validated and restarted if exited""" skip_on_error: NotRequired[bool] r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] @@ -9930,6 +1097,8 @@ class InputResponseInputAzureBlobTypedDict(TypedDict): r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" auth_type: NotRequired[AuthenticationMethodOptions] r"""Authentication method""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" connection_string: NotRequired[str] @@ -9965,7 +1134,7 @@ class InputResponseInputAzureBlobTypedDict(TypedDict): r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" template_azure_cloud: NotRequired[str] r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -10002,7 +1171,7 @@ class InputResponseInputAzureBlob(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -10036,6 +1205,9 @@ class InputResponseInputAzureBlob(BaseModel): skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -10064,6 +1236,9 @@ class InputResponseInputAzureBlob(BaseModel): ] = None r"""Authentication method""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -10141,7 +1316,7 @@ class InputResponseInputAzureBlob(BaseModel): ] = None r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -10176,12 +1351,14 @@ def serialize_model(self, handler): "maxMessages", "servicePeriodSecs", "skipOnError", + "encoding", "metadata", "breakerRulesets", "staleChannelFlushMs", "parquetChunkSizeMB", "parquetChunkDownloadTimeout", "authType", + "autoParse", "description", "connectionString", "textSecret", @@ -10227,7 +1404,7 @@ class InputResponseInputSplunkHecType(str, Enum): class InputResponseInputSplunkHecAuthTokenTypedDict(TypedDict): token: str r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" token_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -10246,7 +1423,7 @@ class InputResponseInputSplunkHecAuthToken(BaseModel): r"""Shared secret to be provided by any client (Authorization: )""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -10272,7 +1449,7 @@ class InputResponseInputSplunkHecAuthToken(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -10326,9 +1503,7 @@ class InputResponseInputSplunkHecTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -10368,6 +1543,8 @@ class InputResponseInputSplunkHecTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" use_fwd_timezone: NotRequired[bool] r"""Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event""" drop_control_fields: NotRequired[bool] @@ -10392,7 +1569,7 @@ class InputResponseInputSplunkHecTypedDict(TypedDict): r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_splunk_hec_api: NotRequired[str] r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -10435,7 +1612,7 @@ class InputResponseInputSplunkHec(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -10532,6 +1709,9 @@ class InputResponseInputSplunkHec(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + use_fwd_timezone: Annotated[ Optional[bool], pydantic.Field(alias="useFwdTimezone") ] = None @@ -10590,7 +1770,7 @@ class InputResponseInputSplunkHec(BaseModel): ] = None r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -10628,6 +1808,7 @@ def serialize_model(self, handler): "splunkHecAcks", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "useFwdTimezone", "dropControlFields", "extractMetrics", @@ -10749,9 +1930,7 @@ class InputResponseInputSplunkSearchTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -10819,7 +1998,7 @@ class InputResponseInputSplunkSearchTypedDict(TypedDict): r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_log_level: NotRequired[str] r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -10876,7 +2055,7 @@ class InputResponseInputSplunkSearch(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -11026,7 +2205,7 @@ class InputResponseInputSplunkSearch(BaseModel): ] = None r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -11124,22 +2303,44 @@ def serialize_model(self, handler): class InputResponseInputSplunkAuthTokenTypedDict(TypedDict): - token: str + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Description""" class InputResponseInputSplunkAuthToken(BaseModel): - token: str + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: Optional[str] = None r"""Description""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description"]) + optional_fields = set(["authType", "tokenSecret", "token", "description"]) serialized = handler(self) m = {} @@ -11195,9 +2396,7 @@ class InputResponseInputSplunkTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -11222,6 +2421,8 @@ class InputResponseInputSplunkTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" auth_tokens: NotRequired[List[InputResponseInputSplunkAuthTokenTypedDict]] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" max_s2_sversion: NotRequired[InputResponseMaxS2SVersion] @@ -11248,7 +2449,7 @@ class InputResponseInputSplunkTypedDict(TypedDict): r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -11288,7 +2489,7 @@ class InputResponseInputSplunk(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -11344,6 +2545,9 @@ class InputResponseInputSplunk(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + auth_tokens: Annotated[ Optional[List[InputResponseInputSplunkAuthToken]], pydantic.Field(alias="authTokens"), @@ -11406,71 +2610,193 @@ class InputResponseInputSplunk(BaseModel): ] = None r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): + if isinstance(value, str): + try: + return models.InputResponseMaxS2SVersion(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.InputResponseCompression(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "authTokens", + "maxS2Sversion", + "description", + "useFwdTimezone", + "dropControlFields", + "extractMetrics", + "compress", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_maxS2Sversion", + "__template_compress", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputHTTPType(str, Enum): + r"""Source type identifier.""" + + HTTP = "http" + + +class InputResponseInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputResponseInputHTTPInputHTTPAuthTokensExtItemsType(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + description: Optional[str] = None + r"""Description""" - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): - if isinstance(value, str): - try: - return models.InputResponseMaxS2SVersion(value) - except ValueError: - return value - return value + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.InputResponseCompression(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "enableProxyHeader", - "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "authTokens", - "maxS2Sversion", - "description", - "useFwdTimezone", - "dropControlFields", - "extractMetrics", - "compress", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_maxS2Sversion", - "__template_compress", - "notifications", - "status", - ] - ) + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) serialized = handler(self) m = {} @@ -11485,10 +2811,22 @@ def serialize_model(self, handler): return m -class InputResponseInputHTTPType(str, Enum): - r"""Source type identifier.""" +InputResponseInputHTTPAuthTokensExtTypedDict = TypeAliasType( + "InputResponseInputHTTPAuthTokensExtTypedDict", + Union[ + InputResponseInputHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputResponseInputHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) - HTTP = "http" + +InputResponseInputHTTPAuthTokensExt = TypeAliasType( + "InputResponseInputHTTPAuthTokensExt", + Union[ + InputResponseInputHTTPInputHTTPAuthTokensExtItemsType, + InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint, + ], +) class InputResponseInputHTTPTypedDict(TypedDict): @@ -11512,9 +2850,7 @@ class InputResponseInputHTTPTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -11556,7 +2892,7 @@ class InputResponseInputHTTPTypedDict(TypedDict): r"""Enable Splunk HEC acknowledgements""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] + auth_tokens_ext: NotRequired[List[InputResponseInputHTTPAuthTokensExtTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -11576,7 +2912,7 @@ class InputResponseInputHTTPTypedDict(TypedDict): r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" template_splunk_hec_api: NotRequired[str] r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -11616,7 +2952,7 @@ class InputResponseInputHTTP(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -11714,7 +3050,7 @@ class InputResponseInputHTTP(BaseModel): r"""Fields to add to events from this input""" auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], + Optional[List[InputResponseInputHTTPAuthTokensExt]], pydantic.Field(alias="authTokensExt"), ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -11762,7 +3098,7 @@ class InputResponseInputHTTP(BaseModel): ] = None r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -11854,9 +3190,7 @@ class InputResponseInputMskTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -11929,6 +3263,8 @@ class InputResponseInputMskTypedDict(TypedDict): r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" max_socket_errors: NotRequired[float] r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] @@ -11957,7 +3293,7 @@ class InputResponseInputMskTypedDict(TypedDict): r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_aws_api_key: NotRequired[str] r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -12006,7 +3342,7 @@ class InputResponseInputMsk(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -12156,6 +3492,9 @@ class InputResponseInputMsk(BaseModel): ] = None r"""Maximum number of network errors before the consumer re-creates a socket""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -12220,7 +3559,7 @@ class InputResponseInputMsk(BaseModel): ] = None r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -12278,6 +3617,7 @@ def serialize_model(self, handler): "maxBytesPerPartition", "maxBytes", "maxSocketErrors", + "autoParse", "description", "awsApiKey", "awsSecret", @@ -12331,9 +3671,7 @@ class InputResponseInputKafkaTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -12392,6 +3730,8 @@ class InputResponseInputKafkaTypedDict(TypedDict): r"""Maximum number of network errors before the consumer re-creates a socket""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -12404,7 +3744,7 @@ class InputResponseInputKafkaTypedDict(TypedDict): r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" template_group_id: NotRequired[str] r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -12444,7 +3784,7 @@ class InputResponseInputKafka(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -12559,6 +3899,9 @@ class InputResponseInputKafka(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -12587,7 +3930,7 @@ class InputResponseInputKafka(BaseModel): ] = None r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -12629,6 +3972,7 @@ def serialize_model(self, handler): "maxBytes", "maxSocketErrors", "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", @@ -12678,9 +4022,7 @@ class InputResponseInputCollectionTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -12701,7 +4043,7 @@ class InputResponseInputCollectionTypedDict(TypedDict): r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -12737,7 +4079,7 @@ class InputResponseInputCollection(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -12781,7 +4123,7 @@ class InputResponseInputCollection(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -12830,74 +4172,91 @@ def serialize_model(self, handler): InputResponseTypedDict = TypeAliasType( "InputResponseTypedDict", Union[ - InputResponseInputDatagenTypedDict, InputResponseInputCriblTypedDict, InputResponseInputKubeEventsTypedDict, - InputResponseInputAppleUnifiedLogsTypedDict, + InputResponseInputDatagenTypedDict, InputResponseInputCriblmetricsTypedDict, + InputResponseInputAppleUnifiedLogsTypedDict, InputResponseInputCollectionTypedDict, - InputResponseInputSystemStateTypedDict, InputResponseInputKubeMetricsTypedDict, + InputResponseInputSystemStateTypedDict, InputResponseInputWindowsMetricsTypedDict, InputResponseInputSystemMetricsTypedDict, InputResponseInputJournalFilesTypedDict, + InputResponseInputKubeLogsTypedDict, InputResponseInputModelDrivenTelemetryTypedDict, InputResponseInputExecTypedDict, InputResponseInputRawUDPTypedDict, - InputResponseInputKubeLogsTypedDict, InputResponseInputSnmpTypedDict, + InputResponseInputProofpointPodTypedDict, + InputResponseInputAnthropicEnterpriseAnalyticsTypedDict, InputResponseInputWinEventLogsTypedDict, InputResponseInputMetricsTypedDict, - InputResponseInputCriblTCPTypedDict, InputResponseInputNetflowTypedDict, + InputResponseInputCriblTCPTypedDict, InputResponseInputOpenaiTypedDict, InputResponseInputOktaTypedDict, InputResponseInputTcpjsonTypedDict, InputResponseInputEventhubAmqpTypedDict, InputResponseInputGooglePubsubTypedDict, InputResponseInputCriblHTTPTypedDict, - InputResponseInputTCPTypedDict, InputResponseInputOffice365ServiceTypedDict, - InputResponseInputFirehoseTypedDict, InputResponseInputWizTypedDict, + InputResponseInputSailpointHecTypedDict, + InputResponseInputTCPTypedDict, + InputResponseInputFirehoseTypedDict, InputResponseInputAnthropicComplianceTypedDict, - InputResponseInputAppscopeTypedDict, + InputResponseInputAkamaiHecTypedDict, InputResponseInputOffice365MgmtTypedDict, - InputResponseInputSplunkTypedDict, - InputResponseInputFileTypedDict, + InputResponseInputAppscopeTypedDict, InputResponseInputDatadogAgentTypedDict, + InputResponseInputSplunkTypedDict, + InputResponseInputAzureVnetFlowLogTypedDict, + InputResponseInputBeyondtrustHecTypedDict, InputResponseInputWefTypedDict, - InputResponseInputWizWebhookTypedDict, + InputResponseInputFileTypedDict, InputResponseInputLokiTypedDict, + InputResponseInputWizWebhookTypedDict, + InputResponseInputVectraAiHecTypedDict, + InputResponseInputGigamonHecTypedDict, + InputResponseInputSysdigHecTypedDict, InputResponseInputPrometheusRwTypedDict, - InputResponseInputKafkaTypedDict, + InputResponseInputTrellixHecTypedDict, + InputResponseInputAquaSecurityHecTypedDict, + InputResponseInputExtrahopRevealx360TypedDict, + InputResponseInputPingIdentityPingoneTypedDict, InputResponseInputUpwindHecTypedDict, - InputResponseInputSysdigHecTypedDict, - InputResponseInputEventhubTypedDict, - InputResponseInputConfluentCloudTypedDict, + InputResponseInputHashicorpHcpVaultDedicatedTypedDict, + InputResponseInputMimecastHecTypedDict, + InputResponseInputTrendMicroVisionOneTypedDict, InputResponseInputZscalerHecTypedDict, - InputResponseInputHTTPTypedDict, + InputResponseInputConfluentCloudTypedDict, InputResponseInputCriblLakeHTTPTypedDict, - InputResponseInputAzureBlobTypedDict, + InputResponseInputKafkaTypedDict, + InputResponseInputHTTPTypedDict, + InputResponseInputF5BigIPTypedDict, InputResponseInputOpenaiComplianceLogsTypedDict, + InputResponseInputMicrosoftCopilotTypedDict, + InputResponseInputEventhubTypedDict, InputResponseInputCloudflareHecTypedDict, InputResponseInputElasticTypedDict, - InputResponseInputOpenTelemetryTypedDict, - InputResponseInputSqsTypedDict, + InputResponseInputAzureBlobTypedDict, InputResponseInputSplunkHecTypedDict, - InputResponseInputKinesisTypedDict, + InputResponseInputSqsTypedDict, InputResponseInputMicrosoftGraphTypedDict, InputResponseInputOffice365MsgTraceTypedDict, + InputResponseInputOpenTelemetryTypedDict, + InputResponseInputKinesisTypedDict, InputResponseInputHTTPRawTypedDict, InputResponseInputSplunkSearchTypedDict, InputResponseInputServicenowTableTypedDict, InputResponseInputMskTypedDict, InputResponseInputEdgePrometheusTypedDict, InputResponseInputCrowdstrikeTypedDict, - InputResponseInputBedrockS3TypedDict, InputResponseInputPrometheusTypedDict, - InputResponseInputS3TypedDict, + InputResponseInputBedrockS3TypedDict, InputResponseInputSecurityLakeTypedDict, + InputResponseInputS3TypedDict, InputResponseInputS3InventoryTypedDict, InputResponseInputGrafanaUnionTypedDict, InputResponseInputSyslogUnionTypedDict, @@ -12925,6 +4284,7 @@ class UnknownInputResponse(BaseModel): "splunk_search": InputResponseInputSplunkSearch, "splunk_hec": InputResponseInputSplunkHec, "azure_blob": InputResponseInputAzureBlob, + "azure_vnet_flow_log": InputResponseInputAzureVnetFlowLog, "elastic": InputResponseInputElastic, "confluent_cloud": InputResponseInputConfluentCloud, "grafana": InputResponseInputGrafanaUnion, @@ -12981,13 +4341,29 @@ class UnknownInputResponse(BaseModel): "security_lake": InputResponseInputSecurityLake, "bedrock_s3": InputResponseInputBedrockS3, "servicenow_table": InputResponseInputServicenowTable, + "proofpoint_pod": InputResponseInputProofpointPod, "zscaler_hec": InputResponseInputZscalerHec, "cloudflare_hec": InputResponseInputCloudflareHec, "sysdig_hec": InputResponseInputSysdigHec, "upwind_hec": InputResponseInputUpwindHec, + "trellix_hec": InputResponseInputTrellixHec, + "sailpoint_hec": InputResponseInputSailpointHec, + "extrahop_revealx_360": InputResponseInputExtrahopRevealx360, + "aqua_security_hec": InputResponseInputAquaSecurityHec, "openai_compliance_logs": InputResponseInputOpenaiComplianceLogs, "anthropic_compliance": InputResponseInputAnthropicCompliance, + "anthropic_enterprise_analytics": InputResponseInputAnthropicEnterpriseAnalytics, + "microsoft_copilot": InputResponseInputMicrosoftCopilot, "okta": InputResponseInputOkta, + "akamai_hec": InputResponseInputAkamaiHec, + "ping_identity_pingone": InputResponseInputPingIdentityPingone, + "gigamon_hec": InputResponseInputGigamonHec, + "vectra_ai_hec": InputResponseInputVectraAiHec, + "f5_big_ip": InputResponseInputF5BigIP, + "beyondtrust_hec": InputResponseInputBeyondtrustHec, + "hashicorp_hcp_vault_dedicated": InputResponseInputHashicorpHcpVaultDedicated, + "mimecast_hec": InputResponseInputMimecastHec, + "trend_micro_vision_one": InputResponseInputTrendMicroVisionOne, } @@ -13001,6 +4377,7 @@ class UnknownInputResponse(BaseModel): InputResponseInputSplunkSearch, InputResponseInputSplunkHec, InputResponseInputAzureBlob, + InputResponseInputAzureVnetFlowLog, InputResponseInputElastic, InputResponseInputConfluentCloud, InputResponseInputGrafanaUnion, @@ -13057,13 +4434,29 @@ class UnknownInputResponse(BaseModel): InputResponseInputSecurityLake, InputResponseInputBedrockS3, InputResponseInputServicenowTable, + InputResponseInputProofpointPod, InputResponseInputZscalerHec, InputResponseInputCloudflareHec, InputResponseInputSysdigHec, InputResponseInputUpwindHec, + InputResponseInputTrellixHec, + InputResponseInputSailpointHec, + InputResponseInputExtrahopRevealx360, + InputResponseInputAquaSecurityHec, InputResponseInputOpenaiComplianceLogs, InputResponseInputAnthropicCompliance, + InputResponseInputAnthropicEnterpriseAnalytics, + InputResponseInputMicrosoftCopilot, InputResponseInputOkta, + InputResponseInputAkamaiHec, + InputResponseInputPingIdentityPingone, + InputResponseInputGigamonHec, + InputResponseInputVectraAiHec, + InputResponseInputF5BigIP, + InputResponseInputBeyondtrustHec, + InputResponseInputHashicorpHcpVaultDedicated, + InputResponseInputMimecastHec, + InputResponseInputTrendMicroVisionOne, UnknownInputResponse, ], BeforeValidator( @@ -13080,207 +4473,47 @@ class UnknownInputResponse(BaseModel): try: - InputResponseCollectors.model_rebuild() -except NameError: - pass -try: - InputResponseInputSystemStatePersistence.model_rebuild() -except NameError: - pass -try: - InputResponseInputSystemState.model_rebuild() -except NameError: - pass -try: - InputResponseInputSystemMetricsCPU.model_rebuild() -except NameError: - pass -try: - InputResponseInputSystemMetricsNetwork.model_rebuild() -except NameError: - pass -try: - InputResponseInputSystemMetricsDisk.model_rebuild() -except NameError: - pass -try: - InputResponseContainer.model_rebuild() -except NameError: - pass -try: - InputResponseInputSystemMetricsPersistence.model_rebuild() -except NameError: - pass -try: - InputResponseInputSystemMetrics.model_rebuild() -except NameError: - pass -try: - InputResponseInputTcpjson.model_rebuild() -except NameError: - pass -try: - InputResponseSplunkHecMetadata.model_rebuild() -except NameError: - pass -try: - InputResponseElasticsearchMetadata.model_rebuild() -except NameError: - pass -try: - InputResponseAuthTokensExt.model_rebuild() -except NameError: - pass -try: - InputResponseInputCriblLakeHTTP.model_rebuild() -except NameError: - pass -try: - InputResponseInputCriblHTTP.model_rebuild() -except NameError: - pass -try: - InputResponseInputCriblTCP.model_rebuild() -except NameError: - pass -try: - InputResponseInputCribl.model_rebuild() -except NameError: - pass -try: - InputResponseInputGooglePubsub.model_rebuild() -except NameError: - pass -try: - InputResponseInputFirehose.model_rebuild() -except NameError: - pass -try: - InputResponseInputExec.model_rebuild() -except NameError: - pass -try: - InputResponseCertificate.model_rebuild() -except NameError: - pass -try: - InputResponseAuth.model_rebuild() -except NameError: - pass -try: - InputResponseAzureBlobStorage.model_rebuild() -except NameError: - pass -try: - InputResponseCheckpointing.model_rebuild() -except NameError: - pass -try: - InputResponseInputEventhubAmqp.model_rebuild() -except NameError: - pass -try: - InputResponseInputEventhub.model_rebuild() -except NameError: - pass -try: - InputResponseInputMicrosoftGraph.model_rebuild() -except NameError: - pass -try: - InputResponseInputOffice365MsgTrace.model_rebuild() -except NameError: - pass -try: - InputResponseInputOffice365ServiceContentConfig.model_rebuild() -except NameError: - pass -try: - InputResponseInputOffice365Service.model_rebuild() -except NameError: - pass -try: - InputResponseInputOffice365MgmtContentConfig.model_rebuild() -except NameError: - pass -try: - InputResponseInputOffice365Mgmt.model_rebuild() -except NameError: - pass -try: - InputResponsePodFilter.model_rebuild() -except NameError: - pass -try: - InputResponseInputEdgePrometheus.model_rebuild() -except NameError: - pass -try: - InputResponseInputPrometheus.model_rebuild() -except NameError: - pass -try: - InputResponseInputPrometheusRw.model_rebuild() -except NameError: - pass -try: - InputResponseInputLoki.model_rebuild() -except NameError: - pass -try: - InputResponsePrometheusAuth2.model_rebuild() -except NameError: - pass -try: - InputResponseLokiAuth2.model_rebuild() -except NameError: - pass -try: - InputResponseInputGrafanaGrafana2.model_rebuild() -except NameError: - pass -try: - InputResponsePrometheusAuth1.model_rebuild() + InputResponseInputElasticProxyMode.model_rebuild() except NameError: pass try: - InputResponseLokiAuth1.model_rebuild() + InputResponseInputElastic.model_rebuild() except NameError: pass try: - InputResponseInputGrafanaGrafana1.model_rebuild() + InputResponseInputAzureVnetFlowLog.model_rebuild() except NameError: pass try: - InputResponseInputConfluentCloud.model_rebuild() + InputResponseInputAzureBlob.model_rebuild() except NameError: pass try: - InputResponseInputElasticProxyMode.model_rebuild() + InputResponseInputSplunkHecAuthToken.model_rebuild() except NameError: pass try: - InputResponseInputElastic.model_rebuild() + InputResponseInputSplunkHec.model_rebuild() except NameError: pass try: - InputResponseInputAzureBlob.model_rebuild() + InputResponseInputSplunkSearch.model_rebuild() except NameError: pass try: - InputResponseInputSplunkHecAuthToken.model_rebuild() + InputResponseInputSplunkAuthToken.model_rebuild() except NameError: pass try: - InputResponseInputSplunkHec.model_rebuild() + InputResponseInputSplunk.model_rebuild() except NameError: pass try: - InputResponseInputSplunkSearch.model_rebuild() + InputResponseInputHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() except NameError: pass try: - InputResponseInputSplunk.model_rebuild() + InputResponseInputHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() except NameError: pass try: diff --git a/src/cribl_control_plane/models/inputresponse_inputelastic_type.py b/src/cribl_control_plane/models/inputresponse_inputelastic_type.py new file mode 100644 index 000000000..ce5724859 --- /dev/null +++ b/src/cribl_control_plane/models/inputresponse_inputelastic_type.py @@ -0,0 +1,14776 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, +) +from .authenticationmethodoptionsclientassertionclientassertionrpc import ( + AuthenticationMethodOptionsClientAssertionClientAssertionrpc, +) +from .authenticationmethodoptionsmanualsecret import ( + AuthenticationMethodOptionsManualSecret, +) +from .authenticationmethodoptionss3collectorconf import ( + AuthenticationMethodOptionsS3CollectorConf, +) +from .authenticationmethodoptionssasl import AuthenticationMethodOptionsSasl +from .authenticationtype import AuthenticationType, AuthenticationTypeTypedDict +from .authenticationtypeoptionslokiauth import AuthenticationTypeOptionsLokiAuth +from .authenticationtypeoptionsprometheusauth import ( + AuthenticationTypeOptionsPrometheusAuth, +) +from .authenticationtypeuse import AuthenticationTypeUse, AuthenticationTypeUseTypedDict +from .authtokenconfinputcribltcp import ( + AuthTokenConfInputCriblTCP, + AuthTokenConfInputCriblTCPTypedDict, +) +from .certificatetype import CertificateType, CertificateTypeTypedDict +from .certoptionstype import CertOptionsType, CertOptionsTypeTypedDict +from .checkpointingtype import CheckpointingType, CheckpointingTypeTypedDict +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .datacompressionformatoptionspersistence import ( + DataCompressionFormatOptionsPersistence, +) +from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict +from .googleauthenticationmethodoptions import GoogleAuthenticationMethodOptions +from .gputype import GpuType, GpuTypeTypedDict +from .inputprovenancetypeoptional import ( + InputProvenanceTypeOptional, + InputProvenanceTypeOptionalTypedDict, +) +from .inputresponse_v3user import InputResponseV3User, InputResponseV3UserTypedDict +from .kafkaschemaregistryauthenticationtype import ( + KafkaSchemaRegistryAuthenticationType, + KafkaSchemaRegistryAuthenticationTypeTypedDict, +) +from .logleveloptions import LogLevelOptions +from .logleveloptionscontentconfigitems import LogLevelOptionsContentConfigItems +from .logleveloptionsdebugerror import LogLevelOptionsDebugError +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .microsoftentraidauthenticationendpointoptionssasl import ( + MicrosoftEntraIDAuthenticationEndpointOptionsSasl, +) +from .modeoptionshost import ModeOptionsHost +from .notification import Notification, NotificationTypedDict +from .pqtype import PqType, PqTypeTypedDict +from .preprocesstype import PreprocessType, PreprocessTypeTypedDict +from .processtype import ProcessType, ProcessTypeTypedDict +from .protocoloptionstargetsitems import ProtocolOptionsTargetsItems +from .recordtypeoptions import RecordTypeOptions +from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( + RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, +) +from .retryrulestypecodesenableheader import ( + RetryRulesTypeCodesEnableHeader, + RetryRulesTypeCodesEnableHeaderTypedDict, +) +from .ruleconfinputkubemetrics import ( + RuleConfInputKubeMetrics, + RuleConfInputKubeMetricsTypedDict, +) +from .searchfilterconfinputprometheus import ( + SearchFilterConfInputPrometheus, + SearchFilterConfInputPrometheusTypedDict, +) +from .sqsauthenticationmethodoptions import SqsAuthenticationMethodOptions +from .statustype import StatusType, StatusTypeTypedDict +from .subscriptionplanoptions import SubscriptionPlanOptions +from .tagafterprocessingoptions import TagAfterProcessingOptions +from .tlssettingsclientsidetype import ( + TLSSettingsClientSideType, + TLSSettingsClientSideTypeTypedDict, +) +from .tlssettingsclientsidetypecapathcertpath import ( + TLSSettingsClientSideTypeCaPathCertPath, + TLSSettingsClientSideTypeCaPathCertPathTypedDict, +) +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from .typeoptionsconfluentcloud import TypeOptionsConfluentcloud +from .typeoptionscribltcp import TypeOptionsCribltcp +from .typeoptionsgooglepubsub import TypeOptionsGooglepubsub +from .typeoptionskinesis import TypeOptionsKinesis +from .typeoptionsprometheus import TypeOptionsPrometheus +from .typeoptionss3 import TypeOptionsS3 +from .typeoptionssnmp import TypeOptionsSnmp +from .typeoptionstcpjson import TypeOptionsTcpjson +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from cribl_control_plane.utils import validate_const +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from pydantic.functional_validators import AfterValidator +from typing import List, Literal, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class InputResponseSNMPv3AuthenticationTypedDict(TypedDict): + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + v3_auth_enabled: bool + r"""Enabled""" + allow_unmatched_trap: NotRequired[bool] + r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" + v3_users: NotRequired[List[InputResponseV3UserTypedDict]] + r"""User credentials for receiving v3 traps""" + + +class InputResponseSNMPv3Authentication(BaseModel): + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + v3_auth_enabled: Annotated[bool, pydantic.Field(alias="v3AuthEnabled")] + r"""Enabled""" + + allow_unmatched_trap: Annotated[ + Optional[bool], pydantic.Field(alias="allowUnmatchedTrap") + ] = None + r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" + + v3_users: Annotated[ + Optional[List[InputResponseV3User]], pydantic.Field(alias="v3Users") + ] = None + r"""User credentials for receiving v3 traps""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["allowUnmatchedTrap", "v3Users"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSnmpTypedDict(TypedDict): + type: TypeOptionsSnmp + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""UDP port to receive SNMP traps on. Defaults to 162.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + snmp_v3_auth: NotRequired[InputResponseSNMPv3AuthenticationTypedDict] + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + varbinds_with_types: NotRequired[bool] + r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + best_effort_parsing: NotRequired[bool] + r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputSnmp(BaseModel): + type: TypeOptionsSnmp + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + + port: float + r"""UDP port to receive SNMP traps on. Defaults to 162.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + snmp_v3_auth: Annotated[ + Optional[InputResponseSNMPv3Authentication], pydantic.Field(alias="snmpV3Auth") + ] = None + r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking.""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + varbinds_with_types: Annotated[ + Optional[bool], pydantic.Field(alias="varbindsWithTypes") + ] = None + r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + + best_effort_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="bestEffortParsing") + ] = None + r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "snmpV3Auth", + "maxBufferSize", + "ipWhitelistRegex", + "metadata", + "udpSocketRxBufSize", + "varbindsWithTypes", + "bestEffortParsing", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputS3InventoryType(str, Enum): + r"""Connector type identifier.""" + + S3_INVENTORY = "s3_inventory" + + +class InputResponseInputS3InventoryTypedDict(TypedDict): + type: InputResponseInputS3InventoryType + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + checksum_suffix: NotRequired[str] + r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ + max_manifest_size_kb: NotRequired[int] + r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" + validate_inventory_files: NotRequired[bool] + r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputS3Inventory(BaseModel): + type: InputResponseInputS3InventoryType + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + checksum_suffix: Annotated[ + Optional[str], pydantic.Field(alias="checksumSuffix") + ] = None + r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ + + max_manifest_size_kb: Annotated[ + Optional[int], pydantic.Field(alias="maxManifestSizeKB") + ] = None + r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" + + validate_inventory_files: Annotated[ + Optional[bool], pydantic.Field(alias="validateInventoryFiles") + ] = None + r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "checksumSuffix", + "maxManifestSizeKB", + "validateInventoryFiles", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputS3TypedDict(TypedDict): + type: TypeOptionsS3 + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + tag_after_processing: NotRequired[bool] + r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputS3(BaseModel): + type: TypeOptionsS3 + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + + tag_after_processing: Annotated[ + Optional[bool], pydantic.Field(alias="tagAfterProcessing") + ] = None + r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "encoding", + "tagAfterProcessing", + "autoParse", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputMetricsType(str, Enum): + r"""Connector type identifier.""" + + METRICS = "metrics" + + +class InputResponseInputMetricsTypedDict(TypedDict): + type: InputResponseInputMetricsType + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + udp_port: NotRequired[float] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + tcp_port: NotRequired[float] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputMetrics(BaseModel): + type: InputResponseInputMetricsType + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + + tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "udpPort", + "tcpPort", + "maxBufferSize", + "ipWhitelistRegex", + "enableProxyHeader", + "tls", + "metadata", + "udpSocketRxBufSize", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCriblmetricsType(str, Enum): + r"""Connector type identifier.""" + + CRIBLMETRICS = "criblmetrics" + + +class InputResponseInputCriblmetricsTypedDict(TypedDict): + type: InputResponseInputCriblmetricsType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + prefix: NotRequired[str] + r"""A prefix that is applied to the metrics provided by Cribl Stream""" + full_fidelity: NotRequired[bool] + r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputCriblmetrics(BaseModel): + type: InputResponseInputCriblmetricsType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + prefix: Optional[str] = None + r"""A prefix that is applied to the metrics provided by Cribl Stream""" + + full_fidelity: Annotated[Optional[bool], pydantic.Field(alias="fullFidelity")] = ( + None + ) + r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "prefix", + "fullFidelity", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseShardIteratorStart(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Location at which to start reading a shard for the first time""" + + # Earliest record + TRIM_HORIZON = "TRIM_HORIZON" + # Latest record + LATEST = "LATEST" + + +class InputResponseRecordDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + + # Cribl + CRIBL = "cribl" + # Newline JSON + NDJSON = "ndjson" + # Cloudwatch Logs + CLOUDWATCH = "cloudwatch" + # Event per line + LINE = "line" + + +class InputResponseShardLoadBalancing(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + + # Consistent Hashing + CONSISTENT_HASHING = "ConsistentHashing" + # Round Robin + ROUND_ROBIN = "RoundRobin" + + +class InputResponseInputKinesisTypedDict(TypedDict): + type: TypeOptionsKinesis + r"""Connector type identifier.""" + stream_name: str + r"""Kinesis Data Stream to read data from""" + region: str + r"""Region where the Kinesis stream is located""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + service_interval: NotRequired[float] + r"""Time interval in minutes between consecutive service calls""" + shard_expr: NotRequired[str] + r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + shard_iterator_type: NotRequired[InputResponseShardIteratorStart] + r"""Location at which to start reading a shard for the first time""" + payload_format: NotRequired[InputResponseRecordDataFormat] + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + get_records_limit: NotRequired[float] + r"""Maximum number of records per getRecords call""" + get_records_limit_total: NotRequired[float] + r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + load_balancing_algorithm: NotRequired[InputResponseShardLoadBalancing] + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Kinesis stream""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + verify_kpl_check_sums: NotRequired[bool] + r"""Verify Kinesis Producer Library (KPL) event checksums""" + avoid_duplicates: NotRequired[bool] + r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + template_shard_iterator_type: NotRequired[str] + r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + template_payload_format: NotRequired[str] + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputKinesis(BaseModel): + type: TypeOptionsKinesis + r"""Connector type identifier.""" + + stream_name: Annotated[str, pydantic.Field(alias="streamName")] + r"""Kinesis Data Stream to read data from""" + + region: str + r"""Region where the Kinesis stream is located""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + service_interval: Annotated[ + Optional[float], pydantic.Field(alias="serviceInterval") + ] = None + r"""Time interval in minutes between consecutive service calls""" + + shard_expr: Annotated[Optional[str], pydantic.Field(alias="shardExpr")] = None + r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + + shard_iterator_type: Annotated[ + Optional[InputResponseShardIteratorStart], + pydantic.Field(alias="shardIteratorType"), + ] = None + r"""Location at which to start reading a shard for the first time""" + + payload_format: Annotated[ + Optional[InputResponseRecordDataFormat], pydantic.Field(alias="payloadFormat") + ] = None + r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + + get_records_limit: Annotated[ + Optional[float], pydantic.Field(alias="getRecordsLimit") + ] = None + r"""Maximum number of records per getRecords call""" + + get_records_limit_total: Annotated[ + Optional[float], pydantic.Field(alias="getRecordsLimitTotal") + ] = None + r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + + load_balancing_algorithm: Annotated[ + Optional[InputResponseShardLoadBalancing], + pydantic.Field(alias="loadBalancingAlgorithm"), + ] = None + r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + endpoint: Optional[str] = None + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Kinesis stream""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + verify_kpl_check_sums: Annotated[ + Optional[bool], pydantic.Field(alias="verifyKPLCheckSums") + ] = None + r"""Verify Kinesis Producer Library (KPL) event checksums""" + + avoid_duplicates: Annotated[ + Optional[bool], pydantic.Field(alias="avoidDuplicates") + ] = None + r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") + ] = None + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + + template_shard_iterator_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_shardIteratorType") + ] = None + r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + + template_payload_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadFormat") + ] = None + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("shard_iterator_type") + def serialize_shard_iterator_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseShardIteratorStart(value) + except ValueError: + return value + return value + + @field_serializer("payload_format") + def serialize_payload_format(self, value): + if isinstance(value, str): + try: + return models.InputResponseRecordDataFormat(value) + except ValueError: + return value + return value + + @field_serializer("load_balancing_algorithm") + def serialize_load_balancing_algorithm(self, value): + if isinstance(value, str): + try: + return models.InputResponseShardLoadBalancing(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "serviceInterval", + "shardExpr", + "shardIteratorType", + "payloadFormat", + "getRecordsLimit", + "getRecordsLimitTotal", + "loadBalancingAlgorithm", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "verifyKPLCheckSums", + "avoidDuplicates", + "metadata", + "autoParse", + "description", + "awsApiKey", + "awsSecret", + "__template_environment", + "__template_streamtags", + "__template_streamName", + "__template_shardIteratorType", + "__template_payloadFormat", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputHTTPRawType(str, Enum): + r"""Source type identifier.""" + + HTTP_RAW = "http_raw" + + +class InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["tokenSecret", "token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputHTTPRawAuthTokensExtTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputResponseInputHTTPRawAuthTokensExt(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +InputResponseInputHTTPRawAuthTokensExtUnionTypedDict = TypeAliasType( + "InputResponseInputHTTPRawAuthTokensExtUnionTypedDict", + Union[ + InputResponseInputHTTPRawAuthTokensExtTypedDict, + InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +InputResponseInputHTTPRawAuthTokensExtUnion = TypeAliasType( + "InputResponseInputHTTPRawAuthTokensExtUnion", + Union[ + InputResponseInputHTTPRawAuthTokensExt, + InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint, + ], +) + + +class InputResponseInputHTTPRawTypedDict(TypedDict): + type: InputResponseInputHTTPRawType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + allowed_paths: NotRequired[List[str]] + r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" + allowed_methods: NotRequired[List[str]] + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + auth_tokens_ext: NotRequired[ + List[InputResponseInputHTTPRawAuthTokensExtUnionTypedDict] + ] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + access_control_allow_methods: NotRequired[List[str]] + r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + access_control_expose_headers: NotRequired[List[str]] + r"""Headers the browser is allowed to access from the response""" + access_control_allow_credentials: NotRequired[bool] + r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + access_control_max_age: NotRequired[float] + r"""How long browsers should cache the preflight response""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_allowed_paths: NotRequired[str] + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputHTTPRaw(BaseModel): + type: InputResponseInputHTTPRawType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + allowed_paths: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedPaths") + ] = None + r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" + + allowed_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedMethods") + ] = None + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + + auth_tokens_ext: Annotated[ + Optional[List[InputResponseInputHTTPRawAuthTokensExtUnion]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + + access_control_allow_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowMethods") + ] = None + r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + + access_control_expose_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlExposeHeaders") + ] = None + r"""Headers the browser is allowed to access from the response""" + + access_control_allow_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="accessControlAllowCredentials") + ] = None + r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + + access_control_max_age: Annotated[ + Optional[float], pydantic.Field(alias="accessControlMaxAge") + ] = None + r"""How long browsers should cache the preflight response""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + template_allowed_paths: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedPaths") + ] = None + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "metadata", + "allowedPaths", + "allowedMethods", + "authTokensExt", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "accessControlAllowMethods", + "accessControlExposeHeaders", + "accessControlAllowCredentials", + "accessControlMaxAge", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + "__template_allowedPaths", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputDatagenType(str, Enum): + r"""Connector type identifier.""" + + DATAGEN = "datagen" + + +class InputResponseSampleTypedDict(TypedDict): + sample: str + r"""Data Generator File Name""" + events_per_sec: float + r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" + + +class InputResponseSample(BaseModel): + sample: str + r"""Data Generator File Name""" + + events_per_sec: Annotated[float, pydantic.Field(alias="eventsPerSec")] + r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" + + +class InputResponseInputDatagenTypedDict(TypedDict): + type: InputResponseInputDatagenType + r"""Connector type identifier.""" + samples: List[InputResponseSampleTypedDict] + r"""Datagens""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputDatagen(BaseModel): + type: InputResponseInputDatagenType + r"""Connector type identifier.""" + + samples: List[InputResponseSample] + r"""Datagens""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputDatadogAgentType(str, Enum): + r"""Source type identifier.""" + + DATADOG_AGENT = "datadog_agent" + + +class InputResponseSamplingRuleTypedDict(TypedDict): + service: str + r"""Datadog service name""" + environment: str + r"""Datadog environment name (example: prod, staging)""" + rate: float + r"""Sampling rate for this service/environment combination (0.0–1.0)""" + + +class InputResponseSamplingRule(BaseModel): + service: str + r"""Datadog service name""" + + environment: str + r"""Datadog environment name (example: prod, staging)""" + + rate: float + r"""Sampling rate for this service/environment combination (0.0–1.0)""" + + +class InputResponseInputDatadogAgentProxyModeTypedDict(TypedDict): + enabled: bool + r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" + reject_unauthorized: NotRequired[bool] + r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + + +class InputResponseInputDatadogAgentProxyMode(BaseModel): + enabled: bool + r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["rejectUnauthorized"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputDatadogAgentTypedDict(TypedDict): + type: InputResponseInputDatadogAgentType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + extract_metrics: NotRequired[bool] + r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + sampling_rate: NotRequired[float] + r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + sampling_rules: NotRequired[List[InputResponseSamplingRuleTypedDict]] + r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + proxy_mode: NotRequired[InputResponseInputDatadogAgentProxyModeTypedDict] + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputDatadogAgent(BaseModel): + type: InputResponseInputDatadogAgentType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + extract_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="extractMetrics") + ] = None + r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + + sampling_rate: Annotated[Optional[float], pydantic.Field(alias="samplingRate")] = ( + None + ) + r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + + sampling_rules: Annotated[ + Optional[List[InputResponseSamplingRule]], pydantic.Field(alias="samplingRules") + ] = None + r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + proxy_mode: Annotated[ + Optional[InputResponseInputDatadogAgentProxyMode], + pydantic.Field(alias="proxyMode"), + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "extractMetrics", + "samplingRate", + "samplingRules", + "metadata", + "proxyMode", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCrowdstrikeType(str, Enum): + r"""Connector type identifier.""" + + CROWDSTRIKE = "crowdstrike" + + +class InputResponseInputCrowdstrikeTypedDict(TypedDict): + type: InputResponseInputCrowdstrikeType + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputCrowdstrike(BaseModel): + type: InputResponseInputCrowdstrikeType + r"""Connector type identifier.""" + + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + None + ) + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", + "metadata", + "checkpointing", + "pollTimeout", + "encoding", + "description", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", + "__template_environment", + "__template_streamtags", + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsType(str, Enum): + r"""Connector type identifier.""" + + WINDOWS_METRICS = "windows_metrics" + + +class InputResponseInputWindowsMetricsSystemMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for system metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputWindowsMetricsSystemTypedDict(TypedDict): + mode: NotRequired[InputResponseInputWindowsMetricsSystemMode] + r"""Select the level of details for system metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all system information""" + + +class InputResponseInputWindowsMetricsSystem(BaseModel): + mode: Optional[InputResponseInputWindowsMetricsSystemMode] = None + r"""Select the level of details for system metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all system information""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputWindowsMetricsSystemMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of details for CPU metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputWindowsMetricsCPUTypedDict(TypedDict): + mode: NotRequired[InputResponseInputWindowsMetricsCPUMode] + r"""Select the level of details for CPU metrics""" + per_cpu: NotRequired[bool] + r"""Generate metrics for each CPU""" + detail: NotRequired[bool] + r"""Generate metrics for all CPU states""" + time: NotRequired[bool] + r"""Generate raw, monotonic CPU time counters""" + + +class InputResponseInputWindowsMetricsCPU(BaseModel): + mode: Optional[InputResponseInputWindowsMetricsCPUMode] = None + r"""Select the level of details for CPU metrics""" + + per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None + r"""Generate metrics for each CPU""" + + detail: Optional[bool] = None + r"""Generate metrics for all CPU states""" + + time: Optional[bool] = None + r"""Generate raw, monotonic CPU time counters""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputWindowsMetricsCPUMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perCpu", "detail", "time"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsMemoryMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for memory metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputWindowsMetricsMemoryTypedDict(TypedDict): + mode: NotRequired[InputResponseInputWindowsMetricsMemoryMode] + r"""Select the level of details for memory metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all memory states""" + + +class InputResponseInputWindowsMetricsMemory(BaseModel): + mode: Optional[InputResponseInputWindowsMetricsMemoryMode] = None + r"""Select the level of details for memory metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all memory states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputWindowsMetricsMemoryMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsNetworkMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of details for network metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputWindowsMetricsNetworkTypedDict(TypedDict): + mode: NotRequired[InputResponseInputWindowsMetricsNetworkMode] + r"""Select the level of details for network metrics""" + detail: NotRequired[bool] + r"""Generate full network metrics""" + protocols: NotRequired[bool] + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + devices: NotRequired[List[str]] + r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + per_interface: NotRequired[bool] + r"""Generate separate metrics for each interface""" + + +class InputResponseInputWindowsMetricsNetwork(BaseModel): + mode: Optional[InputResponseInputWindowsMetricsNetworkMode] = None + r"""Select the level of details for network metrics""" + + detail: Optional[bool] = None + r"""Generate full network metrics""" + + protocols: Optional[bool] = None + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + + devices: Optional[List[str]] = None + r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + + per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + None + ) + r"""Generate separate metrics for each interface""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputWindowsMetricsNetworkMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["mode", "detail", "protocols", "devices", "perInterface"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of details for disk metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputWindowsMetricsDiskTypedDict(TypedDict): + mode: NotRequired[InputResponseInputWindowsMetricsDiskMode] + r"""Select the level of details for disk metrics""" + per_volume: NotRequired[bool] + r"""Generate separate metrics for each volume""" + detail: NotRequired[bool] + r"""Generate full disk metrics""" + volumes: NotRequired[List[str]] + r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" + + +class InputResponseInputWindowsMetricsDisk(BaseModel): + mode: Optional[InputResponseInputWindowsMetricsDiskMode] = None + r"""Select the level of details for disk metrics""" + + per_volume: Annotated[Optional[bool], pydantic.Field(alias="perVolume")] = None + r"""Generate separate metrics for each volume""" + + detail: Optional[bool] = None + r"""Generate full disk metrics""" + + volumes: Optional[List[str]] = None + r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputWindowsMetricsDiskMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perVolume", "detail", "volumes"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsCustomTypedDict(TypedDict): + system: NotRequired[InputResponseInputWindowsMetricsSystemTypedDict] + cpu: NotRequired[InputResponseInputWindowsMetricsCPUTypedDict] + memory: NotRequired[InputResponseInputWindowsMetricsMemoryTypedDict] + network: NotRequired[InputResponseInputWindowsMetricsNetworkTypedDict] + disk: NotRequired[InputResponseInputWindowsMetricsDiskTypedDict] + + +class InputResponseInputWindowsMetricsCustom(BaseModel): + system: Optional[InputResponseInputWindowsMetricsSystem] = None + + cpu: Optional[InputResponseInputWindowsMetricsCPU] = None + + memory: Optional[InputResponseInputWindowsMetricsMemory] = None + + network: Optional[InputResponseInputWindowsMetricsNetwork] = None + + disk: Optional[InputResponseInputWindowsMetricsDisk] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["system", "cpu", "memory", "network", "disk"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsHostTypedDict(TypedDict): + mode: NotRequired[ModeOptionsHost] + r"""Select level of detail for host metrics""" + custom: NotRequired[InputResponseInputWindowsMetricsCustomTypedDict] + + +class InputResponseInputWindowsMetricsHost(BaseModel): + mode: Optional[ModeOptionsHost] = None + r"""Select level of detail for host metrics""" + + custom: Optional[InputResponseInputWindowsMetricsCustom] = None + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptionsHost(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "custom"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + + +class InputResponseInputWindowsMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWindowsMetricsTypedDict(TypedDict): + type: InputResponseInputWindowsMetricsType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + host: NotRequired[InputResponseInputWindowsMetricsHostTypedDict] + process: NotRequired[ProcessTypeTypedDict] + gpu: NotRequired[GpuTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[InputResponseInputWindowsMetricsPersistenceTypedDict] + r"""persistence""" + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputWindowsMetrics(BaseModel): + type: InputResponseInputWindowsMetricsType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + + host: Optional[InputResponseInputWindowsMetricsHost] = None + + process: Optional[ProcessType] = None + + gpu: Optional[GpuType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[InputResponseInputWindowsMetricsPersistence] = None + r"""persistence""" + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "interval", + "host", + "process", + "gpu", + "metadata", + "persistence", + "disableNativeModule", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputKubeEventsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_EVENTS = "kube_events" + + +class InputResponseInputKubeEventsTypedDict(TypedDict): + type: InputResponseInputKubeEventsType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] + r"""Filtering on event fields""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputKubeEvents(BaseModel): + type: InputResponseInputKubeEventsType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + rules: Optional[List[RuleConfInputKubeMetrics]] = None + r"""Filtering on event fields""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "rules", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputKubeLogsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_LOGS = "kube_logs" + + +class InputResponseInputKubeLogsRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class InputResponseInputKubeLogsRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputKubeLogsTypedDict(TypedDict): + type: InputResponseInputKubeLogsType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + rules: NotRequired[List[InputResponseInputKubeLogsRuleTypedDict]] + r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + timestamps: NotRequired[bool] + r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + line_buffer_limit: NotRequired[float] + r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + lb_disable_assembly: NotRequired[bool] + r"""Internal flag to disable LB worker payload reassembly.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[DiskSpoolingTypeTypedDict] + r"""Disk Spooling""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputKubeLogs(BaseModel): + type: InputResponseInputKubeLogsType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + + rules: Optional[List[InputResponseInputKubeLogsRule]] = None + r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + + timestamps: Optional[bool] = None + r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + + line_buffer_limit: Annotated[ + Optional[float], pydantic.Field(alias="lineBufferLimit") + ] = None + r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + + lb_disable_assembly: Annotated[ + Optional[bool], pydantic.Field(alias="__LBDisableAssembly") + ] = None + r"""Internal flag to disable LB worker payload reassembly.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[DiskSpoolingType] = None + r"""Disk Spooling""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "interval", + "rules", + "timestamps", + "lineBufferLimit", + "__LBDisableAssembly", + "metadata", + "persistence", + "breakerRulesets", + "staleChannelFlushMs", + "enableLoadBalancing", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputKubeMetricsType(str, Enum): + r"""Connector type identifier.""" + + KUBE_METRICS = "kube_metrics" + + +class InputResponseInputKubeMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics on disk for Cribl Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + + +class InputResponseInputKubeMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics on disk for Cribl Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputKubeMetricsTypedDict(TypedDict): + type: InputResponseInputKubeMetricsType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + scrape_kubelet: NotRequired[bool] + r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + scrape_cadvisor: NotRequired[bool] + r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] + r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[InputResponseInputKubeMetricsPersistenceTypedDict] + r"""persistence""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputKubeMetrics(BaseModel): + type: InputResponseInputKubeMetricsType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" + + scrape_kubelet: Annotated[Optional[bool], pydantic.Field(alias="scrapeKubelet")] = ( + None + ) + r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" + + scrape_cadvisor: Annotated[ + Optional[bool], pydantic.Field(alias="scrapeCadvisor") + ] = None + r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" + + rules: Optional[List[RuleConfInputKubeMetrics]] = None + r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[InputResponseInputKubeMetricsPersistence] = None + r"""persistence""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "interval", + "scrapeKubelet", + "scrapeCadvisor", + "rules", + "metadata", + "persistence", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemStateType(str, Enum): + r"""Connector type identifier.""" + + SYSTEM_STATE = "system_state" + + +class InputResponseHostsFileTypedDict(TypedDict): + r"""Creates events based on entries collected from the hosts file""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseHostsFile(BaseModel): + r"""Creates events based on entries collected from the hosts file""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInterfacesTypedDict(TypedDict): + r"""Creates events for each of the host’s network interfaces""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseInterfaces(BaseModel): + r"""Creates events for each of the host’s network interfaces""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseDisksAndFileSystemsTypedDict(TypedDict): + r"""Creates events for physical disks, partitions, and file systems""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseDisksAndFileSystems(BaseModel): + r"""Creates events for physical disks, partitions, and file systems""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseHostInfoTypedDict(TypedDict): + r"""Creates events based on the host system’s current state""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseHostInfo(BaseModel): + r"""Creates events based on the host system’s current state""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseRoutesTypedDict(TypedDict): + r"""Creates events based on entries collected from the host’s network routes""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseRoutes(BaseModel): + r"""Creates events based on entries collected from the host’s network routes""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseDNSTypedDict(TypedDict): + r"""Creates events for DNS resolvers and search entries""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseDNS(BaseModel): + r"""Creates events for DNS resolvers and search entries""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseUsersAndGroupsTypedDict(TypedDict): + r"""Creates events for local users and groups""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseUsersAndGroups(BaseModel): + r"""Creates events for local users and groups""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseFirewallTypedDict(TypedDict): + r"""Creates events for Firewall rules entries""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseFirewall(BaseModel): + r"""Creates events for Firewall rules entries""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseServicesTypedDict(TypedDict): + r"""Creates events from the list of services""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseServices(BaseModel): + r"""Creates events from the list of services""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseListeningPortsTypedDict(TypedDict): + r"""Creates events from list of listening ports""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseListeningPorts(BaseModel): + r"""Creates events from list of listening ports""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseLoggedInUsersTypedDict(TypedDict): + r"""Creates events from list of logged-in users""" + + enable: NotRequired[bool] + r"""Enabled""" + + +class InputResponseLoggedInUsers(BaseModel): + r"""Creates events from list of logged-in users""" + + enable: Optional[bool] = None + r"""Enabled""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enable"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseCollectorsTypedDict(TypedDict): + hostsfile: NotRequired[InputResponseHostsFileTypedDict] + r"""Creates events based on entries collected from the hosts file""" + interfaces: NotRequired[InputResponseInterfacesTypedDict] + r"""Creates events for each of the host’s network interfaces""" + disk: NotRequired[InputResponseDisksAndFileSystemsTypedDict] + r"""Creates events for physical disks, partitions, and file systems""" + metadata: NotRequired[InputResponseHostInfoTypedDict] + r"""Creates events based on the host system’s current state""" + routes: NotRequired[InputResponseRoutesTypedDict] + r"""Creates events based on entries collected from the host’s network routes""" + dns: NotRequired[InputResponseDNSTypedDict] + r"""Creates events for DNS resolvers and search entries""" + user: NotRequired[InputResponseUsersAndGroupsTypedDict] + r"""Creates events for local users and groups""" + firewall: NotRequired[InputResponseFirewallTypedDict] + r"""Creates events for Firewall rules entries""" + services: NotRequired[InputResponseServicesTypedDict] + r"""Creates events from the list of services""" + ports: NotRequired[InputResponseListeningPortsTypedDict] + r"""Creates events from list of listening ports""" + login_users: NotRequired[InputResponseLoggedInUsersTypedDict] + r"""Creates events from list of logged-in users""" + + +class InputResponseCollectors(BaseModel): + hostsfile: Optional[InputResponseHostsFile] = None + r"""Creates events based on entries collected from the hosts file""" + + interfaces: Optional[InputResponseInterfaces] = None + r"""Creates events for each of the host’s network interfaces""" + + disk: Optional[InputResponseDisksAndFileSystems] = None + r"""Creates events for physical disks, partitions, and file systems""" + + metadata: Optional[InputResponseHostInfo] = None + r"""Creates events based on the host system’s current state""" + + routes: Optional[InputResponseRoutes] = None + r"""Creates events based on entries collected from the host’s network routes""" + + dns: Optional[InputResponseDNS] = None + r"""Creates events for DNS resolvers and search entries""" + + user: Optional[InputResponseUsersAndGroups] = None + r"""Creates events for local users and groups""" + + firewall: Optional[InputResponseFirewall] = None + r"""Creates events for Firewall rules entries""" + + services: Optional[InputResponseServices] = None + r"""Creates events from the list of services""" + + ports: Optional[InputResponseListeningPorts] = None + r"""Creates events from list of listening ports""" + + login_users: Annotated[ + Optional[InputResponseLoggedInUsers], pydantic.Field(alias="loginUsers") + ] = None + r"""Creates events from list of logged-in users""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "hostsfile", + "interfaces", + "disk", + "metadata", + "routes", + "dns", + "user", + "firewall", + "services", + "ports", + "loginUsers", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemStatePersistenceTypedDict(TypedDict): + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" + + +class InputResponseInputSystemStatePersistence(BaseModel): + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_state""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemStateTypedDict(TypedDict): + type: InputResponseInputSystemStateType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + collectors: NotRequired[InputResponseCollectorsTypedDict] + persistence: NotRequired[InputResponseInputSystemStatePersistenceTypedDict] + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + disable_native_last_log_module: NotRequired[bool] + r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputSystemState(BaseModel): + type: InputResponseInputSystemStateType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive state collections. Default is 300 seconds (5 minutes).""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + collectors: Optional[InputResponseCollectors] = None + + persistence: Optional[InputResponseInputSystemStatePersistence] = None + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell) to collect events instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + + disable_native_last_log_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeLastLogModule") + ] = None + r"""Enable only to collect LastLog data via legacy implementation. This option will be removed in a future release. Please contact Support before enabling. [Learn more](https://docs.cribl.io/edge/sources-system-state/#advanced-tab)""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "interval", + "metadata", + "collectors", + "persistence", + "disableNativeModule", + "disableNativeLastLogModule", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsType(str, Enum): + r"""Connector type identifier.""" + + SYSTEM_METRICS = "system_metrics" + + +class InputResponseInputSystemMetricsSystemMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for system metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputSystemMetricsSystemTypedDict(TypedDict): + mode: NotRequired[InputResponseInputSystemMetricsSystemMode] + r"""Select the level of detail for system metrics""" + processes: NotRequired[bool] + r"""Generate metrics for the numbers of processes in various states""" + + +class InputResponseInputSystemMetricsSystem(BaseModel): + mode: Optional[InputResponseInputSystemMetricsSystemMode] = None + r"""Select the level of detail for system metrics""" + + processes: Optional[bool] = None + r"""Generate metrics for the numbers of processes in various states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputSystemMetricsSystemMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "processes"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for CPU metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputSystemMetricsCPUTypedDict(TypedDict): + mode: NotRequired[InputResponseInputSystemMetricsCPUMode] + r"""Select the level of detail for CPU metrics""" + per_cpu: NotRequired[bool] + r"""Generate metrics for each CPU""" + detail: NotRequired[bool] + r"""Generate metrics for all CPU states""" + time: NotRequired[bool] + r"""Generate raw, monotonic CPU time counters""" + + +class InputResponseInputSystemMetricsCPU(BaseModel): + mode: Optional[InputResponseInputSystemMetricsCPUMode] = None + r"""Select the level of detail for CPU metrics""" + + per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None + r"""Generate metrics for each CPU""" + + detail: Optional[bool] = None + r"""Generate metrics for all CPU states""" + + time: Optional[bool] = None + r"""Generate raw, monotonic CPU time counters""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputSystemMetricsCPUMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "perCpu", "detail", "time"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsMemoryMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for memory metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputSystemMetricsMemoryTypedDict(TypedDict): + mode: NotRequired[InputResponseInputSystemMetricsMemoryMode] + r"""Select the level of detail for memory metrics""" + detail: NotRequired[bool] + r"""Generate metrics for all memory states""" + + +class InputResponseInputSystemMetricsMemory(BaseModel): + mode: Optional[InputResponseInputSystemMetricsMemoryMode] = None + r"""Select the level of detail for memory metrics""" + + detail: Optional[bool] = None + r"""Generate metrics for all memory states""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputSystemMetricsMemoryMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "detail"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsNetworkMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select the level of detail for network metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputSystemMetricsNetworkTypedDict(TypedDict): + mode: NotRequired[InputResponseInputSystemMetricsNetworkMode] + r"""Select the level of detail for network metrics""" + detail: NotRequired[bool] + r"""Generate full network metrics""" + protocols: NotRequired[bool] + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + devices: NotRequired[List[str]] + r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" + per_interface: NotRequired[bool] + r"""Generate separate metrics for each interface""" + + +class InputResponseInputSystemMetricsNetwork(BaseModel): + mode: Optional[InputResponseInputSystemMetricsNetworkMode] = None + r"""Select the level of detail for network metrics""" + + detail: Optional[bool] = None + r"""Generate full network metrics""" + + protocols: Optional[bool] = None + r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + + devices: Optional[List[str]] = None + r"""Network interfaces to include/exclude. Examples: eth0, !lo. All interfaces are included if this list is empty.""" + + per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( + None + ) + r"""Generate separate metrics for each interface""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputSystemMetricsNetworkMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["mode", "detail", "protocols", "devices", "perInterface"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for disk metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputSystemMetricsDiskTypedDict(TypedDict): + mode: NotRequired[InputResponseInputSystemMetricsDiskMode] + r"""Select the level of detail for disk metrics""" + detail: NotRequired[bool] + r"""Generate full disk metrics""" + inodes: NotRequired[bool] + r"""Generate filesystem inode metrics""" + devices: NotRequired[List[str]] + r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" + mountpoints: NotRequired[List[str]] + r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" + fstypes: NotRequired[List[str]] + r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" + per_device: NotRequired[bool] + r"""Generate separate metrics for each device""" + + +class InputResponseInputSystemMetricsDisk(BaseModel): + mode: Optional[InputResponseInputSystemMetricsDiskMode] = None + r"""Select the level of detail for disk metrics""" + + detail: Optional[bool] = None + r"""Generate full disk metrics""" + + inodes: Optional[bool] = None + r"""Generate filesystem inode metrics""" + + devices: Optional[List[str]] = None + r"""Block devices to include/exclude. Examples: sda*, !loop*. Wildcards and ! (not) operators are supported. All devices are included if this list is empty.""" + + mountpoints: Optional[List[str]] = None + r"""Filesystem mountpoints to include/exclude. Examples: /, /home, !/proc*, !/tmp. Wildcards and ! (not) operators are supported. All mountpoints are included if this list is empty.""" + + fstypes: Optional[List[str]] = None + r"""Filesystem types to include/exclude. Examples: ext4, !*tmpfs, !squashfs. Wildcards and ! (not) operators are supported. All types are included if this list is empty.""" + + per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None + r"""Generate separate metrics for each device""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputSystemMetricsDiskMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "mode", + "detail", + "inodes", + "devices", + "mountpoints", + "fstypes", + "perDevice", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsCustomTypedDict(TypedDict): + system: NotRequired[InputResponseInputSystemMetricsSystemTypedDict] + cpu: NotRequired[InputResponseInputSystemMetricsCPUTypedDict] + memory: NotRequired[InputResponseInputSystemMetricsMemoryTypedDict] + network: NotRequired[InputResponseInputSystemMetricsNetworkTypedDict] + disk: NotRequired[InputResponseInputSystemMetricsDiskTypedDict] + + +class InputResponseInputSystemMetricsCustom(BaseModel): + system: Optional[InputResponseInputSystemMetricsSystem] = None + + cpu: Optional[InputResponseInputSystemMetricsCPU] = None + + memory: Optional[InputResponseInputSystemMetricsMemory] = None + + network: Optional[InputResponseInputSystemMetricsNetwork] = None + + disk: Optional[InputResponseInputSystemMetricsDisk] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["system", "cpu", "memory", "network", "disk"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsHostTypedDict(TypedDict): + mode: NotRequired[ModeOptionsHost] + r"""Select level of detail for host metrics""" + custom: NotRequired[InputResponseInputSystemMetricsCustomTypedDict] + + +class InputResponseInputSystemMetricsHost(BaseModel): + mode: Optional[ModeOptionsHost] = None + r"""Select level of detail for host metrics""" + + custom: Optional[InputResponseInputSystemMetricsCustom] = None + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptionsHost(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["mode", "custom"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseContainerMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the level of detail for container metrics""" + + # Basic + BASIC = "basic" + # All + ALL = "all" + # Custom + CUSTOM = "custom" + # Disabled + DISABLED = "disabled" + + +class InputResponseInputSystemMetricsFilterTypedDict(TypedDict): + expr: str + r"""Expression""" + + +class InputResponseInputSystemMetricsFilter(BaseModel): + expr: str + r"""Expression""" + + +class InputResponseContainerTypedDict(TypedDict): + mode: NotRequired[InputResponseContainerMode] + r"""Select the level of detail for container metrics""" + docker_socket: NotRequired[List[str]] + r"""Full paths for Docker's UNIX-domain socket""" + docker_timeout: NotRequired[float] + r"""Timeout, in seconds, for the Docker API""" + filters: NotRequired[List[InputResponseInputSystemMetricsFilterTypedDict]] + r"""Containers matching any of these will be included. All are included if no filters are added.""" + all_containers: NotRequired[bool] + r"""Include stopped and paused containers""" + per_device: NotRequired[bool] + r"""Generate separate metrics for each device""" + detail: NotRequired[bool] + r"""Generate full container metrics""" + + +class InputResponseContainer(BaseModel): + mode: Optional[InputResponseContainerMode] = None + r"""Select the level of detail for container metrics""" + + docker_socket: Annotated[ + Optional[List[str]], pydantic.Field(alias="dockerSocket") + ] = None + r"""Full paths for Docker's UNIX-domain socket""" + + docker_timeout: Annotated[ + Optional[float], pydantic.Field(alias="dockerTimeout") + ] = None + r"""Timeout, in seconds, for the Docker API""" + + filters: Optional[List[InputResponseInputSystemMetricsFilter]] = None + r"""Containers matching any of these will be included. All are included if no filters are added.""" + + all_containers: Annotated[Optional[bool], pydantic.Field(alias="allContainers")] = ( + None + ) + r"""Include stopped and paused containers""" + + per_device: Annotated[Optional[bool], pydantic.Field(alias="perDevice")] = None + r"""Generate separate metrics for each device""" + + detail: Optional[bool] = None + r"""Generate full container metrics""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseContainerMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "mode", + "dockerSocket", + "dockerTimeout", + "filters", + "allContainers", + "perDevice", + "detail", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsPersistenceTypedDict(TypedDict): + r"""persistence""" + + enable: NotRequired[bool] + r"""Spool metrics to disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" + + +class InputResponseInputSystemMetricsPersistence(BaseModel): + r"""persistence""" + + enable: Optional[bool] = None + r"""Spool metrics to disk for Cribl Edge and Search""" + + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/system_metrics""" + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputSystemMetricsTypedDict(TypedDict): + type: InputResponseInputSystemMetricsType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + host: NotRequired[InputResponseInputSystemMetricsHostTypedDict] + process: NotRequired[ProcessTypeTypedDict] + container: NotRequired[InputResponseContainerTypedDict] + gpu: NotRequired[GpuTypeTypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + persistence: NotRequired[InputResponseInputSystemMetricsPersistenceTypedDict] + r"""persistence""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputSystemMetrics(BaseModel): + type: InputResponseInputSystemMetricsType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + interval: Optional[float] = None + r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + + host: Optional[InputResponseInputSystemMetricsHost] = None + + process: Optional[ProcessType] = None + + container: Optional[InputResponseContainer] = None + + gpu: Optional[GpuType] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + persistence: Optional[InputResponseInputSystemMetricsPersistence] = None + r"""persistence""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "interval", + "host", + "process", + "container", + "gpu", + "metadata", + "persistence", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputTcpjsonTypedDict(TypedDict): + type: TypeOptionsTcpjson + r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputTcpjson(BaseModel): + type: TypeOptionsTcpjson + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to establish a connection""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "enableLoadBalancing", + "authType", + "description", + "authToken", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCriblLakeHTTPType(str, Enum): + r"""Source type identifier.""" + + CRIBL_LAKE_HTTP = "cribl_lake_http" + + +class InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""When enabled, the token value is available on events as __hecToken""" + default_dataset: NotRequired[str] + allowed_indexes_at_token: NotRequired[List[str]] + + +class InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata(BaseModel): + enabled: Optional[bool] = None + r"""When enabled, the token value is available on events as __hecToken""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""Elasticsearch""" + default_dataset: NotRequired[str] + + +class InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata(BaseModel): + enabled: Optional[bool] = None + r"""Elasticsearch""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict( + TypedDict +): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Token""" + description: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + splunk_hec_metadata: NotRequired[ + InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadataTypedDict + ] + + +class InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Token""" + + description: Optional[str] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + splunk_hec_metadata: Annotated[ + Optional[InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata], + pydantic.Field(alias="splunkHecMetadata"), + ] = None + + elasticsearch_metadata: Annotated[ + Optional[InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata], + pydantic.Field(alias="elasticsearchMetadata"), + ] = None + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "tokenSecret", + "token", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict(TypedDict): + enabled: NotRequired[bool] + r"""When enabled, the token value is available on events as __hecToken""" + default_dataset: NotRequired[str] + allowed_indexes_at_token: NotRequired[List[str]] + + +class InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata(BaseModel): + enabled: Optional[bool] = None + r"""When enabled, the token value is available on events as __hecToken""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset", "allowedIndexesAtToken"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict( + TypedDict +): + enabled: NotRequired[bool] + r"""Elasticsearch""" + default_dataset: NotRequired[str] + + +class InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata(BaseModel): + enabled: Optional[bool] = None + r"""Elasticsearch""" + + default_dataset: Annotated[ + Optional[str], pydantic.Field(alias="defaultDataset") + ] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "defaultDataset"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict( + TypedDict +): + token: str + r"""Token""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + splunk_hec_metadata: NotRequired[ + InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadataTypedDict + ] + elasticsearch_metadata: NotRequired[ + InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadataTypedDict + ] + + +class InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType(BaseModel): + token: str + r"""Token""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + splunk_hec_metadata: Annotated[ + Optional[InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata], + pydantic.Field(alias="splunkHecMetadata"), + ] = None + + elasticsearch_metadata: Annotated[ + Optional[InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata], + pydantic.Field(alias="elasticsearchMetadata"), + ] = None + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "tokenSecret", + "description", + "metadata", + "splunkHecMetadata", + "elasticsearchMetadata", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +InputResponseInputCriblLakeHTTPAuthTokensExtTypedDict = TypeAliasType( + "InputResponseInputCriblLakeHTTPAuthTokensExtTypedDict", + Union[ + InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsTypeTypedDict, + InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraintTypedDict, + ], +) + + +InputResponseInputCriblLakeHTTPAuthTokensExt = TypeAliasType( + "InputResponseInputCriblLakeHTTPAuthTokensExt", + Union[ + InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType, + InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint, + ], +) + + +class InputResponseInputCriblLakeHTTPTypedDict(TypedDict): + type: InputResponseInputCriblLakeHTTPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + cribl_api: NotRequired[str] + r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" + elastic_api: NotRequired[str] + r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" + splunk_hec_api: NotRequired[str] + r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" + splunk_hec_acks: NotRequired[bool] + r"""Enable Splunk HEC acknowledgements""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_tokens_ext: NotRequired[ + List[InputResponseInputCriblLakeHTTPAuthTokensExtTypedDict] + ] + r"""Auth tokens""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_cribl_api: NotRequired[str] + r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" + template_elastic_api: NotRequired[str] + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + template_splunk_hec_api: NotRequired[str] + r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputCriblLakeHTTP(BaseModel): + type: InputResponseInputCriblLakeHTTPType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + cribl_api: Annotated[Optional[str], pydantic.Field(alias="criblAPI")] = None + r"""Absolute path on which to listen for the Cribl HTTP API requests. Only _bulk (default /cribl/_bulk) is available. Use empty string to disable.""" + + elastic_api: Annotated[Optional[str], pydantic.Field(alias="elasticAPI")] = None + r"""Absolute path on which to listen for the Elasticsearch API requests. Only _bulk (default /elastic/_bulk) is available. Use empty string to disable.""" + + splunk_hec_api: Annotated[Optional[str], pydantic.Field(alias="splunkHecAPI")] = ( + None + ) + r"""Absolute path on which listen for the Splunk HTTP Event Collector API requests. Use empty string to disable.""" + + splunk_hec_acks: Annotated[ + Optional[bool], pydantic.Field(alias="splunkHecAcks") + ] = None + r"""Enable Splunk HEC acknowledgements""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_tokens_ext: Annotated[ + Optional[List[InputResponseInputCriblLakeHTTPAuthTokensExt]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Auth tokens""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + template_cribl_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_criblAPI") + ] = None + r"""Binds 'criblAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'criblAPI' at runtime.""" + + template_elastic_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticAPI") + ] = None + r"""Binds 'elasticAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticAPI' at runtime.""" + + template_splunk_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_splunkHecAPI") + ] = None + r"""Binds 'splunkHecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'splunkHecAPI' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "criblAPI", + "elasticAPI", + "splunkHecAPI", + "splunkHecAcks", + "metadata", + "authTokensExt", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + "__template_criblAPI", + "__template_elasticAPI", + "__template_splunkHecAPI", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCriblHTTPType(str, Enum): + r"""Source type identifier.""" + + CRIBL_HTTP = "cribl_http" + + +class InputResponseInputCriblHTTPTypedDict(TypedDict): + type: InputResponseInputCriblHTTPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputCriblHTTP(BaseModel): + type: InputResponseInputCriblHTTPType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + ] = None + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl HTTP destinations in connected environments.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCriblTCPTypedDict(TypedDict): + type: TypeOptionsCribltcp + r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputCriblTCP(BaseModel): + type: TypeOptionsCribltcp + r"""Connector type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + ] = None + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should be installed in Cribl TCP destinations in connected environments.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "enableLoadBalancing", + "authTokens", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputCriblType(str, Enum): + r"""Connector type identifier.""" + + CRIBL = "cribl" + + +class InputResponseInputCriblTypedDict(TypedDict): + type: InputResponseInputCriblType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + filter_: NotRequired[str] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputCribl(BaseModel): + type: InputResponseInputCriblType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "filter", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputGooglePubsubTypedDict(TypedDict): + type: TypeOptionsGooglepubsub + r"""Connector type identifier.""" + topic_name: str + r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" + subscription_name: str + r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + monitor_subscription: NotRequired[bool] + r"""Use when the subscription is not created by this Source and topic is not known""" + create_topic: NotRequired[bool] + r"""Create topic if it does not exist""" + create_subscription: NotRequired[bool] + r"""Create subscription if it does not exist""" + region: NotRequired[str] + r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + max_backlog: NotRequired[float] + r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" + concurrency: NotRequired[float] + r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" + request_timeout: NotRequired[float] + r"""Pull request timeout, in milliseconds""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + ordered_delivery: NotRequired[bool] + r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_name: NotRequired[str] + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + template_subscription_name: NotRequired[str] + r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputGooglePubsub(BaseModel): + type: TypeOptionsGooglepubsub + r"""Connector type identifier.""" + + topic_name: Annotated[str, pydantic.Field(alias="topicName")] + r"""ID of the topic to receive events from. When Monitor subscription is enabled, any value may be entered.""" + + subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] + r"""ID of the subscription to use when receiving events. When Monitor subscription is enabled, the fully qualified subscription name must be entered. Example: projects/myProject/subscriptions/mySubscription""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + monitor_subscription: Annotated[ + Optional[bool], pydantic.Field(alias="monitorSubscription") + ] = None + r"""Use when the subscription is not created by this Source and topic is not known""" + + create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None + r"""Create topic if it does not exist""" + + create_subscription: Annotated[ + Optional[bool], pydantic.Field(alias="createSubscription") + ] = None + r"""Create subscription if it does not exist""" + + region: Optional[str] = None + r"""Region to retrieve messages from. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + + google_auth_method: Annotated[ + Optional[GoogleAuthenticationMethodOptions], + pydantic.Field(alias="googleAuthMethod"), + ] = None + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + secret: Optional[str] = None + r"""Select or create a stored text secret""" + + max_backlog: Annotated[Optional[float], pydantic.Field(alias="maxBacklog")] = None + r"""If Destination exerts backpressure, this setting limits how many inbound events Stream will queue for processing before it stops retrieving events""" + + concurrency: Optional[float] = None + r"""How many streams to pull messages from at one time. Doubling the value doubles the number of messages this Source pulls from the topic (if available), while consuming more CPU and memory. Defaults to 5.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Pull request timeout, in milliseconds""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + ordered_delivery: Annotated[ + Optional[bool], pydantic.Field(alias="orderedDelivery") + ] = None + r"""Receive events in the order they were added to the queue. The process sending events must have ordering enabled.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_topic_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicName") + ] = None + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + + template_subscription_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_subscriptionName") + ] = None + r"""Binds 'subscriptionName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'subscriptionName' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): + if isinstance(value, str): + try: + return models.GoogleAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "monitorSubscription", + "createTopic", + "createSubscription", + "region", + "googleAuthMethod", + "serviceAccountCredentials", + "secret", + "maxBacklog", + "concurrency", + "requestTimeout", + "metadata", + "autoParse", + "description", + "orderedDelivery", + "__template_environment", + "__template_streamtags", + "__template_topicName", + "__template_subscriptionName", + "__template_region", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputFirehoseType(str, Enum): + r"""Source type identifier.""" + + FIREHOSE = "firehose" + + +class InputResponseInputFirehoseTypedDict(TypedDict): + type: InputResponseInputFirehoseType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputFirehose(BaseModel): + type: InputResponseInputFirehoseType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") + ] = None + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_authTokens", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputExecType(str, Enum): + r"""Connector type identifier.""" + + EXEC = "exec" + + +class InputResponseScheduleType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + + INTERVAL = "interval" + CRON_SCHEDULE = "cronSchedule" + + +class InputResponseInputExecTypedDict(TypedDict): + type: InputResponseInputExecType + r"""Connector type identifier.""" + command: str + r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""Disabled""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + script: NotRequired[str] + r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" + retries: NotRequired[float] + r"""Maximum number of retry attempts in the event that the command fails""" + schedule_type: NotRequired[InputResponseScheduleType] + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + interval: NotRequired[float] + r"""Interval between command executions in seconds.""" + cron_schedule: NotRequired[str] + r"""Cron schedule to execute the command on.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputExec(BaseModel): + type: InputResponseInputExecType + r"""Connector type identifier.""" + + command: str + r"""Command to execute; supports Bourne shell (or CMD on Windows) syntax""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""Disabled""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + script: Optional[str] = None + r"""Optional script content to pipe into the command's stdin. The stdin stream is closed after the script is written.""" + + retries: Optional[float] = None + r"""Maximum number of retry attempts in the event that the command fails""" + + schedule_type: Annotated[ + Optional[InputResponseScheduleType], pydantic.Field(alias="scheduleType") + ] = None + r"""Select a schedule type; either an interval (in seconds) or a cron-style schedule.""" + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + interval: Optional[float] = None + r"""Interval between command executions in seconds.""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Cron schedule to execute the command on.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("schedule_type") + def serialize_schedule_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseScheduleType(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "script", + "retries", + "scheduleType", + "breakerRulesets", + "staleChannelFlushMs", + "metadata", + "autoParse", + "description", + "interval", + "cronSchedule", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputEventhubAmqpType(str, Enum): + r"""Connector type identifier.""" + + EVENTHUB_AMQP = "eventhub_amqp" + + +class InputResponseAuthenticationMechanism(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Authentication mechanism""" + + # Connection String + CONNECTION_STRING = "connection-string" + # OAuth Bearer + OAUTH_BEARER = "oauth-bearer" + + +class InputResponseCertificateTypedDict(TypedDict): + certificate_name: str + r"""The certificate you registered as credentials for your app in the Azure portal""" + cert_path: str + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + priv_key_path: str + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + + +class InputResponseCertificate(BaseModel): + certificate_name: Annotated[str, pydantic.Field(alias="certificateName")] + r"""The certificate you registered as credentials for your app in the Azure portal""" + + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["passphrase"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseAuthTypedDict(TypedDict): + mechanism: InputResponseAuthenticationMechanism + r"""Authentication mechanism""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] + r"""Authentication method""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[InputResponseCertificateTypedDict] + oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] + r"""Endpoint used to acquire authentication tokens from Azure""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory""" + fully_qualified_namespace: NotRequired[str] + r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" + template_oauth_endpoint: NotRequired[str] + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_fully_qualified_namespace: NotRequired[str] + r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" + + +class InputResponseAuth(BaseModel): + mechanism: InputResponseAuthenticationMechanism + r"""Authentication mechanism""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + client_secret_auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuth], + pydantic.Field(alias="clientSecretAuthType"), + ] = None + r"""Authentication method""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[InputResponseCertificate] = None + + oauth_endpoint: Annotated[ + Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], + pydantic.Field(alias="oauthEndpoint"), + ] = None + r"""Endpoint used to acquire authentication tokens from Azure""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory""" + + fully_qualified_namespace: Annotated[ + Optional[str], pydantic.Field(alias="fullyQualifiedNamespace") + ] = None + r"""The fully qualified Event Hubs namespace that the consumer is associated with. This is likely to be similar to {yournamespace}.servicebus.windows.net.""" + + template_oauth_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_oauthEndpoint") + ] = None + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_fully_qualified_namespace: Annotated[ + Optional[str], pydantic.Field(alias="__template_fullyQualifiedNamespace") + ] = None + r"""Binds 'fullyQualifiedNamespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fullyQualifiedNamespace' at runtime.""" + + @field_serializer("mechanism") + def serialize_mechanism(self, value): + if isinstance(value, str): + try: + return models.InputResponseAuthenticationMechanism(value) + except ValueError: + return value + return value + + @field_serializer("client_secret_auth_type") + def serialize_client_secret_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuth(value) + except ValueError: + return value + return value + + @field_serializer("oauth_endpoint") + def serialize_oauth_endpoint(self, value): + if isinstance(value, str): + try: + return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "textSecret", + "clientSecretAuthType", + "clientTextSecret", + "certificate", + "oauthEndpoint", + "clientId", + "tenantId", + "fullyQualifiedNamespace", + "__template_oauthEndpoint", + "__template_clientId", + "__template_tenantId", + "__template_fullyQualifiedNamespace", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseAzureBlobStorageTypedDict(TypedDict): + r"""Azure Blob Storage""" + + container_name: str + r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" + auth_type: NotRequired[AuthenticationMethodOptionsClientAssertionClientAssertionrpc] + r"""Authentication method""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + +class InputResponseAzureBlobStorage(BaseModel): + r"""Azure Blob Storage""" + + container_name: Annotated[str, pydantic.Field(alias="containerName")] + r"""Azure Blob Storage container used to store checkpoints. Must be 3–63 lowercase alphanumeric characters or hyphens.""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsClientAssertionClientAssertionrpc], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") + ] = None + r"""The name of your Azure storage account""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" + + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") + ] = None + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") + ] = None + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return ( + models.AuthenticationMethodOptionsClientAssertionClientAssertionrpc( + value + ) + ) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseCheckpointingTypedDict(TypedDict): + blob_store: InputResponseAzureBlobStorageTypedDict + r"""Azure Blob Storage""" + + +class InputResponseCheckpointing(BaseModel): + blob_store: Annotated[ + InputResponseAzureBlobStorage, pydantic.Field(alias="blobStore") + ] + r"""Azure Blob Storage""" + + +class InputResponseInputEventhubAmqpTypedDict(TypedDict): + type: InputResponseInputEventhubAmqpType + r"""Connector type identifier.""" + consumer_group: str + r"""The consumer group this instance belongs to. Default is '$Default'.""" + checkpointing: InputResponseCheckpointingTypedDict + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + event_hub_name: NotRequired[str] + r"""The name of the Event Hub to consume from""" + auth: NotRequired[InputResponseAuthTypedDict] + from_beginning: NotRequired[bool] + r"""Start reading from earliest available data; relevant only during initial subscription""" + max_batch_size: NotRequired[int] + r"""Maximum number of events in each batch delivered to the consumer""" + max_wait_time_in_seconds: NotRequired[int] + r"""Maximum time to wait for a batch of events before delivering a partial batch""" + prefetch_count: NotRequired[int] + r"""Number of events to prefetch from the service for processing""" + max_retries: NotRequired[int] + r"""Maximum number of retries per operation""" + initial_backoff: NotRequired[int] + r"""Initial delay before the first retry, in milliseconds""" + max_backoff: NotRequired[int] + r"""Maximum delay between retries, in milliseconds""" + timeout_in_ms: NotRequired[int] + r"""Maximum time to wait for a request to complete""" + connection_initial_backoff: NotRequired[int] + r"""Initial delay before the first reconnection attempt, in milliseconds""" + connection_max_backoff: NotRequired[int] + r"""Maximum delay between reconnection attempts, in milliseconds""" + connection_timeout_in_ms: NotRequired[int] + r"""Maximum time to wait for a connection to complete""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputEventhubAmqp(BaseModel): + type: InputResponseInputEventhubAmqpType + r"""Connector type identifier.""" + + consumer_group: Annotated[str, pydantic.Field(alias="consumerGroup")] + r"""The consumer group this instance belongs to. Default is '$Default'.""" + + checkpointing: InputResponseCheckpointing + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + event_hub_name: Annotated[Optional[str], pydantic.Field(alias="eventHubName")] = ( + None + ) + r"""The name of the Event Hub to consume from""" + + auth: Optional[InputResponseAuth] = None + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Start reading from earliest available data; relevant only during initial subscription""" + + max_batch_size: Annotated[Optional[int], pydantic.Field(alias="maxBatchSize")] = ( + None + ) + r"""Maximum number of events in each batch delivered to the consumer""" + + max_wait_time_in_seconds: Annotated[ + Optional[int], pydantic.Field(alias="maxWaitTimeInSeconds") + ] = None + r"""Maximum time to wait for a batch of events before delivering a partial batch""" + + prefetch_count: Annotated[Optional[int], pydantic.Field(alias="prefetchCount")] = ( + None + ) + r"""Number of events to prefetch from the service for processing""" + + max_retries: Annotated[Optional[int], pydantic.Field(alias="maxRetries")] = None + r"""Maximum number of retries per operation""" + + initial_backoff: Annotated[ + Optional[int], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial delay before the first retry, in milliseconds""" + + max_backoff: Annotated[Optional[int], pydantic.Field(alias="maxBackoff")] = None + r"""Maximum delay between retries, in milliseconds""" + + timeout_in_ms: Annotated[Optional[int], pydantic.Field(alias="timeoutInMs")] = None + r"""Maximum time to wait for a request to complete""" + + connection_initial_backoff: Annotated[ + Optional[int], pydantic.Field(alias="connectionInitialBackoff") + ] = None + r"""Initial delay before the first reconnection attempt, in milliseconds""" + + connection_max_backoff: Annotated[ + Optional[int], pydantic.Field(alias="connectionMaxBackoff") + ] = None + r"""Maximum delay between reconnection attempts, in milliseconds""" + + connection_timeout_in_ms: Annotated[ + Optional[int], pydantic.Field(alias="connectionTimeoutInMs") + ] = None + r"""Maximum time to wait for a connection to complete""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "eventHubName", + "auth", + "fromBeginning", + "maxBatchSize", + "maxWaitTimeInSeconds", + "prefetchCount", + "maxRetries", + "initialBackoff", + "maxBackoff", + "timeoutInMs", + "connectionInitialBackoff", + "connectionMaxBackoff", + "connectionTimeoutInMs", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputEventhubType(str, Enum): + r"""Connector type identifier.""" + + EVENTHUB = "eventhub" + + +class InputResponseInputEventhubTypedDict(TypedDict): + type: InputResponseInputEventhubType + r"""Connector type identifier.""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + topics: List[str] + r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + group_id: NotRequired[str] + r"""The consumer group this instance belongs to. Default is 'Cribl'.""" + from_beginning: NotRequired[bool] + r"""Start reading from earliest available data; relevant only during initial subscription""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeUseTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeTypedDict] + r"""TLS settings (client side)""" + session_timeout: NotRequired[float] + r""" + Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + rebalance_timeout: NotRequired[float] + r""" + Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + heartbeat_interval: NotRequired[float] + r""" + Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + auto_commit_interval: NotRequired[float] + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + auto_commit_threshold: NotRequired[float] + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + max_bytes_per_partition: NotRequired[float] + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + max_bytes: NotRequired[float] + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + max_socket_errors: NotRequired[float] + r"""Maximum number of network errors before the consumer re-creates a socket""" + minimize_duplicates: NotRequired[bool] + r"""Minimize duplicate events by starting only one consumer for each topic partition""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topics: NotRequired[str] + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + template_group_id: NotRequired[str] + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputEventhub(BaseModel): + type: InputResponseInputEventhubType + r"""Connector type identifier.""" + + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to (example: yourdomain.servicebus.windows.net:9093). The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + + topics: List[str] + r"""The name of the Event Hub (Kafka topic) to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Event Hubs Source to only a single topic.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""The consumer group this instance belongs to. Default is 'Cribl'.""" + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Start reading from earliest available data; relevant only during initial subscription""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" + + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationTypeUse] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideType] = None + r"""TLS settings (client side)""" + + session_timeout: Annotated[ + Optional[float], pydantic.Field(alias="sessionTimeout") + ] = None + r""" + Timeout (session.timeout.ms in Kafka domain) used to detect client failures when using Kafka's group-management facilities. If the client sends no heartbeats to the broker before the timeout expires, the broker will remove the client from the group and initiate a rebalance. Value must be lower than rebalanceTimeout. See details [here](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + rebalance_timeout: Annotated[ + Optional[float], pydantic.Field(alias="rebalanceTimeout") + ] = None + r""" + Maximum allowed time (rebalance.timeout.ms in Kafka domain) for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + heartbeat_interval: Annotated[ + Optional[float], pydantic.Field(alias="heartbeatInterval") + ] = None + r""" + Expected time (heartbeat.interval.ms in Kafka domain) between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Recommended configurations](https://github.com/Azure/azure-event-hubs-for-kafka/blob/master/CONFIGURATION.md). + """ + + auto_commit_interval: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitInterval") + ] = None + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + auto_commit_threshold: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitThreshold") + ] = None + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + max_bytes_per_partition: Annotated[ + Optional[float], pydantic.Field(alias="maxBytesPerPartition") + ] = None + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + + max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + + max_socket_errors: Annotated[ + Optional[float], pydantic.Field(alias="maxSocketErrors") + ] = None + r"""Maximum number of network errors before the consumer re-creates a socket""" + + minimize_duplicates: Annotated[ + Optional[bool], pydantic.Field(alias="minimizeDuplicates") + ] = None + r"""Minimize duplicate events by starting only one consumer for each topic partition""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") + ] = None + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + + template_topics: Annotated[ + Optional[str], pydantic.Field(alias="__template_topics") + ] = None + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + + template_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_groupId") + ] = None + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "groupId", + "fromBeginning", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", + "sessionTimeout", + "rebalanceTimeout", + "heartbeatInterval", + "autoCommitInterval", + "autoCommitThreshold", + "maxBytesPerPartition", + "maxBytes", + "maxSocketErrors", + "minimizeDuplicates", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "__template_brokers", + "__template_topics", + "__template_groupId", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputMicrosoftGraphType(str, Enum): + r"""Connector type identifier.""" + + MICROSOFT_GRAPH = "microsoft_graph" + + +class InputResponseInputMicrosoftGraphAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + OAUTH = "oauth" + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class InputResponseInputMicrosoftGraphSubscriptionPlan( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + # Microsoft 365 Enterprise + ENTERPRISE_GCC = "enterprise_gcc" + # Microsoft 365 GCC + GCC = "gcc" + # Microsoft 365 GCC High + GCC_HIGH = "gcc_high" + # Microsoft 365 DoD + DOD = "dod" + # Microsoft 365 China (21Vianet) + CHINA = "china" + + +class InputResponseInputMicrosoftGraphTypedDict(TypedDict): + type: InputResponseInputMicrosoftGraphType + r"""Connector type identifier.""" + url: str + r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + start_date: NotRequired[str] + r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + end_date: NotRequired[str] + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + disable_time_filter: NotRequired[bool] + r"""Disables time filtering of events when a date range is specified.""" + max_pages: NotRequired[int] + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + auth_type: NotRequired[InputResponseInputMicrosoftGraphAuthenticationMethod] + r"""Select authentication method.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + reschedule_dropped_tasks: NotRequired[bool] + r"""Reschedule tasks that failed with non-fatal errors""" + max_task_reschedule: NotRequired[float] + r"""Maximum number of times a task can be rescheduled""" + log_level: NotRequired[LogLevelOptionsDebugError] + r"""Log Level (verbosity) for collection runtime behavior.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""client_secret to pass in the OAuth request parameter.""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter.""" + resource: NotRequired[str] + r"""Resource to pass in the OAuth request parameter.""" + plan_type: NotRequired[InputResponseInputMicrosoftGraphSubscriptionPlan] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + text_secret: NotRequired[str] + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + cert_options: NotRequired[CertOptionsTypeTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_resource: NotRequired[str] + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputMicrosoftGraph(BaseModel): + type: InputResponseInputMicrosoftGraphType + r"""Connector type identifier.""" + + url: str + r"""Microsoft Graph API endpoint URL. (ex. https://graph.microsoft.com/v1.0/admin/exchange/tracing/messageTraces)""" + + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None + r"""Backward offset for the search range's head. (E.g.: -3h@h) Microsoft Graph data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + + end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Microsoft Graph data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + + disable_time_filter: Annotated[ + Optional[bool], pydantic.Field(alias="disableTimeFilter") + ] = None + r"""Disables time filtering of events when a date range is specified.""" + + max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + + auth_type: Annotated[ + Optional[InputResponseInputMicrosoftGraphAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + reschedule_dropped_tasks: Annotated[ + Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") + ] = None + r"""Reschedule tasks that failed with non-fatal errors""" + + max_task_reschedule: Annotated[ + Optional[float], pydantic.Field(alias="maxTaskReschedule") + ] = None + r"""Maximum number of times a task can be rescheduled""" + + log_level: Annotated[ + Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") + ] = None + r"""Log Level (verbosity) for collection runtime behavior.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""client_secret to pass in the OAuth request parameter.""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter.""" + + resource: Optional[str] = None + r"""Resource to pass in the OAuth request parameter.""" + + plan_type: Annotated[ + Optional[InputResponseInputMicrosoftGraphSubscriptionPlan], + pydantic.Field(alias="planType"), + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + + cert_options: Annotated[ + Optional[CertOptionsType], pydantic.Field(alias="certOptions") + ] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_resource: Annotated[ + Optional[str], pydantic.Field(alias="__template_resource") + ] = None + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputMicrosoftGraphAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsDebugError(value) + except ValueError: + return value + return value + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputMicrosoftGraphSubscriptionPlan(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "startDate", + "endDate", + "timeout", + "disableTimeFilter", + "maxPages", + "authType", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "rescheduleDroppedTasks", + "maxTaskReschedule", + "logLevel", + "retryRules", + "breakerRulesets", + "staleChannelFlushMs", + "description", + "clientSecret", + "tenantId", + "clientId", + "resource", + "planType", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_url", + "__template_tenantId", + "__template_clientId", + "__template_resource", + "__template_planType", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputOffice365MsgTraceType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_MSG_TRACE = "office365_msg_trace" + + +class InputResponseInputOffice365MsgTraceAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + MANUAL = "manual" + SECRET = "secret" + OAUTH = "oauth" + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class InputResponseInputOffice365MsgTraceTypedDict(TypedDict): + type: InputResponseInputOffice365MsgTraceType + r"""Connector type identifier.""" + url: str + r"""URL to use when retrieving report data.""" + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + start_date: NotRequired[str] + r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + end_date: NotRequired[str] + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + disable_time_filter: NotRequired[bool] + r"""Disables time filtering of events when a date range is specified.""" + auth_type: NotRequired[InputResponseInputOffice365MsgTraceAuthenticationMethod] + r"""Select authentication method.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + reschedule_dropped_tasks: NotRequired[bool] + r"""Reschedule tasks that failed with non-fatal errors""" + max_task_reschedule: NotRequired[float] + r"""Maximum number of times a task can be rescheduled""" + log_level: NotRequired[LogLevelOptionsDebugError] + r"""Log Level (verbosity) for collection runtime behavior.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username to run Message Trace API call.""" + password: NotRequired[str] + r"""Password to run Message Trace API call.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials.""" + client_secret: NotRequired[str] + r"""client_secret to pass in the OAuth request parameter.""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter.""" + resource: NotRequired[str] + r"""Resource to pass in the OAuth request parameter.""" + plan_type: NotRequired[SubscriptionPlanOptions] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + text_secret: NotRequired[str] + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + cert_options: NotRequired[CertOptionsTypeTypedDict] + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_resource: NotRequired[str] + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputOffice365MsgTrace(BaseModel): + type: InputResponseInputOffice365MsgTraceType + r"""Connector type identifier.""" + + url: str + r"""URL to use when retrieving report data.""" + + interval: int + r"""How often (in minutes) to run the report. Must divide evenly into 60 minutes to create a predictable schedule, or Save will fail.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + start_date: Annotated[Optional[str], pydantic.Field(alias="startDate")] = None + r"""Backward offset for the search range's head. (E.g.: -3h@h) Message Trace data is delayed; this parameter (with Date range end) compensates for delay and gaps.""" + + end_date: Annotated[Optional[str], pydantic.Field(alias="endDate")] = None + r"""Backward offset for the search range's tail. (E.g.: -2h@h) Message Trace data is delayed; this parameter (with Date range start) compensates for delay and gaps.""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout. Maximum is 2400 (40 minutes); enter 0 to wait indefinitely.""" + + disable_time_filter: Annotated[ + Optional[bool], pydantic.Field(alias="disableTimeFilter") + ] = None + r"""Disables time filtering of events when a date range is specified.""" + + auth_type: Annotated[ + Optional[InputResponseInputOffice365MsgTraceAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Select authentication method.""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run. Time unit defaults to seconds if not specified (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + reschedule_dropped_tasks: Annotated[ + Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") + ] = None + r"""Reschedule tasks that failed with non-fatal errors""" + + max_task_reschedule: Annotated[ + Optional[float], pydantic.Field(alias="maxTaskReschedule") + ] = None + r"""Maximum number of times a task can be rescheduled""" + + log_level: Annotated[ + Optional[LogLevelOptionsDebugError], pydantic.Field(alias="logLevel") + ] = None + r"""Log Level (verbosity) for collection runtime behavior.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username to run Message Trace API call.""" + + password: Optional[str] = None + r"""Password to run Message Trace API call.""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""client_secret to pass in the OAuth request parameter.""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory.""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter.""" + + resource: Optional[str] = None + r"""Resource to pass in the OAuth request parameter.""" + + plan_type: Annotated[ + Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references your client_secret to pass in the OAuth request parameter.""" + + cert_options: Annotated[ + Optional[CertOptionsType], pydantic.Field(alias="certOptions") + ] = None + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_resource: Annotated[ + Optional[str], pydantic.Field(alias="__template_resource") + ] = None + r"""Binds 'resource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resource' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputOffice365MsgTraceAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsDebugError(value) + except ValueError: + return value + return value + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "startDate", + "endDate", + "timeout", + "disableTimeFilter", + "authType", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "rescheduleDroppedTasks", + "maxTaskReschedule", + "logLevel", + "retryRules", + "description", + "username", + "password", + "credentialsSecret", + "clientSecret", + "tenantId", + "clientId", + "resource", + "planType", + "textSecret", + "certOptions", + "__template_environment", + "__template_streamtags", + "__template_url", + "__template_tenantId", + "__template_clientId", + "__template_resource", + "__template_planType", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputOffice365ServiceType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_SERVICE = "office365_service" + + +class InputResponseInputOffice365ServiceContentConfigTypedDict(TypedDict): + content_type: NotRequired[str] + r"""Microsoft 365 Services API Content Type""" + description: NotRequired[str] + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + interval: NotRequired[float] + r"""Interval""" + log_level: NotRequired[LogLevelOptionsContentConfigItems] + r"""Collector runtime Log Level""" + enabled: NotRequired[bool] + r"""Enabled""" + + +class InputResponseInputOffice365ServiceContentConfig(BaseModel): + content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None + r"""Microsoft 365 Services API Content Type""" + + description: Optional[str] = None + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + + interval: Optional[float] = None + r"""Interval""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime Log Level""" + + enabled: Optional[bool] = None + r"""Enabled""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["contentType", "description", "interval", "logLevel", "enabled"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputOffice365ServiceTypedDict(TypedDict): + type: InputResponseInputOffice365ServiceType + r"""Connector type identifier.""" + tenant_id: str + r"""Microsoft 365 Azure Tenant ID""" + app_id: str + r"""Microsoft 365 Azure Application ID""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + plan_type: NotRequired[SubscriptionPlanOptions] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, use 0 to disable""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + content_config: NotRequired[ + List[InputResponseInputOffice365ServiceContentConfigTypedDict] + ] + r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""Microsoft 365 Azure client secret""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_app_id: NotRequired[str] + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputOffice365Service(BaseModel): + type: InputResponseInputOffice365ServiceType + r"""Connector type identifier.""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Microsoft 365 Azure Tenant ID""" + + app_id: Annotated[str, pydantic.Field(alias="appId")] + r"""Microsoft 365 Azure Application ID""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + plan_type: Annotated[ + Optional[SubscriptionPlanOptions], pydantic.Field(alias="planType") + ] = None + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, use 0 to disable""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + content_config: Annotated[ + Optional[List[InputResponseInputOffice365ServiceContentConfig]], + pydantic.Field(alias="contentConfig"), + ] = None + r"""Enable Microsoft 365 Service Communication API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered for current and historical status must be evenly divisible by 60 to give a predictable schedule.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), + ] = None + r"""Enter client secret directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""Microsoft 365 Azure client secret""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_app_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_appId") + ] = None + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") + ] = None + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "planType", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "contentConfig", + "retryRules", + "authType", + "description", + "clientSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_planType", + "__template_tenantId", + "__template_appId", + "__template_clientSecret", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputOffice365MgmtType(str, Enum): + r"""Connector type identifier.""" + + OFFICE365_MGMT = "office365_mgmt" + + +class InputResponseInputOffice365MgmtContentConfigTypedDict(TypedDict): + content_type: NotRequired[str] + r"""Microsoft 365 Management Activity API Content Type""" + description: NotRequired[str] + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + interval: NotRequired[float] + r"""Interval""" + log_level: NotRequired[LogLevelOptionsContentConfigItems] + r"""Collector runtime Log Level""" + enabled: NotRequired[bool] + r"""Enabled""" + + +class InputResponseInputOffice365MgmtContentConfig(BaseModel): + content_type: Annotated[Optional[str], pydantic.Field(alias="contentType")] = None + r"""Microsoft 365 Management Activity API Content Type""" + + description: Optional[str] = None + r"""If interval type is minutes the value entered must evenly divisible by 60 or save will fail""" + + interval: Optional[float] = None + r"""Interval""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItems], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime Log Level""" + + enabled: Optional[bool] = None + r"""Enabled""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["contentType", "description", "interval", "logLevel", "enabled"] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputOffice365MgmtTypedDict(TypedDict): + type: InputResponseInputOffice365MgmtType + r"""Connector type identifier.""" + plan_type: SubscriptionPlanOptions + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + tenant_id: str + r"""Microsoft 365 Azure Tenant ID""" + app_id: str + r"""Microsoft 365 Azure Application ID""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, use 0 to disable""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + publisher_identifier: NotRequired[str] + r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" + content_config: NotRequired[ + List[InputResponseInputOffice365MgmtContentConfigTypedDict] + ] + r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" + ingestion_lag: NotRequired[float] + r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" + retry_rules: NotRequired[RetryRulesTypeCodesEnableHeaderTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + client_secret: NotRequired[str] + r"""Microsoft 365 Azure client secret""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_app_id: NotRequired[str] + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + template_publisher_identifier: NotRequired[str] + r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputOffice365Mgmt(BaseModel): + type: InputResponseInputOffice365MgmtType + r"""Connector type identifier.""" + + plan_type: Annotated[SubscriptionPlanOptions, pydantic.Field(alias="planType")] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise""" + + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Microsoft 365 Azure Tenant ID""" + + app_id: Annotated[str, pydantic.Field(alias="appId")] + r"""Microsoft 365 Azure Application ID""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, use 0 to disable""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + publisher_identifier: Annotated[ + Optional[str], pydantic.Field(alias="publisherIdentifier") + ] = None + r"""Optional Publisher Identifier to use in API requests, defaults to tenant id if not defined. For more information see [here](https://docs.microsoft.com/en-us/office/office-365-management-api/office-365-management-activity-api-reference#start-a-subscription)""" + + content_config: Annotated[ + Optional[List[InputResponseInputOffice365MgmtContentConfig]], + pydantic.Field(alias="contentConfig"), + ] = None + r"""Enable Microsoft 365 Management Activity API content types and polling intervals. Polling intervals are used to set up search date range and cron schedule, e.g.: */${interval} * * * *. Because of this, intervals entered must be evenly divisible by 60 to give a predictable schedule.""" + + ingestion_lag: Annotated[Optional[float], pydantic.Field(alias="ingestionLag")] = ( + None + ) + r"""Use this setting to account for ingestion lag. This is necessary because there can be a lag of 60 - 90 minutes (or longer) before Microsoft 365 events are available for retrieval.""" + + retry_rules: Annotated[ + Optional[RetryRulesTypeCodesEnableHeader], pydantic.Field(alias="retryRules") + ] = None + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), + ] = None + r"""Enter client secret directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""Microsoft 365 Azure client secret""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") + ] = None + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_app_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_appId") + ] = None + r"""Binds 'appId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'appId' at runtime.""" + + template_publisher_identifier: Annotated[ + Optional[str], pydantic.Field(alias="__template_publisherIdentifier") + ] = None + r"""Binds 'publisherIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'publisherIdentifier' at runtime.""" + + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") + ] = None + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("plan_type") + def serialize_plan_type(self, value): + if isinstance(value, str): + try: + return models.SubscriptionPlanOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "publisherIdentifier", + "contentConfig", + "ingestionLag", + "retryRules", + "authType", + "description", + "clientSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_planType", + "__template_tenantId", + "__template_appId", + "__template_publisherIdentifier", + "__template_clientSecret", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputEdgePrometheusType(str, Enum): + r"""Connector type identifier.""" + + EDGE_PROMETHEUS = "edge_prometheus" + + +class InputResponseInputEdgePrometheusDiscoveryType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + # Static + STATIC = "static" + # DNS + DNS = "dns" + # AWS EC2 + EC2 = "ec2" + # Kubernetes Node + K8S_NODE = "k8s-node" + # Kubernetes Pods + K8S_PODS = "k8s-pods" + # Kubernetes Service Monitor (v4.18+) + K8S_SERVICE_MONITOR = "k8s-service-monitor" + # HTTP SD + HTTP_SD = "http_sd" + + +class InputResponseInputEdgePrometheusAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter credentials directly, or select a stored secret""" + + MANUAL = "manual" + SECRET = "secret" + KUBERNETES = "kubernetes" + + +class InputResponseTargetTypedDict(TypedDict): + host: str + r"""Name of host from which to pull metrics.""" + protocol: NotRequired[ProtocolOptionsTargetsItems] + r"""Protocol to use when collecting metrics""" + port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets.""" + path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + + +class InputResponseTarget(BaseModel): + host: str + r"""Name of host from which to pull metrics.""" + + protocol: Optional[ProtocolOptionsTargetsItems] = None + r"""Protocol to use when collecting metrics""" + + port: Optional[float] = None + r"""The port number in the metrics URL for discovered targets.""" + + path: Optional[str] = None + r"""Path to use when collecting metrics from discovered targets""" + + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptionsTargetsItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["protocol", "port", "path"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponsePodFilterTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class InputResponsePodFilter(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to pods objects. Return 'true' to include it.""" + + description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputEdgePrometheusTypedDict(TypedDict): + type: InputResponseInputEdgePrometheusType + r"""Connector type identifier.""" + discovery_type: InputResponseInputEdgePrometheusDiscoveryType + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + interval: float + r"""How often in seconds to scrape targets for metrics.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + dimension_list: NotRequired[List[str]] + r"""Other dimensions to include in events""" + field_per_metric: NotRequired[bool] + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + timeout: NotRequired[float] + r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" + persistence: NotRequired[DiskSpoolingTypeTypedDict] + r"""Disk Spooling""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_type: NotRequired[InputResponseInputEdgePrometheusAuthenticationMethod] + r"""Enter credentials directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + targets: NotRequired[List[InputResponseTargetTypedDict]] + r"""Targets""" + record_type: NotRequired[RecordTypeOptions] + r"""DNS record type to resolve""" + scrape_port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets.""" + name_list: NotRequired[List[str]] + r"""List of DNS names to resolve""" + scrape_protocol: NotRequired[ProtocolOptionsTargetsItems] + r"""Protocol to use when collecting metrics""" + scrape_path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + use_public_ip: NotRequired[bool] + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] + r"""Filter to apply when searching for EC2 instances""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the EC2 is located""" + endpoint: NotRequired[str] + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access EC2""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + service_monitor_namespace: NotRequired[str] + r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" + scrape_protocol_expr: NotRequired[str] + r"""Protocol to use when collecting metrics""" + scrape_port_expr: NotRequired[str] + r"""The port number in the metrics URL for discovered targets.""" + scrape_path_expr: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + pod_filter: NotRequired[List[InputResponsePodFilterTypedDict]] + r""" + Add rules to decide which pods to discover for metrics. + Pods are searched if no rules are given or of all the rules' + expressions evaluate to true. + + """ + http_discovery_url: NotRequired[str] + r"""URL to fetch target groups from (must be http or https)""" + http_discovery_headers: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Extra headers to send with the discovery request""" + http_discovery_reject_unauthorized: NotRequired[bool] + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + max_response_body_size: NotRequired[str] + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + username: NotRequired[str] + r"""Username for Prometheus Basic authentication""" + password: NotRequired[str] + r"""Password for Prometheus Basic authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_dimension_list: NotRequired[str] + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + template_name_list: NotRequired[str] + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputEdgePrometheus(BaseModel): + type: InputResponseInputEdgePrometheusType + r"""Connector type identifier.""" + + discovery_type: Annotated[ + InputResponseInputEdgePrometheusDiscoveryType, + pydantic.Field(alias="discoveryType"), + ] + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + interval: float + r"""How often in seconds to scrape targets for metrics.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + dimension_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="dimensionList") + ] = None + r"""Other dimensions to include in events""" + + field_per_metric: Annotated[ + Optional[bool], pydantic.Field(alias="fieldPerMetric") + ] = None + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + + timeout: Optional[float] = None + r"""Timeout, in milliseconds, before aborting HTTP connection attempts; 1-60000 or 0 to disable""" + + persistence: Optional[DiskSpoolingType] = None + r"""Disk Spooling""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_type: Annotated[ + Optional[InputResponseInputEdgePrometheusAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter credentials directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + targets: Optional[List[InputResponseTarget]] = None + r"""Targets""" + + record_type: Annotated[ + Optional[RecordTypeOptions], pydantic.Field(alias="recordType") + ] = None + r"""DNS record type to resolve""" + + scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None + r"""The port number in the metrics URL for discovered targets.""" + + name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None + r"""List of DNS names to resolve""" + + scrape_protocol: Annotated[ + Optional[ProtocolOptionsTargetsItems], pydantic.Field(alias="scrapeProtocol") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None + r"""Path to use when collecting metrics from discovered targets""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + + search_filter: Annotated[ + Optional[List[SearchFilterConfInputPrometheus]], + pydantic.Field(alias="searchFilter"), + ] = None + r"""Filter to apply when searching for EC2 instances""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""Region where the EC2 is located""" + + endpoint: Optional[str] = None + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access EC2""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + service_monitor_namespace: Annotated[ + Optional[str], pydantic.Field(alias="serviceMonitorNamespace") + ] = None + r"""Namespace to search for ServiceMonitor resources. Leave empty to search in all namespaces. Note: Kubernetes Service Monitor discovery requires Cribl Edge version 4.18 or greater. Nodes running an older version with this option configured will report an error due to configuration schema validation failure.""" + + scrape_protocol_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapeProtocolExpr") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_port_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapePortExpr") + ] = None + r"""The port number in the metrics URL for discovered targets.""" + + scrape_path_expr: Annotated[ + Optional[str], pydantic.Field(alias="scrapePathExpr") + ] = None + r"""Path to use when collecting metrics from discovered targets""" + + pod_filter: Annotated[ + Optional[List[InputResponsePodFilter]], pydantic.Field(alias="podFilter") + ] = None + r""" + Add rules to decide which pods to discover for metrics. + Pods are searched if no rules are given or of all the rules' + expressions evaluate to true. + + """ + + http_discovery_url: Annotated[ + Optional[str], pydantic.Field(alias="httpDiscoveryUrl") + ] = None + r"""URL to fetch target groups from (must be http or https)""" + + http_discovery_headers: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="httpDiscoveryHeaders"), + ] = None + r"""Extra headers to send with the discovery request""" + + http_discovery_reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") + ] = None + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + + max_response_body_size: Annotated[ + Optional[str], pydantic.Field(alias="maxResponseBodySize") + ] = None + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + + username: Optional[str] = None + r"""Username for Prometheus Basic authentication""" + + password: Optional[str] = None + r"""Password for Prometheus Basic authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_dimension_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_dimensionList") + ] = None + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + + template_name_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_nameList") + ] = None + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("discovery_type") + def serialize_discovery_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputEdgePrometheusDiscoveryType(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputEdgePrometheusAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("record_type") + def serialize_record_type(self, value): + if isinstance(value, str): + try: + return models.RecordTypeOptions(value) + except ValueError: + return value + return value + + @field_serializer("scrape_protocol") + def serialize_scrape_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptionsTargetsItems(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "dimensionList", + "fieldPerMetric", + "timeout", + "persistence", + "metadata", + "authType", + "description", + "targets", + "recordType", + "scrapePort", + "nameList", + "scrapeProtocol", + "scrapePath", + "awsAuthenticationMethod", + "awsApiKey", + "awsSecret", + "usePublicIp", + "searchFilter", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "serviceMonitorNamespace", + "scrapeProtocolExpr", + "scrapePortExpr", + "scrapePathExpr", + "podFilter", + "httpDiscoveryUrl", + "httpDiscoveryHeaders", + "httpDiscoveryRejectUnauthorized", + "maxResponseBodySize", + "username", + "password", + "credentialsSecret", + "__template_environment", + "__template_streamtags", + "__template_dimensionList", + "__template_nameList", + "__template_awsApiKey", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputPrometheusDiscoveryType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + # Static + STATIC = "static" + # DNS + DNS = "dns" + # AWS EC2 + EC2 = "ec2" + # HTTP SD + HTTP_SD = "http_sd" + + +class InputResponseMetricsProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Protocol to use when collecting metrics""" + + HTTP = "http" + HTTPS = "https" + + +class InputResponseInputPrometheusTypedDict(TypedDict): + type: TypeOptionsPrometheus + r"""Connector type identifier.""" + interval: float + r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" + log_level: LogLevelOptions + r"""Collector runtime log level""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + dimension_list: NotRequired[List[str]] + r"""Other dimensions to include in events""" + field_per_metric: NotRequired[bool] + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + discovery_type: NotRequired[InputResponseInputPrometheusDiscoveryType] + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + timeout: NotRequired[float] + r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auth_type: NotRequired[AuthenticationMethodOptionsSasl] + r"""Enter credentials directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + target_list: NotRequired[List[str]] + r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" + record_type: NotRequired[RecordTypeOptions] + r"""DNS record type to resolve""" + scrape_port: NotRequired[float] + r"""The port number in the metrics URL for discovered targets""" + name_list: NotRequired[List[str]] + r"""List of DNS names to resolve""" + scrape_protocol: NotRequired[InputResponseMetricsProtocol] + r"""Protocol to use when collecting metrics""" + scrape_path: NotRequired[str] + r"""Path to use when collecting metrics from discovered targets""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + use_public_ip: NotRequired[bool] + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + search_filter: NotRequired[List[SearchFilterConfInputPrometheusTypedDict]] + r"""Filter to apply when searching for EC2 instances""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the EC2 is located""" + endpoint: NotRequired[str] + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access EC2""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + http_discovery_url: NotRequired[str] + r"""URL to fetch target groups from (must be http or https)""" + http_discovery_headers: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Extra headers to send with the discovery request""" + http_discovery_reject_unauthorized: NotRequired[bool] + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + max_response_body_size: NotRequired[str] + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + username: NotRequired[str] + r"""Username for Prometheus Basic authentication""" + password: NotRequired[str] + r"""Password for Prometheus Basic authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_dimension_list: NotRequired[str] + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + template_discovery_type: NotRequired[str] + r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" + template_log_level: NotRequired[str] + r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" + template_target_list: NotRequired[str] + r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" + template_name_list: NotRequired[str] + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + template_password: NotRequired[str] + r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputPrometheus(BaseModel): + type: TypeOptionsPrometheus + r"""Connector type identifier.""" + + interval: float + r"""How often, in minutes, to scrape targets for metrics. Maximum of 60 minutes. 60 must be evenly divisible by the value you enter.""" + + log_level: Annotated[LogLevelOptions, pydantic.Field(alias="logLevel")] + r"""Collector runtime log level""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + dimension_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="dimensionList") + ] = None + r"""Other dimensions to include in events""" + + field_per_metric: Annotated[ + Optional[bool], pydantic.Field(alias="fieldPerMetric") + ] = None + r"""When enabled, each metric name is used as the event field key (example: go_threads: 9) instead of the default _metric/_value format.""" + + discovery_type: Annotated[ + Optional[InputResponseInputPrometheusDiscoveryType], + pydantic.Field(alias="discoveryType"), + ] = None + r"""Target discovery mechanism. Use static to manually enter a list of targets.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + timeout: Optional[float] = None + r"""Time, in seconds, before aborting HTTP connection attempts; use 0 for no timeout""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ] = None + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ] = None + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsSasl], pydantic.Field(alias="authType") + ] = None + r"""Enter credentials directly, or select a stored secret""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + target_list: Annotated[Optional[List[str]], pydantic.Field(alias="targetList")] = ( + None + ) + r"""List of Prometheus targets to pull metrics from. Values can be in URL or host[:port] format. For example: http://localhost:9090/metrics, localhost:9090, or localhost. In cases where just host[:port] is specified, the endpoint will resolve to 'http://host[:port]/metrics'.""" + + record_type: Annotated[ + Optional[RecordTypeOptions], pydantic.Field(alias="recordType") + ] = None + r"""DNS record type to resolve""" + + scrape_port: Annotated[Optional[float], pydantic.Field(alias="scrapePort")] = None + r"""The port number in the metrics URL for discovered targets""" + + name_list: Annotated[Optional[List[str]], pydantic.Field(alias="nameList")] = None + r"""List of DNS names to resolve""" + + scrape_protocol: Annotated[ + Optional[InputResponseMetricsProtocol], pydantic.Field(alias="scrapeProtocol") + ] = None + r"""Protocol to use when collecting metrics""" + + scrape_path: Annotated[Optional[str], pydantic.Field(alias="scrapePath")] = None + r"""Path to use when collecting metrics from discovered targets""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + use_public_ip: Annotated[Optional[bool], pydantic.Field(alias="usePublicIp")] = None + r"""Use public IP address for discovered targets. Disable to use the private IP address.""" + + search_filter: Annotated[ + Optional[List[SearchFilterConfInputPrometheus]], + pydantic.Field(alias="searchFilter"), + ] = None + r"""Filter to apply when searching for EC2 instances""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""Region where the EC2 is located""" + + endpoint: Optional[str] = None + r"""EC2 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to EC2-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access EC2""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + http_discovery_url: Annotated[ + Optional[str], pydantic.Field(alias="httpDiscoveryUrl") + ] = None + r"""URL to fetch target groups from (must be http or https)""" + + http_discovery_headers: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="httpDiscoveryHeaders"), + ] = None + r"""Extra headers to send with the discovery request""" + + http_discovery_reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="httpDiscoveryRejectUnauthorized") + ] = None + r"""Reject TLS certificates that cannot be verified for the discovery endpoint. Falls back to the source-level setting if not specified.""" + + max_response_body_size: Annotated[ + Optional[str], pydantic.Field(alias="maxResponseBodySize") + ] = None + r"""Maximum size of the HTTP SD response body. Responses exceeding this limit will be rejected. Defaults to 20 MB.""" + + username: Optional[str] = None + r"""Username for Prometheus Basic authentication""" + + password: Optional[str] = None + r"""Password for Prometheus Basic authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_dimension_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_dimensionList") + ] = None + r"""Binds 'dimensionList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dimensionList' at runtime.""" + + template_discovery_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_discoveryType") + ] = None + r"""Binds 'discoveryType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'discoveryType' at runtime.""" + + template_log_level: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLevel") + ] = None + r"""Binds 'logLevel' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLevel' at runtime.""" + + template_target_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_targetList") + ] = None + r"""Binds 'targetList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'targetList' at runtime.""" + + template_name_list: Annotated[ + Optional[str], pydantic.Field(alias="__template_nameList") + ] = None + r"""Binds 'nameList' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nameList' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") + ] = None + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + template_password: Annotated[ + Optional[str], pydantic.Field(alias="__template_password") + ] = None + r"""Binds 'password' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'password' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("discovery_type") + def serialize_discovery_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputPrometheusDiscoveryType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsSasl(value) + except ValueError: + return value + return value + + @field_serializer("record_type") + def serialize_record_type(self, value): + if isinstance(value, str): + try: + return models.RecordTypeOptions(value) + except ValueError: + return value + return value + + @field_serializer("scrape_protocol") + def serialize_scrape_protocol(self, value): + if isinstance(value, str): + try: + return models.InputResponseMetricsProtocol(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "dimensionList", + "fieldPerMetric", + "discoveryType", + "rejectUnauthorized", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "authType", + "description", + "targetList", + "recordType", + "scrapePort", + "nameList", + "scrapeProtocol", + "scrapePath", + "awsAuthenticationMethod", + "awsApiKey", + "awsSecret", + "usePublicIp", + "searchFilter", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "httpDiscoveryUrl", + "httpDiscoveryHeaders", + "httpDiscoveryRejectUnauthorized", + "maxResponseBodySize", + "username", + "password", + "credentialsSecret", + "__template_environment", + "__template_streamtags", + "__template_dimensionList", + "__template_discoveryType", + "__template_logLevel", + "__template_targetList", + "__template_nameList", + "__template_awsApiKey", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_username", + "__template_password", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputPrometheusRwType(str, Enum): + r"""Source type identifier.""" + + PROMETHEUS_RW = "prometheus_rw" + + +class InputResponseInputPrometheusRwTypedDict(TypedDict): + type: InputResponseInputPrometheusRwType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + prometheus_api: str + r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputPrometheusRw(BaseModel): + type: InputResponseInputPrometheusRwType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] + r"""Absolute path on which to listen for Prometheus requests. Defaults to /write, which will expand as: http://:/write.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") + ] = None + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "authType", + "metadata", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_username", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputLokiType(str, Enum): + r"""Source type identifier.""" + + LOKI = "loki" + + +class InputResponseInputLokiTypedDict(TypedDict): + type: InputResponseInputLokiType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + loki_api: str + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputLoki(BaseModel): + type: InputResponseInputLokiType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "authType", + "metadata", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_lokiAPI", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputGrafanaType2(str, Enum): + r"""Source type identifier.""" + + GRAFANA = "grafana" + + +class InputResponsePrometheusAuth2TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class InputResponsePrometheusAuth2(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseLokiAuth2TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class InputResponseLokiAuth2(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputGrafanaGrafana2TypedDict(TypedDict): + type: InputResponseInputGrafanaType2 + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + loki_api: str + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + prometheus_api: NotRequired[str] + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + prometheus_auth: NotRequired[InputResponsePrometheusAuth2TypedDict] + loki_auth: NotRequired[InputResponseLokiAuth2TypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputGrafanaGrafana2(BaseModel): + type: InputResponseInputGrafanaType2 + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + loki_api: Annotated[str, pydantic.Field(alias="lokiAPI")] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + prometheus_api: Annotated[Optional[str], pydantic.Field(alias="prometheusAPI")] = ( + None + ) + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + + prometheus_auth: Annotated[ + Optional[InputResponsePrometheusAuth2], pydantic.Field(alias="prometheusAuth") + ] = None + + loki_auth: Annotated[ + Optional[InputResponseLokiAuth2], pydantic.Field(alias="lokiAuth") + ] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "prometheusAPI", + "prometheusAuth", + "lokiAuth", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_lokiAPI", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputGrafanaType1(str, Enum): + r"""Source type identifier.""" + + GRAFANA = "grafana" + + +class InputResponsePrometheusAuth1TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsPrometheusAuth] + r"""Remote Write authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class InputResponsePrometheusAuth1(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuth], + pydantic.Field(alias="authType"), + ] = None + r"""Remote Write authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseLokiAuth1TypedDict(TypedDict): + auth_type: NotRequired[AuthenticationTypeOptionsLokiAuth] + r"""Loki logs authentication type""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class InputResponseLokiAuth1(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsLokiAuth], pydantic.Field(alias="authType") + ] = None + r"""Loki logs authentication type""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsLokiAuth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "authType", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputGrafanaGrafana1TypedDict(TypedDict): + type: InputResponseInputGrafanaType1 + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + prometheus_api: str + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + enable_health_check: NotRequired[bool] + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + loki_api: NotRequired[str] + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + prometheus_auth: NotRequired[InputResponsePrometheusAuth1TypedDict] + loki_auth: NotRequired[InputResponseLokiAuth1TypedDict] + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_prometheus_api: NotRequired[str] + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + template_loki_api: NotRequired[str] + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputGrafanaGrafana1(BaseModel): + type: InputResponseInputGrafanaType1 + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + prometheus_api: Annotated[str, pydantic.Field(alias="prometheusAPI")] + r"""Absolute path on which to listen for Grafana Agent's Remote Write requests. Defaults to /api/prom/push, which will expand as: 'http://:/api/prom/push'. Either this field or 'Logs API endpoint' must be configured.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""Maximum time to wait for additional data, after the last response was sent, before closing a socket connection. This can be very useful when Grafana Agent remote write's request frequency is high so, reusing connections, would help mitigating the cost of creating a new connection per request. Note that Grafana Agent's embedded Prometheus would attempt to keep connections open for up to 5 minutes.""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + loki_api: Annotated[Optional[str], pydantic.Field(alias="lokiAPI")] = None + r"""Absolute path on which to listen for Loki logs requests. Defaults to /loki/api/v1/push, which will (in this example) expand as: 'http://:/loki/api/v1/push'. Either this field or 'Remote Write API endpoint' must be configured.""" + + prometheus_auth: Annotated[ + Optional[InputResponsePrometheusAuth1], pydantic.Field(alias="prometheusAuth") + ] = None + + loki_auth: Annotated[ + Optional[InputResponseLokiAuth1], pydantic.Field(alias="lokiAuth") + ] = None + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_prometheus_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusAPI") + ] = None + r"""Binds 'prometheusAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusAPI' at runtime.""" + + template_loki_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiAPI") + ] = None + r"""Binds 'lokiAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiAPI' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "lokiAPI", + "prometheusAuth", + "lokiAuth", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_prometheusAPI", + "__template_lokiAPI", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +InputResponseInputGrafanaUnionTypedDict = TypeAliasType( + "InputResponseInputGrafanaUnionTypedDict", + Union[ + InputResponseInputGrafanaGrafana1TypedDict, + InputResponseInputGrafanaGrafana2TypedDict, + ], +) + + +InputResponseInputGrafanaUnion = TypeAliasType( + "InputResponseInputGrafanaUnion", + Union[InputResponseInputGrafanaGrafana1, InputResponseInputGrafanaGrafana2], +) + + +class InputResponseInputConfluentCloudTypedDict(TypedDict): + type: TypeOptionsConfluentcloud + r"""Connector type identifier.""" + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" + topics: List[str] + r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + group_id: NotRequired[str] + r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" + from_beginning: NotRequired[bool] + r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" + kafka_schema_registry: NotRequired[KafkaSchemaRegistryAuthenticationTypeTypedDict] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + session_timeout: NotRequired[float] + r""" + Timeout used to detect client failures when using Kafka's group-management facilities. + If the client sends no heartbeats to the broker before the timeout expires, + the broker will remove the client from the group and initiate a rebalance. + Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. + See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. + """ + rebalance_timeout: NotRequired[float] + r""" + Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. + """ + heartbeat_interval: NotRequired[float] + r""" + Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. + """ + auto_commit_interval: NotRequired[float] + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + auto_commit_threshold: NotRequired[float] + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + max_bytes_per_partition: NotRequired[float] + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + max_bytes: NotRequired[float] + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + max_socket_errors: NotRequired[float] + r"""Maximum number of network errors before the consumer re-creates a socket""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topics: NotRequired[str] + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + template_group_id: NotRequired[str] + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputConfluentCloud(BaseModel): + type: TypeOptionsConfluentcloud + r"""Connector type identifier.""" + + brokers: List[str] + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092""" + + topics: List[str] + r"""Topic to subscribe to. Warning: To optimize performance, Cribl suggests subscribing each Kafka Source to a single topic only.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""The consumer group to which this instance belongs. Defaults to 'Cribl'.""" + + from_beginning: Annotated[Optional[bool], pydantic.Field(alias="fromBeginning")] = ( + None + ) + r"""Leave enabled if you want the Source, upon first subscribing to a topic, to read starting with the earliest available message""" + + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationType], + pydantic.Field(alias="kafkaSchemaRegistry"), + ] = None + r"""Kafka Schema Registry Authentication""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Maximum time to wait for a connection to complete successfully""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to a request""" + + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") + ] = None + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") + ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" + + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") + ] = None + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + session_timeout: Annotated[ + Optional[float], pydantic.Field(alias="sessionTimeout") + ] = None + r""" + Timeout used to detect client failures when using Kafka's group-management facilities. + If the client sends no heartbeats to the broker before the timeout expires, + the broker will remove the client from the group and initiate a rebalance. + Value must be between the broker's configured group.min.session.timeout.ms and group.max.session.timeout.ms. + See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_session.timeout.ms) for details. + """ + + rebalance_timeout: Annotated[ + Optional[float], pydantic.Field(alias="rebalanceTimeout") + ] = None + r""" + Maximum allowed time for each worker to join the group after a rebalance begins. If the timeout is exceeded, the coordinator broker will remove the worker from the group. See [Kafka's documentation](https://kafka.apache.org/documentation/#connectconfigs_rebalance.timeout.ms) for details. + """ + + heartbeat_interval: Annotated[ + Optional[float], pydantic.Field(alias="heartbeatInterval") + ] = None + r""" + Expected time between heartbeats to the consumer coordinator when using Kafka's group-management facilities. Value must be lower than sessionTimeout and typically should not exceed 1/3 of the sessionTimeout value. See [Kafka's documentation](https://kafka.apache.org/documentation/#consumerconfigs_heartbeat.interval.ms) for details. + """ + + auto_commit_interval: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitInterval") + ] = None + r"""How often to commit offsets. If both this and Offset commit threshold are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + auto_commit_threshold: Annotated[ + Optional[float], pydantic.Field(alias="autoCommitThreshold") + ] = None + r"""How many events are needed to trigger an offset commit. If both this and Offset commit interval are set, @{product} commits offsets when either condition is met. If both are empty, @{product} commits offsets after each batch.""" + + max_bytes_per_partition: Annotated[ + Optional[float], pydantic.Field(alias="maxBytesPerPartition") + ] = None + r"""Maximum amount of data that Kafka will return per partition, per fetch request. Must equal or exceed the maximum message size (maxBytesPerPartition) that Kafka is configured to allow. Otherwise, @{product} can get stuck trying to retrieve messages. Defaults to 1048576 (1 MB).""" + + max_bytes: Annotated[Optional[float], pydantic.Field(alias="maxBytes")] = None + r"""Maximum number of bytes that Kafka will return per fetch request. Defaults to 10485760 (10 MB).""" + + max_socket_errors: Annotated[ + Optional[float], pydantic.Field(alias="maxSocketErrors") + ] = None + r"""Maximum number of network errors before the consumer re-creates a socket""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") + ] = None + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + + template_topics: Annotated[ + Optional[str], pydantic.Field(alias="__template_topics") + ] = None + r"""Binds 'topics' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topics' at runtime.""" + + template_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_groupId") + ] = None + r"""Binds 'groupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'groupId' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "groupId", + "fromBeginning", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "sessionTimeout", + "rebalanceTimeout", + "heartbeatInterval", + "autoCommitInterval", + "autoCommitThreshold", + "maxBytesPerPartition", + "maxBytes", + "maxSocketErrors", + "metadata", + "autoParse", + "description", + "__template_environment", + "__template_streamtags", + "__template_brokers", + "__template_topics", + "__template_groupId", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputElasticType(str, Enum): + r"""Source type identifier.""" + + ELASTIC = "elastic" + + +try: + InputResponseSNMPv3Authentication.model_rebuild() +except NameError: + pass +try: + InputResponseInputSnmp.model_rebuild() +except NameError: + pass +try: + InputResponseInputS3Inventory.model_rebuild() +except NameError: + pass +try: + InputResponseInputS3.model_rebuild() +except NameError: + pass +try: + InputResponseInputMetrics.model_rebuild() +except NameError: + pass +try: + InputResponseInputCriblmetrics.model_rebuild() +except NameError: + pass +try: + InputResponseInputKinesis.model_rebuild() +except NameError: + pass +try: + InputResponseInputHTTPRawInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + InputResponseInputHTTPRawAuthTokensExt.model_rebuild() +except NameError: + pass +try: + InputResponseInputHTTPRaw.model_rebuild() +except NameError: + pass +try: + InputResponseSample.model_rebuild() +except NameError: + pass +try: + InputResponseInputDatagen.model_rebuild() +except NameError: + pass +try: + InputResponseInputDatadogAgentProxyMode.model_rebuild() +except NameError: + pass +try: + InputResponseInputDatadogAgent.model_rebuild() +except NameError: + pass +try: + InputResponseInputCrowdstrike.model_rebuild() +except NameError: + pass +try: + InputResponseInputWindowsMetricsCPU.model_rebuild() +except NameError: + pass +try: + InputResponseInputWindowsMetricsNetwork.model_rebuild() +except NameError: + pass +try: + InputResponseInputWindowsMetricsDisk.model_rebuild() +except NameError: + pass +try: + InputResponseInputWindowsMetricsPersistence.model_rebuild() +except NameError: + pass +try: + InputResponseInputWindowsMetrics.model_rebuild() +except NameError: + pass +try: + InputResponseInputKubeEvents.model_rebuild() +except NameError: + pass +try: + InputResponseInputKubeLogsRule.model_rebuild() +except NameError: + pass +try: + InputResponseInputKubeLogs.model_rebuild() +except NameError: + pass +try: + InputResponseInputKubeMetricsPersistence.model_rebuild() +except NameError: + pass +try: + InputResponseInputKubeMetrics.model_rebuild() +except NameError: + pass +try: + InputResponseCollectors.model_rebuild() +except NameError: + pass +try: + InputResponseInputSystemStatePersistence.model_rebuild() +except NameError: + pass +try: + InputResponseInputSystemState.model_rebuild() +except NameError: + pass +try: + InputResponseInputSystemMetricsCPU.model_rebuild() +except NameError: + pass +try: + InputResponseInputSystemMetricsNetwork.model_rebuild() +except NameError: + pass +try: + InputResponseInputSystemMetricsDisk.model_rebuild() +except NameError: + pass +try: + InputResponseContainer.model_rebuild() +except NameError: + pass +try: + InputResponseInputSystemMetricsPersistence.model_rebuild() +except NameError: + pass +try: + InputResponseInputSystemMetrics.model_rebuild() +except NameError: + pass +try: + InputResponseInputTcpjson.model_rebuild() +except NameError: + pass +try: + InputResponseInputHTTPAuthTypeSecretConstraintSplunkHecMetadata.model_rebuild() +except NameError: + pass +try: + InputResponseInputHTTPAuthTypeSecretConstraintElasticsearchMetadata.model_rebuild() +except NameError: + pass +try: + InputResponseInputCriblLakeHTTPInputHTTPAuthTypeSecretConstraint.model_rebuild() +except NameError: + pass +try: + InputResponseInputHTTPAuthTokensExtItemsTypeSplunkHecMetadata.model_rebuild() +except NameError: + pass +try: + InputResponseInputHTTPAuthTokensExtItemsTypeElasticsearchMetadata.model_rebuild() +except NameError: + pass +try: + InputResponseInputCriblLakeHTTPInputHTTPAuthTokensExtItemsType.model_rebuild() +except NameError: + pass +try: + InputResponseInputCriblLakeHTTP.model_rebuild() +except NameError: + pass +try: + InputResponseInputCriblHTTP.model_rebuild() +except NameError: + pass +try: + InputResponseInputCriblTCP.model_rebuild() +except NameError: + pass +try: + InputResponseInputCribl.model_rebuild() +except NameError: + pass +try: + InputResponseInputGooglePubsub.model_rebuild() +except NameError: + pass +try: + InputResponseInputFirehose.model_rebuild() +except NameError: + pass +try: + InputResponseInputExec.model_rebuild() +except NameError: + pass +try: + InputResponseCertificate.model_rebuild() +except NameError: + pass +try: + InputResponseAuth.model_rebuild() +except NameError: + pass +try: + InputResponseAzureBlobStorage.model_rebuild() +except NameError: + pass +try: + InputResponseCheckpointing.model_rebuild() +except NameError: + pass +try: + InputResponseInputEventhubAmqp.model_rebuild() +except NameError: + pass +try: + InputResponseInputEventhub.model_rebuild() +except NameError: + pass +try: + InputResponseInputMicrosoftGraph.model_rebuild() +except NameError: + pass +try: + InputResponseInputOffice365MsgTrace.model_rebuild() +except NameError: + pass +try: + InputResponseInputOffice365ServiceContentConfig.model_rebuild() +except NameError: + pass +try: + InputResponseInputOffice365Service.model_rebuild() +except NameError: + pass +try: + InputResponseInputOffice365MgmtContentConfig.model_rebuild() +except NameError: + pass +try: + InputResponseInputOffice365Mgmt.model_rebuild() +except NameError: + pass +try: + InputResponsePodFilter.model_rebuild() +except NameError: + pass +try: + InputResponseInputEdgePrometheus.model_rebuild() +except NameError: + pass +try: + InputResponseInputPrometheus.model_rebuild() +except NameError: + pass +try: + InputResponseInputPrometheusRw.model_rebuild() +except NameError: + pass +try: + InputResponseInputLoki.model_rebuild() +except NameError: + pass +try: + InputResponsePrometheusAuth2.model_rebuild() +except NameError: + pass +try: + InputResponseLokiAuth2.model_rebuild() +except NameError: + pass +try: + InputResponseInputGrafanaGrafana2.model_rebuild() +except NameError: + pass +try: + InputResponsePrometheusAuth1.model_rebuild() +except NameError: + pass +try: + InputResponseLokiAuth1.model_rebuild() +except NameError: + pass +try: + InputResponseInputGrafanaGrafana1.model_rebuild() +except NameError: + pass +try: + InputResponseInputConfluentCloud.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputresponse_inputkubemetrics.py b/src/cribl_control_plane/models/inputresponse_v3user.py similarity index 75% rename from src/cribl_control_plane/models/inputresponse_inputkubemetrics.py rename to src/cribl_control_plane/models/inputresponse_v3user.py index fbfbc44c9..c36f3bb81 100644 --- a/src/cribl_control_plane/models/inputresponse_inputkubemetrics.py +++ b/src/cribl_control_plane/models/inputresponse_v3user.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionsmanualsecret import ( AuthenticationMethodOptionsManualSecret, @@ -14,10 +14,6 @@ AuthTokenConfInputCloudflareHec, AuthTokenConfInputCloudflareHecTypedDict, ) -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, -) from .checkpointingtype import CheckpointingType, CheckpointingTypeTypedDict from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -26,11 +22,9 @@ from .datacompressionformatoptionspersistence import ( DataCompressionFormatOptionsPersistence, ) -from .diskspoolingtype import DiskSpoolingType, DiskSpoolingTypeTypedDict -from .gputype import GpuType, GpuTypeTypedDict -from .inputcollectionorigindatasourcediscoverywithdestinationarnconstraint import ( - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint, - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict, +from .inputprovenancetypeoptional import ( + InputProvenanceTypeOptional, + InputProvenanceTypeOptionalTypedDict, ) from .logleveloptions import LogLevelOptions from .logleveloptionscontentconfigitemsdebugerror import ( @@ -42,8 +36,7 @@ MetadataConfInputCollectionTypedDict, ) from .minimumtlsversionoptionstls import MinimumTLSVersionOptionsTLS -from .modeoptionshost import ModeOptionsHost -from .notification_union import NotificationUnion, NotificationUnionTypedDict +from .notification import Notification, NotificationTypedDict from .oauthheaderconfinputservicenowtable import ( OauthHeaderConfInputServicenowTable, OauthHeaderConfInputServicenowTableTypedDict, @@ -54,28 +47,27 @@ ) from .pqtype import PqType, PqTypeTypedDict from .preprocesstype import PreprocessType, PreprocessTypeTypedDict -from .processtype import ProcessType, ProcessTypeTypedDict from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, ) from .retryrulestype import RetryRulesType, RetryRulesTypeTypedDict -from .ruleconfinputkubemetrics import ( - RuleConfInputKubeMetrics, - RuleConfInputKubeMetricsTypedDict, +from .retrytypeoptionshealthcheckcollectorconfretryrules import ( + RetryTypeOptionsHealthCheckCollectorConfRetryRules, ) from .sqsauthenticationmethodoptions import SqsAuthenticationMethodOptions from .statustype import StatusType, StatusTypeTypedDict from .tagafterprocessingoptions import TagAfterProcessingOptions +from .tlssettingsclientsidetypecapathcertpath import ( + TLSSettingsClientSideTypeCaPathCertPath, + TLSSettingsClientSideTypeCaPathCertPathTypedDict, +) from .tlssettingsserversidetype import ( TLSSettingsServerSideType, TLSSettingsServerSideTypeTypedDict, ) -from .typeoptionskinesis import TypeOptionsKinesis from .typeoptionsnetflow import TypeOptionsNetflow -from .typeoptionss3 import TypeOptionsS3 from .typeoptionssecuritylake import TypeOptionsSecuritylake -from .typeoptionssnmp import TypeOptionsSnmp from .typeoptionssqs import TypeOptionsSqs from .typeoptionssyslog import TypeOptionsSyslog from cribl_control_plane import models, utils @@ -89,27 +81,21 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict -class InputResponseInputOktaType(str, Enum): - r"""Connector type identifier.""" - - OKTA = "okta" - - -class InputResponseInputOktaManageStateTypedDict(TypedDict): - pass - +class InputResponseInputTrendMicroVisionOneType(str, Enum): + r"""Source type identifier.""" -class InputResponseInputOktaManageState(BaseModel): - pass + TREND_MICRO_VISION_ONE = "trend_micro_vision_one" -class InputResponseInputOktaTypedDict(TypedDict): - type: InputResponseInputOktaType - r"""Connector type identifier.""" - okta_domain: str - r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" - text_secret: str - r"""Select or create a stored text secret""" +class InputResponseInputTrendMicroVisionOneTypedDict(TypedDict): + type: InputResponseInputTrendMicroVisionOneType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -124,60 +110,82 @@ class InputResponseInputOktaTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - okta_token: NotRequired[str] - r"""Your Okta API token for authentication""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - manage_state: NotRequired[InputResponseInputOktaManageStateTypedDict] - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_okta_domain: NotRequired[str] - r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputOkta(BaseModel): - type: InputResponseInputOktaType - r"""Connector type identifier.""" +class InputResponseInputTrendMicroVisionOne(BaseModel): + type: InputResponseInputTrendMicroVisionOneType + r"""Source type identifier.""" - okta_domain: Annotated[str, pydantic.Field(alias="oktaDomain")] - r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored text secret""" + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -203,7 +211,7 @@ class InputResponseInputOkta(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -213,54 +221,92 @@ class InputResponseInputOkta(BaseModel): pq: Optional[PqType] = None - okta_token: Annotated[Optional[str], pydantic.Field(alias="oktaToken")] = None - r"""Your Okta API token for authentication""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - manage_state: Annotated[ - Optional[InputResponseInputOktaManageState], pydantic.Field(alias="manageState") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -275,12 +321,37 @@ class InputResponseInputOkta(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_okta_domain: Annotated[ - Optional[str], pydantic.Field(alias="__template_oktaDomain") + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -300,23 +371,33 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "oktaToken", - "cronSchedule", - "earliest", - "latest", - "manageState", - "jobTimeout", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", "requestTimeout", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "retryRules", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", - "__template_oktaDomain", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", "notifications", "status", ] @@ -335,189 +416,325 @@ def serialize_model(self, handler): return m -class InputResponseInputAnthropicComplianceType(str, Enum): - r"""Connector type identifier.""" +class InputResponseInputMimecastHecType(str, Enum): + r"""Source type identifier.""" - ANTHROPIC_COMPLIANCE = "anthropic_compliance" + MIMECAST_HEC = "mimecast_hec" -class InputResponseActivitiesManageStateTypedDict(TypedDict): - pass +class InputResponseInputMimecastHecTypedDict(TypedDict): + type: InputResponseInputMimecastHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseActivitiesManageState(BaseModel): - pass +class InputResponseInputMimecastHec(BaseModel): + type: InputResponseInputMimecastHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" -class InputResponseActivitiesTypedDict(TypedDict): - r"""Activities""" + port: float + r"""Port to listen on""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[InputResponseActivitiesManageStateTypedDict] + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Mimecast HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + id: Optional[str] = None + r"""Unique ID for this input""" -class InputResponseActivities(BaseModel): - r"""Activities""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - enabled: Optional[bool] = None - r"""Enabled""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - manage_state: Annotated[ - Optional[InputResponseActivitiesManageState], - pydantic.Field(alias="manageState"), + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None + r"""Add request headers to events, in the __headers field""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - return m + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" -class InputResponseChatsManageStateTypedDict(TypedDict): - pass + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" -class InputResponseChatsManageState(BaseModel): - pass + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class InputResponseChatsTypedDict(TypedDict): - r"""Chats""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[InputResponseChatsManageStateTypedDict] + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" -class InputResponseChats(BaseModel): - r"""Chats""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - enabled: Optional[bool] = None - r"""Enabled""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - manage_state: Annotated[ - Optional[InputResponseChatsManageState], pydantic.Field(alias="manageState") + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", ] ) serialized = handler(self) @@ -534,183 +751,325 @@ def serialize_model(self, handler): return m -class InputResponseProjectsManageStateTypedDict(TypedDict): - pass +class InputResponseInputHashicorpHcpVaultDedicatedType(str, Enum): + r"""Source type identifier.""" + HASHICORP_HCP_VAULT_DEDICATED = "hashicorp_hcp_vault_dedicated" -class InputResponseProjectsManageState(BaseModel): - pass +class InputResponseInputHashicorpHcpVaultDedicatedTypedDict(TypedDict): + type: InputResponseInputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseProjectsTypedDict(TypedDict): - r"""Projects""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[InputResponseProjectsManageStateTypedDict] +class InputResponseInputHashicorpHcpVaultDedicated(BaseModel): + type: InputResponseInputHashicorpHcpVaultDedicatedType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" -class InputResponseProjects(BaseModel): - r"""Projects""" + port: float + r"""Port to listen on""" - enabled: Optional[bool] = None - r"""Enabled""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for HashiCorp HCP Vault Dedicated HTTP Event Collector API requests""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + id: Optional[str] = None + r"""Unique ID for this input""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Select whether to send data to Routes, or directly to Destinations.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - manage_state: Annotated[ - Optional[InputResponseProjectsManageState], pydantic.Field(alias="manageState") + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" - return m + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" -class InputResponseChatMessagesManageStateTypedDict(TypedDict): - pass + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class InputResponseChatMessagesManageState(BaseModel): - pass + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" -class InputResponseChatMessagesTypedDict(TypedDict): - r"""Chat Messages""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[InputResponseChatMessagesManageStateTypedDict] + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" -class InputResponseChatMessages(BaseModel): - r"""Chat Messages""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - enabled: Optional[bool] = None - r"""Enabled""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""JavaScript expression that defines how to update the state from an event""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - manage_state: Annotated[ - Optional[InputResponseChatMessagesManageState], - pydantic.Field(alias="manageState"), + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", ] ) serialized = handler(self) @@ -727,268 +1086,21 @@ def serialize_model(self, handler): return m -class InputResponseProjectDetailsManageStateTypedDict(TypedDict): - pass - - -class InputResponseProjectDetailsManageState(BaseModel): - pass +class InputResponseInputBeyondtrustHecType(str, Enum): + r"""Source type identifier.""" + BEYONDTRUST_HEC = "beyondtrust_hec" -class InputResponseProjectDetailsTypedDict(TypedDict): - r"""Project Details""" - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - earliest: NotRequired[str] - r"""Earliest time for data collection, relative to now""" - latest: NotRequired[str] - r"""Latest time for data collection, relative to now""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[InputResponseProjectDetailsManageStateTypedDict] - - -class InputResponseProjectDetails(BaseModel): - r"""Project Details""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - earliest: Optional[str] = None - r"""Earliest time for data collection, relative to now""" - - latest: Optional[str] = None - r"""Latest time for data collection, relative to now""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" - - manage_state: Annotated[ - Optional[InputResponseProjectDetailsManageState], - pydantic.Field(alias="manageState"), - ] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enabled", - "cronSchedule", - "earliest", - "latest", - "jobTimeout", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseGroupsTypedDict(TypedDict): - r"""Groups""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class InputResponseGroups(BaseModel): - r"""Groups""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseOrganizationsTypedDict(TypedDict): - r"""Organizations""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class InputResponseOrganizations(BaseModel): - r"""Organizations""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseOrganizationUsersTypedDict(TypedDict): - r"""Organization Users""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class InputResponseOrganizationUsers(BaseModel): - r"""Organization Users""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseOrganizationRolesTypedDict(TypedDict): - r"""Organization Roles""" - - enabled: NotRequired[bool] - r"""Enabled""" - cron_schedule: NotRequired[str] - r"""Schedule on which to run this collection job""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - -class InputResponseOrganizationRoles(BaseModel): - r"""Organization Roles""" - - enabled: Optional[bool] = None - r"""Enabled""" - - cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None - r"""Schedule on which to run this collection job""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputAnthropicComplianceTypedDict(TypedDict): - type: InputResponseInputAnthropicComplianceType - r"""Connector type identifier.""" - text_secret: str - r"""Select or create a stored Anthropic API key""" +class InputResponseInputBeyondtrustHecTypedDict(TypedDict): + type: InputResponseInputBeyondtrustHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -1003,68 +1115,78 @@ class InputResponseInputAnthropicComplianceTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - api_key: NotRequired[str] - r"""API key""" - activities: NotRequired[InputResponseActivitiesTypedDict] - r"""Activities""" - chats: NotRequired[InputResponseChatsTypedDict] - r"""Chats""" - projects: NotRequired[InputResponseProjectsTypedDict] - r"""Projects""" - chat_messages: NotRequired[InputResponseChatMessagesTypedDict] - r"""Chat Messages""" - project_details: NotRequired[InputResponseProjectDetailsTypedDict] - r"""Project Details""" - groups: NotRequired[InputResponseGroupsTypedDict] - r"""Groups""" - organizations: NotRequired[InputResponseOrganizationsTypedDict] - r"""Organizations""" - org_users: NotRequired[InputResponseOrganizationUsersTypedDict] - r"""Organization Users""" - org_roles: NotRequired[InputResponseOrganizationRolesTypedDict] - r"""Organization Roles""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputAnthropicCompliance(BaseModel): - type: InputResponseInputAnthropicComplianceType - r"""Connector type identifier.""" +class InputResponseInputBeyondtrustHec(BaseModel): + type: InputResponseInputBeyondtrustHecType + r"""Source type identifier.""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored Anthropic API key""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for BeyondTrust HTTP Event Collector API requests. BeyondTrust sends event payloads to the standard HEC endpoint.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -1090,7 +1212,7 @@ class InputResponseInputAnthropicCompliance(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -1100,75 +1222,87 @@ class InputResponseInputAnthropicCompliance(BaseModel): pq: Optional[PqType] = None - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" - - activities: Optional[InputResponseActivities] = None - r"""Activities""" - - chats: Optional[InputResponseChats] = None - r"""Chats""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - projects: Optional[InputResponseProjects] = None - r"""Projects""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - chat_messages: Optional[InputResponseChatMessages] = None - r"""Chat Messages""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - project_details: Optional[InputResponseProjectDetails] = None - r"""Project Details""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - groups: Optional[InputResponseGroups] = None - r"""Groups""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - organizations: Optional[InputResponseOrganizations] = None - r"""Organizations""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - org_users: Optional[InputResponseOrganizationUsers] = None - r"""Organization Users""" + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" - org_roles: Optional[InputResponseOrganizationRoles] = None - r"""Organization Roles""" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -1183,7 +1317,32 @@ class InputResponseInputAnthropicCompliance(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -1203,28 +1362,31 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "apiKey", - "activities", - "chats", - "projects", - "chat_messages", - "project_details", - "groups", - "organizations", - "org_users", - "org_roles", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", "requestTimeout", - "breakerRulesets", - "staleChannelFlushMs", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "retryRules", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", "notifications", "status", ] @@ -1243,38 +1405,21 @@ def serialize_model(self, handler): return m -class InputResponseInputOpenaiComplianceLogsType(str, Enum): - r"""Connector type identifier.""" - - OPENAI_COMPLIANCE_LOGS = "openai_compliance_logs" - - -class InputResponseAccountType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Account type""" - - # Workspace - WORKSPACE = "workspace" - # Organization - ORGANIZATION = "organization" - - -class InputResponseInputOpenaiComplianceLogsManageStateTypedDict(TypedDict): - pass - +class InputResponseInputF5BigIPType(str, Enum): + r"""Source type identifier.""" -class InputResponseInputOpenaiComplianceLogsManageState(BaseModel): - pass + F5_BIG_IP = "f5_big_ip" -class InputResponseInputOpenaiComplianceLogsTypedDict(TypedDict): - type: InputResponseInputOpenaiComplianceLogsType - r"""Connector type identifier.""" - text_secret: str - r"""Select or create a stored text secret""" - account_type: InputResponseAccountType - r"""Account type""" - cron_schedule: str - r"""Cron schedule""" +class InputResponseInputF5BigIPTypedDict(TypedDict): + type: InputResponseInputF5BigIPType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -1289,89 +1434,84 @@ class InputResponseInputOpenaiComplianceLogsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - api_key: NotRequired[str] - r"""API key""" - earliest: NotRequired[str] - r"""Relative to the current time. Format: [+|-]""" - latest: NotRequired[str] - r"""Relative to the current time. Format: [+|-]""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] - r"""Collector runtime log level""" - max_pages: NotRequired[float] - r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_alive_time: NotRequired[float] - r"""How often workers should check in with the scheduler to keep job subscription alive""" - max_missed_keep_alives: NotRequired[float] - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - ttl: NotRequired[str] - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - ignore_group_jobs_limit: NotRequired[bool] - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - retry_rules: NotRequired[RetryRulesTypeTypedDict] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - workspace_id: NotRequired[str] - r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" - workspace_event_types: NotRequired[List[str]] - r"""One or more compliance log categories to collect""" - organization_id: NotRequired[str] - r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" - organization_event_types: NotRequired[List[str]] - r"""One or more compliance log categories to collect""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[ - InputResponseInputOpenaiComplianceLogsManageStateTypedDict - ] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_workspace_id: NotRequired[str] - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_organization_id: NotRequired[str] - r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputOpenaiComplianceLogs(BaseModel): - type: InputResponseInputOpenaiComplianceLogsType - r"""Connector type identifier.""" +class InputResponseInputF5BigIP(BaseModel): + type: InputResponseInputF5BigIPType + r"""Source type identifier.""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored text secret""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - account_type: Annotated[ - InputResponseAccountType, pydantic.Field(alias="accountType") - ] - r"""Account type""" + port: float + r"""Port to listen on""" - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""Cron schedule""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for F5 BIG-IP HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -1397,7 +1537,7 @@ class InputResponseInputOpenaiComplianceLogs(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -1407,107 +1547,98 @@ class InputResponseInputOpenaiComplianceLogs(BaseModel): pq: Optional[PqType] = None - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" - - earliest: Optional[str] = None - r"""Relative to the current time. Format: [+|-]""" - - latest: Optional[str] = None - r"""Relative to the current time. Format: [+|-]""" - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItemsDebugError], - pydantic.Field(alias="logLevel"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Collector runtime log level""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Track collection progress between consecutive scheduled executions""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""How often workers should check in with the scheduler to keep job subscription alive""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - max_missed_keep_alives: Annotated[ - Optional[float], pydantic.Field(alias="maxMissedKeepAlives") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + r"""Add request headers to events, in the __headers field""" - ttl: Optional[str] = None - r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" - ignore_group_jobs_limit: Annotated[ - Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - retry_rules: Annotated[ - Optional[RetryRulesType], pydantic.Field(alias="retryRules") + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None - r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - workspace_event_types: Annotated[ - Optional[List[str]], pydantic.Field(alias="workspaceEventTypes") + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") ] = None - r"""One or more compliance log categories to collect""" + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - organization_id: Annotated[ - Optional[str], pydantic.Field(alias="organizationId") - ] = None - r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" - organization_event_types: Annotated[ - Optional[List[str]], pydantic.Field(alias="organizationEventTypes") + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""One or more compliance log categories to collect""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - manage_state: Annotated[ - Optional[InputResponseInputOpenaiComplianceLogsManageState], - pydantic.Field(alias="manageState"), - ] = None + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -1517,42 +1648,44 @@ class InputResponseInputOpenaiComplianceLogs(BaseModel): template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - template_workspace_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceId") + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") ] = None - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_organization_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_organizationId") + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None - r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("account_type") - def serialize_account_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseAccountType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItemsDebugError(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -1567,34 +1700,34 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "apiKey", - "earliest", - "latest", - "jobTimeout", - "logLevel", - "maxPages", - "stateTracking", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", "requestTimeout", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "retryRules", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", - "workspaceId", - "workspaceEventTypes", - "organizationId", - "organizationEventTypes", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", "__template_environment", "__template_streamtags", - "__template_workspaceId", - "__template_organizationId", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", "notifications", "status", ] @@ -1613,21 +1746,21 @@ def serialize_model(self, handler): return m -class InputResponseInputUpwindHecType(str, Enum): +class InputResponseInputVectraAiHecType(str, Enum): r"""Source type identifier.""" - UPWIND_HEC = "upwind_hec" + VECTRA_AI_HEC = "vectra_ai_hec" -class InputResponseInputUpwindHecTypedDict(TypedDict): - type: InputResponseInputUpwindHecType +class InputResponseInputVectraAiHecTypedDict(TypedDict): + type: InputResponseInputVectraAiHecType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -1642,9 +1775,7 @@ class InputResponseInputUpwindHecTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -1702,14 +1833,14 @@ class InputResponseInputUpwindHecTypedDict(TypedDict): r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" template_access_control_allow_headers: NotRequired[str] r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputUpwindHec(BaseModel): - type: InputResponseInputUpwindHecType +class InputResponseInputVectraAiHec(BaseModel): + type: InputResponseInputVectraAiHecType r"""Source type identifier.""" host: str @@ -1719,7 +1850,7 @@ class InputResponseInputUpwindHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -1745,7 +1876,7 @@ class InputResponseInputUpwindHec(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -1885,7 +2016,7 @@ class InputResponseInputUpwindHec(BaseModel): ] = None r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -1950,21 +2081,21 @@ def serialize_model(self, handler): return m -class InputResponseInputSysdigHecType(str, Enum): +class InputResponseInputGigamonHecType(str, Enum): r"""Source type identifier.""" - SYSDIG_HEC = "sysdig_hec" + GIGAMON_HEC = "gigamon_hec" -class InputResponseInputSysdigHecTypedDict(TypedDict): - type: InputResponseInputSysdigHecType +class InputResponseInputGigamonHecTypedDict(TypedDict): + type: InputResponseInputGigamonHecType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -1979,9 +2110,7 @@ class InputResponseInputSysdigHecTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -2039,14 +2168,14 @@ class InputResponseInputSysdigHecTypedDict(TypedDict): r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" template_access_control_allow_headers: NotRequired[str] r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputSysdigHec(BaseModel): - type: InputResponseInputSysdigHecType +class InputResponseInputGigamonHec(BaseModel): + type: InputResponseInputGigamonHecType r"""Source type identifier.""" host: str @@ -2056,7 +2185,7 @@ class InputResponseInputSysdigHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + r"""Absolute path on which to listen for Gigamon HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -2082,7 +2211,7 @@ class InputResponseInputSysdigHec(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -2222,183 +2351,55 @@ class InputResponseInputSysdigHec(BaseModel): ] = None r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "ipAllowlistRegex", - "ipDenylistRegex", - "metadata", - "allowedIndexes", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "emitTokenMetrics", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_hecAPI", - "__template_allowedIndexes", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputCloudflareHecType(str, Enum): - r"""Source type identifier.""" - - CLOUDFLARE_HEC = "cloudflare_hec" - - -class InputResponseTLSSettingsServerSideTypedDict(TypedDict): - r"""TLS settings (server side)""" - - disabled: NotRequired[bool] - r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - request_cert: NotRequired[bool] - r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" - common_name_regex: NotRequired[str] - r"""Regex matching allowable common names in peer certificates' subject attribute""" - certificate_name: NotRequired[str] - r"""The name of the predefined certificate""" - priv_key_path: NotRequired[str] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - cert_path: NotRequired[str] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - ca_path: NotRequired[str] - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - min_version: NotRequired[MinimumTLSVersionOptionsTLS] - r"""Minimum TLS version""" - max_version: NotRequired[MaximumTLSVersionOptionsTLS] - r"""Maximum TLS version""" - - -class InputResponseTLSSettingsServerSide(BaseModel): - r"""TLS settings (server side)""" - - disabled: Optional[bool] = None - r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - - request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None - r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" - - common_name_regex: Annotated[ - Optional[str], pydantic.Field(alias="commonNameRegex") - ] = None - r"""Regex matching allowable common names in peer certificates' subject attribute""" - - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") - ] = None - r"""The name of the predefined certificate""" - - priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" - - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" - - cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" - - ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - - min_version: Annotated[ - Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") - ] = None - r"""Minimum TLS version""" - - max_version: Annotated[ - Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") - ] = None - r"""Maximum TLS version""" - - @field_serializer("min_version") - def serialize_min_version(self, value): - if isinstance(value, str): - try: - return models.MinimumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value - - @field_serializer("max_version") - def serialize_max_version(self, value): - if isinstance(value, str): - try: - return models.MaximumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ + "id", "disabled", - "requestCert", - "rejectUnauthorized", - "commonNameRegex", - "certificateName", - "privKeyPath", - "passphrase", - "certPath", - "caPath", - "minVersion", - "maxVersion", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", ] ) serialized = handler(self) @@ -2415,15 +2416,21 @@ def serialize_model(self, handler): return m -class InputResponseInputCloudflareHecTypedDict(TypedDict): - type: InputResponseInputCloudflareHecType +class InputResponseInputPingIdentityPingoneType(str, Enum): + r"""Source type identifier.""" + + PING_IDENTITY_PINGONE = "ping_identity_pingone" + + +class InputResponseInputPingIdentityPingoneTypedDict(TypedDict): + type: InputResponseInputPingIdentityPingoneType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -2438,16 +2445,14 @@ class InputResponseInputCloudflareHecTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[InputResponseTLSSettingsServerSideTypedDict] + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" @@ -2480,10 +2485,6 @@ class InputResponseInputCloudflareHecTypedDict(TypedDict): r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" emit_token_metrics: NotRequired[bool] r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -2502,14 +2503,14 @@ class InputResponseInputCloudflareHecTypedDict(TypedDict): r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" template_access_control_allow_headers: NotRequired[str] r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputCloudflareHec(BaseModel): - type: InputResponseInputCloudflareHecType +class InputResponseInputPingIdentityPingone(BaseModel): + type: InputResponseInputPingIdentityPingoneType r"""Source type identifier.""" host: str @@ -2519,7 +2520,7 @@ class InputResponseInputCloudflareHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Ping Identity PingOne HTTP Event Collector API requests. PingOne posts structured JSON webhooks to the /event endpoint.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -2545,7 +2546,7 @@ class InputResponseInputCloudflareHec(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -2561,7 +2562,7 @@ class InputResponseInputCloudflareHec(BaseModel): ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: Optional[InputResponseTLSSettingsServerSide] = None + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( @@ -2642,16 +2643,6 @@ class InputResponseInputCloudflareHec(BaseModel): ] = None r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -2695,7 +2686,7 @@ class InputResponseInputCloudflareHec(BaseModel): ] = None r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -2733,8 +2724,6 @@ def serialize_model(self, handler): "accessControlAllowOrigin", "accessControlAllowHeaders", "emitTokenMetrics", - "breakerRulesets", - "staleChannelFlushMs", "description", "__template_environment", "__template_streamtags", @@ -2762,100 +2751,21 @@ def serialize_model(self, handler): return m -class InputResponseInputZscalerHecType(str, Enum): +class InputResponseInputAkamaiHecType(str, Enum): r"""Source type identifier.""" - ZSCALER_HEC = "zscaler_hec" - - -class InputResponseInputZscalerHecAuthTokenTypedDict(TypedDict): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - token_secret: NotRequired[str] - r"""Select or create a stored text secret""" - enabled: NotRequired[bool] - r"""Enable token""" - description: NotRequired[str] - r"""Description""" - allowed_indexes_at_token: NotRequired[List[str]] - r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this token""" - - -class InputResponseInputZscalerHecAuthToken(BaseModel): - token: str - r"""Shared secret to be provided by any client (Authorization: )""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None - r"""Select or create a stored text secret""" - - enabled: Optional[bool] = None - r"""Enable token""" - - description: Optional[str] = None - r"""Description""" - - allowed_indexes_at_token: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") - ] = None - r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this token""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "authType", - "tokenSecret", - "enabled", - "description", - "allowedIndexesAtToken", - "metadata", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m + AKAMAI_HEC = "akamai_hec" -class InputResponseInputZscalerHecTypedDict(TypedDict): - type: InputResponseInputZscalerHecType +class InputResponseInputAkamaiHecTypedDict(TypedDict): + type: InputResponseInputAkamaiHecType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" hec_api: str - r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -2870,14 +2780,12 @@ class InputResponseInputZscalerHecTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[InputResponseInputZscalerHecAuthTokenTypedDict]] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" @@ -2904,16 +2812,8 @@ class InputResponseInputZscalerHecTypedDict(TypedDict): r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - allowed_indexes: NotRequired[List[str]] - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - access_control_allow_origin: NotRequired[List[str]] - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - access_control_allow_headers: NotRequired[List[str]] - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - emit_token_metrics: NotRequired[bool] - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" hec_acks: NotRequired[bool] - r"""Whether to enable Zscaler HEC acknowledgements""" + r"""Whether to enable HEC indexer acknowledgements""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -2926,20 +2826,14 @@ class InputResponseInputZscalerHecTypedDict(TypedDict): r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_hec_api: NotRequired[str] r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_allowed_indexes: NotRequired[str] - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - template_access_control_allow_origin: NotRequired[str] - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_access_control_allow_headers: NotRequired[str] - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputZscalerHec(BaseModel): - type: InputResponseInputZscalerHecType +class InputResponseInputAkamaiHec(BaseModel): + type: InputResponseInputAkamaiHecType r"""Source type identifier.""" host: str @@ -2949,7 +2843,7 @@ class InputResponseInputZscalerHec(BaseModel): r"""Port to listen on""" hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] - r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" + r"""Absolute path on which to listen for Akamai DataStream 2 HTTP Event Collector API requests. Akamai delivers to the /raw endpoint beneath this path.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -2975,7 +2869,7 @@ class InputResponseInputZscalerHec(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -2986,7 +2880,7 @@ class InputResponseInputZscalerHec(BaseModel): pq: Optional[PqType] = None auth_tokens: Annotated[ - Optional[List[InputResponseInputZscalerHecAuthToken]], + Optional[List[AuthTokenConfInputCloudflareHec]], pydantic.Field(alias="authTokens"), ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -3052,28 +2946,8 @@ class InputResponseInputZscalerHec(BaseModel): metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - allowed_indexes: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedIndexes") - ] = None - r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - - access_control_allow_origin: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") - ] = None - r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - - access_control_allow_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") - ] = None - r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - - emit_token_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="emitTokenMetrics") - ] = None - r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None - r"""Whether to enable Zscaler HEC acknowledgements""" + r"""Whether to enable HEC indexer acknowledgements""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -3103,22 +2977,7 @@ class InputResponseInputZscalerHec(BaseModel): ] = None r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_allowed_indexes: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedIndexes") - ] = None - r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - - template_access_control_allow_origin: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") - ] = None - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - - template_access_control_allow_headers: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") - ] = None - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -3152,10 +3011,6 @@ def serialize_model(self, handler): "ipAllowlistRegex", "ipDenylistRegex", "metadata", - "allowedIndexes", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "emitTokenMetrics", "hecAcks", "description", "__template_environment", @@ -3163,9 +3018,6 @@ def serialize_model(self, handler): "__template_host", "__template_port", "__template_hecAPI", - "__template_allowedIndexes", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", "notifications", "status", ] @@ -3181,67 +3033,30 @@ def serialize_model(self, handler): if val is not None or k not in optional_fields: m[k] = val - return m - - -class InputResponseInputServicenowTableType(str, Enum): - r"""Connector type identifier.""" - - SERVICENOW_TABLE = "servicenow_table" - - -class InputResponseSortDirection(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Used only when Sort by field is set.""" - - # Ascending - ASC = "asc" - # Descending - DESC = "desc" - - -class InputResponseInputServicenowTableAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""ServiceNow Table API authentication method""" - - # None - NONE = "none" - # Basic - BASIC_SECRET = "basicSecret" - # OAuth - OAUTH_SECRET = "oauthSecret" + return m -class InputResponseGrantType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""ServiceNow OAuth grant type used for token requests""" +class InputResponseInputOktaType(str, Enum): + r"""Connector type identifier.""" - # Password - CLIENT_CREDENTIALS = "client_credentials" - # Client credentials - PASSWORD = "password" + OKTA = "okta" -class InputResponseInputServicenowTableManageStateTypedDict(TypedDict): +class InputResponseInputOktaManageStateTypedDict(TypedDict): pass -class InputResponseInputServicenowTableManageState(BaseModel): +class InputResponseInputOktaManageState(BaseModel): pass -class InputResponseInputServicenowTableTypedDict(TypedDict): - type: InputResponseInputServicenowTableType +class InputResponseInputOktaTypedDict(TypedDict): + type: InputResponseInputOktaType r"""Connector type identifier.""" - instance: str - r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - table_name: str - r"""ServiceNow table name to collect from.""" - cron_schedule: str - r"""Cron schedule on which to run this job""" - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + okta_domain: str + r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" + text_secret: str + r"""Select or create a stored text secret""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -3256,41 +3071,26 @@ class InputResponseInputServicenowTableTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - fields: NotRequired[List[str]] - r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - order_by_field: NotRequired[str] - r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" - order_by_direction: NotRequired[InputResponseSortDirection] - r"""Used only when Sort by field is set.""" - query: NotRequired[str] - r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" - page_size: NotRequired[int] - r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" - max_pages: NotRequired[int] - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - auth_type: NotRequired[InputResponseInputServicenowTableAuthenticationType] - r"""ServiceNow Table API authentication method""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - log_level: NotRequired[LogLevelOptions] - r"""Collector runtime log level""" + okta_token: NotRequired[str] + r"""Your Okta API token for authentication""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + manage_state: NotRequired[InputResponseInputOktaManageStateTypedDict] + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" request_timeout: NotRequired[float] r"""HTTP request inactivity timeout. Use 0 to disable.""" - use_round_robin_dns: NotRequired[bool] - r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" keep_alive_time: NotRequired[float] r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" max_missed_keep_alives: NotRequired[float] r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" ttl: NotRequired[str] @@ -3302,67 +3102,27 @@ class InputResponseInputServicenowTableTypedDict(TypedDict): retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - oauth_grant_type: NotRequired[InputResponseGrantType] - r"""ServiceNow OAuth grant type used for token requests""" - username: NotRequired[str] - r"""ServiceNow username for the password grant type""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret for the ServiceNow password value""" - use_custom_o_auth_params_or_headers: NotRequired[bool] - r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - client_id: NotRequired[str] - r"""ServiceNow OAuth client ID""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret for the OAuth client secret value""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[InputResponseInputServicenowTableManageStateTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_instance: NotRequired[str] - r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - template_order_by_field: NotRequired[str] - r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - template_query: NotRequired[str] - r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" - template_username: NotRequired[str] - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_okta_domain: NotRequired[str] + r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputServicenowTable(BaseModel): - type: InputResponseInputServicenowTableType +class InputResponseInputOkta(BaseModel): + type: InputResponseInputOktaType r"""Connector type identifier.""" - instance: str - r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - - table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""ServiceNow table name to collect from.""" - - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""Cron schedule on which to run this job""" - - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + okta_domain: Annotated[str, pydantic.Field(alias="oktaDomain")] + r"""Your Okta domain (example: your-org). Do not include .okta.com, https://, or trailing slashes.""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" id: Optional[str] = None r"""Unique ID for this input""" @@ -3388,7 +3148,7 @@ class InputResponseInputServicenowTable(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -3398,67 +3158,35 @@ class InputResponseInputServicenowTable(BaseModel): pq: Optional[PqType] = None - fields: Optional[List[str]] = None - r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - - order_by_field: Annotated[Optional[str], pydantic.Field(alias="orderByField")] = ( - None - ) - r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" - - order_by_direction: Annotated[ - Optional[InputResponseSortDirection], pydantic.Field(alias="orderByDirection") - ] = None - r"""Used only when Sort by field is set.""" - - query: Optional[str] = None - r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + okta_token: Annotated[Optional[str], pydantic.Field(alias="oktaToken")] = None + r"""Your Okta API token for authentication""" - page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None - r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - auth_type: Annotated[ - Optional[InputResponseInputServicenowTableAuthenticationType], - pydantic.Field(alias="authType"), + manage_state: Annotated[ + Optional[InputResponseInputOktaManageState], pydantic.Field(alias="manageState") ] = None - r"""ServiceNow Table API authentication method""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" - log_level: Annotated[ - Optional[LogLevelOptions], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime log level""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None r"""HTTP request inactivity timeout. Use 0 to disable.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" - keep_alive_time: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTime") ] = None r"""How often workers should check in with the scheduler to keep job subscription alive""" - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - max_missed_keep_alives: Annotated[ Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None @@ -3482,62 +3210,6 @@ class InputResponseInputServicenowTable(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - oauth_grant_type: Annotated[ - Optional[InputResponseGrantType], pydantic.Field(alias="oauthGrantType") - ] = None - r"""ServiceNow OAuth grant type used for token requests""" - - username: Optional[str] = None - r"""ServiceNow username for the password grant type""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret for the ServiceNow password value""" - - use_custom_o_auth_params_or_headers: Annotated[ - Optional[bool], pydantic.Field(alias="useCustomOAuthParamsOrHeaders") - ] = None - r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""ServiceNow OAuth client ID""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret for the OAuth client secret value""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - - manage_state: Annotated[ - Optional[InputResponseInputServicenowTableManageState], - pydantic.Field(alias="manageState"), - ] = None - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -3546,75 +3218,19 @@ class InputResponseInputServicenowTable(BaseModel): template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_instance: Annotated[ - Optional[str], pydantic.Field(alias="__template_instance") - ] = None - r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - - template_order_by_field: Annotated[ - Optional[str], pydantic.Field(alias="__template_orderByField") - ] = None - r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - - template_query: Annotated[ - Optional[str], pydantic.Field(alias="__template_query") - ] = None - r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" - - template_username: Annotated[ - Optional[str], pydantic.Field(alias="__template_username") - ] = None - r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") + template_okta_domain: Annotated[ + Optional[str], pydantic.Field(alias="__template_oktaDomain") ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + r"""Binds 'oktaDomain' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oktaDomain' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("order_by_direction") - def serialize_order_by_direction(self, value): - if isinstance(value, str): - try: - return models.InputResponseSortDirection(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputServicenowTableAuthenticationType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("oauth_grant_type") - def serialize_oauth_grant_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseGrantType(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -3629,45 +3245,23 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "fields", - "orderByField", - "orderByDirection", - "query", - "pageSize", - "maxPages", - "rejectUnauthorized", - "authType", - "stateTracking", - "logLevel", + "oktaToken", + "cronSchedule", + "earliest", + "latest", + "manageState", + "jobTimeout", "requestTimeout", - "useRoundRobinDns", "keepAliveTime", - "jobTimeout", "maxMissedKeepAlives", "ttl", "ignoreGroupJobsLimit", "metadata", "retryRules", "description", - "credentialsSecret", - "oauthGrantType", - "username", - "textSecret", - "useCustomOAuthParamsOrHeaders", - "oauthParams", - "oauthHeaders", - "clientId", - "clientTextSecret", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", "__template_environment", "__template_streamtags", - "__template_instance", - "__template_orderByField", - "__template_query", - "__template_username", - "__template_clientId", + "__template_oktaDomain", "notifications", "status", ] @@ -3686,17 +3280,176 @@ def serialize_model(self, handler): return m -class InputResponseInputBedrockS3Type(str, Enum): +class InputResponseInputMicrosoftCopilotType(str, Enum): r"""Connector type identifier.""" - BEDROCK_S3 = "bedrock_s3" + MICROSOFT_COPILOT = "microsoft_copilot" -class InputResponseInputBedrockS3TypedDict(TypedDict): - type: InputResponseInputBedrockS3Type +class InputResponseInputMicrosoftCopilotAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select authentication method.""" + + OAUTH_SECRET = "oauthSecret" + OAUTH_CERT = "oauthCert" + + +class InputResponseInputMicrosoftCopilotSubscriptionPlan( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + + ENTERPRISE_GCC = "enterprise_gcc" + GCC = "gcc" + GCC_HIGH = "gcc_high" + DOD = "dod" + + +class InputResponseInputMicrosoftCopilotManageStateTypedDict(TypedDict): + pass + + +class InputResponseInputMicrosoftCopilotManageState(BaseModel): + pass + + +class InputResponseRetryRulesTypedDict(TypedDict): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + interval: NotRequired[float] + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + limit: NotRequired[float] + r"""The maximum number of times to retry a failed HTTP request""" + multiplier: NotRequired[float] + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + codes: NotRequired[List[float]] + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + enable_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + retry_connect_timeout: NotRequired[bool] + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + retry_connect_reset: NotRequired[bool] + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + +class InputResponseRetryRules(BaseModel): + type: RetryTypeOptionsHealthCheckCollectorConfRetryRules + r"""The algorithm to use when performing HTTP retries""" + + interval: Optional[float] = None + r"""Time interval between failed request and first retry (kickoff). Maximum allowed value is 20,000 ms (1/3 minute).""" + + limit: Optional[float] = None + r"""The maximum number of times to retry a failed HTTP request""" + + multiplier: Optional[float] = None + r"""Base for exponential backoff, e.g., base 2 means that retries will occur after 2, then 4, then 8 seconds, and so on""" + + codes: Optional[List[float]] = None + r"""List of HTTP codes that trigger a retry. Leave empty to use the default list of 429, 500, and 503.""" + + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( + None + ) + r"""Honor any Retry-After header that specifies a delay (in seconds) or a timestamp after which to retry the request. The delay is limited to 20 seconds, even if the Retry-After header specifies a longer delay. When disabled, all Retry-After headers are ignored.""" + + retry_connect_timeout: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectTimeout") + ] = None + r"""Make a single retry attempt when a connection timeout (ETIMEDOUT) error occurs""" + + retry_connect_reset: Annotated[ + Optional[bool], pydantic.Field(alias="retryConnectReset") + ] = None + r"""Retry request when a connection reset (ECONNRESET) error occurs""" + + @field_serializer("type") + def serialize_type(self, value): + if isinstance(value, str): + try: + return models.RetryTypeOptionsHealthCheckCollectorConfRetryRules(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "interval", + "limit", + "multiplier", + "codes", + "enableHeader", + "retryConnectTimeout", + "retryConnectReset", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseCertOptionsTypedDict(TypedDict): + priv_key_path: str + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + cert_path: str + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + certificate_name: NotRequired[str] + r"""The name of a predefined certificate""" + passphrase: NotRequired[str] + r"""Passphrase to decrypt the private key""" + + +class InputResponseCertOptions(BaseModel): + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path to the private key (PEM format). Can reference $ENV_VARS.""" + + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path to the certificate (PEM format). Can reference $ENV_VARS.""" + + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The name of a predefined certificate""" + + passphrase: Optional[str] = None + r"""Passphrase to decrypt the private key""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["certificateName", "passphrase"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputMicrosoftCopilotTypedDict(TypedDict): + type: InputResponseInputMicrosoftCopilotType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + tenant_id: str + r"""Directory (tenant) ID from Azure Active Directory""" + client_id: str + r"""Application (client) ID from the app registration""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -3711,133 +3464,81 @@ class InputResponseInputBedrockS3TypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + resource: NotRequired[str] + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" + auth_type: NotRequired[InputResponseInputMicrosoftCopilotAuthenticationMethod] + r"""Select authentication method.""" + plan_type: NotRequired[InputResponseInputMicrosoftCopilotSubscriptionPlan] + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" + cron_schedule: NotRequired[str] + r"""Cron schedule for collection runs""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + page_size: NotRequired[int] + r"""Number of interactions to request per page ($top). Maximum 1000.""" + app_class_filter: NotRequired[List[str]] + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" + filter_by_license: NotRequired[bool] + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" + sku_ids: NotRequired[List[str]] + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" + manage_state: NotRequired[InputResponseInputMicrosoftCopilotManageStateTypedDict] + timeout: NotRequired[float] + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + retry_rules: NotRequired[InputResponseRetryRulesTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + text_secret: NotRequired[str] + r"""Select or create a secret that references the client secret from your app registration""" + cert_options: NotRequired[InputResponseCertOptionsTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_plan_type: NotRequired[str] + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputBedrockS3(BaseModel): - type: InputResponseInputBedrockS3Type +class InputResponseInputMicrosoftCopilot(BaseModel): + type: InputResponseInputMicrosoftCopilotType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Directory (tenant) ID from Azure Active Directory""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""Application (client) ID from the app registration""" id: Optional[str] = None r"""Unique ID for this input""" @@ -3863,7 +3564,7 @@ class InputResponseInputBedrockS3(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -3873,284 +3574,149 @@ class InputResponseInputBedrockS3(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + resource: Optional[str] = None + r"""Microsoft Graph resource URI used in the OAuth token request scope parameter. Derived automatically from the selected plan type.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + auth_type: Annotated[ + Optional[InputResponseInputMicrosoftCopilotAuthenticationMethod], + pydantic.Field(alias="authType"), ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + r"""Select authentication method.""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + plan_type: Annotated[ + Optional[InputResponseInputMicrosoftCopilotSubscriptionPlan], + pydantic.Field(alias="planType"), ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Microsoft 365 subscription plan for your organization, typically Microsoft 365 Enterprise.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Cron schedule for collection runs""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None + r"""Number of interactions to request per page ($top). Maximum 1000.""" - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") + app_class_filter: Annotated[ + Optional[List[str]], pydantic.Field(alias="appClassFilter") ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + r"""Limit collection to specific Copilot app classes. Leave empty to collect all.""" - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + filter_by_license: Annotated[ + Optional[bool], pydantic.Field(alias="filterByLicense") ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + r"""Add a $filter to the /users call for assigned Copilot SKUs. This reduces unnecessary API calls by excluding unlicensed users during discovery rather than skipping them at collection time.""" - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + sku_ids: Annotated[Optional[List[str]], pydantic.Field(alias="skuIds")] = None + r"""Microsoft 365 SKU GUIDs that grant access to the Copilot Interaction Export API. During discovery, users are filtered to those with at least one of these SKUs in their assignedLicenses. Pre-populated with known Copilot SKUs; add custom entries for tenant-specific or new plans.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + manage_state: Annotated[ + Optional[InputResponseInputMicrosoftCopilotManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + timeout: Optional[float] = None + r"""HTTP request inactivity timeout, in seconds. Enter 0 to wait indefinitely.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""External ID to use when assuming role""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Use the same settings for S3 and SQS""" - - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" - - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - - checkpointing: Optional[CheckpointingType] = None - - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" - - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" - - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None - - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") + retry_rules: Annotated[ + Optional[InputResponseRetryRules], pydantic.Field(alias="retryRules") ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a secret that references the client secret from your app registration""" + + cert_options: Annotated[ + Optional[InputResponseCertOptions], pydantic.Field(alias="certOptions") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + template_plan_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_planType") ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + r"""Binds 'planType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'planType' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.SqsAuthenticationMethodOptions(value) + return models.InputResponseInputMicrosoftCopilotAuthenticationMethod( + value + ) except ValueError: return value return value - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): + @field_serializer("plan_type") + def serialize_plan_type(self, value): if isinstance(value, str): try: - return models.TagAfterProcessingOptions(value) + return models.InputResponseInputMicrosoftCopilotSubscriptionPlan(value) except ValueError: return value return value @@ -4169,61 +3735,35 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", + "resource", + "authType", + "planType", + "cronSchedule", + "earliest", + "latest", + "pageSize", + "appClassFilter", + "filterByLicense", + "skuIds", + "manageState", + "timeout", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", "breakerRulesets", "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", + "textSecret", + "certOptions", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "__template_tenantId", + "__template_clientId", + "__template_planType", "notifications", "status", ] @@ -4242,152 +3782,232 @@ def serialize_model(self, handler): return m -class InputResponseInputSecurityLakeTypedDict(TypedDict): - type: TypeOptionsSecuritylake +class InputResponseInputAnthropicEnterpriseAnalyticsType(str, Enum): r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + ANTHROPIC_ENTERPRISE_ANALYTICS = "anthropic_enterprise_analytics" + + +class InputResponseContentType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Content type""" + + USAGE_REPORT = "Usage Report" + COST_REPORT = "Cost Report" + + +class InputResponseGroupBy(str, Enum, metaclass=utils.OpenEnumMeta): + MODEL = "model" + PRODUCT = "product" + CONTEXT_WINDOW = "context_window" + INFERENCE_GEO = "inference_geo" + SPEED = "speed" + RBAC_GROUP_ID = "rbac_group_id" + SLACK_CHANNEL_ID = "slack_channel_id" + TEAMS_CHANNEL_ID = "teams_channel_id" + COST_TYPE = "cost_type" + TOKEN_TYPE = "token_type" + + +class InputResponseBucketWidth(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + + # Daily (1d) + ONED = "1d" + # Hourly (1h) + ONEH = "1h" + # Per-minute (1m) + ONEM = "1m" + + +class InputResponseInputAnthropicEnterpriseAnalyticsContentConfigTypedDict(TypedDict): + content_type: InputResponseContentType + r"""Content type""" + cron_schedule: str + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + disabled: NotRequired[bool] + r"""Enabled""" + state_tracking: NotRequired[bool] + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + state_update_expression: NotRequired[str] + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" + manage_state: NotRequired[bool] + r"""Manage state""" + group_by: NotRequired[List[InputResponseGroupBy]] + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" + bucket_width: NotRequired[InputResponseBucketWidth] + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + +class InputResponseInputAnthropicEnterpriseAnalyticsContentConfig(BaseModel): + content_type: Annotated[ + InputResponseContentType, pydantic.Field(alias="contentType") + ] + r"""Content type""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule for collection runs. The API refreshes data approximately every 4 hours, so polling more frequently will not yield new results.""" + + disabled: Optional[bool] = None + r"""Enabled""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between runs. When enabled, each run resumes from where the last one left off, preventing duplicate data. The API refreshes approximately every 4 hours; runs between refreshes produce zero events until new finalized data becomes available. This is expected behavior.""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression evaluated per event to compute new state. The default tracks the data_refreshed_at watermark reported by the API.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression to merge state across distributed Workers. The default keeps the most recent watermark.""" + + manage_state: Annotated[Optional[bool], pydantic.Field(alias="manageState")] = None + r"""Manage state""" + + group_by: Annotated[ + Optional[List[InputResponseGroupBy]], pydantic.Field(alias="groupBy") + ] = None + r"""Dimensions for breaking down usage. Leave empty to collect a single summed row per time bucket.""" + + bucket_width: Annotated[ + Optional[InputResponseBucketWidth], pydantic.Field(alias="bucketWidth") + ] = None + r"""Time bucket size for aggregated results. Smaller buckets yield more events per collection run.""" + + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now. Used as the initial lower bound on first run before any state exists. Maximum 365 days (API limit). Examples: -7d@d, -24h, -30d.""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @field_serializer("content_type") + def serialize_content_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseContentType(value) + except ValueError: + return value + return value + + @field_serializer("bucket_width") + def serialize_bucket_width(self, value): + if isinstance(value, str): + try: + return models.InputResponseBucketWidth(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "groupBy", + "bucketWidth", + "earliest", + "jobTimeout", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputAnthropicEnterpriseAnalyticsTypedDict(TypedDict): + type: InputResponseInputAnthropicEnterpriseAnalyticsType + r"""Connector type identifier.""" + text_secret: str + r"""Select or create a stored API key with read:analytics scope""" + content_config: List[ + InputResponseInputAnthropicEnterpriseAnalyticsContentConfigTypedDict + ] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + api_key: NotRequired[str] + r"""API key""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputSecurityLake(BaseModel): - type: TypeOptionsSecuritylake +class InputResponseInputAnthropicEnterpriseAnalytics(BaseModel): + type: InputResponseInputAnthropicEnterpriseAnalyticsType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored API key with read:analytics scope""" + + content_config: Annotated[ + List[InputResponseInputAnthropicEnterpriseAnalyticsContentConfig], + pydantic.Field(alias="contentConfig"), + ] + r"""Analytics endpoints to collect from. Each content type runs on its own schedule as a separate collection job.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -4413,7 +4033,7 @@ class InputResponseInputSecurityLake(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -4423,40 +4043,13 @@ class InputResponseInputSecurityLake(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -4468,314 +4061,278 @@ class InputResponseInputSecurityLake(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""External ID to use when assuming role""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "apiKey", + "requestTimeout", + "breakerRulesets", + "staleChannelFlushMs", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + return m - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" +class InputResponseInputAnthropicComplianceType(str, Enum): + r"""Connector type identifier.""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + ANTHROPIC_COMPLIANCE = "anthropic_compliance" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" +class InputResponseActivitiesManageStateTypedDict(TypedDict): + pass - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: Optional[CheckpointingType] = None +class InputResponseActivitiesManageState(BaseModel): + pass - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" +class InputResponseActivitiesTypedDict(TypedDict): + r"""Activities""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseActivitiesManageStateTypedDict] - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" +class InputResponseActivities(BaseModel): + r"""Activities""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" + enabled: Optional[bool] = None + r"""Enabled""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Select or create a stored secret that references your access key and secret key""" + r"""Track collection progress between consecutive scheduled executions""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""SQS secret key""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") + manage_state: Annotated[ + Optional[InputResponseActivitiesManageState], + pydantic.Field(alias="manageState"), ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + return m - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" +class InputResponseChatsManageStateTypedDict(TypedDict): + pass - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" +class InputResponseChatsManageState(BaseModel): + pass - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" +class InputResponseChatsTypedDict(TypedDict): + r"""Chats""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseChatsManageStateTypedDict] - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") - ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" +class InputResponseChats(BaseModel): + r"""Chats""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") - ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + enabled: Optional[bool] = None + r"""Enabled""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[InputResponseChatsManageState], pydantic.Field(alias="manageState") + ] = None @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", - "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", - "notifications", - "status", + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", ] ) serialized = handler(self) @@ -4792,210 +4349,183 @@ def serialize_model(self, handler): return m -class InputResponseInputNetflowTypedDict(TypedDict): - type: TypeOptionsNetflow - r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - port: float - r"""Port to listen on""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - enable_pass_through: NotRequired[bool] - r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - template_cache_minutes: NotRequired[float] - r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" - v5_enabled: NotRequired[bool] - r"""Accept messages in Netflow V5 format.""" - v9_enabled: NotRequired[bool] - r"""Accept messages in Netflow V9 format.""" - ipfix_enabled: NotRequired[bool] - r"""Accept messages in IPFIX format.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" +class InputResponseProjectsManageStateTypedDict(TypedDict): + pass -class InputResponseInputNetflow(BaseModel): - type: TypeOptionsNetflow - r"""Connector type identifier.""" +class InputResponseProjectsManageState(BaseModel): + pass - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - port: float - r"""Port to listen on""" +class InputResponseProjectsTypedDict(TypedDict): + r"""Projects""" - id: Optional[str] = None - r"""Unique ID for this input""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseProjectsManageStateTypedDict] - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" +class InputResponseProjects(BaseModel): + r"""Projects""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + enabled: Optional[bool] = None + r"""Enabled""" + + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" + + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + r"""Track collection progress between consecutive scheduled executions""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), + manage_state: Annotated[ + Optional[InputResponseProjectsManageState], pydantic.Field(alias="manageState") ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m - pq: Optional[PqType] = None - enable_pass_through: Annotated[ - Optional[bool], pydantic.Field(alias="enablePassThrough") - ] = None - r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" +class InputResponseChatMessagesManageStateTypedDict(TypedDict): + pass - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" +class InputResponseChatMessagesManageState(BaseModel): + pass - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") - ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - template_cache_minutes: Annotated[ - Optional[float], pydantic.Field(alias="templateCacheMinutes") - ] = None - r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" +class InputResponseChatMessagesTypedDict(TypedDict): + r"""Chat Messages""" - v5_enabled: Annotated[Optional[bool], pydantic.Field(alias="v5Enabled")] = None - r"""Accept messages in Netflow V5 format.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseChatMessagesManageStateTypedDict] - v9_enabled: Annotated[Optional[bool], pydantic.Field(alias="v9Enabled")] = None - r"""Accept messages in Netflow V9 format.""" - ipfix_enabled: Annotated[Optional[bool], pydantic.Field(alias="ipfixEnabled")] = ( - None - ) - r"""Accept messages in IPFIX format.""" +class InputResponseChatMessages(BaseModel): + r"""Chat Messages""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + enabled: Optional[bool] = None + r"""Enabled""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + r"""Track collection progress between consecutive scheduled executions""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[InputResponseChatMessagesManageState], + pydantic.Field(alias="manageState"), + ] = None @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "enablePassThrough", - "ipAllowlistRegex", - "ipDenylistRegex", - "udpSocketRxBufSize", - "templateCacheMinutes", - "v5Enabled", - "v9Enabled", - "ipfixEnabled", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "notifications", - "status", + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", ] ) serialized = handler(self) @@ -5012,324 +4542,169 @@ def serialize_model(self, handler): return m -class InputResponseInputWizWebhookType(str, Enum): - r"""Source type identifier.""" - - WIZ_WEBHOOK = "wiz_webhook" - - -class InputResponseInputWizWebhookTypedDict(TypedDict): - type: InputResponseInputWizWebhookType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - allowed_paths: NotRequired[List[str]] - r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" - allowed_methods: NotRequired[List[str]] - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_allowed_paths: NotRequired[str] - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputWizWebhook(BaseModel): - type: InputResponseInputWizWebhookType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" +class InputResponseProjectDetailsManageStateTypedDict(TypedDict): + pass - id: Optional[str] = None - r"""Unique ID for this input""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" +class InputResponseProjectDetailsManageState(BaseModel): + pass - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" +class InputResponseProjectDetailsTypedDict(TypedDict): + r"""Project Details""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + earliest: NotRequired[str] + r"""Earliest time for data collection, relative to now""" + latest: NotRequired[str] + r"""Latest time for data collection, relative to now""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseProjectDetailsManageStateTypedDict] - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class InputResponseProjectDetails(BaseModel): + r"""Project Details""" - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + enabled: Optional[bool] = None + r"""Enabled""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - pq: Optional[PqType] = None + earliest: Optional[str] = None + r"""Earliest time for data collection, relative to now""" - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + latest: Optional[str] = None + r"""Latest time for data collection, relative to now""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( None ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + r"""Track collection progress between consecutive scheduled executions""" - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") + manage_state: Annotated[ + Optional[InputResponseProjectDetailsManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "enabled", + "cronSchedule", + "earliest", + "latest", + "jobTimeout", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + ] + ) + serialized = handler(self) + m = {} - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") - ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + return m - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") - ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" +class InputResponseGroupsTypedDict(TypedDict): + r"""Groups""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" +class InputResponseGroups(BaseModel): + r"""Groups""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + enabled: Optional[bool] = None + r"""Enabled""" - allowed_paths: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedPaths") - ] = None - r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" - allowed_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedMethods") - ] = None - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], - pydantic.Field(alias="authTokensExt"), - ] = None - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} - description: Optional[str] = None - r"""Optional description for this configuration.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + return m - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" +class InputResponseOrganizationsTypedDict(TypedDict): + r"""Organizations""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - template_allowed_paths: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedPaths") - ] = None - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" +class InputResponseOrganizations(BaseModel): + r"""Organizations""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + enabled: Optional[bool] = None + r"""Enabled""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "authTokens", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", - "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "breakerRulesets", - "staleChannelFlushMs", - "metadata", - "allowedPaths", - "allowedMethods", - "authTokensExt", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_authTokens", - "__template_allowedPaths", - "notifications", - "status", - ] - ) + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) serialized = handler(self) m = {} @@ -5344,225 +4719,72 @@ def serialize_model(self, handler): return m -class InputResponseInputOpenaiType(str, Enum): - r"""Connector type identifier.""" +class InputResponseOrganizationUsersTypedDict(TypedDict): + r"""Organization Users""" - OPENAI = "openai" + enabled: NotRequired[bool] + r"""Enabled""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" -class InputResponseInputOpenaiManageStateTypedDict(TypedDict): - pass +class InputResponseOrganizationUsers(BaseModel): + r"""Organization Users""" + enabled: Optional[bool] = None + r"""Enabled""" -class InputResponseInputOpenaiManageState(BaseModel): - pass + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" -class InputResponsePaginationType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Pagination type""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) + serialized = handler(self) + m = {} - # None - NONE = "none" - # Response Body Attribute - RESPONSE_BODY = "response_body" - # Response Header Attribute - RESPONSE_HEADER = "response_header" - # RFC 5988 Link Header - RESPONSE_HEADER_LINK = "response_header_link" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val -class InputResponseInputOpenaiLogLevel(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Collector runtime log level.""" + return m - ERROR = "error" - WARN = "warn" - INFO = "info" - DEBUG = "debug" - SILLY = "silly" +class InputResponseOrganizationRolesTypedDict(TypedDict): + r"""Organization Roles""" -class InputResponseInputOpenaiContentConfigTypedDict(TypedDict): - content_type: str - r"""Content type""" - collect_path: str - r"""OpenAI Organization API path""" - request_params: List[ - RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict - ] - r"""Query-string parameters to send with this endpoint""" - pagination_type: InputResponsePaginationType - r"""Pagination type""" - cron_schedule: str - r"""A cron schedule on which to run this job""" - earliest: str - r"""Relative to the current time""" - latest: str - r"""Relative to the current time""" - content_description: NotRequired[str] - r"""Description""" - docs_url: NotRequired[str] - r"""Docs URL""" - disabled: NotRequired[bool] + enabled: NotRequired[bool] r"""Enabled""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions.""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging task state""" - manage_state: NotRequired[InputResponseInputOpenaiManageStateTypedDict] - pagination_attribute: NotRequired[List[str]] - r"""Pagination attributes""" - pagination_last_page_expr: NotRequired[str] - r"""Last page expression""" - max_pages: NotRequired[float] - r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" - pagination_next_relation_attribute: NotRequired[str] - r"""Used only for RFC 5988 link-header pagination""" - pagination_cur_relation_attribute: NotRequired[str] - r"""Optional relation that represents the current page""" + cron_schedule: NotRequired[str] + r"""Schedule on which to run this collection job""" job_timeout: NotRequired[str] r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: NotRequired[InputResponseInputOpenaiLogLevel] - r"""Collector runtime log level.""" - endpoint_metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields automatically added to events from this Content Type""" - - -class InputResponseInputOpenaiContentConfig(BaseModel): - content_type: Annotated[str, pydantic.Field(alias="contentType")] - r"""Content type""" - - collect_path: Annotated[str, pydantic.Field(alias="collectPath")] - r"""OpenAI Organization API path""" - - request_params: Annotated[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret], - pydantic.Field(alias="requestParams"), - ] - r"""Query-string parameters to send with this endpoint""" - - pagination_type: Annotated[ - InputResponsePaginationType, pydantic.Field(alias="paginationType") - ] - r"""Pagination type""" - - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""A cron schedule on which to run this job""" - - earliest: str - r"""Relative to the current time""" - latest: str - r"""Relative to the current time""" - - content_description: Annotated[ - Optional[str], pydantic.Field(alias="contentDescription") - ] = None - r"""Description""" - docs_url: Annotated[Optional[str], pydantic.Field(alias="docsUrl")] = None - r"""Docs URL""" +class InputResponseOrganizationRoles(BaseModel): + r"""Organization Roles""" - disabled: Optional[bool] = None + enabled: Optional[bool] = None r"""Enabled""" - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions.""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging task state""" - - manage_state: Annotated[ - Optional[InputResponseInputOpenaiManageState], - pydantic.Field(alias="manageState"), - ] = None - - pagination_attribute: Annotated[ - Optional[List[str]], pydantic.Field(alias="paginationAttribute") - ] = None - r"""Pagination attributes""" - - pagination_last_page_expr: Annotated[ - Optional[str], pydantic.Field(alias="paginationLastPageExpr") - ] = None - r"""Last page expression""" - - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" - - pagination_next_relation_attribute: Annotated[ - Optional[str], pydantic.Field(alias="paginationNextRelationAttribute") - ] = None - r"""Used only for RFC 5988 link-header pagination""" - - pagination_cur_relation_attribute: Annotated[ - Optional[str], pydantic.Field(alias="paginationCurRelationAttribute") - ] = None - r"""Optional relation that represents the current page""" + cron_schedule: Annotated[Optional[str], pydantic.Field(alias="cronSchedule")] = None + r"""Schedule on which to run this collection job""" job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - log_level: Annotated[ - Optional[InputResponseInputOpenaiLogLevel], pydantic.Field(alias="logLevel") - ] = None - r"""Collector runtime log level.""" - - endpoint_metadata: Annotated[ - Optional[List[MetadataConfInputCollection]], - pydantic.Field(alias="endpointMetadata"), - ] = None - r"""Fields automatically added to events from this Content Type""" - - @field_serializer("pagination_type") - def serialize_pagination_type(self, value): - if isinstance(value, str): - try: - return models.InputResponsePaginationType(value) - except ValueError: - return value - return value - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputOpenaiLogLevel(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "contentDescription", - "docsUrl", - "disabled", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - "paginationAttribute", - "paginationLastPageExpr", - "maxPages", - "paginationNextRelationAttribute", - "paginationCurRelationAttribute", - "jobTimeout", - "logLevel", - "endpointMetadata", - ] - ) + optional_fields = set(["enabled", "cronSchedule", "jobTimeout"]) serialized = handler(self) m = {} @@ -5577,13 +4799,11 @@ def serialize_model(self, handler): return m -class InputResponseInputOpenaiTypedDict(TypedDict): - type: InputResponseInputOpenaiType +class InputResponseInputAnthropicComplianceTypedDict(TypedDict): + type: InputResponseInputAnthropicComplianceType r"""Connector type identifier.""" - content_config: List[InputResponseInputOpenaiContentConfigTypedDict] - r"""Content Types""" text_secret: str - r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" + r"""Select or create a stored Anthropic API key""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -5597,22 +4817,38 @@ class InputResponseInputOpenaiTypedDict(TypedDict): pq_enabled: NotRequired[bool] r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - openai_organization: NotRequired[str] - r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" - openai_project: NotRequired[str] - r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" - request_timeout: NotRequired[float] - r"""HTTP request inactivity timeout. Use 0 to disable.""" + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] api_key: NotRequired[str] r"""API key""" + activities: NotRequired[InputResponseActivitiesTypedDict] + r"""Activities""" + chats: NotRequired[InputResponseChatsTypedDict] + r"""Chats""" + projects: NotRequired[InputResponseProjectsTypedDict] + r"""Projects""" + chat_messages: NotRequired[InputResponseChatMessagesTypedDict] + r"""Chat Messages""" + project_details: NotRequired[InputResponseProjectDetailsTypedDict] + r"""Project Details""" + groups: NotRequired[InputResponseGroupsTypedDict] + r"""Groups""" + organizations: NotRequired[InputResponseOrganizationsTypedDict] + r"""Organizations""" + org_users: NotRequired[InputResponseOrganizationUsersTypedDict] + r"""Organization Users""" + org_roles: NotRequired[InputResponseOrganizationRolesTypedDict] + r"""Organization Roles""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" keep_alive_time: NotRequired[float] r"""How often workers should check in with the scheduler to keep job subscription alive""" max_missed_keep_alives: NotRequired[float] @@ -5630,28 +4866,18 @@ class InputResponseInputOpenaiTypedDict(TypedDict): r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_openai_organization: NotRequired[str] - r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - template_openai_project: NotRequired[str] - r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputOpenai(BaseModel): - type: InputResponseInputOpenaiType +class InputResponseInputAnthropicCompliance(BaseModel): + type: InputResponseInputAnthropicComplianceType r"""Connector type identifier.""" - content_config: Annotated[ - List[InputResponseInputOpenaiContentConfig], - pydantic.Field(alias="contentConfig"), - ] - r"""Content Types""" - text_secret: Annotated[str, pydantic.Field(alias="textSecret")] - r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" + r"""Select or create a stored Anthropic API key""" id: Optional[str] = None r"""Unique ID for this input""" @@ -5677,7 +4903,7 @@ class InputResponseInputOpenai(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -5687,23 +4913,50 @@ class InputResponseInputOpenai(BaseModel): pq: Optional[PqType] = None - openai_organization: Annotated[ - Optional[str], pydantic.Field(alias="openaiOrganization") - ] = None - r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - openai_project: Annotated[Optional[str], pydantic.Field(alias="openaiProject")] = ( - None - ) - r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" + activities: Optional[InputResponseActivities] = None + r"""Activities""" + + chats: Optional[InputResponseChats] = None + r"""Chats""" + + projects: Optional[InputResponseProjects] = None + r"""Projects""" + + chat_messages: Optional[InputResponseChatMessages] = None + r"""Chat Messages""" + + project_details: Optional[InputResponseProjectDetails] = None + r"""Project Details""" + + groups: Optional[InputResponseGroups] = None + r"""Groups""" + + organizations: Optional[InputResponseOrganizations] = None + r"""Organizations""" + + org_users: Optional[InputResponseOrganizationUsers] = None + r"""Organization Users""" + + org_roles: Optional[InputResponseOrganizationRoles] = None + r"""Organization Roles""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None r"""HTTP request inactivity timeout. Use 0 to disable.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""API key""" + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" keep_alive_time: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTime") @@ -5743,17 +4996,7 @@ class InputResponseInputOpenai(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_openai_organization: Annotated[ - Optional[str], pydantic.Field(alias="__template_openaiOrganization") - ] = None - r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - - template_openai_project: Annotated[ - Optional[str], pydantic.Field(alias="__template_openaiProject") - ] = None - r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -5773,160 +5016,30 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "openaiOrganization", - "openaiProject", - "requestTimeout", "apiKey", - "keepAliveTime", - "maxMissedKeepAlives", - "ttl", - "ignoreGroupJobsLimit", - "metadata", - "retryRules", - "description", - "__template_environment", - "__template_streamtags", - "__template_openaiOrganization", - "__template_openaiProject", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputWizType(str, Enum): - r"""Connector type identifier.""" - - WIZ = "wiz" - - -class InputResponseInputWizManageStateTypedDict(TypedDict): - pass - - -class InputResponseInputWizManageState(BaseModel): - pass - - -class InputResponseInputWizContentConfigTypedDict(TypedDict): - content_type: str - r"""The name of the Wiz query""" - content_query: str - r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" - cron_schedule: str - r"""A cron schedule on which to run this job""" - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - content_description: NotRequired[str] - r"""Description""" - enabled: NotRequired[bool] - r"""Enable content""" - state_tracking: NotRequired[bool] - r"""Track collection progress between consecutive scheduled executions""" - state_update_expression: NotRequired[str] - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - state_merge_expression: NotRequired[str] - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - manage_state: NotRequired[InputResponseInputWizManageStateTypedDict] - job_timeout: NotRequired[str] - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" - log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] - r"""Collector runtime log level""" - max_pages: NotRequired[float] - r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" - - -class InputResponseInputWizContentConfig(BaseModel): - content_type: Annotated[str, pydantic.Field(alias="contentType")] - r"""The name of the Wiz query""" - - content_query: Annotated[str, pydantic.Field(alias="contentQuery")] - r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" - - cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] - r"""A cron schedule on which to run this job""" - - earliest: str - r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - - latest: str - r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" - - content_description: Annotated[ - Optional[str], pydantic.Field(alias="contentDescription") - ] = None - r"""Description""" - - enabled: Optional[bool] = None - r"""Enable content""" - - state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( - None - ) - r"""Track collection progress between consecutive scheduled executions""" - - state_update_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateUpdateExpression") - ] = None - r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - - state_merge_expression: Annotated[ - Optional[str], pydantic.Field(alias="stateMergeExpression") - ] = None - r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - - manage_state: Annotated[ - Optional[InputResponseInputWizManageState], pydantic.Field(alias="manageState") - ] = None - - job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None - r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" - - log_level: Annotated[ - Optional[LogLevelOptionsContentConfigItemsDebugError], - pydantic.Field(alias="logLevel"), - ] = None - r"""Collector runtime log level""" - - max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None - r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" - - @field_serializer("log_level") - def serialize_log_level(self, value): - if isinstance(value, str): - try: - return models.LogLevelOptionsContentConfigItemsDebugError(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "contentDescription", - "enabled", - "stateTracking", - "stateUpdateExpression", - "stateMergeExpression", - "manageState", - "jobTimeout", - "logLevel", - "maxPages", + "activities", + "chats", + "projects", + "chat_messages", + "project_details", + "groups", + "organizations", + "org_users", + "org_roles", + "requestTimeout", + "breakerRulesets", + "staleChannelFlushMs", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "retryRules", + "description", + "__template_environment", + "__template_streamtags", + "notifications", + "status", ] ) serialized = handler(self) @@ -5943,17 +5056,38 @@ def serialize_model(self, handler): return m -class InputResponseInputWizTypedDict(TypedDict): - type: InputResponseInputWizType +class InputResponseInputOpenaiComplianceLogsType(str, Enum): r"""Connector type identifier.""" - endpoint: str - r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" - auth_url: str - r"""The authentication URL to generate an OAuth token""" - client_id: str - r"""The client ID of the Wiz application""" - content_config: List[InputResponseInputWizContentConfigTypedDict] - r"""Content types""" + + OPENAI_COMPLIANCE_LOGS = "openai_compliance_logs" + + +class InputResponseAccountType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Account type""" + + # Workspace + WORKSPACE = "workspace" + # Organization + ORGANIZATION = "organization" + + +class InputResponseInputOpenaiComplianceLogsManageStateTypedDict(TypedDict): + pass + + +class InputResponseInputOpenaiComplianceLogsManageState(BaseModel): + pass + + +class InputResponseInputOpenaiComplianceLogsTypedDict(TypedDict): + type: InputResponseInputOpenaiComplianceLogsType + r"""Connector type identifier.""" + text_secret: str + r"""Select or create a stored text secret""" + account_type: InputResponseAccountType + r"""Account type""" + cron_schedule: str + r"""Cron schedule""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -5968,15 +5102,25 @@ class InputResponseInputWizTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_audience_override: NotRequired[str] - r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + api_key: NotRequired[str] + r"""API key""" + earliest: NotRequired[str] + r"""Relative to the current time. Format: [+|-]""" + latest: NotRequired[str] + r"""Relative to the current time. Format: [+|-]""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] + r"""Collector runtime log level""" + max_pages: NotRequired[float] + r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" request_timeout: NotRequired[float] r"""HTTP request inactivity timeout. Use 0 to disable.""" keep_alive_time: NotRequired[float] @@ -5994,47 +5138,51 @@ class InputResponseInputWizTypedDict(TypedDict): stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" retry_rules: NotRequired[RetryRulesTypeTypedDict] - auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] - r"""Enter client secret directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""The client secret of the Wiz application""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" + workspace_id: NotRequired[str] + r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" + workspace_event_types: NotRequired[List[str]] + r"""One or more compliance log categories to collect""" + organization_id: NotRequired[str] + r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + organization_event_types: NotRequired[List[str]] + r"""One or more compliance log categories to collect""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[ + InputResponseInputOpenaiComplianceLogsManageStateTypedDict + ] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_auth_url: NotRequired[str] - r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_workspace_id: NotRequired[str] + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + template_organization_id: NotRequired[str] + r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputWiz(BaseModel): - type: InputResponseInputWizType +class InputResponseInputOpenaiComplianceLogs(BaseModel): + type: InputResponseInputOpenaiComplianceLogsType r"""Connector type identifier.""" - endpoint: str - r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" - - auth_url: Annotated[str, pydantic.Field(alias="authUrl")] - r"""The authentication URL to generate an OAuth token""" - - client_id: Annotated[str, pydantic.Field(alias="clientId")] - r"""The client ID of the Wiz application""" + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" - content_config: Annotated[ - List[InputResponseInputWizContentConfig], pydantic.Field(alias="contentConfig") + account_type: Annotated[ + InputResponseAccountType, pydantic.Field(alias="accountType") ] - r"""Content types""" + r"""Account type""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule""" id: Optional[str] = None r"""Unique ID for this input""" @@ -6060,7 +5208,7 @@ class InputResponseInputWiz(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -6070,10 +5218,31 @@ class InputResponseInputWiz(BaseModel): pq: Optional[PqType] = None - auth_audience_override: Annotated[ - Optional[str], pydantic.Field(alias="authAudienceOverride") + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" + + earliest: Optional[str] = None + r"""Relative to the current time. Format: [+|-]""" + + latest: Optional[str] = None + r"""Relative to the current time. Format: [+|-]""" + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItemsDebugError], + pydantic.Field(alias="logLevel"), ] = None - r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + r"""Collector runtime log level""" + + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of log file listing pages to retrieve per run. Set to 0 to retrieve all pages.""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") @@ -6115,20 +5284,41 @@ class InputResponseInputWiz(BaseModel): Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsManualSecret], - pydantic.Field(alias="authType"), - ] = None - r"""Enter client secret directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""The client secret of the Wiz application""" + workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None + r"""The ID of the ChatGPT workspace to collect logs from (UUID format)""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + workspace_event_types: Annotated[ + Optional[List[str]], pydantic.Field(alias="workspaceEventTypes") + ] = None + r"""One or more compliance log categories to collect""" + + organization_id: Annotated[ + Optional[str], pydantic.Field(alias="organizationId") + ] = None + r"""The ID of the OpenAI API Platform Organization (example: org-XXXXXXXXXXXXXXXXXXXXXXXX)""" + + organization_event_types: Annotated[ + Optional[List[str]], pydantic.Field(alias="organizationEventTypes") + ] = None + r"""One or more compliance log categories to collect""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[InputResponseInputOpenaiComplianceLogsManageState], + pydantic.Field(alias="manageState"), + ] = None template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -6140,32 +5330,36 @@ class InputResponseInputWiz(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_auth_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_authUrl") + template_workspace_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceId") ] = None - r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") + template_organization_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_organizationId") ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + r"""Binds 'organizationId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'organizationId' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("account_type") + def serialize_account_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsManualSecret(value) + return models.InputResponseAccountType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItemsDebugError(value) except ValueError: return value return value @@ -6184,7 +5378,13 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "authAudienceOverride", + "apiKey", + "earliest", + "latest", + "jobTimeout", + "logLevel", + "maxPages", + "stateTracking", "requestTimeout", "keepAliveTime", "maxMissedKeepAlives", @@ -6194,15 +5394,18 @@ def serialize_model(self, handler): "breakerRulesets", "staleChannelFlushMs", "retryRules", - "authType", "description", - "clientSecret", - "textSecret", + "workspaceId", + "workspaceEventTypes", + "organizationId", + "organizationEventTypes", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", "__template_environment", - "__template_streamtags", - "__template_endpoint", - "__template_authUrl", - "__template_clientId", + "__template_streamtags", + "__template_workspaceId", + "__template_organizationId", "notifications", "status", ] @@ -6221,50 +5424,21 @@ def serialize_model(self, handler): return m -class InputResponseInputJournalFilesType(str, Enum): - r"""Connector type identifier.""" - - JOURNAL_FILES = "journal_files" - - -class InputResponseInputJournalFilesRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" - description: NotRequired[str] - r"""Optional description of this rule's purpose""" - - -class InputResponseInputJournalFilesRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" - - description: Optional[str] = None - r"""Optional description of this rule's purpose""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class InputResponseInputAquaSecurityHecType(str, Enum): + r"""Source type identifier.""" - return m + AQUA_SECURITY_HEC = "aqua_security_hec" -class InputResponseInputJournalFilesTypedDict(TypedDict): - type: InputResponseInputJournalFilesType - r"""Connector type identifier.""" - path: str - r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" - journals: List[str] - r"""The full path of discovered journals are matched against this wildcard list.""" +class InputResponseInputAquaSecurityHecTypedDict(TypedDict): + type: InputResponseInputAquaSecurityHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -6279,46 +5453,82 @@ class InputResponseInputJournalFilesTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between scanning for journals.""" - rules: NotRequired[List[InputResponseInputJournalFilesRuleTypedDict]] - r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" - current_boot: NotRequired[bool] - r"""Skip log messages that are not part of the current boot session""" - max_age_dur: NotRequired[str] - r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" - suppress_missing_path_errors: NotRequired[bool] - r"""Suppress errors when search path does not exist""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + hec_acks: NotRequired[bool] + r"""Whether to enable HEC indexer acknowledgements""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputJournalFiles(BaseModel): - type: InputResponseInputJournalFilesType - r"""Connector type identifier.""" +class InputResponseInputAquaSecurityHec(BaseModel): + type: InputResponseInputAquaSecurityHecType + r"""Source type identifier.""" - path: str - r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - journals: List[str] - r"""The full path of discovered journals are matched against this wildcard list.""" + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Aqua Security HTTP Event Collector API requests. This input supports event, raw, and acknowledgement endpoints.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -6344,7 +5554,7 @@ class InputResponseInputJournalFiles(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -6354,25 +5564,90 @@ class InputResponseInputJournalFiles(BaseModel): pq: Optional[PqType] = None - interval: Optional[float] = None - r"""Time, in seconds, between scanning for journals.""" + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - rules: Optional[List[InputResponseInputJournalFilesRule]] = None - r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - current_boot: Annotated[Optional[bool], pydantic.Field(alias="currentBoot")] = None - r"""Skip log messages that are not part of the current boot session""" + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None - r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - suppress_missing_path_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Suppress errors when search path does not exist""" + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable HEC indexer acknowledgements""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -6387,7 +5662,37 @@ class InputResponseInputJournalFiles(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -6407,15 +5712,33 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "interval", - "rules", - "currentBoot", - "maxAgeDur", - "suppressMissingPathErrors", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "hecAcks", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", "notifications", "status", ] @@ -6434,19 +5757,21 @@ def serialize_model(self, handler): return m -class InputResponseInputRawUDPType(str, Enum): - r"""Connector type identifier.""" +class InputResponseInputExtrahopRevealx360Type(str, Enum): + r"""Source type identifier.""" - RAW_UDP = "raw_udp" + EXTRAHOP_REVEALX_360 = "extrahop_revealx_360" -class InputResponseInputRawUDPTypedDict(TypedDict): - type: InputResponseInputRawUDPType - r"""Connector type identifier.""" +class InputResponseInputExtrahopRevealx360TypedDict(TypedDict): + type: InputResponseInputExtrahopRevealx360Type + r"""Source type identifier.""" host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -6461,25 +5786,46 @@ class InputResponseInputRawUDPTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - single_msg_udp_packets: NotRequired[bool] - r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" - ingest_raw_bytes: NotRequired[bool] - r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -6490,22 +5836,33 @@ class InputResponseInputRawUDPTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputRawUDP(BaseModel): - type: InputResponseInputRawUDPType - r"""Connector type identifier.""" +class InputResponseInputExtrahopRevealx360(BaseModel): + type: InputResponseInputExtrahopRevealx360Type + r"""Source type identifier.""" host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for ExtraHop RevealX 360 Splunk HTTP Event Collector requests. This input supports the /event endpoint.""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -6530,7 +5887,7 @@ class InputResponseInputRawUDP(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -6540,33 +5897,92 @@ class InputResponseInputRawUDP(BaseModel): pq: Optional[PqType] = None - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Maximum number of events to buffer when downstream is blocking.""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - ingest_raw_bytes: Annotated[ - Optional[bool], pydantic.Field(alias="ingestRawBytes") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" + r"""Add request headers to events, in the __headers field""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -6591,7 +6007,27 @@ class InputResponseInputRawUDP(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -6611,17 +6047,33 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "maxBufferSize", - "ipWhitelistRegex", - "singleMsgUdpPackets", - "ingestRawBytes", - "udpSocketRxBufSize", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", "notifications", "status", ] @@ -6640,28 +6092,21 @@ def serialize_model(self, handler): return m -class InputResponseInputAppleUnifiedLogsType(str, Enum): - r"""Connector type identifier.""" - - APPLE_UNIFIED_LOGS = "apple_unified_logs" - - -class InputResponseInputAppleUnifiedLogsReadMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" +class InputResponseInputSailpointHecType(str, Enum): + r"""Source type identifier.""" - # Entire log - OLDEST = "oldest" - # From last entry - NEWEST = "newest" + SAILPOINT_HEC = "sailpoint_hec" -class InputResponseInputAppleUnifiedLogsTypedDict(TypedDict): - type: InputResponseInputAppleUnifiedLogsType - r"""Connector type identifier.""" - predicate: str - r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" +class InputResponseInputSailpointHecTypedDict(TypedDict): + type: InputResponseInputSailpointHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -6676,35 +6121,68 @@ class InputResponseInputAppleUnifiedLogsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - read_mode: NotRequired[InputResponseInputAppleUnifiedLogsReadMode] - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputAppleUnifiedLogs(BaseModel): - type: InputResponseInputAppleUnifiedLogsType - r"""Connector type identifier.""" +class InputResponseInputSailpointHec(BaseModel): + type: InputResponseInputSailpointHecType + r"""Source type identifier.""" - predicate: str - r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -6730,7 +6208,7 @@ class InputResponseInputAppleUnifiedLogs(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -6740,14 +6218,72 @@ class InputResponseInputAppleUnifiedLogs(BaseModel): pq: Optional[PqType] = None - read_mode: Annotated[ - Optional[InputResponseInputAppleUnifiedLogsReadMode], - pydantic.Field(alias="readMode"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -6762,21 +6298,27 @@ class InputResponseInputAppleUnifiedLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("read_mode") - def serialize_read_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputAppleUnifiedLogsReadMode(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -6791,11 +6333,26 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "readMode", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", "notifications", "status", ] @@ -6814,35 +6371,21 @@ def serialize_model(self, handler): return m -class InputResponseInputWinEventLogsType(str, Enum): - r"""Connector type identifier.""" - - WIN_EVENT_LOGS = "win_event_logs" - - -class InputResponseInputWinEventLogsReadMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Read all stored and future event logs, or only future events""" - - # Entire log - OLDEST = "oldest" - # From last entry - NEWEST = "newest" - - -class InputResponseEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of individual events""" +class InputResponseInputTrellixHecType(str, Enum): + r"""Source type identifier.""" - # JSON - JSON = "json" - # XML - XML = "xml" + TRELLIX_HEC = "trellix_hec" -class InputResponseInputWinEventLogsTypedDict(TypedDict): - type: InputResponseInputWinEventLogsType - r"""Connector type identifier.""" - log_names: List[str] - r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" +class InputResponseInputTrellixHecTypedDict(TypedDict): + type: InputResponseInputTrellixHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -6857,51 +6400,82 @@ class InputResponseInputWinEventLogsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - suppress_missing_log_errors: NotRequired[bool] - r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - read_mode: NotRequired[InputResponseInputWinEventLogsReadMode] - r"""Read all stored and future event logs, or only future events""" - event_format: NotRequired[InputResponseEventFormat] - r"""Format of individual events""" - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" - interval: NotRequired[float] - r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" - batch_size: NotRequired[float] - r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - max_event_bytes: NotRequired[int] - r"""The maximum number of bytes in an event before it is flushed to the pipelines""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - disable_json_rendering: NotRequired[bool] - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" - disable_xml_rendering: NotRequired[bool] - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputWinEventLogs(BaseModel): - type: InputResponseInputWinEventLogsType - r"""Connector type identifier.""" +class InputResponseInputTrellixHec(BaseModel): + type: InputResponseInputTrellixHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - log_names: Annotated[List[str], pydantic.Field(alias="logNames")] - r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -6927,7 +6501,7 @@ class InputResponseInputWinEventLogs(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -6937,267 +6511,185 @@ class InputResponseInputWinEventLogs(BaseModel): pq: Optional[PqType] = None - suppress_missing_log_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingLogErrors") - ] = None - r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" - - read_mode: Annotated[ - Optional[InputResponseInputWinEventLogsReadMode], - pydantic.Field(alias="readMode"), - ] = None - r"""Read all stored and future event logs, or only future events""" - - event_format: Annotated[ - Optional[InputResponseEventFormat], pydantic.Field(alias="eventFormat") - ] = None - r"""Format of individual events""" - - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" - - interval: Optional[float] = None - r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" - - batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None - r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - max_event_bytes: Annotated[Optional[int], pydantic.Field(alias="maxEventBytes")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""The maximum number of bytes in an event before it is flushed to the pipelines""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - disable_json_rendering: Annotated[ - Optional[bool], pydantic.Field(alias="disableJsonRendering") - ] = None - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - disable_xml_rendering: Annotated[ - Optional[bool], pydantic.Field(alias="disableXmlRendering") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("read_mode") - def serialize_read_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputWinEventLogsReadMode(value) - except ValueError: - return value - return value - - @field_serializer("event_format") - def serialize_event_format(self, value): - if isinstance(value, str): - try: - return models.InputResponseEventFormat(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "suppressMissingLogErrors", - "readMode", - "eventFormat", - "disableNativeModule", - "interval", - "batchSize", - "metadata", - "maxEventBytes", - "description", - "disableJsonRendering", - "disableXmlRendering", - "__template_environment", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputWefType(str, Enum): - r"""Connector type identifier.""" + r"""Add request headers to events, in the __headers field""" - WEF = "wef" + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" -class InputResponseInputWefAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""How to authenticate incoming client connections""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - # Client certificate - CLIENT_CERT = "clientCert" - # Kerberos - KERBEROS = "kerberos" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class InputResponseMTLSSettingsTypedDict(TypedDict): - r"""mTLS settings""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - priv_key_path: str - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - cert_path: str - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - ca_path: str - r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" - disabled: NotRequired[bool] - r"""Enable TLS""" - reject_unauthorized: NotRequired[bool] - r"""Required for WEF certificate authentication""" - request_cert: NotRequired[bool] - r"""Required for WEF certificate authentication""" - certificate_name: NotRequired[str] - r"""Name of the predefined certificate""" - passphrase: NotRequired[str] - r"""Passphrase to use to decrypt private key""" - common_name_regex: NotRequired[str] - r"""Regex matching allowable common names in peer certificates' subject attribute""" - min_version: NotRequired[MinimumTLSVersionOptionsTLS] - r"""Minimum TLS version""" - max_version: NotRequired[MaximumTLSVersionOptionsTLS] - r"""Maximum TLS version""" - ocsp_check: NotRequired[bool] - r"""Enable OCSP check of certificate""" - ocsp_check_fail_close: NotRequired[bool] - r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" -class InputResponseMTLSSettings(BaseModel): - r"""mTLS settings""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] - r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - cert_path: Annotated[str, pydantic.Field(alias="certPath")] - r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - ca_path: Annotated[str, pydantic.Field(alias="caPath")] - r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - disabled: Optional[bool] = None - r"""Enable TLS""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Required for WEF certificate authentication""" - - request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None - r"""Required for WEF certificate authentication""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Name of the predefined certificate""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - passphrase: Optional[str] = None - r"""Passphrase to use to decrypt private key""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - common_name_regex: Annotated[ - Optional[str], pydantic.Field(alias="commonNameRegex") - ] = None - r"""Regex matching allowable common names in peer certificates' subject attribute""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - min_version: Annotated[ - Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Minimum TLS version""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - max_version: Annotated[ - Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Maximum TLS version""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - ocsp_check: Annotated[Optional[bool], pydantic.Field(alias="ocspCheck")] = None - r"""Enable OCSP check of certificate""" + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - ocsp_check_fail_close: Annotated[ - Optional[bool], pydantic.Field(alias="ocspCheckFailClose") + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") ] = None - r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - @field_serializer("min_version") - def serialize_min_version(self, value): - if isinstance(value, str): - try: - return models.MinimumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" - @field_serializer("max_version") - def serialize_max_version(self, value): - if isinstance(value, str): - try: - return models.MaximumTLSVersionOptionsTLS(value) - except ValueError: - return value - return value + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ + "id", "disabled", - "rejectUnauthorized", - "requestCert", - "certificateName", - "passphrase", - "commonNameRegex", - "minVersion", - "maxVersion", - "ocspCheck", - "ocspCheckFailClose", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", ] ) serialized = handler(self) @@ -7214,148 +6706,325 @@ def serialize_model(self, handler): return m -class InputResponseFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Content format in which the endpoint should deliver events""" +class InputResponseInputUpwindHecType(str, Enum): + r"""Source type identifier.""" - RAW = "Raw" - RENDERED_TEXT = "RenderedText" + UPWIND_HEC = "upwind_hec" -class InputResponseQueryBuilderMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Query builder mode""" +class InputResponseInputUpwindHecTypedDict(TypedDict): + type: InputResponseInputUpwindHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputUpwindHec(BaseModel): + type: InputResponseInputUpwindHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Upwind HTTP Event Collector API requests. This input supports the /event endpoint.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - SIMPLE = "simple" - XML = "xml" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" -class InputResponseQueryTypedDict(TypedDict): - path: str - r"""The Path attribute from the relevant XML Select element""" - query_expression: str - r"""The XPath query inside the relevant XML Select element""" + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" -class InputResponseQuery(BaseModel): - path: str - r"""The Path attribute from the relevant XML Select element""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - query_expression: Annotated[str, pydantic.Field(alias="queryExpression")] - r"""The XPath query inside the relevant XML Select element""" + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" -class InputResponseSubscriptionTypedDict(TypedDict): - subscription_name: str - r"""Subscription name""" - content_format: InputResponseFormat - r"""Content format in which the endpoint should deliver events""" - heartbeat_interval: float - r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" - batch_timeout: float - r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" - targets: List[str] - r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" - version: NotRequired[str] - r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" - read_existing_events: NotRequired[bool] - r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" - send_bookmarks: NotRequired[bool] - r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - compress: NotRequired[bool] - r"""Receive compressed events from the source""" - locale: NotRequired[str] - r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" - query_selector: NotRequired[InputResponseQueryBuilderMode] - r"""Query builder mode""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events ingested under this subscription""" - queries: NotRequired[List[InputResponseQueryTypedDict]] - r"""Queries""" - xml_query: NotRequired[str] - r"""The XPath query to use for selecting events""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" -class InputResponseSubscription(BaseModel): - subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] - r"""Subscription name""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - content_format: Annotated[ - InputResponseFormat, pydantic.Field(alias="contentFormat") - ] - r"""Content format in which the endpoint should deliver events""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - heartbeat_interval: Annotated[float, pydantic.Field(alias="heartbeatInterval")] - r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - batch_timeout: Annotated[float, pydantic.Field(alias="batchTimeout")] - r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - targets: List[str] - r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - version: Optional[str] = None - r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - read_existing_events: Annotated[ - Optional[bool], pydantic.Field(alias="readExistingEvents") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - send_bookmarks: Annotated[Optional[bool], pydantic.Field(alias="sendBookmarks")] = ( + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - - compress: Optional[bool] = None - r"""Receive compressed events from the source""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - locale: Optional[str] = None - r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - query_selector: Annotated[ - Optional[InputResponseQueryBuilderMode], pydantic.Field(alias="querySelector") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Query builder mode""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events ingested under this subscription""" + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" - queries: Optional[List[InputResponseQuery]] = None - r"""Queries""" + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - xml_query: Annotated[Optional[str], pydantic.Field(alias="xmlQuery")] = None - r"""The XPath query to use for selecting events""" + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - @field_serializer("content_format") - def serialize_content_format(self, value): - if isinstance(value, str): - try: - return models.InputResponseFormat(value) - except ValueError: - return value - return value + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" - @field_serializer("query_selector") - def serialize_query_selector(self, value): - if isinstance(value, str): - try: - return models.InputResponseQueryBuilderMode(value) - except ValueError: - return value - return value + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "version", - "readExistingEvents", - "sendBookmarks", - "compress", - "locale", - "querySelector", + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "queries", - "xmlQuery", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", ] ) serialized = handler(self) @@ -7372,15 +7041,21 @@ def serialize_model(self, handler): return m -class InputResponseInputWefTypedDict(TypedDict): - type: InputResponseInputWefType - r"""Connector type identifier.""" +class InputResponseInputSysdigHecType(str, Enum): + r"""Source type identifier.""" + + SYSDIG_HEC = "sysdig_hec" + + +class InputResponseInputSysdigHecTypedDict(TypedDict): + type: InputResponseInputSysdigHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" - subscriptions: List[InputResponseSubscriptionTypedDict] - r"""Subscriptions to events on forwarding endpoints""" + hec_api: str + r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -7395,50 +7070,48 @@ class InputResponseInputWefTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_method: NotRequired[InputResponseInputWefAuthenticationMethod] - r"""How to authenticate incoming client connections""" - tls: NotRequired[InputResponseMTLSSettingsTypedDict] - r"""mTLS settings""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" max_requests_per_socket: NotRequired[int] r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" capture_headers: NotRequired[bool] - r"""Add request headers to events in the __headers field""" + r"""Add request headers to events, in the __headers field""" capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: NotRequired[float] r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" ip_allowlist_regex: NotRequired[str] r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - ca_fingerprint: NotRequired[str] - r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" - keytab: NotRequired[str] - r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" - principal: NotRequired[str] - r"""Kerberos principal used for authentication, typically in the form HTTP/@""" - allow_machine_id_mismatch: NotRequired[bool] - r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: NotRequired[str] r"""Optional description for this configuration.""" - log_fingerprint_mismatch: NotRequired[bool] - r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -7447,19 +7120,23 @@ class InputResponseInputWefTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_keytab: NotRequired[str] - r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" - template_principal: NotRequired[str] - r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputWef(BaseModel): - type: InputResponseInputWefType - r"""Connector type identifier.""" +class InputResponseInputSysdigHec(BaseModel): + type: InputResponseInputSysdigHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -7467,8 +7144,8 @@ class InputResponseInputWef(BaseModel): port: float r"""Port to listen on""" - subscriptions: List[InputResponseSubscription] - r"""Subscriptions to events on forwarding endpoints""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Sysdig HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -7494,7 +7171,7 @@ class InputResponseInputWef(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -7504,14 +7181,14 @@ class InputResponseInputWef(BaseModel): pq: Optional[PqType] = None - auth_method: Annotated[ - Optional[InputResponseInputWefAuthenticationMethod], - pydantic.Field(alias="authMethod"), + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""How to authenticate incoming client connections""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: Optional[InputResponseMTLSSettings] = None - r"""mTLS settings""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None @@ -7526,28 +7203,38 @@ class InputResponseInputWef(BaseModel): enable_proxy_header: Annotated[ Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" capture_headers: Annotated[ Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""Add request headers to events in the __headers field""" + r"""Add request headers to events, in the __headers field""" CAPTURE_HEADERS_WARNING: Annotated[ Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], pydantic.Field(alias="captureHeadersWarning"), ] = "" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") - ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None @@ -7558,38 +7245,32 @@ class InputResponseInputWef(BaseModel): ] = None r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - - ca_fingerprint: Annotated[Optional[str], pydantic.Field(alias="caFingerprint")] = ( - None - ) - r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - keytab: Optional[str] = None - r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - principal: Optional[str] = None - r"""Kerberos principal used for authentication, typically in the form HTTP/@""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - allow_machine_id_mismatch: Annotated[ - Optional[bool], pydantic.Field(alias="allowMachineIdMismatch") + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") ] = None - r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" description: Optional[str] = None r"""Optional description for this configuration.""" - log_fingerprint_mismatch: Annotated[ - Optional[bool], pydantic.Field(alias="logFingerprintMismatch") - ] = None - r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -7610,31 +7291,32 @@ class InputResponseInputWef(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_keytab: Annotated[ - Optional[str], pydantic.Field(alias="__template_keytab") + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") ] = None - r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" - template_principal: Annotated[ - Optional[str], pydantic.Field(alias="__template_principal") + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") ] = None - r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("auth_method") - def serialize_auth_method(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputWefAuthenticationMethod(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -7649,108 +7331,37 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "authMethod", + "authTokens", "tls", "maxActiveReq", "maxRequestsPerSocket", "enableProxyHeader", "captureHeaders", "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", "keepAliveTimeout", - "enableHealthCheck", "ipAllowlistRegex", "ipDenylistRegex", - "socketTimeout", - "caFingerprint", - "keytab", - "principal", - "allowMachineIdMismatch", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "description", - "logFingerprintMismatch", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "__template_keytab", - "__template_principal", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputAppscopeType(str, Enum): - r"""Connector type identifier.""" - - APPSCOPE = "appscope" - - -class InputResponseAllowTypedDict(TypedDict): - procname: str - r"""Specify the name of a process or family of processes.""" - config: str - r"""Choose a config to apply to processes that match the process name and/or argument.""" - arg: NotRequired[str] - r"""Specify a string to substring-match against process command-line.""" - - -class InputResponseAllow(BaseModel): - procname: str - r"""Specify the name of a process or family of processes.""" - - config: str - r"""Choose a config to apply to processes that match the process name and/or argument.""" - - arg: Optional[str] = None - r"""Specify a string to substring-match against process command-line.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["arg"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputAppscopeFilterTypedDict(TypedDict): - allow: NotRequired[List[InputResponseAllowTypedDict]] - r"""Specify processes that AppScope should be loaded into, and the config to use.""" - transport_url: NotRequired[str] - r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" - - -class InputResponseInputAppscopeFilter(BaseModel): - allow: Optional[List[InputResponseAllow]] = None - r"""Specify processes that AppScope should be loaded into, and the config to use.""" - - transport_url: Annotated[Optional[str], pydantic.Field(alias="transportURL")] = None - r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["allow", "transportURL"]) + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", + ] + ) serialized = handler(self) m = {} @@ -7765,49 +7376,99 @@ def serialize_model(self, handler): return m -class InputResponseInputAppscopePersistenceTypedDict(TypedDict): - r"""Persistence""" +class InputResponseInputCloudflareHecType(str, Enum): + r"""Source type identifier.""" - enable: NotRequired[bool] - r"""Spool events and metrics on disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" + CLOUDFLARE_HEC = "cloudflare_hec" -class InputResponseInputAppscopePersistence(BaseModel): - r"""Persistence""" +class InputResponseTLSSettingsServerSideTypedDict(TypedDict): + r"""TLS settings (server side)""" - enable: Optional[bool] = None - r"""Spool events and metrics on disk for Cribl Edge and Search""" + disabled: NotRequired[bool] + r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" + request_cert: NotRequired[bool] + r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" + ca_path: NotRequired[str] + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" + common_name_regex: NotRequired[str] + r"""Regex matching allowable common names in peer certificates' subject attribute""" + certificate_name: NotRequired[str] + r"""The name of the predefined certificate""" + priv_key_path: NotRequired[str] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + cert_path: NotRequired[str] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" + min_version: NotRequired[MinimumTLSVersionOptionsTLS] + r"""Minimum TLS version""" + max_version: NotRequired[MaximumTLSVersionOptionsTLS] + r"""Maximum TLS version""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" +class InputResponseTLSSettingsServerSide(BaseModel): + r"""TLS settings (server side)""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + disabled: Optional[bool] = None + r"""Enable or disable TLS. Defaults to enabled for Cloudflare sources.""" - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" + request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None + r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" + ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - @field_serializer("compress") - def serialize_compress(self, value): + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" + + common_name_regex: Annotated[ + Optional[str], pydantic.Field(alias="commonNameRegex") + ] = None + r"""Regex matching allowable common names in peer certificates' subject attribute""" + + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The name of the predefined certificate""" + + priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl private key when TLS is enabled.""" + + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" + + cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS. Defaults to the built-in Cribl certificate when TLS is enabled.""" + + min_version: Annotated[ + Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") + ] = None + r"""Minimum TLS version""" + + max_version: Annotated[ + Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") + ] = None + r"""Maximum TLS version""" + + @field_serializer("min_version") + def serialize_min_version(self, value): if isinstance(value, str): try: - return models.DataCompressionFormatOptionsPersistence(value) + return models.MinimumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value + + @field_serializer("max_version") + def serialize_max_version(self, value): + if isinstance(value, str): + try: + return models.MaximumTLSVersionOptionsTLS(value) except ValueError: return value return value @@ -7816,12 +7477,17 @@ def serialize_compress(self, value): def serialize_model(self, handler): optional_fields = set( [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", + "disabled", + "requestCert", + "caPath", + "rejectUnauthorized", + "commonNameRegex", + "certificateName", + "privKeyPath", + "passphrase", + "certPath", + "minVersion", + "maxVersion", ] ) serialized = handler(self) @@ -7838,21 +7504,15 @@ def serialize_model(self, handler): return m -InputResponseUNIXSocketPermissionsTypedDict = TypeAliasType( - "InputResponseUNIXSocketPermissionsTypedDict", Union[str, float] -) -r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - -InputResponseUNIXSocketPermissions = TypeAliasType( - "InputResponseUNIXSocketPermissions", Union[str, float] -) -r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - - -class InputResponseInputAppscopeTypedDict(TypedDict): - type: InputResponseInputAppscopeType - r"""Connector type identifier.""" +class InputResponseInputCloudflareHecTypedDict(TypedDict): + type: InputResponseInputCloudflareHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -7867,54 +7527,52 @@ class InputResponseInputAppscopeTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[InputResponseTLSSettingsServerSideTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_unix_path: NotRequired[bool] - r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" - filter_: NotRequired[InputResponseInputAppscopeFilterTypedDict] - persistence: NotRequired[InputResponseInputAppscopePersistenceTypedDict] - r"""Persistence""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: NotRequired[float] - r"""Port to listen on""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - unix_socket_path: NotRequired[str] - r"""Path to the UNIX domain socket to listen on.""" - unix_socket_perms: NotRequired[InputResponseUNIXSocketPermissionsTypedDict] - r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -7923,15 +7581,32 @@ class InputResponseInputAppscopeTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputAppscope(BaseModel): - type: InputResponseInputAppscopeType - r"""Connector type identifier.""" +class InputResponseInputCloudflareHec(BaseModel): + type: InputResponseInputCloudflareHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Cloudflare HTTP Event Collector API requests. This input supports the /event endpoint.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -7957,7 +7632,7 @@ class InputResponseInputAppscope(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -7967,95 +7642,105 @@ class InputResponseInputAppscope(BaseModel): pq: Optional[PqType] = None - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + tls: Optional[InputResponseTLSSettingsServerSide] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") - ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: Annotated[ Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - enable_unix_path: Annotated[ - Optional[bool], pydantic.Field(alias="enableUnixPath") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - filter_: Annotated[ - Optional[InputResponseInputAppscopeFilter], pydantic.Field(alias="filter") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - persistence: Optional[InputResponseInputAppscopePersistence] = None - r"""Persistence""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - host: Optional[str] = None - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - port: Optional[float] = None - r"""Port to listen on""" + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" - unix_socket_path: Annotated[ - Optional[str], pydantic.Field(alias="unixSocketPath") + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") ] = None - r"""Path to the UNIX domain socket to listen on.""" + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" - unix_socket_perms: Annotated[ - Optional[InputResponseUNIXSocketPermissions], - pydantic.Field(alias="unixSocketPerms"), + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -8077,21 +7762,32 @@ class InputResponseInputAppscope(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -8106,33 +7802,122 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", "breakerRulesets", "staleChannelFlushMs", - "enableUnixPath", - "filter", - "persistence", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputZscalerHecType(str, Enum): + r"""Source type identifier.""" + + ZSCALER_HEC = "zscaler_hec" + + +class InputResponseInputZscalerHecAuthTokenTypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + enabled: NotRequired[bool] + r"""Enable token""" + description: NotRequired[str] + r"""Description""" + allowed_indexes_at_token: NotRequired[List[str]] + r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputResponseInputZscalerHecAuthToken(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + enabled: Optional[bool] = None + r"""Enable token""" + + description: Optional[str] = None + r"""Description""" + + allowed_indexes_at_token: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexesAtToken") + ] = None + r"""Enter the values you want to allow in the HEC event index field at the token level. Supports wildcards. To skip validation, leave blank.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ "authType", + "tokenSecret", + "enabled", "description", - "host", - "port", - "tls", - "unixSocketPath", - "unixSocketPerms", - "authToken", - "textSecret", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "notifications", - "status", + "allowedIndexesAtToken", + "metadata", ] ) serialized = handler(self) @@ -8149,19 +7934,15 @@ def serialize_model(self, handler): return m -class InputResponseInputTCPType(str, Enum): - r"""Connector type identifier.""" - - TCP = "tcp" - - -class InputResponseInputTCPTypedDict(TypedDict): - type: InputResponseInputTCPType - r"""Connector type identifier.""" +class InputResponseInputZscalerHecTypedDict(TypedDict): + type: InputResponseInputZscalerHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -8176,45 +7957,50 @@ class InputResponseInputTCPTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[InputResponseInputZscalerHecAuthTokenTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_header: NotRequired[bool] - r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + hec_acks: NotRequired[bool] + r"""Whether to enable Zscaler HEC acknowledgements""" description: NotRequired[str] r"""Optional description for this configuration.""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -8223,15 +8009,23 @@ class InputResponseInputTCPTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputTCP(BaseModel): - type: InputResponseInputTCPType - r"""Connector type identifier.""" +class InputResponseInputZscalerHec(BaseModel): + type: InputResponseInputZscalerHecType + r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -8239,6 +8033,9 @@ class InputResponseInputTCP(BaseModel): port: float r"""Port to listen on""" + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Zscaler HTTP Event Collector API requests. This input supports the /event endpoint.""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -8263,7 +8060,7 @@ class InputResponseInputTCP(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -8273,74 +8070,98 @@ class InputResponseInputTCP(BaseModel): pq: Optional[PqType] = None + auth_tokens: Annotated[ + Optional[List[InputResponseInputZscalerHecAuthToken]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") - ] = None - r"""Regex matching IP addresses that are allowed to establish a connection""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Add request headers to events, in the __headers field""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") ] = None - r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( - None - ) - r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + hec_acks: Annotated[Optional[bool], pydantic.Field(alias="hecAcks")] = None + r"""Whether to enable Zscaler HEC acknowledgements""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -8362,21 +8183,32 @@ class InputResponseInputTCP(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -8389,28 +8221,36 @@ def serialize_model(self, handler): "pqEnabled", "streamtags", "criblSourceProvenance", - "connections", - "pq", - "tls", - "ipWhitelistRegex", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", "enableProxyHeader", + "captureHeaders", + "captureHeadersWarning", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", "metadata", - "breakerRulesets", - "staleChannelFlushMs", - "enableHeader", - "preprocess", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "hecAcks", "description", - "authToken", - "authType", - "textSecret", "__template_environment", "__template_streamtags", "__template_host", "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", "notifications", "status", ] @@ -8429,24 +8269,32 @@ def serialize_model(self, handler): return m -class InputResponseInputFileType(str, Enum): +class InputResponseInputProofpointPodType(str, Enum): r"""Connector type identifier.""" - FILE = "file" + PROOFPOINT_POD = "proofpoint_pod" -class InputResponseInputFileMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Choose how to discover files to monitor""" +class InputResponseFeedType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Proofpoint on Demand feed to ingest.""" - # Manual - MANUAL = "manual" - # Auto - AUTO = "auto" + # Message + MESSAGE = "message" + # Mail log + MAILLOG = "maillog" + # Audit + AUDIT = "audit" -class InputResponseInputFileTypedDict(TypedDict): - type: InputResponseInputFileType +class InputResponseInputProofpointPodTypedDict(TypedDict): + type: InputResponseInputProofpointPodType r"""Connector type identifier.""" + cluster_id: str + r"""Proofpoint on Demand cluster ID.""" + feed_type: InputResponseFeedType + r"""Proofpoint on Demand feed to ingest.""" + text_secret: str + r"""Select or create a stored text secret""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -8461,73 +8309,52 @@ class InputResponseInputFileTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - mode: NotRequired[InputResponseInputFileMode] - r"""Choose how to discover files to monitor""" - interval: NotRequired[float] - r"""Time, in seconds, between scanning for files""" - filenames: NotRequired[List[str]] - r"""The full path of discovered files are matched against this wildcard list""" - filter_archived_files: NotRequired[bool] - r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - tail_only: NotRequired[bool] - r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" - idle_timeout: NotRequired[float] - r"""Time, in seconds, before an idle file is closed""" - min_age_dur: NotRequired[str] - r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" - max_age_dur: NotRequired[str] - r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" - check_file_mod_time: NotRequired[bool] - r"""Skip files with modification times earlier than the maximum age duration""" - force_text: NotRequired[bool] - r"""Forces files containing binary data to be streamed as text""" - hash_len: NotRequired[float] - r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - disable_stale_channel_flush: NotRequired[bool] - r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + compress: NotRequired[bool] + r"""Compress the feed connection.""" + handshake_timeout: NotRequired[float] + r"""Maximum time to wait for the connection handshake to complete.""" + keep_alive_interval_sec: NotRequired[float] + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" + max_missed_keep_alives: NotRequired[float] + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" + max_message_size: NotRequired[str] + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" + read_buffer_size: NotRequired[str] + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" description: NotRequired[str] r"""Optional description for this configuration.""" - path: NotRequired[str] - r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" - depth: NotRequired[float] - r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" - suppress_missing_path_errors: NotRequired[bool] - r"""Suppress errors when search path does not exist""" - delete_files: NotRequired[bool] - r"""Delete files after they have been collected""" - salt_hash: NotRequired[bool] - r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" - optimize_leaf_directories: NotRequired[bool] - r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" - include_unidentifiable_binary: NotRequired[bool] - r"""Stream binary files as Base64-encoded chunks""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_cluster_id: NotRequired[str] + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputFile(BaseModel): - type: InputResponseInputFileType +class InputResponseInputProofpointPod(BaseModel): + type: InputResponseInputProofpointPodType r"""Connector type identifier.""" + cluster_id: Annotated[str, pydantic.Field(alias="clusterId")] + r"""Proofpoint on Demand cluster ID.""" + + feed_type: Annotated[InputResponseFeedType, pydantic.Field(alias="feedType")] + r"""Proofpoint on Demand feed to ingest.""" + + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored text secret""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -8552,7 +8379,7 @@ class InputResponseInputFile(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -8562,91 +8389,40 @@ class InputResponseInputFile(BaseModel): pq: Optional[PqType] = None - mode: Optional[InputResponseInputFileMode] = None - r"""Choose how to discover files to monitor""" - - interval: Optional[float] = None - r"""Time, in seconds, between scanning for files""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - filenames: Optional[List[str]] = None - r"""The full path of discovered files are matched against this wildcard list""" + compress: Optional[bool] = None + r"""Compress the feed connection.""" - filter_archived_files: Annotated[ - Optional[bool], pydantic.Field(alias="filterArchivedFiles") + handshake_timeout: Annotated[ + Optional[float], pydantic.Field(alias="handshakeTimeout") ] = None - r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - - tail_only: Annotated[Optional[bool], pydantic.Field(alias="tailOnly")] = None - r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" - - idle_timeout: Annotated[Optional[float], pydantic.Field(alias="idleTimeout")] = None - r"""Time, in seconds, before an idle file is closed""" - - min_age_dur: Annotated[Optional[str], pydantic.Field(alias="minAgeDur")] = None - r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" + r"""Maximum time to wait for the connection handshake to complete.""" - max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None - r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" - - check_file_mod_time: Annotated[ - Optional[bool], pydantic.Field(alias="checkFileModTime") + keep_alive_interval_sec: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveIntervalSec") ] = None - r"""Skip files with modification times earlier than the maximum age duration""" - - force_text: Annotated[Optional[bool], pydantic.Field(alias="forceText")] = None - r"""Forces files containing binary data to be streamed as text""" - - hash_len: Annotated[Optional[float], pydantic.Field(alias="hashLen")] = None - r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + r"""How often to send a keepalive ping while the feed is idle. Use 0 to disable keepalive pings.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + r"""Maximum number of consecutive keepalive pings that can go unanswered before reconnecting.""" - disable_stale_channel_flush: Annotated[ - Optional[bool], pydantic.Field(alias="disableStaleChannelFlush") + max_message_size: Annotated[ + Optional[str], pydantic.Field(alias="maxMessageSize") ] = None - r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" + r"""The maximum size of a single feed message. Enter a numeral with units of KB, MB, etc.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + read_buffer_size: Annotated[ + Optional[str], pydantic.Field(alias="readBufferSize") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""The maximum size to hold in memory before applying backpressure. Enter a numeral with units of KB, MB, etc.""" description: Optional[str] = None r"""Optional description for this configuration.""" - path: Optional[str] = None - r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" - - depth: Optional[float] = None - r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" - - suppress_missing_path_errors: Annotated[ - Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") - ] = None - r"""Suppress errors when search path does not exist""" - - delete_files: Annotated[Optional[bool], pydantic.Field(alias="deleteFiles")] = None - r"""Delete files after they have been collected""" - - salt_hash: Annotated[Optional[bool], pydantic.Field(alias="saltHash")] = None - r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" - - optimize_leaf_directories: Annotated[ - Optional[bool], pydantic.Field(alias="optimizeLeafDirectories") - ] = None - r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" - - include_unidentifiable_binary: Annotated[ - Optional[bool], pydantic.Field(alias="includeUnidentifiableBinary") - ] = None - r"""Stream binary files as Base64-encoded chunks""" - template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -8657,17 +8433,22 @@ class InputResponseInputFile(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_cluster_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clusterId") + ] = None + r"""Binds 'clusterId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterId' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("mode") - def serialize_mode(self, value): + @field_serializer("feed_type") + def serialize_feed_type(self, value): if isinstance(value, str): try: - return models.InputResponseInputFileMode(value) + return models.InputResponseFeedType(value) except ValueError: return value return value @@ -8686,31 +8467,17 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "mode", - "interval", - "filenames", - "filterArchivedFiles", - "tailOnly", - "idleTimeout", - "minAgeDur", - "maxAgeDur", - "checkFileModTime", - "forceText", - "hashLen", - "metadata", - "breakerRulesets", - "disableStaleChannelFlush", - "staleChannelFlushMs", + "tls", + "compress", + "handshakeTimeout", + "keepAliveIntervalSec", + "maxMissedKeepAlives", + "maxMessageSize", + "readBufferSize", "description", - "path", - "depth", - "suppressMissingPathErrors", - "deleteFiles", - "saltHash", - "optimizeLeafDirectories", - "includeUnidentifiableBinary", "__template_environment", "__template_streamtags", + "__template_clusterId", "notifications", "status", ] @@ -8729,13 +8496,64 @@ def serialize_model(self, handler): return m -class InputResponseInputSyslogSyslog2TypedDict(TypedDict): - type: TypeOptionsSyslog +class InputResponseInputServicenowTableType(str, Enum): r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - tcp_port: float - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + + SERVICENOW_TABLE = "servicenow_table" + + +class InputResponseSortDirection(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Used only when Sort by field is set.""" + + # Ascending + ASC = "asc" + # Descending + DESC = "desc" + + +class InputResponseInputServicenowTableAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""ServiceNow Table API authentication method""" + + # None + NONE = "none" + # Basic + BASIC_SECRET = "basicSecret" + # OAuth + OAUTH_SECRET = "oauthSecret" + + +class InputResponseGrantType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""ServiceNow OAuth grant type used for token requests""" + + # Password + CLIENT_CREDENTIALS = "client_credentials" + # Client credentials + PASSWORD = "password" + + +class InputResponseInputServicenowTableManageStateTypedDict(TypedDict): + pass + + +class InputResponseInputServicenowTableManageState(BaseModel): + pass + + +class InputResponseInputServicenowTableTypedDict(TypedDict): + type: InputResponseInputServicenowTableType + r"""Connector type identifier.""" + instance: str + r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" + table_name: str + r"""ServiceNow table name to collect from.""" + cron_schedule: str + r"""Cron schedule on which to run this job""" + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -8750,82 +8568,111 @@ class InputResponseInputSyslogSyslog2TypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - udp_port: NotRequired[float] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - timestamp_timezone: NotRequired[str] - r"""Timezone to assign to timestamps without timezone info""" - single_msg_udp_packets: NotRequired[bool] - r"""Treat UDP packet data received as full syslog message""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - keep_fields_list: NotRequired[List[str]] - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - octet_counting: NotRequired[bool] - r"""Enable if incoming messages use octet counting per RFC 6587.""" - infer_framing: NotRequired[bool] - r"""Enable if we should infer the syslog framing of the incoming messages.""" - strictly_infer_octet_counting: NotRequired[bool] - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - allow_non_standard_app_name: NotRequired[bool] - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + fields: NotRequired[List[str]] + r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" + order_by_field: NotRequired[str] + r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" + order_by_direction: NotRequired[InputResponseSortDirection] + r"""Used only when Sort by field is set.""" + query: NotRequired[str] + r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + page_size: NotRequired[int] + r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" + max_pages: NotRequired[int] + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + auth_type: NotRequired[InputResponseInputServicenowTableAuthenticationType] + r"""ServiceNow Table API authentication method""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + log_level: NotRequired[LogLevelOptions] + r"""Collector runtime log level""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + use_round_robin_dns: NotRequired[bool] + r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: NotRequired[bool] - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + oauth_grant_type: NotRequired[InputResponseGrantType] + r"""ServiceNow OAuth grant type used for token requests""" + username: NotRequired[str] + r"""ServiceNow username for the password grant type""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret for the ServiceNow password value""" + use_custom_o_auth_params_or_headers: NotRequired[bool] + r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + client_id: NotRequired[str] + r"""ServiceNow OAuth client ID""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth client secret value""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseInputServicenowTableManageStateTypedDict] template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - template_timestamp_timezone: NotRequired[str] - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_instance: NotRequired[str] + r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" + template_order_by_field: NotRequired[str] + r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" + template_query: NotRequired[str] + r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" + template_username: NotRequired[str] + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputSyslogSyslog2(BaseModel): - type: TypeOptionsSyslog +class InputResponseInputServicenowTable(BaseModel): + type: InputResponseInputServicenowTableType r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + instance: str + r"""ServiceNow instance base URL for Table API requests. Enter a literal URL (http or https and the instance host, for example a hostname ending in .service-now.com) or a Cribl expression that resolves to a URL.""" - tcp_port: Annotated[float, pydantic.Field(alias="tcpPort")] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""ServiceNow table name to collect from.""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""Cron schedule on which to run this job""" + + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" id: Optional[str] = None r"""Unique ID for this input""" @@ -8851,7 +8698,7 @@ class InputResponseInputSyslogSyslog2(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -8861,102 +8708,145 @@ class InputResponseInputSyslogSyslog2(BaseModel): pq: Optional[PqType] = None - udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + fields: Optional[List[str]] = None + r"""Field names to return from the Table API (sysparm_fields). Leave empty to return all fields.""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + order_by_field: Annotated[Optional[str], pydantic.Field(alias="orderByField")] = ( + None + ) + r"""Optional. Sort results by this field (for example sys_created_on or parent.name). Leave empty to use the server default order.""" + + order_by_direction: Annotated[ + Optional[InputResponseSortDirection], pydantic.Field(alias="orderByDirection") ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""Used only when Sort by field is set.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + query: Optional[str] = None + r"""Optional ServiceNow encoded query for sysparm_query (for example active=true or sys_updated_onRELATIVEGT@hour@ago@1). Enter a literal or a Cribl expression. When combined with Sort by field, the filter and sort are joined with ^. See ServiceNow Table API documentation for encoded query syntax.""" + + page_size: Annotated[Optional[int], pydantic.Field(alias="pageSize")] = None + r"""Maximum records per Table API page request (sysparm_limit). Setting a higher value may increase the risk of timeouts.""" + + max_pages: Annotated[Optional[int], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 to retrieve all pages.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" - timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="timestampTimezone") + auth_type: Annotated[ + Optional[InputResponseInputServicenowTableAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Timezone to assign to timestamps without timezone info""" + r"""ServiceNow Table API authentication method""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" + + log_level: Annotated[ + Optional[LogLevelOptions], pydantic.Field(alias="logLevel") ] = None - r"""Treat UDP packet data received as full syslog message""" + r"""Collector runtime log level""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - keep_fields_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="keepFieldsList") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + r"""When a DNS server returns multiple addresses, @{product} cycles through them in the order returned""" - octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( - None - ) - r"""Enable if incoming messages use octet counting per RFC 6587.""" + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" - infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( - None - ) - r"""Enable if we should infer the syslog framing of the incoming messages.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (e.g., 30, 45s or 15m). Units are seconds, if not specified. Enter 0 for unlimited time.""" - strictly_infer_octet_counting: Annotated[ - Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - allow_non_standard_app_name: Annotated[ - Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + oauth_grant_type: Annotated[ + Optional[InputResponseGrantType], pydantic.Field(alias="oauthGrantType") + ] = None + r"""ServiceNow OAuth grant type used for token requests""" + + username: Optional[str] = None + r"""ServiceNow username for the password grant type""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") - ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret for the ServiceNow password value""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + use_custom_o_auth_params_or_headers: Annotated[ + Optional[bool], pydantic.Field(alias="useCustomOAuthParamsOrHeaders") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""Enable custom OAuth request parameters or headers for advanced ServiceNow configurations. Leave disabled for standard ServiceNow OAuth flows.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""ServiceNow OAuth client ID""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""Select or create a stored text secret for the OAuth client secret value""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""JavaScript expression that defines how to update the state from an event. This source defaults to checking that `_time` is a finite number (not only `__timestampExtracted`), so state still advances when the event breaker assigns a fallback time. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields).""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - enable_enhanced_proxy_header_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + manage_state: Annotated[ + Optional[InputResponseInputServicenowTableManageState], + pydantic.Field(alias="manageState"), ] = None - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -8968,32 +8858,73 @@ class InputResponseInputSyslogSyslog2(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_instance: Annotated[ + Optional[str], pydantic.Field(alias="__template_instance") + ] = None + r"""Binds 'instance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'instance' at runtime.""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") + template_order_by_field: Annotated[ + Optional[str], pydantic.Field(alias="__template_orderByField") ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + r"""Binds 'orderByField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'orderByField' at runtime.""" - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") + template_query: Annotated[ + Optional[str], pydantic.Field(alias="__template_query") ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + r"""Binds 'query' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'query' at runtime.""" - template_timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="__template_timestampTimezone") + template_username: Annotated[ + Optional[str], pydantic.Field(alias="__template_username") ] = None - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + r"""Binds 'username' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'username' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("order_by_direction") + def serialize_order_by_direction(self, value): + if isinstance(value, str): + try: + return models.InputResponseSortDirection(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputServicenowTableAuthenticationType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("oauth_grant_type") + def serialize_oauth_grant_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseGrantType(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -9008,33 +8939,45 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "udpPort", - "maxBufferSize", - "ipWhitelistRegex", - "timestampTimezone", - "singleMsgUdpPackets", - "enableProxyHeader", - "keepFieldsList", - "octetCounting", - "inferFraming", - "strictlyInferOctetCounting", - "allowNonStandardAppName", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "tls", + "fields", + "orderByField", + "orderByDirection", + "query", + "pageSize", + "maxPages", + "rejectUnauthorized", + "authType", + "stateTracking", + "logLevel", + "requestTimeout", + "useRoundRobinDns", + "keepAliveTime", + "jobTimeout", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "udpSocketRxBufSize", - "enableLoadBalancing", + "retryRules", "description", - "enableEnhancedProxyHeaderParsing", + "credentialsSecret", + "oauthGrantType", + "username", + "textSecret", + "useCustomOAuthParamsOrHeaders", + "oauthParams", + "oauthHeaders", + "clientId", + "clientTextSecret", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", "__template_environment", "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", - "__template_timestampTimezone", + "__template_instance", + "__template_orderByField", + "__template_query", + "__template_username", + "__template_clientId", "notifications", "status", ] @@ -9053,13 +8996,17 @@ def serialize_model(self, handler): return m -class InputResponseInputSyslogSyslog1TypedDict(TypedDict): - type: TypeOptionsSyslog +class InputResponseInputBedrockS3Type(str, Enum): r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - udp_port: float - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + + BEDROCK_S3 = "bedrock_s3" + + +class InputResponseInputBedrockS3TypedDict(TypedDict): + type: InputResponseInputBedrockS3Type + r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -9074,82 +9021,131 @@ class InputResponseInputSyslogSyslog1TypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tcp_port: NotRequired[float] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - timestamp_timezone: NotRequired[str] - r"""Timezone to assign to timestamps without timezone info""" - single_msg_udp_packets: NotRequired[bool] - r"""Treat UDP packet data received as full syslog message""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - keep_fields_list: NotRequired[List[str]] - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - octet_counting: NotRequired[bool] - r"""Enable if incoming messages use octet counting per RFC 6587.""" - infer_framing: NotRequired[bool] - r"""Enable if we should infer the syslog framing of the incoming messages.""" - strictly_infer_octet_counting: NotRequired[bool] - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - allow_non_standard_app_name: NotRequired[bool] - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - socket_idle_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - socket_ending_max_wait: NotRequired[float] - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - socket_max_lifespan: NotRequired[float] - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Amazon S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" - enable_enhanced_proxy_header_parsing: NotRequired[bool] - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - template_timestamp_timezone: NotRequired[str] - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputSyslogSyslog1(BaseModel): - type: TypeOptionsSyslog +class InputResponseInputBedrockS3(BaseModel): + type: InputResponseInputBedrockS3Type r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - - udp_port: Annotated[float, pydantic.Field(alias="udpPort")] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -9175,7 +9171,7 @@ class InputResponseInputSyslogSyslog1(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -9185,139 +9181,288 @@ class InputResponseInputSyslogSyslog1(BaseModel): pq: Optional[PqType] = None - tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Regex matching IP addresses that are allowed to send data""" + r"""Reuse connections between requests, which can improve performance""" - timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="timestampTimezone") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Timezone to assign to timestamps without timezone info""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - single_msg_udp_packets: Annotated[ - Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""Treat UDP packet data received as full syslog message""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Amazon S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" + + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") + ] = None + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - keep_fields_list: Annotated[ - Optional[List[str]], pydantic.Field(alias="keepFieldsList") + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), ] = None - r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - - octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( - None - ) - r"""Enable if incoming messages use octet counting per RFC 6587.""" + r"""Choose Auto to use IAM roles""" - infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( None ) - r"""Enable if we should infer the syslog framing of the incoming messages.""" + r"""Select or create a stored secret that references your access key and secret key""" - strictly_infer_octet_counting: Annotated[ - Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") ] = None - r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + r"""SQS secret key""" - allow_non_standard_app_name: Annotated[ - Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") ] = None - r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" - - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - socket_idle_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketIdleTimeout") + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - socket_ending_max_wait: Annotated[ - Optional[float], pydantic.Field(alias="socketEndingMaxWait") + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") ] = None - r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - socket_max_lifespan: Annotated[ - Optional[float], pydantic.Field(alias="socketMaxLifespan") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - enable_enhanced_proxy_header_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_timestamp_timezone: Annotated[ - Optional[str], pydantic.Field(alias="__template_timestampTimezone") + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") ] = None - r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -9332,82 +9477,84 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "tcpPort", - "maxBufferSize", - "ipWhitelistRegex", - "timestampTimezone", - "singleMsgUdpPackets", - "enableProxyHeader", - "keepFieldsList", - "octetCounting", - "inferFraming", - "strictlyInferOctetCounting", - "allowNonStandardAppName", - "maxActiveCxn", - "socketIdleTimeout", - "socketEndingMaxWait", - "socketMaxLifespan", - "tls", + "fileFilter", + "awsAccountId", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", "metadata", - "udpSocketRxBufSize", - "enableLoadBalancing", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", + "pollTimeout", + "encoding", "description", - "enableEnhancedProxyHeaderParsing", + "awsApiKey", + "awsSecret", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", "__template_environment", "__template_streamtags", - "__template_host", - "__template_udpPort", - "__template_tcpPort", - "__template_timestampTimezone", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -InputResponseInputSyslogUnionTypedDict = TypeAliasType( - "InputResponseInputSyslogUnionTypedDict", - Union[ - InputResponseInputSyslogSyslog1TypedDict, - InputResponseInputSyslogSyslog2TypedDict, - ], -) - - -InputResponseInputSyslogUnion = TypeAliasType( - "InputResponseInputSyslogUnion", - Union[InputResponseInputSyslogSyslog1, InputResponseInputSyslogSyslog2], -) + "__template_queueName", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) -class InputResponseQueueType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The queue type used (or created)""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - # Standard - STANDARD = "standard" - # FIFO - FIFO = "fifo" + return m -class InputResponseInputSqsTypedDict(TypedDict): - type: TypeOptionsSqs +class InputResponseInputSecurityLakeTypedDict(TypedDict): + type: TypeOptionsSecuritylake r"""Connector type identifier.""" queue_name: str - r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - queue_type: InputResponseQueueType - r"""The queue type used (or created)""" + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -9422,61 +9569,99 @@ class InputResponseInputSqsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + file_filter: NotRequired[str] + r"""Regex matching file names to download and process. Defaults to: .*""" aws_account_id: NotRequired[str] r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - create_queue: NotRequired[bool] - r"""Create queue if it does not exist""" aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] r"""AWS authentication method. Choose Auto to use IAM roles.""" aws_secret_key: NotRequired[str] r"""Secret key""" region: NotRequired[str] - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" endpoint: NotRequired[str] - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" reuse_connections: NotRequired[bool] r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + socket_timeout: NotRequired[float] + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + skip_on_error: NotRequired[bool] + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + include_sqs_metadata: NotRequired[bool] + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SQS""" + r"""Use Assume Role credentials to access Amazon S3""" assume_role_arn: NotRequired[str] r"""Amazon Resource Name (ARN) of the role to assume""" assume_role_external_id: NotRequired[str] r"""External ID to use when assuming role""" duration_seconds: NotRequired[float] r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + enable_sqs_assume_role: NotRequired[bool] + r"""Use Assume Role credentials when accessing Amazon SQS""" + shared_credentials: NotRequired[bool] + r"""Use the same credential settings for S3 and SQS""" + shared_assume_role_arn: NotRequired[bool] + r"""Use the same settings for S3 and SQS""" + preprocess: NotRequired[PreprocessTypeTypedDict] + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + parquet_chunk_size_mb: NotRequired[float] + r"""Maximum file size for each Parquet chunk""" + parquet_chunk_download_timeout: NotRequired[float] + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + checkpointing: NotRequired[CheckpointingTypeTypedDict] poll_timeout: NotRequired[float] r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: NotRequired[str] + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] r"""Access key""" aws_secret: NotRequired[str] r"""Select or create a stored secret that references your access key and secret key""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + sqs_assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + sqs_assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + sqs_duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] + r"""Choose Auto to use IAM roles""" + sqs_aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + sqs_aws_secret_key: NotRequired[str] + r"""SQS secret key""" + tag_after_processing: NotRequired[TagAfterProcessingOptions] + processed_tag_key: NotRequired[str] + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + processed_tag_value: NotRequired[str] + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_queue_name: NotRequired[str] r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: NotRequired[str] - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" template_aws_account_id: NotRequired[str] r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" template_aws_secret_key: NotRequired[str] @@ -9491,21 +9676,24 @@ class InputResponseInputSqsTypedDict(TypedDict): r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_aws_api_key: NotRequired[str] r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_sqs_assume_role_arn: NotRequired[str] + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + template_sqs_assume_role_external_id: NotRequired[str] + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + template_sqs_aws_secret_key: NotRequired[str] + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputSqs(BaseModel): - type: TypeOptionsSqs +class InputResponseInputSecurityLake(BaseModel): + type: TypeOptionsSecuritylake r"""Connector type identifier.""" queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - - queue_type: Annotated[InputResponseQueueType, pydantic.Field(alias="queueType")] - r"""The queue type used (or created)""" + r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -9531,7 +9719,7 @@ class InputResponseInputSqs(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -9541,14 +9729,14 @@ class InputResponseInputSqs(BaseModel): pq: Optional[PqType] = None + file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None + r"""Regex matching file names to download and process. Defaults to: .*""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( None ) r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None - r"""Create queue if it does not exist""" - aws_authentication_method: Annotated[ Optional[AuthenticationMethodOptionsS3CollectorConf], pydantic.Field(alias="awsAuthenticationMethod"), @@ -9561,10 +9749,10 @@ class InputResponseInputSqs(BaseModel): r"""Secret key""" region: Optional[str] = None - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" endpoint: Optional[str] = None - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" reuse_connections: Annotated[ Optional[bool], pydantic.Field(alias="reuseConnections") @@ -9576,10 +9764,46 @@ class InputResponseInputSqs(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + + skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None + r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + + include_sqs_metadata: Annotated[ + Optional[bool], pydantic.Field(alias="includeSqsMetadata") + ] = None + r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + enable_assume_role: Annotated[ Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Use Assume Role credentials to access SQS""" + r"""Use Assume Role credentials to access Amazon S3""" assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None @@ -9596,20 +9820,45 @@ class InputResponseInputSqs(BaseModel): ] = None r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + enable_sqs_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + ] = None + r"""Use Assume Role credentials when accessing Amazon SQS""" - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") + shared_credentials: Annotated[ + Optional[bool], pydantic.Field(alias="sharedCredentials") ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + r"""Use the same credential settings for S3 and SQS""" + + shared_assume_role_arn: Annotated[ + Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") + ] = None + r"""Use the same settings for S3 and SQS""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + parquet_chunk_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkSizeMB") + ] = None + r"""Maximum file size for each Parquet chunk""" + + parquet_chunk_download_timeout: Annotated[ + Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") + ] = None + r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + + checkpointing: Optional[CheckpointingType] = None + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + encoding: Optional[str] = None + r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -9619,10 +9868,50 @@ class InputResponseInputSqs(BaseModel): aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None r"""Select or create a stored secret that references your access key and secret key""" - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") + ] = None + r"""Amazon Resource Name (ARN) of the role to assume""" + + sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + sqs_duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="SQSDurationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + sqs_aws_authentication_method: Annotated[ + Optional[SqsAuthenticationMethodOptions], + pydantic.Field(alias="SQSAwsAuthenticationMethod"), + ] = None + r"""Choose Auto to use IAM roles""" + + sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( None ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + r"""Select or create a stored secret that references your access key and secret key""" + + sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="SQSAwsSecretKey") + ] = None + r"""SQS secret key""" + + tag_after_processing: Annotated[ + Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") + ] = None + + processed_tag_key: Annotated[ + Optional[str], pydantic.Field(alias="processedTagKey") + ] = None + r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + + processed_tag_value: Annotated[ + Optional[str], pydantic.Field(alias="processedTagValue") + ] = None + r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -9639,11 +9928,6 @@ class InputResponseInputSqs(BaseModel): ] = None r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueType") - ] = None - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - template_aws_account_id: Annotated[ Optional[str], pydantic.Field(alias="__template_awsAccountId") ] = None @@ -9677,28 +9961,52 @@ class InputResponseInputSqs(BaseModel): template_aws_api_key: Annotated[ Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_sqs_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + ] = None + r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + + template_sqs_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + ] = None + r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + + template_sqs_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + ] = None + r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("queue_type") - def serialize_queue_type(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.InputResponseQueueType(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("sqs_aws_authentication_method") + def serialize_sqs_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.SqsAuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("tag_after_processing") + def serialize_tag_after_processing(self, value): + if isinstance(value, str): + try: + return models.TagAfterProcessingOptions(value) except ValueError: return value return value @@ -9717,30 +10025,51 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", + "fileFilter", "awsAccountId", - "createQueue", "awsAuthenticationMethod", "awsSecretKey", "region", "endpoint", "reuseConnections", "rejectUnauthorized", + "breakerRulesets", + "staleChannelFlushMs", + "maxMessages", + "visibilityTimeout", + "numReceivers", + "socketTimeout", + "skipOnError", + "includeSqsMetadata", "enableAssumeRole", "assumeRoleArn", "assumeRoleExternalId", "durationSeconds", - "maxMessages", - "visibilityTimeout", + "enableSQSAssumeRole", + "sharedCredentials", + "sharedAssumeRoleArn", + "preprocess", "metadata", + "parquetChunkSizeMB", + "parquetChunkDownloadTimeout", + "checkpointing", "pollTimeout", + "encoding", "description", "awsApiKey", "awsSecret", - "numReceivers", + "SQSAssumeRoleArn", + "SQSAssumeRoleExternalId", + "SQSDurationSeconds", + "SQSAwsAuthenticationMethod", + "SQSAwsSecret", + "SQSAwsSecretKey", + "tagAfterProcessing", + "processedTagKey", + "processedTagValue", "__template_environment", "__template_streamtags", "__template_queueName", - "__template_queueType", "__template_awsAccountId", "__template_awsSecretKey", "__template_region", @@ -9748,6 +10077,9 @@ def serialize_model(self, handler): "__template_assumeRoleArn", "__template_assumeRoleExternalId", "__template_awsApiKey", + "__template_SQSAssumeRoleArn", + "__template_SQSAssumeRoleExternalId", + "__template_SQSAwsSecretKey", "notifications", "status", ] @@ -9766,17 +10098,11 @@ def serialize_model(self, handler): return m -class InputResponseInputModelDrivenTelemetryType(str, Enum): - r"""Connector type identifier.""" - - MODEL_DRIVEN_TELEMETRY = "model_driven_telemetry" - - -class InputResponseInputModelDrivenTelemetryTypedDict(TypedDict): - type: InputResponseInputModelDrivenTelemetryType +class InputResponseInputNetflowTypedDict(TypedDict): + type: TypeOptionsNetflow r"""Connector type identifier.""" host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" port: float r"""Port to listen on""" id: NotRequired[str] @@ -9793,21 +10119,29 @@ class InputResponseInputModelDrivenTelemetryTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + enable_pass_through: NotRequired[bool] + r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + template_cache_minutes: NotRequired[float] + r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" + v5_enabled: NotRequired[bool] + r"""Accept messages in Netflow V5 format.""" + v9_enabled: NotRequired[bool] + r"""Accept messages in Netflow V9 format.""" + ipfix_enabled: NotRequired[bool] + r"""Accept messages in IPFIX format.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - shutdown_timeout_ms: NotRequired[float] - r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -9818,18 +10152,18 @@ class InputResponseInputModelDrivenTelemetryTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputModelDrivenTelemetry(BaseModel): - type: InputResponseInputModelDrivenTelemetryType +class InputResponseInputNetflow(BaseModel): + type: TypeOptionsNetflow r"""Connector type identifier.""" host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" port: float r"""Port to listen on""" @@ -9858,7 +10192,7 @@ class InputResponseInputModelDrivenTelemetry(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -9868,21 +10202,44 @@ class InputResponseInputModelDrivenTelemetry(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + enable_pass_through: Annotated[ + Optional[bool], pydantic.Field(alias="enablePassThrough") + ] = None + r"""Allow forwarding of events to a NetFlow destination. Enabling this feature will generate an extra event containing __netflowRaw which can be routed to a NetFlow destination. Note that these events will not count against ingest quota.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + + template_cache_minutes: Annotated[ + Optional[float], pydantic.Field(alias="templateCacheMinutes") + ] = None + r"""Specifies how many minutes NetFlow v9 templates are cached before being discarded if not refreshed. Adjust based on your network's template update frequency to optimize performance and memory usage.""" + + v5_enabled: Annotated[Optional[bool], pydantic.Field(alias="v5Enabled")] = None + r"""Accept messages in Netflow V5 format.""" + + v9_enabled: Annotated[Optional[bool], pydantic.Field(alias="v9Enabled")] = None + r"""Accept messages in Netflow V9 format.""" + + ipfix_enabled: Annotated[Optional[bool], pydantic.Field(alias="ipfixEnabled")] = ( None ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + r"""Accept messages in IPFIX format.""" - shutdown_timeout_ms: Annotated[ - Optional[float], pydantic.Field(alias="shutdownTimeoutMs") - ] = None - r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -9907,7 +10264,7 @@ class InputResponseInputModelDrivenTelemetry(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -9927,10 +10284,15 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "tls", + "enablePassThrough", + "ipAllowlistRegex", + "ipDenylistRegex", + "udpSocketRxBufSize", + "templateCacheMinutes", + "v5Enabled", + "v9Enabled", + "ipfixEnabled", "metadata", - "maxActiveCxn", - "shutdownTimeoutMs", "description", "__template_environment", "__template_streamtags", @@ -9954,138 +10316,113 @@ def serialize_model(self, handler): return m -class InputResponseInputOpenTelemetryType(str, Enum): +class InputResponseInputWizWebhookType(str, Enum): r"""Source type identifier.""" - OPEN_TELEMETRY = "open_telemetry" - - -class InputResponseProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - - # gRPC - GRPC = "grpc" - # HTTP - HTTP = "http" - + WIZ_WEBHOOK = "wiz_webhook" -class InputResponseOTLPVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - # 0.10.0 - ZERO_DOT_10_DOT_0 = "0.10.0" - # 1.3.1 - ONE_DOT_3_DOT_1 = "1.3.1" +class InputResponseInputWizWebhookAuthTokensExt2TypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: str + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" -class InputResponseInputOpenTelemetryAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""OpenTelemetry authentication type""" +class InputResponseInputWizWebhookAuthTokensExt2(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" -class InputResponseAuthMethodsExtAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" + description: Optional[str] = None + r"""Description""" - # Token - TOKEN = "token" - # Token (secret) - TOKEN_SECRET = "tokenSecret" - # Basic - BASIC = "basic" - # Basic (credentials secret) - BASIC_SECRET = "basicSecret" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value -class InputResponseAuthMethodsExtTypedDict(TypedDict): - auth_type: InputResponseAuthMethodsExtAuthenticationType - r"""Authentication type""" - token: NotRequired[str] - r"""Bearer token for Authorization header""" - description: NotRequired[str] - r"""Description""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events referencing this auth method""" - enabled: NotRequired[bool] - r"""Enable""" - token_secret: NotRequired[str] - r"""Select or create a stored text secret""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["token", "description", "metadata"]) + serialized = handler(self) + m = {} + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) -class InputResponseAuthMethodsExt(BaseModel): - auth_type: Annotated[ - InputResponseAuthMethodsExtAuthenticationType, pydantic.Field(alias="authType") - ] - r"""Authentication type""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - token: Optional[str] = None - r"""Bearer token for Authorization header""" + return m - description: Optional[str] = None + +class InputResponseInputWizWebhookAuthTokensExt1TypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events referencing this auth method""" - enabled: Optional[bool] = None - r"""Enable""" +class InputResponseInputWizWebhookAuthTokensExt1(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None r"""Select or create a stored text secret""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" + description: Optional[str] = None + r"""Description""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.InputResponseAuthMethodsExtAuthenticationType(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set( - [ - "token", - "description", - "metadata", - "enabled", - "tokenSecret", - "username", - "password", - "credentialsSecret", - ] - ) + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) serialized = handler(self) m = {} @@ -10100,8 +10437,26 @@ def serialize_model(self, handler): return m -class InputResponseInputOpenTelemetryTypedDict(TypedDict): - type: InputResponseInputOpenTelemetryType +InputResponseInputWizWebhookAuthTokensExtUnionTypedDict = TypeAliasType( + "InputResponseInputWizWebhookAuthTokensExtUnionTypedDict", + Union[ + InputResponseInputWizWebhookAuthTokensExt1TypedDict, + InputResponseInputWizWebhookAuthTokensExt2TypedDict, + ], +) + + +InputResponseInputWizWebhookAuthTokensExtUnion = TypeAliasType( + "InputResponseInputWizWebhookAuthTokensExtUnion", + Union[ + InputResponseInputWizWebhookAuthTokensExt1, + InputResponseInputWizWebhookAuthTokensExt2, + ], +) + + +class InputResponseInputWizWebhookTypedDict(TypedDict): + type: InputResponseInputWizWebhookType r"""Source type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -10121,62 +10476,54 @@ class InputResponseInputOpenTelemetryTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[str]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" tls: NotRequired[TLSSettingsServerSideTypeTypedDict] r"""TLS settings (server side)""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" max_requests_per_socket: NotRequired[int] r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" capture_headers_warning: Literal[""] + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" request_timeout: NotRequired[float] r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" socket_timeout: NotRequired[float] r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" enable_health_check: NotRequired[bool] - r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - protocol: NotRequired[InputResponseProtocol] - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - extract_spans: NotRequired[bool] - r"""Enable to extract each incoming span to a separate event""" - extract_metrics: NotRequired[bool] - r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - otlp_version: NotRequired[InputResponseOTLPVersion] - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - auth_type: NotRequired[InputResponseInputOpenTelemetryAuthenticationType] - r"""OpenTelemetry authentication type""" - auth_methods_ext: NotRequired[List[InputResponseAuthMethodsExtTypedDict]] - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - max_active_cxn: NotRequired[float] - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + allowed_paths: NotRequired[List[str]] + r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" + allowed_methods: NotRequired[List[str]] + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" + auth_tokens_ext: NotRequired[ + List[InputResponseInputWizWebhookAuthTokensExtUnionTypedDict] + ] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - extract_logs: NotRequired[bool] - r"""Enable to extract each incoming log record to a separate event""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -10185,18 +10532,18 @@ class InputResponseInputOpenTelemetryTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_protocol: NotRequired[str] - r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" - template_otlp_version: NotRequired[str] - r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_auth_tokens: NotRequired[str] + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" + template_allowed_paths: NotRequired[str] + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputOpenTelemetry(BaseModel): - type: InputResponseInputOpenTelemetryType +class InputResponseInputWizWebhook(BaseModel): + type: InputResponseInputWizWebhookType r"""Source type identifier.""" host: str @@ -10229,7 +10576,7 @@ class InputResponseInputOpenTelemetry(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -10239,6 +10586,11 @@ class InputResponseInputOpenTelemetry(BaseModel): pq: Optional[PqType] = None + auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( + None + ) + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: Optional[TLSSettingsServerSideType] = None r"""TLS settings (server side)""" @@ -10252,11 +10604,26 @@ class InputResponseInputOpenTelemetry(BaseModel): ] = None r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + CAPTURE_HEADERS_WARNING: Annotated[ Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], pydantic.Field(alias="captureHeadersWarning"), ] = "" + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: Annotated[ Optional[float], pydantic.Field(alias="requestTimeout") ] = None @@ -10270,83 +10637,54 @@ class InputResponseInputOpenTelemetry(BaseModel): keep_alive_timeout: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTimeout") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" enable_health_check: Annotated[ Optional[bool], pydantic.Field(alias="enableHealthCheck") ] = None - r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" ip_allowlist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipDenylistRegex") ] = None r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - protocol: Optional[InputResponseProtocol] = None - r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - - extract_spans: Annotated[Optional[bool], pydantic.Field(alias="extractSpans")] = ( - None - ) - r"""Enable to extract each incoming span to a separate event""" - - extract_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="extractMetrics") - ] = None - r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - - otlp_version: Annotated[ - Optional[InputResponseOTLPVersion], pydantic.Field(alias="otlpVersion") - ] = None - r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - - auth_type: Annotated[ - Optional[InputResponseInputOpenTelemetryAuthenticationType], - pydantic.Field(alias="authType"), + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""OpenTelemetry authentication type""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - auth_methods_ext: Annotated[ - Optional[List[InputResponseAuthMethodsExt]], - pydantic.Field(alias="authMethodsExt"), + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""Shared secrets to authenticate clients. Supports Bearer tokens and Basic auth. If empty, unauthenticated access is permitted.""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( - None - ) - r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" + allowed_paths: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedPaths") + ] = None + r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + allowed_methods: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedMethods") ] = None - r"""Select or create a secret that references your credentials""" + r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + auth_tokens_ext: Annotated[ + Optional[List[InputResponseInputWizWebhookAuthTokensExtUnion]], + pydantic.Field(alias="authTokensExt"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - extract_logs: Annotated[Optional[bool], pydantic.Field(alias="extractLogs")] = None - r"""Enable to extract each incoming log record to a separate event""" + description: Optional[str] = None + r"""Optional description for this configuration.""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -10368,48 +10706,21 @@ class InputResponseInputOpenTelemetry(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_protocol: Annotated[ - Optional[str], pydantic.Field(alias="__template_protocol") + template_auth_tokens: Annotated[ + Optional[str], pydantic.Field(alias="__template_authTokens") ] = None - r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_otlp_version: Annotated[ - Optional[str], pydantic.Field(alias="__template_otlpVersion") + template_allowed_paths: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedPaths") ] = None - r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.InputResponseProtocol(value) - except ValueError: - return value - return value - - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.InputResponseOTLPVersion(value) - except ValueError: - return value - return value + r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputOpenTelemetryAuthenticationType(value) - except ValueError: - return value - return value + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -10425,37 +10736,33 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", + "authTokens", "tls", "maxActiveReq", "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", "captureHeadersWarning", + "activityLogSampleRate", "requestTimeout", "socketTimeout", "keepAliveTimeout", "enableHealthCheck", "ipAllowlistRegex", "ipDenylistRegex", - "protocol", - "extractSpans", - "extractMetrics", - "otlpVersion", - "authType", - "authMethodsExt", + "breakerRulesets", + "staleChannelFlushMs", "metadata", - "maxActiveCxn", + "allowedPaths", + "allowedMethods", + "authTokensExt", "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "extractLogs", "__template_environment", "__template_streamtags", "__template_host", "__template_port", - "__template_protocol", - "__template_otlpVersion", + "__template_authTokens", + "__template_allowedPaths", "notifications", "status", ] @@ -10474,345 +10781,223 @@ def serialize_model(self, handler): return m -class InputResponseAuthenticationProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Authentication protocol""" - - # None - NONE = "none" - # MD5 - MD5 = "md5" - # SHA1 - SHA = "sha" - # SHA224 - SHA224 = "sha224" - # SHA256 - SHA256 = "sha256" - # SHA384 - SHA384 = "sha384" - # SHA512 - SHA512 = "sha512" - - -class InputResponsePrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Privacy protocol""" - - # None - NONE = "none" - # DES - DES = "des" - # AES128 - AES = "aes" - # AES256b (Blumenthal) - AES256B = "aes256b" - # AES256r (Reeder) - AES256R = "aes256r" - - -class InputResponseV3UserTypedDict(TypedDict): - name: str - r"""V3 name""" - auth_protocol: NotRequired[InputResponseAuthenticationProtocol] - r"""Authentication protocol""" - auth_key: NotRequired[str] - r"""V3 authentication key""" - priv_protocol: NotRequired[InputResponsePrivacyProtocol] - r"""Privacy protocol""" - priv_key: NotRequired[str] - r"""V3 privacy key""" - - -class InputResponseV3User(BaseModel): - name: str - r"""V3 name""" - - auth_protocol: Annotated[ - Optional[InputResponseAuthenticationProtocol], - pydantic.Field(alias="authProtocol"), - ] = None - r"""Authentication protocol""" - - auth_key: Annotated[Optional[str], pydantic.Field(alias="authKey")] = None - r"""V3 authentication key""" - - priv_protocol: Annotated[ - Optional[InputResponsePrivacyProtocol], pydantic.Field(alias="privProtocol") - ] = None - r"""Privacy protocol""" - - priv_key: Annotated[Optional[str], pydantic.Field(alias="privKey")] = None - r"""V3 privacy key""" - - @field_serializer("auth_protocol") - def serialize_auth_protocol(self, value): - if isinstance(value, str): - try: - return models.InputResponseAuthenticationProtocol(value) - except ValueError: - return value - return value - - @field_serializer("priv_protocol") - def serialize_priv_protocol(self, value): - if isinstance(value, str): - try: - return models.InputResponsePrivacyProtocol(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["authProtocol", "authKey", "privProtocol", "privKey"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - +class InputResponseInputOpenaiType(str, Enum): + r"""Connector type identifier.""" -class InputResponseSNMPv3AuthenticationTypedDict(TypedDict): - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + OPENAI = "openai" - v3_auth_enabled: bool - r"""Enabled""" - allow_unmatched_trap: NotRequired[bool] - r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" - v3_users: NotRequired[List[InputResponseV3UserTypedDict]] - r"""User credentials for receiving v3 traps""" +class InputResponseInputOpenaiManageStateTypedDict(TypedDict): + pass -class InputResponseSNMPv3Authentication(BaseModel): - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" - v3_auth_enabled: Annotated[bool, pydantic.Field(alias="v3AuthEnabled")] - r"""Enabled""" +class InputResponseInputOpenaiManageState(BaseModel): + pass - allow_unmatched_trap: Annotated[ - Optional[bool], pydantic.Field(alias="allowUnmatchedTrap") - ] = None - r"""Pass through traps that don't match any of the configured users. @{product} will not attempt to decrypt these traps.""" - v3_users: Annotated[ - Optional[List[InputResponseV3User]], pydantic.Field(alias="v3Users") - ] = None - r"""User credentials for receiving v3 traps""" +class InputResponsePaginationType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Pagination type""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["allowUnmatchedTrap", "v3Users"]) - serialized = handler(self) - m = {} + # None + NONE = "none" + # Response Body Attribute + RESPONSE_BODY = "response_body" + # Response Header Attribute + RESPONSE_HEADER = "response_header" + # RFC 5988 Link Header + RESPONSE_HEADER_LINK = "response_header_link" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class InputResponseInputOpenaiLogLevel(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Collector runtime log level.""" - return m + ERROR = "error" + WARN = "warn" + INFO = "info" + DEBUG = "debug" + SILLY = "silly" -class InputResponseInputSnmpTypedDict(TypedDict): - type: TypeOptionsSnmp - r"""Connector type identifier.""" - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - port: float - r"""UDP port to receive SNMP traps on. Defaults to 162.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict +class InputResponseInputOpenaiContentConfigTypedDict(TypedDict): + content_type: str + r"""Content type""" + collect_path: str + r"""OpenAI Organization API path""" + request_params: List[ + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - snmp_v3_auth: NotRequired[InputResponseSNMPv3AuthenticationTypedDict] - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" - max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking.""" - ip_whitelist_regex: NotRequired[str] - r"""Regex matching IP addresses that are allowed to send data""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - udp_socket_rx_buf_size: NotRequired[float] - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - varbinds_with_types: NotRequired[bool] - r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" - best_effort_parsing: NotRequired[bool] - r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputSnmp(BaseModel): - type: TypeOptionsSnmp - r"""Connector type identifier.""" - - host: str - r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + r"""Query-string parameters to send with this endpoint""" + pagination_type: InputResponsePaginationType + r"""Pagination type""" + cron_schedule: str + r"""A cron schedule on which to run this job""" + earliest: str + r"""Relative to the current time""" + latest: str + r"""Relative to the current time""" + content_description: NotRequired[str] + r"""Description""" + docs_url: NotRequired[str] + r"""Docs URL""" + disabled: NotRequired[bool] + r"""Enabled""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions.""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseInputOpenaiManageStateTypedDict] + pagination_attribute: NotRequired[List[str]] + r"""Pagination attributes""" + pagination_last_page_expr: NotRequired[str] + r"""Last page expression""" + max_pages: NotRequired[float] + r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" + pagination_next_relation_attribute: NotRequired[str] + r"""Used only for RFC 5988 link-header pagination""" + pagination_cur_relation_attribute: NotRequired[str] + r"""Optional relation that represents the current page""" + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" + log_level: NotRequired[InputResponseInputOpenaiLogLevel] + r"""Collector runtime log level.""" + endpoint_metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields automatically added to events from this Content Type""" - port: float - r"""UDP port to receive SNMP traps on. Defaults to 162.""" - id: Optional[str] = None - r"""Unique ID for this input""" +class InputResponseInputOpenaiContentConfig(BaseModel): + content_type: Annotated[str, pydantic.Field(alias="contentType")] + r"""Content type""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" + collect_path: Annotated[str, pydantic.Field(alias="collectPath")] + r"""OpenAI Organization API path""" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" + request_params: Annotated[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret], + pydantic.Field(alias="requestParams"), + ] + r"""Query-string parameters to send with this endpoint""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" + pagination_type: Annotated[ + InputResponsePaginationType, pydantic.Field(alias="paginationType") + ] + r"""Pagination type""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""A cron schedule on which to run this job""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + earliest: str + r"""Relative to the current time""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + latest: str + r"""Relative to the current time""" - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), + content_description: Annotated[ + Optional[str], pydantic.Field(alias="contentDescription") ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + r"""Description""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + docs_url: Annotated[Optional[str], pydantic.Field(alias="docsUrl")] = None + r"""Docs URL""" - pq: Optional[PqType] = None + disabled: Optional[bool] = None + r"""Enabled""" - snmp_v3_auth: Annotated[ - Optional[InputResponseSNMPv3Authentication], pydantic.Field(alias="snmpV3Auth") - ] = None - r"""Authentication parameters for SNMPv3 trap. Set the log level to debug if you are experiencing authentication or decryption issues.""" + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions.""" - max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="maxBufferSize") + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") ] = None - r"""Maximum number of events to buffer when downstream is blocking.""" + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" - ip_whitelist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipWhitelistRegex") + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") ] = None - r"""Regex matching IP addresses that are allowed to send data""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" - udp_socket_rx_buf_size: Annotated[ - Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + manage_state: Annotated[ + Optional[InputResponseInputOpenaiManageState], + pydantic.Field(alias="manageState"), ] = None - r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" - varbinds_with_types: Annotated[ - Optional[bool], pydantic.Field(alias="varbindsWithTypes") + pagination_attribute: Annotated[ + Optional[List[str]], pydantic.Field(alias="paginationAttribute") ] = None - r"""If enabled, parses varbinds as an array of objects that include OID, value, and type""" + r"""Pagination attributes""" - best_effort_parsing: Annotated[ - Optional[bool], pydantic.Field(alias="bestEffortParsing") + pagination_last_page_expr: Annotated[ + Optional[str], pydantic.Field(alias="paginationLastPageExpr") ] = None - r"""If enabled, the parser will attempt to parse varbind octet strings as UTF-8, first, otherwise will fallback to other methods""" + r"""Last page expression""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Set to 0 only when unlimited pagination is required.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + pagination_next_relation_attribute: Annotated[ + Optional[str], pydantic.Field(alias="paginationNextRelationAttribute") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Used only for RFC 5988 link-header pagination""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + pagination_cur_relation_attribute: Annotated[ + Optional[str], pydantic.Field(alias="paginationCurRelationAttribute") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Optional relation that represents the current page""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Enter 0 for unlimited time.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + log_level: Annotated[ + Optional[InputResponseInputOpenaiLogLevel], pydantic.Field(alias="logLevel") + ] = None + r"""Collector runtime log level.""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + endpoint_metadata: Annotated[ + Optional[List[MetadataConfInputCollection]], + pydantic.Field(alias="endpointMetadata"), + ] = None + r"""Fields automatically added to events from this Content Type""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("pagination_type") + def serialize_pagination_type(self, value): + if isinstance(value, str): + try: + return models.InputResponsePaginationType(value) + except ValueError: + return value + return value + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputOpenaiLogLevel(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "id", + "contentDescription", + "docsUrl", "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "snmpV3Auth", - "maxBufferSize", - "ipWhitelistRegex", - "metadata", - "udpSocketRxBufSize", - "varbindsWithTypes", - "bestEffortParsing", - "description", - "__template_environment", - "__template_streamtags", - "__template_host", - "__template_port", - "notifications", - "status", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "paginationAttribute", + "paginationLastPageExpr", + "maxPages", + "paginationNextRelationAttribute", + "paginationCurRelationAttribute", + "jobTimeout", + "logLevel", + "endpointMetadata", ] ) serialized = handler(self) @@ -10829,17 +11014,13 @@ def serialize_model(self, handler): return m -class InputResponseInputS3InventoryType(str, Enum): - r"""Connector type identifier.""" - - S3_INVENTORY = "s3_inventory" - - -class InputResponseInputS3InventoryTypedDict(TypedDict): - type: InputResponseInputS3InventoryType +class InputResponseInputOpenaiTypedDict(TypedDict): + type: InputResponseInputOpenaiType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + content_config: List[InputResponseInputOpenaiContentConfigTypedDict] + r"""Content Types""" + text_secret: str + r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -10854,137 +11035,58 @@ class InputResponseInputS3InventoryTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + openai_organization: NotRequired[str] + r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" + openai_project: NotRequired[str] + r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + api_key: NotRequired[str] + r"""API key""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - checksum_suffix: NotRequired[str] - r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ - max_manifest_size_kb: NotRequired[int] - r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" - validate_inventory_files: NotRequired[bool] - r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_openai_organization: NotRequired[str] + r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" + template_openai_project: NotRequired[str] + r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputS3Inventory(BaseModel): - type: InputResponseInputS3InventoryType +class InputResponseInputOpenai(BaseModel): + type: InputResponseInputOpenaiType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + content_config: Annotated[ + List[InputResponseInputOpenaiContentConfig], + pydantic.Field(alias="contentConfig"), + ] + r"""Content Types""" + + text_secret: Annotated[str, pydantic.Field(alias="textSecret")] + r"""Select or create a stored API key. Visit [OpenAI's organization admin keys page](https://platform.openai.com/settings/organization/admin-keys) to create an organization admin key.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -11010,310 +11112,88 @@ class InputResponseInputS3Inventory(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - - pq: Optional[PqType] = None - - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") - ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" - - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" - - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" - - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" - - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - - checkpointing: Optional[CheckpointingType] = None - - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - - checksum_suffix: Annotated[ - Optional[str], pydantic.Field(alias="checksumSuffix") - ] = None - r"""Filename suffix of the manifest checksum file. If a filename matching this suffix is received in the queue, the matching manifest file will be downloaded and validated against its value. Defaults to \"checksum\" """ - - max_manifest_size_kb: Annotated[ - Optional[int], pydantic.Field(alias="maxManifestSizeKB") - ] = None - r"""Maximum download size (KB) of each manifest or checksum file. Manifest files larger than this size will not be read. Defaults to 4096.""" - - validate_inventory_files: Annotated[ - Optional[bool], pydantic.Field(alias="validateInventoryFiles") - ] = None - r"""If set to Yes, each inventory file in the manifest will be validated against its checksum. Defaults to false""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" - - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" - - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" - - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" - - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + pq: Optional[PqType] = None - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") + openai_organization: Annotated[ + Optional[str], pydantic.Field(alias="openaiOrganization") ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + r"""Optional `OpenAI-Organization` request header value, typically `org-xxxxxxxxxxxxxxxxxxxxxxxx`""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + openai_project: Annotated[Optional[str], pydantic.Field(alias="openaiProject")] = ( + None + ) + r"""Optional `OpenAI-Project` request header value, typically `proj_xxxxxxxxxxxxxxxxxxxxxxxx`""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""HTTP request inactivity timeout. Use 0 to disable.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""API key""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + r"""How often workers should check in with the scheduler to keep job subscription alive""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + template_openai_organization: Annotated[ + Optional[str], pydantic.Field(alias="__template_openaiOrganization") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""Binds 'openaiOrganization' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiOrganization' at runtime.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + template_openai_project: Annotated[ + Optional[str], pydantic.Field(alias="__template_openaiProject") ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + r"""Binds 'openaiProject' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'openaiProject' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -11328,63 +11208,21 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", + "openaiOrganization", + "openaiProject", + "requestTimeout", + "apiKey", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "checksumSuffix", - "maxManifestSizeKB", - "validateInventoryFiles", + "retryRules", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", + "__template_openaiOrganization", + "__template_openaiProject", "notifications", "status", ] @@ -11403,11 +11241,154 @@ def serialize_model(self, handler): return m -class InputResponseInputS3TypedDict(TypedDict): - type: TypeOptionsS3 +class InputResponseInputWizType(str, Enum): + r"""Connector type identifier.""" + + WIZ = "wiz" + + +class InputResponseInputWizManageStateTypedDict(TypedDict): + pass + + +class InputResponseInputWizManageState(BaseModel): + pass + + +class InputResponseInputWizContentConfigTypedDict(TypedDict): + content_type: str + r"""The name of the Wiz query""" + content_query: str + r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" + cron_schedule: str + r"""A cron schedule on which to run this job""" + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + content_description: NotRequired[str] + r"""Description""" + enabled: NotRequired[bool] + r"""Enable content""" + state_tracking: NotRequired[bool] + r"""Track collection progress between consecutive scheduled executions""" + state_update_expression: NotRequired[str] + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + state_merge_expression: NotRequired[str] + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + manage_state: NotRequired[InputResponseInputWizManageStateTypedDict] + job_timeout: NotRequired[str] + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" + log_level: NotRequired[LogLevelOptionsContentConfigItemsDebugError] + r"""Collector runtime log level""" + max_pages: NotRequired[float] + r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" + + +class InputResponseInputWizContentConfig(BaseModel): + content_type: Annotated[str, pydantic.Field(alias="contentType")] + r"""The name of the Wiz query""" + + content_query: Annotated[str, pydantic.Field(alias="contentQuery")] + r"""Template for POST body to send with the Collect request. Reference global variables, or functions using template params: `${C.vars.myVar}`, or `${Date.now()}`, `${param}`.""" + + cron_schedule: Annotated[str, pydantic.Field(alias="cronSchedule")] + r"""A cron schedule on which to run this job""" + + earliest: str + r"""Earliest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + + latest: str + r"""Latest time, relative to now. Format supported: [+|-]@ (ex: -1hr, -42m, -42m@h)""" + + content_description: Annotated[ + Optional[str], pydantic.Field(alias="contentDescription") + ] = None + r"""Description""" + + enabled: Optional[bool] = None + r"""Enable content""" + + state_tracking: Annotated[Optional[bool], pydantic.Field(alias="stateTracking")] = ( + None + ) + r"""Track collection progress between consecutive scheduled executions""" + + state_update_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateUpdateExpression") + ] = None + r"""JavaScript expression that defines how to update the state from an event. Use the event's data and the current state to compute the new state. See [Understanding State Expression Fields](https://docs.cribl.io/stream/collectors-rest#state-tracking-expression-fields) for more information.""" + + state_merge_expression: Annotated[ + Optional[str], pydantic.Field(alias="stateMergeExpression") + ] = None + r"""JavaScript expression that defines which state to keep when merging a task's newly reported state with previously saved state. Evaluates `prevState` and `newState` variables, resolving to the state to keep.""" + + manage_state: Annotated[ + Optional[InputResponseInputWizManageState], pydantic.Field(alias="manageState") + ] = None + + job_timeout: Annotated[Optional[str], pydantic.Field(alias="jobTimeout")] = None + r"""Maximum time the job is allowed to run (examples: 30, 45s, 15m). Units default to seconds if not specified. Enter 0 for unlimited time.""" + + log_level: Annotated[ + Optional[LogLevelOptionsContentConfigItemsDebugError], + pydantic.Field(alias="logLevel"), + ] = None + r"""Collector runtime log level""" + + max_pages: Annotated[Optional[float], pydantic.Field(alias="maxPages")] = None + r"""Maximum number of pages to retrieve per collection task. Defaults to 0. Set to 0 to retrieve all pages.""" + + @field_serializer("log_level") + def serialize_log_level(self, value): + if isinstance(value, str): + try: + return models.LogLevelOptionsContentConfigItemsDebugError(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "contentDescription", + "enabled", + "stateTracking", + "stateUpdateExpression", + "stateMergeExpression", + "manageState", + "jobTimeout", + "logLevel", + "maxPages", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWizTypedDict(TypedDict): + type: InputResponseInputWizType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + endpoint: str + r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" + auth_url: str + r"""The authentication URL to generate an OAuth token""" + client_id: str + r"""The client ID of the Wiz application""" + content_config: List[InputResponseInputWizContentConfigTypedDict] + r"""Content types""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -11422,134 +11403,71 @@ class InputResponseInputS3TypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + auth_audience_override: NotRequired[str] + r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" + request_timeout: NotRequired[float] + r"""HTTP request inactivity timeout. Use 0 to disable.""" + keep_alive_time: NotRequired[float] + r"""How often workers should check in with the scheduler to keep job subscription alive""" + max_missed_keep_alives: NotRequired[float] + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" + ttl: NotRequired[str] + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + ignore_group_jobs_limit: NotRequired[bool] + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" - preprocess: NotRequired[PreprocessTypeTypedDict] - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - parquet_chunk_size_mb: NotRequired[float] - r"""Maximum file size for each Parquet chunk""" - parquet_chunk_download_timeout: NotRequired[float] - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - tag_after_processing: NotRequired[bool] - r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + retry_rules: NotRequired[RetryRulesTypeTypedDict] + auth_type: NotRequired[AuthenticationMethodOptionsManualSecret] + r"""Enter client secret directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + client_secret: NotRequired[str] + r"""The client secret of the Wiz application""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_endpoint: NotRequired[str] r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_auth_url: NotRequired[str] + r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputS3(BaseModel): - type: TypeOptionsS3 +class InputResponseInputWiz(BaseModel): + type: InputResponseInputWizType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + endpoint: str + r"""The Wiz GraphQL API endpoint. Example: https://api.us1.app.wiz.io/graphql""" + + auth_url: Annotated[str, pydantic.Field(alias="authUrl")] + r"""The authentication URL to generate an OAuth token""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""The client ID of the Wiz application""" + + content_config: Annotated[ + List[InputResponseInputWizContentConfig], pydantic.Field(alias="contentConfig") + ] + r"""Content types""" id: Optional[str] = None r"""Unique ID for this input""" @@ -11575,7 +11493,7 @@ class InputResponseInputS3(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -11585,40 +11503,36 @@ class InputResponseInputS3(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + auth_audience_override: Annotated[ + Optional[str], pydantic.Field(alias="authAudienceOverride") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + r"""The audience to use when requesting an OAuth token for a custom auth URL. When not specified, `wiz-api` will be used.""" - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""HTTP request inactivity timeout. Use 0 to disable.""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often workers should check in with the scheduler to keep job subscription alive""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + max_missed_keep_alives: Annotated[ + Optional[float], pydantic.Field(alias="maxMissedKeepAlives") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""The number of Keep Alive Time periods before an inactive worker will have its job subscription revoked.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ttl: Optional[str] = None + r"""Time to keep the job's artifacts on disk after job completion. This also affects how long a job is listed in the Job Inspector.""" + + ignore_group_jobs_limit: Annotated[ + Optional[bool], pydantic.Field(alias="ignoreGroupJobsLimit") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""When enabled, this job's artifacts are not counted toward the Worker Group's finished job artifacts limit. Artifacts will be removed only after the Collector's configured time to live.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -11630,235 +11544,291 @@ class InputResponseInputS3(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + retry_rules: Annotated[ + Optional[RetryRulesType], pydantic.Field(alias="retryRules") + ] = None - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsManualSecret], + pydantic.Field(alias="authType"), ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + r"""Enter client secret directly, or select a stored secret""" - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( - None - ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""The client secret of the Wiz application""" - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Use Assume Role credentials to access Amazon S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""External ID to use when assuming role""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + template_auth_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_authUrl") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Binds 'authUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authUrl' at runtime.""" - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsManualSecret(value) + except ValueError: + return value + return value - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "authAudienceOverride", + "requestTimeout", + "keepAliveTime", + "maxMissedKeepAlives", + "ttl", + "ignoreGroupJobsLimit", + "metadata", + "breakerRulesets", + "staleChannelFlushMs", + "retryRules", + "authType", + "description", + "clientSecret", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_endpoint", + "__template_authUrl", + "__template_clientId", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} - parquet_chunk_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkSizeMB") - ] = None - r"""Maximum file size for each Parquet chunk""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - parquet_chunk_download_timeout: Annotated[ - Optional[float], pydantic.Field(alias="parquetChunkDownloadTimeout") - ] = None - r"""The maximum time allowed for downloading a Parquet chunk. Processing will stop if a chunk cannot be downloaded within the time specified.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - checkpointing: Optional[CheckpointingType] = None + return m - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" +class InputResponseInputJournalFilesType(str, Enum): + r"""Connector type identifier.""" - tag_after_processing: Annotated[ - Optional[bool], pydantic.Field(alias="tagAfterProcessing") - ] = None - r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + JOURNAL_FILES = "journal_files" + + +class InputResponseInputJournalFilesRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" + description: NotRequired[str] + r"""Optional description of this rule's purpose""" + + +class InputResponseInputJournalFilesRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression applied to Journal objects. Return 'true' to include it.""" description: Optional[str] = None + r"""Optional description of this rule's purpose""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputJournalFilesTypedDict(TypedDict): + type: InputResponseInputJournalFilesType + r"""Connector type identifier.""" + path: str + r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" + journals: List[str] + r"""The full path of discovered journals are matched against this wildcard list.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + interval: NotRequired[float] + r"""Time, in seconds, between scanning for journals.""" + rules: NotRequired[List[InputResponseInputJournalFilesRuleTypedDict]] + r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" + current_boot: NotRequired[bool] + r"""Skip log messages that are not part of the current boot session""" + max_age_dur: NotRequired[str] + r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" + suppress_missing_path_errors: NotRequired[bool] + r"""Suppress errors when search path does not exist""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" +class InputResponseInputJournalFiles(BaseModel): + type: InputResponseInputJournalFilesType + r"""Connector type identifier.""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" + path: str + r"""Directory path to search for journals. Environment variables will be resolved, e.g. $CRIBL_EDGE_FS_ROOT/var/log/journal/$MACHINE_ID.""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + journals: List[str] + r"""The full path of discovered journals are matched against this wildcard list.""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + id: Optional[str] = None + r"""Unique ID for this input""" - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( None ) - r"""Select or create a stored secret that references your access key and secret key""" + r"""Select whether to send data to Routes, or directly to Destinations.""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") - ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + pq: Optional[PqType] = None - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + interval: Optional[float] = None + r"""Time, in seconds, between scanning for journals.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + rules: Optional[List[InputResponseInputJournalFilesRule]] = None + r"""Add rules to decide which journal objects to allow. Events are generated if no rules are given or if all the rules' expressions evaluate to true.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + current_boot: Annotated[Optional[bool], pydantic.Field(alias="currentBoot")] = None + r"""Skip log messages that are not part of the current boot session""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None + r"""The maximum log message age, in duration form (e.g,: 60s, 4h, 3d, 1w). Default of no value will apply no max age filters.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + suppress_missing_path_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Suppress errors when search path does not exist""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") - ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -11873,61 +11843,16 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", + "interval", + "rules", + "currentBoot", + "maxAgeDur", + "suppressMissingPathErrors", "metadata", - "parquetChunkSizeMB", - "parquetChunkDownloadTimeout", - "checkpointing", - "pollTimeout", - "encoding", - "tagAfterProcessing", + "autoParse", "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "processedTagKey", - "processedTagValue", "__template_environment", "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", "notifications", "status", ] @@ -11946,17 +11871,19 @@ def serialize_model(self, handler): return m -class InputResponseInputMetricsType(str, Enum): +class InputResponseInputRawUDPType(str, Enum): r"""Connector type identifier.""" - METRICS = "metrics" + RAW_UDP = "raw_udp" -class InputResponseInputMetricsTypedDict(TypedDict): - type: InputResponseInputMetricsType +class InputResponseInputRawUDPTypedDict(TypedDict): + type: InputResponseInputRawUDPType r"""Connector type identifier.""" host: str r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""Port to listen on""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -11971,29 +11898,25 @@ class InputResponseInputMetricsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - udp_port: NotRequired[float] - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - tcp_port: NotRequired[float] - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" max_buffer_size: NotRequired[float] - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""Maximum number of events to buffer when downstream is blocking.""" ip_whitelist_regex: NotRequired[str] r"""Regex matching IP addresses that are allowed to send data""" - enable_proxy_header: NotRequired[bool] - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" + single_msg_udp_packets: NotRequired[bool] + r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" + ingest_raw_bytes: NotRequired[bool] + r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" udp_socket_rx_buf_size: NotRequired[float] r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] @@ -12002,23 +11925,24 @@ class InputResponseInputMetricsTypedDict(TypedDict): r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_host: NotRequired[str] r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: NotRequired[str] - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - template_tcp_port: NotRequired[str] - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputMetrics(BaseModel): - type: InputResponseInputMetricsType +class InputResponseInputRawUDP(BaseModel): + type: InputResponseInputRawUDPType r"""Connector type identifier.""" host: str r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + port: float + r"""Port to listen on""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -12043,7 +11967,7 @@ class InputResponseInputMetrics(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -12053,38 +11977,37 @@ class InputResponseInputMetrics(BaseModel): pq: Optional[PqType] = None - udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None - r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - - tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None - r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - max_buffer_size: Annotated[ Optional[float], pydantic.Field(alias="maxBufferSize") ] = None - r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + r"""Maximum number of events to buffer when downstream is blocking.""" ip_whitelist_regex: Annotated[ Optional[str], pydantic.Field(alias="ipWhitelistRegex") ] = None r"""Regex matching IP addresses that are allowed to send data""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") ] = None - r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + r"""If true, each UDP packet is assumed to contain a single message. If false, each UDP packet is assumed to contain multiple messages, separated by newlines.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + ingest_raw_bytes: Annotated[ + Optional[bool], pydantic.Field(alias="ingestRawBytes") + ] = None + r"""If true, a __rawBytes field will be added to each event containing the raw bytes of the datagram.""" udp_socket_rx_buf_size: Annotated[ Optional[float], pydantic.Field(alias="udpSocketRxBufSize") ] = None r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -12103,17 +12026,12 @@ class InputResponseInputMetrics(BaseModel): ) r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_udp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_udpPort") - ] = None - r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - - template_tcp_port: Annotated[ - Optional[str], pydantic.Field(alias="__template_tcpPort") - ] = None - r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -12133,20 +12051,18 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "udpPort", - "tcpPort", "maxBufferSize", "ipWhitelistRegex", - "enableProxyHeader", - "tls", - "metadata", + "singleMsgUdpPackets", + "ingestRawBytes", "udpSocketRxBufSize", + "metadata", + "autoParse", "description", "__template_environment", "__template_streamtags", "__template_host", - "__template_udpPort", - "__template_tcpPort", + "__template_port", "notifications", "status", ] @@ -12165,15 +12081,28 @@ def serialize_model(self, handler): return m -class InputResponseInputCriblmetricsType(str, Enum): +class InputResponseInputAppleUnifiedLogsType(str, Enum): r"""Connector type identifier.""" - CRIBLMETRICS = "criblmetrics" + APPLE_UNIFIED_LOGS = "apple_unified_logs" + + +class InputResponseInputAppleUnifiedLogsReadMode( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" + + # Entire log + OLDEST = "oldest" + # From last entry + NEWEST = "newest" -class InputResponseInputCriblmetricsTypedDict(TypedDict): - type: InputResponseInputCriblmetricsType +class InputResponseInputAppleUnifiedLogsTypedDict(TypedDict): + type: InputResponseInputAppleUnifiedLogsType r"""Connector type identifier.""" + predicate: str + r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -12188,17 +12117,13 @@ class InputResponseInputCriblmetricsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - prefix: NotRequired[str] - r"""A prefix that is applied to the metrics provided by Cribl Stream""" - full_fidelity: NotRequired[bool] - r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + read_mode: NotRequired[InputResponseInputAppleUnifiedLogsReadMode] + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" description: NotRequired[str] @@ -12207,16 +12132,19 @@ class InputResponseInputCriblmetricsTypedDict(TypedDict): r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputCriblmetrics(BaseModel): - type: InputResponseInputCriblmetricsType +class InputResponseInputAppleUnifiedLogs(BaseModel): + type: InputResponseInputAppleUnifiedLogsType r"""Connector type identifier.""" + predicate: str + r"""String to filter log entries, in NSPredicate format (e.g., subsystem == \"com.apple.security\" or process == \"kernel\"). See [Common Log Types and Predicates](https://docs.cribl.io/edge/sources-apple-unified-logs/#examples) for more information.""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -12241,7 +12169,7 @@ class InputResponseInputCriblmetrics(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -12251,13 +12179,11 @@ class InputResponseInputCriblmetrics(BaseModel): pq: Optional[PqType] = None - prefix: Optional[str] = None - r"""A prefix that is applied to the metrics provided by Cribl Stream""" - - full_fidelity: Annotated[Optional[bool], pydantic.Field(alias="fullFidelity")] = ( - None - ) - r"""Include granular metrics. Disabling this will drop the following metrics events: `cribl.logstream.host.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.index.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.source.(in_bytes,in_events,out_bytes,out_events)`, `cribl.logstream.sourcetype.(in_bytes,in_events,out_bytes,out_events)`.""" + read_mode: Annotated[ + Optional[InputResponseInputAppleUnifiedLogsReadMode], + pydantic.Field(alias="readMode"), + ] = None + r"""Read all log entries (historical and upcoming), or only upcoming, from the last entry""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" @@ -12275,12 +12201,21 @@ class InputResponseInputCriblmetrics(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("read_mode") + def serialize_read_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputAppleUnifiedLogsReadMode(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -12295,8 +12230,7 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "prefix", - "fullFidelity", + "readMode", "metadata", "description", "__template_environment", @@ -12319,44 +12253,35 @@ def serialize_model(self, handler): return m -class InputResponseShardIteratorStart(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Location at which to start reading a shard for the first time""" +class InputResponseInputWinEventLogsType(str, Enum): + r"""Connector type identifier.""" - # Earliest record - TRIM_HORIZON = "TRIM_HORIZON" - # Latest record - LATEST = "LATEST" + WIN_EVENT_LOGS = "win_event_logs" -class InputResponseRecordDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" +class InputResponseInputWinEventLogsReadMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Read all stored and future event logs, or only future events""" - # Cribl - CRIBL = "cribl" - # Newline JSON - NDJSON = "ndjson" - # Cloudwatch Logs - CLOUDWATCH = "cloudwatch" - # Event per line - LINE = "line" + # Entire log + OLDEST = "oldest" + # From last entry + NEWEST = "newest" -class InputResponseShardLoadBalancing(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" +class InputResponseEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of individual events""" - # Consistent Hashing - CONSISTENT_HASHING = "ConsistentHashing" - # Round Robin - ROUND_ROBIN = "RoundRobin" + # JSON + JSON = "json" + # XML + XML = "xml" -class InputResponseInputKinesisTypedDict(TypedDict): - type: TypeOptionsKinesis +class InputResponseInputWinEventLogsTypedDict(TypedDict): + type: InputResponseInputWinEventLogsType r"""Connector type identifier.""" - stream_name: str - r"""Kinesis Data Stream to read data from""" - region: str - r"""Region where the Kinesis stream is located""" + log_names: List[str] + r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -12371,323 +12296,496 @@ class InputResponseInputKinesisTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - service_interval: NotRequired[float] - r"""Time interval in minutes between consecutive service calls""" - shard_expr: NotRequired[str] - r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" - shard_iterator_type: NotRequired[InputResponseShardIteratorStart] - r"""Location at which to start reading a shard for the first time""" - payload_format: NotRequired[InputResponseRecordDataFormat] - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" - get_records_limit: NotRequired[float] - r"""Maximum number of records per getRecords call""" - get_records_limit_total: NotRequired[float] - r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" - load_balancing_algorithm: NotRequired[InputResponseShardLoadBalancing] - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Kinesis stream""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - verify_kpl_check_sums: NotRequired[bool] - r"""Verify Kinesis Producer Library (KPL) event checksums""" - avoid_duplicates: NotRequired[bool] - r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" + suppress_missing_log_errors: NotRequired[bool] + r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" + read_mode: NotRequired[InputResponseInputWinEventLogsReadMode] + r"""Read all stored and future event logs, or only future events""" + event_format: NotRequired[InputResponseEventFormat] + r"""Format of individual events""" + disable_native_module: NotRequired[bool] + r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" + interval: NotRequired[float] + r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + batch_size: NotRequired[float] + r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + max_event_bytes: NotRequired[int] + r"""The maximum number of bytes in an event before it is flushed to the pipelines""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + disable_json_rendering: NotRequired[bool] + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + include_empty_json_fields: NotRequired[bool] + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" + disable_xml_rendering: NotRequired[bool] + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - template_shard_iterator_type: NotRequired[str] - r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" - template_payload_format: NotRequired[str] - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputKinesis(BaseModel): - type: TypeOptionsKinesis +class InputResponseInputWinEventLogs(BaseModel): + type: InputResponseInputWinEventLogsType + r"""Connector type identifier.""" + + log_names: Annotated[List[str], pydantic.Field(alias="logNames")] + r"""Enter the event logs to collect. Run \"Get-WinEvent -ListLog *\" in PowerShell to see the available logs.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + suppress_missing_log_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingLogErrors") + ] = None + r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" + + read_mode: Annotated[ + Optional[InputResponseInputWinEventLogsReadMode], + pydantic.Field(alias="readMode"), + ] = None + r"""Read all stored and future event logs, or only future events""" + + event_format: Annotated[ + Optional[InputResponseEventFormat], pydantic.Field(alias="eventFormat") + ] = None + r"""Format of individual events""" + + disable_native_module: Annotated[ + Optional[bool], pydantic.Field(alias="disableNativeModule") + ] = None + r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" + + interval: Optional[float] = None + r"""Time, in seconds, between checking for new entries (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + + batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None + r"""The maximum number of events to read in one polling interval. A batch size higher than 500 can cause delays when pulling from multiple event logs. (Applicable for pre-4.8.0 nodes that use Windows Tools)""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" + + max_event_bytes: Annotated[Optional[int], pydantic.Field(alias="maxEventBytes")] = ( + None + ) + r"""The maximum number of bytes in an event before it is flushed to the pipelines""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + disable_json_rendering: Annotated[ + Optional[bool], pydantic.Field(alias="disableJsonRendering") + ] = None + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + + include_empty_json_fields: Annotated[ + Optional[bool], pydantic.Field(alias="includeEmptyJsonFields") + ] = None + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" + + disable_xml_rendering: Annotated[ + Optional[bool], pydantic.Field(alias="disableXmlRendering") + ] = None + r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("read_mode") + def serialize_read_mode(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputWinEventLogsReadMode(value) + except ValueError: + return value + return value + + @field_serializer("event_format") + def serialize_event_format(self, value): + if isinstance(value, str): + try: + return models.InputResponseEventFormat(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "suppressMissingLogErrors", + "readMode", + "eventFormat", + "disableNativeModule", + "interval", + "batchSize", + "metadata", + "maxEventBytes", + "description", + "disableJsonRendering", + "includeEmptyJsonFields", + "disableXmlRendering", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputResponseInputWefType(str, Enum): r"""Connector type identifier.""" - stream_name: Annotated[str, pydantic.Field(alias="streamName")] - r"""Kinesis Data Stream to read data from""" + WEF = "wef" - region: str - r"""Region where the Kinesis stream is located""" - id: Optional[str] = None - r"""Unique ID for this input""" +class InputResponseInputWefAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""How to authenticate incoming client connections""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" + # Client certificate + CLIENT_CERT = "clientCert" + # Kerberos + KERBEROS = "kerberos" + # Negotiate (SPNEGO) + NEGOTIATE = "negotiate" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" +class InputResponseMTLSSettingsTypedDict(TypedDict): + r"""mTLS settings""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + priv_key_path: str + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" + cert_path: str + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" + ca_path: str + r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" + disabled: NotRequired[bool] + r"""Enable TLS""" + reject_unauthorized: NotRequired[bool] + r"""Required for WEF certificate authentication""" + request_cert: NotRequired[bool] + r"""Required for WEF certificate authentication""" + certificate_name: NotRequired[str] + r"""Name of the predefined certificate""" + passphrase: NotRequired[str] + r"""Passphrase to use to decrypt private key""" + common_name_regex: NotRequired[str] + r"""Regex matching allowable common names in peer certificates' subject attribute""" + min_version: NotRequired[MinimumTLSVersionOptionsTLS] + r"""Minimum TLS version""" + max_version: NotRequired[MaximumTLSVersionOptionsTLS] + r"""Maximum TLS version""" + ocsp_check: NotRequired[bool] + r"""Enable OCSP check of certificate""" + ocsp_check_fail_close: NotRequired[bool] + r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class InputResponseMTLSSettings(BaseModel): + r"""mTLS settings""" - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + priv_key_path: Annotated[str, pydantic.Field(alias="privKeyPath")] + r"""Path on server containing the private key to use. PEM format. Can reference $ENV_VARS.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + cert_path: Annotated[str, pydantic.Field(alias="certPath")] + r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - pq: Optional[PqType] = None + ca_path: Annotated[str, pydantic.Field(alias="caPath")] + r"""Server path containing CA certificates (in PEM format) to use. Can reference $ENV_VARS. If multiple certificates are present in a .pem, each must directly certify the one preceding it.""" + + disabled: Optional[bool] = None + r"""Enable TLS""" - service_interval: Annotated[ - Optional[float], pydantic.Field(alias="serviceInterval") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Time interval in minutes between consecutive service calls""" + r"""Required for WEF certificate authentication""" - shard_expr: Annotated[Optional[str], pydantic.Field(alias="shardExpr")] = None - r"""A JavaScript expression to be called with each shardId for the stream. If the expression evaluates to a truthy value, the shard will be processed.""" + request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None + r"""Required for WEF certificate authentication""" - shard_iterator_type: Annotated[ - Optional[InputResponseShardIteratorStart], - pydantic.Field(alias="shardIteratorType"), + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") ] = None - r"""Location at which to start reading a shard for the first time""" + r"""Name of the predefined certificate""" - payload_format: Annotated[ - Optional[InputResponseRecordDataFormat], pydantic.Field(alias="payloadFormat") - ] = None - r"""Format of data inside the Kinesis Stream records. Gzip compression is automatically detected.""" + passphrase: Optional[str] = None + r"""Passphrase to use to decrypt private key""" - get_records_limit: Annotated[ - Optional[float], pydantic.Field(alias="getRecordsLimit") + common_name_regex: Annotated[ + Optional[str], pydantic.Field(alias="commonNameRegex") ] = None - r"""Maximum number of records per getRecords call""" + r"""Regex matching allowable common names in peer certificates' subject attribute""" - get_records_limit_total: Annotated[ - Optional[float], pydantic.Field(alias="getRecordsLimitTotal") + min_version: Annotated[ + Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") ] = None - r"""Maximum number of records, across all shards, to pull down at once per Worker Process""" + r"""Minimum TLS version""" - load_balancing_algorithm: Annotated[ - Optional[InputResponseShardLoadBalancing], - pydantic.Field(alias="loadBalancingAlgorithm"), + max_version: Annotated[ + Optional[MaximumTLSVersionOptionsTLS], pydantic.Field(alias="maxVersion") ] = None - r"""The load-balancing algorithm to use for spreading out shards across Workers and Worker Processes""" + r"""Maximum TLS version""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + ocsp_check: Annotated[Optional[bool], pydantic.Field(alias="ocspCheck")] = None + r"""Enable OCSP check of certificate""" + + ocsp_check_fail_close: Annotated[ + Optional[bool], pydantic.Field(alias="ocspCheckFailClose") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""If enabled, checks will fail on any OCSP error. Otherwise, checks will fail only when a certificate is revoked, ignoring other errors.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + @field_serializer("min_version") + def serialize_min_version(self, value): + if isinstance(value, str): + try: + return models.MinimumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value - endpoint: Optional[str] = None - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + @field_serializer("max_version") + def serialize_max_version(self, value): + if isinstance(value, str): + try: + return models.MaximumTLSVersionOptionsTLS(value) + except ValueError: + return value + return value - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "disabled", + "rejectUnauthorized", + "requestCert", + "certificateName", + "passphrase", + "commonNameRegex", + "minVersion", + "maxVersion", + "ocspCheck", + "ocspCheckFailClose", + ] + ) + serialized = handler(self) + m = {} - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Kinesis stream""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + return m - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" +class InputResponseFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Content format in which the endpoint should deliver events""" - verify_kpl_check_sums: Annotated[ - Optional[bool], pydantic.Field(alias="verifyKPLCheckSums") - ] = None - r"""Verify Kinesis Producer Library (KPL) event checksums""" + RAW = "Raw" + RENDERED_TEXT = "RenderedText" - avoid_duplicates: Annotated[ - Optional[bool], pydantic.Field(alias="avoidDuplicates") - ] = None - r"""When resuming streaming from a stored state, Stream will read the next available record, rather than rereading the last-read record. Enabling this setting can cause data loss after a Worker Node's unexpected shutdown or restart.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" +class InputResponseQueryBuilderMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Query builder mode""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + SIMPLE = "simple" + XML = "xml" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" +class InputResponseQueryTypedDict(TypedDict): + path: str + r"""The Path attribute from the relevant XML Select element""" + query_expression: str + r"""The XPath query inside the relevant XML Select element""" + + +class InputResponseQuery(BaseModel): + path: str + r"""The Path attribute from the relevant XML Select element""" + + query_expression: Annotated[str, pydantic.Field(alias="queryExpression")] + r"""The XPath query inside the relevant XML Select element""" + + +class InputResponseSubscriptionTypedDict(TypedDict): + subscription_name: str + r"""Subscription name""" + content_format: InputResponseFormat + r"""Content format in which the endpoint should deliver events""" + heartbeat_interval: float + r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" + batch_timeout: float + r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" + targets: List[str] + r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" + version: NotRequired[str] + r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" + read_existing_events: NotRequired[bool] + r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" + send_bookmarks: NotRequired[bool] + r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" + compress: NotRequired[bool] + r"""Receive compressed events from the source""" + locale: NotRequired[str] + r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" + query_selector: NotRequired[InputResponseQueryBuilderMode] + r"""Query builder mode""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events ingested under this subscription""" + queries: NotRequired[List[InputResponseQueryTypedDict]] + r"""Queries""" + xml_query: NotRequired[str] + r"""The XPath query to use for selecting events""" + - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" +class InputResponseSubscription(BaseModel): + subscription_name: Annotated[str, pydantic.Field(alias="subscriptionName")] + r"""Subscription name""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + content_format: Annotated[ + InputResponseFormat, pydantic.Field(alias="contentFormat") + ] + r"""Content format in which the endpoint should deliver events""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") - ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + heartbeat_interval: Annotated[float, pydantic.Field(alias="heartbeatInterval")] + r"""Maximum time (in seconds) between endpoint checkins before considering it unavailable""" - template_shard_iterator_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_shardIteratorType") - ] = None - r"""Binds 'shardIteratorType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'shardIteratorType' at runtime.""" + batch_timeout: Annotated[float, pydantic.Field(alias="batchTimeout")] + r"""Interval (in seconds) over which the endpoint should collect events before sending them to Stream""" - template_payload_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadFormat") - ] = None - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + targets: List[str] + r"""The DNS names of the endpoints that should forward these events. You may use wildcards, such as *.mydomain.com""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + version: Optional[str] = None + r"""Version UUID for this subscription. If any subscription parameters are modified, this value will change.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + read_existing_events: Annotated[ + Optional[bool], pydantic.Field(alias="readExistingEvents") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Newly subscribed endpoints will send previously existing events. Disable to receive new events only.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + send_bookmarks: Annotated[Optional[bool], pydantic.Field(alias="sendBookmarks")] = ( + None + ) + r"""Keep track of which events have been received, resuming from that point after a re-subscription. This setting takes precedence over 'Read existing events'. See [Cribl Docs](https://docs.cribl.io/stream/sources-wef/#subscriptions) for more details.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + compress: Optional[bool] = None + r"""Receive compressed events from the source""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + locale: Optional[str] = None + r"""The RFC-3066 locale the Windows clients should use when sending events. Defaults to \"en-US\".""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + query_selector: Annotated[ + Optional[InputResponseQueryBuilderMode], pydantic.Field(alias="querySelector") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + r"""Query builder mode""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events ingested under this subscription""" - @field_serializer("shard_iterator_type") - def serialize_shard_iterator_type(self, value): - if isinstance(value, str): - try: - return models.InputResponseShardIteratorStart(value) - except ValueError: - return value - return value + queries: Optional[List[InputResponseQuery]] = None + r"""Queries""" - @field_serializer("payload_format") - def serialize_payload_format(self, value): - if isinstance(value, str): - try: - return models.InputResponseRecordDataFormat(value) - except ValueError: - return value - return value + xml_query: Annotated[Optional[str], pydantic.Field(alias="xmlQuery")] = None + r"""The XPath query to use for selecting events""" - @field_serializer("load_balancing_algorithm") - def serialize_load_balancing_algorithm(self, value): + @field_serializer("content_format") + def serialize_content_format(self, value): if isinstance(value, str): try: - return models.InputResponseShardLoadBalancing(value) + return models.InputResponseFormat(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("query_selector") + def serialize_query_selector(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.InputResponseQueryBuilderMode(value) except ValueError: return value return value @@ -12696,51 +12794,15 @@ def serialize_aws_authentication_method(self, value): def serialize_model(self, handler): optional_fields = set( [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "serviceInterval", - "shardExpr", - "shardIteratorType", - "payloadFormat", - "getRecordsLimit", - "getRecordsLimitTotal", - "loadBalancingAlgorithm", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "verifyKPLCheckSums", - "avoidDuplicates", + "version", + "readExistingEvents", + "sendBookmarks", + "compress", + "locale", + "querySelector", "metadata", - "description", - "awsApiKey", - "awsSecret", - "__template_environment", - "__template_streamtags", - "__template_streamName", - "__template_shardIteratorType", - "__template_payloadFormat", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "notifications", - "status", + "queries", + "xmlQuery", ] ) serialized = handler(self) @@ -12757,19 +12819,15 @@ def serialize_model(self, handler): return m -class InputResponseInputHTTPRawType(str, Enum): - r"""Source type identifier.""" - - HTTP_RAW = "http_raw" - - -class InputResponseInputHTTPRawTypedDict(TypedDict): - type: InputResponseInputHTTPRawType - r"""Source type identifier.""" +class InputResponseInputWefTypedDict(TypedDict): + type: InputResponseInputWefType + r"""Connector type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" port: float r"""Port to listen on""" + subscriptions: List[InputResponseSubscriptionTypedDict] + r"""Subscriptions to events on forwarding endpoints""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -12784,32 +12842,24 @@ class InputResponseInputHTTPRawTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - auth_tokens: NotRequired[List[str]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" + auth_method: NotRequired[InputResponseInputWefAuthenticationMethod] + r"""How to authenticate incoming client connections""" + tls: NotRequired[InputResponseMTLSSettingsTypedDict] + r"""mTLS settings""" max_active_req: NotRequired[float] r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" max_requests_per_socket: NotRequired[int] r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" + r"""Add request headers to events in the __headers field""" capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" keep_alive_timeout: NotRequired[float] r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" enable_health_check: NotRequired[bool] @@ -12818,32 +12868,22 @@ class InputResponseInputHTTPRawTypedDict(TypedDict): r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" ip_denylist_regex: NotRequired[str] r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + ca_fingerprint: NotRequired[str] + r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" + keytab: NotRequired[str] + r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" + principal: NotRequired[str] + r"""Kerberos principal used for authentication, typically in the form HTTP/@""" + allow_machine_id_mismatch: NotRequired[bool] + r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - allowed_paths: NotRequired[List[str]] - r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" - allowed_methods: NotRequired[List[str]] - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - access_control_allow_origin: NotRequired[List[str]] - r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" - access_control_allow_headers: NotRequired[List[str]] - r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" - access_control_allow_methods: NotRequired[List[str]] - r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" - access_control_expose_headers: NotRequired[List[str]] - r"""Headers the browser is allowed to access from the response""" - access_control_allow_credentials: NotRequired[bool] - r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" - access_control_max_age: NotRequired[float] - r"""How long browsers should cache the preflight response""" description: NotRequired[str] r"""Optional description for this configuration.""" + log_fingerprint_mismatch: NotRequired[bool] + r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -12852,23 +12892,19 @@ class InputResponseInputHTTPRawTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: NotRequired[str] - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - template_allowed_paths: NotRequired[str] - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - template_access_control_allow_origin: NotRequired[str] - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" - template_access_control_allow_headers: NotRequired[str] - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_keytab: NotRequired[str] + r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" + template_principal: NotRequired[str] + r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputHTTPRaw(BaseModel): - type: InputResponseInputHTTPRawType - r"""Source type identifier.""" +class InputResponseInputWef(BaseModel): + type: InputResponseInputWefType + r"""Connector type identifier.""" host: str r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" @@ -12876,6 +12912,9 @@ class InputResponseInputHTTPRaw(BaseModel): port: float r"""Port to listen on""" + subscriptions: List[InputResponseSubscription] + r"""Subscriptions to events on forwarding endpoints""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -12900,7 +12939,7 @@ class InputResponseInputHTTPRaw(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -12910,13 +12949,14 @@ class InputResponseInputHTTPRaw(BaseModel): pq: Optional[PqType] = None - auth_tokens: Annotated[Optional[List[str]], pydantic.Field(alias="authTokens")] = ( - None - ) - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + auth_method: Annotated[ + Optional[InputResponseInputWefAuthenticationMethod], + pydantic.Field(alias="authMethod"), + ] = None + r"""How to authenticate incoming client connections""" - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + tls: Optional[InputResponseMTLSSettings] = None + r"""mTLS settings""" max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( None @@ -12931,32 +12971,17 @@ class InputResponseInputHTTPRaw(BaseModel): enable_proxy_header: Annotated[ Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""Preserve the client’s original IP address in the __srcIpPort field when connecting through an HTTP proxy that supports the X-Forwarded-For header. This does not apply to TCP-layer Proxy Protocol v1/v2.""" capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") - ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" - - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") - ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + Optional[bool], pydantic.Field(alias="captureHeaders") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""Add request headers to events in the __headers field""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" keep_alive_timeout: Annotated[ Optional[float], pydantic.Field(alias="keepAliveTimeout") @@ -12978,68 +13003,38 @@ class InputResponseInputHTTPRaw(BaseModel): ] = None r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") - ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - allowed_paths: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedPaths") - ] = None - r"""List of URI paths accepted by this input, wildcards are supported, e.g /api/v*/hook. Defaults to allow all.""" - - allowed_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="allowedMethods") - ] = None - r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - - auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], - pydantic.Field(alias="authTokensExt"), - ] = None - r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" - - access_control_allow_origin: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") ] = None - r"""HTTP origins allowed to send CORS requests (example: https://pivot.claude.ai). Supports wildcards. Leave empty to disable CORS. Note: IP allowlist/denylist rules are applied before CORS.""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - access_control_allow_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") - ] = None - r"""HTTP headers echoed in Access-Control-Allow-Headers on preflight. Use \"*\" to allow all headers.""" + ca_fingerprint: Annotated[Optional[str], pydantic.Field(alias="caFingerprint")] = ( + None + ) + r"""SHA1 fingerprint expected by the client, if it does not match the first certificate in the configured CA chain""" - access_control_allow_methods: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlAllowMethods") - ] = None - r"""HTTP methods echoed in Access-Control-Allow-Methods on preflight.""" + keytab: Optional[str] = None + r"""Path to the keytab file containing the service principal credentials. @{product} will use `/etc/krb5.keytab` if not provided.""" - access_control_expose_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="accessControlExposeHeaders") - ] = None - r"""Headers the browser is allowed to access from the response""" + principal: Optional[str] = None + r"""Kerberos principal used for authentication, typically in the form HTTP/@""" - access_control_allow_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="accessControlAllowCredentials") + allow_machine_id_mismatch: Annotated[ + Optional[bool], pydantic.Field(alias="allowMachineIdMismatch") ] = None - r"""Include credentials in cross-origin requests. Cannot be used with wildcard origins.""" + r"""Allow events to be ingested even if their MachineID does not match the client certificate CN""" - access_control_max_age: Annotated[ - Optional[float], pydantic.Field(alias="accessControlMaxAge") - ] = None - r"""How long browsers should cache the preflight response""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" description: Optional[str] = None r"""Optional description for this configuration.""" + log_fingerprint_mismatch: Annotated[ + Optional[bool], pydantic.Field(alias="logFingerprintMismatch") + ] = None + r"""Log a warning if the client certificate authority (CA) fingerprint does not match the expected value. A mismatch prevents Cribl from receiving events from the Windows Event Forwarder.""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -13060,32 +13055,31 @@ class InputResponseInputHTTPRaw(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_auth_tokens: Annotated[ - Optional[str], pydantic.Field(alias="__template_authTokens") - ] = None - r"""Binds 'authTokens' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'authTokens' at runtime.""" - - template_allowed_paths: Annotated[ - Optional[str], pydantic.Field(alias="__template_allowedPaths") - ] = None - r"""Binds 'allowedPaths' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedPaths' at runtime.""" - - template_access_control_allow_origin: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + template_keytab: Annotated[ + Optional[str], pydantic.Field(alias="__template_keytab") ] = None - r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + r"""Binds 'keytab' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'keytab' at runtime.""" - template_access_control_allow_headers: Annotated[ - Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + template_principal: Annotated[ + Optional[str], pydantic.Field(alias="__template_principal") ] = None - r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + r"""Binds 'principal' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'principal' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("auth_method") + def serialize_auth_method(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputWefAuthenticationMethod(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -13100,41 +13094,31 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "authTokens", + "authMethod", "tls", "maxActiveReq", "maxRequestsPerSocket", "enableProxyHeader", "captureHeaders", "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", "keepAliveTimeout", "enableHealthCheck", "ipAllowlistRegex", "ipDenylistRegex", - "breakerRulesets", - "staleChannelFlushMs", + "socketTimeout", + "caFingerprint", + "keytab", + "principal", + "allowMachineIdMismatch", "metadata", - "allowedPaths", - "allowedMethods", - "authTokensExt", - "accessControlAllowOrigin", - "accessControlAllowHeaders", - "accessControlAllowMethods", - "accessControlExposeHeaders", - "accessControlAllowCredentials", - "accessControlMaxAge", "description", + "logFingerprintMismatch", "__template_environment", "__template_streamtags", "__template_host", "__template_port", - "__template_authTokens", - "__template_allowedPaths", - "__template_accessControlAllowOrigin", - "__template_accessControlAllowHeaders", + "__template_keytab", + "__template_principal", "notifications", "status", ] @@ -13153,152 +13137,65 @@ def serialize_model(self, handler): return m -class InputResponseInputDatagenType(str, Enum): - r"""Connector type identifier.""" - - DATAGEN = "datagen" - - -class InputResponseSampleTypedDict(TypedDict): - sample: str - r"""Data Generator File Name""" - events_per_sec: float - r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" - - -class InputResponseSample(BaseModel): - sample: str - r"""Data Generator File Name""" - - events_per_sec: Annotated[float, pydantic.Field(alias="eventsPerSec")] - r"""Maximum number of events to generate per second per Worker Node. Defaults to 10.""" - - -class InputResponseInputDatagenTypedDict(TypedDict): - type: InputResponseInputDatagenType - r"""Connector type identifier.""" - samples: List[InputResponseSampleTypedDict] - r"""Datagens""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class InputResponseInputDatagen(BaseModel): - type: InputResponseInputDatagenType +class InputResponseInputAppscopeType(str, Enum): r"""Connector type identifier.""" - samples: List[InputResponseSample] - r"""Datagens""" - - id: Optional[str] = None - r"""Unique ID for this input""" - - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" - - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + APPSCOPE = "appscope" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class InputResponseAllowTypedDict(TypedDict): + procname: str + r"""Specify the name of a process or family of processes.""" + config: str + r"""Choose a config to apply to processes that match the process name and/or argument.""" + arg: NotRequired[str] + r"""Specify a string to substring-match against process command-line.""" - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" +class InputResponseAllow(BaseModel): + procname: str + r"""Specify the name of a process or family of processes.""" - pq: Optional[PqType] = None + config: str + r"""Choose a config to apply to processes that match the process name and/or argument.""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + arg: Optional[str] = None + r"""Specify a string to substring-match against process command-line.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["arg"]) + serialized = handler(self) + m = {} - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + return m - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "metadata", - "description", - "__template_environment", - "__template_streamtags", - "notifications", - "status", - ] - ) +class InputResponseInputAppscopeFilterTypedDict(TypedDict): + allow: NotRequired[List[InputResponseAllowTypedDict]] + r"""Specify processes that AppScope should be loaded into, and the config to use.""" + transport_url: NotRequired[str] + r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" + + +class InputResponseInputAppscopeFilter(BaseModel): + allow: Optional[List[InputResponseAllow]] = None + r"""Specify processes that AppScope should be loaded into, and the config to use.""" + + transport_url: Annotated[Optional[str], pydantic.Field(alias="transportURL")] = None + r"""To override the UNIX domain socket or address/port specified in General Settings (while leaving Authentication settings as is), enter a URL.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["allow", "transportURL"]) serialized = handler(self) m = {} @@ -13313,51 +13210,65 @@ def serialize_model(self, handler): return m -class InputResponseInputDatadogAgentType(str, Enum): - r"""Source type identifier.""" - - DATADOG_AGENT = "datadog_agent" - +class InputResponseInputAppscopePersistenceTypedDict(TypedDict): + r"""Persistence""" -class InputResponseSamplingRuleTypedDict(TypedDict): - service: str - r"""Datadog service name""" - environment: str - r"""Datadog environment name (example: prod, staging)""" - rate: float - r"""Sampling rate for this service/environment combination (0.0–1.0)""" + enable: NotRequired[bool] + r"""Spool events and metrics on disk for Cribl Edge and Search""" + time_window: NotRequired[str] + r"""Time span for each file bucket""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" -class InputResponseSamplingRule(BaseModel): - service: str - r"""Datadog service name""" +class InputResponseInputAppscopePersistence(BaseModel): + r"""Persistence""" - environment: str - r"""Datadog environment name (example: prod, staging)""" + enable: Optional[bool] = None + r"""Spool events and metrics on disk for Cribl Edge and Search""" - rate: float - r"""Sampling rate for this service/environment combination (0.0–1.0)""" + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time span for each file bucket""" + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" -class InputResponseInputDatadogAgentProxyModeTypedDict(TypedDict): - enabled: bool - r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" - reject_unauthorized: NotRequired[bool] - r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" -class InputResponseInputDatadogAgentProxyMode(BaseModel): - enabled: bool - r"""Forward key validation requests from the Datadog Agent to the Datadog API. If disabled, Stream handles key validation requests locally by always responding that the key is valid.""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/appscope""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Whether to reject certificates that cannot be verified against a valid CA (such as self-signed certificates)""" + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.DataCompressionFormatOptionsPersistence(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["rejectUnauthorized"]) + optional_fields = set( + [ + "enable", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", + ] + ) serialized = handler(self) m = {} @@ -13372,13 +13283,21 @@ def serialize_model(self, handler): return m -class InputResponseInputDatadogAgentTypedDict(TypedDict): - type: InputResponseInputDatadogAgentType - r"""Source type identifier.""" - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - port: float - r"""Port to listen on""" +InputResponseUNIXSocketPermissionsTypedDict = TypeAliasType( + "InputResponseUNIXSocketPermissionsTypedDict", Union[str, float] +) +r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + + +InputResponseUNIXSocketPermissions = TypeAliasType( + "InputResponseUNIXSocketPermissions", Union[str, float] +) +r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + + +class InputResponseInputAppscopeTypedDict(TypedDict): + type: InputResponseInputAppscopeType + r"""Connector type identifier.""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -13393,49 +13312,52 @@ class InputResponseInputDatadogAgentTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - tls: NotRequired[TLSSettingsServerSideTypeTypedDict] - r"""TLS settings (server side)""" - max_active_req: NotRequired[float] - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" - max_requests_per_socket: NotRequired[int] - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" enable_proxy_header: NotRequired[bool] - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" - capture_headers: NotRequired[bool] - r"""Add request headers to events, in the __headers field""" - capture_headers_warning: Literal[""] - activity_log_sample_rate: NotRequired[float] - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" - request_timeout: NotRequired[float] - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" - socket_timeout: NotRequired[float] - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" - keep_alive_timeout: NotRequired[float] - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" - enable_health_check: NotRequired[bool] - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" - ip_allowlist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: NotRequired[str] - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - extract_metrics: NotRequired[bool] - r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" - sampling_rate: NotRequired[float] - r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" - sampling_rules: NotRequired[List[InputResponseSamplingRuleTypedDict]] - r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - proxy_mode: NotRequired[InputResponseInputDatadogAgentProxyModeTypedDict] + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + enable_unix_path: NotRequired[bool] + r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" + filter_: NotRequired[InputResponseInputAppscopeFilterTypedDict] + persistence: NotRequired[InputResponseInputAppscopePersistenceTypedDict] + r"""Persistence""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" + host: NotRequired[str] + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: NotRequired[float] + r"""Port to listen on""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + unix_socket_path: NotRequired[str] + r"""Path to the UNIX domain socket to listen on.""" + unix_socket_perms: NotRequired[InputResponseUNIXSocketPermissionsTypedDict] + r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] @@ -13444,21 +13366,15 @@ class InputResponseInputDatadogAgentTypedDict(TypedDict): r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" template_port: NotRequired[str] r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputDatadogAgent(BaseModel): - type: InputResponseInputDatadogAgentType - r"""Source type identifier.""" - - host: str - r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - - port: float - r"""Port to listen on""" +class InputResponseInputAppscope(BaseModel): + type: InputResponseInputAppscopeType + r"""Connector type identifier.""" id: Optional[str] = None r"""Unique ID for this input""" @@ -13484,7 +13400,7 @@ class InputResponseInputDatadogAgent(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -13494,94 +13410,95 @@ class InputResponseInputDatadogAgent(BaseModel): pq: Optional[PqType] = None - tls: Optional[TLSSettingsServerSideType] = None - r"""TLS settings (server side)""" + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to establish a connection""" - max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( None ) - r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - max_requests_per_socket: Annotated[ - Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") ] = None - r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - enable_proxy_header: Annotated[ - Optional[bool], pydantic.Field(alias="enableProxyHeader") + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") ] = None - r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - capture_headers: Annotated[ - Optional[bool], pydantic.Field(alias="captureHeaders") + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") ] = None - r"""Add request headers to events, in the __headers field""" - - CAPTURE_HEADERS_WARNING: Annotated[ - Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], - pydantic.Field(alias="captureHeadersWarning"), - ] = "" + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - activity_log_sample_rate: Annotated[ - Optional[float], pydantic.Field(alias="activityLogSampleRate") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") ] = None - r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - keep_alive_timeout: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTimeout") + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_health_check: Annotated[ - Optional[bool], pydantic.Field(alias="enableHealthCheck") + enable_unix_path: Annotated[ + Optional[bool], pydantic.Field(alias="enableUnixPath") ] = None - r"""Expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + r"""Toggle to Yes to specify a file-backed UNIX domain socket connection, instead of a network host and port.""" - ip_allowlist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipAllowlistRegex") + filter_: Annotated[ + Optional[InputResponseInputAppscopeFilter], pydantic.Field(alias="filter") ] = None - r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" - ip_denylist_regex: Annotated[ - Optional[str], pydantic.Field(alias="ipDenylistRegex") - ] = None - r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + persistence: Optional[InputResponseInputAppscopePersistence] = None + r"""Persistence""" - extract_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="extractMetrics") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Extract each incoming metric to multiple events, one per data point. Recommended when sending metrics to a statsd-type output. If sending metrics to DatadogHQ or any destination that accepts arbitrary JSON, leave disabled.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - sampling_rate: Annotated[Optional[float], pydantic.Field(alias="samplingRate")] = ( - None - ) - r"""The rate_by_service hint sent to connected tracers as the catch-all sampling rate. Applies to any service/environment not explicitly listed in Per-Service Sampling Rules. 1.0 = keep all traces (default); 0.0 = suggest dropping all.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - sampling_rules: Annotated[ - Optional[List[InputResponseSamplingRule]], pydantic.Field(alias="samplingRules") - ] = None - r"""Per-service sampling rate hints. Each row maps to a \"service:,env:\" key in the rate_by_service response sent to tracers.""" + host: Optional[str] = None + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + port: Optional[float] = None + r"""Port to listen on""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + unix_socket_path: Annotated[ + Optional[str], pydantic.Field(alias="unixSocketPath") + ] = None + r"""Path to the UNIX domain socket to listen on.""" - proxy_mode: Annotated[ - Optional[InputResponseInputDatadogAgentProxyMode], - pydantic.Field(alias="proxyMode"), + unix_socket_perms: Annotated[ + Optional[InputResponseUNIXSocketPermissions], + pydantic.Field(alias="unixSocketPerms"), ] = None + r"""Permissions to set for socket e.g., 777. If empty, falls back to the runtime user's default permissions.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") @@ -13603,12 +13520,21 @@ class InputResponseInputDatadogAgent(BaseModel): ) r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -13623,25 +13549,27 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "tls", - "maxActiveReq", - "maxRequestsPerSocket", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", "enableProxyHeader", - "captureHeaders", - "captureHeadersWarning", - "activityLogSampleRate", - "requestTimeout", - "socketTimeout", - "keepAliveTimeout", - "enableHealthCheck", - "ipAllowlistRegex", - "ipDenylistRegex", - "extractMetrics", - "samplingRate", - "samplingRules", "metadata", - "proxyMode", + "breakerRulesets", + "staleChannelFlushMs", + "enableUnixPath", + "filter", + "persistence", + "authType", "description", + "host", + "port", + "tls", + "unixSocketPath", + "unixSocketPerms", + "authToken", + "textSecret", "__template_environment", "__template_streamtags", "__template_host", @@ -13664,17 +13592,19 @@ def serialize_model(self, handler): return m -class InputResponseInputCrowdstrikeType(str, Enum): +class InputResponseInputTCPType(str, Enum): r"""Connector type identifier.""" - CROWDSTRIKE = "crowdstrike" + TCP = "tcp" -class InputResponseInputCrowdstrikeTypedDict(TypedDict): - type: InputResponseInputCrowdstrikeType +class InputResponseInputTCPTypedDict(TypedDict): + type: InputResponseInputTCPType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -13689,129 +13619,68 @@ class InputResponseInputCrowdstrikeTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - file_filter: NotRequired[str] - r"""Regex matching file names to download and process. Defaults to: .*""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to establish a connection""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" breaker_rulesets: NotRequired[List[str]] r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - max_messages: NotRequired[float] - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - visibility_timeout: NotRequired[float] - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" - num_receivers: NotRequired[float] - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" - socket_timeout: NotRequired[float] - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" - skip_on_error: NotRequired[bool] - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" - include_sqs_metadata: NotRequired[bool] - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Amazon S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - enable_sqs_assume_role: NotRequired[bool] - r"""Use Assume Role credentials when accessing Amazon SQS""" - shared_credentials: NotRequired[bool] - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: NotRequired[bool] - r"""Use the same settings for S3 and SQS""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + enable_header: NotRequired[bool] + r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" preprocess: NotRequired[PreprocessTypeTypedDict] r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - checkpointing: NotRequired[CheckpointingTypeTypedDict] - poll_timeout: NotRequired[float] - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - encoding: NotRequired[str] - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - sqs_assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - sqs_duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - sqs_aws_authentication_method: NotRequired[SqsAuthenticationMethodOptions] - r"""Choose Auto to use IAM roles""" - sqs_aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - sqs_aws_secret_key: NotRequired[str] - r"""SQS secret key""" - tag_after_processing: NotRequired[TagAfterProcessingOptions] - processed_tag_key: NotRequired[str] - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" - processed_tag_value: NotRequired[str] - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_sqs_assume_role_arn: NotRequired[str] - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" - template_sqs_assume_role_external_id: NotRequired[str] - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" - template_sqs_aws_secret_key: NotRequired[str] - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputCrowdstrike(BaseModel): - type: InputResponseInputCrowdstrikeType +class InputResponseInputTCP(BaseModel): + type: InputResponseInputTCPType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to read notifications from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" id: Optional[str] = None r"""Unique ID for this input""" @@ -13837,7 +13706,7 @@ class InputResponseInputCrowdstrike(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -13847,40 +13716,41 @@ class InputResponseInputCrowdstrike(BaseModel): pq: Optional[PqType] = None - file_filter: Annotated[Optional[str], pydantic.Field(alias="fileFilter")] = None - r"""Regex matching file names to download and process. Defaults to: .*""" - - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Regex matching IP addresses that are allowed to establish a connection""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( None ) - r"""Secret key""" + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" - region: Optional[str] = None - r"""AWS Region where the S3 bucket and SQS queue are located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Enable if the connection is proxied by a device that supports proxy protocol v1 or v2""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" breaker_rulesets: Annotated[ Optional[List[str]], pydantic.Field(alias="breakerRulesets") @@ -13890,367 +13760,436 @@ class InputResponseInputCrowdstrike(BaseModel): stale_channel_flush_ms: Annotated[ Optional[float], pydantic.Field(alias="staleChannelFlushMs") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( + None + ) + r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" + + preprocess: Optional[PreprocessType] = None + r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None - r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - visibility_timeout: Annotated[ - Optional[float], pydantic.Field(alias="visibilityTimeout") + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") ] = None - r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - socket_timeout: Annotated[ - Optional[float], pydantic.Field(alias="socketTimeout") - ] = None - r"""Socket inactivity timeout (in seconds). Increase this value if timeouts occur due to backpressure.""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - skip_on_error: Annotated[Optional[bool], pydantic.Field(alias="skipOnError")] = None - r"""Skip files that trigger a processing error. Disabled by default, which allows retries after processing errors.""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" - include_sqs_metadata: Annotated[ - Optional[bool], pydantic.Field(alias="includeSqsMetadata") - ] = None - r"""Attach SQS notification metadata to a __sqsMetadata field on each event""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Amazon S3""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tls", + "ipWhitelistRegex", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "enableProxyHeader", + "metadata", + "breakerRulesets", + "staleChannelFlushMs", + "autoParse", + "enableHeader", + "preprocess", + "description", + "authToken", + "authType", + "textSecret", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - enable_sqs_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableSQSAssumeRole") - ] = None - r"""Use Assume Role credentials when accessing Amazon SQS""" + return m - shared_credentials: Annotated[ - Optional[bool], pydantic.Field(alias="sharedCredentials") - ] = None - r"""Use the same credential settings for S3 and SQS""" - shared_assume_role_arn: Annotated[ - Optional[bool], pydantic.Field(alias="sharedAssumeRoleArn") - ] = None - r"""Use the same settings for S3 and SQS""" +class InputResponseInputFileType(str, Enum): + r"""Connector type identifier.""" - preprocess: Optional[PreprocessType] = None - r"""Optional preprocessing step that pipes collected data through an external command before ingestion.""" + FILE = "file" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - checkpointing: Optional[CheckpointingType] = None +class InputResponseInputFileMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Choose how to discover files to monitor""" - poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None - r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + # Manual + MANUAL = "manual" + # Auto + AUTO = "auto" - encoding: Optional[str] = None - r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" - description: Optional[str] = None +class InputResponseInputFileTypedDict(TypedDict): + type: InputResponseInputFileType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + mode: NotRequired[InputResponseInputFileMode] + r"""Choose how to discover files to monitor""" + interval: NotRequired[float] + r"""Time, in seconds, between scanning for files""" + filenames: NotRequired[List[str]] + r"""The full path of discovered files are matched against this wildcard list""" + filter_archived_files: NotRequired[bool] + r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" + tail_only: NotRequired[bool] + r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" + idle_timeout: NotRequired[float] + r"""Time, in seconds, before an idle file is closed""" + min_age_dur: NotRequired[str] + r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" + max_age_dur: NotRequired[str] + r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" + check_file_mod_time: NotRequired[bool] + r"""Skip files with modification times earlier than the maximum age duration""" + force_text: NotRequired[bool] + r"""Forces files containing binary data to be streamed as text""" + hash_len: NotRequired[float] + r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + breaker_rulesets: NotRequired[List[str]] + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + disable_stale_channel_flush: NotRequired[bool] + r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" + stale_channel_flush_ms: NotRequired[float] + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] r"""Optional description for this configuration.""" + path: NotRequired[str] + r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" + depth: NotRequired[float] + r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" + suppress_missing_path_errors: NotRequired[bool] + r"""Suppress errors when search path does not exist""" + delete_files: NotRequired[bool] + r"""Delete files after they have been collected""" + salt_hash: NotRequired[bool] + r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" + optimize_leaf_directories: NotRequired[bool] + r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" + enable_discovery_throttle: NotRequired[bool] + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" + discovery_throttle_cpu_percent: NotRequired[float] + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" + include_unidentifiable_binary: NotRequired[bool] + r"""Stream binary files as Base64-encoded chunks""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleArn") - ] = None - r"""Amazon Resource Name (ARN) of the role to assume""" +class InputResponseInputFile(BaseModel): + type: InputResponseInputFileType + r"""Connector type identifier.""" - sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="SQSAssumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + id: Optional[str] = None + r"""Unique ID for this input""" - sqs_duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="SQSDurationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - sqs_aws_authentication_method: Annotated[ - Optional[SqsAuthenticationMethodOptions], - pydantic.Field(alias="SQSAwsAuthenticationMethod"), - ] = None - r"""Choose Auto to use IAM roles""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - sqs_aws_secret: Annotated[Optional[str], pydantic.Field(alias="SQSAwsSecret")] = ( + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( None ) - r"""Select or create a stored secret that references your access key and secret key""" + r"""Select whether to send data to Routes, or directly to Destinations.""" - sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="SQSAwsSecretKey") - ] = None - r"""SQS secret key""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - tag_after_processing: Annotated[ - Optional[TagAfterProcessingOptions], pydantic.Field(alias="tagAfterProcessing") - ] = None + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - processed_tag_key: Annotated[ - Optional[str], pydantic.Field(alias="processedTagKey") - ] = None - r"""The key for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - processed_tag_value: Annotated[ - Optional[str], pydantic.Field(alias="processedTagValue") + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), ] = None - r"""The value for the S3 object tag applied after processing. This field accepts an expression for dynamic generation.""" + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") - ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + pq: Optional[PqType] = None - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + mode: Optional[InputResponseInputFileMode] = None + r"""Choose how to discover files to monitor""" - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + interval: Optional[float] = None + r"""Time, in seconds, between scanning for files""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + filenames: Optional[List[str]] = None + r"""The full path of discovered files are matched against this wildcard list""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + filter_archived_files: Annotated[ + Optional[bool], pydantic.Field(alias="filterArchivedFiles") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Apply filename allowlist to file entries in archive file types, like tar or zip.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + tail_only: Annotated[Optional[bool], pydantic.Field(alias="tailOnly")] = None + r"""Read only new entries at the end of all files discovered at next startup. @{product} will then read newly discovered files from the head. Disable this to resume reading all files from head.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + idle_timeout: Annotated[Optional[float], pydantic.Field(alias="idleTimeout")] = None + r"""Time, in seconds, before an idle file is closed""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + min_age_dur: Annotated[Optional[str], pydantic.Field(alias="minAgeDur")] = None + r"""The minimum age of files to monitor. Format examples: 30s, 15m, 1h. Age is relative to file modification time. Leave empty to apply no age filters.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + max_age_dur: Annotated[Optional[str], pydantic.Field(alias="maxAgeDur")] = None + r"""The maximum age of event timestamps to collect. Format examples: 60s, 4h, 3d, 1w. Can be used in conjuction with \"Check file modification times\". Leave empty to apply no age filters.""" - template_sqs_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleArn") + check_file_mod_time: Annotated[ + Optional[bool], pydantic.Field(alias="checkFileModTime") ] = None - r"""Binds 'SQSAssumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleArn' at runtime.""" + r"""Skip files with modification times earlier than the maximum age duration""" - template_sqs_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAssumeRoleExternalId") - ] = None - r"""Binds 'SQSAssumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAssumeRoleExternalId' at runtime.""" + force_text: Annotated[Optional[bool], pydantic.Field(alias="forceText")] = None + r"""Forces files containing binary data to be streamed as text""" - template_sqs_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_SQSAwsSecretKey") - ] = None - r"""Binds 'SQSAwsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'SQSAwsSecretKey' at runtime.""" + hash_len: Annotated[Optional[float], pydantic.Field(alias="hashLen")] = None + r"""Length of file header bytes to use in hash for unique file identification. Values above 16384 may cause issues with re-ingesting files.""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + breaker_rulesets: Annotated[ + Optional[List[str]], pydantic.Field(alias="breakerRulesets") + ] = None + r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - @field_serializer("sqs_aws_authentication_method") - def serialize_sqs_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.SqsAuthenticationMethodOptions(value) - except ValueError: - return value - return value + disable_stale_channel_flush: Annotated[ + Optional[bool], pydantic.Field(alias="disableStaleChannelFlush") + ] = None + r"""When enabled, no Event Breaker channel flush timeout applies and the timeout below is ignored. Prefer this option when using header-based breakers for file types such as CSV or IIS.""" - @field_serializer("tag_after_processing") - def serialize_tag_after_processing(self, value): - if isinstance(value, str): - try: - return models.TagAfterProcessingOptions(value) - except ValueError: - return value - return value + stale_channel_flush_ms: Annotated[ + Optional[float], pydantic.Field(alias="staleChannelFlushMs") + ] = None + r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "fileFilter", - "awsAccountId", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "breakerRulesets", - "staleChannelFlushMs", - "maxMessages", - "visibilityTimeout", - "numReceivers", - "socketTimeout", - "skipOnError", - "includeSqsMetadata", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "enableSQSAssumeRole", - "sharedCredentials", - "sharedAssumeRoleArn", - "preprocess", - "metadata", - "checkpointing", - "pollTimeout", - "encoding", - "description", - "awsApiKey", - "awsSecret", - "SQSAssumeRoleArn", - "SQSAssumeRoleExternalId", - "SQSDurationSeconds", - "SQSAwsAuthenticationMethod", - "SQSAwsSecret", - "SQSAwsSecretKey", - "tagAfterProcessing", - "processedTagKey", - "processedTagValue", - "__template_environment", - "__template_streamtags", - "__template_queueName", - "__template_awsAccountId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_awsApiKey", - "__template_SQSAssumeRoleArn", - "__template_SQSAssumeRoleExternalId", - "__template_SQSAwsSecretKey", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + description: Optional[str] = None + r"""Optional description for this configuration.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + path: Optional[str] = None + r"""Directory path to search for files. Environment variables will be resolved (example: $CRIBL_HOME/log/).""" - return m + depth: Optional[float] = None + r"""Set how many subdirectories deep to search. Use 0 to search only files in the given path, 1 to also look in its immediate subdirectories, etc. Leave it empty for unlimited depth.""" + suppress_missing_path_errors: Annotated[ + Optional[bool], pydantic.Field(alias="suppressMissingPathErrors") + ] = None + r"""Suppress errors when search path does not exist""" -class InputResponseInputWindowsMetricsType(str, Enum): - r"""Connector type identifier.""" + delete_files: Annotated[Optional[bool], pydantic.Field(alias="deleteFiles")] = None + r"""Delete files after they have been collected""" - WINDOWS_METRICS = "windows_metrics" + salt_hash: Annotated[Optional[bool], pydantic.Field(alias="saltHash")] = None + r"""Salt the file hash with the Source file path. Ensures that all files with the same header hash, such as CSV files, are ingested. Moving or renaming the file, or toggling this after starting the Source will cause re-ingestion.""" + optimize_leaf_directories: Annotated[ + Optional[bool], pydantic.Field(alias="optimizeLeafDirectories") + ] = None + r"""Skip rescans of unchanged directories based on directory modification time. Uses an exponential backoff strategy, reducing load on the filesystems, but possibly delaying detection of new data. This option is optimized for search paths where files exist in the leaf directories.""" -class InputResponseInputWindowsMetricsSystemMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for system metrics""" + enable_discovery_throttle: Annotated[ + Optional[bool], pydantic.Field(alias="enableDiscoveryThrottle") + ] = None + r"""When enabled, discovery will throttle CPU usage to the configured target percentage.""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + discovery_throttle_cpu_percent: Annotated[ + Optional[float], pydantic.Field(alias="discoveryThrottleCpuPercent") + ] = None + r"""Target CPU utilization percentage during file discovery. Discovery alternates between work and yield periods within a 200ms cycle. For example, 25% processes entries for 50ms then yields for 150ms. Lower values reduce CPU usage at the cost of longer discovery times.""" + include_unidentifiable_binary: Annotated[ + Optional[bool], pydantic.Field(alias="includeUnidentifiableBinary") + ] = None + r"""Stream binary files as Base64-encoded chunks""" -class InputResponseInputWindowsMetricsSystemTypedDict(TypedDict): - mode: NotRequired[InputResponseInputWindowsMetricsSystemMode] - r"""Select the level of details for system metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all system information""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class InputResponseInputWindowsMetricsSystem(BaseModel): - mode: Optional[InputResponseInputWindowsMetricsSystemMode] = None - r"""Select the level of details for system metrics""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" - detail: Optional[bool] = None - r"""Generate metrics for all system information""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @field_serializer("mode") def serialize_mode(self, value): if isinstance(value, str): try: - return models.InputResponseInputWindowsMetricsSystemMode(value) + return models.InputResponseInputFileMode(value) except ValueError: return value return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "mode", + "interval", + "filenames", + "filterArchivedFiles", + "tailOnly", + "idleTimeout", + "minAgeDur", + "maxAgeDur", + "checkFileModTime", + "forceText", + "hashLen", + "enableLoadBalancing", + "metadata", + "breakerRulesets", + "disableStaleChannelFlush", + "staleChannelFlushMs", + "autoParse", + "description", + "path", + "depth", + "suppressMissingPathErrors", + "deleteFiles", + "saltHash", + "optimizeLeafDirectories", + "enableDiscoveryThrottle", + "discoveryThrottleCpuPercent", + "includeUnidentifiableBinary", + "__template_environment", + "__template_streamtags", + "notifications", + "status", + ] + ) serialized = handler(self) m = {} @@ -14265,183 +14204,319 @@ def serialize_model(self, handler): return m -class InputResponseInputWindowsMetricsCPUMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of details for CPU metrics""" +class InputResponseInputSyslogSyslog2TypedDict(TypedDict): + type: TypeOptionsSyslog + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + tcp_port: float + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + udp_port: NotRequired[float] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + timestamp_timezone: NotRequired[str] + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: NotRequired[bool] + r"""Treat UDP packet data received as full syslog message""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: NotRequired[List[str]] + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + octet_counting: NotRequired[bool] + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: NotRequired[bool] + r"""Enable if we should infer the syslog framing of the incoming messages.""" + strictly_infer_octet_counting: NotRequired[bool] + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + allow_non_standard_app_name: NotRequired[bool] + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: NotRequired[bool] + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + template_timestamp_timezone: NotRequired[str] + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class InputResponseInputSyslogSyslog2(BaseModel): + type: TypeOptionsSyslog + r"""Connector type identifier.""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + tcp_port: Annotated[float, pydantic.Field(alias="tcpPort")] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" -class InputResponseInputWindowsMetricsCPUTypedDict(TypedDict): - mode: NotRequired[InputResponseInputWindowsMetricsCPUMode] - r"""Select the level of details for CPU metrics""" - per_cpu: NotRequired[bool] - r"""Generate metrics for each CPU""" - detail: NotRequired[bool] - r"""Generate metrics for all CPU states""" - time: NotRequired[bool] - r"""Generate raw, monotonic CPU time counters""" + id: Optional[str] = None + r"""Unique ID for this input""" + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" -class InputResponseInputWindowsMetricsCPU(BaseModel): - mode: Optional[InputResponseInputWindowsMetricsCPUMode] = None - r"""Select the level of details for CPU metrics""" + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - per_cpu: Annotated[Optional[bool], pydantic.Field(alias="perCpu")] = None - r"""Generate metrics for each CPU""" + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - detail: Optional[bool] = None - r"""Generate metrics for all CPU states""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - time: Optional[bool] = None - r"""Generate raw, monotonic CPU time counters""" + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputWindowsMetricsCPUMode(value) - except ValueError: - return value - return value + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perCpu", "detail", "time"]) - serialized = handler(self) - m = {} + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + pq: Optional[PqType] = None - return m + udp_port: Annotated[Optional[float], pydantic.Field(alias="udpPort")] = None + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" -class InputResponseInputWindowsMetricsMemoryMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for memory metrics""" + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="timestampTimezone") + ] = None + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + ] = None + r"""Treat UDP packet data received as full syslog message""" -class InputResponseInputWindowsMetricsMemoryTypedDict(TypedDict): - mode: NotRequired[InputResponseInputWindowsMetricsMemoryMode] - r"""Select the level of details for memory metrics""" - detail: NotRequired[bool] - r"""Generate metrics for all memory states""" + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="keepFieldsList") + ] = None + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" -class InputResponseInputWindowsMetricsMemory(BaseModel): - mode: Optional[InputResponseInputWindowsMetricsMemoryMode] = None - r"""Select the level of details for memory metrics""" + octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + None + ) + r"""Enable if incoming messages use octet counting per RFC 6587.""" - detail: Optional[bool] = None - r"""Generate metrics for all memory states""" + infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( + None + ) + r"""Enable if we should infer the syslog framing of the incoming messages.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputWindowsMetricsMemoryMode(value) - except ValueError: - return value - return value + strictly_infer_octet_counting: Annotated[ + Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + ] = None + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "detail"]) - serialized = handler(self) - m = {} + allow_non_standard_app_name: Annotated[ + Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ] = None + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - return m + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" -class InputResponseInputWindowsMetricsNetworkMode( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select the level of details for network metrics""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" + description: Optional[str] = None + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + ] = None + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" -class InputResponseInputWindowsMetricsNetworkTypedDict(TypedDict): - mode: NotRequired[InputResponseInputWindowsMetricsNetworkMode] - r"""Select the level of details for network metrics""" - detail: NotRequired[bool] - r"""Generate full network metrics""" - protocols: NotRequired[bool] - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" - devices: NotRequired[List[str]] - r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" - per_interface: NotRequired[bool] - r"""Generate separate metrics for each interface""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" -class InputResponseInputWindowsMetricsNetwork(BaseModel): - mode: Optional[InputResponseInputWindowsMetricsNetworkMode] = None - r"""Select the level of details for network metrics""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - detail: Optional[bool] = None - r"""Generate full network metrics""" + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - protocols: Optional[bool] = None - r"""Generate protocol metrics for ICMP, ICMPMsg, IP, TCP, UDP and UDPLite""" + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - devices: Optional[List[str]] = None - r"""Network interfaces to include/exclude. All interfaces are included if this list is empty.""" + template_timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="__template_timestampTimezone") + ] = None + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" - per_interface: Annotated[Optional[bool], pydantic.Field(alias="perInterface")] = ( - None - ) - r"""Generate separate metrics for each interface""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputWindowsMetricsNetworkMode(value) - except ValueError: - return value - return value + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( - ["mode", "detail", "protocols", "devices", "perInterface"] + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "udpPort", + "maxBufferSize", + "ipWhitelistRegex", + "timestampTimezone", + "singleMsgUdpPackets", + "enableProxyHeader", + "keepFieldsList", + "octetCounting", + "inferFraming", + "strictlyInferOctetCounting", + "allowNonStandardAppName", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "tls", + "metadata", + "udpSocketRxBufSize", + "enableLoadBalancing", + "autoParse", + "description", + "enableEnhancedProxyHeaderParsing", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + "__template_timestampTimezone", + "notifications", + "status", + ] ) serialized = handler(self) m = {} @@ -14457,200 +14532,318 @@ def serialize_model(self, handler): return m -class InputResponseInputWindowsMetricsDiskMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the level of details for disk metrics""" - - # Basic - BASIC = "basic" - # All - ALL = "all" - # Custom - CUSTOM = "custom" - # Disabled - DISABLED = "disabled" - - -class InputResponseInputWindowsMetricsDiskTypedDict(TypedDict): - mode: NotRequired[InputResponseInputWindowsMetricsDiskMode] - r"""Select the level of details for disk metrics""" - per_volume: NotRequired[bool] - r"""Generate separate metrics for each volume""" - detail: NotRequired[bool] - r"""Generate full disk metrics""" - volumes: NotRequired[List[str]] - r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" +class InputResponseInputSyslogSyslog1TypedDict(TypedDict): + type: TypeOptionsSyslog + r"""Connector type identifier.""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" + udp_port: float + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + tcp_port: NotRequired[float] + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" + max_buffer_size: NotRequired[float] + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" + ip_whitelist_regex: NotRequired[str] + r"""Regex matching IP addresses that are allowed to send data""" + timestamp_timezone: NotRequired[str] + r"""Timezone to assign to timestamps without timezone info""" + single_msg_udp_packets: NotRequired[bool] + r"""Treat UDP packet data received as full syslog message""" + enable_proxy_header: NotRequired[bool] + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" + keep_fields_list: NotRequired[List[str]] + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" + octet_counting: NotRequired[bool] + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: NotRequired[bool] + r"""Enable if we should infer the syslog framing of the incoming messages.""" + strictly_infer_octet_counting: NotRequired[bool] + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + allow_non_standard_app_name: NotRequired[bool] + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" + socket_idle_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" + socket_ending_max_wait: NotRequired[float] + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" + socket_max_lifespan: NotRequired[float] + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events from this input""" + udp_socket_rx_buf_size: NotRequired[float] + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: NotRequired[bool] + r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: NotRequired[bool] + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_udp_port: NotRequired[str] + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" + template_tcp_port: NotRequired[str] + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" + template_timestamp_timezone: NotRequired[str] + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Source.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputWindowsMetricsDisk(BaseModel): - mode: Optional[InputResponseInputWindowsMetricsDiskMode] = None - r"""Select the level of details for disk metrics""" +class InputResponseInputSyslogSyslog1(BaseModel): + type: TypeOptionsSyslog + r"""Connector type identifier.""" - per_volume: Annotated[Optional[bool], pydantic.Field(alias="perVolume")] = None - r"""Generate separate metrics for each volume""" + host: str + r"""Address to bind on. For IPv4 (all addresses), use the default '0.0.0.0'. For IPv6, enter '::' (all addresses) or specify an IP address.""" - detail: Optional[bool] = None - r"""Generate full disk metrics""" + udp_port: Annotated[float, pydantic.Field(alias="udpPort")] + r"""Enter UDP port number to listen on. Not required if listening on TCP.""" - volumes: Optional[List[str]] = None - r"""Windows volumes to include/exclude. E.g.: C:, !E:, etc. Wildcards and ! (not) operators are supported. All volumes are included if this list is empty.""" + id: Optional[str] = None + r"""Unique ID for this input""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.InputResponseInputWindowsMetricsDiskMode(value) - except ValueError: - return value - return value + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "perVolume", "detail", "volumes"]) - serialized = handler(self) - m = {} + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - return m + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" -class InputResponseInputWindowsMetricsCustomTypedDict(TypedDict): - system: NotRequired[InputResponseInputWindowsMetricsSystemTypedDict] - cpu: NotRequired[InputResponseInputWindowsMetricsCPUTypedDict] - memory: NotRequired[InputResponseInputWindowsMetricsMemoryTypedDict] - network: NotRequired[InputResponseInputWindowsMetricsNetworkTypedDict] - disk: NotRequired[InputResponseInputWindowsMetricsDiskTypedDict] + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" -class InputResponseInputWindowsMetricsCustom(BaseModel): - system: Optional[InputResponseInputWindowsMetricsSystem] = None + pq: Optional[PqType] = None - cpu: Optional[InputResponseInputWindowsMetricsCPU] = None + tcp_port: Annotated[Optional[float], pydantic.Field(alias="tcpPort")] = None + r"""Enter TCP port number to listen on. Not required if listening on UDP.""" - memory: Optional[InputResponseInputWindowsMetricsMemory] = None + max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="maxBufferSize") + ] = None + r"""Maximum number of events to buffer when downstream is blocking. Only applies to UDP.""" - network: Optional[InputResponseInputWindowsMetricsNetwork] = None + ip_whitelist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipWhitelistRegex") + ] = None + r"""Regex matching IP addresses that are allowed to send data""" - disk: Optional[InputResponseInputWindowsMetricsDisk] = None + timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="timestampTimezone") + ] = None + r"""Timezone to assign to timestamps without timezone info""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["system", "cpu", "memory", "network", "disk"]) - serialized = handler(self) - m = {} + single_msg_udp_packets: Annotated[ + Optional[bool], pydantic.Field(alias="singleMsgUdpPackets") + ] = None + r"""Treat UDP packet data received as full syslog message""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Enable if the connection is proxied by a device that supports Proxy Protocol V1 or V2""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + keep_fields_list: Annotated[ + Optional[List[str]], pydantic.Field(alias="keepFieldsList") + ] = None + r"""Wildcard list of fields to keep from source data; * = ALL (default)""" - return m + octet_counting: Annotated[Optional[bool], pydantic.Field(alias="octetCounting")] = ( + None + ) + r"""Enable if incoming messages use octet counting per RFC 6587.""" + infer_framing: Annotated[Optional[bool], pydantic.Field(alias="inferFraming")] = ( + None + ) + r"""Enable if we should infer the syslog framing of the incoming messages.""" -class InputResponseInputWindowsMetricsHostTypedDict(TypedDict): - mode: NotRequired[ModeOptionsHost] - r"""Select level of detail for host metrics""" - custom: NotRequired[InputResponseInputWindowsMetricsCustomTypedDict] + strictly_infer_octet_counting: Annotated[ + Optional[bool], pydantic.Field(alias="strictlyInferOctetCounting") + ] = None + r"""Enable if we should infer octet counting only if the messages comply with RFC 5424.""" + allow_non_standard_app_name: Annotated[ + Optional[bool], pydantic.Field(alias="allowNonStandardAppName") + ] = None + r"""Enable if RFC 3164-formatted messages have hyphens in the app name portion of the TAG section. If disabled, only alphanumeric characters and underscores are allowed. Ignored for RFC 5424-formatted messages.""" -class InputResponseInputWindowsMetricsHost(BaseModel): - mode: Optional[ModeOptionsHost] = None - r"""Select level of detail for host metrics""" + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process for TCP connections. Use 0 for unlimited.""" - custom: Optional[InputResponseInputWindowsMetricsCustom] = None + socket_idle_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketIdleTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. After this time, the connection will be closed. Leave at 0 for no inactive socket monitoring.""" - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptionsHost(value) - except ValueError: - return value - return value + socket_ending_max_wait: Annotated[ + Optional[float], pydantic.Field(alias="socketEndingMaxWait") + ] = None + r"""How long the server will wait after initiating a closure for a client to close its end of the connection. If the client doesn't close the connection within this time, the server will forcefully terminate the socket to prevent resource leaks and ensure efficient connection cleanup and system stability. Leave at 0 for no inactive socket monitoring.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["mode", "custom"]) - serialized = handler(self) - m = {} + socket_max_lifespan: Annotated[ + Optional[float], pydantic.Field(alias="socketMaxLifespan") + ] = None + r"""The maximum duration a socket can remain open, even if active. This helps manage resources and mitigate issues caused by TCP pinning. Set to 0 to disable.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events from this input""" - return m + udp_socket_rx_buf_size: Annotated[ + Optional[float], pydantic.Field(alias="udpSocketRxBufSize") + ] = None + r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" + enable_load_balancing: Annotated[ + Optional[bool], pydantic.Field(alias="enableLoadBalancing") + ] = None + r"""Load balance traffic across all Worker Processes""" -class InputResponseInputWindowsMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" - enable: NotRequired[bool] - r"""Spool metrics to disk for Cribl Edge and Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + enable_enhanced_proxy_header_parsing: Annotated[ + Optional[bool], pydantic.Field(alias="enableEnhancedProxyHeaderParsing") + ] = None + r"""When enabled, parses PROXY protocol headers during the TLS handshake. Disable if compatibility issues arise.""" -class InputResponseInputWindowsMetricsPersistence(BaseModel): - r"""persistence""" + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - enable: Optional[bool] = None - r"""Spool metrics to disk for Cribl Edge and Search""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + template_udp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_udpPort") + ] = None + r"""Binds 'udpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'udpPort' at runtime.""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + template_tcp_port: Annotated[ + Optional[str], pydantic.Field(alias="__template_tcpPort") + ] = None + r"""Binds 'tcpPort' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tcpPort' at runtime.""" - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" + template_timestamp_timezone: Annotated[ + Optional[str], pydantic.Field(alias="__template_timestampTimezone") + ] = None + r"""Binds 'timestampTimezone' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'timestampTimezone' at runtime.""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/windows_metrics""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Source.""" - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "criblSourceProvenance", + "connections", + "pq", + "tcpPort", + "maxBufferSize", + "ipWhitelistRegex", + "timestampTimezone", + "singleMsgUdpPackets", + "enableProxyHeader", + "keepFieldsList", + "octetCounting", + "inferFraming", + "strictlyInferOctetCounting", + "allowNonStandardAppName", + "maxActiveCxn", + "socketIdleTimeout", + "socketEndingMaxWait", + "socketMaxLifespan", + "tls", + "metadata", + "udpSocketRxBufSize", + "enableLoadBalancing", + "autoParse", + "description", + "enableEnhancedProxyHeaderParsing", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_udpPort", + "__template_tcpPort", + "__template_timestampTimezone", + "notifications", + "status", ] ) serialized = handler(self) @@ -14667,9 +14860,37 @@ def serialize_model(self, handler): return m -class InputResponseInputWindowsMetricsTypedDict(TypedDict): - type: InputResponseInputWindowsMetricsType +InputResponseInputSyslogUnionTypedDict = TypeAliasType( + "InputResponseInputSyslogUnionTypedDict", + Union[ + InputResponseInputSyslogSyslog1TypedDict, + InputResponseInputSyslogSyslog2TypedDict, + ], +) + + +InputResponseInputSyslogUnion = TypeAliasType( + "InputResponseInputSyslogUnion", + Union[InputResponseInputSyslogSyslog1, InputResponseInputSyslogSyslog2], +) + + +class InputResponseQueueType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The queue type used (or created)""" + + # Standard + STANDARD = "standard" + # FIFO + FIFO = "fifo" + + +class InputResponseInputSqsTypedDict(TypedDict): + type: TypeOptionsSqs r"""Connector type identifier.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + queue_type: InputResponseQueueType + r"""The queue type used (or created)""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -14684,40 +14905,91 @@ class InputResponseInputWindowsMetricsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" - host: NotRequired[InputResponseInputWindowsMetricsHostTypedDict] - process: NotRequired[ProcessTypeTypedDict] - gpu: NotRequired[GpuTypeTypedDict] + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + create_queue: NotRequired[bool] + r"""Create queue if it does not exist""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SQS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_messages: NotRequired[float] + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" + visibility_timeout: NotRequired[float] + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - persistence: NotRequired[InputResponseInputWindowsMetricsPersistenceTypedDict] - r"""persistence""" - disable_native_module: NotRequired[bool] - r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + poll_timeout: NotRequired[float] + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + num_receivers: NotRequired[float] + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_queue_type: NotRequired[str] + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputWindowsMetrics(BaseModel): - type: InputResponseInputWindowsMetricsType +class InputResponseInputSqs(BaseModel): + type: TypeOptionsSqs r"""Connector type identifier.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to read events from. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Value must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can only be evaluated at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + + queue_type: Annotated[InputResponseQueueType, pydantic.Field(alias="queueType")] + r"""The queue type used (or created)""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -14742,7 +15014,7 @@ class InputResponseInputWindowsMetrics(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -14752,29 +15024,92 @@ class InputResponseInputWindowsMetrics(BaseModel): pq: Optional[PqType] = None - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metric collections. Default is 10 seconds.""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + + create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None + r"""Create queue if it does not exist""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + region: Optional[str] = None + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SQS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" - host: Optional[InputResponseInputWindowsMetricsHost] = None + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - process: Optional[ProcessType] = None + max_messages: Annotated[Optional[float], pydantic.Field(alias="maxMessages")] = None + r"""The maximum number of messages SQS should return in a poll request. Amazon SQS never returns more messages than this value (however, fewer messages might be returned). Valid values: 1 to 10.""" - gpu: Optional[GpuType] = None + visibility_timeout: Annotated[ + Optional[float], pydantic.Field(alias="visibilityTimeout") + ] = None + r"""After messages are retrieved by a ReceiveMessage request, @{product} will hide them from subsequent retrieve requests for at least this duration. You can set this as high as 43200 sec. (12 hours).""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - persistence: Optional[InputResponseInputWindowsMetricsPersistence] = None - r"""persistence""" + poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None + r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" - disable_native_module: Annotated[ - Optional[bool], pydantic.Field(alias="disableNativeModule") - ] = None - r"""Enable to use built-in tools (PowerShell) to collect metrics instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-metrics/#advanced-tab)""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: Optional[str] = None r"""Optional description for this configuration.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + num_receivers: Annotated[Optional[float], pydantic.Field(alias="numReceivers")] = ( + None + ) + r"""How many receiver processes to run. The higher the number, the better the throughput - at the expense of CPU overhead.""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -14785,12 +15120,75 @@ class InputResponseInputWindowsMetrics(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_queue_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueType") + ] = None + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("queue_type") + def serialize_queue_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseQueueType(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -14805,16 +15203,38 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "interval", - "host", - "process", - "gpu", + "awsAccountId", + "createQueue", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxMessages", + "visibilityTimeout", "metadata", - "persistence", - "disableNativeModule", + "pollTimeout", + "autoParse", "description", + "awsApiKey", + "awsSecret", + "numReceivers", "__template_environment", "__template_streamtags", + "__template_queueName", + "__template_queueType", + "__template_awsAccountId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_awsApiKey", "notifications", "status", ] @@ -14833,15 +15253,19 @@ def serialize_model(self, handler): return m -class InputResponseInputKubeEventsType(str, Enum): +class InputResponseInputModelDrivenTelemetryType(str, Enum): r"""Connector type identifier.""" - KUBE_EVENTS = "kube_events" + MODEL_DRIVEN_TELEMETRY = "model_driven_telemetry" -class InputResponseInputKubeEventsTypedDict(TypedDict): - type: InputResponseInputKubeEventsType +class InputResponseInputModelDrivenTelemetryTypedDict(TypedDict): + type: InputResponseInputModelDrivenTelemetryType r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -14856,33 +15280,49 @@ class InputResponseInputKubeEventsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] - r"""Filtering on event fields""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" + shutdown_timeout_ms: NotRequired[float] + r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputKubeEvents(BaseModel): - type: InputResponseInputKubeEventsType +class InputResponseInputModelDrivenTelemetry(BaseModel): + type: InputResponseInputModelDrivenTelemetryType r"""Connector type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + id: Optional[str] = None r"""Unique ID for this input""" @@ -14907,7 +15347,7 @@ class InputResponseInputKubeEvents(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -14917,12 +15357,32 @@ class InputResponseInputKubeEvents(BaseModel): pq: Optional[PqType] = None - rules: Optional[List[RuleConfInputKubeMetrics]] = None - r"""Filtering on event fields""" + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited.""" + + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") + ] = None + r"""Maximum size, in KB, of a single received gRPC message. Messages exceeding this limit are rejected before processing. Compressed messages are checked against their decompressed size.""" + + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") + ] = None + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds the number of connections, not the streams multiplexed on each.""" + + shutdown_timeout_ms: Annotated[ + Optional[float], pydantic.Field(alias="shutdownTimeoutMs") + ] = None + r"""Time in milliseconds to allow the server to shutdown gracefully before forcing shutdown. Defaults to 5000.""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -14936,7 +15396,17 @@ class InputResponseInputKubeEvents(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None @@ -14956,11 +15426,17 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "rules", + "tls", "metadata", + "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", + "shutdownTimeoutMs", "description", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", "notifications", "status", ] @@ -14979,29 +15455,164 @@ def serialize_model(self, handler): return m -class InputResponseInputKubeLogsType(str, Enum): - r"""Connector type identifier.""" +class InputResponseInputOpenTelemetryType(str, Enum): + r"""Source type identifier.""" - KUBE_LOGS = "kube_logs" + OPEN_TELEMETRY = "open_telemetry" -class InputResponseInputKubeLogsRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" +class InputResponseProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" + + # gRPC + GRPC = "grpc" + # HTTP + HTTP = "http" + + +class InputResponseOTLPVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" + + # 0.10.0 + ZERO_DOT_10_DOT_0 = "0.10.0" + # 1.3.1 + ONE_DOT_3_DOT_1 = "1.3.1" + + +class InputResponseInputOpenTelemetryAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""OpenTelemetry authentication type""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + + +class InputResponseAuthMethodsExtAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" + + # Token + TOKEN = "token" + # Token (secret) + TOKEN_SECRET = "tokenSecret" + # Basic + BASIC = "basic" + # Basic (credentials secret) + BASIC_SECRET = "basicSecret" + # OAuth + OAUTH = "oauth" + + +class InputResponseAuthMethodsExtTypedDict(TypedDict): + auth_type: InputResponseAuthMethodsExtAuthenticationType + r"""Authentication type""" + token: NotRequired[str] + r"""Bearer token for Authorization header""" description: NotRequired[str] - r"""Optional description of this rule's purpose""" + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this auth method""" + enabled: NotRequired[bool] + r"""Enable""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + issuer: NotRequired[str] + r"""Expected token issuer (iss claim)""" + jwks_uri: NotRequired[str] + r"""URL of the JWKS endpoint used to fetch signing keys""" + audience: NotRequired[str] + r"""Expected token audience (aud claim)""" + scopes: NotRequired[List[str]] + r"""Scopes the token must grant (optional)""" -class InputResponseInputKubeLogsRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression applied to Pod objects. Return 'true' to include it.""" +class InputResponseAuthMethodsExt(BaseModel): + auth_type: Annotated[ + InputResponseAuthMethodsExtAuthenticationType, pydantic.Field(alias="authType") + ] + r"""Authentication type""" + + token: Optional[str] = None + r"""Bearer token for Authorization header""" description: Optional[str] = None - r"""Optional description of this rule's purpose""" + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this auth method""" + + enabled: Optional[bool] = None + r"""Enable""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + issuer: Optional[str] = None + r"""Expected token issuer (iss claim)""" + + jwks_uri: Annotated[Optional[str], pydantic.Field(alias="jwksUri")] = None + r"""URL of the JWKS endpoint used to fetch signing keys""" + + audience: Optional[str] = None + r"""Expected token audience (aud claim)""" + + scopes: Optional[List[str]] = None + r"""Scopes the token must grant (optional)""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseAuthMethodsExtAuthenticationType(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description"]) + optional_fields = set( + [ + "token", + "description", + "metadata", + "enabled", + "tokenSecret", + "username", + "password", + "credentialsSecret", + "issuer", + "jwksUri", + "audience", + "scopes", + ] + ) serialized = handler(self) m = {} @@ -15016,9 +15627,13 @@ def serialize_model(self, handler): return m -class InputResponseInputKubeLogsTypedDict(TypedDict): - type: InputResponseInputKubeLogsType - r"""Connector type identifier.""" +class InputResponseInputOpenTelemetryTypedDict(TypedDict): + type: InputResponseInputOpenTelemetryType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" id: NotRequired[str] r"""Unique ID for this input""" disabled: NotRequired[bool] @@ -15033,48 +15648,91 @@ class InputResponseInputKubeLogsTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" - rules: NotRequired[List[InputResponseInputKubeLogsRuleTypedDict]] - r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" - timestamps: NotRequired[bool] - r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" - line_buffer_limit: NotRequired[float] - r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" - lb_disable_assembly: NotRequired[bool] - r"""Internal flag to disable LB worker payload reassembly.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + capture_headers_warning: Literal[""] + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + enable_health_check: NotRequired[bool] + r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + protocol: NotRequired[InputResponseProtocol] + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" + extract_spans: NotRequired[bool] + r"""Enable to extract each incoming span to a separate event""" + extract_metrics: NotRequired[bool] + r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" + otlp_version: NotRequired[InputResponseOTLPVersion] + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" + auth_type: NotRequired[InputResponseInputOpenTelemetryAuthenticationType] + r"""OpenTelemetry authentication type""" + auth_methods_ext: NotRequired[List[InputResponseAuthMethodsExtTypedDict]] + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] r"""Fields to add to events from this input""" - persistence: NotRequired[DiskSpoolingTypeTypedDict] - r"""Disk Spooling""" - breaker_rulesets: NotRequired[List[str]] - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" - stale_channel_flush_ms: NotRequired[float] - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" - enable_load_balancing: NotRequired[bool] - r"""Load balance traffic across all Worker Processes""" + max_active_cxn: NotRequired[float] + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" + max_message_size_kb: NotRequired[float] + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" + max_concurrent_streams: NotRequired[float] + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: NotRequired[str] r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + extract_logs: NotRequired[bool] + r"""Enable to extract each incoming log record to a separate event""" template_environment: NotRequired[str] r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_protocol: NotRequired[str] + r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + template_otlp_version: NotRequired[str] + r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Source.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class InputResponseInputKubeLogs(BaseModel): - type: InputResponseInputKubeLogsType - r"""Connector type identifier.""" +class InputResponseInputOpenTelemetry(BaseModel): + type: InputResponseInputOpenTelemetryType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" id: Optional[str] = None r"""Unique ID for this input""" @@ -15099,60 +15757,136 @@ class InputResponseInputKubeLogs(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), + cribl_source_provenance: Annotated[ + Optional[InputProvenanceTypeOptional], + pydantic.Field(alias="criblSourceProvenance"), + ] = None + r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + CAPTURE_HEADERS_WARNING: Annotated[ + Annotated[Optional[Literal[""]], AfterValidator(validate_const(""))], + pydantic.Field(alias="captureHeadersWarning"), + ] = "" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 sec.; maximum 600 sec. (10 min.).""" + + enable_health_check: Annotated[ + Optional[bool], pydantic.Field(alias="enableHealthCheck") + ] = None + r"""Enable to expose the /cribl_health endpoint, which returns 200 OK when this Source is healthy""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist.""" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" - pq: Optional[PqType] = None + protocol: Optional[InputResponseProtocol] = None + r"""Select whether to leverage gRPC or HTTP for OpenTelemetry""" - interval: Optional[float] = None - r"""Time, in seconds, between checks for new containers. Default is 15 secs.""" + extract_spans: Annotated[Optional[bool], pydantic.Field(alias="extractSpans")] = ( + None + ) + r"""Enable to extract each incoming span to a separate event""" - rules: Optional[List[InputResponseInputKubeLogsRule]] = None - r"""Add rules to decide which Pods to collect logs from. Logs are collected if no rules are given or if all the rules' expressions evaluate to true.""" + extract_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="extractMetrics") + ] = None + r"""Enable to extract each incoming Gauge or IntGauge metric to multiple events, one per data point""" - timestamps: Optional[bool] = None - r"""For use when containers do not emit a timestamp, prefix each line of output with a timestamp. If you enable this setting, you can use the Kubernetes Logs Event Breaker and the kubernetes_logs Pre-processing Pipeline to remove them from the events after the timestamps are extracted.""" + otlp_version: Annotated[ + Optional[InputResponseOTLPVersion], pydantic.Field(alias="otlpVersion") + ] = None + r"""The version of OTLP Protobuf definitions to use when interpreting received data""" - line_buffer_limit: Annotated[ - Optional[float], pydantic.Field(alias="lineBufferLimit") + auth_type: Annotated[ + Optional[InputResponseInputOpenTelemetryAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum bytes to buffer while reassembling a single log line. A line that exceeds this size is flushed as-is, either whole or partially. The default is 1048576 (1 MB).""" + r"""OpenTelemetry authentication type""" - lb_disable_assembly: Annotated[ - Optional[bool], pydantic.Field(alias="__LBDisableAssembly") + auth_methods_ext: Annotated[ + Optional[List[InputResponseAuthMethodsExt]], + pydantic.Field(alias="authMethodsExt"), ] = None - r"""Internal flag to disable LB worker payload reassembly.""" + r"""Shared secrets to authenticate clients. Supports Bearer tokens, Basic auth, and OAuth (JWKS-backed JWT) methods. If empty, unauthenticated access is permitted.""" metadata: Optional[List[MetadataConfInputCollection]] = None r"""Fields to add to events from this input""" - persistence: Optional[DiskSpoolingType] = None - r"""Disk Spooling""" - - breaker_rulesets: Annotated[ - Optional[List[str]], pydantic.Field(alias="breakerRulesets") - ] = None - r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" + max_active_cxn: Annotated[Optional[float], pydantic.Field(alias="maxActiveCxn")] = ( + None + ) + r"""Maximum number of active connections allowed per Worker Process. Use 0 for unlimited. This does not limit concurrent HTTP/2 streams on a connection; use Maximum concurrent streams and Maximum message size for that bound.""" - stale_channel_flush_ms: Annotated[ - Optional[float], pydantic.Field(alias="staleChannelFlushMs") + max_message_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxMessageSizeKB") ] = None - r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + r"""Maximum size, in KB, of a single received gRPC message (OTLP export request). Requests exceeding this limit are rejected before processing. Compressed requests are checked against their decompressed size.""" - enable_load_balancing: Annotated[ - Optional[bool], pydantic.Field(alias="enableLoadBalancing") + max_concurrent_streams: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentStreams") ] = None - r"""Load balance traffic across all Worker Processes""" + r"""Maximum number of concurrent HTTP/2 streams allowed on a single gRPC connection. Combined with Maximum message size, this bounds per-connection receive and decompress state. Active connection limit only bounds connections.""" description: Optional[str] = None r"""Optional description for this configuration.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + extract_logs: Annotated[Optional[bool], pydantic.Field(alias="extractLogs")] = None + r"""Enable to extract each incoming log record to a separate event""" + template_environment: Annotated[ Optional[str], pydantic.Field(alias="__template_environment") ] = None @@ -15163,12 +15897,59 @@ class InputResponseInputKubeLogs(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_protocol: Annotated[ + Optional[str], pydantic.Field(alias="__template_protocol") + ] = None + r"""Binds 'protocol' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'protocol' at runtime.""" + + template_otlp_version: Annotated[ + Optional[str], pydantic.Field(alias="__template_otlpVersion") + ] = None + r"""Binds 'otlpVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'otlpVersion' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Source.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.InputResponseProtocol(value) + except ValueError: + return value + return value + + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): + if isinstance(value, str): + try: + return models.InputResponseOTLPVersion(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseInputOpenTelemetryAuthenticationType(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -15183,19 +15964,39 @@ def serialize_model(self, handler): "criblSourceProvenance", "connections", "pq", - "interval", - "rules", - "timestamps", - "lineBufferLimit", - "__LBDisableAssembly", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "captureHeadersWarning", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "enableHealthCheck", + "ipAllowlistRegex", + "ipDenylistRegex", + "protocol", + "extractSpans", + "extractMetrics", + "otlpVersion", + "authType", + "authMethodsExt", "metadata", - "persistence", - "breakerRulesets", - "staleChannelFlushMs", - "enableLoadBalancing", + "maxActiveCxn", + "maxMessageSizeKB", + "maxConcurrentStreams", "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "extractLogs", "__template_environment", "__template_streamtags", + "__template_host", + "__template_port", + "__template_protocol", + "__template_otlpVersion", "notifications", "status", ] @@ -15214,237 +16015,169 @@ def serialize_model(self, handler): return m -class InputResponseInputKubeMetricsType(str, Enum): - r"""Connector type identifier.""" - - KUBE_METRICS = "kube_metrics" - - -class InputResponseInputKubeMetricsPersistenceTypedDict(TypedDict): - r"""persistence""" - - enable: NotRequired[bool] - r"""Spool metrics on disk for Cribl Search""" - time_window: NotRequired[str] - r"""Time span for each file bucket""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - - -class InputResponseInputKubeMetricsPersistence(BaseModel): - r"""persistence""" - - enable: Optional[bool] = None - r"""Spool metrics on disk for Cribl Search""" - - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time span for each file bucket""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.DataCompressionFormatOptionsPersistence(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "enable", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "destPath", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class InputResponseInputKubeMetricsTypedDict(TypedDict): - type: InputResponseInputKubeMetricsType - r"""Connector type identifier.""" - id: NotRequired[str] - r"""Unique ID for this input""" - disabled: NotRequired[bool] - r"""If true, the Source is disabled and will not collect data.""" - pipeline: NotRequired[str] - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: NotRequired[bool] - r"""Select whether to send data to Routes, or directly to Destinations.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - pq_enabled: NotRequired[bool] - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" - connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: NotRequired[PqTypeTypedDict] - interval: NotRequired[float] - r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" - scrape_kubelet: NotRequired[bool] - r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" - scrape_cadvisor: NotRequired[bool] - r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" - rules: NotRequired[List[RuleConfInputKubeMetricsTypedDict]] - r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - persistence: NotRequired[InputResponseInputKubeMetricsPersistenceTypedDict] - r"""persistence""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_environment: NotRequired[str] - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Source.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" +class InputResponseAuthenticationProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Authentication protocol""" + # None + NONE = "none" + # MD5 + MD5 = "md5" + # SHA1 + SHA = "sha" + # SHA224 + SHA224 = "sha224" + # SHA256 + SHA256 = "sha256" + # SHA384 + SHA384 = "sha384" + # SHA512 + SHA512 = "sha512" -class InputResponseInputKubeMetrics(BaseModel): - type: InputResponseInputKubeMetricsType - r"""Connector type identifier.""" - id: Optional[str] = None - r"""Unique ID for this input""" +class InputResponseV3AuthenticationKeyType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - disabled: Optional[bool] = None - r"""If true, the Source is disabled and will not collect data.""" + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" - pipeline: Optional[str] = None - r"""Pipeline to process data from this Source before sending it through the Routes""" - send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( - None - ) - r"""Select whether to send data to Routes, or directly to Destinations.""" +class InputResponsePrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Privacy protocol""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + # None + NONE = "none" + # DES + DES = "des" + # AES128 + AES = "aes" + # AES256b (Blumenthal) + AES256B = "aes256b" + # AES256r (Reeder) + AES256R = "aes256r" - pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None - r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" +class InputResponseV3PrivacyKeyType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], - pydantic.Field(alias="criblSourceProvenance"), - ] = None - r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" - connections: Optional[List[ConnectionConfInputCollection]] = None - r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" - pq: Optional[PqType] = None +class InputResponseV3UserTypedDict(TypedDict): + name: str + r"""V3 name""" + auth_protocol: NotRequired[InputResponseAuthenticationProtocol] + r"""Authentication protocol""" + auth_key_type: NotRequired[InputResponseV3AuthenticationKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + auth_key: NotRequired[str] + r"""V3 authentication key""" + auth_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" + priv_protocol: NotRequired[InputResponsePrivacyProtocol] + r"""Privacy protocol""" + priv_key_type: NotRequired[InputResponseV3PrivacyKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + priv_key: NotRequired[str] + r"""V3 privacy key""" + priv_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" - interval: Optional[float] = None - r"""Time, in seconds, between consecutive metrics collections. Default is 15 secs.""" - scrape_kubelet: Annotated[Optional[bool], pydantic.Field(alias="scrapeKubelet")] = ( - None - ) - r"""Enable to scrape kubelet metrics from https://:10250/metrics. Requires Edge to run as a DaemonSet with direct network access to the node.""" +class InputResponseV3User(BaseModel): + name: str + r"""V3 name""" - scrape_cadvisor: Annotated[ - Optional[bool], pydantic.Field(alias="scrapeCadvisor") + auth_protocol: Annotated[ + Optional[InputResponseAuthenticationProtocol], + pydantic.Field(alias="authProtocol"), ] = None - r"""Scrape cAdvisor container metrics from https://:10250/metrics/cadvisor. Requires Edge to run as a DaemonSet with direct network access to the Node.""" - - rules: Optional[List[RuleConfInputKubeMetrics]] = None - r"""Add rules to decide which Kubernetes objects to generate metrics for. Events are generated if no rules are given or of all the rules' expressions evaluate to true.""" + r"""Authentication protocol""" - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" + auth_key_type: Annotated[ + Optional[InputResponseV3AuthenticationKeyType], + pydantic.Field(alias="authKeyType"), + ] = None + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - persistence: Optional[InputResponseInputKubeMetricsPersistence] = None - r"""persistence""" + auth_key: Annotated[Optional[str], pydantic.Field(alias="authKey")] = None + r"""V3 authentication key""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + auth_key_secret: Annotated[Optional[str], pydantic.Field(alias="authKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" - template_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_environment") + priv_protocol: Annotated[ + Optional[InputResponsePrivacyProtocol], pydantic.Field(alias="privProtocol") ] = None - r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + r"""Privacy protocol""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + priv_key_type: Annotated[ + Optional[InputResponseV3PrivacyKeyType], pydantic.Field(alias="privKeyType") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Source.""" + priv_key: Annotated[Optional[str], pydantic.Field(alias="privKey")] = None + r"""V3 privacy key""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + priv_key_secret: Annotated[Optional[str], pydantic.Field(alias="privKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" + + @field_serializer("auth_protocol") + def serialize_auth_protocol(self, value): + if isinstance(value, str): + try: + return models.InputResponseAuthenticationProtocol(value) + except ValueError: + return value + return value + + @field_serializer("auth_key_type") + def serialize_auth_key_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseV3AuthenticationKeyType(value) + except ValueError: + return value + return value + + @field_serializer("priv_protocol") + def serialize_priv_protocol(self, value): + if isinstance(value, str): + try: + return models.InputResponsePrivacyProtocol(value) + except ValueError: + return value + return value + + @field_serializer("priv_key_type") + def serialize_priv_key_type(self, value): + if isinstance(value, str): + try: + return models.InputResponseV3PrivacyKeyType(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( [ - "id", - "disabled", - "pipeline", - "sendToRoutes", - "environment", - "pqEnabled", - "streamtags", - "criblSourceProvenance", - "connections", - "pq", - "interval", - "scrapeKubelet", - "scrapeCadvisor", - "rules", - "metadata", - "persistence", - "description", - "__template_environment", - "__template_streamtags", - "notifications", - "status", + "authProtocol", + "authKeyType", + "authKey", + "authKeySecret", + "privProtocol", + "privKeyType", + "privKey", + "privKeySecret", ] ) serialized = handler(self) @@ -15462,286 +16195,278 @@ def serialize_model(self, handler): try: - InputResponseInputOkta.model_rebuild() -except NameError: - pass -try: - InputResponseActivities.model_rebuild() -except NameError: - pass -try: - InputResponseChats.model_rebuild() + InputResponseInputTrendMicroVisionOne.model_rebuild() except NameError: pass try: - InputResponseProjects.model_rebuild() + InputResponseInputMimecastHec.model_rebuild() except NameError: pass try: - InputResponseChatMessages.model_rebuild() + InputResponseInputHashicorpHcpVaultDedicated.model_rebuild() except NameError: pass try: - InputResponseProjectDetails.model_rebuild() + InputResponseInputBeyondtrustHec.model_rebuild() except NameError: pass try: - InputResponseGroups.model_rebuild() + InputResponseInputF5BigIP.model_rebuild() except NameError: pass try: - InputResponseOrganizations.model_rebuild() + InputResponseInputVectraAiHec.model_rebuild() except NameError: pass try: - InputResponseOrganizationUsers.model_rebuild() + InputResponseInputGigamonHec.model_rebuild() except NameError: pass try: - InputResponseOrganizationRoles.model_rebuild() + InputResponseInputPingIdentityPingone.model_rebuild() except NameError: pass try: - InputResponseInputAnthropicCompliance.model_rebuild() + InputResponseInputAkamaiHec.model_rebuild() except NameError: pass try: - InputResponseInputOpenaiComplianceLogs.model_rebuild() + InputResponseInputOkta.model_rebuild() except NameError: pass try: - InputResponseInputUpwindHec.model_rebuild() + InputResponseRetryRules.model_rebuild() except NameError: pass try: - InputResponseInputSysdigHec.model_rebuild() + InputResponseCertOptions.model_rebuild() except NameError: pass try: - InputResponseTLSSettingsServerSide.model_rebuild() + InputResponseInputMicrosoftCopilot.model_rebuild() except NameError: pass try: - InputResponseInputCloudflareHec.model_rebuild() + InputResponseInputAnthropicEnterpriseAnalyticsContentConfig.model_rebuild() except NameError: pass try: - InputResponseInputZscalerHecAuthToken.model_rebuild() + InputResponseInputAnthropicEnterpriseAnalytics.model_rebuild() except NameError: pass try: - InputResponseInputZscalerHec.model_rebuild() + InputResponseActivities.model_rebuild() except NameError: pass try: - InputResponseInputServicenowTable.model_rebuild() + InputResponseChats.model_rebuild() except NameError: pass try: - InputResponseInputBedrockS3.model_rebuild() + InputResponseProjects.model_rebuild() except NameError: pass try: - InputResponseInputSecurityLake.model_rebuild() + InputResponseChatMessages.model_rebuild() except NameError: pass try: - InputResponseInputNetflow.model_rebuild() + InputResponseProjectDetails.model_rebuild() except NameError: pass try: - InputResponseInputWizWebhook.model_rebuild() + InputResponseGroups.model_rebuild() except NameError: pass try: - InputResponseInputOpenaiContentConfig.model_rebuild() + InputResponseOrganizations.model_rebuild() except NameError: pass try: - InputResponseInputOpenai.model_rebuild() + InputResponseOrganizationUsers.model_rebuild() except NameError: pass try: - InputResponseInputWizContentConfig.model_rebuild() + InputResponseOrganizationRoles.model_rebuild() except NameError: pass try: - InputResponseInputWiz.model_rebuild() + InputResponseInputAnthropicCompliance.model_rebuild() except NameError: pass try: - InputResponseInputJournalFilesRule.model_rebuild() + InputResponseInputOpenaiComplianceLogs.model_rebuild() except NameError: pass try: - InputResponseInputJournalFiles.model_rebuild() + InputResponseInputAquaSecurityHec.model_rebuild() except NameError: pass try: - InputResponseInputRawUDP.model_rebuild() + InputResponseInputExtrahopRevealx360.model_rebuild() except NameError: pass try: - InputResponseInputAppleUnifiedLogs.model_rebuild() + InputResponseInputSailpointHec.model_rebuild() except NameError: pass try: - InputResponseInputWinEventLogs.model_rebuild() + InputResponseInputTrellixHec.model_rebuild() except NameError: pass try: - InputResponseMTLSSettings.model_rebuild() + InputResponseInputUpwindHec.model_rebuild() except NameError: pass try: - InputResponseQuery.model_rebuild() + InputResponseInputSysdigHec.model_rebuild() except NameError: pass try: - InputResponseSubscription.model_rebuild() + InputResponseTLSSettingsServerSide.model_rebuild() except NameError: pass try: - InputResponseInputWef.model_rebuild() + InputResponseInputCloudflareHec.model_rebuild() except NameError: pass try: - InputResponseInputAppscopeFilter.model_rebuild() + InputResponseInputZscalerHecAuthToken.model_rebuild() except NameError: pass try: - InputResponseInputAppscopePersistence.model_rebuild() + InputResponseInputZscalerHec.model_rebuild() except NameError: pass try: - InputResponseInputAppscope.model_rebuild() + InputResponseInputProofpointPod.model_rebuild() except NameError: pass try: - InputResponseInputTCP.model_rebuild() + InputResponseInputServicenowTable.model_rebuild() except NameError: pass try: - InputResponseInputFile.model_rebuild() + InputResponseInputBedrockS3.model_rebuild() except NameError: pass try: - InputResponseInputSyslogSyslog2.model_rebuild() + InputResponseInputSecurityLake.model_rebuild() except NameError: pass try: - InputResponseInputSyslogSyslog1.model_rebuild() + InputResponseInputNetflow.model_rebuild() except NameError: pass try: - InputResponseInputSqs.model_rebuild() + InputResponseInputWizWebhookAuthTokensExt2.model_rebuild() except NameError: pass try: - InputResponseInputModelDrivenTelemetry.model_rebuild() + InputResponseInputWizWebhookAuthTokensExt1.model_rebuild() except NameError: pass try: - InputResponseAuthMethodsExt.model_rebuild() + InputResponseInputWizWebhook.model_rebuild() except NameError: pass try: - InputResponseInputOpenTelemetry.model_rebuild() + InputResponseInputOpenaiContentConfig.model_rebuild() except NameError: pass try: - InputResponseV3User.model_rebuild() + InputResponseInputOpenai.model_rebuild() except NameError: pass try: - InputResponseSNMPv3Authentication.model_rebuild() + InputResponseInputWizContentConfig.model_rebuild() except NameError: pass try: - InputResponseInputSnmp.model_rebuild() + InputResponseInputWiz.model_rebuild() except NameError: pass try: - InputResponseInputS3Inventory.model_rebuild() + InputResponseInputJournalFilesRule.model_rebuild() except NameError: pass try: - InputResponseInputS3.model_rebuild() + InputResponseInputJournalFiles.model_rebuild() except NameError: pass try: - InputResponseInputMetrics.model_rebuild() + InputResponseInputRawUDP.model_rebuild() except NameError: pass try: - InputResponseInputCriblmetrics.model_rebuild() + InputResponseInputAppleUnifiedLogs.model_rebuild() except NameError: pass try: - InputResponseInputKinesis.model_rebuild() + InputResponseInputWinEventLogs.model_rebuild() except NameError: pass try: - InputResponseInputHTTPRaw.model_rebuild() + InputResponseMTLSSettings.model_rebuild() except NameError: pass try: - InputResponseSample.model_rebuild() + InputResponseQuery.model_rebuild() except NameError: pass try: - InputResponseInputDatagen.model_rebuild() + InputResponseSubscription.model_rebuild() except NameError: pass try: - InputResponseInputDatadogAgentProxyMode.model_rebuild() + InputResponseInputWef.model_rebuild() except NameError: pass try: - InputResponseInputDatadogAgent.model_rebuild() + InputResponseInputAppscopeFilter.model_rebuild() except NameError: pass try: - InputResponseInputCrowdstrike.model_rebuild() + InputResponseInputAppscopePersistence.model_rebuild() except NameError: pass try: - InputResponseInputWindowsMetricsCPU.model_rebuild() + InputResponseInputAppscope.model_rebuild() except NameError: pass try: - InputResponseInputWindowsMetricsNetwork.model_rebuild() + InputResponseInputTCP.model_rebuild() except NameError: pass try: - InputResponseInputWindowsMetricsDisk.model_rebuild() + InputResponseInputFile.model_rebuild() except NameError: pass try: - InputResponseInputWindowsMetricsPersistence.model_rebuild() + InputResponseInputSyslogSyslog2.model_rebuild() except NameError: pass try: - InputResponseInputWindowsMetrics.model_rebuild() + InputResponseInputSyslogSyslog1.model_rebuild() except NameError: pass try: - InputResponseInputKubeEvents.model_rebuild() + InputResponseInputSqs.model_rebuild() except NameError: pass try: - InputResponseInputKubeLogsRule.model_rebuild() + InputResponseInputModelDrivenTelemetry.model_rebuild() except NameError: pass try: - InputResponseInputKubeLogs.model_rebuild() + InputResponseAuthMethodsExt.model_rebuild() except NameError: pass try: - InputResponseInputKubeMetricsPersistence.model_rebuild() + InputResponseInputOpenTelemetry.model_rebuild() except NameError: pass try: - InputResponseInputKubeMetrics.model_rebuild() + InputResponseV3User.model_rebuild() except NameError: pass diff --git a/src/cribl_control_plane/models/inputs3_input.py b/src/cribl_control_plane/models/inputs3_input.py index 3f207106f..afae7d843 100644 --- a/src/cribl_control_plane/models/inputs3_input.py +++ b/src/cribl_control_plane/models/inputs3_input.py @@ -108,6 +108,8 @@ class InputS3InputTypedDict(TypedDict): r"""Character encoding to use when parsing ingested data. When not set, @{product} will default to UTF-8 but may incorrectly interpret multi-byte characters.""" tag_after_processing: NotRequired[bool] r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] @@ -328,6 +330,9 @@ class InputS3Input(BaseModel): ] = None r"""Add a tag to processed S3 objects. Requires s3:GetObjectTagging and s3:PutObjectTagging AWS permissions.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -505,6 +510,7 @@ def serialize_model(self, handler): "pollTimeout", "encoding", "tagAfterProcessing", + "autoParse", "description", "awsApiKey", "awsSecret", diff --git a/src/cribl_control_plane/models/inputsailpointhec_input.py b/src/cribl_control_plane/models/inputsailpointhec_input.py new file mode 100644 index 000000000..9d350873c --- /dev/null +++ b/src/cribl_control_plane/models/inputsailpointhec_input.py @@ -0,0 +1,283 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputSailpointHecType(str, Enum): + r"""Source type identifier.""" + + SAILPOINT_HEC = "sailpoint_hec" + + +class InputSailpointHecInputTypedDict(TypedDict): + type: InputSailpointHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + +class InputSailpointHecInput(BaseModel): + type: InputSailpointHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for SailPoint Virtual Appliance HTTP Event Collector requests. This source uses the /services/collector endpoint.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputSailpointHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputsnmp_input.py b/src/cribl_control_plane/models/inputsnmp_input.py index 02be6bb50..918b20322 100644 --- a/src/cribl_control_plane/models/inputsnmp_input.py +++ b/src/cribl_control_plane/models/inputsnmp_input.py @@ -39,6 +39,15 @@ class InputSnmpAuthenticationProtocol(str, Enum, metaclass=utils.OpenEnumMeta): SHA512 = "sha512" +class V3AuthenticationKeyType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" + + class PrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): r"""Privacy protocol""" @@ -54,17 +63,34 @@ class PrivacyProtocol(str, Enum, metaclass=utils.OpenEnumMeta): AES256R = "aes256r" +class V3PrivacyKeyType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" + + class InputSnmpV3UserTypedDict(TypedDict): name: str r"""V3 name""" auth_protocol: NotRequired[InputSnmpAuthenticationProtocol] r"""Authentication protocol""" + auth_key_type: NotRequired[V3AuthenticationKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" auth_key: NotRequired[str] r"""V3 authentication key""" + auth_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" priv_protocol: NotRequired[PrivacyProtocol] r"""Privacy protocol""" + priv_key_type: NotRequired[V3PrivacyKeyType] + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" priv_key: NotRequired[str] r"""V3 privacy key""" + priv_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" class InputSnmpV3User(BaseModel): @@ -76,17 +102,37 @@ class InputSnmpV3User(BaseModel): ] = None r"""Authentication protocol""" + auth_key_type: Annotated[ + Optional[V3AuthenticationKeyType], pydantic.Field(alias="authKeyType") + ] = None + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + auth_key: Annotated[Optional[str], pydantic.Field(alias="authKey")] = None r"""V3 authentication key""" + auth_key_secret: Annotated[Optional[str], pydantic.Field(alias="authKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" + priv_protocol: Annotated[ Optional[PrivacyProtocol], pydantic.Field(alias="privProtocol") ] = None r"""Privacy protocol""" + priv_key_type: Annotated[ + Optional[V3PrivacyKeyType], pydantic.Field(alias="privKeyType") + ] = None + r"""Select Manual to enter the key directly, or Secret to use a stored text secret""" + priv_key: Annotated[Optional[str], pydantic.Field(alias="privKey")] = None r"""V3 privacy key""" + priv_key_secret: Annotated[Optional[str], pydantic.Field(alias="privKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" + @field_serializer("auth_protocol") def serialize_auth_protocol(self, value): if isinstance(value, str): @@ -96,6 +142,15 @@ def serialize_auth_protocol(self, value): return value return value + @field_serializer("auth_key_type") + def serialize_auth_key_type(self, value): + if isinstance(value, str): + try: + return models.V3AuthenticationKeyType(value) + except ValueError: + return value + return value + @field_serializer("priv_protocol") def serialize_priv_protocol(self, value): if isinstance(value, str): @@ -105,9 +160,29 @@ def serialize_priv_protocol(self, value): return value return value + @field_serializer("priv_key_type") + def serialize_priv_key_type(self, value): + if isinstance(value, str): + try: + return models.V3PrivacyKeyType(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["authProtocol", "authKey", "privProtocol", "privKey"]) + optional_fields = set( + [ + "authProtocol", + "authKeyType", + "authKey", + "authKeySecret", + "privProtocol", + "privKeyType", + "privKey", + "privKeySecret", + ] + ) serialized = handler(self) m = {} diff --git a/src/cribl_control_plane/models/inputsplunk_input.py b/src/cribl_control_plane/models/inputsplunk_input.py index 65742a08a..319f1305d 100644 --- a/src/cribl_control_plane/models/inputsplunk_input.py +++ b/src/cribl_control_plane/models/inputsplunk_input.py @@ -1,6 +1,9 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, +) from .connectionconfinputcollection import ( ConnectionConfInputCollection, ConnectionConfInputCollectionTypedDict, @@ -25,22 +28,44 @@ class InputSplunkAuthTokenTypedDict(TypedDict): - token: str + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + token: NotRequired[str] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Description""" class InputSplunkAuthToken(BaseModel): - token: str + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + token: Optional[str] = None r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" description: Optional[str] = None r"""Description""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description"]) + optional_fields = set(["authType", "tokenSecret", "token", "description"]) serialized = handler(self) m = {} @@ -119,6 +144,8 @@ class InputSplunkInputTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" auth_tokens: NotRequired[List[InputSplunkAuthTokenTypedDict]] r"""Shared secrets to be provided by any Splunk forwarder. If empty, unauthorized access is permitted.""" max_s2_sversion: NotRequired[MaxS2SVersion] @@ -231,6 +258,9 @@ class InputSplunkInput(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + auth_tokens: Annotated[ Optional[List[InputSplunkAuthToken]], pydantic.Field(alias="authTokens") ] = None @@ -333,6 +363,7 @@ def serialize_model(self, handler): "metadata", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "authTokens", "maxS2Sversion", "description", @@ -362,6 +393,10 @@ def serialize_model(self, handler): return m +try: + InputSplunkAuthToken.model_rebuild() +except NameError: + pass try: InputSplunkInput.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/inputsplunkhec_input.py b/src/cribl_control_plane/models/inputsplunkhec_input.py index 88be41a90..2c33593f2 100644 --- a/src/cribl_control_plane/models/inputsplunkhec_input.py +++ b/src/cribl_control_plane/models/inputsplunkhec_input.py @@ -1,16 +1,16 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, ConnectionConfInputCollectionTypedDict, ) -from .inputcollectionorigindatasourcediscoverywithdestinationarnconstraint import ( - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint, - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict, +from .inputprovenancetypeoptional import ( + InputProvenanceTypeOptional, + InputProvenanceTypeOptionalTypedDict, ) from .metadataconfinputcollection import ( MetadataConfInputCollection, @@ -41,7 +41,7 @@ class InputSplunkHecType(str, Enum): class InputSplunkHecAuthTokenTypedDict(TypedDict): token: str r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" token_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -60,7 +60,7 @@ class InputSplunkHecAuthToken(BaseModel): r"""Shared secret to be provided by any client (Authorization: )""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -86,7 +86,7 @@ class InputSplunkHecAuthToken(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -177,6 +177,8 @@ class InputSplunkHecInputTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" use_fwd_timezone: NotRequired[bool] r"""Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event""" drop_control_fields: NotRequired[bool] @@ -325,6 +327,9 @@ class InputSplunkHecInput(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + use_fwd_timezone: Annotated[ Optional[bool], pydantic.Field(alias="useFwdTimezone") ] = None @@ -413,6 +418,7 @@ def serialize_model(self, handler): "splunkHecAcks", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "useFwdTimezone", "dropControlFields", "extractMetrics", @@ -464,9 +470,7 @@ class InputSplunkHecTypedDict(TypedDict): r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - cribl_source_provenance: NotRequired[ - InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraintTypedDict - ] + cribl_source_provenance: NotRequired[InputProvenanceTypeOptionalTypedDict] r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" @@ -506,6 +510,8 @@ class InputSplunkHecTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" use_fwd_timezone: NotRequired[bool] r"""Event Breakers will determine events' time zone from UF-provided metadata, when TZ can't be inferred from the raw event""" drop_control_fields: NotRequired[bool] @@ -569,7 +575,7 @@ class InputSplunkHec(BaseModel): r"""Metadata tags used for categorization and filtering.""" cribl_source_provenance: Annotated[ - Optional[InputCollectionOriginDataSourceDiscoveryWithDestinationArnConstraint], + Optional[InputProvenanceTypeOptional], pydantic.Field(alias="criblSourceProvenance"), ] = None r"""Read-only metadata that records how the Source was created. Preserved on update when omitted from the request body. Cannot be set on create.""" @@ -665,6 +671,9 @@ class InputSplunkHec(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + use_fwd_timezone: Annotated[ Optional[bool], pydantic.Field(alias="useFwdTimezone") ] = None @@ -755,6 +764,7 @@ def serialize_model(self, handler): "splunkHecAcks", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "useFwdTimezone", "dropControlFields", "extractMetrics", diff --git a/src/cribl_control_plane/models/inputsqs_input.py b/src/cribl_control_plane/models/inputsqs_input.py index a45c18eb0..03c7be4e6 100644 --- a/src/cribl_control_plane/models/inputsqs_input.py +++ b/src/cribl_control_plane/models/inputsqs_input.py @@ -88,6 +88,8 @@ class InputSqsInputTypedDict(TypedDict): r"""Fields to add to events from this input""" poll_timeout: NotRequired[float] r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] @@ -227,6 +229,9 @@ class InputSqsInput(BaseModel): poll_timeout: Annotated[Optional[float], pydantic.Field(alias="pollTimeout")] = None r"""How long to wait for events before trying polling again. The lower the number the higher the AWS bill. The higher the number the longer it will take for the source to react to configuration changes and system restarts.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -343,6 +348,7 @@ def serialize_model(self, handler): "visibilityTimeout", "metadata", "pollTimeout", + "autoParse", "description", "awsApiKey", "awsSecret", diff --git a/src/cribl_control_plane/models/inputsyslog_input_union.py b/src/cribl_control_plane/models/inputsyslog_input_union.py index 8dcb14787..a96546159 100644 --- a/src/cribl_control_plane/models/inputsyslog_input_union.py +++ b/src/cribl_control_plane/models/inputsyslog_input_union.py @@ -84,6 +84,8 @@ class InputSyslogSyslogInput2TypedDict(TypedDict): r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" enable_load_balancing: NotRequired[bool] r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" enable_enhanced_proxy_header_parsing: NotRequired[bool] @@ -229,6 +231,9 @@ class InputSyslogSyslogInput2(BaseModel): ] = None r"""Load balance traffic across all Worker Processes""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -299,6 +304,7 @@ def serialize_model(self, handler): "metadata", "udpSocketRxBufSize", "enableLoadBalancing", + "autoParse", "description", "enableEnhancedProxyHeaderParsing", "__template_environment", @@ -385,6 +391,8 @@ class InputSyslogSyslogInput1TypedDict(TypedDict): r"""Optionally, set the SO_RCVBUF socket option for the UDP socket. This value tells the operating system how many bytes can be buffered in the kernel before events are dropped. Leave blank to use the OS default. Caution: Increasing this value will affect OS memory utilization.""" enable_load_balancing: NotRequired[bool] r"""Load balance traffic across all Worker Processes""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" description: NotRequired[str] r"""Optional description for this configuration.""" enable_enhanced_proxy_header_parsing: NotRequired[bool] @@ -530,6 +538,9 @@ class InputSyslogSyslogInput1(BaseModel): ] = None r"""Load balance traffic across all Worker Processes""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -600,6 +611,7 @@ def serialize_model(self, handler): "metadata", "udpSocketRxBufSize", "enableLoadBalancing", + "autoParse", "description", "enableEnhancedProxyHeaderParsing", "__template_environment", diff --git a/src/cribl_control_plane/models/inputtcp_input.py b/src/cribl_control_plane/models/inputtcp_input.py index 7f82a971d..6286a01d5 100644 --- a/src/cribl_control_plane/models/inputtcp_input.py +++ b/src/cribl_control_plane/models/inputtcp_input.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -77,6 +77,8 @@ class InputTCPInputTypedDict(TypedDict): r"""A list of event-breaking rulesets that will be applied, in order, to the input data stream""" stale_channel_flush_ms: NotRequired[float] r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: NotRequired[bool] + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" enable_header: NotRequired[bool] r"""Client will pass the header record with every new connection. The header can contain an authToken, and an object with a list of fields and values to add to every event. These fields can be used to simplify Event Breaker selection, routing, etc. Header has this format, and must be followed by a newline: { \"authToken\" : \"myToken\", \"fields\": { \"field1\": \"value1\", \"field2\": \"value2\" } }""" preprocess: NotRequired[PreprocessTypeTypedDict] @@ -85,7 +87,7 @@ class InputTCPInputTypedDict(TypedDict): r"""Optional description for this configuration.""" auth_token: NotRequired[str] r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -183,6 +185,9 @@ class InputTCPInput(BaseModel): ] = None r"""How long (in milliseconds) the Event Breaker will wait for new data to be sent to a specific channel before flushing the data stream out, as is, to the Pipelines""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""Detect the datatype of each event and extract its top-level fields before the data reaches any of the processing pipelines (pre-processing, main processing, post-processing).""" + enable_header: Annotated[Optional[bool], pydantic.Field(alias="enableHeader")] = ( None ) @@ -198,7 +203,7 @@ class InputTCPInput(BaseModel): r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -230,7 +235,7 @@ class InputTCPInput(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -258,6 +263,7 @@ def serialize_model(self, handler): "metadata", "breakerRulesets", "staleChannelFlushMs", + "autoParse", "enableHeader", "preprocess", "description", diff --git a/src/cribl_control_plane/models/inputtcpjson_input.py b/src/cribl_control_plane/models/inputtcpjson_input.py index 6a1eb42f2..682748ac3 100644 --- a/src/cribl_control_plane/models/inputtcpjson_input.py +++ b/src/cribl_control_plane/models/inputtcpjson_input.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -68,7 +68,7 @@ class InputTcpjsonInputTypedDict(TypedDict): r"""Fields to add to events from this input""" enable_load_balancing: NotRequired[bool] r"""Load balance traffic across all Worker Processes""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -166,7 +166,7 @@ class InputTcpjsonInput(BaseModel): r"""Load balance traffic across all Worker Processes""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -204,7 +204,7 @@ class InputTcpjsonInput(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/inputtrellixhec_input.py b/src/cribl_control_plane/models/inputtrellixhec_input.py new file mode 100644 index 000000000..44adeb952 --- /dev/null +++ b/src/cribl_control_plane/models/inputtrellixhec_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputTrellixHecType(str, Enum): + r"""Source type identifier.""" + + TRELLIX_HEC = "trellix_hec" + + +class InputTrellixHecInputTypedDict(TypedDict): + type: InputTrellixHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputTrellixHecInput(BaseModel): + type: InputTrellixHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trellix HTTP Event Collector API requests. This input supports the /event endpoint.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputTrellixHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputtrendmicrovisionone_input.py b/src/cribl_control_plane/models/inputtrendmicrovisionone_input.py new file mode 100644 index 000000000..a5018e378 --- /dev/null +++ b/src/cribl_control_plane/models/inputtrendmicrovisionone_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputTrendMicroVisionOneType(str, Enum): + r"""Source type identifier.""" + + TREND_MICRO_VISION_ONE = "trend_micro_vision_one" + + +class InputTrendMicroVisionOneInputTypedDict(TypedDict): + type: InputTrendMicroVisionOneType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputTrendMicroVisionOneInput(BaseModel): + type: InputTrendMicroVisionOneType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for the Trend Micro Vision One HTTP Event Collector API requests. This input supports the /event endpoint.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputTrendMicroVisionOneInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputvectraaihec_input.py b/src/cribl_control_plane/models/inputvectraaihec_input.py new file mode 100644 index 000000000..baa203bfd --- /dev/null +++ b/src/cribl_control_plane/models/inputvectraaihec_input.py @@ -0,0 +1,339 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .authtokenconfinputcloudflarehec import ( + AuthTokenConfInputCloudflareHec, + AuthTokenConfInputCloudflareHecTypedDict, +) +from .connectionconfinputcollection import ( + ConnectionConfInputCollection, + ConnectionConfInputCollectionTypedDict, +) +from .metadataconfinputcollection import ( + MetadataConfInputCollection, + MetadataConfInputCollectionTypedDict, +) +from .pqtype import PqType, PqTypeTypedDict +from .tlssettingsserversidetype import ( + TLSSettingsServerSideType, + TLSSettingsServerSideTypeTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class InputVectraAiHecType(str, Enum): + r"""Source type identifier.""" + + VECTRA_AI_HEC = "vectra_ai_hec" + + +class InputVectraAiHecInputTypedDict(TypedDict): + type: InputVectraAiHecType + r"""Source type identifier.""" + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + port: float + r"""Port to listen on""" + hec_api: str + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + id: NotRequired[str] + r"""Unique ID for this input""" + disabled: NotRequired[bool] + r"""If true, the Source is disabled and will not collect data.""" + pipeline: NotRequired[str] + r"""Pipeline to process data from this Source before sending it through the Routes""" + send_to_routes: NotRequired[bool] + r"""Select whether to send data to Routes, or directly to Destinations.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + pq_enabled: NotRequired[bool] + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + connections: NotRequired[List[ConnectionConfInputCollectionTypedDict]] + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + pq: NotRequired[PqTypeTypedDict] + auth_tokens: NotRequired[List[AuthTokenConfInputCloudflareHecTypedDict]] + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + tls: NotRequired[TLSSettingsServerSideTypeTypedDict] + r"""TLS settings (server side)""" + max_active_req: NotRequired[float] + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + max_requests_per_socket: NotRequired[int] + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + enable_proxy_header: NotRequired[bool] + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + capture_headers: NotRequired[bool] + r"""Add request headers to events, in the __headers field""" + activity_log_sample_rate: NotRequired[float] + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + request_timeout: NotRequired[float] + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + socket_timeout: NotRequired[float] + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + keep_alive_timeout: NotRequired[float] + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + ip_allowlist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + ip_denylist_regex: NotRequired[str] + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + allowed_indexes: NotRequired[List[str]] + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + access_control_allow_origin: NotRequired[List[str]] + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + access_control_allow_headers: NotRequired[List[str]] + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + emit_token_metrics: NotRequired[bool] + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + template_environment: NotRequired[str] + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_hec_api: NotRequired[str] + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + template_allowed_indexes: NotRequired[str] + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + template_access_control_allow_origin: NotRequired[str] + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + template_access_control_allow_headers: NotRequired[str] + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + +class InputVectraAiHecInput(BaseModel): + type: InputVectraAiHecType + r"""Source type identifier.""" + + host: str + r"""Address to bind on. Defaults to 0.0.0.0 (all addresses).""" + + port: float + r"""Port to listen on""" + + hec_api: Annotated[str, pydantic.Field(alias="hecAPI")] + r"""Absolute path on which to listen for Vectra AI HTTP Event Collector API requests. This input supports the /event and /raw endpoints.""" + + id: Optional[str] = None + r"""Unique ID for this input""" + + disabled: Optional[bool] = None + r"""If true, the Source is disabled and will not collect data.""" + + pipeline: Optional[str] = None + r"""Pipeline to process data from this Source before sending it through the Routes""" + + send_to_routes: Annotated[Optional[bool], pydantic.Field(alias="sendToRoutes")] = ( + None + ) + r"""Select whether to send data to Routes, or directly to Destinations.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + pq_enabled: Annotated[Optional[bool], pydantic.Field(alias="pqEnabled")] = None + r"""Use a disk queue to minimize data loss when connected services block. See [Cribl Docs](https://docs.cribl.io/stream/persistent-queues) for PQ defaults (Cribl-managed Cloud Workers) and configuration options (on-prem and hybrid Workers).""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + connections: Optional[List[ConnectionConfInputCollection]] = None + r"""Direct connections to Destinations, and optionally via a Pipeline or a Pack""" + + pq: Optional[PqType] = None + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCloudflareHec]], + pydantic.Field(alias="authTokens"), + ] = None + r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" + + tls: Optional[TLSSettingsServerSideType] = None + r"""TLS settings (server side)""" + + max_active_req: Annotated[Optional[float], pydantic.Field(alias="maxActiveReq")] = ( + None + ) + r"""Maximum number of active requests allowed per Worker Process. Set to 0 for unlimited. Caution: Increasing the limit above the default value, or setting it to unlimited, may degrade performance and reduce throughput.""" + + max_requests_per_socket: Annotated[ + Optional[int], pydantic.Field(alias="maxRequestsPerSocket") + ] = None + r"""Maximum number of requests per socket before @{product} instructs the client to close the connection. Default is 0 (unlimited).""" + + enable_proxy_header: Annotated[ + Optional[bool], pydantic.Field(alias="enableProxyHeader") + ] = None + r"""Extract the client IP and port from PROXY protocol v1/v2. When enabled, the X-Forwarded-For header is ignored. Disable to use the X-Forwarded-For header for client IP extraction.""" + + capture_headers: Annotated[ + Optional[bool], pydantic.Field(alias="captureHeaders") + ] = None + r"""Add request headers to events, in the __headers field""" + + activity_log_sample_rate: Annotated[ + Optional[float], pydantic.Field(alias="activityLogSampleRate") + ] = None + r"""How often request activity is logged at the `info` level. A value of 1 would log every request, 10 every 10th request, etc.""" + + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") + ] = None + r"""How long to wait for an incoming request to complete before aborting it. Use 0 to disable.""" + + socket_timeout: Annotated[ + Optional[float], pydantic.Field(alias="socketTimeout") + ] = None + r"""How long @{product} should wait before assuming that an inactive socket has timed out. To wait forever, set to 0.""" + + keep_alive_timeout: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTimeout") + ] = None + r"""After the last response is sent, @{product} will wait this long for additional data before closing the socket connection. Minimum 1 second, maximum 600 seconds (10 minutes).""" + + ip_allowlist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipAllowlistRegex") + ] = None + r"""Messages from matched IP addresses will be processed, unless also matched by the denylist""" + + ip_denylist_regex: Annotated[ + Optional[str], pydantic.Field(alias="ipDenylistRegex") + ] = None + r"""Messages from matched IP addresses will be ignored. This takes precedence over the allowlist.""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to every event. May be overridden by fields added at the token or request level.""" + + allowed_indexes: Annotated[ + Optional[List[str]], pydantic.Field(alias="allowedIndexes") + ] = None + r"""List values allowed in HEC event index field. Leave blank to skip validation. Supports wildcards. The values here can expand index validation at the token level.""" + + access_control_allow_origin: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowOrigin") + ] = None + r"""HTTP origins to which @{product} should send CORS (cross-origin resource sharing) Access-Control-Allow-* headers. Supports wildcards.""" + + access_control_allow_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="accessControlAllowHeaders") + ] = None + r"""HTTP headers that @{product} will send to allowed origins as \"Access-Control-Allow-Headers\" in a CORS preflight response. Use \"*\" to allow all headers.""" + + emit_token_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="emitTokenMetrics") + ] = None + r"""Emit per-token (.http.perToken) and summary (.http.summary) request metrics""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_environment") + ] = None + r"""Binds 'environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'environment' at runtime.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + template_hec_api: Annotated[ + Optional[str], pydantic.Field(alias="__template_hecAPI") + ] = None + r"""Binds 'hecAPI' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'hecAPI' at runtime.""" + + template_allowed_indexes: Annotated[ + Optional[str], pydantic.Field(alias="__template_allowedIndexes") + ] = None + r"""Binds 'allowedIndexes' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'allowedIndexes' at runtime.""" + + template_access_control_allow_origin: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowOrigin") + ] = None + r"""Binds 'accessControlAllowOrigin' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowOrigin' at runtime.""" + + template_access_control_allow_headers: Annotated[ + Optional[str], pydantic.Field(alias="__template_accessControlAllowHeaders") + ] = None + r"""Binds 'accessControlAllowHeaders' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accessControlAllowHeaders' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "disabled", + "pipeline", + "sendToRoutes", + "environment", + "pqEnabled", + "streamtags", + "connections", + "pq", + "authTokens", + "tls", + "maxActiveReq", + "maxRequestsPerSocket", + "enableProxyHeader", + "captureHeaders", + "activityLogSampleRate", + "requestTimeout", + "socketTimeout", + "keepAliveTimeout", + "ipAllowlistRegex", + "ipDenylistRegex", + "metadata", + "allowedIndexes", + "accessControlAllowOrigin", + "accessControlAllowHeaders", + "emitTokenMetrics", + "description", + "__template_environment", + "__template_streamtags", + "__template_host", + "__template_port", + "__template_hecAPI", + "__template_allowedIndexes", + "__template_accessControlAllowOrigin", + "__template_accessControlAllowHeaders", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + InputVectraAiHecInput.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/inputwef_input.py b/src/cribl_control_plane/models/inputwef_input.py index 82fa4c91e..ec1f2cdff 100644 --- a/src/cribl_control_plane/models/inputwef_input.py +++ b/src/cribl_control_plane/models/inputwef_input.py @@ -34,6 +34,8 @@ class InputWefAuthenticationMethod(str, Enum, metaclass=utils.OpenEnumMeta): CLIENT_CERT = "clientCert" # Kerberos KERBEROS = "kerberos" + # Negotiate (SPNEGO) + NEGOTIATE = "negotiate" class MTLSSettingsTypedDict(TypedDict): diff --git a/src/cribl_control_plane/models/inputwineventlogs_input.py b/src/cribl_control_plane/models/inputwineventlogs_input.py index 83ebb1028..5c588fcdf 100644 --- a/src/cribl_control_plane/models/inputwineventlogs_input.py +++ b/src/cribl_control_plane/models/inputwineventlogs_input.py @@ -34,7 +34,7 @@ class InputWinEventLogsReadMode(str, Enum, metaclass=utils.OpenEnumMeta): NEWEST = "newest" -class EventFormat(str, Enum, metaclass=utils.OpenEnumMeta): +class InputWinEventLogsEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): r"""Format of individual events""" # JSON @@ -69,7 +69,7 @@ class InputWinEventLogsInputTypedDict(TypedDict): r"""When enabled, missing event log channels will not cause the Source to report errors. Use in Fleets where some hosts may not have all configured event logs.""" read_mode: NotRequired[InputWinEventLogsReadMode] r"""Read all stored and future event logs, or only future events""" - event_format: NotRequired[EventFormat] + event_format: NotRequired[InputWinEventLogsEventFormat] r"""Format of individual events""" disable_native_module: NotRequired[bool] r"""Enable to use built-in tools (PowerShell for JSON, wevtutil for XML) to collect event logs instead of native API (default) [Learn more](https://docs.cribl.io/edge/sources-windows-event-logs/#advanced-settings)""" @@ -85,6 +85,8 @@ class InputWinEventLogsInputTypedDict(TypedDict): r"""Optional description for this configuration.""" disable_json_rendering: NotRequired[bool] r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + include_empty_json_fields: NotRequired[bool] + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" disable_xml_rendering: NotRequired[bool] r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" template_environment: NotRequired[str] @@ -139,7 +141,7 @@ class InputWinEventLogsInput(BaseModel): r"""Read all stored and future event logs, or only future events""" event_format: Annotated[ - Optional[EventFormat], pydantic.Field(alias="eventFormat") + Optional[InputWinEventLogsEventFormat], pydantic.Field(alias="eventFormat") ] = None r"""Format of individual events""" @@ -170,6 +172,11 @@ class InputWinEventLogsInput(BaseModel): ] = None r"""Enable/disable the rendering of localized event message strings (Applicable for 4.8.0 nodes and newer that use the Native API)""" + include_empty_json_fields: Annotated[ + Optional[bool], pydantic.Field(alias="includeEmptyJsonFields") + ] = None + r"""Preserve fields with empty values (such as '-') in the JSON output instead of omitting them""" + disable_xml_rendering: Annotated[ Optional[bool], pydantic.Field(alias="disableXmlRendering") ] = None @@ -198,7 +205,7 @@ def serialize_read_mode(self, value): def serialize_event_format(self, value): if isinstance(value, str): try: - return models.EventFormat(value) + return models.InputWinEventLogsEventFormat(value) except ValueError: return value return value @@ -226,6 +233,7 @@ def serialize_model(self, handler): "maxEventBytes", "description", "disableJsonRendering", + "includeEmptyJsonFields", "disableXmlRendering", "__template_environment", "__template_streamtags", diff --git a/src/cribl_control_plane/models/inputwizwebhook_input.py b/src/cribl_control_plane/models/inputwizwebhook_input.py index 4fea5b8c4..36f4c8d5a 100644 --- a/src/cribl_control_plane/models/inputwizwebhook_input.py +++ b/src/cribl_control_plane/models/inputwizwebhook_input.py @@ -1,9 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authtokensextconfinputhttp import ( - AuthTokensExtConfInputHTTP, - AuthTokensExtConfInputHTTPTypedDict, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -18,12 +17,13 @@ TLSSettingsServerSideType, TLSSettingsServerSideTypeTypedDict, ) +from cribl_control_plane import models from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum import pydantic -from pydantic import model_serializer -from typing import List, Optional -from typing_extensions import Annotated, NotRequired, TypedDict +from pydantic import field_serializer, model_serializer +from typing import List, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict class InputWizWebhookType(str, Enum): @@ -32,6 +32,135 @@ class InputWizWebhookType(str, Enum): WIZ_WEBHOOK = "wiz_webhook" +class InputWizWebhookAuthTokensExt2TypedDict(TypedDict): + auth_type: AuthenticationMethodOptionsAuthTokensExtItems + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: str + r"""Select or create a stored text secret""" + token: NotRequired[str] + r"""Shared secret to be provided by any client (Authorization: )""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputWizWebhookAuthTokensExt2(BaseModel): + auth_type: Annotated[ + AuthenticationMethodOptionsAuthTokensExtItems, pydantic.Field(alias="authType") + ] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" + + token: Optional[str] = None + r"""Shared secret to be provided by any client (Authorization: )""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["token", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class InputWizWebhookAuthTokensExt1TypedDict(TypedDict): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + token_secret: NotRequired[str] + r"""Select or create a stored text secret""" + description: NotRequired[str] + r"""Description""" + metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] + r"""Fields to add to events referencing this token""" + + +class InputWizWebhookAuthTokensExt1(BaseModel): + token: str + r"""Shared secret to be provided by any client (Authorization: )""" + + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + token_secret: Annotated[Optional[str], pydantic.Field(alias="tokenSecret")] = None + r"""Select or create a stored text secret""" + + description: Optional[str] = None + r"""Description""" + + metadata: Optional[List[MetadataConfInputCollection]] = None + r"""Fields to add to events referencing this token""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "tokenSecret", "description", "metadata"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +InputWizWebhookAuthTokensExtUnionTypedDict = TypeAliasType( + "InputWizWebhookAuthTokensExtUnionTypedDict", + Union[ + InputWizWebhookAuthTokensExt1TypedDict, InputWizWebhookAuthTokensExt2TypedDict + ], +) + + +InputWizWebhookAuthTokensExtUnion = TypeAliasType( + "InputWizWebhookAuthTokensExtUnion", + Union[InputWizWebhookAuthTokensExt1, InputWizWebhookAuthTokensExt2], +) + + class InputWizWebhookInputTypedDict(TypedDict): type: InputWizWebhookType r"""Source type identifier.""" @@ -92,7 +221,7 @@ class InputWizWebhookInputTypedDict(TypedDict): r"""List of URI paths accepted by this input. Wildcards are supported (such as /api/v*/hook). Defaults to allow all.""" allowed_methods: NotRequired[List[str]] r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" - auth_tokens_ext: NotRequired[List[AuthTokensExtConfInputHTTPTypedDict]] + auth_tokens_ext: NotRequired[List[InputWizWebhookAuthTokensExtUnionTypedDict]] r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -235,7 +364,7 @@ class InputWizWebhookInput(BaseModel): r"""List of HTTP methods accepted by this input. Wildcards are supported (such as P*, GET). Defaults to allow all.""" auth_tokens_ext: Annotated[ - Optional[List[AuthTokensExtConfInputHTTP]], + Optional[List[InputWizWebhookAuthTokensExtUnion]], pydantic.Field(alias="authTokensExt"), ] = None r"""Shared secrets to be provided by any client (Authorization: ). If empty, unauthorized access is permitted.""" @@ -328,6 +457,14 @@ def serialize_model(self, handler): return m +try: + InputWizWebhookAuthTokensExt2.model_rebuild() +except NameError: + pass +try: + InputWizWebhookAuthTokensExt1.model_rebuild() +except NameError: + pass try: InputWizWebhookInput.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/inputzscalerhec_input.py b/src/cribl_control_plane/models/inputzscalerhec_input.py index 7d76e8938..27594efa3 100644 --- a/src/cribl_control_plane/models/inputzscalerhec_input.py +++ b/src/cribl_control_plane/models/inputzscalerhec_input.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .connectionconfinputcollection import ( ConnectionConfInputCollection, @@ -35,7 +35,7 @@ class InputZscalerHecType(str, Enum): class InputZscalerHecAuthTokenTypedDict(TypedDict): token: str r"""Shared secret to be provided by any client (Authorization: )""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" token_secret: NotRequired[str] r"""Select or create a stored text secret""" @@ -54,7 +54,7 @@ class InputZscalerHecAuthToken(BaseModel): r"""Shared secret to be provided by any client (Authorization: )""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -80,7 +80,7 @@ class InputZscalerHecAuthToken(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/lakedatasetsearchconfig.py b/src/cribl_control_plane/models/lakedatasetsearchconfig.py index bb3816b66..829f65a0d 100644 --- a/src/cribl_control_plane/models/lakedatasetsearchconfig.py +++ b/src/cribl_control_plane/models/lakedatasetsearchconfig.py @@ -3,6 +3,7 @@ from __future__ import annotations from .datasetmetadata import DatasetMetadata, DatasetMetadataTypedDict from .objectstoragefilter import ObjectStorageFilter, ObjectStorageFilterTypedDict +from .searchexecutionconfig import SearchExecutionConfig, SearchExecutionConfigTypedDict from .searchversion import SearchVersion from cribl_control_plane import models from cribl_control_plane.types import BaseModel, UNSET_SENTINEL @@ -20,6 +21,7 @@ class LakeDatasetSearchConfigTypedDict(TypedDict): metadata: NotRequired[DatasetMetadataTypedDict] path_filters: NotRequired[List[ObjectStorageFilterTypedDict]] r"""Glob-to-Datatype mappings for the Lake bucket path. Used only for search execution v2.""" + search_execution: NotRequired[SearchExecutionConfigTypedDict] search_version: NotRequired[SearchVersion] tags: NotRequired[str] r"""Comma-separated tags for the Dataset search configuration.""" @@ -39,6 +41,10 @@ class LakeDatasetSearchConfig(BaseModel): ] = None r"""Glob-to-Datatype mappings for the Lake bucket path. Used only for search execution v2.""" + search_execution: Annotated[ + Optional[SearchExecutionConfig], pydantic.Field(alias="searchExecution") + ] = None + search_version: Annotated[ Optional[SearchVersion], pydantic.Field(alias="searchVersion") ] = None @@ -63,6 +69,7 @@ def serialize_model(self, handler): "description", "metadata", "pathFilters", + "searchExecution", "searchVersion", "tags", ] diff --git a/src/cribl_control_plane/models/logininfo.py b/src/cribl_control_plane/models/logininfo.py index f7f56a81a..9738188aa 100644 --- a/src/cribl_control_plane/models/logininfo.py +++ b/src/cribl_control_plane/models/logininfo.py @@ -7,10 +7,14 @@ class LoginInfoTypedDict(TypedDict): password: str + r"""Password for the account.""" username: str + r"""Username of the account to authenticate.""" class LoginInfo(BaseModel): password: str + r"""Password for the account.""" username: str + r"""Username of the account to authenticate.""" diff --git a/src/cribl_control_plane/models/metadataitem.py b/src/cribl_control_plane/models/metadataitem.py new file mode 100644 index 000000000..c8912b6ff --- /dev/null +++ b/src/cribl_control_plane/models/metadataitem.py @@ -0,0 +1,20 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel +from typing_extensions import TypedDict + + +class MetadataItemTypedDict(TypedDict): + name: str + r"""Name of the metadata field.""" + value: str + r"""JavaScript expression to compute the metadata field's value, enclosed in quotes or backticks. Can evaluate to a constant.""" + + +class MetadataItem(BaseModel): + name: str + r"""Name of the metadata field.""" + + value: str + r"""JavaScript expression to compute the metadata field's value, enclosed in quotes or backticks. Can evaluate to a constant.""" diff --git a/src/cribl_control_plane/models/namefieldtype.py b/src/cribl_control_plane/models/namefieldtype.py index 4eb441586..ab0257526 100644 --- a/src/cribl_control_plane/models/namefieldtype.py +++ b/src/cribl_control_plane/models/namefieldtype.py @@ -13,11 +13,19 @@ class NameFieldTypeTypedDict(TypedDict): + r"""Reference to a field by its original text and parsed path segments.""" + raw: str + r"""Field name or expression before parsing.""" path: List[PathTypedDict] + r"""Path segments for the field name. For example, [\"level1\", \"level2\"] represents level1.level2.""" class NameFieldType(BaseModel): + r"""Reference to a field by its original text and parsed path segments.""" + raw: str + r"""Field name or expression before parsing.""" path: List[Path] + r"""Path segments for the field name. For example, [\"level1\", \"level2\"] represents level1.level2.""" diff --git a/src/cribl_control_plane/models/notification.py b/src/cribl_control_plane/models/notification.py new file mode 100644 index 000000000..f5fbfc9b9 --- /dev/null +++ b/src/cribl_control_plane/models/notification.py @@ -0,0 +1,164 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .metadataitem import MetadataItem, MetadataItemTypedDict +from .notificationmode import NotificationMode +from .notificationtargetconfig import ( + NotificationTargetConfig, + NotificationTargetConfigTypedDict, +) +from .notificationtargetdetails import ( + NotificationTargetDetails, + NotificationTargetDetailsTypedDict, +) +from cribl_control_plane import models +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +import pydantic +from pydantic import field_serializer, model_serializer +from typing import Any, Dict, List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class NotificationTemplateTargetPairTypedDict(TypedDict): + target_id: str + r"""The id of the Notification target to send the Notification to.""" + template_id: str + r"""The id of the Notification template to use.""" + + +class NotificationTemplateTargetPair(BaseModel): + target_id: Annotated[str, pydantic.Field(alias="targetId")] + r"""The id of the Notification target to send the Notification to.""" + + template_id: Annotated[str, pydantic.Field(alias="templateId")] + r"""The id of the Notification template to use.""" + + +class NotificationTypedDict(TypedDict): + condition: str + r"""The condition that triggers the Notification. Use GET /conditions for a list of supported condition values.""" + conf: Dict[str, Any] + r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. Use GET /conditions/{id} to review the configuration for a specific condition.""" + id: str + r"""Unique identifier.""" + targets: List[str] + r"""List of the id values for the Notification targets to send the Notification to.""" + src_group: NotRequired[str] + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + src_overridden: NotRequired[bool] + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" + disabled: NotRequired[bool] + r"""If true, the Notification is disabled and the specified condition will not trigger it.""" + group: NotRequired[str] + r"""The id of the Worker Group or Edge Fleet that the Notification applies to.""" + metadata: NotRequired[List[MetadataItemTypedDict]] + r"""Metadata tags for the Notification.""" + mode: NotRequired[NotificationMode] + pack: NotRequired[str] + r"""The id of the Pack the Notification belongs to. Automatically populated and returned in responses.""" + target_configs: NotRequired[List[NotificationTargetConfigTypedDict]] + r"""Override settings to apply for each referenced Notification target.""" + target_details: NotRequired[List[NotificationTargetDetailsTypedDict]] + r"""Additional details about referenced Notification targets. Optionally populated on request.""" + template_target_pairs: NotRequired[List[NotificationTemplateTargetPairTypedDict]] + r"""If mode is direct, the key-value pairs that define the Notification templates and targets to use for sending Notifications.""" + + +class Notification(BaseModel): + condition: str + r"""The condition that triggers the Notification. Use GET /conditions for a list of supported condition values.""" + + conf: Dict[str, Any] + r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition. Use GET /conditions/{id} to review the configuration for a specific condition.""" + + id: str + r"""Unique identifier.""" + + targets: List[str] + r"""List of the id values for the Notification targets to send the Notification to.""" + + src_group: Annotated[Optional[str], pydantic.Field(alias="__srcGroup")] = None + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + + src_overridden: Annotated[ + Optional[bool], pydantic.Field(alias="__srcOverridden") + ] = None + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" + + disabled: Optional[bool] = None + r"""If true, the Notification is disabled and the specified condition will not trigger it.""" + + group: Optional[str] = None + r"""The id of the Worker Group or Edge Fleet that the Notification applies to.""" + + metadata: Optional[List[MetadataItem]] = None + r"""Metadata tags for the Notification.""" + + mode: Optional[NotificationMode] = None + + pack: Optional[str] = None + r"""The id of the Pack the Notification belongs to. Automatically populated and returned in responses.""" + + target_configs: Annotated[ + Optional[List[NotificationTargetConfig]], pydantic.Field(alias="targetConfigs") + ] = None + r"""Override settings to apply for each referenced Notification target.""" + + target_details: Annotated[ + Optional[List[NotificationTargetDetails]], pydantic.Field(alias="targetDetails") + ] = None + r"""Additional details about referenced Notification targets. Optionally populated on request.""" + + template_target_pairs: Annotated[ + Optional[List[NotificationTemplateTargetPair]], + pydantic.Field(alias="templateTargetPairs"), + ] = None + r"""If mode is direct, the key-value pairs that define the Notification templates and targets to use for sending Notifications.""" + + @field_serializer("mode") + def serialize_mode(self, value): + if isinstance(value, str): + try: + return models.NotificationMode(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "__srcGroup", + "__srcOverridden", + "disabled", + "group", + "metadata", + "mode", + "pack", + "targetConfigs", + "targetDetails", + "templateTargetPairs", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + NotificationTemplateTargetPair.model_rebuild() +except NameError: + pass +try: + Notification.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/notification_union.py b/src/cribl_control_plane/models/notification_union.py deleted file mode 100644 index f7e9629a9..000000000 --- a/src/cribl_control_plane/models/notification_union.py +++ /dev/null @@ -1,766 +0,0 @@ -"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" - -from __future__ import annotations -from .metadataconfinputcollection import ( - MetadataConfInputCollection, - MetadataConfInputCollectionTypedDict, -) -from .templatetargetpairconffunctionconfschemanotificationpolicies import ( - TemplateTargetPairConfFunctionConfSchemaNotificationPolicies, - TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict, -) -from cribl_control_plane import models, utils -from cribl_control_plane.types import BaseModel, UNSET_SENTINEL -from enum import Enum -import pydantic -from pydantic import field_serializer, model_serializer -from typing import List, Optional, Union -from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict - - -class NotificationMode3(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Notification mode: direct or policy-based""" - - DIRECT = "direct" - POLICY = "policy" - - -class EmailRecipient3TypedDict(TypedDict): - r"""Email recipient settings for the Notification target.""" - - to: str - r"""Recipients' email addresses""" - cc: NotRequired[str] - r"""Cc: Recipients' email addresses""" - bcc: NotRequired[str] - r"""Bcc: Recipients' email addresses""" - - -class EmailRecipient3(BaseModel): - r"""Email recipient settings for the Notification target.""" - - to: str - r"""Recipients' email addresses""" - - cc: Optional[str] = None - r"""Cc: Recipients' email addresses""" - - bcc: Optional[str] = None - r"""Bcc: Recipients' email addresses""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["cc", "bcc"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class NotificationConfigForSMTPTarget3TypedDict(TypedDict): - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - subject: NotRequired[str] - r"""Email subject""" - body: NotRequired[str] - r"""Email body""" - email_recipient: NotRequired[EmailRecipient3TypedDict] - r"""Email recipient settings for the Notification target.""" - - -class NotificationConfigForSMTPTarget3(BaseModel): - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - subject: Optional[str] = None - r"""Email subject""" - - body: Optional[str] = None - r"""Email body""" - - email_recipient: Annotated[ - Optional[EmailRecipient3], pydantic.Field(alias="emailRecipient") - ] = None - r"""Email recipient settings for the Notification target.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["subject", "body", "emailRecipient"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class TargetConfig3TypedDict(TypedDict): - id: str - r"""The id of the Notification target.""" - conf: NotRequired[NotificationConfigForSMTPTarget3TypedDict] - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - -class TargetConfig3(BaseModel): - id: str - r"""The id of the Notification target.""" - - conf: Optional[NotificationConfigForSMTPTarget3] = None - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["conf"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -TargetConfigUnion3TypedDict = TargetConfig3TypedDict - - -TargetConfigUnion3 = TargetConfig3 - - -class ConditionSpecificConfigurations3TypedDict(TypedDict): - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - -class ConditionSpecificConfigurations3(BaseModel): - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - -class Notification3TypedDict(TypedDict): - id: str - r"""Unique identifier for the Notification.""" - condition: str - r"""The condition that triggers the Notification.""" - mode: NotRequired[NotificationMode3] - r"""Notification mode: direct or policy-based""" - disabled: NotRequired[bool] - r"""If true, the Notification is disabled and the specified condition will not trigger it.""" - targets: NotRequired[List[str]] - r"""List of the IDs for the Notification targets to send the Notification to.""" - target_configs: NotRequired[List[TargetConfigUnion3TypedDict]] - r"""Override settings to apply for each referenced Notification target.""" - conf: NotRequired[ConditionSpecificConfigurations3TypedDict] - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - group: NotRequired[str] - r"""The worker group/fleet this notification belongs to""" - pack: NotRequired[str] - r"""The pack this notification belongs to""" - template_target_pairs: NotRequired[ - List[TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict] - ] - r"""Pairs of templates and targets for notification routing""" - - -class Notification3(BaseModel): - id: str - r"""Unique identifier for the Notification.""" - - condition: str - r"""The condition that triggers the Notification.""" - - mode: Optional[NotificationMode3] = None - r"""Notification mode: direct or policy-based""" - - disabled: Optional[bool] = None - r"""If true, the Notification is disabled and the specified condition will not trigger it.""" - - targets: Optional[List[str]] = None - r"""List of the IDs for the Notification targets to send the Notification to.""" - - target_configs: Annotated[ - Optional[List[TargetConfigUnion3]], pydantic.Field(alias="targetConfigs") - ] = None - r"""Override settings to apply for each referenced Notification target.""" - - conf: Optional[ConditionSpecificConfigurations3] = None - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - group: Optional[str] = None - r"""The worker group/fleet this notification belongs to""" - - pack: Optional[str] = None - r"""The pack this notification belongs to""" - - template_target_pairs: Annotated[ - Optional[List[TemplateTargetPairConfFunctionConfSchemaNotificationPolicies]], - pydantic.Field(alias="templateTargetPairs"), - ] = None - r"""Pairs of templates and targets for notification routing""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.NotificationMode3(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mode", - "disabled", - "targets", - "targetConfigs", - "conf", - "metadata", - "group", - "pack", - "templateTargetPairs", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class NotificationMode2(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Notification mode: direct or policy-based""" - - DIRECT = "direct" - POLICY = "policy" - - -class EmailRecipient2TypedDict(TypedDict): - r"""Email recipient settings for the Notification target.""" - - to: str - r"""Recipients' email addresses""" - cc: NotRequired[str] - r"""Cc: Recipients' email addresses""" - bcc: NotRequired[str] - r"""Bcc: Recipients' email addresses""" - - -class EmailRecipient2(BaseModel): - r"""Email recipient settings for the Notification target.""" - - to: str - r"""Recipients' email addresses""" - - cc: Optional[str] = None - r"""Cc: Recipients' email addresses""" - - bcc: Optional[str] = None - r"""Bcc: Recipients' email addresses""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["cc", "bcc"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class NotificationConfigForSMTPTarget2TypedDict(TypedDict): - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - subject: NotRequired[str] - r"""Email subject""" - body: NotRequired[str] - r"""Email body""" - email_recipient: NotRequired[EmailRecipient2TypedDict] - r"""Email recipient settings for the Notification target.""" - - -class NotificationConfigForSMTPTarget2(BaseModel): - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - subject: Optional[str] = None - r"""Email subject""" - - body: Optional[str] = None - r"""Email body""" - - email_recipient: Annotated[ - Optional[EmailRecipient2], pydantic.Field(alias="emailRecipient") - ] = None - r"""Email recipient settings for the Notification target.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["subject", "body", "emailRecipient"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class TargetConfig2TypedDict(TypedDict): - id: str - r"""The id of the Notification target.""" - conf: NotRequired[NotificationConfigForSMTPTarget2TypedDict] - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - -class TargetConfig2(BaseModel): - id: str - r"""The id of the Notification target.""" - - conf: Optional[NotificationConfigForSMTPTarget2] = None - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["conf"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -TargetConfigUnion2TypedDict = TargetConfig2TypedDict - - -TargetConfigUnion2 = TargetConfig2 - - -class ConditionSpecificConfigurations2TypedDict(TypedDict): - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - -class ConditionSpecificConfigurations2(BaseModel): - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - -class Notification2TypedDict(TypedDict): - mode: NotificationMode2 - r"""Notification mode: direct or policy-based""" - id: str - r"""Unique identifier for the Notification.""" - condition: str - r"""The condition that triggers the Notification.""" - template_target_pairs: NotRequired[ - List[TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict] - ] - r"""Pairs of templates and targets for notification routing""" - disabled: NotRequired[bool] - r"""If true, the Notification is disabled and the specified condition will not trigger it.""" - targets: NotRequired[List[str]] - r"""List of the IDs for the Notification targets to send the Notification to.""" - target_configs: NotRequired[List[TargetConfigUnion2TypedDict]] - r"""Override settings to apply for each referenced Notification target.""" - conf: NotRequired[ConditionSpecificConfigurations2TypedDict] - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - group: NotRequired[str] - r"""The worker group/fleet this notification belongs to""" - pack: NotRequired[str] - r"""The pack this notification belongs to""" - - -class Notification2(BaseModel): - mode: NotificationMode2 - r"""Notification mode: direct or policy-based""" - - id: str - r"""Unique identifier for the Notification.""" - - condition: str - r"""The condition that triggers the Notification.""" - - template_target_pairs: Annotated[ - Optional[List[TemplateTargetPairConfFunctionConfSchemaNotificationPolicies]], - pydantic.Field(alias="templateTargetPairs"), - ] = None - r"""Pairs of templates and targets for notification routing""" - - disabled: Optional[bool] = None - r"""If true, the Notification is disabled and the specified condition will not trigger it.""" - - targets: Optional[List[str]] = None - r"""List of the IDs for the Notification targets to send the Notification to.""" - - target_configs: Annotated[ - Optional[List[TargetConfigUnion2]], pydantic.Field(alias="targetConfigs") - ] = None - r"""Override settings to apply for each referenced Notification target.""" - - conf: Optional[ConditionSpecificConfigurations2] = None - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - group: Optional[str] = None - r"""The worker group/fleet this notification belongs to""" - - pack: Optional[str] = None - r"""The pack this notification belongs to""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.NotificationMode2(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "templateTargetPairs", - "disabled", - "targets", - "targetConfigs", - "conf", - "metadata", - "group", - "pack", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class NotificationMode1(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Notification mode: direct or policy-based""" - - DIRECT = "direct" - POLICY = "policy" - - -class EmailRecipient1TypedDict(TypedDict): - r"""Email recipient settings for the Notification target.""" - - to: str - r"""Recipients' email addresses""" - cc: NotRequired[str] - r"""Cc: Recipients' email addresses""" - bcc: NotRequired[str] - r"""Bcc: Recipients' email addresses""" - - -class EmailRecipient1(BaseModel): - r"""Email recipient settings for the Notification target.""" - - to: str - r"""Recipients' email addresses""" - - cc: Optional[str] = None - r"""Cc: Recipients' email addresses""" - - bcc: Optional[str] = None - r"""Bcc: Recipients' email addresses""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["cc", "bcc"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class NotificationConfigForSMTPTarget1TypedDict(TypedDict): - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - subject: NotRequired[str] - r"""Email subject""" - body: NotRequired[str] - r"""Email body""" - email_recipient: NotRequired[EmailRecipient1TypedDict] - r"""Email recipient settings for the Notification target.""" - - -class NotificationConfigForSMTPTarget1(BaseModel): - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - subject: Optional[str] = None - r"""Email subject""" - - body: Optional[str] = None - r"""Email body""" - - email_recipient: Annotated[ - Optional[EmailRecipient1], pydantic.Field(alias="emailRecipient") - ] = None - r"""Email recipient settings for the Notification target.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["subject", "body", "emailRecipient"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class TargetConfig1TypedDict(TypedDict): - id: str - r"""The id of the Notification target.""" - conf: NotRequired[NotificationConfigForSMTPTarget1TypedDict] - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - -class TargetConfig1(BaseModel): - id: str - r"""The id of the Notification target.""" - - conf: Optional[NotificationConfigForSMTPTarget1] = None - r"""Simple Mail Transfer Protocol (SMTP) configuration for the Notification target.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["conf"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -TargetConfigUnion1TypedDict = TargetConfig1TypedDict - - -TargetConfigUnion1 = TargetConfig1 - - -class ConditionSpecificConfigurations1TypedDict(TypedDict): - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - -class ConditionSpecificConfigurations1(BaseModel): - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - -class Notification1TypedDict(TypedDict): - mode: NotificationMode1 - r"""Notification mode: direct or policy-based""" - template_target_pairs: List[ - TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict - ] - r"""Pairs of templates and targets for notification routing""" - id: str - r"""Unique identifier for the Notification.""" - condition: str - r"""The condition that triggers the Notification.""" - disabled: NotRequired[bool] - r"""If true, the Notification is disabled and the specified condition will not trigger it.""" - targets: NotRequired[List[str]] - r"""List of the IDs for the Notification targets to send the Notification to.""" - target_configs: NotRequired[List[TargetConfigUnion1TypedDict]] - r"""Override settings to apply for each referenced Notification target.""" - conf: NotRequired[ConditionSpecificConfigurations1TypedDict] - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - metadata: NotRequired[List[MetadataConfInputCollectionTypedDict]] - r"""Fields to add to events from this input""" - group: NotRequired[str] - r"""The worker group/fleet this notification belongs to""" - pack: NotRequired[str] - r"""The pack this notification belongs to""" - - -class Notification1(BaseModel): - mode: NotificationMode1 - r"""Notification mode: direct or policy-based""" - - template_target_pairs: Annotated[ - List[TemplateTargetPairConfFunctionConfSchemaNotificationPolicies], - pydantic.Field(alias="templateTargetPairs"), - ] - r"""Pairs of templates and targets for notification routing""" - - id: str - r"""Unique identifier for the Notification.""" - - condition: str - r"""The condition that triggers the Notification.""" - - disabled: Optional[bool] = None - r"""If true, the Notification is disabled and the specified condition will not trigger it.""" - - targets: Optional[List[str]] = None - r"""List of the IDs for the Notification targets to send the Notification to.""" - - target_configs: Annotated[ - Optional[List[TargetConfigUnion1]], pydantic.Field(alias="targetConfigs") - ] = None - r"""Override settings to apply for each referenced Notification target.""" - - conf: Optional[ConditionSpecificConfigurations1] = None - r"""Configuration for the condition that triggers the Notification. Supported fields vary depending on the condition.""" - - metadata: Optional[List[MetadataConfInputCollection]] = None - r"""Fields to add to events from this input""" - - group: Optional[str] = None - r"""The worker group/fleet this notification belongs to""" - - pack: Optional[str] = None - r"""The pack this notification belongs to""" - - @field_serializer("mode") - def serialize_mode(self, value): - if isinstance(value, str): - try: - return models.NotificationMode1(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "disabled", - "targets", - "targetConfigs", - "conf", - "metadata", - "group", - "pack", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -NotificationUnionTypedDict = TypeAliasType( - "NotificationUnionTypedDict", - Union[Notification1TypedDict, Notification2TypedDict, Notification3TypedDict], -) - - -NotificationUnion = TypeAliasType( - "NotificationUnion", Union[Notification1, Notification2, Notification3] -) - - -try: - NotificationConfigForSMTPTarget3.model_rebuild() -except NameError: - pass -try: - Notification3.model_rebuild() -except NameError: - pass -try: - NotificationConfigForSMTPTarget2.model_rebuild() -except NameError: - pass -try: - Notification2.model_rebuild() -except NameError: - pass -try: - NotificationConfigForSMTPTarget1.model_rebuild() -except NameError: - pass -try: - Notification1.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/notificationmode.py b/src/cribl_control_plane/models/notificationmode.py new file mode 100644 index 000000000..3f6bd6fd8 --- /dev/null +++ b/src/cribl_control_plane/models/notificationmode.py @@ -0,0 +1,10 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane import utils +from enum import Enum + + +class NotificationMode(str, Enum, metaclass=utils.OpenEnumMeta): + DIRECT = "direct" + POLICY = "policy" diff --git a/src/cribl_control_plane/models/notificationsmtptargetconfig.py b/src/cribl_control_plane/models/notificationsmtptargetconfig.py new file mode 100644 index 000000000..3fc1552cf --- /dev/null +++ b/src/cribl_control_plane/models/notificationsmtptargetconfig.py @@ -0,0 +1,49 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .emailrecipient import EmailRecipient, EmailRecipientTypedDict +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +import pydantic +from pydantic import model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class NotificationSMTPTargetConfigTypedDict(TypedDict): + email_recipient: EmailRecipientTypedDict + body: NotRequired[str] + r"""Email body.""" + subject: NotRequired[str] + r"""Email subject.""" + + +class NotificationSMTPTargetConfig(BaseModel): + email_recipient: Annotated[EmailRecipient, pydantic.Field(alias="emailRecipient")] + + body: Optional[str] = None + r"""Email body.""" + + subject: Optional[str] = None + r"""Email subject.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["body", "subject"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + NotificationSMTPTargetConfig.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/notificationtargetconfig.py b/src/cribl_control_plane/models/notificationtargetconfig.py new file mode 100644 index 000000000..2497aeb06 --- /dev/null +++ b/src/cribl_control_plane/models/notificationtargetconfig.py @@ -0,0 +1,40 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .notificationsmtptargetconfig import ( + NotificationSMTPTargetConfig, + NotificationSMTPTargetConfigTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from pydantic import model_serializer +from typing import Optional +from typing_extensions import NotRequired, TypedDict + + +class NotificationTargetConfigTypedDict(TypedDict): + id: str + r"""The id of the Notification target.""" + conf: NotRequired[NotificationSMTPTargetConfigTypedDict] + + +class NotificationTargetConfig(BaseModel): + id: str + r"""The id of the Notification target.""" + + conf: Optional[NotificationSMTPTargetConfig] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["conf"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m diff --git a/src/cribl_control_plane/models/notificationtargetdetails.py b/src/cribl_control_plane/models/notificationtargetdetails.py new file mode 100644 index 000000000..5ef61c0cf --- /dev/null +++ b/src/cribl_control_plane/models/notificationtargetdetails.py @@ -0,0 +1,20 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane.types import BaseModel +from typing_extensions import TypedDict + + +class NotificationTargetDetailsTypedDict(TypedDict): + id: str + r"""The id of the Notification target.""" + type: str + r"""The type of the Notification target.""" + + +class NotificationTargetDetails(BaseModel): + id: str + r"""The id of the Notification target.""" + + type: str + r"""The type of the Notification target.""" diff --git a/src/cribl_control_plane/models/originoptionscriblsourceprovenance.py b/src/cribl_control_plane/models/originoptionscriblsourceprovenance.py new file mode 100644 index 000000000..fb8ff3af0 --- /dev/null +++ b/src/cribl_control_plane/models/originoptionscriblsourceprovenance.py @@ -0,0 +1,11 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane import utils +from enum import Enum + + +class OriginOptionsCriblSourceProvenance(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Feature that created the Source.""" + + DATA_SOURCE_DISCOVERY = "data_source_discovery" diff --git a/src/cribl_control_plane/models/output.py b/src/cribl_control_plane/models/output.py index ade2bb742..d15627af8 100644 --- a/src/cribl_control_plane/models/output.py +++ b/src/cribl_control_plane/models/output.py @@ -36,6 +36,10 @@ OutputCustomerMetricsStorageTypedDict, ) from .outputdatabricks import OutputDatabricks, OutputDatabricksTypedDict +from .outputdatabrickszerobus import ( + OutputDatabricksZerobus, + OutputDatabricksZerobusTypedDict, +) from .outputdatadog import OutputDatadog, OutputDatadogTypedDict from .outputdataset import OutputDataset, OutputDatasetTypedDict from .outputdefault import OutputDefault, OutputDefaultTypedDict @@ -117,6 +121,7 @@ from .outputsumologic import OutputSumoLogic, OutputSumoLogicTypedDict from .outputsyslog import OutputSyslog, OutputSyslogTypedDict from .outputtcpjson import OutputTcpjson, OutputTcpjsonTypedDict +from .outputtraversalotlp import OutputTraversalOtlp, OutputTraversalOtlpTypedDict from .outputwavefront import OutputWavefront, OutputWavefrontTypedDict from .outputwebhook_union import OutputWebhookUnion, OutputWebhookUnionTypedDict from .outputwizhec import OutputWizHec, OutputWizHecTypedDict @@ -133,78 +138,80 @@ OutputDevnullTypedDict, OutputDefaultTypedDict, OutputRouterTypedDict, - OutputNetflowTypedDict, OutputSnmpTypedDict, + OutputNetflowTypedDict, OutputDiskSpoolTypedDict, OutputRingTypedDict, - OutputStatsdExtTypedDict, - OutputStatsdTypedDict, OutputGraphiteTypedDict, + OutputStatsdTypedDict, + OutputStatsdExtTypedDict, + OutputDatabricksZerobusTypedDict, OutputGoogleBigqueryTypedDict, OutputGooglePubsubTypedDict, OutputCriblTCPTypedDict, - OutputAzureEventhubTypedDict, OutputWavefrontTypedDict, - OutputSignalfxTypedDict, OutputGoogleCloudObservabilityTypedDict, - OutputMicrosoftFabricTypedDict, + OutputSignalfxTypedDict, OutputHoneycombTypedDict, - OutputExabeamTypedDict, + OutputAzureEventhubTypedDict, + OutputMicrosoftFabricTypedDict, OutputTcpjsonTypedDict, OutputSplunkTypedDict, - OutputSumoLogicTypedDict, - OutputCrowdstrikeNextGenSiemTypedDict, OutputHumioHecTypedDict, + OutputCrowdstrikeNextGenSiemTypedDict, + OutputSumoLogicTypedDict, OutputSnsTypedDict, OutputKafkaTypedDict, OutputElasticCloudTypedDict, - OutputCloudwatchTypedDict, - OutputSyslogTypedDict, - OutputAzureLogsTypedDict, OutputConfluentCloudTypedDict, OutputSplunkLbTypedDict, - OutputWizHecTypedDict, - OutputNewrelicEventsTypedDict, + OutputSyslogTypedDict, + OutputAzureLogsTypedDict, + OutputCloudwatchTypedDict, OutputKinesisTypedDict, - OutputCriblSearchEngineTypedDict, + OutputExabeamTypedDict, + OutputNewrelicEventsTypedDict, OutputNewrelicTypedDict, OutputCriblHTTPTypedDict, - OutputXsiamTypedDict, - OutputDatasetTypedDict, OutputLokiTypedDict, + OutputDatasetTypedDict, + OutputWizHecTypedDict, + OutputXsiamTypedDict, OutputDynatraceHTTPTypedDict, - OutputSplunkHecTypedDict, + OutputCriblSearchEngineTypedDict, OutputFilesystemTypedDict, + OutputSplunkHecTypedDict, OutputSqsTypedDict, - OutputCriblLakeTypedDict, OutputDynatraceOtlpTypedDict, OutputSnowflakeStreamingTypedDict, OutputServiceNowTypedDict, + OutputAmazonManagedPrometheusTypedDict, OutputDatadogTypedDict, OutputInfluxdbTypedDict, - OutputAmazonManagedPrometheusTypedDict, + OutputCriblLakeTypedDict, OutputGoogleChronicleTypedDict, OutputElasticTypedDict, OutputSentinelOneAiSiemTypedDict, + OutputClickHouseTypedDict, OutputCustomerMetricsStorageTypedDict, OutputChronicleTypedDict, - OutputClickHouseTypedDict, OutputLocalSearchStorageTypedDict, OutputPrometheusTypedDict, + OutputTraversalOtlpTypedDict, OutputDatabricksTypedDict, OutputAlphasocS3TypedDict, OutputMskTypedDict, - OutputStorjS3TypedDict, OutputIbmCloudS3TypedDict, + OutputStorjS3TypedDict, OutputNutanixObjectsTypedDict, OutputScalityS3TypedDict, OutputOpenTelemetryTypedDict, OutputDellS3TypedDict, OutputCloudflareR2TypedDict, - OutputSentinelTypedDict, OutputAlibabaCloudS3TypedDict, OutputGoogleCloudStorageTypedDict, OutputAzureBlobTypedDict, + OutputSentinelTypedDict, OutputCloudianS3TypedDict, OutputMinioTypedDict, OutputSecurityLakeTypedDict, @@ -212,8 +219,8 @@ OutputDlS3TypedDict, OutputS3TypedDict, OutputAzureDataExplorerTypedDict, - OutputWebhookUnionTypedDict, OutputGrafanaCloudUnionTypedDict, + OutputWebhookUnionTypedDict, ], ) @@ -290,6 +297,7 @@ Annotated[OutputNetflow, Tag("netflow")], Annotated[OutputDynatraceHTTP, Tag("dynatrace_http")], Annotated[OutputDynatraceOtlp, Tag("dynatrace_otlp")], + Annotated[OutputTraversalOtlp, Tag("traversal_otlp")], Annotated[OutputSentinelOneAiSiem, Tag("sentinel_one_ai_siem")], Annotated[OutputChronicle, Tag("chronicle")], Annotated[OutputDatabricks, Tag("databricks")], @@ -304,6 +312,7 @@ Annotated[OutputScalityS3, Tag("scality_s3")], Annotated[OutputAlibabaCloudS3, Tag("alibaba_cloud_s3")], Annotated[OutputIbmCloudS3, Tag("ibm_cloud_s3")], + Annotated[OutputDatabricksZerobus, Tag("databricks_zerobus")], ], Discriminator(lambda m: get_discriminator(m, "type", "type")), ] diff --git a/src/cribl_control_plane/models/outputcribllake.py b/src/cribl_control_plane/models/outputcribllake.py index bf01471b4..87b5346db 100644 --- a/src/cribl_control_plane/models/outputcribllake.py +++ b/src/cribl_control_plane/models/outputcribllake.py @@ -91,6 +91,7 @@ class OutputCriblLakeTypedDict(TypedDict): dynamic_dataset: NotRequired[bool] max_closing_files_to_backpressure: NotRequired[float] max_concurrent_file_parts: NotRequired[float] + freshness_grace_period_sec: NotRequired[float] description: NotRequired[str] r"""Optional description for this configuration.""" compress: NotRequired[CompressionOptionsHTTP] @@ -268,6 +269,10 @@ class OutputCriblLake(BaseModel): Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None + freshness_grace_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="freshnessGracePeriodSec") + ] = None + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -485,6 +490,7 @@ def serialize_model(self, handler): "dynamicDataset", "maxClosingFilesToBackpressure", "maxConcurrentFileParts", + "freshnessGracePeriodSec", "description", "compress", "compressionLevel", diff --git a/src/cribl_control_plane/models/outputcriblsearchengine.py b/src/cribl_control_plane/models/outputcriblsearchengine.py index 8328e3bfe..b7f1175d5 100644 --- a/src/cribl_control_plane/models/outputcriblsearchengine.py +++ b/src/cribl_control_plane/models/outputcriblsearchengine.py @@ -31,7 +31,7 @@ URLConfOutputCriblHTTP, URLConfOutputCriblHTTPTypedDict, ) -from cribl_control_plane import models +from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum import pydantic @@ -46,6 +46,17 @@ class OutputCriblSearchEngineType(str, Enum): CRIBL_SEARCH_ENGINE = "cribl_search_engine" +class SendAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + + # Logs + LOGS = "logs" + # Metrics + METRICS = "metrics" + # Logs and Metrics + BOTH = "both" + + class OutputCriblSearchEnginePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" @@ -113,6 +124,8 @@ class OutputCriblSearchEngineTypedDict(TypedDict): r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + send_as: NotRequired[SendAs] + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" use_round_robin_dns: NotRequired[bool] r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" description: NotRequired[str] @@ -284,6 +297,9 @@ class OutputCriblSearchEngine(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" + send_as: Annotated[Optional[SendAs], pydantic.Field(alias="sendAs")] = None + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None @@ -412,6 +428,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("send_as") + def serialize_send_as(self, value): + if isinstance(value, str): + try: + return models.SendAs(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -469,6 +494,7 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "authTokens", "onBackpressure", + "sendAs", "useRoundRobinDns", "description", "url", diff --git a/src/cribl_control_plane/models/outputcrowdstrikenextgensiem.py b/src/cribl_control_plane/models/outputcrowdstrikenextgensiem.py index a8171c84a..e8f1bdf89 100644 --- a/src/cribl_control_plane/models/outputcrowdstrikenextgensiem.py +++ b/src/cribl_control_plane/models/outputcrowdstrikenextgensiem.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionspq import CompressionOptionsPq @@ -91,7 +91,7 @@ class OutputCrowdstrikeNextGenSiemTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -231,7 +231,7 @@ class OutputCrowdstrikeNextGenSiem(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -362,7 +362,7 @@ def serialize_format_(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputdatabrickszerobus.py b/src/cribl_control_plane/models/outputdatabrickszerobus.py new file mode 100644 index 000000000..66aa547b5 --- /dev/null +++ b/src/cribl_control_plane/models/outputdatabrickszerobus.py @@ -0,0 +1,337 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .backpressurebehavioroptions import BackpressureBehaviorOptions +from .compressionoptionspq import CompressionOptionsPq +from .modeoptions import ModeOptions +from .queuefullbehavioroptions import QueueFullBehaviorOptions +from cribl_control_plane import models +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class OutputDatabricksZerobusType(str, Enum): + r"""Connector type identifier.""" + + DATABRICKS_ZEROBUS = "databricks_zerobus" + + +class OutputDatabricksZerobusPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputDatabricksZerobusPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputDatabricksZerobusTypedDict(TypedDict): + type: OutputDatabricksZerobusType + r"""Connector type identifier.""" + workspace_url: str + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" + workspace_id: str + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" + zerobus_endpoint: str + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + client_id: str + r"""OAuth client ID of the service principal authorized to write to the target table""" + client_text_secret: str + r"""OAuth client secret of the service principal""" + table_name: str + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + max_batch_size_kb: NotRequired[int] + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" + max_batch_records: NotRequired[int] + r"""Maximum number of records to include in a single ingest batch""" + max_buffered_kb: NotRequired[int] + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" + max_inflight_batches: NotRequired[int] + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" + flush_period_sec: NotRequired[int] + r"""Maximum time, in seconds, to hold a batch before sending it""" + ack_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" + connection_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputDatabricksZerobusPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + +class OutputDatabricksZerobus(BaseModel): + type: OutputDatabricksZerobusType + r"""Connector type identifier.""" + + workspace_url: Annotated[str, pydantic.Field(alias="workspaceUrl")] + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" + + workspace_id: Annotated[str, pydantic.Field(alias="workspaceId")] + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" + + zerobus_endpoint: Annotated[str, pydantic.Field(alias="zerobusEndpoint")] + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""OAuth client ID of the service principal authorized to write to the target table""" + + client_text_secret: Annotated[str, pydantic.Field(alias="clientTextSecret")] + r"""OAuth client secret of the service principal""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + max_batch_size_kb: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchSizeKB") + ] = None + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" + + max_batch_records: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchRecords") + ] = None + r"""Maximum number of records to include in a single ingest batch""" + + max_buffered_kb: Annotated[Optional[int], pydantic.Field(alias="maxBufferedKB")] = ( + None + ) + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" + + max_inflight_batches: Annotated[ + Optional[int], pydantic.Field(alias="maxInflightBatches") + ] = None + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" + + flush_period_sec: Annotated[ + Optional[int], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time, in seconds, to hold a batch before sending it""" + + ack_timeout_sec: Annotated[Optional[int], pydantic.Field(alias="ackTimeoutSec")] = ( + None + ) + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" + + connection_timeout_sec: Annotated[ + Optional[int], pydantic.Field(alias="connectionTimeoutSec") + ] = None + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[OutputDatabricksZerobusPqControls], pydantic.Field(alias="pqControls") + ] = None + r"""Persistent queue controls.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "maxBatchSizeKB", + "maxBatchRecords", + "maxBufferedKB", + "maxInflightBatches", + "flushPeriodSec", + "ackTimeoutSec", + "connectionTimeoutSec", + "onBackpressure", + "description", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_onBackpressure", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + OutputDatabricksZerobus.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/outputexabeam.py b/src/cribl_control_plane/models/outputexabeam.py index 59312c561..2ec860903 100644 --- a/src/cribl_control_plane/models/outputexabeam.py +++ b/src/cribl_control_plane/models/outputexabeam.py @@ -12,7 +12,7 @@ ) from .retrysettingstype import RetrySettingsType, RetrySettingsTypeTypedDict from .storageclassoptionsarchivecoldline import StorageClassOptionsArchiveColdline -from cribl_control_plane import models +from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum import pydantic @@ -27,6 +27,15 @@ class OutputExabeamType(str, Enum): EXABEAM = "exabeam" +class OutputExabeamAuthenticationMethod(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Authentication method""" + + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" + + class OutputExabeamTypedDict(TypedDict): type: OutputExabeamType r"""Connector type identifier.""" @@ -83,12 +92,22 @@ class OutputExabeamTypedDict(TypedDict): r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" encoded_configuration: NotRequired[str] r"""Enter an encoded string containing Exabeam configurations""" + aws_authentication_method: NotRequired[OutputExabeamAuthenticationMethod] + r"""Authentication method""" site_name: NotRequired[str] r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" site_id: NotRequired[str] r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" timezone_offset: NotRequired[str] r"""Timezone offset""" + hostname: NotRequired[str] + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" + forwarder: NotRequired[str] + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" + origin: NotRequired[str] + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" + logtags: NotRequired[str] + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" aws_api_key: NotRequired[str] r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" aws_secret_key: NotRequired[str] @@ -103,6 +122,8 @@ class OutputExabeamTypedDict(TypedDict): r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_region: NotRequired[str] @@ -236,6 +257,12 @@ class OutputExabeam(BaseModel): ] = None r"""Enter an encoded string containing Exabeam configurations""" + aws_authentication_method: Annotated[ + Optional[OutputExabeamAuthenticationMethod], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""Authentication method""" + site_name: Annotated[Optional[str], pydantic.Field(alias="siteName")] = None r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" @@ -247,6 +274,18 @@ class OutputExabeam(BaseModel): ] = None r"""Timezone offset""" + hostname: Optional[str] = None + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" + + forwarder: Optional[str] = None + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" + + origin: Optional[str] = None + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" + + logtags: Optional[str] = None + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" @@ -278,6 +317,9 @@ class OutputExabeam(BaseModel): ) r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -346,6 +388,15 @@ def serialize_on_disk_full_backpressure(self, value): return value return value + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.OutputExabeamAuthenticationMethod(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -371,9 +422,14 @@ def serialize_model(self, handler): "orphans", "maxFileSizeMB", "encodedConfiguration", + "awsAuthenticationMethod", "siteName", "siteId", "timezoneOffset", + "hostname", + "forwarder", + "origin", + "logtags", "awsApiKey", "awsSecretKey", "description", @@ -381,6 +437,7 @@ def serialize_model(self, handler): "directoryBatchSize", "deadletterPath", "maxRetryNum", + "awsSecret", "__template_streamtags", "__template_region", "__template_endpoint", diff --git a/src/cribl_control_plane/models/outputhumiohec.py b/src/cribl_control_plane/models/outputhumiohec.py index 67f0e565c..a17e00e40 100644 --- a/src/cribl_control_plane/models/outputhumiohec.py +++ b/src/cribl_control_plane/models/outputhumiohec.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionspq import CompressionOptionsPq @@ -89,7 +89,7 @@ class OutputHumioHecTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -227,7 +227,7 @@ class OutputHumioHec(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -357,7 +357,7 @@ def serialize_format_(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputresponse.py b/src/cribl_control_plane/models/outputresponse.py index 165493996..f8f2546c3 100644 --- a/src/cribl_control_plane/models/outputresponse.py +++ b/src/cribl_control_plane/models/outputresponse.py @@ -1,8 +1,115 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .notification_union import NotificationUnion, NotificationUnionTypedDict -from .outputresponse_outputdefault_type import ( +from .backpressurebehavioroptions import BackpressureBehaviorOptions +from .compressionoptionspq import CompressionOptionsPq +from .extrahttpheaderconfinputelastic import ( + ExtraHTTPHeaderConfInputElastic, + ExtraHTTPHeaderConfInputElasticTypedDict, +) +from .failedrequestloggingmodeoptions import FailedRequestLoggingModeOptions +from .methodoptions import MethodOptions +from .modeoptions import ModeOptions +from .notification import Notification, NotificationTypedDict +from .oauthheaderconfinputservicenowtable import ( + OauthHeaderConfInputServicenowTable, + OauthHeaderConfInputServicenowTableTypedDict, +) +from .oauthparamconfinputservicenowtable import ( + OauthParamConfInputServicenowTable, + OauthParamConfInputServicenowTableTypedDict, +) +from .outputresponse_outputsns_pqcontrols import ( + OutputResponseOutputAlibabaCloudS3, + OutputResponseOutputAlibabaCloudS3TypedDict, + OutputResponseOutputAlphasocS3, + OutputResponseOutputAlphasocS3TypedDict, + OutputResponseOutputAmazonManagedPrometheus, + OutputResponseOutputAmazonManagedPrometheusTypedDict, + OutputResponseOutputChronicle, + OutputResponseOutputChronicleTypedDict, + OutputResponseOutputClickHouse, + OutputResponseOutputClickHouseTypedDict, + OutputResponseOutputCloudflareR2, + OutputResponseOutputCloudflareR2TypedDict, + OutputResponseOutputCloudianS3, + OutputResponseOutputCloudianS3TypedDict, + OutputResponseOutputCriblHTTP, + OutputResponseOutputCriblHTTPTypedDict, + OutputResponseOutputCriblLake, + OutputResponseOutputCriblLakeTypedDict, + OutputResponseOutputCriblSearchEngine, + OutputResponseOutputCriblSearchEngineTypedDict, + OutputResponseOutputCriblTCP, + OutputResponseOutputCriblTCPTypedDict, + OutputResponseOutputCrowdstrikeNextGenSiem, + OutputResponseOutputCrowdstrikeNextGenSiemTypedDict, + OutputResponseOutputCustomerMetricsStorage, + OutputResponseOutputCustomerMetricsStorageTypedDict, + OutputResponseOutputDatabricks, + OutputResponseOutputDatabricksTypedDict, + OutputResponseOutputDatabricksZerobus, + OutputResponseOutputDatabricksZerobusTypedDict, + OutputResponseOutputDatadog, + OutputResponseOutputDatadogTypedDict, + OutputResponseOutputDataset, + OutputResponseOutputDatasetTypedDict, + OutputResponseOutputDellS3, + OutputResponseOutputDellS3TypedDict, + OutputResponseOutputDiskSpool, + OutputResponseOutputDiskSpoolTypedDict, + OutputResponseOutputDlS3, + OutputResponseOutputDlS3TypedDict, + OutputResponseOutputDynatraceHTTP, + OutputResponseOutputDynatraceHTTPTypedDict, + OutputResponseOutputDynatraceOtlp, + OutputResponseOutputDynatraceOtlpTypedDict, + OutputResponseOutputGrafanaCloudUnion, + OutputResponseOutputGrafanaCloudUnionTypedDict, + OutputResponseOutputHumioHec, + OutputResponseOutputHumioHecTypedDict, + OutputResponseOutputIbmCloudS3, + OutputResponseOutputIbmCloudS3TypedDict, + OutputResponseOutputLocalSearchStorage, + OutputResponseOutputLocalSearchStorageTypedDict, + OutputResponseOutputLoki, + OutputResponseOutputLokiTypedDict, + OutputResponseOutputMicrosoftFabric, + OutputResponseOutputMicrosoftFabricTypedDict, + OutputResponseOutputNetflow, + OutputResponseOutputNetflowTypedDict, + OutputResponseOutputNutanixObjects, + OutputResponseOutputNutanixObjectsTypedDict, + OutputResponseOutputOpenTelemetry, + OutputResponseOutputOpenTelemetryTypedDict, + OutputResponseOutputPrometheus, + OutputResponseOutputPrometheusTypedDict, + OutputResponseOutputRing, + OutputResponseOutputRingTypedDict, + OutputResponseOutputScalityS3, + OutputResponseOutputScalityS3TypedDict, + OutputResponseOutputSecurityLake, + OutputResponseOutputSecurityLakeTypedDict, + OutputResponseOutputSentinelOneAiSiem, + OutputResponseOutputSentinelOneAiSiemTypedDict, + OutputResponseOutputServiceNow, + OutputResponseOutputServiceNowTypedDict, + OutputResponseOutputSnmp, + OutputResponseOutputSnmpTypedDict, + OutputResponseOutputSnowflakeStreaming, + OutputResponseOutputSnowflakeStreamingTypedDict, + OutputResponseOutputSqs, + OutputResponseOutputSqsTypedDict, + OutputResponseOutputStorjS3, + OutputResponseOutputStorjS3TypedDict, + OutputResponseOutputSumoLogic, + OutputResponseOutputSumoLogicTypedDict, + OutputResponseOutputTraversalOtlp, + OutputResponseOutputTraversalOtlpTypedDict, + OutputResponseOutputXsiam, + OutputResponseOutputXsiamTypedDict, +) +from .outputresponse_outputwebhook_format_2 import ( OutputResponseOutputAzureBlob, OutputResponseOutputAzureBlobTypedDict, OutputResponseOutputAzureDataExplorer, @@ -15,7 +122,6 @@ OutputResponseOutputCloudwatchTypedDict, OutputResponseOutputConfluentCloud, OutputResponseOutputConfluentCloudTypedDict, - OutputResponseOutputDefaultType, OutputResponseOutputDevnull, OutputResponseOutputDevnullTypedDict, OutputResponseOutputElastic, @@ -38,6 +144,8 @@ OutputResponseOutputGoogleCloudStorageTypedDict, OutputResponseOutputGooglePubsub, OutputResponseOutputGooglePubsubTypedDict, + OutputResponseOutputGraphite, + OutputResponseOutputGraphiteTypedDict, OutputResponseOutputHoneycomb, OutputResponseOutputHoneycombTypedDict, OutputResponseOutputInfluxdb, @@ -54,12 +162,16 @@ OutputResponseOutputNewrelicEvents, OutputResponseOutputNewrelicEventsTypedDict, OutputResponseOutputNewrelicTypedDict, + OutputResponseOutputRouter, + OutputResponseOutputRouterTypedDict, OutputResponseOutputS3, OutputResponseOutputS3TypedDict, OutputResponseOutputSentinel, OutputResponseOutputSentinelTypedDict, OutputResponseOutputSignalfx, OutputResponseOutputSignalfxTypedDict, + OutputResponseOutputSns, + OutputResponseOutputSnsTypedDict, OutputResponseOutputSplunk, OutputResponseOutputSplunkHec, OutputResponseOutputSplunkHecTypedDict, @@ -76,112 +188,1617 @@ OutputResponseOutputTcpjsonTypedDict, OutputResponseOutputWavefront, OutputResponseOutputWavefrontTypedDict, - OutputResponseOutputWebhookUnion, - OutputResponseOutputWebhookUnionTypedDict, + OutputResponseOutputWebhookFormat2, + OutputResponseOutputWebhookType2, OutputResponseOutputWizHec, OutputResponseOutputWizHecTypedDict, ) -from .outputresponse_outputstatsdext_type import ( - OutputResponseOutputAlibabaCloudS3, - OutputResponseOutputAlibabaCloudS3TypedDict, - OutputResponseOutputAlphasocS3, - OutputResponseOutputAlphasocS3TypedDict, - OutputResponseOutputAmazonManagedPrometheus, - OutputResponseOutputAmazonManagedPrometheusTypedDict, - OutputResponseOutputChronicle, - OutputResponseOutputChronicleTypedDict, - OutputResponseOutputClickHouse, - OutputResponseOutputClickHouseTypedDict, - OutputResponseOutputCloudflareR2, - OutputResponseOutputCloudflareR2TypedDict, - OutputResponseOutputCloudianS3, - OutputResponseOutputCloudianS3TypedDict, - OutputResponseOutputCriblHTTP, - OutputResponseOutputCriblHTTPTypedDict, - OutputResponseOutputCriblLake, - OutputResponseOutputCriblLakeTypedDict, - OutputResponseOutputCriblSearchEngine, - OutputResponseOutputCriblSearchEngineTypedDict, - OutputResponseOutputCriblTCP, - OutputResponseOutputCriblTCPTypedDict, - OutputResponseOutputCrowdstrikeNextGenSiem, - OutputResponseOutputCrowdstrikeNextGenSiemTypedDict, - OutputResponseOutputCustomerMetricsStorage, - OutputResponseOutputCustomerMetricsStorageTypedDict, - OutputResponseOutputDatabricks, - OutputResponseOutputDatabricksTypedDict, - OutputResponseOutputDatadog, - OutputResponseOutputDatadogTypedDict, - OutputResponseOutputDataset, - OutputResponseOutputDatasetTypedDict, - OutputResponseOutputDellS3, - OutputResponseOutputDellS3TypedDict, - OutputResponseOutputDiskSpool, - OutputResponseOutputDiskSpoolTypedDict, - OutputResponseOutputDlS3, - OutputResponseOutputDlS3TypedDict, - OutputResponseOutputDynatraceHTTP, - OutputResponseOutputDynatraceHTTPTypedDict, - OutputResponseOutputDynatraceOtlp, - OutputResponseOutputDynatraceOtlpTypedDict, - OutputResponseOutputGrafanaCloudUnion, - OutputResponseOutputGrafanaCloudUnionTypedDict, - OutputResponseOutputGraphite, - OutputResponseOutputGraphiteTypedDict, - OutputResponseOutputHumioHec, - OutputResponseOutputHumioHecTypedDict, - OutputResponseOutputIbmCloudS3, - OutputResponseOutputIbmCloudS3TypedDict, - OutputResponseOutputLocalSearchStorage, - OutputResponseOutputLocalSearchStorageTypedDict, - OutputResponseOutputLoki, - OutputResponseOutputLokiTypedDict, - OutputResponseOutputMicrosoftFabric, - OutputResponseOutputMicrosoftFabricTypedDict, - OutputResponseOutputNetflow, - OutputResponseOutputNetflowTypedDict, - OutputResponseOutputNutanixObjects, - OutputResponseOutputNutanixObjectsTypedDict, - OutputResponseOutputOpenTelemetry, - OutputResponseOutputOpenTelemetryTypedDict, - OutputResponseOutputPrometheus, - OutputResponseOutputPrometheusTypedDict, - OutputResponseOutputRing, - OutputResponseOutputRingTypedDict, - OutputResponseOutputRouter, - OutputResponseOutputRouterTypedDict, - OutputResponseOutputScalityS3, - OutputResponseOutputScalityS3TypedDict, - OutputResponseOutputSecurityLake, - OutputResponseOutputSecurityLakeTypedDict, - OutputResponseOutputSentinelOneAiSiem, - OutputResponseOutputSentinelOneAiSiemTypedDict, - OutputResponseOutputServiceNow, - OutputResponseOutputServiceNowTypedDict, - OutputResponseOutputSnmp, - OutputResponseOutputSnmpTypedDict, - OutputResponseOutputSnowflakeStreaming, - OutputResponseOutputSnowflakeStreamingTypedDict, - OutputResponseOutputSns, - OutputResponseOutputSnsTypedDict, - OutputResponseOutputSqs, - OutputResponseOutputSqsTypedDict, - OutputResponseOutputStorjS3, - OutputResponseOutputStorjS3TypedDict, - OutputResponseOutputSumoLogic, - OutputResponseOutputSumoLogicTypedDict, - OutputResponseOutputXsiam, - OutputResponseOutputXsiamTypedDict, +from .queuefullbehavioroptions import QueueFullBehaviorOptions +from .refreshrequestparamconfhealthcheckauthenticationoauthsecret import ( + RefreshRequestParamConfHealthCheckAuthenticationOauthSecret, + RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict, +) +from .responseretrysettingconfoutputwebhook import ( + ResponseRetrySettingConfOutputWebhook, + ResponseRetrySettingConfOutputWebhookTypedDict, +) +from .statustype import StatusType, StatusTypeTypedDict +from .timeoutretrysettingstype import ( + TimeoutRetrySettingsType, + TimeoutRetrySettingsTypeTypedDict, +) +from .tlssettingsclientsidetypecapathcertpathextended import ( + TLSSettingsClientSideTypeCaPathCertPathExtended, + TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict, +) +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, Nullable, UNSET_SENTINEL +from cribl_control_plane.utils.unions import parse_open_union +from enum import Enum +from functools import partial +import pydantic +from pydantic import ConfigDict, field_serializer, model_serializer +from pydantic.functional_validators import BeforeValidator +from typing import Any, List, Literal, Optional, Union +from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class OutputResponseOutputWebhookAuthenticationType2( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method to use for the HTTP request""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth + OAUTH = "oauth" + + +class OutputResponseOutputWebhookPqControls2TypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputWebhookPqControls2(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputWebhookURL2TypedDict(TypedDict): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class OutputResponseOutputWebhookURL2(BaseModel): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputWebhookWebhook2TypedDict(TypedDict): + type: OutputResponseOutputWebhookType2 + r"""Connector type identifier.""" + urls: List[OutputResponseOutputWebhookURL2TypedDict] + r"""Webhook URLs""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + format_: NotRequired[OutputResponseOutputWebhookFormat2] + r"""How to format events before sending out""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[OutputResponseOutputWebhookAuthenticationType2] + r"""Authentication method to use for the HTTP request""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_source_expression: NotRequired[str] + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + custom_drop_when_null: NotRequired[bool] + r"""Whether to drop events when the source expression evaluates to null""" + custom_event_delimiter: NotRequired[str] + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + custom_content_type: NotRequired[str] + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + custom_payload_expression: NotRequired[str] + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + advanced_content_type: NotRequired[str] + r"""HTTP content-type header value""" + format_event_code: NotRequired[str] + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + format_payload_code: NotRequired[str] + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputWebhookPqControls2TypedDict] + r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + secret: NotRequired[str] + r"""Secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + url: NotRequired[str] + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_refresh_url: NotRequired[str] + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class OutputResponseOutputWebhookWebhook2(BaseModel): + type: OutputResponseOutputWebhookType2 + r"""Connector type identifier.""" + + urls: List[OutputResponseOutputWebhookURL2] + r"""Webhook URLs""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + format_: Annotated[ + Optional[OutputResponseOutputWebhookFormat2], pydantic.Field(alias="format") + ] = None + r"""How to format events before sending out""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[OutputResponseOutputWebhookAuthenticationType2], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method to use for the HTTP request""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_source_expression: Annotated[ + Optional[str], pydantic.Field(alias="customSourceExpression") + ] = None + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + + custom_drop_when_null: Annotated[ + Optional[bool], pydantic.Field(alias="customDropWhenNull") + ] = None + r"""Whether to drop events when the source expression evaluates to null""" + + custom_event_delimiter: Annotated[ + Optional[str], pydantic.Field(alias="customEventDelimiter") + ] = None + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + + custom_content_type: Annotated[ + Optional[str], pydantic.Field(alias="customContentType") + ] = None + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + + custom_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="customPayloadExpression") + ] = None + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + + advanced_content_type: Annotated[ + Optional[str], pydantic.Field(alias="advancedContentType") + ] = None + r"""HTTP content-type header value""" + + format_event_code: Annotated[ + Optional[str], pydantic.Field(alias="formatEventCode") + ] = None + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + format_payload_code: Annotated[ + Optional[str], pydantic.Field(alias="formatPayloadCode") + ] = None + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[OutputResponseOutputWebhookPqControls2], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + secret: Optional[str] = None + r"""Secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + url: Optional[str] = None + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + + template_refresh_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_refreshUrl") + ] = None + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputWebhookFormat2(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputWebhookAuthenticationType2(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "method", + "format", + "keepAlive", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "tls", + "totalMemoryLimitKB", + "loadBalanced", + "description", + "customSourceExpression", + "customDropWhenNull", + "customEventDelimiter", + "customContentType", + "customPayloadExpression", + "advancedContentType", + "formatEventCode", + "formatPayloadCode", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "secret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "url", + "excludeSelf", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "__template_streamtags", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "__template_loginUrl", + "__template_secret", + "__template_refreshUrl", + "__template_url", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputWebhookType1(str, Enum): + r"""Connector type identifier.""" + + WEBHOOK = "webhook" + + +class OutputResponseOutputWebhookFormat1(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How to format events before sending out""" + + # NDJSON (Newline Delimited JSON) + NDJSON = "ndjson" + # JSON Array + JSON_ARRAY = "json_array" + # Custom + CUSTOM = "custom" + # Advanced + ADVANCED = "advanced" + + +class OutputResponseOutputWebhookAuthenticationType1( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method to use for the HTTP request""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth + OAUTH = "oauth" + + +class OutputResponseOutputWebhookPqControls1TypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputWebhookPqControls1(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputWebhookURL1TypedDict(TypedDict): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class OutputResponseOutputWebhookURL1(BaseModel): + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputWebhookWebhook1TypedDict(TypedDict): + type: OutputResponseOutputWebhookType1 + r"""Connector type identifier.""" + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + format_: NotRequired[OutputResponseOutputWebhookFormat1] + r"""How to format events before sending out""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[OutputResponseOutputWebhookAuthenticationType1] + r"""Authentication method to use for the HTTP request""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_source_expression: NotRequired[str] + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + custom_drop_when_null: NotRequired[bool] + r"""Whether to drop events when the source expression evaluates to null""" + custom_event_delimiter: NotRequired[str] + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + custom_content_type: NotRequired[str] + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + custom_payload_expression: NotRequired[str] + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + advanced_content_type: NotRequired[str] + r"""HTTP content-type header value""" + format_event_code: NotRequired[str] + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + format_payload_code: NotRequired[str] + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputWebhookPqControls1TypedDict] + r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + secret: NotRequired[str] + r"""Secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[OutputResponseOutputWebhookURL1TypedDict]] + r"""Webhook URLs""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_refresh_url: NotRequired[str] + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class OutputResponseOutputWebhookWebhook1(BaseModel): + type: OutputResponseOutputWebhookType1 + r"""Connector type identifier.""" + + url: str + r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" + + format_: Annotated[ + Optional[OutputResponseOutputWebhookFormat1], pydantic.Field(alias="format") + ] = None + r"""How to format events before sending out""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + auth_type: Annotated[ + Optional[OutputResponseOutputWebhookAuthenticationType1], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication method to use for the HTTP request""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_source_expression: Annotated[ + Optional[str], pydantic.Field(alias="customSourceExpression") + ] = None + r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + + custom_drop_when_null: Annotated[ + Optional[bool], pydantic.Field(alias="customDropWhenNull") + ] = None + r"""Whether to drop events when the source expression evaluates to null""" + + custom_event_delimiter: Annotated[ + Optional[str], pydantic.Field(alias="customEventDelimiter") + ] = None + r"""Delimiter string to insert between individual events. Defaults to newline character.""" + + custom_content_type: Annotated[ + Optional[str], pydantic.Field(alias="customContentType") + ] = None + r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + + custom_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="customPayloadExpression") + ] = None + r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + + advanced_content_type: Annotated[ + Optional[str], pydantic.Field(alias="advancedContentType") + ] = None + r"""HTTP content-type header value""" + + format_event_code: Annotated[ + Optional[str], pydantic.Field(alias="formatEventCode") + ] = None + r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + format_payload_code: Annotated[ + Optional[str], pydantic.Field(alias="formatPayloadCode") + ] = None + r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[OutputResponseOutputWebhookPqControls1], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + secret: Optional[str] = None + r"""Secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[OutputResponseOutputWebhookURL1]] = None + r"""Webhook URLs""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + + template_refresh_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_refreshUrl") + ] = None + r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("method") + def serialize_method(self, value): + if isinstance(value, str): + try: + return models.MethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputWebhookFormat1(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputWebhookAuthenticationType1(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "method", + "format", + "keepAlive", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", + "authType", + "tls", + "totalMemoryLimitKB", + "loadBalanced", + "description", + "customSourceExpression", + "customDropWhenNull", + "customEventDelimiter", + "customContentType", + "customPayloadExpression", + "advancedContentType", + "formatEventCode", + "formatPayloadCode", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "secret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "__template_streamtags", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "__template_loginUrl", + "__template_secret", + "__template_refreshUrl", + "__template_url", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +OutputResponseOutputWebhookUnionTypedDict = TypeAliasType( + "OutputResponseOutputWebhookUnionTypedDict", + Union[ + OutputResponseOutputWebhookWebhook1TypedDict, + OutputResponseOutputWebhookWebhook2TypedDict, + ], +) + + +OutputResponseOutputWebhookUnion = TypeAliasType( + "OutputResponseOutputWebhookUnion", + Union[OutputResponseOutputWebhookWebhook1, OutputResponseOutputWebhookWebhook2], ) -from .statustype import StatusType, StatusTypeTypedDict -from cribl_control_plane.types import BaseModel, Nullable, UNSET_SENTINEL -from cribl_control_plane.utils.unions import parse_open_union -from functools import partial -import pydantic -from pydantic import ConfigDict, model_serializer -from pydantic.functional_validators import BeforeValidator -from typing import Any, List, Literal, Optional, Union -from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict + + +class OutputResponseOutputDefaultType(str, Enum): + r"""Connector type identifier.""" + + DEFAULT = "default" class OutputResponseOutputDefaultTypedDict(TypedDict): @@ -201,7 +1818,7 @@ class OutputResponseOutputDefaultTypedDict(TypedDict): r"""Metadata tags used for categorization and filtering.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @@ -236,7 +1853,7 @@ class OutputResponseOutputDefault(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -285,78 +1902,80 @@ def serialize_model(self, handler): OutputResponseOutputDevnullTypedDict, OutputResponseOutputDefaultTypedDict, OutputResponseOutputRouterTypedDict, - OutputResponseOutputNetflowTypedDict, OutputResponseOutputSnmpTypedDict, + OutputResponseOutputNetflowTypedDict, OutputResponseOutputDiskSpoolTypedDict, OutputResponseOutputRingTypedDict, - OutputResponseOutputStatsdExtTypedDict, - OutputResponseOutputStatsdTypedDict, OutputResponseOutputGraphiteTypedDict, + OutputResponseOutputStatsdTypedDict, + OutputResponseOutputStatsdExtTypedDict, + OutputResponseOutputDatabricksZerobusTypedDict, OutputResponseOutputGoogleBigqueryTypedDict, OutputResponseOutputGooglePubsubTypedDict, OutputResponseOutputCriblTCPTypedDict, - OutputResponseOutputAzureEventhubTypedDict, OutputResponseOutputWavefrontTypedDict, - OutputResponseOutputSignalfxTypedDict, OutputResponseOutputGoogleCloudObservabilityTypedDict, - OutputResponseOutputMicrosoftFabricTypedDict, + OutputResponseOutputSignalfxTypedDict, OutputResponseOutputHoneycombTypedDict, - OutputResponseOutputExabeamTypedDict, + OutputResponseOutputAzureEventhubTypedDict, + OutputResponseOutputMicrosoftFabricTypedDict, OutputResponseOutputTcpjsonTypedDict, OutputResponseOutputSplunkTypedDict, - OutputResponseOutputSumoLogicTypedDict, - OutputResponseOutputCrowdstrikeNextGenSiemTypedDict, OutputResponseOutputHumioHecTypedDict, + OutputResponseOutputCrowdstrikeNextGenSiemTypedDict, + OutputResponseOutputSumoLogicTypedDict, OutputResponseOutputSnsTypedDict, OutputResponseOutputKafkaTypedDict, OutputResponseOutputElasticCloudTypedDict, - OutputResponseOutputCloudwatchTypedDict, - OutputResponseOutputSyslogTypedDict, - OutputResponseOutputAzureLogsTypedDict, OutputResponseOutputConfluentCloudTypedDict, OutputResponseOutputSplunkLbTypedDict, - OutputResponseOutputWizHecTypedDict, - OutputResponseOutputNewrelicEventsTypedDict, + OutputResponseOutputSyslogTypedDict, + OutputResponseOutputAzureLogsTypedDict, + OutputResponseOutputCloudwatchTypedDict, OutputResponseOutputKinesisTypedDict, - OutputResponseOutputCriblSearchEngineTypedDict, + OutputResponseOutputExabeamTypedDict, + OutputResponseOutputNewrelicEventsTypedDict, OutputResponseOutputNewrelicTypedDict, OutputResponseOutputCriblHTTPTypedDict, - OutputResponseOutputXsiamTypedDict, - OutputResponseOutputDatasetTypedDict, OutputResponseOutputLokiTypedDict, + OutputResponseOutputDatasetTypedDict, + OutputResponseOutputWizHecTypedDict, + OutputResponseOutputXsiamTypedDict, OutputResponseOutputDynatraceHTTPTypedDict, - OutputResponseOutputSplunkHecTypedDict, + OutputResponseOutputCriblSearchEngineTypedDict, OutputResponseOutputFilesystemTypedDict, + OutputResponseOutputSplunkHecTypedDict, OutputResponseOutputSqsTypedDict, - OutputResponseOutputCriblLakeTypedDict, OutputResponseOutputDynatraceOtlpTypedDict, OutputResponseOutputSnowflakeStreamingTypedDict, OutputResponseOutputServiceNowTypedDict, + OutputResponseOutputAmazonManagedPrometheusTypedDict, OutputResponseOutputDatadogTypedDict, OutputResponseOutputInfluxdbTypedDict, - OutputResponseOutputAmazonManagedPrometheusTypedDict, + OutputResponseOutputCriblLakeTypedDict, OutputResponseOutputGoogleChronicleTypedDict, OutputResponseOutputElasticTypedDict, OutputResponseOutputSentinelOneAiSiemTypedDict, + OutputResponseOutputClickHouseTypedDict, OutputResponseOutputCustomerMetricsStorageTypedDict, OutputResponseOutputChronicleTypedDict, - OutputResponseOutputClickHouseTypedDict, OutputResponseOutputLocalSearchStorageTypedDict, OutputResponseOutputPrometheusTypedDict, + OutputResponseOutputTraversalOtlpTypedDict, OutputResponseOutputDatabricksTypedDict, OutputResponseOutputAlphasocS3TypedDict, OutputResponseOutputMskTypedDict, - OutputResponseOutputStorjS3TypedDict, OutputResponseOutputIbmCloudS3TypedDict, + OutputResponseOutputStorjS3TypedDict, OutputResponseOutputNutanixObjectsTypedDict, OutputResponseOutputScalityS3TypedDict, OutputResponseOutputOpenTelemetryTypedDict, OutputResponseOutputDellS3TypedDict, OutputResponseOutputCloudflareR2TypedDict, - OutputResponseOutputSentinelTypedDict, OutputResponseOutputAlibabaCloudS3TypedDict, OutputResponseOutputGoogleCloudStorageTypedDict, OutputResponseOutputAzureBlobTypedDict, + OutputResponseOutputSentinelTypedDict, OutputResponseOutputCloudianS3TypedDict, OutputResponseOutputMinioTypedDict, OutputResponseOutputSecurityLakeTypedDict, @@ -364,8 +1983,8 @@ def serialize_model(self, handler): OutputResponseOutputDlS3TypedDict, OutputResponseOutputS3TypedDict, OutputResponseOutputAzureDataExplorerTypedDict, - OutputResponseOutputWebhookUnionTypedDict, OutputResponseOutputGrafanaCloudUnionTypedDict, + OutputResponseOutputWebhookUnionTypedDict, ], ) r"""Destination configuration with optional Notifications and runtime status.""" @@ -452,6 +2071,7 @@ class UnknownOutputResponse(BaseModel): "netflow": OutputResponseOutputNetflow, "dynatrace_http": OutputResponseOutputDynatraceHTTP, "dynatrace_otlp": OutputResponseOutputDynatraceOtlp, + "traversal_otlp": OutputResponseOutputTraversalOtlp, "sentinel_one_ai_siem": OutputResponseOutputSentinelOneAiSiem, "chronicle": OutputResponseOutputChronicle, "databricks": OutputResponseOutputDatabricks, @@ -466,6 +2086,7 @@ class UnknownOutputResponse(BaseModel): "scality_s3": OutputResponseOutputScalityS3, "alibaba_cloud_s3": OutputResponseOutputAlibabaCloudS3, "ibm_cloud_s3": OutputResponseOutputIbmCloudS3, + "databricks_zerobus": OutputResponseOutputDatabricksZerobus, } @@ -541,6 +2162,7 @@ class UnknownOutputResponse(BaseModel): OutputResponseOutputNetflow, OutputResponseOutputDynatraceHTTP, OutputResponseOutputDynatraceOtlp, + OutputResponseOutputTraversalOtlp, OutputResponseOutputSentinelOneAiSiem, OutputResponseOutputChronicle, OutputResponseOutputDatabricks, @@ -555,6 +2177,7 @@ class UnknownOutputResponse(BaseModel): OutputResponseOutputScalityS3, OutputResponseOutputAlibabaCloudS3, OutputResponseOutputIbmCloudS3, + OutputResponseOutputDatabricksZerobus, UnknownOutputResponse, ], BeforeValidator( @@ -570,6 +2193,22 @@ class UnknownOutputResponse(BaseModel): r"""Destination configuration with optional Notifications and runtime status.""" +try: + OutputResponseOutputWebhookURL2.model_rebuild() +except NameError: + pass +try: + OutputResponseOutputWebhookWebhook2.model_rebuild() +except NameError: + pass +try: + OutputResponseOutputWebhookURL1.model_rebuild() +except NameError: + pass +try: + OutputResponseOutputWebhookWebhook1.model_rebuild() +except NameError: + pass try: OutputResponseOutputDefault.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/outputresponse_outputstatsdext_type.py b/src/cribl_control_plane/models/outputresponse_outputsns_pqcontrols.py similarity index 97% rename from src/cribl_control_plane/models/outputresponse_outputstatsdext_type.py rename to src/cribl_control_plane/models/outputresponse_outputsns_pqcontrols.py index a704bcd3f..9f029f947 100644 --- a/src/cribl_control_plane/models/outputresponse_outputstatsdext_type.py +++ b/src/cribl_control_plane/models/outputresponse_outputsns_pqcontrols.py @@ -4,8 +4,8 @@ from .acknowledgmentsoptions import AcknowledgmentsOptions from .authenticationmethodoptionsapi import AuthenticationMethodOptionsAPI from .authenticationmethodoptionsauth import AuthenticationMethodOptionsAuth -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionsautosecret import AuthenticationMethodOptionsAutoSecret from .authenticationmethodoptionss3collectorconf import ( @@ -42,7 +42,6 @@ ) from .dataformatoptions import DataFormatOptions from .datapageversionoptions import DataPageVersionOptions -from .destinationprotocoloptions import DestinationProtocolOptions from .diskspaceprotectionoptions import DiskSpaceProtectionOptions from .extrahttpheaderconfinputelastic import ( ExtraHTTPHeaderConfInputElastic, @@ -62,7 +61,7 @@ MicrosoftEntraIDAuthenticationEndpointOptionsSasl, ) from .modeoptions import ModeOptions -from .notification_union import NotificationUnion, NotificationUnionTypedDict +from .notification import Notification, NotificationTypedDict from .oauthheaderconfinputservicenowtable import ( OauthHeaderConfInputServicenowTable, OauthHeaderConfInputServicenowTableTypedDict, @@ -145,21 +144,35 @@ from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict -class OutputResponseOutputIbmCloudS3Type(str, Enum): +class OutputResponseOutputDatabricksZerobusType(str, Enum): r"""Connector type identifier.""" - IBM_CLOUD_S3 = "ibm_cloud_s3" + DATABRICKS_ZEROBUS = "databricks_zerobus" -class OutputResponseOutputIbmCloudS3TypedDict(TypedDict): - type: OutputResponseOutputIbmCloudS3Type +class OutputResponseOutputDatabricksZerobusPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputDatabricksZerobusPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputDatabricksZerobusTypedDict(TypedDict): + type: OutputResponseOutputDatabricksZerobusType r"""Connector type identifier.""" - endpoint: str - r"""IBM Cloud Object Storage S3-compatible endpoint URL (example: https://s3.us-south.cloud-object-storage.appdomain.cloud)""" - bucket: str - r"""Name of the destination IBM Cloud Object Storage bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + workspace_url: str + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" + workspace_id: str + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" + zerobus_endpoint: str + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + client_id: str + r"""OAuth client ID of the service principal authorized to write to the target table""" + client_text_secret: str + r"""OAuth client secret of the service principal""" + table_name: str + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -170,133 +183,79 @@ class OutputResponseOutputIbmCloudS3TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsSecret] - r"""Authentication method.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + max_batch_size_kb: NotRequired[int] + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" + max_batch_records: NotRequired[int] + r"""Maximum number of records to include in a single ingest batch""" + max_buffered_kb: NotRequired[int] + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" + max_inflight_batches: NotRequired[int] + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" + flush_period_sec: NotRequired[int] + r"""Maximum time, in seconds, to hold a batch before sending it""" + ack_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" + connection_timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputDatabricksZerobusPqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputIbmCloudS3(BaseModel): - type: OutputResponseOutputIbmCloudS3Type +class OutputResponseOutputDatabricksZerobus(BaseModel): + type: OutputResponseOutputDatabricksZerobusType r"""Connector type identifier.""" - endpoint: str - r"""IBM Cloud Object Storage S3-compatible endpoint URL (example: https://s3.us-south.cloud-object-storage.appdomain.cloud)""" + workspace_url: Annotated[str, pydantic.Field(alias="workspaceUrl")] + r"""HTTPS URL of the Databricks Workspace, used for OAuth token exchange (example: https://dbc-1234abcd-5e6f.cloud.databricks.com). Must start with https://""" - bucket: str - r"""Name of the destination IBM Cloud Object Storage bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + workspace_id: Annotated[str, pydantic.Field(alias="workspaceId")] + r"""Unique identifier for the Databricks Workspace. Scopes the OAuth token to this Workspace.""" - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + zerobus_endpoint: Annotated[str, pydantic.Field(alias="zerobusEndpoint")] + r"""Hostname of the Workspace Zerobus ingest endpoint. Omit the scheme, port, and path (example: 1234567890.zerobus.us-west-2.cloud.databricks.com).""" + + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""OAuth client ID of the service principal authorized to write to the target table""" + + client_text_secret: Annotated[str, pydantic.Field(alias="clientTextSecret")] + r"""OAuth client secret of the service principal""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Three-part Unity Catalog name of the target table: catalog.schema.table""" id: Optional[str] = None r"""Unique ID for this output""" @@ -315,346 +274,152 @@ class OutputResponseOutputIbmCloudS3(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsSecret], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""Authentication method.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + max_batch_size_kb: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchSizeKB") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum size, in KB, of the serialized records in a single ingest batch""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + max_batch_records: Annotated[ + Optional[int], pydantic.Field(alias="maxBatchRecords") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Maximum number of records to include in a single ingest batch""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_buffered_kb: Annotated[Optional[int], pydantic.Field(alias="maxBufferedKB")] = ( + None + ) + r"""Maximum size, in KB, of unacknowledged records per Worker Process before blocking. Must be at least the configured Batch size limit. Records larger than this limit are dropped.""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + max_inflight_batches: Annotated[ + Optional[int], pydantic.Field(alias="maxInflightBatches") ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + r"""Maximum number of unacknowledged batches per Worker Process before blocking""" - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") + flush_period_sec: Annotated[ + Optional[int], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + r"""Maximum time, in seconds, to hold a batch before sending it""" - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + ack_timeout_sec: Annotated[Optional[int], pydantic.Field(alias="ackTimeoutSec")] = ( + None + ) + r"""Amount of time, in seconds, to wait for Databricks to acknowledge sent batches before reconnecting""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + connection_timeout_sec: Annotated[ + Optional[int], pydantic.Field(alias="connectionTimeoutSec") ] = None - r"""Add the Output ID value to staging location""" + r"""Amount of time, in seconds, to wait for a new ingest stream to open before canceling it""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + r"""How to handle events when all receivers are exerting backpressure""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None - r"""Buffer size used to write to a file""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""Codec to use to compress the persisted data""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + pq_controls: Annotated[ + Optional[OutputResponseOutputDatabricksZerobusPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + r"""Persistent queue controls.""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsSecret(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -668,61 +433,29 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", + "maxBatchSizeKB", + "maxBatchRecords", + "maxBufferedKB", + "maxInflightBatches", + "flushPeriodSec", + "ackTimeoutSec", + "connectionTimeoutSec", "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", "description", - "awsSecret", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_endpoint", - "__template_bucket", - "__template_destPath", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", "notifications", "status", ] @@ -741,32 +474,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputAlibabaCloudS3Type(str, Enum): +class OutputResponseOutputIbmCloudS3Type(str, Enum): r"""Connector type identifier.""" - ALIBABA_CLOUD_S3 = "alibaba_cloud_s3" - - -class OutputResponseOutputAlibabaCloudS3AuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method.""" - - # Auto - AUTO = "auto" - # Secret - SECRET = "secret" + IBM_CLOUD_S3 = "ibm_cloud_s3" -class OutputResponseOutputAlibabaCloudS3TypedDict(TypedDict): - type: OutputResponseOutputAlibabaCloudS3Type +class OutputResponseOutputIbmCloudS3TypedDict(TypedDict): + type: OutputResponseOutputIbmCloudS3Type r"""Connector type identifier.""" + endpoint: str + r"""IBM Cloud Object Storage S3-compatible endpoint URL (example: https://s3.us-south.cloud-object-storage.appdomain.cloud)""" bucket: str - r"""Name of the destination Alibaba OSS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination IBM Cloud Object Storage bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Alibaba OSS S3-compatible endpoint URL. Examples: public `https://s3.oss-{region}.aliyuncs.com`, internal `https://s3.oss-{region}-internal.aliyuncs.com`""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -777,9 +499,7 @@ class OutputResponseOutputAlibabaCloudS3TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[ - OutputResponseOutputAlibabaCloudS3AuthenticationMethod - ] + aws_authentication_method: NotRequired[AuthenticationMethodOptionsSecret] r"""Authentication method.""" reuse_connections: NotRequired[bool] r"""Reuse connections between requests, which can improve performance""" @@ -828,16 +548,6 @@ class OutputResponseOutputAlibabaCloudS3TypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Alibaba OSS""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - assume_role_arn: NotRequired[str] - r"""ARN of the RAM role to assume. Format: acs:ram:::role/. Example: acs:ram::123456789:role/OSSAccessRole""" - assume_role_external_id: NotRequired[str] - r"""External ID for the assumed role (optional, for security when configured in the role trust policy)""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_secret: NotRequired[str] @@ -878,6 +588,8 @@ class OutputResponseOutputAlibabaCloudS3TypedDict(TypedDict): r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_dest_path: NotRequired[str] @@ -892,37 +604,29 @@ class OutputResponseOutputAlibabaCloudS3TypedDict(TypedDict): r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputAlibabaCloudS3(BaseModel): - type: OutputResponseOutputAlibabaCloudS3Type +class OutputResponseOutputIbmCloudS3(BaseModel): + type: OutputResponseOutputIbmCloudS3Type r"""Connector type identifier.""" + endpoint: str + r"""IBM Cloud Object Storage S3-compatible endpoint URL (example: https://s3.us-south.cloud-object-storage.appdomain.cloud)""" + bucket: str - r"""Name of the destination Alibaba OSS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination IBM Cloud Object Storage bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Alibaba OSS S3-compatible endpoint URL. Examples: public `https://s3.oss-{region}.aliyuncs.com`, internal `https://s3.oss-{region}-internal.aliyuncs.com`""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -941,7 +645,7 @@ class OutputResponseOutputAlibabaCloudS3(BaseModel): r"""Metadata tags used for categorization and filtering.""" aws_authentication_method: Annotated[ - Optional[OutputResponseOutputAlibabaCloudS3AuthenticationMethod], + Optional[AuthenticationMethodOptionsSecret], pydantic.Field(alias="awsAuthenticationMethod"), ] = None r"""Authentication method.""" @@ -1061,31 +765,6 @@ class OutputResponseOutputAlibabaCloudS3(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Alibaba OSS""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""ARN of the RAM role to assume. Format: acs:ram:::role/. Example: acs:ram::123456789:role/OSSAccessRole""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID for the assumed role (optional, for security when configured in the role trust policy)""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -1181,6 +860,11 @@ class OutputResponseOutputAlibabaCloudS3(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_bucket: Annotated[ Optional[str], pydantic.Field(alias="__template_bucket") ] = None @@ -1216,26 +900,6 @@ class OutputResponseOutputAlibabaCloudS3(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_compress: Annotated[ Optional[str], pydantic.Field(alias="__template_compress") ] = None @@ -1246,7 +910,7 @@ class OutputResponseOutputAlibabaCloudS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -1256,9 +920,7 @@ class OutputResponseOutputAlibabaCloudS3(BaseModel): def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputAlibabaCloudS3AuthenticationMethod( - value - ) + return models.AuthenticationMethodOptionsSecret(value) except ValueError: return value return value @@ -1290,15 +952,6 @@ def serialize_on_disk_full_backpressure(self, value): return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): - if isinstance(value, str): - try: - return models.ObjectACLOptions(value) - except ValueError: - return value - return value - @field_serializer("compress") def serialize_compress(self, value): if isinstance(value, str): @@ -1369,11 +1022,6 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "objectACL", - "enableAssumeRole", - "durationSeconds", - "assumeRoleArn", - "assumeRoleExternalId", "description", "awsSecret", "compress", @@ -1394,6 +1042,7 @@ def serialize_model(self, handler): "deadletterPath", "maxRetryNum", "__template_streamtags", + "__template_endpoint", "__template_bucket", "__template_destPath", "__template_partitionExpr", @@ -1401,10 +1050,6 @@ def serialize_model(self, handler): "__template_baseFileName", "__template_fileNameSuffix", "__template_onBackpressure", - "__template_objectACL", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", "__template_compress", "__template_parquetSchema", "notifications", @@ -1425,21 +1070,32 @@ def serialize_model(self, handler): return m -class OutputResponseOutputScalityS3Type(str, Enum): +class OutputResponseOutputAlibabaCloudS3Type(str, Enum): r"""Connector type identifier.""" - SCALITY_S3 = "scality_s3" + ALIBABA_CLOUD_S3 = "alibaba_cloud_s3" -class OutputResponseOutputScalityS3TypedDict(TypedDict): - type: OutputResponseOutputScalityS3Type +class OutputResponseOutputAlibabaCloudS3AuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method.""" + + # Auto + AUTO = "auto" + # Secret + SECRET = "secret" + + +class OutputResponseOutputAlibabaCloudS3TypedDict(TypedDict): + type: OutputResponseOutputAlibabaCloudS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination Scality bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Alibaba OSS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" endpoint: str - r"""Scality RING S3-compatible endpoint URL (example: https://s3.scality.example.com)""" + r"""Alibaba OSS S3-compatible endpoint URL. Examples: public `https://s3.oss-{region}.aliyuncs.com`, internal `https://s3.oss-{region}-internal.aliyuncs.com`""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -1450,14 +1106,14 @@ class OutputResponseOutputScalityS3TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsSecret] + aws_authentication_method: NotRequired[ + OutputResponseOutputAlibabaCloudS3AuthenticationMethod + ] r"""Authentication method.""" reuse_connections: NotRequired[bool] r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the Scality bucket is located""" dest_path: NotRequired[str] r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] @@ -1501,6 +1157,16 @@ class OutputResponseOutputScalityS3TypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Alibaba OSS""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + assume_role_arn: NotRequired[str] + r"""ARN of the RAM role to assume. Format: acs:ram:::role/. Example: acs:ram::123456789:role/OSSAccessRole""" + assume_role_external_id: NotRequired[str] + r"""External ID for the assumed role (optional, for security when configured in the role trust policy)""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_secret: NotRequired[str] @@ -1543,8 +1209,6 @@ class OutputResponseOutputScalityS3TypedDict(TypedDict): r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_dest_path: NotRequired[str] r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" template_partition_expr: NotRequired[str] @@ -1557,30 +1221,36 @@ class OutputResponseOutputScalityS3TypedDict(TypedDict): r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" template_endpoint: NotRequired[str] r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputScalityS3(BaseModel): - type: OutputResponseOutputScalityS3Type +class OutputResponseOutputAlibabaCloudS3(BaseModel): + type: OutputResponseOutputAlibabaCloudS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination Scality bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Alibaba OSS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" endpoint: str - r"""Scality RING S3-compatible endpoint URL (example: https://s3.scality.example.com)""" + r"""Alibaba OSS S3-compatible endpoint URL. Examples: public `https://s3.oss-{region}.aliyuncs.com`, internal `https://s3.oss-{region}-internal.aliyuncs.com`""" id: Optional[str] = None r"""Unique ID for this output""" @@ -1600,7 +1270,7 @@ class OutputResponseOutputScalityS3(BaseModel): r"""Metadata tags used for categorization and filtering.""" aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsSecret], + Optional[OutputResponseOutputAlibabaCloudS3AuthenticationMethod], pydantic.Field(alias="awsAuthenticationMethod"), ] = None r"""Authentication method.""" @@ -1615,9 +1285,6 @@ class OutputResponseOutputScalityS3(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: Optional[str] = None - r"""Region where the Scality bucket is located""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" @@ -1723,24 +1390,49 @@ class OutputResponseOutputScalityS3(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + ] = None + r"""Object ACL to assign to uploaded objects""" - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Use Assume Role credentials to access Alibaba OSS""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""ARN of the RAM role to assume. Format: acs:ram:::role/. Example: acs:ram::123456789:role/OSSAccessRole""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID for the assumed role (optional, for security when configured in the role trust policy)""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" + + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") + ] = None + r"""Automatically calculate the schema based on the events of each Parquet file generated""" parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( None @@ -1823,11 +1515,6 @@ class OutputResponseOutputScalityS3(BaseModel): ] = None r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: Annotated[ Optional[str], pydantic.Field(alias="__template_destPath") ] = None @@ -1858,11 +1545,26 @@ class OutputResponseOutputScalityS3(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_endpoint: Annotated[ Optional[str], pydantic.Field(alias="__template_endpoint") ] = None r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_compress: Annotated[ Optional[str], pydantic.Field(alias="__template_compress") ] = None @@ -1873,7 +1575,7 @@ class OutputResponseOutputScalityS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -1883,7 +1585,9 @@ class OutputResponseOutputScalityS3(BaseModel): def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsSecret(value) + return models.OutputResponseOutputAlibabaCloudS3AuthenticationMethod( + value + ) except ValueError: return value return value @@ -1915,6 +1619,15 @@ def serialize_on_disk_full_backpressure(self, value): return value return value + @field_serializer("object_acl") + def serialize_object_acl(self, value): + if isinstance(value, str): + try: + return models.ObjectACLOptions(value) + except ValueError: + return value + return value + @field_serializer("compress") def serialize_compress(self, value): if isinstance(value, str): @@ -1963,7 +1676,6 @@ def serialize_model(self, handler): "awsAuthenticationMethod", "reuseConnections", "rejectUnauthorized", - "region", "destPath", "maxConcurrentFileParts", "verifyPermissions", @@ -1986,6 +1698,11 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", + "objectACL", + "enableAssumeRole", + "durationSeconds", + "assumeRoleArn", + "assumeRoleExternalId", "description", "awsSecret", "compress", @@ -2007,14 +1724,16 @@ def serialize_model(self, handler): "maxRetryNum", "__template_streamtags", "__template_bucket", - "__template_region", "__template_destPath", "__template_partitionExpr", "__template_format", "__template_baseFileName", "__template_fileNameSuffix", "__template_onBackpressure", + "__template_objectACL", "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_compress", "__template_parquetSchema", "notifications", @@ -2035,21 +1754,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCloudianS3Type(str, Enum): +class OutputResponseOutputScalityS3Type(str, Enum): r"""Connector type identifier.""" - CLOUDIAN_S3 = "cloudian_s3" + SCALITY_S3 = "scality_s3" -class OutputResponseOutputCloudianS3TypedDict(TypedDict): - type: OutputResponseOutputCloudianS3Type +class OutputResponseOutputScalityS3TypedDict(TypedDict): + type: OutputResponseOutputScalityS3Type r"""Connector type identifier.""" - endpoint: str - r"""Cloudian HyperStore S3-compatible endpoint URL (example: https://s3.hyperstore.example.com)""" bucket: str - r"""Name of the destination Cloudian bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Scality bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Scality RING S3-compatible endpoint URL (example: https://s3.scality.example.com)""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -2067,7 +1786,7 @@ class OutputResponseOutputCloudianS3TypedDict(TypedDict): reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" region: NotRequired[str] - r"""Region where the Cloudian bucket is located""" + r"""Region where the Scality bucket is located""" dest_path: NotRequired[str] r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] @@ -2111,14 +1830,6 @@ class OutputResponseOutputCloudianS3TypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_secret: NotRequired[str] @@ -2159,8 +1870,6 @@ class OutputResponseOutputCloudianS3TypedDict(TypedDict): r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: NotRequired[str] @@ -2177,37 +1886,31 @@ class OutputResponseOutputCloudianS3TypedDict(TypedDict): r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputCloudianS3(BaseModel): - type: OutputResponseOutputCloudianS3Type +class OutputResponseOutputScalityS3(BaseModel): + type: OutputResponseOutputScalityS3Type r"""Connector type identifier.""" - endpoint: str - r"""Cloudian HyperStore S3-compatible endpoint URL (example: https://s3.hyperstore.example.com)""" - bucket: str - r"""Name of the destination Cloudian bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Scality bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Scality RING S3-compatible endpoint URL (example: https://s3.scality.example.com)""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -2242,7 +1945,7 @@ class OutputResponseOutputCloudianS3(BaseModel): r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" region: Optional[str] = None - r"""Region where the Cloudian bucket is located""" + r"""Region where the Scality bucket is located""" dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" @@ -2349,25 +2052,6 @@ class OutputResponseOutputCloudianS3(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" - - storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") - ] = None - r"""Storage class to select for uploaded objects""" - - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), - ] = None - r"""Server-side encryption to use for uploaded objects""" - - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -2463,11 +2147,6 @@ class OutputResponseOutputCloudianS3(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_bucket: Annotated[ Optional[str], pydantic.Field(alias="__template_bucket") ] = None @@ -2508,25 +2187,10 @@ class OutputResponseOutputCloudianS3(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") - ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_compress: Annotated[ Optional[str], pydantic.Field(alias="__template_compress") @@ -2538,7 +2202,7 @@ class OutputResponseOutputCloudianS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -2580,33 +2244,6 @@ def serialize_on_disk_full_backpressure(self, value): return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): - if isinstance(value, str): - try: - return models.ObjectACLOptions(value) - except ValueError: - return value - return value - - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptions(value) - except ValueError: - return value - return value - - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): - if isinstance(value, str): - try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) - except ValueError: - return value - return value - @field_serializer("compress") def serialize_compress(self, value): if isinstance(value, str): @@ -2678,10 +2315,6 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "objectACL", - "storageClass", - "serverSideEncryption", - "kmsKeyId", "description", "awsSecret", "compress", @@ -2702,7 +2335,6 @@ def serialize_model(self, handler): "deadletterPath", "maxRetryNum", "__template_streamtags", - "__template_endpoint", "__template_bucket", "__template_region", "__template_destPath", @@ -2711,10 +2343,7 @@ def serialize_model(self, handler): "__template_baseFileName", "__template_fileNameSuffix", "__template_onBackpressure", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", + "__template_endpoint", "__template_compress", "__template_parquetSchema", "notifications", @@ -2735,21 +2364,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDellS3Type(str, Enum): +class OutputResponseOutputCloudianS3Type(str, Enum): r"""Connector type identifier.""" - DELL_S3 = "dell_s3" + CLOUDIAN_S3 = "cloudian_s3" -class OutputResponseOutputDellS3TypedDict(TypedDict): - type: OutputResponseOutputDellS3Type +class OutputResponseOutputCloudianS3TypedDict(TypedDict): + type: OutputResponseOutputCloudianS3Type r"""Connector type identifier.""" + endpoint: str + r"""Cloudian HyperStore S3-compatible endpoint URL (example: https://s3.hyperstore.example.com)""" bucket: str - r"""Name of the destination Dell PowerScale OneFS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Cloudian bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Dell PowerScale OneFS S3-compatible endpoint URL (example: https://powerscale.example.com:9021)""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -2767,7 +2396,7 @@ class OutputResponseOutputDellS3TypedDict(TypedDict): reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" region: NotRequired[str] - r"""Region where the Dell PowerScale OneFS bucket is located""" + r"""Region where the Cloudian bucket is located""" dest_path: NotRequired[str] r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] @@ -2813,6 +2442,12 @@ class OutputResponseOutputDellS3TypedDict(TypedDict): r"""Orphan file recovery""" object_acl: NotRequired[ObjectACLOptions] r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_secret: NotRequired[str] @@ -2853,6 +2488,8 @@ class OutputResponseOutputDellS3TypedDict(TypedDict): r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: NotRequired[str] @@ -2871,31 +2508,35 @@ class OutputResponseOutputDellS3TypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_object_acl: NotRequired[str] r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputDellS3(BaseModel): - type: OutputResponseOutputDellS3Type +class OutputResponseOutputCloudianS3(BaseModel): + type: OutputResponseOutputCloudianS3Type r"""Connector type identifier.""" + endpoint: str + r"""Cloudian HyperStore S3-compatible endpoint URL (example: https://s3.hyperstore.example.com)""" + bucket: str - r"""Name of the destination Dell PowerScale OneFS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Cloudian bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Dell PowerScale OneFS S3-compatible endpoint URL (example: https://powerscale.example.com:9021)""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -2930,7 +2571,7 @@ class OutputResponseOutputDellS3(BaseModel): r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" region: Optional[str] = None - r"""Region where the Dell PowerScale OneFS bucket is located""" + r"""Region where the Cloudian bucket is located""" dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" @@ -3042,8 +2683,22 @@ class OutputResponseOutputDellS3(BaseModel): ] = None r"""Object ACL to assign to uploaded objects""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + ] = None + r"""Storage class to select for uploaded objects""" + + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" + + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None r"""Select or create a stored secret that references your access key and secret key""" @@ -3137,6 +2792,11 @@ class OutputResponseOutputDellS3(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_bucket: Annotated[ Optional[str], pydantic.Field(alias="__template_bucket") ] = None @@ -3182,10 +2842,20 @@ class OutputResponseOutputDellS3(BaseModel): ] = None r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + ] = None + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") + ] = None + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" template_compress: Annotated[ Optional[str], pydantic.Field(alias="__template_compress") @@ -3197,7 +2867,7 @@ class OutputResponseOutputDellS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -3248,6 +2918,24 @@ def serialize_object_acl(self, value): return value return value + @field_serializer("storage_class") + def serialize_storage_class(self, value): + if isinstance(value, str): + try: + return models.StorageClassOptions(value) + except ValueError: + return value + return value + + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): + if isinstance(value, str): + try: + return models.ServerSideEncryptionForUploadedObjectsOptions(value) + except ValueError: + return value + return value + @field_serializer("compress") def serialize_compress(self, value): if isinstance(value, str): @@ -3320,6 +3008,9 @@ def serialize_model(self, handler): "retrySettings", "orphans", "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", "description", "awsSecret", "compress", @@ -3340,6 +3031,7 @@ def serialize_model(self, handler): "deadletterPath", "maxRetryNum", "__template_streamtags", + "__template_endpoint", "__template_bucket", "__template_region", "__template_destPath", @@ -3349,7 +3041,9 @@ def serialize_model(self, handler): "__template_fileNameSuffix", "__template_onBackpressure", "__template_objectACL", - "__template_endpoint", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", "__template_compress", "__template_parquetSchema", "notifications", @@ -3370,19 +3064,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputAlphasocS3Type(str, Enum): +class OutputResponseOutputDellS3Type(str, Enum): r"""Connector type identifier.""" - ALPHASOC_S3 = "alphasoc_s3" + DELL_S3 = "dell_s3" -class OutputResponseOutputAlphasocS3TypedDict(TypedDict): - type: OutputResponseOutputAlphasocS3Type +class OutputResponseOutputDellS3TypedDict(TypedDict): + type: OutputResponseOutputDellS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination AlphaSOC bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Dell PowerScale OneFS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Dell PowerScale OneFS S3-compatible endpoint URL (example: https://powerscale.example.com:9021)""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -3399,6 +3095,8 @@ class OutputResponseOutputAlphasocS3TypedDict(TypedDict): r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the Dell PowerScale OneFS bucket is located""" dest_path: NotRequired[str] r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] @@ -3442,8 +3140,8 @@ class OutputResponseOutputAlphasocS3TypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - endpoint: NotRequired[str] - r"""AlphaSOC S3-compatible endpoint URL (example: https://s3.alphasoc.net)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_secret: NotRequired[str] @@ -3486,8 +3184,12 @@ class OutputResponseOutputAlphasocS3TypedDict(TypedDict): r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_dest_path: NotRequired[str] r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" template_format: NotRequired[str] r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_base_file_name: NotRequired[str] @@ -3496,28 +3198,33 @@ class OutputResponseOutputAlphasocS3TypedDict(TypedDict): r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" template_endpoint: NotRequired[str] r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputAlphasocS3(BaseModel): - type: OutputResponseOutputAlphasocS3Type +class OutputResponseOutputDellS3(BaseModel): + type: OutputResponseOutputDellS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination AlphaSOC bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Dell PowerScale OneFS bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Dell PowerScale OneFS S3-compatible endpoint URL (example: https://powerscale.example.com:9021)""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -3551,6 +3258,9 @@ class OutputResponseOutputAlphasocS3(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: Optional[str] = None + r"""Region where the Dell PowerScale OneFS bucket is located""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" @@ -3656,8 +3366,10 @@ class OutputResponseOutputAlphasocS3(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - endpoint: Optional[str] = None - r"""AlphaSOC S3-compatible endpoint URL (example: https://s3.alphasoc.net)""" + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + ] = None + r"""Object ACL to assign to uploaded objects""" description: Optional[str] = None r"""Optional description for this configuration.""" @@ -3759,11 +3471,21 @@ class OutputResponseOutputAlphasocS3(BaseModel): ] = None r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: Annotated[ Optional[str], pydantic.Field(alias="__template_destPath") ] = None r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: Annotated[ Optional[str], pydantic.Field(alias="__template_format") ] = None @@ -3784,6 +3506,11 @@ class OutputResponseOutputAlphasocS3(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_endpoint: Annotated[ Optional[str], pydantic.Field(alias="__template_endpoint") ] = None @@ -3799,7 +3526,7 @@ class OutputResponseOutputAlphasocS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -3841,6 +3568,15 @@ def serialize_on_disk_full_backpressure(self, value): return value return value + @field_serializer("object_acl") + def serialize_object_acl(self, value): + if isinstance(value, str): + try: + return models.ObjectACLOptions(value) + except ValueError: + return value + return value + @field_serializer("compress") def serialize_compress(self, value): if isinstance(value, str): @@ -3889,6 +3625,7 @@ def serialize_model(self, handler): "awsAuthenticationMethod", "reuseConnections", "rejectUnauthorized", + "region", "destPath", "maxConcurrentFileParts", "verifyPermissions", @@ -3911,7 +3648,7 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "endpoint", + "objectACL", "description", "awsSecret", "compress", @@ -3933,11 +3670,14 @@ def serialize_model(self, handler): "maxRetryNum", "__template_streamtags", "__template_bucket", + "__template_region", "__template_destPath", + "__template_partitionExpr", "__template_format", "__template_baseFileName", "__template_fileNameSuffix", "__template_onBackpressure", + "__template_objectACL", "__template_endpoint", "__template_compress", "__template_parquetSchema", @@ -3959,21 +3699,19 @@ def serialize_model(self, handler): return m -class OutputResponseOutputStorjS3Type(str, Enum): +class OutputResponseOutputAlphasocS3Type(str, Enum): r"""Connector type identifier.""" - STORJ_S3 = "storj_s3" + ALPHASOC_S3 = "alphasoc_s3" -class OutputResponseOutputStorjS3TypedDict(TypedDict): - type: OutputResponseOutputStorjS3Type +class OutputResponseOutputAlphasocS3TypedDict(TypedDict): + type: OutputResponseOutputAlphasocS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination Storj bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination AlphaSOC bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Storj S3-compatible gateway endpoint URL (example: https://gateway.storjshare.io)""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -4033,6 +3771,8 @@ class OutputResponseOutputStorjS3TypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" + endpoint: NotRequired[str] + r"""AlphaSOC S3-compatible endpoint URL (example: https://s3.alphasoc.net)""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_secret: NotRequired[str] @@ -4077,8 +3817,6 @@ class OutputResponseOutputStorjS3TypedDict(TypedDict): r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_dest_path: NotRequired[str] r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" template_format: NotRequired[str] r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_base_file_name: NotRequired[str] @@ -4093,25 +3831,22 @@ class OutputResponseOutputStorjS3TypedDict(TypedDict): r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputStorjS3(BaseModel): - type: OutputResponseOutputStorjS3Type +class OutputResponseOutputAlphasocS3(BaseModel): + type: OutputResponseOutputAlphasocS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination Storj bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination AlphaSOC bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Storj S3-compatible gateway endpoint URL (example: https://gateway.storjshare.io)""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -4250,6 +3985,9 @@ class OutputResponseOutputStorjS3(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" + endpoint: Optional[str] = None + r"""AlphaSOC S3-compatible endpoint URL (example: https://s3.alphasoc.net)""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -4355,11 +4093,6 @@ class OutputResponseOutputStorjS3(BaseModel): ] = None r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: Annotated[ Optional[str], pydantic.Field(alias="__template_format") ] = None @@ -4395,7 +4128,7 @@ class OutputResponseOutputStorjS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -4507,6 +4240,7 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", + "endpoint", "description", "awsSecret", "compress", @@ -4529,7 +4263,6 @@ def serialize_model(self, handler): "__template_streamtags", "__template_bucket", "__template_destPath", - "__template_partitionExpr", "__template_format", "__template_baseFileName", "__template_fileNameSuffix", @@ -4555,21 +4288,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputNutanixObjectsType(str, Enum): +class OutputResponseOutputStorjS3Type(str, Enum): r"""Connector type identifier.""" - NUTANIX_OBJECTS = "nutanix_objects" + STORJ_S3 = "storj_s3" -class OutputResponseOutputNutanixObjectsTypedDict(TypedDict): - type: OutputResponseOutputNutanixObjectsType +class OutputResponseOutputStorjS3TypedDict(TypedDict): + type: OutputResponseOutputStorjS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination Nutanix Objects bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Storj bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" endpoint: str - r"""Nutanix Objects S3-compatible endpoint URL (example: https://objects.nutanix.local)""" + r"""Storj S3-compatible gateway endpoint URL (example: https://gateway.storjshare.io)""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -4586,8 +4319,6 @@ class OutputResponseOutputNutanixObjectsTypedDict(TypedDict): r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the Nutanix Objects bucket is located""" dest_path: NotRequired[str] r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] @@ -4673,8 +4404,6 @@ class OutputResponseOutputNutanixObjectsTypedDict(TypedDict): r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_dest_path: NotRequired[str] r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" template_partition_expr: NotRequired[str] @@ -4693,24 +4422,24 @@ class OutputResponseOutputNutanixObjectsTypedDict(TypedDict): r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputNutanixObjects(BaseModel): - type: OutputResponseOutputNutanixObjectsType +class OutputResponseOutputStorjS3(BaseModel): + type: OutputResponseOutputStorjS3Type r"""Connector type identifier.""" bucket: str - r"""Name of the destination Nutanix Objects bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Storj bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" endpoint: str - r"""Nutanix Objects S3-compatible endpoint URL (example: https://objects.nutanix.local)""" + r"""Storj S3-compatible gateway endpoint URL (example: https://gateway.storjshare.io)""" id: Optional[str] = None r"""Unique ID for this output""" @@ -4745,9 +4474,6 @@ class OutputResponseOutputNutanixObjects(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: Optional[str] = None - r"""Region where the Nutanix Objects bucket is located""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" @@ -4953,11 +4679,6 @@ class OutputResponseOutputNutanixObjects(BaseModel): ] = None r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: Annotated[ Optional[str], pydantic.Field(alias="__template_destPath") ] = None @@ -5003,7 +4724,7 @@ class OutputResponseOutputNutanixObjects(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -5093,7 +4814,6 @@ def serialize_model(self, handler): "awsAuthenticationMethod", "reuseConnections", "rejectUnauthorized", - "region", "destPath", "maxConcurrentFileParts", "verifyPermissions", @@ -5137,7 +4857,6 @@ def serialize_model(self, handler): "maxRetryNum", "__template_streamtags", "__template_bucket", - "__template_region", "__template_destPath", "__template_partitionExpr", "__template_format", @@ -5165,21 +4884,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCloudflareR2Type(str, Enum): +class OutputResponseOutputNutanixObjectsType(str, Enum): r"""Connector type identifier.""" - CLOUDFLARE_R2 = "cloudflare_r2" + NUTANIX_OBJECTS = "nutanix_objects" -class OutputResponseOutputCloudflareR2TypedDict(TypedDict): - type: OutputResponseOutputCloudflareR2Type +class OutputResponseOutputNutanixObjectsTypedDict(TypedDict): + type: OutputResponseOutputNutanixObjectsType r"""Connector type identifier.""" bucket: str - r"""Name of the destination R2 bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Nutanix Objects bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: str r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" endpoint: str - r"""Cloudflare R2 service URL (example: https://.r2.cloudflarestorage.com)""" + r"""Nutanix Objects S3-compatible endpoint URL (example: https://objects.nutanix.local)""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -5190,12 +4909,14 @@ class OutputResponseOutputCloudflareR2TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] - r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsSecret] + r"""Authentication method.""" reuse_connections: NotRequired[bool] r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the Nutanix Objects bucket is located""" dest_path: NotRequired[str] r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" max_concurrent_file_parts: NotRequired[float] @@ -5239,14 +4960,6 @@ class OutputResponseOutputCloudflareR2TypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ - ServerSideEncryptionForUploadedObjectsOptionsAes256 - ] - r"""Server-side encryption to use for uploaded objects""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_secret: NotRequired[str] @@ -5289,6 +5002,8 @@ class OutputResponseOutputCloudflareR2TypedDict(TypedDict): r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_bucket: NotRequired[str] r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_dest_path: NotRequired[str] r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" template_partition_expr: NotRequired[str] @@ -5301,34 +5016,30 @@ class OutputResponseOutputCloudflareR2TypedDict(TypedDict): r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputCloudflareR2(BaseModel): - type: OutputResponseOutputCloudflareR2Type +class OutputResponseOutputNutanixObjects(BaseModel): + type: OutputResponseOutputNutanixObjectsType r"""Connector type identifier.""" bucket: str - r"""Name of the destination R2 bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + r"""Name of the destination Nutanix Objects bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" stage_path: Annotated[str, pydantic.Field(alias="stagePath")] r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" endpoint: str - r"""Cloudflare R2 service URL (example: https://.r2.cloudflarestorage.com)""" + r"""Nutanix Objects S3-compatible endpoint URL (example: https://objects.nutanix.local)""" id: Optional[str] = None r"""Unique ID for this output""" @@ -5348,10 +5059,10 @@ class OutputResponseOutputCloudflareR2(BaseModel): r"""Metadata tags used for categorization and filtering.""" aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsAutoSecret], + Optional[AuthenticationMethodOptionsSecret], pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Authentication method.""" reuse_connections: Annotated[ Optional[bool], pydantic.Field(alias="reuseConnections") @@ -5363,6 +5074,9 @@ class OutputResponseOutputCloudflareR2(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: Optional[str] = None + r"""Region where the Nutanix Objects bucket is located""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" @@ -5468,23 +5182,6 @@ class OutputResponseOutputCloudflareR2(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - - storage_class: Annotated[ - Optional[StorageClassOptionsReducedredundancyStandard], - pydantic.Field(alias="storageClass"), - ] = None - r"""Storage class to select for uploaded objects""" - - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], - pydantic.Field(alias="serverSideEncryption"), - ] = None - r"""Server-side encryption to use for uploaded objects""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -5585,6 +5282,11 @@ class OutputResponseOutputCloudflareR2(BaseModel): ] = None r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: Annotated[ Optional[str], pydantic.Field(alias="__template_destPath") ] = None @@ -5615,20 +5317,10 @@ class OutputResponseOutputCloudflareR2(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" template_compress: Annotated[ Optional[str], pydantic.Field(alias="__template_compress") @@ -5640,7 +5332,7 @@ class OutputResponseOutputCloudflareR2(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -5650,7 +5342,7 @@ class OutputResponseOutputCloudflareR2(BaseModel): def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAutoSecret(value) + return models.AuthenticationMethodOptionsSecret(value) except ValueError: return value return value @@ -5682,24 +5374,6 @@ def serialize_on_disk_full_backpressure(self, value): return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptionsReducedredundancyStandard(value) - except ValueError: - return value - return value - - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): - if isinstance(value, str): - try: - return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) - except ValueError: - return value - return value - @field_serializer("compress") def serialize_compress(self, value): if isinstance(value, str): @@ -5748,6 +5422,7 @@ def serialize_model(self, handler): "awsAuthenticationMethod", "reuseConnections", "rejectUnauthorized", + "region", "destPath", "maxConcurrentFileParts", "verifyPermissions", @@ -5770,9 +5445,6 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "awsSecretKey", - "storageClass", - "serverSideEncryption", "description", "awsSecret", "compress", @@ -5794,15 +5466,14 @@ def serialize_model(self, handler): "maxRetryNum", "__template_streamtags", "__template_bucket", + "__template_region", "__template_destPath", "__template_partitionExpr", "__template_format", "__template_baseFileName", "__template_fileNameSuffix", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_storageClass", - "__template_serverSideEncryption", + "__template_endpoint", "__template_compress", "__template_parquetSchema", "notifications", @@ -5823,482 +5494,492 @@ def serialize_model(self, handler): return m -class OutputResponseOutputMicrosoftFabricType(str, Enum): +class OutputResponseOutputCloudflareR2Type(str, Enum): r"""Connector type identifier.""" - MICROSOFT_FABRIC = "microsoft_fabric" - + CLOUDFLARE_R2 = "cloudflare_r2" -class OutputResponseAuthenticationTypedDict(TypedDict): - r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" - disabled: bool - r"""Disabled""" - mechanism: NotRequired[SaslMechanismOptionsSaslOauthbearerPlain] - r"""SASL mechanism""" - username: NotRequired[str] - r"""The username for authentication. This should always be $ConnectionString.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret corresponding to the SASL JASS Password Primary or Password Secondary""" - client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] - r"""Authentication method""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate_name: NotRequired[str] - r"""Select or create a stored certificate""" - cert_path: NotRequired[str] - priv_key_path: NotRequired[str] - passphrase: NotRequired[str] - oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] - r"""Endpoint used to acquire authentication tokens from Azure""" - client_id: NotRequired[str] - r"""client_id to pass in the OAuth request parameter""" - tenant_id: NotRequired[str] - r"""Directory ID (tenant identifier) in Azure Active Directory""" - scope: NotRequired[str] - r"""Scope to pass in the OAuth request parameter""" - template_mechanism: NotRequired[str] - r"""Binds 'mechanism' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mechanism' at runtime.""" - template_oauth_endpoint: NotRequired[str] - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_scope: NotRequired[str] - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" +class OutputResponseOutputCloudflareR2TypedDict(TypedDict): + type: OutputResponseOutputCloudflareR2Type + r"""Connector type identifier.""" + bucket: str + r"""Name of the destination R2 bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Cloudflare R2 service URL (example: https://.r2.cloudflarestorage.com)""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ + ServerSideEncryptionForUploadedObjectsOptionsAes256 + ] + r"""Server-side encryption to use for uploaded objects""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseAuthentication(BaseModel): - r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" +class OutputResponseOutputCloudflareR2(BaseModel): + type: OutputResponseOutputCloudflareR2Type + r"""Connector type identifier.""" - disabled: bool - r"""Disabled""" + bucket: str + r"""Name of the destination R2 bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - mechanism: Optional[SaslMechanismOptionsSaslOauthbearerPlain] = None - r"""SASL mechanism""" + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - username: Optional[str] = None - r"""The username for authentication. This should always be $ConnectionString.""" + endpoint: str + r"""Cloudflare R2 service URL (example: https://.r2.cloudflarestorage.com)""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret corresponding to the SASL JASS Password Primary or Password Secondary""" + id: Optional[str] = None + r"""Unique ID for this output""" - client_secret_auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuth], - pydantic.Field(alias="clientSecretAuthType"), + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Authentication method""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsAutoSecret], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Select or create a stored text secret""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Select or create a stored certificate""" + r"""Reuse connections between requests, which can improve performance""" - cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - passphrase: Optional[str] = None + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - oauth_endpoint: Annotated[ - Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], - pydantic.Field(alias="oauthEndpoint"), + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Endpoint used to acquire authentication tokens from Azure""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""client_id to pass in the OAuth request parameter""" + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + ] = None + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""Directory ID (tenant identifier) in Azure Active Directory""" + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" - scope: Optional[str] = None - r"""Scope to pass in the OAuth request parameter""" + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" - template_mechanism: Annotated[ - Optional[str], pydantic.Field(alias="__template_mechanism") + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Binds 'mechanism' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mechanism' at runtime.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - template_oauth_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_oauthEndpoint") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - template_scope: Annotated[ - Optional[str], pydantic.Field(alias="__template_scope") + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + r"""Buffer size used to write to a file""" - @field_serializer("mechanism") - def serialize_mechanism(self, value): - if isinstance(value, str): - try: - return models.SaslMechanismOptionsSaslOauthbearerPlain(value) - except ValueError: - return value - return value + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), + ] = None + r"""How to handle events when all receivers are exerting backpressure""" - @field_serializer("client_secret_auth_type") - def serialize_client_secret_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuth(value) - except ValueError: - return value - return value + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - @field_serializer("oauth_endpoint") - def serialize_oauth_endpoint(self, value): - if isinstance(value, str): - try: - return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) - except ValueError: - return value - return value + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "mechanism", - "username", - "textSecret", - "clientSecretAuthType", - "clientTextSecret", - "certificateName", - "certPath", - "privKeyPath", - "passphrase", - "oauthEndpoint", - "clientId", - "tenantId", - "scope", - "__template_mechanism", - "__template_oauthEndpoint", - "__template_clientId", - "__template_tenantId", - "__template_scope", - ] - ) - serialized = handler(self) - m = {} + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - return m + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + storage_class: Annotated[ + Optional[StorageClassOptionsReducedredundancyStandard], + pydantic.Field(alias="storageClass"), + ] = None + r"""Storage class to select for uploaded objects""" -class OutputResponseOutputMicrosoftFabricPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" + description: Optional[str] = None + r"""Optional description for this configuration.""" -class OutputResponseOutputMicrosoftFabricPqControls(BaseModel): - r"""Persistent queue controls.""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" -class OutputResponseOutputMicrosoftFabricTypedDict(TypedDict): - type: OutputResponseOutputMicrosoftFabricType - r"""Connector type identifier.""" - topic: str - r"""Topic name from Fabric Eventstream's endpoint""" - bootstrap_server: str - r"""Bootstrap server from Fabric Eventstream's endpoint""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - ack: NotRequired[AcknowledgmentsOptions] - r"""Control the number of required acknowledgments""" - format_: NotRequired[RecordDataFormatOptions] - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - flush_event_count: NotRequired[float] - r"""Maximum number of events in a batch before forcing a flush""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[OutputResponseAuthenticationTypedDict] - r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeTypedDict] - r"""TLS settings (client side)""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputMicrosoftFabricPqControlsTypedDict] - r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_bootstrap_server: NotRequired[str] - r"""Binds 'bootstrap_server' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bootstrap_server' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class OutputResponseOutputMicrosoftFabric(BaseModel): - type: OutputResponseOutputMicrosoftFabricType - r"""Connector type identifier.""" - - topic: str - r"""Topic name from Fabric Eventstream's endpoint""" + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" - bootstrap_server: str - r"""Bootstrap server from Fabric Eventstream's endpoint""" + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") + ] = None + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - id: Optional[str] = None - r"""Unique ID for this output""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + ] = None + r"""Determines which data types are supported and how they are represented""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") + ] = None + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - ack: Optional[AcknowledgmentsOptions] = None - r"""Control the number of required acknowledgments""" + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - format_: Annotated[ - Optional[RecordDataFormatOptions], pydantic.Field(alias="format") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""Maximum number of events in a batch before forcing a flush""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""How frequently, in seconds, to clean up empty directories""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Maximum time to wait for Kafka to respond to a request""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - sasl: Optional[OutputResponseAuthentication] = None - r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - tls: Optional[TLSSettingsClientSideType] = None - r"""TLS settings (client side)""" + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[OutputResponseOutputMicrosoftFabricPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") - ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_bootstrap_server: Annotated[ - Optional[str], pydantic.Field(alias="__template_bootstrap_server") - ] = None - r"""Binds 'bootstrap_server' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bootstrap_server' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("ack") - def serialize_ack(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AcknowledgmentsOptions(value) + return models.AuthenticationMethodOptionsAutoSecret(value) except ValueError: return value return value @@ -6307,7 +5988,7 @@ def serialize_ack(self, value): def serialize_format_(self, value): if isinstance(value, str): try: - return models.RecordDataFormatOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -6316,34 +5997,70 @@ def serialize_format_(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.StorageClassOptionsReducedredundancyStandard(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -6357,40 +6074,66 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "ack", + "awsAuthenticationMethod", + "reuseConnections", + "rejectUnauthorized", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", "format", - "maxRecordSizeKB", - "flushEventCount", - "flushPeriodSec", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "tls", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "storageClass", + "serverSideEncryption", "description", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_topic", + "__template_bucket", + "__template_destPath", + "__template_partitionExpr", "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", - "__template_bootstrap_server", + "__template_awsSecretKey", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_compress", + "__template_parquetSchema", "notifications", "status", ] @@ -6409,49 +6152,209 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSnowflakeStreamingType(str, Enum): +class OutputResponseOutputMicrosoftFabricType(str, Enum): r"""Connector type identifier.""" - SNOWFLAKE_STREAMING = "snowflake_streaming" - + MICROSOFT_FABRIC = "microsoft_fabric" -class OutputResponsePrivateKeyTypedDict(TypedDict): - r"""Private key""" - key_name: str - r"""Select the stored secret containing the RSA private key (PEM format) for Snowflake key-pair authentication""" +class OutputResponseAuthenticationTypedDict(TypedDict): + r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" + disabled: bool + r"""Disabled""" + mechanism: NotRequired[SaslMechanismOptionsSaslOauthbearerPlain] + r"""SASL mechanism""" + username: NotRequired[str] + r"""The username for authentication. This should always be $ConnectionString.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret corresponding to the SASL JASS Password Primary or Password Secondary""" + client_secret_auth_type: NotRequired[AuthenticationMethodOptionsAuth] + r"""Authentication method""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate_name: NotRequired[str] + r"""Select or create a stored certificate""" + cert_path: NotRequired[str] + priv_key_path: NotRequired[str] + passphrase: NotRequired[str] + oauth_endpoint: NotRequired[MicrosoftEntraIDAuthenticationEndpointOptionsSasl] + r"""Endpoint used to acquire authentication tokens from Azure""" + client_id: NotRequired[str] + r"""client_id to pass in the OAuth request parameter""" + tenant_id: NotRequired[str] + r"""Directory ID (tenant identifier) in Azure Active Directory""" + scope: NotRequired[str] + r"""Scope to pass in the OAuth request parameter""" + template_mechanism: NotRequired[str] + r"""Binds 'mechanism' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mechanism' at runtime.""" + template_oauth_endpoint: NotRequired[str] + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_scope: NotRequired[str] + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" -class OutputResponsePrivateKey(BaseModel): - r"""Private key""" - key_name: Annotated[str, pydantic.Field(alias="keyName")] - r"""Select the stored secret containing the RSA private key (PEM format) for Snowflake key-pair authentication""" +class OutputResponseAuthentication(BaseModel): + r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" + disabled: bool + r"""Disabled""" -class OutputResponseOutputSnowflakeStreamingPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" + mechanism: Optional[SaslMechanismOptionsSaslOauthbearerPlain] = None + r"""SASL mechanism""" + username: Optional[str] = None + r"""The username for authentication. This should always be $ConnectionString.""" -class OutputResponseOutputSnowflakeStreamingPqControls(BaseModel): + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret corresponding to the SASL JASS Password Primary or Password Secondary""" + + client_secret_auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuth], + pydantic.Field(alias="clientSecretAuthType"), + ] = None + r"""Authentication method""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""Select or create a stored certificate""" + + cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None + + priv_key_path: Annotated[Optional[str], pydantic.Field(alias="privKeyPath")] = None + + passphrase: Optional[str] = None + + oauth_endpoint: Annotated[ + Optional[MicrosoftEntraIDAuthenticationEndpointOptionsSasl], + pydantic.Field(alias="oauthEndpoint"), + ] = None + r"""Endpoint used to acquire authentication tokens from Azure""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""client_id to pass in the OAuth request parameter""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""Directory ID (tenant identifier) in Azure Active Directory""" + + scope: Optional[str] = None + r"""Scope to pass in the OAuth request parameter""" + + template_mechanism: Annotated[ + Optional[str], pydantic.Field(alias="__template_mechanism") + ] = None + r"""Binds 'mechanism' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mechanism' at runtime.""" + + template_oauth_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_oauthEndpoint") + ] = None + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_scope: Annotated[ + Optional[str], pydantic.Field(alias="__template_scope") + ] = None + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + + @field_serializer("mechanism") + def serialize_mechanism(self, value): + if isinstance(value, str): + try: + return models.SaslMechanismOptionsSaslOauthbearerPlain(value) + except ValueError: + return value + return value + + @field_serializer("client_secret_auth_type") + def serialize_client_secret_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuth(value) + except ValueError: + return value + return value + + @field_serializer("oauth_endpoint") + def serialize_oauth_endpoint(self, value): + if isinstance(value, str): + try: + return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "mechanism", + "username", + "textSecret", + "clientSecretAuthType", + "clientTextSecret", + "certificateName", + "certPath", + "privKeyPath", + "passphrase", + "oauthEndpoint", + "clientId", + "tenantId", + "scope", + "__template_mechanism", + "__template_oauthEndpoint", + "__template_clientId", + "__template_tenantId", + "__template_scope", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputMicrosoftFabricPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSnowflakeStreamingTypedDict(TypedDict): - type: OutputResponseOutputSnowflakeStreamingType +class OutputResponseOutputMicrosoftFabricPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputMicrosoftFabricTypedDict(TypedDict): + type: OutputResponseOutputMicrosoftFabricType r"""Connector type identifier.""" - account_identifier: str - r"""Snowflake account identifier in org-account format (example: MYORG-MYACCOUNT)""" - user: str - r"""Snowflake user with key-pair authentication configured""" - pem: OutputResponsePrivateKeyTypedDict - r"""Private key""" - database: str - r"""Target database""" - schema_: str - r"""Target schema""" - table: str - r"""Target table""" + topic: str + r"""Topic name from Fabric Eventstream's endpoint""" + bootstrap_server: str + r"""Bootstrap server from Fabric Eventstream's endpoint""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -6462,46 +6365,36 @@ class OutputResponseOutputSnowflakeStreamingTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - url: NotRequired[str] - r"""Override endpoint URL (for PrivateLink or custom deployments). Defaults to https://.snowflakecomputing.com:443""" - role: NotRequired[str] - r"""Snowflake role to assume for this connection""" - keep_alive: NotRequired[bool] - r"""Keep connections open between requests. Disable only if experiencing connection pooling issues.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum uncompressed size of each batch. With compression enabled (default), batches are zstd-compressed before sending. Snowflake has observed a ~4 MB limit on the compressed wire size.""" - max_payload_events: NotRequired[float] - r"""Maximum number of events per request. Default is 0 (unlimited, size-gated only).""" - compress: NotRequired[bool] - r"""Compress the payload body using zstd compression before sending.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + ack: NotRequired[AcknowledgmentsOptions] + r"""Control the number of required acknowledgments""" + format_: NotRequired[RecordDataFormatOptions] + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" + max_record_size_kb: NotRequired[float] + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" + flush_event_count: NotRequired[float] + r"""Maximum number of events in a batch before forcing a flush""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - control_request_timeout_sec: NotRequired[float] - r"""Timeout in seconds for token exchange, channel open/close, and hostname discovery. Defaults to 30 seconds.""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[OutputResponseAuthenticationTypedDict] + r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeTypedDict] + r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] @@ -6528,55 +6421,33 @@ class OutputResponseOutputSnowflakeStreamingTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSnowflakeStreamingPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputMicrosoftFabricPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_account_identifier: NotRequired[str] - r"""Binds 'accountIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountIdentifier' at runtime.""" - template_user: NotRequired[str] - r"""Binds 'user' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'user' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_schema: NotRequired[str] - r"""Binds 'schema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'schema' at runtime.""" - template_table: NotRequired[str] - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_role: NotRequired[str] - r"""Binds 'role' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'role' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_bootstrap_server: NotRequired[str] + r"""Binds 'bootstrap_server' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bootstrap_server' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSnowflakeStreaming(BaseModel): - type: OutputResponseOutputSnowflakeStreamingType +class OutputResponseOutputMicrosoftFabric(BaseModel): + type: OutputResponseOutputMicrosoftFabricType r"""Connector type identifier.""" - account_identifier: Annotated[str, pydantic.Field(alias="accountIdentifier")] - r"""Snowflake account identifier in org-account format (example: MYORG-MYACCOUNT)""" + topic: str + r"""Topic name from Fabric Eventstream's endpoint""" - user: str - r"""Snowflake user with key-pair authentication configured""" - - pem: OutputResponsePrivateKey - r"""Private key""" - - database: str - r"""Target database""" - - schema_: Annotated[str, pydantic.Field(alias="schema")] - r"""Target schema""" - - table: str - r"""Target table""" + bootstrap_server: str + r"""Bootstrap server from Fabric Eventstream's endpoint""" id: Optional[str] = None r"""Unique ID for this output""" @@ -6595,88 +6466,68 @@ class OutputResponseOutputSnowflakeStreaming(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - url: Optional[str] = None - r"""Override endpoint URL (for PrivateLink or custom deployments). Defaults to https://.snowflakecomputing.com:443""" - - role: Optional[str] = None - r"""Snowflake role to assume for this connection""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Keep connections open between requests. Disable only if experiencing connection pooling issues.""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum uncompressed size of each batch. With compression enabled (default), batches are zstd-compressed before sending. Snowflake has observed a ~4 MB limit on the compressed wire size.""" + ack: Optional[AcknowledgmentsOptions] = None + r"""Control the number of required acknowledgments""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + format_: Annotated[ + Optional[RecordDataFormatOptions], pydantic.Field(alias="format") ] = None - r"""Maximum number of events per request. Default is 0 (unlimited, size-gated only).""" - - compress: Optional[bool] = None - r"""Compress the payload body using zstd compression before sending.""" + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of events in a batch before forcing a flush""" flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Headers to add to all events""" + r"""Maximum time to wait for a connection to complete successfully""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Maximum time to wait for Kafka to respond to a request""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - control_request_timeout_sec: Annotated[ - Optional[float], pydantic.Field(alias="controlRequestTimeoutSec") - ] = None - r"""Timeout in seconds for token exchange, channel open/close, and hostname discovery. Defaults to 30 seconds.""" + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[OutputResponseAuthentication] = None + r"""Authentication parameters to use when connecting to bootstrap server. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideType] = None + r"""TLS settings (client side)""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -6736,7 +6587,7 @@ class OutputResponseOutputSnowflakeStreaming(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSnowflakeStreamingPqControls], + Optional[OutputResponseOutputMicrosoftFabricPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -6746,62 +6597,46 @@ class OutputResponseOutputSnowflakeStreaming(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_account_identifier: Annotated[ - Optional[str], pydantic.Field(alias="__template_accountIdentifier") - ] = None - r"""Binds 'accountIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountIdentifier' at runtime.""" - - template_user: Annotated[Optional[str], pydantic.Field(alias="__template_user")] = ( - None - ) - r"""Binds 'user' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'user' at runtime.""" - - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") - ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - - template_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_schema") - ] = None - r"""Binds 'schema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'schema' at runtime.""" - - template_table: Annotated[ - Optional[str], pydantic.Field(alias="__template_table") + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") ] = None - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - template_role: Annotated[Optional[str], pydantic.Field(alias="__template_role")] = ( - None - ) - r"""Binds 'role' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'role' at runtime.""" + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_bootstrap_server: Annotated[ + Optional[str], pydantic.Field(alias="__template_bootstrap_server") + ] = None + r"""Binds 'bootstrap_server' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bootstrap_server' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AcknowledgmentsOptions(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.RecordDataFormatOptions(value) except ValueError: return value return value @@ -6851,24 +6686,21 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "url", - "role", - "keepAlive", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", + "ack", + "format", + "maxRecordSizeKB", + "flushEventCount", "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "controlRequestTimeoutSec", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", "onBackpressure", "description", "pqStrictOrdering", @@ -6884,15 +6716,10 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_accountIdentifier", - "__template_user", - "__template_database", - "__template_schema", - "__template_table", - "__template_url", - "__template_role", - "__template_failedRequestLoggingMode", + "__template_topic", + "__template_format", "__template_onBackpressure", + "__template_bootstrap_server", "notifications", "status", ] @@ -6911,29 +6738,49 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDatabricksType(str, Enum): +class OutputResponseOutputSnowflakeStreamingType(str, Enum): r"""Connector type identifier.""" - DATABRICKS = "databricks" + SNOWFLAKE_STREAMING = "snowflake_streaming" -class OutputResponseOutputDatabricksTypedDict(TypedDict): - type: OutputResponseOutputDatabricksType +class OutputResponsePrivateKeyTypedDict(TypedDict): + r"""Private key""" + + key_name: str + r"""Select the stored secret containing the RSA private key (PEM format) for Snowflake key-pair authentication""" + + +class OutputResponsePrivateKey(BaseModel): + r"""Private key""" + + key_name: Annotated[str, pydantic.Field(alias="keyName")] + r"""Select the stored secret containing the RSA private key (PEM format) for Snowflake key-pair authentication""" + + +class OutputResponseOutputSnowflakeStreamingPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputSnowflakeStreamingPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputSnowflakeStreamingTypedDict(TypedDict): + type: OutputResponseOutputSnowflakeStreamingType r"""Connector type identifier.""" - workspace_id: str - r"""Unique identifier for the Databricks workspace. Used to construct the OAuth login URL and API base URL.""" - scope: str - r"""OAuth scope for Unity Catalog authentication""" - client_id: str - r"""OAuth client ID for Unity Catalog authentication""" - catalog: str - r"""Name of the Unity Catalog catalog to use for the Destination.""" + account_identifier: str + r"""Snowflake account identifier in org-account format (example: MYORG-MYACCOUNT)""" + user: str + r"""Snowflake user with key-pair authentication configured""" + pem: OutputResponsePrivateKeyTypedDict + r"""Private key""" + database: str + r"""Target database""" schema_: str - r"""Name of the Unity Catalog schema to use for the Destination.""" - events_volume_name: str - r"""Name of the Unity Catalog volume where event data is written.""" - client_text_secret: str - r"""OAuth client secret for Unity Catalog authentication""" + r"""Target schema""" + table: str + r"""Target table""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -6944,131 +6791,121 @@ class OutputResponseOutputDatabricksTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - dest_path: NotRequired[str] - r"""Optional path to prepend to files before uploading.""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant, stable storage.""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + url: NotRequired[str] + r"""Override endpoint URL (for PrivateLink or custom deployments). Defaults to https://.snowflakecomputing.com:443""" + role: NotRequired[str] + r"""Snowflake role to assume for this connection""" + keep_alive: NotRequired[bool] + r"""Keep connections open between requests. Disable only if experiencing connection pooling issues.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum uncompressed size of each batch. With compression enabled (default), batches are zstd-compressed before sending. Snowflake has observed a ~4 MB limit on the compressed wire size.""" + max_payload_events: NotRequired[float] + r"""Maximum number of events per request. Default is 0 (unlimited, size-gated only).""" + compress: NotRequired[bool] + r"""Compress the payload body using zstd compression before sending.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + control_request_timeout_sec: NotRequired[float] + r"""Timeout in seconds for token exchange, channel open/close, and hostname discovery. Defaults to 30 seconds.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - workspace_host: NotRequired[str] - r"""Hostname for the Databricks workspace. Override this to connect to government or secure cloud environments (e.g. cloud.databricks.us, cloud.databricks.mil, azuredatabricks.net).""" - timeout_sec: NotRequired[int] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputSnowflakeStreamingPqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_account_identifier: NotRequired[str] + r"""Binds 'accountIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountIdentifier' at runtime.""" + template_user: NotRequired[str] + r"""Binds 'user' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'user' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_schema: NotRequired[str] + r"""Binds 'schema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'schema' at runtime.""" + template_table: NotRequired[str] + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_role: NotRequired[str] + r"""Binds 'role' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'role' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputDatabricks(BaseModel): - type: OutputResponseOutputDatabricksType +class OutputResponseOutputSnowflakeStreaming(BaseModel): + type: OutputResponseOutputSnowflakeStreamingType r"""Connector type identifier.""" - workspace_id: Annotated[str, pydantic.Field(alias="workspaceId")] - r"""Unique identifier for the Databricks workspace. Used to construct the OAuth login URL and API base URL.""" + account_identifier: Annotated[str, pydantic.Field(alias="accountIdentifier")] + r"""Snowflake account identifier in org-account format (example: MYORG-MYACCOUNT)""" - scope: str - r"""OAuth scope for Unity Catalog authentication""" + user: str + r"""Snowflake user with key-pair authentication configured""" - client_id: Annotated[str, pydantic.Field(alias="clientId")] - r"""OAuth client ID for Unity Catalog authentication""" + pem: OutputResponsePrivateKey + r"""Private key""" - catalog: str - r"""Name of the Unity Catalog catalog to use for the Destination.""" + database: str + r"""Target database""" schema_: Annotated[str, pydantic.Field(alias="schema")] - r"""Name of the Unity Catalog schema to use for the Destination.""" - - events_volume_name: Annotated[str, pydantic.Field(alias="eventsVolumeName")] - r"""Name of the Unity Catalog volume where event data is written.""" + r"""Target schema""" - client_text_secret: Annotated[str, pydantic.Field(alias="clientTextSecret")] - r"""OAuth client secret for Unity Catalog authentication""" + table: str + r"""Target table""" id: Optional[str] = None r"""Unique ID for this output""" @@ -7087,245 +6924,213 @@ class OutputResponseOutputDatabricks(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Optional path to prepend to files before uploading.""" + url: Optional[str] = None + r"""Override endpoint URL (for PrivateLink or custom deployments). Defaults to https://.snowflakecomputing.com:443""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant, stable storage.""" + role: Optional[str] = None + r"""Snowflake role to assume for this connection""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Keep connections open between requests. Disable only if experiencing connection pooling issues.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Remove empty staging directories after moving files""" + r"""Maximum uncompressed size of each batch. With compression enabled (default), batches are zstd-compressed before sending. Snowflake has observed a ~4 MB limit on the compressed wire size.""" - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events per request. Default is 0 (unlimited, size-gated only).""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + compress: Optional[bool] = None + r"""Compress the payload body using zstd compression before sending.""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Buffer size used to write to a file""" + r"""Headers to add to all events""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""List of headers that are safe to log in plain text""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + control_request_timeout_sec: Annotated[ + Optional[float], pydantic.Field(alias="controlRequestTimeoutSec") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""Timeout in seconds for token exchange, channel open/close, and hostname discovery. Defaults to 30 seconds.""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - workspace_host: Annotated[Optional[str], pydantic.Field(alias="workspaceHost")] = ( - None - ) - r"""Hostname for the Databricks workspace. Override this to connect to government or secure cloud environments (e.g. cloud.databricks.us, cloud.databricks.mil, azuredatabricks.net).""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - timeout_sec: Annotated[Optional[int], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + r"""Codec to use to compress the persisted data""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_controls: Annotated[ + Optional[OutputResponseOutputSnowflakeStreamingPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Persistent queue controls.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + template_account_identifier: Annotated[ + Optional[str], pydantic.Field(alias="__template_accountIdentifier") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""Binds 'accountIdentifier' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountIdentifier' at runtime.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + template_user: Annotated[Optional[str], pydantic.Field(alias="__template_user")] = ( None ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + r"""Binds 'user' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'user' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") + template_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_schema") ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + r"""Binds 'schema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'schema' at runtime.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_table: Annotated[ + Optional[str], pydantic.Field(alias="__template_table") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_role: Annotated[Optional[str], pydantic.Field(alias="__template_role")] = ( + None + ) + r"""Binds 'role' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'role' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.DataFormatOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -7334,52 +7139,34 @@ def serialize_format_(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -7393,54 +7180,48 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "destPath", - "stagePath", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "workspaceHost", + "url", + "role", + "keepAlive", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "controlRequestTimeoutSec", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", + "__template_accountIdentifier", + "__template_user", + "__template_database", + "__template_schema", + "__template_table", + "__template_url", + "__template_role", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", "notifications", "status", ] @@ -7459,76 +7240,29 @@ def serialize_model(self, handler): return m -class OutputResponseOutputChronicleType(str, Enum): +class OutputResponseOutputDatabricksType(str, Enum): r"""Connector type identifier.""" - CHRONICLE = "chronicle" - - -class OutputResponseOutputChronicleAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method""" - - SERVICE_ACCOUNT = "serviceAccount" - SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" - - -class OutputResponseCustomLabelTypedDict(TypedDict): - key: str - r"""Key""" - value: str - r"""Value""" - rbac_enabled: NotRequired[bool] - r"""Designate this label for role-based access control and filtering""" - - -class OutputResponseCustomLabel(BaseModel): - key: str - r"""Key""" - - value: str - r"""Value""" - - rbac_enabled: Annotated[Optional[bool], pydantic.Field(alias="rbacEnabled")] = None - r"""Designate this label for role-based access control and filtering""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["rbacEnabled"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputChroniclePqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputChroniclePqControls(BaseModel): - r"""Persistent queue controls.""" + DATABRICKS = "databricks" -class OutputResponseOutputChronicleTypedDict(TypedDict): - type: OutputResponseOutputChronicleType +class OutputResponseOutputDatabricksTypedDict(TypedDict): + type: OutputResponseOutputDatabricksType r"""Connector type identifier.""" - region: str - r"""Regional endpoint to send events to""" - log_type: str - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" - gcp_project_id: str - r"""The Google Cloud Platform (GCP) project ID to send events to""" - gcp_instance: str - r"""The Google Cloud Platform (GCP) instance to send events to. This is the Chronicle customer uuid.""" + workspace_id: str + r"""Unique identifier for the Databricks workspace. Used to construct the OAuth login URL and API base URL.""" + scope: str + r"""OAuth scope for Unity Catalog authentication""" + client_id: str + r"""OAuth client ID for Unity Catalog authentication""" + catalog: str + r"""Name of the Unity Catalog catalog to use for the Destination.""" + schema_: str + r"""Name of the Unity Catalog schema to use for the Destination.""" + events_volume_name: str + r"""Name of the Unity Catalog volume where event data is written.""" + client_text_secret: str + r"""OAuth client secret for Unity Catalog authentication""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -7539,131 +7273,131 @@ class OutputResponseOutputChronicleTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - api_version: NotRequired[str] - r"""API version""" - authentication_method: NotRequired[ - OutputResponseOutputChronicleAuthenticationMethod - ] - r"""Authentication method""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - ingestion_method: NotRequired[str] - r"""Chronicle API ingestion method""" - namespace: NotRequired[str] - r"""User-configured environment namespace to identify the data domain the logs originated from. This namespace is used as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" - log_text_field: NotRequired[str] - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" - custom_labels: NotRequired[List[OutputResponseCustomLabelTypedDict]] - r"""Custom labels to be added to every event""" - endpoint: NotRequired[str] - r"""Chronicle API service endpoint. If empty, defaults to the Region-specific endpoint. Otherwise, it must point to a Chronicle API-compatible endpoint. (Example: https://custom-endpoint.googleapis.com)""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - service_account_credentials_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputChroniclePqControlsTypedDict] - r"""Persistent queue controls.""" + dest_path: NotRequired[str] + r"""Optional path to prepend to files before uploading.""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant, stable storage.""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + workspace_host: NotRequired[str] + r"""Hostname for the Databricks workspace. Override this to connect to government or secure cloud environments (e.g. cloud.databricks.us, cloud.databricks.mil, azuredatabricks.net).""" + timeout_sec: NotRequired[int] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_namespace: NotRequired[str] - r"""Binds 'namespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'namespace' at runtime.""" - template_log_type: NotRequired[str] - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" - template_log_text_field: NotRequired[str] - r"""Binds 'logTextField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logTextField' at runtime.""" - template_gcp_project_id: NotRequired[str] - r"""Binds 'gcpProjectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpProjectId' at runtime.""" - template_gcp_instance: NotRequired[str] - r"""Binds 'gcpInstance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpInstance' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputChronicle(BaseModel): - type: OutputResponseOutputChronicleType +class OutputResponseOutputDatabricks(BaseModel): + type: OutputResponseOutputDatabricksType r"""Connector type identifier.""" - region: str - r"""Regional endpoint to send events to""" + workspace_id: Annotated[str, pydantic.Field(alias="workspaceId")] + r"""Unique identifier for the Databricks workspace. Used to construct the OAuth login URL and API base URL.""" - log_type: Annotated[str, pydantic.Field(alias="logType")] - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + scope: str + r"""OAuth scope for Unity Catalog authentication""" - gcp_project_id: Annotated[str, pydantic.Field(alias="gcpProjectId")] - r"""The Google Cloud Platform (GCP) project ID to send events to""" + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""OAuth client ID for Unity Catalog authentication""" - gcp_instance: Annotated[str, pydantic.Field(alias="gcpInstance")] - r"""The Google Cloud Platform (GCP) instance to send events to. This is the Chronicle customer uuid.""" + catalog: str + r"""Name of the Unity Catalog catalog to use for the Destination.""" + + schema_: Annotated[str, pydantic.Field(alias="schema")] + r"""Name of the Unity Catalog schema to use for the Destination.""" + + events_volume_name: Annotated[str, pydantic.Field(alias="eventsVolumeName")] + r"""Name of the Unity Catalog volume where event data is written.""" + + client_text_secret: Annotated[str, pydantic.Field(alias="clientTextSecret")] + r"""OAuth client secret for Unity Catalog authentication""" id: Optional[str] = None r"""Unique ID for this output""" @@ -7682,294 +7416,299 @@ class OutputResponseOutputChronicle(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - api_version: Annotated[Optional[str], pydantic.Field(alias="apiVersion")] = None - r"""API version""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Optional path to prepend to files before uploading.""" - authentication_method: Annotated[ - Optional[OutputResponseOutputChronicleAuthenticationMethod], - pydantic.Field(alias="authenticationMethod"), - ] = None - r"""Authentication method""" + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant, stable storage.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Add the Output ID value to staging location""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None + r"""Remove empty staging directories after moving files""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Maximum size, in KB, of the request body""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Buffer size used to write to a file""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""How to handle events when all receivers are exerting backpressure""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Headers to add to all events""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - ingestion_method: Annotated[ - Optional[str], pydantic.Field(alias="ingestionMethod") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Chronicle API ingestion method""" - namespace: Optional[str] = None - r"""User-configured environment namespace to identify the data domain the logs originated from. This namespace is used as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( + workspace_host: Annotated[Optional[str], pydantic.Field(alias="workspaceHost")] = ( None ) - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" - - custom_labels: Annotated[ - Optional[List[OutputResponseCustomLabel]], pydantic.Field(alias="customLabels") - ] = None - r"""Custom labels to be added to every event""" + r"""Hostname for the Databricks workspace. Override this to connect to government or secure cloud environments (e.g. cloud.databricks.us, cloud.databricks.mil, azuredatabricks.net).""" - endpoint: Optional[str] = None - r"""Chronicle API service endpoint. If empty, defaults to the Region-specific endpoint. Otherwise, it must point to a Chronicle API-compatible endpoint. (Example: https://custom-endpoint.googleapis.com)""" + timeout_sec: Annotated[Optional[int], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" description: Optional[str] = None r"""Optional description for this configuration.""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""Compression level to apply before moving files to final destination""" - service_account_credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Select or create a stored text secret""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Determines which data types are supported and how they are represented""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") + ] = None + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") + ] = None + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Codec to use to compress the persisted data""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - pq_controls: Annotated[ - Optional[OutputResponseOutputChroniclePqControls], - pydantic.Field(alias="pqControls"), + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""Persistent queue controls.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_namespace: Annotated[ - Optional[str], pydantic.Field(alias="__template_namespace") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'namespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'namespace' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_log_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_logType") + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_log_text_field: Annotated[ - Optional[str], pydantic.Field(alias="__template_logTextField") + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") ] = None - r"""Binds 'logTextField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logTextField' at runtime.""" + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_gcp_project_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_gcpProjectId") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'gcpProjectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpProjectId' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_gcp_instance: Annotated[ - Optional[str], pydantic.Field(alias="__template_gcpInstance") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'gcpInstance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpInstance' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("authentication_method") - def serialize_authentication_method(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputChronicleAuthenticationMethod(value) + return models.DataFormatOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -7983,55 +7722,54 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "apiVersion", - "authenticationMethod", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "useRoundRobinDns", + "destPath", + "stagePath", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", - "totalMemoryLimitKB", - "ingestionMethod", - "namespace", - "logTextField", - "customLabels", - "endpoint", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "workspaceHost", + "timeoutSec", "description", - "serviceAccountCredentials", - "serviceAccountCredentialsSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_region", - "__template_failedRequestLoggingMode", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", - "__template_namespace", - "__template_logType", - "__template_logTextField", - "__template_gcpProjectId", - "__template_gcpInstance", - "__template_endpoint", + "__template_compress", + "__template_parquetSchema", "notifications", "status", ] @@ -8050,46 +7788,76 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSentinelOneAiSiemType(str, Enum): +class OutputResponseOutputChronicleType(str, Enum): r"""Connector type identifier.""" - SENTINEL_ONE_AI_SIEM = "sentinel_one_ai_siem" + CHRONICLE = "chronicle" -class OutputResponseRegion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The SentinelOne region to send events to. In most cases you can find the region by either looking at your SentinelOne URL or knowing what geographic region your SentinelOne instance is contained in.""" +class OutputResponseOutputChronicleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method""" - US = "US" - CA = "CA" - EMEA = "EMEA" - AP = "AP" - APS = "APS" - AU = "AU" - CUSTOM = "Custom" + SERVICE_ACCOUNT = "serviceAccount" + SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" -class OutputResponseAISIEMEndpointPath(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Endpoint to send events to. Use /services/collector/event for structured JSON payloads with standard HEC top-level fields. Use /services/collector/raw for unstructured log lines (plain text).""" +class OutputResponseCustomLabelTypedDict(TypedDict): + key: str + r"""Key""" + value: str + r"""Value""" + rbac_enabled: NotRequired[bool] + r"""Designate this label for role-based access control and filtering""" - ROOT_SERVICES_COLLECTOR_EVENT = "/services/collector/event" - ROOT_SERVICES_COLLECTOR_RAW = "/services/collector/raw" +class OutputResponseCustomLabel(BaseModel): + key: str + r"""Key""" + + value: str + r"""Value""" -class OutputResponseOutputSentinelOneAiSiemPqControlsTypedDict(TypedDict): + rbac_enabled: Annotated[Optional[bool], pydantic.Field(alias="rbacEnabled")] = None + r"""Designate this label for role-based access control and filtering""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["rbacEnabled"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputChroniclePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSentinelOneAiSiemPqControls(BaseModel): +class OutputResponseOutputChroniclePqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSentinelOneAiSiemTypedDict(TypedDict): - type: OutputResponseOutputSentinelOneAiSiemType +class OutputResponseOutputChronicleTypedDict(TypedDict): + type: OutputResponseOutputChronicleType r"""Connector type identifier.""" - region: OutputResponseRegion - r"""The SentinelOne region to send events to. In most cases you can find the region by either looking at your SentinelOne URL or knowing what geographic region your SentinelOne instance is contained in.""" - endpoint: OutputResponseAISIEMEndpointPath - r"""Endpoint to send events to. Use /services/collector/event for structured JSON payloads with standard HEC top-level fields. Use /services/collector/raw for unstructured log lines (plain text).""" + region: str + r"""Regional endpoint to send events to""" + log_type: str + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + gcp_project_id: str + r"""The Google Cloud Platform (GCP) project ID to send events to""" + gcp_instance: str + r"""The Google Cloud Platform (GCP) instance to send events to. This is the Chronicle customer uuid.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -8100,6 +7868,19 @@ class OutputResponseOutputSentinelOneAiSiemTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + api_version: NotRequired[str] + r"""API version""" + authentication_method: NotRequired[ + OutputResponseOutputChronicleAuthenticationMethod + ] + r"""Authentication method""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -8125,53 +7906,28 @@ class OutputResponseOutputSentinelOneAiSiemTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + ingestion_method: NotRequired[str] + r"""Chronicle API ingestion method""" + namespace: NotRequired[str] + r"""User-configured environment namespace to identify the data domain the logs originated from. This namespace is used as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + log_text_field: NotRequired[str] + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + custom_labels: NotRequired[List[OutputResponseCustomLabelTypedDict]] + r"""Custom labels to be added to every event""" + endpoint: NotRequired[str] + r"""Chronicle API service endpoint. If empty, defaults to the Region-specific endpoint. Otherwise, it must point to a Chronicle API-compatible endpoint. (Example: https://custom-endpoint.googleapis.com)""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""In the SentinelOne Console select Policy & Settings then select the Singularity AI SIEM section, API Keys will be at the bottom. Under Log Access Keys select a Write token and copy it here""" - text_secret: NotRequired[str] + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + service_account_credentials_secret: NotRequired[str] r"""Select or create a stored text secret""" - base_url: NotRequired[str] - r"""Base URL of the endpoint used to send events to, such as https://.sentinelone.net. Must begin with http:// or https://, can include a port number, and no trailing slashes. Matches pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$.""" - host_expression: NotRequired[str] - r"""Define serverHost for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myServer').""" - source_expression: NotRequired[str] - r"""Define logFile for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myLogFile.txt').""" - source_type_expression: NotRequired[str] - r"""Define the parser for events using a JavaScript expression. This value helps parse data into AI SIEM. You must enclose text constants in quotes (such as, 'dottedJson'). For custom parsers, substitute 'dottedJson' with your parser's name.""" - data_source_category_expression: NotRequired[str] - r"""Define the dataSource.category for events using a JavaScript expression. This value helps categorize data and helps enable extra features in SentinelOne AI SIEM. You must enclose text constants in quotes. The default value is 'security'.""" - data_source_name_expression: NotRequired[str] - r"""Define the dataSource.name for events using a JavaScript expression. This value should reflect the type of data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'networkActivity' or 'authLogs').""" - data_source_vendor_expression: NotRequired[str] - r"""Define the dataSource.vendor for events using a JavaScript expression. This value should reflect the vendor of the data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'Cisco' or 'Microsoft').""" - event_type_expression: NotRequired[str] - r"""Optionally, define the event.type for events using a JavaScript expression. This value acts as a label, grouping events into meaningful categories. You must enclose text constants in quotes (such as, 'Process Creation' or 'Network Connection').""" - host: NotRequired[str] - r"""Define the serverHost for events using a JavaScript expression. This value will be passed to AI SIEM. You must enclose text constants in quotes (such as, 'myServerName').""" - source: NotRequired[str] - r"""Specify the logFile value to pass as a parameter to SentinelOne AI SIEM. Don't quote this value. The default is cribl.""" - source_type: NotRequired[str] - r"""Specify the sourcetype parameter for SentinelOne AI SIEM, which determines the parser. Don't quote this value. For custom parsers, substitute hecRawParser with your parser's name. The default is hecRawParser.""" - data_source_category: NotRequired[str] - r"""Specify the dataSource.category value to pass as a parameter to SentinelOne AI SIEM. This value helps categorize data and enables additional features. Don't quote this value. The default is security.""" - data_source_name: NotRequired[str] - r"""Specify the dataSource.name value to pass as a parameter to AI SIEM. This value should reflect the type of data being inserted. Don't quote this value. The default is cribl.""" - data_source_vendor: NotRequired[str] - r"""Specify the dataSource.vendorvalue to pass as a parameter to AI SIEM. This value should reflect the vendor of the data being inserted. Don't quote this value. The default is cribl.""" - event_type: NotRequired[str] - r"""Specify the event.type value to pass as an optional parameter to AI SIEM. This value acts as a label, grouping events into meaningful categories like Process Creation, File Modification, or Network Connection. Don't quote this value. By default, this field is empty.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -8194,32 +7950,52 @@ class OutputResponseOutputSentinelOneAiSiemTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSentinelOneAiSiemPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputChroniclePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_namespace: NotRequired[str] + r"""Binds 'namespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'namespace' at runtime.""" + template_log_type: NotRequired[str] + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + template_log_text_field: NotRequired[str] + r"""Binds 'logTextField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logTextField' at runtime.""" + template_gcp_project_id: NotRequired[str] + r"""Binds 'gcpProjectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpProjectId' at runtime.""" + template_gcp_instance: NotRequired[str] + r"""Binds 'gcpInstance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpInstance' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSentinelOneAiSiem(BaseModel): - type: OutputResponseOutputSentinelOneAiSiemType +class OutputResponseOutputChronicle(BaseModel): + type: OutputResponseOutputChronicleType r"""Connector type identifier.""" - region: OutputResponseRegion - r"""The SentinelOne region to send events to. In most cases you can find the region by either looking at your SentinelOne URL or knowing what geographic region your SentinelOne instance is contained in.""" + region: str + r"""Regional endpoint to send events to""" - endpoint: OutputResponseAISIEMEndpointPath - r"""Endpoint to send events to. Use /services/collector/event for structured JSON payloads with standard HEC top-level fields. Use /services/collector/raw for unstructured log lines (plain text).""" + log_type: Annotated[str, pydantic.Field(alias="logType")] + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" - id: Optional[str] = None - r"""Unique ID for this output""" + gcp_project_id: Annotated[str, pydantic.Field(alias="gcpProjectId")] + r"""The Google Cloud Platform (GCP) project ID to send events to""" + + gcp_instance: Annotated[str, pydantic.Field(alias="gcpInstance")] + r"""The Google Cloud Platform (GCP) instance to send events to. This is the Chronicle customer uuid.""" + + id: Optional[str] = None + r"""Unique ID for this output""" pipeline: Optional[str] = None r"""Pipeline to process data before sending out to this output""" @@ -8235,6 +8011,30 @@ class OutputResponseOutputSentinelOneAiSiem(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + api_version: Annotated[Optional[str], pydantic.Field(alias="apiVersion")] = None + r"""API version""" + + authentication_method: Annotated[ + Optional[OutputResponseOutputChronicleAuthenticationMethod], + pydantic.Field(alias="authenticationMethod"), + ] = None + r"""Authentication method""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -8289,105 +8089,54 @@ class OutputResponseOutputSentinelOneAiSiem(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - token: Optional[str] = None - r"""In the SentinelOne Console select Policy & Settings then select the Singularity AI SIEM section, API Keys will be at the bottom. Under Log Access Keys select a Write token and copy it here""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - base_url: Annotated[Optional[str], pydantic.Field(alias="baseUrl")] = None - r"""Base URL of the endpoint used to send events to, such as https://.sentinelone.net. Must begin with http:// or https://, can include a port number, and no trailing slashes. Matches pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$.""" - - host_expression: Annotated[ - Optional[str], pydantic.Field(alias="hostExpression") - ] = None - r"""Define serverHost for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myServer').""" - - source_expression: Annotated[ - Optional[str], pydantic.Field(alias="sourceExpression") - ] = None - r"""Define logFile for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myLogFile.txt').""" - - source_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="sourceTypeExpression") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None - r"""Define the parser for events using a JavaScript expression. This value helps parse data into AI SIEM. You must enclose text constants in quotes (such as, 'dottedJson'). For custom parsers, substitute 'dottedJson' with your parser's name.""" + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - data_source_category_expression: Annotated[ - Optional[str], pydantic.Field(alias="dataSourceCategoryExpression") + ingestion_method: Annotated[ + Optional[str], pydantic.Field(alias="ingestionMethod") ] = None - r"""Define the dataSource.category for events using a JavaScript expression. This value helps categorize data and helps enable extra features in SentinelOne AI SIEM. You must enclose text constants in quotes. The default value is 'security'.""" + r"""Chronicle API ingestion method""" - data_source_name_expression: Annotated[ - Optional[str], pydantic.Field(alias="dataSourceNameExpression") - ] = None - r"""Define the dataSource.name for events using a JavaScript expression. This value should reflect the type of data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'networkActivity' or 'authLogs').""" + namespace: Optional[str] = None + r"""User-configured environment namespace to identify the data domain the logs originated from. This namespace is used as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" - data_source_vendor_expression: Annotated[ - Optional[str], pydantic.Field(alias="dataSourceVendorExpression") - ] = None - r"""Define the dataSource.vendor for events using a JavaScript expression. This value should reflect the vendor of the data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'Cisco' or 'Microsoft').""" + log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( + None + ) + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" - event_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="eventTypeExpression") + custom_labels: Annotated[ + Optional[List[OutputResponseCustomLabel]], pydantic.Field(alias="customLabels") ] = None - r"""Optionally, define the event.type for events using a JavaScript expression. This value acts as a label, grouping events into meaningful categories. You must enclose text constants in quotes (such as, 'Process Creation' or 'Network Connection').""" - - host: Optional[str] = None - r"""Define the serverHost for events using a JavaScript expression. This value will be passed to AI SIEM. You must enclose text constants in quotes (such as, 'myServerName').""" - - source: Optional[str] = None - r"""Specify the logFile value to pass as a parameter to SentinelOne AI SIEM. Don't quote this value. The default is cribl.""" + r"""Custom labels to be added to every event""" - source_type: Annotated[Optional[str], pydantic.Field(alias="sourceType")] = None - r"""Specify the sourcetype parameter for SentinelOne AI SIEM, which determines the parser. Don't quote this value. For custom parsers, substitute hecRawParser with your parser's name. The default is hecRawParser.""" + endpoint: Optional[str] = None + r"""Chronicle API service endpoint. If empty, defaults to the Region-specific endpoint. Otherwise, it must point to a Chronicle API-compatible endpoint. (Example: https://custom-endpoint.googleapis.com)""" - data_source_category: Annotated[ - Optional[str], pydantic.Field(alias="dataSourceCategory") - ] = None - r"""Specify the dataSource.category value to pass as a parameter to SentinelOne AI SIEM. This value helps categorize data and enables additional features. Don't quote this value. The default is security.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - data_source_name: Annotated[ - Optional[str], pydantic.Field(alias="dataSourceName") + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") ] = None - r"""Specify the dataSource.name value to pass as a parameter to AI SIEM. This value should reflect the type of data being inserted. Don't quote this value. The default is cribl.""" + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - data_source_vendor: Annotated[ - Optional[str], pydantic.Field(alias="dataSourceVendor") + service_account_credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") ] = None - r"""Specify the dataSource.vendorvalue to pass as a parameter to AI SIEM. This value should reflect the vendor of the data being inserted. Don't quote this value. The default is cribl.""" - - event_type: Annotated[Optional[str], pydantic.Field(alias="eventType")] = None - r"""Specify the event.type value to pass as an optional parameter to AI SIEM. This value acts as a label, grouping events into meaningful categories like Process Creation, File Modification, or Network Connection. Don't quote this value. By default, this field is empty.""" + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -8439,7 +8188,7 @@ class OutputResponseOutputSentinelOneAiSiem(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSentinelOneAiSiemPqControls], + Optional[OutputResponseOutputChroniclePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -8449,6 +8198,11 @@ class OutputResponseOutputSentinelOneAiSiem(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -8459,44 +8213,56 @@ class OutputResponseOutputSentinelOneAiSiem(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_namespace: Annotated[ + Optional[str], pydantic.Field(alias="__template_namespace") + ] = None + r"""Binds 'namespace' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'namespace' at runtime.""" + + template_log_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_logType") + ] = None + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + + template_log_text_field: Annotated[ + Optional[str], pydantic.Field(alias="__template_logTextField") + ] = None + r"""Binds 'logTextField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logTextField' at runtime.""" + + template_gcp_project_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_gcpProjectId") + ] = None + r"""Binds 'gcpProjectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpProjectId' at runtime.""" + + template_gcp_instance: Annotated[ + Optional[str], pydantic.Field(alias="__template_gcpInstance") + ] = None + r"""Binds 'gcpInstance' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'gcpInstance' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @field_serializer("region") - def serialize_region(self, value): + @field_serializer("authentication_method") + def serialize_authentication_method(self, value): if isinstance(value, str): try: - return models.OutputResponseRegion(value) + return models.OutputResponseOutputChronicleAuthenticationMethod(value) except ValueError: return value return value - @field_serializer("endpoint") - def serialize_endpoint(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.OutputResponseAISIEMEndpointPath(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -8546,6 +8312,11 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "apiVersion", + "authenticationMethod", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -8557,29 +8328,17 @@ def serialize_model(self, handler): "extraHttpHeaders", "failedRequestLoggingMode", "safeHeaders", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "useRoundRobinDns", "onBackpressure", + "totalMemoryLimitKB", + "ingestionMethod", + "namespace", + "logTextField", + "customLabels", + "endpoint", "description", - "token", - "textSecret", - "baseUrl", - "hostExpression", - "sourceExpression", - "sourceTypeExpression", - "dataSourceCategoryExpression", - "dataSourceNameExpression", - "dataSourceVendorExpression", - "eventTypeExpression", - "host", - "source", - "sourceType", - "dataSourceCategory", - "dataSourceName", - "dataSourceVendor", - "eventType", + "serviceAccountCredentials", + "serviceAccountCredentialsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -8593,8 +8352,15 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_region", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_namespace", + "__template_logType", + "__template_logTextField", + "__template_gcpProjectId", + "__template_gcpInstance", + "__template_endpoint", "notifications", "status", ] @@ -8613,51 +8379,46 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDynatraceOtlpType(str, Enum): +class OutputResponseOutputSentinelOneAiSiemType(str, Enum): r"""Connector type identifier.""" - DYNATRACE_OTLP = "dynatrace_otlp" + SENTINEL_ONE_AI_SIEM = "sentinel_one_ai_siem" -class OutputResponseOutputDynatraceOtlpProtocol( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Select a transport option for Dynatrace""" +class OutputResponseRegion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The SentinelOne region to send events to. In most cases you can find the region by either looking at your SentinelOne URL or knowing what geographic region your SentinelOne instance is contained in.""" - # HTTP - HTTP = "http" + US = "US" + CA = "CA" + EMEA = "EMEA" + AP = "AP" + APS = "APS" + AU = "AU" + CUSTOM = "Custom" -class OutputResponseEndpointType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Select the type of Dynatrace endpoint configured""" +class OutputResponseAISIEMEndpointPath(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Endpoint to send events to. Use /services/collector/event for structured JSON payloads with standard HEC top-level fields. Use /services/collector/raw for unstructured log lines (plain text).""" - # SaaS - SAAS = "saas" - # ActiveGate - AG = "ag" + ROOT_SERVICES_COLLECTOR_EVENT = "/services/collector/event" + ROOT_SERVICES_COLLECTOR_RAW = "/services/collector/raw" -class OutputResponseOutputDynatraceOtlpPqControlsTypedDict(TypedDict): +class OutputResponseOutputSentinelOneAiSiemPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputDynatraceOtlpPqControls(BaseModel): +class OutputResponseOutputSentinelOneAiSiemPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputDynatraceOtlpTypedDict(TypedDict): - type: OutputResponseOutputDynatraceOtlpType +class OutputResponseOutputSentinelOneAiSiemTypedDict(TypedDict): + type: OutputResponseOutputSentinelOneAiSiemType r"""Connector type identifier.""" - protocol: OutputResponseOutputDynatraceOtlpProtocol - r"""Select a transport option for Dynatrace""" - endpoint: str - r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - otlp_version: OtlpVersionOptions - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - endpoint_type: OutputResponseEndpointType - r"""Select the type of Dynatrace endpoint configured""" - token_secret: str - r"""Select or create a stored text secret""" + region: OutputResponseRegion + r"""The SentinelOne region to send events to. In most cases you can find the region by either looking at your SentinelOne URL or knowing what geographic region your SentinelOne instance is contained in.""" + endpoint: OutputResponseAISIEMEndpointPath + r"""Endpoint to send events to. Use /services/collector/event for structured JSON payloads with standard HEC top-level fields. Use /services/collector/raw for unstructured log lines (plain text).""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -8668,59 +8429,33 @@ class OutputResponseOutputDynatraceOtlpTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - compress: NotRequired[CompressionOptionsDeflateGzip] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_compress: NotRequired[CompressionOptionsMessages] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: NotRequired[str] - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_metrics_endpoint_override: NotRequired[str] - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: NotRequired[str] - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - auth_token_name: NotRequired[str] - r"""Api-Token name""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -8728,6 +8463,44 @@ class OutputResponseOutputDynatraceOtlpTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + token: NotRequired[str] + r"""In the SentinelOne Console select Policy & Settings then select the Singularity AI SIEM section, API Keys will be at the bottom. Under Log Access Keys select a Write token and copy it here""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + base_url: NotRequired[str] + r"""Base URL of the endpoint used to send events to, such as https://.sentinelone.net. Must begin with http:// or https://, can include a port number, and no trailing slashes. Matches pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$.""" + host_expression: NotRequired[str] + r"""Define serverHost for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myServer').""" + source_expression: NotRequired[str] + r"""Define logFile for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myLogFile.txt').""" + source_type_expression: NotRequired[str] + r"""Define the parser for events using a JavaScript expression. This value helps parse data into AI SIEM. You must enclose text constants in quotes (such as, 'dottedJson'). For custom parsers, substitute 'dottedJson' with your parser's name.""" + data_source_category_expression: NotRequired[str] + r"""Define the dataSource.category for events using a JavaScript expression. This value helps categorize data and helps enable extra features in SentinelOne AI SIEM. You must enclose text constants in quotes. The default value is 'security'.""" + data_source_name_expression: NotRequired[str] + r"""Define the dataSource.name for events using a JavaScript expression. This value should reflect the type of data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'networkActivity' or 'authLogs').""" + data_source_vendor_expression: NotRequired[str] + r"""Define the dataSource.vendor for events using a JavaScript expression. This value should reflect the vendor of the data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'Cisco' or 'Microsoft').""" + event_type_expression: NotRequired[str] + r"""Optionally, define the event.type for events using a JavaScript expression. This value acts as a label, grouping events into meaningful categories. You must enclose text constants in quotes (such as, 'Process Creation' or 'Network Connection').""" + host: NotRequired[str] + r"""Define the serverHost for events using a JavaScript expression. This value will be passed to AI SIEM. You must enclose text constants in quotes (such as, 'myServerName').""" + source: NotRequired[str] + r"""Specify the logFile value to pass as a parameter to SentinelOne AI SIEM. Don't quote this value. The default is cribl.""" + source_type: NotRequired[str] + r"""Specify the sourcetype parameter for SentinelOne AI SIEM, which determines the parser. Don't quote this value. For custom parsers, substitute hecRawParser with your parser's name. The default is hecRawParser.""" + data_source_category: NotRequired[str] + r"""Specify the dataSource.category value to pass as a parameter to SentinelOne AI SIEM. This value helps categorize data and enables additional features. Don't quote this value. The default is security.""" + data_source_name: NotRequired[str] + r"""Specify the dataSource.name value to pass as a parameter to AI SIEM. This value should reflect the type of data being inserted. Don't quote this value. The default is cribl.""" + data_source_vendor: NotRequired[str] + r"""Specify the dataSource.vendorvalue to pass as a parameter to AI SIEM. This value should reflect the vendor of the data being inserted. Don't quote this value. The default is cribl.""" + event_type: NotRequired[str] + r"""Specify the event.type value to pass as an optional parameter to AI SIEM. This value acts as a label, grouping events into meaningful categories like Process Creation, File Modification, or Network Connection. Don't quote this value. By default, this field is empty.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -8750,7 +8523,7 @@ class OutputResponseOutputDynatraceOtlpTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputDynatraceOtlpPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSentinelOneAiSiemPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -8758,32 +8531,21 @@ class OutputResponseOutputDynatraceOtlpTypedDict(TypedDict): r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputDynatraceOtlp(BaseModel): - type: OutputResponseOutputDynatraceOtlpType +class OutputResponseOutputSentinelOneAiSiem(BaseModel): + type: OutputResponseOutputSentinelOneAiSiemType r"""Connector type identifier.""" - protocol: OutputResponseOutputDynatraceOtlpProtocol - r"""Select a transport option for Dynatrace""" - - endpoint: str - r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - - otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - - endpoint_type: Annotated[ - OutputResponseEndpointType, pydantic.Field(alias="endpointType") - ] - r"""Select the type of Dynatrace endpoint configured""" + region: OutputResponseRegion + r"""The SentinelOne region to send events to. In most cases you can find the region by either looking at your SentinelOne URL or knowing what geographic region your SentinelOne instance is contained in.""" - token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] - r"""Select or create a stored text secret""" + endpoint: OutputResponseAISIEMEndpointPath + r"""Endpoint to send events to. Use /services/collector/event for structured JSON payloads with standard HEC top-level fields. Use /services/collector/raw for unstructured log lines (plain text).""" id: Optional[str] = None r"""Unique ID for this output""" @@ -8802,54 +8564,29 @@ class OutputResponseOutputDynatraceOtlp(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") - ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - - compress: Optional[CompressionOptionsDeflateGzip] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - - http_compress: Annotated[ - Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") - ] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - - http_traces_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") - ] = None - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - - http_metrics_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") - ] = None - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - - http_logs_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") - ] = None - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + r"""Maximum size, in KB, of the request body""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -8864,29 +8601,43 @@ class OutputResponseOutputDynatraceOtlp(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), ] = None r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""List of headers that are safe to log in plain text""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""How often the sender should ping the peer to keep the connection open""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( - None - ) - r"""Api-Token name""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -8896,44 +8647,76 @@ class OutputResponseOutputDynatraceOtlp(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + token: Optional[str] = None + r"""In the SentinelOne Console select Policy & Settings then select the Singularity AI SIEM section, API Keys will be at the bottom. Under Log Access Keys select a Write token and copy it here""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + base_url: Annotated[Optional[str], pydantic.Field(alias="baseUrl")] = None + r"""Base URL of the endpoint used to send events to, such as https://.sentinelone.net. Must begin with http:// or https://, can include a port number, and no trailing slashes. Matches pattern: ^https?://[a-zA-Z0-9.-]+(:[0-9]+)?$.""" + + host_expression: Annotated[ + Optional[str], pydantic.Field(alias="hostExpression") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Define serverHost for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myServer').""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + source_expression: Annotated[ + Optional[str], pydantic.Field(alias="sourceExpression") ] = None - r"""Headers to add to all events""" + r"""Define logFile for events using a JavaScript expression. You must enclose text constants in quotes (such as, 'myLogFile.txt').""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + source_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="sourceTypeExpression") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Define the parser for events using a JavaScript expression. This value helps parse data into AI SIEM. You must enclose text constants in quotes (such as, 'dottedJson'). For custom parsers, substitute 'dottedJson' with your parser's name.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + data_source_category_expression: Annotated[ + Optional[str], pydantic.Field(alias="dataSourceCategoryExpression") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Define the dataSource.category for events using a JavaScript expression. This value helps categorize data and helps enable extra features in SentinelOne AI SIEM. You must enclose text constants in quotes. The default value is 'security'.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + data_source_name_expression: Annotated[ + Optional[str], pydantic.Field(alias="dataSourceNameExpression") ] = None + r"""Define the dataSource.name for events using a JavaScript expression. This value should reflect the type of data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'networkActivity' or 'authLogs').""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + data_source_vendor_expression: Annotated[ + Optional[str], pydantic.Field(alias="dataSourceVendorExpression") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Define the dataSource.vendor for events using a JavaScript expression. This value should reflect the vendor of the data being inserted into AI SIEM. You must enclose text constants in quotes (such as, 'Cisco' or 'Microsoft').""" + + event_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="eventTypeExpression") + ] = None + r"""Optionally, define the event.type for events using a JavaScript expression. This value acts as a label, grouping events into meaningful categories. You must enclose text constants in quotes (such as, 'Process Creation' or 'Network Connection').""" + + host: Optional[str] = None + r"""Define the serverHost for events using a JavaScript expression. This value will be passed to AI SIEM. You must enclose text constants in quotes (such as, 'myServerName').""" + + source: Optional[str] = None + r"""Specify the logFile value to pass as a parameter to SentinelOne AI SIEM. Don't quote this value. The default is cribl.""" + + source_type: Annotated[Optional[str], pydantic.Field(alias="sourceType")] = None + r"""Specify the sourcetype parameter for SentinelOne AI SIEM, which determines the parser. Don't quote this value. For custom parsers, substitute hecRawParser with your parser's name. The default is hecRawParser.""" + + data_source_category: Annotated[ + Optional[str], pydantic.Field(alias="dataSourceCategory") + ] = None + r"""Specify the dataSource.category value to pass as a parameter to SentinelOne AI SIEM. This value helps categorize data and enables additional features. Don't quote this value. The default is security.""" + + data_source_name: Annotated[ + Optional[str], pydantic.Field(alias="dataSourceName") + ] = None + r"""Specify the dataSource.name value to pass as a parameter to AI SIEM. This value should reflect the type of data being inserted. Don't quote this value. The default is cribl.""" + + data_source_vendor: Annotated[ + Optional[str], pydantic.Field(alias="dataSourceVendor") + ] = None + r"""Specify the dataSource.vendorvalue to pass as a parameter to AI SIEM. This value should reflect the vendor of the data being inserted. Don't quote this value. The default is cribl.""" + + event_type: Annotated[Optional[str], pydantic.Field(alias="eventType")] = None + r"""Specify the event.type value to pass as an optional parameter to AI SIEM. This value acts as a label, grouping events into meaningful categories like Process Creation, File Modification, or Network Connection. Don't quote this value. By default, this field is empty.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -8985,7 +8768,7 @@ class OutputResponseOutputDynatraceOtlp(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputDynatraceOtlpPqControls], + Optional[OutputResponseOutputSentinelOneAiSiemPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -9005,62 +8788,44 @@ class OutputResponseOutputDynatraceOtlp(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputDynatraceOtlpProtocol(value) - except ValueError: - return value - return value - - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.OtlpVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CompressionOptionsDeflateGzip(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("http_compress") - def serialize_http_compress(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CompressionOptionsMessages(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("region") + def serialize_region(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OutputResponseRegion(value) except ValueError: return value return value - @field_serializer("endpoint_type") - def serialize_endpoint_type(self, value): + @field_serializer("endpoint") + def serialize_endpoint(self, value): if isinstance(value, str): try: - return models.OutputResponseEndpointType(value) + return models.OutputResponseAISIEMEndpointPath(value) except ValueError: return value return value @@ -9110,34 +8875,40 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "preserveNativeAnyValue", - "compress", - "httpCompress", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", - "httpLogsEndpointOverride", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "keepAlive", - "authTokenName", - "onBackpressure", - "description", - "rejectUnauthorized", - "useRoundRobinDns", "extraHttpHeaders", + "failedRequestLoggingMode", "safeHeaders", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", + "onBackpressure", + "description", + "token", + "textSecret", + "baseUrl", + "hostExpression", + "sourceExpression", + "sourceTypeExpression", + "dataSourceCategoryExpression", + "dataSourceNameExpression", + "dataSourceVendorExpression", + "eventTypeExpression", + "host", + "source", + "sourceType", + "dataSourceCategory", + "dataSourceName", + "dataSourceVendor", + "eventType", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9171,71 +8942,40 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDynatraceHTTPType(str, Enum): +class OutputResponseOutputTraversalOtlpType(str, Enum): r"""Connector type identifier.""" - DYNATRACE_HTTP = "dynatrace_http" + TRAVERSAL_OTLP = "traversal_otlp" -class OutputResponseOutputDynatraceHTTPAuthenticationType( +class OutputResponseOutputTraversalOtlpAuthenticationType( str, Enum, metaclass=utils.OpenEnumMeta ): r"""Authentication type""" - # Auth token - TOKEN = "token" + # None + NONE = "none" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" # Token (text secret) TEXT_SECRET = "textSecret" + # OAuth (text secret) + OAUTH_SECRET = "oauthSecret" -class OutputResponseOutputDynatraceHTTPFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - - # JSON - JSON_ARRAY = "json_array" - # Plaintext - PLAINTEXT = "plaintext" - - -class OutputResponseOutputDynatraceHTTPEndpoint( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Endpoint""" - - # Cloud - CLOUD = "cloud" - # ActiveGate - ACTIVE_GATE = "activeGate" - # Manual - MANUAL = "manual" - - -class OutputResponseTelemetryType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Telemetry type""" - - # Logs - LOGS = "logs" - # Metrics - METRICS = "metrics" - - -class OutputResponseOutputDynatraceHTTPPqControlsTypedDict(TypedDict): +class OutputResponseOutputTraversalOtlpPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputDynatraceHTTPPqControls(BaseModel): +class OutputResponseOutputTraversalOtlpPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputDynatraceHTTPTypedDict(TypedDict): - type: OutputResponseOutputDynatraceHTTPType +class OutputResponseOutputTraversalOtlpTypedDict(TypedDict): + type: OutputResponseOutputTraversalOtlpType r"""Connector type identifier.""" - format_: OutputResponseOutputDynatraceHTTPFormat - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - endpoint: OutputResponseOutputDynatraceHTTPEndpoint - r"""Endpoint""" - telemetry_type: OutputResponseTelemetryType - r"""Telemetry type""" + endpoint: str + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -9246,52 +8986,86 @@ class OutputResponseOutputDynatraceHTTPTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + auth_type: NotRequired[OutputResponseOutputTraversalOtlpAuthenticationType] + r"""Authentication type""" + protocol: NotRequired[ProtocolOptions] + r"""Select a transport option for OpenTelemetry""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[OutputResponseOutputDynatraceHTTPAuthenticationType] - r"""Authentication type""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9314,48 +9088,28 @@ class OutputResponseOutputDynatraceHTTPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputDynatraceHTTPPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputTraversalOtlpPqControlsTypedDict] r"""Persistent queue controls.""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - environment_id: NotRequired[str] - r"""ID of the environment to send to""" - active_gate_domain: NotRequired[str] - r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" - url: NotRequired[str] - r"""URL to send events to. Can be overwritten by an event's __url field.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputDynatraceHTTP(BaseModel): - type: OutputResponseOutputDynatraceHTTPType +class OutputResponseOutputTraversalOtlp(BaseModel): + type: OutputResponseOutputTraversalOtlpType r"""Connector type identifier.""" - format_: Annotated[ - OutputResponseOutputDynatraceHTTPFormat, pydantic.Field(alias="format") - ] - r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - - endpoint: OutputResponseOutputDynatraceHTTPEndpoint - r"""Endpoint""" - - telemetry_type: Annotated[ - OutputResponseTelemetryType, pydantic.Field(alias="telemetryType") - ] - r"""Telemetry type""" + endpoint: str + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" id: Optional[str] = None r"""Unique ID for this output""" @@ -9374,35 +9128,53 @@ class OutputResponseOutputDynatraceHTTP(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" + auth_type: Annotated[ + Optional[OutputResponseOutputTraversalOtlpAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" + protocol: Optional[ProtocolOptions] = None + r"""Select a transport option for OpenTelemetry""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Batch event data upon dynamic metadata (whether presented or not)""" + + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") + ] = None + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -9417,22 +9189,99 @@ class OutputResponseOutputDynatraceHTTP(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Headers to add to all events""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") @@ -9454,24 +9303,8 @@ class OutputResponseOutputDynatraceHTTP(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - auth_type: Annotated[ - Optional[OutputResponseOutputDynatraceHTTPAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""Authentication type""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -9523,30 +9356,11 @@ class OutputResponseOutputDynatraceHTTP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputDynatraceHTTPPqControls], + Optional[OutputResponseOutputTraversalOtlpPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - environment_id: Annotated[Optional[str], pydantic.Field(alias="environmentId")] = ( - None - ) - r"""ID of the environment to send to""" - - active_gate_domain: Annotated[ - Optional[str], pydantic.Field(alias="activeGateDomain") - ] = None - r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" - - url: Optional[str] = None - r"""URL to send events to. Can be overwritten by an event's __url field.""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -9562,76 +9376,67 @@ class OutputResponseOutputDynatraceHTTP(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("method") - def serialize_method(self, value): - if isinstance(value, str): - try: - return models.MethodOptions(value) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OutputResponseOutputTraversalOtlpAuthenticationType(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.ProtocolOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputDynatraceHTTPAuthenticationType(value) + return models.CompressionOptionsDeflateGzip(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("http_compress") + def serialize_http_compress(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputDynatraceHTTPFormat(value) + return models.CompressionOptionsMessages(value) except ValueError: return value return value - @field_serializer("endpoint") - def serialize_endpoint(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputDynatraceHTTPEndpoint(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("telemetry_type") - def serialize_telemetry_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseTelemetryType(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -9672,27 +9477,44 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "keepAlive", + "authType", + "protocol", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "onBackpressure", + "description", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "oauthTextSecret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "totalMemoryLimitKB", - "description", + "tls", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9705,15 +9527,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "token", - "textSecret", - "environmentId", - "activeGateDomain", - "url", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", + "__template_loginUrl", "notifications", "status", ] @@ -9732,56 +9549,51 @@ def serialize_model(self, handler): return m -class OutputResponseOutputNetflowHostTypedDict(TypedDict): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 2055""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" +class OutputResponseOutputDynatraceOtlpType(str, Enum): + r"""Connector type identifier.""" + + DYNATRACE_OTLP = "dynatrace_otlp" -class OutputResponseOutputNetflowHost(BaseModel): - host: str - r"""Destination host""" +class OutputResponseOutputDynatraceOtlpProtocol( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Select a transport option for Dynatrace""" - port: float - r"""Destination port, default is 2055""" + # HTTP + HTTP = "http" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" +class OutputResponseEndpointType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Select the type of Dynatrace endpoint configured""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["__template_host", "__template_port"]) - serialized = handler(self) - m = {} + # SaaS + SAAS = "saas" + # ActiveGate + AG = "ag" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class OutputResponseOutputDynatraceOtlpPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - return m +class OutputResponseOutputDynatraceOtlpPqControls(BaseModel): + r"""Persistent queue controls.""" -class OutputResponseOutputNetflowTypedDict(TypedDict): - type: TypeOptionsNetflow + +class OutputResponseOutputDynatraceOtlpTypedDict(TypedDict): + type: OutputResponseOutputDynatraceOtlpType r"""Connector type identifier.""" - hosts: List[OutputResponseOutputNetflowHostTypedDict] - r"""One or more NetFlow Destinations to forward events to""" + protocol: OutputResponseOutputDynatraceOtlpProtocol + r"""Select a transport option for Dynatrace""" + endpoint: str + r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + otlp_version: OtlpVersionOptions + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + endpoint_type: OutputResponseEndpointType + r"""Select the type of Dynatrace endpoint configured""" + token_secret: str + r"""Select or create a stored text secret""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -9792,198 +9604,59 @@ class OutputResponseOutputNetflowTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_traces_endpoint_override: NotRequired[str] + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_metrics_endpoint_override: NotRequired[str] + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + auth_token_name: NotRequired[str] + r"""Api-Token name""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_record_size: NotRequired[float] - r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class OutputResponseOutputNetflow(BaseModel): - type: TypeOptionsNetflow - r"""Connector type identifier.""" - - hosts: List[OutputResponseOutputNetflowHost] - r"""One or more NetFlow Destinations to forward events to""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") - ] = None - r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") - ] = None - r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "pipeline", - "systemFields", - "environment", - "streamtags", - "dnsResolvePeriodSec", - "enableIpSpoofing", - "description", - "maxRecordSize", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputXsiamType(str, Enum): - r"""Connector type identifier.""" - - XSIAM = "xsiam" - - -class OutputResponseOutputXsiamAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter a token directly, or provide a secret referencing a token""" - - TOKEN = "token" - SECRET = "secret" - - -class OutputResponseOutputXsiamURLTypedDict(TypedDict): - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - -class OutputResponseOutputXsiamURL(BaseModel): - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputXsiamPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputXsiamPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class OutputResponseOutputXsiamTypedDict(TypedDict): - type: OutputResponseOutputXsiamType - r"""Connector type identifier.""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), that value will take precedence. """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[OutputResponseOutputXsiamAuthenticationMethod] - r"""Enter a token directly, or provide a secret referencing a token""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -9991,30 +9664,6 @@ class OutputResponseOutputXsiamTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - throttle_rate_req_per_sec: NotRequired[int] - r"""Maximum number of requests to limit to per second""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[OutputResponseOutputXsiamURLTypedDict]] - r"""XSIAM Endpoints""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - token: NotRequired[str] - r"""XSIAM authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -10037,7 +9686,7 @@ class OutputResponseOutputXsiamTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputXsiamPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputDynatraceOtlpPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -10045,18 +9694,33 @@ class OutputResponseOutputXsiamTypedDict(TypedDict): r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputXsiam(BaseModel): - type: OutputResponseOutputXsiamType +class OutputResponseOutputDynatraceOtlp(BaseModel): + type: OutputResponseOutputDynatraceOtlpType r"""Connector type identifier.""" + protocol: OutputResponseOutputDynatraceOtlpProtocol + r"""Select a transport option for Dynatrace""" + + endpoint: str + r"""The endpoint where Dynatrace events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + + otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + endpoint_type: Annotated[ + OutputResponseEndpointType, pydantic.Field(alias="endpointType") + ] + r"""Select the type of Dynatrace endpoint configured""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -10074,133 +9738,138 @@ class OutputResponseOutputXsiam(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + http_traces_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + http_metrics_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") + ] = None + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Batch event data upon dynamic metadata (whether presented or not)""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Maximum size (in KB) of the request body. The maximum payload size is 4 MB. If this limit is exceeded, the entire OTLP message is dropped""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - auth_type: Annotated[ - Optional[OutputResponseOutputXsiamAuthenticationMethod], - pydantic.Field(alias="authType"), + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Enter a token directly, or provide a secret referencing a token""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - throttle_rate_req_per_sec: Annotated[ - Optional[int], pydantic.Field(alias="throttleRateReqPerSec") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""Maximum number of requests to limit to per second""" + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( + None + ) + r"""Api-Token name""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[OutputResponseOutputXsiamURL]] = None - r"""XSIAM Endpoints""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + r"""List of headers that are safe to log in plain text""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - token: Optional[str] = None - r"""XSIAM authentication token""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -10252,7 +9921,7 @@ class OutputResponseOutputXsiam(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputXsiamPqControls], + Optional[OutputResponseOutputDynatraceOtlpPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -10272,17 +9941,48 @@ class OutputResponseOutputXsiam(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputDynatraceOtlpProtocol(value) + except ValueError: + return value + return value + + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): + if isinstance(value, str): + try: + return models.OtlpVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsDeflateGzip(value) + except ValueError: + return value + return value + + @field_serializer("http_compress") + def serialize_http_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsMessages(value) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -10292,11 +9992,11 @@ def serialize_failed_request_logging_mode(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("endpoint_type") + def serialize_endpoint_type(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputXsiamAuthenticationMethod(value) + return models.OutputResponseEndpointType(value) except ValueError: return value return value @@ -10346,34 +10046,34 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "authTokenName", + "onBackpressure", + "description", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", "safeHeaders", - "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "throttleRateReqPerSec", - "onBackpressure", - "totalMemoryLimitKB", - "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "token", - "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10389,7 +10089,6 @@ def serialize_model(self, handler): "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", "notifications", "status", ] @@ -10408,149 +10107,71 @@ def serialize_model(self, handler): return m -class OutputResponseOutputLocalSearchStorageType(str, Enum): +class OutputResponseOutputDynatraceHTTPType(str, Enum): r"""Connector type identifier.""" - LOCAL_SEARCH_STORAGE = "local_search_storage" + DYNATRACE_HTTP = "dynatrace_http" -class OutputResponseOutputLocalSearchStorageFormat( +class OutputResponseOutputDynatraceHTTPAuthenticationType( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Data format to use when sending data. Defaults to JSON Compact.""" + r"""Authentication type""" - # JSONCompactEachRowWithNames - JSON_COMPACT_EACH_ROW_WITH_NAMES = "json-compact-each-row-with-names" - # JSONEachRow - JSON_EACH_ROW = "json-each-row" + # Auth token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" -class OutputResponseMappingType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How event fields are mapped to columns.""" +class OutputResponseOutputDynatraceHTTPFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - # Automatic - AUTOMATIC = "automatic" - # Custom - CUSTOM = "custom" + # JSON + JSON_ARRAY = "json_array" + # Plaintext + PLAINTEXT = "plaintext" -class OutputResponseStatsDestinationTypedDict(TypedDict): - url: NotRequired[str] - database: NotRequired[str] - table_name: NotRequired[str] - auth_type: NotRequired[str] - username: NotRequired[str] - sql_username: NotRequired[str] - password: NotRequired[str] - wait_for_async_inserts: NotRequired[bool] - concurrency: NotRequired[float] +class OutputResponseOutputDynatraceHTTPEndpoint( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Endpoint""" + # Cloud + CLOUD = "cloud" + # ActiveGate + ACTIVE_GATE = "activeGate" + # Manual + MANUAL = "manual" -class OutputResponseStatsDestination(BaseModel): - url: Optional[str] = None - database: Optional[str] = None +class OutputResponseTelemetryType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Telemetry type""" - table_name: Annotated[Optional[str], pydantic.Field(alias="tableName")] = None + # Logs + LOGS = "logs" + # Metrics + METRICS = "metrics" - auth_type: Annotated[Optional[str], pydantic.Field(alias="authType")] = None - username: Optional[str] = None - - sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None - - password: Optional[str] = None - - wait_for_async_inserts: Annotated[ - Optional[bool], pydantic.Field(alias="waitForAsyncInserts") - ] = None - - concurrency: Optional[float] = None - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "url", - "database", - "tableName", - "authType", - "username", - "sqlUsername", - "password", - "waitForAsyncInserts", - "concurrency", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseColumnMappingTypedDict(TypedDict): - column_name: str - r"""Name of the column that will store field value""" - column_value_expression: str - r"""JavaScript expression to compute value to be inserted into the table""" - column_type: NotRequired[str] - r"""Type of the column in the database""" - - -class OutputResponseColumnMapping(BaseModel): - column_name: Annotated[str, pydantic.Field(alias="columnName")] - r"""Name of the column that will store field value""" - - column_value_expression: Annotated[ - str, pydantic.Field(alias="columnValueExpression") - ] - r"""JavaScript expression to compute value to be inserted into the table""" - - column_type: Annotated[Optional[str], pydantic.Field(alias="columnType")] = None - r"""Type of the column in the database""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["columnType"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputLocalSearchStoragePqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseOutputDynatraceHTTPPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" -class OutputResponseOutputLocalSearchStoragePqControls(BaseModel): +class OutputResponseOutputDynatraceHTTPPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputLocalSearchStorageTypedDict(TypedDict): - type: OutputResponseOutputLocalSearchStorageType +class OutputResponseOutputDynatraceHTTPTypedDict(TypedDict): + type: OutputResponseOutputDynatraceHTTPType r"""Connector type identifier.""" - url: str - r"""URL of the database instance. Example: http://localhost:8123/""" - database: str - r"""Database""" - table_name: str - r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + format_: OutputResponseOutputDynatraceHTTPFormat + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" + endpoint: OutputResponseOutputDynatraceHTTPEndpoint + r"""Endpoint""" + telemetry_type: OutputResponseTelemetryType + r"""Telemetry type""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -10561,16 +10182,10 @@ class OutputResponseOutputLocalSearchStorageTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationTypeOptions] - r"""Authentication type""" - format_: NotRequired[OutputResponseOutputLocalSearchStorageFormat] - r"""Data format to use when sending data. Defaults to JSON Compact.""" - mapping_type: NotRequired[OutputResponseMappingType] - r"""How event fields are mapped to columns.""" - async_inserts: NotRequired[bool] - r"""Collect data into batches for later processing. Disable to write to a table immediately.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + method: NotRequired[MethodOptions] + r"""The method to use when sending events""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -10591,7 +10206,7 @@ class OutputResponseOutputLocalSearchStorageTypedDict(TypedDict): flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" use_round_robin_dns: NotRequired[bool] r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] @@ -10605,31 +10220,14 @@ class OutputResponseOutputLocalSearchStorageTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - workload: NotRequired[str] - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - dump_format_errors_to_disk: NotRequired[bool] - r"""Log the most recent event that fails to match the table schema""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - stats_destination: NotRequired[OutputResponseStatsDestinationTypedDict] + auth_type: NotRequired[OutputResponseOutputDynatraceHTTPAuthenticationType] + r"""Authentication type""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - sql_username: NotRequired[str] - r"""Username for certificate authentication""" - wait_for_async_inserts: NotRequired[bool] - r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - exclude_mapping_fields: NotRequired[List[str]] - r"""Fields to exclude from sending""" - describe_table: NotRequired[str] - r"""Retrieves the table schema and populates the Column Mapping table""" - column_mappings: NotRequired[List[OutputResponseColumnMappingTypedDict]] - r"""Column Mapping""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -10652,38 +10250,48 @@ class OutputResponseOutputLocalSearchStorageTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputLocalSearchStoragePqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputDynatraceHTTPPqControlsTypedDict] r"""Persistent queue controls.""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + environment_id: NotRequired[str] + r"""ID of the environment to send to""" + active_gate_domain: NotRequired[str] + r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" + url: NotRequired[str] + r"""URL to send events to. Can be overwritten by an event's __url field.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_table_name: NotRequired[str] - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputLocalSearchStorage(BaseModel): - type: OutputResponseOutputLocalSearchStorageType +class OutputResponseOutputDynatraceHTTP(BaseModel): + type: OutputResponseOutputDynatraceHTTPType r"""Connector type identifier.""" - url: str - r"""URL of the database instance. Example: http://localhost:8123/""" + format_: Annotated[ + OutputResponseOutputDynatraceHTTPFormat, pydantic.Field(alias="format") + ] + r"""How to format events before sending. Defaults to JSON. Plaintext is not currently supported.""" - database: str - r"""Database""" + endpoint: OutputResponseOutputDynatraceHTTPEndpoint + r"""Endpoint""" - table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + telemetry_type: Annotated[ + OutputResponseTelemetryType, pydantic.Field(alias="telemetryType") + ] + r"""Telemetry type""" id: Optional[str] = None r"""Unique ID for this output""" @@ -10702,29 +10310,11 @@ class OutputResponseOutputLocalSearchStorage(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") - ] = None - r"""Authentication type""" - - format_: Annotated[ - Optional[OutputResponseOutputLocalSearchStorageFormat], - pydantic.Field(alias="format"), - ] = None - r"""Data format to use when sending data. Defaults to JSON Compact.""" - - mapping_type: Annotated[ - Optional[OutputResponseMappingType], pydantic.Field(alias="mappingType") - ] = None - r"""How event fields are mapped to columns.""" - - async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( - None - ) - r"""Collect data into batches for later processing. Disable to write to a table immediately.""" + method: Optional[MethodOptions] = None + r"""The method to use when sending events""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -10767,7 +10357,7 @@ class OutputResponseOutputLocalSearchStorage(BaseModel): Optional[List[ExtraHTTPHeaderConfInputElastic]], pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Headers to add to all events""" + r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") @@ -10800,82 +10390,45 @@ class OutputResponseOutputLocalSearchStorage(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - workload: Optional[str] = None - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - - dump_format_errors_to_disk: Annotated[ - Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") - ] = None - r"""Log the most recent event that fails to match the table schema""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - stats_destination: Annotated[ - Optional[OutputResponseStatsDestination], - pydantic.Field(alias="statsDestination"), + auth_type: Annotated[ + Optional[OutputResponseOutputDynatraceHTTPAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: Optional[str] = None r"""Optional description for this configuration.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Select or create a secret that references your credentials""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None - r"""Username for certificate authentication""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - wait_for_async_inserts: Annotated[ - Optional[bool], pydantic.Field(alias="waitForAsyncInserts") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - exclude_mapping_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeMappingFields") - ] = None - r"""Fields to exclude from sending""" - - describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( - None - ) - r"""Retrieves the table schema and populates the Column Mapping table""" - - column_mappings: Annotated[ - Optional[List[OutputResponseColumnMapping]], - pydantic.Field(alias="columnMappings"), - ] = None - r"""Column Mapping""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" @@ -10906,30 +10459,34 @@ class OutputResponseOutputLocalSearchStorage(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputLocalSearchStoragePqControls], + Optional[OutputResponseOutputDynatraceHTTPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + environment_id: Annotated[Optional[str], pydantic.Field(alias="environmentId")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""ID of the environment to send to""" - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") + active_gate_domain: Annotated[ + Optional[str], pydantic.Field(alias="activeGateDomain") ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + r"""ActiveGate domain with Log analytics collector module enabled. For example https://{activeGate-domain}:9999/e/{environment-id}/api/v2/logs/ingest.""" - template_table_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_tableName") + url: Optional[str] = None + r"""URL to send events to. Can be overwritten by an event's __url field.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -10941,53 +10498,76 @@ class OutputResponseOutputLocalSearchStorage(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("method") + def serialize_method(self, value): if isinstance(value, str): try: - return models.AuthenticationTypeOptions(value) + return models.MethodOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputLocalSearchStorageFormat(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("mapping_type") - def serialize_mapping_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseMappingType(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OutputResponseOutputDynatraceHTTPAuthenticationType(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.OutputResponseOutputDynatraceHTTPFormat(value) + except ValueError: + return value + return value + + @field_serializer("endpoint") + def serialize_endpoint(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputDynatraceHTTPEndpoint(value) + except ValueError: + return value + return value + + @field_serializer("telemetry_type") + def serialize_telemetry_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseTelemetryType(value) except ValueError: return value return value @@ -11028,11 +10608,8 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "format", - "mappingType", - "asyncInserts", - "tls", + "method", + "keepAlive", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -11048,19 +10625,10 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "workload", - "dumpFormatErrorsToDisk", "onBackpressure", - "statsDestination", + "authType", + "totalMemoryLimitKB", "description", - "username", - "password", - "credentialsSecret", - "sqlUsername", - "waitForAsyncInserts", - "excludeMappingFields", - "describeTable", - "columnMappings", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -11073,12 +10641,15 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "token", + "textSecret", + "environmentId", + "activeGateDomain", + "url", "__template_streamtags", - "__template_url", - "__template_database", - "__template_tableName", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_url", "notifications", "status", ] @@ -11097,29 +10668,56 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCustomerMetricsStorageType(str, Enum): - r"""Connector type identifier.""" +class OutputResponseOutputNetflowHostTypedDict(TypedDict): + host: str + r"""Destination host""" + port: float + r"""Destination port, default is 2055""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - CUSTOMER_METRICS_STORAGE = "customer_metrics_storage" +class OutputResponseOutputNetflowHost(BaseModel): + host: str + r"""Destination host""" + + port: float + r"""Destination port, default is 2055""" -class OutputResponseOutputCustomerMetricsStoragePqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class OutputResponseOutputCustomerMetricsStoragePqControls(BaseModel): - r"""Persistent queue controls.""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["__template_host", "__template_port"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + return m -class OutputResponseOutputCustomerMetricsStorageTypedDict(TypedDict): - type: OutputResponseOutputCustomerMetricsStorageType + +class OutputResponseOutputNetflowTypedDict(TypedDict): + type: TypeOptionsNetflow r"""Connector type identifier.""" - url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" - database: str - r"""ClickHouse database""" - table_name: str - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + hosts: List[OutputResponseOutputNetflowHostTypedDict] + r"""One or more NetFlow Destinations to forward events to""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -11130,130 +10728,28 @@ class OutputResponseOutputCustomerMetricsStorageTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationTypeOptions] - r"""Authentication type""" - format_: NotRequired[FormatOptions] - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - mapping_type: NotRequired[MappingTypeOptions] - r"""How event fields are mapped to ClickHouse columns""" - async_inserts: NotRequired[bool] - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - workload: NotRequired[str] - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - dump_format_errors_to_disk: NotRequired[bool] - r"""Log the most recent event that fails to match the table schema""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - sql_username: NotRequired[str] - r"""Username for certificate authentication""" - wait_for_async_inserts: NotRequired[bool] - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - exclude_mapping_fields: NotRequired[List[str]] - r"""Fields to exclude from sending to ClickHouse""" - describe_table: NotRequired[str] - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] - r"""Column Mapping""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - OutputResponseOutputCustomerMetricsStoragePqControlsTypedDict - ] - r"""Persistent queue controls.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + max_record_size: NotRequired[float] + r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_table_name: NotRequired[str] - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputCustomerMetricsStorage(BaseModel): - type: OutputResponseOutputCustomerMetricsStorageType +class OutputResponseOutputNetflow(BaseModel): + type: TypeOptionsNetflow r"""Connector type identifier.""" - url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" - - database: str - r"""ClickHouse database""" - - table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + hosts: List[OutputResponseOutputNetflowHost] + r"""One or more NetFlow Destinations to forward events to""" id: Optional[str] = None r"""Unique ID for this output""" @@ -11272,275 +10768,471 @@ class OutputResponseOutputCustomerMetricsStorage(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Authentication type""" - - format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every datagram sent will incur a DNS lookup.""" - mapping_type: Annotated[ - Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") ] = None - r"""How event fields are mapped to ClickHouse columns""" - - async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( - None - ) - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + r"""Send NetFlow traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") ] = None - r"""Maximum size, in KB, of the request body""" + r"""MTU in bytes. The actual maximum NetFlow payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). For example, with the default MTU of 1500, the max payload is 1472 bytes for IPv4. Payloads exceeding this limit will be dropped.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "dnsResolvePeriodSec", + "enableIpSpoofing", + "description", + "maxRecordSize", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + return m - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" +class OutputResponseOutputXsiamType(str, Enum): + r"""Connector type identifier.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + XSIAM = "xsiam" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None +class OutputResponseOutputXsiamAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Enter a token directly, or provide a secret referencing a token""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + TOKEN = "token" + SECRET = "secret" - workload: Optional[str] = None - r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - dump_format_errors_to_disk: Annotated[ - Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") - ] = None - r"""Log the most recent event that fails to match the table schema""" +class OutputResponseOutputXsiamURLTypedDict(TypedDict): + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" +class OutputResponseOutputXsiamURL(BaseModel): + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - username: Optional[str] = None - r"""Username""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight"]) + serialized = handler(self) + m = {} - password: Optional[str] = None - r"""Password""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None - r"""Username for certificate authentication""" + return m - wait_for_async_inserts: Annotated[ - Optional[bool], pydantic.Field(alias="waitForAsyncInserts") - ] = None - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - exclude_mapping_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeMappingFields") - ] = None - r"""Fields to exclude from sending to ClickHouse""" +class OutputResponseOutputXsiamPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( - None - ) - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - column_mappings: Annotated[ - Optional[List[ColumnMappingConfOutputClickHouse]], - pydantic.Field(alias="columnMappings"), - ] = None - r"""Column Mapping""" +class OutputResponseOutputXsiamPqControls(BaseModel): + r"""Persistent queue controls.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None +class OutputResponseOutputXsiamTypedDict(TypedDict): + type: OutputResponseOutputXsiamType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + auth_type: NotRequired[OutputResponseOutputXsiamAuthenticationMethod] + r"""Enter a token directly, or provide a secret referencing a token""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + throttle_rate_req_per_sec: NotRequired[int] + r"""Maximum number of requests to limit to per second""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + url: NotRequired[str] + r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[OutputResponseOutputXsiamURLTypedDict]] + r"""XSIAM Endpoints""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""XSIAM authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + pq_mode: NotRequired[ModeOptions] r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputXsiamPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + +class OutputResponseOutputXsiam(BaseModel): + type: OutputResponseOutputXsiamType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Maximum size, in KB, of the request body""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Codec to use to compress the persisted data""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Headers to add to all events""" - pq_controls: Annotated[ - Optional[OutputResponseOutputCustomerMetricsStoragePqControls], - pydantic.Field(alias="pqControls"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Persistent queue controls.""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""List of headers that are safe to log in plain text""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + auth_type: Annotated[ + Optional[OutputResponseOutputXsiamAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter a token directly, or provide a secret referencing a token""" - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - template_table_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_tableName") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + throttle_rate_req_per_sec: Annotated[ + Optional[int], pydantic.Field(alias="throttleRateReqPerSec") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Maximum number of requests to limit to per second""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptions(value) - except ValueError: - return value - return value + description: Optional[str] = None + r"""Optional description for this configuration.""" - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.FormatOptions(value) - except ValueError: - return value - return value + url: Optional[str] = None + r"""XSIAM endpoint URL to send events to, such as https://api-{tenant external URL}/logs/v1/event""" - @field_serializer("mapping_type") - def serialize_mapping_type(self, value): + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[OutputResponseOutputXsiamURL]] = None + r"""XSIAM Endpoints""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" + + token: Optional[str] = None + r"""XSIAM authentication token""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[OutputResponseOutputXsiamPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.MappingTypeOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OutputResponseOutputXsiamAuthenticationMethod(value) except ValueError: return value return value @@ -11590,11 +11282,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "format", - "mappingType", - "asyncInserts", - "tls", + "loadBalanced", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -11604,24 +11292,24 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "workload", - "dumpFormatErrorsToDisk", + "throttleRateReqPerSec", "onBackpressure", + "totalMemoryLimitKB", "description", - "username", - "password", - "credentialsSecret", - "sqlUsername", - "waitForAsyncInserts", - "excludeMappingFields", - "describeTable", - "columnMappings", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -11635,11 +11323,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_url", - "__template_database", - "__template_tableName", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_url", "notifications", "status", ] @@ -11658,73 +11344,193 @@ def serialize_model(self, handler): return m -class OutputResponseOutputClickHouseType(str, Enum): +class OutputResponseOutputLocalSearchStorageType(str, Enum): r"""Connector type identifier.""" - CLICK_HOUSE = "click_house" + LOCAL_SEARCH_STORAGE = "local_search_storage" -class OutputResponseOutputClickHousePqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseOutputLocalSearchStorageFormat( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Data format to use when sending data. Defaults to JSON Compact.""" + # JSONCompactEachRowWithNames + JSON_COMPACT_EACH_ROW_WITH_NAMES = "json-compact-each-row-with-names" + # JSONEachRow + JSON_EACH_ROW = "json-each-row" -class OutputResponseOutputClickHousePqControls(BaseModel): - r"""Persistent queue controls.""" +class OutputResponseMappingType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How event fields are mapped to columns.""" -class OutputResponseOutputClickHouseTypedDict(TypedDict): - type: OutputResponseOutputClickHouseType - r"""Connector type identifier.""" - url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" - database: str - r"""ClickHouse database""" - table_name: str - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationTypeOptions] - r"""Authentication type""" - format_: NotRequired[FormatOptions] - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - mapping_type: NotRequired[MappingTypeOptions] - r"""How event fields are mapped to ClickHouse columns""" - async_inserts: NotRequired[bool] - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + # Automatic + AUTOMATIC = "automatic" + # Custom + CUSTOM = "custom" + + +class OutputResponseStatsDestinationTypedDict(TypedDict): + url: NotRequired[str] + database: NotRequired[str] + table_name: NotRequired[str] + auth_type: NotRequired[str] + username: NotRequired[str] + sql_username: NotRequired[str] + password: NotRequired[str] + wait_for_async_inserts: NotRequired[bool] concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + + +class OutputResponseStatsDestination(BaseModel): + url: Optional[str] = None + + database: Optional[str] = None + + table_name: Annotated[Optional[str], pydantic.Field(alias="tableName")] = None + + auth_type: Annotated[Optional[str], pydantic.Field(alias="authType")] = None + + username: Optional[str] = None + + sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + + password: Optional[str] = None + + wait_for_async_inserts: Annotated[ + Optional[bool], pydantic.Field(alias="waitForAsyncInserts") + ] = None + + concurrency: Optional[float] = None + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "url", + "database", + "tableName", + "authType", + "username", + "sqlUsername", + "password", + "waitForAsyncInserts", + "concurrency", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseColumnMappingTypedDict(TypedDict): + column_name: str + r"""Name of the column that will store field value""" + column_value_expression: str + r"""JavaScript expression to compute value to be inserted into the table""" + column_type: NotRequired[str] + r"""Type of the column in the database""" + + +class OutputResponseColumnMapping(BaseModel): + column_name: Annotated[str, pydantic.Field(alias="columnName")] + r"""Name of the column that will store field value""" + + column_value_expression: Annotated[ + str, pydantic.Field(alias="columnValueExpression") + ] + r"""JavaScript expression to compute value to be inserted into the table""" + + column_type: Annotated[Optional[str], pydantic.Field(alias="columnType")] = None + r"""Type of the column in the database""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["columnType"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputLocalSearchStoragePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputLocalSearchStoragePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputLocalSearchStorageTypedDict(TypedDict): + type: OutputResponseOutputLocalSearchStorageType + r"""Connector type identifier.""" + url: str + r"""URL of the database instance. Example: http://localhost:8123/""" + database: str + r"""Database""" + table_name: str + r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + auth_type: NotRequired[AuthenticationTypeOptions] + r"""Authentication type""" + format_: NotRequired[OutputResponseOutputLocalSearchStorageFormat] + r"""Data format to use when sending data. Defaults to JSON Compact.""" + mapping_type: NotRequired[OutputResponseMappingType] + r"""How event fields are mapped to columns.""" + async_inserts: NotRequired[bool] + r"""Collect data into batches for later processing. Disable to write to a table immediately.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" @@ -11741,6 +11547,7 @@ class OutputResponseOutputClickHouseTypedDict(TypedDict): r"""Log the most recent event that fails to match the table schema""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + stats_destination: NotRequired[OutputResponseStatsDestinationTypedDict] description: NotRequired[str] r"""Optional description for this configuration.""" username: NotRequired[str] @@ -11752,12 +11559,12 @@ class OutputResponseOutputClickHouseTypedDict(TypedDict): sql_username: NotRequired[str] r"""Username for certificate authentication""" wait_for_async_inserts: NotRequired[bool] - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" exclude_mapping_fields: NotRequired[List[str]] - r"""Fields to exclude from sending to ClickHouse""" + r"""Fields to exclude from sending""" describe_table: NotRequired[str] - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] + r"""Retrieves the table schema and populates the Column Mapping table""" + column_mappings: NotRequired[List[OutputResponseColumnMappingTypedDict]] r"""Column Mapping""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" @@ -11781,7 +11588,7 @@ class OutputResponseOutputClickHouseTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputClickHousePqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputLocalSearchStoragePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" @@ -11795,24 +11602,24 @@ class OutputResponseOutputClickHouseTypedDict(TypedDict): r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputClickHouse(BaseModel): - type: OutputResponseOutputClickHouseType +class OutputResponseOutputLocalSearchStorage(BaseModel): + type: OutputResponseOutputLocalSearchStorageType r"""Connector type identifier.""" url: str - r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + r"""URL of the database instance. Example: http://localhost:8123/""" database: str - r"""ClickHouse database""" + r"""Database""" table_name: Annotated[str, pydantic.Field(alias="tableName")] - r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + r"""Name of the table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" id: Optional[str] = None r"""Unique ID for this output""" @@ -11836,18 +11643,21 @@ class OutputResponseOutputClickHouse(BaseModel): ] = None r"""Authentication type""" - format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None - r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + format_: Annotated[ + Optional[OutputResponseOutputLocalSearchStorageFormat], + pydantic.Field(alias="format"), + ] = None + r"""Data format to use when sending data. Defaults to JSON Compact.""" mapping_type: Annotated[ - Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") + Optional[OutputResponseMappingType], pydantic.Field(alias="mappingType") ] = None - r"""How event fields are mapped to ClickHouse columns""" + r"""How event fields are mapped to columns.""" async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( None ) - r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + r"""Collect data into batches for later processing. Disable to write to a table immediately.""" tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None r"""TLS settings (client side)""" @@ -11939,6 +11749,11 @@ class OutputResponseOutputClickHouse(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" + stats_destination: Annotated[ + Optional[OutputResponseStatsDestination], + pydantic.Field(alias="statsDestination"), + ] = None + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -11959,20 +11774,20 @@ class OutputResponseOutputClickHouse(BaseModel): wait_for_async_inserts: Annotated[ Optional[bool], pydantic.Field(alias="waitForAsyncInserts") ] = None - r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + r"""Cribl will wait for confirmation that data has been fully inserted into the database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" exclude_mapping_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="excludeMappingFields") ] = None - r"""Fields to exclude from sending to ClickHouse""" + r"""Fields to exclude from sending""" describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( None ) - r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" + r"""Retrieves the table schema and populates the Column Mapping table""" column_mappings: Annotated[ - Optional[List[ColumnMappingConfOutputClickHouse]], + Optional[List[OutputResponseColumnMapping]], pydantic.Field(alias="columnMappings"), ] = None r"""Column Mapping""" @@ -12027,7 +11842,7 @@ class OutputResponseOutputClickHouse(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputClickHousePqControls], + Optional[OutputResponseOutputLocalSearchStoragePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -12062,7 +11877,7 @@ class OutputResponseOutputClickHouse(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -12081,7 +11896,7 @@ def serialize_auth_type(self, value): def serialize_format_(self, value): if isinstance(value, str): try: - return models.FormatOptions(value) + return models.OutputResponseOutputLocalSearchStorageFormat(value) except ValueError: return value return value @@ -12090,7 +11905,7 @@ def serialize_format_(self, value): def serialize_mapping_type(self, value): if isinstance(value, str): try: - return models.MappingTypeOptions(value) + return models.OutputResponseMappingType(value) except ValueError: return value return value @@ -12172,6 +11987,7 @@ def serialize_model(self, handler): "workload", "dumpFormatErrorsToDisk", "onBackpressure", + "statsDestination", "description", "username", "password", @@ -12217,15 +12033,29 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDiskSpoolType(str, Enum): +class OutputResponseOutputCustomerMetricsStorageType(str, Enum): r"""Connector type identifier.""" - DISK_SPOOL = "disk_spool" + CUSTOMER_METRICS_STORAGE = "customer_metrics_storage" -class OutputResponseOutputDiskSpoolTypedDict(TypedDict): - type: OutputResponseOutputDiskSpoolType +class OutputResponseOutputCustomerMetricsStoragePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputCustomerMetricsStoragePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputCustomerMetricsStorageTypedDict(TypedDict): + type: OutputResponseOutputCustomerMetricsStorageType r"""Connector type identifier.""" + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + database: str + r"""ClickHouse database""" + table_name: str + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -12236,36 +12066,137 @@ class OutputResponseOutputDiskSpoolTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - time_window: NotRequired[str] - r"""Time period for grouping spooled events. Default is 10m.""" - max_data_size: NotRequired[str] - r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" - compress: NotRequired[CompressionOptionsPersistence] - r"""Data compression format. Default is gzip.""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class OutputResponseOutputDiskSpool(BaseModel): - type: OutputResponseOutputDiskSpoolType - r"""Connector type identifier.""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - + auth_type: NotRequired[AuthenticationTypeOptions] + r"""Authentication type""" + format_: NotRequired[FormatOptions] + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + mapping_type: NotRequired[MappingTypeOptions] + r"""How event fields are mapped to ClickHouse columns""" + async_inserts: NotRequired[bool] + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + workload: NotRequired[str] + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" + dump_format_errors_to_disk: NotRequired[bool] + r"""Log the most recent event that fails to match the table schema""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + sql_username: NotRequired[str] + r"""Username for certificate authentication""" + wait_for_async_inserts: NotRequired[bool] + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + exclude_mapping_fields: NotRequired[List[str]] + r"""Fields to exclude from sending to ClickHouse""" + describe_table: NotRequired[str] + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" + column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] + r"""Column Mapping""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[ + OutputResponseOutputCustomerMetricsStoragePqControlsTypedDict + ] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_table_name: NotRequired[str] + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class OutputResponseOutputCustomerMetricsStorage(BaseModel): + type: OutputResponseOutputCustomerMetricsStorageType + r"""Connector type identifier.""" + + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + + database: str + r"""ClickHouse database""" + + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None @@ -12277,514 +12208,311 @@ class OutputResponseOutputDiskSpool(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None - r"""Time period for grouping spooled events. Default is 10m.""" - - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" + auth_type: Annotated[ + Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") + ] = None + r"""Authentication type""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - compress: Optional[CompressionOptionsPersistence] = None - r"""Data compression format. Default is gzip.""" + mapping_type: Annotated[ + Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") + ] = None + r"""How event fields are mapped to ClickHouse columns""" - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( None ) - r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Maximum size, in KB, of the request body""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPersistence(value) - except ValueError: - return value - return value + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "pipeline", - "systemFields", - "environment", - "streamtags", - "timeWindow", - "maxDataSize", - "maxDataTime", - "compress", - "partitionExpr", - "description", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - return m + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" -class OutputResponseOutputCriblLakeType(str, Enum): - r"""Connector type identifier.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - CRIBL_LAKE = "cribl_lake" + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" -class OutputResponseOutputCriblLakeFormat(str, Enum, metaclass=utils.OpenEnumMeta): - JSON = "json" - PARQUET = "parquet" - RAW = "raw" - + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None -class OutputResponseOutputCriblLakeTypedDict(TypedDict): - type: OutputResponseOutputCriblLakeType - r"""Connector type identifier.""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - storage_location_id: NotRequired[str] - r"""Storage location that contains the target Lake dataset.""" - dest_path: NotRequired[str] - r"""Lake dataset to send the data to.""" - format_: NotRequired[OutputResponseOutputCriblLakeFormat] - dynamic_dataset: NotRequired[bool] - max_closing_files_to_backpressure: NotRequired[float] - max_concurrent_file_parts: NotRequired[float] - description: NotRequired[str] - r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + workload: Optional[str] = None + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" -class OutputResponseOutputCriblLake(BaseModel): - type: OutputResponseOutputCriblLakeType - r"""Connector type identifier.""" + dump_format_errors_to_disk: Annotated[ + Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") + ] = None + r"""Log the most recent event that fails to match the table schema""" - id: Optional[str] = None - r"""Unique ID for this output""" + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + username: Optional[str] = None + r"""Username""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + password: Optional[str] = None + r"""Password""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + r"""Username for certificate authentication""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + wait_for_async_inserts: Annotated[ + Optional[bool], pydantic.Field(alias="waitForAsyncInserts") ] = None - r"""Add the Output ID value to staging location""" + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + exclude_mapping_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeMappingFields") ] = None - r"""Remove empty staging directories after moving files""" + r"""Fields to exclude from sending to ClickHouse""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( None ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + column_mappings: Annotated[ + Optional[List[ColumnMappingConfOutputClickHouse]], + pydantic.Field(alias="columnMappings"), ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Column Mapping""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Buffer size used to write to a file""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Codec to use to compress the persisted data""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + pq_controls: Annotated[ + Optional[OutputResponseOutputCustomerMetricsStoragePqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + r"""Persistent queue controls.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - storage_location_id: Annotated[ - Optional[str], pydantic.Field(alias="storageLocationId") - ] = None - r"""Storage location that contains the target Lake dataset.""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Lake dataset to send the data to.""" - - format_: Annotated[ - Optional[OutputResponseOutputCriblLakeFormat], pydantic.Field(alias="format") - ] = None - - dynamic_dataset: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicDataset") - ] = None - - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" - - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + template_table_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_tableName") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.AuthenticationTypeOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.FormatOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("mapping_type") + def serialize_mapping_type(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputCriblLakeFormat(value) + return models.MappingTypeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -12798,60 +12526,62 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "stagePath", - "addIdToStagePath", - "removeEmptyDirs", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "storageLocationId", - "destPath", + "authType", "format", - "dynamicDataset", - "maxClosingFilesToBackpressure", - "maxConcurrentFileParts", - "description", + "mappingType", + "asyncInserts", + "tls", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "__template_streamtags", - "__template_baseFileName", - "__template_fileNameSuffix", - "__template_onBackpressure", - "__template_destPath", - "__template_compress", - "__template_parquetSchema", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "workload", + "dumpFormatErrorsToDisk", + "onBackpressure", + "description", + "username", + "password", + "credentialsSecret", + "sqlUsername", + "waitForAsyncInserts", + "excludeMappingFields", + "describeTable", + "columnMappings", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_url", + "__template_database", + "__template_tableName", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} for n, f in type(self).model_fields.items(): k = f.alias or n @@ -12864,187 +12594,161 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSecurityLakeTypedDict(TypedDict): - type: TypeOptionsSecuritylake +class OutputResponseOutputClickHouseType(str, Enum): r"""Connector type identifier.""" - assume_role_arn: str - r"""Amazon Resource Name (ARN) of the role to assume""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - region: str - r"""Region where the Amazon Security Lake is located.""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - account_id: str - r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" - custom_source: str - r"""Name of the custom source configured in Amazon Security Lake""" + + CLICK_HOUSE = "click_house" + + +class OutputResponseOutputClickHousePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputClickHousePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputClickHouseTypedDict(TypedDict): + type: OutputResponseOutputClickHouseType + r"""Connector type identifier.""" + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" + database: str + r"""ClickHouse database""" + table_name: str + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - endpoint: NotRequired[str] - r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access S3""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + auth_type: NotRequired[AuthenticationTypeOptions] + r"""Authentication type""" + format_: NotRequired[FormatOptions] + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" + mapping_type: NotRequired[MappingTypeOptions] + r"""How event fields are mapped to ClickHouse columns""" + async_inserts: NotRequired[bool] + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + workload: NotRequired[str] + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" + dump_format_errors_to_disk: NotRequired[bool] + r"""Log the most recent event that fails to match the table schema""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_account_id: NotRequired[str] - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - template_custom_source: NotRequired[str] - r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + sql_username: NotRequired[str] + r"""Username for certificate authentication""" + wait_for_async_inserts: NotRequired[bool] + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" + exclude_mapping_fields: NotRequired[List[str]] + r"""Fields to exclude from sending to ClickHouse""" + describe_table: NotRequired[str] + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" + column_mappings: NotRequired[List[ColumnMappingConfOutputClickHouseTypedDict]] + r"""Column Mapping""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputClickHousePqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_table_name: NotRequired[str] + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSecurityLake(BaseModel): - type: TypeOptionsSecuritylake +class OutputResponseOutputClickHouse(BaseModel): + type: OutputResponseOutputClickHouseType r"""Connector type identifier.""" - assume_role_arn: Annotated[str, pydantic.Field(alias="assumeRoleArn")] - r"""Amazon Resource Name (ARN) of the role to assume""" - - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - - region: str - r"""Region where the Amazon Security Lake is located.""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + url: str + r"""URL of the ClickHouse instance. Example: http://localhost:8123/""" - account_id: Annotated[str, pydantic.Field(alias="accountId")] - r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" + database: str + r"""ClickHouse database""" - custom_source: Annotated[str, pydantic.Field(alias="customSource")] - r"""Name of the custom source configured in Amazon Security Lake""" + table_name: Annotated[str, pydantic.Field(alias="tableName")] + r"""Name of the ClickHouse table where data will be inserted. Name can contain letters (A-Z, a-z), numbers (0-9), and the character \"_\", and must start with either a letter or the character \"_\".""" id: Optional[str] = None r"""Unique ID for this output""" @@ -13055,7 +12759,7 @@ class OutputResponseOutputSecurityLake(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -13063,395 +12767,311 @@ class OutputResponseOutputSecurityLake(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - endpoint: Optional[str] = None - r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + auth_type: Annotated[ + Optional[AuthenticationTypeOptions], pydantic.Field(alias="authType") ] = None - r"""Use Assume Role credentials to access S3""" + r"""Authentication type""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + format_: Annotated[Optional[FormatOptions], pydantic.Field(alias="format")] = None + r"""Data format to use when sending data to ClickHouse. Defaults to JSON Compact.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + mapping_type: Annotated[ + Optional[MappingTypeOptions], pydantic.Field(alias="mappingType") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""How event fields are mapped to ClickHouse columns""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + async_inserts: Annotated[Optional[bool], pydantic.Field(alias="asyncInserts")] = ( + None + ) + r"""Collect data into batches for later processing on the ClickHouse server. Disable to write to a ClickHouse table immediately. Cribl sends the configured value with every insert (async_insert=1 or async_insert=0) so behavior is consistent across ClickHouse versions, including 26.3 LTS and later, where async inserts are enabled by default on the server.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Maximum size, in KB, of the request body""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Add the Output ID value to staging location""" + r"""Headers to add to all events""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Remove empty staging directories after moving files""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""List of headers that are safe to log in plain text""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + workload: Optional[str] = None + r"""Optional ClickHouse workload name to append as a SETTINGS clause on INSERT queries. Used for workload scheduling classification.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + dump_format_errors_to_disk: Annotated[ + Optional[bool], pydantic.Field(alias="dumpFormatErrorsToDisk") ] = None - r"""Buffer size used to write to a file""" + r"""Log the most recent event that fails to match the table schema""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + username: Optional[str] = None + r"""Username""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + password: Optional[str] = None + r"""Password""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + r"""Select or create a secret that references your credentials""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + sql_username: Annotated[Optional[str], pydantic.Field(alias="sqlUsername")] = None + r"""Username for certificate authentication""" + + wait_for_async_inserts: Annotated[ + Optional[bool], pydantic.Field(alias="waitForAsyncInserts") ] = None + r"""Cribl will wait for confirmation that data has been fully inserted into the ClickHouse database before proceeding. Disabling this option can increase throughput, but Cribl won't be able to verify data has been completely inserted.""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + exclude_mapping_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeMappingFields") + ] = None + r"""Fields to exclude from sending to ClickHouse""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + describe_table: Annotated[Optional[str], pydantic.Field(alias="describeTable")] = ( None ) - r"""Secret key""" + r"""Retrieves the table schema from ClickHouse and populates the Column Mapping table""" - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" - - storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") - ] = None - r"""Storage class to select for uploaded objects""" - - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), - ] = None - r"""Server-side encryption to use for uploaded objects""" - - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + column_mappings: Annotated[ + Optional[List[ColumnMappingConfOutputClickHouse]], + pydantic.Field(alias="columnMappings"), ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + r"""Column Mapping""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Determines which data types are supported and how they are represented""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + r"""Codec to use to compress the persisted data""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + pq_controls: Annotated[ + Optional[OutputResponseOutputClickHousePqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + r"""Persistent queue controls.""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_table_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_tableName") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'tableName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableName' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") - ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") - ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") - ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") - ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - - template_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_accountId") - ] = None - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - - template_custom_source: Annotated[ - Optional[str], pydantic.Field(alias="__template_customSource") - ] = None - r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.AuthenticationTypeOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.FormatOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("mapping_type") + def serialize_mapping_type(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.MappingTypeOptions(value) except ValueError: return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.ObjectACLOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.StorageClassOptions(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -13465,71 +13085,56 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "endpoint", - "enableAssumeRole", - "assumeRoleExternalId", - "durationSeconds", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", - "addIdToStagePath", - "removeEmptyDirs", - "baseFileName", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", + "authType", + "format", + "mappingType", + "asyncInserts", + "tls", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "workload", + "dumpFormatErrorsToDisk", "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", - "kmsKeyId", - "automaticSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", "description", - "awsApiKey", - "awsSecret", - "emptyDirCleanupSec", - "directoryBatchSize", - "parquetSchema", - "deadletterPath", - "maxRetryNum", + "username", + "password", + "credentialsSecret", + "sqlUsername", + "waitForAsyncInserts", + "excludeMappingFields", + "describeTable", + "columnMappings", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_bucket", - "__template_region", - "__template_baseFileName", + "__template_url", + "__template_database", + "__template_tableName", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", - "__template_accountId", - "__template_customSource", - "__template_awsApiKey", - "__template_parquetSchema", "notifications", "status", ] @@ -13548,19 +13153,15 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDlS3Type(str, Enum): +class OutputResponseOutputDiskSpoolType(str, Enum): r"""Connector type identifier.""" - DL_S3 = "dl_s3" + DISK_SPOOL = "disk_spool" -class OutputResponseOutputDlS3TypedDict(TypedDict): - type: OutputResponseOutputDlS3Type +class OutputResponseOutputDiskSpoolTypedDict(TypedDict): + type: OutputResponseOutputDiskSpoolType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -13571,173 +13172,30 @@ class OutputResponseOutputDlS3TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the S3 bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - partitioning_fields: NotRequired[List[str]] - r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" + time_window: NotRequired[str] + r"""Time period for grouping spooled events. Default is 10m.""" + max_data_size: NotRequired[str] + r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + compress: NotRequired[CompressionOptionsPersistence] + r"""Data compression format. Default is gzip.""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_partitioning_fields: NotRequired[str] - r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputDlS3(BaseModel): - type: OutputResponseOutputDlS3Type +class OutputResponseOutputDiskSpool(BaseModel): + type: OutputResponseOutputDiskSpoolType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -13755,185 +13213,334 @@ class OutputResponseOutputDlS3(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + time_window: Annotated[Optional[str], pydantic.Field(alias="timeWindow")] = None + r"""Time period for grouping spooled events. Default is 10m.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access S3""" + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space that can be consumed before older buckets are deleted. Examples: 420MB, 4GB. Default is 1GB.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data before older buckets are deleted. Examples: 2h, 4d. Default is 24h.""" + + compress: Optional[CompressionOptionsPersistence] = None + r"""Data compression format. Default is gzip.""" + + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( None ) - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""JavaScript expression defining how files are partitioned and organized within the time-buckets. If blank, the event's __partition property is used and otherwise, events go directly into the time-bucket directory.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPersistence(value) + except ValueError: + return value + return value - region: Optional[str] = None - r"""Region where the S3 bucket is located""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "timeWindow", + "maxDataSize", + "maxDataTime", + "compress", + "partitionExpr", + "description", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") - ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + return m - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" +class OutputResponseOutputCriblLakeType(str, Enum): + r"""Connector type identifier.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" + CRIBL_LAKE = "cribl_lake" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" +class OutputResponseOutputCriblLakeFormat(str, Enum, metaclass=utils.OpenEnumMeta): + JSON = "json" + PARQUET = "parquet" + RAW = "raw" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None +class OutputResponseOutputCriblLakeTypedDict(TypedDict): + type: OutputResponseOutputCriblLakeType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None + max_file_open_time_sec: NotRequired[float] r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None + max_file_idle_time_sec: NotRequired[float] r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) + max_open_files: NotRequired[float] r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + header_line: NotRequired[str] r"""If set, this line will be written to the beginning of each output file""" - - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None + write_high_water_mark: NotRequired[float] r"""Buffer size used to write to a file""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None + deadletter_enabled: NotRequired[bool] r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None + force_close_on_shutdown: NotRequired[bool] r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" - - storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") - ] = None - r"""Storage class to select for uploaded objects""" - - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), - ] = None - r"""Server-side encryption to use for uploaded objects""" - - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" - - partitioning_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="partitioningFields") - ] = None - r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" - - description: Optional[str] = None + storage_location_id: NotRequired[str] + r"""Storage location that contains the target Lake dataset.""" + dest_path: NotRequired[str] + r"""Lake dataset to send the data to.""" + format_: NotRequired[OutputResponseOutputCriblLakeFormat] + dynamic_dataset: NotRequired[bool] + max_closing_files_to_backpressure: NotRequired[float] + max_concurrent_file_parts: NotRequired[float] + freshness_grace_period_sec: NotRequired[float] + description: NotRequired[str] r"""Optional description for this configuration.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" +class OutputResponseOutputCriblLake(BaseModel): + type: OutputResponseOutputCriblLakeType + r"""Connector type identifier.""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + storage_location_id: Annotated[ + Optional[str], pydantic.Field(alias="storageLocationId") + ] = None + r"""Storage location that contains the target Lake dataset.""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Lake dataset to send the data to.""" + + format_: Annotated[ + Optional[OutputResponseOutputCriblLakeFormat], pydantic.Field(alias="format") + ] = None + + dynamic_dataset: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicDataset") + ] = None + + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + ] = None + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + + freshness_grace_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="freshnessGracePeriodSec") + ] = None + + description: Optional[str] = None + r"""Optional description for this configuration.""" compress: Optional[CompressionOptionsHTTP] = None r"""Data compression format to apply to HTTP content before it is delivered""" @@ -14024,41 +13631,6 @@ class OutputResponseOutputDlS3(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: Annotated[ Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None @@ -14074,75 +13646,27 @@ class OutputResponseOutputDlS3(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") - ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") - ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - - template_partitioning_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitioningFields") - ] = None - r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -14161,29 +13685,11 @@ def serialize_on_disk_full_backpressure(self, value): return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): - if isinstance(value, str): - try: - return models.ObjectACLOptions(value) - except ValueError: - return value - return value - - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptions(value) - except ValueError: - return value - return value - - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) + return models.OutputResponseOutputCriblLakeFormat(value) except ValueError: return value return value @@ -14233,22 +13739,9 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "endpoint", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "region", - "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", + "stagePath", "addIdToStagePath", "removeEmptyDirs", - "format", "baseFileName", "fileNameSuffix", "maxFileSizeMB", @@ -14263,15 +13756,14 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", - "kmsKeyId", - "partitioningFields", + "storageLocationId", + "destPath", + "format", + "dynamicDataset", + "maxClosingFilesToBackpressure", + "maxConcurrentFileParts", + "freshnessGracePeriodSec", "description", - "awsApiKey", - "awsSecret", "compress", "compressionLevel", "automaticSchema", @@ -14290,23 +13782,10 @@ def serialize_model(self, handler): "deadletterPath", "maxRetryNum", "__template_streamtags", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_bucket", - "__template_region", - "__template_destPath", - "__template_format", "__template_baseFileName", "__template_fileNameSuffix", "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", - "__template_partitioningFields", - "__template_awsApiKey", + "__template_destPath", "__template_compress", "__template_parquetSchema", "notifications", @@ -14327,134 +13806,187 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCrowdstrikeNextGenSiemType(str, Enum): - r"""Connector type identifier.""" - - CROWDSTRIKE_NEXT_GEN_SIEM = "crowdstrike_next_gen_siem" - - -class OutputResponseOutputCrowdstrikeNextGenSiemPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputCrowdstrikeNextGenSiemPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class OutputResponseOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): - type: OutputResponseOutputCrowdstrikeNextGenSiemType +class OutputResponseOutputSecurityLakeTypedDict(TypedDict): + type: TypeOptionsSecuritylake r"""Connector type identifier.""" - url: str - r"""URL provided from a CrowdStrike data connector. - Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector - """ - format_: RequestFormatOptions - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + assume_role_arn: str + r"""Amazon Resource Name (ARN) of the role to assume""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + region: str + r"""Region where the Amazon Security Lake is located.""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + account_id: str + r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" + custom_source: str + r"""Name of the custom source configured in Amazon Security Lake""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + endpoint: NotRequired[str] + r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access S3""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""Next-Gen SIEM authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - OutputResponseOutputCrowdstrikeNextGenSiemPqControlsTypedDict - ] - r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_account_id: NotRequired[str] + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + template_custom_source: NotRequired[str] + r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputCrowdstrikeNextGenSiem(BaseModel): - type: OutputResponseOutputCrowdstrikeNextGenSiemType +class OutputResponseOutputSecurityLake(BaseModel): + type: TypeOptionsSecuritylake r"""Connector type identifier.""" - url: str - r"""URL provided from a CrowdStrike data connector. - Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector - """ + assume_role_arn: Annotated[str, pydantic.Field(alias="assumeRoleArn")] + r"""Amazon Resource Name (ARN) of the role to assume""" - format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + region: str + r"""Region where the Amazon Security Lake is located.""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + account_id: Annotated[str, pydantic.Field(alias="accountId")] + r"""ID of the AWS account whose data the Destination will write to Security Lake. This should have been configured when creating the Amazon Security Lake custom source.""" + + custom_source: Annotated[str, pydantic.Field(alias="customSource")] + r"""Name of the custom source configured in Amazon Security Lake""" id: Optional[str] = None r"""Unique ID for this output""" @@ -14465,7 +13997,7 @@ class OutputResponseOutputCrowdstrikeNextGenSiem(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -14473,289 +14005,473 @@ class OutputResponseOutputCrowdstrikeNextGenSiem(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + endpoint: Optional[str] = None + r"""Amazon Security Lake service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Amazon Security Lake-compatible endpoint.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Use Assume Role credentials to access S3""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""External ID to use when assuming role""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""AWS authentication method. Choose Auto to use IAM roles.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Headers to add to all events""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Add the Output ID value to staging location""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Remove empty staging directories after moving files""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Buffer size used to write to a file""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" - - token: Optional[str] = None - r"""Next-Gen SIEM authentication token""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Object ACL to assign to uploaded objects""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Storage class to select for uploaded objects""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Codec to use to compress the persisted data""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Determines which data types are supported and how they are represented""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_controls: Annotated[ - Optional[OutputResponseOutputCrowdstrikeNextGenSiemPqControls], - pydantic.Field(alias="pqControls"), + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""Persistent queue controls.""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), + ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") + ] = None + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") + ] = None + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + ] = None + r"""How frequently, in seconds, to clean up empty directories""" + + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") + ] = None + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + ] = None + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") + ] = None + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + + template_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_accountId") + ] = None + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + + template_custom_source: Annotated[ + Optional[str], pydantic.Field(alias="__template_customSource") + ] = None + r"""Binds 'customSource' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customSource' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.RequestFormatOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.StorageClassOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ServerSideEncryptionForUploadedObjectsOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ParquetVersionOptions(value) except ValueError: return value return value - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ "id", "pipeline", "systemFields", "environment", "streamtags", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "endpoint", + "enableAssumeRole", + "assumeRoleExternalId", + "durationSeconds", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "baseFileName", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", + "automaticSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsApiKey", + "awsSecret", + "emptyDirCleanupSec", + "directoryBatchSize", + "parquetSchema", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_bucket", + "__template_region", + "__template_baseFileName", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", + "__template_accountId", + "__template_customSource", + "__template_awsApiKey", + "__template_parquetSchema", "notifications", "status", ] @@ -14774,27 +14490,19 @@ def serialize_model(self, handler): return m -class OutputResponseOutputHumioHecType(str, Enum): +class OutputResponseOutputDlS3Type(str, Enum): r"""Connector type identifier.""" - HUMIO_HEC = "humio_hec" - - -class OutputResponseOutputHumioHecPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputHumioHecPqControls(BaseModel): - r"""Persistent queue controls.""" + DL_S3 = "dl_s3" -class OutputResponseOutputHumioHecTypedDict(TypedDict): - type: OutputResponseOutputHumioHecType +class OutputResponseOutputDlS3TypedDict(TypedDict): + type: OutputResponseOutputDlS3Type r"""Connector type identifier.""" - url: str - r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" - format_: RequestFormatOptions - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -14805,295 +14513,565 @@ class OutputResponseOutputHumioHecTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the S3 bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + partitioning_fields: NotRequired[List[str]] + r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_partitioning_fields: NotRequired[str] + r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class OutputResponseOutputDlS3(BaseModel): + type: OutputResponseOutputDlS3Type + r"""Connector type identifier.""" + + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access S3""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + region: Optional[str] = None + r"""Region where the S3 bucket is located""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") + ] = None + r"""Disable if you can access files within the bucket but not the bucket itself""" + + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + ] = None + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), + ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""CrowdStrike Falcon LogScale authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputHumioHecPqControlsTypedDict] - r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" -class OutputResponseOutputHumioHec(BaseModel): - type: OutputResponseOutputHumioHecType - r"""Connector type identifier.""" + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - url: str - r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] - r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None - id: Optional[str] = None - r"""Unique ID for this output""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Object ACL to assign to uploaded objects""" - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + ] = None + r"""Storage class to select for uploaded objects""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + partitioning_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="partitioningFields") ] = None - r"""Maximum size, in KB, of the request body""" + r"""List of fields to partition the path by, in addition to time, which is included automatically. The effective partition will be YYYY/MM/DD/HH/.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Compression level to apply before moving files to final destination""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") + ] = None + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Determines which data types are supported and how they are represented""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""Headers to add to all events""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""List of headers that are safe to log in plain text""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""How frequently, in seconds, to clean up empty directories""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - token: Optional[str] = None - r"""CrowdStrike Falcon LogScale authentication token""" + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") + ] = None + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Codec to use to compress the persisted data""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - pq_controls: Annotated[ - Optional[OutputResponseOutputHumioHecPqControls], - pydantic.Field(alias="pqControls"), + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") ] = None - r"""Persistent queue controls.""" + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_partitioning_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitioningFields") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'partitioningFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitioningFields' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -15102,52 +15080,88 @@ def serialize_failed_request_logging_mode(self, value): def serialize_format_(self, value): if isinstance(value, str): try: - return models.RequestFormatOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.StorageClassOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ServerSideEncryptionForUploadedObjectsOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -15161,42 +15175,82 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "endpoint", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", + "partitioningFields", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_bucket", + "__template_region", + "__template_destPath", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", + "__template_partitioningFields", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", "notifications", "status", ] @@ -15215,23 +15269,29 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCriblSearchEngineType(str, Enum): +class OutputResponseOutputCrowdstrikeNextGenSiemType(str, Enum): r"""Connector type identifier.""" - CRIBL_SEARCH_ENGINE = "cribl_search_engine" + CROWDSTRIKE_NEXT_GEN_SIEM = "crowdstrike_next_gen_siem" -class OutputResponseOutputCriblSearchEnginePqControlsTypedDict(TypedDict): +class OutputResponseOutputCrowdstrikeNextGenSiemPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputCriblSearchEnginePqControls(BaseModel): +class OutputResponseOutputCrowdstrikeNextGenSiemPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputCriblSearchEngineTypedDict(TypedDict): - type: OutputResponseOutputCriblSearchEngineType +class OutputResponseOutputCrowdstrikeNextGenSiemTypedDict(TypedDict): + type: OutputResponseOutputCrowdstrikeNextGenSiemType r"""Connector type identifier.""" + url: str + r"""URL provided from a CrowdStrike data connector. + Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector + """ + format_: RequestFormatOptions + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -15242,22 +15302,14 @@ class OutputResponseOutputCriblSearchEngineTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - exclude_fields: NotRequired[List[str]] - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -15271,12 +15323,14 @@ class OutputResponseOutputCriblSearchEngineTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -15284,24 +15338,14 @@ class OutputResponseOutputCriblSearchEngineTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] - r"""Cribl Worker endpoints""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""Next-Gen SIEM authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15324,26 +15368,36 @@ class OutputResponseOutputCriblSearchEngineTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputCriblSearchEnginePqControlsTypedDict] + pq_controls: NotRequired[ + OutputResponseOutputCrowdstrikeNextGenSiemPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputCriblSearchEngine(BaseModel): - type: OutputResponseOutputCriblSearchEngineType +class OutputResponseOutputCrowdstrikeNextGenSiem(BaseModel): + type: OutputResponseOutputCrowdstrikeNextGenSiemType r"""Connector type identifier.""" + url: str + r"""URL provided from a CrowdStrike data connector. + Example: https://ingest..crowdstrike.com/api/ingest/hec//v1/services/collector + """ + + format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -15361,27 +15415,6 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") - ] = None - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") - ] = None - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - - compression: Optional[CompressionOptionsGzipNone] = None - r"""Codec to use to compress the data before sending""" - concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -15395,6 +15428,9 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): ] = None r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -15422,6 +15458,11 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -15433,10 +15474,11 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], @@ -15453,42 +15495,19 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: Annotated[ - Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[URLConfOutputCriblHTTP]] = None - r"""Cribl Worker endpoints""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + token: Optional[str] = None + r"""Next-Gen SIEM authentication token""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -15540,7 +15559,7 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputCriblSearchEnginePqControls], + Optional[OutputResponseOutputCrowdstrikeNextGenSiemPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -15550,6 +15569,11 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -15560,31 +15584,35 @@ class OutputResponseOutputCriblSearchEngine(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipNone(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.RequestFormatOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -15634,34 +15662,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "tls", - "tokenTTLMinutes", - "excludeFields", - "compression", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", + "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "throttleRatePerSec", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "authTokens", "onBackpressure", - "useRoundRobinDns", "description", - "url", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -15675,9 +15695,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", "notifications", "status", ] @@ -15696,23 +15716,27 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCriblHTTPType(str, Enum): +class OutputResponseOutputHumioHecType(str, Enum): r"""Connector type identifier.""" - CRIBL_HTTP = "cribl_http" + HUMIO_HEC = "humio_hec" -class OutputResponseOutputCriblHTTPPqControlsTypedDict(TypedDict): +class OutputResponseOutputHumioHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputCriblHTTPPqControls(BaseModel): +class OutputResponseOutputHumioHecPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputCriblHTTPTypedDict(TypedDict): - type: OutputResponseOutputCriblHTTPType +class OutputResponseOutputHumioHecTypedDict(TypedDict): + type: OutputResponseOutputHumioHecType r"""Connector type identifier.""" + url: str + r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + format_: RequestFormatOptions + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -15723,22 +15747,14 @@ class OutputResponseOutputCriblHTTPTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - exclude_fields: NotRequired[List[str]] - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -15752,12 +15768,14 @@ class OutputResponseOutputCriblHTTPTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -15765,24 +15783,14 @@ class OutputResponseOutputCriblHTTPTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] - r"""Cribl Worker endpoints""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""CrowdStrike Falcon LogScale authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15805,26 +15813,32 @@ class OutputResponseOutputCriblHTTPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputCriblHTTPPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputHumioHecPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputCriblHTTP(BaseModel): - type: OutputResponseOutputCriblHTTPType +class OutputResponseOutputHumioHec(BaseModel): + type: OutputResponseOutputHumioHecType r"""Connector type identifier.""" + url: str + r"""URL to a CrowdStrike Falcon LogScale endpoint to send events to. Examples: https://cloud.us.humio.com/api/v1/ingest/hec for JSON and https://cloud.us.humio.com/api/v1/ingest/hec/raw for raw""" + + format_: Annotated[RequestFormatOptions, pydantic.Field(alias="format")] + r"""When set to JSON, the event is automatically formatted with required fields before sending. When set to Raw, only the event's `_raw` value is sent.""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -15842,27 +15856,6 @@ class OutputResponseOutputCriblHTTP(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") - ] = None - r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") - ] = None - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - - compression: Optional[CompressionOptionsGzipNone] = None - r"""Codec to use to compress the data before sending""" - concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -15876,6 +15869,9 @@ class OutputResponseOutputCriblHTTP(BaseModel): ] = None r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -15903,6 +15899,11 @@ class OutputResponseOutputCriblHTTP(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -15914,10 +15915,11 @@ class OutputResponseOutputCriblHTTP(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], @@ -15934,11 +15936,6 @@ class OutputResponseOutputCriblHTTP(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_tokens: Annotated[ - Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") - ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None @@ -15947,29 +15944,11 @@ class OutputResponseOutputCriblHTTP(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[URLConfOutputCriblHTTP]] = None - r"""Cribl Worker endpoints""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + token: Optional[str] = None + r"""CrowdStrike Falcon LogScale authentication token""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16021,7 +16000,7 @@ class OutputResponseOutputCriblHTTP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputCriblHTTPPqControls], + Optional[OutputResponseOutputHumioHecPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -16031,6 +16010,11 @@ class OutputResponseOutputCriblHTTP(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -16041,31 +16025,35 @@ class OutputResponseOutputCriblHTTP(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipNone(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.RequestFormatOptions(value) + except ValueError: + return value + return value + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -16115,34 +16103,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "tls", - "tokenTTLMinutes", - "excludeFields", - "compression", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", + "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "throttleRatePerSec", + "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "authTokens", "onBackpressure", "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16156,9 +16136,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_url", "notifications", "status", ] @@ -16177,16 +16157,33 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCriblTCPPqControlsTypedDict(TypedDict): +class OutputResponseOutputCriblSearchEngineType(str, Enum): + r"""Connector type identifier.""" + + CRIBL_SEARCH_ENGINE = "cribl_search_engine" + + +class OutputResponseSendAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + + # Logs + LOGS = "logs" + # Metrics + METRICS = "metrics" + # Logs and Metrics + BOTH = "both" + + +class OutputResponseOutputCriblSearchEnginePqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputCriblTCPPqControls(BaseModel): +class OutputResponseOutputCriblSearchEnginePqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputCriblTCPTypedDict(TypedDict): - type: TypeOptionsCribltcp +class OutputResponseOutputCriblSearchEngineTypedDict(TypedDict): + type: OutputResponseOutputCriblSearchEngineType r"""Connector type identifier.""" id: NotRequired[str] r"""Unique ID for this output""" @@ -16199,43 +16196,67 @@ class OutputResponseOutputCriblTCPTypedDict(TypedDict): streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" load_balanced: NotRequired[bool] - r"""Use load-balanced destinations""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" exclude_fields: NotRequired[List[str]] r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + send_as: NotRequired[OutputResponseSendAs] + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" + url: NotRequired[str] + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" + urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] + r"""Cribl Worker endpoints""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16258,24 +16279,24 @@ class OutputResponseOutputCriblTCPTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputCriblTCPPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputCriblSearchEnginePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - -class OutputResponseOutputCriblTCP(BaseModel): - type: TypeOptionsCribltcp + +class OutputResponseOutputCriblSearchEngine(BaseModel): + type: OutputResponseOutputCriblSearchEngineType r"""Connector type identifier.""" id: Optional[str] = None @@ -16298,68 +16319,126 @@ class OutputResponseOutputCriblTCP(BaseModel): load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Use load-balanced destinations""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") + ] = None + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" + + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") + ] = None + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" compression: Optional[CompressionOptionsGzipNone] = None r"""Codec to use to compress the data before sending""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" throttle_rate_per_sec: Annotated[ Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - auth_tokens: Annotated[ - Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") ] = None - r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl Search Source in Cribl.Cloud.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + send_as: Annotated[ + Optional[OutputResponseSendAs], pydantic.Field(alias="sendAs") + ] = None + r"""Which signals this Destination carries. Logs sends everything to log search, including metric events. Metrics routes metric events to the metric store and drops everything else. Logs and Metrics routes metric events to the metric store and sends the rest to log search. Metric routing requires the receiving Cribl Search Source to be enabled for metrics storage; if it is not, metric events are discarded rather than stored as logs.""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + description: Optional[str] = None r"""Optional description for this configuration.""" - host: Optional[str] = None - r"""The hostname of the receiver""" - - port: Optional[float] = None - r"""The port to connect to on the provided host""" + url: Optional[str] = None + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" + urls: Optional[List[URLConfOutputCriblHTTP]] = None + r"""Cribl Worker endpoints""" dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") @@ -16371,11 +16450,6 @@ class OutputResponseOutputCriblTCP(BaseModel): ] = None r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") - ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -16426,7 +16500,7 @@ class OutputResponseOutputCriblTCP(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputCriblTCPPqControls], + Optional[OutputResponseOutputCriblSearchEnginePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -16436,22 +16510,22 @@ class OutputResponseOutputCriblTCP(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -16466,6 +16540,15 @@ def serialize_compression(self, value): return value return value + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -16475,6 +16558,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("send_as") + def serialize_send_as(self, value): + if isinstance(value, str): + try: + return models.OutputResponseSendAs(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -16512,24 +16604,34 @@ def serialize_model(self, handler): "environment", "streamtags", "loadBalanced", - "compression", - "logFailedRequests", - "throttleRatePerSec", "tls", - "connectionTimeout", - "writeTimeout", "tokenTTLMinutes", - "authTokens", "excludeFields", + "compression", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "throttleRatePerSec", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "authTokens", "onBackpressure", + "sendAs", + "useRoundRobinDns", "description", - "host", - "port", + "url", "excludeSelf", - "hosts", + "urls", "dnsResolvePeriodSec", "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -16543,9 +16645,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_host", - "__template_port", + "__template_url", "notifications", "status", ] @@ -16564,52 +16666,22 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDatasetType(str, Enum): +class OutputResponseOutputCriblHTTPType(str, Enum): r"""Connector type identifier.""" - DATASET = "dataset" - - -class OutputResponseOutputDatasetSeverity(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - - # 0 - finest - FINEST = "finest" - # 1 - finer - FINER = "finer" - # 2 - fine - FINE = "fine" - # 3 - info - INFO = "info" - # 4 - warning - WARNING = "warning" - # 5 - error - ERROR = "error" - # 6 - fatal - FATAL = "fatal" - - -class OutputResponseDataSetSite(str, Enum, metaclass=utils.OpenEnumMeta): - r"""DataSet site to which events should be sent""" - - # US - US = "us" - # Europe - EU = "eu" - # Custom - CUSTOM = "custom" + CRIBL_HTTP = "cribl_http" -class OutputResponseOutputDatasetPqControlsTypedDict(TypedDict): +class OutputResponseOutputCriblHTTPPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputDatasetPqControls(BaseModel): +class OutputResponseOutputCriblHTTPPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputDatasetTypedDict(TypedDict): - type: OutputResponseOutputDatasetType +class OutputResponseOutputCriblHTTPTypedDict(TypedDict): + type: OutputResponseOutputCriblHTTPType r"""Connector type identifier.""" id: NotRequired[str] r"""Unique ID for this output""" @@ -16621,33 +16693,22 @@ class OutputResponseOutputDatasetTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - message_field: NotRequired[str] - r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" + load_balanced: NotRequired[bool] + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + token_ttl_minutes: NotRequired[float] + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" exclude_fields: NotRequired[List[str]] - r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - server_host_field: NotRequired[str] - r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - timestamp_field: NotRequired[str] - r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - default_severity: NotRequired[OutputResponseOutputDatasetSeverity] - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - site: NotRequired[OutputResponseDataSetSite] - r"""DataSet site to which events should be sent""" + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -16661,21 +16722,37 @@ class OutputResponseOutputDatasetTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + auth_tokens: NotRequired[List[AuthTokenConfOutputCriblHTTPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + url: NotRequired[str] + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[URLConfOutputCriblHTTPTypedDict]] + r"""Cribl Worker endpoints""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16698,28 +16775,24 @@ class OutputResponseOutputDatasetTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputDatasetPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputCriblHTTPPqControlsTypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""A 'Log Write Access' API key for the DataSet account""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: NotRequired[str] - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputDataset(BaseModel): - type: OutputResponseOutputDatasetType +class OutputResponseOutputCriblHTTP(BaseModel): + type: OutputResponseOutputCriblHTTPType r"""Connector type identifier.""" id: Optional[str] = None @@ -16739,47 +16812,26 @@ class OutputResponseOutputDataset(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None - r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" - - exclude_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="excludeFields") - ] = None - r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - - server_host_field: Annotated[ - Optional[str], pydantic.Field(alias="serverHostField") - ] = None - r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - - timestamp_field: Annotated[ - Optional[str], pydantic.Field(alias="timestampField") - ] = None - r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - - default_severity: Annotated[ - Optional[OutputResponseOutputDatasetSeverity], - pydantic.Field(alias="defaultSeverity"), - ] = None - r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") ] = None + r"""The number of minutes before the internally generated authentication token expires. Valid values are between 1 and 60.""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" - site: Optional[OutputResponseDataSetSite] = None - r"""DataSet site to which events should be sent""" + compression: Optional[CompressionOptionsGzipNone] = None + r"""Codec to use to compress the data before sending""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -16794,9 +16846,6 @@ class OutputResponseOutputDataset(BaseModel): ] = None r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -16824,11 +16873,6 @@ class OutputResponseOutputDataset(BaseModel): ] = None r"""Headers to add to all events""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -16840,25 +16884,62 @@ class OutputResponseOutputDataset(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Enter API key directly, or select a stored secret""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + auth_tokens: Annotated[ + Optional[List[AuthTokenConfOutputCriblHTTP]], pydantic.Field(alias="authTokens") + ] = None + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl HTTP Source in Cribl.Cloud.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + url: Optional[str] = None + r"""URL of a Cribl Worker to send events to, such as http://localhost:10200""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[URLConfOutputCriblHTTP]] = None + r"""Cribl Worker endpoints""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16910,17 +16991,11 @@ class OutputResponseOutputDataset(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputDatasetPqControls], + Optional[OutputResponseOutputCriblHTTPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""A 'Log Write Access' API key for the DataSet account""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -16936,31 +17011,22 @@ class OutputResponseOutputDataset(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_customUrl") - ] = None - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("default_severity") - def serialize_default_severity(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputDatasetSeverity(value) - except ValueError: - return value - return value - - @field_serializer("site") - def serialize_site(self, value): + @field_serializer("compression") + def serialize_compression(self, value): if isinstance(value, str): try: - return models.OutputResponseDataSetSite(value) + return models.CompressionOptionsGzipNone(value) except ValueError: return value return value @@ -16983,15 +17049,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -17028,32 +17085,34 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "messageField", + "loadBalanced", + "tls", + "tokenTTLMinutes", "excludeFields", - "serverHostField", - "timestampField", - "defaultSeverity", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "site", + "compression", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", - "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", + "throttleRatePerSec", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "authTokens", "onBackpressure", - "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17066,12 +17125,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_customUrl", + "__template_url", "notifications", "status", ] @@ -17090,31 +17147,17 @@ def serialize_model(self, handler): return m -class OutputResponseOutputServiceNowType(str, Enum): - r"""Connector type identifier.""" - - SERVICE_NOW = "service_now" - - -class OutputResponseOutputServiceNowPqControlsTypedDict(TypedDict): +class OutputResponseOutputCriblTCPPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputServiceNowPqControls(BaseModel): +class OutputResponseOutputCriblTCPPqControls(BaseModel): r"""Persistent queue controls.""" - -class OutputResponseOutputServiceNowTypedDict(TypedDict): - type: OutputResponseOutputServiceNowType - r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - token_secret: str - r"""Select or create a stored text secret""" - otlp_version: OtlpVersionOptions - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - protocol: ProtocolOptions - r"""Select a transport option for OpenTelemetry""" + +class OutputResponseOutputCriblTCPTypedDict(TypedDict): + type: TypeOptionsCribltcp + r"""Connector type identifier.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -17125,68 +17168,44 @@ class OutputResponseOutputServiceNowTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_token_name: NotRequired[str] - r"""Auth token name""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - compress: NotRequired[CompressionOptionsDeflateGzip] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_compress: NotRequired[CompressionOptionsMessages] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_traces_endpoint_override: NotRequired[str] - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_metrics_endpoint_override: NotRequired[str] - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: NotRequired[str] - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + load_balanced: NotRequired[bool] + r"""Use load-balanced destinations""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" connection_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + token_ttl_minutes: NotRequired[float] + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" + auth_tokens: NotRequired[List[AuthTokenConfInputCriblTCPTypedDict]] + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" + exclude_fields: NotRequired[List[str]] + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] - r"""TLS settings (client side)""" + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -17209,36 +17228,26 @@ class OutputResponseOutputServiceNowTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputServiceNowPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputCriblTCPPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputServiceNow(BaseModel): - type: OutputResponseOutputServiceNowType +class OutputResponseOutputCriblTCP(BaseModel): + type: TypeOptionsCribltcp r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" - - token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] - r"""Select or create a stored text secret""" - - otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - - protocol: ProtocolOptions - r"""Select a transport option for OpenTelemetry""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -17256,91 +17265,51 @@ class OutputResponseOutputServiceNow(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Auth token name""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") - ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - - compress: Optional[CompressionOptionsDeflateGzip] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - - http_compress: Annotated[ - Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") - ] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - - http_traces_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") - ] = None - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - - http_metrics_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") - ] = None - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - - http_logs_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") - ] = None - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + r"""Use load-balanced destinations""" - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + compression: Optional[CompressionOptionsGzipNone] = None + r"""Codec to use to compress the data before sending""" - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + r"""Use to troubleshoot issues with sending data""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + auth_tokens: Annotated[ + Optional[List[AuthTokenConfInputCriblTCP]], pydantic.Field(alias="authTokens") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Shared secrets to be used by connected environments to authorize connections. These tokens should also be installed in Cribl TCP Source in Cribl.Cloud.""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") ] = None - r"""How often the sender should ping the peer to keep the connection open""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" + r"""Fields to exclude from the event. By default, all internal fields except `__output` are sent. Example: `cribl_pipe`, `c*`. Wildcards supported.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -17350,47 +17319,32 @@ class OutputResponseOutputServiceNow(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + host: Optional[str] = None + r"""The hostname of the receiver""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + port: Optional[float] = None + r"""The port to connect to on the provided host""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None + r"""How far back in time to keep traffic stats for load balancing purposes""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - tls: Optional[TLSSettingsClientSideTypeExtended] = None - r"""TLS settings (client side)""" + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17442,7 +17396,7 @@ class OutputResponseOutputServiceNow(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputServiceNowPqControls], + Optional[OutputResponseOutputCriblTCPPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -17452,63 +17406,32 @@ class OutputResponseOutputServiceNow(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.OtlpVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.ProtocolOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsDeflateGzip(value) - except ValueError: - return value - return value - - @field_serializer("http_compress") - def serialize_http_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsMessages(value) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("compression") + def serialize_compression(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.CompressionOptionsGzipNone(value) except ValueError: return value return value @@ -17558,35 +17481,25 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authTokenName", - "maxPayloadSizeKB", - "preserveNativeAnyValue", - "compress", - "httpCompress", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", - "httpLogsEndpointOverride", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", - "concurrency", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "failedRequestLoggingMode", + "loadBalanced", + "compression", + "logFailedRequests", + "throttleRatePerSec", + "tls", "connectionTimeout", - "keepAliveTime", - "keepAlive", + "writeTimeout", + "tokenTTLMinutes", + "authTokens", + "excludeFields", "onBackpressure", "description", - "rejectUnauthorized", - "useRoundRobinDns", - "extraHttpHeaders", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "tls", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17600,8 +17513,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_host", + "__template_port", "notifications", "status", ] @@ -17620,55 +17534,53 @@ def serialize_model(self, handler): return m -class OutputResponseOutputOpenTelemetryType(str, Enum): +class OutputResponseOutputDatasetType(str, Enum): r"""Connector type identifier.""" - OPEN_TELEMETRY = "open_telemetry" + DATASET = "dataset" -class OutputResponseOutputOpenTelemetryOTLPVersion( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" +class OutputResponseOutputDatasetSeverity(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - # 0.10.0 - ZERO_DOT_10_DOT_0 = "0.10.0" - # 1.3.1 - ONE_DOT_3_DOT_1 = "1.3.1" + # 0 - finest + FINEST = "finest" + # 1 - finer + FINER = "finer" + # 2 - fine + FINE = "fine" + # 3 - info + INFO = "info" + # 4 - warning + WARNING = "warning" + # 5 - error + ERROR = "error" + # 6 - fatal + FATAL = "fatal" -class OutputResponseOutputOpenTelemetryAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication type""" +class OutputResponseDataSetSite(str, Enum, metaclass=utils.OpenEnumMeta): + r"""DataSet site to which events should be sent""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth (text secret) - OAUTH_SECRET = "oauthSecret" + # US + US = "us" + # Europe + EU = "eu" + # Custom + CUSTOM = "custom" -class OutputResponseOutputOpenTelemetryPqControlsTypedDict(TypedDict): +class OutputResponseOutputDatasetPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputOpenTelemetryPqControls(BaseModel): +class OutputResponseOutputDatasetPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputOpenTelemetryTypedDict(TypedDict): - type: OutputResponseOutputOpenTelemetryType +class OutputResponseOutputDatasetTypedDict(TypedDict): + type: OutputResponseOutputDatasetType r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -17679,98 +17591,61 @@ class OutputResponseOutputOpenTelemetryTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[ProtocolOptions] - r"""Select a transport option for OpenTelemetry""" - otlp_version: NotRequired[OutputResponseOutputOpenTelemetryOTLPVersion] - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - compress: NotRequired[CompressionOptionsDeflateGzip] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - http_compress: NotRequired[CompressionOptionsMessages] - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - auth_type: NotRequired[OutputResponseOutputOpenTelemetryAuthenticationType] - r"""Authentication type""" - http_traces_endpoint_override: NotRequired[str] - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_metrics_endpoint_override: NotRequired[str] - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - http_logs_endpoint_override: NotRequired[str] - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" - oauth_text_secret: NotRequired[str] - r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + message_field: NotRequired[str] + r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" + exclude_fields: NotRequired[List[str]] + r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" + server_host_field: NotRequired[str] + r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" + timestamp_field: NotRequired[str] + r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" + default_severity: NotRequired[OutputResponseOutputDatasetSeverity] + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + site: NotRequired[OutputResponseDataSetSite] + r"""DataSet site to which events should be sent""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), that value will take precedence. """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] - r"""TLS settings (client side)""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -17793,29 +17668,30 @@ class OutputResponseOutputOpenTelemetryTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputOpenTelemetryPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputDatasetPqControlsTypedDict] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""A 'Log Write Access' API key for the DataSet account""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_custom_url: NotRequired[str] + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputOpenTelemetry(BaseModel): - type: OutputResponseOutputOpenTelemetryType +class OutputResponseOutputDataset(BaseModel): + type: OutputResponseOutputDatasetType r"""Connector type identifier.""" - endpoint: str - r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -17833,61 +17709,47 @@ class OutputResponseOutputOpenTelemetry(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[ProtocolOptions] = None - r"""Select a transport option for OpenTelemetry""" - - otlp_version: Annotated[ - Optional[OutputResponseOutputOpenTelemetryOTLPVersion], - pydantic.Field(alias="otlpVersion"), - ] = None - r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None + r"""Name of the event field that contains the message or attributes to send. If not specified, all of the event's non-internal fields will be sent as attributes.""" - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + exclude_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="excludeFields") ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - - compress: Optional[CompressionOptionsDeflateGzip] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + r"""Fields to exclude from the event if the Message field is either unspecified or refers to an object. Ignored if the Message field is a string. If empty, we send all non-internal fields.""" - http_compress: Annotated[ - Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + server_host_field: Annotated[ + Optional[str], pydantic.Field(alias="serverHostField") ] = None - r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + r"""Name of the event field that contains the `serverHost` identifier. If not specified, defaults to `cribl_`.""" - auth_type: Annotated[ - Optional[OutputResponseOutputOpenTelemetryAuthenticationType], - pydantic.Field(alias="authType"), + timestamp_field: Annotated[ + Optional[str], pydantic.Field(alias="timestampField") ] = None - r"""Authentication type""" + r"""Name of the event field that contains the timestamp. If not specified, defaults to `ts`, `_time`, or `Date.now()`, in that order.""" - http_traces_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") + default_severity: Annotated[ + Optional[OutputResponseOutputDatasetSeverity], + pydantic.Field(alias="defaultSeverity"), ] = None - r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + r"""Default value for event severity. If the `sev` or `__severity` fields are set on an event, the first one matching will override this value.""" - http_metrics_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - http_logs_endpoint_override: Annotated[ - Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") - ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + site: Optional[OutputResponseDataSetSite] = None + r"""DataSet site to which events should be sent""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -17897,6 +17759,22 @@ class OutputResponseOutputOpenTelemetry(BaseModel): ] = None r"""Maximum size, in KB, of the request body""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -17910,131 +17788,47 @@ class OutputResponseOutputOpenTelemetry(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") - ] = None - r"""How often the sender should ping the peer to keep the connection open""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - - oauth_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="oauthTextSecret") - ] = None - r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" - - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Headers to add to all events""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None r"""List of headers that are safe to log in plain text""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""How to handle events when all receivers are exerting backpressure""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") ] = None + r"""Enter API key directly, or select a stored secret""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - tls: Optional[TLSSettingsClientSideTypeExtended] = None - r"""TLS settings (client side)""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18086,11 +17880,17 @@ class OutputResponseOutputOpenTelemetry(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputOpenTelemetryPqControls], + Optional[OutputResponseOutputDatasetPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""A 'Log Write Access' API key for the DataSet account""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None @@ -18106,49 +17906,49 @@ class OutputResponseOutputOpenTelemetry(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") + template_custom_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_customUrl") ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + @field_serializer("default_severity") + def serialize_default_severity(self, value): if isinstance(value, str): try: - return models.ProtocolOptions(value) + return models.OutputResponseOutputDatasetSeverity(value) except ValueError: return value return value - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): + @field_serializer("site") + def serialize_site(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputOpenTelemetryOTLPVersion(value) + return models.OutputResponseDataSetSite(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.CompressionOptionsDeflateGzip(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("http_compress") - def serialize_http_compress(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsMessages(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -18157,25 +17957,7 @@ def serialize_http_compress(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputOpenTelemetryAuthenticationType(value) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) + return models.AuthenticationMethodOptionsAPI(value) except ValueError: return value return value @@ -18216,50 +17998,32 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "otlpVersion", - "preserveNativeAnyValue", - "compress", - "httpCompress", - "authType", - "httpTracesEndpointOverride", - "httpMetricsEndpointOverride", - "httpLogsEndpointOverride", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", + "messageField", + "excludeFields", + "serverHostField", + "timestampField", + "defaultSeverity", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "site", "concurrency", "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "keepAlive", + "safeHeaders", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", - "oauthTextSecret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "rejectUnauthorized", - "useRoundRobinDns", - "extraHttpHeaders", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "tls", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -18272,10 +18036,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_loginUrl", + "__template_customUrl", "notifications", "status", ] @@ -18294,22 +18060,31 @@ def serialize_model(self, handler): return m -class OutputResponseOutputRingType(str, Enum): +class OutputResponseOutputServiceNowType(str, Enum): r"""Connector type identifier.""" - RING = "ring" + SERVICE_NOW = "service_now" -class OutputResponseOutputRingDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format of the output data.""" +class OutputResponseOutputServiceNowPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - JSON = "json" - RAW = "raw" + +class OutputResponseOutputServiceNowPqControls(BaseModel): + r"""Persistent queue controls.""" -class OutputResponseOutputRingTypedDict(TypedDict): - type: OutputResponseOutputRingType +class OutputResponseOutputServiceNowTypedDict(TypedDict): + type: OutputResponseOutputServiceNowType r"""Connector type identifier.""" + endpoint: str + r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + token_secret: str + r"""Select or create a stored text secret""" + otlp_version: OtlpVersionOptions + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + protocol: ProtocolOptions + r"""Select a transport option for OpenTelemetry""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -18320,35 +18095,119 @@ class OutputResponseOutputRingTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - format_: NotRequired[OutputResponseOutputRingDataFormat] - r"""Format of the output data.""" - partition_expr: NotRequired[str] - r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" - max_data_size: NotRequired[str] - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - max_data_time: NotRequired[str] - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - compress: NotRequired[DataCompressionFormatOptionsPersistence] - r"""Data compression format""" - dest_path: NotRequired[str] - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + auth_token_name: NotRequired[str] + r"""Auth token name""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_traces_endpoint_override: NotRequired[str] + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_metrics_endpoint_override: NotRequired[str] + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputServiceNowPqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputRing(BaseModel): - type: OutputResponseOutputRingType - r"""Connector type identifier.""" +class OutputResponseOutputServiceNow(BaseModel): + type: OutputResponseOutputServiceNowType + r"""Connector type identifier.""" + + endpoint: str + r"""The endpoint where ServiceNow events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets)""" + + token_secret: Annotated[str, pydantic.Field(alias="tokenSecret")] + r"""Select or create a stored text secret""" + + otlp_version: Annotated[OtlpVersionOptions, pydantic.Field(alias="otlpVersion")] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + protocol: ProtocolOptions + r"""Select a transport option for OpenTelemetry""" id: Optional[str] = None r"""Unique ID for this output""" @@ -18367,76 +18226,295 @@ class OutputResponseOutputRing(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - format_: Annotated[ - Optional[OutputResponseOutputRingDataFormat], pydantic.Field(alias="format") - ] = None - r"""Format of the output data.""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + auth_token_name: Annotated[Optional[str], pydantic.Field(alias="authTokenName")] = ( None ) - r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" + r"""Auth token name""" - max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None - r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None - r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - compress: Optional[DataCompressionFormatOptionsPersistence] = None - r"""Data compression format""" + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + ] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + http_traces_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") + ] = None + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + http_metrics_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") + ] = None + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + ] = None + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + ] = None + r"""Batch event data upon dynamic metadata (whether presented or not)""" + + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") + ] = None + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[OutputResponseOutputServiceNowPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): + if isinstance(value, str): + try: + return models.OtlpVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsDeflateGzip(value) + except ValueError: + return value + return value + + @field_serializer("http_compress") + def serialize_http_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsMessages(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputRingDataFormat(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.DataCompressionFormatOptionsPersistence(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -18450,15 +18528,49 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "format", - "partitionExpr", - "maxDataSize", - "maxDataTime", + "authTokenName", + "maxPayloadSizeKB", + "preserveNativeAnyValue", "compress", - "destPath", + "httpCompress", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", + "concurrency", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", "onBackpressure", "description", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "tls", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", "notifications", "status", @@ -18478,10 +18590,27 @@ def serialize_model(self, handler): return m -class OutputResponseOutputPrometheusAuthenticationType( +class OutputResponseOutputOpenTelemetryType(str, Enum): + r"""Connector type identifier.""" + + OPEN_TELEMETRY = "open_telemetry" + + +class OutputResponseOutputOpenTelemetryOTLPVersion( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Remote Write authentication type""" + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + + # 0.10.0 + ZERO_DOT_10_DOT_0 = "0.10.0" + # 1.3.1 + ONE_DOT_3_DOT_1 = "1.3.1" + + +class OutputResponseOutputOpenTelemetryAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication type""" # None NONE = "none" @@ -18493,62 +18622,114 @@ class OutputResponseOutputPrometheusAuthenticationType( TOKEN = "token" # Token (text secret) TEXT_SECRET = "textSecret" - # AWS Signature v4 - AWS_SIGV4 = "aws_sigv4" + # OAuth (text secret) + OAUTH_SECRET = "oauthSecret" -class OutputResponseOutputPrometheusPqControlsTypedDict(TypedDict): +class OutputResponseOutputOpenTelemetryPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputPrometheusPqControls(BaseModel): +class OutputResponseOutputOpenTelemetryPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputPrometheusTypedDict(TypedDict): - type: TypeOptionsPrometheus +class OutputResponseOutputOpenTelemetryTypedDict(TypedDict): + type: OutputResponseOutputOpenTelemetryType r"""Connector type identifier.""" - url: str - r"""The endpoint to send metrics to""" + endpoint: str + r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - send_metadata: NotRequired[bool] - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - use_prometheus_histogram_bucket_suffix: NotRequired[bool] - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" + protocol: NotRequired[ProtocolOptions] + r"""Select a transport option for OpenTelemetry""" + otlp_version: NotRequired[OutputResponseOutputOpenTelemetryOTLPVersion] + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + auth_type: NotRequired[OutputResponseOutputOpenTelemetryAuthenticationType] + r"""Authentication type""" + http_traces_endpoint_override: NotRequired[str] + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_metrics_endpoint_override: NotRequired[str] + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" response_retry_settings: NotRequired[ @@ -18558,14 +18739,8 @@ class OutputResponseOutputPrometheusTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[OutputResponseOutputPrometheusAuthenticationType] - r"""Remote Write authentication type""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - metrics_flush_period_sec: NotRequired[float] - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -18588,62 +18763,28 @@ class OutputResponseOutputPrometheusTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputPrometheusPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputOpenTelemetryPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - region: NotRequired[str] - r"""AWS region used to sign Remote Write requests""" - aws_service: NotRequired[str] - r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Prometheus""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_aws_service: NotRequired[str] - r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputPrometheus(BaseModel): - type: TypeOptionsPrometheus +class OutputResponseOutputOpenTelemetry(BaseModel): + type: OutputResponseOutputOpenTelemetryType r"""Connector type identifier.""" - url: str - r"""The endpoint to send metrics to""" + endpoint: str + r"""The endpoint where OTel events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets). Unspecified ports will default to 4317, unless the endpoint is an HTTPS-based URL or TLS is enabled, in which case 443 will be used.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -18654,7 +18795,7 @@ class OutputResponseOutputPrometheus(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -18662,20 +18803,61 @@ class OutputResponseOutputPrometheus(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") + protocol: Optional[ProtocolOptions] = None + r"""Select a transport option for OpenTelemetry""" + + otlp_version: Annotated[ + Optional[OutputResponseOutputOpenTelemetryOTLPVersion], + pydantic.Field(alias="otlpVersion"), ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + r"""The version of OTLP Protobuf definitions to use when structuring data to send""" - send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( - None - ) - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - use_prometheus_histogram_bucket_suffix: Annotated[ - Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") ] = None - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + auth_type: Annotated[ + Optional[OutputResponseOutputOpenTelemetryAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + + http_traces_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpTracesEndpointOverride") + ] = None + r"""If you want to send traces to the default `{endpoint}/v1/traces` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + http_metrics_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpMetricsEndpointOverride") + ] = None + r"""If you want to send metrics to the default `{endpoint}/v1/metrics` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + ] = None + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + ] = None + r"""Batch event data upon dynamic metadata (whether presented or not)""" + + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") + ] = None + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -18685,19 +18867,6 @@ class OutputResponseOutputPrometheus(BaseModel): ] = None r"""Maximum size, in KB, of the request body""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -18711,22 +18880,108 @@ class OutputResponseOutputPrometheus(BaseModel): ] = None r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Headers to add to all events""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Headers to add to all events""" safe_headers: Annotated[ Optional[List[str]], pydantic.Field(alias="safeHeaders") @@ -18748,24 +19003,8 @@ class OutputResponseOutputPrometheus(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - auth_type: Annotated[ - Optional[OutputResponseOutputPrometheusAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""Remote Write authentication type""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - metrics_flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") - ] = None - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18802,88 +19041,31 @@ class OutputResponseOutputPrometheus(BaseModel): r"""The location for the persistent queue files. To this field's value, the system will append: //.""" pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[OutputResponseOutputPrometheusPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsAutoSecret], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - region: Optional[str] = None - r"""AWS region used to sign Remote Write requests""" - - aws_service: Annotated[Optional[str], pydantic.Field(alias="awsService")] = None - r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Use Assume Role credentials to access Prometheus""" + r"""Codec to use to compress the persisted data""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""External ID to use when assuming role""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + pq_controls: Annotated[ + Optional[OutputResponseOutputOpenTelemetryPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Persistent queue controls.""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -18894,46 +19076,49 @@ class OutputResponseOutputPrometheus(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_aws_service: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsService") - ] = None - r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.ProtocolOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.OutputResponseOutputOpenTelemetryOTLPVersion(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsDeflateGzip(value) + except ValueError: + return value + return value + + @field_serializer("http_compress") + def serialize_http_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsMessages(value) except ValueError: return value return value @@ -18942,7 +19127,25 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputPrometheusAuthenticationType(value) + return models.OutputResponseOutputOpenTelemetryAuthenticationType(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -18974,15 +19177,6 @@ def serialize_pq_on_backpressure(self, value): return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAutoSecret(value) - except ValueError: - return value - return value - @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -18992,27 +19186,50 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "metricRenameExpr", - "sendMetadata", - "usePrometheusHistogramBucketSuffix", + "protocol", + "otlpVersion", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "authType", + "httpTracesEndpointOverride", + "httpMetricsEndpointOverride", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "onBackpressure", + "description", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "oauthTextSecret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", "safeHeaders", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "description", - "metricsFlushPeriodSec", + "tls", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -19025,27 +19242,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "awsAuthenticationMethod", - "awsSecret", - "region", - "awsService", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", "__template_streamtags", - "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_region", - "__template_awsService", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_loginUrl", "notifications", "status", ] @@ -19064,159 +19264,62 @@ def serialize_model(self, handler): return m -class OutputResponseOutputAmazonManagedPrometheusType(str, Enum): +class OutputResponseOutputRingType(str, Enum): r"""Connector type identifier.""" - AMAZON_MANAGED_PROMETHEUS = "amazon_managed_prometheus" - + RING = "ring" -class OutputResponseOutputAmazonManagedPrometheusPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseOutputRingDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format of the output data.""" -class OutputResponseOutputAmazonManagedPrometheusPqControls(BaseModel): - r"""Persistent queue controls.""" + JSON = "json" + RAW = "raw" -class OutputResponseOutputAmazonManagedPrometheusTypedDict(TypedDict): - type: OutputResponseOutputAmazonManagedPrometheusType +class OutputResponseOutputRingTypedDict(TypedDict): + type: OutputResponseOutputRingType r"""Connector type identifier.""" - url: str - r"""The Amazon Managed Service for Prometheus remote_write endpoint""" - aws_authentication_method: AuthenticationMethodOptionsAutoSecret - r"""AWS authentication method. Choose Auto to use IAM roles.""" - region: str - r"""Region where the AMSP is located""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access AMSP""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - send_metadata: NotRequired[bool] - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - use_prometheus_histogram_bucket_suffix: NotRequired[bool] - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + format_: NotRequired[OutputResponseOutputRingDataFormat] + r"""Format of the output data.""" + partition_expr: NotRequired[str] + r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" + max_data_size: NotRequired[str] + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" + max_data_time: NotRequired[str] + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" + compress: NotRequired[DataCompressionFormatOptionsPersistence] + r"""Data compression format""" + dest_path: NotRequired[str] + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - metrics_flush_period_sec: NotRequired[float] - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - OutputResponseOutputAmazonManagedPrometheusPqControlsTypedDict - ] - r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputAmazonManagedPrometheus(BaseModel): - type: OutputResponseOutputAmazonManagedPrometheusType +class OutputResponseOutputRing(BaseModel): + type: OutputResponseOutputRingType r"""Connector type identifier.""" - url: str - r"""The Amazon Managed Service for Prometheus remote_write endpoint""" - - aws_authentication_method: Annotated[ - AuthenticationMethodOptionsAutoSecret, - pydantic.Field(alias="awsAuthenticationMethod"), - ] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - region: str - r"""Region where the AMSP is located""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -19226,7 +19329,7 @@ class OutputResponseOutputAmazonManagedPrometheus(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -19234,248 +19337,67 @@ class OutputResponseOutputAmazonManagedPrometheus(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access AMSP""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") + format_: Annotated[ + Optional[OutputResponseOutputRingDataFormat], pydantic.Field(alias="format") ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + r"""Format of the output data.""" - send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( None ) - r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - - use_prometheus_histogram_bucket_suffix: Annotated[ - Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") - ] = None - r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - metrics_flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") - ] = None - r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[OutputResponseOutputAmazonManagedPrometheusPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""JS expression to define how files are partitioned and organized. If left blank, Cribl Stream will fallback on event.__partition.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + max_data_size: Annotated[Optional[str], pydantic.Field(alias="maxDataSize")] = None + r"""Maximum disk space allowed to be consumed (examples: 420MB, 4GB). When limit is reached, older data will be deleted.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + max_data_time: Annotated[Optional[str], pydantic.Field(alias="maxDataTime")] = None + r"""Maximum amount of time to retain data (examples: 2h, 4d). When limit is reached, older data will be deleted.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + compress: Optional[DataCompressionFormatOptionsPersistence] = None + r"""Data compression format""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Path to use to write metrics. Defaults to $CRIBL_HOME/state/""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""How to handle events when all receivers are exerting backpressure""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAutoSecret(value) + return models.OutputResponseOutputRingDataFormat(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataCompressionFormatOptionsPersistence(value) except ValueError: return value return value @@ -19484,34 +19406,7 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPq(value) - except ValueError: - return value - return value - - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value @@ -19525,51 +19420,15 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsSecretKey", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "metricRenameExpr", - "sendMetadata", - "usePrometheusHistogramBucketSuffix", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "format", + "partitionExpr", + "maxDataSize", + "maxDataTime", + "compress", + "destPath", "onBackpressure", "description", - "awsSecret", - "metricsFlushPeriodSec", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", "__template_streamtags", - "__template_url", - "__template_awsSecretKey", - "__template_region", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_failedRequestLoggingMode", "__template_onBackpressure", "notifications", "status", @@ -19589,53 +19448,60 @@ def serialize_model(self, handler): return m -class OutputResponseOutputLokiType(str, Enum): - r"""Connector type identifier.""" +class OutputResponseOutputPrometheusAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Remote Write authentication type""" - LOKI = "loki" + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + # AWS Signature v4 + AWS_SIGV4 = "aws_sigv4" -class OutputResponseOutputLokiPqControlsTypedDict(TypedDict): +class OutputResponseOutputPrometheusPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputLokiPqControls(BaseModel): +class OutputResponseOutputPrometheusPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputLokiTypedDict(TypedDict): - type: OutputResponseOutputLokiType +class OutputResponseOutputPrometheusTypedDict(TypedDict): + type: TypeOptionsPrometheus r"""Connector type identifier.""" url: str - r"""The endpoint to send logs to""" + r"""The endpoint to send metrics to""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - message: NotRequired[str] - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - message_format: NotRequired[MessageFormatOptions] - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - labels: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - auth_type: NotRequired[ - AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret - ] - r"""Authentication type""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + send_metadata: NotRequired[bool] + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + use_prometheus_histogram_bucket_suffix: NotRequired[bool] + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -19646,7 +19512,7 @@ class OutputResponseOutputLokiTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -19662,26 +19528,14 @@ class OutputResponseOutputLokiTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_dynamic_headers: NotRequired[bool] - r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[OutputResponseOutputPrometheusAuthenticationType] + r"""Remote Write authentication type""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - username: NotRequired[str] - r"""Username for authentication""" - password: NotRequired[str] - r"""Password (API key in Grafana Cloud domain) for authentication""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" + metrics_flush_period_sec: NotRequired[float] + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -19704,26 +19558,62 @@ class OutputResponseOutputLokiTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputLokiPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputPrometheusPqControlsTypedDict] r"""Persistent queue controls.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsAutoSecret] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + region: NotRequired[str] + r"""AWS region used to sign Remote Write requests""" + aws_service: NotRequired[str] + r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Prometheus""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_aws_service: NotRequired[str] + r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputLoki(BaseModel): - type: OutputResponseOutputLokiType +class OutputResponseOutputPrometheus(BaseModel): + type: TypeOptionsPrometheus r"""Connector type identifier.""" url: str - r"""The endpoint to send logs to""" + r"""The endpoint to send metrics to""" id: Optional[str] = None r"""Unique ID for this output""" @@ -19734,45 +19624,41 @@ class OutputResponseOutputLoki(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - message: Optional[str] = None - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - - message_format: Annotated[ - Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") - ] = None - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + r"""Metadata tags used for categorization and filtering.""" - labels: Optional[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") ] = None - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - auth_type: Annotated[ - Optional[AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret], - pydantic.Field(alias="authType"), + send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + None + ) + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + + use_prometheus_histogram_bucket_suffix: Annotated[ + Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") ] = None - r"""Authentication type""" + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -19793,7 +19679,7 @@ class OutputResponseOutputLoki(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -19832,43 +19718,24 @@ class OutputResponseOutputLoki(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - enable_dynamic_headers: Annotated[ - Optional[bool], pydantic.Field(alias="enableDynamicHeaders") - ] = None - r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + auth_type: Annotated[ + Optional[OutputResponseOutputPrometheusAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Remote Write authentication type""" description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - username: Optional[str] = None - r"""Username for authentication""" - - password: Optional[str] = None - r"""Password (API key in Grafana Cloud domain) for authentication""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + metrics_flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") ] = None - r"""Select or create a secret that references your credentials""" + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19920,15 +19787,73 @@ class OutputResponseOutputLoki(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputLokiPqControls], pydantic.Field(alias="pqControls") + Optional[OutputResponseOutputPrometheusPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsAutoSecret], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + region: Optional[str] = None + r"""AWS region used to sign Remote Write requests""" + + aws_service: Annotated[Optional[str], pydantic.Field(alias="awsService")] = None + r"""ID used to sign Remote Write requests (for example, `aps` for Amazon Managed Service for Prometheus)""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access Prometheus""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -19939,32 +19864,32 @@ class OutputResponseOutputLoki(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_aws_service: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsService") + ] = None + r"""Binds 'awsService' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsService' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("message_format") - def serialize_message_format(self, value): - if isinstance(value, str): - try: - return models.MessageFormatOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret( - value - ) - except ValueError: - return value - return value - @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -19983,6 +19908,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputPrometheusAuthenticationType(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -20010,6 +19944,15 @@ def serialize_pq_on_backpressure(self, value): return value return value + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAutoSecret(value) + except ValueError: + return value + return value + @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( @@ -20019,10 +19962,9 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "message", - "messageFormat", - "labels", - "authType", + "metricRenameExpr", + "sendMetadata", + "usePrometheusHistogramBucketSuffix", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -20037,16 +19979,10 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", - "enableDynamicHeaders", "onBackpressure", - "totalMemoryLimitKB", + "authType", "description", - "compress", - "token", - "textSecret", - "username", - "password", - "credentialsSecret", + "metricsFlushPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -20059,9 +19995,27 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "username", + "password", + "token", + "credentialsSecret", + "textSecret", + "awsAuthenticationMethod", + "awsSecret", + "region", + "awsService", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "__template_streamtags", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_region", + "__template_awsService", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "notifications", "status", ] @@ -20080,68 +20034,74 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGrafanaCloudType2(str, Enum): +class OutputResponseOutputAmazonManagedPrometheusType(str, Enum): r"""Connector type identifier.""" - GRAFANA_CLOUD = "grafana_cloud" + AMAZON_MANAGED_PROMETHEUS = "amazon_managed_prometheus" -class OutputResponseOutputGrafanaCloudPqControls2TypedDict(TypedDict): +class OutputResponseOutputAmazonManagedPrometheusPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputGrafanaCloudPqControls2(BaseModel): +class OutputResponseOutputAmazonManagedPrometheusPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): - type: OutputResponseOutputGrafanaCloudType2 +class OutputResponseOutputAmazonManagedPrometheusTypedDict(TypedDict): + type: OutputResponseOutputAmazonManagedPrometheusType r"""Connector type identifier.""" - prometheus_url: str - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + url: str + r"""The Amazon Managed Service for Prometheus remote_write endpoint""" + aws_authentication_method: AuthenticationMethodOptionsAutoSecret + r"""AWS authentication method. Choose Auto to use IAM roles.""" + region: str + r"""Region where the AMSP is located""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - loki_url: NotRequired[str] - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" - message: NotRequired[str] - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - message_format: NotRequired[MessageFormatOptions] - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - labels: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] - loki_auth: NotRequired[PrometheusAuthTypeTypedDict] - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Metadata tags used for categorization and filtering.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), that value will take precedence. """ + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access AMSP""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + send_metadata: NotRequired[bool] + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" + use_prometheus_histogram_bucket_suffix: NotRequired[bool] + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" timeout_sec: NotRequired[float] r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" + r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" use_round_robin_dns: NotRequired[bool] r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] @@ -20159,8 +20119,10 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[bool] - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + metrics_flush_period_sec: NotRequired[float] + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -20183,30 +20145,47 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputGrafanaCloudPqControls2TypedDict] + pq_controls: NotRequired[ + OutputResponseOutputAmazonManagedPrometheusPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: NotRequired[str] - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - template_prometheus_url: NotRequired[str] - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): - type: OutputResponseOutputGrafanaCloudType2 +class OutputResponseOutputAmazonManagedPrometheus(BaseModel): + type: OutputResponseOutputAmazonManagedPrometheusType r"""Connector type identifier.""" - prometheus_url: Annotated[str, pydantic.Field(alias="prometheusUrl")] - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + url: str + r"""The Amazon Managed Service for Prometheus remote_write endpoint""" + + aws_authentication_method: Annotated[ + AuthenticationMethodOptionsAutoSecret, + pydantic.Field(alias="awsAuthenticationMethod"), + ] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + region: str + r"""Region where the AMSP is located""" id: Optional[str] = None r"""Unique ID for this output""" @@ -20217,7 +20196,7 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions to generated metrics.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -20225,55 +20204,66 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - loki_url: Annotated[Optional[str], pydantic.Field(alias="lokiUrl")] = None - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - message: Optional[str] = None - r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - message_format: Annotated[ - Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + r"""Use Assume Role credentials to access AMSP""" - labels: Optional[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" metric_rename_expr: Annotated[ Optional[str], pydantic.Field(alias="metricRenameExpr") ] = None r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") - ] = None + send_metadata: Annotated[Optional[bool], pydantic.Field(alias="sendMetadata")] = ( + None + ) + r"""Generate and send metadata (`type` and `metricFamilyName`) requests""" - loki_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") + use_prometheus_histogram_bucket_suffix: Annotated[ + Optional[bool], pydantic.Field(alias="usePrometheusHistogramBucketSuffix") ] = None + r"""Serialize histogram bucket series as `_bucket` to match Prometheus histogram naming convention""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum uncompressed size, in KB, of the request body. The 1 MB cap is intentional and protects against data that compresses poorly, since oversized requests fail with a non-retryable 413.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" @@ -20286,13 +20276,13 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Headers to add to all events""" + r"""Headers to add to all events. SigV4-managed headers and the Prometheus remote-write protocol version header are generated by this Destination and cannot be configured here.""" use_round_robin_dns: Annotated[ Optional[bool], pydantic.Field(alias="useRoundRobinDns") @@ -20333,8 +20323,13 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[bool] = None - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + metrics_flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="metricsFlushPeriodSec") + ] = None + r"""How frequently metrics metadata is sent out. Value cannot be smaller than the base Flush period set above.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -20386,7 +20381,7 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputGrafanaCloudPqControls2], + Optional[OutputResponseOutputAmazonManagedPrometheusPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -20396,15 +20391,30 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiUrl") + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_prometheus_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusUrl") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -20416,17 +20426,17 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("message_format") - def serialize_message_format(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.MessageFormatOptions(value) + return models.AuthenticationMethodOptionsAutoSecret(value) except ValueError: return value return value @@ -20485,17 +20495,18 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "lokiUrl", - "message", - "messageFormat", - "labels", + "awsSecretKey", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "metricRenameExpr", - "prometheusAuth", - "lokiAuth", + "sendMetadata", + "usePrometheusHistogramBucketSuffix", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", - "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", "flushPeriodSec", @@ -20508,7 +20519,8 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "description", - "compress", + "awsSecret", + "metricsFlushPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -20522,8 +20534,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_lokiUrl", - "__template_prometheusUrl", + "__template_url", + "__template_awsSecretKey", + "__template_region", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_failedRequestLoggingMode", "__template_onBackpressure", "notifications", @@ -20544,37 +20559,35 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGrafanaCloudType1(str, Enum): +class OutputResponseOutputLokiType(str, Enum): r"""Connector type identifier.""" - GRAFANA_CLOUD = "grafana_cloud" + LOKI = "loki" -class OutputResponseOutputGrafanaCloudPqControls1TypedDict(TypedDict): +class OutputResponseOutputLokiPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputGrafanaCloudPqControls1(BaseModel): +class OutputResponseOutputLokiPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): - type: OutputResponseOutputGrafanaCloudType1 +class OutputResponseOutputLokiTypedDict(TypedDict): + type: OutputResponseOutputLokiType r"""Connector type identifier.""" - loki_url: str - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + url: str + r"""The endpoint to send logs to""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - prometheus_url: NotRequired[str] - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" message: NotRequired[str] r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" message_format: NotRequired[MessageFormatOptions] @@ -20583,16 +20596,16 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] ] r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: NotRequired[str] - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] - loki_auth: NotRequired[PrometheusAuthTypeTypedDict] + auth_type: NotRequired[ + AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret + ] + r"""Authentication type""" concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -20603,7 +20616,7 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -20619,12 +20632,26 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + enable_dynamic_headers: NotRequired[bool] + r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" compress: NotRequired[bool] - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + r"""Compress the payload body before sending""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + username: NotRequired[str] + r"""Username for authentication""" + password: NotRequired[str] + r"""Password (API key in Grafana Cloud domain) for authentication""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -20647,30 +20674,26 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputGrafanaCloudPqControls1TypedDict] + pq_controls: NotRequired[OutputResponseOutputLokiPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: NotRequired[str] - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - template_prometheus_url: NotRequired[str] - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): - type: OutputResponseOutputGrafanaCloudType1 +class OutputResponseOutputLoki(BaseModel): + type: OutputResponseOutputLokiType r"""Connector type identifier.""" - loki_url: Annotated[str, pydantic.Field(alias="lokiUrl")] - r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" + url: str + r"""The endpoint to send logs to""" id: Optional[str] = None r"""Unique ID for this output""" @@ -20681,7 +20704,7 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as labels to generated logs.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -20689,11 +20712,6 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - prometheus_url: Annotated[Optional[str], pydantic.Field(alias="prometheusUrl")] = ( - None - ) - r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" - message: Optional[str] = None r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" @@ -20707,31 +20725,24 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - metric_rename_expr: Annotated[ - Optional[str], pydantic.Field(alias="metricRenameExpr") - ] = None - r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - - prometheus_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") - ] = None - - loki_auth: Annotated[ - Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") + auth_type: Annotated[ + Optional[AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret], + pydantic.Field(alias="authType"), ] = None + r"""Authentication type""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum number of events to include in the request body. Defaults to 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -20752,7 +20763,7 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -20791,16 +20802,43 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + enable_dynamic_headers: Annotated[ + Optional[bool], pydantic.Field(alias="enableDynamicHeaders") + ] = None + r"""Add per-event HTTP headers from the __headers field to outgoing requests. Events with different headers are batched and sent separately.""" + on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" compress: Optional[bool] = None - r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + r"""Compress the payload body before sending""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header. In Grafana Cloud, this is generally built by concatenating the username and the API key, separated by a colon. Example: :""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + username: Optional[str] = None + r"""Username for authentication""" + + password: Optional[str] = None + r"""Password (API key in Grafana Cloud domain) for authentication""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -20852,8 +20890,7 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputGrafanaCloudPqControls1], - pydantic.Field(alias="pqControls"), + Optional[OutputResponseOutputLokiPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -20862,16 +20899,6 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_loki_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_lokiUrl") - ] = None - r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" - - template_prometheus_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_prometheusUrl") - ] = None - r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -20882,7 +20909,7 @@ class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -20897,6 +20924,17 @@ def serialize_message_format(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationTypeOptionsPrometheusAuthBasicCredentialsSecret( + value + ) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -20951,13 +20989,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "prometheusUrl", "message", "messageFormat", "labels", - "metricRenameExpr", - "prometheusAuth", - "lokiAuth", + "authType", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -20972,9 +21007,16 @@ def serialize_model(self, handler): "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", + "enableDynamicHeaders", "onBackpressure", + "totalMemoryLimitKB", "description", "compress", + "token", + "textSecret", + "username", + "password", + "credentialsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -20988,8 +21030,6 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_lokiUrl", - "__template_prometheusUrl", "__template_failedRequestLoggingMode", "__template_onBackpressure", "notifications", @@ -21010,130 +21050,55 @@ def serialize_model(self, handler): return m -OutputResponseOutputGrafanaCloudUnionTypedDict = TypeAliasType( - "OutputResponseOutputGrafanaCloudUnionTypedDict", - Union[ - OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict, - OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict, - ], -) - - -OutputResponseOutputGrafanaCloudUnion = TypeAliasType( - "OutputResponseOutputGrafanaCloudUnion", - Union[ - OutputResponseOutputGrafanaCloudGrafanaCloud1, - OutputResponseOutputGrafanaCloudGrafanaCloud2, - ], -) - - -class OutputResponseOutputDatadogType(str, Enum): +class OutputResponseOutputGrafanaCloudType2(str, Enum): r"""Connector type identifier.""" - DATADOG = "datadog" - - -class OutputResponseSendLogsAs(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The content type to use when sending logs""" - - # text/plain - TEXT = "text" - # application/json - JSON = "json" - - -class OutputResponseOutputDatadogSeverity(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - - # emergency - EMERGENCY = "emergency" - # alert - ALERT = "alert" - # critical - CRITICAL = "critical" - # error - ERROR = "error" - # warning - WARNING = "warning" - # notice - NOTICE = "notice" - # info - INFO = "info" - # debug - DEBUG = "debug" - - -class OutputResponseDatadogSite(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Datadog site to which events should be sent""" - - # US - US = "us" - # US3 - US3 = "us3" - # US5 - US5 = "us5" - # Europe - EU = "eu" - # US1-FED - FED1 = "fed1" - # AP1 - AP1 = "ap1" - # Custom - CUSTOM = "custom" + GRAFANA_CLOUD = "grafana_cloud" -class OutputResponseOutputDatadogPqControlsTypedDict(TypedDict): +class OutputResponseOutputGrafanaCloudPqControls2TypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputDatadogPqControls(BaseModel): +class OutputResponseOutputGrafanaCloudPqControls2(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputDatadogTypedDict(TypedDict): - type: OutputResponseOutputDatadogType +class OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict(TypedDict): + type: OutputResponseOutputGrafanaCloudType2 r"""Connector type identifier.""" + prometheus_url: str + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - content_type: NotRequired[OutputResponseSendLogsAs] - r"""The content type to use when sending logs""" + loki_url: NotRequired[str] + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" message: NotRequired[str] r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - source: NotRequired[str] - r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" - host: NotRequired[str] - r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" - service: NotRequired[str] - r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" - tags: NotRequired[List[str]] - r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" - batch_by_tags: NotRequired[bool] - r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" - allow_api_key_from_events: NotRequired[bool] - r"""Allow API key to be set from the event's '__agent_api_key' field""" - severity: NotRequired[OutputResponseOutputDatadogSeverity] - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - site: NotRequired[OutputResponseDatadogSite] - r"""Datadog site to which events should be sent""" - send_counters_as_count: NotRequired[bool] - r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" + message_format: NotRequired[MessageFormatOptions] + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + labels: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] + loki_auth: NotRequired[PrometheusAuthTypeTypedDict] concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -21144,7 +21109,7 @@ class OutputResponseOutputDatadogTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -21162,13 +21127,10 @@ class OutputResponseOutputDatadogTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + compress: NotRequired[bool] + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -21191,30 +21153,31 @@ class OutputResponseOutputDatadogTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputDatadogPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputGrafanaCloudPqControls2TypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""Organization's API key in Datadog""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_tags: NotRequired[str] - r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_loki_url: NotRequired[str] + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + template_prometheus_url: NotRequired[str] + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputDatadog(BaseModel): - type: OutputResponseOutputDatadogType +class OutputResponseOutputGrafanaCloudGrafanaCloud2(BaseModel): + type: OutputResponseOutputGrafanaCloudType2 r"""Connector type identifier.""" + prometheus_url: Annotated[str, pydantic.Field(alias="prometheusUrl")] + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -21224,7 +21187,7 @@ class OutputResponseOutputDatadog(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -21232,60 +21195,47 @@ class OutputResponseOutputDatadog(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - content_type: Annotated[ - Optional[OutputResponseSendLogsAs], pydantic.Field(alias="contentType") - ] = None - r"""The content type to use when sending logs""" + loki_url: Annotated[Optional[str], pydantic.Field(alias="lokiUrl")] = None + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" message: Optional[str] = None r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - source: Optional[str] = None - r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" - - host: Optional[str] = None - r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" - - service: Optional[str] = None - r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" - - tags: Optional[List[str]] = None - r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" - - batch_by_tags: Annotated[Optional[bool], pydantic.Field(alias="batchByTags")] = None - r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + message_format: Annotated[ + Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + ] = None + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" - allow_api_key_from_events: Annotated[ - Optional[bool], pydantic.Field(alias="allowApiKeyFromEvents") + labels: Optional[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] ] = None - r"""Allow API key to be set from the event's '__agent_api_key' field""" + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" - severity: Optional[OutputResponseOutputDatadogSeverity] = None - r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") + ] = None + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - site: Optional[OutputResponseDatadogSite] = None - r"""Datadog site to which events should be sent""" + prometheus_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") + ] = None - send_counters_as_count: Annotated[ - Optional[bool], pydantic.Field(alias="sendCountersAsCount") + loki_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") ] = None - r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -21306,7 +21256,7 @@ class OutputResponseOutputDatadog(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -21350,20 +21300,11 @@ class OutputResponseOutputDatadog(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + compress: Optional[bool] = None + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -21415,26 +21356,25 @@ class OutputResponseOutputDatadog(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputDatadogPqControls], + Optional[OutputResponseOutputGrafanaCloudPqControls2], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""Organization's API key in Datadog""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_tags: Annotated[Optional[str], pydantic.Field(alias="__template_tags")] = ( - None - ) - r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_loki_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiUrl") + ] = None + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + + template_prometheus_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusUrl") + ] = None + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -21446,35 +21386,17 @@ class OutputResponseOutputDatadog(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("content_type") - def serialize_content_type(self, value): - if isinstance(value, str): - try: - return models.OutputResponseSendLogsAs(value) - except ValueError: - return value - return value - - @field_serializer("severity") - def serialize_severity(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputDatadogSeverity(value) - except ValueError: - return value - return value - - @field_serializer("site") - def serialize_site(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.OutputResponseDatadogSite(value) + return models.MessageFormatOptions(value) except ValueError: return value return value @@ -21497,15 +21419,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAPI(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -21542,21 +21455,16 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "contentType", + "lokiUrl", "message", - "source", - "host", - "service", - "tags", - "batchByTags", - "allowApiKeyFromEvents", - "severity", - "site", - "sendCountersAsCount", + "messageFormat", + "labels", + "metricRenameExpr", + "prometheusAuth", + "lokiAuth", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", - "compress", "rejectUnauthorized", "timeoutSec", "maxConnectionReuseSec", @@ -21569,10 +21477,8 @@ def serialize_model(self, handler): "timeoutRetrySettings", "responseHonorRetryAfterHeader", "onBackpressure", - "authType", - "totalMemoryLimitKB", "description", - "customUrl", + "compress", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -21585,10 +21491,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", - "textSecret", "__template_streamtags", - "__template_tags", + "__template_lokiUrl", + "__template_prometheusUrl", "__template_failedRequestLoggingMode", "__template_onBackpressure", "notifications", @@ -21609,58 +21514,55 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSumoLogicType(str, Enum): +class OutputResponseOutputGrafanaCloudType1(str, Enum): r"""Connector type identifier.""" - SUMO_LOGIC = "sumo_logic" - - -class OutputResponseOutputSumoLogicDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Preserve the raw event format instead of JSONifying it""" - - # JSON - JSON = "json" - # Raw - RAW = "raw" + GRAFANA_CLOUD = "grafana_cloud" -class OutputResponseOutputSumoLogicPqControlsTypedDict(TypedDict): +class OutputResponseOutputGrafanaCloudPqControls1TypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSumoLogicPqControls(BaseModel): +class OutputResponseOutputGrafanaCloudPqControls1(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSumoLogicTypedDict(TypedDict): - type: OutputResponseOutputSumoLogicType +class OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict(TypedDict): + type: OutputResponseOutputGrafanaCloudType1 r"""Connector type identifier.""" - url: str - r"""Sumo Logic HTTP collector URL to which events should be sent""" + loki_url: str + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: NotRequired[str] r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - custom_source: NotRequired[str] - r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" - custom_category: NotRequired[str] - r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - format_: NotRequired[OutputResponseOutputSumoLogicDataFormat] - r"""Preserve the raw event format instead of JSONifying it""" + prometheus_url: NotRequired[str] + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + message: NotRequired[str] + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + message_format: NotRequired[MessageFormatOptions] + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + labels: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + metric_rename_expr: NotRequired[str] + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" + prometheus_auth: NotRequired[PrometheusAuthTypeTypedDict] + loki_auth: NotRequired[PrometheusAuthTypeTypedDict] concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). Enabled by default. When this setting is also present in TLS Settings (Client Side), @@ -21671,7 +21573,7 @@ class OutputResponseOutputSumoLogicTypedDict(TypedDict): max_connection_reuse_sec: NotRequired[float] r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" use_round_robin_dns: NotRequired[bool] @@ -21689,10 +21591,10 @@ class OutputResponseOutputSumoLogicTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + compress: NotRequired[bool] + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -21715,28 +21617,30 @@ class OutputResponseOutputSumoLogicTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSumoLogicPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputGrafanaCloudPqControls1TypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_loki_url: NotRequired[str] + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + template_prometheus_url: NotRequired[str] + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSumoLogic(BaseModel): - type: OutputResponseOutputSumoLogicType +class OutputResponseOutputGrafanaCloudGrafanaCloud1(BaseModel): + type: OutputResponseOutputGrafanaCloudType1 r"""Connector type identifier.""" - url: str - r"""Sumo Logic HTTP collector URL to which events should be sent""" + loki_url: Annotated[str, pydantic.Field(alias="lokiUrl")] + r"""The endpoint to send logs to, such as https://logs-prod-us-central1.grafana.net""" id: Optional[str] = None r"""Unique ID for this output""" @@ -21747,7 +21651,7 @@ class OutputResponseOutputSumoLogic(BaseModel): system_fields: Annotated[ Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards. These fields are added as dimensions and labels to generated metrics and logs, respectively.""" environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" @@ -21755,35 +21659,49 @@ class OutputResponseOutputSumoLogic(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - custom_source: Annotated[Optional[str], pydantic.Field(alias="customSource")] = None - r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" + prometheus_url: Annotated[Optional[str], pydantic.Field(alias="prometheusUrl")] = ( + None + ) + r"""The remote_write endpoint to send Prometheus metrics to, such as https://prometheus-blocks-prod-us-central1.grafana.net/api/prom/push""" + + message: Optional[str] = None + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + + message_format: Annotated[ + Optional[MessageFormatOptions], pydantic.Field(alias="messageFormat") + ] = None + r"""Format to use when sending logs to Loki (Protobuf or JSON)""" + + labels: Optional[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret] + ] = None + r"""List of labels to send with logs. Labels define Loki streams, so use static labels to avoid proliferating label value combinations and streams. Can be merged and/or overridden by the event's __labels field. Example: '__labels: {host: \"cribl.io\", level: \"error\"}'""" + + metric_rename_expr: Annotated[ + Optional[str], pydantic.Field(alias="metricRenameExpr") + ] = None + r"""JavaScript expression that can be used to rename metrics. For example, name.replace(/\./g, '_') will replace all '.' characters in a metric's name with the supported '_' character. Use the 'name' global variable to access the metric's name. You can access event fields' values via __e..""" - custom_category: Annotated[ - Optional[str], pydantic.Field(alias="customCategory") + prometheus_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="prometheusAuth") ] = None - r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - format_: Annotated[ - Optional[OutputResponseOutputSumoLogicDataFormat], - pydantic.Field(alias="format"), + loki_auth: Annotated[ + Optional[PrometheusAuthType], pydantic.Field(alias="lokiAuth") ] = None - r"""Preserve the raw event format instead of JSONifying it""" concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Maximum number of ongoing requests before blocking. Warning: Setting this value > 1 can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size, in KB, of the request body. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited). Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") @@ -21804,7 +21722,7 @@ class OutputResponseOutputSumoLogic(BaseModel): flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Maximum time between requests. Small values can reduce the payload size below the configured 'Max record size' and 'Max events per request'. Warning: Setting this too low can increase the number of ongoing requests (depending on the value of 'Request concurrency'); this can cause Loki and Prometheus to complain about entries being delivered out of order.""" extra_http_headers: Annotated[ Optional[List[ExtraHTTPHeaderConfInputElastic]], @@ -21848,14 +21766,12 @@ class OutputResponseOutputSumoLogic(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending. Applies only to JSON payloads; the Protobuf variant for both Prometheus and Loki are snappy-compressed by default.""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -21906,7 +21822,7 @@ class OutputResponseOutputSumoLogic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSumoLogicPqControls], + Optional[OutputResponseOutputGrafanaCloudPqControls1], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -21916,10 +21832,15 @@ class OutputResponseOutputSumoLogic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_loki_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_lokiUrl") + ] = None + r"""Binds 'lokiUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'lokiUrl' at runtime.""" + + template_prometheus_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_prometheusUrl") + ] = None + r"""Binds 'prometheusUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'prometheusUrl' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -21931,17 +21852,17 @@ class OutputResponseOutputSumoLogic(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputSumoLogicDataFormat(value) + return models.MessageFormatOptions(value) except ValueError: return value return value @@ -21983,206 +21904,13 @@ def serialize_pq_compress(self, value): return value @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "pipeline", - "systemFields", - "environment", - "streamtags", - "customSource", - "customCategory", - "format", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "onBackpressure", - "totalMemoryLimitKB", - "description", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputSnmpHostTypedDict(TypedDict): - host: str - r"""Destination host""" - port: float - r"""Destination port, default is 162""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - -class OutputResponseOutputSnmpHost(BaseModel): - host: str - r"""Destination host""" - - port: float - r"""Destination port, default is 162""" - - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["__template_host", "__template_port"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputSnmpTypedDict(TypedDict): - type: TypeOptionsSnmp - r"""Connector type identifier.""" - hosts: List[OutputResponseOutputSnmpHostTypedDict] - r"""One or more SNMP destinations to forward traps to""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - max_record_size: NotRequired[float] - r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class OutputResponseOutputSnmp(BaseModel): - type: TypeOptionsSnmp - r"""Connector type identifier.""" - - hosts: List[OutputResponseOutputSnmpHost] - r"""One or more SNMP destinations to forward traps to""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" - - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") - ] = None - r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") - ] = None - r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -22193,11 +21921,47 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "dnsResolvePeriodSec", - "enableIpSpoofing", + "prometheusUrl", + "message", + "messageFormat", + "labels", + "metricRenameExpr", + "prometheusAuth", + "lokiAuth", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "maxRecordSize", + "compress", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", + "__template_lokiUrl", + "__template_prometheusUrl", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", "notifications", "status", ] @@ -22216,30 +21980,90 @@ def serialize_model(self, handler): return m -class OutputResponseQueueType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The queue type used (or created). Defaults to Standard.""" +OutputResponseOutputGrafanaCloudUnionTypedDict = TypeAliasType( + "OutputResponseOutputGrafanaCloudUnionTypedDict", + Union[ + OutputResponseOutputGrafanaCloudGrafanaCloud1TypedDict, + OutputResponseOutputGrafanaCloudGrafanaCloud2TypedDict, + ], +) - # Standard - STANDARD = "standard" - # FIFO - FIFO = "fifo" + +OutputResponseOutputGrafanaCloudUnion = TypeAliasType( + "OutputResponseOutputGrafanaCloudUnion", + Union[ + OutputResponseOutputGrafanaCloudGrafanaCloud1, + OutputResponseOutputGrafanaCloudGrafanaCloud2, + ], +) -class OutputResponseOutputSqsPqControlsTypedDict(TypedDict): +class OutputResponseOutputDatadogType(str, Enum): + r"""Connector type identifier.""" + + DATADOG = "datadog" + + +class OutputResponseSendLogsAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The content type to use when sending logs""" + + # text/plain + TEXT = "text" + # application/json + JSON = "json" + + +class OutputResponseOutputDatadogSeverity(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + + # emergency + EMERGENCY = "emergency" + # alert + ALERT = "alert" + # critical + CRITICAL = "critical" + # error + ERROR = "error" + # warning + WARNING = "warning" + # notice + NOTICE = "notice" + # info + INFO = "info" + # debug + DEBUG = "debug" + + +class OutputResponseDatadogSite(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Datadog site to which events should be sent""" + + # US + US = "us" + # US3 + US3 = "us3" + # US5 + US5 = "us5" + # Europe + EU = "eu" + # US1-FED + FED1 = "fed1" + # AP1 + AP1 = "ap1" + # Custom + CUSTOM = "custom" + + +class OutputResponseOutputDatadogPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSqsPqControls(BaseModel): +class OutputResponseOutputDatadogPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSqsTypedDict(TypedDict): - type: TypeOptionsSqs +class OutputResponseOutputDatadogTypedDict(TypedDict): + type: OutputResponseOutputDatadogType r"""Connector type identifier.""" - queue_name: str - r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - queue_type: OutputResponseQueueType - r"""The queue type used (or created). Defaults to Standard.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -22250,48 +22074,71 @@ class OutputResponseOutputSqsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_account_id: NotRequired[str] - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - message_group_id: NotRequired[str] - r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" - create_queue: NotRequired[bool] - r"""Create queue if it does not exist.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" - endpoint: NotRequired[str] - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + content_type: NotRequired[OutputResponseSendLogsAs] + r"""The content type to use when sending logs""" + message: NotRequired[str] + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" + source: NotRequired[str] + r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" + host: NotRequired[str] + r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" + service: NotRequired[str] + r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" + tags: NotRequired[List[str]] + r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" + batch_by_tags: NotRequired[bool] + r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + allow_api_key_from_events: NotRequired[bool] + r"""Allow API key to be set from the event's '__agent_api_key' field""" + severity: NotRequired[OutputResponseOutputDatadogSeverity] + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" + site: NotRequired[OutputResponseDatadogSite] + r"""Datadog site to which events should be sent""" + send_counters_as_count: NotRequired[bool] + r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SQS""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking.""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -22314,48 +22161,30 @@ class OutputResponseOutputSqsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSqsPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputDatadogPqControlsTypedDict] r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: NotRequired[str] - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - template_queue_type: NotRequired[str] - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - template_aws_account_id: NotRequired[str] - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - template_message_group_id: NotRequired[str] - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + api_key: NotRequired[str] + r"""Organization's API key in Datadog""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_tags: NotRequired[str] + r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSqs(BaseModel): - type: TypeOptionsSqs +class OutputResponseOutputDatadog(BaseModel): + type: OutputResponseOutputDatadogType r"""Connector type identifier.""" - queue_name: Annotated[str, pydantic.Field(alias="queueName")] - r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - - queue_type: Annotated[OutputResponseQueueType, pydantic.Field(alias="queueType")] - r"""The queue type used (or created). Defaults to Standard.""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -22373,99 +22202,138 @@ class OutputResponseOutputSqs(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( - None - ) - r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - - message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="messageGroupId") + content_type: Annotated[ + Optional[OutputResponseSendLogsAs], pydantic.Field(alias="contentType") ] = None - r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" + r"""The content type to use when sending logs""" - create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None - r"""Create queue if it does not exist.""" + message: Optional[str] = None + r"""Name of the event field that contains the message to send. If not specified, Stream sends a JSON representation of the whole event.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + source: Optional[str] = None + r"""Name of the source to send with logs. When you send logs as JSON objects, the event's 'source' field (if set) will override this value.""" + + host: Optional[str] = None + r"""Name of the host to send with logs. When you send logs as JSON objects, the event's 'host' field (if set) will override this value.""" + + service: Optional[str] = None + r"""Name of the service to send with logs. When you send logs as JSON objects, the event's '__service' field (if set) will override this value.""" + + tags: Optional[List[str]] = None + r"""List of tags to send with logs, such as 'env:prod' and 'env_staging:east'""" + + batch_by_tags: Annotated[Optional[bool], pydantic.Field(alias="batchByTags")] = None + r"""Batch events by API key and the ddtags field on the event. When disabled, batches events only by API key. If incoming events have high cardinality in the ddtags field, disabling this setting may improve Destination performance.""" + + allow_api_key_from_events: Annotated[ + Optional[bool], pydantic.Field(alias="allowApiKeyFromEvents") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Allow API key to be set from the event's '__agent_api_key' field""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + severity: Optional[OutputResponseOutputDatadogSeverity] = None + r"""Default value for message severity. When you send logs as JSON objects, the event's '__severity' field (if set) will override this value.""" - region: Optional[str] = None - r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + site: Optional[OutputResponseDatadogSite] = None + r"""Datadog site to which events should be sent""" - endpoint: Optional[str] = None - r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + send_counters_as_count: Annotated[ + Optional[bool], pydantic.Field(alias="sendCountersAsCount") + ] = None + r"""If not enabled, Datadog will transform 'counter' metrics to 'gauge'. [Learn more about Datadog metrics types.](https://docs.datadoghq.com/metrics/types/?tab=count)""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Use Assume Role credentials to access SQS""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""External ID to use when assuming role""" + r"""Headers to add to all events""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + r"""List of headers that are safe to log in plain text""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The maximum number of in-progress API requests before backpressure is applied.""" + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + ] = None + r"""Enter API key directly, or select a stored secret""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -22517,90 +22385,75 @@ class OutputResponseOutputSqs(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSqsPqControls], pydantic.Field(alias="pqControls") + Optional[OutputResponseOutputDatadogPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""Organization's API key in Datadog""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_queue_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueName") - ] = None - r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" - - template_queue_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_queueType") - ] = None - r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" - - template_aws_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsAccountId") - ] = None - r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" - - template_message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageGroupId") - ] = None - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_tags: Annotated[Optional[str], pydantic.Field(alias="__template_tags")] = ( + None + ) + r"""Binds 'tags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tags' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("queue_type") - def serialize_queue_type(self, value): + @field_serializer("content_type") + def serialize_content_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseSendLogsAs(value) + except ValueError: + return value + return value + + @field_serializer("severity") + def serialize_severity(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputDatadogSeverity(value) + except ValueError: + return value + return value + + @field_serializer("site") + def serialize_site(self, value): if isinstance(value, str): try: - return models.OutputResponseQueueType(value) + return models.OutputResponseDatadogSite(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -22614,6 +22467,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -22650,27 +22512,37 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAccountId", - "messageGroupId", - "createQueue", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", + "contentType", + "message", + "source", + "host", + "service", + "tags", + "batchByTags", + "allowApiKeyFromEvents", + "severity", + "site", + "sendCountersAsCount", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "maxQueueSize", - "maxRecordSizeKB", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "maxInProgress", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", - "awsApiKey", - "awsSecret", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -22683,18 +22555,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_queueName", - "__template_queueType", - "__template_awsAccountId", - "__template_messageGroupId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_tags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsApiKey", "notifications", "status", ] @@ -22713,27 +22579,34 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSnsType(str, Enum): +class OutputResponseOutputSumoLogicType(str, Enum): r"""Connector type identifier.""" - SNS = "sns" + SUMO_LOGIC = "sumo_logic" -class OutputResponseOutputSnsPqControlsTypedDict(TypedDict): +class OutputResponseOutputSumoLogicDataFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Preserve the raw event format instead of JSONifying it""" + + # JSON + JSON = "json" + # Raw + RAW = "raw" + + +class OutputResponseOutputSumoLogicPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSnsPqControls(BaseModel): +class OutputResponseOutputSumoLogicPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSnsTypedDict(TypedDict): - type: OutputResponseOutputSnsType +class OutputResponseOutputSumoLogicTypedDict(TypedDict): + type: OutputResponseOutputSumoLogicType r"""Connector type identifier.""" - topic_arn: str - r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - message_group_id: str - r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + url: str + r"""Sumo Logic HTTP collector URL to which events should be sent""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -22744,36 +22617,52 @@ class OutputResponseOutputSnsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - max_retries: NotRequired[float] - r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - region: NotRequired[str] - r"""Region where the SNS is located""" - endpoint: NotRequired[str] - r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + custom_source: NotRequired[str] + r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" + custom_category: NotRequired[str] + r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" + format_: NotRequired[OutputResponseOutputSumoLogicDataFormat] + r"""Preserve the raw event format instead of JSONifying it""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access SNS""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -22796,43 +22685,28 @@ class OutputResponseOutputSnsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSnsPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSumoLogicPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_arn: NotRequired[str] - r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" - template_message_group_id: NotRequired[str] - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSns(BaseModel): - type: OutputResponseOutputSnsType +class OutputResponseOutputSumoLogic(BaseModel): + type: OutputResponseOutputSumoLogicType r"""Connector type identifier.""" - topic_arn: Annotated[str, pydantic.Field(alias="topicArn")] - r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - - message_group_id: Annotated[str, pydantic.Field(alias="messageGroupId")] - r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + url: str + r"""Sumo Logic HTTP collector URL to which events should be sent""" id: Optional[str] = None r"""Unique ID for this output""" @@ -22851,70 +22725,107 @@ class OutputResponseOutputSns(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" + custom_source: Annotated[Optional[str], pydantic.Field(alias="customSource")] = None + r"""Override the source name configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceName field.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), + custom_category: Annotated[ + Optional[str], pydantic.Field(alias="customCategory") ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" + r"""Override the source category configured on the Sumo Logic HTTP collector. This can also be overridden at the event level with the __sourceCategory field.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + format_: Annotated[ + Optional[OutputResponseOutputSumoLogicDataFormat], + pydantic.Field(alias="format"), + ] = None + r"""Preserve the raw event format instead of JSONifying it""" - region: Optional[str] = None - r"""Region where the SNS is located""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - endpoint: Optional[str] = None - r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""List of headers that are safe to log in plain text""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Use Assume Role credentials to access SNS""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""External ID to use when assuming role""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -22965,7 +22876,8 @@ class OutputResponseOutputSns(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSnsPqControls], pydantic.Field(alias="pqControls") + Optional[OutputResponseOutputSumoLogicPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -22974,62 +22886,41 @@ class OutputResponseOutputSns(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicArn") - ] = None - r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" - - template_message_group_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageGroupId") - ] = None - r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.OutputResponseOutputSumoLogicDataFormat(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -23079,21 +22970,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "maxRetries", - "awsAuthenticationMethod", - "awsSecretKey", - "region", - "endpoint", - "reuseConnections", + "customSource", + "customCategory", + "format", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", + "totalMemoryLimitKB", "description", - "awsApiKey", - "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -23107,15 +23004,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topicArn", - "__template_messageGroupId", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_url", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsApiKey", "notifications", "status", ] @@ -23134,39 +23025,37 @@ def serialize_model(self, handler): return m -class OutputResponseOutputRouterType(str, Enum): - r"""Connector type identifier.""" - - ROUTER = "router" - - -class OutputResponseRuleTypedDict(TypedDict): - filter_: str - r"""JavaScript expression to select events to send to output""" - output: str - r"""Output to send matching events to""" - description: NotRequired[str] - r"""Description of this rule's purpose""" - final: NotRequired[bool] - r"""Flag to control whether to stop the event from being checked against other rules""" +class OutputResponseOutputSnmpHostTypedDict(TypedDict): + host: str + r"""Destination host""" + port: float + r"""Destination port, default is 162""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" -class OutputResponseRule(BaseModel): - filter_: Annotated[str, pydantic.Field(alias="filter")] - r"""JavaScript expression to select events to send to output""" +class OutputResponseOutputSnmpHost(BaseModel): + host: str + r"""Destination host""" - output: str - r"""Output to send matching events to""" + port: float + r"""Destination port, default is 162""" - description: Optional[str] = None - r"""Description of this rule's purpose""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - final: Optional[bool] = None - r"""Flag to control whether to stop the event from being checked against other rules""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["description", "final"]) + optional_fields = set(["__template_host", "__template_port"]) serialized = handler(self) m = {} @@ -23181,11 +23070,11 @@ def serialize_model(self, handler): return m -class OutputResponseOutputRouterTypedDict(TypedDict): - type: OutputResponseOutputRouterType +class OutputResponseOutputSnmpTypedDict(TypedDict): + type: TypeOptionsSnmp r"""Connector type identifier.""" - rules: List[OutputResponseRuleTypedDict] - r"""Event routing rules""" + hosts: List[OutputResponseOutputSnmpHostTypedDict] + r"""One or more SNMP destinations to forward traps to""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -23196,22 +23085,28 @@ class OutputResponseOutputRouterTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" description: NotRequired[str] r"""Optional description for this configuration.""" + max_record_size: NotRequired[float] + r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputRouter(BaseModel): - type: OutputResponseOutputRouterType +class OutputResponseOutputSnmp(BaseModel): + type: TypeOptionsSnmp r"""Connector type identifier.""" - rules: List[OutputResponseRule] - r"""Event routing rules""" + hosts: List[OutputResponseOutputSnmpHost] + r"""One or more SNMP destinations to forward traps to""" id: Optional[str] = None r"""Unique ID for this output""" @@ -23230,15 +23125,30 @@ class OutputResponseOutputRouter(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""How often to resolve the destination hostname to an IP address. Ignored if all destinations are IP addresses. A value of 0 means every trap sent will incur a DNS lookup.""" + + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") + ] = None + r"""Send SNMP Trap traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + description: Optional[str] = None r"""Optional description for this configuration.""" + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") + ] = None + r"""MTU in bytes. The actual maximum SNMP Trap payload size will be MTU minus IP and UDP headers (28 bytes for IPv4, 48 bytes for IPv6). Payloads exceeding this limit will be dropped.""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -23253,7 +23163,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "dnsResolvePeriodSec", + "enableIpSpoofing", "description", + "maxRecordSize", "__template_streamtags", "notifications", "status", @@ -23273,29 +23186,30 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGraphiteType(str, Enum): - r"""Connector type identifier.""" +class OutputResponseQueueType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The queue type used (or created). Defaults to Standard.""" - GRAPHITE = "graphite" + # Standard + STANDARD = "standard" + # FIFO + FIFO = "fifo" -class OutputResponseOutputGraphitePqControlsTypedDict(TypedDict): +class OutputResponseOutputSqsPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputGraphitePqControls(BaseModel): +class OutputResponseOutputSqsPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputGraphiteTypedDict(TypedDict): - type: OutputResponseOutputGraphiteType +class OutputResponseOutputSqsTypedDict(TypedDict): + type: TypeOptionsSqs r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + queue_name: str + r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" + queue_type: OutputResponseQueueType + r"""The queue type used (or created). Defaults to Standard.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -23306,22 +23220,48 @@ class OutputResponseOutputGraphiteTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + aws_account_id: NotRequired[str] + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" + message_group_id: NotRequired[str] + r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" + create_queue: NotRequired[bool] + r"""Create queue if it does not exist.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + endpoint: NotRequired[str] + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SQS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -23344,30 +23284,47 @@ class OutputResponseOutputGraphiteTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputGraphitePqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSqsPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: NotRequired[str] + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + template_queue_type: NotRequired[str] + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + template_aws_account_id: NotRequired[str] + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + template_message_group_id: NotRequired[str] + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGraphite(BaseModel): - type: OutputResponseOutputGraphiteType +class OutputResponseOutputSqs(BaseModel): + type: TypeOptionsSqs r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - - host: str - r"""The hostname of the destination.""" + queue_name: Annotated[str, pydantic.Field(alias="queueName")] + r"""The name, URL, or ARN of the SQS queue to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. Example: 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" - port: float - r"""Destination port.""" + queue_type: Annotated[OutputResponseQueueType, pydantic.Field(alias="queueType")] + r"""The queue type used (or created). Defaults to Standard.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -23386,42 +23343,100 @@ class OutputResponseOutputGraphite(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - mtu: Optional[float] = None - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + aws_account_id: Annotated[Optional[str], pydantic.Field(alias="awsAccountId")] = ( + None + ) + r"""SQS queue owner's AWS account ID. Leave empty if SQS queue is in same AWS account.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="messageGroupId") ] = None - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + r"""This parameter applies only to FIFO queues. The tag that specifies that a message belongs to a specific message group. Messages that belong to the same message group are processed in a FIFO manner. Use event field __messageGroupId to override this value.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + create_queue: Annotated[Optional[bool], pydantic.Field(alias="createQueue")] = None + r"""Create queue if it does not exist.""" + + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + region: Optional[str] = None + r"""AWS Region where the SQS queue is located. Required, unless the Queue entry is a URL or ARN that includes a Region.""" + + endpoint: Optional[str] = None + r"""SQS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SQS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Reuse connections between requests, which can improve performance""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SQS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking.""" + + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") + ] = None + r"""Maximum size (KB) of batches to send. Per the SQS spec, the max allowed value is 256 KB.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") + ] = None + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -23472,8 +23487,7 @@ class OutputResponseOutputGraphite(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputGraphitePqControls], - pydantic.Field(alias="pqControls"), + Optional[OutputResponseOutputSqsPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -23482,22 +23496,81 @@ class OutputResponseOutputGraphite(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_queue_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueName") + ] = None + r"""Binds 'queueName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueName' at runtime.""" + + template_queue_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_queueType") + ] = None + r"""Binds 'queueType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'queueType' at runtime.""" + + template_aws_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsAccountId") + ] = None + r"""Binds 'awsAccountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsAccountId' at runtime.""" + + template_message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageGroupId") + ] = None + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + @field_serializer("queue_type") + def serialize_queue_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseQueueType(value) + except ValueError: + return value + return value + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.DestinationProtocolOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -23547,14 +23620,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "mtu", + "awsAccountId", + "messageGroupId", + "createQueue", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxQueueSize", + "maxRecordSizeKB", "flushPeriodSec", - "dnsResolvePeriodSec", - "description", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "maxInProgress", "onBackpressure", + "description", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -23568,7 +23654,17 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_queueName", + "__template_queueType", + "__template_awsAccountId", + "__template_messageGroupId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", "notifications", "status", ] @@ -23587,12 +23683,24 @@ def serialize_model(self, handler): return m -class OutputResponseOutputStatsdExtType(str, Enum): +class OutputResponseOutputSnsType(str, Enum): r"""Connector type identifier.""" - STATSD_EXT = "statsd_ext" + SNS = "sns" + + +class OutputResponseOutputSnsPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputSnsPqControls(BaseModel): + r"""Persistent queue controls.""" +try: + OutputResponseOutputDatabricksZerobus.model_rebuild() +except NameError: + pass try: OutputResponseOutputIbmCloudS3.model_rebuild() except NameError: @@ -23661,6 +23769,10 @@ class OutputResponseOutputStatsdExtType(str, Enum): OutputResponseOutputSentinelOneAiSiem.model_rebuild() except NameError: pass +try: + OutputResponseOutputTraversalOtlp.model_rebuild() +except NameError: + pass try: OutputResponseOutputDynatraceOtlp.model_rebuild() except NameError: @@ -23793,19 +23905,3 @@ class OutputResponseOutputStatsdExtType(str, Enum): OutputResponseOutputSqs.model_rebuild() except NameError: pass -try: - OutputResponseOutputSns.model_rebuild() -except NameError: - pass -try: - OutputResponseRule.model_rebuild() -except NameError: - pass -try: - OutputResponseOutputRouter.model_rebuild() -except NameError: - pass -try: - OutputResponseOutputGraphite.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/outputresponse_outputdefault_type.py b/src/cribl_control_plane/models/outputresponse_outputwebhook_format_2.py similarity index 94% rename from src/cribl_control_plane/models/outputresponse_outputdefault_type.py rename to src/cribl_control_plane/models/outputresponse_outputwebhook_format_2.py index 150800632..7e3358f1c 100644 --- a/src/cribl_control_plane/models/outputresponse_outputdefault_type.py +++ b/src/cribl_control_plane/models/outputresponse_outputwebhook_format_2.py @@ -5,8 +5,8 @@ from .acknowledgmentsoptionsallleader import AcknowledgmentsOptionsAllLeader from .authenticationmethodoptions import AuthenticationMethodOptions from .authenticationmethodoptionsapi import AuthenticationMethodOptionsAPI -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .authenticationmethodoptionss3collectorconf import ( AuthenticationMethodOptionsS3CollectorConf, @@ -50,21 +50,12 @@ LogLabelConfOutputGoogleCloudLoggingTypedDict, ) from .maxs2sversionoptions import MaxS2SVersionOptions -from .methodoptions import MethodOptions from .microsoftentraidauthenticationendpointoptionssasl import ( MicrosoftEntraIDAuthenticationEndpointOptionsSasl, ) from .modeoptions import ModeOptions from .nestedfieldserializationoptions import NestedFieldSerializationOptions -from .notification_union import NotificationUnion, NotificationUnionTypedDict -from .oauthheaderconfinputservicenowtable import ( - OauthHeaderConfInputServicenowTable, - OauthHeaderConfInputServicenowTableTypedDict, -) -from .oauthparamconfinputservicenowtable import ( - OauthParamConfInputServicenowTable, - OauthParamConfInputServicenowTableTypedDict, -) +from .notification import Notification, NotificationTypedDict from .objectacloptions import ObjectACLOptions from .objectacloptionsauthenticatedreadbucketownerfullcontrol import ( ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol, @@ -73,7 +64,11 @@ OrphanFileRecoveryType, OrphanFileRecoveryTypeTypedDict, ) -from .outputresponse_outputstatsdext_type import OutputResponseOutputStatsdExtType +from .outputresponse_outputsns_pqcontrols import ( + OutputResponseOutputSnsPqControls, + OutputResponseOutputSnsPqControlsTypedDict, + OutputResponseOutputSnsType, +) from .parquetversionoptions import ParquetVersionOptions from .queuefullbehavioroptions import QueueFullBehaviorOptions from .recorddataformatoptions import RecordDataFormatOptions @@ -139,27 +134,17 @@ from enum import Enum import pydantic from pydantic import field_serializer, model_serializer -from typing import List, Optional, Union -from typing_extensions import Annotated, NotRequired, TypeAliasType, TypedDict - - -class OutputResponseOutputStatsdExtPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict -class OutputResponseOutputStatsdExtPqControls(BaseModel): - r"""Persistent queue controls.""" - -class OutputResponseOutputStatsdExtTypedDict(TypedDict): - type: OutputResponseOutputStatsdExtType +class OutputResponseOutputSnsTypedDict(TypedDict): + type: OutputResponseOutputSnsType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + topic_arn: str + r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" + message_group_id: str + r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -170,22 +155,36 @@ class OutputResponseOutputStatsdExtTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + max_retries: NotRequired[float] + r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + region: NotRequired[str] + r"""Region where the SNS is located""" + endpoint: NotRequired[str] + r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access SNS""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -208,30 +207,43 @@ class OutputResponseOutputStatsdExtTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputStatsdExtPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSnsPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_arn: NotRequired[str] + r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" + template_message_group_id: NotRequired[str] + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputStatsdExt(BaseModel): - type: OutputResponseOutputStatsdExtType +class OutputResponseOutputSns(BaseModel): + type: OutputResponseOutputSnsType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - - host: str - r"""The hostname of the destination.""" + topic_arn: Annotated[str, pydantic.Field(alias="topicArn")] + r"""The ARN of the SNS topic to send events to. When a non-AWS URL is specified, format must be: '{url}/myQueueName'. E.g., 'https://host:port/myQueueName'. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`""" - port: float - r"""Destination port.""" + message_group_id: Annotated[str, pydantic.Field(alias="messageGroupId")] + r"""Messages in the same group are processed in a FIFO manner. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `https://host:port/myQueue-${C.vars.myVar}`.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -250,42 +262,70 @@ class OutputResponseOutputStatsdExt(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - mtu: Optional[float] = None - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""Maximum number of retries before the output returns an error. Note that not all errors are retryable. The retries use an exponential backoff policy.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + region: Optional[str] = None + r"""Region where the SNS is located""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + endpoint: Optional[str] = None + r"""SNS service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to SNS-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Reuse connections between requests, which can improve performance""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access SNS""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( None ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -336,8 +376,7 @@ class OutputResponseOutputStatsdExt(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputStatsdExtPqControls], - pydantic.Field(alias="pqControls"), + Optional[OutputResponseOutputSnsPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -346,22 +385,62 @@ class OutputResponseOutputStatsdExt(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_topic_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicArn") + ] = None + r"""Binds 'topicArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicArn' at runtime.""" + + template_message_group_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageGroupId") + ] = None + r"""Binds 'messageGroupId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageGroupId' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("protocol") - def serialize_protocol(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.DestinationProtocolOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -411,14 +490,21 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "mtu", - "flushPeriodSec", - "dnsResolvePeriodSec", - "description", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "maxRetries", + "awsAuthenticationMethod", + "awsSecretKey", + "region", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", "onBackpressure", + "description", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -432,7 +518,15 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_topicArn", + "__template_messageGroupId", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", "notifications", "status", ] @@ -451,29 +545,58 @@ def serialize_model(self, handler): return m -class OutputResponseOutputStatsdType(str, Enum): +class OutputResponseOutputRouterType(str, Enum): r"""Connector type identifier.""" - STATSD = "statsd" + ROUTER = "router" -class OutputResponseOutputStatsdPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseRuleTypedDict(TypedDict): + filter_: str + r"""JavaScript expression to select events to send to output""" + output: str + r"""Output to send matching events to""" + description: NotRequired[str] + r"""Description of this rule's purpose""" + final: NotRequired[bool] + r"""Flag to control whether to stop the event from being checked against other rules""" -class OutputResponseOutputStatsdPqControls(BaseModel): - r"""Persistent queue controls.""" +class OutputResponseRule(BaseModel): + filter_: Annotated[str, pydantic.Field(alias="filter")] + r"""JavaScript expression to select events to send to output""" + output: str + r"""Output to send matching events to""" -class OutputResponseOutputStatsdTypedDict(TypedDict): - type: OutputResponseOutputStatsdType + description: Optional[str] = None + r"""Description of this rule's purpose""" + + final: Optional[bool] = None + r"""Flag to control whether to stop the event from being checked against other rules""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description", "final"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputRouterTypedDict(TypedDict): + type: OutputResponseOutputRouterType r"""Connector type identifier.""" - protocol: DestinationProtocolOptions - r"""Protocol to use when communicating with the destination.""" - host: str - r"""The hostname of the destination.""" - port: float - r"""Destination port.""" + rules: List[OutputResponseRuleTypedDict] + r"""Event routing rules""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -484,20 +607,138 @@ class OutputResponseOutputStatsdTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - mtu: NotRequired[float] - r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - flush_period_sec: NotRequired[float] - r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + report_branch_metrics: NotRequired[bool] + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" description: NotRequired[str] r"""Optional description for this configuration.""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + +class OutputResponseOutputRouter(BaseModel): + type: OutputResponseOutputRouterType + r"""Connector type identifier.""" + + rules: List[OutputResponseRule] + r"""Event routing rules""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + report_branch_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="reportBranchMetrics") + ] = None + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "reportBranchMetrics", + "description", + "__template_streamtags", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputGraphiteType(str, Enum): + r"""Connector type identifier.""" + + GRAPHITE = "graphite" + + +class OutputResponseOutputGraphitePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputGraphitePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputGraphiteTypedDict(TypedDict): + type: OutputResponseOutputGraphiteType + r"""Connector type identifier.""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + flush_period_sec: NotRequired[float] + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" pq_strict_ordering: NotRequired[bool] @@ -522,20 +763,20 @@ class OutputResponseOutputStatsdTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputStatsdPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputGraphitePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputStatsd(BaseModel): - type: OutputResponseOutputStatsdType +class OutputResponseOutputGraphite(BaseModel): + type: OutputResponseOutputGraphiteType r"""Connector type identifier.""" protocol: DestinationProtocolOptions @@ -650,7 +891,7 @@ class OutputResponseOutputStatsd(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputStatsdPqControls], + Optional[OutputResponseOutputGraphitePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -665,7 +906,7 @@ class OutputResponseOutputStatsd(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -765,21 +1006,29 @@ def serialize_model(self, handler): return m -class OutputResponseOutputMinioType(str, Enum): +class OutputResponseOutputStatsdExtType(str, Enum): r"""Connector type identifier.""" - MINIO = "minio" + STATSD_EXT = "statsd_ext" -class OutputResponseOutputMinioTypedDict(TypedDict): - type: OutputResponseOutputMinioType +class OutputResponseOutputStatsdExtPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputStatsdExtPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputStatsdExtTypedDict(TypedDict): + type: OutputResponseOutputStatsdExtType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""MinIO service url (e.g. http://minioHost:9000)""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -790,157 +1039,68 @@ class OutputResponseOutputMinioTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the MinIO bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ - ServerSideEncryptionForUploadedObjectsOptionsAes256 - ] - r"""Server-side encryption to use for uploaded objects""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + flush_period_sec: NotRequired[float] + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputStatsdExtPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputMinio(BaseModel): - type: OutputResponseOutputMinioType +class OutputResponseOutputStatsdExt(BaseModel): + type: OutputResponseOutputStatsdExtType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + host: str + r"""The hostname of the destination.""" - endpoint: str - r"""MinIO service url (e.g. http://minioHost:9000)""" + port: float + r"""Destination port.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -959,426 +1119,468 @@ class OutputResponseOutputMinio(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - region: Optional[str] = None - r"""Region where the MinIO bucket is located""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + mtu: Optional[float] = None + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Add the Output ID value to staging location""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Remove empty staging directories after moving files""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( None ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Buffer size used to write to a file""" + r"""Codec to use to compress the persisted data""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + pq_controls: Annotated[ + Optional[OutputResponseOutputStatsdExtPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""Persistent queue controls.""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.DestinationProtocolOptions(value) + except ValueError: + return value + return value - storage_class: Annotated[ - Optional[StorageClassOptionsReducedredundancyStandard], - pydantic.Field(alias="storageClass"), - ] = None - r"""Storage class to select for uploaded objects""" + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], - pydantic.Field(alias="serverSideEncryption"), - ] = None - r"""Server-side encryption to use for uploaded objects""" + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value - description: Optional[str] = None - r"""Optional description for this configuration.""" + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "mtu", + "flushPeriodSec", + "dnsResolvePeriodSec", + "description", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "onBackpressure", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_onBackpressure", + "notifications", + "status", + ] + ) + serialized = handler(self) + m = {} - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" + return m - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" +class OutputResponseOutputStatsdType(str, Enum): + r"""Connector type identifier.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + STATSD = "statsd" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" +class OutputResponseOutputStatsdPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ +class OutputResponseOutputStatsdPqControls(BaseModel): + r"""Persistent queue controls.""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" +class OutputResponseOutputStatsdTypedDict(TypedDict): + type: OutputResponseOutputStatsdType + r"""Connector type identifier.""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" + host: str + r"""The hostname of the destination.""" + port: float + r"""Destination port.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + mtu: NotRequired[float] + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" + flush_period_sec: NotRequired[float] + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" + dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputStatsdPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" +class OutputResponseOutputStatsd(BaseModel): + type: OutputResponseOutputStatsdType + r"""Connector type identifier.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + protocol: DestinationProtocolOptions + r"""Protocol to use when communicating with the destination.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + host: str + r"""The hostname of the destination.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + port: float + r"""Destination port.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + id: Optional[str] = None + r"""Unique ID for this output""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") - ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + mtu: Optional[float] = None + r"""When protocol is UDP, specifies the maximum size of packets sent to the destination. Also known as the MTU for the network path to the destination system.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""When protocol is TCP, specifies how often buffers should be flushed, resulting in records sent to the destination.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every batch sent will incur a DNS lookup.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""How to handle events when all receivers are exerting backpressure""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) - except ValueError: - return value - return value + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value + pq_controls: Annotated[ + Optional[OutputResponseOutputStatsdPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" - @field_serializer("object_acl") - def serialize_object_acl(self, value): - if isinstance(value, str): - try: - return models.ObjectACLOptions(value) - except ValueError: - return value - return value + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.StorageClassOptionsReducedredundancyStandard(value) - except ValueError: - return value - return value + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) + return models.DestinationProtocolOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -1392,72 +1594,28 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "region", - "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", + "mtu", + "flushPeriodSec", + "dnsResolvePeriodSec", "description", - "awsApiKey", - "awsSecret", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "__template_streamtags", - "__template_bucket", - "__template_region", - "__template_destPath", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", - "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_awsApiKey", - "__template_compress", - "__template_parquetSchema", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "onBackpressure", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_onBackpressure", "notifications", "status", ] @@ -1476,29 +1634,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputCloudwatchType(str, Enum): +class OutputResponseOutputMinioType(str, Enum): r"""Connector type identifier.""" - CLOUDWATCH = "cloudwatch" - - -class OutputResponseOutputCloudwatchPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputCloudwatchPqControls(BaseModel): - r"""Persistent queue controls.""" + MINIO = "minio" -class OutputResponseOutputCloudwatchTypedDict(TypedDict): - type: OutputResponseOutputCloudwatchType +class OutputResponseOutputMinioTypedDict(TypedDict): + type: OutputResponseOutputMinioType r"""Connector type identifier.""" - log_group_name: str - r"""CloudWatch log group to associate events with""" - log_stream_name: str - r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" - region: str - r"""Region where the CloudWatchLogs is located""" + bucket: str + r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""MinIO service url (e.g. http://minioHost:9000)""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -1511,98 +1661,155 @@ class OutputResponseOutputCloudwatchTypedDict(TypedDict): r"""Metadata tags used for categorization and filtering.""" aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" reuse_connections: NotRequired[bool] r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access CloudWatchLogs""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + region: NotRequired[str] + r"""Region where the MinIO bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsReducedredundancyStandard] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ + ServerSideEncryptionForUploadedObjectsOptionsAes256 + ] + r"""Server-side encryption to use for uploaded objects""" description: NotRequired[str] r"""Optional description for this configuration.""" aws_api_key: NotRequired[str] - r"""Access key""" + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" aws_secret: NotRequired[str] r"""Select or create a stored secret that references your access key and secret key""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputCloudwatchPqControlsTypedDict] - r"""Persistent queue controls.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_group_name: NotRequired[str] - r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" - template_log_stream_name: NotRequired[str] - r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" template_aws_api_key: NotRequired[str] r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputCloudwatch(BaseModel): - type: OutputResponseOutputCloudwatchType +class OutputResponseOutputMinio(BaseModel): + type: OutputResponseOutputMinioType r"""Connector type identifier.""" - log_group_name: Annotated[str, pydantic.Field(alias="logGroupName")] - r"""CloudWatch log group to associate events with""" + bucket: str + r"""Name of the destination MinIO bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - log_stream_name: Annotated[str, pydantic.Field(alias="logStreamName")] - r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - region: str - r"""Region where the CloudWatchLogs is located""" + endpoint: str + r"""MinIO service url (e.g. http://minioHost:9000)""" id: Optional[str] = None r"""Unique ID for this output""" @@ -1627,14 +1834,6 @@ class OutputResponseOutputCloudwatch(BaseModel): ] = None r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" - - endpoint: Optional[str] = None - r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - reuse_connections: Annotated[ Optional[bool], pydantic.Field(alias="reuseConnections") ] = None @@ -1645,161 +1844,310 @@ class OutputResponseOutputCloudwatch(BaseModel): ] = None r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access CloudWatchLogs""" + region: Optional[str] = None + r"""Region where the MinIO bucket is located""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""External ID to use when assuming role""" + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") + ] = None + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( None ) - r"""Maximum number of queued batches before blocking""" + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + ] = None + r"""Object ACL to assign to uploaded objects""" + + storage_class: Annotated[ + Optional[StorageClassOptionsReducedredundancyStandard], + pydantic.Field(alias="storageClass"), + ] = None + r"""Storage class to select for uploaded objects""" + + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptionsAes256], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" + description: Optional[str] = None r"""Optional description for this configuration.""" aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None r"""Select or create a stored secret that references your access key and secret key""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Compression level to apply before moving files to final destination""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Determines which data types are supported and how they are represented""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""Codec to use to compress the persisted data""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_controls: Annotated[ - Optional[OutputResponseOutputCloudwatchPqControls], - pydantic.Field(alias="pqControls"), + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Persistent queue controls.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""How frequently, in seconds, to clean up empty directories""" - template_log_group_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_logGroupName") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - template_log_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_logStreamName") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: Annotated[ Optional[str], pydantic.Field(alias="__template_region") ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + ] = None + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_aws_api_key: Annotated[ Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -1814,38 +2162,92 @@ def serialize_aws_authentication_method(self, value): return value return value + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.DataFormatOptions(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.StorageClassOptionsReducedredundancyStandard(value) + except ValueError: + return value + return value + + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): + if isinstance(value, str): + try: + return models.ServerSideEncryptionForUploadedObjectsOptionsAes256(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -1860,43 +2262,71 @@ def serialize_model(self, handler): "environment", "streamtags", "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", "reuseConnections", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "maxQueueSize", - "maxRecordSizeKB", - "flushPeriodSec", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", "description", "awsApiKey", "awsSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_logGroupName", - "__template_logStreamName", - "__template_awsSecretKey", + "__template_bucket", "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_destPath", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", "notifications", "status", ] @@ -1915,59 +2345,29 @@ def serialize_model(self, handler): return m -class OutputResponseOutputInfluxdbType(str, Enum): +class OutputResponseOutputCloudwatchType(str, Enum): r"""Connector type identifier.""" - INFLUXDB = "influxdb" - - -class OutputResponseTimestampPrecision(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - - # Nanoseconds - NS = "ns" - # Microseconds - U = "u" - # Milliseconds - MS = "ms" - # Seconds - S = "s" - # Minutes - M = "m" - # Hours - H = "h" - - -class OutputResponseOutputInfluxdbAuthenticationType( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""InfluxDB authentication type""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" + CLOUDWATCH = "cloudwatch" -class OutputResponseOutputInfluxdbPqControlsTypedDict(TypedDict): +class OutputResponseOutputCloudwatchPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputInfluxdbPqControls(BaseModel): +class OutputResponseOutputCloudwatchPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputInfluxdbTypedDict(TypedDict): - type: OutputResponseOutputInfluxdbType +class OutputResponseOutputCloudwatchTypedDict(TypedDict): + type: OutputResponseOutputCloudwatchType r"""Connector type identifier.""" - url: str - r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + log_group_name: str + r"""CloudWatch log group to associate events with""" + log_stream_name: str + r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + region: str + r"""Region where the CloudWatchLogs is located""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -1978,60 +2378,38 @@ class OutputResponseOutputInfluxdbTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - use_v2_api: NotRequired[bool] - r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - timestamp_precision: NotRequired[OutputResponseTimestampPrecision] - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - dynamic_value_field_name: NotRequired[bool] - r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" - value_field_name: NotRequired[str] - r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access CloudWatchLogs""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[OutputResponseOutputInfluxdbAuthenticationType] - r"""InfluxDB authentication type""" description: NotRequired[str] r"""Optional description for this configuration.""" - database: NotRequired[str] - r"""Database to write to.""" - bucket: NotRequired[str] - r"""Bucket to write to.""" - org: NotRequired[str] - r"""Organization ID for this bucket.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -2054,42 +2432,46 @@ class OutputResponseOutputInfluxdbTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputInfluxdbPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputCloudwatchPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_log_group_name: NotRequired[str] + r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" + template_log_stream_name: NotRequired[str] + r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputInfluxdb(BaseModel): - type: OutputResponseOutputInfluxdbType +class OutputResponseOutputCloudwatch(BaseModel): + type: OutputResponseOutputCloudwatchType r"""Connector type identifier.""" - url: str - r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" + log_group_name: Annotated[str, pydantic.Field(alias="logGroupName")] + r"""CloudWatch log group to associate events with""" + + log_stream_name: Annotated[str, pydantic.Field(alias="logStreamName")] + r"""Prefix for CloudWatch log stream name. This prefix will be used to generate a unique log stream name per cribl instance, for example: myStream_myHost_myOutputId""" + + region: str + r"""Region where the CloudWatchLogs is located""" id: Optional[str] = None r"""Unique ID for this output""" @@ -2108,121 +2490,78 @@ class OutputResponseOutputInfluxdb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - use_v2_api: Annotated[Optional[bool], pydantic.Field(alias="useV2API")] = None - r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - - timestamp_precision: Annotated[ - Optional[OutputResponseTimestampPrecision], - pydantic.Field(alias="timestampPrecision"), - ] = None - r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - - dynamic_value_field_name: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicValueFieldName") - ] = None - r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" - - value_field_name: Annotated[ - Optional[str], pydantic.Field(alias="valueFieldName") + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" + r"""AWS authentication method. Choose Auto to use IAM roles.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + endpoint: Optional[str] = None + r"""CloudWatchLogs service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to CloudWatchLogs-compatible endpoint.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Headers to add to all events""" + r"""Use Assume Role credentials to access CloudWatchLogs""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""External ID to use when assuming role""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None + r"""Maximum size (KB) of each individual record before compression. For non compressible data 1MB is the max recommended size""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[OutputResponseOutputInfluxdbAuthenticationType], - pydantic.Field(alias="authType"), - ] = None - r"""InfluxDB authentication type""" - description: Optional[str] = None r"""Optional description for this configuration.""" - database: Optional[str] = None - r"""Database to write to.""" - - bucket: Optional[str] = None - r"""Bucket to write to.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" - org: Optional[str] = None - r"""Organization ID for this bucket.""" + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -2274,78 +2613,72 @@ class OutputResponseOutputInfluxdb(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputInfluxdbPqControls], + Optional[OutputResponseOutputCloudwatchPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - password: Optional[str] = None - r"""Password""" + template_log_group_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_logGroupName") + ] = None + r"""Binds 'logGroupName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logGroupName' at runtime.""" - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" + template_log_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_logStreamName") + ] = None + r"""Binds 'logStreamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logStreamName' at runtime.""" - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") ] = None - r"""Select or create a secret that references your credentials""" + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") - ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("timestamp_precision") - def serialize_timestamp_precision(self, value): - if isinstance(value, str): - try: - return models.OutputResponseTimestampPrecision(value) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value @@ -2359,15 +2692,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputInfluxdbAuthenticationType(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -2404,31 +2728,22 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "useV2API", - "timestampPrecision", - "dynamicValueFieldName", - "valueFieldName", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "maxQueueSize", + "maxRecordSizeKB", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", "onBackpressure", - "authType", "description", - "database", - "bucket", - "org", + "awsApiKey", + "awsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -2441,17 +2756,16 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", "__template_streamtags", - "__template_url", - "__template_failedRequestLoggingMode", + "__template_logGroupName", + "__template_logStreamName", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", - "__template_database", - "__template_bucket", + "__template_awsApiKey", "notifications", "status", ] @@ -2470,27 +2784,59 @@ def serialize_model(self, handler): return m -class OutputResponseOutputNewrelicEventsType(str, Enum): +class OutputResponseOutputInfluxdbType(str, Enum): r"""Connector type identifier.""" - NEWRELIC_EVENTS = "newrelic_events" + INFLUXDB = "influxdb" -class OutputResponseOutputNewrelicEventsPqControlsTypedDict(TypedDict): +class OutputResponseTimestampPrecision(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" + + # Nanoseconds + NS = "ns" + # Microseconds + U = "u" + # Milliseconds + MS = "ms" + # Seconds + S = "s" + # Minutes + M = "m" + # Hours + H = "h" + + +class OutputResponseOutputInfluxdbAuthenticationType( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""InfluxDB authentication type""" + + # None + NONE = "none" + # Basic + BASIC = "basic" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token + TOKEN = "token" + # Token (text secret) + TEXT_SECRET = "textSecret" + + +class OutputResponseOutputInfluxdbPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputNewrelicEventsPqControls(BaseModel): +class OutputResponseOutputInfluxdbPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputNewrelicEventsTypedDict(TypedDict): - type: OutputResponseOutputNewrelicEventsType +class OutputResponseOutputInfluxdbTypedDict(TypedDict): + type: OutputResponseOutputInfluxdbType r"""Connector type identifier.""" - account_id: str - r"""New Relic account ID""" - event_type: str - r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" + url: str + r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -2501,8 +2847,14 @@ class OutputResponseOutputNewrelicEventsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - region: NotRequired[RegionOptions] - r"""Which New Relic region endpoint to use.""" + use_v2_api: NotRequired[bool] + r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" + timestamp_precision: NotRequired[OutputResponseTimestampPrecision] + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" + dynamic_value_field_name: NotRequired[bool] + r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" + value_field_name: NotRequired[str] + r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -2539,11 +2891,16 @@ class OutputResponseOutputNewrelicEventsTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" + auth_type: NotRequired[OutputResponseOutputInfluxdbAuthenticationType] + r"""InfluxDB authentication type""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_url: NotRequired[str] + database: NotRequired[str] + r"""Database to write to.""" + bucket: NotRequired[str] + r"""Bucket to write to.""" + org: NotRequired[str] + r"""Organization ID for this bucket.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -2566,41 +2923,42 @@ class OutputResponseOutputNewrelicEventsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputNewrelicEventsPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputInfluxdbPqControlsTypedDict] r"""Persistent queue controls.""" - api_key: NotRequired[str] - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + username: NotRequired[str] + r"""Username""" + password: NotRequired[str] + r"""Password""" + token: NotRequired[str] + r"""Bearer token to include in the authorization header""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_account_id: NotRequired[str] - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - template_event_type: NotRequired[str] - r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: NotRequired[str] - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputNewrelicEvents(BaseModel): - type: OutputResponseOutputNewrelicEventsType +class OutputResponseOutputInfluxdb(BaseModel): + type: OutputResponseOutputInfluxdbType r"""Connector type identifier.""" - account_id: Annotated[str, pydantic.Field(alias="accountId")] - r"""New Relic account ID""" - - event_type: Annotated[str, pydantic.Field(alias="eventType")] - r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" + url: str + r"""URL of an InfluxDB cluster to send events to, e.g., http://localhost:8086/write""" id: Optional[str] = None r"""Unique ID for this output""" @@ -2619,21 +2977,37 @@ class OutputResponseOutputNewrelicEvents(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - region: Optional[RegionOptions] = None - r"""Which New Relic region endpoint to use.""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + use_v2_api: Annotated[Optional[bool], pydantic.Field(alias="useV2API")] = None + r"""The v2 API can be enabled with InfluxDB versions 1.8 and later.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + timestamp_precision: Annotated[ + Optional[OutputResponseTimestampPrecision], + pydantic.Field(alias="timestampPrecision"), ] = None - r"""Maximum size, in KB, of the request body""" + r"""Sets the precision for the supplied Unix time values. Defaults to milliseconds.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + dynamic_value_field_name: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicValueFieldName") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Enabling this will pull the value field from the metric name. E,g, 'db.query.user' will use 'db.query' as the measurement and 'user' as the value field.""" + + value_field_name: Annotated[ + Optional[str], pydantic.Field(alias="valueFieldName") + ] = None + r"""Name of the field in which to store the metric when sending to InfluxDB. If dynamic generation is enabled and fails, this will be used as a fallback.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: Optional[bool] = None r"""Compress the payload body before sending""" @@ -2702,14 +3076,22 @@ class OutputResponseOutputNewrelicEvents(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + Optional[OutputResponseOutputInfluxdbAuthenticationType], + pydantic.Field(alias="authType"), ] = None - r"""Enter API key directly, or select a stored secret""" + r"""InfluxDB authentication type""" description: Optional[str] = None r"""Optional description for this configuration.""" - custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + database: Optional[str] = None + r"""Database to write to.""" + + bucket: Optional[str] = None + r"""Bucket to write to.""" + + org: Optional[str] = None + r"""Organization ID for this bucket.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -2761,13 +3143,24 @@ class OutputResponseOutputNewrelicEvents(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputNewrelicEventsPqControls], + Optional[OutputResponseOutputInfluxdbPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + username: Optional[str] = None + r"""Username""" + + password: Optional[str] = None + r"""Password""" + + token: Optional[str] = None + r"""Bearer token to include in the authorization header""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -2777,20 +3170,10 @@ class OutputResponseOutputNewrelicEvents(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_account_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_accountId") - ] = None - r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - - template_event_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_eventType") - ] = None - r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -2802,22 +3185,27 @@ class OutputResponseOutputNewrelicEvents(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_custom_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_customUrl") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("region") - def serialize_region(self, value): + @field_serializer("timestamp_precision") + def serialize_timestamp_precision(self, value): if isinstance(value, str): try: - return models.RegionOptions(value) + return models.OutputResponseTimestampPrecision(value) except ValueError: return value return value @@ -2844,7 +3232,7 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAPI(value) + return models.OutputResponseOutputInfluxdbAuthenticationType(value) except ValueError: return value return value @@ -2885,7 +3273,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "region", + "useV2API", + "timestampPrecision", + "dynamicValueFieldName", + "valueFieldName", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -2904,7 +3295,9 @@ def serialize_model(self, handler): "onBackpressure", "authType", "description", - "customUrl", + "database", + "bucket", + "org", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -2917,15 +3310,17 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "apiKey", + "username", + "password", + "token", + "credentialsSecret", "textSecret", "__template_streamtags", - "__template_region", - "__template_accountId", - "__template_eventType", + "__template_url", "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_customUrl", + "__template_database", + "__template_bucket", "notifications", "status", ] @@ -2944,56 +3339,27 @@ def serialize_model(self, handler): return m -class OutputResponseOutputNewrelicType(str, Enum): +class OutputResponseOutputNewrelicEventsType(str, Enum): r"""Connector type identifier.""" - NEWRELIC = "newrelic" - - -class OutputResponseFieldName(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Name of the metadata field.""" - - SERVICE = "service" - HOSTNAME = "hostname" - TIMESTAMP = "timestamp" - AUDIT_ID = "auditId" - - -class OutputResponseMetadatumTypedDict(TypedDict): - name: OutputResponseFieldName - r"""Name of the metadata field.""" - value: str - r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - - -class OutputResponseMetadatum(BaseModel): - name: OutputResponseFieldName - r"""Name of the metadata field.""" - - value: str - r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" - - @field_serializer("name") - def serialize_name(self, value): - if isinstance(value, str): - try: - return models.OutputResponseFieldName(value) - except ValueError: - return value - return value + NEWRELIC_EVENTS = "newrelic_events" -class OutputResponseOutputNewrelicPqControlsTypedDict(TypedDict): +class OutputResponseOutputNewrelicEventsPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputNewrelicPqControls(BaseModel): +class OutputResponseOutputNewrelicEventsPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputNewrelicTypedDict(TypedDict): - type: OutputResponseOutputNewrelicType +class OutputResponseOutputNewrelicEventsTypedDict(TypedDict): + type: OutputResponseOutputNewrelicEventsType r"""Connector type identifier.""" + account_id: str + r"""New Relic account ID""" + event_type: str + r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -3006,12 +3372,6 @@ class OutputResponseOutputNewrelicTypedDict(TypedDict): r"""Metadata tags used for categorization and filtering.""" region: NotRequired[RegionOptions] r"""Which New Relic region endpoint to use.""" - log_type: NotRequired[str] - r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" - message_field: NotRequired[str] - r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" - metadata: NotRequired[List[OutputResponseMetadatumTypedDict]] - r"""Fields to add to events from this input""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -3050,8 +3410,6 @@ class OutputResponseOutputNewrelicTypedDict(TypedDict): r"""How to handle events when all receivers are exerting backpressure""" auth_type: NotRequired[AuthenticationMethodOptionsAPI] r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" custom_url: NotRequired[str] @@ -3077,7 +3435,7 @@ class OutputResponseOutputNewrelicTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputNewrelicPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputNewrelicEventsPqControlsTypedDict] r"""Persistent queue controls.""" api_key: NotRequired[str] r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" @@ -3087,24 +3445,32 @@ class OutputResponseOutputNewrelicTypedDict(TypedDict): r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_log_type: NotRequired[str] - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" - template_message_field: NotRequired[str] - r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" + template_account_id: NotRequired[str] + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" + template_event_type: NotRequired[str] + r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_custom_url: NotRequired[str] + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputNewrelic(BaseModel): - type: OutputResponseOutputNewrelicType +class OutputResponseOutputNewrelicEvents(BaseModel): + type: OutputResponseOutputNewrelicEventsType r"""Connector type identifier.""" + account_id: Annotated[str, pydantic.Field(alias="accountId")] + r"""New Relic account ID""" + + event_type: Annotated[str, pydantic.Field(alias="eventType")] + r"""Default New Relic eventType to use when event type is not present. For more information, see the [New Relic eventType documentation](https://docs.newrelic.com/docs/telemetry-data-platform/custom-data/custom-events/data-requirements-limits-custom-event-data/#reserved-words).""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -3125,15 +3491,6 @@ class OutputResponseOutputNewrelic(BaseModel): region: Optional[RegionOptions] = None r"""Which New Relic region endpoint to use.""" - log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None - r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" - - message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None - r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" - - metadata: Optional[List[OutputResponseMetadatum]] = None - r"""Fields to add to events from this input""" - concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -3218,11 +3575,6 @@ class OutputResponseOutputNewrelic(BaseModel): ] = None r"""Enter API key directly, or select a stored secret""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -3278,7 +3630,7 @@ class OutputResponseOutputNewrelic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputNewrelicPqControls], + Optional[OutputResponseOutputNewrelicEventsPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -3299,15 +3651,15 @@ class OutputResponseOutputNewrelic(BaseModel): ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_log_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_logType") + template_account_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_accountId") ] = None - r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + r"""Binds 'accountId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'accountId' at runtime.""" - template_message_field: Annotated[ - Optional[str], pydantic.Field(alias="__template_messageField") + template_event_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_eventType") ] = None - r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" + r"""Binds 'eventType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'eventType' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") @@ -3319,7 +3671,12 @@ class OutputResponseOutputNewrelic(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_custom_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_customUrl") + ] = None + r"""Binds 'customUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customUrl' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -3398,9 +3755,6 @@ def serialize_model(self, handler): "environment", "streamtags", "region", - "logType", - "messageField", - "metadata", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -3418,7 +3772,6 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "authType", - "totalMemoryLimitKB", "description", "customUrl", "pqStrictOrdering", @@ -3437,10 +3790,11 @@ def serialize_model(self, handler): "textSecret", "__template_streamtags", "__template_region", - "__template_logType", - "__template_messageField", + "__template_accountId", + "__template_eventType", "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_customUrl", "notifications", "status", ] @@ -3459,28 +3813,57 @@ def serialize_model(self, handler): return m -class OutputResponseOutputElasticCloudType(str, Enum): +class OutputResponseOutputNewrelicType(str, Enum): r"""Connector type identifier.""" - ELASTIC_CLOUD = "elastic_cloud" + NEWRELIC = "newrelic" -class OutputResponseOutputElasticCloudPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseFieldName(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Name of the metadata field.""" + SERVICE = "service" + HOSTNAME = "hostname" + TIMESTAMP = "timestamp" + AUDIT_ID = "auditId" -class OutputResponseOutputElasticCloudPqControls(BaseModel): - r"""Persistent queue controls.""" +class OutputResponseMetadatumTypedDict(TypedDict): + name: OutputResponseFieldName + r"""Name of the metadata field.""" + value: str + r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" -class OutputResponseOutputElasticCloudTypedDict(TypedDict): - type: OutputResponseOutputElasticCloudType - r"""Connector type identifier.""" - url: str - r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" - index: str - r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" - id: NotRequired[str] + +class OutputResponseMetadatum(BaseModel): + name: OutputResponseFieldName + r"""Name of the metadata field.""" + + value: str + r"""JavaScript expression to compute field's value, enclosed in quotes or backticks. (Can evaluate to a constant.)""" + + @field_serializer("name") + def serialize_name(self, value): + if isinstance(value, str): + try: + return models.OutputResponseFieldName(value) + except ValueError: + return value + return value + + +class OutputResponseOutputNewrelicPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputNewrelicPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputNewrelicTypedDict(TypedDict): + type: OutputResponseOutputNewrelicType + r"""Connector type identifier.""" + id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] r"""Pipeline to process data before sending out to this output""" @@ -3490,6 +3873,14 @@ class OutputResponseOutputElasticCloudTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + region: NotRequired[RegionOptions] + r"""Which New Relic region endpoint to use.""" + log_type: NotRequired[str] + r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + message_field: NotRequired[str] + r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + metadata: NotRequired[List[OutputResponseMetadatumTypedDict]] + r"""Fields to add to events from this input""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -3511,17 +3902,12 @@ class OutputResponseOutputElasticCloudTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] - r"""Extra parameters to use in HTTP requests""" - auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] - elastic_pipeline: NotRequired[str] - r"""Optional Elastic Cloud Destination pipeline""" - include_doc_id: NotRequired[bool] - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -3531,8 +3917,13 @@ class OutputResponseOutputElasticCloudTypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + custom_url: NotRequired[str] pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -3555,36 +3946,34 @@ class OutputResponseOutputElasticCloudTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputElasticCloudPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputNewrelicPqControlsTypedDict] r"""Persistent queue controls.""" + api_key: NotRequired[str] + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_index: NotRequired[str] - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_log_type: NotRequired[str] + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + template_message_field: NotRequired[str] + r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: NotRequired[str] - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputElasticCloud(BaseModel): - type: OutputResponseOutputElasticCloudType +class OutputResponseOutputNewrelic(BaseModel): + type: OutputResponseOutputNewrelicType r"""Connector type identifier.""" - url: str - r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" - - index: str - r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -3602,6 +3991,18 @@ class OutputResponseOutputElasticCloud(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + region: Optional[RegionOptions] = None + r"""Which New Relic region endpoint to use.""" + + log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None + r"""Name of the logtype to send with events, e.g.: observability, access_log. The event's 'sourcetype' field (if set) will override this value.""" + + message_field: Annotated[Optional[str], pydantic.Field(alias="messageField")] = None + r"""Name of field to send as log message value. If not present, event will be serialized and sent as JSON.""" + + metadata: Optional[List[OutputResponseMetadatum]] = None + r"""Fields to add to events from this input""" + concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -3645,6 +4046,11 @@ class OutputResponseOutputElasticCloud(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -3656,23 +4062,6 @@ class OutputResponseOutputElasticCloud(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - extra_params: Annotated[ - Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") - ] = None - r"""Extra parameters to use in HTTP requests""" - - auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - - elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="elasticPipeline") - ] = None - r"""Optional Elastic Cloud Destination pipeline""" - - include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( - None - ) - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -3693,9 +4082,21 @@ class OutputResponseOutputElasticCloud(BaseModel): ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + ] = None + r"""Enter API key directly, or select a stored secret""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + description: Optional[str] = None r"""Optional description for this configuration.""" + custom_url: Annotated[Optional[str], pydantic.Field(alias="customUrl")] = None + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -3746,47 +4147,62 @@ class OutputResponseOutputElasticCloud(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputElasticCloudPqControls], + Optional[OutputResponseOutputNewrelicPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""New Relic API key. Can be overridden using __newRelic_apiKey field.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_index: Annotated[ - Optional[str], pydantic.Field(alias="__template_index") + template_log_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_logType") ] = None - r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + r"""Binds 'logType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logType' at runtime.""" + + template_message_field: Annotated[ + Optional[str], pydantic.Field(alias="__template_messageField") + ] = None + r"""Binds 'messageField' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'messageField' at runtime.""" template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_elastic_pipeline: Annotated[ - Optional[str], pydantic.Field(alias="__template_elasticPipeline") - ] = None - r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + @field_serializer("region") + def serialize_region(self, value): + if isinstance(value, str): + try: + return models.RegionOptions(value) + except ValueError: + return value + return value + @field_serializer("failed_request_logging_mode") def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): @@ -3805,6 +4221,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAPI(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -3841,6 +4266,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "region", + "logType", + "messageField", + "metadata", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -3850,17 +4279,17 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "extraParams", - "auth", - "elasticPipeline", - "includeDocId", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", "onBackpressure", + "authType", + "totalMemoryLimitKB", "description", + "customUrl", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -3873,11 +4302,13 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "apiKey", + "textSecret", "__template_streamtags", - "__template_url", - "__template_index", + "__template_region", + "__template_logType", + "__template_messageField", "__template_failedRequestLoggingMode", - "__template_elasticPipeline", "__template_onBackpressure", "notifications", "status", @@ -3897,83 +4328,27 @@ def serialize_model(self, handler): return m -class OutputResponseOutputElasticType(str, Enum): +class OutputResponseOutputElasticCloudType(str, Enum): r"""Connector type identifier.""" - ELASTIC = "elastic" - - -class OutputResponseElasticVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - - # Auto - AUTO = "auto" - # 6.x - SIX = "6" - # 7.x - SEVEN = "7" - + ELASTIC_CLOUD = "elastic_cloud" -class OutputResponseWriteAction(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - # Index - INDEX = "index" - # Create - CREATE = "create" +class OutputResponseOutputElasticCloudPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" -class OutputResponseOutputElasticURLTypedDict(TypedDict): - url: str - r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" +class OutputResponseOutputElasticCloudPqControls(BaseModel): + r"""Persistent queue controls.""" -class OutputResponseOutputElasticURL(BaseModel): +class OutputResponseOutputElasticCloudTypedDict(TypedDict): + type: OutputResponseOutputElasticCloudType + r"""Connector type identifier.""" url: str - r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" - - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputElasticPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputElasticPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class OutputResponseOutputElasticTypedDict(TypedDict): - type: OutputResponseOutputElasticType - r"""Connector type identifier.""" + r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" index: str - r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" + r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -3984,10 +4359,6 @@ class OutputResponseOutputElasticTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - doc_type: NotRequired[str] - r"""Document type to use for events. Can be overwritten by an event's __type field.""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -4013,6 +4384,13 @@ class OutputResponseOutputElasticTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" + extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] + r"""Extra parameters to use in HTTP requests""" + auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] + elastic_pipeline: NotRequired[str] + r"""Optional Elastic Cloud Destination pipeline""" + include_doc_id: NotRequired[bool] + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -4020,35 +4398,10 @@ class OutputResponseOutputElasticTypedDict(TypedDict): timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] response_honor_retry_after_header: NotRequired[bool] r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] - r"""Extra parameters""" - auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] - elastic_version: NotRequired[OutputResponseElasticVersion] - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - elastic_pipeline: NotRequired[str] - r"""Optional Elasticsearch destination pipeline""" - include_doc_id: NotRequired[bool] - r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - write_action: NotRequired[OutputResponseWriteAction] - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - retry_partial_errors: NotRequired[bool] - r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[OutputResponseOutputElasticURLTypedDict]] - r"""Bulk API URLs""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -4071,34 +4424,35 @@ class OutputResponseOutputElasticTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputElasticPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputElasticCloudPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_index: NotRequired[str] r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_doc_type: NotRequired[str] - r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_elastic_pipeline: NotRequired[str] r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputElastic(BaseModel): - type: OutputResponseOutputElasticType +class OutputResponseOutputElasticCloud(BaseModel): + type: OutputResponseOutputElasticCloudType r"""Connector type identifier.""" + url: str + r"""Enter Cloud ID of the Elastic Cloud environment to send events to""" + index: str - r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" + r"""Data stream or index to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -4117,14 +4471,6 @@ class OutputResponseOutputElastic(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - - doc_type: Annotated[Optional[str], pydantic.Field(alias="docType")] = None - r"""Document type to use for events. Can be overwritten by an event's __type field.""" - concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -4179,52 +4525,37 @@ class OutputResponseOutputElastic(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - extra_params: Annotated[ Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") ] = None - r"""Extra parameters""" + r"""Extra parameters to use in HTTP requests""" auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None - elastic_version: Annotated[ - Optional[OutputResponseElasticVersion], pydantic.Field(alias="elasticVersion") - ] = None - r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - elastic_pipeline: Annotated[ Optional[str], pydantic.Field(alias="elasticPipeline") ] = None - r"""Optional Elasticsearch destination pipeline""" + r"""Optional Elastic Cloud Destination pipeline""" include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( None ) r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - write_action: Annotated[ - Optional[OutputResponseWriteAction], pydantic.Field(alias="writeAction") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - retry_partial_errors: Annotated[ - Optional[bool], pydantic.Field(alias="retryPartialErrors") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -4234,30 +4565,6 @@ class OutputResponseOutputElastic(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - urls: Optional[List[OutputResponseOutputElasticURL]] = None - r"""Bulk API URLs""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -4308,7 +4615,7 @@ class OutputResponseOutputElastic(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputElasticPqControls], + Optional[OutputResponseOutputElasticCloudPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -4318,16 +4625,16 @@ class OutputResponseOutputElastic(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + template_index: Annotated[ Optional[str], pydantic.Field(alias="__template_index") ] = None r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_doc_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_docType") - ] = None - r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" - template_failed_request_logging_mode: Annotated[ Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None @@ -4343,12 +4650,7 @@ class OutputResponseOutputElastic(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -4363,24 +4665,6 @@ def serialize_failed_request_logging_mode(self, value): return value return value - @field_serializer("elastic_version") - def serialize_elastic_version(self, value): - if isinstance(value, str): - try: - return models.OutputResponseElasticVersion(value) - except ValueError: - return value - return value - - @field_serializer("write_action") - def serialize_write_action(self, value): - if isinstance(value, str): - try: - return models.OutputResponseWriteAction(value) - except ValueError: - return value - return value - @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -4426,8 +4710,6 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "docType", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -4439,24 +4721,15 @@ def serialize_model(self, handler): "extraHttpHeaders", "failedRequestLoggingMode", "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", "extraParams", "auth", - "elasticVersion", "elasticPipeline", "includeDocId", - "writeAction", - "retryPartialErrors", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -4470,12 +4743,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_url", "__template_index", - "__template_docType", "__template_failedRequestLoggingMode", "__template_elasticPipeline", "__template_onBackpressure", - "__template_url", "notifications", "status", ] @@ -4494,97 +4766,158 @@ def serialize_model(self, handler): return m -class OutputResponseOutputMskPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseOutputElasticType(str, Enum): + r"""Connector type identifier.""" + ELASTIC = "elastic" -class OutputResponseOutputMskPqControls(BaseModel): - r"""Persistent queue controls.""" +class OutputResponseElasticVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" -class OutputResponseOutputMskTypedDict(TypedDict): - type: TypeOptionsMsk - r"""Connector type identifier.""" - brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" - aws_authentication_method: AuthenticationMethodOptionsS3CollectorConf - r"""AWS authentication method. Choose Auto to use IAM roles.""" - region: str - r"""Region where the MSK cluster is located""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - ack: NotRequired[AcknowledgmentsOptionsAllLeader] - r"""Control the number of required acknowledgments.""" - format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] - r"""Format to use to serialize events before writing to Kafka.""" - compression: NotRequired[CompressionOptionsGzipLz4] - r"""Codec to use to compress the data before sending to Kafka""" - max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - flush_event_count: NotRequired[float] - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" - flush_period_sec: NotRequired[float] - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - kafka_schema_registry: NotRequired[ - KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict - ] - r"""Kafka Schema Registry Authentication""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" + # Auto + AUTO = "auto" + # 6.x + SIX = "6" + # 7.x + SEVEN = "7" + + +class OutputResponseWriteAction(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + + # Index + INDEX = "index" + # Create + CREATE = "create" + + +class OutputResponseOutputElasticURLTypedDict(TypedDict): + url: str + r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class OutputResponseOutputElasticURL(BaseModel): + url: str + r"""The URL to an Elastic node to send events to. Example: http://elastic:9200/_bulk""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputElasticPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputElasticPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputElasticTypedDict(TypedDict): + type: OutputResponseOutputElasticType + r"""Connector type identifier.""" + index: str + r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + doc_type: NotRequired[str] + r"""Document type to use for events. Can be overwritten by an event's __type field.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access MSK""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + extra_params: NotRequired[List[SaslExtensionConfInputKafkaTypedDict]] + r"""Extra parameters""" + auth: NotRequired[AuthTypeTemplatemanualAPIKeyAuthTypeTypedDict] + elastic_version: NotRequired[OutputResponseElasticVersion] + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" + elastic_pipeline: NotRequired[str] + r"""Optional Elasticsearch destination pipeline""" + include_doc_id: NotRequired[bool] + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" + write_action: NotRequired[OutputResponseWriteAction] + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" + retry_partial_errors: NotRequired[bool] + r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - protobuf_library_id: NotRequired[str] - r"""Select a set of Protobuf definitions for the events you want to send""" - protobuf_encoding_id: NotRequired[str] - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + url: NotRequired[str] + r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[OutputResponseOutputElasticURLTypedDict]] + r"""Bulk API URLs""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -4607,54 +4940,34 @@ class OutputResponseOutputMskTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputMskPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputElasticPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compression: NotRequired[str] - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_index: NotRequired[str] + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" + template_doc_type: NotRequired[str] + r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_elastic_pipeline: NotRequired[str] + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputMsk(BaseModel): - type: TypeOptionsMsk +class OutputResponseOutputElastic(BaseModel): + type: OutputResponseOutputElasticType r"""Connector type identifier.""" - brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" - - topic: str - r"""The topic to publish events to. Can be overridden using the __topicOut field.""" - - aws_authentication_method: Annotated[ - AuthenticationMethodOptionsS3CollectorConf, - pydantic.Field(alias="awsAuthenticationMethod"), - ] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - region: str - r"""Region where the MSK cluster is located""" + index: str + r"""Index or data stream to send events to. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be overwritten by an event's __index field.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -4673,112 +4986,114 @@ class OutputResponseOutputMsk(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - ack: Optional[AcknowledgmentsOptionsAllLeader] = None - r"""Control the number of required acknowledgments.""" + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - format_: Annotated[ - Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") - ] = None - r"""Format to use to serialize events before writing to Kafka.""" + doc_type: Annotated[Optional[str], pydantic.Field(alias="docType")] = None + r"""Document type to use for events. Can be overwritten by an event's __type field.""" - compression: Optional[CompressionOptionsGzipLz4] = None - r"""Codec to use to compress the data before sending to Kafka""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + r"""Maximum size, in KB, of the request body""" - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - kafka_schema_registry: Annotated[ - Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], - pydantic.Field(alias="kafkaSchemaRegistry"), - ] = None - r"""Kafka Schema Registry Authentication""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + r"""Headers to add to all events""" - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + r"""List of headers that are safe to log in plain text""" - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None - endpoint: Optional[str] = None - r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + extra_params: Annotated[ + Optional[List[SaslExtensionConfInputKafka]], pydantic.Field(alias="extraParams") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Extra parameters""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + auth: Optional[AuthTypeTemplatemanualAPIKeyAuthType] = None + + elastic_version: Annotated[ + Optional[OutputResponseElasticVersion], pydantic.Field(alias="elasticVersion") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Optional Elasticsearch version, used to format events. If not specified, will auto-discover version.""" - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") + elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="elasticPipeline") ] = None - r"""Use Assume Role credentials to access MSK""" + r"""Optional Elasticsearch destination pipeline""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + include_doc_id: Annotated[Optional[bool], pydantic.Field(alias="includeDocId")] = ( None ) - r"""Amazon Resource Name (ARN) of the role to assume""" + r"""Include the `document_id` field when sending events to an Elastic TSDS (time series data stream)""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + write_action: Annotated[ + Optional[OutputResponseWriteAction], pydantic.Field(alias="writeAction") ] = None - r"""External ID to use when assuming role""" + r"""Action to use when writing events. Must be set to `Create` when writing to a data stream.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + retry_partial_errors: Annotated[ + Optional[bool], pydantic.Field(alias="retryPartialErrors") ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + r"""Retry failed events when a bulk request to Elastic is successful, but the response body returns an error for one or more events in the batch""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -4788,21 +5103,29 @@ class OutputResponseOutputMsk(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" + url: Optional[str] = None + r"""The Cloud ID or URL to an Elastic cluster to send events to. Example: http://elastic:9200/_bulk""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - protobuf_library_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufLibraryId") + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[OutputResponseOutputElasticURL]] = None + r"""Bulk API URLs""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Select a set of Protobuf definitions for the events you want to send""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - protobuf_encoding_id: Annotated[ - Optional[str], pydantic.Field(alias="protobufEncodingId") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + r"""How far back in time to keep traffic stats for load balancing purposes""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -4854,7 +5177,8 @@ class OutputResponseOutputMsk(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputMskPqControls], pydantic.Field(alias="pqControls") + Optional[OutputResponseOutputElasticPqControls], + pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -4863,94 +5187,65 @@ class OutputResponseOutputMsk(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") - ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_compression: Annotated[ - Optional[str], pydantic.Field(alias="__template_compression") - ] = None - r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" - - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") - ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + template_index: Annotated[ + Optional[str], pydantic.Field(alias="__template_index") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""Binds 'index' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'index' at runtime.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_doc_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_docType") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'docType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'docType' at runtime.""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + template_elastic_pipeline: Annotated[ + Optional[str], pydantic.Field(alias="__template_elasticPipeline") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Binds 'elasticPipeline' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'elasticPipeline' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("ack") - def serialize_ack(self, value): - if isinstance(value, str): - try: - return models.AcknowledgmentsOptionsAllLeader(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.RecordDataFormatOptionsJSONProtobuf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("elastic_version") + def serialize_elastic_version(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipLz4(value) + return models.OutputResponseElasticVersion(value) except ValueError: return value return value - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("write_action") + def serialize_write_action(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.OutputResponseWriteAction(value) except ValueError: return value return value @@ -5000,39 +5295,40 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "ack", - "format", - "compression", - "maxRecordSizeKB", - "flushEventCount", - "flushPeriodSec", - "kafkaSchemaRegistry", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "awsSecretKey", - "endpoint", - "reuseConnections", + "loadBalanced", + "docType", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "tls", - "onBackpressure", - "description", - "awsApiKey", - "awsSecret", - "protobufLibraryId", - "protobufEncodingId", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "extraParams", + "auth", + "elasticVersion", + "elasticPipeline", + "includeDocId", + "writeAction", + "retryPartialErrors", + "onBackpressure", + "description", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", "pqMaxBufferSize", "pqMaxBackpressureSec", "pqMaxFileSize", @@ -5043,16 +5339,12 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_topic", - "__template_format", - "__template_compression", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_index", + "__template_docType", + "__template_failedRequestLoggingMode", + "__template_elasticPipeline", "__template_onBackpressure", - "__template_awsApiKey", + "__template_url", "notifications", "status", ] @@ -5071,21 +5363,25 @@ def serialize_model(self, handler): return m -class OutputResponseOutputConfluentCloudPqControlsTypedDict(TypedDict): +class OutputResponseOutputMskPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputConfluentCloudPqControls(BaseModel): +class OutputResponseOutputMskPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputConfluentCloudTypedDict(TypedDict): - type: TypeOptionsConfluentcloud +class OutputResponseOutputMskTypedDict(TypedDict): + type: TypeOptionsMsk r"""Connector type identifier.""" brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + aws_authentication_method: AuthenticationMethodOptionsS3CollectorConf + r"""AWS authentication method. Choose Auto to use IAM roles.""" + region: str + r"""Region where the MSK cluster is located""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -5096,8 +5392,6 @@ class OutputResponseOutputConfluentCloudTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" ack: NotRequired[AcknowledgmentsOptionsAllLeader] r"""Control the number of required acknowledgments.""" format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] @@ -5130,12 +5424,32 @@ class OutputResponseOutputConfluentCloudTypedDict(TypedDict): r"""Maximum time to wait for Kafka to respond to an authentication request""" reauthentication_threshold: NotRequired[float] r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access MSK""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" protobuf_library_id: NotRequired[str] r"""Select a set of Protobuf definitions for the events you want to send""" protobuf_encoding_id: NotRequired[str] @@ -5162,36 +5476,55 @@ class OutputResponseOutputConfluentCloudTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputConfluentCloudPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputMskPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" template_topic: NotRequired[str] r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" template_format: NotRequired[str] r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_compression: NotRequired[str] r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputConfluentCloud(BaseModel): - type: TypeOptionsConfluentcloud +class OutputResponseOutputMsk(BaseModel): + type: TypeOptionsMsk r"""Connector type identifier.""" brokers: List[str] - r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" + aws_authentication_method: Annotated[ + AuthenticationMethodOptionsS3CollectorConf, + pydantic.Field(alias="awsAuthenticationMethod"), + ] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + region: str + r"""Region where the MSK cluster is located""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -5209,9 +5542,6 @@ class OutputResponseOutputConfluentCloud(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - ack: Optional[AcknowledgmentsOptionsAllLeader] = None r"""Control the number of required acknowledgments.""" @@ -5278,8 +5608,46 @@ class OutputResponseOutputConfluentCloud(BaseModel): ] = None r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: Optional[AuthenticationType] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" + + endpoint: Optional[str] = None + r"""MSK cluster service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to MSK cluster-compatible endpoint.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") + ] = None + r"""Use Assume Role credentials to access MSK""" + + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" + + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") + ] = None + r"""External ID to use when assuming role""" + + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") + ] = None + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -5289,6 +5657,12 @@ class OutputResponseOutputConfluentCloud(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + protobuf_library_id: Annotated[ Optional[str], pydantic.Field(alias="protobufLibraryId") ] = None @@ -5349,8 +5723,7 @@ class OutputResponseOutputConfluentCloud(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputConfluentCloudPqControls], - pydantic.Field(alias="pqControls"), + Optional[OutputResponseOutputMskPqControls], pydantic.Field(alias="pqControls") ] = None r"""Persistent queue controls.""" @@ -5359,11 +5732,6 @@ class OutputResponseOutputConfluentCloud(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") - ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topic: Annotated[ Optional[str], pydantic.Field(alias="__template_topic") ] = None @@ -5379,12 +5747,42 @@ class OutputResponseOutputConfluentCloud(BaseModel): ] = None r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -5417,6 +5815,15 @@ def serialize_compression(self, value): return value return value + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsS3CollectorConf(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -5462,7 +5869,6 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "tls", "ack", "format", "compression", @@ -5478,9 +5884,19 @@ def serialize_model(self, handler): "backoffRate", "authenticationTimeout", "reauthenticationThreshold", - "sasl", + "awsSecretKey", + "endpoint", + "reuseConnections", + "rejectUnauthorized", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "tls", "onBackpressure", "description", + "awsApiKey", + "awsSecret", "protobufLibraryId", "protobufEncodingId", "pqStrictOrdering", @@ -5496,11 +5912,16 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_brokers", "__template_topic", "__template_format", "__template_compression", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", + "__template_awsApiKey", "notifications", "status", ] @@ -5519,19 +5940,19 @@ def serialize_model(self, handler): return m -class OutputResponseOutputKafkaPqControlsTypedDict(TypedDict): +class OutputResponseOutputConfluentCloudPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputKafkaPqControls(BaseModel): +class OutputResponseOutputConfluentCloudPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputKafkaTypedDict(TypedDict): - type: TypeOptions +class OutputResponseOutputConfluentCloudTypedDict(TypedDict): + type: TypeOptionsConfluentcloud r"""Connector type identifier.""" brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" id: NotRequired[str] @@ -5544,6 +5965,8 @@ class OutputResponseOutputKafkaTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" ack: NotRequired[AcknowledgmentsOptionsAllLeader] r"""Control the number of required acknowledgments.""" format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] @@ -5578,8 +6001,6 @@ class OutputResponseOutputKafkaTypedDict(TypedDict): r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" sasl: NotRequired[AuthenticationTypeTypedDict] r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] @@ -5610,10 +6031,12 @@ class OutputResponseOutputKafkaTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputKafkaPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputConfluentCloudPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" template_topic: NotRequired[str] r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" template_format: NotRequired[str] @@ -5622,18 +6045,18 @@ class OutputResponseOutputKafkaTypedDict(TypedDict): r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputKafka(BaseModel): - type: TypeOptions +class OutputResponseOutputConfluentCloud(BaseModel): + type: TypeOptionsConfluentcloud r"""Connector type identifier.""" brokers: List[str] - r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" + r"""List of Confluent Cloud bootstrap servers to use, such as yourAccount.confluent.cloud:9092.""" topic: str r"""The topic to publish events to. Can be overridden using the __topicOut field.""" @@ -5655,8 +6078,11 @@ class OutputResponseOutputKafka(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - ack: Optional[AcknowledgmentsOptionsAllLeader] = None - r"""Control the number of required acknowledgments.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + ack: Optional[AcknowledgmentsOptionsAllLeader] = None + r"""Control the number of required acknowledgments.""" format_: Annotated[ Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") @@ -5724,9 +6150,6 @@ class OutputResponseOutputKafka(BaseModel): sasl: Optional[AuthenticationType] = None r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" - on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None @@ -5795,7 +6218,7 @@ class OutputResponseOutputKafka(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputKafkaPqControls], + Optional[OutputResponseOutputConfluentCloudPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -5805,6 +6228,11 @@ class OutputResponseOutputKafka(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") + ] = None + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topic: Annotated[ Optional[str], pydantic.Field(alias="__template_topic") ] = None @@ -5825,7 +6253,7 @@ class OutputResponseOutputKafka(BaseModel): ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -5903,6 +6331,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "tls", "ack", "format", "compression", @@ -5919,7 +6348,6 @@ def serialize_model(self, handler): "authenticationTimeout", "reauthenticationThreshold", "sasl", - "tls", "onBackpressure", "description", "protobufLibraryId", @@ -5937,6 +6365,7 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", + "__template_brokers", "__template_topic", "__template_format", "__template_compression", @@ -5959,27 +6388,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputExabeamType(str, Enum): - r"""Connector type identifier.""" +class OutputResponseOutputKafkaPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - EXABEAM = "exabeam" +class OutputResponseOutputKafkaPqControls(BaseModel): + r"""Persistent queue controls.""" -class OutputResponseOutputExabeamTypedDict(TypedDict): - type: OutputResponseOutputExabeamType - r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" - region: str - r"""Region where the bucket is located""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - endpoint: str - r"""Google Cloud Storage service endpoint""" - collector_instance_id: str - r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 - """ +class OutputResponseOutputKafkaTypedDict(TypedDict): + type: TypeOptions + r"""Connector type identifier.""" + brokers: List[str] + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -5990,95 +6413,99 @@ class OutputResponseOutputExabeamTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsArchiveColdline] - r"""Storage class to select for uploaded objects""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] + ack: NotRequired[AcknowledgmentsOptionsAllLeader] + r"""Control the number of required acknowledgments.""" + format_: NotRequired[RecordDataFormatOptionsJSONProtobuf] + r"""Format to use to serialize events before writing to Kafka.""" + compression: NotRequired[CompressionOptionsGzipLz4] + r"""Codec to use to compress the data before sending to Kafka""" + max_record_size_kb: NotRequired[float] + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" + flush_event_count: NotRequired[float] + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" + flush_period_sec: NotRequired[float] + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" + kafka_schema_registry: NotRequired[ + KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuthTypedDict + ] + r"""Kafka Schema Registry Authentication""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - encoded_configuration: NotRequired[str] - r"""Enter an encoded string containing Exabeam configurations""" - site_name: NotRequired[str] - r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" - site_id: NotRequired[str] - r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" - timezone_offset: NotRequired[str] - r"""Timezone offset""" - aws_api_key: NotRequired[str] - r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - aws_secret_key: NotRequired[str] - r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" description: NotRequired[str] r"""Optional description for this configuration.""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + protobuf_library_id: NotRequired[str] + r"""Select a set of Protobuf definitions for the events you want to send""" + protobuf_encoding_id: NotRequired[str] + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputKafkaPqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_compression: NotRequired[str] + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputExabeam(BaseModel): - type: OutputResponseOutputExabeamType +class OutputResponseOutputKafka(BaseModel): + type: TypeOptions r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" - - region: str - r"""Region where the bucket is located""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - - endpoint: str - r"""Google Cloud Storage service endpoint""" - - collector_instance_id: Annotated[str, pydantic.Field(alias="collectorInstanceId")] - r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + brokers: List[str] + r"""Enter each Kafka bootstrap server you want to use. Specify hostname and port, e.g., mykafkabroker:9092, or just hostname, in which case @{product} will assign port 9092.""" - """ + topic: str + r"""The topic to publish events to. Can be overridden using the __topicOut field.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -6097,181 +6524,205 @@ class OutputResponseOutputExabeam(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - object_acl: Annotated[ - Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], - pydantic.Field(alias="objectACL"), - ] = None - r"""Object ACL to assign to uploaded objects""" + ack: Optional[AcknowledgmentsOptionsAllLeader] = None + r"""Control the number of required acknowledgments.""" - storage_class: Annotated[ - Optional[StorageClassOptionsArchiveColdline], - pydantic.Field(alias="storageClass"), + format_: Annotated[ + Optional[RecordDataFormatOptionsJSONProtobuf], pydantic.Field(alias="format") ] = None - r"""Storage class to select for uploaded objects""" + r"""Format to use to serialize events before writing to Kafka.""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + compression: Optional[CompressionOptionsGzipLz4] = None + r"""Codec to use to compress the data before sending to Kafka""" + + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum size of each record batch before compression. The value must not exceed the Kafka brokers' message.max.bytes setting.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""The maximum number of events you want the Destination to allow in a batch before forcing a flush""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Add the Output ID value to staging location""" + r"""The maximum amount of time you want the Destination to wait before forcing a flush. Shorter intervals tend to result in smaller batches being sent.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + kafka_schema_registry: Annotated[ + Optional[KafkaSchemaRegistryAuthenticationTypeTemplateschemaRegistryURLAuth], + pydantic.Field(alias="kafkaSchemaRegistry"), ] = None - r"""Remove empty staging directories after moving files""" + r"""Kafka Schema Registry Authentication""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Maximum time to wait for a connection to complete successfully""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + r"""Maximum time to wait for Kafka to respond to a request""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""Maximum time to wait for Kafka to respond to an authentication request""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + sasl: Optional[AuthenticationType] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None + r"""How to handle events when all receivers are exerting backpressure""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + protobuf_library_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufLibraryId") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Select a set of Protobuf definitions for the events you want to send""" - encoded_configuration: Annotated[ - Optional[str], pydantic.Field(alias="encodedConfiguration") + protobuf_encoding_id: Annotated[ + Optional[str], pydantic.Field(alias="protobufEncodingId") ] = None - r"""Enter an encoded string containing Exabeam configurations""" + r"""Select the type of object you want the Protobuf definitions to use for event encoding""" - site_name: Annotated[Optional[str], pydantic.Field(alias="siteName")] = None - r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - site_id: Annotated[Optional[str], pydantic.Field(alias="siteId")] = None - r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - timezone_offset: Annotated[ - Optional[str], pydantic.Field(alias="timezoneOffset") + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Timezone offset""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Codec to use to compress the persisted data""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + pq_controls: Annotated[ + Optional[OutputResponseOutputKafkaPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + template_compression: Annotated[ + Optional[str], pydantic.Field(alias="__template_compression") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Binds 'compression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compression' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( - value - ) + return models.AcknowledgmentsOptionsAllLeader(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.StorageClassOptionsArchiveColdline(value) + return models.RecordDataFormatOptionsJSONProtobuf(value) + except ValueError: + return value + return value + + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsGzipLz4(value) except ValueError: return value return value @@ -6280,16 +6731,34 @@ def serialize_storage_class(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -6303,37 +6772,43 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "objectACL", - "storageClass", - "reuseConnections", - "rejectUnauthorized", - "addIdToStagePath", - "removeEmptyDirs", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", + "ack", + "format", + "compression", + "maxRecordSizeKB", + "flushEventCount", + "flushPeriodSec", + "kafkaSchemaRegistry", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "retrySettings", - "orphans", - "maxFileSizeMB", - "encodedConfiguration", - "siteName", - "siteId", - "timezoneOffset", - "awsApiKey", - "awsSecretKey", "description", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", + "protobufLibraryId", + "protobufEncodingId", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_region", - "__template_endpoint", - "__template_objectACL", - "__template_storageClass", + "__template_topic", + "__template_format", + "__template_compression", "__template_onBackpressure", "notifications", "status", @@ -6353,19 +6828,38 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGooglePubsubPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseOutputExabeamType(str, Enum): + r"""Connector type identifier.""" + EXABEAM = "exabeam" -class OutputResponseOutputGooglePubsubPqControls(BaseModel): - r"""Persistent queue controls.""" +class OutputResponseOutputExabeamAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Authentication method""" + + # Manual + MANUAL = "manual" + # Secret + SECRET = "secret" -class OutputResponseOutputGooglePubsubTypedDict(TypedDict): - type: TypeOptionsGooglepubsub + +class OutputResponseOutputExabeamTypedDict(TypedDict): + type: OutputResponseOutputExabeamType r"""Connector type identifier.""" - topic_name: str - r"""ID of the topic to send events to.""" + bucket: str + r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" + region: str + r"""Region where the bucket is located""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + endpoint: str + r"""Google Cloud Storage service endpoint""" + collector_instance_id: str + r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + + """ id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -6376,78 +6870,109 @@ class OutputResponseOutputGooglePubsubTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - create_topic: NotRequired[bool] - r"""If enabled, create topic if it does not exist.""" - ordered_delivery: NotRequired[bool] - r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" - region: NotRequired[str] - r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - batch_size: NotRequired[float] - r"""The maximum number of items the Google API should batch before it sends them to the topic.""" - batch_timeout: NotRequired[float] - r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking.""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of batches to send.""" - flush_period: NotRequired[float] - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsArchiveColdline] + r"""Storage class to select for uploaded objects""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + encoded_configuration: NotRequired[str] + r"""Enter an encoded string containing Exabeam configurations""" + aws_authentication_method: NotRequired[ + OutputResponseOutputExabeamAuthenticationMethod + ] + r"""Authentication method""" + site_name: NotRequired[str] + r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" + site_id: NotRequired[str] + r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" + timezone_offset: NotRequired[str] + r"""Timezone offset""" + hostname: NotRequired[str] + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" + forwarder: NotRequired[str] + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" + origin: NotRequired[str] + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" + logtags: NotRequired[str] + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" + aws_api_key: NotRequired[str] + r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + aws_secret_key: NotRequired[str] + r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" description: NotRequired[str] r"""Optional description for this configuration.""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputGooglePubsubPqControlsTypedDict] - r"""Persistent queue controls.""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: NotRequired[str] - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGooglePubsub(BaseModel): - type: TypeOptionsGooglepubsub +class OutputResponseOutputExabeam(BaseModel): + type: OutputResponseOutputExabeamType r"""Connector type identifier.""" - topic_name: Annotated[str, pydantic.Field(alias="topicName")] - r"""ID of the topic to send events to.""" + bucket: str + r"""Name of the destination bucket. A constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a JavaScript Global Variable: `myBucket-${C.vars.myVar}`.""" + + region: str + r"""Region where the bucket is located""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + + endpoint: str + r"""Google Cloud Storage service endpoint""" + + collector_instance_id: Annotated[str, pydantic.Field(alias="collectorInstanceId")] + r"""ID of the Exabeam Collector where data should be sent. Example: 11112222-3333-4444-5555-666677778888 + + """ id: Optional[str] = None r"""Unique ID for this output""" @@ -6466,187 +6991,229 @@ class OutputResponseOutputGooglePubsub(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None - r"""If enabled, create topic if it does not exist.""" + object_acl: Annotated[ + Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], + pydantic.Field(alias="objectACL"), + ] = None + r"""Object ACL to assign to uploaded objects""" - ordered_delivery: Annotated[ - Optional[bool], pydantic.Field(alias="orderedDelivery") + storage_class: Annotated[ + Optional[StorageClassOptionsArchiveColdline], + pydantic.Field(alias="storageClass"), ] = None - r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" + r"""Storage class to select for uploaded objects""" - region: Optional[str] = None - r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" - google_auth_method: Annotated[ - Optional[GoogleAuthenticationMethodOptions], - pydantic.Field(alias="googleAuthMethod"), + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""Add the Output ID value to staging location""" - secret: Optional[str] = None - r"""Select or create a stored text secret""" + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" - batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None - r"""The maximum number of items the Google API should batch before it sends them to the topic.""" + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - batch_timeout: Annotated[Optional[float], pydantic.Field(alias="batchTimeout")] = ( - None - ) - r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( None ) - r"""Maximum number of queued batches before blocking.""" - - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") - ] = None - r"""Maximum size (KB) of batches to send.""" - - flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") - ] = None - r"""The maximum number of in-progress API requests before backpressure is applied.""" + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + encoded_configuration: Annotated[ + Optional[str], pydantic.Field(alias="encodedConfiguration") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Enter an encoded string containing Exabeam configurations""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + aws_authentication_method: Annotated[ + Optional[OutputResponseOutputExabeamAuthenticationMethod], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Authentication method""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + site_name: Annotated[Optional[str], pydantic.Field(alias="siteName")] = None + r"""Constant or JavaScript expression to create an Exabeam site name. Values that aren't successfully evaluated will be treated as string constants.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + site_id: Annotated[Optional[str], pydantic.Field(alias="siteId")] = None + r"""Exabeam site ID. If left blank, @{product} will use the value of the Exabeam site name.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + timezone_offset: Annotated[ + Optional[str], pydantic.Field(alias="timezoneOffset") ] = None - r"""Codec to use to compress the persisted data""" + r"""Timezone offset""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + hostname: Optional[str] = None + r"""JavaScript expression for the host from which the log was ingested into the SIEM, evaluated per event. Static values must be quoted or backticked (for example, 'collector-1.example.com'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${host}`. Emitted as the \"hostname\" metadata field; omitted when empty or not a usable scalar.""" + + forwarder: Optional[str] = None + r"""JavaScript expression for the host that forwarded the log, evaluated per event. Static values must be quoted or backticked (for example, 'fwd-1'); unquoted text is evaluated as JavaScript, not as a literal. To reference an event field use an expression, such as `${__forwarder}`. Emitted as the \"forwarder\" metadata field; omitted when empty or not a usable scalar.""" + + origin: Optional[str] = None + r"""JavaScript expression that must resolve to an object describing the interim agent collector, such as {hostname: origin_host, '@timestamp': _time, path: source}. Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"origin\" metadata field; omitted when the result is not a non-empty object.""" + + logtags: Optional[str] = None + r"""JavaScript expression that must resolve to an object of custom metadata key/value pairs (searchable in Exabeam as m_c_logtags_). Assemble the object upstream and reference it here (example: __exabeam_logtags), or build it inline (example: {department: dept, servertype: stype}). Evaluated per event. Unquoted text is evaluated as JavaScript, not as a literal. Emitted as the \"logtags\" metadata field; omitted when the result is not a non-empty object.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""HMAC access key. Can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""HMAC secret. Can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - pq_controls: Annotated[ - Optional[OutputResponseOutputGooglePubsubPqControls], - pydantic.Field(alias="pqControls"), + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""Persistent queue controls.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_topic_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_topicName") - ] = None - r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" - template_region: Annotated[ Optional[str], pydantic.Field(alias="__template_region") ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") + ] = None + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.GoogleAuthenticationMethodOptions(value) + return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( + value + ) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.StorageClassOptionsArchiveColdline(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.OutputResponseOutputExabeamAuthenticationMethod(value) except ValueError: return value return value @@ -6660,35 +7227,43 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "createTopic", - "orderedDelivery", - "region", - "googleAuthMethod", - "serviceAccountCredentials", - "secret", - "batchSize", - "batchTimeout", - "maxQueueSize", - "maxRecordSizeKB", - "flushPeriod", - "maxInProgress", + "objectACL", + "storageClass", + "reuseConnections", + "rejectUnauthorized", + "addIdToStagePath", + "removeEmptyDirs", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "retrySettings", + "orphans", + "maxFileSizeMB", + "encodedConfiguration", + "awsAuthenticationMethod", + "siteName", + "siteId", + "timezoneOffset", + "hostname", + "forwarder", + "origin", + "logtags", + "awsApiKey", + "awsSecretKey", "description", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", + "awsSecret", "__template_streamtags", - "__template_topicName", "__template_region", + "__template_endpoint", + "__template_objectACL", + "__template_storageClass", "__template_onBackpressure", "notifications", "status", @@ -6708,62 +7283,19 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGoogleCloudObservabilityType(str, Enum): - r"""Connector type identifier.""" - - GOOGLE_CLOUD_OBSERVABILITY = "google_cloud_observability" - - -class OutputResponseOutputGoogleCloudObservabilityProtocol( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Discriminator value.""" - - GRPC = "grpc" - - -class OutputResponseOutputGoogleCloudObservabilityOtlpVersion( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Discriminator value.""" - - ONE_DOT_3_DOT_1 = "1.3.1" - - -class OutputResponseOutputGoogleCloudObservabilityEndpoint( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - - TELEMETRY_GOOGLEAPIS_COM_443 = "telemetry.googleapis.com:443" - - -class OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" - - # Auto - AUTO = "auto" - # Secret - SECRET = "secret" - - -class OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict(TypedDict): +class OutputResponseOutputGooglePubsubPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputGoogleCloudObservabilityPqControls(BaseModel): +class OutputResponseOutputGooglePubsubPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputGoogleCloudObservabilityTypedDict(TypedDict): - type: OutputResponseOutputGoogleCloudObservabilityType +class OutputResponseOutputGooglePubsubTypedDict(TypedDict): + type: TypeOptionsGooglepubsub r"""Connector type identifier.""" - google_auth_method: ( - OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod - ) - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + topic_name: str + r"""ID of the topic to send events to.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -6774,46 +7306,34 @@ class OutputResponseOutputGoogleCloudObservabilityTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[OutputResponseOutputGoogleCloudObservabilityProtocol] - r"""Discriminator value.""" - otlp_version: NotRequired[OutputResponseOutputGoogleCloudObservabilityOtlpVersion] - r"""Discriminator value.""" - endpoint: NotRequired[OutputResponseOutputGoogleCloudObservabilityEndpoint] - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - preserve_native_any_value: NotRequired[bool] - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - dynamic_headers_enabled: NotRequired[bool] - r"""Batch event data upon dynamic metadata (whether presented or not)""" - dynamic_headers_field: NotRequired[str] - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - keep_alive_time: NotRequired[float] - r"""How often the sender should ping the peer to keep the connection open""" - tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] - r"""TLS settings (client side)""" - max_payload_events: NotRequired[float] - r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" + create_topic: NotRequired[bool] + r"""If enabled, create topic if it does not exist.""" + ordered_delivery: NotRequired[bool] + r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" + region: NotRequired[str] + r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" + google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + batch_size: NotRequired[float] + r"""The maximum number of items the Google API should batch before it sends them to the topic.""" + batch_timeout: NotRequired[float] + r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of batches to send.""" + flush_period: NotRequired[float] + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] r"""Optional description for this configuration.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -6836,31 +7356,28 @@ class OutputResponseOutputGoogleCloudObservabilityTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[ - OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict - ] + pq_controls: NotRequired[OutputResponseOutputGooglePubsubPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_topic_name: NotRequired[str] + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGoogleCloudObservability(BaseModel): - type: OutputResponseOutputGoogleCloudObservabilityType +class OutputResponseOutputGooglePubsub(BaseModel): + type: TypeOptionsGooglepubsub r"""Connector type identifier.""" - google_auth_method: Annotated[ - OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod, - pydantic.Field(alias="googleAuthMethod"), - ] - r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + topic_name: Annotated[str, pydantic.Field(alias="topicName")] + r"""ID of the topic to send events to.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -6879,80 +7396,56 @@ class OutputResponseOutputGoogleCloudObservability(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[OutputResponseOutputGoogleCloudObservabilityProtocol] = None - r"""Discriminator value.""" - - otlp_version: Annotated[ - Optional[OutputResponseOutputGoogleCloudObservabilityOtlpVersion], - pydantic.Field(alias="otlpVersion"), - ] = None - r"""Discriminator value.""" - - endpoint: Optional[OutputResponseOutputGoogleCloudObservabilityEndpoint] = None - r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + create_topic: Annotated[Optional[bool], pydantic.Field(alias="createTopic")] = None + r"""If enabled, create topic if it does not exist.""" - preserve_native_any_value: Annotated[ - Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ordered_delivery: Annotated[ + Optional[bool], pydantic.Field(alias="orderedDelivery") ] = None - r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - - metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None - r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + r"""If enabled, send events in the order they were added to the queue. For this to work correctly, the process receiving events must have ordering enabled.""" - dynamic_headers_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") - ] = None - r"""Batch event data upon dynamic metadata (whether presented or not)""" + region: Optional[str] = None + r"""Region to publish messages to. Select 'default' to allow Google to auto-select the nearest region. When using ordered delivery, the selected region must be allowed by message storage policy.""" - dynamic_headers_field: Annotated[ - Optional[str], pydantic.Field(alias="dynamicHeadersField") + google_auth_method: Annotated[ + Optional[GoogleAuthenticationMethodOptions], + pydantic.Field(alias="googleAuthMethod"), ] = None - r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") ] = None - r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + batch_size: Annotated[Optional[float], pydantic.Field(alias="batchSize")] = None + r"""The maximum number of items the Google API should batch before it sends them to the topic.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + batch_timeout: Annotated[Optional[float], pydantic.Field(alias="batchTimeout")] = ( + None + ) + r"""The maximum amount of time, in milliseconds, that the Google API should wait to send a batch (if the Batch size is not reached).""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") - ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking.""" - keep_alive_time: Annotated[ - Optional[float], pydantic.Field(alias="keepAliveTime") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""How often the sender should ping the peer to keep the connection open""" + r"""Maximum size (KB) of batches to send.""" - tls: Optional[TLSSettingsClientSideTypeExtended] = None - r"""TLS settings (client side)""" + flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") ] = None - r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" + r"""The maximum number of in-progress API requests before backpressure is applied.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -6962,9 +7455,6 @@ class OutputResponseOutputGoogleCloudObservability(BaseModel): description: Optional[str] = None r"""Optional description for this configuration.""" - secret: Optional[str] = None - r"""Select or create a stored text secret""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -7015,7 +7505,7 @@ class OutputResponseOutputGoogleCloudObservability(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputGoogleCloudObservabilityPqControls], + Optional[OutputResponseOutputGooglePubsubPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -7025,71 +7515,32 @@ class OutputResponseOutputGoogleCloudObservability(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_topic_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_topicName") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'topicName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topicName' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputGoogleCloudObservabilityProtocol( - value - ) - except ValueError: - return value - return value - - @field_serializer("otlp_version") - def serialize_otlp_version(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputGoogleCloudObservabilityOtlpVersion( - value - ) - except ValueError: - return value - return value - - @field_serializer("endpoint") - def serialize_endpoint(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputGoogleCloudObservabilityEndpoint( - value - ) - except ValueError: - return value - return value - @field_serializer("google_auth_method") def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) + return models.GoogleAuthenticationMethodOptions(value) except ValueError: return value return value @@ -7139,26 +7590,20 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "otlpVersion", - "endpoint", - "preserveNativeAnyValue", - "metadata", - "dynamicHeadersEnabled", - "dynamicHeadersField", - "concurrency", - "maxPayloadSizeKB", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "failedRequestLoggingMode", - "connectionTimeout", - "keepAliveTime", - "tls", - "maxPayloadEvents", + "createTopic", + "orderedDelivery", + "region", + "googleAuthMethod", + "serviceAccountCredentials", + "secret", + "batchSize", + "batchTimeout", + "maxQueueSize", + "maxRecordSizeKB", + "flushPeriod", + "maxInProgress", "onBackpressure", "description", - "secret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -7172,7 +7617,8 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_topicName", + "__template_region", "__template_onBackpressure", "notifications", "status", @@ -7192,51 +7638,62 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGoogleCloudLoggingType(str, Enum): +class OutputResponseOutputGoogleCloudObservabilityType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CLOUD_LOGGING = "google_cloud_logging" + GOOGLE_CLOUD_OBSERVABILITY = "google_cloud_observability" -class OutputResponseLogLocationType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Log location type""" +class OutputResponseOutputGoogleCloudObservabilityProtocol( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Discriminator value.""" - # Project - PROJECT = "project" - # Organization - ORGANIZATION = "organization" - # Billing Account - BILLING_ACCOUNT = "billingAccount" - # Folder - FOLDER = "folder" + GRPC = "grpc" -class OutputResponsePayloadFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Format to use when sending payload. Defaults to Text.""" +class OutputResponseOutputGoogleCloudObservabilityOtlpVersion( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Discriminator value.""" - # Text - TEXT = "text" - # JSON - JSON = "json" + ONE_DOT_3_DOT_1 = "1.3.1" -class OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict(TypedDict): +class OutputResponseOutputGoogleCloudObservabilityEndpoint( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + + TELEMETRY_GOOGLEAPIS_COM_443 = "telemetry.googleapis.com:443" + + +class OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" + + # Auto + AUTO = "auto" + # Secret + SECRET = "secret" + + +class OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputGoogleCloudLoggingPqControls(BaseModel): +class OutputResponseOutputGoogleCloudObservabilityPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputGoogleCloudLoggingTypedDict(TypedDict): - type: OutputResponseOutputGoogleCloudLoggingType +class OutputResponseOutputGoogleCloudObservabilityTypedDict(TypedDict): + type: OutputResponseOutputGoogleCloudObservabilityType r"""Connector type identifier.""" - log_location_type: OutputResponseLogLocationType - r"""Log location type""" - log_name_expression: str - r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" - log_location_expression: str - r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + google_auth_method: ( + OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod + ) + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -7247,106 +7704,46 @@ class OutputResponseOutputGoogleCloudLoggingTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - sanitize_log_names: NotRequired[bool] - r"""Validate and correct log name""" - payload_format: NotRequired[OutputResponsePayloadFormat] - r"""Format to use when sending payload. Defaults to Text.""" - log_labels: NotRequired[List[LogLabelConfOutputGoogleCloudLoggingTypedDict]] - r"""Labels to apply to the log entry""" - resource_type_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - resource_type_labels: NotRequired[ - List[LogLabelConfOutputGoogleCloudLoggingTypedDict] - ] - r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" - severity_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" - insert_id_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the insert ID field.""" - google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" + protocol: NotRequired[OutputResponseOutputGoogleCloudObservabilityProtocol] + r"""Discriminator value.""" + otlp_version: NotRequired[OutputResponseOutputGoogleCloudObservabilityOtlpVersion] + r"""Discriminator value.""" + endpoint: NotRequired[OutputResponseOutputGoogleCloudObservabilityEndpoint] + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body.""" - max_payload_events: NotRequired[float] - r"""Max number of events to include in the request body. Default is 0 (unlimited).""" + r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" connection_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" - throttle_rate_req_per_sec: NotRequired[int] - r"""Maximum number of requests to limit to per second.""" - request_method_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - request_url_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - request_size_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - status_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - response_size_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - user_agent_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - remote_ip_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - server_ip_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - referer_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - latency_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_lookup_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_hit_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_validated_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - cache_fill_bytes_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - protocol_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - id_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - producer_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - first_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - last_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - file_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - line_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - function_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - uid_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - index_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - total_splits_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - trace_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - span_id_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - trace_sampled_expression: NotRequired[str] - r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" + max_payload_events: NotRequired[float] + r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - payload_expression: NotRequired[str] - r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -7369,56 +7766,31 @@ class OutputResponseOutputGoogleCloudLoggingTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict] + pq_controls: NotRequired[ + OutputResponseOutputGoogleCloudObservabilityPqControlsTypedDict + ] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_location_type: NotRequired[str] - r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" - template_log_name_expression: NotRequired[str] - r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" - template_payload_format: NotRequired[str] - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" - template_resource_type_expression: NotRequired[str] - r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" - template_severity_expression: NotRequired[str] - r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" - template_insert_id_expression: NotRequired[str] - r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" - template_trace_expression: NotRequired[str] - r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" - template_span_id_expression: NotRequired[str] - r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" - template_trace_sampled_expression: NotRequired[str] - r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_log_location_expression: NotRequired[str] - r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - template_payload_expression: NotRequired[str] - r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGoogleCloudLogging(BaseModel): - type: OutputResponseOutputGoogleCloudLoggingType +class OutputResponseOutputGoogleCloudObservability(BaseModel): + type: OutputResponseOutputGoogleCloudObservabilityType r"""Connector type identifier.""" - log_location_type: Annotated[ - OutputResponseLogLocationType, pydantic.Field(alias="logLocationType") - ] - r"""Log location type""" - - log_name_expression: Annotated[str, pydantic.Field(alias="logNameExpression")] - r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" - - log_location_expression: Annotated[ - str, pydantic.Field(alias="logLocationExpression") + google_auth_method: Annotated[ + OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod, + pydantic.Field(alias="googleAuthMethod"), ] - r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + r"""Choose Auto to use Google Application Default Credentials (ADC). Choose Secret to select or create a stored secret that references Google service account credentials.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -7437,243 +7809,91 @@ class OutputResponseOutputGoogleCloudLogging(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - sanitize_log_names: Annotated[ - Optional[bool], pydantic.Field(alias="sanitizeLogNames") - ] = None - r"""Validate and correct log name""" + protocol: Optional[OutputResponseOutputGoogleCloudObservabilityProtocol] = None + r"""Discriminator value.""" - payload_format: Annotated[ - Optional[OutputResponsePayloadFormat], pydantic.Field(alias="payloadFormat") + otlp_version: Annotated[ + Optional[OutputResponseOutputGoogleCloudObservabilityOtlpVersion], + pydantic.Field(alias="otlpVersion"), ] = None - r"""Format to use when sending payload. Defaults to Text.""" + r"""Discriminator value.""" - log_labels: Annotated[ - Optional[List[LogLabelConfOutputGoogleCloudLogging]], - pydantic.Field(alias="logLabels"), - ] = None - r"""Labels to apply to the log entry""" + endpoint: Optional[OutputResponseOutputGoogleCloudObservabilityEndpoint] = None + r"""Fixed Google Cloud Observability gRPC endpoint. All three signals share this transport; the OTLP service path determines whether the call lands on traces, metrics, or logs.""" - resource_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="resourceTypeExpression") + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") ] = None - r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - - resource_type_labels: Annotated[ - Optional[List[LogLabelConfOutputGoogleCloudLogging]], - pydantic.Field(alias="resourceTypeLabels"), - ] = None - r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" - - severity_expression: Annotated[ - Optional[str], pydantic.Field(alias="severityExpression") - ] = None - r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" - insert_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="insertIdExpression") - ] = None - r"""JavaScript expression to compute the value of the insert ID field.""" + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" - google_auth_method: Annotated[ - Optional[GoogleAuthenticationMethodOptions], - pydantic.Field(alias="googleAuthMethod"), + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") ] = None - r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + r"""Batch event data upon dynamic metadata (whether presented or not)""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" - secret: Optional[str] = None - r"""Select or create a stored text secret""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body.""" + r"""Maximum size, in KB, of the request body sent to Google Cloud Observability""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Max number of events to include in the request body. Default is 0 (unlimited).""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" connection_timeout: Annotated[ Optional[float], pydantic.Field(alias="connectionTimeout") ] = None r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" - - throttle_rate_req_per_sec: Annotated[ - Optional[int], pydantic.Field(alias="throttleRateReqPerSec") - ] = None - r"""Maximum number of requests to limit to per second.""" - - request_method_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestMethodExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - request_url_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestUrlExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - request_size_expression: Annotated[ - Optional[str], pydantic.Field(alias="requestSizeExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - status_expression: Annotated[ - Optional[str], pydantic.Field(alias="statusExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - response_size_expression: Annotated[ - Optional[str], pydantic.Field(alias="responseSizeExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - user_agent_expression: Annotated[ - Optional[str], pydantic.Field(alias="userAgentExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - remote_ip_expression: Annotated[ - Optional[str], pydantic.Field(alias="remoteIpExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - server_ip_expression: Annotated[ - Optional[str], pydantic.Field(alias="serverIpExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - referer_expression: Annotated[ - Optional[str], pydantic.Field(alias="refererExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - latency_expression: Annotated[ - Optional[str], pydantic.Field(alias="latencyExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - cache_lookup_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheLookupExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - cache_hit_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheHitExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - cache_validated_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheValidatedExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - cache_fill_bytes_expression: Annotated[ - Optional[str], pydantic.Field(alias="cacheFillBytesExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - protocol_expression: Annotated[ - Optional[str], pydantic.Field(alias="protocolExpression") - ] = None - r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - - id_expression: Annotated[Optional[str], pydantic.Field(alias="idExpression")] = None - r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - - producer_expression: Annotated[ - Optional[str], pydantic.Field(alias="producerExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - - first_expression: Annotated[ - Optional[str], pydantic.Field(alias="firstExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - - last_expression: Annotated[ - Optional[str], pydantic.Field(alias="lastExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - - file_expression: Annotated[ - Optional[str], pydantic.Field(alias="fileExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - line_expression: Annotated[ - Optional[str], pydantic.Field(alias="lineExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - function_expression: Annotated[ - Optional[str], pydantic.Field(alias="functionExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - - uid_expression: Annotated[Optional[str], pydantic.Field(alias="uidExpression")] = ( - None - ) - r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - index_expression: Annotated[ - Optional[str], pydantic.Field(alias="indexExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - total_splits_expression: Annotated[ - Optional[str], pydantic.Field(alias="totalSplitsExpression") - ] = None - r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - - trace_expression: Annotated[ - Optional[str], pydantic.Field(alias="traceExpression") + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") ] = None - r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + r"""How often the sender should ping the peer to keep the connection open""" - span_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="spanIdExpression") - ] = None - r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" - trace_sampled_expression: Annotated[ - Optional[str], pydantic.Field(alias="traceSampledExpression") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + r"""Max number of events to include in the request body. Default is 0 (unlimited). Use to keep outgoing data points within GCO request limits. For metrics, combine with the OTLP Metrics function batchSize.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") - ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - description: Optional[str] = None r"""Optional description for this configuration.""" - payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="payloadExpression") - ] = None - r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -7725,7 +7945,7 @@ class OutputResponseOutputGoogleCloudLogging(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputGoogleCloudLoggingPqControls], + Optional[OutputResponseOutputGoogleCloudObservabilityPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -7735,86 +7955,51 @@ class OutputResponseOutputGoogleCloudLogging(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_log_location_type: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLocationType") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_log_name_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_logNameExpression") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_payload_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadFormat") - ] = None - r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" - template_resource_type_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_resourceTypeExpression") - ] = None - r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - template_severity_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_severityExpression") - ] = None - r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputGoogleCloudObservabilityProtocol( + value + ) + except ValueError: + return value + return value - template_insert_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_insertIdExpression") - ] = None - r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" - - template_trace_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_traceExpression") - ] = None - r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" - - template_span_id_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_spanIdExpression") - ] = None - r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" - - template_trace_sampled_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_traceSampledExpression") - ] = None - r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_log_location_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_logLocationExpression") - ] = None - r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - - template_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="__template_payloadExpression") - ] = None - r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("log_location_type") - def serialize_log_location_type(self, value): + @field_serializer("otlp_version") + def serialize_otlp_version(self, value): if isinstance(value, str): try: - return models.OutputResponseLogLocationType(value) + return models.OutputResponseOutputGoogleCloudObservabilityOtlpVersion( + value + ) except ValueError: return value return value - @field_serializer("payload_format") - def serialize_payload_format(self, value): + @field_serializer("endpoint") + def serialize_endpoint(self, value): if isinstance(value, str): try: - return models.OutputResponsePayloadFormat(value) + return models.OutputResponseOutputGoogleCloudObservabilityEndpoint( + value + ) except ValueError: return value return value @@ -7823,7 +8008,18 @@ def serialize_payload_format(self, value): def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.GoogleAuthenticationMethodOptions(value) + return models.OutputResponseOutputGoogleCloudObservabilityGoogleAuthenticationMethod( + value + ) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -7873,55 +8069,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "sanitizeLogNames", - "payloadFormat", - "logLabels", - "resourceTypeExpression", - "resourceTypeLabels", - "severityExpression", - "insertIdExpression", - "googleAuthMethod", - "serviceAccountCredentials", - "secret", + "protocol", + "otlpVersion", + "endpoint", + "preserveNativeAnyValue", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", + "concurrency", "maxPayloadSizeKB", - "maxPayloadEvents", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "concurrency", + "failedRequestLoggingMode", "connectionTimeout", - "timeoutSec", - "throttleRateReqPerSec", - "requestMethodExpression", - "requestUrlExpression", - "requestSizeExpression", - "statusExpression", - "responseSizeExpression", - "userAgentExpression", - "remoteIpExpression", - "serverIpExpression", - "refererExpression", - "latencyExpression", - "cacheLookupExpression", - "cacheHitExpression", - "cacheValidatedExpression", - "cacheFillBytesExpression", - "protocolExpression", - "idExpression", - "producerExpression", - "firstExpression", - "lastExpression", - "fileExpression", - "lineExpression", - "functionExpression", - "uidExpression", - "indexExpression", - "totalSplitsExpression", - "traceExpression", - "spanIdExpression", - "traceSampledExpression", + "keepAliveTime", + "tls", + "maxPayloadEvents", "onBackpressure", - "totalMemoryLimitKB", "description", - "payloadExpression", + "secret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -7935,18 +8102,8 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_logLocationType", - "__template_logNameExpression", - "__template_payloadFormat", - "__template_resourceTypeExpression", - "__template_severityExpression", - "__template_insertIdExpression", - "__template_traceExpression", - "__template_spanIdExpression", - "__template_traceSampledExpression", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_logLocationExpression", - "__template_payloadExpression", "notifications", "status", ] @@ -7965,36 +8122,51 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGoogleCloudStorageType(str, Enum): +class OutputResponseOutputGoogleCloudLoggingType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CLOUD_STORAGE = "google_cloud_storage" + GOOGLE_CLOUD_LOGGING = "google_cloud_logging" -class OutputResponseOutputGoogleCloudStorageAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method""" +class OutputResponseLogLocationType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Log location type""" - # auto - AUTO = "auto" - # manual - MANUAL = "manual" - # Secret Key pair - SECRET = "secret" + # Project + PROJECT = "project" + # Organization + ORGANIZATION = "organization" + # Billing Account + BILLING_ACCOUNT = "billingAccount" + # Folder + FOLDER = "folder" -class OutputResponseOutputGoogleCloudStorageTypedDict(TypedDict): - type: OutputResponseOutputGoogleCloudStorageType +class OutputResponsePayloadFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Format to use when sending payload. Defaults to Text.""" + + # Text + TEXT = "text" + # JSON + JSON = "json" + + +class OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputGoogleCloudLoggingPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputGoogleCloudLoggingTypedDict(TypedDict): + type: OutputResponseOutputGoogleCloudLoggingType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - region: str - r"""Region where the bucket is located""" - endpoint: str - r"""Google Cloud Storage service endpoint""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + log_location_type: OutputResponseLogLocationType + r"""Log location type""" + log_name_expression: str + r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" + log_location_expression: str + r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -8005,152 +8177,178 @@ class OutputResponseOutputGoogleCloudStorageTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[ - OutputResponseOutputGoogleCloudStorageAuthenticationMethod + sanitize_log_names: NotRequired[bool] + r"""Validate and correct log name""" + payload_format: NotRequired[OutputResponsePayloadFormat] + r"""Format to use when sending payload. Defaults to Text.""" + log_labels: NotRequired[List[LogLabelConfOutputGoogleCloudLoggingTypedDict]] + r"""Labels to apply to the log entry""" + resource_type_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" + resource_type_labels: NotRequired[ + List[LogLabelConfOutputGoogleCloudLoggingTypedDict] ] - r"""Authentication method""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptionsArchiveColdline] - r"""Storage class to select for uploaded objects""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" + r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" + severity_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" + insert_id_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the insert ID field.""" + google_auth_method: NotRequired[GoogleAuthenticationMethodOptions] + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body.""" + max_payload_events: NotRequired[float] + r"""Max number of events to include in the request body. Default is 0 (unlimited).""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" + throttle_rate_req_per_sec: NotRequired[int] + r"""Maximum number of requests to limit to per second.""" + request_method_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + request_url_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + request_size_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + status_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + response_size_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + user_agent_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + remote_ip_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + server_ip_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + referer_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + latency_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_lookup_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_hit_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_validated_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + cache_fill_bytes_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + protocol_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" + id_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + producer_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + first_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + last_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + file_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + line_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + function_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" + uid_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + index_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + total_splits_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" + trace_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + span_id_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + trace_sampled_expression: NotRequired[str] + r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - aws_api_key: NotRequired[str] - r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" - aws_secret_key: NotRequired[str] - r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" + payload_expression: NotRequired[str] + r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputGoogleCloudLoggingPqControlsTypedDict] + r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + template_log_location_type: NotRequired[str] + r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" + template_log_name_expression: NotRequired[str] + r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" + template_payload_format: NotRequired[str] + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + template_resource_type_expression: NotRequired[str] + r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" + template_severity_expression: NotRequired[str] + r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" + template_insert_id_expression: NotRequired[str] + r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" + template_trace_expression: NotRequired[str] + r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" + template_span_id_expression: NotRequired[str] + r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" + template_trace_sampled_expression: NotRequired[str] + r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_log_location_expression: NotRequired[str] + r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" + template_payload_expression: NotRequired[str] + r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGoogleCloudStorage(BaseModel): - type: OutputResponseOutputGoogleCloudStorageType +class OutputResponseOutputGoogleCloudLogging(BaseModel): + type: OutputResponseOutputGoogleCloudLoggingType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" - - region: str - r"""Region where the bucket is located""" + log_location_type: Annotated[ + OutputResponseLogLocationType, pydantic.Field(alias="logLocationType") + ] + r"""Log location type""" - endpoint: str - r"""Google Cloud Storage service endpoint""" + log_name_expression: Annotated[str, pydantic.Field(alias="logNameExpression")] + r"""JavaScript expression to compute the value of the log name. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + log_location_expression: Annotated[ + str, pydantic.Field(alias="logLocationExpression") + ] + r"""JavaScript expression to compute the value of the folder ID with which log entries should be associated. If Validate and correct log name is enabled, invalid characters (characters other than alphanumerics, forward-slashes, underscores, hyphens, and periods) will be replaced with an underscore.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -8169,351 +8367,393 @@ class OutputResponseOutputGoogleCloudStorage(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[OutputResponseOutputGoogleCloudStorageAuthenticationMethod], - pydantic.Field(alias="awsAuthenticationMethod"), + sanitize_log_names: Annotated[ + Optional[bool], pydantic.Field(alias="sanitizeLogNames") ] = None - r"""Authentication method""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + r"""Validate and correct log name""" - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") + payload_format: Annotated[ + Optional[OutputResponsePayloadFormat], pydantic.Field(alias="payloadFormat") ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" + r"""Format to use when sending payload. Defaults to Text.""" - object_acl: Annotated[ - Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], - pydantic.Field(alias="objectACL"), + log_labels: Annotated[ + Optional[List[LogLabelConfOutputGoogleCloudLogging]], + pydantic.Field(alias="logLabels"), ] = None - r"""Object ACL to assign to uploaded objects""" + r"""Labels to apply to the log entry""" - storage_class: Annotated[ - Optional[StorageClassOptionsArchiveColdline], - pydantic.Field(alias="storageClass"), + resource_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="resourceTypeExpression") ] = None - r"""Storage class to select for uploaded objects""" + r"""JavaScript expression to compute the value of the managed resource type field. Must evaluate to one of the valid values [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types). Defaults to \"global\".""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + resource_type_labels: Annotated[ + Optional[List[LogLabelConfOutputGoogleCloudLogging]], + pydantic.Field(alias="resourceTypeLabels"), ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Labels to apply to the managed resource. These must correspond to the valid labels for the specified resource type (see [here](https://cloud.google.com/logging/docs/api/v2/resource-list#resource-types)). Otherwise, they will be dropped by Google Cloud Logging.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + severity_expression: Annotated[ + Optional[str], pydantic.Field(alias="severityExpression") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""JavaScript expression to compute the value of the severity field. Must evaluate to one of the severity values supported by Google Cloud Logging [here](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logseverity) (case insensitive). Defaults to \"DEFAULT\".""" - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") + insert_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="insertIdExpression") ] = None - r"""Add the Output ID value to staging location""" + r"""JavaScript expression to compute the value of the insert ID field.""" - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") + google_auth_method: Annotated[ + Optional[GoogleAuthenticationMethodOptions], + pydantic.Field(alias="googleAuthMethod"), ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + r"""Choose Auto to use Google Application Default Credentials (ADC), Manual to enter Google service account credentials directly, or Secret to select or create a stored secret that references Google service account credentials.""" - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + r"""Maximum size, in KB, of the request body.""" - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + r"""Max number of events to include in the request body. Default is 0 (unlimited).""" - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking.""" - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it.""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") + throttle_rate_req_per_sec: Annotated[ + Optional[int], pydantic.Field(alias="throttleRateReqPerSec") ] = None - r"""Buffer size used to write to a file""" + r"""Maximum number of requests to limit to per second.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), + request_method_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestMethodExpression") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""A JavaScript expression that evaluates to the HTTP request method as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") + request_url_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestUrlExpression") ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + r"""A JavaScript expression that evaluates to the HTTP request URL as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), + request_size_expression: Annotated[ + Optional[str], pydantic.Field(alias="requestSizeExpression") ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + r"""A JavaScript expression that evaluates to the HTTP request size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + status_expression: Annotated[ + Optional[str], pydantic.Field(alias="statusExpression") ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + r"""A JavaScript expression that evaluates to the HTTP request method as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + response_size_expression: Annotated[ + Optional[str], pydantic.Field(alias="responseSizeExpression") ] = None + r"""A JavaScript expression that evaluates to the HTTP response size as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + user_agent_expression: Annotated[ + Optional[str], pydantic.Field(alias="userAgentExpression") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""A JavaScript expression that evaluates to the HTTP request user agent as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + remote_ip_expression: Annotated[ + Optional[str], pydantic.Field(alias="remoteIpExpression") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + r"""A JavaScript expression that evaluates to the HTTP request remote IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + server_ip_expression: Annotated[ + Optional[str], pydantic.Field(alias="serverIpExpression") ] = None - r"""Determines which data types are supported and how they are represented""" + r"""A JavaScript expression that evaluates to the HTTP request server IP as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + referer_expression: Annotated[ + Optional[str], pydantic.Field(alias="refererExpression") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""A JavaScript expression that evaluates to the HTTP request referer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") + latency_expression: Annotated[ + Optional[str], pydantic.Field(alias="latencyExpression") ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + r"""A JavaScript expression that evaluates to the HTTP request latency, formatted as .s (for example, 1.23s). See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + cache_lookup_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheLookupExpression") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""A JavaScript expression that evaluates to the HTTP request cache lookup as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + cache_hit_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheHitExpression") ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + r"""A JavaScript expression that evaluates to the HTTP request cache hit as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), + cache_validated_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheValidatedExpression") ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + r"""A JavaScript expression that evaluates to the HTTP request cache validated with origin server as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") + cache_fill_bytes_expression: Annotated[ + Optional[str], pydantic.Field(alias="cacheFillBytesExpression") ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + r"""A JavaScript expression that evaluates to the HTTP request cache fill bytes as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") + protocol_expression: Annotated[ + Optional[str], pydantic.Field(alias="protocolExpression") ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + r"""A JavaScript expression that evaluates to the HTTP request protocol as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#httprequest) for details.""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + id_expression: Annotated[Optional[str], pydantic.Field(alias="idExpression")] = None + r"""A JavaScript expression that evaluates to the log entry operation ID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" + + producer_expression: Annotated[ + Optional[str], pydantic.Field(alias="producerExpression") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""A JavaScript expression that evaluates to the log entry operation producer as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + first_expression: Annotated[ + Optional[str], pydantic.Field(alias="firstExpression") ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""A JavaScript expression that evaluates to the log entry operation first flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") + last_expression: Annotated[ + Optional[str], pydantic.Field(alias="lastExpression") ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + r"""A JavaScript expression that evaluates to the log entry operation last flag as a boolean. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentryoperation) for details.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") + file_expression: Annotated[ + Optional[str], pydantic.Field(alias="fileExpression") ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + r"""A JavaScript expression that evaluates to the log entry source location file as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + line_expression: Annotated[ + Optional[str], pydantic.Field(alias="lineExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location line as a string, in int64 format. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + function_expression: Annotated[ + Optional[str], pydantic.Field(alias="functionExpression") + ] = None + r"""A JavaScript expression that evaluates to the log entry source location function as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logentrysourcelocation) for details.""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + uid_expression: Annotated[Optional[str], pydantic.Field(alias="uidExpression")] = ( None ) - r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + r"""A JavaScript expression that evaluates to the log entry log split UID as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + index_expression: Annotated[ + Optional[str], pydantic.Field(alias="indexExpression") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""A JavaScript expression that evaluates to the log entry log split index as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + total_splits_expression: Annotated[ + Optional[str], pydantic.Field(alias="totalSplitsExpression") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""A JavaScript expression that evaluates to the log entry log split total splits as a number. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry#logsplit) for details.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + trace_expression: Annotated[ + Optional[str], pydantic.Field(alias="traceExpression") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""A JavaScript expression that evaluates to the REST resource name of the trace being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + span_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="spanIdExpression") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""A JavaScript expression that evaluates to the ID of the cloud trace span associated with the current operation in which the log is being written as a string. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") + trace_sampled_expression: Annotated[ + Optional[str], pydantic.Field(alias="traceSampledExpression") ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + r"""A JavaScript expression that evaluates to the the sampling decision of the span associated with the log entry. See the [documentation](https://cloud.google.com/logging/docs/reference/v2/rest/v2/LogEntry) for details.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""How to handle events when all receivers are exerting backpressure""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="payloadExpression") ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + r"""JavaScript expression to compute the value of the payload. Must evaluate to a JavaScript object value. If an invalid value is encountered it will result in the default value instead. Defaults to the entire event.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + r"""Codec to use to compress the persisted data""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[OutputResponseOutputGoogleCloudLoggingPqControls], + pydantic.Field(alias="pqControls"), + ] = None + r"""Persistent queue controls.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_log_location_type: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLocationType") + ] = None + r"""Binds 'logLocationType' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationType' at runtime.""" + + template_log_name_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_logNameExpression") + ] = None + r"""Binds 'logNameExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logNameExpression' at runtime.""" + + template_payload_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadFormat") + ] = None + r"""Binds 'payloadFormat' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadFormat' at runtime.""" + + template_resource_type_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_resourceTypeExpression") + ] = None + r"""Binds 'resourceTypeExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'resourceTypeExpression' at runtime.""" + + template_severity_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_severityExpression") + ] = None + r"""Binds 'severityExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'severityExpression' at runtime.""" + + template_insert_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_insertIdExpression") + ] = None + r"""Binds 'insertIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'insertIdExpression' at runtime.""" + + template_trace_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_traceExpression") + ] = None + r"""Binds 'traceExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceExpression' at runtime.""" + + template_span_id_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_spanIdExpression") + ] = None + r"""Binds 'spanIdExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'spanIdExpression' at runtime.""" + + template_trace_sampled_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_traceSampledExpression") + ] = None + r"""Binds 'traceSampledExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'traceSampledExpression' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_log_location_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_logLocationExpression") + ] = None + r"""Binds 'logLocationExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'logLocationExpression' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_payload_expression: Annotated[ + Optional[str], pydantic.Field(alias="__template_payloadExpression") + ] = None + r"""Binds 'payloadExpression' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'payloadExpression' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): - if isinstance(value, str): - try: - return ( - models.OutputResponseOutputGoogleCloudStorageAuthenticationMethod( - value - ) - ) - except ValueError: - return value - return value - - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("log_location_type") + def serialize_log_location_type(self, value): if isinstance(value, str): try: - return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( - value - ) + return models.OutputResponseLogLocationType(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("payload_format") + def serialize_payload_format(self, value): if isinstance(value, str): try: - return models.StorageClassOptionsArchiveColdline(value) + return models.OutputResponsePayloadFormat(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.DataFormatOptions(value) + return models.GoogleAuthenticationMethodOptions(value) except ValueError: return value return value @@ -8522,52 +8762,34 @@ def serialize_format_(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -8581,68 +8803,80 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "destPath", - "verifyPermissions", - "objectACL", - "storageClass", - "reuseConnections", - "rejectUnauthorized", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", + "sanitizeLogNames", + "payloadFormat", + "logLabels", + "resourceTypeExpression", + "resourceTypeLabels", + "severityExpression", + "insertIdExpression", + "googleAuthMethod", + "serviceAccountCredentials", + "secret", + "maxPayloadSizeKB", + "maxPayloadEvents", + "flushPeriodSec", + "concurrency", + "connectionTimeout", + "timeoutSec", + "throttleRateReqPerSec", + "requestMethodExpression", + "requestUrlExpression", + "requestSizeExpression", + "statusExpression", + "responseSizeExpression", + "userAgentExpression", + "remoteIpExpression", + "serverIpExpression", + "refererExpression", + "latencyExpression", + "cacheLookupExpression", + "cacheHitExpression", + "cacheValidatedExpression", + "cacheFillBytesExpression", + "protocolExpression", + "idExpression", + "producerExpression", + "firstExpression", + "lastExpression", + "fileExpression", + "lineExpression", + "functionExpression", + "uidExpression", + "indexExpression", + "totalSplitsExpression", + "traceExpression", + "spanIdExpression", + "traceSampledExpression", + "onBackpressure", + "totalMemoryLimitKB", "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "awsApiKey", - "awsSecretKey", - "awsSecret", + "payloadExpression", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_bucket", - "__template_region", - "__template_endpoint", - "__template_destPath", - "__template_objectACL", - "__template_storageClass", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", + "__template_logLocationType", + "__template_logNameExpression", + "__template_payloadFormat", + "__template_resourceTypeExpression", + "__template_severityExpression", + "__template_insertIdExpression", + "__template_traceExpression", + "__template_spanIdExpression", + "__template_traceSampledExpression", "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", - "__template_awsApiKey", - "__template_awsSecretKey", + "__template_logLocationExpression", + "__template_payloadExpression", "notifications", "status", ] @@ -8661,96 +8895,36 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGoogleChronicleType(str, Enum): +class OutputResponseOutputGoogleCloudStorageType(str, Enum): r"""Connector type identifier.""" - GOOGLE_CHRONICLE = "google_chronicle" - - -class OutputResponseAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): - r"""API version""" - - # V1 - V1 = "v1" - # V2 - V2 = "v2" + GOOGLE_CLOUD_STORAGE = "google_cloud_storage" -class OutputResponseOutputGoogleChronicleAuthenticationMethod( +class OutputResponseOutputGoogleCloudStorageAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): r"""Authentication method""" - # API key + # auto + AUTO = "auto" + # manual MANUAL = "manual" - # API key secret + # Secret Key pair SECRET = "secret" - # Service account credentials - SERVICE_ACCOUNT = "serviceAccount" - # Service account credentials secret - SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" - - -class OutputResponseSendEventsAs(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Send events as""" - - # Unstructured - UNSTRUCTURED = "unstructured" - # UDM - UDM = "udm" - - -class OutputResponseExtraLogTypeTypedDict(TypedDict): - log_type: str - r"""Log Type""" - description: NotRequired[str] - r"""Description""" - - -class OutputResponseExtraLogType(BaseModel): - log_type: Annotated[str, pydantic.Field(alias="logType")] - r"""Log Type""" - - description: Optional[str] = None - r"""Description""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["description"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseUDMType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" - - ENTITIES = "entities" - LOGS = "logs" - - -class OutputResponseOutputGoogleChroniclePqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputGoogleChroniclePqControls(BaseModel): - r"""Persistent queue controls.""" -class OutputResponseOutputGoogleChronicleTypedDict(TypedDict): - type: OutputResponseOutputGoogleChronicleType +class OutputResponseOutputGoogleCloudStorageTypedDict(TypedDict): + type: OutputResponseOutputGoogleCloudStorageType r"""Connector type identifier.""" - log_format_type: OutputResponseSendEventsAs - r"""Send events as""" + bucket: str + r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" + region: str + r"""Region where the bucket is located""" + endpoint: str + r"""Google Cloud Storage service endpoint""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -8761,126 +8935,152 @@ class OutputResponseOutputGoogleChronicleTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - api_version: NotRequired[OutputResponseAPIVersion] - r"""API version""" - authentication_method: NotRequired[ - OutputResponseOutputGoogleChronicleAuthenticationMethod + aws_authentication_method: NotRequired[ + OutputResponseOutputGoogleCloudStorageAuthenticationMethod ] r"""Authentication method""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - region: NotRequired[str] - r"""Regional endpoint to send events to""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + object_acl: NotRequired[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptionsArchiveColdline] + r"""Storage class to select for uploaded objects""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - extra_log_types: NotRequired[List[OutputResponseExtraLogTypeTypedDict]] - r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" - log_type: NotRequired[str] - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" - log_text_field: NotRequired[str] - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" - customer_id: NotRequired[str] - r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" - namespace: NotRequired[str] - r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" - custom_labels: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""Custom labels to be added to every batch""" - udm_type: NotRequired[OutputResponseUDMType] - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" - api_key: NotRequired[str] - r"""Organization's API key in Google SecOps""" - api_key_secret: NotRequired[str] - r"""Select or create a stored text secret""" - service_account_credentials: NotRequired[str] - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" - service_account_credentials_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputGoogleChroniclePqControlsTypedDict] - r"""Persistent queue controls.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + aws_api_key: NotRequired[str] + r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + aws_secret_key: NotRequired[str] + r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_api_version: NotRequired[str] - r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: NotRequired[str] r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_customer_id: NotRequired[str] - r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGoogleChronicle(BaseModel): - type: OutputResponseOutputGoogleChronicleType +class OutputResponseOutputGoogleCloudStorage(BaseModel): + type: OutputResponseOutputGoogleCloudStorageType r"""Connector type identifier.""" - log_format_type: Annotated[ - OutputResponseSendEventsAs, pydantic.Field(alias="logFormatType") - ] - r"""Send events as""" + bucket: str + r"""Name of the destination bucket. This value can be a constant or a JavaScript expression that can only be evaluated at init time. Example of referencing a Global Variable: `myBucket-${C.vars.myVar}`.""" + + region: str + r"""Region where the bucket is located""" + + endpoint: str + r"""Google Cloud Storage service endpoint""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -8899,281 +9099,351 @@ class OutputResponseOutputGoogleChronicle(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - api_version: Annotated[ - Optional[OutputResponseAPIVersion], pydantic.Field(alias="apiVersion") - ] = None - r"""API version""" - - authentication_method: Annotated[ - Optional[OutputResponseOutputGoogleChronicleAuthenticationMethod], - pydantic.Field(alias="authenticationMethod"), + aws_authentication_method: Annotated[ + Optional[OutputResponseOutputGoogleCloudStorageAuthenticationMethod], + pydantic.Field(alias="awsAuthenticationMethod"), ] = None r"""Authentication method""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None + r"""Disable if you can access files within the bucket but not the bucket itself""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + object_acl: Annotated[ + Optional[ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol], + pydantic.Field(alias="objectACL"), ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - region: Optional[str] = None - r"""Regional endpoint to send events to""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Object ACL to assign to uploaded objects""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + storage_class: Annotated[ + Optional[StorageClassOptionsArchiveColdline], + pydantic.Field(alias="storageClass"), ] = None - r"""Maximum size, in KB, of the request body""" + r"""Storage class to select for uploaded objects""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Add the Output ID value to staging location""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Remove empty staging directories after moving files""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""List of headers that are safe to log in plain text""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None r"""How to handle events when all receivers are exerting backpressure""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - extra_log_types: Annotated[ - Optional[List[OutputResponseExtraLogType]], - pydantic.Field(alias="extraLogTypes"), + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") ] = None - r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None - r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None - log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( - None - ) - r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" - customer_id: Annotated[Optional[str], pydantic.Field(alias="customerId")] = None - r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - namespace: Optional[str] = None - r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" - custom_labels: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="customLabels"), + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") ] = None - r"""Custom labels to be added to every batch""" + r"""Compression level to apply before moving files to final destination""" - udm_type: Annotated[ - Optional[OutputResponseUDMType], pydantic.Field(alias="udmType") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" - - api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None - r"""Organization's API key in Google SecOps""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - api_key_secret: Annotated[Optional[str], pydantic.Field(alias="apiKeySecret")] = ( + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( None ) - r"""Select or create a stored text secret""" + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - service_account_credentials: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentials") + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + r"""Determines which data types are supported and how they are represented""" - service_account_credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") ] = None - r"""Select or create a stored text secret""" + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") + ] = None + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Codec to use to compress the persisted data""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - pq_controls: Annotated[ - Optional[OutputResponseOutputGoogleChroniclePqControls], - pydantic.Field(alias="pqControls"), + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None - r"""Persistent queue controls.""" + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""HMAC access key. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_ACCESS_KEY}`.""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""HMAC secret. This value can be a constant or a JavaScript expression, such as `${C.env.GCS_SECRET}`.""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_api_version: Annotated[ - Optional[str], pydantic.Field(alias="__template_apiVersion") + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") ] = None - r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" template_region: Annotated[ Optional[str], pydantic.Field(alias="__template_region") ] = None r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_customer_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_customerId") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") + ] = None + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - @field_serializer("api_version") - def serialize_api_version(self, value): - if isinstance(value, str): - try: - return models.OutputResponseAPIVersion(value) - except ValueError: - return value - return value + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - @field_serializer("authentication_method") - def serialize_authentication_method(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputGoogleChronicleAuthenticationMethod( + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") + ] = None + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" + + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" + + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): + if isinstance(value, str): + try: + return ( + models.OutputResponseOutputGoogleCloudStorageAuthenticationMethod( + value + ) + ) + except ValueError: + return value + return value + + @field_serializer("object_acl") + def serialize_object_acl(self, value): + if isinstance(value, str): + try: + return models.ObjectACLOptionsAuthenticatedreadBucketownerfullcontrol( value ) except ValueError: return value return value - @field_serializer("log_format_type") - def serialize_log_format_type(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.OutputResponseSendEventsAs(value) + return models.StorageClassOptionsArchiveColdline(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -9182,43 +9452,52 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("udm_type") - def serialize_udm_type(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseUDMType(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -9232,56 +9511,68 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "apiVersion", - "authenticationMethod", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "region", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "awsAuthenticationMethod", + "destPath", + "verifyPermissions", + "objectACL", + "storageClass", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "useRoundRobinDns", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", - "totalMemoryLimitKB", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", "description", - "extraLogTypes", - "logType", - "logTextField", - "customerId", - "namespace", - "customLabels", - "udmType", - "apiKey", - "apiKeySecret", - "serviceAccountCredentials", - "serviceAccountCredentialsSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", + "awsApiKey", + "awsSecretKey", + "awsSecret", "__template_streamtags", - "__template_apiVersion", + "__template_bucket", "__template_region", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_destPath", + "__template_objectACL", + "__template_storageClass", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", - "__template_customerId", + "__template_compress", + "__template_parquetSchema", + "__template_awsApiKey", + "__template_awsSecretKey", "notifications", "status", ] @@ -9300,42 +9591,96 @@ def serialize_model(self, handler): return m -class OutputResponseOutputGoogleBigqueryType(str, Enum): +class OutputResponseOutputGoogleChronicleType(str, Enum): r"""Connector type identifier.""" - GOOGLE_BIGQUERY = "google_bigquery" + GOOGLE_CHRONICLE = "google_chronicle" -class OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod( +class OutputResponseAPIVersion(str, Enum, metaclass=utils.OpenEnumMeta): + r"""API version""" + + # V1 + V1 = "v1" + # V2 + V2 = "v2" + + +class OutputResponseOutputGoogleChronicleAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + r"""Authentication method""" - # Auto - AUTO = "auto" - # Secret + # API key + MANUAL = "manual" + # API key secret SECRET = "secret" + # Service account credentials + SERVICE_ACCOUNT = "serviceAccount" + # Service account credentials secret + SERVICE_ACCOUNT_SECRET = "serviceAccountSecret" -class OutputResponseOutputGoogleBigqueryPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseSendEventsAs(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Send events as""" + # Unstructured + UNSTRUCTURED = "unstructured" + # UDM + UDM = "udm" -class OutputResponseOutputGoogleBigqueryPqControls(BaseModel): - r"""Persistent queue controls.""" +class OutputResponseExtraLogTypeTypedDict(TypedDict): + log_type: str + r"""Log Type""" + description: NotRequired[str] + r"""Description""" -class OutputResponseOutputGoogleBigqueryTypedDict(TypedDict): - type: OutputResponseOutputGoogleBigqueryType - r"""Connector type identifier.""" - project_id: str - r"""Google Cloud project ID that contains the BigQuery dataset""" - dataset_id: str - r"""BigQuery dataset ID""" - table_id: str - r"""BigQuery table ID""" - google_auth_method: OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + +class OutputResponseExtraLogType(BaseModel): + log_type: Annotated[str, pydantic.Field(alias="logType")] + r"""Log Type""" + + description: Optional[str] = None + r"""Description""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["description"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseUDMType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + + ENTITIES = "entities" + LOGS = "logs" + + +class OutputResponseOutputGoogleChroniclePqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputGoogleChroniclePqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputGoogleChronicleTypedDict(TypedDict): + type: OutputResponseOutputGoogleChronicleType + r"""Connector type identifier.""" + log_format_type: OutputResponseSendEventsAs + r"""Send events as""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -9346,24 +9691,76 @@ class OutputResponseOutputGoogleBigqueryTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - timestamp_column: NotRequired[str] - r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - secret: NotRequired[str] - r"""Select or create a stored text secret""" - flush_period: NotRequired[float] - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_queue_size: NotRequired[float] - r"""Maximum number of queued batches before blocking""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" - max_in_progress: NotRequired[float] - r"""The maximum number of in-progress API requests before backpressure is applied""" - max_send_retries: NotRequired[float] - r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" + api_version: NotRequired[OutputResponseAPIVersion] + r"""API version""" + authentication_method: NotRequired[ + OutputResponseOutputGoogleChronicleAuthenticationMethod + ] + r"""Authentication method""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + region: NotRequired[str] + r"""Regional endpoint to send events to""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + total_memory_limit_kb: NotRequired[float] + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" description: NotRequired[str] r"""Optional description for this configuration.""" + extra_log_types: NotRequired[List[OutputResponseExtraLogTypeTypedDict]] + r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + log_type: NotRequired[str] + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + log_text_field: NotRequired[str] + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + customer_id: NotRequired[str] + r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + namespace: NotRequired[str] + r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + custom_labels: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""Custom labels to be added to every batch""" + udm_type: NotRequired[OutputResponseUDMType] + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + api_key: NotRequired[str] + r"""Organization's API key in Google SecOps""" + api_key_secret: NotRequired[str] + r"""Select or create a stored text secret""" + service_account_credentials: NotRequired[str] + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + service_account_credentials_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -9386,42 +9783,34 @@ class OutputResponseOutputGoogleBigqueryTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputGoogleBigqueryPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputGoogleChroniclePqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_project_id: NotRequired[str] - r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" - template_dataset_id: NotRequired[str] - r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" - template_table_id: NotRequired[str] - r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" + template_api_version: NotRequired[str] + r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_customer_id: NotRequired[str] + r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputGoogleBigquery(BaseModel): - type: OutputResponseOutputGoogleBigqueryType +class OutputResponseOutputGoogleChronicle(BaseModel): + type: OutputResponseOutputGoogleChronicleType r"""Connector type identifier.""" - project_id: Annotated[str, pydantic.Field(alias="projectId")] - r"""Google Cloud project ID that contains the BigQuery dataset""" - - dataset_id: Annotated[str, pydantic.Field(alias="datasetId")] - r"""BigQuery dataset ID""" - - table_id: Annotated[str, pydantic.Field(alias="tableId")] - r"""BigQuery table ID""" - - google_auth_method: Annotated[ - OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod, - pydantic.Field(alias="googleAuthMethod"), + log_format_type: Annotated[ + OutputResponseSendEventsAs, pydantic.Field(alias="logFormatType") ] - r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + r"""Send events as""" id: Optional[str] = None r"""Unique ID for this output""" @@ -9440,77 +9829,188 @@ class OutputResponseOutputGoogleBigquery(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - timestamp_column: Annotated[ - Optional[str], pydantic.Field(alias="timestampColumn") + api_version: Annotated[ + Optional[OutputResponseAPIVersion], pydantic.Field(alias="apiVersion") ] = None - r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - - secret: Optional[str] = None - r"""Select or create a stored text secret""" - - flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None - r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - - max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( - None - ) - r"""Maximum number of queued batches before blocking""" + r"""API version""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + authentication_method: Annotated[ + Optional[OutputResponseOutputGoogleChronicleAuthenticationMethod], + pydantic.Field(alias="authenticationMethod"), ] = None - r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" + r"""Authentication method""" - max_in_progress: Annotated[ - Optional[float], pydantic.Field(alias="maxInProgress") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""The maximum number of in-progress API requests before backpressure is applied""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - max_send_retries: Annotated[ - Optional[float], pydantic.Field(alias="maxSendRetries") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + region: Optional[str] = None + r"""Regional endpoint to send events to""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Maximum size, in KB, of the request body""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + total_memory_limit_kb: Annotated[ + Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + ] = None + r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + extra_log_types: Annotated[ + Optional[List[OutputResponseExtraLogType]], + pydantic.Field(alias="extraLogTypes"), + ] = None + r"""Custom log types. If the value \"Custom\" is selected in the setting \"Default log type\" above, the first custom log type in this table will be automatically selected as default log type.""" + + log_type: Annotated[Optional[str], pydantic.Field(alias="logType")] = None + r"""Default log type value to send to SecOps. Can be overwritten by event field __logType.""" + + log_text_field: Annotated[Optional[str], pydantic.Field(alias="logTextField")] = ( + None + ) + r"""Name of the event field that contains the log text to send. If not specified, Stream sends a JSON representation of the whole event.""" + + customer_id: Annotated[Optional[str], pydantic.Field(alias="customerId")] = None + r"""A unique identifier (UUID) for your Google SecOps instance. This is provided by your Google representative and is required for API V2 authentication.""" + + namespace: Optional[str] = None + r"""User-configured environment namespace to identify the data domain the logs originated from. Use namespace as a tag to identify the appropriate data domain for indexing and enrichment functionality. Can be overwritten by event field __namespace.""" + + custom_labels: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="customLabels"), + ] = None + r"""Custom labels to be added to every batch""" + + udm_type: Annotated[ + Optional[OutputResponseUDMType], pydantic.Field(alias="udmType") + ] = None + r"""Defines the specific format for UDM events sent to Google SecOps. This must match the type of UDM data being sent.""" + + api_key: Annotated[Optional[str], pydantic.Field(alias="apiKey")] = None + r"""Organization's API key in Google SecOps""" + + api_key_secret: Annotated[Optional[str], pydantic.Field(alias="apiKeySecret")] = ( + None + ) + r"""Select or create a stored text secret""" + + service_account_credentials: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentials") + ] = None + r"""Contents of service account credentials (JSON keys) file downloaded from Google Cloud. To upload a file, click the upload button at this field's upper right.""" + + service_account_credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="serviceAccountCredentialsSecret") + ] = None + r"""Select or create a stored text secret""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None r"""The location for the persistent queue files. To this field's value, the system will append: //.""" pq_compress: Annotated[ @@ -9529,7 +10029,7 @@ class OutputResponseOutputGoogleBigquery(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputGoogleBigqueryPqControls], + Optional[OutputResponseOutputGoogleChroniclePqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -9539,45 +10039,75 @@ class OutputResponseOutputGoogleBigquery(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_project_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_projectId") + template_api_version: Annotated[ + Optional[str], pydantic.Field(alias="__template_apiVersion") ] = None - r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + r"""Binds 'apiVersion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'apiVersion' at runtime.""" - template_dataset_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_datasetId") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_table_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tableId") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_customer_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_customerId") + ] = None + r"""Binds 'customerId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'customerId' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("google_auth_method") - def serialize_google_auth_method(self, value): + @field_serializer("api_version") + def serialize_api_version(self, value): if isinstance(value, str): try: - return ( - models.OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod( - value - ) + return models.OutputResponseAPIVersion(value) + except ValueError: + return value + return value + + @field_serializer("authentication_method") + def serialize_authentication_method(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputGoogleChronicleAuthenticationMethod( + value ) except ValueError: return value return value + @field_serializer("log_format_type") + def serialize_log_format_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseSendEventsAs(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + @field_serializer("on_backpressure") def serialize_on_backpressure(self, value): if isinstance(value, str): @@ -9587,6 +10117,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("udm_type") + def serialize_udm_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseUDMType(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -9623,15 +10162,38 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "timestampColumn", - "secret", - "flushPeriod", - "maxQueueSize", - "maxRecordSizeKB", - "maxInProgress", - "maxSendRetries", + "apiVersion", + "authenticationMethod", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "region", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", + "useRoundRobinDns", "onBackpressure", + "totalMemoryLimitKB", "description", + "extraLogTypes", + "logType", + "logTextField", + "customerId", + "namespace", + "customLabels", + "udmType", + "apiKey", + "apiKeySecret", + "serviceAccountCredentials", + "serviceAccountCredentialsSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -9645,10 +10207,11 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_projectId", - "__template_datasetId", - "__template_tableId", + "__template_apiVersion", + "__template_region", + "__template_failedRequestLoggingMode", "__template_onBackpressure", + "__template_customerId", "notifications", "status", ] @@ -9667,27 +10230,42 @@ def serialize_model(self, handler): return m -class OutputResponseOutputAzureEventhubType(str, Enum): +class OutputResponseOutputGoogleBigqueryType(str, Enum): r"""Connector type identifier.""" - AZURE_EVENTHUB = "azure_eventhub" + GOOGLE_BIGQUERY = "google_bigquery" -class OutputResponseOutputAzureEventhubPqControlsTypedDict(TypedDict): +class OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" + + # Auto + AUTO = "auto" + # Secret + SECRET = "secret" + + +class OutputResponseOutputGoogleBigqueryPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputAzureEventhubPqControls(BaseModel): +class OutputResponseOutputGoogleBigqueryPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputAzureEventhubTypedDict(TypedDict): - type: OutputResponseOutputAzureEventhubType +class OutputResponseOutputGoogleBigqueryTypedDict(TypedDict): + type: OutputResponseOutputGoogleBigqueryType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" - topic: str - r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" + project_id: str + r"""Google Cloud project ID that contains the BigQuery dataset""" + dataset_id: str + r"""BigQuery dataset ID""" + table_id: str + r"""BigQuery table ID""" + google_auth_method: OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -9698,36 +10276,20 @@ class OutputResponseOutputAzureEventhubTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - ack: NotRequired[AcknowledgmentsOptions] - r"""Control the number of required acknowledgments""" - format_: NotRequired[RecordDataFormatOptions] - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" + timestamp_column: NotRequired[str] + r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" + secret: NotRequired[str] + r"""Select or create a stored text secret""" + flush_period: NotRequired[float] + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" + max_queue_size: NotRequired[float] + r"""Maximum number of queued batches before blocking""" max_record_size_kb: NotRequired[float] - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - flush_event_count: NotRequired[float] - r"""Maximum number of events in a batch before forcing a flush""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - connection_timeout: NotRequired[float] - r"""Maximum time to wait for a connection to complete successfully""" - request_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to a request""" - max_retries: NotRequired[float] - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - max_back_off: NotRequired[float] - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - initial_backoff: NotRequired[float] - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - backoff_rate: NotRequired[float] - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" - authentication_timeout: NotRequired[float] - r"""Maximum time to wait for Kafka to respond to an authentication request""" - reauthentication_threshold: NotRequired[float] - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - sasl: NotRequired[AuthenticationTypeUseTypedDict] - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - tls: NotRequired[TLSSettingsClientSideTypeTypedDict] - r"""TLS settings (client side)""" + r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" + max_in_progress: NotRequired[float] + r"""The maximum number of in-progress API requests before backpressure is applied""" + max_send_retries: NotRequired[float] + r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" description: NotRequired[str] @@ -9754,33 +10316,42 @@ class OutputResponseOutputAzureEventhubTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputAzureEventhubPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputGoogleBigqueryPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: NotRequired[str] - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" - template_topic: NotRequired[str] - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_project_id: NotRequired[str] + r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" + template_dataset_id: NotRequired[str] + r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" + template_table_id: NotRequired[str] + r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputAzureEventhub(BaseModel): - type: OutputResponseOutputAzureEventhubType +class OutputResponseOutputGoogleBigquery(BaseModel): + type: OutputResponseOutputGoogleBigqueryType r"""Connector type identifier.""" - brokers: List[str] - r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + project_id: Annotated[str, pydantic.Field(alias="projectId")] + r"""Google Cloud project ID that contains the BigQuery dataset""" - topic: str - r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" + dataset_id: Annotated[str, pydantic.Field(alias="datasetId")] + r"""BigQuery dataset ID""" + + table_id: Annotated[str, pydantic.Field(alias="tableId")] + r"""BigQuery table ID""" + + google_auth_method: Annotated[ + OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod, + pydantic.Field(alias="googleAuthMethod"), + ] + r"""Choose Auto to use Google Application Default Credentials (ADC), or Secret to select or create a stored secret that references Google service account credentials""" id: Optional[str] = None r"""Unique ID for this output""" @@ -9799,68 +10370,36 @@ class OutputResponseOutputAzureEventhub(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - ack: Optional[AcknowledgmentsOptions] = None - r"""Control the number of required acknowledgments""" - - format_: Annotated[ - Optional[RecordDataFormatOptions], pydantic.Field(alias="format") - ] = None - r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") - ] = None - r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - - flush_event_count: Annotated[ - Optional[float], pydantic.Field(alias="flushEventCount") - ] = None - r"""Maximum number of events in a batch before forcing a flush""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + timestamp_column: Annotated[ + Optional[str], pydantic.Field(alias="timestampColumn") ] = None - r"""Maximum time to wait for a connection to complete successfully""" + r"""Column name to write event time (`_time`) as a BigQuery TIMESTAMP. Used for time partitioning""" - request_timeout: Annotated[ - Optional[float], pydantic.Field(alias="requestTimeout") - ] = None - r"""Maximum time to wait for Kafka to respond to a request""" + secret: Optional[str] = None + r"""Select or create a stored text secret""" - max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None - r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + flush_period: Annotated[Optional[float], pydantic.Field(alias="flushPeriod")] = None + r"""Maximum time to wait before sending a batch (when batch size limit is not reached)""" - max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None - r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + max_queue_size: Annotated[Optional[float], pydantic.Field(alias="maxQueueSize")] = ( + None + ) + r"""Maximum number of queued batches before blocking""" - initial_backoff: Annotated[ - Optional[float], pydantic.Field(alias="initialBackoff") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - - backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None - r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + r"""Maximum size (KB) of a single append request. BigQuery limit is 10 MB""" - authentication_timeout: Annotated[ - Optional[float], pydantic.Field(alias="authenticationTimeout") + max_in_progress: Annotated[ + Optional[float], pydantic.Field(alias="maxInProgress") ] = None - r"""Maximum time to wait for Kafka to respond to an authentication request""" + r"""The maximum number of in-progress API requests before backpressure is applied""" - reauthentication_threshold: Annotated[ - Optional[float], pydantic.Field(alias="reauthenticationThreshold") + max_send_retries: Annotated[ + Optional[float], pydantic.Field(alias="maxSendRetries") ] = None - r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" - - sasl: Optional[AuthenticationTypeUse] = None - r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" - - tls: Optional[TLSSettingsClientSideType] = None - r"""TLS settings (client side)""" + r"""Maximum retries per batch for retryable failures (transient, rate-limit, unknown) before dropping. 0 (default) retries indefinitely.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") @@ -9920,7 +10459,7 @@ class OutputResponseOutputAzureEventhub(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputAzureEventhubPqControls], + Optional[OutputResponseOutputGoogleBigqueryPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -9930,46 +10469,41 @@ class OutputResponseOutputAzureEventhub(BaseModel): ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_brokers: Annotated[ - Optional[str], pydantic.Field(alias="__template_brokers") + template_project_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_projectId") ] = None - r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + r"""Binds 'projectId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'projectId' at runtime.""" - template_topic: Annotated[ - Optional[str], pydantic.Field(alias="__template_topic") + template_dataset_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_datasetId") ] = None - r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + r"""Binds 'datasetId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'datasetId' at runtime.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_table_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tableId") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'tableId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tableId' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("ack") - def serialize_ack(self, value): - if isinstance(value, str): - try: - return models.AcknowledgmentsOptions(value) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("google_auth_method") + def serialize_google_auth_method(self, value): if isinstance(value, str): try: - return models.RecordDataFormatOptions(value) + return ( + models.OutputResponseOutputGoogleBigqueryGoogleAuthenticationMethod( + value + ) + ) except ValueError: return value return value @@ -10019,21 +10553,13 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "ack", - "format", + "timestampColumn", + "secret", + "flushPeriod", + "maxQueueSize", "maxRecordSizeKB", - "flushEventCount", - "flushPeriodSec", - "connectionTimeout", - "requestTimeout", - "maxRetries", - "maxBackOff", - "initialBackoff", - "backoffRate", - "authenticationTimeout", - "reauthenticationThreshold", - "sasl", - "tls", + "maxInProgress", + "maxSendRetries", "onBackpressure", "description", "pqStrictOrdering", @@ -10049,9 +10575,9 @@ def serialize_model(self, handler): "pqMaxBufferSizeBytes", "pqControls", "__template_streamtags", - "__template_brokers", - "__template_topic", - "__template_format", + "__template_projectId", + "__template_datasetId", + "__template_tableId", "__template_onBackpressure", "notifications", "status", @@ -10071,25 +10597,27 @@ def serialize_model(self, handler): return m -class OutputResponseOutputHoneycombType(str, Enum): +class OutputResponseOutputAzureEventhubType(str, Enum): r"""Connector type identifier.""" - HONEYCOMB = "honeycomb" + AZURE_EVENTHUB = "azure_eventhub" -class OutputResponseOutputHoneycombPqControlsTypedDict(TypedDict): +class OutputResponseOutputAzureEventhubPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputHoneycombPqControls(BaseModel): +class OutputResponseOutputAzureEventhubPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputHoneycombTypedDict(TypedDict): - type: OutputResponseOutputHoneycombType +class OutputResponseOutputAzureEventhubTypedDict(TypedDict): + type: OutputResponseOutputAzureEventhubType r"""Connector type identifier.""" - dataset: str - r"""Name of the dataset to send events to – e.g., observability""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + topic: str + r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -10100,44 +10628,38 @@ class OutputResponseOutputHoneycombTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + ack: NotRequired[AcknowledgmentsOptions] + r"""Control the number of required acknowledgments""" + format_: NotRequired[RecordDataFormatOptions] + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" + max_record_size_kb: NotRequired[float] + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" + flush_event_count: NotRequired[float] + r"""Maximum number of events in a batch before forcing a flush""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + connection_timeout: NotRequired[float] + r"""Maximum time to wait for a connection to complete successfully""" + request_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to a request""" + max_retries: NotRequired[float] + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" + max_back_off: NotRequired[float] + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" + initial_backoff: NotRequired[float] + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" + backoff_rate: NotRequired[float] + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + authentication_timeout: NotRequired[float] + r"""Maximum time to wait for Kafka to respond to an authentication request""" + reauthentication_threshold: NotRequired[float] + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + sasl: NotRequired[AuthenticationTypeUseTypedDict] + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + tls: NotRequired[TLSSettingsClientSideTypeTypedDict] + r"""TLS settings (client side)""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAPI] - r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" pq_strict_ordering: NotRequired[bool] @@ -10162,30 +10684,33 @@ class OutputResponseOutputHoneycombTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputHoneycombPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputAzureEventhubPqControlsTypedDict] r"""Persistent queue controls.""" - team: NotRequired[str] - r"""Team API key where the dataset belongs""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_brokers: NotRequired[str] + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + template_topic: NotRequired[str] + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputHoneycomb(BaseModel): - type: OutputResponseOutputHoneycombType +class OutputResponseOutputAzureEventhub(BaseModel): + type: OutputResponseOutputAzureEventhubType r"""Connector type identifier.""" - dataset: str - r"""Name of the dataset to send events to – e.g., observability""" + brokers: List[str] + r"""List of Event Hubs Kafka brokers to connect to, eg. yourdomain.servicebus.windows.net:9093. The hostname can be found in the host portion of the primary or secondary connection string in Shared Access Policies.""" + + topic: str + r"""The name of the Event Hub (Kafka Topic) to publish events. Can be overwritten using field __topicOut.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -10204,90 +10729,74 @@ class OutputResponseOutputHoneycomb(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + ack: Optional[AcknowledgmentsOptions] = None + r"""Control the number of required acknowledgments""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + format_: Annotated[ + Optional[RecordDataFormatOptions], pydantic.Field(alias="format") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Format to use to serialize events before writing to the Event Hubs Kafka brokers""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Maximum size of each record batch before compression. Setting should be < message.max.bytes settings in Event Hubs brokers.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + flush_event_count: Annotated[ + Optional[float], pydantic.Field(alias="flushEventCount") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of events in a batch before forcing a flush""" flush_period_sec: Annotated[ Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Headers to add to all events""" + r"""Maximum time to wait for a connection to complete successfully""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + request_timeout: Annotated[ + Optional[float], pydantic.Field(alias="requestTimeout") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Maximum time to wait for Kafka to respond to a request""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + max_retries: Annotated[Optional[float], pydantic.Field(alias="maxRetries")] = None + r"""If messages are failing, you can set the maximum number of retries as high as 100 to prevent loss of data""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + max_back_off: Annotated[Optional[float], pydantic.Field(alias="maxBackOff")] = None + r"""The maximum wait time for a retry, in milliseconds. Default (and minimum) is 30,000 ms (30 seconds); maximum is 180,000 ms (180 seconds).""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + initial_backoff: Annotated[ + Optional[float], pydantic.Field(alias="initialBackoff") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Initial value used to calculate the retry, in milliseconds. Maximum is 600,000 ms (10 minutes).""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + backoff_rate: Annotated[Optional[float], pydantic.Field(alias="backoffRate")] = None + r"""Set the backoff multiplier (2-20) to control the retry frequency for failed messages. For faster retries, use a lower multiplier. For slower retries with more delay between attempts, use a higher multiplier. The multiplier is used in an exponential backoff formula; see the Kafka [documentation](https://kafka.js.org/docs/retry-detailed) for details.""" + + authentication_timeout: Annotated[ + Optional[float], pydantic.Field(alias="authenticationTimeout") ] = None + r"""Maximum time to wait for Kafka to respond to an authentication request""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + reauthentication_threshold: Annotated[ + Optional[float], pydantic.Field(alias="reauthenticationThreshold") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Specifies a time window during which @{product} can reauthenticate if needed. Creates the window measuring backward from the moment when credentials are set to expire.""" + + sasl: Optional[AuthenticationTypeUse] = None + r"""Authentication parameters to use when connecting to brokers. Using TLS is highly recommended.""" + + tls: Optional[TLSSettingsClientSideType] = None + r"""TLS settings (client side)""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") - ] = None - r"""Enter API key directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" @@ -10341,61 +10850,65 @@ class OutputResponseOutputHoneycomb(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputHoneycombPqControls], + Optional[OutputResponseOutputAzureEventhubPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - team: Optional[str] = None - r"""Team API key where the dataset belongs""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_brokers: Annotated[ + Optional[str], pydantic.Field(alias="__template_brokers") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'brokers' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'brokers' at runtime.""" + + template_topic: Annotated[ + Optional[str], pydantic.Field(alias="__template_topic") + ] = None + r"""Binds 'topic' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'topic' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("ack") + def serialize_ack(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AcknowledgmentsOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.RecordDataFormatOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAPI(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -10436,23 +10949,22 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", + "ack", + "format", + "maxRecordSizeKB", + "flushEventCount", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "connectionTimeout", + "requestTimeout", + "maxRetries", + "maxBackOff", + "initialBackoff", + "backoffRate", + "authenticationTimeout", + "reauthenticationThreshold", + "sasl", + "tls", "onBackpressure", - "authType", "description", "pqStrictOrdering", "pqRatePerSec", @@ -10466,10 +10978,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "team", - "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_brokers", + "__template_topic", + "__template_format", "__template_onBackpressure", "notifications", "status", @@ -10489,30 +11001,25 @@ def serialize_model(self, handler): return m -class OutputResponseCompression(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Compression type to use for records""" +class OutputResponseOutputHoneycombType(str, Enum): + r"""Connector type identifier.""" - # None - NONE = "none" - # Gzip - GZIP = "gzip" + HONEYCOMB = "honeycomb" -class OutputResponseOutputKinesisPqControlsTypedDict(TypedDict): +class OutputResponseOutputHoneycombPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputKinesisPqControls(BaseModel): +class OutputResponseOutputHoneycombPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputKinesisTypedDict(TypedDict): - type: TypeOptionsKinesis +class OutputResponseOutputHoneycombTypedDict(TypedDict): + type: OutputResponseOutputHoneycombType r"""Connector type identifier.""" - stream_name: str - r"""Kinesis stream name to send events to.""" - region: str - r"""Region where the Kinesis stream is located""" + dataset: str + r"""Name of the dataset to send events to – e.g., observability""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -10523,46 +11030,46 @@ class OutputResponseOutputKinesisTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - aws_secret_key: NotRequired[str] - r"""Secret key""" - endpoint: NotRequired[str] - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access Kinesis stream""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" concurrency: NotRequired[float] - r"""Maximum number of ongoing put requests before blocking.""" - max_record_size_kb: NotRequired[float] - r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - compression: NotRequired[OutputResponseCompression] - r"""Compression type to use for records""" - use_list_shards: NotRequired[bool] - r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" - as_ndjson: NotRequired[bool] - r"""Batch events into a single record as NDJSON""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAPI] + r"""Enter API key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""Access key""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - max_events_per_flush: NotRequired[float] - r"""Maximum number of records to send in a single request""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -10585,41 +11092,30 @@ class OutputResponseOutputKinesisTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputKinesisPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputHoneycombPqControlsTypedDict] r"""Persistent queue controls.""" + team: NotRequired[str] + r"""Team API key where the dataset belongs""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputKinesis(BaseModel): - type: TypeOptionsKinesis +class OutputResponseOutputHoneycomb(BaseModel): + type: OutputResponseOutputHoneycombType r"""Connector type identifier.""" - stream_name: Annotated[str, pydantic.Field(alias="streamName")] - r"""Kinesis stream name to send events to.""" - - region: str - r"""Region where the Kinesis stream is located""" + dataset: str + r"""Name of the dataset to send events to – e.g., observability""" id: Optional[str] = None r"""Unique ID for this output""" @@ -10638,93 +11134,93 @@ class OutputResponseOutputKinesis(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - endpoint: Optional[str] = None - r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Reuse connections between requests, which can improve performance""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access Kinesis stream""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""External ID to use when assuming role""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + r"""Headers to add to all events""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing put requests before blocking.""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - max_record_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSizeKB") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + r"""List of headers that are safe to log in plain text""" - compression: Optional[OutputResponseCompression] = None - r"""Compression type to use for records""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - use_list_shards: Annotated[ - Optional[bool], pydantic.Field(alias="useListShards") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" - as_ndjson: Annotated[Optional[bool], pydantic.Field(alias="asNdjson")] = None - r"""Batch events into a single record as NDJSON""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAPI], pydantic.Field(alias="authType") + ] = None + r"""Enter API key directly, or select a stored secret""" + description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""Access key""" - - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" - - max_events_per_flush: Annotated[ - Optional[float], pydantic.Field(alias="maxEventsPerFlush") - ] = None - r"""Maximum number of records to send in a single request""" - pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -10775,85 +11271,61 @@ class OutputResponseOutputKinesis(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputKinesisPqControls], + Optional[OutputResponseOutputHoneycombPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + team: Optional[str] = None + r"""Team API key where the dataset belongs""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") - ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") - ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") - ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") - ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") - ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseCompression(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.AuthenticationMethodOptionsAPI(value) except ValueError: return value return value @@ -10894,26 +11366,24 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "awsAuthenticationMethod", - "awsSecretKey", - "endpoint", - "reuseConnections", - "rejectUnauthorized", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", "concurrency", - "maxRecordSizeKB", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", "flushPeriodSec", - "compression", - "useListShards", - "asNdjson", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", + "authType", "description", - "awsApiKey", - "awsSecret", - "maxEventsPerFlush", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -10926,15 +11396,11 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "team", + "textSecret", "__template_streamtags", - "__template_streamName", - "__template_awsSecretKey", - "__template_region", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_awsApiKey", "notifications", "status", ] @@ -10953,34 +11419,30 @@ def serialize_model(self, handler): return m -class OutputResponseOutputAzureLogsType(str, Enum): - r"""Connector type identifier.""" - - AZURE_LOGS = "azure_logs" - - -class OutputResponseOutputAzureLogsAuthenticationMethod( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Enter workspace ID and workspace key directly, or select a stored secret""" +class OutputResponseCompression(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Compression type to use for records""" - MANUAL = "manual" - SECRET = "secret" + # None + NONE = "none" + # Gzip + GZIP = "gzip" -class OutputResponseOutputAzureLogsPqControlsTypedDict(TypedDict): +class OutputResponseOutputKinesisPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputAzureLogsPqControls(BaseModel): +class OutputResponseOutputKinesisPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputAzureLogsTypedDict(TypedDict): - type: OutputResponseOutputAzureLogsType +class OutputResponseOutputKinesisTypedDict(TypedDict): + type: TypeOptionsKinesis r"""Connector type identifier.""" - log_type: str - r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + stream_name: str + r"""Kinesis stream name to send events to.""" + region: str + r"""Region where the Kinesis stream is located""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -10991,49 +11453,46 @@ class OutputResponseOutputAzureLogsTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - resource_id: NotRequired[str] - r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + aws_secret_key: NotRequired[str] + r"""Secret key""" + endpoint: NotRequired[str] + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access Kinesis stream""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing put requests before blocking.""" + max_record_size_kb: NotRequired[float] + r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - api_url: NotRequired[str] - r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" + compression: NotRequired[OutputResponseCompression] + r"""Compression type to use for records""" + use_list_shards: NotRequired[bool] + r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" + as_ndjson: NotRequired[bool] + r"""Batch events into a single record as NDJSON""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[OutputResponseOutputAzureLogsAuthenticationMethod] - r"""Enter workspace ID and workspace key directly, or select a stored secret""" description: NotRequired[str] r"""Optional description for this configuration.""" + aws_api_key: NotRequired[str] + r"""Access key""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + max_events_per_flush: NotRequired[float] + r"""Maximum number of records to send in a single request""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -11056,36 +11515,41 @@ class OutputResponseOutputAzureLogsTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputAzureLogsPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputKinesisPqControlsTypedDict] r"""Persistent queue controls.""" - workspace_id: NotRequired[str] - r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" - workspace_key: NotRequired[str] - r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" - keypair_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_workspace_id: NotRequired[str] - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_workspace_key: NotRequired[str] - r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputAzureLogs(BaseModel): - type: OutputResponseOutputAzureLogsType +class OutputResponseOutputKinesis(BaseModel): + type: TypeOptionsKinesis r"""Connector type identifier.""" - log_type: Annotated[str, pydantic.Field(alias="logType")] - r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + stream_name: Annotated[str, pydantic.Field(alias="streamName")] + r"""Kinesis stream name to send events to.""" + + region: str + r"""Region where the Kinesis stream is located""" id: Optional[str] = None r"""Unique ID for this output""" @@ -11104,99 +11568,93 @@ class OutputResponseOutputAzureLogs(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - resource_id: Annotated[Optional[str], pydantic.Field(alias="resourceId")] = None - r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + endpoint: Optional[str] = None + r"""Kinesis stream service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to Kinesis stream-compatible endpoint.""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Use Assume Role credentials to access Kinesis stream""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Headers to add to all events""" + r"""External ID to use when assuming role""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing put requests before blocking.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + max_record_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSizeKB") ] = None - r"""List of headers that are safe to log in plain text""" - - api_url: Annotated[Optional[str], pydantic.Field(alias="apiUrl")] = None - r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" + r"""Maximum size (KB) of each individual record before compression. For uncompressed or non-compressible data 1MB is the max recommended size""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Max record size.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None + compression: Optional[OutputResponseCompression] = None + r"""Compression type to use for records""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + use_list_shards: Annotated[ + Optional[bool], pydantic.Field(alias="useListShards") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Provides higher stream rate limits, improving delivery speed and reliability by minimizing throttling. See the [ListShards API](https://docs.aws.amazon.com/kinesis/latest/APIReference/API_ListShards.html) documentation for details.""" + + as_ndjson: Annotated[Optional[bool], pydantic.Field(alias="asNdjson")] = None + r"""Batch events into a single record as NDJSON""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[OutputResponseOutputAzureLogsAuthenticationMethod], - pydantic.Field(alias="authType"), - ] = None - r"""Enter workspace ID and workspace key directly, or select a stored secret""" - description: Optional[str] = None r"""Optional description for this configuration.""" + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""Access key""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + max_events_per_flush: Annotated[ + Optional[float], pydantic.Field(alias="maxEventsPerFlush") + ] = None + r"""Maximum number of records to send in a single request""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -11247,76 +11705,85 @@ class OutputResponseOutputAzureLogs(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputAzureLogsPqControls], + Optional[OutputResponseOutputKinesisPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None - r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" - - workspace_key: Annotated[Optional[str], pydantic.Field(alias="workspaceKey")] = None - r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" - - keypair_secret: Annotated[Optional[str], pydantic.Field(alias="keypairSecret")] = ( - None - ) - r"""Select or create a stored secret that references your access key and secret key""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") + ] = None + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") + ] = None + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_workspace_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceId") - ] = None - r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - - template_workspace_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_workspaceKey") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compression") + def serialize_compression(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.OutputResponseCompression(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputAzureLogsAuthenticationMethod(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -11357,26 +11824,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "resourceId", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "awsAuthenticationMethod", + "awsSecretKey", + "endpoint", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "concurrency", + "maxRecordSizeKB", "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "apiUrl", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "compression", + "useListShards", + "asNdjson", "onBackpressure", - "authType", "description", + "awsApiKey", + "awsSecret", + "maxEventsPerFlush", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -11389,14 +11856,15 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "workspaceId", - "workspaceKey", - "keypairSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_streamName", + "__template_awsSecretKey", + "__template_region", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", "__template_onBackpressure", - "__template_workspaceId", - "__template_workspaceKey", + "__template_awsApiKey", "notifications", "status", ] @@ -11415,1619 +11883,352 @@ def serialize_model(self, handler): return m -class OutputResponseOutputAzureDataExplorerType(str, Enum): +class OutputResponseOutputAzureLogsType(str, Enum): r"""Connector type identifier.""" - AZURE_DATA_EXPLORER = "azure_data_explorer" - - -class OutputResponseIngestionMode(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Ingestion mode""" - - # Batching - BATCHING = "batching" - # Streaming - STREAMING = "streaming" + AZURE_LOGS = "azure_logs" -class OutputResponseOutputAzureDataExplorerAuthenticationMethod( +class OutputResponseOutputAzureLogsAuthenticationMethod( str, Enum, metaclass=utils.OpenEnumMeta ): - r"""The type of OAuth 2.0 client credentials grant flow to use""" - - # Client secret - CLIENT_SECRET = "clientSecret" - # Client secret (text secret) - CLIENT_TEXT_SECRET = "clientTextSecret" - # Certificate - CERTIFICATE = "certificate" - - -class OutputResponseCertificateTypedDict(TypedDict): - certificate_name: NotRequired[str] - r"""The certificate you registered as credentials for your app in the Azure portal""" - + r"""Enter workspace ID and workspace key directly, or select a stored secret""" -class OutputResponseCertificate(BaseModel): - certificate_name: Annotated[ - Optional[str], pydantic.Field(alias="certificateName") - ] = None - r"""The certificate you registered as credentials for your app in the Azure portal""" + MANUAL = "manual" + SECRET = "secret" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["certificateName"]) - serialized = handler(self) - m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) +class OutputResponseOutputAzureLogsPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - return m +class OutputResponseOutputAzureLogsPqControls(BaseModel): + r"""Persistent queue controls.""" -class OutputResponsePrefixOptional(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Prefix (optional)""" +class OutputResponseOutputAzureLogsTypedDict(TypedDict): + type: OutputResponseOutputAzureLogsType + r"""Connector type identifier.""" + log_type: str + r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + resource_id: NotRequired[str] + r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + api_url: NotRequired[str] + r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[OutputResponseOutputAzureLogsAuthenticationMethod] + r"""Enter workspace ID and workspace key directly, or select a stored secret""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputAzureLogsPqControlsTypedDict] + r"""Persistent queue controls.""" + workspace_id: NotRequired[str] + r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" + workspace_key: NotRequired[str] + r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" + keypair_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_workspace_id: NotRequired[str] + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" + template_workspace_key: NotRequired[str] + r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - # drop-by - DROP_BY = "dropBy" - # ingest-by - INGEST_BY = "ingestBy" +class OutputResponseOutputAzureLogs(BaseModel): + type: OutputResponseOutputAzureLogsType + r"""Connector type identifier.""" -class OutputResponseExtentTagTypedDict(TypedDict): - value: str - r"""Value""" - prefix: NotRequired[OutputResponsePrefixOptional] - r"""Prefix (optional)""" + log_type: Annotated[str, pydantic.Field(alias="logType")] + r"""The Log Type of events sent to this LogAnalytics workspace. Defaults to `Cribl`. Use only letters, numbers, and `_` characters, and can't exceed 100 characters. Can be overwritten by event field __logType.""" + id: Optional[str] = None + r"""Unique ID for this output""" -class OutputResponseExtentTag(BaseModel): - value: str - r"""Value""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - prefix: Optional[OutputResponsePrefixOptional] = None - r"""Prefix (optional)""" + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - @field_serializer("prefix") - def serialize_prefix(self, value): - if isinstance(value, str): - try: - return models.OutputResponsePrefixOptional(value) - except ValueError: - return value - return value + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["prefix"]) - serialized = handler(self) - m = {} + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + resource_id: Annotated[Optional[str], pydantic.Field(alias="resourceId")] = None + r"""Optional Resource ID of the Azure resource to associate the data with. Can be overridden by the __resourceId event field. This ID populates the _ResourceId property, allowing the data to be included in resource-centric queries. If the ID is neither specified nor overridden, resource-centric queries will omit the data.""" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - return m + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" -class OutputResponseIngestIfNotExistTypedDict(TypedDict): - value: str - r"""Value""" + compress: Optional[bool] = None + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ -class OutputResponseIngestIfNotExist(BaseModel): - value: str - r"""Value""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" -class OutputResponseReportLevel(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - # FailuresOnly - FAILURES_ONLY = "failuresOnly" - # DoNotReport - DO_NOT_REPORT = "doNotReport" - # FailuresAndSuccesses - FAILURES_AND_SUCCESSES = "failuresAndSuccesses" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" -class OutputResponseReportMethod(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Target of the ingestion status reporting. Defaults to Queue.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - # Queue - QUEUE = "queue" - # Table - TABLE = "table" - # QueueAndTable - QUEUE_AND_TABLE = "queueAndTable" + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + api_url: Annotated[Optional[str], pydantic.Field(alias="apiUrl")] = None + r"""The DNS name of the Log API endpoint that sends log data to a Log Analytics workspace in Azure Monitor. Defaults to .ods.opinsights.azure.com. @{product} will add a prefix and suffix to construct a URI in this format: /api/logs?api-version=.""" -class OutputResponseAdditionalPropertyTypedDict(TypedDict): - key: str - r"""Key""" - value: str - r"""Value""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None -class OutputResponseAdditionalProperty(BaseModel): - key: str - r"""Key""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - value: str - r"""Value""" + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" - -class OutputResponseOutputAzureDataExplorerPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputAzureDataExplorerPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class OutputResponseOutputAzureDataExplorerTypedDict(TypedDict): - type: OutputResponseOutputAzureDataExplorerType - r"""Connector type identifier.""" - cluster_url: str - r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - database: str - r"""Name of the database containing the table where data will be ingested""" - table: str - r"""Name of the table to ingest data into""" - oauth_endpoint: MicrosoftEntraIDAuthenticationEndpointOptionsSasl - r"""Endpoint used to acquire authentication tokens from Azure""" - tenant_id: str - r"""Directory ID (tenant identifier) in Azure Active Directory""" - client_id: str - r"""client_id to pass in the OAuth request parameter""" - scope: str - r"""Scope to pass in the OAuth request parameter""" - oauth_type: OutputResponseOutputAzureDataExplorerAuthenticationMethod - r"""The type of OAuth 2.0 client credentials grant flow to use""" - compress: CompressionOptionsHTTP - r"""Data compression format to apply to HTTP content before it is delivered""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - validate_database_settings: NotRequired[bool] - r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" - ingest_mode: NotRequired[OutputResponseIngestionMode] - r"""Ingestion mode""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - client_secret: NotRequired[str] - r"""The client secret that you generated for your app in the Azure portal""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[OutputResponseCertificateTypedDict] - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - is_mapping_obj: NotRequired[bool] - r"""Send a JSON mapping object instead of specifying an existing named data mapping""" - mapping_obj: NotRequired[str] - r"""Enter a JSON object that defines your desired data mapping""" - mapping_ref: NotRequired[str] - r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" - ingest_url: NotRequired[str] - r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - flush_immediately: NotRequired[bool] - r"""Bypass the data management service's aggregation mechanism""" - retain_blob_on_success: NotRequired[bool] - r"""Prevent blob deletion after ingestion is complete""" - extent_tags: NotRequired[List[OutputResponseExtentTagTypedDict]] - r"""Strings or tags associated with the extent (ingested data shard)""" - ingest_if_not_exists: NotRequired[List[OutputResponseIngestIfNotExistTypedDict]] - r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" - report_level: NotRequired[OutputResponseReportLevel] - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" - report_method: NotRequired[OutputResponseReportMethod] - r"""Target of the ingestion status reporting. Defaults to Queue.""" - additional_properties: NotRequired[List[OutputResponseAdditionalPropertyTypedDict]] - r"""Optionally, enter additional configuration properties to send to the ingestion service""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputAzureDataExplorerPqControlsTypedDict] - r"""Persistent queue controls.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_cluster_url: NotRequired[str] - r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" - template_database: NotRequired[str] - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_table: NotRequired[str] - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - template_oauth_endpoint: NotRequired[str] - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_scope: NotRequired[str] - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_client_secret: NotRequired[str] - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_mapping_ref: NotRequired[str] - r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" - template_ingest_url: NotRequired[str] - r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class OutputResponseOutputAzureDataExplorer(BaseModel): - type: OutputResponseOutputAzureDataExplorerType - r"""Connector type identifier.""" - - cluster_url: Annotated[str, pydantic.Field(alias="clusterUrl")] - r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - - database: str - r"""Name of the database containing the table where data will be ingested""" - - table: str - r"""Name of the table to ingest data into""" - - oauth_endpoint: Annotated[ - MicrosoftEntraIDAuthenticationEndpointOptionsSasl, - pydantic.Field(alias="oauthEndpoint"), - ] - r"""Endpoint used to acquire authentication tokens from Azure""" - - tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] - r"""Directory ID (tenant identifier) in Azure Active Directory""" - - client_id: Annotated[str, pydantic.Field(alias="clientId")] - r"""client_id to pass in the OAuth request parameter""" - - scope: str - r"""Scope to pass in the OAuth request parameter""" - - oauth_type: Annotated[ - OutputResponseOutputAzureDataExplorerAuthenticationMethod, - pydantic.Field(alias="oauthType"), - ] - r"""The type of OAuth 2.0 client credentials grant flow to use""" - - compress: CompressionOptionsHTTP - r"""Data compression format to apply to HTTP content before it is delivered""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - validate_database_settings: Annotated[ - Optional[bool], pydantic.Field(alias="validateDatabaseSettings") - ] = None - r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" - - ingest_mode: Annotated[ - Optional[OutputResponseIngestionMode], pydantic.Field(alias="ingestMode") - ] = None - r"""Ingestion mode""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None - r"""The client secret that you generated for your app in the Azure portal""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - certificate: Optional[OutputResponseCertificate] = None - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") - ] = None - r"""Compression level to apply before moving files to final destination""" - - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") - ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" - - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") - ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") - ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") - ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") - ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") - ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") - ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" - - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") - ] = None - r"""How frequently, in seconds, to clean up empty directories""" - - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( - None - ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - is_mapping_obj: Annotated[Optional[bool], pydantic.Field(alias="isMappingObj")] = ( - None - ) - r"""Send a JSON mapping object instead of specifying an existing named data mapping""" - - mapping_obj: Annotated[Optional[str], pydantic.Field(alias="mappingObj")] = None - r"""Enter a JSON object that defines your desired data mapping""" - - mapping_ref: Annotated[Optional[str], pydantic.Field(alias="mappingRef")] = None - r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" - - ingest_url: Annotated[Optional[str], pydantic.Field(alias="ingestUrl")] = None - r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - flush_immediately: Annotated[ - Optional[bool], pydantic.Field(alias="flushImmediately") - ] = None - r"""Bypass the data management service's aggregation mechanism""" - - retain_blob_on_success: Annotated[ - Optional[bool], pydantic.Field(alias="retainBlobOnSuccess") - ] = None - r"""Prevent blob deletion after ingestion is complete""" - - extent_tags: Annotated[ - Optional[List[OutputResponseExtentTag]], pydantic.Field(alias="extentTags") - ] = None - r"""Strings or tags associated with the extent (ingested data shard)""" - - ingest_if_not_exists: Annotated[ - Optional[List[OutputResponseIngestIfNotExist]], - pydantic.Field(alias="ingestIfNotExists"), - ] = None - r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" - - report_level: Annotated[ - Optional[OutputResponseReportLevel], pydantic.Field(alias="reportLevel") - ] = None - r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" - - report_method: Annotated[ - Optional[OutputResponseReportMethod], pydantic.Field(alias="reportMethod") - ] = None - r"""Target of the ingestion status reporting. Defaults to Queue.""" - - additional_properties: Annotated[ - Optional[List[OutputResponseAdditionalProperty]], - pydantic.Field(alias="additionalProperties"), - ] = None - r"""Optionally, enter additional configuration properties to send to the ingestion service""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") - ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") - ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") - ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") - ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") - ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") - ] = None - r"""Codec to use to compress the persisted data""" - - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") - ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") - ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - - pq_controls: Annotated[ - Optional[OutputResponseOutputAzureDataExplorerPqControls], - pydantic.Field(alias="pqControls"), - ] = None - r"""Persistent queue controls.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - template_cluster_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_clusterUrl") - ] = None - r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" - - template_database: Annotated[ - Optional[str], pydantic.Field(alias="__template_database") - ] = None - r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - - template_table: Annotated[ - Optional[str], pydantic.Field(alias="__template_table") - ] = None - r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - - template_oauth_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_oauthEndpoint") - ] = None - r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") - ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - - template_scope: Annotated[ - Optional[str], pydantic.Field(alias="__template_scope") - ] = None - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - - template_client_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientSecret") - ] = None - r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - template_mapping_ref: Annotated[ - Optional[str], pydantic.Field(alias="__template_mappingRef") - ] = None - r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" - - template_ingest_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_ingestUrl") - ] = None - r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") - ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("ingest_mode") - def serialize_ingest_mode(self, value): - if isinstance(value, str): - try: - return models.OutputResponseIngestionMode(value) - except ValueError: - return value - return value - - @field_serializer("oauth_endpoint") - def serialize_oauth_endpoint(self, value): - if isinstance(value, str): - try: - return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) - except ValueError: - return value - return value - - @field_serializer("oauth_type") - def serialize_oauth_type(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputAzureDataExplorerAuthenticationMethod( - value - ) - except ValueError: - return value - return value - - @field_serializer("format_") - def serialize_format_(self, value): - if isinstance(value, str): - try: - return models.DataFormatOptions(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsHTTP(value) - except ValueError: - return value - return value - - @field_serializer("compression_level") - def serialize_compression_level(self, value): - if isinstance(value, str): - try: - return models.CompressionLevelOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): - if isinstance(value, str): - try: - return models.ParquetVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): - if isinstance(value, str): - try: - return models.DataPageVersionOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("report_level") - def serialize_report_level(self, value): - if isinstance(value, str): - try: - return models.OutputResponseReportLevel(value) - except ValueError: - return value - return value - - @field_serializer("report_method") - def serialize_report_method(self, value): - if isinstance(value, str): - try: - return models.OutputResponseReportMethod(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPq(value) - except ValueError: - return value - return value - - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "pipeline", - "systemFields", - "environment", - "streamtags", - "validateDatabaseSettings", - "ingestMode", - "description", - "clientSecret", - "textSecret", - "certificate", - "format", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "removeEmptyDirs", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterEnabled", - "deadletterPath", - "maxRetryNum", - "isMappingObj", - "mappingObj", - "mappingRef", - "ingestUrl", - "onBackpressure", - "stagePath", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "maxConcurrentFileParts", - "onDiskFullBackpressure", - "addIdToStagePath", - "retrySettings", - "orphans", - "timeoutSec", - "flushImmediately", - "retainBlobOnSuccess", - "extentTags", - "ingestIfNotExists", - "reportLevel", - "reportMethod", - "additionalProperties", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "maxConnectionReuseSec", - "flushPeriodSec", - "rejectUnauthorized", - "useRoundRobinDns", - "keepAlive", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "__template_streamtags", - "__template_clusterUrl", - "__template_database", - "__template_table", - "__template_oauthEndpoint", - "__template_tenantId", - "__template_clientId", - "__template_scope", - "__template_clientSecret", - "__template_format", - "__template_compress", - "__template_parquetSchema", - "__template_mappingRef", - "__template_ingestUrl", - "__template_onBackpressure", - "__template_fileNameSuffix", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseBlobAccessTier(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Blob access tier""" - - # Default account access tier - INFERRED = "Inferred" - # Hot tier - HOT = "Hot" - # Cool tier - COOL = "Cool" - # Cold tier - COLD = "Cold" - # Archive tier - ARCHIVE = "Archive" - - -class OutputResponseOutputAzureBlobTypedDict(TypedDict): - type: TypeOptionsAzureblob - r"""Connector type identifier.""" - container_name: str - r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - stage_path: str - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - create_container: NotRequired[bool] - r"""Create the configured container in Azure Blob Storage if it does not already exist""" - dest_path: NotRequired[str] - r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - auth_type: NotRequired[AuthenticationMethodOptions] - r"""Authentication method""" - storage_class: NotRequired[OutputResponseBlobAccessTier] - r"""Blob access tier""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" - compression_level: NotRequired[CompressionLevelOptions] - r"""Compression level to apply before moving files to final destination""" - automatic_schema: NotRequired[bool] - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - parquet_schema: NotRequired[str] - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" - parquet_version: NotRequired[ParquetVersionOptions] - r"""Determines which data types are supported and how they are represented""" - parquet_data_page_version: NotRequired[DataPageVersionOptions] - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - parquet_row_group_length: NotRequired[float] - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - parquet_page_size: NotRequired[str] - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - should_log_invalid_rows: NotRequired[bool] - r"""Log up to 3 rows that @{product} skips due to data mismatch""" - key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - enable_statistics: NotRequired[bool] - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - enable_write_page_index: NotRequired[bool] - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - enable_page_checksum: NotRequired[bool] - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - empty_dir_cleanup_sec: NotRequired[float] - r"""How frequently, in seconds, to clean up empty directories""" - directory_batch_size: NotRequired[float] - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - deadletter_path: NotRequired[str] - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - max_retry_num: NotRequired[float] - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - connection_string: NotRequired[str] - r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - storage_account_name: NotRequired[str] - r"""The name of your Azure storage account""" - tenant_id: NotRequired[str] - r"""The service principal's tenant ID""" - client_id: NotRequired[str] - r"""The service principal's client ID""" - azure_cloud: NotRequired[str] - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - endpoint_suffix: NotRequired[str] - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - client_text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - certificate: NotRequired[CertificateTypeTypedDict] - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_container_name: NotRequired[str] - r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - template_format: NotRequired[str] - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_parquet_schema: NotRequired[str] - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - template_connection_string: NotRequired[str] - r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" - template_storage_account_name: NotRequired[str] - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - template_tenant_id: NotRequired[str] - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_azure_cloud: NotRequired[str] - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class OutputResponseOutputAzureBlob(BaseModel): - type: TypeOptionsAzureblob - r"""Connector type identifier.""" - - container_name: Annotated[str, pydantic.Field(alias="containerName")] - r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - create_container: Annotated[ - Optional[bool], pydantic.Field(alias="createContainer") - ] = None - r"""Create the configured container in Azure Blob Storage if it does not already exist""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" - - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file""" - - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" - - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None - r"""Buffer size used to write to a file""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None - - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" - - auth_type: Annotated[ - Optional[AuthenticationMethodOptions], pydantic.Field(alias="authType") - ] = None - r"""Authentication method""" - - storage_class: Annotated[ - Optional[OutputResponseBlobAccessTier], pydantic.Field(alias="storageClass") - ] = None - r"""Blob access tier""" + auth_type: Annotated[ + Optional[OutputResponseOutputAzureLogsAuthenticationMethod], + pydantic.Field(alias="authType"), + ] = None + r"""Enter workspace ID and workspace key directly, or select a stored secret""" description: Optional[str] = None r"""Optional description for this configuration.""" - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" - - compression_level: Annotated[ - Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None - r"""Compression level to apply before moving files to final destination""" + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - automatic_schema: Annotated[ - Optional[bool], pydantic.Field(alias="automaticSchema") + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") ] = None - r"""Automatically calculate the schema based on the events of each Parquet file generated""" - - parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( - None - ) - r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - parquet_version: Annotated[ - Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") - ] = None - r"""Determines which data types are supported and how they are represented""" + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - parquet_data_page_version: Annotated[ - Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") ] = None - r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - parquet_row_group_length: Annotated[ - Optional[float], pydantic.Field(alias="parquetRowGroupLength") + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") ] = None - r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - parquet_page_size: Annotated[ - Optional[str], pydantic.Field(alias="parquetPageSize") + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") ] = None - r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - should_log_invalid_rows: Annotated[ - Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") - ] = None - r"""Log up to 3 rows that @{product} skips due to data mismatch""" + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - key_value_metadata: Annotated[ - Optional[List[KeyValueMetadataConfOutputFilesystem]], - pydantic.Field(alias="keyValueMetadata"), - ] = None - r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - enable_statistics: Annotated[ - Optional[bool], pydantic.Field(alias="enableStatistics") + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + r"""Codec to use to compress the persisted data""" - enable_write_page_index: Annotated[ - Optional[bool], pydantic.Field(alias="enableWritePageIndex") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - enable_page_checksum: Annotated[ - Optional[bool], pydantic.Field(alias="enablePageChecksum") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - empty_dir_cleanup_sec: Annotated[ - Optional[float], pydantic.Field(alias="emptyDirCleanupSec") + pq_controls: Annotated[ + Optional[OutputResponseOutputAzureLogsPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""How frequently, in seconds, to clean up empty directories""" + r"""Persistent queue controls.""" - directory_batch_size: Annotated[ - Optional[float], pydantic.Field(alias="directoryBatchSize") - ] = None - r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + workspace_id: Annotated[Optional[str], pydantic.Field(alias="workspaceId")] = None + r"""Azure Log Analytics Workspace ID. See Azure Dashboard Workspace > Advanced settings.""" - deadletter_path: Annotated[ - Optional[str], pydantic.Field(alias="deadletterPath") - ] = None - r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + workspace_key: Annotated[Optional[str], pydantic.Field(alias="workspaceKey")] = None + r"""Azure Log Analytics Workspace Primary or Secondary Shared Key. See Azure Dashboard Workspace > Advanced settings.""" - max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + keypair_secret: Annotated[Optional[str], pydantic.Field(alias="keypairSecret")] = ( None ) - r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - - connection_string: Annotated[ - Optional[str], pydantic.Field(alias="connectionString") - ] = None - r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="storageAccountName") - ] = None - r"""The name of your Azure storage account""" - - tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None - r"""The service principal's tenant ID""" - - client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None - r"""The service principal's client ID""" - - azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None - r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" - - endpoint_suffix: Annotated[ - Optional[str], pydantic.Field(alias="endpointSuffix") - ] = None - r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" - - client_text_secret: Annotated[ - Optional[str], pydantic.Field(alias="clientTextSecret") - ] = None - r"""Select or create a stored text secret""" - - certificate: Optional[CertificateType] = None + r"""Select or create a stored secret that references your access key and secret key""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_container_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_containerName") - ] = None - r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" - - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") - ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") - ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") - ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") - ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - template_parquet_schema: Annotated[ - Optional[str], pydantic.Field(alias="__template_parquetSchema") - ] = None - r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - - template_connection_string: Annotated[ - Optional[str], pydantic.Field(alias="__template_connectionString") - ] = None - r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" - - template_storage_account_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageAccountName") - ] = None - r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" - - template_tenant_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_tenantId") - ] = None - r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_clientId") + template_workspace_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceId") ] = None - r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + r"""Binds 'workspaceId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceId' at runtime.""" - template_azure_cloud: Annotated[ - Optional[str], pydantic.Field(alias="__template_azureCloud") + template_workspace_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_workspaceKey") ] = None - r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + r"""Binds 'workspaceKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'workspaceKey' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.DataFormatOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -13036,70 +12237,43 @@ def serialize_format_(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) - except ValueError: - return value - return value - - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): - if isinstance(value, str): - try: - return models.DiskSpaceProtectionOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptions(value) - except ValueError: - return value - return value - - @field_serializer("storage_class") - def serialize_storage_class(self, value): - if isinstance(value, str): - try: - return models.OutputResponseBlobAccessTier(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - - @field_serializer("compress") - def serialize_compress(self, value): + + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.OutputResponseOutputAzureLogsAuthenticationMethod(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.ModeOptions(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.CompressionOptionsPq(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -13113,71 +12287,46 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "createContainer", - "destPath", - "addIdToStagePath", - "maxConcurrentFileParts", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", + "resourceId", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "apiUrl", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", "authType", - "storageClass", "description", - "compress", - "compressionLevel", - "automaticSchema", - "parquetSchema", - "parquetVersion", - "parquetDataPageVersion", - "parquetRowGroupLength", - "parquetPageSize", - "shouldLogInvalidRows", - "keyValueMetadata", - "enableStatistics", - "enableWritePageIndex", - "enablePageChecksum", - "emptyDirCleanupSec", - "directoryBatchSize", - "deadletterPath", - "maxRetryNum", - "connectionString", - "textSecret", - "storageAccountName", - "tenantId", - "clientId", - "azureCloud", - "endpointSuffix", - "clientTextSecret", - "certificate", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "workspaceId", + "workspaceKey", + "keypairSecret", "__template_streamtags", - "__template_containerName", - "__template_destPath", - "__template_partitionExpr", - "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_compress", - "__template_parquetSchema", - "__template_connectionString", - "__template_storageAccountName", - "__template_tenantId", - "__template_clientId", - "__template_azureCloud", + "__template_workspaceId", + "__template_workspaceKey", "notifications", "status", ] @@ -13185,24 +12334,198 @@ def serialize_model(self, handler): serialized = handler(self) m = {} - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputAzureDataExplorerType(str, Enum): + r"""Connector type identifier.""" + + AZURE_DATA_EXPLORER = "azure_data_explorer" + + +class OutputResponseIngestionMode(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Ingestion mode""" + + # Batching + BATCHING = "batching" + # Streaming + STREAMING = "streaming" + + +class OutputResponseOutputAzureDataExplorerAuthenticationMethod( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""The type of OAuth 2.0 client credentials grant flow to use""" + + # Client secret + CLIENT_SECRET = "clientSecret" + # Client secret (text secret) + CLIENT_TEXT_SECRET = "clientTextSecret" + # Certificate + CERTIFICATE = "certificate" + + +class OutputResponseCertificateTypedDict(TypedDict): + certificate_name: NotRequired[str] + r"""The certificate you registered as credentials for your app in the Azure portal""" + + +class OutputResponseCertificate(BaseModel): + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""The certificate you registered as credentials for your app in the Azure portal""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["certificateName"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponsePrefixOptional(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Prefix (optional)""" + + # drop-by + DROP_BY = "dropBy" + # ingest-by + INGEST_BY = "ingestBy" + + +class OutputResponseExtentTagTypedDict(TypedDict): + value: str + r"""Value""" + prefix: NotRequired[OutputResponsePrefixOptional] + r"""Prefix (optional)""" + + +class OutputResponseExtentTag(BaseModel): + value: str + r"""Value""" + + prefix: Optional[OutputResponsePrefixOptional] = None + r"""Prefix (optional)""" + + @field_serializer("prefix") + def serialize_prefix(self, value): + if isinstance(value, str): + try: + return models.OutputResponsePrefixOptional(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["prefix"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseIngestIfNotExistTypedDict(TypedDict): + value: str + r"""Value""" + + +class OutputResponseIngestIfNotExist(BaseModel): + value: str + r"""Value""" + + +class OutputResponseReportLevel(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + + # FailuresOnly + FAILURES_ONLY = "failuresOnly" + # DoNotReport + DO_NOT_REPORT = "doNotReport" + # FailuresAndSuccesses + FAILURES_AND_SUCCESSES = "failuresAndSuccesses" + + +class OutputResponseReportMethod(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Target of the ingestion status reporting. Defaults to Queue.""" + + # Queue + QUEUE = "queue" + # Table + TABLE = "table" + # QueueAndTable + QUEUE_AND_TABLE = "queueAndTable" - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - return m +class OutputResponseAdditionalPropertyTypedDict(TypedDict): + key: str + r"""Key""" + value: str + r"""Value""" -class OutputResponseOutputS3TypedDict(TypedDict): - type: TypeOptionsS3 +class OutputResponseAdditionalProperty(BaseModel): + key: str + r"""Key""" + + value: str + r"""Value""" + + +class OutputResponseOutputAzureDataExplorerPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputAzureDataExplorerPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputAzureDataExplorerTypedDict(TypedDict): + type: OutputResponseOutputAzureDataExplorerType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - stage_path: str - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + cluster_url: str + r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" + database: str + r"""Name of the database containing the table where data will be ingested""" + table: str + r"""Name of the table to ingest data into""" + oauth_endpoint: MicrosoftEntraIDAuthenticationEndpointOptionsSasl + r"""Endpoint used to acquire authentication tokens from Azure""" + tenant_id: str + r"""Directory ID (tenant identifier) in Azure Active Directory""" + client_id: str + r"""client_id to pass in the OAuth request parameter""" + scope: str + r"""Scope to pass in the OAuth request parameter""" + oauth_type: OutputResponseOutputAzureDataExplorerAuthenticationMethod + r"""The type of OAuth 2.0 client credentials grant flow to use""" + compress: CompressionOptionsHTTP + r"""Data compression format to apply to HTTP content before it is delivered""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -13213,85 +12536,19 @@ class OutputResponseOutputS3TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - endpoint: NotRequired[str] - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - enable_assume_role: NotRequired[bool] - r"""Use Assume Role credentials to access S3""" - assume_role_arn: NotRequired[str] - r"""Amazon Resource Name (ARN) of the role to assume""" - assume_role_external_id: NotRequired[str] - r"""External ID to use when assuming role""" - duration_seconds: NotRequired[float] - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] - r"""AWS authentication method. Choose Auto to use IAM roles.""" - reuse_connections: NotRequired[bool] - r"""Reuse connections between requests, which can improve performance""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - region: NotRequired[str] - r"""Region where the S3 bucket is located""" - dest_path: NotRequired[str] - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - max_concurrent_file_parts: NotRequired[float] - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - verify_permissions: NotRequired[bool] - r"""Disable if you can access files within the bucket but not the bucket itself""" - max_closing_files_to_backpressure: NotRequired[float] - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - add_id_to_stage_path: NotRequired[bool] - r"""Add the Output ID value to staging location""" - remove_empty_dirs: NotRequired[bool] - r"""Remove empty staging directories after moving files""" - partition_expr: NotRequired[str] - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - format_: NotRequired[DataFormatOptions] - r"""Format of the output data""" - base_file_name: NotRequired[str] - r"""JavaScript expression to define the output filename prefix (can be constant)""" - file_name_suffix: NotRequired[str] - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - max_file_size_mb: NotRequired[float] - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - max_file_open_time_sec: NotRequired[float] - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - max_file_idle_time_sec: NotRequired[float] - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - max_open_files: NotRequired[float] - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" - header_line: NotRequired[str] - r"""If set, this line will be written to the beginning of each output file""" - write_high_water_mark: NotRequired[float] - r"""Buffer size used to write to a file""" - on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] - r"""How to handle events when all receivers are exerting backpressure""" - deadletter_enabled: NotRequired[bool] - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - force_close_on_shutdown: NotRequired[bool] - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - retry_settings: NotRequired[RetrySettingsTypeTypedDict] - orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] - r"""Orphan file recovery""" - aws_secret_key: NotRequired[str] - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" - object_acl: NotRequired[ObjectACLOptions] - r"""Object ACL to assign to uploaded objects""" - storage_class: NotRequired[StorageClassOptions] - r"""Storage class to select for uploaded objects""" - server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] - r"""Server-side encryption to use for uploaded objects""" - kms_key_id: NotRequired[str] - r"""ID or ARN of the KMS customer-managed key to use for encryption""" + validate_database_settings: NotRequired[bool] + r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" + ingest_mode: NotRequired[OutputResponseIngestionMode] + r"""Ingestion mode""" description: NotRequired[str] r"""Optional description for this configuration.""" - aws_api_key: NotRequired[str] - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" - aws_secret: NotRequired[str] - r"""Select or create a stored secret that references your access key and secret key""" - compress: NotRequired[CompressionOptionsHTTP] - r"""Data compression format to apply to HTTP content before it is delivered""" + client_secret: NotRequired[str] + r"""The client secret that you generated for your app in the Azure portal""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[OutputResponseCertificateTypedDict] + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" compression_level: NotRequired[CompressionLevelOptions] r"""Compression level to apply before moving files to final destination""" automatic_schema: NotRequired[bool] @@ -13316,269 +12573,232 @@ class OutputResponseOutputS3TypedDict(TypedDict): r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" enable_page_checksum: NotRequired[bool] r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" empty_dir_cleanup_sec: NotRequired[float] r"""How frequently, in seconds, to clean up empty directories""" directory_batch_size: NotRequired[float] r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" deadletter_path: NotRequired[str] r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_endpoint: NotRequired[str] - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - template_assume_role_arn: NotRequired[str] - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - template_assume_role_external_id: NotRequired[str] - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - template_bucket: NotRequired[str] - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - template_region: NotRequired[str] - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - template_dest_path: NotRequired[str] - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - template_partition_expr: NotRequired[str] - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + is_mapping_obj: NotRequired[bool] + r"""Send a JSON mapping object instead of specifying an existing named data mapping""" + mapping_obj: NotRequired[str] + r"""Enter a JSON object that defines your desired data mapping""" + mapping_ref: NotRequired[str] + r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" + ingest_url: NotRequired[str] + r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + flush_immediately: NotRequired[bool] + r"""Bypass the data management service's aggregation mechanism""" + retain_blob_on_success: NotRequired[bool] + r"""Prevent blob deletion after ingestion is complete""" + extent_tags: NotRequired[List[OutputResponseExtentTagTypedDict]] + r"""Strings or tags associated with the extent (ingested data shard)""" + ingest_if_not_exists: NotRequired[List[OutputResponseIngestIfNotExistTypedDict]] + r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" + report_level: NotRequired[OutputResponseReportLevel] + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + report_method: NotRequired[OutputResponseReportMethod] + r"""Target of the ingestion status reporting. Defaults to Queue.""" + additional_properties: NotRequired[List[OutputResponseAdditionalPropertyTypedDict]] + r"""Optionally, enter additional configuration properties to send to the ingestion service""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputResponseOutputAzureDataExplorerPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_cluster_url: NotRequired[str] + r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" + template_database: NotRequired[str] + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" + template_table: NotRequired[str] + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" + template_oauth_endpoint: NotRequired[str] + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_scope: NotRequired[str] + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_client_secret: NotRequired[str] + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" template_format: NotRequired[str] r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - template_base_file_name: NotRequired[str] - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - template_file_name_suffix: NotRequired[str] - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - template_on_backpressure: NotRequired[str] - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_aws_secret_key: NotRequired[str] - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - template_object_acl: NotRequired[str] - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - template_storage_class: NotRequired[str] - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - template_server_side_encryption: NotRequired[str] - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - template_kms_key_id: NotRequired[str] - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_aws_api_key: NotRequired[str] - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" template_compress: NotRequired[str] r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_mapping_ref: NotRequired[str] + r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" + template_ingest_url: NotRequired[str] + r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputS3(BaseModel): - type: TypeOptionsS3 +class OutputResponseOutputAzureDataExplorer(BaseModel): + type: OutputResponseOutputAzureDataExplorerType r"""Connector type identifier.""" - bucket: str - r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" - - stage_path: Annotated[str, pydantic.Field(alias="stagePath")] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - endpoint: Optional[str] = None - r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" - - enable_assume_role: Annotated[ - Optional[bool], pydantic.Field(alias="enableAssumeRole") - ] = None - r"""Use Assume Role credentials to access S3""" - - assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( - None - ) - r"""Amazon Resource Name (ARN) of the role to assume""" - - assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="assumeRoleExternalId") - ] = None - r"""External ID to use when assuming role""" - - duration_seconds: Annotated[ - Optional[float], pydantic.Field(alias="durationSeconds") - ] = None - r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - - aws_authentication_method: Annotated[ - Optional[AuthenticationMethodOptionsS3CollectorConf], - pydantic.Field(alias="awsAuthenticationMethod"), - ] = None - r"""AWS authentication method. Choose Auto to use IAM roles.""" - - reuse_connections: Annotated[ - Optional[bool], pydantic.Field(alias="reuseConnections") - ] = None - r"""Reuse connections between requests, which can improve performance""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - - region: Optional[str] = None - r"""Region where the S3 bucket is located""" - - dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None - r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" - - max_concurrent_file_parts: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentFileParts") - ] = None - r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - - verify_permissions: Annotated[ - Optional[bool], pydantic.Field(alias="verifyPermissions") - ] = None - r"""Disable if you can access files within the bucket but not the bucket itself""" - - max_closing_files_to_backpressure: Annotated[ - Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") - ] = None - r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - - add_id_to_stage_path: Annotated[ - Optional[bool], pydantic.Field(alias="addIdToStagePath") - ] = None - r"""Add the Output ID value to staging location""" - - remove_empty_dirs: Annotated[ - Optional[bool], pydantic.Field(alias="removeEmptyDirs") - ] = None - r"""Remove empty staging directories after moving files""" - - partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( - None - ) - r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - - format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( - None - ) - r"""Format of the output data""" - - base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( - None - ) - r"""JavaScript expression to define the output filename prefix (can be constant)""" - - file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="fileNameSuffix") - ] = None - r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - - max_file_size_mb: Annotated[ - Optional[float], pydantic.Field(alias="maxFileSizeMB") - ] = None - r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - - max_file_open_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") - ] = None - r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - - max_file_idle_time_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") - ] = None - r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - - max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( - None - ) - r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + cluster_url: Annotated[str, pydantic.Field(alias="clusterUrl")] + r"""The base URI for your cluster. Typically, `https://..kusto.windows.net`.""" - header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None - r"""If set, this line will be written to the beginning of each output file""" + database: str + r"""Name of the database containing the table where data will be ingested""" - write_high_water_mark: Annotated[ - Optional[float], pydantic.Field(alias="writeHighWaterMark") - ] = None - r"""Buffer size used to write to a file""" + table: str + r"""Name of the table to ingest data into""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptionsBlockDrop], - pydantic.Field(alias="onBackpressure"), - ] = None - r"""How to handle events when all receivers are exerting backpressure""" + oauth_endpoint: Annotated[ + MicrosoftEntraIDAuthenticationEndpointOptionsSasl, + pydantic.Field(alias="oauthEndpoint"), + ] + r"""Endpoint used to acquire authentication tokens from Azure""" - deadletter_enabled: Annotated[ - Optional[bool], pydantic.Field(alias="deadletterEnabled") - ] = None - r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + tenant_id: Annotated[str, pydantic.Field(alias="tenantId")] + r"""Directory ID (tenant identifier) in Azure Active Directory""" - on_disk_full_backpressure: Annotated[ - Optional[DiskSpaceProtectionOptions], - pydantic.Field(alias="onDiskFullBackpressure"), - ] = None - r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + client_id: Annotated[str, pydantic.Field(alias="clientId")] + r"""client_id to pass in the OAuth request parameter""" - force_close_on_shutdown: Annotated[ - Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") - ] = None - r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + scope: str + r"""Scope to pass in the OAuth request parameter""" - retry_settings: Annotated[ - Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") - ] = None + oauth_type: Annotated[ + OutputResponseOutputAzureDataExplorerAuthenticationMethod, + pydantic.Field(alias="oauthType"), + ] + r"""The type of OAuth 2.0 client credentials grant flow to use""" - orphans: Optional[OrphanFileRecoveryType] = None - r"""Orphan file recovery""" + compress: CompressionOptionsHTTP + r"""Data compression format to apply to HTTP content before it is delivered""" - aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( - None - ) - r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + id: Optional[str] = None + r"""Unique ID for this output""" - object_acl: Annotated[ - Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") - ] = None - r"""Object ACL to assign to uploaded objects""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - storage_class: Annotated[ - Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Storage class to select for uploaded objects""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - server_side_encryption: Annotated[ - Optional[ServerSideEncryptionForUploadedObjectsOptions], - pydantic.Field(alias="serverSideEncryption"), + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + validate_database_settings: Annotated[ + Optional[bool], pydantic.Field(alias="validateDatabaseSettings") ] = None - r"""Server-side encryption to use for uploaded objects""" + r"""When saving or starting the Destination, validate the database name and credentials; also validate table name, except when creating a new table. Disable if your Azure app does not have both the Database Viewer and the Table Viewer role.""" - kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None - r"""ID or ARN of the KMS customer-managed key to use for encryption""" + ingest_mode: Annotated[ + Optional[OutputResponseIngestionMode], pydantic.Field(alias="ingestMode") + ] = None + r"""Ingestion mode""" description: Optional[str] = None r"""Optional description for this configuration.""" - aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None - r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + client_secret: Annotated[Optional[str], pydantic.Field(alias="clientSecret")] = None + r"""The client secret that you generated for your app in the Azure portal""" - aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None - r"""Select or create a stored secret that references your access key and secret key""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - compress: Optional[CompressionOptionsHTTP] = None - r"""Data compression format to apply to HTTP content before it is delivered""" + certificate: Optional[OutputResponseCertificate] = None + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" compression_level: Annotated[ Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") @@ -13641,6 +12861,11 @@ class OutputResponseOutputS3(BaseModel): ] = None r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + empty_dir_cleanup_sec: Annotated[ Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None @@ -13651,6 +12876,11 @@ class OutputResponseOutputS3(BaseModel): ] = None r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + deadletter_path: Annotated[ Optional[str], pydantic.Field(alias="deadletterPath") ] = None @@ -13661,95 +12891,274 @@ class OutputResponseOutputS3(BaseModel): ) r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + is_mapping_obj: Annotated[Optional[bool], pydantic.Field(alias="isMappingObj")] = ( + None + ) + r"""Send a JSON mapping object instead of specifying an existing named data mapping""" + + mapping_obj: Annotated[Optional[str], pydantic.Field(alias="mappingObj")] = None + r"""Enter a JSON object that defines your desired data mapping""" + + mapping_ref: Annotated[Optional[str], pydantic.Field(alias="mappingRef")] = None + r"""Enter the name of a data mapping associated with your target table. Or, if incoming event and target table fields match exactly, you can leave the field empty.""" + + ingest_url: Annotated[Optional[str], pydantic.Field(alias="ingestUrl")] = None + r"""The ingestion service URI for your cluster. Typically, `https://ingest-..kusto.windows.net`.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""How to handle events when all receivers are exerting backpressure""" - template_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_endpoint") + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - template_assume_role_arn: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - template_assume_role_external_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - template_bucket: Annotated[ - Optional[str], pydantic.Field(alias="__template_bucket") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + flush_immediately: Annotated[ + Optional[bool], pydantic.Field(alias="flushImmediately") + ] = None + r"""Bypass the data management service's aggregation mechanism""" + + retain_blob_on_success: Annotated[ + Optional[bool], pydantic.Field(alias="retainBlobOnSuccess") + ] = None + r"""Prevent blob deletion after ingestion is complete""" + + extent_tags: Annotated[ + Optional[List[OutputResponseExtentTag]], pydantic.Field(alias="extentTags") + ] = None + r"""Strings or tags associated with the extent (ingested data shard)""" + + ingest_if_not_exists: Annotated[ + Optional[List[OutputResponseIngestIfNotExist]], + pydantic.Field(alias="ingestIfNotExists"), + ] = None + r"""Prevents duplicate ingestion by verifying whether an extent with the specified ingest-by tag already exists""" + + report_level: Annotated[ + Optional[OutputResponseReportLevel], pydantic.Field(alias="reportLevel") + ] = None + r"""Level of ingestion status reporting. Defaults to FailuresOnly.""" + + report_method: Annotated[ + Optional[OutputResponseReportMethod], pydantic.Field(alias="reportMethod") + ] = None + r"""Target of the ingestion status reporting. Defaults to Queue.""" + + additional_properties: Annotated[ + Optional[List[OutputResponseAdditionalProperty]], + pydantic.Field(alias="additionalProperties"), + ] = None + r"""Optionally, enter additional configuration properties to send to the ingestion service""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") ] = None - r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + r"""Codec to use to compress the persisted data""" - template_region: Annotated[ - Optional[str], pydantic.Field(alias="__template_region") + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") ] = None - r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - template_dest_path: Annotated[ - Optional[str], pydantic.Field(alias="__template_destPath") + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") ] = None - r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - template_partition_expr: Annotated[ - Optional[str], pydantic.Field(alias="__template_partitionExpr") + pq_controls: Annotated[ + Optional[OutputResponseOutputAzureDataExplorerPqControls], + pydantic.Field(alias="pqControls"), ] = None - r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + r"""Persistent queue controls.""" - template_format: Annotated[ - Optional[str], pydantic.Field(alias="__template_format") + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_base_file_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_baseFileName") + template_cluster_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_clusterUrl") ] = None - r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + r"""Binds 'clusterUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clusterUrl' at runtime.""" - template_file_name_suffix: Annotated[ - Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + template_database: Annotated[ + Optional[str], pydantic.Field(alias="__template_database") ] = None - r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + r"""Binds 'database' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'database' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_table: Annotated[ + Optional[str], pydantic.Field(alias="__template_table") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'table' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'table' at runtime.""" - template_aws_secret_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsSecretKey") + template_oauth_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_oauthEndpoint") ] = None - r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + r"""Binds 'oauthEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'oauthEndpoint' at runtime.""" - template_object_acl: Annotated[ - Optional[str], pydantic.Field(alias="__template_objectACL") + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") ] = None - r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" - template_storage_class: Annotated[ - Optional[str], pydantic.Field(alias="__template_storageClass") + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") ] = None - r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" - template_server_side_encryption: Annotated[ - Optional[str], pydantic.Field(alias="__template_serverSideEncryption") + template_scope: Annotated[ + Optional[str], pydantic.Field(alias="__template_scope") ] = None - r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_kms_key_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_kmsKeyId") + template_client_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientSecret") ] = None - r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + r"""Binds 'clientSecret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientSecret' at runtime.""" - template_aws_api_key: Annotated[ - Optional[str], pydantic.Field(alias="__template_awsApiKey") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" template_compress: Annotated[ Optional[str], pydantic.Field(alias="__template_compress") @@ -13761,17 +13170,57 @@ class OutputResponseOutputS3(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_mapping_ref: Annotated[ + Optional[str], pydantic.Field(alias="__template_mappingRef") + ] = None + r"""Binds 'mappingRef' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'mappingRef' at runtime.""" + + template_ingest_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_ingestUrl") + ] = None + r"""Binds 'ingestUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'ingestUrl' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("aws_authentication_method") - def serialize_aws_authentication_method(self, value): + @field_serializer("ingest_mode") + def serialize_ingest_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsS3CollectorConf(value) + return models.OutputResponseIngestionMode(value) + except ValueError: + return value + return value + + @field_serializer("oauth_endpoint") + def serialize_oauth_endpoint(self, value): + if isinstance(value, str): + try: + return models.MicrosoftEntraIDAuthenticationEndpointOptionsSasl(value) + except ValueError: + return value + return value + + @field_serializer("oauth_type") + def serialize_oauth_type(self, value): + if isinstance(value, str): + try: + return models.OutputResponseOutputAzureDataExplorerAuthenticationMethod( + value + ) except ValueError: return value return value @@ -13785,83 +13234,101 @@ def serialize_format_(self, value): return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptionsBlockDrop(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("on_disk_full_backpressure") - def serialize_on_disk_full_backpressure(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.DiskSpaceProtectionOptions(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value - @field_serializer("object_acl") - def serialize_object_acl(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.ObjectACLOptions(value) + return models.ParquetVersionOptions(value) except ValueError: return value return value - @field_serializer("storage_class") - def serialize_storage_class(self, value): + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): if isinstance(value, str): try: - return models.StorageClassOptions(value) + return models.DataPageVersionOptions(value) except ValueError: return value return value - @field_serializer("server_side_encryption") - def serialize_server_side_encryption(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.ServerSideEncryptionForUploadedObjectsOptions(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.CompressionOptionsHTTP(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("compression_level") - def serialize_compression_level(self, value): + @field_serializer("report_level") + def serialize_report_level(self, value): if isinstance(value, str): try: - return models.CompressionLevelOptions(value) + return models.OutputResponseReportLevel(value) except ValueError: return value return value - @field_serializer("parquet_version") - def serialize_parquet_version(self, value): + @field_serializer("report_method") + def serialize_report_method(self, value): if isinstance(value, str): try: - return models.ParquetVersionOptions(value) + return models.OutputResponseReportMethod(value) except ValueError: return value return value - @field_serializer("parquet_data_page_version") - def serialize_parquet_data_page_version(self, value): + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): if isinstance(value, str): try: - return models.DataPageVersionOptions(value) + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -13875,46 +13342,13 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "endpoint", - "enableAssumeRole", - "assumeRoleArn", - "assumeRoleExternalId", - "durationSeconds", - "awsAuthenticationMethod", - "reuseConnections", - "rejectUnauthorized", - "region", - "destPath", - "maxConcurrentFileParts", - "verifyPermissions", - "maxClosingFilesToBackpressure", - "addIdToStagePath", - "removeEmptyDirs", - "partitionExpr", - "format", - "baseFileName", - "fileNameSuffix", - "maxFileSizeMB", - "maxFileOpenTimeSec", - "maxFileIdleTimeSec", - "maxOpenFiles", - "headerLine", - "writeHighWaterMark", - "onBackpressure", - "deadletterEnabled", - "onDiskFullBackpressure", - "forceCloseOnShutdown", - "retrySettings", - "orphans", - "awsSecretKey", - "objectACL", - "storageClass", - "serverSideEncryption", - "kmsKeyId", + "validateDatabaseSettings", + "ingestMode", "description", - "awsApiKey", - "awsSecret", - "compress", + "clientSecret", + "textSecret", + "certificate", + "format", "compressionLevel", "automaticSchema", "parquetSchema", @@ -13927,30 +13361,75 @@ def serialize_model(self, handler): "enableStatistics", "enableWritePageIndex", "enablePageChecksum", + "removeEmptyDirs", "emptyDirCleanupSec", "directoryBatchSize", + "deadletterEnabled", "deadletterPath", "maxRetryNum", + "isMappingObj", + "mappingObj", + "mappingRef", + "ingestUrl", + "onBackpressure", + "stagePath", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "maxConcurrentFileParts", + "onDiskFullBackpressure", + "addIdToStagePath", + "retrySettings", + "orphans", + "timeoutSec", + "flushImmediately", + "retainBlobOnSuccess", + "extentTags", + "ingestIfNotExists", + "reportLevel", + "reportMethod", + "additionalProperties", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "maxConnectionReuseSec", + "flushPeriodSec", + "rejectUnauthorized", + "useRoundRobinDns", + "keepAlive", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", "__template_streamtags", - "__template_endpoint", - "__template_assumeRoleArn", - "__template_assumeRoleExternalId", - "__template_bucket", - "__template_region", - "__template_destPath", - "__template_partitionExpr", + "__template_clusterUrl", + "__template_database", + "__template_table", + "__template_oauthEndpoint", + "__template_tenantId", + "__template_clientId", + "__template_scope", + "__template_clientSecret", "__template_format", - "__template_baseFileName", - "__template_fileNameSuffix", - "__template_onBackpressure", - "__template_awsSecretKey", - "__template_objectACL", - "__template_storageClass", - "__template_serverSideEncryption", - "__template_kmsKeyId", - "__template_awsApiKey", "__template_compress", "__template_parquetSchema", + "__template_mappingRef", + "__template_ingestUrl", + "__template_onBackpressure", + "__template_fileNameSuffix", "notifications", "status", ] @@ -13969,17 +13448,28 @@ def serialize_model(self, handler): return m -class OutputResponseOutputFilesystemType(str, Enum): - r"""Connector type identifier.""" +class OutputResponseBlobAccessTier(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Blob access tier""" - FILESYSTEM = "filesystem" + # Default account access tier + INFERRED = "Inferred" + # Hot tier + HOT = "Hot" + # Cool tier + COOL = "Cool" + # Cold tier + COLD = "Cold" + # Archive tier + ARCHIVE = "Archive" -class OutputResponseOutputFilesystemTypedDict(TypedDict): - type: OutputResponseOutputFilesystemType +class OutputResponseOutputAzureBlobTypedDict(TypedDict): + type: TypeOptionsAzureblob r"""Connector type identifier.""" - dest_path: str - r"""Final destination for the output files""" + container_name: str + r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" + stage_path: str + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -13990,10 +13480,14 @@ class OutputResponseOutputFilesystemTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - stage_path: NotRequired[str] - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + create_container: NotRequired[bool] + r"""Create the configured container in Azure Blob Storage if it does not already exist""" + dest_path: NotRequired[str] + r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" add_id_to_stage_path: NotRequired[bool] r"""Add the Output ID value to staging location""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file""" remove_empty_dirs: NotRequired[bool] r"""Remove empty staging directories after moving files""" partition_expr: NotRequired[str] @@ -14027,6 +13521,10 @@ class OutputResponseOutputFilesystemTypedDict(TypedDict): retry_settings: NotRequired[RetrySettingsTypeTypedDict] orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] r"""Orphan file recovery""" + auth_type: NotRequired[AuthenticationMethodOptions] + r"""Authentication method""" + storage_class: NotRequired[OutputResponseBlobAccessTier] + r"""Blob access tier""" description: NotRequired[str] r"""Optional description for this configuration.""" compress: NotRequired[CompressionOptionsHTTP] @@ -14063,8 +13561,29 @@ class OutputResponseOutputFilesystemTypedDict(TypedDict): r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" max_retry_num: NotRequired[float] r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + connection_string: NotRequired[str] + r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + storage_account_name: NotRequired[str] + r"""The name of your Azure storage account""" + tenant_id: NotRequired[str] + r"""The service principal's tenant ID""" + client_id: NotRequired[str] + r"""The service principal's client ID""" + azure_cloud: NotRequired[str] + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + endpoint_suffix: NotRequired[str] + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + client_text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + certificate: NotRequired[CertificateTypeTypedDict] template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_container_name: NotRequired[str] + r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" template_partition_expr: NotRequired[str] r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" template_format: NotRequired[str] @@ -14079,18 +13598,31 @@ class OutputResponseOutputFilesystemTypedDict(TypedDict): r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" template_parquet_schema: NotRequired[str] r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_connection_string: NotRequired[str] + r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" + template_storage_account_name: NotRequired[str] + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + template_tenant_id: NotRequired[str] + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + template_azure_cloud: NotRequired[str] + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputFilesystem(BaseModel): - type: OutputResponseOutputFilesystemType +class OutputResponseOutputAzureBlob(BaseModel): + type: TypeOptionsAzureblob r"""Connector type identifier.""" - dest_path: Annotated[str, pydantic.Field(alias="destPath")] - r"""Final destination for the output files""" + container_name: Annotated[str, pydantic.Field(alias="containerName")] + r"""The Azure Blob Storage container name. Name can include only lowercase letters, numbers, and hyphens. For dynamic container names, enter a JavaScript expression within quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myContainer-${C.env[\"CRIBL_WORKER_ID\"]}`.""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files before compressing and moving to final destination. Use performant and stable storage.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -14109,14 +13641,24 @@ class OutputResponseOutputFilesystem(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None - r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + create_container: Annotated[ + Optional[bool], pydantic.Field(alias="createContainer") + ] = None + r"""Create the configured container in Azure Blob Storage if it does not already exist""" + + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Root directory prepended to path before uploading. Value can be a JavaScript expression enclosed in quotes or backticks, to be evaluated at initialization. The expression can evaluate to a constant value and can reference Global Variables, such as `myBlobPrefix-${C.env[\"CRIBL_WORKER_ID\"]}`.""" add_id_to_stage_path: Annotated[ Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None r"""Add the Output ID value to staging location""" + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") + ] = None + r"""Maximum number of parts to upload in parallel per file""" + remove_empty_dirs: Annotated[ Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None @@ -14199,6 +13741,16 @@ class OutputResponseOutputFilesystem(BaseModel): orphans: Optional[OrphanFileRecoveryType] = None r"""Orphan file recovery""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptions], pydantic.Field(alias="authType") + ] = None + r"""Authentication method""" + + storage_class: Annotated[ + Optional[OutputResponseBlobAccessTier], pydantic.Field(alias="storageClass") + ] = None + r"""Blob access tier""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -14286,11 +13838,55 @@ class OutputResponseOutputFilesystem(BaseModel): ) r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + connection_string: Annotated[ + Optional[str], pydantic.Field(alias="connectionString") + ] = None + r"""Enter your Azure Storage account connection string. If left blank, Stream will fall back to env.AZURE_STORAGE_CONNECTION_STRING.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="storageAccountName") + ] = None + r"""The name of your Azure storage account""" + + tenant_id: Annotated[Optional[str], pydantic.Field(alias="tenantId")] = None + r"""The service principal's tenant ID""" + + client_id: Annotated[Optional[str], pydantic.Field(alias="clientId")] = None + r"""The service principal's client ID""" + + azure_cloud: Annotated[Optional[str], pydantic.Field(alias="azureCloud")] = None + r"""The Azure cloud to use. Defaults to Azure Public Cloud.""" + + endpoint_suffix: Annotated[ + Optional[str], pydantic.Field(alias="endpointSuffix") + ] = None + r"""Endpoint suffix for the service URL. Takes precedence over the Azure Cloud setting. Defaults to core.windows.net.""" + + client_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="clientTextSecret") + ] = None + r"""Select or create a stored text secret""" + + certificate: Optional[CertificateType] = None + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_container_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_containerName") + ] = None + r"""Binds 'containerName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'containerName' at runtime.""" + + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") + ] = None + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: Annotated[ Optional[str], pydantic.Field(alias="__template_partitionExpr") ] = None @@ -14326,7 +13922,32 @@ class OutputResponseOutputFilesystem(BaseModel): ] = None r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_connection_string: Annotated[ + Optional[str], pydantic.Field(alias="__template_connectionString") + ] = None + r"""Binds 'connectionString' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'connectionString' at runtime.""" + + template_storage_account_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageAccountName") + ] = None + r"""Binds 'storageAccountName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageAccountName' at runtime.""" + + template_tenant_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_tenantId") + ] = None + r"""Binds 'tenantId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'tenantId' at runtime.""" + + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_clientId") + ] = None + r"""Binds 'clientId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'clientId' at runtime.""" + + template_azure_cloud: Annotated[ + Optional[str], pydantic.Field(alias="__template_azureCloud") + ] = None + r"""Binds 'azureCloud' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'azureCloud' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None @@ -14359,6 +13980,24 @@ def serialize_on_disk_full_backpressure(self, value): return value return value + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptions(value) + except ValueError: + return value + return value + + @field_serializer("storage_class") + def serialize_storage_class(self, value): + if isinstance(value, str): + try: + return models.OutputResponseBlobAccessTier(value) + except ValueError: + return value + return value + @field_serializer("compress") def serialize_compress(self, value): if isinstance(value, str): @@ -14404,8 +14043,10 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "stagePath", + "createContainer", + "destPath", "addIdToStagePath", + "maxConcurrentFileParts", "removeEmptyDirs", "partitionExpr", "format", @@ -14423,6 +14064,8 @@ def serialize_model(self, handler): "forceCloseOnShutdown", "retrySettings", "orphans", + "authType", + "storageClass", "description", "compress", "compressionLevel", @@ -14441,7 +14084,18 @@ def serialize_model(self, handler): "directoryBatchSize", "deadletterPath", "maxRetryNum", + "connectionString", + "textSecret", + "storageAccountName", + "tenantId", + "clientId", + "azureCloud", + "endpointSuffix", + "clientTextSecret", + "certificate", "__template_streamtags", + "__template_containerName", + "__template_destPath", "__template_partitionExpr", "__template_format", "__template_baseFileName", @@ -14449,6 +14103,11 @@ def serialize_model(self, handler): "__template_onBackpressure", "__template_compress", "__template_parquetSchema", + "__template_connectionString", + "__template_storageAccountName", + "__template_tenantId", + "__template_clientId", + "__template_azureCloud", "notifications", "status", ] @@ -14467,25 +14126,13 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSignalfxType(str, Enum): - r"""Connector type identifier.""" - - SIGNALFX = "signalfx" - - -class OutputResponseOutputSignalfxPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputSignalfxPqControls(BaseModel): - r"""Persistent queue controls.""" - - -class OutputResponseOutputSignalfxTypedDict(TypedDict): - type: OutputResponseOutputSignalfxType +class OutputResponseOutputS3TypedDict(TypedDict): + type: TypeOptionsS3 r"""Connector type identifier.""" - realm: str - r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + stage_path: str + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -14496,92 +14143,172 @@ class OutputResponseOutputSignalfxTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" + endpoint: NotRequired[str] + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + enable_assume_role: NotRequired[bool] + r"""Use Assume Role credentials to access S3""" + assume_role_arn: NotRequired[str] + r"""Amazon Resource Name (ARN) of the role to assume""" + assume_role_external_id: NotRequired[str] + r"""External ID to use when assuming role""" + duration_seconds: NotRequired[float] + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" + aws_authentication_method: NotRequired[AuthenticationMethodOptionsS3CollectorConf] + r"""AWS authentication method. Choose Auto to use IAM roles.""" + reuse_connections: NotRequired[bool] + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" + region: NotRequired[str] + r"""Region where the S3 bucket is located""" + dest_path: NotRequired[str] + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + max_concurrent_file_parts: NotRequired[float] + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" + verify_permissions: NotRequired[bool] + r"""Disable if you can access files within the bucket but not the bucket itself""" + max_closing_files_to_backpressure: NotRequired[float] + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" + aws_secret_key: NotRequired[str] + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + object_acl: NotRequired[ObjectACLOptions] + r"""Object ACL to assign to uploaded objects""" + storage_class: NotRequired[StorageClassOptions] + r"""Storage class to select for uploaded objects""" + server_side_encryption: NotRequired[ServerSideEncryptionForUploadedObjectsOptions] + r"""Server-side encryption to use for uploaded objects""" + kms_key_id: NotRequired[str] + r"""ID or ARN of the KMS customer-managed key to use for encryption""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSignalfxPqControlsTypedDict] - r"""Persistent queue controls.""" + aws_api_key: NotRequired[str] + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + aws_secret: NotRequired[str] + r"""Select or create a stored secret that references your access key and secret key""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_endpoint: NotRequired[str] + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" + template_assume_role_arn: NotRequired[str] + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" + template_assume_role_external_id: NotRequired[str] + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" + template_bucket: NotRequired[str] + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" + template_region: NotRequired[str] + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" + template_dest_path: NotRequired[str] + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_aws_secret_key: NotRequired[str] + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" + template_object_acl: NotRequired[str] + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" + template_storage_class: NotRequired[str] + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" + template_server_side_encryption: NotRequired[str] + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" + template_kms_key_id: NotRequired[str] + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" + template_aws_api_key: NotRequired[str] + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSignalfx(BaseModel): - type: OutputResponseOutputSignalfxType +class OutputResponseOutputS3(BaseModel): + type: TypeOptionsS3 r"""Connector type identifier.""" - realm: str - r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + bucket: str + r"""Name of the destination S3 bucket. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at initialization time. Example referencing a Global Variable: `myBucket-${C.vars.myVar}`""" + + stage_path: Annotated[str, pydantic.Field(alias="stagePath")] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -14600,190 +14327,390 @@ class OutputResponseOutputSignalfx(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + endpoint: Optional[str] = None + r"""S3 service endpoint. If empty, defaults to the AWS Region-specific endpoint. Otherwise, it must point to S3-compatible endpoint.""" + + enable_assume_role: Annotated[ + Optional[bool], pydantic.Field(alias="enableAssumeRole") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""Use Assume Role credentials to access S3""" - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + assume_role_arn: Annotated[Optional[str], pydantic.Field(alias="assumeRoleArn")] = ( + None + ) + r"""Amazon Resource Name (ARN) of the role to assume""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="assumeRoleExternalId") ] = None - r"""Maximum size, in KB, of the request body""" + r"""External ID to use when assuming role""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + duration_seconds: Annotated[ + Optional[float], pydantic.Field(alias="durationSeconds") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Duration of the assumed role's session, in seconds. Minimum is 900 (15 minutes), default is 3600 (1 hour), and maximum is 43200 (12 hours).""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + aws_authentication_method: Annotated[ + Optional[AuthenticationMethodOptionsS3CollectorConf], + pydantic.Field(alias="awsAuthenticationMethod"), + ] = None + r"""AWS authentication method. Choose Auto to use IAM roles.""" + + reuse_connections: Annotated[ + Optional[bool], pydantic.Field(alias="reuseConnections") + ] = None + r"""Reuse connections between requests, which can improve performance""" reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + r"""Reject certificates that cannot be verified against a valid CA, such as self-signed certificates""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + region: Optional[str] = None + r"""Region where the S3 bucket is located""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + dest_path: Annotated[Optional[str], pydantic.Field(alias="destPath")] = None + r"""Prefix to prepend to files before uploading. Must be a JavaScript expression (which can evaluate to a constant value), enclosed in quotes or backticks. Can be evaluated only at init time. Example referencing a Global Variable: `myKeyPrefix-${C.vars.myVar}`""" + + max_concurrent_file_parts: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentFileParts") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""Maximum number of parts to upload in parallel per file. Minimum part size is 5MB.""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + verify_permissions: Annotated[ + Optional[bool], pydantic.Field(alias="verifyPermissions") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Disable if you can access files within the bucket but not the bucket itself""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + max_closing_files_to_backpressure: Annotated[ + Optional[float], pydantic.Field(alias="maxClosingFilesToBackpressure") ] = None - r"""Headers to add to all events""" + r"""Maximum number of files that can be waiting for upload before backpressure is applied""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") + ] = None + r"""Add the Output ID value to staging location""" + + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") + ] = None + r"""Remove empty staging directories after moving files""" + + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" + + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" + + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") + ] = None + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") + ] = None + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") + ] = None + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") + ] = None + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") + ] = None + r"""Buffer size used to write to a file""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") + ] = None + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), + ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") + ] = None + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") + ] = None + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" + + aws_secret_key: Annotated[Optional[str], pydantic.Field(alias="awsSecretKey")] = ( + None + ) + r"""Secret key. This value can be a constant or a JavaScript expression. Example: `${C.env.SOME_SECRET}`)""" + + object_acl: Annotated[ + Optional[ObjectACLOptions], pydantic.Field(alias="objectACL") + ] = None + r"""Object ACL to assign to uploaded objects""" + + storage_class: Annotated[ + Optional[StorageClassOptions], pydantic.Field(alias="storageClass") + ] = None + r"""Storage class to select for uploaded objects""" + + server_side_encryption: Annotated[ + Optional[ServerSideEncryptionForUploadedObjectsOptions], + pydantic.Field(alias="serverSideEncryption"), + ] = None + r"""Server-side encryption to use for uploaded objects""" + + kms_key_id: Annotated[Optional[str], pydantic.Field(alias="kmsKeyId")] = None + r"""ID or ARN of the KMS customer-managed key to use for encryption""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + aws_api_key: Annotated[Optional[str], pydantic.Field(alias="awsApiKey")] = None + r"""This value can be a constant or a JavaScript expression (`${C.env.SOME_ACCESS_KEY}`)""" + + aws_secret: Annotated[Optional[str], pydantic.Field(alias="awsSecret")] = None + r"""Select or create a stored secret that references your access key and secret key""" + + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" + + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" + + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") + ] = None + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") + ] = None + r"""Determines which data types are supported and how they are represented""" + + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") + ] = None + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") + ] = None + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") + ] = None + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), + ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""List of headers that are safe to log in plain text""" + r"""How frequently, in seconds, to clean up empty directories""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + template_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_endpoint") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Binds 'endpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'endpoint' at runtime.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + template_assume_role_arn: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleArn") + ] = None + r"""Binds 'assumeRoleArn' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleArn' at runtime.""" - token: Optional[str] = None - r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" + template_assume_role_external_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_assumeRoleExternalId") + ] = None + r"""Binds 'assumeRoleExternalId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'assumeRoleExternalId' at runtime.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + template_bucket: Annotated[ + Optional[str], pydantic.Field(alias="__template_bucket") + ] = None + r"""Binds 'bucket' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'bucket' at runtime.""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + template_region: Annotated[ + Optional[str], pydantic.Field(alias="__template_region") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Binds 'region' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'region' at runtime.""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + template_dest_path: Annotated[ + Optional[str], pydantic.Field(alias="__template_destPath") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Binds 'destPath' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'destPath' at runtime.""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") + ] = None + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + template_aws_secret_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsSecretKey") + ] = None + r"""Binds 'awsSecretKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsSecretKey' at runtime.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + template_object_acl: Annotated[ + Optional[str], pydantic.Field(alias="__template_objectACL") ] = None - r"""Codec to use to compress the persisted data""" + r"""Binds 'objectACL' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'objectACL' at runtime.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + template_storage_class: Annotated[ + Optional[str], pydantic.Field(alias="__template_storageClass") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Binds 'storageClass' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'storageClass' at runtime.""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + template_server_side_encryption: Annotated[ + Optional[str], pydantic.Field(alias="__template_serverSideEncryption") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""Binds 'serverSideEncryption' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'serverSideEncryption' at runtime.""" - pq_controls: Annotated[ - Optional[OutputResponseOutputSignalfxPqControls], - pydantic.Field(alias="pqControls"), + template_kms_key_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_kmsKeyId") ] = None - r"""Persistent queue controls.""" + r"""Binds 'kmsKeyId' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'kmsKeyId' at runtime.""" - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") + template_aws_api_key: Annotated[ + Optional[str], pydantic.Field(alias="__template_awsApiKey") ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + r"""Binds 'awsApiKey' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'awsApiKey' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("aws_authentication_method") + def serialize_aws_authentication_method(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsS3CollectorConf(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DataFormatOptions(value) except ValueError: return value return value @@ -14792,34 +14719,79 @@ def serialize_failed_request_logging_mode(self, value): def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("object_acl") + def serialize_object_acl(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ObjectACLOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("storage_class") + def serialize_storage_class(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.StorageClassOptions(value) + except ValueError: + return value + return value + + @field_serializer("server_side_encryption") + def serialize_server_side_encryption(self, value): + if isinstance(value, str): + try: + return models.ServerSideEncryptionForUploadedObjectsOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsHTTP(value) + except ValueError: + return value + return value + + @field_serializer("compression_level") + def serialize_compression_level(self, value): + if isinstance(value, str): + try: + return models.CompressionLevelOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): + if isinstance(value, str): + try: + return models.ParquetVersionOptions(value) + except ValueError: + return value + return value + + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): + if isinstance(value, str): + try: + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -14833,41 +14805,82 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", + "endpoint", + "enableAssumeRole", + "assumeRoleArn", + "assumeRoleExternalId", + "durationSeconds", + "awsAuthenticationMethod", + "reuseConnections", "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "region", + "destPath", + "maxConcurrentFileParts", + "verifyPermissions", + "maxClosingFilesToBackpressure", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", + "awsSecretKey", + "objectACL", + "storageClass", + "serverSideEncryption", + "kmsKeyId", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "awsApiKey", + "awsSecret", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_endpoint", + "__template_assumeRoleArn", + "__template_assumeRoleExternalId", + "__template_bucket", + "__template_region", + "__template_destPath", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_awsSecretKey", + "__template_objectACL", + "__template_storageClass", + "__template_serverSideEncryption", + "__template_kmsKeyId", + "__template_awsApiKey", + "__template_compress", + "__template_parquetSchema", "notifications", "status", ] @@ -14886,25 +14899,17 @@ def serialize_model(self, handler): return m -class OutputResponseOutputWavefrontType(str, Enum): +class OutputResponseOutputFilesystemType(str, Enum): r"""Connector type identifier.""" - WAVEFRONT = "wavefront" - - -class OutputResponseOutputWavefrontPqControlsTypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputWavefrontPqControls(BaseModel): - r"""Persistent queue controls.""" + FILESYSTEM = "filesystem" -class OutputResponseOutputWavefrontTypedDict(TypedDict): - type: OutputResponseOutputWavefrontType +class OutputResponseOutputFilesystemTypedDict(TypedDict): + type: OutputResponseOutputFilesystemType r"""Connector type identifier.""" - domain: str - r"""WaveFront domain name, e.g. \"longboard\" """ + dest_path: str + r"""Final destination for the output files""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -14915,92 +14920,107 @@ class OutputResponseOutputWavefrontTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] + stage_path: NotRequired[str] + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" + add_id_to_stage_path: NotRequired[bool] + r"""Add the Output ID value to staging location""" + remove_empty_dirs: NotRequired[bool] + r"""Remove empty staging directories after moving files""" + partition_expr: NotRequired[str] + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" + format_: NotRequired[DataFormatOptions] + r"""Format of the output data""" + base_file_name: NotRequired[str] + r"""JavaScript expression to define the output filename prefix (can be constant)""" + file_name_suffix: NotRequired[str] + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" + max_file_size_mb: NotRequired[float] + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" + max_file_open_time_sec: NotRequired[float] + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" + max_file_idle_time_sec: NotRequired[float] + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" + max_open_files: NotRequired[float] + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + header_line: NotRequired[str] + r"""If set, this line will be written to the beginning of each output file""" + write_high_water_mark: NotRequired[float] + r"""Buffer size used to write to a file""" + on_backpressure: NotRequired[BackpressureBehaviorOptionsBlockDrop] r"""How to handle events when all receivers are exerting backpressure""" + deadletter_enabled: NotRequired[bool] + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" + on_disk_full_backpressure: NotRequired[DiskSpaceProtectionOptions] + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" + force_close_on_shutdown: NotRequired[bool] + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" + retry_settings: NotRequired[RetrySettingsTypeTypedDict] + orphans: NotRequired[OrphanFileRecoveryTypeTypedDict] + r"""Orphan file recovery""" description: NotRequired[str] r"""Optional description for this configuration.""" - token: NotRequired[str] - r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - pq_strict_ordering: NotRequired[bool] - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" - pq_rate_per_sec: NotRequired[float] - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" - pq_mode: NotRequired[ModeOptions] - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" - pq_max_buffer_size: NotRequired[float] - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" - pq_max_backpressure_sec: NotRequired[float] - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" - pq_max_file_size: NotRequired[str] - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" - pq_max_size: NotRequired[str] - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" - pq_path: NotRequired[str] - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" - pq_compress: NotRequired[CompressionOptionsPq] - r"""Codec to use to compress the persisted data""" - pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" - pq_max_buffer_size_bytes: NotRequired[str] - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputWavefrontPqControlsTypedDict] - r"""Persistent queue controls.""" + compress: NotRequired[CompressionOptionsHTTP] + r"""Data compression format to apply to HTTP content before it is delivered""" + compression_level: NotRequired[CompressionLevelOptions] + r"""Compression level to apply before moving files to final destination""" + automatic_schema: NotRequired[bool] + r"""Automatically calculate the schema based on the events of each Parquet file generated""" + parquet_schema: NotRequired[str] + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + parquet_version: NotRequired[ParquetVersionOptions] + r"""Determines which data types are supported and how they are represented""" + parquet_data_page_version: NotRequired[DataPageVersionOptions] + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" + parquet_row_group_length: NotRequired[float] + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" + parquet_page_size: NotRequired[str] + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" + should_log_invalid_rows: NotRequired[bool] + r"""Log up to 3 rows that @{product} skips due to data mismatch""" + key_value_metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ + enable_statistics: NotRequired[bool] + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" + enable_write_page_index: NotRequired[bool] + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" + enable_page_checksum: NotRequired[bool] + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" + empty_dir_cleanup_sec: NotRequired[float] + r"""How frequently, in seconds, to clean up empty directories""" + directory_batch_size: NotRequired[float] + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + deadletter_path: NotRequired[str] + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + max_retry_num: NotRequired[float] + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_partition_expr: NotRequired[str] + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + template_format: NotRequired[str] + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + template_base_file_name: NotRequired[str] + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + template_file_name_suffix: NotRequired[str] + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_parquet_schema: NotRequired[str] + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputWavefront(BaseModel): - type: OutputResponseOutputWavefrontType +class OutputResponseOutputFilesystem(BaseModel): + type: OutputResponseOutputFilesystemType r"""Connector type identifier.""" - domain: str - r"""WaveFront domain name, e.g. \"longboard\" """ + dest_path: Annotated[str, pydantic.Field(alias="destPath")] + r"""Final destination for the output files""" id: Optional[str] = None r"""Unique ID for this output""" @@ -15019,226 +15039,288 @@ class OutputResponseOutputWavefront(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + stage_path: Annotated[Optional[str], pydantic.Field(alias="stagePath")] = None + r"""Filesystem location in which to buffer files, before compressing and moving to final destination. Use performant and stable storage.""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + add_id_to_stage_path: Annotated[ + Optional[bool], pydantic.Field(alias="addIdToStagePath") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Add the Output ID value to staging location""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + remove_empty_dirs: Annotated[ + Optional[bool], pydantic.Field(alias="removeEmptyDirs") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + r"""Remove empty staging directories after moving files""" - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + partition_expr: Annotated[Optional[str], pydantic.Field(alias="partitionExpr")] = ( + None + ) + r"""JavaScript expression defining how files are partitioned and organized. Default is date-based. If blank, Stream will fall back to the event's __partition field value – if present – otherwise to each location's root directory.""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ + format_: Annotated[Optional[DataFormatOptions], pydantic.Field(alias="format")] = ( + None + ) + r"""Format of the output data""" - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + base_file_name: Annotated[Optional[str], pydantic.Field(alias="baseFileName")] = ( + None + ) + r"""JavaScript expression to define the output filename prefix (can be constant)""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="fileNameSuffix") ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + r"""JavaScript expression to define the output filename suffix (can be constant). The `__format` variable refers to the value of the `Data format` field (`json` or `raw`). The `__compression` field refers to the kind of compression being used (`none` or `gzip`).""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + max_file_size_mb: Annotated[ + Optional[float], pydantic.Field(alias="maxFileSizeMB") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Maximum uncompressed output file size. Files of this size will be closed and moved to final output location.""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), + max_file_open_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileOpenTimeSec") ] = None - r"""Headers to add to all events""" + r"""Maximum amount of time to write to a file. Files open for longer than this will be closed and moved to final output location.""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") + max_file_idle_time_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxFileIdleTimeSec") ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + r"""Maximum amount of time to keep inactive files open. Files open for longer than this will be closed and moved to final output location.""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + max_open_files: Annotated[Optional[float], pydantic.Field(alias="maxOpenFiles")] = ( + None + ) + r"""Maximum number of files to keep open concurrently. When exceeded, @{product} will close the oldest open files and move them to the final output location.""" + + header_line: Annotated[Optional[str], pydantic.Field(alias="headerLine")] = None + r"""If set, this line will be written to the beginning of each output file""" + + write_high_water_mark: Annotated[ + Optional[float], pydantic.Field(alias="writeHighWaterMark") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""Buffer size used to write to a file""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptionsBlockDrop], + pydantic.Field(alias="onBackpressure"), ] = None - r"""List of headers that are safe to log in plain text""" + r"""How to handle events when all receivers are exerting backpressure""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), + deadletter_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="deadletterEnabled") ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + r"""If a file fails to move to its final destination after the maximum number of retries, move it to a designated directory to prevent further errors""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + on_disk_full_backpressure: Annotated[ + Optional[DiskSpaceProtectionOptions], + pydantic.Field(alias="onDiskFullBackpressure"), ] = None + r"""How to handle events when disk space is below the global 'Min free disk space' limit""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + force_close_on_shutdown: Annotated[ + Optional[bool], pydantic.Field(alias="forceCloseOnShutdown") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Force all staged files to close during an orderly Node shutdown. This triggers immediate upload of in-progress data — regardless of idle time, file age, or size thresholds — to minimize data loss.""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + retry_settings: Annotated[ + Optional[RetrySettingsType], pydantic.Field(alias="retrySettings") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + + orphans: Optional[OrphanFileRecoveryType] = None + r"""Orphan file recovery""" description: Optional[str] = None r"""Optional description for this configuration.""" - token: Optional[str] = None - r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" + compress: Optional[CompressionOptionsHTTP] = None + r"""Data compression format to apply to HTTP content before it is delivered""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + compression_level: Annotated[ + Optional[CompressionLevelOptions], pydantic.Field(alias="compressionLevel") + ] = None + r"""Compression level to apply before moving files to final destination""" - pq_strict_ordering: Annotated[ - Optional[bool], pydantic.Field(alias="pqStrictOrdering") + automatic_schema: Annotated[ + Optional[bool], pydantic.Field(alias="automaticSchema") ] = None - r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + r"""Automatically calculate the schema based on the events of each Parquet file generated""" - pq_rate_per_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqRatePerSec") + parquet_schema: Annotated[Optional[str], pydantic.Field(alias="parquetSchema")] = ( + None + ) + r"""To add a new schema, navigate to Processing > Knowledge > Parquet Schemas""" + + parquet_version: Annotated[ + Optional[ParquetVersionOptions], pydantic.Field(alias="parquetVersion") ] = None - r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + r"""Determines which data types are supported and how they are represented""" - pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None - r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + parquet_data_page_version: Annotated[ + Optional[DataPageVersionOptions], pydantic.Field(alias="parquetDataPageVersion") + ] = None + r"""Serialization format of data pages. Note that some reader implementations use Data page V2's attributes to work more efficiently, while others ignore it.""" - pq_max_buffer_size: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBufferSize") + parquet_row_group_length: Annotated[ + Optional[float], pydantic.Field(alias="parquetRowGroupLength") ] = None - r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + r"""The number of rows that every group will contain. The final group can contain a smaller number of rows.""" - pq_max_backpressure_sec: Annotated[ - Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + parquet_page_size: Annotated[ + Optional[str], pydantic.Field(alias="parquetPageSize") ] = None - r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + r"""Target memory size for page segments, such as 1MB or 128MB. Generally, lower values improve reading speed, while higher values improve compression.""" - pq_max_file_size: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxFileSize") + should_log_invalid_rows: Annotated[ + Optional[bool], pydantic.Field(alias="shouldLogInvalidRows") ] = None - r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + r"""Log up to 3 rows that @{product} skips due to data mismatch""" - pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None - r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + key_value_metadata: Annotated[ + Optional[List[KeyValueMetadataConfOutputFilesystem]], + pydantic.Field(alias="keyValueMetadata"), + ] = None + r"""The metadata of files the Destination writes will include the properties you add here as key-value pairs. Useful for tagging. Examples: \"key\":\"OCSF Event Class\", \"value\":\"9001\" """ - pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None - r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + enable_statistics: Annotated[ + Optional[bool], pydantic.Field(alias="enableStatistics") + ] = None + r"""Statistics profile an entire file in terms of minimum/maximum values within data, numbers of nulls, etc. You can use Parquet tools to view statistics.""" - pq_compress: Annotated[ - Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + enable_write_page_index: Annotated[ + Optional[bool], pydantic.Field(alias="enableWritePageIndex") ] = None - r"""Codec to use to compress the persisted data""" + r"""One page index contains statistics for one data page. Parquet readers use statistics to enable page skipping.""" - pq_on_backpressure: Annotated[ - Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + enable_page_checksum: Annotated[ + Optional[bool], pydantic.Field(alias="enablePageChecksum") ] = None - r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + r"""Parquet tools can use the checksum of a Parquet page to verify data integrity""" - pq_max_buffer_size_bytes: Annotated[ - Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + empty_dir_cleanup_sec: Annotated[ + Optional[float], pydantic.Field(alias="emptyDirCleanupSec") ] = None - r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + r"""How frequently, in seconds, to clean up empty directories""" - pq_controls: Annotated[ - Optional[OutputResponseOutputWavefrontPqControls], - pydantic.Field(alias="pqControls"), + directory_batch_size: Annotated[ + Optional[float], pydantic.Field(alias="directoryBatchSize") ] = None - r"""Persistent queue controls.""" + r"""Number of directories to process in each batch during cleanup of empty directories. Minimum is 10, maximum is 10000. Higher values may require more memory.""" + + deadletter_path: Annotated[ + Optional[str], pydantic.Field(alias="deadletterPath") + ] = None + r"""Storage location for files that fail to reach their final destination after maximum retries are exceeded""" + + max_retry_num: Annotated[Optional[float], pydantic.Field(alias="maxRetryNum")] = ( + None + ) + r"""The maximum number of times a file will attempt to move to its final destination before being dead-lettered""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + template_partition_expr: Annotated[ + Optional[str], pydantic.Field(alias="__template_partitionExpr") ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + r"""Binds 'partitionExpr' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'partitionExpr' at runtime.""" + + template_format: Annotated[ + Optional[str], pydantic.Field(alias="__template_format") + ] = None + r"""Binds 'format' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'format' at runtime.""" + + template_base_file_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_baseFileName") + ] = None + r"""Binds 'baseFileName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'baseFileName' at runtime.""" + + template_file_name_suffix: Annotated[ + Optional[str], pydantic.Field(alias="__template_fileNameSuffix") + ] = None + r"""Binds 'fileNameSuffix' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'fileNameSuffix' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + template_parquet_schema: Annotated[ + Optional[str], pydantic.Field(alias="__template_parquetSchema") + ] = None + r"""Binds 'parquetSchema' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'parquetSchema' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("format_") + def serialize_format_(self, value): + if isinstance(value, str): + try: + return models.DataFormatOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptionsBlockDrop(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("on_disk_full_backpressure") + def serialize_on_disk_full_backpressure(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.DiskSpaceProtectionOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptionsHTTP(value) except ValueError: return value return value - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): + @field_serializer("compression_level") + def serialize_compression_level(self, value): if isinstance(value, str): try: - return models.ModeOptions(value) + return models.CompressionLevelOptions(value) except ValueError: return value return value - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): + @field_serializer("parquet_version") + def serialize_parquet_version(self, value): if isinstance(value, str): try: - return models.CompressionOptionsPq(value) + return models.ParquetVersionOptions(value) except ValueError: return value return value - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): + @field_serializer("parquet_data_page_version") + def serialize_parquet_data_page_version(self, value): if isinstance(value, str): try: - return models.QueueFullBehaviorOptions(value) + return models.DataPageVersionOptions(value) except ValueError: return value return value @@ -15252,41 +15334,51 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "authType", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + "stagePath", + "addIdToStagePath", + "removeEmptyDirs", + "partitionExpr", + "format", + "baseFileName", + "fileNameSuffix", + "maxFileSizeMB", + "maxFileOpenTimeSec", + "maxFileIdleTimeSec", + "maxOpenFiles", + "headerLine", + "writeHighWaterMark", "onBackpressure", + "deadletterEnabled", + "onDiskFullBackpressure", + "forceCloseOnShutdown", + "retrySettings", + "orphans", "description", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", + "compress", + "compressionLevel", + "automaticSchema", + "parquetSchema", + "parquetVersion", + "parquetDataPageVersion", + "parquetRowGroupLength", + "parquetPageSize", + "shouldLogInvalidRows", + "keyValueMetadata", + "enableStatistics", + "enableWritePageIndex", + "enablePageChecksum", + "emptyDirCleanupSec", + "directoryBatchSize", + "deadletterPath", + "maxRetryNum", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_partitionExpr", + "__template_format", + "__template_baseFileName", + "__template_fileNameSuffix", "__template_onBackpressure", + "__template_compress", + "__template_parquetSchema", "notifications", "status", ] @@ -15305,17 +15397,25 @@ def serialize_model(self, handler): return m -class OutputResponseOutputTcpjsonPqControlsTypedDict(TypedDict): +class OutputResponseOutputSignalfxType(str, Enum): + r"""Connector type identifier.""" + + SIGNALFX = "signalfx" + + +class OutputResponseOutputSignalfxPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputTcpjsonPqControls(BaseModel): +class OutputResponseOutputSignalfxPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputTcpjsonTypedDict(TypedDict): - type: TypeOptionsTcpjson +class OutputResponseOutputSignalfxTypedDict(TypedDict): + type: OutputResponseOutputSignalfxType r"""Connector type identifier.""" + realm: str + r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -15326,44 +15426,50 @@ class OutputResponseOutputTcpjsonTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - load_balanced: NotRequired[bool] - r"""Use load-balanced destinations""" - compression: NotRequired[CompressionOptionsGzipNone] - r"""Codec to use to compress the data before sending""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] - r"""TLS settings (client side)""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - token_ttl_minutes: NotRequired[float] - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - send_header: NotRequired[bool] - r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + token: NotRequired[str] + r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -15386,30 +15492,27 @@ class OutputResponseOutputTcpjsonTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputTcpjsonPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSignalfxPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Optional authentication token to include as part of the connection header""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputTcpjson(BaseModel): - type: TypeOptionsTcpjson +class OutputResponseOutputSignalfx(BaseModel): + type: OutputResponseOutputSignalfxType r"""Connector type identifier.""" + realm: str + r"""SignalFx realm name, e.g. \"us0\". For a complete list of available SignalFx realm names, please check [here](https://docs.splunk.com/observability/en/get-started/service-description.html#sd-regions).""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -15427,85 +15530,99 @@ class OutputResponseOutputTcpjson(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Use load-balanced destinations""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - compression: Optional[CompressionOptionsGzipNone] = None - r"""Codec to use to compress the data before sending""" + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") + ] = None + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Headers to add to all events""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""List of headers that are safe to log in plain text""" - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - token_ttl_minutes: Annotated[ - Optional[float], pydantic.Field(alias="tokenTTLMinutes") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - send_header: Annotated[Optional[bool], pydantic.Field(alias="sendHeader")] = None - r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None r"""How to handle events when all receivers are exerting backpressure""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - description: Optional[str] = None r"""Optional description for this configuration.""" - host: Optional[str] = None - r"""The hostname of the receiver""" - - port: Optional[float] = None - r"""The port to connect to on the provided host""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + token: Optional[str] = None + r"""SignalFx API access token (see [here](https://docs.signalfx.com/en/latest/admin-guide/tokens.html#working-with-access-tokens))""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") - ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -15557,66 +15674,55 @@ class OutputResponseOutputTcpjson(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputTcpjsonPqControls], + Optional[OutputResponseOutputSignalfxPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Optional authentication token to include as part of the connection header""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("compression") - def serialize_compression(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.CompressionOptionsGzipNone(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -15657,25 +15763,26 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "loadBalanced", - "compression", - "logFailedRequests", - "throttleRatePerSec", - "tls", - "connectionTimeout", - "writeTimeout", - "tokenTTLMinutes", - "sendHeader", - "onBackpressure", "authType", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "useRoundRobinDns", + "failedRequestLoggingMode", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "host", - "port", - "excludeSelf", - "hosts", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -15688,12 +15795,9 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_host", - "__template_port", "notifications", "status", ] @@ -15712,31 +15816,25 @@ def serialize_model(self, handler): return m -class OutputResponseOutputWizHecType(str, Enum): +class OutputResponseOutputWavefrontType(str, Enum): r"""Connector type identifier.""" - WIZ_HEC = "wiz_hec" + WAVEFRONT = "wavefront" -class OutputResponseOutputWizHecPqControlsTypedDict(TypedDict): +class OutputResponseOutputWavefrontPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputWizHecPqControls(BaseModel): +class OutputResponseOutputWavefrontPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputWizHecTypedDict(TypedDict): - type: OutputResponseOutputWizHecType +class OutputResponseOutputWavefrontTypedDict(TypedDict): + type: OutputResponseOutputWavefrontType r"""Connector type identifier.""" - wiz_connector_id: str - r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" - wiz_environment: str - r"""Your Wiz deployment environment""" - data_center: str - r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - wiz_sourcetype: str - r"""Wiz Defend Source type""" + domain: str + r"""WaveFront domain name, e.g. \"longboard\" """ id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -15747,8 +15845,8 @@ class OutputResponseOutputWizHecTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] @@ -15770,12 +15868,12 @@ class OutputResponseOutputWizHecTypedDict(TypedDict): r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] r"""Headers to add to all events""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] ] @@ -15788,7 +15886,7 @@ class OutputResponseOutputWizHecTypedDict(TypedDict): description: NotRequired[str] r"""Optional description for this configuration.""" token: NotRequired[str] - r"""Wiz Defend Auth token""" + r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] @@ -15813,41 +15911,26 @@ class OutputResponseOutputWizHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputWizHecPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputWavefrontPqControlsTypedDict] r"""Persistent queue controls.""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_wiz_environment: NotRequired[str] - r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" - template_data_center: NotRequired[str] - r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" - template_wiz_sourcetype: NotRequired[str] - r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputWizHec(BaseModel): - type: OutputResponseOutputWizHecType +class OutputResponseOutputWavefront(BaseModel): + type: OutputResponseOutputWavefrontType r"""Connector type identifier.""" - wiz_connector_id: str - r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" - - wiz_environment: str - r"""Your Wiz deployment environment""" - - data_center: str - r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - - wiz_sourcetype: str - r"""Wiz Defend Source type""" + domain: str + r"""WaveFront domain name, e.g. \"longboard\" """ id: Optional[str] = None r"""Unique ID for this output""" @@ -15866,8 +15949,11 @@ class OutputResponseOutputWizHec(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: Optional[float] = None r"""Maximum number of ongoing requests before blocking""" @@ -15912,6 +15998,11 @@ class OutputResponseOutputWizHec(BaseModel): ] = None r"""Headers to add to all events""" + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + failed_request_logging_mode: Annotated[ Optional[FailedRequestLoggingModeOptions], pydantic.Field(alias="failedRequestLoggingMode"), @@ -15923,12 +16014,6 @@ class OutputResponseOutputWizHec(BaseModel): ] = None r"""List of headers that are safe to log in plain text""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: Annotated[ Optional[List[ResponseRetrySettingConfOutputWebhook]], pydantic.Field(alias="responseRetrySettings"), @@ -15953,7 +16038,7 @@ class OutputResponseOutputWizHec(BaseModel): r"""Optional description for this configuration.""" token: Optional[str] = None - r"""Wiz Defend Auth token""" + r"""WaveFront API authentication token (see [here](https://docs.wavefront.com/wavefront_api.html#generating-an-api-token))""" text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" @@ -16008,7 +16093,7 @@ class OutputResponseOutputWizHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputWizHecPqControls], + Optional[OutputResponseOutputWavefrontPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" @@ -16023,46 +16108,31 @@ class OutputResponseOutputWizHec(BaseModel): ] = None r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_wiz_environment: Annotated[ - Optional[str], pydantic.Field(alias="__template_wiz_environment") - ] = None - r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" - - template_data_center: Annotated[ - Optional[str], pydantic.Field(alias="__template_data_center") - ] = None - r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" - - template_wiz_sourcetype: Annotated[ - Optional[str], pydantic.Field(alias="__template_wiz_sourcetype") - ] = None - r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value @@ -16112,7 +16182,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "tls", + "authType", "concurrency", "maxPayloadSizeKB", "maxPayloadEvents", @@ -16122,9 +16192,9 @@ def serialize_model(self, handler): "maxConnectionReuseSec", "flushPeriodSec", "extraHttpHeaders", + "useRoundRobinDns", "failedRequestLoggingMode", "safeHeaders", - "authType", "responseRetrySettings", "timeoutRetrySettings", "responseHonorRetryAfterHeader", @@ -16146,9 +16216,6 @@ def serialize_model(self, handler): "pqControls", "__template_streamtags", "__template_failedRequestLoggingMode", - "__template_wiz_environment", - "__template_data_center", - "__template_wiz_sourcetype", "__template_onBackpressure", "notifications", "status", @@ -16168,60 +16235,16 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSplunkHecType(str, Enum): - r"""Connector type identifier.""" - - SPLUNK_HEC = "splunk_hec" - - -class OutputResponseOutputSplunkHecURLTypedDict(TypedDict): - url: str - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - -class OutputResponseOutputSplunkHecURL(BaseModel): - url: str - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputSplunkHecPqControlsTypedDict(TypedDict): +class OutputResponseOutputTcpjsonPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSplunkHecPqControls(BaseModel): +class OutputResponseOutputTcpjsonPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSplunkHecTypedDict(TypedDict): - type: OutputResponseOutputSplunkHecType +class OutputResponseOutputTcpjsonTypedDict(TypedDict): + type: TypeOptionsTcpjson r"""Connector type identifier.""" id: NotRequired[str] r"""Unique ID for this output""" @@ -16234,69 +16257,43 @@ class OutputResponseOutputSplunkHecTypedDict(TypedDict): streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] + r"""Use load-balanced destinations""" + compression: NotRequired[CompressionOptionsGzipNone] + r"""Codec to use to compress the data before sending""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - next_queue: NotRequired[str] - r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" - tcp_routing: NotRequired[str] - r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + token_ttl_minutes: NotRequired[float] + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" + send_header: NotRequired[bool] + r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - url: NotRequired[str] - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" exclude_self: NotRequired[bool] r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[OutputResponseOutputSplunkHecURLTypedDict]] - r"""Splunk HEC Endpoints""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" - token: NotRequired[str] - r"""Splunk HEC authentication token""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16319,24 +16316,28 @@ class OutputResponseOutputSplunkHecTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSplunkHecPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputTcpjsonPqControlsTypedDict] r"""Persistent queue controls.""" + auth_token: NotRequired[str] + r"""Optional authentication token to include as part of the connection header""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSplunkHec(BaseModel): - type: OutputResponseOutputSplunkHecType +class OutputResponseOutputTcpjson(BaseModel): + type: TypeOptionsTcpjson r"""Connector type identifier.""" id: Optional[str] = None @@ -16359,118 +16360,67 @@ class OutputResponseOutputSplunkHec(BaseModel): load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" + r"""Use load-balanced destinations""" - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" + compression: Optional[CompressionOptionsGzipNone] = None + r"""Codec to use to compress the data before sending""" - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" + r"""Use to troubleshoot issues with sending data""" - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events""" + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), + token_ttl_minutes: Annotated[ + Optional[float], pydantic.Field(alias="tokenTTLMinutes") ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + r"""The number of minutes before the internally generated authentication token expires, valid values between 1 and 60""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + send_header: Annotated[Optional[bool], pydantic.Field(alias="sendHeader")] = None + r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" - enable_multi_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="enableMultiMetrics") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" + r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None - - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - - next_queue: Annotated[Optional[str], pydantic.Field(alias="nextQueue")] = None - r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" - - tcp_routing: Annotated[Optional[str], pydantic.Field(alias="tcpRouting")] = None - r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" - - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" - description: Optional[str] = None r"""Optional description for this configuration.""" - url: Optional[str] = None - r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + host: Optional[str] = None + r"""The hostname of the receiver""" - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + port: Optional[float] = None + r"""The port to connect to on the provided host""" exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: Optional[List[OutputResponseOutputSplunkHecURL]] = None - r"""Splunk HEC Endpoints""" + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") @@ -16482,11 +16432,10 @@ class OutputResponseOutputSplunkHec(BaseModel): ] = None r"""How far back in time to keep traffic stats for load balancing purposes""" - token: Optional[str] = None - r"""Splunk HEC authentication token""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") + ] = None + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -16538,278 +16487,93 @@ class OutputResponseOutputSplunkHec(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSplunkHecPqControls], + Optional[OutputResponseOutputTcpjsonPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Optional authentication token to include as part of the connection header""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): - if isinstance(value, str): - try: - return models.FailedRequestLoggingModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.BackpressureBehaviorOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_mode") - def serialize_pq_mode(self, value): - if isinstance(value, str): - try: - return models.ModeOptions(value) - except ValueError: - return value - return value - - @field_serializer("pq_compress") - def serialize_pq_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptionsPq(value) - except ValueError: - return value - return value - - @field_serializer("pq_on_backpressure") - def serialize_pq_on_backpressure(self, value): - if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "pipeline", - "systemFields", - "environment", - "streamtags", - "loadBalanced", - "tls", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "failedRequestLoggingMode", - "safeHeaders", - "enableMultiMetrics", - "authType", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "nextQueue", - "tcpRouting", - "onBackpressure", - "description", - "url", - "useRoundRobinDns", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "token", - "textSecret", - "pqStrictOrdering", - "pqRatePerSec", - "pqMode", - "pqMaxBufferSize", - "pqMaxBackpressureSec", - "pqMaxFileSize", - "pqMaxSize", - "pqPath", - "pqCompress", - "pqOnBackpressure", - "pqMaxBufferSizeBytes", - "pqControls", - "__template_streamtags", - "__template_failedRequestLoggingMode", - "__template_onBackpressure", - "__template_url", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputSplunkLbType(str, Enum): - r"""Connector type identifier.""" - - SPLUNK_LB = "splunk_lb" - - -class OutputResponseAuthTokenTypedDict(TypedDict): - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class OutputResponseAuthToken(BaseModel): - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["authType", "authToken", "textSecret"]) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseIndexerDiscoveryConfigsTypedDict(TypedDict): - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - - site: str - r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" - master_uri: str - r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" - refresh_interval_sec: float - r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" - reject_unauthorized: NotRequired[bool] - r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" - auth_tokens: NotRequired[List[OutputResponseAuthTokenTypedDict]] - r"""Tokens required to authenticate to cluster manager for indexer discovery""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - auth_token: NotRequired[str] - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - - -class OutputResponseIndexerDiscoveryConfigs(BaseModel): - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - - site: str - r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" - - master_uri: Annotated[str, pydantic.Field(alias="masterUri")] - r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" - - refresh_interval_sec: Annotated[float, pydantic.Field(alias="refreshIntervalSec")] - r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - auth_tokens: Annotated[ - Optional[List[OutputResponseAuthToken]], pydantic.Field(alias="authTokens") - ] = None - r"""Tokens required to authenticate to cluster manager for indexer discovery""" + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), - ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" + @field_serializer("compression") + def serialize_compression(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsGzipNone(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value @field_serializer("auth_type") def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) except ValueError: return value return value @@ -16817,7 +16581,52 @@ def serialize_auth_type(self, value): @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( - ["rejectUnauthorized", "authTokens", "authType", "authToken", "textSecret"] + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "loadBalanced", + "compression", + "logFailedRequests", + "throttleRatePerSec", + "tls", + "connectionTimeout", + "writeTimeout", + "tokenTTLMinutes", + "sendHeader", + "onBackpressure", + "authType", + "description", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "authToken", + "textSecret", + "__template_streamtags", + "__template_onBackpressure", + "__template_host", + "__template_port", + "notifications", + "status", + ] ) serialized = handler(self) m = {} @@ -16833,19 +16642,51 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSplunkLbPqControlsTypedDict(TypedDict): +class OutputResponseOutputWizHecType(str, Enum): + r"""Connector type identifier.""" + + WIZ_HEC = "wiz_hec" + + +class OutputResponseWizDefendSourceType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" + + AWS_CLOUDTRAIL = "AWS_CLOUDTRAIL" + AWS_EKS_AUDIT_LOGS = "AWS_EKS_AUDIT_LOGS" + AWS_RESOLVER_QUERY_LOGS = "AWS_RESOLVER_QUERY_LOGS" + AZURE_ACTIVITY_LOGS = "AZURE_ACTIVITY_LOGS" + GCP_AUDIT_LOGS = "GCP_AUDIT_LOGS" + GITHUB_AUDIT_LOGS = "GITHUB_AUDIT_LOGS" + OCI_AUDIT_LOGS = "OCI_AUDIT_LOGS" + AWS_VPC_FLOW_LOGS = "AWS_VPC_FLOW_LOGS" + + +class OutputResponseEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The format of the VPC Flow Log events""" + + JSON = "json" + CSV_ROW = "csv_row" + + +class OutputResponseOutputWizHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSplunkLbPqControls(BaseModel): +class OutputResponseOutputWizHecPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSplunkLbTypedDict(TypedDict): - type: OutputResponseOutputSplunkLbType +class OutputResponseOutputWizHecTypedDict(TypedDict): + type: OutputResponseOutputWizHecType r"""Connector type identifier.""" - hosts: List[HostConfOutputSyslogTypedDict] - r"""Set of Splunk indexers to load-balance data to.""" + wiz_connector_id: str + r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" + wiz_environment: str + r"""Your Wiz deployment environment""" + data_center: str + r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" + wiz_sourcetype: OutputResponseWizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -16856,50 +16697,54 @@ class OutputResponseOutputSplunkLbTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" - max_concurrent_senders: NotRequired[float] - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - nested_fields: NotRequired[NestedFieldSerializationOptions] - r"""How to serialize nested fields into index-time fields""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" - enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - enable_ack: NotRequired[bool] - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - max_s2_sversion: NotRequired[MaxS2SVersionOptions] - r"""The highest S2S protocol version to advertise during handshake""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - indexer_discovery: NotRequired[bool] - r"""Automatically discover indexers in indexer clustering environment.""" - sender_unhealthy_time_allowance: NotRequired[float] - r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_failed_health_checks: NotRequired[float] - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - compress: NotRequired[CompressionOptions] - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" - indexer_discovery_configs: NotRequired[ - OutputResponseIndexerDiscoveryConfigsTypedDict - ] - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + token: NotRequired[str] + r"""Wiz Defend Auth token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + wiz_vpc_event_format: NotRequired[OutputResponseEventFormat] + r"""The format of the VPC Flow Log events""" + wiz_vpc_flow_log_format: NotRequired[str] + r"""The format string for VPC Flow Log fields""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -16922,34 +16767,41 @@ class OutputResponseOutputSplunkLbTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSplunkLbPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputWizHecPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_nested_fields: NotRequired[str] - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_max_s2_sversion: NotRequired[str] - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_wiz_environment: NotRequired[str] + r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" + template_data_center: NotRequired[str] + r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" + template_wiz_sourcetype: NotRequired[str] + r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSplunkLb(BaseModel): - type: OutputResponseOutputSplunkLbType +class OutputResponseOutputWizHec(BaseModel): + type: OutputResponseOutputWizHecType r"""Connector type identifier.""" - hosts: List[HostConfOutputSyslog] - r"""Set of Splunk indexers to load-balance data to.""" + wiz_connector_id: str + r"""The unique identifier for the specific Cribl connector defined in your Wiz Settings. This is used to cross-validate the bearer token and ensure traffic is originating from the authorized integration.""" + + wiz_environment: str + r"""Your Wiz deployment environment""" + + data_center: str + r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" + + wiz_sourcetype: OutputResponseWizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -16965,105 +16817,106 @@ class OutputResponseOutputSplunkLb(BaseModel): environment: Optional[str] = None r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + r"""Maximum size, in KB, of the request body""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - max_concurrent_senders: Annotated[ - Optional[float], pydantic.Field(alias="maxConcurrentSenders") - ] = None - r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + compress: Optional[bool] = None + r"""Compress the payload body before sending""" - nested_fields: Annotated[ - Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""How to serialize nested fields into index-time fields""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") - ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - enable_multi_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="enableMultiMetrics") + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), ] = None - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + r"""Headers to add to all events""" - enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""Use to troubleshoot issues with sending data""" + r"""List of headers that are safe to log in plain text""" - max_s2_sversion: Annotated[ - Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""The highest S2S protocol version to advertise during handshake""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - indexer_discovery: Annotated[ - Optional[bool], pydantic.Field(alias="indexerDiscovery") + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") ] = None - r"""Automatically discover indexers in indexer clustering environment.""" - sender_unhealthy_time_allowance: Annotated[ - Optional[float], pydantic.Field(alias="senderUnhealthyTimeAllowance") + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") ] = None - r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], - pydantic.Field(alias="authType"), + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + r"""How to handle events when all receivers are exerting backpressure""" description: Optional[str] = None r"""Optional description for this configuration.""" - max_failed_health_checks: Annotated[ - Optional[float], pydantic.Field(alias="maxFailedHealthChecks") - ] = None - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + token: Optional[str] = None + r"""Wiz Defend Auth token""" - compress: Optional[CompressionOptions] = None - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" - indexer_discovery_configs: Annotated[ - Optional[OutputResponseIndexerDiscoveryConfigs], - pydantic.Field(alias="indexerDiscoveryConfigs"), - ] = None - r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + wiz_vpc_event_format: Optional[OutputResponseEventFormat] = None + r"""The format of the VPC Flow Log events""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + wiz_vpc_flow_log_format: Optional[str] = None + r"""The format string for VPC Flow Log fields""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17115,89 +16968,88 @@ class OutputResponseOutputSplunkLb(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSplunkLbPqControls], + Optional[OutputResponseOutputWizHecPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_nested_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_nestedFields") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - template_max_s2_sversion: Annotated[ - Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + template_wiz_environment: Annotated[ + Optional[str], pydantic.Field(alias="__template_wiz_environment") ] = None - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + r"""Binds 'wiz_environment' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_environment' at runtime.""" + + template_data_center: Annotated[ + Optional[str], pydantic.Field(alias="__template_data_center") + ] = None + r"""Binds 'data_center' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'data_center' at runtime.""" + + template_wiz_sourcetype: Annotated[ + Optional[str], pydantic.Field(alias="__template_wiz_sourcetype") + ] = None + r"""Binds 'wiz_sourcetype' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'wiz_sourcetype' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("nested_fields") - def serialize_nested_fields(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.NestedFieldSerializationOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.MaxS2SVersionOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("wiz_sourcetype") + def serialize_wiz_sourcetype(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.OutputResponseWizDefendSourceType(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("compress") - def serialize_compress(self, value): + @field_serializer("wiz_vpc_event_format") + def serialize_wiz_vpc_event_format(self, value): if isinstance(value, str): try: - return models.CompressionOptions(value) + return models.OutputResponseEventFormat(value) except ValueError: return value return value @@ -17238,27 +17090,28 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", - "maxConcurrentSenders", - "nestedFields", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", "tls", - "enableMultiMetrics", - "enableACK", - "logFailedRequests", - "maxS2Sversion", - "onBackpressure", - "indexerDiscovery", - "senderUnhealthyTimeAllowance", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", "authType", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "onBackpressure", "description", - "maxFailedHealthChecks", - "compress", - "indexerDiscoveryConfigs", - "excludeSelf", + "token", + "textSecret", + "wiz_vpc_event_format", + "wiz_vpc_flow_log_format", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17271,13 +17124,12 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", - "__template_nestedFields", - "__template_maxS2Sversion", + "__template_failedRequestLoggingMode", + "__template_wiz_environment", + "__template_data_center", + "__template_wiz_sourcetype", "__template_onBackpressure", - "__template_compress", "notifications", "status", ] @@ -17296,21 +17148,61 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSplunkPqControlsTypedDict(TypedDict): +class OutputResponseOutputSplunkHecType(str, Enum): + r"""Connector type identifier.""" + + SPLUNK_HEC = "splunk_hec" + + +class OutputResponseOutputSplunkHecURLTypedDict(TypedDict): + url: str + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + weight: NotRequired[float] + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + +class OutputResponseOutputSplunkHecURL(BaseModel): + url: str + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + + weight: Optional[float] = None + r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["weight", "__template_url"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseOutputSplunkHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSplunkPqControls(BaseModel): +class OutputResponseOutputSplunkHecPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSplunkTypedDict(TypedDict): - type: TypeOptionsSplunk +class OutputResponseOutputSplunkHecTypedDict(TypedDict): + type: OutputResponseOutputSplunkHecType r"""Connector type identifier.""" - host: str - r"""The hostname of the receiver""" - port: float - r"""The port to connect to on the provided host""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -17321,34 +17213,70 @@ class OutputResponseOutputSplunkTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - nested_fields: NotRequired[NestedFieldSerializationOptions] - r"""How to serialize nested fields into index-time fields""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - connection_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - write_timeout: NotRequired[float] - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + load_balanced: NotRequired[bool] + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] r"""TLS settings (client side)""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + max_payload_events: NotRequired[float] + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" + compress: NotRequired[bool] + r"""Compress the payload body before sending""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" enable_multi_metrics: NotRequired[bool] - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - enable_ack: NotRequired[bool] - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - max_s2_sversion: NotRequired[MaxS2SVersionOptions] - r"""The highest S2S protocol version to advertise during handshake""" + r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + next_queue: NotRequired[str] + r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" + tcp_routing: NotRequired[str] + r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] - r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - max_failed_health_checks: NotRequired[float] - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - compress: NotRequired[CompressionOptions] - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + url: NotRequired[str] + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + urls: NotRequired[List[OutputResponseOutputSplunkHecURLTypedDict]] + r"""Splunk HEC Endpoints""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + token: NotRequired[str] + r"""Splunk HEC authentication token""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -17371,42 +17299,26 @@ class OutputResponseOutputSplunkTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSplunkPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSplunkHecPqControlsTypedDict] r"""Persistent queue controls.""" - auth_token: NotRequired[str] - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_nested_fields: NotRequired[str] - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_max_s2_sversion: NotRequired[str] - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: NotRequired[str] - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_url: NotRequired[str] + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSplunk(BaseModel): - type: TypeOptionsSplunk +class OutputResponseOutputSplunkHec(BaseModel): + type: OutputResponseOutputSplunkHecType r"""Connector type identifier.""" - host: str - r"""The hostname of the receiver""" - - port: float - r"""The port to connect to on the provided host""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -17424,68 +17336,137 @@ class OutputResponseOutputSplunk(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - nested_fields: Annotated[ - Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( + None + ) + r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None + r"""TLS settings (client side)""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""How to serialize nested fields into index-time fields""" + r"""Maximum size, in KB, of the request body""" - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") + max_payload_events: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadEvents") ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - connection_timeout: Annotated[ - Optional[float], pydantic.Field(alias="connectionTimeout") + compress: Optional[bool] = None + r"""Compress the payload body before sending""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None - r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ - write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( - None - ) - r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None - r"""TLS settings (client side)""" + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - enable_multi_metrics: Annotated[ - Optional[bool], pydantic.Field(alias="enableMultiMetrics") + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") ] = None - r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None - r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), ] = None - r"""Use to troubleshoot issues with sending data""" + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - max_s2_sversion: Annotated[ - Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") ] = None - r"""The highest S2S protocol version to advertise during handshake""" + r"""List of headers that are safe to log in plain text""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + enable_multi_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="enableMultiMetrics") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + next_queue: Annotated[Optional[str], pydantic.Field(alias="nextQueue")] = None + r"""In the Splunk app, define which Splunk processing queue to send the events after HEC processing.""" + + tcp_routing: Annotated[Optional[str], pydantic.Field(alias="tcpRouting")] = None + r"""In the Splunk app, set the value of _TCP_ROUTING for events that do not have _ctrl._TCP_ROUTING set.""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + description: Optional[str] = None r"""Optional description for this configuration.""" - max_failed_health_checks: Annotated[ - Optional[float], pydantic.Field(alias="maxFailedHealthChecks") + url: Optional[str] = None + r"""URL to a Splunk HEC endpoint to send events to, e.g., http://localhost:8088/services/collector/event""" + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + urls: Optional[List[OutputResponseOutputSplunkHecURL]] = None + r"""Splunk HEC Endpoints""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") + ] = None + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - compress: Optional[CompressionOptions] = None - r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + token: Optional[str] = None + r"""Splunk HEC authentication token""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -17537,72 +17518,51 @@ class OutputResponseOutputSplunk(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSplunkPqControls], + Optional[OutputResponseOutputSplunkHecPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None - r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - - template_nested_fields: Annotated[ - Optional[str], pydantic.Field(alias="__template_nestedFields") - ] = None - r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - - template_max_s2_sversion: Annotated[ - Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") ] = None - r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_compress: Annotated[ - Optional[str], pydantic.Field(alias="__template_compress") - ] = None - r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + None + ) + r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("nested_fields") - def serialize_nested_fields(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.NestedFieldSerializationOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("max_s2_sversion") - def serialize_max_s2_sversion(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.MaxS2SVersionOptions(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -17616,24 +17576,6 @@ def serialize_on_backpressure(self, value): return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): - if isinstance(value, str): - try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) - except ValueError: - return value - return value - - @field_serializer("compress") - def serialize_compress(self, value): - if isinstance(value, str): - try: - return models.CompressionOptions(value) - except ValueError: - return value - return value - @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -17670,20 +17612,36 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "nestedFields", - "throttleRatePerSec", - "connectionTimeout", - "writeTimeout", + "loadBalanced", "tls", + "concurrency", + "maxPayloadSizeKB", + "maxPayloadEvents", + "compress", + "rejectUnauthorized", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "extraHttpHeaders", + "failedRequestLoggingMode", + "safeHeaders", "enableMultiMetrics", - "enableACK", - "logFailedRequests", - "maxS2Sversion", - "onBackpressure", "authType", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "nextQueue", + "tcpRouting", + "onBackpressure", "description", - "maxFailedHealthChecks", - "compress", + "url", + "useRoundRobinDns", + "excludeSelf", + "urls", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "token", + "textSecret", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -17696,15 +17654,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "authToken", - "textSecret", "__template_streamtags", - "__template_host", - "__template_port", - "__template_nestedFields", - "__template_maxS2Sversion", + "__template_failedRequestLoggingMode", "__template_onBackpressure", - "__template_compress", + "__template_url", "notifications", "status", ] @@ -17723,114 +17676,156 @@ def serialize_model(self, handler): return m -class OutputResponseOutputSyslogProtocol(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The network protocol to use for sending out syslog messages""" +class OutputResponseOutputSplunkLbType(str, Enum): + r"""Connector type identifier.""" - # TCP - TCP = "tcp" - # UDP - UDP = "udp" + SPLUNK_LB = "splunk_lb" -class OutputResponseFacility(int, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" +class OutputResponseAuthTokenTypedDict(TypedDict): + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" - # kern - KERN = 0 - # user - USER = 1 - # mail - MAIL = 2 - # daemon - DAEMON = 3 - # auth - AUTH = 4 - # syslog - SYSLOG = 5 - # lpr - LPR = 6 - # news - NEWS = 7 - # uucp - UUCP = 8 - # cron - CRON = 9 - # authpriv - AUTHPRIV = 10 - # ftp - FTP = 11 - # ntp - NTP = 12 - # security - SECURITY = 13 - # console - CONSOLE = 14 - # solaris-cron - SOLARIS_CRON = 15 - # local0 - LOCAL0 = 16 - # local1 - LOCAL1 = 17 - # local2 - LOCAL2 = 18 - # local3 - LOCAL3 = 19 - # local4 - LOCAL4 = 20 - # local5 - LOCAL5 = 21 +class OutputResponseAuthToken(BaseModel): + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["authType", "authToken", "textSecret"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +class OutputResponseIndexerDiscoveryConfigsTypedDict(TypedDict): + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + site: str + r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" + master_uri: str + r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" + refresh_interval_sec: float + r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" + reject_unauthorized: NotRequired[bool] + r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" + auth_tokens: NotRequired[List[OutputResponseAuthTokenTypedDict]] + r"""Tokens required to authenticate to cluster manager for indexer discovery""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + auth_token: NotRequired[str] + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + + +class OutputResponseIndexerDiscoveryConfigs(BaseModel): + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + site: str + r"""Clustering site of the indexers from where indexers need to be discovered. In case of single site cluster, it defaults to 'default' site.""" + + master_uri: Annotated[str, pydantic.Field(alias="masterUri")] + r"""Full URI of Splunk cluster manager (scheme://host:port). Example: https://managerAddress:8089""" + + refresh_interval_sec: Annotated[float, pydantic.Field(alias="refreshIntervalSec")] + r"""Time interval, in seconds, between two consecutive indexer list fetches from cluster manager""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" + + auth_tokens: Annotated[ + Optional[List[OutputResponseAuthToken]], pydantic.Field(alias="authTokens") + ] = None + r"""Tokens required to authenticate to cluster manager for indexer discovery""" -class OutputResponseOutputSyslogSeverity(int, Enum, metaclass=utils.OpenEnumMeta): - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), + ] = None + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - # emergency - EMERGENCY = 0 - # alert - ALERT = 1 - # critical - CRITICAL = 2 - # error - ERROR = 3 - # warning - WARNING = 4 - # notice - NOTICE = 5 - # info - INFO = 6 - # debug - DEBUG = 7 + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" -class OutputResponseMessageFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""The syslog message format depending on the receiver's support""" + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value - # RFC3164 - RFC3164 = "rfc3164" - # RFC5424 - RFC5424 = "rfc5424" + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + ["rejectUnauthorized", "authTokens", "authType", "authToken", "textSecret"] + ) + serialized = handler(self) + m = {} + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) -class OutputResponseTimestampFormat(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Timestamp format to use when serializing event's time field""" + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val - # Syslog - SYSLOG = "syslog" - # ISO8601 - ISO8601 = "iso8601" + return m -class OutputResponseOutputSyslogPqControlsTypedDict(TypedDict): +class OutputResponseOutputSplunkLbPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSyslogPqControls(BaseModel): +class OutputResponseOutputSplunkLbPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSyslogTypedDict(TypedDict): - type: TypeOptionsSyslog +class OutputResponseOutputSplunkLbTypedDict(TypedDict): + type: OutputResponseOutputSplunkLbType r"""Connector type identifier.""" + hosts: List[HostConfOutputSyslogTypedDict] + r"""Set of Splunk indexers to load-balance data to.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -17841,56 +17836,50 @@ class OutputResponseOutputSyslogTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - protocol: NotRequired[OutputResponseOutputSyslogProtocol] - r"""The network protocol to use for sending out syslog messages""" - facility: NotRequired[OutputResponseFacility] - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - severity: NotRequired[OutputResponseOutputSyslogSeverity] - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - app_name: NotRequired[str] - r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - message_format: NotRequired[OutputResponseMessageFormat] - r"""The syslog message format depending on the receiver's support""" - timestamp_format: NotRequired[OutputResponseTimestampFormat] - r"""Timestamp format to use when serializing event's time field""" - throttle_rate_per_sec: NotRequired[str] - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - octet_count_framing: NotRequired[bool] - r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - log_failed_requests: NotRequired[bool] - r"""Use to troubleshoot issues with sending data""" - description: NotRequired[str] - r"""Optional description for this configuration.""" - load_balanced: NotRequired[bool] - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - host: NotRequired[str] - r"""The hostname of the receiver""" - port: NotRequired[float] - r"""The port to connect to on the provided host""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] - r"""Set of hosts to load-balance data to""" dns_resolve_period_sec: NotRequired[float] r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" load_balance_stats_period_sec: NotRequired[float] r"""How far back in time to keep traffic stats for load balancing purposes""" max_concurrent_senders: NotRequired[float] r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + nested_fields: NotRequired[NestedFieldSerializationOptions] + r"""How to serialize nested fields into index-time fields""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" connection_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" write_timeout: NotRequired[float] r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] r"""TLS settings (client side)""" + enable_multi_metrics: NotRequired[bool] + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + enable_ack: NotRequired[bool] + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + max_s2_sversion: NotRequired[MaxS2SVersionOptions] + r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - max_record_size: NotRequired[float] - r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" - udp_dns_resolve_period_sec: NotRequired[float] - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" - enable_ip_spoofing: NotRequired[bool] - r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + indexer_discovery: NotRequired[bool] + r"""Automatically discover indexers in indexer clustering environment.""" + sender_unhealthy_time_allowance: NotRequired[float] + r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + max_failed_health_checks: NotRequired[float] + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + compress: NotRequired[CompressionOptions] + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + indexer_discovery_configs: NotRequired[ + OutputResponseIndexerDiscoveryConfigsTypedDict + ] + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -17913,26 +17902,35 @@ class OutputResponseOutputSyslogTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSyslogPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSplunkLbPqControlsTypedDict] r"""Persistent queue controls.""" + auth_token: NotRequired[str] + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: NotRequired[str] - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_port: NotRequired[str] - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_nested_fields: NotRequired[str] + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + template_max_s2_sversion: NotRequired[str] + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSyslog(BaseModel): - type: TypeOptionsSyslog +class OutputResponseOutputSplunkLb(BaseModel): + type: OutputResponseOutputSplunkLbType r"""Connector type identifier.""" + hosts: List[HostConfOutputSyslog] + r"""Set of Splunk indexers to load-balance data to.""" + id: Optional[str] = None r"""Unique ID for this output""" @@ -17950,63 +17948,6 @@ class OutputResponseOutputSyslog(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - protocol: Optional[OutputResponseOutputSyslogProtocol] = None - r"""The network protocol to use for sending out syslog messages""" - - facility: Optional[OutputResponseFacility] = None - r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - - severity: Optional[OutputResponseOutputSyslogSeverity] = None - r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - - app_name: Annotated[Optional[str], pydantic.Field(alias="appName")] = None - r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - - message_format: Annotated[ - Optional[OutputResponseMessageFormat], pydantic.Field(alias="messageFormat") - ] = None - r"""The syslog message format depending on the receiver's support""" - - timestamp_format: Annotated[ - Optional[OutputResponseTimestampFormat], pydantic.Field(alias="timestampFormat") - ] = None - r"""Timestamp format to use when serializing event's time field""" - - throttle_rate_per_sec: Annotated[ - Optional[str], pydantic.Field(alias="throttleRatePerSec") - ] = None - r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - - octet_count_framing: Annotated[ - Optional[bool], pydantic.Field(alias="octetCountFraming") - ] = None - r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - - log_failed_requests: Annotated[ - Optional[bool], pydantic.Field(alias="logFailedRequests") - ] = None - r"""Use to troubleshoot issues with sending data""" - - description: Optional[str] = None - r"""Optional description for this configuration.""" - - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - - host: Optional[str] = None - r"""The hostname of the receiver""" - - port: Optional[float] = None - r"""The port to connect to on the provided host""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - hosts: Optional[List[HostConfOutputSyslog]] = None - r"""Set of hosts to load-balance data to""" - dns_resolve_period_sec: Annotated[ Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None @@ -18022,6 +17963,16 @@ class OutputResponseOutputSyslog(BaseModel): ] = None r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + nested_fields: Annotated[ + Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") + ] = None + r"""How to serialize nested fields into index-time fields""" + + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") + ] = None + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: Annotated[ Optional[float], pydantic.Field(alias="connectionTimeout") ] = None @@ -18035,25 +17986,64 @@ class OutputResponseOutputSyslog(BaseModel): tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None r"""TLS settings (client side)""" + enable_multi_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="enableMultiMetrics") + ] = None + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + + enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") + ] = None + r"""Use to troubleshoot issues with sending data""" + + max_s2_sversion: Annotated[ + Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") + ] = None + r"""The highest S2S protocol version to advertise during handshake""" + on_backpressure: Annotated[ Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""How to handle events when all receivers are exerting backpressure""" + + indexer_discovery: Annotated[ + Optional[bool], pydantic.Field(alias="indexerDiscovery") + ] = None + r"""Automatically discover indexers in indexer clustering environment.""" + + sender_unhealthy_time_allowance: Annotated[ + Optional[float], pydantic.Field(alias="senderUnhealthyTimeAllowance") + ] = None + r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - max_record_size: Annotated[ - Optional[float], pydantic.Field(alias="maxRecordSize") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - udp_dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="udpDnsResolvePeriodSec") + description: Optional[str] = None + r"""Optional description for this configuration.""" + + max_failed_health_checks: Annotated[ + Optional[float], pydantic.Field(alias="maxFailedHealthChecks") ] = None - r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" - enable_ip_spoofing: Annotated[ - Optional[bool], pydantic.Field(alias="enableIpSpoofing") + compress: Optional[CompressionOptions] = None + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" + + indexer_discovery_configs: Annotated[ + Optional[OutputResponseIndexerDiscoveryConfigs], + pydantic.Field(alias="indexerDiscoveryConfigs"), ] = None - r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" + r"""List of configurations to set up indexer discovery in Splunk Indexer clustering environment.""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18105,87 +18095,89 @@ class OutputResponseOutputSyslog(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSyslogPqControls], + Optional[OutputResponseOutputSplunkLbPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( - None - ) - r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_nested_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_nestedFields") + ] = None + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( - None - ) - r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_max_s2_sversion: Annotated[ + Optional[str], pydantic.Field(alias="__template_maxS2Sversion") + ] = None + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("protocol") - def serialize_protocol(self, value): - if isinstance(value, str): - try: - return models.OutputResponseOutputSyslogProtocol(value) - except ValueError: - return value - return value - - @field_serializer("facility") - def serialize_facility(self, value): + @field_serializer("nested_fields") + def serialize_nested_fields(self, value): if isinstance(value, str): try: - return models.OutputResponseFacility(value) + return models.NestedFieldSerializationOptions(value) except ValueError: return value return value - @field_serializer("severity") - def serialize_severity(self, value): + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputSyslogSeverity(value) + return models.MaxS2SVersionOptions(value) except ValueError: return value return value - @field_serializer("message_format") - def serialize_message_format(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseMessageFormat(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("timestamp_format") - def serialize_timestamp_format(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.OutputResponseTimestampFormat(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.CompressionOptions(value) except ValueError: return value return value @@ -18226,31 +18218,27 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "protocol", - "facility", - "severity", - "appName", - "messageFormat", - "timestampFormat", - "throttleRatePerSec", - "octetCountFraming", - "logFailedRequests", - "description", - "loadBalanced", - "host", - "port", - "excludeSelf", - "hosts", "dnsResolvePeriodSec", "loadBalanceStatsPeriodSec", "maxConcurrentSenders", + "nestedFields", + "throttleRatePerSec", "connectionTimeout", "writeTimeout", "tls", + "enableMultiMetrics", + "enableACK", + "logFailedRequests", + "maxS2Sversion", "onBackpressure", - "maxRecordSize", - "udpDnsResolvePeriodSec", - "enableIpSpoofing", + "indexerDiscovery", + "senderUnhealthyTimeAllowance", + "authType", + "description", + "maxFailedHealthChecks", + "compress", + "indexerDiscoveryConfigs", + "excludeSelf", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -18263,10 +18251,13 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "authToken", + "textSecret", "__template_streamtags", - "__template_host", - "__template_port", + "__template_nestedFields", + "__template_maxS2Sversion", "__template_onBackpressure", + "__template_compress", "notifications", "status", ] @@ -18285,140 +18276,21 @@ def serialize_model(self, handler): return m -class OutputResponseOutputDevnullType(str, Enum): - r"""Connector type identifier.""" - - DEVNULL = "devnull" - - -class OutputResponseOutputDevnullTypedDict(TypedDict): - type: OutputResponseOutputDevnullType - r"""Connector type identifier.""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - template_streamtags: NotRequired[str] - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] - r"""Notifications attached to the Destination.""" - status: NotRequired[StatusTypeTypedDict] - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - -class OutputResponseOutputDevnull(BaseModel): - type: OutputResponseOutputDevnullType - r"""Connector type identifier.""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - template_streamtags: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamtags") - ] = None - r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None - r"""Notifications attached to the Destination.""" - - status: Optional[StatusType] = None - r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "pipeline", - "systemFields", - "environment", - "streamtags", - "__template_streamtags", - "notifications", - "status", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class OutputResponseOutputSentinelType(str, Enum): - r"""Connector type identifier.""" - - SENTINEL = "sentinel" - - -class OutputResponseAuthType(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Discriminator value.""" - - OAUTH = "oauth" - - -class OutputResponseEndpointConfiguration(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Enter the data collection endpoint URL or the individual ID""" - - # URL - URL = "url" - # ID - ID = "ID" - - -class OutputResponseOutputSentinelFormat(str, Enum, metaclass=utils.OpenEnumMeta): - NDJSON = "ndjson" - JSON_ARRAY = "json_array" - CUSTOM = "custom" - ADVANCED = "advanced" - - -class OutputResponseOutputSentinelPqControlsTypedDict(TypedDict): +class OutputResponseOutputSplunkPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" -class OutputResponseOutputSentinelPqControls(BaseModel): +class OutputResponseOutputSplunkPqControls(BaseModel): r"""Persistent queue controls.""" -class OutputResponseOutputSentinelTypedDict(TypedDict): - type: OutputResponseOutputSentinelType +class OutputResponseOutputSplunkTypedDict(TypedDict): + type: TypeOptionsSplunk r"""Connector type identifier.""" - login_url: str - r"""URL for OAuth""" - secret: str - r"""Secret parameter value to pass in request body""" - client_id: str - r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" - endpoint_url_configuration: OutputResponseEndpointConfiguration - r"""Enter the data collection endpoint URL or the individual ID""" + host: str + r"""The hostname of the receiver""" + port: float + r"""The port to connect to on the provided host""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -18429,79 +18301,34 @@ class OutputResponseOutputSentinelTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + nested_fields: NotRequired[NestedFieldSerializationOptions] + r"""How to serialize nested fields into index-time fields""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + enable_multi_metrics: NotRequired[bool] + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" + enable_ack: NotRequired[bool] + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" + max_s2_sversion: NotRequired[MaxS2SVersionOptions] + r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[OutputResponseAuthType] - r"""Discriminator value.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - scope: NotRequired[str] - r"""Scope to pass in the OAuth request""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" - format_: NotRequired[OutputResponseOutputSentinelFormat] - custom_source_expression: NotRequired[str] - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" - custom_drop_when_null: NotRequired[bool] - r"""Whether to drop events when the source expression evaluates to null""" - custom_event_delimiter: NotRequired[str] - r"""Delimiter string to insert between individual events. Defaults to newline character.""" - custom_content_type: NotRequired[str] - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" - custom_payload_expression: NotRequired[str] - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" - advanced_content_type: NotRequired[str] - r"""HTTP content-type header value""" - format_event_code: NotRequired[str] - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" - format_payload_code: NotRequired[str] - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + max_failed_health_checks: NotRequired[float] + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + compress: NotRequired[CompressionOptions] + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -18524,242 +18351,121 @@ class OutputResponseOutputSentinelTypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputSentinelPqControlsTypedDict] + pq_controls: NotRequired[OutputResponseOutputSplunkPqControlsTypedDict] r"""Persistent queue controls.""" - url: NotRequired[str] - r"""URL to send events to. Can be overwritten by an event's __url field.""" - dcr_id: NotRequired[str] - r"""Immutable ID for the Data Collection Rule (DCR)""" - dce_endpoint: NotRequired[str] - r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" - stream_name: NotRequired[str] - r"""The name of the stream (Sentinel table) in which to store the events""" + auth_token: NotRequired[str] + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" + template_nested_fields: NotRequired[str] + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" + template_max_s2_sversion: NotRequired[str] + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: NotRequired[str] - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - template_client_id: NotRequired[str] - r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" - template_scope: NotRequired[str] - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - template_dcr_id: NotRequired[str] - r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" - template_dce_endpoint: NotRequired[str] - r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" - template_stream_name: NotRequired[str] - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_compress: NotRequired[str] + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputSentinel(BaseModel): - type: OutputResponseOutputSentinelType +class OutputResponseOutputSplunk(BaseModel): + type: TypeOptionsSplunk r"""Connector type identifier.""" - login_url: Annotated[str, pydantic.Field(alias="loginUrl")] - r"""URL for OAuth""" - - secret: str - r"""Secret parameter value to pass in request body""" - - client_id: str - r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" - - endpoint_url_configuration: Annotated[ - OutputResponseEndpointConfiguration, - pydantic.Field(alias="endpointURLConfiguration"), - ] - r"""Enter the data collection endpoint URL or the individual ID""" - - id: Optional[str] = None - r"""Unique ID for this output""" - - pipeline: Optional[str] = None - r"""Pipeline to process data before sending out to this output""" - - system_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="systemFields") - ] = None - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - - environment: Optional[str] = None - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - - streamtags: Optional[List[str]] = None - r"""Metadata tags used for categorization and filtering.""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" - - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") - ] = None + host: str + r"""The hostname of the receiver""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") - ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + port: float + r"""The port to connect to on the provided host""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") - ] = None - r"""How to handle events when all receivers are exerting backpressure""" + id: Optional[str] = None + r"""Unique ID for this output""" - auth_type: Annotated[ - Optional[OutputResponseAuthType], pydantic.Field(alias="authType") - ] = None - r"""Discriminator value.""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") - ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), + nested_fields: Annotated[ + Optional[NestedFieldSerializationOptions], pydantic.Field(alias="nestedFields") ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + r"""How to serialize nested fields into index-time fields""" - scope: Optional[str] = None - r"""Scope to pass in the OAuth request""" + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") + ] = None + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" - format_: Annotated[ - Optional[OutputResponseOutputSentinelFormat], pydantic.Field(alias="format") - ] = None + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" - custom_source_expression: Annotated[ - Optional[str], pydantic.Field(alias="customSourceExpression") + enable_multi_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="enableMultiMetrics") ] = None - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + r"""Output metrics in multiple-metric format in a single event. Supported in Splunk 8.0 and above.""" - custom_drop_when_null: Annotated[ - Optional[bool], pydantic.Field(alias="customDropWhenNull") - ] = None - r"""Whether to drop events when the source expression evaluates to null""" + enable_ack: Annotated[Optional[bool], pydantic.Field(alias="enableACK")] = None + r"""Check if indexer is shutting down and stop sending data. This helps minimize data loss during shutdown.""" - custom_event_delimiter: Annotated[ - Optional[str], pydantic.Field(alias="customEventDelimiter") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Delimiter string to insert between individual events. Defaults to newline character.""" + r"""Use to troubleshoot issues with sending data""" - custom_content_type: Annotated[ - Optional[str], pydantic.Field(alias="customContentType") + max_s2_sversion: Annotated[ + Optional[MaxS2SVersionOptions], pydantic.Field(alias="maxS2Sversion") ] = None - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + r"""The highest S2S protocol version to advertise during handshake""" - custom_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="customPayloadExpression") + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + r"""How to handle events when all receivers are exerting backpressure""" - advanced_content_type: Annotated[ - Optional[str], pydantic.Field(alias="advancedContentType") + auth_type: Annotated[ + Optional[AuthenticationMethodOptionsAuthTokensExtItems], + pydantic.Field(alias="authType"), ] = None - r"""HTTP content-type header value""" + r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" - format_event_code: Annotated[ - Optional[str], pydantic.Field(alias="formatEventCode") - ] = None - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + description: Optional[str] = None + r"""Optional description for this configuration.""" - format_payload_code: Annotated[ - Optional[str], pydantic.Field(alias="formatPayloadCode") + max_failed_health_checks: Annotated[ + Optional[float], pydantic.Field(alias="maxFailedHealthChecks") ] = None - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""Maximum number of times healthcheck can fail before we close connection. If set to 0 (disabled), and the connection to Splunk is forcibly closed, some data loss might occur.""" + + compress: Optional[CompressionOptions] = None + r"""Controls whether the sender should send compressed data to the server. Select 'Disabled' to reject compressed connections or 'Always' to ignore server's configuration and send compressed data.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -18811,130 +18517,99 @@ class OutputResponseOutputSentinel(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputSentinelPqControls], + Optional[OutputResponseOutputSplunkPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - url: Optional[str] = None - r"""URL to send events to. Can be overwritten by an event's __url field.""" - - dcr_id: Annotated[Optional[str], pydantic.Field(alias="dcrID")] = None - r"""Immutable ID for the Data Collection Rule (DCR)""" - - dce_endpoint: Annotated[Optional[str], pydantic.Field(alias="dceEndpoint")] = None - r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" + auth_token: Annotated[Optional[str], pydantic.Field(alias="authToken")] = None + r"""Shared secret token to use when establishing a connection to a Splunk indexer.""" - stream_name: Annotated[Optional[str], pydantic.Field(alias="streamName")] = None - r"""The name of the stream (Sentinel table) in which to store the events""" + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" - - template_on_backpressure: Annotated[ - Optional[str], pydantic.Field(alias="__template_onBackpressure") - ] = None - r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - - template_refresh_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_refreshUrl") - ] = None - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - - template_client_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_client_id") - ] = None - r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" - - template_scope: Annotated[ - Optional[str], pydantic.Field(alias="__template_scope") - ] = None - r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( None ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" - template_dcr_id: Annotated[ - Optional[str], pydantic.Field(alias="__template_dcrID") + template_nested_fields: Annotated[ + Optional[str], pydantic.Field(alias="__template_nestedFields") ] = None - r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + r"""Binds 'nestedFields' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'nestedFields' at runtime.""" - template_dce_endpoint: Annotated[ - Optional[str], pydantic.Field(alias="__template_dceEndpoint") + template_max_s2_sversion: Annotated[ + Optional[str], pydantic.Field(alias="__template_maxS2Sversion") ] = None - r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + r"""Binds 'maxS2Sversion' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'maxS2Sversion' at runtime.""" - template_stream_name: Annotated[ - Optional[str], pydantic.Field(alias="__template_streamName") + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None - r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_compress: Annotated[ + Optional[str], pydantic.Field(alias="__template_compress") + ] = None + r"""Binds 'compress' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'compress' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("nested_fields") + def serialize_nested_fields(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.NestedFieldSerializationOptions(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("max_s2_sversion") + def serialize_max_s2_sversion(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.MaxS2SVersionOptions(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseAuthType(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("endpoint_url_configuration") - def serialize_endpoint_url_configuration(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.OutputResponseEndpointConfiguration(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("compress") + def serialize_compress(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputSentinelFormat(value) + return models.CompressionOptions(value) except ValueError: return value return value @@ -18960,55 +18635,35 @@ def serialize_pq_compress(self, value): @field_serializer("pq_on_backpressure") def serialize_pq_on_backpressure(self, value): if isinstance(value, str): - try: - return models.QueueFullBehaviorOptions(value) - except ValueError: - return value - return value - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "id", - "pipeline", - "systemFields", - "environment", - "streamtags", - "keepAlive", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "nestedFields", + "throttleRatePerSec", + "connectionTimeout", + "writeTimeout", + "tls", + "enableMultiMetrics", + "enableACK", + "logFailedRequests", + "maxS2Sversion", "onBackpressure", "authType", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "scope", - "totalMemoryLimitKB", "description", - "format", - "customSourceExpression", - "customDropWhenNull", - "customEventDelimiter", - "customContentType", - "customPayloadExpression", - "advancedContentType", - "formatEventCode", - "formatPayloadCode", + "maxFailedHealthChecks", + "compress", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -19021,22 +18676,15 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "url", - "dcrID", - "dceEndpoint", - "streamName", + "authToken", + "textSecret", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_host", + "__template_port", + "__template_nestedFields", + "__template_maxS2Sversion", "__template_onBackpressure", - "__template_loginUrl", - "__template_secret", - "__template_refreshUrl", - "__template_client_id", - "__template_scope", - "__template_url", - "__template_dcrID", - "__template_dceEndpoint", - "__template_streamName", + "__template_compress", "notifications", "status", ] @@ -19055,173 +18703,174 @@ def serialize_model(self, handler): return m -class OutputResponseOutputWebhookType2(str, Enum): - r"""Connector type identifier.""" - - WEBHOOK = "webhook" - - -class OutputResponseOutputWebhookFormat2(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How to format events before sending out""" - - # NDJSON (Newline Delimited JSON) - NDJSON = "ndjson" - # JSON Array - JSON_ARRAY = "json_array" - # Custom - CUSTOM = "custom" - # Advanced - ADVANCED = "advanced" - - -class OutputResponseOutputWebhookAuthenticationType2( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method to use for the HTTP request""" - - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth - OAUTH = "oauth" - - -class OutputResponseOutputWebhookPqControls2TypedDict(TypedDict): - r"""Persistent queue controls.""" - - -class OutputResponseOutputWebhookPqControls2(BaseModel): - r"""Persistent queue controls.""" - - -class OutputResponseOutputWebhookURL2TypedDict(TypedDict): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - +class OutputResponseOutputSyslogProtocol(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The network protocol to use for sending out syslog messages""" -class OutputResponseOutputWebhookURL2(BaseModel): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + # TCP + TCP = "tcp" + # UDP + UDP = "udp" - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" +class OutputResponseFacility(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) - serialized = handler(self) - m = {} + # kern + KERN = 0 + # user + USER = 1 + # mail + MAIL = 2 + # daemon + DAEMON = 3 + # auth + AUTH = 4 + # syslog + SYSLOG = 5 + # lpr + LPR = 6 + # news + NEWS = 7 + # uucp + UUCP = 8 + # cron + CRON = 9 + # authpriv + AUTHPRIV = 10 + # ftp + FTP = 11 + # ntp + NTP = 12 + # security + SECURITY = 13 + # console + CONSOLE = 14 + # solaris-cron + SOLARIS_CRON = 15 + # local0 + LOCAL0 = 16 + # local1 + LOCAL1 = 17 + # local2 + LOCAL2 = 18 + # local3 + LOCAL3 = 19 + # local4 + LOCAL4 = 20 + # local5 + LOCAL5 = 21 - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val +class OutputResponseOutputSyslogSeverity(int, Enum, metaclass=utils.OpenEnumMeta): + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - return m + # emergency + EMERGENCY = 0 + # alert + ALERT = 1 + # critical + CRITICAL = 2 + # error + ERROR = 3 + # warning + WARNING = 4 + # notice + NOTICE = 5 + # info + INFO = 6 + # debug + DEBUG = 7 -class OutputResponseOutputWebhookWebhook2TypedDict(TypedDict): - type: OutputResponseOutputWebhookType2 - r"""Connector type identifier.""" - urls: List[OutputResponseOutputWebhookURL2TypedDict] - r"""Webhook URLs""" - id: NotRequired[str] - r"""Unique ID for this output""" - pipeline: NotRequired[str] - r"""Pipeline to process data before sending out to this output""" - system_fields: NotRequired[List[str]] - r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" - environment: NotRequired[str] - r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" - streamtags: NotRequired[List[str]] - r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - format_: NotRequired[OutputResponseOutputWebhookFormat2] - r"""How to format events before sending out""" - keep_alive: NotRequired[bool] - r"""Disable to close the connection immediately after sending the outgoing request""" - concurrency: NotRequired[float] - r"""Maximum number of ongoing requests before blocking""" - max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" - max_payload_events: NotRequired[float] - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - compress: NotRequired[bool] - r"""Compress the payload body before sending""" - reject_unauthorized: NotRequired[bool] - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - timeout_sec: NotRequired[float] - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - max_connection_reuse_sec: NotRequired[float] - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - flush_period_sec: NotRequired[float] - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - use_round_robin_dns: NotRequired[bool] - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" - failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" - safe_headers: NotRequired[List[str]] - r"""List of headers that are safe to log in plain text""" - response_retry_settings: NotRequired[ - List[ResponseRetrySettingConfOutputWebhookTypedDict] - ] - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" - timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] - response_honor_retry_after_header: NotRequired[bool] - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" - on_backpressure: NotRequired[BackpressureBehaviorOptions] - r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[OutputResponseOutputWebhookAuthenticationType2] - r"""Authentication method to use for the HTTP request""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" - total_memory_limit_kb: NotRequired[float] - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" +class OutputResponseMessageFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The syslog message format depending on the receiver's support""" + + # RFC3164 + RFC3164 = "rfc3164" + # RFC5424 + RFC5424 = "rfc5424" + + +class OutputResponseTimestampFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Timestamp format to use when serializing event's time field""" + + # Syslog + SYSLOG = "syslog" + # ISO8601 + ISO8601 = "iso8601" + + +class OutputResponseOutputSyslogPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputSyslogPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputSyslogTypedDict(TypedDict): + type: TypeOptionsSyslog + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + protocol: NotRequired[OutputResponseOutputSyslogProtocol] + r"""The network protocol to use for sending out syslog messages""" + facility: NotRequired[OutputResponseFacility] + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" + severity: NotRequired[OutputResponseOutputSyslogSeverity] + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" + app_name: NotRequired[str] + r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" + message_format: NotRequired[OutputResponseMessageFormat] + r"""The syslog message format depending on the receiver's support""" + timestamp_format: NotRequired[OutputResponseTimestampFormat] + r"""Timestamp format to use when serializing event's time field""" + throttle_rate_per_sec: NotRequired[str] + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" + octet_count_framing: NotRequired[bool] + r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" + log_failed_requests: NotRequired[bool] + r"""Use to troubleshoot issues with sending data""" description: NotRequired[str] r"""Optional description for this configuration.""" - custom_source_expression: NotRequired[str] - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" - custom_drop_when_null: NotRequired[bool] - r"""Whether to drop events when the source expression evaluates to null""" - custom_event_delimiter: NotRequired[str] - r"""Delimiter string to insert between individual events. Defaults to newline character.""" - custom_content_type: NotRequired[str] - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" - custom_payload_expression: NotRequired[str] - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" - advanced_content_type: NotRequired[str] - r"""HTTP content-type header value""" - format_event_code: NotRequired[str] - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" - format_payload_code: NotRequired[str] - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + load_balanced: NotRequired[bool] + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" + host: NotRequired[str] + r"""The hostname of the receiver""" + port: NotRequired[float] + r"""The port to connect to on the provided host""" + exclude_self: NotRequired[bool] + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + hosts: NotRequired[List[HostConfOutputSyslogTypedDict]] + r"""Set of hosts to load-balance data to""" + dns_resolve_period_sec: NotRequired[float] + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + load_balance_stats_period_sec: NotRequired[float] + r"""How far back in time to keep traffic stats for load balancing purposes""" + max_concurrent_senders: NotRequired[float] + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + write_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathTypedDict] + r"""TLS settings (client side)""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + max_record_size: NotRequired[float] + r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" + udp_dns_resolve_period_sec: NotRequired[float] + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" + enable_ip_spoofing: NotRequired[bool] + r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -19244,79 +18893,26 @@ class OutputResponseOutputWebhookWebhook2TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputWebhookPqControls2TypedDict] + pq_controls: NotRequired[OutputResponseOutputSyslogPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" - secret: NotRequired[str] - r"""Secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - url: NotRequired[str] - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: NotRequired[str] - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: NotRequired[str] + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + template_port: NotRequired[str] + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_on_backpressure: NotRequired[str] r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: NotRequired[str] - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: NotRequired[str] - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputWebhookWebhook2(BaseModel): - type: OutputResponseOutputWebhookType2 +class OutputResponseOutputSyslog(BaseModel): + type: TypeOptionsSyslog r"""Connector type identifier.""" - urls: List[OutputResponseOutputWebhookURL2] - r"""Webhook URLs""" - id: Optional[str] = None r"""Unique ID for this output""" @@ -19334,157 +18930,110 @@ class OutputResponseOutputWebhookWebhook2(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" - - format_: Annotated[ - Optional[OutputResponseOutputWebhookFormat2], pydantic.Field(alias="format") - ] = None - r"""How to format events before sending out""" - - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None - r"""Disable to close the connection immediately after sending the outgoing request""" - - concurrency: Optional[float] = None - r"""Maximum number of ongoing requests before blocking""" - - max_payload_size_kb: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadSizeKB") - ] = None - r"""Maximum size, in KB, of the request body""" - - max_payload_events: Annotated[ - Optional[float], pydantic.Field(alias="maxPayloadEvents") - ] = None - r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" - - compress: Optional[bool] = None - r"""Compress the payload body before sending""" - - reject_unauthorized: Annotated[ - Optional[bool], pydantic.Field(alias="rejectUnauthorized") - ] = None - r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). - Enabled by default. When this setting is also present in TLS Settings (Client Side), - that value will take precedence. - """ - - timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None - r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" - - max_connection_reuse_sec: Annotated[ - Optional[float], pydantic.Field(alias="maxConnectionReuseSec") - ] = None - r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" - - flush_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="flushPeriodSec") - ] = None - r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" - - extra_http_headers: Annotated[ - Optional[List[ExtraHTTPHeaderConfInputElastic]], - pydantic.Field(alias="extraHttpHeaders"), - ] = None - r"""Headers to add to all events. You can also add headers dynamically on a per-event basis in the __headers field, as explained in [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook/#internal-fields).""" - - use_round_robin_dns: Annotated[ - Optional[bool], pydantic.Field(alias="useRoundRobinDns") - ] = None - r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + protocol: Optional[OutputResponseOutputSyslogProtocol] = None + r"""The network protocol to use for sending out syslog messages""" - failed_request_logging_mode: Annotated[ - Optional[FailedRequestLoggingModeOptions], - pydantic.Field(alias="failedRequestLoggingMode"), - ] = None - r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + facility: Optional[OutputResponseFacility] = None + r"""Default value for message facility. Will be overwritten by value of __facility if set. Defaults to user.""" - safe_headers: Annotated[ - Optional[List[str]], pydantic.Field(alias="safeHeaders") - ] = None - r"""List of headers that are safe to log in plain text""" + severity: Optional[OutputResponseOutputSyslogSeverity] = None + r"""Default value for message severity. Will be overwritten by value of __severity if set. Defaults to notice.""" - response_retry_settings: Annotated[ - Optional[List[ResponseRetrySettingConfOutputWebhook]], - pydantic.Field(alias="responseRetrySettings"), - ] = None - r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + app_name: Annotated[Optional[str], pydantic.Field(alias="appName")] = None + r"""Default name for device or application that originated the message. Defaults to Cribl, but will be overwritten by value of __appname if set.""" - timeout_retry_settings: Annotated[ - Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + message_format: Annotated[ + Optional[OutputResponseMessageFormat], pydantic.Field(alias="messageFormat") ] = None + r"""The syslog message format depending on the receiver's support""" - response_honor_retry_after_header: Annotated[ - Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + timestamp_format: Annotated[ + Optional[OutputResponseTimestampFormat], pydantic.Field(alias="timestampFormat") ] = None - r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + r"""Timestamp format to use when serializing event's time field""" - on_backpressure: Annotated[ - Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + throttle_rate_per_sec: Annotated[ + Optional[str], pydantic.Field(alias="throttleRatePerSec") ] = None - r"""How to handle events when all receivers are exerting backpressure""" + r"""Rate (in bytes per second) to throttle while writing to an output. Accepts values with multiple-byte units, such as KB, MB, and GB. (Example: 42 MB) Default value of 0 specifies no throttling.""" - auth_type: Annotated[ - Optional[OutputResponseOutputWebhookAuthenticationType2], - pydantic.Field(alias="authType"), + octet_count_framing: Annotated[ + Optional[bool], pydantic.Field(alias="octetCountFraming") ] = None - r"""Authentication method to use for the HTTP request""" - - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + r"""Prefix messages with the byte count of the message. If disabled, no prefix will be set, and the message will be appended with a \n.""" - total_memory_limit_kb: Annotated[ - Optional[float], pydantic.Field(alias="totalMemoryLimitKB") + log_failed_requests: Annotated[ + Optional[bool], pydantic.Field(alias="logFailedRequests") ] = None - r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" + r"""Use to troubleshoot issues with sending data""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( None ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" + r"""For optimal performance, enable load balancing even if you have one hostname, as it can expand to multiple IPs. If this setting is disabled, consider enabling round-robin DNS.""" - description: Optional[str] = None - r"""Optional description for this configuration.""" + host: Optional[str] = None + r"""The hostname of the receiver""" - custom_source_expression: Annotated[ - Optional[str], pydantic.Field(alias="customSourceExpression") + port: Optional[float] = None + r"""The port to connect to on the provided host""" + + exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None + r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + + hosts: Optional[List[HostConfOutputSyslog]] = None + r"""Set of hosts to load-balance data to""" + + dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") ] = None - r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" + r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - custom_drop_when_null: Annotated[ - Optional[bool], pydantic.Field(alias="customDropWhenNull") + load_balance_stats_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") ] = None - r"""Whether to drop events when the source expression evaluates to null""" + r"""How far back in time to keep traffic stats for load balancing purposes""" - custom_event_delimiter: Annotated[ - Optional[str], pydantic.Field(alias="customEventDelimiter") + max_concurrent_senders: Annotated[ + Optional[float], pydantic.Field(alias="maxConcurrentSenders") ] = None - r"""Delimiter string to insert between individual events. Defaults to newline character.""" + r"""Maximum number of concurrent connections (per Worker Process). A random set of IPs will be picked on every DNS resolution period. Use 0 for unlimited.""" - custom_content_type: Annotated[ - Optional[str], pydantic.Field(alias="customContentType") + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") ] = None - r"""Content type to use for request. Defaults to application/x-ndjson. Any content types set in Advanced Settings > Extra HTTP headers will override this entry.""" + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" - custom_payload_expression: Annotated[ - Optional[str], pydantic.Field(alias="customPayloadExpression") + write_timeout: Annotated[Optional[float], pydantic.Field(alias="writeTimeout")] = ( + None + ) + r"""Amount of time (milliseconds) to wait for a write to complete before assuming connection is dead""" + + tls: Optional[TLSSettingsClientSideTypeCaPathCertPath] = None + r"""TLS settings (client side)""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") ] = None - r"""Expression specifying how to format the payload for each batch. To reference the events to send, use the `${events}` variable. Example expression: `{ \"items\" : [${events}] }` would send the batch inside a JSON object.""" + r"""How to handle events when all receivers are exerting backpressure""" - advanced_content_type: Annotated[ - Optional[str], pydantic.Field(alias="advancedContentType") + max_record_size: Annotated[ + Optional[float], pydantic.Field(alias="maxRecordSize") ] = None - r"""HTTP content-type header value""" + r"""Maximum size of syslog messages. Make sure this value is less than or equal to the MTU to avoid UDP packet fragmentation.""" - format_event_code: Annotated[ - Optional[str], pydantic.Field(alias="formatEventCode") + udp_dns_resolve_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="udpDnsResolvePeriodSec") ] = None - r"""Custom JavaScript code to format incoming event data accessible through the __e variable. The formatted content is added to (__e['__eventOut']) if available. Otherwise, the original event is serialized as JSON. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""How often to resolve the destination hostname to an IP address. Ignored if the destination is an IP address. A value of 0 means every message sent will incur a DNS lookup.""" - format_payload_code: Annotated[ - Optional[str], pydantic.Field(alias="formatPayloadCode") + enable_ip_spoofing: Annotated[ + Optional[bool], pydantic.Field(alias="enableIpSpoofing") ] = None - r"""Optional JavaScript code to format the payload sent to the Destination. The payload, containing a batch of formatted events, is accessible through the __e['payload'] variable. The formatted payload is returned in the __e['__payloadOut'] variable. Caution: This function is evaluated in an unprotected context, allowing you to execute almost any JavaScript code.""" + r"""Send Syslog traffic using the original event's Source IP and port. To enable this, you must install the external `udp-sender` helper binary at `/usr/bin/udp-sender` on all Worker Nodes and grant it the `CAP_NET_RAW` capability.""" pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") @@ -19536,183 +19085,87 @@ class OutputResponseOutputWebhookWebhook2(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputWebhookPqControls2], + Optional[OutputResponseOutputSyslogPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - - secret: Optional[str] = None - r"""Secret parameter value to pass in request body""" - - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") - ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") - ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), - ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - - url: Optional[str] = None - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" - template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") ] = None r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - template_failed_request_logging_mode: Annotated[ - Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") - ] = None - r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_host: Annotated[Optional[str], pydantic.Field(alias="__template_host")] = ( + None + ) + r"""Binds 'host' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'host' at runtime.""" + + template_port: Annotated[Optional[str], pydantic.Field(alias="__template_port")] = ( + None + ) + r"""Binds 'port' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'port' at runtime.""" template_on_backpressure: Annotated[ Optional[str], pydantic.Field(alias="__template_onBackpressure") ] = None r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" - template_login_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_loginUrl") - ] = None - r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - - template_refresh_url: Annotated[ - Optional[str], pydantic.Field(alias="__template_refreshUrl") - ] = None - r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" - - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("method") - def serialize_method(self, value): + @field_serializer("protocol") + def serialize_protocol(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.OutputResponseOutputSyslogProtocol(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("facility") + def serialize_facility(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputWebhookFormat2(value) + return models.OutputResponseFacility(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("severity") + def serialize_severity(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OutputResponseOutputSyslogSeverity(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("message_format") + def serialize_message_format(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.OutputResponseMessageFormat(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("timestamp_format") + def serialize_timestamp_format(self, value): + if isinstance(value, str): + try: + return models.OutputResponseTimestampFormat(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputWebhookAuthenticationType2(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value @@ -19753,38 +19206,31 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "format", - "keepAlive", - "concurrency", - "maxPayloadSizeKB", - "maxPayloadEvents", - "compress", - "rejectUnauthorized", - "timeoutSec", - "maxConnectionReuseSec", - "flushPeriodSec", - "extraHttpHeaders", - "useRoundRobinDns", - "failedRequestLoggingMode", - "safeHeaders", - "responseRetrySettings", - "timeoutRetrySettings", - "responseHonorRetryAfterHeader", - "onBackpressure", - "authType", - "tls", - "totalMemoryLimitKB", - "loadBalanced", + "protocol", + "facility", + "severity", + "appName", + "messageFormat", + "timestampFormat", + "throttleRatePerSec", + "octetCountFraming", + "logFailedRequests", "description", - "customSourceExpression", - "customDropWhenNull", - "customEventDelimiter", - "customContentType", - "customPayloadExpression", - "advancedContentType", - "formatEventCode", - "formatPayloadCode", + "loadBalanced", + "host", + "port", + "excludeSelf", + "hosts", + "dnsResolvePeriodSec", + "loadBalanceStatsPeriodSec", + "maxConcurrentSenders", + "connectionTimeout", + "writeTimeout", + "tls", + "onBackpressure", + "maxRecordSize", + "udpDnsResolvePeriodSec", + "enableIpSpoofing", "pqStrictOrdering", "pqRatePerSec", "pqMode", @@ -19797,34 +19243,10 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", - "secret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "url", - "excludeSelf", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", "__template_streamtags", - "__template_failedRequestLoggingMode", + "__template_host", + "__template_port", "__template_onBackpressure", - "__template_loginUrl", - "__template_secret", - "__template_refreshUrl", - "__template_url", "notifications", "status", ] @@ -19843,76 +19265,79 @@ def serialize_model(self, handler): return m -class OutputResponseOutputWebhookType1(str, Enum): +class OutputResponseOutputDevnullType(str, Enum): r"""Connector type identifier.""" - WEBHOOK = "webhook" - - -class OutputResponseOutputWebhookFormat1(str, Enum, metaclass=utils.OpenEnumMeta): - r"""How to format events before sending out""" - - # NDJSON (Newline Delimited JSON) - NDJSON = "ndjson" - # JSON Array - JSON_ARRAY = "json_array" - # Custom - CUSTOM = "custom" - # Advanced - ADVANCED = "advanced" - + DEVNULL = "devnull" -class OutputResponseOutputWebhookAuthenticationType1( - str, Enum, metaclass=utils.OpenEnumMeta -): - r"""Authentication method to use for the HTTP request""" - # None - NONE = "none" - # Basic - BASIC = "basic" - # Basic (credentials secret) - CREDENTIALS_SECRET = "credentialsSecret" - # Token - TOKEN = "token" - # Token (text secret) - TEXT_SECRET = "textSecret" - # OAuth - OAUTH = "oauth" +class OutputResponseOutputDevnullTypedDict(TypedDict): + type: OutputResponseOutputDevnullType + r"""Connector type identifier.""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] + r"""Notifications attached to the Destination.""" + status: NotRequired[StatusTypeTypedDict] + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputWebhookPqControls1TypedDict(TypedDict): - r"""Persistent queue controls.""" +class OutputResponseOutputDevnull(BaseModel): + type: OutputResponseOutputDevnullType + r"""Connector type identifier.""" + id: Optional[str] = None + r"""Unique ID for this output""" -class OutputResponseOutputWebhookPqControls1(BaseModel): - r"""Persistent queue controls.""" + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" -class OutputResponseOutputWebhookURL1TypedDict(TypedDict): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" - weight: NotRequired[float] - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" - template_url: NotRequired[str] - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" -class OutputResponseOutputWebhookURL1(BaseModel): - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" - weight: Optional[float] = None - r"""Assign a weight (>0) to each endpoint to indicate its traffic-handling capability""" + notifications: Optional[List[Notification]] = None + r"""Notifications attached to the Destination.""" - template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( - None - ) - r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" + status: Optional[StatusType] = None + r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["weight", "__template_url"]) + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "__template_streamtags", + "notifications", + "status", + ] + ) serialized = handler(self) m = {} @@ -19927,11 +19352,58 @@ def serialize_model(self, handler): return m -class OutputResponseOutputWebhookWebhook1TypedDict(TypedDict): - type: OutputResponseOutputWebhookType1 +class OutputResponseOutputSentinelType(str, Enum): r"""Connector type identifier.""" - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + + SENTINEL = "sentinel" + + +class OutputResponseAuthType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Discriminator value.""" + + OAUTH = "oauth" + + +class OutputResponseOAuthSecretSource(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Enter the OAuth secret directly, or select a stored text secret""" + + INLINE = "inline" + SECRET = "secret" + + +class OutputResponseEndpointConfiguration(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Enter the data collection endpoint URL or the individual ID""" + + # URL + URL = "url" + # ID + ID = "ID" + + +class OutputResponseOutputSentinelFormat(str, Enum, metaclass=utils.OpenEnumMeta): + NDJSON = "ndjson" + JSON_ARRAY = "json_array" + CUSTOM = "custom" + ADVANCED = "advanced" + + +class OutputResponseOutputSentinelPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputResponseOutputSentinelPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputResponseOutputSentinelTypedDict(TypedDict): + type: OutputResponseOutputSentinelType + r"""Connector type identifier.""" + login_url: str + r"""URL for OAuth""" + client_id: str + r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" + endpoint_url_configuration: OutputResponseEndpointConfiguration + r"""Enter the data collection endpoint URL or the individual ID""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -19942,16 +19414,12 @@ class OutputResponseOutputWebhookWebhook1TypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - method: NotRequired[MethodOptions] - r"""The method to use when sending events""" - format_: NotRequired[OutputResponseOutputWebhookFormat1] - r"""How to format events before sending out""" keep_alive: NotRequired[bool] r"""Disable to close the connection immediately after sending the outgoing request""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" max_payload_size_kb: NotRequired[float] - r"""Maximum size, in KB, of the request body""" + r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" max_payload_events: NotRequired[float] r"""Maximum number of events to include in the request body. Default is 0 (unlimited).""" compress: NotRequired[bool] @@ -19984,16 +19452,27 @@ class OutputResponseOutputWebhookWebhook1TypedDict(TypedDict): r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[OutputResponseOutputWebhookAuthenticationType1] - r"""Authentication method to use for the HTTP request""" - tls: NotRequired[TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict] - r"""TLS settings (client side)""" + auth_type: NotRequired[OutputResponseAuthType] + r"""Discriminator value.""" + refresh_token_field: NotRequired[str] + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + rotate_refresh_token: NotRequired[bool] + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + refresh_url: NotRequired[str] + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + refresh_request_params: NotRequired[ + List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] + ] + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + oauth_secret_source: NotRequired[OutputResponseOAuthSecretSource] + r"""Enter the OAuth secret directly, or select a stored text secret""" + scope: NotRequired[str] + r"""Scope to pass in the OAuth request""" total_memory_limit_kb: NotRequired[float] r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: NotRequired[bool] - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" description: NotRequired[str] r"""Optional description for this configuration.""" + format_: NotRequired[OutputResponseOutputSentinelFormat] custom_source_expression: NotRequired[str] r"""Expression to evaluate on events to generate output. Example: `raw=${_raw}`. See [Cribl Docs](https://docs.cribl.io/stream/destinations-webhook#custom-format) for other examples. If empty, the full event is sent as stringified JSON.""" custom_drop_when_null: NotRequired[bool] @@ -20032,52 +19511,20 @@ class OutputResponseOutputWebhookWebhook1TypedDict(TypedDict): r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" pq_max_buffer_size_bytes: NotRequired[str] r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" - pq_controls: NotRequired[OutputResponseOutputWebhookPqControls1TypedDict] + pq_controls: NotRequired[OutputResponseOutputSentinelPqControlsTypedDict] r"""Persistent queue controls.""" - username: NotRequired[str] - r"""Username""" - password: NotRequired[str] - r"""Password""" - token: NotRequired[str] - r"""Bearer token to include in the authorization header""" - credentials_secret: NotRequired[str] - r"""Select or create a secret that references your credentials""" - text_secret: NotRequired[str] - r"""Select or create a stored text secret""" - login_url: NotRequired[str] - r"""URL for OAuth""" - secret_param_name: NotRequired[str] - r"""Secret parameter name to pass in request body""" secret: NotRequired[str] r"""Secret parameter value to pass in request body""" - token_attribute_name: NotRequired[str] - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - auth_header_expr: NotRequired[str] - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - token_timeout_secs: NotRequired[float] - r"""How often the OAuth token should be refreshed.""" - oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - refresh_token_field: NotRequired[str] - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - rotate_refresh_token: NotRequired[bool] - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - refresh_url: NotRequired[str] - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - refresh_request_params: NotRequired[ - List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] - ] - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" - exclude_self: NotRequired[bool] - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" - urls: NotRequired[List[OutputResponseOutputWebhookURL1TypedDict]] - r"""Webhook URLs""" - dns_resolve_period_sec: NotRequired[float] - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" - load_balance_stats_period_sec: NotRequired[float] - r"""How far back in time to keep traffic stats for load balancing purposes""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret value""" + url: NotRequired[str] + r"""URL to send events to. Can be overwritten by an event's __url field.""" + dcr_id: NotRequired[str] + r"""Immutable ID for the Data Collection Rule (DCR)""" + dce_endpoint: NotRequired[str] + r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" + stream_name: NotRequired[str] + r"""The name of the stream (Sentinel table) in which to store the events""" template_streamtags: NotRequired[str] r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" template_failed_request_logging_mode: NotRequired[str] @@ -20086,24 +19533,43 @@ class OutputResponseOutputWebhookWebhook1TypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_login_url: NotRequired[str] r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_refresh_url: NotRequired[str] r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_client_id: NotRequired[str] + r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" + template_scope: NotRequired[str] + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_url: NotRequired[str] r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + template_dcr_id: NotRequired[str] + r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + template_dce_endpoint: NotRequired[str] + r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + template_stream_name: NotRequired[str] + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + notifications: NotRequired[List[NotificationTypedDict]] r"""Notifications attached to the Destination.""" status: NotRequired[StatusTypeTypedDict] r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" -class OutputResponseOutputWebhookWebhook1(BaseModel): - type: OutputResponseOutputWebhookType1 +class OutputResponseOutputSentinel(BaseModel): + type: OutputResponseOutputSentinelType r"""Connector type identifier.""" - url: str - r"""URL of a webhook endpoint to send events to, such as http://localhost:10200""" + login_url: Annotated[str, pydantic.Field(alias="loginUrl")] + r"""URL for OAuth""" + + client_id: str + r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" + + endpoint_url_configuration: Annotated[ + OutputResponseEndpointConfiguration, + pydantic.Field(alias="endpointURLConfiguration"), + ] + r"""Enter the data collection endpoint URL or the individual ID""" id: Optional[str] = None r"""Unique ID for this output""" @@ -20122,14 +19588,6 @@ class OutputResponseOutputWebhookWebhook1(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" - method: Optional[MethodOptions] = None - r"""The method to use when sending events""" - - format_: Annotated[ - Optional[OutputResponseOutputWebhookFormat1], pydantic.Field(alias="format") - ] = None - r"""How to format events before sending out""" - keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None r"""Disable to close the connection immediately after sending the outgoing request""" @@ -20139,7 +19597,7 @@ class OutputResponseOutputWebhookWebhook1(BaseModel): max_payload_size_kb: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadSizeKB") ] = None - r"""Maximum size, in KB, of the request body""" + r"""Maximum size (KB) of the request body (defaults to the API's maximum limit of 1000 KB)""" max_payload_events: Annotated[ Optional[float], pydantic.Field(alias="maxPayloadEvents") @@ -20213,27 +19671,50 @@ class OutputResponseOutputWebhookWebhook1(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[OutputResponseOutputWebhookAuthenticationType1], - pydantic.Field(alias="authType"), + Optional[OutputResponseAuthType], pydantic.Field(alias="authType") ] = None - r"""Authentication method to use for the HTTP request""" + r"""Discriminator value.""" - tls: Optional[TLSSettingsClientSideTypeCaPathCertPathExtended] = None - r"""TLS settings (client side)""" + refresh_token_field: Annotated[ + Optional[str], pydantic.Field(alias="refreshTokenField") + ] = None + r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" + + rotate_refresh_token: Annotated[ + Optional[bool], pydantic.Field(alias="rotateRefreshToken") + ] = None + r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" + + refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None + r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" + + refresh_request_params: Annotated[ + Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], + pydantic.Field(alias="refreshRequestParams"), + ] = None + r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + + oauth_secret_source: Annotated[ + Optional[OutputResponseOAuthSecretSource], + pydantic.Field(alias="oauthSecretSource"), + ] = None + r"""Enter the OAuth secret directly, or select a stored text secret""" + + scope: Optional[str] = None + r"""Scope to pass in the OAuth request""" total_memory_limit_kb: Annotated[ Optional[float], pydantic.Field(alias="totalMemoryLimitKB") ] = None r"""Maximum total size of the batches waiting to be sent. If left blank, defaults to 5 times the max body size (if set). If 0, no limit is enforced.""" - load_balanced: Annotated[Optional[bool], pydantic.Field(alias="loadBalanced")] = ( - None - ) - r"""Enable for optimal performance. Even if you have one hostname, it can expand to multiple IPs. If disabled, consider enabling round-robin DNS.""" - description: Optional[str] = None r"""Optional description for this configuration.""" + format_: Annotated[ + Optional[OutputResponseOutputSentinelFormat], pydantic.Field(alias="format") + ] = None + custom_source_expression: Annotated[ Optional[str], pydantic.Field(alias="customSourceExpression") ] = None @@ -20324,100 +19805,30 @@ class OutputResponseOutputWebhookWebhook1(BaseModel): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: Annotated[ - Optional[OutputResponseOutputWebhookPqControls1], + Optional[OutputResponseOutputSentinelPqControls], pydantic.Field(alias="pqControls"), ] = None r"""Persistent queue controls.""" - username: Optional[str] = None - r"""Username""" - - password: Optional[str] = None - r"""Password""" - - token: Optional[str] = None - r"""Bearer token to include in the authorization header""" - - credentials_secret: Annotated[ - Optional[str], pydantic.Field(alias="credentialsSecret") - ] = None - r"""Select or create a secret that references your credentials""" - - text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None - r"""Select or create a stored text secret""" - - login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None - r"""URL for OAuth""" - - secret_param_name: Annotated[ - Optional[str], pydantic.Field(alias="secretParamName") - ] = None - r"""Secret parameter name to pass in request body""" - secret: Optional[str] = None r"""Secret parameter value to pass in request body""" - token_attribute_name: Annotated[ - Optional[str], pydantic.Field(alias="tokenAttributeName") - ] = None - r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" - - auth_header_expr: Annotated[ - Optional[str], pydantic.Field(alias="authHeaderExpr") - ] = None - r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" - - token_timeout_secs: Annotated[ - Optional[float], pydantic.Field(alias="tokenTimeoutSecs") - ] = None - r"""How often the OAuth token should be refreshed.""" - - oauth_params: Annotated[ - Optional[List[OauthParamConfInputServicenowTable]], - pydantic.Field(alias="oauthParams"), - ] = None - r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - oauth_headers: Annotated[ - Optional[List[OauthHeaderConfInputServicenowTable]], - pydantic.Field(alias="oauthHeaders"), - ] = None - r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" - - refresh_token_field: Annotated[ - Optional[str], pydantic.Field(alias="refreshTokenField") - ] = None - r"""Field name in the token response that contains a refresh token (example: 'refresh_token'). When set, @{product} will use the refresh token to obtain new access tokens without re-sending credentials.""" - - rotate_refresh_token: Annotated[ - Optional[bool], pydantic.Field(alias="rotateRefreshToken") - ] = None - r"""@{product} will update the stored value on each successful refresh. Enable if the server issues a new refresh token on every use.""" - - refresh_url: Annotated[Optional[str], pydantic.Field(alias="refreshUrl")] = None - r"""Override the refresh endpoint URL if it differs from the Login URL. Defaults to Login URL.""" - - refresh_request_params: Annotated[ - Optional[List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecret]], - pydantic.Field(alias="refreshRequestParams"), + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") ] = None - r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + r"""Select or create a stored text secret for the OAuth secret value""" - exclude_self: Annotated[Optional[bool], pydantic.Field(alias="excludeSelf")] = None - r"""Exclude all IPs of the current host from the list of any resolved hostnames""" + url: Optional[str] = None + r"""URL to send events to. Can be overwritten by an event's __url field.""" - urls: Optional[List[OutputResponseOutputWebhookURL1]] = None - r"""Webhook URLs""" + dcr_id: Annotated[Optional[str], pydantic.Field(alias="dcrID")] = None + r"""Immutable ID for the Data Collection Rule (DCR)""" - dns_resolve_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="dnsResolvePeriodSec") - ] = None - r"""The interval in which to re-resolve any hostnames and pick up destinations from A records""" + dce_endpoint: Annotated[Optional[str], pydantic.Field(alias="dceEndpoint")] = None + r"""Data collection endpoint (DCE) URL. In the format: `https://-..ingest.monitor.azure.com`""" - load_balance_stats_period_sec: Annotated[ - Optional[float], pydantic.Field(alias="loadBalanceStatsPeriodSec") - ] = None - r"""How far back in time to keep traffic stats for load balancing purposes""" + stream_name: Annotated[Optional[str], pydantic.Field(alias="streamName")] = None + r"""The name of the stream (Sentinel table) in which to store the events""" template_streamtags: Annotated[ Optional[str], pydantic.Field(alias="__template_streamtags") @@ -20439,68 +19850,102 @@ class OutputResponseOutputWebhookWebhook1(BaseModel): ] = None r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: Annotated[ Optional[str], pydantic.Field(alias="__template_refreshUrl") ] = None r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" + template_client_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_client_id") + ] = None + r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" + + template_scope: Annotated[ + Optional[str], pydantic.Field(alias="__template_scope") + ] = None + r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" - notifications: Optional[List[NotificationUnion]] = None + template_dcr_id: Annotated[ + Optional[str], pydantic.Field(alias="__template_dcrID") + ] = None + r"""Binds 'dcrID' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dcrID' at runtime.""" + + template_dce_endpoint: Annotated[ + Optional[str], pydantic.Field(alias="__template_dceEndpoint") + ] = None + r"""Binds 'dceEndpoint' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'dceEndpoint' at runtime.""" + + template_stream_name: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamName") + ] = None + r"""Binds 'streamName' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamName' at runtime.""" + + notifications: Optional[List[Notification]] = None r"""Notifications attached to the Destination.""" status: Optional[StatusType] = None r"""Runtime status: health, metrics, and optional persistent-queue info. Fields may be absent when data is unavailable.""" - @field_serializer("method") - def serialize_method(self, value): + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): if isinstance(value, str): try: - return models.MethodOptions(value) + return models.FailedRequestLoggingModeOptions(value) except ValueError: return value return value - @field_serializer("format_") - def serialize_format_(self, value): + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputWebhookFormat1(value) + return models.BackpressureBehaviorOptions(value) except ValueError: return value return value - @field_serializer("failed_request_logging_mode") - def serialize_failed_request_logging_mode(self, value): + @field_serializer("auth_type") + def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.FailedRequestLoggingModeOptions(value) + return models.OutputResponseAuthType(value) except ValueError: return value return value - @field_serializer("on_backpressure") - def serialize_on_backpressure(self, value): + @field_serializer("oauth_secret_source") + def serialize_oauth_secret_source(self, value): if isinstance(value, str): try: - return models.BackpressureBehaviorOptions(value) + return models.OutputResponseOAuthSecretSource(value) except ValueError: return value return value - @field_serializer("auth_type") - def serialize_auth_type(self, value): + @field_serializer("endpoint_url_configuration") + def serialize_endpoint_url_configuration(self, value): + if isinstance(value, str): + try: + return models.OutputResponseEndpointConfiguration(value) + except ValueError: + return value + return value + + @field_serializer("format_") + def serialize_format_(self, value): if isinstance(value, str): try: - return models.OutputResponseOutputWebhookAuthenticationType1(value) + return models.OutputResponseOutputSentinelFormat(value) except ValueError: return value return value @@ -20541,8 +19986,6 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", - "method", - "format", "keepAlive", "concurrency", "maxPayloadSizeKB", @@ -20561,10 +20004,15 @@ def serialize_model(self, handler): "responseHonorRetryAfterHeader", "onBackpressure", "authType", - "tls", + "refreshTokenField", + "rotateRefreshToken", + "refreshUrl", + "refreshRequestParams", + "oauthSecretSource", + "scope", "totalMemoryLimitKB", - "loadBalanced", "description", + "format", "customSourceExpression", "customDropWhenNull", "customEventDelimiter", @@ -20585,34 +20033,24 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", - "username", - "password", - "token", - "credentialsSecret", - "textSecret", - "loginUrl", - "secretParamName", "secret", - "tokenAttributeName", - "authHeaderExpr", - "tokenTimeoutSecs", - "oauthParams", - "oauthHeaders", - "refreshTokenField", - "rotateRefreshToken", - "refreshUrl", - "refreshRequestParams", - "excludeSelf", - "urls", - "dnsResolvePeriodSec", - "loadBalanceStatsPeriodSec", + "oauthTextSecret", + "url", + "dcrID", + "dceEndpoint", + "streamName", "__template_streamtags", "__template_failedRequestLoggingMode", "__template_onBackpressure", "__template_loginUrl", - "__template_secret", "__template_refreshUrl", + "__template_client_id", + "__template_scope", + "__template_secret", "__template_url", + "__template_dcrID", + "__template_dceEndpoint", + "__template_streamName", "notifications", "status", ] @@ -20631,27 +20069,41 @@ def serialize_model(self, handler): return m -OutputResponseOutputWebhookUnionTypedDict = TypeAliasType( - "OutputResponseOutputWebhookUnionTypedDict", - Union[ - OutputResponseOutputWebhookWebhook1TypedDict, - OutputResponseOutputWebhookWebhook2TypedDict, - ], -) - +class OutputResponseOutputWebhookType2(str, Enum): + r"""Connector type identifier.""" -OutputResponseOutputWebhookUnion = TypeAliasType( - "OutputResponseOutputWebhookUnion", - Union[OutputResponseOutputWebhookWebhook1, OutputResponseOutputWebhookWebhook2], -) + WEBHOOK = "webhook" -class OutputResponseOutputDefaultType(str, Enum): - r"""Connector type identifier.""" +class OutputResponseOutputWebhookFormat2(str, Enum, metaclass=utils.OpenEnumMeta): + r"""How to format events before sending out""" - DEFAULT = "default" + # NDJSON (Newline Delimited JSON) + NDJSON = "ndjson" + # JSON Array + JSON_ARRAY = "json_array" + # Custom + CUSTOM = "custom" + # Advanced + ADVANCED = "advanced" +try: + OutputResponseOutputSns.model_rebuild() +except NameError: + pass +try: + OutputResponseRule.model_rebuild() +except NameError: + pass +try: + OutputResponseOutputRouter.model_rebuild() +except NameError: + pass +try: + OutputResponseOutputGraphite.model_rebuild() +except NameError: + pass try: OutputResponseOutputStatsdExt.model_rebuild() except NameError: @@ -20824,19 +20276,3 @@ class OutputResponseOutputDefaultType(str, Enum): OutputResponseOutputSentinel.model_rebuild() except NameError: pass -try: - OutputResponseOutputWebhookURL2.model_rebuild() -except NameError: - pass -try: - OutputResponseOutputWebhookWebhook2.model_rebuild() -except NameError: - pass -try: - OutputResponseOutputWebhookURL1.model_rebuild() -except NameError: - pass -try: - OutputResponseOutputWebhookWebhook1.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/outputrouter.py b/src/cribl_control_plane/models/outputrouter.py index 2a665878f..af7bff1ea 100644 --- a/src/cribl_control_plane/models/outputrouter.py +++ b/src/cribl_control_plane/models/outputrouter.py @@ -71,6 +71,8 @@ class OutputRouterTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" + report_branch_metrics: NotRequired[bool] + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" description: NotRequired[str] r"""Optional description for this configuration.""" template_streamtags: NotRequired[str] @@ -101,6 +103,11 @@ class OutputRouter(BaseModel): streamtags: Optional[List[str]] = None r"""Metadata tags used for categorization and filtering.""" + report_branch_metrics: Annotated[ + Optional[bool], pydantic.Field(alias="reportBranchMetrics") + ] = None + r"""Report per-rule event counts and percentages as internal metrics (router.out_events, router.out_events_pct, router.in_events, router.unmatched_events, router.unmatched_events_pct). Adds metric series per rule.""" + description: Optional[str] = None r"""Optional description for this configuration.""" @@ -118,6 +125,7 @@ def serialize_model(self, handler): "systemFields", "environment", "streamtags", + "reportBranchMetrics", "description", "__template_streamtags", ] diff --git a/src/cribl_control_plane/models/outputsentinel.py b/src/cribl_control_plane/models/outputsentinel.py index 90e2bee22..7a49d618c 100644 --- a/src/cribl_control_plane/models/outputsentinel.py +++ b/src/cribl_control_plane/models/outputsentinel.py @@ -43,6 +43,13 @@ class AuthTypeEnum(str, Enum, metaclass=utils.OpenEnumMeta): OAUTH = "oauth" +class OAuthSecretSource(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Enter the OAuth secret directly, or select a stored text secret""" + + INLINE = "inline" + SECRET = "secret" + + class EndpointConfiguration(str, Enum, metaclass=utils.OpenEnumMeta): r"""Enter the data collection endpoint URL or the individual ID""" @@ -72,8 +79,6 @@ class OutputSentinelTypedDict(TypedDict): r"""Connector type identifier.""" login_url: str r"""URL for OAuth""" - secret: str - r"""Secret parameter value to pass in request body""" client_id: str r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" endpoint_url_configuration: EndpointConfiguration @@ -138,6 +143,8 @@ class OutputSentinelTypedDict(TypedDict): List[RefreshRequestParamConfHealthCheckAuthenticationOauthSecretTypedDict] ] r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + oauth_secret_source: NotRequired[OAuthSecretSource] + r"""Enter the OAuth secret directly, or select a stored text secret""" scope: NotRequired[str] r"""Scope to pass in the OAuth request""" total_memory_limit_kb: NotRequired[float] @@ -185,6 +192,10 @@ class OutputSentinelTypedDict(TypedDict): r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" pq_controls: NotRequired[OutputSentinelPqControlsTypedDict] r"""Persistent queue controls.""" + secret: NotRequired[str] + r"""Secret parameter value to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret value""" url: NotRequired[str] r"""URL to send events to. Can be overwritten by an event's __url field.""" dcr_id: NotRequired[str] @@ -201,14 +212,14 @@ class OutputSentinelTypedDict(TypedDict): r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" template_login_url: NotRequired[str] r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: NotRequired[str] - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_refresh_url: NotRequired[str] r"""Binds 'refreshUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'refreshUrl' at runtime.""" template_client_id: NotRequired[str] r"""Binds 'client_id' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'client_id' at runtime.""" template_scope: NotRequired[str] r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_secret: NotRequired[str] + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" template_url: NotRequired[str] r"""Binds 'url' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'url' at runtime.""" template_dcr_id: NotRequired[str] @@ -226,9 +237,6 @@ class OutputSentinel(BaseModel): login_url: Annotated[str, pydantic.Field(alias="loginUrl")] r"""URL for OAuth""" - secret: str - r"""Secret parameter value to pass in request body""" - client_id: str r"""JavaScript expression to compute the Client ID for the Azure application. Can be a constant.""" @@ -360,6 +368,11 @@ class OutputSentinel(BaseModel): ] = None r"""Parameters to include in the refresh token request body. Most servers require 'client_id' here. If not set, @{product} sends only grant_type, refresh_token, and client_secret.""" + oauth_secret_source: Annotated[ + Optional[OAuthSecretSource], pydantic.Field(alias="oauthSecretSource") + ] = None + r"""Enter the OAuth secret directly, or select a stored text secret""" + scope: Optional[str] = None r"""Scope to pass in the OAuth request""" @@ -469,6 +482,14 @@ class OutputSentinel(BaseModel): ] = None r"""Persistent queue controls.""" + secret: Optional[str] = None + r"""Secret parameter value to pass in request body""" + + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth secret value""" + url: Optional[str] = None r"""URL to send events to. Can be overwritten by an event's __url field.""" @@ -501,11 +522,6 @@ class OutputSentinel(BaseModel): ] = None r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" - template_secret: Annotated[ - Optional[str], pydantic.Field(alias="__template_secret") - ] = None - r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" - template_refresh_url: Annotated[ Optional[str], pydantic.Field(alias="__template_refreshUrl") ] = None @@ -521,6 +537,11 @@ class OutputSentinel(BaseModel): ] = None r"""Binds 'scope' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'scope' at runtime.""" + template_secret: Annotated[ + Optional[str], pydantic.Field(alias="__template_secret") + ] = None + r"""Binds 'secret' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'secret' at runtime.""" + template_url: Annotated[Optional[str], pydantic.Field(alias="__template_url")] = ( None ) @@ -568,6 +589,15 @@ def serialize_auth_type(self, value): return value return value + @field_serializer("oauth_secret_source") + def serialize_oauth_secret_source(self, value): + if isinstance(value, str): + try: + return models.OAuthSecretSource(value) + except ValueError: + return value + return value + @field_serializer("endpoint_url_configuration") def serialize_endpoint_url_configuration(self, value): if isinstance(value, str): @@ -644,6 +674,7 @@ def serialize_model(self, handler): "rotateRefreshToken", "refreshUrl", "refreshRequestParams", + "oauthSecretSource", "scope", "totalMemoryLimitKB", "description", @@ -668,6 +699,8 @@ def serialize_model(self, handler): "pqOnBackpressure", "pqMaxBufferSizeBytes", "pqControls", + "secret", + "oauthTextSecret", "url", "dcrID", "dceEndpoint", @@ -676,10 +709,10 @@ def serialize_model(self, handler): "__template_failedRequestLoggingMode", "__template_onBackpressure", "__template_loginUrl", - "__template_secret", "__template_refreshUrl", "__template_client_id", "__template_scope", + "__template_secret", "__template_url", "__template_dcrID", "__template_dceEndpoint", diff --git a/src/cribl_control_plane/models/outputsentineloneaisiem.py b/src/cribl_control_plane/models/outputsentineloneaisiem.py index bbe4ea567..7bfb28b1a 100644 --- a/src/cribl_control_plane/models/outputsentineloneaisiem.py +++ b/src/cribl_control_plane/models/outputsentineloneaisiem.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionspq import CompressionOptionsPq @@ -105,7 +105,7 @@ class OutputSentinelOneAiSiemTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -266,7 +266,7 @@ class OutputSentinelOneAiSiem(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -447,7 +447,7 @@ def serialize_failed_request_logging_mode(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputsignalfx.py b/src/cribl_control_plane/models/outputsignalfx.py index c06790f0b..69a82c8d6 100644 --- a/src/cribl_control_plane/models/outputsignalfx.py +++ b/src/cribl_control_plane/models/outputsignalfx.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionspq import CompressionOptionsPq @@ -59,7 +59,7 @@ class OutputSignalfxTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" @@ -160,7 +160,7 @@ class OutputSignalfx(BaseModel): r"""Metadata tags used for categorization and filtering.""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -326,7 +326,7 @@ class OutputSignalfx(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputsplunk.py b/src/cribl_control_plane/models/outputsplunk.py index 664026fb4..3161ec2f1 100644 --- a/src/cribl_control_plane/models/outputsplunk.py +++ b/src/cribl_control_plane/models/outputsplunk.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptions import CompressionOptions @@ -69,7 +69,7 @@ class OutputSplunkTypedDict(TypedDict): r"""The highest S2S protocol version to advertise during handshake""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -195,7 +195,7 @@ class OutputSplunk(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -337,7 +337,7 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputsplunkhec.py b/src/cribl_control_plane/models/outputsplunkhec.py index 5ed9353a4..0a4692d3f 100644 --- a/src/cribl_control_plane/models/outputsplunkhec.py +++ b/src/cribl_control_plane/models/outputsplunkhec.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionspq import CompressionOptionsPq @@ -130,7 +130,7 @@ class OutputSplunkHecTypedDict(TypedDict): r"""List of headers that are safe to log in plain text""" enable_multi_metrics: NotRequired[bool] r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -286,7 +286,7 @@ class OutputSplunkHec(BaseModel): r"""Output metrics in multiple-metric format, supported in Splunk 8.0 and above to allow multiple metrics in a single event.""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -437,7 +437,7 @@ def serialize_failed_request_logging_mode(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputsplunklb.py b/src/cribl_control_plane/models/outputsplunklb.py index fa72dfd16..c388db825 100644 --- a/src/cribl_control_plane/models/outputsplunklb.py +++ b/src/cribl_control_plane/models/outputsplunklb.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptions import CompressionOptions @@ -32,7 +32,7 @@ class OutputSplunkLbType(str, Enum): class OutputSplunkLbAuthTokenTypedDict(TypedDict): - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" auth_token: NotRequired[str] r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" @@ -42,7 +42,7 @@ class OutputSplunkLbAuthTokenTypedDict(TypedDict): class OutputSplunkLbAuthToken(BaseModel): auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -57,7 +57,7 @@ class OutputSplunkLbAuthToken(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -92,7 +92,7 @@ class IndexerDiscoveryConfigsTypedDict(TypedDict): r"""During indexer discovery, reject cluster manager certificates that are not authorized by the system's CA. Disable to allow untrusted (for example, self-signed) certificates.""" auth_tokens: NotRequired[List[OutputSplunkLbAuthTokenTypedDict]] r"""Tokens required to authenticate to cluster manager for indexer discovery""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" auth_token: NotRequired[str] r"""Shared secret to be provided by any client (in authToken header field). If empty, unauthorized access is permitted.""" @@ -123,7 +123,7 @@ class IndexerDiscoveryConfigs(BaseModel): r"""Tokens required to authenticate to cluster manager for indexer discovery""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -138,7 +138,7 @@ class IndexerDiscoveryConfigs(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value @@ -215,7 +215,7 @@ class OutputSplunkLbTypedDict(TypedDict): r"""Automatically discover indexers in indexer clustering environment.""" sender_unhealthy_time_allowance: NotRequired[float] r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -363,7 +363,7 @@ class OutputSplunkLb(BaseModel): r"""How long (in milliseconds) each LB endpoint can report blocked before the Destination reports unhealthy, blocking the sender. (Grace period for fluctuations.) Use 0 to disable; max 1 minute.""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -504,7 +504,7 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputtcpjson.py b/src/cribl_control_plane/models/outputtcpjson.py index 60545d0dc..48f187e67 100644 --- a/src/cribl_control_plane/models/outputtcpjson.py +++ b/src/cribl_control_plane/models/outputtcpjson.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionsgzipnone import CompressionOptionsGzipNone @@ -64,7 +64,7 @@ class OutputTcpjsonTypedDict(TypedDict): r"""Upon connection, send a header-like record containing the auth token and other metadata.This record will not contain an actual event – only subsequent records will.""" on_backpressure: NotRequired[BackpressureBehaviorOptions] r"""How to handle events when all receivers are exerting backpressure""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" description: NotRequired[str] r"""Optional description for this configuration.""" @@ -186,7 +186,7 @@ class OutputTcpjson(BaseModel): r"""How to handle events when all receivers are exerting backpressure""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -323,7 +323,7 @@ def serialize_on_backpressure(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputtraversalotlp.py b/src/cribl_control_plane/models/outputtraversalotlp.py new file mode 100644 index 000000000..5d01e76e0 --- /dev/null +++ b/src/cribl_control_plane/models/outputtraversalotlp.py @@ -0,0 +1,644 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .backpressurebehavioroptions import BackpressureBehaviorOptions +from .compressionoptionsdeflategzip import CompressionOptionsDeflateGzip +from .compressionoptionsmessages import CompressionOptionsMessages +from .compressionoptionspq import CompressionOptionsPq +from .extrahttpheaderconfinputelastic import ( + ExtraHTTPHeaderConfInputElastic, + ExtraHTTPHeaderConfInputElasticTypedDict, +) +from .failedrequestloggingmodeoptions import FailedRequestLoggingModeOptions +from .keyvaluemetadataconfoutputfilesystem import ( + KeyValueMetadataConfOutputFilesystem, + KeyValueMetadataConfOutputFilesystemTypedDict, +) +from .modeoptions import ModeOptions +from .oauthheaderconfinputservicenowtable import ( + OauthHeaderConfInputServicenowTable, + OauthHeaderConfInputServicenowTableTypedDict, +) +from .oauthparamconfinputservicenowtable import ( + OauthParamConfInputServicenowTable, + OauthParamConfInputServicenowTableTypedDict, +) +from .protocoloptions import ProtocolOptions +from .queuefullbehavioroptions import QueueFullBehaviorOptions +from .responseretrysettingconfoutputwebhook import ( + ResponseRetrySettingConfOutputWebhook, + ResponseRetrySettingConfOutputWebhookTypedDict, +) +from .timeoutretrysettingstype import ( + TimeoutRetrySettingsType, + TimeoutRetrySettingsTypeTypedDict, +) +from .tlssettingsclientsidetypeextended import ( + TLSSettingsClientSideTypeExtended, + TLSSettingsClientSideTypeExtendedTypedDict, +) +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class OutputTraversalOtlpType(str, Enum): + r"""Connector type identifier.""" + + TRAVERSAL_OTLP = "traversal_otlp" + + +class OutputTraversalOtlpAuthenticationType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""Authentication type""" + + # None + NONE = "none" + # Basic (credentials secret) + CREDENTIALS_SECRET = "credentialsSecret" + # Token (text secret) + TEXT_SECRET = "textSecret" + # OAuth (text secret) + OAUTH_SECRET = "oauthSecret" + + +class OutputTraversalOtlpPqControlsTypedDict(TypedDict): + r"""Persistent queue controls.""" + + +class OutputTraversalOtlpPqControls(BaseModel): + r"""Persistent queue controls.""" + + +class OutputTraversalOtlpTypedDict(TypedDict): + type: OutputTraversalOtlpType + r"""Connector type identifier.""" + endpoint: str + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" + id: NotRequired[str] + r"""Unique ID for this output""" + pipeline: NotRequired[str] + r"""Pipeline to process data before sending out to this output""" + system_fields: NotRequired[List[str]] + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + environment: NotRequired[str] + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + streamtags: NotRequired[List[str]] + r"""Metadata tags used for categorization and filtering.""" + auth_type: NotRequired[OutputTraversalOtlpAuthenticationType] + r"""Authentication type""" + protocol: NotRequired[ProtocolOptions] + r"""Select a transport option for OpenTelemetry""" + preserve_native_any_value: NotRequired[bool] + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + compress: NotRequired[CompressionOptionsDeflateGzip] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_compress: NotRequired[CompressionOptionsMessages] + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + http_logs_endpoint_override: NotRequired[str] + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + metadata: NotRequired[List[KeyValueMetadataConfOutputFilesystemTypedDict]] + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + dynamic_headers_enabled: NotRequired[bool] + r"""Batch event data upon dynamic metadata (whether presented or not)""" + dynamic_headers_field: NotRequired[str] + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + concurrency: NotRequired[float] + r"""Maximum number of ongoing requests before blocking""" + max_payload_size_kb: NotRequired[float] + r"""Maximum size, in KB, of the request body""" + timeout_sec: NotRequired[float] + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + max_connection_reuse_sec: NotRequired[float] + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + flush_period_sec: NotRequired[float] + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + failed_request_logging_mode: NotRequired[FailedRequestLoggingModeOptions] + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + connection_timeout: NotRequired[float] + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + keep_alive_time: NotRequired[float] + r"""How often the sender should ping the peer to keep the connection open""" + keep_alive: NotRequired[bool] + r"""Disable to close the connection immediately after sending the outgoing request""" + on_backpressure: NotRequired[BackpressureBehaviorOptions] + r"""How to handle events when all receivers are exerting backpressure""" + description: NotRequired[str] + r"""Optional description for this configuration.""" + credentials_secret: NotRequired[str] + r"""Select or create a secret that references your credentials""" + text_secret: NotRequired[str] + r"""Select or create a stored text secret""" + login_url: NotRequired[str] + r"""URL for OAuth""" + secret_param_name: NotRequired[str] + r"""Secret parameter name to pass in request body""" + oauth_text_secret: NotRequired[str] + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + token_attribute_name: NotRequired[str] + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + auth_header_expr: NotRequired[str] + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + token_timeout_secs: NotRequired[float] + r"""How often the OAuth token should be refreshed.""" + oauth_params: NotRequired[List[OauthParamConfInputServicenowTableTypedDict]] + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + oauth_headers: NotRequired[List[OauthHeaderConfInputServicenowTableTypedDict]] + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + reject_unauthorized: NotRequired[bool] + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + use_round_robin_dns: NotRequired[bool] + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + extra_http_headers: NotRequired[List[ExtraHTTPHeaderConfInputElasticTypedDict]] + r"""Headers to add to all events""" + safe_headers: NotRequired[List[str]] + r"""List of headers that are safe to log in plain text""" + response_retry_settings: NotRequired[ + List[ResponseRetrySettingConfOutputWebhookTypedDict] + ] + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + timeout_retry_settings: NotRequired[TimeoutRetrySettingsTypeTypedDict] + response_honor_retry_after_header: NotRequired[bool] + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + tls: NotRequired[TLSSettingsClientSideTypeExtendedTypedDict] + r"""TLS settings (client side)""" + pq_strict_ordering: NotRequired[bool] + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + pq_rate_per_sec: NotRequired[float] + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + pq_mode: NotRequired[ModeOptions] + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + pq_max_buffer_size: NotRequired[float] + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + pq_max_backpressure_sec: NotRequired[float] + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + pq_max_file_size: NotRequired[str] + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + pq_max_size: NotRequired[str] + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + pq_path: NotRequired[str] + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + pq_compress: NotRequired[CompressionOptionsPq] + r"""Codec to use to compress the persisted data""" + pq_on_backpressure: NotRequired[QueueFullBehaviorOptions] + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + pq_max_buffer_size_bytes: NotRequired[str] + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + pq_controls: NotRequired[OutputTraversalOtlpPqControlsTypedDict] + r"""Persistent queue controls.""" + template_streamtags: NotRequired[str] + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + template_failed_request_logging_mode: NotRequired[str] + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + template_on_backpressure: NotRequired[str] + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + template_login_url: NotRequired[str] + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + +class OutputTraversalOtlp(BaseModel): + type: OutputTraversalOtlpType + r"""Connector type identifier.""" + + endpoint: str + r"""The endpoint where OTel log events will be sent. Enter any valid URL or an IP address (IPv4 or IPv6; enclose IPv6 addresses in square brackets).""" + + id: Optional[str] = None + r"""Unique ID for this output""" + + pipeline: Optional[str] = None + r"""Pipeline to process data before sending out to this output""" + + system_fields: Annotated[ + Optional[List[str]], pydantic.Field(alias="systemFields") + ] = None + r"""Fields to automatically add to events, such as cribl_pipe. Supports wildcards.""" + + environment: Optional[str] = None + r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" + + streamtags: Optional[List[str]] = None + r"""Metadata tags used for categorization and filtering.""" + + auth_type: Annotated[ + Optional[OutputTraversalOtlpAuthenticationType], + pydantic.Field(alias="authType"), + ] = None + r"""Authentication type""" + + protocol: Optional[ProtocolOptions] = None + r"""Select a transport option for OpenTelemetry""" + + preserve_native_any_value: Annotated[ + Optional[bool], pydantic.Field(alias="preserveNativeAnyValue") + ] = None + r"""Values already in OTLP AnyValue form (e.g. {string_value: \"...\"}) are serialized directly instead of being wrapped as key-value maps""" + + compress: Optional[CompressionOptionsDeflateGzip] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + http_compress: Annotated[ + Optional[CompressionOptionsMessages], pydantic.Field(alias="httpCompress") + ] = None + r"""Type of compression to apply to messages sent to the OpenTelemetry endpoint""" + + http_logs_endpoint_override: Annotated[ + Optional[str], pydantic.Field(alias="httpLogsEndpointOverride") + ] = None + r"""If you want to send logs to the default `{endpoint}/v1/logs` endpoint, leave this field empty; otherwise, specify the desired endpoint""" + + metadata: Optional[List[KeyValueMetadataConfOutputFilesystem]] = None + r"""List of key-value pairs to send with each gRPC request. Value supports JavaScript expressions that are evaluated just once, when the destination gets started. To pass credentials as metadata, use 'C.Secret'.""" + + dynamic_headers_enabled: Annotated[ + Optional[bool], pydantic.Field(alias="dynamicHeadersEnabled") + ] = None + r"""Batch event data upon dynamic metadata (whether presented or not)""" + + dynamic_headers_field: Annotated[ + Optional[str], pydantic.Field(alias="dynamicHeadersField") + ] = None + r"""When presented, this field which contains metadata, will be injected into the Destination metadata and used to batch events.""" + + concurrency: Optional[float] = None + r"""Maximum number of ongoing requests before blocking""" + + max_payload_size_kb: Annotated[ + Optional[float], pydantic.Field(alias="maxPayloadSizeKB") + ] = None + r"""Maximum size, in KB, of the request body""" + + timeout_sec: Annotated[Optional[float], pydantic.Field(alias="timeoutSec")] = None + r"""Amount of time, in seconds, to wait for a request to complete before canceling it""" + + max_connection_reuse_sec: Annotated[ + Optional[float], pydantic.Field(alias="maxConnectionReuseSec") + ] = None + r"""How long, in seconds, to reuse a keep-alive connection after its first use before forcing it closed. Set to 0 to disable the time-based close and reuse connections for as long as the destination server permits.""" + + flush_period_sec: Annotated[ + Optional[float], pydantic.Field(alias="flushPeriodSec") + ] = None + r"""Maximum time between requests. Small values could cause the payload size to be smaller than the configured Body size limit.""" + + failed_request_logging_mode: Annotated[ + Optional[FailedRequestLoggingModeOptions], + pydantic.Field(alias="failedRequestLoggingMode"), + ] = None + r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" + + connection_timeout: Annotated[ + Optional[float], pydantic.Field(alias="connectionTimeout") + ] = None + r"""Amount of time (milliseconds) to wait for the connection to establish before retrying""" + + keep_alive_time: Annotated[ + Optional[float], pydantic.Field(alias="keepAliveTime") + ] = None + r"""How often the sender should ping the peer to keep the connection open""" + + keep_alive: Annotated[Optional[bool], pydantic.Field(alias="keepAlive")] = None + r"""Disable to close the connection immediately after sending the outgoing request""" + + on_backpressure: Annotated[ + Optional[BackpressureBehaviorOptions], pydantic.Field(alias="onBackpressure") + ] = None + r"""How to handle events when all receivers are exerting backpressure""" + + description: Optional[str] = None + r"""Optional description for this configuration.""" + + credentials_secret: Annotated[ + Optional[str], pydantic.Field(alias="credentialsSecret") + ] = None + r"""Select or create a secret that references your credentials""" + + text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None + r"""Select or create a stored text secret""" + + login_url: Annotated[Optional[str], pydantic.Field(alias="loginUrl")] = None + r"""URL for OAuth""" + + secret_param_name: Annotated[ + Optional[str], pydantic.Field(alias="secretParamName") + ] = None + r"""Secret parameter name to pass in request body""" + + oauth_text_secret: Annotated[ + Optional[str], pydantic.Field(alias="oauthTextSecret") + ] = None + r"""Select or create a stored text secret for the OAuth secret parameter value to pass in request body""" + + token_attribute_name: Annotated[ + Optional[str], pydantic.Field(alias="tokenAttributeName") + ] = None + r"""Name of the auth token attribute in the OAuth response. Can be top-level (e.g., 'token'); or nested, using a period (e.g., 'data.token').""" + + auth_header_expr: Annotated[ + Optional[str], pydantic.Field(alias="authHeaderExpr") + ] = None + r"""JavaScript expression to compute the Authorization header value to pass in requests. The value `${token}` is used to reference the token obtained from authentication, e.g.: `Bearer ${token}`.""" + + token_timeout_secs: Annotated[ + Optional[float], pydantic.Field(alias="tokenTimeoutSecs") + ] = None + r"""How often the OAuth token should be refreshed.""" + + oauth_params: Annotated[ + Optional[List[OauthParamConfInputServicenowTable]], + pydantic.Field(alias="oauthParams"), + ] = None + r"""Additional parameters to send in the OAuth login request. @{product} will combine the secret with these parameters, and will send the URL-encoded result in a POST request to the endpoint specified in the 'Login URL'. We'll automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + oauth_headers: Annotated[ + Optional[List[OauthHeaderConfInputServicenowTable]], + pydantic.Field(alias="oauthHeaders"), + ] = None + r"""Additional headers to send in the OAuth login request. @{product} will automatically add the content-type header 'application/x-www-form-urlencoded' when sending this request.""" + + reject_unauthorized: Annotated[ + Optional[bool], pydantic.Field(alias="rejectUnauthorized") + ] = None + r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's). + Enabled by default. When this setting is also present in TLS Settings (Client Side), + that value will take precedence. + """ + + use_round_robin_dns: Annotated[ + Optional[bool], pydantic.Field(alias="useRoundRobinDns") + ] = None + r"""Enable round-robin DNS lookup. When a DNS server returns multiple addresses, @{product} will cycle through them in the order returned. For optimal performance, consider enabling this setting for non-load balanced destinations.""" + + extra_http_headers: Annotated[ + Optional[List[ExtraHTTPHeaderConfInputElastic]], + pydantic.Field(alias="extraHttpHeaders"), + ] = None + r"""Headers to add to all events""" + + safe_headers: Annotated[ + Optional[List[str]], pydantic.Field(alias="safeHeaders") + ] = None + r"""List of headers that are safe to log in plain text""" + + response_retry_settings: Annotated[ + Optional[List[ResponseRetrySettingConfOutputWebhook]], + pydantic.Field(alias="responseRetrySettings"), + ] = None + r"""Automatically retry after unsuccessful response status codes, such as 429 (Too Many Requests) or 503 (Service Unavailable)""" + + timeout_retry_settings: Annotated[ + Optional[TimeoutRetrySettingsType], pydantic.Field(alias="timeoutRetrySettings") + ] = None + + response_honor_retry_after_header: Annotated[ + Optional[bool], pydantic.Field(alias="responseHonorRetryAfterHeader") + ] = None + r"""Honor any Retry-After header that specifies a delay (in seconds) no longer than 180 seconds after the retry request. @{product} limits the delay to 180 seconds, even if the Retry-After header specifies a longer delay. When enabled, takes precedence over user-configured retry options. When disabled, all Retry-After headers are ignored.""" + + tls: Optional[TLSSettingsClientSideTypeExtended] = None + r"""TLS settings (client side)""" + + pq_strict_ordering: Annotated[ + Optional[bool], pydantic.Field(alias="pqStrictOrdering") + ] = None + r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" + + pq_rate_per_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqRatePerSec") + ] = None + r"""Throttling rate (in events per second) to impose while writing to Destinations from PQ. Defaults to 0, which disables throttling.""" + + pq_mode: Annotated[Optional[ModeOptions], pydantic.Field(alias="pqMode")] = None + r"""In Error mode, PQ writes events to the filesystem if the Destination is unavailable. In Backpressure mode, PQ writes events to the filesystem when it detects backpressure from the Destination. In Always On mode, PQ always writes events to the filesystem.""" + + pq_max_buffer_size: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBufferSize") + ] = None + r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use pqMaxBufferSizeBytes instead.""" + + pq_max_backpressure_sec: Annotated[ + Optional[float], pydantic.Field(alias="pqMaxBackpressureSec") + ] = None + r"""How long (in seconds) to wait for backpressure to resolve before engaging the queue""" + + pq_max_file_size: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxFileSize") + ] = None + r"""The maximum size to store in each queue file before closing and optionally compressing (KB, MB, etc.)""" + + pq_max_size: Annotated[Optional[str], pydantic.Field(alias="pqMaxSize")] = None + r"""The maximum disk space that the queue can consume (as an average per Worker Process) before queueing stops. Enter a numeral with units of KB, MB, etc.""" + + pq_path: Annotated[Optional[str], pydantic.Field(alias="pqPath")] = None + r"""The location for the persistent queue files. To this field's value, the system will append: //.""" + + pq_compress: Annotated[ + Optional[CompressionOptionsPq], pydantic.Field(alias="pqCompress") + ] = None + r"""Codec to use to compress the persisted data""" + + pq_on_backpressure: Annotated[ + Optional[QueueFullBehaviorOptions], pydantic.Field(alias="pqOnBackpressure") + ] = None + r"""How to handle events when the queue is exerting backpressure (full capacity or low disk). 'Block' is the same behavior as non-PQ blocking. 'Drop new data' throws away incoming data, while leaving the contents of the PQ unchanged.""" + + pq_max_buffer_size_bytes: Annotated[ + Optional[str], pydantic.Field(alias="pqMaxBufferSizeBytes") + ] = None + r"""The maximum size to hold in memory before writing events to disk. Enter a numeral with units of KB, MB, etc. The minimum value is 64KB and the maximum value is 10MB.""" + + pq_controls: Annotated[ + Optional[OutputTraversalOtlpPqControls], pydantic.Field(alias="pqControls") + ] = None + r"""Persistent queue controls.""" + + template_streamtags: Annotated[ + Optional[str], pydantic.Field(alias="__template_streamtags") + ] = None + r"""Binds 'streamtags' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'streamtags' at runtime.""" + + template_failed_request_logging_mode: Annotated[ + Optional[str], pydantic.Field(alias="__template_failedRequestLoggingMode") + ] = None + r"""Binds 'failedRequestLoggingMode' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'failedRequestLoggingMode' at runtime.""" + + template_on_backpressure: Annotated[ + Optional[str], pydantic.Field(alias="__template_onBackpressure") + ] = None + r"""Binds 'onBackpressure' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'onBackpressure' at runtime.""" + + template_login_url: Annotated[ + Optional[str], pydantic.Field(alias="__template_loginUrl") + ] = None + r"""Binds 'loginUrl' to a variable for dynamic value resolution. Set to variable ID (pack-scoped) or 'cribl.'/'edge.' prefixed ID (group-scoped). Variable value overrides 'loginUrl' at runtime.""" + + @field_serializer("auth_type") + def serialize_auth_type(self, value): + if isinstance(value, str): + try: + return models.OutputTraversalOtlpAuthenticationType(value) + except ValueError: + return value + return value + + @field_serializer("protocol") + def serialize_protocol(self, value): + if isinstance(value, str): + try: + return models.ProtocolOptions(value) + except ValueError: + return value + return value + + @field_serializer("compress") + def serialize_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsDeflateGzip(value) + except ValueError: + return value + return value + + @field_serializer("http_compress") + def serialize_http_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsMessages(value) + except ValueError: + return value + return value + + @field_serializer("failed_request_logging_mode") + def serialize_failed_request_logging_mode(self, value): + if isinstance(value, str): + try: + return models.FailedRequestLoggingModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("on_backpressure") + def serialize_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.BackpressureBehaviorOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_mode") + def serialize_pq_mode(self, value): + if isinstance(value, str): + try: + return models.ModeOptions(value) + except ValueError: + return value + return value + + @field_serializer("pq_compress") + def serialize_pq_compress(self, value): + if isinstance(value, str): + try: + return models.CompressionOptionsPq(value) + except ValueError: + return value + return value + + @field_serializer("pq_on_backpressure") + def serialize_pq_on_backpressure(self, value): + if isinstance(value, str): + try: + return models.QueueFullBehaviorOptions(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set( + [ + "id", + "pipeline", + "systemFields", + "environment", + "streamtags", + "authType", + "protocol", + "preserveNativeAnyValue", + "compress", + "httpCompress", + "httpLogsEndpointOverride", + "metadata", + "dynamicHeadersEnabled", + "dynamicHeadersField", + "concurrency", + "maxPayloadSizeKB", + "timeoutSec", + "maxConnectionReuseSec", + "flushPeriodSec", + "failedRequestLoggingMode", + "connectionTimeout", + "keepAliveTime", + "keepAlive", + "onBackpressure", + "description", + "credentialsSecret", + "textSecret", + "loginUrl", + "secretParamName", + "oauthTextSecret", + "tokenAttributeName", + "authHeaderExpr", + "tokenTimeoutSecs", + "oauthParams", + "oauthHeaders", + "rejectUnauthorized", + "useRoundRobinDns", + "extraHttpHeaders", + "safeHeaders", + "responseRetrySettings", + "timeoutRetrySettings", + "responseHonorRetryAfterHeader", + "tls", + "pqStrictOrdering", + "pqRatePerSec", + "pqMode", + "pqMaxBufferSize", + "pqMaxBackpressureSec", + "pqMaxFileSize", + "pqMaxSize", + "pqPath", + "pqCompress", + "pqOnBackpressure", + "pqMaxBufferSizeBytes", + "pqControls", + "__template_streamtags", + "__template_failedRequestLoggingMode", + "__template_onBackpressure", + "__template_loginUrl", + ] + ) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + OutputTraversalOtlp.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/outputwavefront.py b/src/cribl_control_plane/models/outputwavefront.py index be5289f66..34189dae9 100644 --- a/src/cribl_control_plane/models/outputwavefront.py +++ b/src/cribl_control_plane/models/outputwavefront.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionspq import CompressionOptionsPq @@ -59,7 +59,7 @@ class OutputWavefrontTypedDict(TypedDict): r"""Optionally, enable this config only on a specified Git branch. If empty, will be enabled everywhere.""" streamtags: NotRequired[List[str]] r"""Metadata tags used for categorization and filtering.""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" concurrency: NotRequired[float] r"""Maximum number of ongoing requests before blocking""" @@ -160,7 +160,7 @@ class OutputWavefront(BaseModel): r"""Metadata tags used for categorization and filtering.""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -326,7 +326,7 @@ class OutputWavefront(BaseModel): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) except ValueError: return value return value diff --git a/src/cribl_control_plane/models/outputwizhec.py b/src/cribl_control_plane/models/outputwizhec.py index aefd5a7a3..38cd46899 100644 --- a/src/cribl_control_plane/models/outputwizhec.py +++ b/src/cribl_control_plane/models/outputwizhec.py @@ -1,8 +1,8 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations -from .authenticationmethodoptionsauthtokensitems import ( - AuthenticationMethodOptionsAuthTokensItems, +from .authenticationmethodoptionsauthtokensextitems import ( + AuthenticationMethodOptionsAuthTokensExtItems, ) from .backpressurebehavioroptions import BackpressureBehaviorOptions from .compressionoptionspq import CompressionOptionsPq @@ -25,7 +25,7 @@ TLSSettingsClientSideTypeCaPathCertPathExtended, TLSSettingsClientSideTypeCaPathCertPathExtendedTypedDict, ) -from cribl_control_plane import models +from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum import pydantic @@ -40,6 +40,26 @@ class OutputWizHecType(str, Enum): WIZ_HEC = "wiz_hec" +class WizDefendSourceType(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" + + AWS_CLOUDTRAIL = "AWS_CLOUDTRAIL" + AWS_EKS_AUDIT_LOGS = "AWS_EKS_AUDIT_LOGS" + AWS_RESOLVER_QUERY_LOGS = "AWS_RESOLVER_QUERY_LOGS" + AZURE_ACTIVITY_LOGS = "AZURE_ACTIVITY_LOGS" + GCP_AUDIT_LOGS = "GCP_AUDIT_LOGS" + GITHUB_AUDIT_LOGS = "GITHUB_AUDIT_LOGS" + OCI_AUDIT_LOGS = "OCI_AUDIT_LOGS" + AWS_VPC_FLOW_LOGS = "AWS_VPC_FLOW_LOGS" + + +class OutputWizHecEventFormat(str, Enum, metaclass=utils.OpenEnumMeta): + r"""The format of the VPC Flow Log events""" + + JSON = "json" + CSV_ROW = "csv_row" + + class OutputWizHecPqControlsTypedDict(TypedDict): r"""Persistent queue controls.""" @@ -57,8 +77,8 @@ class OutputWizHecTypedDict(TypedDict): r"""Your Wiz deployment environment""" data_center: str r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - wiz_sourcetype: str - r"""Wiz Defend Source type""" + wiz_sourcetype: WizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" id: NotRequired[str] r"""Unique ID for this output""" pipeline: NotRequired[str] @@ -96,7 +116,7 @@ class OutputWizHecTypedDict(TypedDict): r"""Data to log when a request fails. All headers are redacted by default, unless listed as safe headers below.""" safe_headers: NotRequired[List[str]] r"""List of headers that are safe to log in plain text""" - auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensItems] + auth_type: NotRequired[AuthenticationMethodOptionsAuthTokensExtItems] r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" response_retry_settings: NotRequired[ List[ResponseRetrySettingConfOutputWebhookTypedDict] @@ -113,6 +133,10 @@ class OutputWizHecTypedDict(TypedDict): r"""Wiz Defend Auth token""" text_secret: NotRequired[str] r"""Select or create a stored text secret""" + wiz_vpc_event_format: NotRequired[OutputWizHecEventFormat] + r"""The format of the VPC Flow Log events""" + wiz_vpc_flow_log_format: NotRequired[str] + r"""The format string for VPC Flow Log fields""" pq_strict_ordering: NotRequired[bool] r"""Use FIFO (first in, first out) processing. Disable to forward new events to receivers before queue is flushed.""" pq_rate_per_sec: NotRequired[float] @@ -164,8 +188,8 @@ class OutputWizHec(BaseModel): data_center: str r"""Your Wiz deployment data center (such as us1, us8, or eu1). From Tenant Info → Data Center and Regions → Tenant Data Center in your Wiz console.""" - wiz_sourcetype: str - r"""Wiz Defend Source type""" + wiz_sourcetype: WizDefendSourceType + r"""The Wiz log source type. Select a predefined type or enter a custom value.""" id: Optional[str] = None r"""Unique ID for this output""" @@ -242,7 +266,7 @@ class OutputWizHec(BaseModel): r"""List of headers that are safe to log in plain text""" auth_type: Annotated[ - Optional[AuthenticationMethodOptionsAuthTokensItems], + Optional[AuthenticationMethodOptionsAuthTokensExtItems], pydantic.Field(alias="authType"), ] = None r"""Select Manual to enter an auth token directly, or select Secret to use a text secret to authenticate""" @@ -276,6 +300,12 @@ class OutputWizHec(BaseModel): text_secret: Annotated[Optional[str], pydantic.Field(alias="textSecret")] = None r"""Select or create a stored text secret""" + wiz_vpc_event_format: Optional[OutputWizHecEventFormat] = None + r"""The format of the VPC Flow Log events""" + + wiz_vpc_flow_log_format: Optional[str] = None + r"""The format string for VPC Flow Log fields""" + pq_strict_ordering: Annotated[ Optional[bool], pydantic.Field(alias="pqStrictOrdering") ] = None @@ -373,7 +403,16 @@ def serialize_failed_request_logging_mode(self, value): def serialize_auth_type(self, value): if isinstance(value, str): try: - return models.AuthenticationMethodOptionsAuthTokensItems(value) + return models.AuthenticationMethodOptionsAuthTokensExtItems(value) + except ValueError: + return value + return value + + @field_serializer("wiz_sourcetype") + def serialize_wiz_sourcetype(self, value): + if isinstance(value, str): + try: + return models.WizDefendSourceType(value) except ValueError: return value return value @@ -387,6 +426,15 @@ def serialize_on_backpressure(self, value): return value return value + @field_serializer("wiz_vpc_event_format") + def serialize_wiz_vpc_event_format(self, value): + if isinstance(value, str): + try: + return models.OutputWizHecEventFormat(value) + except ValueError: + return value + return value + @field_serializer("pq_mode") def serialize_pq_mode(self, value): if isinstance(value, str): @@ -443,6 +491,8 @@ def serialize_model(self, handler): "description", "token", "textSecret", + "wiz_vpc_event_format", + "wiz_vpc_flow_log_format", "pqStrictOrdering", "pqRatePerSec", "pqMode", diff --git a/src/cribl_control_plane/models/packinfo.py b/src/cribl_control_plane/models/packinfo.py index 8d6d940a4..ab3fe00ed 100644 --- a/src/cribl_control_plane/models/packinfo.py +++ b/src/cribl_control_plane/models/packinfo.py @@ -17,6 +17,10 @@ class PackInfoTypedDict(TypedDict): r"""Unique identifier.""" source: str r"""Source of the Pack — a file path, URL, or Git URL from which the Pack was installed.""" + src_group: NotRequired[str] + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + src_overridden: NotRequired[bool] + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" author: NotRequired[str] r"""Name or identifier of the Pack author.""" collectors: NotRequired[float] @@ -54,6 +58,14 @@ class PackInfo(BaseModel): source: str r"""Source of the Pack — a file path, URL, or Git URL from which the Pack was installed.""" + src_group: Annotated[Optional[str], pydantic.Field(alias="__srcGroup")] = None + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + + src_overridden: Annotated[ + Optional[bool], pydantic.Field(alias="__srcOverridden") + ] = None + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" + author: Optional[str] = None r"""Name or identifier of the Pack author.""" @@ -102,6 +114,8 @@ class PackInfo(BaseModel): def serialize_model(self, handler): optional_fields = set( [ + "__srcGroup", + "__srcOverridden", "author", "collectors", "dependencies", diff --git a/src/cribl_control_plane/models/packinstallinfo.py b/src/cribl_control_plane/models/packinstallinfo.py index 04f8b6caf..c438bc81a 100644 --- a/src/cribl_control_plane/models/packinstallinfo.py +++ b/src/cribl_control_plane/models/packinstallinfo.py @@ -17,6 +17,10 @@ class PackInstallInfoTypedDict(TypedDict): r"""Unique identifier.""" source: str r"""Source of the Pack — a file path, URL, or Git URL from which the Pack was installed.""" + src_group: NotRequired[str] + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + src_overridden: NotRequired[bool] + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" author: NotRequired[str] r"""Name or identifier of the Pack author.""" collectors: NotRequired[float] @@ -55,6 +59,14 @@ class PackInstallInfo(BaseModel): source: str r"""Source of the Pack — a file path, URL, or Git URL from which the Pack was installed.""" + src_group: Annotated[Optional[str], pydantic.Field(alias="__srcGroup")] = None + r"""Fleet or group id this entity was inherited from when served by a Config Helper for a child fleet. Present when inherited from parent, including when the child has a local overlay. Omitted when the entity is local and not inherited. Display-only; never persisted.""" + + src_overridden: Annotated[ + Optional[bool], pydantic.Field(alias="__srcOverridden") + ] = None + r"""If true, the child fleet has a local overlay on an inherited entity. Omitted when inherited and unmodified, or when local and not inherited. Display-only; never persisted.""" + author: Optional[str] = None r"""Name or identifier of the Pack author.""" @@ -105,6 +117,8 @@ class PackInstallInfo(BaseModel): def serialize_model(self, handler): optional_fields = set( [ + "__srcGroup", + "__srcOverridden", "author", "collectors", "dependencies", diff --git a/src/cribl_control_plane/models/packrequestbody_union.py b/src/cribl_control_plane/models/packrequestbody_union.py index c6b990037..7241d1476 100644 --- a/src/cribl_control_plane/models/packrequestbody_union.py +++ b/src/cribl_control_plane/models/packrequestbody_union.py @@ -55,7 +55,7 @@ def serialize_model(self, handler): class PackRequestBody2TypedDict(TypedDict): source: str - r"""Source of the Pack. Provide a staging source ID from PUT /packs, a direct URL to a .crbl file, or a git+<repo-url> Git repository URL. If omitted, an empty Pack is created.""" + r"""Where to install the Pack from: an uploaded Pack source, a direct URL to a .crbl file, or a Git repository URL. Leave empty to create an empty Pack.""" id: NotRequired[str] r"""Unique identifier for the Pack.""" spec: NotRequired[str] @@ -73,14 +73,14 @@ class PackRequestBody2TypedDict(TypedDict): tags: NotRequired[Tags2TypedDict] r"""Categorization tags for the Pack.""" allow_custom_functions: NotRequired[bool] - r"""If true or omitted, allow the Pack to use custom JavaScript functions. If false, reject Packs that use custom JavaScript functions.""" + r"""Allow the Pack to use custom JavaScript functions. When disabled, Packs that use custom JavaScript functions are rejected.""" force: NotRequired[bool] - r"""If true, overwrite an existing Pack with the same ID. Otherwise, false.""" + r"""Overwrite an existing Pack that has the same ID.""" class PackRequestBody2(BaseModel): source: str - r"""Source of the Pack. Provide a staging source ID from PUT /packs, a direct URL to a .crbl file, or a git+<repo-url> Git repository URL. If omitted, an empty Pack is created.""" + r"""Where to install the Pack from: an uploaded Pack source, a direct URL to a .crbl file, or a Git repository URL. Leave empty to create an empty Pack.""" id: Optional[str] = None r"""Unique identifier for the Pack.""" @@ -111,10 +111,10 @@ class PackRequestBody2(BaseModel): allow_custom_functions: Annotated[ Optional[bool], pydantic.Field(alias="allowCustomFunctions") ] = None - r"""If true or omitted, allow the Pack to use custom JavaScript functions. If false, reject Packs that use custom JavaScript functions.""" + r"""Allow the Pack to use custom JavaScript functions. When disabled, Packs that use custom JavaScript functions are rejected.""" force: Optional[bool] = None - r"""If true, overwrite an existing Pack with the same ID. Otherwise, false.""" + r"""Overwrite an existing Pack that has the same ID.""" @model_serializer(mode="wrap") def serialize_model(self, handler): @@ -207,13 +207,13 @@ class PackRequestBody1TypedDict(TypedDict): description: NotRequired[str] r"""Brief description of the Pack and its purpose.""" source: NotRequired[str] - r"""Source of the Pack. Provide a staging source ID from PUT /packs, a direct URL to a .crbl file, or a git+<repo-url> Git repository URL. If omitted, an empty Pack is created.""" + r"""Where to install the Pack from: an uploaded Pack source, a direct URL to a .crbl file, or a Git repository URL. Leave empty to create an empty Pack.""" tags: NotRequired[Tags1TypedDict] r"""Categorization tags for the Pack.""" allow_custom_functions: NotRequired[bool] - r"""If true or omitted, allow the Pack to use custom JavaScript functions. If false, reject Packs that use custom JavaScript functions.""" + r"""Allow the Pack to use custom JavaScript functions. When disabled, Packs that use custom JavaScript functions are rejected.""" force: NotRequired[bool] - r"""If true, overwrite an existing Pack with the same ID. Otherwise, false.""" + r"""Overwrite an existing Pack that has the same ID.""" class PackRequestBody1(BaseModel): @@ -241,7 +241,7 @@ class PackRequestBody1(BaseModel): r"""Brief description of the Pack and its purpose.""" source: Optional[str] = None - r"""Source of the Pack. Provide a staging source ID from PUT /packs, a direct URL to a .crbl file, or a git+<repo-url> Git repository URL. If omitted, an empty Pack is created.""" + r"""Where to install the Pack from: an uploaded Pack source, a direct URL to a .crbl file, or a Git repository URL. Leave empty to create an empty Pack.""" tags: Optional[Tags1] = None r"""Categorization tags for the Pack.""" @@ -249,10 +249,10 @@ class PackRequestBody1(BaseModel): allow_custom_functions: Annotated[ Optional[bool], pydantic.Field(alias="allowCustomFunctions") ] = None - r"""If true or omitted, allow the Pack to use custom JavaScript functions. If false, reject Packs that use custom JavaScript functions.""" + r"""Allow the Pack to use custom JavaScript functions. When disabled, Packs that use custom JavaScript functions are rejected.""" force: Optional[bool] = None - r"""If true, overwrite an existing Pack with the same ID. Otherwise, false.""" + r"""Overwrite an existing Pack that has the same ID.""" @model_serializer(mode="wrap") def serialize_model(self, handler): diff --git a/src/cribl_control_plane/models/paginatedconfiggroup.py b/src/cribl_control_plane/models/paginatedconfiggroup.py index 381b0aefa..45902a832 100644 --- a/src/cribl_control_plane/models/paginatedconfiggroup.py +++ b/src/cribl_control_plane/models/paginatedconfiggroup.py @@ -11,9 +11,9 @@ class PaginatedConfigGroupTypedDict(TypedDict): items: List[ConfigGroupTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedConfigGroupTypedDict(TypedDict): class PaginatedConfigGroup(BaseModel): items: List[ConfigGroup] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedcribllakedataset.py b/src/cribl_control_plane/models/paginatedcribllakedataset.py index 4a7448cd1..bdde2db15 100644 --- a/src/cribl_control_plane/models/paginatedcribllakedataset.py +++ b/src/cribl_control_plane/models/paginatedcribllakedataset.py @@ -11,9 +11,9 @@ class PaginatedCriblLakeDatasetTypedDict(TypedDict): items: List[CriblLakeDatasetTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedCriblLakeDatasetTypedDict(TypedDict): class PaginatedCriblLakeDataset(BaseModel): items: List[CriblLakeDataset] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginateddistributedsummary.py b/src/cribl_control_plane/models/paginateddistributedsummary.py index 4d1e65ae1..695fdc79b 100644 --- a/src/cribl_control_plane/models/paginateddistributedsummary.py +++ b/src/cribl_control_plane/models/paginateddistributedsummary.py @@ -11,9 +11,9 @@ class PaginatedDistributedSummaryTypedDict(TypedDict): items: List[DistributedSummaryTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedDistributedSummaryTypedDict(TypedDict): class PaginatedDistributedSummary(BaseModel): items: List[DistributedSummary] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedfunctionresponse.py b/src/cribl_control_plane/models/paginatedfunctionresponse.py index bb2369e0b..6b110aa84 100644 --- a/src/cribl_control_plane/models/paginatedfunctionresponse.py +++ b/src/cribl_control_plane/models/paginatedfunctionresponse.py @@ -11,9 +11,9 @@ class PaginatedFunctionResponseTypedDict(TypedDict): items: List[FunctionResponseTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedFunctionResponseTypedDict(TypedDict): class PaginatedFunctionResponse(BaseModel): items: List[FunctionResponse] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedgitlogresult.py b/src/cribl_control_plane/models/paginatedgitlogresult.py index 63b5898e6..b5314bcc7 100644 --- a/src/cribl_control_plane/models/paginatedgitlogresult.py +++ b/src/cribl_control_plane/models/paginatedgitlogresult.py @@ -11,9 +11,9 @@ class PaginatedGitLogResultTypedDict(TypedDict): items: List[GitLogResultTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedGitLogResultTypedDict(TypedDict): class PaginatedGitLogResult(BaseModel): items: List[GitLogResult] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedinputresponse.py b/src/cribl_control_plane/models/paginatedinputresponse.py index 50ac3a06f..d223436fb 100644 --- a/src/cribl_control_plane/models/paginatedinputresponse.py +++ b/src/cribl_control_plane/models/paginatedinputresponse.py @@ -11,9 +11,9 @@ class PaginatedInputResponseTypedDict(TypedDict): items: List[InputResponseTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedInputResponseTypedDict(TypedDict): class PaginatedInputResponse(BaseModel): items: List[InputResponse] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedinputstatus.py b/src/cribl_control_plane/models/paginatedinputstatus.py index 175883885..b0dc3ceaa 100644 --- a/src/cribl_control_plane/models/paginatedinputstatus.py +++ b/src/cribl_control_plane/models/paginatedinputstatus.py @@ -11,9 +11,9 @@ class PaginatedInputStatusTypedDict(TypedDict): items: List[InputStatusTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedInputStatusTypedDict(TypedDict): class PaginatedInputStatus(BaseModel): items: List[InputStatus] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedmasterworkerentry.py b/src/cribl_control_plane/models/paginatedmasterworkerentry.py index 3327fb5ae..0aa528702 100644 --- a/src/cribl_control_plane/models/paginatedmasterworkerentry.py +++ b/src/cribl_control_plane/models/paginatedmasterworkerentry.py @@ -11,9 +11,9 @@ class PaginatedMasterWorkerEntryTypedDict(TypedDict): items: List[MasterWorkerEntryTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedMasterWorkerEntryTypedDict(TypedDict): class PaginatedMasterWorkerEntry(BaseModel): items: List[MasterWorkerEntry] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedoutputresponse.py b/src/cribl_control_plane/models/paginatedoutputresponse.py index 881433f50..004befdde 100644 --- a/src/cribl_control_plane/models/paginatedoutputresponse.py +++ b/src/cribl_control_plane/models/paginatedoutputresponse.py @@ -11,9 +11,9 @@ class PaginatedOutputResponseTypedDict(TypedDict): items: List[OutputResponseTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedOutputResponseTypedDict(TypedDict): class PaginatedOutputResponse(BaseModel): items: List[OutputResponse] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedoutputstatus.py b/src/cribl_control_plane/models/paginatedoutputstatus.py index 873c9ead3..b5464491c 100644 --- a/src/cribl_control_plane/models/paginatedoutputstatus.py +++ b/src/cribl_control_plane/models/paginatedoutputstatus.py @@ -11,9 +11,9 @@ class PaginatedOutputStatusTypedDict(TypedDict): items: List[OutputStatusTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedOutputStatusTypedDict(TypedDict): class PaginatedOutputStatus(BaseModel): items: List[OutputStatus] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedpackinfo.py b/src/cribl_control_plane/models/paginatedpackinfo.py index 574388311..3d5cf2523 100644 --- a/src/cribl_control_plane/models/paginatedpackinfo.py +++ b/src/cribl_control_plane/models/paginatedpackinfo.py @@ -11,9 +11,9 @@ class PaginatedPackInfoTypedDict(TypedDict): items: List[PackInfoTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedPackInfoTypedDict(TypedDict): class PaginatedPackInfo(BaseModel): items: List[PackInfo] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedpipeline.py b/src/cribl_control_plane/models/paginatedpipeline.py index 0f5d72ea3..33313dac0 100644 --- a/src/cribl_control_plane/models/paginatedpipeline.py +++ b/src/cribl_control_plane/models/paginatedpipeline.py @@ -11,9 +11,9 @@ class PaginatedPipelineTypedDict(TypedDict): items: List[PipelineTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedPipelineTypedDict(TypedDict): class PaginatedPipeline(BaseModel): items: List[Pipeline] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/paginatedroutes.py b/src/cribl_control_plane/models/paginatedroutes.py new file mode 100644 index 000000000..413950bf6 --- /dev/null +++ b/src/cribl_control_plane/models/paginatedroutes.py @@ -0,0 +1,61 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .routes import Routes, RoutesTypedDict +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +import pydantic +from pydantic import model_serializer +from typing import List, Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class PaginatedRoutesTypedDict(TypedDict): + items: List[RoutesTypedDict] + r"""The items returned in this response, after any offset/limit pagination has been applied.""" + count: int + r"""Number of items returned in the items array.""" + offset: NotRequired[int] + r"""Pagination offset. Returned when offset/limit query parameters are provided.""" + limit: NotRequired[int] + r"""Pagination limit. Returned when offset/limit query parameters are provided.""" + total_count: NotRequired[int] + r"""Total number of items available. Returned when offset/limit query parameters are provided.""" + + +class PaginatedRoutes(BaseModel): + items: List[Routes] + r"""The items returned in this response, after any offset/limit pagination has been applied.""" + + count: int + r"""Number of items returned in the items array.""" + + offset: Optional[int] = None + r"""Pagination offset. Returned when offset/limit query parameters are provided.""" + + limit: Optional[int] = None + r"""Pagination limit. Returned when offset/limit query parameters are provided.""" + + total_count: Annotated[Optional[int], pydantic.Field(alias="totalCount")] = None + r"""Total number of items available. Returned when offset/limit query parameters are provided.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["offset", "limit", "totalCount"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + PaginatedRoutes.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/paginatedsavedjobresponse.py b/src/cribl_control_plane/models/paginatedsavedjobresponse.py index c29e0cb8a..b8ab5435c 100644 --- a/src/cribl_control_plane/models/paginatedsavedjobresponse.py +++ b/src/cribl_control_plane/models/paginatedsavedjobresponse.py @@ -11,9 +11,9 @@ class PaginatedSavedJobResponseTypedDict(TypedDict): items: List[SavedJobResponseTypedDict] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: NotRequired[int] r"""Pagination offset. Returned when offset/limit query parameters are provided.""" limit: NotRequired[int] @@ -24,10 +24,10 @@ class PaginatedSavedJobResponseTypedDict(TypedDict): class PaginatedSavedJobResponse(BaseModel): items: List[SavedJobResponse] - r"""The pre-limited items in the list of results""" + r"""The items returned in this response, after any offset/limit pagination has been applied.""" count: int - r"""Number of items present in the items array""" + r"""Number of items returned in the items array.""" offset: Optional[int] = None r"""Pagination offset. Returned when offset/limit query parameters are provided.""" diff --git a/src/cribl_control_plane/models/pipeline.py b/src/cribl_control_plane/models/pipeline.py index 441463550..52bc47433 100644 --- a/src/cribl_control_plane/models/pipeline.py +++ b/src/cribl_control_plane/models/pipeline.py @@ -19,7 +19,7 @@ class PipelineGroupsTypedDict(TypedDict): description: NotRequired[str] r"""Brief description of the group.""" disabled: NotRequired[bool] - r"""If true, disable all items in the group. Otherwise, false.""" + r"""Disable all items in the group.""" class PipelineGroups(BaseModel): @@ -30,7 +30,7 @@ class PipelineGroups(BaseModel): r"""Brief description of the group.""" disabled: Optional[bool] = None - r"""If true, disable all items in the group. Otherwise, false.""" + r"""Disable all items in the group.""" @model_serializer(mode="wrap") def serialize_model(self, handler): diff --git a/src/cribl_control_plane/models/pipelinefunctionconf.py b/src/cribl_control_plane/models/pipelinefunctionconf.py index 3d7f7cb89..507b796d6 100644 --- a/src/cribl_control_plane/models/pipelinefunctionconf.py +++ b/src/cribl_control_plane/models/pipelinefunctionconf.py @@ -21,6 +21,10 @@ PipelineFunctionComment, PipelineFunctionCommentTypedDict, ) +from .pipelinefunctiondetectionrules import ( + PipelineFunctionDetectionRules, + PipelineFunctionDetectionRulesTypedDict, +) from .pipelinefunctiondistinct import ( PipelineFunctionDistinct, PipelineFunctionDistinctTypedDict, @@ -78,6 +82,10 @@ PipelineFunctionLakeExport, PipelineFunctionLakeExportTypedDict, ) +from .pipelinefunctionlakehouseenginemetricsnormalizer import ( + PipelineFunctionLakehouseEngineMetricsNormalizer, + PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict, +) from .pipelinefunctionlimit import PipelineFunctionLimit, PipelineFunctionLimitTypedDict from .pipelinefunctionlocalsearchdatatypeparser import ( PipelineFunctionLocalSearchDatatypeParser, @@ -108,6 +116,10 @@ PipelineFunctionMetricsExport, PipelineFunctionMetricsExportTypedDict, ) +from .pipelinefunctionmetricstimerangegate import ( + PipelineFunctionMetricsTimeRangeGate, + PipelineFunctionMetricsTimeRangeGateTypedDict, +) from .pipelinefunctionmvexpand import ( PipelineFunctionMvExpand, PipelineFunctionMvExpandTypedDict, @@ -237,6 +249,7 @@ PipelineFunctionCloneTypedDict, PipelineFunctionCodeTypedDict, PipelineFunctionCommentTypedDict, + PipelineFunctionDetectionRulesTypedDict, PipelineFunctionDistinctTypedDict, PipelineFunctionDNSLookupTypedDict, PipelineFunctionDropTypedDict, @@ -255,6 +268,7 @@ PipelineFunctionJoinTypedDict, PipelineFunctionJSONUnrollTypedDict, PipelineFunctionLakeExportTypedDict, + PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict, PipelineFunctionLimitTypedDict, PipelineFunctionLocalSearchDatatypeParserTypedDict, PipelineFunctionLocalSearchRulesetRunnerTypedDict, @@ -264,6 +278,7 @@ PipelineFunctionLookupTypedDict, PipelineFunctionMaskTypedDict, PipelineFunctionMetricsExportTypedDict, + PipelineFunctionMetricsTimeRangeGateTypedDict, PipelineFunctionMvExpandTypedDict, PipelineFunctionMvPullTypedDict, PipelineFunctionNotificationPoliciesTypedDict, @@ -321,6 +336,7 @@ class UnknownPipelineFunctionConf(BaseModel): "clone": PipelineFunctionClone, "code": PipelineFunctionCode, "comment": PipelineFunctionComment, + "detection_rules": PipelineFunctionDetectionRules, "distinct": PipelineFunctionDistinct, "dns_lookup": PipelineFunctionDNSLookup, "drop": PipelineFunctionDrop, @@ -339,6 +355,7 @@ class UnknownPipelineFunctionConf(BaseModel): "join": PipelineFunctionJoin, "json_unroll": PipelineFunctionJSONUnroll, "lake_export": PipelineFunctionLakeExport, + "lakehouse_engine_metrics_normalizer": PipelineFunctionLakehouseEngineMetricsNormalizer, "limit": PipelineFunctionLimit, "local_search_datatype_parser": PipelineFunctionLocalSearchDatatypeParser, "local_search_ruleset_runner": PipelineFunctionLocalSearchRulesetRunner, @@ -348,6 +365,7 @@ class UnknownPipelineFunctionConf(BaseModel): "lookup": PipelineFunctionLookup, "mask": PipelineFunctionMask, "metrics_export": PipelineFunctionMetricsExport, + "metrics_time_range_gate": PipelineFunctionMetricsTimeRangeGate, "mv_expand": PipelineFunctionMvExpand, "mv_pull": PipelineFunctionMvPull, "notification_policies": PipelineFunctionNotificationPolicies, @@ -395,6 +413,7 @@ class UnknownPipelineFunctionConf(BaseModel): PipelineFunctionClone, PipelineFunctionCode, PipelineFunctionComment, + PipelineFunctionDetectionRules, PipelineFunctionDistinct, PipelineFunctionDNSLookup, PipelineFunctionDrop, @@ -413,6 +432,7 @@ class UnknownPipelineFunctionConf(BaseModel): PipelineFunctionJoin, PipelineFunctionJSONUnroll, PipelineFunctionLakeExport, + PipelineFunctionLakehouseEngineMetricsNormalizer, PipelineFunctionLimit, PipelineFunctionLocalSearchDatatypeParser, PipelineFunctionLocalSearchRulesetRunner, @@ -422,6 +442,7 @@ class UnknownPipelineFunctionConf(BaseModel): PipelineFunctionLookup, PipelineFunctionMask, PipelineFunctionMetricsExport, + PipelineFunctionMetricsTimeRangeGate, PipelineFunctionMvExpand, PipelineFunctionMvPull, PipelineFunctionNotificationPolicies, diff --git a/src/cribl_control_plane/models/pipelinefunctionconf_input.py b/src/cribl_control_plane/models/pipelinefunctionconf_input.py index 24c9d7f0f..682b6d588 100644 --- a/src/cribl_control_plane/models/pipelinefunctionconf_input.py +++ b/src/cribl_control_plane/models/pipelinefunctionconf_input.py @@ -24,6 +24,10 @@ PipelineFunctionComment, PipelineFunctionCommentTypedDict, ) +from .pipelinefunctiondetectionrules import ( + PipelineFunctionDetectionRules, + PipelineFunctionDetectionRulesTypedDict, +) from .pipelinefunctiondistinct import ( PipelineFunctionDistinct, PipelineFunctionDistinctTypedDict, @@ -81,6 +85,10 @@ PipelineFunctionLakeExport, PipelineFunctionLakeExportTypedDict, ) +from .pipelinefunctionlakehouseenginemetricsnormalizer import ( + PipelineFunctionLakehouseEngineMetricsNormalizer, + PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict, +) from .pipelinefunctionlimit import PipelineFunctionLimit, PipelineFunctionLimitTypedDict from .pipelinefunctionlocalsearchdatatypeparser import ( PipelineFunctionLocalSearchDatatypeParser, @@ -111,6 +119,10 @@ PipelineFunctionMetricsExport, PipelineFunctionMetricsExportTypedDict, ) +from .pipelinefunctionmetricstimerangegate import ( + PipelineFunctionMetricsTimeRangeGate, + PipelineFunctionMetricsTimeRangeGateTypedDict, +) from .pipelinefunctionmvexpand import ( PipelineFunctionMvExpand, PipelineFunctionMvExpandTypedDict, @@ -237,6 +249,7 @@ PipelineFunctionCloneTypedDict, PipelineFunctionCodeTypedDict, PipelineFunctionCommentTypedDict, + PipelineFunctionDetectionRulesTypedDict, PipelineFunctionDistinctTypedDict, PipelineFunctionDNSLookupTypedDict, PipelineFunctionDropTypedDict, @@ -255,6 +268,7 @@ PipelineFunctionJoinTypedDict, PipelineFunctionJSONUnrollTypedDict, PipelineFunctionLakeExportTypedDict, + PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict, PipelineFunctionLimitTypedDict, PipelineFunctionLocalSearchDatatypeParserTypedDict, PipelineFunctionLocalSearchRulesetRunnerTypedDict, @@ -264,6 +278,7 @@ PipelineFunctionLookupTypedDict, PipelineFunctionMaskTypedDict, PipelineFunctionMetricsExportTypedDict, + PipelineFunctionMetricsTimeRangeGateTypedDict, PipelineFunctionMvExpandTypedDict, PipelineFunctionMvPullTypedDict, PipelineFunctionNotificationPoliciesTypedDict, @@ -312,6 +327,7 @@ Annotated[PipelineFunctionClone, Tag("clone")], Annotated[PipelineFunctionCode, Tag("code")], Annotated[PipelineFunctionComment, Tag("comment")], + Annotated[PipelineFunctionDetectionRules, Tag("detection_rules")], Annotated[PipelineFunctionDistinct, Tag("distinct")], Annotated[PipelineFunctionDNSLookup, Tag("dns_lookup")], Annotated[PipelineFunctionDrop, Tag("drop")], @@ -330,6 +346,10 @@ Annotated[PipelineFunctionJoin, Tag("join")], Annotated[PipelineFunctionJSONUnroll, Tag("json_unroll")], Annotated[PipelineFunctionLakeExport, Tag("lake_export")], + Annotated[ + PipelineFunctionLakehouseEngineMetricsNormalizer, + Tag("lakehouse_engine_metrics_normalizer"), + ], Annotated[PipelineFunctionLimit, Tag("limit")], Annotated[ PipelineFunctionLocalSearchDatatypeParser, @@ -351,6 +371,7 @@ Annotated[PipelineFunctionLookup, Tag("lookup")], Annotated[PipelineFunctionMask, Tag("mask")], Annotated[PipelineFunctionMetricsExport, Tag("metrics_export")], + Annotated[PipelineFunctionMetricsTimeRangeGate, Tag("metrics_time_range_gate")], Annotated[PipelineFunctionMvExpand, Tag("mv_expand")], Annotated[PipelineFunctionMvPull, Tag("mv_pull")], Annotated[PipelineFunctionNotificationPolicies, Tag("notification_policies")], diff --git a/src/cribl_control_plane/models/pipelinefunctiondetectionrules.py b/src/cribl_control_plane/models/pipelinefunctiondetectionrules.py new file mode 100644 index 000000000..291e73062 --- /dev/null +++ b/src/cribl_control_plane/models/pipelinefunctiondetectionrules.py @@ -0,0 +1,79 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .functionconfschemadetectionrules import ( + FunctionConfSchemaDetectionRules, + FunctionConfSchemaDetectionRulesTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class PipelineFunctionDetectionRulesID(str, Enum): + r"""Identifier of the Function. Always detection_rules""" + + DETECTION_RULES = "detection_rules" + + +class PipelineFunctionDetectionRulesTypedDict(TypedDict): + id: PipelineFunctionDetectionRulesID + r"""Identifier of the Function. Always detection_rules""" + conf: FunctionConfSchemaDetectionRulesTypedDict + filter_: NotRequired[str] + r"""JavaScript expression that selects data to pass through the Function.""" + description: NotRequired[str] + r"""Brief description of the Pipeline function.""" + disabled: NotRequired[bool] + r"""If true, disable the Pipeline function so that events are not passed through it. Otherwise, false.""" + final: NotRequired[bool] + r"""If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false.""" + group_id: NotRequired[str] + r"""Unique identifier of the group that contains the Pipeline Function.""" + + +class PipelineFunctionDetectionRules(BaseModel): + id: PipelineFunctionDetectionRulesID + r"""Identifier of the Function. Always detection_rules""" + + conf: FunctionConfSchemaDetectionRules + + filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None + r"""JavaScript expression that selects data to pass through the Function.""" + + description: Optional[str] = None + r"""Brief description of the Pipeline function.""" + + disabled: Optional[bool] = None + r"""If true, disable the Pipeline function so that events are not passed through it. Otherwise, false.""" + + final: Optional[bool] = None + r"""If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false.""" + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""Unique identifier of the group that contains the Pipeline Function.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["filter", "description", "disabled", "final", "groupId"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + PipelineFunctionDetectionRules.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/pipelinefunctionlakehouseenginemetricsnormalizer.py b/src/cribl_control_plane/models/pipelinefunctionlakehouseenginemetricsnormalizer.py new file mode 100644 index 000000000..70fc134ad --- /dev/null +++ b/src/cribl_control_plane/models/pipelinefunctionlakehouseenginemetricsnormalizer.py @@ -0,0 +1,79 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .functionconfschemalakehouseenginemetricsnormalizer import ( + FunctionConfSchemaLakehouseEngineMetricsNormalizer, + FunctionConfSchemaLakehouseEngineMetricsNormalizerTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class PipelineFunctionLakehouseEngineMetricsNormalizerID(str, Enum): + r"""Identifier of the Function. Always lakehouse_engine_metrics_normalizer""" + + LAKEHOUSE_ENGINE_METRICS_NORMALIZER = "lakehouse_engine_metrics_normalizer" + + +class PipelineFunctionLakehouseEngineMetricsNormalizerTypedDict(TypedDict): + id: PipelineFunctionLakehouseEngineMetricsNormalizerID + r"""Identifier of the Function. Always lakehouse_engine_metrics_normalizer""" + conf: FunctionConfSchemaLakehouseEngineMetricsNormalizerTypedDict + filter_: NotRequired[str] + r"""JavaScript expression that selects data to pass through the Function.""" + description: NotRequired[str] + r"""Brief description of the Pipeline function.""" + disabled: NotRequired[bool] + r"""If true, disable the Pipeline function so that events are not passed through it. Otherwise, false.""" + final: NotRequired[bool] + r"""If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false.""" + group_id: NotRequired[str] + r"""Unique identifier of the group that contains the Pipeline Function.""" + + +class PipelineFunctionLakehouseEngineMetricsNormalizer(BaseModel): + id: PipelineFunctionLakehouseEngineMetricsNormalizerID + r"""Identifier of the Function. Always lakehouse_engine_metrics_normalizer""" + + conf: FunctionConfSchemaLakehouseEngineMetricsNormalizer + + filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None + r"""JavaScript expression that selects data to pass through the Function.""" + + description: Optional[str] = None + r"""Brief description of the Pipeline function.""" + + disabled: Optional[bool] = None + r"""If true, disable the Pipeline function so that events are not passed through it. Otherwise, false.""" + + final: Optional[bool] = None + r"""If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false.""" + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""Unique identifier of the group that contains the Pipeline Function.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["filter", "description", "disabled", "final", "groupId"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + PipelineFunctionLakehouseEngineMetricsNormalizer.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/pipelinefunctionmetricsexport.py b/src/cribl_control_plane/models/pipelinefunctionmetricsexport.py index e59f532d2..f730072c5 100644 --- a/src/cribl_control_plane/models/pipelinefunctionmetricsexport.py +++ b/src/cribl_control_plane/models/pipelinefunctionmetricsexport.py @@ -18,22 +18,28 @@ class PipelineFunctionMetricsExportID(str, Enum): class PipelineFunctionMetricsExportMode2(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Discriminator value.""" + r"""Type of label configuration. Always list.""" LIST = "list" class LabelFields2TypedDict(TypedDict): + r"""Label configuration that reads values from a list of fields.""" + mode: PipelineFunctionMetricsExportMode2 - r"""Discriminator value.""" + r"""Type of label configuration. Always list.""" fields: List[NameFieldTypeTypedDict] + r"""Field references to attach as labels to each exported metric.""" class LabelFields2(BaseModel): + r"""Label configuration that reads values from a list of fields.""" + mode: PipelineFunctionMetricsExportMode2 - r"""Discriminator value.""" + r"""Type of label configuration. Always list.""" fields: List[NameFieldType] + r"""Field references to attach as labels to each exported metric.""" @field_serializer("mode") def serialize_mode(self, value): @@ -46,22 +52,28 @@ def serialize_mode(self, value): class PipelineFunctionMetricsExportMode1(str, Enum, metaclass=utils.OpenEnumMeta): - r"""Discriminator value.""" + r"""Type of label configuration. Always object.""" OBJECT = "object" class LabelFields1TypedDict(TypedDict): + r"""Label configuration that reads key-value pairs from one object field.""" + mode: PipelineFunctionMetricsExportMode1 - r"""Discriminator value.""" + r"""Type of label configuration. Always object.""" field: NameFieldTypeTypedDict + r"""Reference to a field by its original text and parsed path segments.""" class LabelFields1(BaseModel): + r"""Label configuration that reads key-value pairs from one object field.""" + mode: PipelineFunctionMetricsExportMode1 - r"""Discriminator value.""" + r"""Type of label configuration. Always object.""" field: NameFieldType + r"""Reference to a field by its original text and parsed path segments.""" @field_serializer("mode") def serialize_mode(self, value): @@ -76,29 +88,36 @@ def serialize_mode(self, value): LabelFieldsUnionTypedDict = TypeAliasType( "LabelFieldsUnionTypedDict", Union[LabelFields1TypedDict, LabelFields2TypedDict] ) +r"""Field references to attach as labels to each exported metric. Specify one field or a list of fields.""" LabelFieldsUnion = TypeAliasType("LabelFieldsUnion", Union[LabelFields1, LabelFields2]) +r"""Field references to attach as labels to each exported metric. Specify one field or a list of fields.""" class MetricsExportConfigurationTypedDict(TypedDict): r"""Configuration specific to the Pipeline Function.""" search_job_id: str - r"""Id of the search job this function is running on.""" + r"""Unique identifier for the Search Job that runs this Function.""" dataset: str - r"""Id of the metrics dataset""" + r"""Unique identifier for the metrics Dataset.""" name_field: NotRequired[NameFieldTypeTypedDict] + r"""Reference to a field by its original text and parsed path segments.""" time_field: NotRequired[NameFieldTypeTypedDict] + r"""Reference to a field by its original text and parsed path segments.""" value_field: NotRequired[NameFieldTypeTypedDict] + r"""Reference to a field by its original text and parsed path segments.""" type_field: NotRequired[NameFieldTypeTypedDict] + r"""Reference to a field by its original text and parsed path segments.""" label_fields: NotRequired[LabelFieldsUnionTypedDict] + r"""Field references to attach as labels to each exported metric. Specify one field or a list of fields.""" tee: NotRequired[bool] - r"""Tee results to search. When set to true results will be shipped instead of stats""" + r"""If true, pass processed events to downstream Functions. If false, emit export statistics.""" flush_ms: NotRequired[float] - r"""How often stats are flushed in ms""" + r"""Interval, in milliseconds, between export statistics updates.""" suppress_previews: NotRequired[bool] - r"""Disables generation of intermediate stats. When true stats will be emitted only on end""" + r"""If true, emit export statistics only when processing completes. If false, emit periodic statistics.""" class MetricsExportConfiguration(BaseModel): @@ -110,41 +129,46 @@ class MetricsExportConfiguration(BaseModel): __pydantic_extra__: Dict[str, Any] = pydantic.Field(init=False) search_job_id: Annotated[str, pydantic.Field(alias="searchJobId")] - r"""Id of the search job this function is running on.""" + r"""Unique identifier for the Search Job that runs this Function.""" dataset: str - r"""Id of the metrics dataset""" + r"""Unique identifier for the metrics Dataset.""" name_field: Annotated[ Optional[NameFieldType], pydantic.Field(alias="nameField") ] = None + r"""Reference to a field by its original text and parsed path segments.""" time_field: Annotated[ Optional[NameFieldType], pydantic.Field(alias="timeField") ] = None + r"""Reference to a field by its original text and parsed path segments.""" value_field: Annotated[ Optional[NameFieldType], pydantic.Field(alias="valueField") ] = None + r"""Reference to a field by its original text and parsed path segments.""" type_field: Annotated[ Optional[NameFieldType], pydantic.Field(alias="typeField") ] = None + r"""Reference to a field by its original text and parsed path segments.""" label_fields: Annotated[ Optional[LabelFieldsUnion], pydantic.Field(alias="labelFields") ] = None + r"""Field references to attach as labels to each exported metric. Specify one field or a list of fields.""" tee: Optional[bool] = None - r"""Tee results to search. When set to true results will be shipped instead of stats""" + r"""If true, pass processed events to downstream Functions. If false, emit export statistics.""" flush_ms: Annotated[Optional[float], pydantic.Field(alias="flushMs")] = None - r"""How often stats are flushed in ms""" + r"""Interval, in milliseconds, between export statistics updates.""" suppress_previews: Annotated[ Optional[bool], pydantic.Field(alias="suppressPreviews") ] = None - r"""Disables generation of intermediate stats. When true stats will be emitted only on end""" + r"""If true, emit export statistics only when processing completes. If false, emit periodic statistics.""" @property def additional_properties(self): diff --git a/src/cribl_control_plane/models/pipelinefunctionmetricstimerangegate.py b/src/cribl_control_plane/models/pipelinefunctionmetricstimerangegate.py new file mode 100644 index 000000000..1f95b6728 --- /dev/null +++ b/src/cribl_control_plane/models/pipelinefunctionmetricstimerangegate.py @@ -0,0 +1,79 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from .functionconfschemametricstimerangegate import ( + FunctionConfSchemaMetricsTimeRangeGate, + FunctionConfSchemaMetricsTimeRangeGateTypedDict, +) +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class PipelineFunctionMetricsTimeRangeGateID(str, Enum): + r"""Identifier of the Function. Always metrics_time_range_gate""" + + METRICS_TIME_RANGE_GATE = "metrics_time_range_gate" + + +class PipelineFunctionMetricsTimeRangeGateTypedDict(TypedDict): + id: PipelineFunctionMetricsTimeRangeGateID + r"""Identifier of the Function. Always metrics_time_range_gate""" + conf: FunctionConfSchemaMetricsTimeRangeGateTypedDict + filter_: NotRequired[str] + r"""JavaScript expression that selects data to pass through the Function.""" + description: NotRequired[str] + r"""Brief description of the Pipeline function.""" + disabled: NotRequired[bool] + r"""If true, disable the Pipeline function so that events are not passed through it. Otherwise, false.""" + final: NotRequired[bool] + r"""If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false.""" + group_id: NotRequired[str] + r"""Unique identifier of the group that contains the Pipeline Function.""" + + +class PipelineFunctionMetricsTimeRangeGate(BaseModel): + id: PipelineFunctionMetricsTimeRangeGateID + r"""Identifier of the Function. Always metrics_time_range_gate""" + + conf: FunctionConfSchemaMetricsTimeRangeGate + + filter_: Annotated[Optional[str], pydantic.Field(alias="filter")] = None + r"""JavaScript expression that selects data to pass through the Function.""" + + description: Optional[str] = None + r"""Brief description of the Pipeline function.""" + + disabled: Optional[bool] = None + r"""If true, disable the Pipeline function so that events are not passed through it. Otherwise, false.""" + + final: Optional[bool] = None + r"""If true, stop passing events to downstream Pipeline Functions after the Function executes. Otherwise, false.""" + + group_id: Annotated[Optional[str], pydantic.Field(alias="groupId")] = None + r"""Unique identifier of the group that contains the Pipeline Function.""" + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["filter", "description", "disabled", "final", "groupId"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + PipelineFunctionMetricsTimeRangeGate.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/pipelinefunctionserde.py b/src/cribl_control_plane/models/pipelinefunctionserde.py index 496338ca5..723b77800 100644 --- a/src/cribl_control_plane/models/pipelinefunctionserde.py +++ b/src/cribl_control_plane/models/pipelinefunctionserde.py @@ -72,8 +72,6 @@ class SerdeTypeGrokTypedDict(TypedDict): r"""Name of the field to add fields to. Extract mode only.""" pattern_list: NotRequired[List[PatternListConfSerdeTypeGrokTypedDict]] r"""Additional Grok patterns to apply to the source field.""" - tag_datatype: NotRequired[bool] - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" keep: NotRequired[List[str]] r"""List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'.""" remove: NotRequired[List[str]] @@ -120,9 +118,6 @@ class SerdeTypeGrok(BaseModel): ] = None r"""Additional Grok patterns to apply to the source field.""" - tag_datatype: Annotated[Optional[bool], pydantic.Field(alias="tagDatatype")] = None - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" - keep: Optional[List[str]] = None r"""List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'.""" @@ -191,7 +186,6 @@ def serialize_model(self, handler): "srcField", "dstField", "patternList", - "tagDatatype", "keep", "remove", "fieldFilterExpr", @@ -270,8 +264,6 @@ class SerdeTypeRegexTypedDict(TypedDict): r"""JavaScript expression to format field names when _NAME_n and _VALUE_n capturing groups are used. Original field name is in global variable 'name'. Example: To append XX to all field names, use `${name}_XX` (backticks are literal). If empty, names will be sanitized using this regex: /^[_0-9]+|[^a-zA-Z0-9_]+/g. You can access other fields values via __e..""" overwrite: NotRequired[bool] r"""Overwrite existing event fields with extracted values. If disabled, existing fields will be converted to an array.""" - tag_datatype: NotRequired[bool] - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" keep: NotRequired[List[str]] r"""List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'.""" remove: NotRequired[List[str]] @@ -322,9 +314,6 @@ class SerdeTypeRegex(BaseModel): overwrite: Optional[bool] = None r"""Overwrite existing event fields with extracted values. If disabled, existing fields will be converted to an array.""" - tag_datatype: Annotated[Optional[bool], pydantic.Field(alias="tagDatatype")] = None - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" - keep: Optional[List[str]] = None r"""List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'.""" @@ -386,7 +375,6 @@ def serialize_model(self, handler): "iterations", "fieldNameExpression", "overwrite", - "tagDatatype", "keep", "remove", "fieldFilterExpr", @@ -458,8 +446,6 @@ class SerdeTypeJSONTypedDict(TypedDict): r"""List of fields to remove. Supports wildcards (*). Cannot remove fields that match 'Fields to keep'.""" field_filter_expr: NotRequired[str] r"""Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it.""" - tag_datatype: NotRequired[bool] - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" allowed_key_chars: NotRequired[List[str]] r"""A list of characters that may be present in a key name, even though they are normally separator or control characters""" allowed_value_chars: NotRequired[List[str]] @@ -506,9 +492,6 @@ class SerdeTypeJSON(BaseModel): ] = None r"""Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it.""" - tag_datatype: Annotated[Optional[bool], pydantic.Field(alias="tagDatatype")] = None - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" - allowed_key_chars: Annotated[ Optional[List[str]], pydantic.Field(alias="allowedKeyChars") ] = None @@ -577,7 +560,6 @@ def serialize_model(self, handler): "keep", "remove", "fieldFilterExpr", - "tagDatatype", "allowedKeyChars", "allowedValueChars", "fields", @@ -653,8 +635,6 @@ class SerdeTypeCsvTypedDict(TypedDict): r"""List of fields to remove. Supports wildcards (*). Cannot remove fields that match 'Fields to keep'.""" field_filter_expr: NotRequired[str] r"""Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it.""" - tag_datatype: NotRequired[bool] - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" allowed_key_chars: NotRequired[List[str]] r"""A list of characters that may be present in a key name, even though they are normally separator or control characters""" allowed_value_chars: NotRequired[List[str]] @@ -702,9 +682,6 @@ class SerdeTypeCsv(BaseModel): ] = None r"""Expression evaluated against {index, name, value} context. Return truthy to keep a field, or falsy to remove it.""" - tag_datatype: Annotated[Optional[bool], pydantic.Field(alias="tagDatatype")] = None - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" - allowed_key_chars: Annotated[ Optional[List[str]], pydantic.Field(alias="allowedKeyChars") ] = None @@ -771,7 +748,6 @@ def serialize_model(self, handler): "keep", "remove", "fieldFilterExpr", - "tagDatatype", "allowedKeyChars", "allowedValueChars", "regex", @@ -854,8 +830,6 @@ class SerdeTypeDelimTypedDict(TypedDict): r"""Escape character used to escape delimiter or quote character""" null_value: NotRequired[str] r"""Field value representing the null value. Null fields will be omitted.""" - tag_datatype: NotRequired[bool] - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" allowed_key_chars: NotRequired[List[str]] r"""A list of characters that may be present in a key name, even though they are normally separator or control characters""" allowed_value_chars: NotRequired[List[str]] @@ -915,9 +889,6 @@ class SerdeTypeDelim(BaseModel): null_value: Annotated[Optional[str], pydantic.Field(alias="nullValue")] = None r"""Field value representing the null value. Null fields will be omitted.""" - tag_datatype: Annotated[Optional[bool], pydantic.Field(alias="tagDatatype")] = None - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" - allowed_key_chars: Annotated[ Optional[List[str]], pydantic.Field(alias="allowedKeyChars") ] = None @@ -988,7 +959,6 @@ def serialize_model(self, handler): "quoteChar", "escapeChar", "nullValue", - "tagDatatype", "allowedKeyChars", "allowedValueChars", "regex", @@ -1067,8 +1037,6 @@ class SerdeTypeKvpTypedDict(TypedDict): r"""A list of characters that may be present in a key name, even though they are normally separator or control characters""" allowed_value_chars: NotRequired[List[str]] r"""A list of characters that may be present in a value, even though they are normally separator or control characters""" - tag_datatype: NotRequired[bool] - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" fields: NotRequired[List[str]] r"""The fields to be extracted, listed in order. Will auto-generate if empty.""" regex: NotRequired[str] @@ -1124,9 +1092,6 @@ class SerdeTypeKvp(BaseModel): ] = None r"""A list of characters that may be present in a value, even though they are normally separator or control characters""" - tag_datatype: Annotated[Optional[bool], pydantic.Field(alias="tagDatatype")] = None - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" - fields: Optional[List[str]] = None r"""The fields to be extracted, listed in order. Will auto-generate if empty.""" @@ -1188,7 +1153,6 @@ def serialize_model(self, handler): "cleanFields", "allowedKeyChars", "allowedValueChars", - "tagDatatype", "fields", "regex", "regexList", @@ -1250,8 +1214,6 @@ class SerdeTypeAutoTypedDict(TypedDict): r"""Parser or formatter type to use.""" mode: SerdeTypeAutoOperationMode r"""Extract creates new fields. Reserialize extracts and filters fields, and then reserializes.""" - tag_datatype: NotRequired[bool] - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" keep: NotRequired[List[str]] r"""List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'.""" remove: NotRequired[List[str]] @@ -1287,9 +1249,6 @@ class SerdeTypeAuto(BaseModel): mode: SerdeTypeAutoOperationMode r"""Extract creates new fields. Reserialize extracts and filters fields, and then reserializes.""" - tag_datatype: Annotated[Optional[bool], pydantic.Field(alias="tagDatatype")] = None - r"""Keep the detected datatype field and set isParsed to true on each event. Enable this when events are bound for downstream Cribl Search processing.""" - keep: Optional[List[str]] = None r"""List of fields to keep. Supports wildcards (*). Takes precedence over 'Fields to remove'.""" @@ -1364,7 +1323,6 @@ def serialize_mode(self, value): def serialize_model(self, handler): optional_fields = set( [ - "tagDatatype", "keep", "remove", "fieldFilterExpr", diff --git a/src/cribl_control_plane/models/pqtype.py b/src/cribl_control_plane/models/pqtype.py index 6b16b6447..a8cf68154 100644 --- a/src/cribl_control_plane/models/pqtype.py +++ b/src/cribl_control_plane/models/pqtype.py @@ -28,7 +28,7 @@ class PqTypeTypedDict(TypedDict): max_buffer_size: NotRequired[float] r"""Maximum number of events to hold in memory before writing the events to disk. Deprecated and only supported in workers < v4.17.0. Use maxBufferSizeBytes instead.""" commit_frequency: NotRequired[float] - r"""The number of events to send downstream before committing that Stream has read them""" + r"""The number of events to send downstream before committing that Stream has read them. Lower values increase cursor-write IOPS and can add disk pressure, including on shared storage.""" max_file_size: NotRequired[str] r"""The maximum size to store in each queue file before closing and optionally compressing. Enter a numeral with units of KB, MB, etc.""" max_size: NotRequired[str] @@ -60,7 +60,7 @@ class PqType(BaseModel): commit_frequency: Annotated[ Optional[float], pydantic.Field(alias="commitFrequency") ] = None - r"""The number of events to send downstream before committing that Stream has read them""" + r"""The number of events to send downstream before committing that Stream has read them. Lower values increase cursor-write IOPS and can add disk pressure, including on shared storage.""" max_file_size: Annotated[Optional[str], pydantic.Field(alias="maxFileSize")] = None r"""The maximum size to store in each queue file before closing and optionally compressing. Enter a numeral with units of KB, MB, etc.""" diff --git a/src/cribl_control_plane/models/rbacresource.py b/src/cribl_control_plane/models/rbacresource.py index 1f1efe17c..1a6de0b86 100644 --- a/src/cribl_control_plane/models/rbacresource.py +++ b/src/cribl_control_plane/models/rbacresource.py @@ -7,6 +7,7 @@ class RbacResource(str, Enum, metaclass=utils.OpenEnumMeta): GROUPS = "groups" + INSIGHTS_APPS = "insights-apps" DATASETS = "datasets" DATASET_PROVIDERS = "dataset-providers" PROJECTS = "projects" @@ -15,3 +16,4 @@ class RbacResource(str, Enum, metaclass=utils.OpenEnumMeta): NOTEBOOKS = "notebooks" NOTEBOOK_TEMPLATES = "notebook-templates" APPS = "apps" + SECRET_FOLDERS = "secret-folders" diff --git a/src/cribl_control_plane/models/routeconf.py b/src/cribl_control_plane/models/routeconf.py index eb401ee4b..78715859e 100644 --- a/src/cribl_control_plane/models/routeconf.py +++ b/src/cribl_control_plane/models/routeconf.py @@ -19,6 +19,8 @@ class RouteConfTypedDict(TypedDict): r"""Name of the Route.""" pipeline: str r"""Pipeline that the Route sends matching events to.""" + auto_parse: NotRequired[bool] + r"""If true, detect each matched event's datatype and extract fields from _raw before the Pipeline processes the event, so Functions and Filters can reference the extracted fields. Otherwise, false (the default).""" clones: NotRequired[List[Dict[str, str]]] r"""Array of clone configurations, each with a key-value pair to set or overwrite in cloned events. Original events continue to the next Route.""" context: NotRequired[str] @@ -53,6 +55,9 @@ class RouteConf(BaseModel): pipeline: str r"""Pipeline that the Route sends matching events to.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""If true, detect each matched event's datatype and extract fields from _raw before the Pipeline processes the event, so Functions and Filters can reference the extracted fields. Otherwise, false (the default).""" + clones: Optional[List[Dict[str, str]]] = None r"""Array of clone configurations, each with a key-value pair to set or overwrite in cloned events. Original events continue to the next Route.""" @@ -101,6 +106,7 @@ def serialize_target_context(self, value): def serialize_model(self, handler): optional_fields = set( [ + "autoParse", "clones", "context", "description", diff --git a/src/cribl_control_plane/models/routeconfinput.py b/src/cribl_control_plane/models/routeconfinput.py index bade53beb..e00e1be2a 100644 --- a/src/cribl_control_plane/models/routeconfinput.py +++ b/src/cribl_control_plane/models/routeconfinput.py @@ -15,6 +15,8 @@ class RouteConfInputTypedDict(TypedDict): r"""Name of the Route.""" pipeline: str r"""Pipeline that the Route sends matching events to.""" + auto_parse: NotRequired[bool] + r"""If true, detect each matched event's datatype and extract fields from _raw before the Pipeline processes the event, so Functions and Filters can reference the extracted fields. Otherwise, false (the default).""" clones: NotRequired[List[Dict[str, str]]] r"""Array of clone configurations, each with a key-value pair to set or overwrite in cloned events. Original events continue to the next Route.""" context: NotRequired[str] @@ -47,6 +49,9 @@ class RouteConfInput(BaseModel): pipeline: str r"""Pipeline that the Route sends matching events to.""" + auto_parse: Annotated[Optional[bool], pydantic.Field(alias="autoParse")] = None + r"""If true, detect each matched event's datatype and extract fields from _raw before the Pipeline processes the event, so Functions and Filters can reference the extracted fields. Otherwise, false (the default).""" + clones: Optional[List[Dict[str, str]]] = None r"""Array of clone configurations, each with a key-value pair to set or overwrite in cloned events. Original events continue to the next Route.""" @@ -101,6 +106,7 @@ def serialize_target_context(self, value): def serialize_model(self, handler): optional_fields = set( [ + "autoParse", "clones", "context", "description", diff --git a/src/cribl_control_plane/models/runnablejobcollection.py b/src/cribl_control_plane/models/runnablejobcollection.py index ee7bbf24f..1d5f48ad2 100644 --- a/src/cribl_control_plane/models/runnablejobcollection.py +++ b/src/cribl_control_plane/models/runnablejobcollection.py @@ -14,10 +14,6 @@ ScheduleTypeRunnableJobCollection, ScheduleTypeRunnableJobCollectionTypedDict, ) -from .timewarningtyperunnablejobcollectionschedulerun import ( - TimeWarningTypeRunnableJobCollectionScheduleRun, - TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict, -) from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum @@ -129,6 +125,8 @@ def serialize_model(self, handler): class RunnableJobCollectionRunTypedDict(TypedDict): + r"""Run settings that control how and when the Collection job runs.""" + mode: RunnableJobCollectionMode r"""Job run mode. Preview will either return up to N matching results, or will run until capture time T is reached. Discovery will gather the list of files to turn into streaming tasks, without running the data collection job. Full Run will run the collection job.""" reschedule_dropped_tasks: NotRequired[bool] @@ -147,8 +145,6 @@ class RunnableJobCollectionRunTypedDict(TypedDict): r"""Latest time to collect data for the selected timezone""" timestamp_timezone: NotRequired[str] r"""Timezone to use for Earliest and Latest times""" - time_warning: NotRequired[TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict] - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" expression: NotRequired[str] r"""A filter for tokens in the provided collect path and/or the events being collected""" min_task_size: NotRequired[str] @@ -168,6 +164,8 @@ class RunnableJobCollectionRunTypedDict(TypedDict): class RunnableJobCollectionRun(BaseModel): + r"""Run settings that control how and when the Collection job runs.""" + mode: RunnableJobCollectionMode r"""Job run mode. Preview will either return up to N matching results, or will run until capture time T is reached. Discovery will gather the list of files to turn into streaming tasks, without running the data collection job. Full Run will run the collection job.""" @@ -206,12 +204,6 @@ class RunnableJobCollectionRun(BaseModel): ] = None r"""Timezone to use for Earliest and Latest times""" - time_warning: Annotated[ - Optional[TimeWarningTypeRunnableJobCollectionScheduleRun], - pydantic.Field(alias="timeWarning"), - ] = None - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" - expression: Optional[str] = None r"""A filter for tokens in the provided collect path and/or the events being collected""" @@ -274,7 +266,6 @@ def serialize_model(self, handler): "earliest", "latest", "timestampTimezone", - "timeWarning", "expression", "minTaskSize", "maxTaskSize", @@ -302,6 +293,7 @@ class RunnableJobCollectionTypedDict(TypedDict): collector: CollectorTypedDict r"""Collector configuration""" run: RunnableJobCollectionRunTypedDict + r"""Run settings that control how and when the Collection job runs.""" id: NotRequired[str] r"""Unique ID for this Job""" description: NotRequired[str] @@ -337,6 +329,7 @@ class RunnableJobCollection(BaseModel): r"""Collector configuration""" run: RunnableJobCollectionRun + r"""Run settings that control how and when the Collection job runs.""" id: Optional[str] = None r"""Unique ID for this Job""" diff --git a/src/cribl_control_plane/models/runnablejobexecutor.py b/src/cribl_control_plane/models/runnablejobexecutor.py index f1d97ace6..f01e73ad6 100644 --- a/src/cribl_control_plane/models/runnablejobexecutor.py +++ b/src/cribl_control_plane/models/runnablejobexecutor.py @@ -22,6 +22,8 @@ class RunnableJobExecutorRunTypedDict(TypedDict): + r"""Run settings that control how and when the Executor job runs.""" + reschedule_dropped_tasks: NotRequired[bool] r"""Reschedule tasks that failed with non-fatal errors""" max_task_reschedule: NotRequired[float] @@ -33,6 +35,8 @@ class RunnableJobExecutorRunTypedDict(TypedDict): class RunnableJobExecutorRun(BaseModel): + r"""Run settings that control how and when the Executor job runs.""" + reschedule_dropped_tasks: Annotated[ Optional[bool], pydantic.Field(alias="rescheduleDroppedTasks") ] = None @@ -86,6 +90,7 @@ class RunnableJobExecutorTypedDict(TypedDict): executor: ExecutorTypeRunnableJobExecutorTypedDict r"""Executor configuration, including the executor type and its settings.""" run: RunnableJobExecutorRunTypedDict + r"""Run settings that control how and when the Executor job runs.""" id: NotRequired[str] r"""Unique ID for this Job""" description: NotRequired[str] @@ -117,6 +122,7 @@ class RunnableJobExecutor(BaseModel): r"""Executor configuration, including the executor type and its settings.""" run: RunnableJobExecutorRun + r"""Run settings that control how and when the Executor job runs.""" id: Optional[str] = None r"""Unique ID for this Job""" diff --git a/src/cribl_control_plane/models/runsettingstyperunnablejobcollectionschedule.py b/src/cribl_control_plane/models/runsettingstyperunnablejobcollectionschedule.py index 118fd230e..db54ce89b 100644 --- a/src/cribl_control_plane/models/runsettingstyperunnablejobcollectionschedule.py +++ b/src/cribl_control_plane/models/runsettingstyperunnablejobcollectionschedule.py @@ -4,10 +4,6 @@ from .logleveloptionsrunnablejobcollectionschedulerun import ( LogLevelOptionsRunnableJobCollectionScheduleRun, ) -from .timewarningtyperunnablejobcollectionschedulerun import ( - TimeWarningTypeRunnableJobCollectionScheduleRun, - TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict, -) from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum @@ -72,8 +68,6 @@ class RunSettingsTypeRunnableJobCollectionScheduleTypedDict(TypedDict): r"""Latest time to collect data for the selected timezone""" timestamp_timezone: NotRequired[str] r"""IANA timezone name for interpreting timestamp values in the collection time range.""" - time_warning: NotRequired[TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict] - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" expression: NotRequired[str] r"""A filter for tokens in the provided collect path and/or the events being collected""" min_task_size: NotRequired[str] @@ -132,12 +126,6 @@ class RunSettingsTypeRunnableJobCollectionSchedule(BaseModel): ] = None r"""IANA timezone name for interpreting timestamp values in the collection time range.""" - time_warning: Annotated[ - Optional[TimeWarningTypeRunnableJobCollectionScheduleRun], - pydantic.Field(alias="timeWarning"), - ] = None - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" - expression: Optional[str] = None r"""A filter for tokens in the provided collect path and/or the events being collected""" @@ -184,7 +172,6 @@ def serialize_model(self, handler): "earliest", "latest", "timestampTimezone", - "timeWarning", "expression", "minTaskSize", "maxTaskSize", diff --git a/src/cribl_control_plane/models/runsettingstypesavedjobresponsecollectionschedule.py b/src/cribl_control_plane/models/runsettingstypesavedjobresponsecollectionschedule.py index db3424d2b..cd8b87598 100644 --- a/src/cribl_control_plane/models/runsettingstypesavedjobresponsecollectionschedule.py +++ b/src/cribl_control_plane/models/runsettingstypesavedjobresponsecollectionschedule.py @@ -4,10 +4,6 @@ from .logleveloptionsrunnablejobcollectionschedulerun import ( LogLevelOptionsRunnableJobCollectionScheduleRun, ) -from .timewarningtyperunnablejobcollectionschedulerun import ( - TimeWarningTypeRunnableJobCollectionScheduleRun, - TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict, -) from cribl_control_plane import models, utils from cribl_control_plane.types import BaseModel, UNSET_SENTINEL from enum import Enum @@ -78,8 +74,6 @@ class RunSettingsTypeSavedJobResponseCollectionScheduleTypedDict(TypedDict): r"""Latest time to collect data for the selected timezone""" timestamp_timezone: NotRequired[str] r"""IANA timezone name for interpreting timestamp values in the collection time range.""" - time_warning: NotRequired[TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict] - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" expression: NotRequired[str] r"""A filter for tokens in the provided collect path and/or the events being collected""" min_task_size: NotRequired[str] @@ -138,12 +132,6 @@ class RunSettingsTypeSavedJobResponseCollectionSchedule(BaseModel): ] = None r"""IANA timezone name for interpreting timestamp values in the collection time range.""" - time_warning: Annotated[ - Optional[TimeWarningTypeRunnableJobCollectionScheduleRun], - pydantic.Field(alias="timeWarning"), - ] = None - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" - expression: Optional[str] = None r"""A filter for tokens in the provided collect path and/or the events being collected""" @@ -192,7 +180,6 @@ def serialize_model(self, handler): "earliest", "latest", "timestampTimezone", - "timeWarning", "expression", "minTaskSize", "maxTaskSize", diff --git a/src/cribl_control_plane/models/savedjobresponse.py b/src/cribl_control_plane/models/savedjobresponse.py index e767e842e..30cab1e9a 100644 --- a/src/cribl_control_plane/models/savedjobresponse.py +++ b/src/cribl_control_plane/models/savedjobresponse.py @@ -15,7 +15,7 @@ InputTypeRunnableJobCollectionTypedDict, ) from .jobtypeoptionsrunnablejobcollection import JobTypeOptionsRunnableJobCollection -from .notification_union import NotificationUnion, NotificationUnionTypedDict +from .notification import Notification, NotificationTypedDict from .scheduletypesavedjobresponsecollection import ( ScheduleTypeSavedJobResponseCollection, ScheduleTypeSavedJobResponseCollectionTypedDict, @@ -59,7 +59,7 @@ class SavedJobResponseScheduledSearchTypedDict(TypedDict): Dict[str, AdditionalPropertiesTypeEnrichedFieldsSavedStateTypedDict] ] r"""Runtime collection state.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notification targets.""" @@ -116,7 +116,7 @@ class SavedJobResponseScheduledSearch(BaseModel): ] = None r"""Runtime collection state.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notification targets.""" @field_serializer("type") @@ -191,7 +191,7 @@ class SavedJobResponseExecutorTypedDict(TypedDict): Dict[str, AdditionalPropertiesTypeEnrichedFieldsSavedStateTypedDict] ] r"""Runtime collection state.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notification targets.""" @@ -248,7 +248,7 @@ class SavedJobResponseExecutor(BaseModel): ] = None r"""Runtime collection state.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notification targets.""" @field_serializer("type") @@ -327,7 +327,7 @@ class SavedJobResponseCollectionTypedDict(TypedDict): Dict[str, AdditionalPropertiesTypeEnrichedFieldsSavedStateTypedDict] ] r"""Runtime collection state.""" - notifications: NotRequired[List[NotificationUnionTypedDict]] + notifications: NotRequired[List[NotificationTypedDict]] r"""Notification targets.""" @@ -392,7 +392,7 @@ class SavedJobResponseCollection(BaseModel): ] = None r"""Runtime collection state.""" - notifications: Optional[List[NotificationUnion]] = None + notifications: Optional[List[Notification]] = None r"""Notification targets.""" @field_serializer("type") diff --git a/src/cribl_control_plane/models/searchexecutionconfig.py b/src/cribl_control_plane/models/searchexecutionconfig.py new file mode 100644 index 000000000..9f704f864 --- /dev/null +++ b/src/cribl_control_plane/models/searchexecutionconfig.py @@ -0,0 +1,61 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane import models, utils +from cribl_control_plane.types import BaseModel, UNSET_SENTINEL +from enum import Enum +import pydantic +from pydantic import field_serializer, model_serializer +from typing import Optional +from typing_extensions import Annotated, NotRequired, TypedDict + + +class BackendID(str, Enum, metaclass=utils.OpenEnumMeta): + DYNAMIC = "dynamic" + BYO = "byo" + + +class SearchExecutionConfigTypedDict(TypedDict): + backend_id: BackendID + pool_routing_key: NotRequired[str] + r"""Selects the ordinary BYO executor pool. Required only when backendId is byo; not used for Lake datasets.""" + + +class SearchExecutionConfig(BaseModel): + backend_id: Annotated[BackendID, pydantic.Field(alias="backendId")] + + pool_routing_key: Annotated[ + Optional[str], pydantic.Field(alias="poolRoutingKey") + ] = None + r"""Selects the ordinary BYO executor pool. Required only when backendId is byo; not used for Lake datasets.""" + + @field_serializer("backend_id") + def serialize_backend_id(self, value): + if isinstance(value, str): + try: + return models.BackendID(value) + except ValueError: + return value + return value + + @model_serializer(mode="wrap") + def serialize_model(self, handler): + optional_fields = set(["poolRoutingKey"]) + serialized = handler(self) + m = {} + + for n, f in type(self).model_fields.items(): + k = f.alias or n + val = serialized.get(k, serialized.get(n)) + + if val != UNSET_SENTINEL: + if val is not None or k not in optional_fields: + m[k] = val + + return m + + +try: + SearchExecutionConfig.model_rebuild() +except NameError: + pass diff --git a/src/cribl_control_plane/models/ssltypesystemsettingsconfapi.py b/src/cribl_control_plane/models/ssltypesystemsettingsconfapi.py index df804aca4..1bf02595c 100644 --- a/src/cribl_control_plane/models/ssltypesystemsettingsconfapi.py +++ b/src/cribl_control_plane/models/ssltypesystemsettingsconfapi.py @@ -21,6 +21,8 @@ class SslTypeSystemSettingsConfAPITypedDict(TypedDict): r"""Filesystem path to the PEM-encoded TLS private key.""" ca_path: NotRequired[str] r"""Filesystem path to the PEM-encoded Certificate Authority (CA) certificate for client authentication.""" + certificate_name: NotRequired[str] + r"""Name of a predefined Certificate stored in Cribl.""" class SslTypeSystemSettingsConfAPI(BaseModel): @@ -41,9 +43,14 @@ class SslTypeSystemSettingsConfAPI(BaseModel): ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None r"""Filesystem path to the PEM-encoded Certificate Authority (CA) certificate for client authentication.""" + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""Name of a predefined Certificate stored in Cribl.""" + @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["caPath"]) + optional_fields = set(["caPath", "certificateName"]) serialized = handler(self) m = {} diff --git a/src/cribl_control_plane/models/systemsettingsconfresponse.py b/src/cribl_control_plane/models/systemsettingsconfresponse.py index 878f77181..6b0d24651 100644 --- a/src/cribl_control_plane/models/systemsettingsconfresponse.py +++ b/src/cribl_control_plane/models/systemsettingsconfresponse.py @@ -1,6 +1,10 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" from __future__ import annotations +from .apitypesystemsettingsconf import ( + APITypeSystemSettingsConf, + APITypeSystemSettingsConfTypedDict, +) from .appstypesystemsettingsconf import ( AppsTypeSystemSettingsConf, AppsTypeSystemSettingsConfTypedDict, @@ -28,184 +32,33 @@ SocketsTypeSystemSettingsConf, SocketsTypeSystemSettingsConfTypedDict, ) -from .ssltypesystemsettingsconfapi import ( - SslTypeSystemSettingsConfAPI, - SslTypeSystemSettingsConfAPITypedDict, -) from .supporttypesystemsettingsconf import ( SupportTypeSystemSettingsConf, SupportTypeSystemSettingsConfTypedDict, ) +from .systemtypesystemsettingsconf import ( + SystemTypeSystemSettingsConf, + SystemTypeSystemSettingsConfTypedDict, +) from .tlssettings_union import TLSSettingsUnion, TLSSettingsUnionTypedDict from .upgradegroupsettings import UpgradeGroupSettings, UpgradeGroupSettingsTypedDict -from .upgradeoptionssystemsettingsconfsystem import ( - UpgradeOptionsSystemSettingsConfSystem, -) from .upgradesettings import UpgradeSettings, UpgradeSettingsTypedDict from .workerstypesystemsettingsconf import ( WorkersTypeSystemSettingsConf, WorkersTypeSystemSettingsConfTypedDict, ) -from cribl_control_plane import models from cribl_control_plane.types import BaseModel, UNSET_SENTINEL import pydantic -from pydantic import field_serializer, model_serializer -from typing import Dict, List, Optional +from pydantic import model_serializer +from typing import Optional from typing_extensions import Annotated, NotRequired, TypedDict -class SystemSettingsConfResponseAPITypedDict(TypedDict): - disabled: bool - r"""If true, the API server is disabled. Otherwise, false.""" - host: str - r"""Hostname or IP address the API server listens on.""" - port: int - r"""Port number the API server listens on.""" - base_url: NotRequired[str] - r"""Base URL for the API server. Used when the server is behind a reverse proxy.""" - disable_api_cache: NotRequired[bool] - r"""If true, disable the API response cache. Otherwise, false.""" - headers: NotRequired[Dict[str, str]] - r"""Custom HTTP response headers to include in every API response.""" - idle_session_ttl: NotRequired[int] - r"""Idle session timeout in seconds. Sessions are invalidated after the specified seconds of inactivity.""" - listen_on_port: NotRequired[bool] - r"""If true, bind to the configured port as the server listen port. Otherwise, false.""" - login_rate_limit: NotRequired[str] - r"""Rate limit for login attempts. Value is a string such as 100/min.""" - protocol: NotRequired[str] - r"""API protocol: http or https.""" - scripts: NotRequired[bool] - r"""If true, enable JavaScript scripting support in the API. Otherwise, false.""" - sensitive_fields: NotRequired[List[str]] - r"""List of field names whose values are redacted in API responses and logs.""" - ssl: NotRequired[SslTypeSystemSettingsConfAPITypedDict] - r"""TLS configuration for the API server.""" - sso_rate_limit: NotRequired[str] - r"""Rate limit for SSO authentication attempts. Value is a string such as 100/min.""" - worker_remote_access: NotRequired[bool] - r"""If true, enable remote access (teleporting) to Worker Processes via the API. Otherwise, false.""" - - -class SystemSettingsConfResponseAPI(BaseModel): - disabled: bool - r"""If true, the API server is disabled. Otherwise, false.""" - - host: str - r"""Hostname or IP address the API server listens on.""" - - port: int - r"""Port number the API server listens on.""" - - base_url: Annotated[Optional[str], pydantic.Field(alias="baseUrl")] = None - r"""Base URL for the API server. Used when the server is behind a reverse proxy.""" - - disable_api_cache: Annotated[ - Optional[bool], pydantic.Field(alias="disableApiCache") - ] = None - r"""If true, disable the API response cache. Otherwise, false.""" - - headers: Optional[Dict[str, str]] = None - r"""Custom HTTP response headers to include in every API response.""" - - idle_session_ttl: Annotated[ - Optional[int], pydantic.Field(alias="idleSessionTTL") - ] = None - r"""Idle session timeout in seconds. Sessions are invalidated after the specified seconds of inactivity.""" - - listen_on_port: Annotated[Optional[bool], pydantic.Field(alias="listenOnPort")] = ( - None - ) - r"""If true, bind to the configured port as the server listen port. Otherwise, false.""" - - login_rate_limit: Annotated[ - Optional[str], pydantic.Field(alias="loginRateLimit") - ] = None - r"""Rate limit for login attempts. Value is a string such as 100/min.""" - - protocol: Optional[str] = None - r"""API protocol: http or https.""" - - scripts: Optional[bool] = None - r"""If true, enable JavaScript scripting support in the API. Otherwise, false.""" - - sensitive_fields: Annotated[ - Optional[List[str]], pydantic.Field(alias="sensitiveFields") - ] = None - r"""List of field names whose values are redacted in API responses and logs.""" - - ssl: Optional[SslTypeSystemSettingsConfAPI] = None - r"""TLS configuration for the API server.""" - - sso_rate_limit: Annotated[Optional[str], pydantic.Field(alias="ssoRateLimit")] = ( - None - ) - r"""Rate limit for SSO authentication attempts. Value is a string such as 100/min.""" - - worker_remote_access: Annotated[ - Optional[bool], pydantic.Field(alias="workerRemoteAccess") - ] = None - r"""If true, enable remote access (teleporting) to Worker Processes via the API. Otherwise, false.""" - - @model_serializer(mode="wrap") - def serialize_model(self, handler): - optional_fields = set( - [ - "baseUrl", - "disableApiCache", - "headers", - "idleSessionTTL", - "listenOnPort", - "loginRateLimit", - "protocol", - "scripts", - "sensitiveFields", - "ssl", - "ssoRateLimit", - "workerRemoteAccess", - ] - ) - serialized = handler(self) - m = {} - - for n, f in type(self).model_fields.items(): - k = f.alias or n - val = serialized.get(k, serialized.get(n)) - - if val != UNSET_SENTINEL: - if val is not None or k not in optional_fields: - m[k] = val - - return m - - -class SystemSettingsConfResponseSystemTypedDict(TypedDict): - intercom: bool - r"""If true, enable Intercom integration for in-product messaging. Otherwise, false.""" - upgrade: UpgradeOptionsSystemSettingsConfSystem - r"""Upgrade permission policy: api to allow upgrades from the UI or API or false to disable.""" - - -class SystemSettingsConfResponseSystem(BaseModel): - intercom: bool - r"""If true, enable Intercom integration for in-product messaging. Otherwise, false.""" - - upgrade: UpgradeOptionsSystemSettingsConfSystem - r"""Upgrade permission policy: api to allow upgrades from the UI or API or false to disable.""" - - @field_serializer("upgrade") - def serialize_upgrade(self, value): - if isinstance(value, str): - try: - return models.UpgradeOptionsSystemSettingsConfSystem(value) - except ValueError: - return value - return value - - class SystemSettingsConfResponseTypedDict(TypedDict): - api: SystemSettingsConfResponseAPITypedDict - system: SystemSettingsConfResponseSystemTypedDict + api: APITypeSystemSettingsConfTypedDict + r"""API server configuration for the Cribl instance.""" + system: SystemTypeSystemSettingsConfTypedDict + r"""System-level operational settings for the Cribl instance.""" apps: NotRequired[AppsTypeSystemSettingsConfTypedDict] r"""App configuration.""" backups: NotRequired[BackupsSettingsUnionTypedDict] @@ -230,9 +83,11 @@ class SystemSettingsConfResponseTypedDict(TypedDict): class SystemSettingsConfResponse(BaseModel): - api: SystemSettingsConfResponseAPI + api: APITypeSystemSettingsConf + r"""API server configuration for the Cribl instance.""" - system: SystemSettingsConfResponseSystem + system: SystemTypeSystemSettingsConf + r"""System-level operational settings for the Cribl instance.""" apps: Optional[AppsTypeSystemSettingsConf] = None r"""App configuration.""" @@ -309,10 +164,6 @@ def serialize_model(self, handler): return m -try: - SystemSettingsConfResponseAPI.model_rebuild() -except NameError: - pass try: SystemSettingsConfResponse.model_rebuild() except NameError: diff --git a/src/cribl_control_plane/models/systemsettingsconfupdate.py b/src/cribl_control_plane/models/systemsettingsconfupdate.py index 223b7339b..20c51e046 100644 --- a/src/cribl_control_plane/models/systemsettingsconfupdate.py +++ b/src/cribl_control_plane/models/systemsettingsconfupdate.py @@ -33,6 +33,8 @@ class SslTypedDict(TypedDict): r"""Filesystem path to the PEM-encoded Certificate Authority (CA) certificate for client authentication.""" cert_path: NotRequired[str] r"""Filesystem path to the PEM-encoded TLS certificate.""" + certificate_name: NotRequired[str] + r"""Name of a predefined Certificate stored in Cribl.""" disabled: NotRequired[bool] r"""If true, TLS is disabled for the API server. Otherwise, false.""" passphrase: NotRequired[str] @@ -50,6 +52,11 @@ class Ssl(BaseModel): cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None r"""Filesystem path to the PEM-encoded TLS certificate.""" + certificate_name: Annotated[ + Optional[str], pydantic.Field(alias="certificateName") + ] = None + r"""Name of a predefined Certificate stored in Cribl.""" + disabled: Optional[bool] = None r"""If true, TLS is disabled for the API server. Otherwise, false.""" @@ -62,7 +69,14 @@ class Ssl(BaseModel): @model_serializer(mode="wrap") def serialize_model(self, handler): optional_fields = set( - ["caPath", "certPath", "disabled", "passphrase", "privKeyPath"] + [ + "caPath", + "certPath", + "certificateName", + "disabled", + "passphrase", + "privKeyPath", + ] ) serialized = handler(self) m = {} @@ -78,7 +92,7 @@ def serialize_model(self, handler): return m -class SystemSettingsConfUpdateAPITypedDict(TypedDict): +class APITypedDict(TypedDict): r"""API server configuration for the Cribl instance.""" base_url: NotRequired[str] @@ -113,7 +127,7 @@ class SystemSettingsConfUpdateAPITypedDict(TypedDict): r"""If true, enable remote access (teleporting) to Worker Processes via the API. Otherwise, false.""" -class SystemSettingsConfUpdateAPI(BaseModel): +class API(BaseModel): r"""API server configuration for the Cribl instance.""" base_url: Annotated[Optional[str], pydantic.Field(alias="baseUrl")] = None @@ -213,6 +227,20 @@ def serialize_model(self, handler): class AppsTypedDict(TypedDict): r"""App configuration.""" + app_backend_broker_origin: NotRequired[str] + r"""Public origin for App Platform backend broker callbacks (standalone/on-prem only). Must be an absolute HTTP(S) URL.""" + app_backend_max_callbacks_per_installation: NotRequired[int] + r"""Maximum number of broker callbacks per minute a single app backend installation may make. Over-limit callbacks receive HTTP 429.""" + app_backend_max_callbacks_total: NotRequired[int] + r"""Maximum number of broker callbacks per minute across all app backend installations on this Leader. Unlimited when unset. Over-limit callbacks receive HTTP 429.""" + app_backend_max_in_flight: NotRequired[int] + r"""Maximum number of concurrent App Platform backend invocations across all apps on this Leader.""" + app_schedule_body_expression_max_length: NotRequired[int] + r"""Maximum number of characters allowed in a schedule bodyExpression.""" + app_scheduled_concurrent_job_limit: NotRequired[int] + r"""Maximum number of concurrent scheduled App Platform function jobs across all apps on this Leader (group-wide). Changes require a Leader restart.""" + app_schedules_max: NotRequired[int] + r"""Maximum number of schedule records a single App may declare.""" enabled: NotRequired[bool] r"""If true, enable Apps. Otherwise, false.""" @@ -220,12 +248,58 @@ class AppsTypedDict(TypedDict): class Apps(BaseModel): r"""App configuration.""" + app_backend_broker_origin: Annotated[ + Optional[str], pydantic.Field(alias="appBackendBrokerOrigin") + ] = None + r"""Public origin for App Platform backend broker callbacks (standalone/on-prem only). Must be an absolute HTTP(S) URL.""" + + app_backend_max_callbacks_per_installation: Annotated[ + Optional[int], pydantic.Field(alias="appBackendMaxCallbacksPerInstallation") + ] = None + r"""Maximum number of broker callbacks per minute a single app backend installation may make. Over-limit callbacks receive HTTP 429.""" + + app_backend_max_callbacks_total: Annotated[ + Optional[int], pydantic.Field(alias="appBackendMaxCallbacksTotal") + ] = None + r"""Maximum number of broker callbacks per minute across all app backend installations on this Leader. Unlimited when unset. Over-limit callbacks receive HTTP 429.""" + + app_backend_max_in_flight: Annotated[ + Optional[int], pydantic.Field(alias="appBackendMaxInFlight") + ] = None + r"""Maximum number of concurrent App Platform backend invocations across all apps on this Leader.""" + + app_schedule_body_expression_max_length: Annotated[ + Optional[int], pydantic.Field(alias="appScheduleBodyExpressionMaxLength") + ] = None + r"""Maximum number of characters allowed in a schedule bodyExpression.""" + + app_scheduled_concurrent_job_limit: Annotated[ + Optional[int], pydantic.Field(alias="appScheduledConcurrentJobLimit") + ] = None + r"""Maximum number of concurrent scheduled App Platform function jobs across all apps on this Leader (group-wide). Changes require a Leader restart.""" + + app_schedules_max: Annotated[ + Optional[int], pydantic.Field(alias="appSchedulesMax") + ] = None + r"""Maximum number of schedule records a single App may declare.""" + enabled: Optional[bool] = None r"""If true, enable Apps. Otherwise, false.""" @model_serializer(mode="wrap") def serialize_model(self, handler): - optional_fields = set(["enabled"]) + optional_fields = set( + [ + "appBackendBrokerOrigin", + "appBackendMaxCallbacksPerInstallation", + "appBackendMaxCallbacksTotal", + "appBackendMaxInFlight", + "appScheduleBodyExpressionMaxLength", + "appScheduledConcurrentJobLimit", + "appSchedulesMax", + "enabled", + ] + ) serialized = handler(self) m = {} @@ -585,7 +659,7 @@ def serialize_model(self, handler): class SystemSettingsConfUpdateTypedDict(TypedDict): - api: NotRequired[SystemSettingsConfUpdateAPITypedDict] + api: NotRequired[APITypedDict] r"""API server configuration for the Cribl instance.""" apps: NotRequired[AppsTypedDict] r"""App configuration.""" @@ -613,7 +687,7 @@ class SystemSettingsConfUpdateTypedDict(TypedDict): class SystemSettingsConfUpdate(BaseModel): - api: Optional[SystemSettingsConfUpdateAPI] = None + api: Optional[API] = None r"""API server configuration for the Cribl instance.""" apps: Optional[Apps] = None @@ -701,7 +775,11 @@ def serialize_model(self, handler): except NameError: pass try: - SystemSettingsConfUpdateAPI.model_rebuild() + API.model_rebuild() +except NameError: + pass +try: + Apps.model_rebuild() except NameError: pass try: diff --git a/src/cribl_control_plane/models/teamaccesscontrollist.py b/src/cribl_control_plane/models/teamaccesscontrollist.py index 38e2579ef..8b948b395 100644 --- a/src/cribl_control_plane/models/teamaccesscontrollist.py +++ b/src/cribl_control_plane/models/teamaccesscontrollist.py @@ -9,10 +9,14 @@ class TeamAccessControlListTypedDict(TypedDict): perms: List[ResourcePolicyTypedDict] + r"""List of resource policies that define the access permissions for this team.""" team: str + r"""Name of the team whose access control entries are listed.""" class TeamAccessControlList(BaseModel): perms: List[ResourcePolicy] + r"""List of resource policies that define the access permissions for this team.""" team: str + r"""Name of the team whose access control entries are listed.""" diff --git a/src/cribl_control_plane/models/templatefamilyoptionscriblsourceprovenance.py b/src/cribl_control_plane/models/templatefamilyoptionscriblsourceprovenance.py new file mode 100644 index 000000000..1eca6019c --- /dev/null +++ b/src/cribl_control_plane/models/templatefamilyoptionscriblsourceprovenance.py @@ -0,0 +1,14 @@ +"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" + +from __future__ import annotations +from cribl_control_plane import utils +from enum import Enum + + +class TemplateFamilyOptionsCriblSourceProvenance( + str, Enum, metaclass=utils.OpenEnumMeta +): + r"""Infrastructure-as-code family that provisioned the AWS resources (absent means cloudformation).""" + + CLOUDFORMATION = "cloudformation" + TERRAFORM = "terraform" diff --git a/src/cribl_control_plane/models/templatetargetpairconffunctionconfschemanotificationpolicies.py b/src/cribl_control_plane/models/templatetargetpairconffunctionconfschemanotificationpolicies.py deleted file mode 100644 index 66e568e07..000000000 --- a/src/cribl_control_plane/models/templatetargetpairconffunctionconfschemanotificationpolicies.py +++ /dev/null @@ -1,27 +0,0 @@ -"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" - -from __future__ import annotations -from cribl_control_plane.types import BaseModel -import pydantic -from typing_extensions import Annotated, TypedDict - - -class TemplateTargetPairConfFunctionConfSchemaNotificationPoliciesTypedDict(TypedDict): - template_id: str - r"""ID of the notification template to use""" - target_id: str - r"""ID of the notification target (output)""" - - -class TemplateTargetPairConfFunctionConfSchemaNotificationPolicies(BaseModel): - template_id: Annotated[str, pydantic.Field(alias="templateId")] - r"""ID of the notification template to use""" - - target_id: Annotated[str, pydantic.Field(alias="targetId")] - r"""ID of the notification target (output)""" - - -try: - TemplateTargetPairConfFunctionConfSchemaNotificationPolicies.model_rebuild() -except NameError: - pass diff --git a/src/cribl_control_plane/models/timewarningtyperunnablejobcollectionschedulerun.py b/src/cribl_control_plane/models/timewarningtyperunnablejobcollectionschedulerun.py deleted file mode 100644 index 89e2a9542..000000000 --- a/src/cribl_control_plane/models/timewarningtyperunnablejobcollectionschedulerun.py +++ /dev/null @@ -1,13 +0,0 @@ -"""Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" - -from __future__ import annotations -from cribl_control_plane.types import BaseModel -from typing_extensions import TypedDict - - -class TimeWarningTypeRunnableJobCollectionScheduleRunTypedDict(TypedDict): - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" - - -class TimeWarningTypeRunnableJobCollectionScheduleRun(BaseModel): - r"""Warning state used when the collection time range is unset for time-sensitive Collectors.""" diff --git a/src/cribl_control_plane/models/tlssettingsserversidetype.py b/src/cribl_control_plane/models/tlssettingsserversidetype.py index fb47e79ab..6b7ded935 100644 --- a/src/cribl_control_plane/models/tlssettingsserversidetype.py +++ b/src/cribl_control_plane/models/tlssettingsserversidetype.py @@ -18,6 +18,8 @@ class TLSSettingsServerSideTypeTypedDict(TypedDict): r"""If true, TLS is disabled on this connection.""" request_cert: NotRequired[bool] r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" + ca_path: NotRequired[str] + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" reject_unauthorized: NotRequired[bool] r"""Reject certificates not authorized by a CA in the CA certificate path or by another trusted CA (such as the system's)""" common_name_regex: NotRequired[str] @@ -30,8 +32,6 @@ class TLSSettingsServerSideTypeTypedDict(TypedDict): r"""Passphrase to use to decrypt private key""" cert_path: NotRequired[str] r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - ca_path: NotRequired[str] - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" min_version: NotRequired[MinimumTLSVersionOptionsTLS] r"""Minimum TLS version""" max_version: NotRequired[MaximumTLSVersionOptionsTLS] @@ -47,6 +47,9 @@ class TLSSettingsServerSideType(BaseModel): request_cert: Annotated[Optional[bool], pydantic.Field(alias="requestCert")] = None r"""Require clients to present their certificates. Used to perform client authentication using SSL certs.""" + ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None + r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" + reject_unauthorized: Annotated[ Optional[bool], pydantic.Field(alias="rejectUnauthorized") ] = None @@ -71,9 +74,6 @@ class TLSSettingsServerSideType(BaseModel): cert_path: Annotated[Optional[str], pydantic.Field(alias="certPath")] = None r"""Path on server containing certificates to use. PEM format. Can reference $ENV_VARS.""" - ca_path: Annotated[Optional[str], pydantic.Field(alias="caPath")] = None - r"""Path on server containing CA certificates to use. PEM format. Can reference $ENV_VARS.""" - min_version: Annotated[ Optional[MinimumTLSVersionOptionsTLS], pydantic.Field(alias="minVersion") ] = None @@ -108,13 +108,13 @@ def serialize_model(self, handler): [ "disabled", "requestCert", + "caPath", "rejectUnauthorized", "commonNameRegex", "certificateName", "privKeyPath", "passphrase", "certPath", - "caPath", "minVersion", "maxVersion", ] diff --git a/src/cribl_control_plane/models/updatepacksop.py b/src/cribl_control_plane/models/updatepacksop.py index e4a2ca529..8f13a3109 100644 --- a/src/cribl_control_plane/models/updatepacksop.py +++ b/src/cribl_control_plane/models/updatepacksop.py @@ -12,6 +12,7 @@ class UpdatePacksRequestTypedDict(TypedDict): filename: str r"""Filename of the Pack file to upload.""" request_body: Union[bytes, IO[bytes], io.IOBase] + r"""Binary contents of the .crbl Pack file to stage for installation""" class UpdatePacksRequest(BaseModel): @@ -23,3 +24,4 @@ class UpdatePacksRequest(BaseModel): request_body: Annotated[ Union[bytes, IO[bytes], io.IOBase], FieldMetadata(request=True) ] + r"""Binary contents of the .crbl Pack file to stage for installation""" diff --git a/src/cribl_control_plane/models/useraccesscontrollist.py b/src/cribl_control_plane/models/useraccesscontrollist.py index 81d6dd326..0b2d4fb5d 100644 --- a/src/cribl_control_plane/models/useraccesscontrollist.py +++ b/src/cribl_control_plane/models/useraccesscontrollist.py @@ -9,10 +9,14 @@ class UserAccessControlListTypedDict(TypedDict): perms: List[ResourcePolicyTypedDict] + r"""List of resource policies that define the access permissions for this member.""" user: str + r"""Username of the member whose access control entries are listed.""" class UserAccessControlList(BaseModel): perms: List[ResourcePolicy] + r"""List of resource policies that define the access permissions for this member.""" user: str + r"""Username of the member whose access control entries are listed.""" diff --git a/src/cribl_control_plane/models/workerpqstatus.py b/src/cribl_control_plane/models/workerpqstatus.py index b0519d95e..5982126f8 100644 --- a/src/cribl_control_plane/models/workerpqstatus.py +++ b/src/cribl_control_plane/models/workerpqstatus.py @@ -9,18 +9,24 @@ class WorkerPQStatusTypedDict(TypedDict): - health: float + health: int + r"""Persistent queue health status for the Worker Process, as a numeric code.

0 == Healthy (green; normal operation)

1 == Degraded (yellow; potential issues)

2 == Critical (red; problem or error that affects operation).""" metrics: Dict[str, Any] - timestamp: float + r"""Persistent-queue metrics reported for the Worker Process.""" + timestamp: int + r"""Timestamp (in Unix time) when the persistent queue status was last reported for the Worker Process, in milliseconds.""" error: NotRequired[StatusErrorTypedDict] class WorkerPQStatus(BaseModel): - health: float + health: int + r"""Persistent queue health status for the Worker Process, as a numeric code.

0 == Healthy (green; normal operation)

1 == Degraded (yellow; potential issues)

2 == Critical (red; problem or error that affects operation).""" metrics: Dict[str, Any] + r"""Persistent-queue metrics reported for the Worker Process.""" - timestamp: float + timestamp: int + r"""Timestamp (in Unix time) when the persistent queue status was last reported for the Worker Process, in milliseconds.""" error: Optional[StatusError] = None diff --git a/src/cribl_control_plane/nodes.py b/src/cribl_control_plane/nodes.py index fc374a6ee..891a12026 100644 --- a/src/cribl_control_plane/nodes.py +++ b/src/cribl_control_plane/nodes.py @@ -100,7 +100,11 @@ def count( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -200,7 +204,11 @@ async def count_async( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -315,7 +323,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -464,7 +476,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -603,7 +619,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -703,7 +723,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -808,7 +832,11 @@ def restart( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -913,7 +941,11 @@ async def restart_async( self.sdk_configuration.security, models.Security ), tags=["workers"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs.py b/src/cribl_control_plane/packs.py index 56ede74a2..d26f4bbdd 100644 --- a/src/cribl_control_plane/packs.py +++ b/src/cribl_control_plane/packs.py @@ -118,7 +118,11 @@ def install( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -220,7 +224,11 @@ async def install_async( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -323,7 +331,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -454,7 +466,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -525,7 +541,7 @@ def upload( Upload a Pack file. Returns the source ID needed to install the Pack with POST /packs, which you must call separately. :param filename: Filename of the Pack file to upload. - :param request_body: + :param request_body: Binary contents of the .crbl Pack file to stage for installation :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -592,7 +608,11 @@ def upload( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -632,7 +652,7 @@ async def upload_async( Upload a Pack file. Returns the source ID needed to install the Pack with POST /packs, which you must call separately. :param filename: Filename of the Pack file to upload. - :param request_body: + :param request_body: Binary contents of the .crbl Pack file to stage for installation :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -699,7 +719,11 @@ async def upload_async( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -796,7 +820,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -812,7 +840,7 @@ def get( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["409", "4XX"], "*"): http_res_text = utils.stream_to_text(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -893,7 +921,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -909,7 +941,7 @@ async def get_async( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["409", "4XX"], "*"): http_res_text = await utils.stream_to_text_async(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -1011,7 +1043,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1027,7 +1063,7 @@ def update( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["409", "4XX"], "*"): http_res_text = utils.stream_to_text(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -1129,7 +1165,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1145,7 +1185,7 @@ async def update_async( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["409", "4XX"], "*"): http_res_text = await utils.stream_to_text_async(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -1226,7 +1266,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1242,7 +1286,7 @@ def delete( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["409", "4XX"], "*"): http_res_text = utils.stream_to_text(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): @@ -1323,7 +1367,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["packs"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1339,7 +1387,7 @@ async def delete_async( if utils.match_response(http_res, "500", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) - if utils.match_response(http_res, "4XX", "*"): + if utils.match_response(http_res, ["409", "4XX"], "*"): http_res_text = await utils.stream_to_text_async(http_res) raise errors.APIError("API error occurred", http_res, http_res_text) if utils.match_response(http_res, "5XX", "*"): diff --git a/src/cribl_control_plane/packs_destinations.py b/src/cribl_control_plane/packs_destinations.py index a86de1757..87d86cfd9 100644 --- a/src/cribl_control_plane/packs_destinations.py +++ b/src/cribl_control_plane/packs_destinations.py @@ -116,7 +116,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -253,7 +257,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -399,7 +407,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -511,7 +523,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -611,7 +627,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -711,7 +731,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -817,7 +841,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -923,7 +951,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1023,7 +1055,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1123,7 +1159,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_destinations_pq.py b/src/cribl_control_plane/packs_destinations_pq.py index 4b68149e3..4d877f46d 100644 --- a/src/cribl_control_plane/packs_destinations_pq.py +++ b/src/cribl_control_plane/packs_destinations_pq.py @@ -85,7 +85,11 @@ def clear( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -185,7 +189,11 @@ async def clear_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -285,7 +293,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -385,7 +397,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_destinations_statuses.py b/src/cribl_control_plane/packs_destinations_statuses.py index 4f719c4bd..46fdffd7b 100644 --- a/src/cribl_control_plane/packs_destinations_statuses.py +++ b/src/cribl_control_plane/packs_destinations_statuses.py @@ -95,7 +95,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -234,7 +238,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -375,7 +383,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -481,7 +493,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_hectokens.py b/src/cribl_control_plane/packs_hectokens.py index 6318bd0a0..1537de097 100644 --- a/src/cribl_control_plane/packs_hectokens.py +++ b/src/cribl_control_plane/packs_hectokens.py @@ -118,7 +118,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -251,7 +255,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -384,7 +392,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -517,7 +529,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_pipelines.py b/src/cribl_control_plane/packs_pipelines.py index 80546fc61..ff2085941 100644 --- a/src/cribl_control_plane/packs_pipelines.py +++ b/src/cribl_control_plane/packs_pipelines.py @@ -27,8 +27,8 @@ def list( Get a list of all Pipelines within the specified Pack. :param pack: The id of the Pack. - :param offset: Pagination offset - :param limit: Maximum number of items to return + :param offset: Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. + :param limit: Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -89,7 +89,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -158,8 +162,8 @@ async def list_async( Get a list of all Pipelines within the specified Pack. :param pack: The id of the Pack. - :param offset: Pagination offset - :param limit: Maximum number of items to return + :param offset: Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. + :param limit: Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -220,7 +224,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -359,7 +367,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -467,7 +479,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -567,7 +583,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -667,7 +687,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -778,7 +802,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -889,7 +917,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -989,7 +1021,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1089,7 +1125,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_routes.py b/src/cribl_control_plane/packs_routes.py index 8b1570092..367d7dcfe 100644 --- a/src/cribl_control_plane/packs_routes.py +++ b/src/cribl_control_plane/packs_routes.py @@ -6,7 +6,8 @@ from cribl_control_plane.types import OptionalNullable, UNSET from cribl_control_plane.utils import get_security_from_env from cribl_control_plane.utils.unmarshal_json_response import unmarshal_json_response -from typing import Any, Dict, Iterable, List, Mapping, Optional, Union +from jsonpath import JSONPath +from typing import Any, Awaitable, Dict, Iterable, List, Mapping, Optional, Union class PacksRoutes(BaseSDK): @@ -14,16 +15,20 @@ def list( self, *, pack: str, + offset: Optional[int] = None, + limit: Optional[int] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> models.CountedRoutes: + ) -> Optional[models.GetRoutesByPackResponse]: r"""List all Routes within a Pack Get a list of all Routes within the specified Pack. :param pack: The id of the Pack. + :param offset: Pagination offset + :param limit: Maximum number of items to return :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -40,6 +45,8 @@ def list( base_url = self._get_url(base_url, url_variables) request = models.GetRoutesByPackRequest( + offset=offset, + limit=limit, pack=pack, ) @@ -82,16 +89,48 @@ def list( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) + def next_func() -> Optional[models.GetRoutesByPackResponse]: + body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) + + offset = request.offset if isinstance(request.offset, int) else 0 + + if not http_res.text: + return None + results = JSONPath("$.items").parse(body) + if len(results) == 0 or len(results[0]) == 0: + return None + limit_ = request.limit if isinstance(request.limit, int) else 0 + if len(results[0]) < limit_: + return None + next_offset = offset + len(results[0]) + + return self.list( + pack=pack, + offset=next_offset, + limit=limit, + retries=retries, + server_url=server_url, + timeout_ms=timeout_ms, + http_headers=http_headers, + ) + response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return unmarshal_json_response(models.CountedRoutes, http_res) + return models.GetRoutesByPackResponse( + result=unmarshal_json_response(models.PaginatedRoutes, http_res), + next=next_func, + ) if utils.match_response(http_res, "401", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) @@ -111,16 +150,20 @@ async def list_async( self, *, pack: str, + offset: Optional[int] = None, + limit: Optional[int] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> models.CountedRoutes: + ) -> Optional[models.GetRoutesByPackResponse]: r"""List all Routes within a Pack Get a list of all Routes within the specified Pack. :param pack: The id of the Pack. + :param offset: Pagination offset + :param limit: Maximum number of items to return :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -137,6 +180,8 @@ async def list_async( base_url = self._get_url(base_url, url_variables) request = models.GetRoutesByPackRequest( + offset=offset, + limit=limit, pack=pack, ) @@ -179,16 +224,51 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) + def next_func() -> Awaitable[Optional[models.GetRoutesByPackResponse]]: + body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) + + async def empty_result(): + return None + + offset = request.offset if isinstance(request.offset, int) else 0 + + if not http_res.text: + return empty_result() + results = JSONPath("$.items").parse(body) + if len(results) == 0 or len(results[0]) == 0: + return empty_result() + limit_ = request.limit if isinstance(request.limit, int) else 0 + if len(results[0]) < limit_: + return empty_result() + next_offset = offset + len(results[0]) + + return self.list_async( + pack=pack, + offset=next_offset, + limit=limit, + retries=retries, + server_url=server_url, + timeout_ms=timeout_ms, + http_headers=http_headers, + ) + response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return unmarshal_json_response(models.CountedRoutes, http_res) + return models.GetRoutesByPackResponse( + result=unmarshal_json_response(models.PaginatedRoutes, http_res), + next=next_func, + ) if utils.match_response(http_res, "401", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) @@ -279,7 +359,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -379,7 +463,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -510,7 +598,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -641,7 +733,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -751,7 +847,11 @@ def append( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -861,7 +961,11 @@ async def append_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_samples.py b/src/cribl_control_plane/packs_samples.py index 12e75aac2..c87b5cffa 100644 --- a/src/cribl_control_plane/packs_samples.py +++ b/src/cribl_control_plane/packs_samples.py @@ -85,7 +85,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -187,7 +191,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -301,7 +309,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -413,7 +425,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_sources.py b/src/cribl_control_plane/packs_sources.py index 1d54562df..fb34b5cd2 100644 --- a/src/cribl_control_plane/packs_sources.py +++ b/src/cribl_control_plane/packs_sources.py @@ -116,7 +116,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -251,7 +255,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -395,7 +403,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -507,7 +519,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -607,7 +623,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -707,7 +727,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -813,7 +837,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -919,7 +947,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1019,7 +1051,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1119,7 +1155,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_sources_pq.py b/src/cribl_control_plane/packs_sources_pq.py index bd12910d4..23d033646 100644 --- a/src/cribl_control_plane/packs_sources_pq.py +++ b/src/cribl_control_plane/packs_sources_pq.py @@ -85,7 +85,11 @@ def clear( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -185,7 +189,11 @@ async def clear_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -285,7 +293,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -385,7 +397,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/packs_sources_statuses.py b/src/cribl_control_plane/packs_sources_statuses.py index 62e329214..b167120ba 100644 --- a/src/cribl_control_plane/packs_sources_statuses.py +++ b/src/cribl_control_plane/packs_sources_statuses.py @@ -95,7 +95,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -234,7 +238,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -375,7 +383,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -481,7 +493,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/pipelines.py b/src/cribl_control_plane/pipelines.py index 08a20b2e9..0d407a760 100644 --- a/src/cribl_control_plane/pipelines.py +++ b/src/cribl_control_plane/pipelines.py @@ -27,8 +27,8 @@ def list( Get a list of all Pipelines. - :param offset: Pagination offset - :param limit: Maximum number of items to return + :param offset: Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. + :param limit: Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -88,7 +88,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -154,8 +158,8 @@ async def list_async( Get a list of all Pipelines. - :param offset: Pagination offset - :param limit: Maximum number of items to return + :param offset: Starting point from which to retrieve results for this request. Use with limit to paginate the response into manageable batches. + :param limit: Maximum number of Pipelines to return in the response for this request. Use with offset to paginate the response into manageable batches. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -215,7 +219,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -348,7 +356,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -451,7 +463,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -548,7 +564,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -645,7 +665,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -742,7 +766,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -839,7 +867,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -947,7 +979,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1055,7 +1091,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["pipelines"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/routes_sdk.py b/src/cribl_control_plane/routes_sdk.py index 78f9b61bd..ce02b214d 100644 --- a/src/cribl_control_plane/routes_sdk.py +++ b/src/cribl_control_plane/routes_sdk.py @@ -6,7 +6,8 @@ from cribl_control_plane.types import OptionalNullable, UNSET from cribl_control_plane.utils import get_security_from_env from cribl_control_plane.utils.unmarshal_json_response import unmarshal_json_response -from typing import Any, Dict, Iterable, List, Mapping, Optional, Union +from jsonpath import JSONPath +from typing import Any, Awaitable, Dict, Iterable, List, Mapping, Optional, Union class RoutesSDK(BaseSDK): @@ -15,15 +16,19 @@ class RoutesSDK(BaseSDK): def list( self, *, + offset: Optional[int] = None, + limit: Optional[int] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> models.CountedRoutes: + ) -> Optional[models.GetRoutesResponse]: r"""List all Routes Get a list of all Routes. + :param offset: Pagination offset + :param limit: Maximum number of items to return :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -38,12 +43,18 @@ def list( base_url = server_url else: base_url = self._get_url(base_url, url_variables) + + request = models.GetRoutesRequest( + offset=offset, + limit=limit, + ) + req = self._build_request( method="GET", path="/routes", base_url=base_url, url_variables=url_variables, - request=None, + request=request, request_body_required=False, request_has_path_params=False, request_has_query_params=True, @@ -77,16 +88,47 @@ def list( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) + def next_func() -> Optional[models.GetRoutesResponse]: + body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) + + offset = request.offset if isinstance(request.offset, int) else 0 + + if not http_res.text: + return None + results = JSONPath("$.items").parse(body) + if len(results) == 0 or len(results[0]) == 0: + return None + limit_ = request.limit if isinstance(request.limit, int) else 0 + if len(results[0]) < limit_: + return None + next_offset = offset + len(results[0]) + + return self.list( + offset=next_offset, + limit=limit, + retries=retries, + server_url=server_url, + timeout_ms=timeout_ms, + http_headers=http_headers, + ) + response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return unmarshal_json_response(models.CountedRoutes, http_res) + return models.GetRoutesResponse( + result=unmarshal_json_response(models.PaginatedRoutes, http_res), + next=next_func, + ) if utils.match_response(http_res, "401", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) @@ -105,15 +147,19 @@ def list( async def list_async( self, *, + offset: Optional[int] = None, + limit: Optional[int] = None, retries: OptionalNullable[utils.RetryConfig] = UNSET, server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> models.CountedRoutes: + ) -> Optional[models.GetRoutesResponse]: r"""List all Routes Get a list of all Routes. + :param offset: Pagination offset + :param limit: Maximum number of items to return :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -128,12 +174,18 @@ async def list_async( base_url = server_url else: base_url = self._get_url(base_url, url_variables) + + request = models.GetRoutesRequest( + offset=offset, + limit=limit, + ) + req = self._build_request_async( method="GET", path="/routes", base_url=base_url, url_variables=url_variables, - request=None, + request=request, request_body_required=False, request_has_path_params=False, request_has_query_params=True, @@ -167,16 +219,50 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) + def next_func() -> Awaitable[Optional[models.GetRoutesResponse]]: + body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) + + async def empty_result(): + return None + + offset = request.offset if isinstance(request.offset, int) else 0 + + if not http_res.text: + return empty_result() + results = JSONPath("$.items").parse(body) + if len(results) == 0 or len(results[0]) == 0: + return empty_result() + limit_ = request.limit if isinstance(request.limit, int) else 0 + if len(results[0]) < limit_: + return empty_result() + next_offset = offset + len(results[0]) + + return self.list_async( + offset=next_offset, + limit=limit, + retries=retries, + server_url=server_url, + timeout_ms=timeout_ms, + http_headers=http_headers, + ) + response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return unmarshal_json_response(models.CountedRoutes, http_res) + return models.GetRoutesResponse( + result=unmarshal_json_response(models.PaginatedRoutes, http_res), + next=next_func, + ) if utils.match_response(http_res, "401", "application/json"): response_data = unmarshal_json_response(errors.ErrorData, http_res) raise errors.Error(response_data, http_res) @@ -264,7 +350,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -361,7 +451,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -489,7 +583,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -617,7 +715,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -724,7 +826,11 @@ def append( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -831,7 +937,11 @@ async def append_async( self.sdk_configuration.security, models.Security ), tags=["routes"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/samples.py b/src/cribl_control_plane/samples.py index ee781c26a..f7cbc7ac7 100644 --- a/src/cribl_control_plane/samples.py +++ b/src/cribl_control_plane/samples.py @@ -82,7 +82,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -181,7 +185,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -292,7 +300,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -401,7 +413,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["destinations"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/settings.py b/src/cribl_control_plane/settings.py index 02a02987c..f2c5897cb 100644 --- a/src/cribl_control_plane/settings.py +++ b/src/cribl_control_plane/settings.py @@ -89,7 +89,11 @@ def restart( self.sdk_configuration.security, models.Security ), tags=["system"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -181,7 +185,11 @@ async def restart_async( self.sdk_configuration.security, models.Security ), tags=["system"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/sources.py b/src/cribl_control_plane/sources.py index f38cbab1c..83cd2eb2b 100644 --- a/src/cribl_control_plane/sources.py +++ b/src/cribl_control_plane/sources.py @@ -45,7 +45,7 @@ def list( server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> Optional[models.ListInputResponse]: + ) -> Optional[models.GetInputResponse]: r"""List all Sources Get a list of all Sources. @@ -68,7 +68,7 @@ def list( else: base_url = self._get_url(base_url, url_variables) - request = models.ListInputRequest( + request = models.GetInputRequest( type=utils.unmarshal(type_, Optional[List[str]]), offset=offset, limit=limit, @@ -107,20 +107,24 @@ def list( hook_ctx=HookContext( config=self.sdk_configuration, base_url=base_url or "", - operation_id="listInput", + operation_id="getInput", oauth2_scopes=[], security_source=get_security_from_env( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) - def next_func() -> Optional[models.ListInputResponse]: + def next_func() -> Optional[models.GetInputResponse]: body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) offset = request.offset if isinstance(request.offset, int) else 0 @@ -147,7 +151,7 @@ def next_func() -> Optional[models.ListInputResponse]: response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return models.ListInputResponse( + return models.GetInputResponse( result=unmarshal_json_response(models.PaginatedInputResponse, http_res), next=next_func, ) @@ -176,7 +180,7 @@ async def list_async( server_url: Optional[str] = None, timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, - ) -> Optional[models.ListInputResponse]: + ) -> Optional[models.GetInputResponse]: r"""List all Sources Get a list of all Sources. @@ -199,7 +203,7 @@ async def list_async( else: base_url = self._get_url(base_url, url_variables) - request = models.ListInputRequest( + request = models.GetInputRequest( type=utils.unmarshal(type_, Optional[List[str]]), offset=offset, limit=limit, @@ -238,20 +242,24 @@ async def list_async( hook_ctx=HookContext( config=self.sdk_configuration, base_url=base_url or "", - operation_id="listInput", + operation_id="getInput", oauth2_scopes=[], security_source=get_security_from_env( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), retry_config=retry_config, ) - def next_func() -> Awaitable[Optional[models.ListInputResponse]]: + def next_func() -> Awaitable[Optional[models.GetInputResponse]]: body = utils.unmarshal_json(http_res.text, Union[Dict[Any, Any], List[Any]]) async def empty_result(): @@ -281,7 +289,7 @@ async def empty_result(): response_data: Any = None if utils.match_response(http_res, "200", "application/json"): - return models.ListInputResponse( + return models.GetInputResponse( result=unmarshal_json_response(models.PaginatedInputResponse, http_res), next=next_func, ) @@ -375,7 +383,11 @@ def create( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -475,7 +487,11 @@ async def create_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -572,7 +588,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -669,7 +689,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -772,7 +796,11 @@ def update( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -875,7 +903,11 @@ async def update_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -972,7 +1004,11 @@ def delete( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -1069,7 +1105,11 @@ async def delete_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/sources_pq.py b/src/cribl_control_plane/sources_pq.py index 09e63bfce..6122322de 100644 --- a/src/cribl_control_plane/sources_pq.py +++ b/src/cribl_control_plane/sources_pq.py @@ -82,7 +82,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -179,7 +183,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -276,7 +284,11 @@ def clear( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -373,7 +385,11 @@ async def clear_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/sources_statuses.py b/src/cribl_control_plane/sources_statuses.py index bc5acf19d..409d37dd7 100644 --- a/src/cribl_control_plane/sources_statuses.py +++ b/src/cribl_control_plane/sources_statuses.py @@ -92,7 +92,11 @@ def list( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -227,7 +231,11 @@ async def list_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -362,7 +370,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -465,7 +477,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["sources"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/summaries.py b/src/cribl_control_plane/summaries.py index f59180619..7fe068292 100644 --- a/src/cribl_control_plane/summaries.py +++ b/src/cribl_control_plane/summaries.py @@ -89,7 +89,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["distributed"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -222,7 +226,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["distributed"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/teams.py b/src/cribl_control_plane/teams.py index 01ae36b6e..d3cbeab20 100644 --- a/src/cribl_control_plane/teams.py +++ b/src/cribl_control_plane/teams.py @@ -21,12 +21,12 @@ def get( timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, ) -> models.CountedTeamAccessControlList: - r"""Get the Access Control List for teams with permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product + r"""Get the team access control list for a Worker Group, Outpost Group, or Edge Fleet - Get the Access Control List (ACL) for teams that have permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product. + Get the Team access control list (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet.

This endpoint lists Teams with explicit access assignments on the Group or Fleet. The response does not include access granted to individual Team Members through direct user assignments or inherited based on Team Permissions and Roles at the Organization/Global, Workspace, or product level.

To list the user ACL for a Group or Fleet, use GET /products/{product}/groups/{id}/acl. :param product: Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. - :param id: The id of the Worker Group, Outpost Group, or Edge Fleet to get the team ACL for. + :param id: The id of the Worker Group, Outpost Group, or Edge Fleet to get the Team ACL for. :param type: Filter for limiting the response to ACL entries for the specified RBAC resource type. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method @@ -88,7 +88,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["teams"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -126,12 +130,12 @@ async def get_async( timeout_ms: Optional[int] = None, http_headers: Optional[Mapping[str, str]] = None, ) -> models.CountedTeamAccessControlList: - r"""Get the Access Control List for teams with permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product + r"""Get the team access control list for a Worker Group, Outpost Group, or Edge Fleet - Get the Access Control List (ACL) for teams that have permissions on a Worker Group, Outpost Group, or Edge Fleet for the specified Cribl product. + Get the Team access control list (ACL) for the specified Worker Group, Outpost Group, or Edge Fleet.

This endpoint lists Teams with explicit access assignments on the Group or Fleet. The response does not include access granted to individual Team Members through direct user assignments or inherited based on Team Permissions and Roles at the Organization/Global, Workspace, or product level.

To list the user ACL for a Group or Fleet, use GET /products/{product}/groups/{id}/acl. :param product: Name of the Cribl product that contains the Worker Group, Outpost Group, or Edge Fleet. - :param id: The id of the Worker Group, Outpost Group, or Edge Fleet to get the team ACL for. + :param id: The id of the Worker Group, Outpost Group, or Edge Fleet to get the Team ACL for. :param type: Filter for limiting the response to ACL entries for the specified RBAC resource type. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method @@ -193,7 +197,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["teams"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/tokens.py b/src/cribl_control_plane/tokens.py index d2c6b4c14..1fd0af8dc 100644 --- a/src/cribl_control_plane/tokens.py +++ b/src/cribl_control_plane/tokens.py @@ -23,8 +23,8 @@ def get( This endpoint is unavailable on Cribl.Cloud. Instead, follow the instructions at https://docs.cribl.io/stream/api-tutorials/#criblcloud to get an Auth token for Cribl.Cloud. - :param password: - :param username: + :param password: Password for the account. + :param username: Username of the account to authenticate. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -84,7 +84,11 @@ def get( oauth2_scopes=None, security_source=None, tags=["auth"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -128,8 +132,8 @@ async def get_async( This endpoint is unavailable on Cribl.Cloud. Instead, follow the instructions at https://docs.cribl.io/stream/api-tutorials/#criblcloud to get an Auth token for Cribl.Cloud. - :param password: - :param username: + :param password: Password for the account. + :param username: Username of the account to authenticate. :param retries: Override the default retry configuration for this method :param server_url: Override the default server URL for this method :param timeout_ms: Override the default request timeout configuration for this method in milliseconds @@ -189,7 +193,11 @@ async def get_async( oauth2_scopes=None, security_source=None, tags=["auth"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "node", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/utils/__init__.py b/src/cribl_control_plane/utils/__init__.py index 6120a33ee..0b27ffce2 100644 --- a/src/cribl_control_plane/utils/__init__.py +++ b/src/cribl_control_plane/utils/__init__.py @@ -36,6 +36,7 @@ async def run_sync_in_thread(func: Callable[..., _T], *args) -> _T: from .security import get_security, get_security_from_env from .serializers import ( + ALLOW_UNKNOWN_UNION_VARIANTS, get_pydantic_model, marshal_json, unmarshal, @@ -108,6 +109,7 @@ async def run_sync_in_thread(func: Callable[..., _T], *args) -> _T: "stream_to_bytes", "stream_to_bytes_async", "template_url", + "ALLOW_UNKNOWN_UNION_VARIANTS", "unmarshal", "unmarshal_json", "validate_decimal", @@ -130,6 +132,7 @@ async def run_sync_in_thread(func: Callable[..., _T], *args) -> _T: "parse_duration": ".datetimes", "get_global_from_env": ".values", "get_headers": ".headers", + "ALLOW_UNKNOWN_UNION_VARIANTS": ".serializers", "get_pydantic_model": ".serializers", "get_query_params": ".queryparams", "get_response_headers": ".headers", diff --git a/src/cribl_control_plane/utils/retries.py b/src/cribl_control_plane/utils/retries.py index c7418a628..406c1e7c3 100644 --- a/src/cribl_control_plane/utils/retries.py +++ b/src/cribl_control_plane/utils/retries.py @@ -318,6 +318,7 @@ def retry_with_backoff( retry_after_ms = _parse_retry_after_ms_header(exception.response) if retry_after_ms is not None: exception.retry_after = retry_after_ms + exception.response.close() sleep = _get_sleep_interval( exception, initial_interval, @@ -358,6 +359,7 @@ async def retry_with_backoff_async( retry_after_ms = _parse_retry_after_ms_header(exception.response) if retry_after_ms is not None: exception.retry_after = retry_after_ms + await exception.response.aclose() sleep = _get_sleep_interval( exception, initial_interval, diff --git a/src/cribl_control_plane/utils/serializers.py b/src/cribl_control_plane/utils/serializers.py index 1031ed930..5e57d36e8 100644 --- a/src/cribl_control_plane/utils/serializers.py +++ b/src/cribl_control_plane/utils/serializers.py @@ -112,11 +112,26 @@ def validate(c): return validate +ALLOW_UNKNOWN_UNION_VARIANTS = "speakeasy_allow_unknown_union_variants" +"""Validation-context key enabling the Unknown fallback on open discriminated +unions. The SDK sets it when deserializing server responses; validation +without it (e.g. of user-constructed request payloads) stays strict. Pass +``context={ALLOW_UNKNOWN_UNION_VARIANTS: True}`` to ``model_validate`` to +opt in when parsing response payloads manually.""" + + def unmarshal_json(raw, typ: Any) -> Any: - return unmarshal(from_json(raw), typ, coerce_iterables=False) + return unmarshal( + from_json(raw), typ, coerce_iterables=False, allow_unknown_union_variants=True + ) -def unmarshal(val, typ: Any, coerce_iterables: bool = True) -> Any: +def unmarshal( + val, + typ: Any, + coerce_iterables: bool = True, + allow_unknown_union_variants: bool = False, +) -> Any: if coerce_iterables: val = _coerce_iterables_for_type(val, typ) unmarshaller = create_model( @@ -125,7 +140,12 @@ def unmarshal(val, typ: Any, coerce_iterables: bool = True) -> Any: __config__=ConfigDict(populate_by_name=True, arbitrary_types_allowed=True), ) - m = unmarshaller(body=val) + if allow_unknown_union_variants: + m = unmarshaller.model_validate( + {"body": val}, context={ALLOW_UNKNOWN_UNION_VARIANTS: True} + ) + else: + m = unmarshaller(body=val) # pyright: ignore[reportAttributeAccessIssue] return m.body # type: ignore diff --git a/src/cribl_control_plane/utils/unions.py b/src/cribl_control_plane/utils/unions.py index 243464023..45248ff68 100644 --- a/src/cribl_control_plane/utils/unions.py +++ b/src/cribl_control_plane/utils/unions.py @@ -1,12 +1,13 @@ """Code generated by Speakeasy (https://speakeasy.com). DO NOT EDIT.""" -from typing import Any +from typing import Any, Mapping -from pydantic import BaseModel, TypeAdapter, ValidationError +from pydantic import BaseModel, TypeAdapter, ValidationError, ValidationInfo def parse_open_union( v: Any, + info: ValidationInfo, *, disc_key: str, variants: dict[str, Any], @@ -16,26 +17,42 @@ def parse_open_union( """Parse an open discriminated union value with forward-compatibility. Known discriminator values are dispatched to their variant types. - Unknown discriminator values — or known discriminator values whose - payload fails variant validation (e.g. a partial variant emitted by a - newer server) — produce an instance of the fallback class, preserving - the raw payload for inspection. + + The Unknown fallback only applies when the validation context carries + ALLOW_UNKNOWN_UNION_VARIANTS, which the SDK sets when deserializing + server responses. There, unknown discriminator values — or known + discriminator values whose payload fails variant validation (e.g. a + partial variant emitted by a newer server) — produce an instance of the + fallback class, preserving the raw payload for inspection. Without the + flag (e.g. user-constructed request payloads), invalid values raise so + mistakes surface locally instead of being sent to the server. Non-dict values and dicts missing the discriminator deliberately raise instead of falling back, so pydantic can try sibling branches of an enclosing union (e.g. None in Optional[...]). """ + # pylint: disable=import-outside-toplevel + from .serializers import ALLOW_UNKNOWN_UNION_VARIANTS + if isinstance(v, BaseModel): return v if not isinstance(v, dict) or disc_key not in v: raise ValueError(f"{union_name}: expected object with '{disc_key}' field") + context = info.context + fallback_allowed = isinstance(context, Mapping) and bool( + context.get(ALLOW_UNKNOWN_UNION_VARIANTS) + ) disc = v[disc_key] variant_cls = variants.get(disc) - if variant_cls is not None: - try: - if isinstance(variant_cls, type) and issubclass(variant_cls, BaseModel): - return variant_cls.model_validate(v) - return TypeAdapter(variant_cls).validate_python(v) - except ValidationError: + if variant_cls is None: + if fallback_allowed: return unknown_cls(raw=v) - return unknown_cls(raw=v) + raise ValueError(f"{union_name}: unrecognized {disc_key} value {disc!r}") + try: + if isinstance(variant_cls, type) and issubclass(variant_cls, BaseModel): + return variant_cls.model_validate(v, context=info.context) + return TypeAdapter(variant_cls).validate_python(v, context=info.context) + except ValidationError: + if not fallback_allowed: + raise + return unknown_cls(raw=v) diff --git a/src/cribl_control_plane/versions_configs.py b/src/cribl_control_plane/versions_configs.py index af835b469..3987d69ec 100644 --- a/src/cribl_control_plane/versions_configs.py +++ b/src/cribl_control_plane/versions_configs.py @@ -75,7 +75,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -165,7 +169,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), diff --git a/src/cribl_control_plane/versions_statuses.py b/src/cribl_control_plane/versions_statuses.py index a04f305ea..1e54b75c9 100644 --- a/src/cribl_control_plane/versions_statuses.py +++ b/src/cribl_control_plane/versions_statuses.py @@ -75,7 +75,11 @@ def get( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c), @@ -165,7 +169,11 @@ async def get_async( self.sdk_configuration.security, models.Security ), tags=["versioning"], - extensions={"x-cribl-availability": "both", "x-cribl-internal": False}, + extensions={ + "x-cribl-api-context": ["group", "leader", "single"], + "x-cribl-availability": "both", + "x-cribl-internal": False, + }, ), request=req, is_error_status_code=lambda c: utils.match_status_codes(["4XX", "5XX"], c),